Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet

 Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet
  • Hackers exploited trusted software updates to deliver malware directly into car head units
  • Kaspersky says this is the first campaign tailored specifically for vehicle head units
  • The malware can run silently without showing drivers any visible interface

Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.

A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.

According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.

Compromised update channels deliver malware straight into vehicles

Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.

The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.

Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.

Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.

Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.

The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.

Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.

The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.

BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.

Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.

According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.

Head units present a growing and largely unprotected attack surface

Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.

Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.

This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.

Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.

However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.

That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.

The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.

Google logo on a black background next to text reading 'Click to follow TechRadar'



from Latest from TechRadar US in Computing News https://ift.tt/Az1SUkY
via

New malware targets Microsoft Teams users by posing as your company's IT helpdesk

 New malware targets Microsoft Teams users by posing as your company's IT helpdesk
  • Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages
  • Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control
  • Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering

For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.

According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.

The malware itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.

This is not SickKids' first attack

BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.

The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device.

The full list of Indicators of Compromise (IoC) can be found on this link. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.

Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.

Via BleepingComputer



from Latest from TechRadar US in Computing News https://ift.tt/7Q5R1sC
via

Canadian SickKids hospital hit again by cyberattacks, more data stolen

 Canadian SickKids hospital hit again by cyberattacks, more data stolen
  • SickKids hospital in Canada hit by third‑party software vulnerability, exposing employee data
  • Clinical systems and patient records unaffected; patient care continued without disruption
  • Affected staff and applicants offered 24 months of free credit monitoring and identity protection

The Hospital for Sick Children, a major pediatric hospital in Canada, suffered a cyberattack that affected parts of its website, and resulted in the loss of some employee personal information.

In an announcement published on its website, the organization (also known as SickKids) said the unnamed attackers abused a “vulnerability in a third-party software application used by SickKids and other organizations.” The announcement did not say exactly which app was used in the attack, or what the vulnerability was, but stressed that clinical systems and patient information were not affected.

“Patient care has continued as usual”, it added.

This is not SickKids' first attack

After launching an investigation, SickKids learned that personal information of some former and current employees working at SickKids, Boomerang, and SickKids Foundation, as well as SickKids job applications, was exposed. It did not detail the nature of the exposed information, or how many people are affected.

Whatever that number is, those people have been offered 24 months of complimentary credit monitoring and identity protection services, for free.

“We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us,” the company concluded. Ironically, SickKids was also committed in late 2022 and early 2023, when it was struck by LockBit and had its systems locked down by the ransomware threat actor.

While, in that incident, LockBit apologized, gave the decryptor away for free, excommunicated the affiliate responsible, and did not mention any stolen data, by late 2022 double extortion attacks were standard practice, meaning data was likely exfiltrated then, as well.

At the time, LockBit was one of the most active and most dangerous ransomware operators. In early 2024, its operations were severely disrupted through Operation Cronos, but it seems the group is making a comeback. There are reports from late 2025 of LockBit 5.0 claims, including a purported attack on U.S Bank, but the news is yet to be confirmed.

Via The Record



from Latest from TechRadar US in Computing News https://ift.tt/pEHaDc2
via

Private equity giant Apollo confirms data breach saw personal info stolen

 Private equity giant Apollo confirms data breach saw personal info stolen
  • Apollo confirms July 2026 cyberattack via social engineering exposed PII in its cloud environment
  • Data included names, DOB, contact info, addresses, and Social Security numbers
  • Firm offers two years of identity protection; no evidence of dark web leaks yet

Apollo, one of the biggest private equity firms in the world, has confirmed it suffered a cyberattack which compromised some people’s personally identifiable information.

The company notified California’s Attorney General’s Office about the breach and shared a copy of the letter it is now sending out to affected individuals. It is impossible to discern from the letter if the victims are Apollo employees, customers, or someone else entirely, but the company did clearly explain what happened.

As per the letter, an unidentified threat actor tricked an Apollo employee into granting them access to the company’s cloud environment. The attackers used social engineering (usually phishing), which means the victim either tried logging in using a spoofed landing page, unknowingly installed an infostealer, or was convinced to grant the attackers access via remote monitoring and management software.

Was there really a hack?

The company spotted the attack a few days later, and after activating its safety protocols (notifying the police, enhancing its security protocols, and bringing in third-party forensic experts), launched an investigation which showed that the attackers accessed its cloud platform between July 6 and 10.

“During our investigation, we learned on August 12, 2026 that the information potentially impacted by this incident included your name, date of birth, contact information, home address, and your Social Security Number (SSN),” the company said. This means that financial data such as credit card or bank account information, was not compromised.

Still, cybercriminals can make use of this type of information, as is often the case in identity theft, business email compromise, and even wire fraud.

Apollo is now offering two years of free identity theft protection and monitoring for affected individuals through Cyberscout.

At press time, no threat actors claimed responsibility for the attack, and the data has not yet surfaced anywhere on the dark web.

Via TechCrunch



from Latest from TechRadar US in Computing News https://ift.tt/VTFzds8
via

No driver, no problem — devs use Claude AI to craft native macOS tool for an 'obscure' Windows-only printer

 No driver, no problem — devs use Claude AI to craft native macOS tool for an 'obscure' Windows-only printer
  • India-based developer Kuber Mehta uses Claude Code to create a macOS driver for the HP Laser 1008a
  • Previously, only the official drivers for Windows and Linux were available for the relatively obscure 2023 laser printer
  • The AI-generated driver was created over a series of meticulous prompts, and is now available via GitHub

The days of avoiding hardware that is incompatible with your operating system could be over. A developer based in India has created a macOS driver for a largely unknown HP printer using Claude Code, the agentic command-line coding tool developed by Anthropic.

Released in 2023, the HP Laser 1008a was issued with drivers for Windows and Linux, but not macOS. By using AI to generate a driver for macOS, developer Kuber Mehta has demonstrated that incompatible hardware could soon be a thing of the past.

Mehta has shared the code on GitHub and has also posted about the process on social media, and also compiled a transcript of the exchange, which has been published online for reference.

HP’s Samsung printer

Describing the issue in the introduction to the transcript, Mehta explains that the HP Laser 1008a is a “rebadged Samsung, host-based printer that speaks a proprietary raster language (SPL3), and it has no macOS driver and no AirPrint.”

No SPL3 drivers have been published for macOS previously, so the process relied on a conversation with Claude Code and reference to the Windows and Linux drivers.

The GitHub intro adds that the HP Laser 1008a and siblings in the series (1003 and 1006 a/w) have another problem: “They do not speak PostScript or PCL.” Anyone familiar with the world of printer drivers will recognize the challenge faced by Mehta, which makes the use of Claude Code even more impressive.

Using Claude Code with the Opus 4.8 model, the driver was compiled in 30-40 prompts. This might have been even quicker had the AI not made various assertions that required correcting.

The process moved through “install the drivers” to establishing the print language by analysing the printer’s error pages, via direct contact with the device and “running HP's real rastertospl codec inside a Linux container to produce genuine SPL3, to a reboot-safe background daemon.”

From here, Mehta and Claude Code moved to the published, MIT-licensed installer, which patches the macOS open-source printer driver package SpliX, adding support for the SPL3 printers (by default, SpliX handles SPL2 and SPLc drivers).

Building from AI

While already a developer, Kuber Mehta admitted learning about macOS drivers from the process, perhaps an unforeseen benefit of using generative AI tools for coding.

The GitHub repo outlines some revisions that have been made to the initial release, which is now “a tiny native IOKit helper” that dispenses with Python, pyusb, and libusb and can be swiftly installed from the Terminal.



from Latest from TechRadar US in Computing News https://ift.tt/ZF7gr2m
via

'We're offering gamers not just two more headsets, but two different ways to experience their games' — Audio specialist beyerdynamic announces two new, affordable wireless headsets, the MMX 100 and MMX 130

 'We're offering gamers not just two more headsets, but two different ways to experience their games' — Audio specialist beyerdynamic announces two new, affordable wireless headsets, the MMX 100 and MMX 130
  • Beyerdynamic has announced the MMX 100 wireless and MMX 130 wireless
  • The MMX 100 wireless launches on September 1 for £89
  • The MMX 130 wireless arrives in October for £109

German audio specialist beyerdynamic has announced two new wireless headsets, the closed-back MMX 100 wireless and the open-back MMX 130 wireless.

Beyerdynamic's MMX gaming range expands with two new wireless headsets representing two styles of gaming: the closed-back MMX 100 wireless for players who want to minimize distracting ambient noise and focus on their game, or the MMX 130 wireless, which is ideal for gamers who prefer to experience the atmosphere, soundtracks, and ambient sounds in greater detail.

"With these two models, beyerdynamic is making its audio expertise accessible to an even wider gaming audience," the company said. "Rather than offering a plethora of unnecessary features and gimmicks, both headsets focus on the essentials: precise sound, high levels of comfort, flexible connectivity, and long-lasting quality."

The MX 100, with its velour ear pads and a lightweight 275-gram design, offers a closed-back design to reduce external noise, a detachable Meta Voice microphone for clear communication, and a replaceable battery that lasts over 80 hours.

It can also be connected to PCs, consoles, smartphones, and handheld devices via Bluetooth 6.0, the included low-latency USB dongle, or a cable.

As for the MMX 130, gamers can expect a wireless headset designed for audio enthusiasts, with an open-back design that balances "a natural, spacious soundstage" with external noise, whatever the user is listening to.

Sporting a titanium-coated 40 mm driver for precise sounds, the MMX 1300 is recommended for gamers who enjoy story-driven, open-world, role-playing games (RPGs), and simulation games.

"With the MMX 100 wireless and MMX 130 wireless, we're offering gamers not just two more headsets, but two different ways to experience their games," said Matthias Heilig, product marketing manager for gaming at beyerdynamic. "Those looking for focus and isolation will find it in the closed-back MMX 100 wireless. Those who want to experience gaming worlds as naturally and spatially as possible will find an exciting alternative in the open-back MMX 130 wireless."

The MMX 100 wireless will launch first on September 1 in Black and Arctic White for £89, while the MMX 130 wireless will follow in October, also in Black and Arctic White, for £109.

The MMX 100 wireless will also premiere at Gamescom 2026 and be available for public testing.



from Latest from TechRadar US in Gaming News https://ift.tt/eWCp0iL
via TECHNICAL SAFEER

Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams

 Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams
  • Infoblox Threat Intel counted roughly 65,000 expired domains re-registered every day in the first half of 2026, close to one in five of all new registrations
  • An actor it calls Sable Squirrel controls more than 10,000 domains and is estimated, by extrapolation, to have spent over $7 million buying expired names for their inherited traffic and domain authority
  • Some of the domains are also used to function as command-and-control structures for existing malware that can be traced back to the same group

A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about.

New research from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least one criminal operation has been buying it in bulk.

The study, published as a three-part series, focuses on what the industry calls dropcatch domains: names that lapsed, were released back to the registry, and were then re-registered by someone else entirely.

A dropcatch domain situation: A gambling business with a malware-enabling catch

Dropcatch domains aren't new; software has been primed to spot expiring domains for years, and it sometimes snags the occasional massive win for users who deploy such solutions.

This lets users start with domains that already have history that benefits them or flip certain domains for a price that is often a multiple of the domain's original purchase price.

Infoblox counted an average of 50,400 such re-registrations a day across generic top-level domains in the first half of 2026, rising to roughly 65,000 once country-code domains are added. That amounts to close to a fifth of all daily registrations. The rate is highest on .net and .xyz, where nearly three in ten newly observed names had a previous life, with .com behind them at 24.5%.

The problem is that not all of these are seemingly innocent or small-scale scalping operations: Infoblox has identified an entity it has labeled Sable Squirrel, part of a naming convention the company applies to domain hoarders. It controls more than 10,000 domains, most of which support a large Vietnamese-language sports piracy operation operating under brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom.

Infoblox estimates the actor's total spend on expired domains at north of $7 million, which it describes as the largest domain acquisition budget it has identified for a single actor in the industry. The bigger problem is that Infoblox also found that a subset of these streaming domains runs as malware command and control while continuing to serve live football to human visitors.

More than 31,000 samples identified called back to Sable Squirrel's infrastructure, spanning Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, plus samples carrying HiddenTear ransomware signatures.

Infoblox said the operator's carelessness made finding a link easier: many samples carry the actor's brand names in their Windows executable metadata, with fields reading socolive, xoilac, and 8xbet. Infoblox confirmed 405 domains as malware C2, which is roughly four percent of the total domains the organization controls, and the weaponization arrived as a single wave in late 2025 rather than as the operation's original purpose.

Sable Squirrel's core business is gambling, and while the entity tries to mask it as a streaming operation, it also doubles as an acquisition channel for the same. While law enforcement has not been silent here, it has had limited luck at best: Vietnamese authorities froze some of the flagship sites in February 2026 and charged 30 suspects in March.

They also seized assets Infoblox puts at roughly $12 million, but it seems to have survived and continues to expand, having acquired and run World Cup-centric domains since June, further expanding its footprint in a world where it has already identified and secured a large chunk of what is arguably a very important commodity: Domain authority.



from Latest from TechRadar US in Computing News https://ift.tt/F8MsKW9
via

Security experts targeted by fake crypto conference in scam to hand over details

 Security experts targeted by fake crypto conference in scam to hand over details
  • Huntress spotted a ClickFix campaign targeting security pros via fake conference invites
  • Victims tricked into pasting code that installs AMOS infostealer on macOS
  • If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets

Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer malware, experts have warned.

An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers Huntress, who were targets themselves.

The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim.

Follow-up attack

Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.

From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.

Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.

The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”.

“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”



from Latest from TechRadar US in Computing News https://ift.tt/FfEJ6vz
via

Are your PC games crashing after the latest Windows 11 update? Microsoft is investigating whether a nasty new bug is the cause — but there are workarounds

 Are your PC games crashing after the latest Windows 11 update? Microsoft is investigating whether a nasty new bug is the cause — but there are workarounds
  • Windows 11's August update has broken some PC games
  • Microsoft is investigating reports of crashes, but right now it's unclear what the root cause is
  • Theories point to security measures in the update potentially causing issues with certain drivers and conflicts with anti-cheat tools

Windows 11 has run into trouble with gamers (again) after the latest monthly update for the OS, and Microsoft is investigating what's gone wrong.

The Register noticed that Microsoft has posted on the Windows release health dashboard about "reports of certain games becoming unresponsive" following its latest patch.

In some cases, games are either freezing and becoming unresponsive, as mentioned, or simply closing (crashing to the desktop), with an error ('Exception Access Violation') being displayed in some cases. There are also some reports of spontaneous reboots occurring after a game crashes.

Not all PC games are affected by any means, with Microsoft noting that reports are coming in from players of Arc Raiders, Marvel Tokon: Fighting Souls, and The Finals.

Microsoft is currently trying to work out what's going on, saying: "Ongoing investigation indicates that this issue is related to peripherals or internal device components which have RGB lighting features. Such devices may install drivers or code components with file names similar to inpoutx64. In systems where these drivers are found, the issue is then triggered by launching certain games."

Microsoft adds that it's currently trying to "understand the relationship between these RGB components and the games which trigger this issue", and says it will update gamers when more information becomes available.

Analysis: theories and workarounds

A Raider fires at a distant robotic spider-like enemy in a desert setting

(Image credit: Embark)

Microsoft is suggesting that this may be a driver-related issue of some kind, rather than a problem with Windows 11 itself. Of course, changes to Windows 11 could be the root cause, and the company admits that, and says it's still trying to "determine if this is an issue caused by Microsoft" on the release health dashboard.

As The Register points out, some on Reddit are theorizing that this bug is to do with "tightened kernel handle validation" which was introduced with the latest patch for Windows 11. Essentially meaning that Microsoft has tightened aspects of security with the August update, and that this is causing driver glitches, ones that were previously ignored, to be picked up (and subsequently crashing games).

The mentioned driver (inpoutx64) isn't just used in software controlling RGB lighting, but also in some system utilities needing low-level system access (for hardware monitoring, for example, and one such tool is mentioned in the above Reddit post: ZenTimings). It seems that if this driver is present on the host PC, the game's anti-cheat probing it now throws up a problem (post-patch), and that leads to the crash.

If this bug is causing you grief — and there are a lot of Arc Raiders players out there in that particular boat — there are workarounds that can make the game playable again.

The first is the most obvious and easiest fix: remove the August update for Windows 11 (or roll back the OS to before it was installed). You can remove an update in Windows Update, in the Update History panel — just find the patch (KB5121003 in this case) and uninstall it. However, bear in mind that you will be without a bunch of security fixes (and other features, including faster app launching) if you don't have this update on your PC.

The other alternative is to remove the problematic driver file, which seemingly won't harm your system (that said, if you do so, it's at your own risk — I haven't tested this). Going by the advice in the above Reddit thread — and also from the developer of Arc Raiders (Embark) — what you need to do is open the Command Prompt in Windows 11 by typing cmd in the search box, then right-click on Command Prompt and select 'Run as administrator'.

Once the prompt appears, type the following and press enter:

sc stop inpoutx64

Then type this second line and press enter:

sc delete inpoutx64

Now close the Command Prompt, open File Explorer, and find the following folder: C:\Windows\System32\drivers.

In that folder you should see the inpoutx64 file, it may be a SYS or DLL file (or both). Delete any of those files which are present.

That's the driver removed, and you should now be good to go, and you can still have the August update installed. But as I already noted, proceed at your own risk if you take this route.

The best bet for now may be to sit tight and wait for the results of Microsoft's investigation, and hopefully we'll hear something soon. However, this could be a somewhat thorny problem to untangle, and it rather sounds like a case of Microsoft dealing with a security issue — one which should be fixed — and that cure causing collateral damage due to driver wonkiness.

Whatever the case, on social media, a good many PC gamers are blaming Microsoft for this latest gaming-related issue in Windows 11.

One Redditor delivers the following barb: "They can't even keep the one thing they had over Linux. If you have to worry about whether or not your games work anyway, why still use Windows?"

Another observes: "Since 2025 December update till today — EVERY single month the update breaks something! There was no single month without issues."

There's no shortage of shots fired at Microsoft for monthly update woes, accusations of this being the fault of vibe coding (AI), and threats to leave for greener Linux desktop pastures. Business as usual, then.



from Latest from TechRadar US in Gaming News https://ift.tt/5B2ScrT
via TECHNICAL SAFEER

Are your PC games crashing after the latest Windows 11 update? Microsoft is investigating whether a nasty new bug is the cause — but there are workarounds

 Are your PC games crashing after the latest Windows 11 update? Microsoft is investigating whether a nasty new bug is the cause — but there are workarounds
  • Windows 11's August update has broken some PC games
  • Microsoft is investigating reports of crashes, but right now it's unclear what the root cause is
  • Theories point to security measures in the update potentially causing issues with certain drivers and conflicts with anti-cheat tools

Windows 11 has run into trouble with gamers (again) after the latest monthly update for the OS, and Microsoft is investigating what's gone wrong.

The Register noticed that Microsoft has posted on the Windows release health dashboard about "reports of certain games becoming unresponsive" following its latest patch.

In some cases, games are either freezing and becoming unresponsive, as mentioned, or simply closing (crashing to the desktop), with an error ('Exception Access Violation') being displayed in some cases. There are also some reports of spontaneous reboots occurring after a game crashes.

Not all PC games are affected by any means, with Microsoft noting that reports are coming in from players of Arc Raiders, Marvel Tokon: Fighting Souls, and The Finals.

Microsoft is currently trying to work out what's going on, saying: "Ongoing investigation indicates that this issue is related to peripherals or internal device components which have RGB lighting features. Such devices may install drivers or code components with file names similar to inpoutx64. In systems where these drivers are found, the issue is then triggered by launching certain games."

Microsoft adds that it's currently trying to "understand the relationship between these RGB components and the games which trigger this issue", and says it will update gamers when more information becomes available.

Analysis: theories and workarounds

A Raider fires at a distant robotic spider-like enemy in a desert setting

(Image credit: Embark)

Microsoft is suggesting that this may be a driver-related issue of some kind, rather than a problem with Windows 11 itself. Of course, changes to Windows 11 could be the root cause, and the company admits that, and says it's still trying to "determine if this is an issue caused by Microsoft" on the release health dashboard.

As The Register points out, some on Reddit are theorizing that this bug is to do with "tightened kernel handle validation" which was introduced with the latest patch for Windows 11. Essentially meaning that Microsoft has tightened aspects of security with the August update, and that this is causing driver glitches, ones that were previously ignored, to be picked up (and subsequently crashing games).

The mentioned driver (inpoutx64) isn't just used in software controlling RGB lighting, but also in some system utilities needing low-level system access (for hardware monitoring, for example, and one such tool is mentioned in the above Reddit post: ZenTimings). It seems that if this driver is present on the host PC, the game's anti-cheat probing it now throws up a problem (post-patch), and that leads to the crash.

If this bug is causing you grief — and there are a lot of Arc Raiders players out there in that particular boat — there are workarounds that can make the game playable again.

The first is the most obvious and easiest fix: remove the August update for Windows 11 (or roll back the OS to before it was installed). You can remove an update in Windows Update, in the Update History panel — just find the patch (KB5121003 in this case) and uninstall it. However, bear in mind that you will be without a bunch of security fixes (and other features, including faster app launching) if you don't have this update on your PC.

The other alternative is to remove the problematic driver file, which seemingly won't harm your system (that said, if you do so, it's at your own risk — I haven't tested this). Going by the advice in the above Reddit thread — and also from the developer of Arc Raiders (Embark) — what you need to do is open the Command Prompt in Windows 11 by typing cmd in the search box, then right-click on Command Prompt and select 'Run as administrator'.

Once the prompt appears, type the following and press enter:

sc stop inpoutx64

Then type this second line and press enter:

sc delete inpoutx64

Now close the Command Prompt, open File Explorer, and find the following folder: C:\Windows\System32\drivers.

In that folder you should see the inpoutx64 file, it may be a SYS or DLL file (or both). Delete any of those files which are present.

That's the driver removed, and you should now be good to go, and you can still have the August update installed. But as I already noted, proceed at your own risk if you take this route.

The best bet for now may be to sit tight and wait for the results of Microsoft's investigation, and hopefully we'll hear something soon. However, this could be a somewhat thorny problem to untangle, and it rather sounds like a case of Microsoft dealing with a security issue — one which should be fixed — and that cure causing collateral damage due to driver wonkiness.

Whatever the case, on social media, a good many PC gamers are blaming Microsoft for this latest gaming-related issue in Windows 11.

One Redditor delivers the following barb: "They can't even keep the one thing they had over Linux. If you have to worry about whether or not your games work anyway, why still use Windows?"

Another observes: "Since 2025 December update till today — EVERY single month the update breaks something! There was no single month without issues."

There's no shortage of shots fired at Microsoft for monthly update woes, accusations of this being the fault of vibe coding (AI), and threats to leave for greener Linux desktop pastures. Business as usual, then.



from Latest from TechRadar US in Computing News https://ift.tt/5B2ScrT
via

Meta smart glasses could soon be banned in cinemas, says UK trade body — but this time it’s more about piracy than privacy

 Meta smart glasses could soon be banned in cinemas, says UK trade body — but this time it’s more about piracy than privacy
  • UK movie theatres considering smart glasses ban
  • The ban would be over privacy and piracy concerns
  • It's yet another instance of private bans restricting the tech

Privacy concerns have rocked Meta’s smart glasses business. They’re being ridiculed online as ‘perv glasses,’ and their use is banned in a growing number of spaces. In the UK, this could also soon include cinemas, though it’s for a very different p-word: piracy.

The main concern with camera glasses, like the ones Meta produces with its partners Ray-Ban and Oakley, is that people can record in a fairly secretive way. This is an issue for the general public as they don’t know when or if they’re being recorded, and for venues like cinemas and theatres as it allows movies and live shows to be subtly recorded by the audience.

With a stable enough internet connection, the viewing could even be live-streamed.

The ban hasn’t taken effect yet, but its consideration is another blow for smart glasses makers and users, who are finding it increasingly difficult to wear their specs because of their spy-camera capabilities.

Meta Ray-Ban Gen 2

(Image credit: Meta)

Meta would argue that recording isn’t covert. There is a light that comes on and stays on while you record. Plus, Meta has taken numerous steps to disable recording capabilities if this light is tampered with — either via a simple cover or by fiddling with the hardware.

However, critics have argued the light is easy to miss if you don’t know to look for it, especially if you're outdoors during the day or in a bright place.

In a dark theatre or cinema, the recording light would arguably be a lot more noticeable, though the proposed ban would reduce the risk that bad actors sneak through — while also addressing privacy concerns the glasses raise for other patrons, and banning glasses that allow more covert filming.

Because while Meta is the most well-known smart glasses maker, and so is taking the heaviest share of the backlash, it isn’t the only player in town. Some glasses manufacturers aren't as strict about tackling modders who disable their recording indicator, while others make the indicator even less noticeable or don’t ship with one installed.

Meta Ray-Ban Scriber Optics

(Image credit: Future / Hamish Hector)

Going, going, gone?

Governments have also been considering action against smart glasses; however, we have yet to see much in the way of widespread bans. At this rate, we might not need to.

The court of public opinion has issued an overwhelmingly negative verdict on smart glasses. The privacy concerns for people wearing the glasses, and for passersby caught in their gaze who never consented to having their life captured by smart specs,

Even previous champions of the technology I’ve spoken with — journalists like myself who have used and tested, and loved these glasses — have stopped wearing them outside of our reviews. I’ve written before how I’m genuinely fearful I’ll get accosted in the street if I’m caught wearing these glasses.

Besides the threat of retaliation, the steady banning of these glasses across various venues makes them increasingly useless. That’s doubly true for folks who need prescription glasses — smart glasses bans often say that the glasses having prescription lenses is no excuse, meaning you could spend $500 / £500 / AU$750 plus on a pair of glasses you can’t wear anywhere.

The Ray-Ban Meta Smart Glasses Collection is stylish

(Image credit: Meta)

Is this the end of smart glasses then? A serious perception overhaul could help, though it’s unclear how that would be achieved without such major software changes or hardware alterations, such as removing the camera altogether — though, from experience, cameraless smart specs don’t impress me. It’s too useful a feature to lose out on.

To that end, it’s a lose-lose, and that’s a shame for a category I think is quite fun and cool when people aren’t being creeps with them. They’re also proving a handy tool for people with visual impairments as the glasses can see and describe the world for them.

We’ll have to wait and see what happens, but I expect it’ll continue to be a rocky road ahead for smart glasses.



from Latest from TechRadar US in Computing News https://ift.tt/sfcqSjG
via

Adobe Firefly just added three new AI audio tools for creators and marketers — I tested them all to see if they're any good

 Adobe Firefly just added three new AI audio tools for creators and marketers — I tested them all to see if they're any good
  • Adobe releases three new AI audio tools on Firefly
  • Creators can now use Generate Music, Generate Speech, and Generate Sound Effects
  • I tried them out to see how they perform in video creation

After sitting in beta for sometime, Adobe Firefly has now made three new AI audio tools promising "studio-quality sound" available for all creators. I had a play with each one to see if the results were as good as promised - and on the whole, they delivered, with a few quirks.

Generate Music, Generate Sound Effects, and Generate Speech are the latest audio features to hit Adobe's browser-based AI platform (no prizes for guessing what each of these do (sorry)). From my experimenting with all three, Generate Music is the high-point here, it's way better than I thought it'd be and I can see marketers and creators getting serious use from it.

The launch coincides with a recent survey conducted by Adobe alongside Berklee College of Music, 32.7% of video creators, musicians, and marketers confirmed they use AI-generated music "as the final track in their published work." And it's that sizeable figure, I suspect, driving this particular update.

So, what's new?

There are three AI tools now available to everyone. They're all pretty self-explanatory, but here's what you need to know.

  • Generate Music lets you create licensed tracks matching your videos' length and mood.
  • Generate Speech takes scripts and turns them into voiceovers.
  • Generate Sound Effects generates - you guessed it - sound effects that match the action and timing of a video.

But are they any good?

I've written before about my agnosticism towards AI in general, and my issues using it for creative work. It's a facsimile of art.

Still, Adobe's tools have impressed even the hyper AI-sceptics on my team - notably features like Generative Extend in its video editing software. And I'm nothing if not open minded. So, I decided to try these tools out for myself to find out what's really going on here. You can try them yourself by clicking here.

The focus here, at least for now, is around speeding up creative workflows for the likes of marketers and content creators.

Creating AI music

Using three new AI audio tools in Adobe Firefly to generate music, speech, and sound effects

(Image credit: Adobe // Future)

I started with Generate Music, where you prompt freely or upload a video and the AI will take a punt at what sort of music you want. I used a short 27-second clip I filmed for my reMarkable Paper Pure review (mostly because it was still in my download folder).

Based on that, Firefly suggested a prompt for "a calm, thoughtful song with ambient electronic style for a product demonstration."

I hit Generate, and in a couple of seconds - it's actually impressively fast - I was served four tracks to choose from, all different but with the same vibe. They were...ok. A bit generic, but they'd do in a pinch. Or to rush a project to completion.

I decided to add a few more terms to the prompt, like "jazz", "cinematic", for use in a "vlog" and "trailer". I changed the Energy from "low" to "medium." The results were a big improvement.

Like all AI tools, the more prompting, the better the output, and there is an option to describe the vibe, style, and purpose yourself if you have an idea in mind.

You can download the music and video, or just the music from here.

Creating AI voiceovers

Using three new AI audio tools in Adobe Firefly to generate music, speech, and sound effects

(Image credit: Adobe // Future)

Switching over to Generate Speech, I first used the side-bar to determine which AI model to use - at the time of writing, there's Adobe's commercially safe Firefly and the ElevenLabs Multilingual V2 partner model.

I then picked a speaker from a list of 45, each variably described as male, female, non-binary, young adult, middle-aged, senior, and so on.

Finally, I pasted in my text into the text field - Firefly can figure out what language I'm using, but you do get the option to choose it yourself. I used the poem Ozymandias (with my greatest apologies to Shelley).

What I liked here was that with your text in place, you can choose to add additional text, or tell the AI to pause in certain places.

To actually preview, I had to select the entire passage and use the context menu to (it's where you also fix pronunciation and adjust the tone of voice).

For all the talk of speeding up workflows, this feels like a misstep to me. It just needs a play button at the bottom of the screen, as it was with generating music.

I had to tweak the pauses to give my text room to breathe, and once in place, I could alter the timings by clicking the pause on the preview screen. And for some reason, the word "land", of all things, is what tripped up the AI, where it was pronounced "lan."

Creating AI SFX

Using three new AI audio tools in Adobe Firefly to generate music, speech, and sound effects

(Image credit: Adobe // Future)

For this test, I again used a video filmed for my reMarkable review - this time a 12-second clip comparing the reMarkable 2 with the Paper Pure.

This process is a lot more in-depth, in the sense that the AI isn't going to guess what the likely SFX should be. I had to manually describe what I wanted. After that, I clicked the "Enhance Prompt", which added more descriptions.

We end up, then, with "A sliding whistle descending softly with a metallic timbre and gentle resonance." Clicking Generate, the service rapidly produced four ear-piercing variations. I won't subject you to those results. It's not fair on anyone.

Instead, I changed the prompt to a more soothing "crickets in a field" for a duration of 12 seconds, to fill the video length.

What's nice about the SFX option is that you can add multiple audio tracks and use the handles to adjust its positioning.

With a timeline sprawled across the bottom of the screen, it feels more like a real audio editor (to a degree, at least). Tug in the handles of the audio and you can further adjust volume or delete the track.

Worth it?

Overall, there are some UI tweaks I'd like to see here to make production workflows faster.

I don't think they'll substitute professional sound designers, composers, and musicians any time soon. But having worked in marketing, I can see they have their place for marketers and everyday video creation.

Speech is a world away from the days of robotic Microsoft Sam sound-alikes, but for nuanced line delivery, nothing's going to beat a performer in a booth.

Sound Effects has a lot more utility, though. Across a spectrum of generations, I couldn't tell the difference between the AI sounds and those playing on an old SFX CD I own.

The real winner here is Generate Music. Even the base prompt delivered audio that wouldn't feel out of place in a product demo, review, business explainer, or similar. And it got better with every generation I created.

An update worth exploring, then, for fast-moving video production.

Google logo on a black background next to text reading 'Click to follow TechRadar'



from Latest from TechRadar US in Computing News https://ift.tt/9c4MfEx
via

Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service

 Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service
  • Researcher inds ClarityCheck’s exposed 450GB database with 9M+ user images
  • Leak included faces, profiles, and photos, risking identity theft and phishing abuse
  • Company secured access quickly; no evidence of dark web distribution or misuse so far

An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting people at risk of identity theft, phishing, and more, experts have warned.

Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, recently found one totaling 450.2GB in size.

It contained exactly 9,042,977 image files - profile pictures, screenshots, and scans of physical photographs - all seemingly uploaded by the users. The images showed adults, teenagers, and even children, and were stored in folders labeled “faces” and “profiles”.

What happened?

Further investigation showed the database belonging to a company called ClarityCheck. This is a US-registered firm describing itself as a “reverse phone, email, image, vehicle lookup”, allowing users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from “trusted sources”.

It is a legitimate business whose use case grows more important by the day - cybercriminals create fake internet personas every day, and use them in all sorts of schemes, from romance scams, to fake job offers, to anything in between. To do that, they will either steal other people’s photos, obtain (or buy) them on the dark web, or generate them using artificial intelligence.

Being able to verify someone’s identity has become everyone’s essential due diligence, regardless of if it’s a personal or business matter.

How ClarityCheck responded

As soon as Fowler confirmed who owned the database, he reached out to ClarityCheck and responsibly disclosed his findings. The company responded quickly, barring further access, and thanking the researcher for his work.

“I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy,” the company’s representative told Fowler.

Unfortunately, without a deeper investigation on ClarityCheck’s end, there is no way of confirming exactly how long the database remained open, or if anyone accessed it before. However, so far there is no evidence of abuse, since a “ClarityCheck photo database” is currently not being distributed or sold anywhere on the dark web.

Exposing people to hackers

In a world where data theft and leaks are increasingly common, a cause that’s easiest to address, is also the one resulting in most exposures - misconfigured databases. Nowadays, almost every business harvests and stores data about their employees, partners, and customers. Most of them store these files in cloud databases, for easier access and better integration with business intelligence software.

However, cloud service providers work on a so-called “shared responsibility model”, which means they are responsible for providing industry-standard security features. Users, on the other hand, are responsible for using those features and properly configuring their databases (namely, setting up a strong password or encrypting the content). Unfortunately, many organizations don’t seem to be aware of the shared responsibility model, firmly believing it’s the service provider’s task to keep the data safe. Others simply keep these archives accessible by mistake.

Criminals are aware of this, and are taking advantage of the situation to steal valuable information. By using widely available tools like Shodan, Censys, or FOFA, they can scour the web for unencrypted, non-password protected databases, and exfiltrate data to be used in phishing, business email compromise, and other forms of cyberattacks.

Over the years, Fowler and other searchers have found dozens of enormous databases that have leaked sensitive data on hundreds of millions of people.

In 2026, researchers found that European cloud provider Nextcloud kept an unprotected database on the public internet, containing 367,000 records (8GB) of sensitive employee and client data.

In 2025, IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, was leaking 38GB of sensitive personal records. The unencrypted and non-password-protected database held 10,820 in total.

In 2024, sports analytics technology company TrackMan exposed sensitive customer data: 110TB and 31,602,260 records. The database had no password.



from Latest from TechRadar US in Computing News https://ift.tt/OZJcj2H
via