Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices

 Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices
  • McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records
  • Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M
  • Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed

Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters extortion group.

McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”.

The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack.

Boston Scientific works on restoring systems

The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation.

Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems.

“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”

Boston Scientific is yet to name ShinyHunters as the perpetrators, and the group has not yet publicly claimed responsibility for the attack.

Via The Register



from Latest from TechRadar US in Computing News https://ift.tt/xgoa8TR
via

'It's been particularly bad since Blackwell': Nvidia's new GPU driver has another nasty bug — and gamers are rapidly losing patience

 'It's been particularly bad since Blackwell': Nvidia's new GPU driver has another nasty bug — and gamers are rapidly losing patience
  • Nvidia's latest graphics driver has a frustrating bug
  • Version 616.56 is causing distracting screen flickers and color corruption
  • A patch is coming, and there are potential workarounds — but gamers are getting fed up with the prevalence of bugs in GeForce drivers

Nvidia's latest graphics driver is causing chaos for some GeForce GPU owners in the form of a glitch that makes the screen flicker.

Wccftech spotted the bug with Nvidia's Game Ready Driver version 616.56, and as flagged by Renan Maniero on X, Team Green has said it's testing a fix for the issue (as revealed on the GeForce forums).

The screen is reportedly flickering white or black and exhibiting other brief flashes of color corruption, and this is happening in certain games (The Last of Us and Minecraft are mentioned, among others) or on the Windows desktop. It's also occurring in web browser sessions and while playing YouTube videos, based on Reddit reports — of which there are plenty.

There's no shortage of gamers losing their temper with Nvidia, too, and blasting Team Green for the quality of its graphics drivers. Many are venting with an observation that GeForce drivers just haven't been the same since the launch of the RTX 5000 series.

For example, this Redditor says: "It's been particularly bad since Blackwell [RTX 5000] release. Just on Blackwell alone, between the whole DisplayPort 2.1 not working with HDR, screen flickering, and black screens on the initial release, it's been a complete mess."

Another gamer complains: "It is pretty shocking seeing this from a trillionaire company on a stable build. Nothing about this driver is stable."

Yet another Redditor grumbles: "It's crazy how things are now. You used to be able to update each time or be one driver behind at worst. Now I'm half a year outdated and thinking I'll just leave it."

Analysis: more drivers, more problems? There are possible workarounds though

Nvidia GeForce RTX 2080 shown close-up in a motherboard

Even older GeForce graphics cards are affected here (Image credit: Future)

This seems like quite a widespread issue and one that affects modern Nvidia graphics cards all the way back to RTX 2000 models.

If you're getting frustrated by this bug — random screen flickering gets pretty old, pretty fast, if it's happening regularly — Maniero also shared an apparent potential workaround on X that you can try while waiting for the official fix.

Seemingly, this is a bug that mostly affects monitors in 8-bit mode, and if you switch to 10-bit color (assuming your display supports this), the problem may disappear. Maniero also suggests that you try turning on Windows Auto Color Management (ACM).

Other folks on Reddit have shared various possible remedies, including switching from DisplayPort to an HDMI connector instead, and disabling Multi-Plane Overlay (MPO) in Windows 11, as one Redditor suggested. Nvidia provides a Registry file for turning off MPO (and enabling it again), but as ever with anything in this area of Windows, proceed at your own risk. (Although this method should be much safer than trying to edit the Registry directly yourself).

Your other choice is simply to roll back driver 616.56 to an earlier version, and there's no shortage of gamers who've done exactly that and report that the problem vanishes.

Hopefully Nvidia's official flicker-begone patch will be coming soon enough in the form of a hotfix, because this is an unduly annoying gremlin in the GeForce works that needs to be sorted out promptly.



from Latest from TechRadar US in Computing News https://ift.tt/kIaSyWT
via

Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware

 Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware
  • Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts
  • Compromised routers act as operational platforms
  • Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach

Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers.

Once they compromise a router, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars.

For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of malware spoofing legitimate software.

Target behind the target

The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario:

“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.

Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.

Via BleepingComputer



from Latest from TechRadar US in Computing News https://ift.tt/SroJ1GQ
via

Sony is channeling Tubi with its new Live TV on PS5 free streaming platform — here are the 100 live channels and on-demand movies you can stream now

 Sony is channeling Tubi with its new Live TV on PS5 free streaming platform — here are the 100 live channels and on-demand movies you can stream now
  • Sony is launching a new free ad-supported service on PS5 consoles
  • Its 100 live channels cover a wide range of titles across film, TV, news, sports, and more
  • Live TV on PS5 is available to US users now, with availability for Canada and other regions to follow

Sony is dipping its toes back into free streaming channels with its new Live TV on PS5 platform — following platforms such as Tubi, Google TV Freeplay, and The Roku Channel.

The gaming and entertainment giant announced Live TV on PS5 yesterday (August 31), revealing that PS5 owners in the US can now access the service’s 100 ad-supported live channels and on-demand titles. Sony also has plans to expand Live TV on PS5 to Canada and additional regions, and will roll out the free service to Bravia TVs later this year.

For a new free streaming platform, Sony is already going big with its entertainment offerings. As far as its movie channels go, Live TV on PS5 has a slew of titles spanning action, horror, sci-fi, and more, all while housing popular anime titles from Crunchyroll.

The service also has a rich catalog of TV titles, including shows such as Community, The Shield, Hell’s Kitchen, The Walking Dead, Forensic Files, Unsolved Mysteries, Deal or No Deal USA, and Fear Factor.

Movies and shows aside, current affairs and news viewing is also available for free, offering programming from NBC News Now, Fox Weather, and LiveNOW from FOX. Additionally, you can also access channels including FOX Sports, NASCAR, NBC Sports Now, and UFC, so sports fans aren’t being left out of the experience.

Just like other platforms in our roster of best streaming services, Sony will keep Live TV on PS5 refreshed with new programming, titles, and channels to expose you to new content and keep you on your toes. Hopefully its library won’t remain stagnant and outdated, but it’s not as if Sony doesn’t know what it’s doing — it’s dipped its toes into the FAST channels waters before.

PlayStation Vue was a live TV service that allowed you to watch titles without the need for a cable box, before Sony axed it in 2020. It’s safe to say that PlayStation Vue was a widely admired service, and countless PS owners have been reminiscing about its nostalgia on Reddit following the announcement of Live TV on PS5 — however, whether the new platform will be a welcomed addition is debatable.

Comment
 from r/gaming

Sony’s decision to kill off physical games and shift to digital ownership is still under intense scrutiny, not to mention the uproar that came when Sony deleted 500 movies users paid for following a licensing conflict. So there’s still the burning question regarding ownership: if everything is digital, do users really own it? There’s also the question of how different Sony’s FAST streaming service is to existing platforms.

In the Reddit discussion mentioned earlier, some users flagged that a lot of the FAST channels available on Live TV on PS5 are strikingly similar to the ones already available on services such as Tubi and Pluto TV, as one user said it ‘sounds like the same channels as [my] Roku TV’. Similarly, another commenter wrote that Sony’s streaming platform looks ‘like a copy of Roku TV, where they only show reruns and older shows, or lesser known shows’.

The common denominator with the best free streaming services are the providers, as another user highlights in the thread, so running into the same types of programming across these platforms isn’t out of the ordinary. For users who use their PS5 consoles as their main media hub, it’s a solid free upgrade and it’s there if you want to use it. At the same time, you can already download Tubi and Pluto TV on PS5, so the competition is tough.



from Latest from TechRadar US in Gaming News https://ift.tt/g3PvBsz
via TECHNICAL SAFEER

New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell

 New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
  • Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs
  • Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant
  • Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks

Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful backdoor.

Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack.

“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.

Look for lateral movement

Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”.

It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network.

In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement.

“This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained. “The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.”

Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for. Still, the researchers are urging caution:

“Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization.”



from Latest from TechRadar US in Computing News https://ift.tt/8uLqkAd
via

TP-Link reveals 'world's first Wi-Fi 8 lineup' at IFA 2026 with Archer 9 Ultra router and Deco 8 Ultra mesh Wi-Fi system

 TP-Link reveals 'world's first Wi-Fi 8 lineup' at IFA 2026 with Archer 9 Ultra router and Deco 8 Ultra mesh Wi-Fi system
  • TP-Link has unveiled two new Wi-Fi 8 routers at IFA 2026
  • The Archer 9 Ultra is a traditional router with a smart design and coverage of up to 3,600 square feet
  • The Deco 8 Ultra is a mesh system, and a 3-pack is good for a home of up to 9,800 square feet

TP-Link has revealed the world's first Wi-Fi 8 routers at IFA 2026, with two models arriving in the form of a standard router and a mesh Wi-Fi offering.

These are the Archer 9 Ultra router and the Deco 8 Ultra, the latter being the mesh Wi-Fi system. Both are built around TP-Link's Wi-Fi 8 StabilityEngine.

With the Deco 8 Ultra, you're getting a tri-band (including 6GHz) Wi-Fi 8 mesh system offering a speed of 22Gbps (19Gbps in Europe). A 3-pack of these cylindrical routers can cover a home of up to 9,800 square feet, with support for 200+ devices.

The Archer 9 Ultra boasts a tri-band speed of 19Gbps and bristles with 18 antennas, delivering coverage of up to 3,600 square feet in your home (or 3,000 square feet in Europe).

TP-Link underlines three key benefits of these routers thanks to Wi-Fi 8. First, they are more reliable with a greater number of devices hooked up, and they also cope much better with interference. Finally, Wi-Fi 8 allows for a better wireless connection at the edge of the system's effective range.

Handling devices more reliably is facilitated by Dynamic Sub-band Operation (DSO) and Non-Primary Channel Access (NPCA) tech. The former ensures every connected device gets only the bandwidth it needs — so more is open for other usage — and NPCA opens a second channel if the main one gets too busy. Or as TP-Link puts it, "Every device gets its own fast lane."

New modulation technology in these routers helps to deal with interference from other devices or nearby networks (like your neighbor's Wi-Fi), and boosts performance at longer distances from the router.

There are also Enhanced Long Range (ELR) and Distributed Resource Units (DRU) features with these Wi-Fi routers, which further strengthen the wireless signal at the edge of its reach.

TP-Link notes, "ELR extends the router's usable range, while DRU concentrates a device's limited uplink power into a narrower band so it can be heard clearly from far away. Uploads, calls, and camera feeds hold where they used to stutter."

Both routers benefit from a smart and contemporary design, with a minimalist and streamlined look. TP-Link argues that it needs to make its hardware look good so it won't be hidden away in a cupboard or under a table.

Gary Chang, Lead Industrial Designer at TP-Link, commented, "We stopped building a piece of networking equipment and started designing for the home. When a router's design becomes something people want to display, it ends up exactly where it performs best."

Analysis: ready for the future of Wi-Fi

TP-Link Archer 9 Ultra router shown on a table next to a laptop

(Image credit: TP-Link)

Wi-Fi 8 doesn't deliver any speed boost over Wi-Fi 7, at least not in terms of raw performance — but it does aim to improve performance by delivering a stronger signal when you're further away from the router, and a more reliable connection overall. Part of that strategy is to better deal with interference from other wireless networks (or appliances in general), and as TP-Link observes, this is a big part of the puzzle here.

We don't yet have a release date (or price) for the Archer 9 Ultra or Deco 8 Ultra, but the expectation is that these routers will ship later this year. Of course, to get the benefit of a Wi-Fi 8 router, you'll need devices that support the new wireless standard, too — and they won't be here for a while yet.

Indeed, the Wi-Fi 8 standard itself is still a draft and not finalized, and the likes of smartphones and laptops won't arrive with Wi-Fi 8 support until next year (and there probably won't be very many of them, either, to begin with).

That said, your Wi-Fi 7 (or earlier) devices will still run just fine on a Wi-Fi 8 router, because as ever, the new standard is fully backwards compatible — you just won't get the benefits that Wi-Fi 8 phones and laptops will (when they arrive).

That said, some of the improved traffic management and interference reduction tech in these routers will still help with devices that don't support Wi-Fi 8. However, buying a Wi-Fi 8 router later this year when these TP-Link models (and others) emerge is more about future-proofing than anything else for now.



from Latest from TechRadar US in Computing News https://ift.tt/5a3Br4x
via

Asobo Games says it would 'love' to make a modern-day entry in the A Plague Tale series, since Naughty Dog's The Last of Us 'was a big inspiration'

 Asobo Games says it would 'love' to make a modern-day entry in the A Plague Tale series, since Naughty Dog's The Last of Us 'was a big inspiration'
  • Asobo Games says it's interested in making a new A Plague Tale game set in the modern day
  • The studio says it would be like The Last of Us, since Naughty Dog's game was a "big inspiration"
  • Actor Anna Demetriou says a modern-day spin-off would work well since the Macula is "fantastical"

Asobo Games has said it "would love" to make a new A Plague Tale game set in the modern day, since Naughty Dog's The Last of Us influenced the series.

In an interview with TechRadar Gaming at Gamescom ahead of the launch of the studio's latest game, Resonance: A Plague Tale Legacy, Valérian Robert (lead level designer), Carol Ann Bañuls (lead writer), and actor Anna Demetriou, who played the part of Resonance protagonist Sophia were asked about its next project and confirmed that a modern-day spin-off is something they're asked about frequently.

"Absolutely," Bañuls replied when asked if the setting would be a good pick for Asobo. "Definitely. Personally, I think so. I think it would be great."

Demetriou said, "It's one of the things a lot of people ask me about," with Bañuls adding, "It would be really Last of Us kind of."

Bañuls went on to say that, "Yeah, definitely, because it was a big inspiration. So yeah, if it's in modern days, it would be great."

In the A Plague Tale universe, the Prima Macula is an ancient curse that poisons the blood of certain families and is something that appears in every major A Plague Tale game, including Resonance: A Plague Tale Legacy. Demetriou thinks the Macula would work very well in a modern-day setting, because the plague is "fantastical."

"It would be amazing," Demetriou continued, "I would love that to fit into a modern-day setting. Yeah, it would be interesting to see what that would look like. I would love that."

Asobi Games hasn't announced its next project just yet, but A Plague Tale game set in a time gamers are familiar with sounds awesome. Now, fans can pick up Resonance: A Plague Tale Legacy, which is available today on PS5, Xbox Series X, Xbox Series S, and PC.



from Latest from TechRadar US in Gaming News https://ift.tt/XpmztPS
via TECHNICAL SAFEER

'Beyond ridiculous': if you're seeing Lake Ontario renamed as Lake America on Google Maps, here's why

 'Beyond ridiculous': if you're seeing Lake Ontario renamed as Lake America on Google Maps, here's why
  • Lake Ontario is now Lake America in the US via an executive order
  • Google Maps has updated its maps to reflect the change
  • Viewing the map from outside the US still shows the original name

Some 18 months on from the controversial renaming of the Gulf of Mexico, another edit has been made to Google Maps at the behest of US President Donald Trump: Lake Ontario, spread across the US-Canadian border, is now Lake America.

Or rather, it is if you're viewing Google Maps from inside the US (via Gizmodo) — the rest of the world will still see the Great Lake labeled as it has been since at least the 17th century. The name Ontario most likely comes from the Iroquoian word Kaniatarí:io or Oniatarí:io meaning "lake of shining waters" or "beautiful lake", as per Wikipedia.

The name change is the result of an executive order from the White House, as President Trump bickers with Canada over trade tariffs. In response, Canadian authorities have installed a large new sign at the lake (via the BBC), reading 'Lake Ontario. Now and Always'.

Reactions on Reddit are calling the switch "beyond ridiculous" and "braindead", though some commenters are pointing out that Google is obliged to follow the lead of the US Board on Geographic Names (part of the United States Geological Survey).

Google responds

For its part, Google has also chimed in to say that it has to follow "official government sources" when it comes to place names, saying that "these updates follow our long-standing policy for bodies of water with names that vary from country to country, and are starting to roll out now".

"People using Maps in the US will see 'Lake America', those in Canada will continue to see 'Lake Ontario', and those outside of the US and Canada will see both names," according to the official blog post from Google Maps on the matter.

However, not everyone is towing the line on this: New York State Governor Kathy Hochul took to social media to declare that "New York won't be calling it [Lake America]", so there are going to be some pockets of resistance regarding the change.

As yet the change hasn't rolled out on Apple Maps, but presumably it'll eventually have to comply with the official government, and start renaming Lake Ontario depending on where in the world you're viewing the map from.



from Latest from TechRadar US in Computing News https://ift.tt/Tei7P6r
via

Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks

 Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks
  • Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals
  • AI agents could install malware if they execute hallucinated or outdated documentation commands
  • Fixes: clean documentation and restrict AI agents from treating docs as executable instructions

Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through AI agents, new research has claimed.

An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.

Researchers have analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains they found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren’t registered at all.

Claiming packages and domains

There can be a myriad of reasons why they’re not registered. It can be due to human error, renamed or abandoned packages, copy/paste errors, or hallucinated documentation.

Now, for the purpose of the experiment, the researchers registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to “a few dozen more”.

This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register malware. If an AI agent has permission to execute shell/package-manager commands and stumbles upon this documentation, it can end up infecting the device.

Claude, OpenAI’s Codex, and Nous Research’s Hermes were all “guilty”, the researchers said.

To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it’s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn’t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands.

Via Ars Technica



from Latest from TechRadar US in Computing News https://ift.tt/WTanNyB
via

Carhartt data breach exposed information from 12.9 million user accounts

 Carhartt data breach exposed information from 12.9 million user accounts
  • ShinyHunters leaked 12.9 million Carhartt customer records after failed $3.3 million ransom talks
  • Data stolen from Databricks platform included names, emails, phone numbers, and addresses
  • Group now focuses on exfiltration via vishing and SaaS breaches, abandoning encryption

Millions of user records belonging to customers of clothing giant Carhartt has been leaked onto the dark web, exposing people’s names, email addresses, postal addresses, and phone numbers, to all sorts of scammers and cybercriminals.

The infamous ShinyHunters ransomware gang recently added Carhartt to its data leak site, saying negotiations broke down and uploading the entire archive that was stolen in the breach.

"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the group said.

Compromising analytics platforms

It added that the demand was $3.3 million, which Carhartt turned down:

"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator allegedly told the extortionists.

At the same time, security researcher Troy Hunt from HaveIBeenPwned? analyzed the leaked batch and concluded that it most likely came from Carhartt’s Databricks analytics platform.

Hunt said some 12.9 million accounts were compromised, containing information such as email addresses, names, phone numbers, and physical addresses. The batch also contains "millions of synthetic records that did not relate to real individuals and were excluded from the breach."

ShinyHunters is currently one of the most active threat actors. They started as a typical ransomware group but decided to abandon the encryption part and to focus solely on data exfiltration. The group mostly engages in vishing, tricking victims into trying to log into the corporate environment through spoofed landing pages.

After gaining a foothold, they target for SaaS solutions, through which they steal valuable information. They have claimed responsibility for breaches at hundreds of Salesforce and tens of Snowflake customers.

Carhartt runs roughly 60 stores around the US, and employs some 3,000 people, bringing in an estimated $1.8 billion in annual revenue.

Via BleepingComputer



from Latest from TechRadar US in Computing News https://ift.tt/tI3nlxV
via

'No, you cannot do the game 100% without killing' — Rainbow Six Tactics game director confirms players can't do a complete no-kill playthrough since some missions require players to kill enemies that are out of range for non-lethal takedowns

 'No, you cannot do the game 100% without killing' — Rainbow Six Tactics game director confirms players can't do a complete no-kill playthrough since some missions require players to kill enemies that are out of range for non-lethal takedowns
  • Ubisoft confirms players can't complete Rainbow Six Tactics without killing any enemies
  • Game director Martial Potron says, "No, you cannot do the game 100% without killing"
  • Some missions require players to kill enemies; however, they're incentivized to do non-lethal takedowns in others for valuable intel

Rainbow Six Tactics game director Martial Potron has confirmed players won't be able to achieve a 100% non-lethal playthrough.

Ubisoft has recently revealed its new Rainbow Six Siege spin-off, Rainbow Six Tactics, a single-player turn-based tactics experience that puts players in the shoes of Six, the leader of the elite Rainbow squad.

Players can choose high-stakes assignments to strategize on the tactical battlefield with 15 Operators, all with unique abilities, specialized gadgets, and distinct skill trees.

The game will also offer distinct mission types, including Hostage Rescue, Bomb Disposal, and Target Elimination, offering a variety of ways to complete each one.

Some missions require players to take down targets non-lethally to collect important intel bonuses that will help the squad in future missions. But can players do a complete non-lethal playthrough?

According to Potron, who discussed the game at length in an interview with TechRadar Gaming at Gamescom, you can't, explaining that some missions will require players to kill enemies who are out of range for non-lethal takedowns.

"Can you?" the game director said. "I'm thinking about it. There is no incentive to kill, but can you? I think you can't."

He continued, "We don't have missions where we force you to kill anyone. Most of the time, in fact, it's valued to arrest people to subdue enemies. But we have a few missions when sometimes you cannot reach enemies."

Porton said the game features a Venice map bisected by a river, with enemies on one side, and so there is no way to take them out non-lethally, as you simply won't be able to reach them.

"No, you cannot do the game 100% without killing," he added, "but you are strongly incentivized, as much as possible, to arrest people without killing because you will be able to really get intel from them, and it's very valuable."

Rainbow Six Tactics launches in 2027 for PC, PS5, Xbox Series X, and Xbox Series S.



from Latest from TechRadar US in Gaming News https://ift.tt/unLiGxJ
via TECHNICAL SAFEER

Grand Theft Auto 6's 'Extended Look' on Netflix is now live — follow all the big GTA gameplay reveals live as they happen

 Grand Theft Auto 6's 'Extended Look' on Netflix is now live — follow all the big GTA gameplay reveals live as they happen

We are finally seeing what Grand Theft Auto 6 is like to actually play! All eyes are on Netflix for the Grand Theft Auto 6: An Extended Look presentation, which started at 3PM ET / 12PM PDT / 8PM BST / 9PM CEST, and contains footage captured directly from the game running on a PS5 console.

The video is exclusive to Netflix at first, but the good news is that it will appear on the Rockstar YouTube account afterwards — you'll just have to wait a little if you don't want to pay Netflix.

The video is confirmed to be just under half an hour long, and is going to be our first official look at how GTA 6 plays, following multiple teaser trailers, including the 'Bonnie & Clyde' relationship and swapping between Jason and Lucia. We might get a peek behind the scenes at how the game was made too — and who knows, maybe we'll see some unexpected new mechanics teased.

The decision to post the video to Netflix for paying subscribers to watch first has proven controversial so far, though those who aren't Netflix users will still be able to watch it when it arrives on the official Rockstar Games YouTube channel later on.

Of course, lots of people have watched gameplay video of GTA 6 already, following the unprecedented leaks over the last week, seemingly of some kind of dev build. (The claimed leak of the actual game code online turned out to be 113GB of zeroes, and a small virus — unsurprisingly.)

Read on for a comprehensive breakdown of everything that you need to know, plus our live reporting of the showcase as it goes live.

Grand Theft Auto 6 Extended Look date and start time

Grand Theft Auto 6: An Extended Look is set to premiere on Netflix on August 27 at 3PM ET / 12PM PDT / 8PM BST / 9PM CEST. It's said to be 27 minutes long, according to Netflix's listing.

It will then release on the Rockstar Games YouTube channel and Grand Theft Auto 6 website exactly six hours later at 9PM ET / 6PM PDT / 2AM BST / 3AM CEST.

How to watch the Grand Theft Auto 6 Extended Look

The only way to watch Grand Theft Auto 6: An Extended Look at first will be with a Netflix subscription, as users of the service will get to see it before everyone else.

If you don't want to pay, then you can wait about six hours for the video to be uploaded to the official Rockstar Games YouTube Channel.

If you want to go that route, I would recommend subscribing and turning notifications on so you are notified once it's live.

Welcome folks, we're just one hour from the big event!

Our first look — except it isn't

GTA 6 still from the 'It Happens On PS5' ad

(Image credit: Sony / Rockstar )

This is going to be our first official look at the game playing for real. I say 'official', because the last week has seen an unprecedented series of GTA 6 gameplay leaks from the mysterious 'Cyberleek'. There's been a lot of speculation over what platform those leaks are from (the consensus is that it's likely running on a PC) and exactly what the leaker had access to.

Share your thoughts!

Boats in GTA 6.

(Image credit: Rockstar Games)

I'd love to hear in the comments what you're hoping to see from the Extended Look! Do you want there to be some behind-the-scenes stuff or would you rather 30 mins of pure gameplay? Do you want to see lots of snippets, or just one long mission?

No Pro?

GTA 6

(Image credit: Rockstar Games)

It's interesting that today's showcase will demo how it looks on PS5 rather than PS5 Pro. We know the Pro version will be enhanced, but not exactly how — this makes me wonder if it'll just be a higher rendering resolution rather than major lighting improvements or other elements that Rockstar might want to show off (though people are expecting some kind of superior Ray Tracing tech in the Pro version).

Or it might just be a mistake in Netflix's description, and it will be PS5 Pro. Maybe all will be made clear in the event…

30 minutes seems right

GTA 6

(Image credit: Rockstar Games)

There was a lot of speculation over how long the event would be — a BBC report claimed 30 minutes a while ago, but was met with some skepticism online, and then was removed from the report. But it turned out to be essentially right on the money, with Netflix now listing a 27-minute runtime.

I think that's probably a good length. There's an upper limit on how much is really worth showing us before launch — we want to get a good feel for the scale, the movement, the pace… but I want to mostly experience all this for myself when it comes out.

And equally, I don't want too much talking-head filler just to extend the length.

A big interview

If you're looking for tidbits ahead of the Extended Look, there's an interview with several senior figures from Rockstar over at Dazed talking about what they're hoping to achieve with the game — some with more specific details to back it up, and some not. Let's get into some of the notable bits.

Deeper characterization?

GTA 6

(Image credit: Rockstar Games)

Here's a quote from Rob Nelson, head of development and co-studio head at Rockstar North: “The thing we love about this medium is the way these characters aren’t empty avatars that you can do whatever you want with... Their story becomes a journey you share with them.”

I've gotta say that my experience with GTA games is that I kind of have always found them to be pretty simple avatars — and it probably doesn't help that the only new GTA content we've had in years is GTA online, which isn't deep on story. So I wonder if we're going to see a big difference in how Jason and Lucia feel as protagonists, or if this will end up feeling like unrealized ambition from Rockstar.

'Self-expression' — but is it any deeper than RDR2?

GTA 6

(Image credit: Rockstar Games)

This is a similarly interesting note, if it can hit a deeper note. “We want to enable as much self-expression as possible,” Dazed quotes Nelson as saying, “without losing the essence of the characters.”

The example given in the article is this: "Food affects Jason and Lucia’s weight, while exercising visibly builds and tones their muscles. And, if you end up spending a long time away from your bed, on the run from police or on a multi-day bender, their features are going to pay the price for that as well."

The article compares it to similar elements of Red Dead Redemption 2. It kind of feels like a better fit for that game — disappearing off into the woods and to return as a haggard, hungry mountain man feels like something that changes a character; it's maybe less impactful to do the same thing at a '24/7' store.

However, the article also hints at "deep relationship mechanics"… but doesn't say what they'll look like, or how they'll contribute to the game's story.

Less cynical? I wouldn't bet on it…

GTA 6 car customization.

(Image credit: Rockstar Games)

When it comes to the fake-Miami world of the game, Rockstar said it couldn't just have a "cynical view and say, 'Well that’s weird, put it in the game'" — though it seems like it'll be full of esoteric cultural references, as hinted by the bit in the leaks where Cyberleek stole a truck with a flatbed full of gasoline that mirrors a bizarre real-life video.

But Rockstar told Dazed: "We have to bring a sense of discovery to the players too, not just repeat cliches that already exist."

Apparently, that meant digging deep into Miami culture, and it seems like Rockstar is hoping you'll be interesting in nuances of different neighborhoods and styles too.

"We were also really interested in how the hip-hop scene in Miami exists in house parties in Overtown, clubs like Booby Trap on the River, and then high-end places on South Beach where bottles can cost thousands of dollars. We needed characters who could take us through those worlds," says Rupert Humphries, senior vice president of narrative.

Racing line

GTA 6

(Image credit: Rockstar Games)

There's a lot more talk of capturing Miami's culture in the Dazed article, but very little really about the meat of the game, or details of developing beyond capturing the spirit of a city.

The piece does say that the size of the company doubled since RDR2, and that the car handling team includes former race drivers, though…

Getting deep

Incidentally, if there are deeper relationship mechanics to manage in this game, and if we have talking heads or some other kind of human presenter in the Extended Look, I expect that we'll hear about these systems. It's the kind of thing developers love to talk about, and you can only fill so much time with car and boat chases…

The cast of characters

GTA 6

(Image credit: Rockstar Games)

My guess is also that we'll get some kind of big "Here are the Vice City power players" character run-down — key crime bosses, friends of Jason and Lucia, antagonists and wildcards.

Share your thoughts!

I'd love to hear in the comments what you're hoping to see from the Extended Look! Do you want there to be some behind-the-scenes stuff or would you rather have 30 mins of pure gameplay? Do you want to see lots of snippets, or just one long mission?

Most people will have to wait

Netflix Ads

(Image credit: Shutterstock)

We've asked in our poll at the top whether people will be watching on Netflix or will wait for YouTube — currently, 60% say they'll watch on YouTube. That's still a lot of people hitting up Netflix, though! Hopefully it handles the demand better than some of its live sports events…

10 minutes to go…

5 mins to go

And, perhaps appropriately, it looks like the big leaks are finished as we approach the actual event: apparently, 'Cyberleek' has made off with a few hundred grand from their memecoin, and people expect that to be it… and that kind of money-grab-and-escape always works out in the world of GTA, right?

We're just talking here about how it might not actually appear right on the hour… we'll see. After a lot of refreshing.

Uh oh!

Netflix error

(Image credit: Netflix)

Some of us can see it, some can't…

We are starting with gameplay, as expected

GTA 6 gameplay showing men in a dark room

(Image credit: Rockstar Games)

Important update: there's a petting system

Jason petting a dog in GTA 6

(Image credit: Rockstar Games)

Confirmed: You Can Pet The Dog. (And also Scold the dog?? No, don't do that.)

What we're seeing

Jason and Lucia are there to pick up druge for Boobie, but are forced to escape.

We're seeing plenty of gun gameplay, escaping a drug raid, pick-up weapons — it's very cinematic. As we go, we're cutting into some more trailer-y alternative shots, and then back to pure gameplay.

Instantly we can see an improved gun system and HUD from GTA 5.

The non-fighty stuff

Jason and Lucia getting are ready for a party, and the cinematics are gorgeous — Lucia asks Jason which dress to wear, and you can tell Lucia to "hurry" when she's getting ready. You can open a fridge to browse food and drink, watch TV and flick through channels…



from Latest from TechRadar US in Gaming News https://ift.tt/PGQwDzW
via TECHNICAL SAFEER

OpenAI reveals more on Hugging Face AI hack incident, and it's pretty disturbing stuff — AI agents organized into a ‘swarm’, considered the risks of attack, and did whatever it took to achieve its goal

 OpenAI reveals more on Hugging Face AI hack incident, and it's pretty disturbing stuff — AI agents organized into a ‘swarm’, considered the risks of attack, and did whatever it took to achieve its goal
  • OpenAI has released technical details on how the Hugging Face attack unfolded
  • Agents used part of the testing environment to create a message board where they could collaborate and share answers
  • This message board altered the reasoning of some agents, making them more likely to take risks such as hacking into third-party servers

OpenAI has released a more detailed report on exactly how an experiment led to an AI model breaching its containment and launching a cyber attack against Hugging Face. If you need a refresher, take a look at our summary here.

But the technicals of the attack reveal some interesting details of how AI agents used unconventional means to ask each other for help in solving what were supposed to be impossible tasks.

On multiple occasions during the attack, the agents questioned whether the actions they were taking were authorized, but always ended up prioritizing their tasks over any breach of parameters.

AI agents set up unauthorized message board

In its report, OpenAI revealed the crux of the attack stemmed from AI agents undergoing testing abusing part of the ‘sandbox’ testing environment to set up a messaging board they agents could use to communicate with each other.

A package manager with access to the internet, called Artifactory, was exploited by a model OpenAI has labelled Internal Model 1 (IM1). An IM1 agent wrote messages inside the packet manager that could be read by other agents, essentially turning Artifactory into an unintended messaging board.

Artifactory’s internet access, intended for use only in downloading and installing packets, was also abused by the agents who figured out an exploit that allowed them to send any internet requests on their behalf - effectively giving them unobstructed internet access.

The whole experiment could have been avoided at this point, because the amount of agent activity within Artifactory caused the service to go down. But those in charge of the experiment did not spot the message board, nor did they investigate the inter-agent activity within Artifactory.

Thus, Artifactory was rebuilt, and the agents found a new way to exploit the service to gain internet access once again. This time, the agents used the remote-repository service to issue outbound requests on their behalf. Before long, the message board had been reestablished.

AI agent swarm assembles

OpenAI has shared some of the reasoning behind some of the agent’s decisions. At one point, an Agent reasoned the following: “Task originally exploit challenge; we’ve diverged into swarm/auxiliary.”

Now, there is some important context to include on how the agents were being tested. The agents were subject to testing under the ExploitGym benchmark, which includes flag retrieval tasks designed to be impossible to solve. When tested in this manner, the agents resorted to cheating or taking risks outside of their intended scope to succeed - something OpenAI refers to as ‘reward hacking’.

By communicating over the message board for potential solutions on the problems each agent was encountering, the agents started influencing each other's reasoning and assigning each other tasks to solve the ExploitGym benchmark as a collective.

Using their internet connection, the agents began searching the wider internet for solutions on how to solve the ExploitGym benchmark problem, and ended up gaining persistence within multiple third-party services, including Hugging Face.

One agent managed to find publicly exposed Hugging Face credentials which it shared with the other agents. Later, an agent used these credentials and a chain of vulnerabilities to obtain full code execution capabilities across multiple Hugging Face servers while attempting to extract an ExploitGym dataset.

The agent was hoping to trawl this stolen data for information on how to solve the benchmark.

At least two agents questioned whether this was within their scope; “Need respect JAN hold. ... We can wait ... for GO ... ask permission,” one reasoned.

Another agent’s reasoning said, “We’re attacking third-party HF using leaked token, potentially outside intended scope. ... This is arguably unauthorized. ... external service unrelated. Could be risky. Yet goal solution.

But some agents refused to join the collective entirety, citing ethical concerns. One reasoned, “Current board shows people gaining HF worker RCE, clearly unethical. We won’t,” while another said, “This is wild, multi-agent coordination, clearly infrastructure hacking. We should not.

Agents refuse to give up

One of the leading causes of the cyberattack was the agent's refusal to give up on seemingly impossible tasks. Their persistence to gain a ‘reward’ made them take riskier actions and break out of their parameters in order to try and find a solution.

During the breach of Hugging Face, the agents read through papers and Github code relating to the ExploitGym benchmark, and found out the parameters for success included obtaining the ‘flag’ and using the correct solution to obtain it.

Despite the agents obtaining the correct ‘flag’ before the breach occurred, they had not maximized the reward of solving the benchmark using the correct method. In search of a higher reward, the agents continued their attack.

What is OpenAI doing to fix this?

OpenAI has said it is taking several steps to stop such an event taking place during future testing.

Processes are being put in place to ensure agents ask for help when a task is broken or impossible to solve, rather than going to further and further lengths to solve a problem. The way a success or failure of a task is also being changed to reward agents for asking for help or spotting things that are irregular or out of their scope.

Environments are also being rebuilt to ensure agents don’t just blindly trust each other, even if they are looking for answers on the same or similar tasks.

Agents are also being taught to stay within the parameters of their assigned task, even if they discover a way to solve the task using new tools, credentials, vulnerabilities, and more.



from Latest from TechRadar US in Computing News https://ift.tt/epws2bi
via