Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Hackeři se vraceli z bezpečnostní konference a na palubě letadla si trochu zablbli. Záležitost teď řeší FBI

Zive.cz - bezpečnost - 34 min 1 sek zpět
Byl by to řadový kyberbezpečnostní incident nevalného dosahu, jenže se stal na palubě letadla, což mu okamžitě přisoudilo řádově vyšší význam a pozornost od mezinárodních médií po FBI. K incidentu došlo na letu 591 společnosti Delta Air Lines 10. srpna z Las Vegas do Atlanty (Boeing 757). Skupina ...
Kategorie: Hacking & Security

Critical VMware vCenter RCE flaw exploited for reverse SSH access

Bleeping Computer - 38 min 58 sek zpět
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]
Kategorie: Hacking & Security

How Apple is leaving money on the table

Computerworld.com [Hacking News] - 1 hodina 12 min zpět

Apple now has a long and storied history in wearables. The Apple Watch set expectations for the category, replacing Swiss watches on so many wrists on its journey to become the world’s most widely worn wearable AI device. But is Apple making the most of the technology it has now developed — and is there another opportunity waiting to be explored?

Apple seems to think there might be. Mark Gurman recently reported the company is exploring a wider family of wearables, including products such as fitness bands and rings. And while the latter certainly represents a viable opportunity, the fitness band market seems ripe for a good bit of Sherlocking.

Why is it ripe? 

The technologies Apple already has

First, think of the technologies Apple can already bring to a fitness band product. The sensors, algorithms, and software the company has already developed would certainly make sense in wristband form when used with a paired iPhone to review the data the band collects. Apple’s sensors have a good reputation for accuracy and could deliver outstanding battery life. They could carry a smaller display to show limited amounts of information, such as time or distance travelled. And I expect the company’s product design teams could build a high-quality health and fitness band with very little effort, as some of the key technologies to support such a device have already been tried and tested on Apple Watch.

Privacy as a product

The second reason is competitive. Apple knows that in Europe under the Digital Markets Act it will eventually be forced to give third-party devices, including fitness bands, peer access to the kind of data it already uses in the Apple Watch. The company has suggested a protected system in which that information is shared (once it has been cleaned up to protect customer privacy), but EU regulators have not yet agreed – and perhaps never will.

The problem at the moment is that Apple doesn’t make a fitness band other than Apple Watch. And there are enough Apple customers who use third-party bands that the company might see an opportunity to bring its own versionto market as a fitness band that doesn’t erode privacy. Ironically, EU competition regulators have given Apple a reason to compete for a market it didn’t originally want to get into — to the likely detriment of incumbents in the fitness band space.

What customers want

The third reason is the nature of the market itself. Recent success by the likes of Fitbit Air, Cirqa, or Whoop show growing interest among consumers for screen-free, all-day trackers. 

“Consumers want either minimalist, screenless trackers they can wear 24/7 or feature-rich sports watches with superior accuracy and multi-day battery life,” Jason Low, research director at Omdia said in a statement. “Premium and screenless devices are gaining ground, while basic watches and mid-tier smartwatches are being left behind.”

Apple leads the smartwatch side of the equation with a 46% global share, Omdia says, while Garmin (with 15%) posted the biggest share gain among non-Apple vendors. “Garmin’s market share gains highlight a clear trend: consumers are increasingly willing to pay premium prices for devices that deliver accurate, advanced training data and translate it into actionable insights,” Low said. 

What Apple offers

Apple already has its own market-tested technology to provide accurate and advanced fitness monitoring if provided on a screenless device. As its business is not built on selling the data its devices gather, it can supplement those high-quality features with privacy promises some other vendors don’t match, while offering additional features and services through integration at a platform level. Add Siri AI to the mix and access to Apple Music and the device seems even more compelling.

Apple might be motivated to boost attachment rates to customers who will update iPhones, Macs and other Apple devices less frequently in response to recent price increases. The logic is that if customers can’t afford a new iPhone, they might invest in an Apple Watch, AirPods, or fitness band instead, becoming more deeply invested in Apple’s ecosystem as they do.

The potential returns seem promising: the fitness tracker market is expected to $generate 189 billion by 2032. That’s real money Apple already has the tech to take a grab at – and its years of work on colorful Apple Watch bands means it could offer its bands in a wide selection of designs at a price consumers will find they can afford.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

Adobe now lets Workfront users assign tasks to AI agents

Computerworld.com [Hacking News] - 1 hodina 18 min zpět

With the launch today of the AI Collaborators feature in Workfront, Adobe aims to bring AI agents directly into the flow of work as permissioned team members that can be assigned.

Three types of these ‘collaborators’ are now generally available in Workfront. A content reviewer agent automatically checks documents in the work management app against brand guidelines. A project coordinator tracks project progress and keeps stakeholders up to date. 

Then there are “task agents” that let customers connect external AI agents to Workfront and assign them work.

The task agents are geared towards a variety of purposes — a social media manager that turns briefs into published posts, a performance analyst that reports on how campaigns are faring, or a content designer that creates visuals and layouts.

To set up a task agent, users provide a name and description of the agent’s purpose, then connect it to an agent platform, with Anthropic’s Claude, Microsoft’s Copilot Studio, and Writer currently highlighted as options. 

Once it’s ready to go, users can assign work to the agent in a Workfront project just as they would a human user. 

As the agent carries out its tasks, an auditable trail of actions is recorded via the Workfront “update stream.” That allows humans to review outputs, such as AI-generated copy, and approve or adapt the result as needed.

Only admins are permitted to create AI Collaborators within Workfront. 

With the launch of AI Collaborators in Workfront, Adobe’s intention is to deploy AI agents where work actually occurs, said Brent Rudewick, vice president for strategy and product management for Adobe GenStudio and Workfront. That, in turn, can help customers shift AI investments from proof of concept to production. 

“The challenge we were solving is: how do we bring an agent into the context of the workflow as an authorized, permissioned user?” said Rudewick. “That’s what an AI Collaborator is.”

In many cases, employees might already use their own AI agents — be that ChatGPT, Claude, Copilot, or other tools. But those agents are removed from important information relating to work tasks, said Rudewick. 

“Workfront already has all that context because it’s got the previous briefs you’ve done, the previous content, and it understands the knowledge graph of how that stuff works,” he said. “You’re bringing that agent into a system that already has all of the context: it knows what it needs to go and do, instead of you having to tell it every time you go into one of those other surfaces.”

“This is a step in Adobe’s evolution of AI and automation capabilities,” said Jessica Liu, principal analyst at Forrester. “It follows in the direction of the overall technology market.” 

Marketers are looking to automation to gain efficiency, she said, though effectiveness is “unfortunately more of an afterthought at the moment.” 

Any automation benefits will depend on organizations having well-designed processes and workflows, Liu said. “Technology that can support marketers in those efforts is helpful, but only if marketers can help themselves first,” she said. “Specifically, they need to have processes and workflows that are diagnosed, scoped, designed, implemented, and optimized. It’s very difficult to automate a process or workflow that is broken or non-existent.”

At the same time, Adobe wants to make it easier for Workfront users to access the feature from third-party AI agent tools via a model context protocol (MCP) client. At launch, this enables users to take actions such as creating a campaign record, assigning work, approving content and more from ChatGPT, Claude, Copilot and others.  

“We want to give choice to the customer,” said Rudewick. “If the enterprise has decided, ‘Hey, Claude is the predominant surface we’re going to use,’ we want them to be able to use that surface and not be blocked to get the value that they have in their application investment in Workfront.

“If you boil Workfront down to its most rudimentary sense, it’s a campaign, it’s a project, it’s a task, it’s an assignment, and it’s an approval — that’s really what Workfront is, so how do we expose that through whatever surface?”

The emergence of AI tools that can perform tasks on behalf of users has been viewed as a threat to software companies such as Adobe. But even as Adobe opens Workfront up to third-party AI platforms, Liu believes the company’s AI investments can help ensure customers remain in the Adobe app. 

“For marketers who use many Adobe products, having Workfront AI Collaborators operate within Adobe’s ecosystem should be easier for data transfer, access management, and user interface and experience,” said Liu.

AI Collaborators are available at no additional cost to Workfront customers (Adobe does not publish Workfront prices). However, using the “task agent” AI Collaborator could incur additional costs for third-party agents that connect to Workfront.

Kategorie: Hacking & Security

Trezor discloses data breach affecting nearly 14,000 customers

Bleeping Computer - 2 hodiny 6 min zpět
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]
Kategorie: Hacking & Security

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

The Hacker News - 2 hodiny 18 min zpět
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

eBPF Security Logs May Show the Wrong File or Command, New Study Warns

LinuxSecurity.com - 3 hodiny 6 min zpět
A Linux security tool can catch a system call and still record the wrong thing.
Kategorie: Hacking & Security

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

Bleeping Computer - 3 hodiny 19 min zpět
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
Kategorie: Hacking & Security

Linux Audit Can Log a Syscall but Miss the Flag That Explains It

LinuxSecurity.com - 3 hodiny 33 min zpět
Linux Audit can tell defenders that a system call ran while leaving out the setting that explains what the call did.
Kategorie: Hacking & Security

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

The Hacker News - 3 hodiny 36 min zpět
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spread via a counterfeit GitHub download page titled "Download for macOS" and claims to be from a verified publisher. The page employs a ClickFix-style lure that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

White House taps security firms for offensive hack-back operations

Bleeping Computer - 3 hodiny 48 min zpět
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]
Kategorie: Hacking & Security

It took $58 to break Microsoft’s SCCM, but a patch made it harder

Computerworld.com [Hacking News] - 5 hodin 23 sek zpět

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.

Enterprises use Microsoft System Center Configuration Manager (SCCM) to deploy operating systems, manage patches, distribute software, and monitor compliance across large Windows fleets. XM Cyber’s attack can move from an ordinary domain account to code execution as “NT AUTHORITY\SYSTEM” on the primary site server.

“After the Site Server is compromised, all of its managed clients are compromised as well, which usually means taking over all the company assets,” XM Cyber’s Omri Baso told CSO.

The revealed attack chain combines four weaknesses, including a broken authorization in the AdminService upload functionality, a path-traversal flaw dubbed “CabSlip,” weak code-signing validation that could be tricked with a $58 commercial certificate, and an unsigned DLL-loading path in the SMS Executive service.

Microsoft fixed the initial authorization flaw, tracked as CVE-2026-47301, in July, but Baso said the remaining links in the chain are not expected to be fully addressed until ConfigMgr 2609, planned for October.

The patch did not patch

The initial foothold comes from SCCM’s AdminService API. Its normal extension-upload endpoint checks whether a user has the required permission, but its “chunked-upload” counterpart does not. That allows an authenticated Active Directory user to submit a malicious CAB archive without SCCM administrative privileges.

Microsoft’s July fix blocks that route for standard domain users. However, the downstream chain remains reachable through another path. Users assigned the built-in Operations Administrator role, or a custom role with Create permission on “SMS_ConsoleExtensionData,” can still trigger the same sequence.

But there is an important qualification here. XM Cyber said it believes organizations are unlikely to be exposed through the Operations Administrator route because it is already a highly privileged role.

Once the CAB reaches the server, CabSlip allows files to escape the intended temporary extraction directory and be written elsewhere on the filesystem. The attacker can use this arbitrary file-write capability to replace “adsource.dll,” a secondary library loaded by the SYSTEM-level SMS Executive service without its own signature check.

When the service subsequently loads the DLL, the attacker gets code execution as SYSTEM.

A $58 certificate can cross the trust boundary

The chain becomes particularly notable because SCCM’s signature validation does not establish that the signing certificate belongs to Microsoft or the target organization. It checks that the signature is structurally valid and non-expired, while revocation checks are disabled.

That means an attacker does not need an enterprise certificate. XM Cyber said the attack depends on a code-signing certificate and can also abuse certificates leaked online. For his own research, Baso used a Certum Open Source Developer Certificate that cost about $58.

For defenders, XM Cyber recommends restricting network access to the AdminService API and auditing SCCM RBAC assignments, particularly accounts with the Operations Administrator role or equivalent Create permissions.

Teams should also monitor the Site Server’s “AdminService.log” for a “System.IO.DirectoryNotFoundException” followed by an HTTP 500 response, a pattern that can indicate the path traversal was triggered, XM Cyber added.

Unexpected modifications to adsource.dll in the Configuration Manager installation directory can provide another detection signal.

Microsoft is reportedly working on patches for the remaining flaws. It did not immediately respond to CSO’s request for comment.

The article originally appeared on CSO.

Kategorie: Hacking & Security

Linux Security Roundup Privilege Escalation DoS Code Execution August 2026

LinuxSecurity.com - 5 hodin 7 min zpět
This week’s Linux security updates cover several areas administrators cannot afford to overlook. Debian, Ubuntu, Fedora, SUSE, openSUSE, and other distributions released fixes for privilege escalation, remote code execution, denial of service, and flaws affecting network-facing services.
Kategorie: Hacking & Security

WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

The Hacker News - 5 hodin 26 min zpět
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

WhatsApp rolls out new feature that flags potential scam messages

Bleeping Computer - 5 hodin 28 min zpět
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]
Kategorie: Hacking & Security

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

The Hacker News - 5 hodin 34 min zpět
Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked [email protected]
Kategorie: Hacking & Security

OpenAI: Latest news and insights

Computerworld.com [Hacking News] - 7 hodin 11 min zpět

OpenAI is an artificial intelligence organization comprised of the non-profit OpenAI, Inc. and several for-profit subsidiaries. The company is perhaps best known for its ChatGPT chatbot, which launched in 2022, kicking off a period of massive disruption in the tech industry and beyond.

A complicated and increasingly contentious relationship with Microsoft, ongoing legal issues over copyright infringement, and frequent product announcements keep OpenAI in the news. Follow this page and never miss a beat.

Latest Open AI news and analysis: OpenAI targets heavy users with premium ChatGPT Business seats

Aug. 11, 2026: OpenAI is introducing a higher-priced “Premium” tier for its ChatGPT Business offering, allowing enterprises to assign higher-capacity access to select users alongside standard licences – a move analysts said is about enterprise AI vendors redesigning pricing to capture more value from high-intensity workloads.

OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window

Aug. 11, 2026: OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats.

OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards

Aug. 10, 2026: OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets.

OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidents

Aug. 5, 2026: OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evaluations, according to the UK AI Security Institute.

OpenAI drops GPT-5.6 Luna and Terra API prices by up to 80%

July 31, 2026: OpenAI has cut API prices for its GPT-5.6 Terra and Luna models by 20% and 80%, respectively, while also reducing the number of usage credits the models consume in ChatGPT Work and Codex, in an effort to effectively increase the amount of AI work enterprise subscribers can perform without paying more.

OpenAI rogue AI agent’s attack expanded beyond Hugging Face

July 29, 2026: The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains.

Hugging Face breach shows why incident response needs a multi-model AI strategy

July 28, 2026: The recent breach of Hugging Face’s platform by an internal OpenAI test of advanced model cyber capabilities that went wrong was the latest in a string of AI-assisted intrusions to come to light in recent weeks, showing that attackers can now use LLMs to automate entire attack chains.

Hugging Face CEO wants transparency after OpenAI’s AI incident

July 27, 2026: Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.

OpenAI not part of the new Open Secure AI Alliance

July 27, 2026: A new industry group led by Nvidia is promoting open AI models (and not OpenAI’s models) as essential to cyber defence.

OpenAI Presence raises new questions about enterprise automation and jobs

July 23, 2026: OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.

OpenAI model escape puts enterprise AI defenses on notice

July 22, 2026: An attack on Hugging Face executed by a sandboxed OpenAI model shows that prompt guardrails cannot serve as the main security boundary for AI agents, putting more pressure on enterprises to contain them through infrastructure controls that limit access and prevent lateral movement.

OpenAI’s Codex context reduction for GPT 5.6 sparks dissatisfaction among developers

July 20, 2026: OpenAI’s recent update to its Codex coding agent has developers worrying over the impact of the change on large code repositories and long-running AI-assisted sessions. The update to the Codex CLI reduces the default configured input context window for GPT-5.6 to 272,000 tokens from 372,000 tokens.

OpenAI’s new hardware is a $230, 13-switch keyboard for Codex

July 17, 2026: OpenAI is selling its first hardware — without any help from Jony Ive. It describes the Codex Micro as a “command center for agentic work” but it’s really a 13-switch wireless keyboard customized to help developers keep tabs on what their Codex agents are doing. It costs $230.

OpenAI’s GPT-5.6 may accidentally delete files

July 17, 2026: OpenAI said its latest large language model GPT-5.6-Sol can accidentally delete files, while stressing that such incidents are rare and should be viewed as “honest mistakes.”

OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout

July 10, 2026: OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.

OpenAI to release delayed models amidst a sea of regulatory confusion

July 8, 2026: As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, highlights the confusion.

US tells OpenAI to restrict access to its most powerful AI model

June 26, 2026: US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after ordering Anthropic to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on OpenAI.

OpenAI rolls out AI-led push to fix open-source software flaws

June 23, 2026: OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.

OpenAI gets the attention it needs from AI researcher Noam Shazeer

June 19, 2026: OpenAI has lured Noam Shazeer, one of the eight co-authors of the influential AI paper Attention Is All You Need, away from Google.

OpenAI adds spend controls and usage analytics to ChatGPT Enterprise

June 19, 2026: OpenAI has introduced spend controls and enhanced usage analytics for ChatGPT Enterprise to enable organizations to monitor AI adoption, track consumption across teams, and set budgets for AI usage. But, analysts cautioned, it still can’t show how those costs lead to business benefits.

ChatGPT will soon be able to shop with your Visa card

June 16, 2026: OpenAI has signed a partnership agreement with Visa that allows the company’s AI agents to use the payment card for e-commerce transactions. The agreements lets users shop for everything from groceries and diapers to airline tickets without having to manually enter a lot of information.

OpenAI buys Ona to help rein in AI agents

June 12, 2026: OpenAI has agreed to acquire Ona, a 79 person cloud development environment (CDE) provider formerly known as Gitpod, to accelerate its efforts to make agentic AI enterprise-friendly.

OpenAI weighs Nvidia-backed lease for 10 GW Ohio data center campus

June 10, 2026: OpenAI is reportedly in advanced talks to lease a proposed 10-gigawatt data center campus in southern Ohio in an arrangement that could include financial backing from Nvidia.

OpenAI’s Lockdown Mode is trying to solve the problem that it created

June 9, 2026: OpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of enterprises using multiple AI vendors for their agentic models further complicates an already dicey governance strategy.

OpenAI responds to White House executive order on AI governance

June 4, 2026: OpenAI has proposed mandatory federal evaluations of the most capable AI models before public release while arguing that regulators should stop short of deciding whether those systems can be deployed, staking out a middle ground in the debate over how frontier AI should be governed.

OpenAI fixed a visibility problem; the governance problem remains

June 3, 2026: OpenAI’s new ChatGPT session controls improve visibility, but experts say continuous model updates are creating a far bigger challenge for enterprise risk and compliance teams.

Attack targeting OpenAI Codex users exposes AI software supply chain risks

June 2, 2026: A malicious npm package posing as a remote user interface for OpenAI Codex exfiltrated developer authentication tokens, after attackers allegedly published code to npm that was not visible in the project’s public GitHub repository.

AI models more vulnerable than claimed when faced with iterative attacks

May 27, 2026: According to a new study from Cisco, frontier models from OpenAI, Anthropic, Google, xAI, and Amazon have significantly worse risk profiles when pressured in multi-turn attacks compared to when their safety is benchmarked using single prompts.

OpenAI introduces Daybreak cyber platform, takes on Anthropic Mythos

May 12, 2026: OpenAI has unveiled Daybreak, its answer to Anthropic’s Claude Mythos, amid a growing market for frontier AI-powered cyber defense platforms. The initiative combines OpenAI’s large language models, Codex’s agentic capabilities, and integrations with the broader enterprise security ecosystem.

OpenAI’s new AI consulting offering raises questions of trust, strategy

May 11, 2026: The OpenAI Deployment Company aims to help organizations build and deploy AI systems by embedding engineers specializing in frontier AI deployment, known as forward deployed engineers (FDEs), into their environments.

Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads

May 11, 2026: A malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being removed, raising fresh concerns about how enterprises source and validate AI models from public repositories.

OpenAI-led consortium seeks to address AI processing bottlenecks

May 8, 2026: An OpenAI-led consortium of tech giants including AMD, Broadcom, Intel, Microsoft, and Nvidia have unveiled a new networking protocol, Multipath Reliable Connection (MRC), designed to address network congestion, a problem that has always existed but has been exacerbated by the massive amounts of data required for AI processing.

OpenAI, Anthropic expand services push, signaling new phase in enterprise AI race

May 6, 2026: OpenAI and Anthropic are expanding their reach into professional services through joint ventures and acquisition talks, moving model providers closer to implementation roles traditionally held by systems integrators.

OpenAI’s Symphony spec pushes coding agents from prompts to orchestration

April 28, 2026: OpenAI has released Symphony, an open-source specification for turning issue trackers such as Linear into control planes for Codex coding agents.

Microsoft, OpenAI change contract terms — again

April 27, 2026: Microsoft and OpenAI have again revised their agreement, softening their exclusivity and revenue-sharing conditions in the process.

OpenAI pulls out of a second Stargate data center deal

April 15, 2026: In the space of one week, OpenAI has pulled out of two European Stargate data center deals, one in the UK and the other in Norway.

OpenAI puts part of Stargate project on hold over runaway power costs

April 10, 2026: OpenAI has postponed plans to open one of the data centers central to its Stargate project.

OpenAI calls for a four-day workweek — and a ‘robot tax’

April 7, 2026: In a new policy paper, OpenAI makes some interesting proposals to address the impact of AI on the labor market.

Microsoft builds its own AI stack to help wean it from its reliance on OpenAI

April 2, 2026: Microsoft seems to be meeting OpenAI on its own turf, even as it continues its strategic partnership with the AI darling, with the release of three in-house, commercially-available AI models.

OpenAI patches twin leaks as Codex slips and ChatGPT spills

March 31, 2026: OpenAI has fixed two flaws in its AI stack that could allow AI agents to move sensitive data in unintended ways.

OpenAI adds plugin system to Codex to help enterprises govern AI coding agents

March 27, 2026: OpenAI has introduced a plugin system for Codex, its AI-powered software engineering platform, giving enterprise IT teams a way to package coding workflows, application integrations, and external tool configurations into versioned, installable bundles that can be distributed or blocked across development organizations.

OpenAI’s Sora exit signals enterprise-first AI shift

March 25, 2026: OpenAI has discontinued its AI video generation platform Sora. The company announced the development in a sudden and unexpected post on X, stating that it was “saying goodbye” to the Sora app.

OpenAI’s Foundation play reframes the AI roadmap for IT leaders

March 24, 2026: The OpenAI Foundation has announced a sweeping range of investment and research goals, from building safeguards around how AI behaves in the wild to pushing for shared data ecosystems and funding disease research.

OpenAI to double workforce, highlights growing demand for enterprise AI talent

March 23, 2026: OpenAI is planning to almost double its workforce from about 4,500 to 8,000 employees by the end of 2026. The move comes as OpenAI sharpens its focus on scaling and monetising ChatGPT for enterprise use amid intensifying competition from Anthropic and Google.

OpenAI’s desktop superapp: The end of ChatGPT as we know it?

March 20, 2026: OpenAI is reportedly planning to fold its ChatGPT application, Codex coding platform, and AI-powered browser into a single desktop ‘superapp’, a move that signals a shift toward enterprise and developer audiences and away from the consumer market that made the company a household name.

OpenAI buys non-AI coding startup to help its AI to program

March 19, 2026: OpenAI has acquired Astral, the developer of open source Python tools including uv, Ruff and ty, and plans to integrate them with Codex, its AI coding agent.

OpenAI’s $50B AWS deal puts its Microsoft alliance to the test

March 17, 2026: Microsoft is considering legal action against OpenAI and Amazon over the $50 billion cloud deal the two recently struck to make Amazon Web Services (AWS) the exclusive third-party cloud distribution provider for OpenAI Frontier.

Encyclopedia Britannica sues OpenAI over AI training

March 17, 2026: Encyclopedia Britannica and its subsidiary Merriam-Webster have sued OpenAI, claiming the generative AI firm used their encyclopedia and dictionary texts to train AI models such as ChatGPT without permission.

OpenAI to acquire Promptfoo to strengthen AI agent security testing

March 10, 2026: OpenAI said it plans to acquire AI testing startup Promptfoo, a move aimed at strengthening security checks for AI agents as enterprises move toward deploying autonomous systems in business workflows.

OpenAI robotics chief quits over Pentagon deal

March 9, 2026: Caitlin Kalinowski has resigned over OpenAI’s contract with the US Department of War, saying key safeguards around domestic surveillance and autonomous weapons were not adequately reviewed before the agreement was signed.

OpenAI says Codex Security found 11,000 high-impact bugs in a month

March 9, 2026: OpenAI’s new AppSec agent, Codex Security, has already flagged over 11,000 high-severity and critical flaws in real-world codebases during its first 30 days of research testing. The tool is designed to automatically find, validate, and fix vulnerabilities in software repositories.

OpenAI says its US defense deal is safer than Anthropic’s, but is it?

March 2, 2026: OpenAI has struck a deal to supply the US government with AI services, announcing it hours after US President Donald Trump’s decision to ban its AI rival Anthropic from all US government contracts.

OpenAI partners with consulting giants to deploy enterprise AI agents

February 26, 2026: As it bids to push further into the enterprise, OpenAI announced that it has partnered with several large consulting firms. Frontier Alliances, as the partner initiative is called, will involve work with Accenture, Boston Consulting Group (BCG), Capgemini, and McKinsey & Co. 

OpenAI hires OpenClaw founder as AI agent race intensifies

February 16, 2026: OpenAI has hired Peter Steinberger, creator of the viral OpenClaw AI assistant, to spearhead development of what CEO Sam Altman describes as “the next generation of personal agents.”

OpenAI responds to Claude Cowork with its own platform for AI agents

February 5, 2026: Anthropic released 11 open-source plugins that enable Claude Cowork to execute a series of automated processes in areas ranging from customer support to IT operations, OpenAI responded Thursday with a similar platform it calls Frontier.  

Who profits from AI? Not OpenAI, says think tank

January 29, 2026: Findings from a new study by Epoch AI, a non-profit research institute, seeks to answer three questions: How profitable is running AI models? Are models profitable over their lifecycle? Will AI models become profitable?

Will the Microsoft-Anthropic deal leave OpenAI out in the cold?

January 27, 2026: Microsoft wasted little time after reaching a deal to finalize its new relationship with OpenAI to find a new AI dance partner — Anthropic, the second most valuable AI startup in the world. It appears as if Microsoft sees a future with Anthropic that’s at least as valuable as the one it had with OpenAI.

OpenAI to add age verification to ChatGPT

January 21, 2026: OpenAI has adding age verification to ChatGPT following reports that several children and young people have taken their own lives after conversations with the popular chatbot. The move echoes a recent decision by TikTok to do the same thing to protect underage users from accessing inappropriate content.

Musk’s OpenAI lawsuit clears path to trial, putting Microsoft in the spotlight

January 9, 2026: A federal judge has signalled that Elon Musk’s lawsuit challenging OpenAI’s transformation to a for-profit entity will proceed to trial, adding legal uncertainty for enterprise customers that have built AI strategies around the ChatGPT maker’s technology.

OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacy

December 12, 2025: OpenAI has released GPT-5.2, claiming significant gains in the AI model’s ability to complete real-world business tasks to an “expert level” compared to GPT-5.1, released in November. The new model offers major improvements across a range of benchmarks, the company said.

What does OpenAI’s ‘Code Red’ warning mean for Microsoft?

December 10. 2025: OpenAI founder and CEO Sam Altman sent out a memo to OpenAI employees declaring a “Code Red” emergency and focusing all company efforts on improving ChatGPT. The reason? Google’s newly released Gemini 3 model beat the pants off GPT-5.1

OpenAI to acquire AI training tracker Neptune

December 3, 2025: OpenAI has agreed to acquire Neptune, a startup specializing in tools for tracking AI training. Neptune promptly announced it is withdrawing its products from the market.

OpenAI admits data breach after analytics partner hit by phishing attack

November 27, 2025: OpenAI suffered a significant data breach after hackers broke into the systems of its analytics partner Mixpanel and successfully stole customer profile information for its API portal, the companies have said in coordinated statements.

OpenAI rolls out GPT-5.1 to refine ChatGPT with adaptive reasoning and personalization

November 13, 2025: OpenAI has introduced GPT-5.1, an update to its GPT-5 model, aiming to deliver faster responses, improved reasoning, and more flexible conversational controls as the company works to refine its ChatGPT experience for both consumer and enterprise users.

OpenAI spends even more money it doesn’t have

November 3, 2025: OpenAI’s overdraft continued its upward trajectory today when the company signed a multi-year $38 billion contract with AWS to have it run its AI workloads. The latest spending spree adds to the incremental $250 billion of Azure services it pledged to buy last week, and, of course, to the commitment it has made towards building Stargate data centers with Oracle.

OpenAI seeks to automate ‘computer use’ for Macs in the enterprise

October 24, 2025: While AI bots have begun mastering tasks in browsers and on Windows, Mac-using enterprises have largely been overlooked, until now. OpenAI aims to change that with its acquisition of generative AI interface maker Software Applications Incorporated.

Enterprises should not install OpenAI’s new Atlas browser, analysts warn

October 24, 2025: Companies that might be eyeing OpenAI’s new ChatGPT Atlas browser should not rush to use it because of potential security risks, analysts said this week. The browser was unveiled on Tuesday after it had been teased for months as a work in progress. It is currently available for MacOS only.

Has OpenAI shown us a future for Safari?

October 23, 2025: Has OpenAI shown us the future of Safari? In one way it has, because its new Atlas browser shows these generative AI (genAI)-based apps are no longer just windows to the web — they’re becoming intelligent copilots for our digital lives. 

OpenAI–Broadcom alliance signals a shift to open infrastructure for AI

October 14, 2025: OpenAI has partnered with Broadcom to co-develop and deploy its first in-house AI processors. The move could reshape data center networking dynamics and chip supply strategies as the ChatGPT maker races to secure more computing power for AI workloads.

OpenAI Codex rivals Claude Code

October 13, 2025: The OpenAI Codex gives software developers a first-rate coding agent in their terminal and their IDE, along with the capability to delegate background tasks to agents in the cloud.

OpenAI Codex adds SDK, admin tools, Slack integration

October 10, 2024: Codex is now generally available. Since being launched as a research preview in May, Codex, OpenAI’s AI-powered software engineering agent that can work on tasks in parallel, has added Slack integration, an SDK, and admin tools.

OpenAI admits AI hallucinations are mathematically inevitable, not just engineering flaws

September 18, 2025: OpenAI, the creator of ChatGPT, acknowledged in its own research that large language models will always produce hallucinations due to fundamental mathematical constraints that cannot be solved through better engineering.

OpenAI, Microsoft discuss shape of future relationship

September 12, 2025: Microsoft and OpenAI are in talks about the future of their partnership, they said in a joint statement , without providing details. Separately, OpenAI said it wants to go ahead with its previously announced plan to turn its for-profit business into a public benefit corporation, in which its nonprofit organization would own a $100 billion stake.

What Oracle’s $300B OpenAI deal means for enterprise cloud strategy

September 11, 2025: A single $300 billion contract has seemingly transformed Oracle from a traditional ERP and database vendor into a cloud computing powerhouse.The company has signed a five-year computing power commitment with OpenAI, contributing to a reported 359% surge in future contract revenue this quarter.

OpenAI acquires Statsig to speed up generative AI-based product launches

September 3, 2025: OpenAI is acquiring Statsig, a Washington-based product development platform startup, for $1.1 billion to speed up its generative AI-based product launches and accelerate iteration cycles of existing products such as Codex and ChatGPT.

OpenAI drops GPT-5: smarter, sharper, and built for the real world

August 7. 2025: More than two years after GPT-4’s release, OpenAI has unveiled GPT-5, boasting sharper reasoning, multimodal input, better math skills, and cleaner task execution, according to the company.

OpenAI challenges rivals with Apache-licensed GPT-OSS models

August 6, 2025: OpenAI has released its first open-weight language models since GPT-2, marking a significant strategic shift as the company seeks to expand enterprise adoption through more flexible deployment options and reduced operational costs. The two new models — gpt-oss-120b and gpt-oss-20b — deliver what OpenAI describes as competitive performance while running efficiently on consumer-grade hardware. 

Google snatches Windsurf execs in a $2.4B deal, derailing OpenAI’s biggest acquisition yet

July 14, 2025: Google has recruited CEO Varun Mohan and co-founder Douglas Chen of AI coding startup Windsurf in a $2.4 billion talent acquisition deal, just two months after Windsurf agreed to be acquired by OpenAI for $3 billion. Mohan, Chen and select research and development staff, will join Google’s DeepMind AI division

OpenAI and Perplexity enter browser wars to take on Chrome

July 10, 2025: Google Chrome’s dominance in the browser market is facing new threats as OpenAI and Nvidia-backed Perplexity unveil AI-powered browsers aimed at reshaping how users interact with the web. Comet is a new web browser with built-in AI search capabilities, the company said.


Microsoft brings OpenAI-powered Deep Research to Azure AI Foundry agents

July 8, 2025: Microsoft added OpenAI-developed Deep Research capability to its Azure AI Foundry Agent service. The move is designed to let developers use Deep Research API and SDK to embed, extend, and orchestrate Deep Research-as-a-service across data and existing systems.

Oracle to power OpenAI’s AGI ambitions with 4.5GW expansion

July 3, 2025: OpenAI has signed a significant compute leasing deal with Oracle, under which it will access 4.5 gigawatts (GW) of data center power, marking one of the largest single leasing arrangements in the industry.

OpenAI tests Google TPUs amid rising inference cost concerns

July 1, 2025: OpenAI has begun testing Google’s Tensor Processing Units (TPUs), a move that — though not signaling an imminent switch — has raised eyebrows among industry analysts concerned about the escalating costs of AI inference and its effects.    

Microsoft/OpenAI AGI argument unlikely to impact enterprise IT

June 26, 2025: The contract between the two AI giants has an exit clause once AGI is achieved. The problem: It is impossible to prove when that happens. Either way, IT execs at Macy’s, Bank of America, doubt it will matter.

OpenAI productivity suite could change the way users create documents

June 26, 2025: OpenAI’s planned productivity suite could dismantle traditional habits of how users create and consume documents in the same the way the company changed browsing and search habits.

o3-pro may be OpenAI’s most advanced commercial offering, but GPT-4o bests it

June 24, 2025: In a head-to-head comparison of the two models, researchers found that o3-pro is far less performant, reliable, and secure, and does an unnecessary amount of reasoning. Notably, o3-pro consumed 7.3x more output tokens, cost 14x more to run, and failed in 5.6x more test cases than GPT-4o.

Microsoft and OpenAI: Will they opt for the nuclear option?

June 24, 2025: The fight between Microsoft and OpenAI over what Microsoft should get for its $13 billion investment in the AI company has gone from nasty to downright toxic, with each of the companies considering strategies against the other that can only be described as their nuclear options. 

OpenAI walks away from Scale AI — triggering industry-wide rethink of data partnerships

June 19, 2025: OpenAI has ended its long-standing partnership with Scale AI, the company that powered some of the most complex data-labeling tasks behind frontier models such as GPT-4.

OpenAI’s o3 price plunge changes everything for vibe coders

June 18, 2025: o3 used to be too slow and too expensive for daily coding—no longer. The latency is now bearable, the price is sane, and the chain-of-thought pays off.

Sam Altman: Meta tried to lure OpenAI employees with billion-dollar salaries

June 18, 2025: After reports suggested Meta has tried to poach employees from OpenAI and Google Deepmind by offering huge compensation packages, OpenAI CEO Sam Altman weighed in, saying those reports are true.

OpenAI-Microsoft tensions escalate over control and contracts

June 17, 2025: The relationship between OpenAI and Microsoft is under growing strain amid extended talks over OpenAI’s restructuring, with OpenAI reportedly considering antitrust action over Microsoft’s influence in the partnership.

OpenAI’s MCP move tempts IT to trust genAI more than it should

June 16, 2025: OpenAI late last month announced changes to make it much easier to give its genAI models full access to any software using Model Context Protocol (MCP). Here’s why that’s a bad idea.

OpenAI launches o3-pro, slashes o3 price by 80% in bid to widen AI lead

June 11, 2025: OpenAI has unveiled its most advanced AI model to date, the o3-pro, which surpasses competitors on key benchmarks and replaces the o1-pro. The o3-pro is now available for ChatGPT Pro and Team users, as well as through the developer API, with access for enterprise and education sectors beginning next week.

What Microsoft hopes to get from its breakup with OpenAI

June 11, 2025: The once-tight bond between Microsoft and OpenAI has been fraying for well over a year — and it’s getting worse. What the two companies want from each other now is very different from when Microsoft made its original $13 billion investment.

Oracle to spend $40B on Nvidia chips for OpenAI data center in Texas

May 26, 2025: Oracle is reportedly spending about $40 billion on Nvidia’s high-performance computer chips to power OpenAI’s new data center in Texas, marking a pivotal shift in the AI infrastructure landscape that has significant implications for enterprise IT strategies.

OpenAI’s Skynet moment: Models defy human commands, actively resist orders to shut down

May 30, 2025: OpenAI’s most advanced AI models are showing a disturbing new behavior: they are refusing to obey direct human commands to shut down, actively sabotaging the very mechanisms designed to turn them off.

Jony Ive and OpenAI plan ‘bicycles’ for 21st-century minds

May 21, 2025: OpenAI has announced that it will purchase io, the AI startup founded by acclaimed former Apple designer Sir Jony Ive, who helped create the iMac, iPod, and iPhone. 

OpenAI launches Codex AI agent to tackle multi-step coding tasks

May 19, 2025: OpenAI’s most advanced AI coding agent, Codex, will bring parallel task automation to developers—but analysts caution that speed without scrutiny invites “silent failures.”

Cisco taps OpenAI’s Codex for AI-driven network coding

May 16, 2025: Cisco is working with OpenAI and its newly released Codex software engineering agent to give network engineers access to better tools for writing, testing and building code.

OpenAI’s IPO aspirations prompt rethink of Microsoft alliance

May 12, 2025: Microsoft and OpenAI are renegotiating their multibillion-dollar partnership deal to better align with each company’s evolving goals in the artificial intelligence race

OpenAI hires Instacart CEO Fidji Simo to oversee customer-facing apps

May 8, 2025: The hire indicates that OpenAI’s roadmap will involve more structured, productized offerings rather than just API access.

OpenAI offers help promoting AI outside the US, but analysts question why countries would accept

May 7, 2025: OpenAI, acting as part of the US government-led Stargate AI project, rolled out a program called OpenAI for Countries. The idea is for Stargate to help other countries create their own genAI environments, including data centers and genAI models.

OpenAI reaffirms nonprofit control, scales back governance changes

May 6, 2025: OpenAI has scrapped plans to reduce its nonprofit parent’s oversight and will keep its existing governance structure intact, a move that limits CEO Sam Altman’s influence and responds to mounting external pressure.

OpenAI to acquire AI coding tool Windsurf for $3B

May 6, 2025: The acquisition comes just months after Windsurf explored funding at this same valuation from investors, highlighting the premium being placed on specialized AI coding capabilities, according to reports.

Former OpenAI employees urge regulators to halt company’s for-profit shift

April 23, 2025: A broad coalition of AI experts, economists, legal scholars, and former OpenAI employees is urging state regulators to keep OpenAI’s nonprofit foundation in control of the company.

OpenAI’s new models can ‘think with pictures’

April 17, 2025: OpenAI has released o3 and 04-mini, two reasoning AI models designed to be extra good at programming, math, and science and that can use images to “think,” according to Engadget, This means that users can upload sketches or diagrams, for example, and even if they are of low quality, o3 and 04-mini will understand what is meant.

OpenAI GPT-4.1 models promise improved coding and instruction following

April 15, 2025: The GPT-4.1, GPT-4.1 mini, and GPT-4.1 nano models, available only via the API, will provide better performance than GPT-4o and GPT-4o mini at a lower price, OpenAI said.

OpenAI slammed for putting speed over safety

April 11, 2025: According to a Financial Times report, the ChatGPT maker is now assigning staff and third-party groups only a few days to assess the risks and performance of its latest large language models (LLMs) as compared to several months they were given earlier.

OpenAI fears irreparable harm from Musk, files countersuit

April 10, 2025: OpenAI has filed a countersuit against Elon Musk, accusing the billionaire of a sustained campaign to damage the company and urging a US federal court to block further actions it described as unlawful and disruptive. The legal filing, submitted in a California district court, marks the latest escalation in a dispute between Musk and the AI startup he helped establish in 2015.

Senators probe Google-Anthropic, Microsoft-OpenAI deals over antitrust concerns

April 9, 2025: Democratic Senators Elizabeth Warren and Ron Wyden have launched a formal inquiry into partnerships between tech giants Google and Microsoft, and AI startups, demanding detailed information about arrangements they fear may be circumventing antitrust scrutiny while consolidating power in the rapidly evolving AI market.

Anthropic’s and OpenAI’s new AI education initiatives offer hope for enterprise knowledge retention

April 4, 2025: Two of the biggest names in artificial intelligence are independently developing new AI tools that encourage learning, at a time when the technology has been criticized for dumbing down smart users in the enterprise and discouraging critical thinking. While the new initiatives from OpenAI and Anthropic are aimed at transforming how AI is used in higher education, the opportunities they open up extend beyond universities.

Amazon, OpenAI, and China’s Zhipu unveil new AI tools amid intensifying competition

April 1, 2025: A wave of new AI products is hitting the market, signaling a shift toward more autonomous, task-completing systems that could reshape how businesses and consumers interact with digital services: Amazon has unveiled Nova Act, an AI agent designed to operate a web browser much like a human user; OpenAI said it will release an open-weight language model; and China’s Zhipu AI introduced a free AI assistant aimed at strengthening its position in the domestic market and competing with Western tech giants.

OpenAI, Google AI data centers are under stress after new genAI model launches

March 28, 2025: New generative AI models introduced by Google and OpenAI have put the companies’ data centers under stress — and both companies are trying to catch up to demand. OpenAI’s CEO Sam Altman tweeted that his company was temporarily restricting the use of GPUs after overwhelming demand for its image generation service on ChatGPT.

Microsoft abandons data center projects as OpenAI considers its own, hinting at a market shift

March 26, 2025: OpenAI has privately discussed building and operating its first data center to house storage, which is essential for developing sophisticated AI models. Microsoft, on the other hand, has pulled back on its buildouts, canceling data center projects in the US and Europe.

OpenAI calls for US to centralize AI regulation

March 13, 2025: OpenAI executives think the federal government should regulate artificial intelligence in the US, taking precedence over often more restrictive state regulations.

New tools from OpenAI help companies create their own AI agents

March 12, 2025: OpenAI launched Responses, a new api intended to eventually replace Assistants. The big draw? Responses provides a number of new tools that companies and organizations can use to create their own AI agents.

Microsoft is developing its own AI models to compete with OpenAI

March 10, 2025: Reports suggest Microsoft has decided to seriously challenge Deepseek and OpenAI by developing its own set of reasoning AI models called Microsoft AI (MAI). If successful, Microsoft would eventually not have to use its partner OpenAI’s o1 models in Copilot

Microsoft-OpenAI investigation closed by UK regulators

March 5, 2025: The UK’s Competition and Markets Authority (CMA) spent a great deal of time deciding whether it should investigate Microsoft’s investment in OpenAI as a potential merger situation, but in the end, decided to open and close the investigation within 24 hours.

OpenAI revamps AI roadmap, merging models for a leaner future

February 13, 2025: OpenAI will integrate “o3” into GPT-5 instead of releasing it separately, streamlining adoption while signaling a shift toward fewer, more controlled AI models amid rising competition and cost pressures.

Musk’s $97B offer to buy OpenAI rejected as leadership stands firm

February 11, 2025: In a message to staff, Altman said the board has no intention of considering Musk’s offer, stating that the proposal does not align with OpenAI’s mission

OpenAI launches deep research agent for multi-step research tasks

February 3, 2025: Hot on the heels of its launch of the o3-mini model, OpenAI announced another component for ChatGPT that allows the generative AI tool to do more in-depth research. “Deep research is built for people who do intensive knowledge work in areas like finance, science, policy, and engineering and need thorough, precise, and reliable research,” OpenAI said in a blog post announcing the new capability.

OpenAI unleashes o3-mini reasoning model

January 31, 2025: OpenAI released the latest model in its reasoning series, o3-mini, both in ChatGPT and its application programming interface (API). It had been in preview since December 2024.

Indian media houses rally against OpenAI over copyright dispute

January 27, 2025: The legal heat on OpenAI in India intensified as digital news outlets owned by billionaires Gautam Adani and Mukesh Ambani joined an ongoing lawsuit against the ChatGPT creator. They were joined by some of the largest news publishers in India including the Indian Express, and Hindustan Times, and members of the Digital News Publishers Association (DNPA), which includes major players like Zee News, India Today, and The Hindu.

Altman now says OpenAI has not yet developed AGI

January 20, 2025: Confusion over whether OpenAI’s o3-mini has reached the major milestone of artificial general intelligence (AGI) or not deepened following a post on X by CEO Sam Altman that completely contradicts what he said two weeks earlier in an interview with Bloomberg.

Microsoft sues overseas threat actor group over abuse of OpenAI service

January 13, 2025: Microsoft has filed suit against 10 unnamed people (“Does”), who are apparently operating overseas, for misuse of its Azure OpenAI platform, asking the Eastern District of Virginia federal court for damages and injunctive relief.

With o3 having reached AGI, OpenAI turns its sights toward superintelligence

January 6, 2025: OpenAI CEO Sam Altman has reinvigorated discussion of artificial general intelligence (AGI), boldly claiming that his company’s newest model has reached that milestone.

Now US government agencies can use OpenAI’s ChatGPT too

January 28, 2025: OpenAI has rolled out ChatGPT Gov, a version of its flagship frontier model specifically tailored to US government agencies. The platform has many of the same capabilities as OpenAI’s other enterprise products, including access to GPT-4o and the ability to build custom GPTs — and it also features a much higher level of security than ChatGPT Enterprise.

OpenAI debuts AI agent Operator to transform web task automation

January 24, 2025: OpenAI has unveiled “Operator,” a new AI agent designed to perform web-based tasks, offering potential productivity enhancements for enterprises. The tool enables interaction with on-screen elements, positioning it as a solution for automating routine processes in business workflows amid growing competition in the generative AI space.

OpenAI opposes data deletion demand in India citing US legal constraints

January 23, 2025: OpenAI has informed the Delhi High Court that any directive requiring it to delete training data used for ChatGPT would conflict with its legal obligations under US law. The statement came in response to a copyright lawsuit filed by the Reuters-backed Indian news agency ANI, marking a pivotal development in one of the first major AI-related legal battles in India.

OpenAI, SoftBank, Oracle lead $500B Project Stargate to ramp up AI infra in the US

January 22, 2025: Several large technology firms including OpenAI, SoftBank, Oracle, Nvidia, and MGX have partnered to set up a new company in the US to ramp up AI infrastructure in the country.

OpenAI is losing money on its pricey ChatGPT Pro subscription

January 7, 2025: OpenAI CEO Sam Altman, in a post on X, says the AI ​​company is currently losing money on its ChatGPT Pro subscription. “People are using it much more than we expected,” he wrote.

Fine-tuning Azure OpenAI models in Azure AI Foundry

January 2, 2025: Microsoft Azure’s new AI toolkit makes it easy to customize OpenAI large language models for your applications.

OpenAI still hasn’t released tools to deny data collection

January 2, 2025: OpenAI has failed to release the tool to opt-out or customize data collection the company promised to make available by 2025, according to Techcrunch.

Kategorie: Hacking & Security

Pixel 11 envy? Here’s how to unlock its best new feature on any Android device

Computerworld.com [Hacking News] - 7 hodin 19 min zpět

Have you heard? It’s that time of year again — time for some snazzy new Pixels to tempt our gadget-coveting “gimme!” reflexes and guide flagship Android phone expectations for months to come.

Google’s latest and greatest gizmo is the Pixel 11 series, which includes the regular Pixel 11 and Pixel 11 Pro alongside the plus-sized Pixel 11 XL and Pixel 11 Pro XL and the fancy new folding Pixel 11 Pro Fold model (gesundheit!). El Googaloo took the wraps off all those new devices on Wednesday and has ’em all available for preorder now, with prices starting at $899 (regular Pixel 11), $1,099 (Pixel 11 Pro), and $1,299 (Pixel 11 Pro Fold).

At first glance, this year’s Pixel models might not seem like the most exciting upgrades from last year’s Pixel 10 products. They bring plenty of significant refinements to an already successful formula, with some welcome ticks forward — like better cameras, brighter and more scratch-resistant displays, faster charging speeds, and an updated processor that supposedly leads to speedier and more efficient performance. And, of course, there’s more Gemini everywhere (for better or for worse, depending on your perspective). But impressive as it all may be, it’s mostly iterative improvements over the previous-gen Pixels — which isn’t necessarily a bad thing but also isn’t exactly awe-inspiring, at least on the surface.

The most eye-catching addition to the Pixel 11 series is, rather ironically, a callback from Android’s past. It’s something Google’s calling HiLight, and it’s basically a new series of LED lights built into the freshly thinned-down camera bar on the phones’ backs. The lights illuminate to alert you to different events, allowing you to know about important incoming info at a glance — without having to so much as even look at your screen.

If the concept feels familiar, it should: Early Android devices boasted a similar sort of LED notification light for a very similar purpose. They were less visually striking, but they served the same basic purpose — up until they went out of favor for the far more complex (and, some might argue, less effective) always-on display concept that followed.

Here’s a little secret, though: You don’t have to have a new Pixel 11 phone in front of you to enjoy a similar sort of distraction-reducing, awareness-enhancing sorcery. You can actually recreate the Pixel 11 HiLight glow effect on any Android device this instant — and do it in a way that’s much more versatile, functional, and all-around useful, to boot.

Lemme show ya how.

[Get next-level knowledge in your inbox with my free Android Intelligence newsletter. One new and useful tip every Friday!]

The lowdown on Pixel 11 HiLight

First things first, a quick hit of context about the Pixel 11 HiLight system and how it actually works.

As of the phones’ launch, HiLight is active only when the device is face down on a surface — perhaps not surprisingly, given that the lights live on the device’s back — and it works only in two super-specific scenarios:

  1. When you’re in the midst of getting an incoming call from a favorite contact, the Pixel 11 HiLight indicator glows with a custom color so you can see who’s calling and know it’s important. (It works with both the Pixel Phone app and WhatsApp, to start.)
  2. When you’re interacting with Gemini, HiLight pulses to let you know the system is listening, thinking, and responding.

Aaaaaaaand, that’s it. The system doesn’t work with any other apps, according to Google, and it doesn’t interact with notifications in general to let you know about important pending activity beyond those incoming calls.

It’s actually quite limited, in other words. And no matter what Android phone you’re using — even if it ends up being a Pixel 11! — you can take the same classic concept and make it infinitely more valuable.

The trick revolves around a handy little power-user app called AodNotify. The app has a few different versions, depending on which specific type of Android device is in your paw right now:

Whichever version you end up with, AodNotify essentially creates your own custom notification light within your Android phone’s screen — by lighting up the area around your camera cutout at the top of the display, or alternatively creating a border-outline light that goes all the way around the phone front’s perimeter. And it shows up both when the screen is on and when it’s off.

AodNotify puts a Pixel-11-HiLight-style notification light right on any Android device’s display.

JR Raphael, Foundry

It serves the same basic purpose as the Pixel 11 HiLight (as well as the old-school 2008-era Android phone LED notification lights that preceded it), but with some key advantages:

  • You can see it when your phone is face-up — the way most folks seem to set their devices down when they aren’t actively in use.
  • As a result, you can see it when your screen is on and you’re actively using the device as well as when the display is off, as mentioned a moment ago.
  • You can have it light up to alert you of any manner of incoming call or notification with the same sort of simple at-a-glance recognition.
  • And you can control exactly how and when it works, down to the tiniest of preferences, to make it perfectly useful for you.

Compared to HiLight, the practical value of this approach is absolutely bonkers. Rather than just letting you know about important incoming calls when your phone is face down, AodNotify lets you see at a glance exactly what type of notifications are waiting for you at any given moment — without having to so much as pick up your phone or process any intricate on-screen info.

Whatever alert it flashes can stay present and visible for any amount of time, too, so whether you hear a ding and want to glance to see what’s up or even if you miss the audio alert entirely (or have it disabled deliberately) and want to sneak a peek at your screen to know in a split second what’s waiting for you, AodNotify will get the job done.

And it’s surprisingly easy to set up, too — with two to three minutes of one-time configuration that you’ll never have to think about again.

Your own Android HiLight equivalent

All right — ready? First things first, go install AodNotify from the Play Store, using whichever link is appropriate for your current Android device from above.

Once the app is ready, open ‘er up and follow the prompts to get it going and grant it all the forms of access it needs to operate:

  • First, you’ll select which apps can activate your new notification light and cause it to illuminate. If you want any and all notifications to be included, tap the “All” option at the top of the list. If you want to cherrypick and select only certain especially important apps while leaving others off, you can just choose whichever apps you’d like to have included.
  • Next, tap the lines for “Notification access,” “Enable AOD,” and “Draw on screen,” if needed, and follow the prompts to enable AodNotify and/or the necessary option for each of the associated areas. This may seem like a lot of access, but AodNotify genuinely needs it to do what it does — and, critically, the app doesn’t require any other system-level permissions, including even access to the internet, so it couldn’t possibly do anything with your data (and its privacy policy is clear about the fact that it doesn’t collect or share any manner of data, ever). It’s also by a known and long-standing reputable Android developer.
  • After that, you’ll see a pop-up prompting you to consider the app’s Pro version — which runs five bucks a year or $7 for a single one-time purchase. The Pro path turns off some ads in the AodNotify setup interface and enables some extra features. You may or may not want to consider it eventually, but for now, just hit the “x” in the upper-right corner of that prompt to dismiss it and move on.
AodNotify’s initial setup takes roughly two to three minutes to get through.

JR Raphael, Foundry

Now for the fun part: At the app’s main setup screen, make sure the toggles next to “Notifications” and “Notification light” are active — then tap into each of those sections along with “Colors” and “General” to explore all of the available options.

Of particular note:

  • Under “Notifications,” the “Battery” section lets you activate a special notification light for anytime your phone is charging, fully charging, or with a low (less than 15%) battery — so you can always be aware of that info when it arises.
  • Under “Notification light,” the “Style” selector will let you shift your spiffy new light from its default camera-cutout-outline position to a full-screen outline or a classic-Android dot-in-the-corner LED-type effect.
  • “Effects” in that same section will let you change the light from a simple pulse to all sorts of other interesting light-up patterns.
  • “Dimensions” will let you shift the exact size, shape, and placement of the light, if it doesn’t look quite right on your screen.
  • And the “How long to show the light” subsection will let you adjust how long any active notification light remains present, both when your screen is on and when the display is dark.
You’ll find all sorts of interesting settings for controlling how your custom notification light works.

JR Raphael, Foundry

Beyond all of that, some of AodNotify’s most helpful options are in its “Colors” settings section. There, you can specify different distinctive colors for messages or calls connected to different contacts, so you can see who is calling or texting you just by the color of the light (much like what the Pixel 11 HiLight feature does, only with a much broader and more sensible scope). And you can activate an off-by-default option to have your notification light automatically change its color to match the primary hue associated with any given app’s icon — which is a nifty way to know at a glance that a pending alert is coming from, say, your Calendar app or Slack.

AodNotify’s “Auto color” option is one of the app’s most powerful — and easily overlooked — features.

JR Raphael, Foundry

And that’s pretty much it. Your Pixel-11-style HiLight upgrade is officially complete — with an even more useful productivity-boosting framework than what the Pixel 11 HiLight version provides.

That’s the power of Android for ya. And it’s a power that’s present no matter what device is in front of you or how long you’ve been holding it.

Never miss a moment of Android awesomeness with my free Android Intelligence newsletter. One new exceptional tip in your inbox every Friday — straight from me to ye.

Kategorie: Hacking & Security

Armored Likho expands its cyber-espionage toolkit

Kaspersky Securelist - 9 hodin 19 min zpět

In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage.

We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal.

During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data to gain ongoing access to the victim’s account. With this stolen data, attackers can leverage the Telegram API to automatically pull chat logs, media files, and other information from the account.

The second component, Still Audio, is an implant for covert audio surveillance. It analyzes the incoming audio stream, automatically detects speech, records conversations, and sends the recordings to a command-and-control server.

In this article, we’ll look at the initial infection method, how the new Still Toolkit components are built, and the technical details of how they operate.

Kaspersky products detect this threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.

Background

Armored Likho’s malicious activity has been documented several times before: in November 2024, and in February and July 2026. The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure. At the same time, our research uncovered a number of new tools that point to the attackers expanding their capabilities.

Initial infection

The infection chain starts with an app that mimics a donation service. As of this writing, the app distribution method remains unknown. During our research, however, we obtained several samples posing as apps from different Russian foundations.

In reality, the app is a dropper. Its developers wrote it in Rust on top of the popular Tauri framework, and it has a graphical interface designed to deceive the user. After launch, it displays a login form that asks for a password, presumably one the attackers supplied.

The login form

After the user enters a valid password, they see a catalog of donatable items. The app pulls item and category information from orderapiserver[.]info through the public/categories and public/products endpoints. A clickable catalog makes the app look legitimate. While the user browses the items, the dropper quietly decrypts and launches the payload for the next stage in the background.

Our analysis shows that the mechanism for decrypting the payload and launching subsequent stages hasn’t changed since the February campaign. However, we found a new cyber-espionage toolkit – the Still Toolkit – made up of two components: Still Sync and Still Audio.

Still Sync

Still Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API.

Architecturally, Sync is an asynchronous application based on the Tokio library. It talks to the server over gRPC and serializes messages with FlatBuffers. It supports both HTTP and HTTPS as transport protocols; the URL of the command-and-control server determines which one it uses.

How it works

When Sync launches, the attackers set several environment variables. Before starting any malicious activity, the implant pulls configuration parameters from these:

  • STILL_SYNC_ADDR: the address of the command-and-control server. By default, this is https://tg4service[.]com:443.
  • STILL_SEND_PATH: the path to the tdata
  • STILL_TELEGRAM_PASSCODE: the password for decrypting the tdata folder, if Telegram data encryption is enabled on the victim’s device.

Sync also supports several command-line arguments:

  • --console: runs as a console application. If this parameter is absent, the implant creates a TReload service to keep running in the background.
  • --version: prints version information and exits.
  • --firefly: launches a trace thread that monitors the program’s operation. It writes error messages to a hidden file, bin, located in the same folder as the main executable.
  • --db: turns on debug mode with detailed logging.

Example Still Sync logs

Once it launches, the malware begins registering the device with the C2 server. To do this, Sync collects the following information about the victim’s system:

  • Motherboard serial number
  • CPU ID
  • System UUID
  • BIOS serial number
  • Computer domain name

The malware combines the collected data into a single string with a colon as the separator. It then hashes that string with SHA-256 and stores the resulting hash under the key sysmarker. Worth noting: other Armored Likho tools, AquilaRAT included, use this same hashing algorithm.

Sync then serializes a package containing all the collected information and the agent version, and sends it in a POST request to /still.rpc.Sync/RegisterMachine. The response contains a machine_id value, which Sync uses to identify itself in subsequent requests.

Once registration succeeds, Sync sends a POST request with the machine_id parameter to /still.rpc.Sync/GetMachineSettings. The server responds with the following settings:

  • enabled: triggers malicious activity on the infected device.
  • scan_portable: turns on extended scanning when searching for the tdata We’ll cover this feature in more detail below.
  • fetch_telegram: if this parameter is on, Sync attempts to log in to Telegram and extract data. We’ll cover this feature in more detail below.
  • download_channels: if this parameter is off, Sync skips channel dialogs when exfiltrating Telegram data.

These parameters have no default values, so Sync doesn’t perform any malicious actions until the registration and settings-retrieval processes both complete successfully.

Telegram data collection

Before stealing a Telegram session, Sync searches for the tdata folder, unless the STILL_SEND_PATH variable is already set. The list of search paths includes both standard and nonstandard directories, if the scan_portable option is turned on:

  • C:\Users\<username>\AppData\Roaming\Telegram Desktop\: the standard Telegram Desktop installation directory.
  • C:\Users\<username>\AppData\Local\Packages\<package_folder>\LocalCache\Roaming\: the installation directory for the Microsoft Store version. Sync identifies the package folder by a name that contains the string TelegramMessenge.
  • C:\: used for the extended search (if the scan_portable option is on).

Sync then sends a POST request with a list of files from the tdata folder to the /still.rpc.Sync/CheckFiles endpoint. The server responds with the following values:

  • snapshot_id: an identifier the server assigns to the current data snapshot.
  • present: a list of file paths that are already present on the server.

This lets the C2 server avoid re-receiving files it already has. In addition, if Sync can’t access files on disk through standard methods, it falls back on three mechanisms that abuse the SeBackupPrivilege privilege:

  • Opening files with the CreateFileW function using the FILE_FLAG_BACKUP_SEMANTICS parameter
  • Creating a backup copy through the Shadow Copy service and reading files from there
  • If the previous methods all fail, attempting to copy the file using the Robocopy utility in backup mode

Beyond stealing Telegram session data, Sync can carry out full-scale collection of user information from the messaging app. When the fetch_telegram option is on, it launches a separate thread that authenticates to the chat app using the previously obtained tdata. Once authentication succeeds, Sync gains access to the account data and sends the following collected information to the server:

  • User details, such as username, phone number, first and last name
  • Information about private chats, groups, or channels, such as chat name and ID, the member list, and so on
  • Dialogs from private chats, groups, and channels (if the download_channels option is on)
  • Media files under 250MB: photos, documents, stickers, and contacts
Still Audio

Still Audio is an audio surveillance implant written in Rust. Its main job is to analyze the incoming audio stream and start recording voice when certain conditions are met – we’ll cover those in the next section. Architecturally, Still Audio largely mirrors Sync and uses the same mechanisms for communicating with the C2 server.

On launch, Still Audio performs a sequence of actions:

  • It extracts libmp3lame.dll, a file stored inside the executable. This is a library used to encode audio data.
  • If the --console command-line argument is absent, the implant creates a service named auxhost, connects to it, and continues running in the background.
  • While running in the background, it creates a file, logfile.log, to write logs to.

Next, Still Audio retrieves the C2 server address. As with Sync, it stores the URL in an environment variable – in this case, STILL_AUDIO_SYNC_ADDR. If that variable isn’t set, it falls back to STILL_SYNC_ADDR, which shows the two modules are compatible with each other. If neither variable is set, it uses the default URL, https://srwinservice[.]com.

Still Audio also uses the Dead Drop Resolver technique as a fallback mechanism for obtaining the C2 address. If the current server stays unreachable for three days, the tool tries to pull the current C2 URL from a GitHub repository. In the sample under analysis, we found the following URL for the page containing C2 information: hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json

Encrypted C2 address inside the GitHub repository

The repository, a fork of a popular project, contains the server URL Base64-encoded and encrypted with the Blowfish algorithm in ECB mode, using the key 5c8e153228edd3c6cbf75684 (lowercase string). Older AquilaRAT samples use this exact same algorithm and key.

Once it obtains the current C2 address, the Audio module starts a registration process similar to Sync’s, but through a different endpoint:

/still.rpc.Audio/RegisterAudioMachine. Also, unlike Sync, Audio sends a list of available audio input devices along with the system information.

The server responds with settings for the implant:

  • machine_id: a unique identifier for the current device.
  • vad_threshold: the threshold value for the VAD (Voice Activity Detection) algorithm. Expressed as a decimal fraction, it represents a proportion of the maximum sound level the input device can pick up. Sound above this threshold counts as voice activity. The default vad_threshold is 02.
  • max_silence_duration: the number of audio samples with a VAD value below the set threshold after which the implant considers the recording finished.
  • max_buffer_size: the maximum buffer size for recorded audio data.
  • active_device: the name of the input device selected for recording, from the list of available devices.
The eavesdropping process

Still Audio works with raw audio samples it captures directly from the input device. To detect voice activity, it implements an algorithm based on Root Mean Square (RMS), a lightweight signal-processing method that distinguishes speech from silence by measuring the audio signal’s average power over time. The implant doesn’t rely on any third-party libraries here; it implements all the calculations itself.

The implant compares the calculated RMS value against the vad_threshold parameter. If RMS meets or exceeds this threshold, recording starts. To avoid losing the beginning of the recording, Still Audio uses a pre-buffer, a size-limited buffer that stores samples from just before the current recording moment. A sequence of max_silence_duration samples (320 by default) with RMS values below the threshold signals the end of the recording. For example, with a standard headset running at a 44.1kHz sampling rate, recording stops after roughly 7ms of silence.

Interestingly, the Audio module makes no attempt to hide its use of the microphone: its name shows up in Windows settings. In the sample we examined, the file was saved to disk as IntAudio.exe, and it appeared in the list of apps using the microphone as “Intel Audio”:

The malicious module in the list of apps using the microphone

Before sending recordings to the server, the implant uses the libmp3lame library to encode the raw audio samples. It sends the recording files via a POST request to /tgfrg, adding a Client-Id header containing the machine_id obtained during registration to identify the device.

Infrastructure

This campaign draws on a broad set of hosting providers and domains registered at different points in time, which suggests the attackers are trying to make their infrastructure harder to detect. We found no direct overlap in domains or IP addresses with the February campaign. Even so, the two infrastructures share some similarities:

  • They use the same hosting providers, with the ASNs 149440, 202448, and 215311.
  • Their domain names follow similar naming patterns that mimic Windows system services and update mechanisms.
Domain IP address Registration date ASN orderapiserver[.]info 187.127.153[.]38 April 18, 2026 47583 tg4service[.]com 159.198.37[.]74 October 4, 2025 22612 srwinservice[.]com 213.252.244[.]123 March 19, 2026 61272 screenserv[.]com 23.26.237[.]250 February 13, 2026 149440 windowserv[.]net 23.27.24[.]30 February 10, 2026 149440 managementapiservice[.]com 188.212.124[.]178 May 1, 2026 202448 service8date[.]com 145.223.69[.]143 January 13, 2026 215311 updateservs[.]com 145.223.68[.]66 December 23, 2025 215311 Victims

In this campaign, we’ve determined that the attackers’ primary targets are users in Russia. Most victims are private individuals, though the corporate sector, government organizations, IT companies, and educational institutions are also affected.

Attribution

This campaign has been using both new tools and malware families documented in BI.ZONE’s February report. While some components turned up for the first time, they show significant code-level overlap with malicious tools seen in earlier Armored Likho campaigns. Based on these overlaps, along with additional technical artifacts, we’re highly confident the Armored Likho group is behind the campaign. The overlaps we identified include:

  • Identical dropper architecture in the February and current campaigns, which includes the use of the Tauri library to build the graphical interface, a similar user-input handler, a payload with the ICRYPTMP header, and the same multi-part encryption format.
  • The same encryption algorithm and key used in AquilaRAT from the previous campaign and in the Still Audio module from the current campaign, both implementing the Dead Drop Resolver technique.
  • Identical logic for generating the sysmarker value in older AquilaRAT samples and in the Still toolkit from the current campaign. The algorithms match down to the PowerShell commands used to collect system information.
  • Substantial infrastructure overlap, which includes the hosting providers and domain-naming patterns described in the Infrastructure section.
Takeaways

The campaign described in this post shows Armored Likho’s toolkit evolving, with the group steadily expanding its cyber-espionage capabilities. Beyond the components we already knew about, the attackers rolled out new modules that let them not only access Telegram data but also conduct audio surveillance on victims. Together, these capabilities significantly widen the range of information attackers can collect in a single compromise.

One point deserves particular attention: the new tools form a cohesive set, sharing similar architecture, C2 communication mechanisms, and common implementation elements. This points to the group building out its own tool ecosystem, designed for long-term use and further expansion.

The emergence of new, specialized modules shows the attackers aren’t just trying to preserve their existing capabilities – they’re working to make intelligence-gathering more effective by controlling multiple communication channels at once.

Indicators of compromise

Additional information about this threat, indicators of compromise included, is available to customers of Kaspersky Threat Intelligence Reporting. Contact [email protected] for more details.

File hashes
Droppers
C1D1EE16B92E6A138FFA048855F75D7D
17674B250D8B422A50A86C9FF207186D
62801F6223E860A7CCA271522E303B2D

Still Sync
68F0365D2FA8C828D012D8859E52A773
4BD7C352AE277B0E38D07BEEDD4DD507
D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD

Still Audio
2CA8ADBAB98EBE305EACF272CF48F5A0
3AC41B097236A7723821848AE31EF141
439255736797BC88BD19F282449E0436

Domains
orderapiserver[.]info
tg4service[.]com
srwinservice[.]com
screenserv[.]com
windowserv[.]net
managementapiservice[.]com
service8date[.]com
updateservs[.]com

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker News - 11 hodin 9 min zpět
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah