Agregátor RSS

Apple’s price hikes are a warning to IT

Computerworld.com [Hacking News] - 11 Srpen, 2026 - 17:59

IT purchasing is being hit by a double-whammy: Enterprises want to ensure their hardware is good enough to support AI, even as memory shortages caused by AI deployments are driving steep price increases for Macs, iPhones, iPads, tablets, Android devices and Windows PCs. 

The root cause is widely known. JP Morgan estimates DRAM prices have risen more than 400% since the beginning of 2024 as data center construction and hyperscaler demand consumed a gargantuan chunk of global memory production capacity.

More pain is coming

“It is not a secret that the industry will stay in shortage for multiple years,” warned analyst Jay Kwon. IDC analysis expects DRAM manufacturing capacity to fall short of demand, while SK Hynix believes demand will exceed supply well into the next decade. AI data centers are absorbing around 70% of output. 

This tough provisioning juggling act plays out as economic insecurity continues and the supply of key materials beyond memory also remains constrained. It makes for a perfect storm of shrinking purchasing budgets, rapid price increases, and competitive pressure to accelerate ongoing patterns of digital transformation.

To some extent, business leasing schemes will probably become more popular, while IaaS and SaaS vendors will widen their offerings to also include the kind of AI services businesses need. But the scale of the problem is pretty clear:

These price increases are not isolated; they reflect the global memory price challenge. Gartner expects memory prices will increase roughly 130% by the end of the year, while TrendForce’s recent survey sees further DRAM price increases ahead.

No one will be spared

This is a global challenge affecting businesses and consumers everywhere in real time. What’s important about these price hikes is their unpredictability; in most cases, business leaders will not have known the increases were coming, which means existing, pre-determined purchasing budgets do not reflect this new reality.

“The IT landscape faces a seismic shift, and its epicenter is memory,” according to Insight. “The market dynamics have fundamentally changed.” In other words, this challenge is long-term, structural, and here to stay.

As a result, every device that contains memory or a processor will get more expensive; this is already particularly visible in networking equipment, the cost of which climbed up to seven-fold in some cases this year. Games consoles, smart TVs and streaming boxes — including Apple TV — have not been spared.

IT purchasers are looking at these trends and wondering what to do. When it comes to PCs, price unpredictability means that lower cost isn’t necessarily an advantage. It makes more sense to spend a little more today to end up with a system that can continue working for your business for five years or more. Purchasers want longer hardware life cycles and are more willing than they once were to look at refurbished devices, which is driving growth in reconditioned markets.

(Apple sees this, which is why it recently raised trade-in prices for its kit as it seeks to recondition and resell its own products where possible.)

Reliability, resale value, and recycling and energy costs need to be considered, concerns that are in part driving businesses toward Macs. Regular readers will recognize the numbers often add up. Forrester’s Total Economic Impact research says lower support costs mean Macs save hundreds of dollars per seat in comparison to PCs over just three years, while Cisco has reported significant cost savings

So, what should IT purchasers do?

Waiting for prices to stabilize isn’t a strategy. All the analyses show there will be no change for some time. Seeking some resilience, purchasers are seeking multi-year leasing agreements and bulk purchase deals even while vendors become more resistant to them.

Three-year replacement cycles are being extended, prompting purchasers to make better buying decisions in the first place, and canny buyers should already be auditing what roles need what kind of machine. Does every computer need to be AI-ready? Probably not, so it’s important not to over-spec the whole fleet. 

Many purchasers will likely be investing more in Macs as they seek to diversify vendor exposure, while total cost of ownership over time is becoming a far more significant concern than before. It really matters that Macs are cheaper to run over time than PCs, particularly when costs have become so unpredictable. The same logic applies to tablets and smartphones, too.

None of these steps take the problem away. But sensible decision making now could help manage what is likely to be a highly uncertain period in IT purchasing, reiterating the need for resilience, so anticipated price shocks don’t blow your budgets apart.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

Wesco confirms security incident after ExfilSquad claims data theft

Bleeping Computer - 11 Srpen, 2026 - 17:59
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]
Kategorie: Hacking & Security

Two wars and a World Cup lead to epic DDoS attacks on publishers

The Register - Anti-Virus - 11 Srpen, 2026 - 17:33
Ongoing wars in Ukraine and Iran and the FIFA World Cup all contributed to a DDoS walloping of media organizations throughout 2026 so far, according to Cloudflare’s latest data, which identified the sector as the most targeted this year. Attacks on media, production, and publishing accounted for 14.2 percent of all DDoS attacks launched since January 1. Over the first six months of the year, the sector saw nearly four times the number of attacks leveled at the second most-targeted sector, gambling and casinos, and six times more in Q2 alone. “DDoS attacks on media organisations can be highly effective at achieving their core goals, which differ fundamentally from attacks on other sectors," Blake Darché, Head of Cloudforce One and Threat Intelligence at Cloudflare, told The Register. "For publishers, availability is the deliverable. While a DDoS attack on an e-commerce site could aim to steal transaction revenue, an attack on a publisher is typically aimed at censorship, information suppression or timing disruption. “DDoS attacks are uniquely effective against publishers because news expires quickly - taking an outlet offline for just two hours during an election night, a military conflict, or a breaking news story successfully silences it at peak readership. The attack succeeds even if systems recover shortly after.” Cloudflare's data aligns with third-party reporting shortly after the US started a war with Iran in February. Akamai reported a 245 percent uplift in cybercrime in the immediate weeks following the war breaking out, with DDoS attacks up 38 percent. Similarly, Justin Moore, senior manager at Palo Alto Networks' Unit 42, previously told The Register that by the start of March, the company’s telemetry showed a clear increase in pro-Russia hacktivism too. Hacktivists rely heavily on DDoS attacks to carry out their objectives. Often assembled on social media platforms, hacktivist groups decide on which organizations they will attempt to down and launch coordinated attacks against them. Signals intelligence agencies say these efforts are almost always low-level and low-impact, but equally advise that businesses should not underestimate these groups. The advice applies largely to operators of critical infrastructure, which if attacked successfully and for a sustained period, could lead to vital service disruption. The US’ war in Iran also led to a major uptick in attacks targeting government entities. From the 29th most-targeted sector in Q1, it jumped to number nine in Q2. The US and China comprised the two most-targeted regions, although Turkey shot up to third after it hosted the Ankara NATO summit in July. 1 Tbps network-layer attacks explode Cloudflare said it mitigated 805 network-layer attacks exceeding 1 Tbps in Q2 alone, representing a 519 percent increase compared to Q1. To quickly debunk some jargon for the uninitiated, network-layer attacks are confined to layer 3 of the Open Systems Interconnection (OSI) model, meaning that they target core routing, transport, and infrastructure protocols to overwhelm networking equipment. Not all 1 Tbps+ attacks target the network layer. These high-packet onslaughts are referred to as hyper-volumetric DDoS attacks and involve transmitting a huge amount of data to a network – enough to take down even the most robust internet infrastructure. Despite the growth in these hyper-volumetric attacks, these comprise only the smallest fraction of DDoS attacks overall (0.004 percent). The vast majority – 96.62 percent – transmit less than 500 Mbps and 90.6 percent end in under ten minutes. That isn’t to say that these attacks are inconsequential, either. Cloudflare said that even attacks of this size would be enough to knock most networks offline. Putting it into perspective, the company said a 100 Mbps attack would be sufficient to knock a website or server offline, while a 1 Gbps attack could disrupt an entire datacenter if it wasn’t protected from DDoS attacks. 1 Tbps hyper-volumetric attacks are among the fastest ever observed. The first of this kind on record targeted Dyn DNS in 2016, in turn downing major websites such as Twitter, Netflix, Reddit, Spotify, and GitHub, and they have become increasingly common since then, despite their markedly low proportion compared to other DDoS attacks. A law enforcement operation in March disrupted the infrastructure relied upon by four of the most significant botnets operating at the time, including Aisuru, which by the end of 2025 had recruited up to 4 million devices and was rattling out multiple 1 Tbps attacks daily. Hyper-volumetric attacks are often short-lived, measured in seconds rather than greater units, although Cloudflare said even this is enough to cause significant damage. “Whether an attack lasts half a minute or ten minutes, there is no practical window for human intervention: By the time an alert reaches a security analyst, the attack has already completed,” said Cloudflare in its report. “Manual mitigation and on-demand solutions are simply too slow for this reality. Yet while the attack itself may be brief, its aftershocks are not. The cascading effects of even a short burst can trigger routing instability, TCP retransmissions, application timeouts, and downstream service degradation that takes hours or days to fully resolve – all while services remain down or impaired.” ®
Kategorie: Viry a Červi

Levnější předplatné YouTube Premium Lite míří do Česka. Zbaví vás reklam, ale jen někde

Živě.cz - 11 Srpen, 2026 - 16:45
YouTube Premium Lite zamíří všude, kde je normální Premium. • U nás by levnější tarif mohl stát něco přes sto korun za měsíc. • Lite odstraňuje reklamy u všech nehudebních videí, ale má i určitá omezení.
Kategorie: IT News

Million-Person Study Finds a Rare Gene Variant That Slashes the Risk of Diabetes and Heart Disease

Singularity HUB - 11 Srpen, 2026 - 16:00

The discovery could lead to treatments and demonstrates the power of efforts to unearth rare, beneficial genes in large populations.

“Burn fat, build muscle.” It’s a familiar workout slogan, but the benefits go far beyond aesthetics. Having less belly fat and more muscle guards against heart attacks, Type 2 diabetes, and a host of other metabolic diseases.

Some people may have a genetic edge.

A massive study of over one million people across three continents discovered a rare mutation in a gene called FNIP1 is linked to a healthier metabolic profile. The gene helps cells sense nutrients and generate energy. All of us have FNIP1, but about one in 7,000 people inherit a protective version. On average, they had a 60 percent lower risk of heart disease and metabolic disorders.

Silencing FNIP1 in human liver cells switched on a genetic program that breaks down fats. In mice fed a tasty but high-fat diet, disabling the gene curbed weight gain, prevented fatty liver disease, improved insulin sensitivity, and kept their blood sugar levels steady.

The findings are great news for everyone else. Rather than relying on a naturally occurring mutation, future gene editing therapies could potentially recreate its protective effects in people against a host of cardiometabolic diseases, a leading cause of death worldwide.

Everyone has a unique metabolic profile shaped by both genes and environment. By analyzing diverse populations, the study fished out a protective variant that spans ancestries and lifestyles. The broad reach suggests targeting FNIP1 could benefit people around the world.

The study illustrates the power of efforts to find rare, beneficial genes across large populations, wrote the authors at Regeneron Pharmaceuticals, a New York biotechnology company.

Mutant Protector

Small changes in DNA can have large consequences. Some genetic variants raise the risk for health issues. The APOE4 variant, for example, increases the chances of developing Alzheimer’s disease. Others, however, are a gold mine for new treatments.

A notable example is CCR5. People who inherit a rare mutation in both copies of thegene are naturally resistant to HIV. The mutation prevents the virus from tunneling into immune cells and replicating. The discovery has led to multiple success stories in which bone marrow transplants from donors carrying the mutation kept HIV at bay, without the need for lifelong antiviral drugs.

Protective mutations could also lower the risk of heart disease. Rare variants of PCSK9, a gene involved in cholesterol metabolism, disable the gene and slash dangerously high levels of LDL, or “bad” cholesterol that clogs arteries. The discovery has already spurred a handful of therapies that block the gene or its protein with early successes.

“Identifying genetic variants associated with protection from disease is a powerful strategy,” wrote the authors. “However, protective genetic variants are often extremely rare, so finding them requires sequencing the genomes of large populations.”

Go Big

To better understand cardiometabolic diseases, the team sequenced the genomes of over a million people from 11 studies across the Americas, Europe, and Asia, including people with African ancestry. They also linked genetic data with participants’ health records.

The researchers searched for gene variants that influence a blood biomarker for cardiometabolic disease. Called TG:HDL, the biomarker is the ratio between two types of fats. The first, triglycerides, is packaged into tiny “bubbles” that circulate the bloodstream. High levels are linked to heart attacks, strokes, and other metabolic problems. In contrast, high-density lipoprotein, often called “good” cholesterol, ferries excess fat away from tissues and blood vessel walls to the liver, where it can be cleared.

Across the populations in the study, a lower TG:HDL ratio—that is less TG, more HDL, or both—tracked with better metabolic health. People with lower ratios had reduced insulin levels, lower blood pressure, and less fat buildup in the liver and muscles. The biomarker also predicted diabetes risk, heart problems, and liver scarring, making it a powerful snapshot of overall metabolic health.

The team then scanned the genome for rare gene variants linked to TG:HDL. Roughly 60 genes popped up, all involved in energy storage and active in the liver and fat tissues.

But one gene stood out: FNIP1. Rare variants essentially disable the gene by disrupting its protein-making instructions. People with one copy of these variants had lower liver fat and blood sugar and roughly 60 percent lower risk of cardiometabolic disease.

The finding “was remarkable and thought-provoking, and immediately motivated us to dig deeper into the biology of this discovery,” wrote the team. But a key question remained: Were the variants actually protecting people, or were they simply correlated with better health?

To find out, the team silenced the gene in human liver cells using a method called siRNA. Rather than snipping the gene, siRNA blocks cells from producing targeted proteins. Without functional FNIP1, liver cells ramped up genes involved in breaking down fats.

The researchers then turned to mice. Using CRISPR-Cas9, they got rid of FNIP1 and related signaling pathways specifically in mice fed a high-fat, high-sugar diet. The intervention rapidly activated mitochondria—the cell’s energy factories—and lysosomes, the acid-filled recycling centers that break down waste. Despite gorging on the unhealthy diet, mice lacking functional FNIP1 had less body and liver fat, more muscle mass, and better sensitivity to insulin.

That’s not to say FNIP1 is a “villain” gene. Normally, it acts as a metabolic brake, helping the body conserve precious energy when food is scarce. But many of us now face the opposite problem, an abundance of calories and not enough physical activity. Releasing that brake, through medication or gene editing, could rev up the body’s natural fat-burning machinery.

Turning the finding into a therapy won’t be simple. The protective effects were found in people who carried the mutation from birth. A short-term drug or gene therapy delivered later in life might not reproduce the same effects.

Safety is another major concern. Paradoxically, people who have mutations in both copies of FNIP1 develop heart disease and immune deficiency. And mice without functional FNIP1 throughout the body are more prone to liver damage and cancer. Targeting treatments specifically to the liver—for example, using lipid nanoparticles—could limit side effects, but any potential therapy will need to be thoroughly tested for safety.

The team is searching for drug candidates that inhibit FNIP1. But for now, they’ve shown the power of large-scale genetic screens across diverse populations to find rare protective variants—and potential paths towards treating diseases that affect millions of people.

“Identifying FNIP1, a previously poorly characterized gene involved in lipid metabolism, is highly novel and promising for future drug development for metabolic health,” Satoshi Koyama at the Broad Institute, who was not involved in the study, said in a research briefing. “I sincerely hope that this discovery will one day benefit patients with metabolic disorders.”

The post Million-Person Study Finds a Rare Gene Variant That Slashes the Risk of Diabetes and Heart Disease appeared first on SingularityHub.

Kategorie: Transhumanismus

Jak nastupovat do letadla rychle a bez tlačenic. Řešení existuje 18 let, aerolinky ho nepoužívají

Živě.cz - 11 Srpen, 2026 - 15:45
Fyzik spočítal matematicky nejrychlejší způsob nastupování cestujících do letadla. • Tato metoda usazuje pasažéry postupně od oken po uličky ob jednu řadu. • Letecké společnosti tento postup nepoužívají kvůli lidské neukázněnosti a ziskům.
Kategorie: IT News

Public SCTPhantom Exploit Tests Linux Container Security Defaults

LinuxSecurity.com - 11 Srpen, 2026 - 15:30
Public exploit code is now available for SCTPhantom, a Linux kernel flaw that researchers used to escape an unprivileged container and take control of the underlying host. 
Kategorie: Hacking & Security

Mozilla updates GPG signing key for Firefox releases after exposure

Bleeping Computer - 11 Srpen, 2026 - 15:20
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]
Kategorie: Hacking & Security

Vague Task, Total Access: When AI Delegation Becomes a Security Risk

Bleeping Computer - 11 Srpen, 2026 - 15:15
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. [...]
Kategorie: Hacking & Security

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

The Hacker News - 11 Srpen, 2026 - 15:11
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-riskRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

DDoS attacks over 1 Tbps surged fivefold in the second quarter

Bleeping Computer - 11 Srpen, 2026 - 15:00
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]
Kategorie: Hacking & Security

Drony britského námořnictva tajně posílaly data do Číny

AbcLinuxu [zprávičky] - 11 Srpen, 2026 - 14:46
Námořní drony používané elitními jednotkami britského královského námořnictva tajně posílaly údaje do Číny. Stroje vybavené čínskými komponenty měly být využívány pro vojenské operace na Blízkém východě. Kamery na dálkově řízených průzkumných člunech K3 Scout byly vybavené součástkami, které bez vědomí britského námořnictva odesílaly informace do spojeného zařízení v Číně. Britské námořní síly využívaly flotilu námořních dronů za 12 milionů liber (336 milionů korun). Po zjištění informací o propojení s Čínou nechalo ministerstvo obrany z kamer využívaných čluny odstranit veškeré spojení s internetem.
Kategorie: GNU/Linux & BSD

Deepfake hiccup unmasks suspected digital certificate fraudster

The Register - Anti-Virus - 11 Srpen, 2026 - 14:27
Spain's national police say they caught a cybercriminal after a momentary technical glitch exposed his face to a video identification platform. The unnamed man allegedly made 38 attempts to impersonate 30 people and obtain digital certificates in their names, succeeding on multiple occasions. A digital certificate uses public key infrastructure to bind a cryptographic key to a verified identity, allowing its holder to authenticate themselves and create legally recognized electronic signatures. In Spain and other EU countries, certificates can be used to sign contracts, authorize transactions and deal with public bodies online, avoiding some of the in-person appointments traditionally required for administrative procedures. A certificate issued in someone else's name would therefore give a scammer a powerful tool for impersonation. Police allege that the suspect planned to use the fraudulently obtained credentials in further cybercrimes. The alleged fraudster targeted a security company authorized to issue digital certificates and bypassed its identity checks using forged documents, altered photographs, deepfake tools, and a carefully arranged lighting rig. The verification process required a live video check comparing the applicant's face with the photograph on the identity document. He allegedly used deepfake technology to alter his face in real time so that he could bypass the visual identity checks, and used custom lighting to recreate the appearance of each document's holograms. "The alleged perpetrator used household spotlights with strategically placed colored bulbs to simulate the flashes and security features found on physical identity documents under real light," police said (machine translated). "He then balanced the counterfeit documents in front of the webcam, perfectly recreating the official holograms. He also used VPNs to anonymize his connections and employed manipulated documents with apparent security features." Police did not say how many of the 38 attempts succeeded, only that certificates were issued on "multiple" occasions. His luck allegedly ran out when the face-changing software suffered a momentary processing delay. The disguise dropped for "barely a second," exposing his real face to the verification camera, police said. Investigators eventually identified and located the suspect, who was arrested on suspicion of repeatedly forging official documents. A search of his home yielded a laptop protected by high-grade encryption, several mobile phones, storage devices, and documents, according to police. The investigation was complicated by the use of more than 320 phone lines across 24 devices. Most had allegedly been registered under stolen identities, with police tracing their sale to outlets in the Murcia region. ®
Kategorie: Viry a Červi

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

Bleeping Computer - 11 Srpen, 2026 - 14:12
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]
Kategorie: Hacking & Security

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

The Hacker News - 11 Srpen, 2026 - 14:05
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

The Hacker News - 11 Srpen, 2026 - 14:04
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with. That decision carries a cost for Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Kaspersky Securelist - 11 Srpen, 2026 - 14:00

Overview of the attack

In July 2026, Kaspersky experts detected a new attack by the Head Mare group. Previously, we classified them as hacktivists, but now we define them as an APT group due to the sophistication of their TTPs and the absence of destructive activity (encryption, wiping) in the targeted infrastructures. In this latest campaign, the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server and replaced the original TrueConf client installers with infected versions that installed the PhantomCore malware on the system.

An investigation of the compromised server revealed that the attackers used a combination of two new vulnerabilities (assigned the internal identifiers KLCERT-26-057 and KLCERT-26-058), allowing them to execute arbitrary code with the highest privileges.

The attack occurs in several stages:

  1. The attackers connect to the TrueConf server without prior authorization via port 4307/TCP, which, according to the product documentation, is open by default. The attack targets TrueConf servers running versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5.
  2. Once connected, attackers call a server function to transmit a malicious script and execute it on the server. The vulnerability that allows this stage of the attack to be carried out has been assigned the internal identifier KLCERT-26-057.
  3. The received script runs on the TrueConf server in an isolated environment. By default, operating system functions are not accessible in this environment, which should limit the capabilities of the executed code.
  4. To escape the isolated environment, attackers exploit a second vulnerability, assigned the internal identifier KLCERT-26-058. Exploiting this vulnerability allows them to bypass the restrictions of the isolated environment and proceed to execute commands in the context of the operating system.
  5. Once the environment’s restrictions are bypassed, attackers gain the ability to execute arbitrary code on the server with the privileges of the NT AUTHORITY\SYSTEM account.
  6. Once they have gained elevated privileges, attackers replace the file …\public\js\locale.php with a web shell, which can be used for subsequent remote control of the compromised server.

This web shell was used for the following activities:

  • collecting data on the IT infrastructure;
  • gaining privileged access to the TrueConf database;
  • replacing the original TrueConf Client distribution with an infected version containing the PhantomCore backdoor.

The vulnerabilities exploited by the attackers were patched by the vendor in the latest TrueConf Server updates (versions 5.3.9, 5.4.9, and 5.5.5). These updates were released on June 18, 2026.

The PhantomCore backdoor was successfully detected by Kaspersky solutions.

To automatically launch the malware after the system boots, a registry key is created: HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32, with the value set to the path to the malicious program’s file.

Using a web shell, in addition to PhantomCore, the attackers load a backdoor that we have named PhantomGraph, consisting of two modules:

  • SysExcSvc.dll is responsible for receiving commands from the attackers and transmitting the results of their execution. The attackers used an account on Microsoft OneDrive cloud storage as their command-and-control (C2) server.
  • SysReadSvc.dll reads the command transmitted by the first module, executes it, and saves the execution result.

To establish persistence on the system, the attackers execute a Base64-encoded PowerShell command that installs SysExcSvc.dll and SysReadSvc.dll as Windows services. We believe the attackers deliberately split this malicious command into two components to make it harder to detect using EDR tools. Additionally, the program’s code partially matches that of PhantomCore, indicating that it belongs to Head Mare’s arsenal.

We also managed to identify the commands executed by the attackers when connecting to the backdoor. The SysReadSvc module executes commands using a BATCH file. Example of execution:

$system32\cmd.exe /c cmd /c ""$temp\cmd_cmd_4488.bat"" 2>&1

Commands detected:

  • Memory dump of the lsass.exe process:

  • Reconnaissance of the user and system names:

hostname whoami "$system32\WindowsPowerShell\v1.0\powershell.exe" -noexit -command Set-Location -literalPath '$system32\inetsrv'

  • Launching an SSH reverse tunnel:

In addition, we discovered several commands that did not work due to the attackers’ typos and encoding issues.

We are observing several active Head Mare campaigns targeting Russian organizations across various industries: instrument manufacturing, electronics, transportation, energy,
IT, and software development. The attackers distribute their backdoors using various methods, including phishing, exploiting public web servers, or through a subcontractor.

We recommend that all organizations using TrueConf software install the latest server version (versions 5.3.9, 5.4.9, and 5.5.5) in accordance with the vendor’s recommendations.

We also recommend verifying that the client distributions downloaded from the TrueConf server used by your organization have a valid TrueConf digital signature and have not been tampered with. The malicious distributions we detected did not have a valid digital signature. You can also verify authenticity on the vendor’s website.

Important: Even if your organization does not use a TrueConf server, your employees may connect to compromised TrueConf servers belonging to business partners to participate in online meetings and download infected installation packages.

The attack mechanism and the vulnerabilities exploited are described in more detail on the Kaspersky ICS CERT website.

Detection by Kaspersky solutions

Kaspersky security solutions successfully detect malicious activity associated with the attacks described above.

The malware used in this attack is detected by our solutions with the following detection names:

  • Backdoor.PHP.WebShell.abi,
  • Backdoor.Win64.PhantomCore.dt,
  • Trojan.Win64.Agent.smgvnc,
  • Trojan.Win64.Agent.smgvnb,
  • HEUR:Backdoor.Win64.PhantomCore.gen,
  • HEUR:Backdoor.Linux.Agent.fb,
  • HEUR:Backdoor.Linux.PhantomHook.a,
  • HEUR:Backdoor.Linux.PhantomReact.a,
  • Trojan.Win64.PhantomGraph.gen
  • UDS:Backdoor.Win64.PhantomCore.a

Let’s take a closer look using Kaspersky Endpoint Detection and Response Expert (KEDR Expert) as an example.

Specifically, activity involving the replacement of the legitimate file …\public\js\locale.php with a web shell, as well as the deletion of entries from TrueConf event logs, is detected by the rule unusual_php_file_creation_from_trueconf_process.

Downloading a file containing the PhantomCore backdoor via the replaced legitimate file …\public\js\locale.php is detected by KEDR Expert with the rule unusual_file_creation_from_trueconf.

Activity related to the installation of an infected TrueConf client installer containing the PhantomCore backdoor is detected by KEDR Expert using the unsigned_trueconf_installer rule.

The Kaspersky Managed Detection and Response service detects the described attack by monitoring the following actions:

  1. Creation of suspicious files by TrueConf Server processes.
  2. Execution of a TrueConf Client installer file that lacks a software developer’s signature.
  3. Suspicious process chains associated with TrueConf Client executables and TrueConf Client update executables.
  4. Registration of suspicious libraries in the HKEY_CURRENT_USER\Software\Classes\CLSID\ registry key.
  5. Actions related to retrieving information about the lsass.exe process.
  6. Memory dump creation for the lsass.exe process using the comsvcs.dll library.
  7. Accessing the memory of the lsass.exe process.
  8. Creating tunnels using the ssh process.

To protect companies using our Kaspersky SIEM system, a general set of rules is available in the product repository that allows detection of the following techniques:

  1. Creation of suspicious files in the C:\Windows\System32\inetsrv\* directory:
    R405_07_File write to IIS native modules folder or OWA via WriteData.
  2. Creating a memory dump of the lsass.exe process using the comsvcs.dll library:
    R233_04_Process memory dump via comsvcs.dll.
  3. Accessing the memory of the lsass.exe process:
    R262_Suspicious access to the LSASS process.

We also recommend paying attention to the following events when developing your own detection rules or conducting threat hunting:

  1. Registration of suspicious libraries in the registry key \Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32:
    (DeviceEventClassID = '4657' OR DeviceEventClassID = '13') AND FileName like '%\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}%' AND DeviceCustomString6 = 'InprocServer32'
  2. Creating the SysExcSvc and SysReadSvc services to run executables from temporary directories in the background via cmd:
    DeviceEventClassID = '4697' AND (DestinationServiceName = 'SysExcSvc' OR DestinationServiceName = 'SysReadSvc') AND match (FileName, '.*cmd\s+\/c.*temp\\cmd_cmd_.*\.bat.*')
  3. Creation of suspicious processes originating from the TrueConf update process (trueconf_windows_update.exe)
    (DeviceEventClassID = '4688' OR DeviceEventClassID = '1') AND SourceProcessName LIKE '%\trueconf_windows_update.exe'

For the detection rules to work correctly, ensure that events from Windows systems are received in full, including Security events 4688, 4663, 4657, and 4697 and Sysmon events 1, 7, 11, and 13.

Indicators of compromise File hashes (MD5)

Web shell
4d27b4eb1c5dbb3d8160f29b8119523e locale.php

Infected installer
748c9f8cb1065000616204935f96207f trueconf_windows_update.exe

PhantomCore DLL
c5a460e4e68a088f6e51b2c6474642ec
129462164a7d52e9ea8560b60f0412c5 doc.txt
ec0bf4a2186a88874e9f26f07cfeb532 usocacheddata.txt
b348642146ea34771e5785c5857950f5
c915cb6c2aeb863ee8479238e1644217 doc.txt
0e79996d9483d1e44fea32b0a48c2c19 doc.txt
2bb75c20e778eb5c416965bd4d4259b1 trueconf_windows_client_x64_[redacted].exe
b3a6fee3307f1c26841fd5c603e2b013 usocacheddata.txt
8fcc3e4ccbf1725d9989fb464abf3561 usocacheddata.txt

PhantomGraph
489f43be558b2679284ceabed7adc4f3 sysexcsvc.dll
dd1fd2b459b97b7d59375cb8383cd19a sysreadsvc.dll
0e4541c3153ec5ed01497f19cf4f63d0 sysexcsvc.dll
12d4e8f5295f2ef7e0f9bfc0f4830939 sysexcsvc.dll
7f267006cac10f341c356b62fe493527 sysexcsvc.dll
ee2861d5965e8730708cd1da8a93fa4c sysexcsvc.dll

Backdoor (ELF)
c3a2abe8756910f42582b04a44ea3514
43f435c3c437bc879a2d7d4634f43494

Rootkit
aee9642b45b099cb7f3053b9b680b425

IP

81.177.32[.]12
194.87.239[.]71 ssh
194.87.93[.]153 ssh
38.244.205[.]244
31.59.102[.]61

Domains

penzadogshelter[.]site
trendy-market[.]site
bright-deals[.]site
nova-stream[.]site
rinomobile[.]ink
urbanpixel[.]store
flexish[.]shop
media-hub[.]today
cosmetic-deals[.]store
vks.gossopka[.]forum

Windows service names

SysExcSvc
SysReadSvc

File paths

C:\Windows\System32\inetsrv\SysExcSvc.dll
C:\Windows\System32\inetsrv\SysReadSvc.dll
C:\Windows\System32\inetsrv\graphi-refresh.dat
C:\Windows\System32\inetsrv\share\input_*.txt
C:\Windows\System32\inetsrv\share\output_*.txt
%TEMP%\cmd_cmd_*.bat
%LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll
/etc/systemd/system/omicluster.service
/etc/systemd/system/schedul2-bin.service
/opt/acronis/bin/schedul2-bin
/omi/bin/omicluster
/usr/lib64/libzvbi-tchain.so.2
/var/tmp/cx2

Registry keys

HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32

Kaspersky detection names

Backdoor.PHP.WebShell.abi
Backdoor.Win64.PhantomCore.dt
Trojan.Win64.Agent.smgvnc
Trojan.Win64.Agent.smgvnb
HEUR:Backdoor.Win64.PhantomCore.gen
HEUR:Backdoor.Linux.Agent.fb
HEUR:Backdoor.Linux.PhantomHook.a
HEUR:Backdoor.Linux.PhantomReact.a
Trojan.Win64.PhantomGraph.gen
UDS:Backdoor.Win64.PhantomCore.a

YARA rules

import "pe" rule apt_HeadMare_PhantomCore { meta: description = "Rule to detect PhantomCore used by HeadMare" author = "Kaspersky ICS CERT" copyright = "Kaspersky ICS CERT" version = "1.0" last_modified = "2026-08-02" hash = "c5a460e4e68a088f6e51b2c6474642ec" strings: $a1 = "lying.dll" ascii $a2 = { 2D 7F 95 4C 2D F4 51 58 } $a3 = { 4F 81 67 F7 7E 7B 05 14 } condition: (uint16(0) == 0x5A4D) and (filesize > 4MB) and (filesize 20MB) and (all of them) and (pe.number_of_signatures == 0) }

rule apt_HeadMare_FakeConf_installer { meta: description = "Rule to detect any unsigned TrueConf installers" author = "Kaspersky" copyright = "Kaspersky" version = "1.0" last_modified = "2026-08-02" hash = "748c9f8cb1065000616204935f96207f" strings: $a1 = "TrueConf Setup" wide $a2 = "This installation was built with Inno Setup." wide condition: (uint16(0) == 0x5A4D) and (filesize > 20MB) and (all of them) and (pe.number_of_signatures == 0) }

rule apt_HeadMare_PhantomCore_exchange { meta: description = "Rule to detect PhantomCore exchange module used by HeadMare" author = "Kaspersky ICS CERT" copyright = "Kaspersky ICS CERT" version = "1.0" last_modified = "2026-08-02" hash = "489f43be558b2679284ceabed7adc4f3" strings: $a1 = "graphi_exchange.dll" ascii $a2 = "graphi-client/1.0" ascii $b1 = "https://graph.microsoft.com/v1.0/me/drive/root:/" ascii $b2 = ":/children?$select=name,id&$top=200" ascii $b3 = "offline_access Files.ReadWrite" ascii $b4 = "GRAPHI_INSECURE" ascii $b5 = "\"@microsoft.graph.conflictBehavior\":\"replace\"}" ascii $b6 = "https://login.microsoftonline.com/" ascii condition: (uint16(0) == 0x5A4D) and (any of ($a*)) and (3 of ($b*)) }

rule apt_HeadMare_PhantomCore_executor { meta: description = "Rule to detect PhantomCore executor module used by HeadMare" author = "Kaspersky ICS CERT" copyright = "Kaspersky ICS CERT" version = "1.0" last_modified = "2026-08-02" hash = "dd1fd2b459b97b7d59375cb8383cd19a" strings: $a1 = "graphi_reader.dll" ascii $a2 = "^input_(.+)\\.txt$" ascii $b1 = "output_" ascii $b2 = "cmd_cmd_" ascii $b3 = "cmd /c \"\"" ascii $b4 = "error: failed to start cmd process" ascii $b5 = "share" ascii $b6 = "SysReadSvc" ascii condition: (uint16(0) == 0x5A4D) and (filesize < 4MB) and (any of ($a*)) and (4 of ($b*)) }

rule apt_HeadMare_FakeLocale_webshell { meta: description = "Rule to detect the HeadMare TrueConf web shell" author = "Kaspersky" copyright = "Kaspersky" version = "1.0" last_modified = "2026-08-04" hash = "4d27b4eb1c5dbb3d8160f29b8119523e" strings: $a1 = "X-Redirect-Bit" ascii wide nocase $a2 = "tc_vcs_web_db_conn" ascii wide $a3 = "user=postgres" ascii wide $b1 = "UPL ok::" ascii wide $b2 = "DWN fail nexs" ascii wide $b3 = "DWN fail inv" ascii wide condition: (2 of ($a*)) or (2 of ($b*)) }

rule apt_HeadMare_TrueConf_Rootkit { meta: description = "Rule to detect the HeadMare rootkit installed on TrueConf servers" author = "Kaspersky" copyright = "Kaspersky" version = "1.0" last_modified = "2026-08-06" hash = "aee9642b45b099cb7f3053b9b680b425" strings: $a1 = "PQconnectdb" $a2 = "obfuscated_data" $a3 = "install_hook" condition: (uint32(0) == 0x464c457f) and (filesize < 400000) and (all of them) }

rule apt_HeadMare_Github_Backdoor { meta: description = "Rule to detect the HeadMare backdoor with Github C2" author = "Kaspersky" copyright = "Kaspersky" version = "1.0" last_modified = "2026-08-06" hash = "43f435c3c437bc879a2d7d4634f43494" hash = "c3a2abe8756910f42582b04a44ea3514" strings: $a1 = "cryptor5crypt" $a2 = "execraw_task" $a3 = "jitter_task" $a4 = "upload_task" $a5 = "exec_task" $a6 = "react_comment" condition: (uint32(0) == 0x464c457f) and (filesize > 5000000) and (filesize < 10000000) and (4 of them) }

HBO Max a 30 nejoblíbenějších filmů a seriálů v srpnu 2026. Tohle Češi na HBO nejvíc sledují

Živě.cz - 11 Srpen, 2026 - 13:45
Tyto filmy a seriály jsou teď na českém Max (dříve HBO Max) nejoblíbenější. Nerozlišujeme žánr, stáří ani hodnocení na filmových webech. Jde o souhrnnou oblíbenost za poslední týdny, kterou zjišťuje a počítá web FlixPatrol.
Kategorie: IT News
Syndikovat obsah