Agregátor RSS

Huntress CEO says threat hunter used 'poor judgment' in alerting ransomware crim about law enforcement probe

The Register - Anti-Virus - 30 Červen, 2026 - 18:54
Huntress CEO Kyle Hanslovan said he is aware of “questionable, long-term threat actor communications” between a threat hunter who is still employed with the security firm and a cybercriminal, and called this “poor judgment.” “In one particular exchange, our current teammate disclosed to a threat actor that law enforcement had reached out to them about the threat actor,” Hanslovan said in a blog post, addressing a former employee’s accusations that the current Huntress analyst is an insider threat to the company. “While this disclosure was not illegal, it reflected poor judgment,” he wrote. The incident came to light last week when former Huntress security operations analyst Ben Folland, who left the company in February, alleged that “another Huntress employee passed communications from US law enforcement to a cybercriminal, Devman, who is actively and publicly targeting my family and me.” Devman is a ransomware operator, believed to be located in Russia, who uses modified DragonForce code built on top of the leaked Conti source code. Folland alleged that this insider, still employed by Huntress, was “caught by the FBI,” and that their involvement with Devman “would cause significant reputational damage to Huntress and, in my view, continues to put clients at risk.” “If you are an employee at a cybersecurity company, you should not be helping cybercriminals,” Folland said. “You should not be informing them of active investigations. You should not be engaging in cybercriminal activity yourself.” At the time, Hanslovan said he “firmly disagree[d]” with Folland’s accusations – but declined to provide additional details about what happened between the employee and the criminal. In the Tuesday blog post, Hanslovan elaborated further and said that he believed that the communications did not constitute insider activity. “As a result of the investigation, my team implemented more robust policies for our researchers, coached teammates on engaging with threat actors, and took appropriate administrative actions,” he wrote. “While we haven't found evidence of illegal conduct, insider activity, or additional disclosures, we are continuing our investigation. Due to the privacy rights of our teammates, we will not comment further on the investigation.” Folland disagrees. In a Tuesday LinkedIn post responding to Hanslovan’s blog, he asserted that the communications between the Huntress analyst and Devman “meet the definition of an insider threat.” When the FBI reached out to the Huntress employee for intel on Devman, “She immediately forwarded the exact FBI communications to the threat actor, including screenshots containing FBI agent names,” Folland claimed in his post on LinkedIn. “She informed Devman that law enforcement was actively looking into him. She also refused to cooperate because they wanted Devman.” According to Folland, the FBI notified him of this incident with the current Huntress analyst. The Register reached out to the FBI for comment and did not receive a response. “This was not just ‘poor judgment,’” Folland wrote. “This was a Huntress employee taking sensitive knowledge about a law enforcement approach and passing it directly to the person being investigated. If someone inside a bank warns a fraudster that police are investigating them, nobody would describe that as merely ‘poor judgment.’ They would call it what it is – an insider.” Huntress declined to comment further. ®
Kategorie: Viry a Červi

Jak dobře vybrat operační paměť. Kapacita RAM, frekvence, časování a kanály jsou velká alchymie

Živě.cz - 30 Červen, 2026 - 18:45
Paměť RAM je základní komponentou počítače. • Mezi její parametry patří kapacita, frekvence, časování nebo podpora více kanálů. • Kvůli mnoha kombinacím je výběr složitější, než se na první pohled zdá.
Kategorie: IT News

First Foxconn, now Tata — Apple suppliers keep getting hacked

Computerworld.com [Hacking News] - 30 Červen, 2026 - 18:35

The recently reported cyberattack against Tata Electronics is shaping up to be one of the most consequential attacks exposing important trade secrets belonging to Apple and, conceivably, other clients, including a slew of details about the upcoming iPhone 18 Pro. The attack follows May’s assault against key Apple manufacturing partner Foxconn.

World Leaks iPhone 18 Pro

Hackers from the ransomware group World Leaks managed to penetrate systems belonging to Apple’s most important manufacturing partner in India to exfiltrate hundreds of documents, including drop test videos, schematics, design details — even specifics about Apple’s C2 modem design. 

Reuters confirmed last week’s Apple Insider scoop that the leaked documents also included the purported board layouts for the iPhone 18 Pro and 18 Pro Max, as well as data sheets for the rumored A20 Pro chip.

The data reveals some of this year’s colors, including a red, dark cherry, and gray, and indicate that the basic design remains the same, albeit with a slightly wider camera bump. They also suggest the upcoming high-end iPhone is a little thicker than current models and hint at a smaller Dynamic Island.

A brand new processor design

But the leaks also show something far more interesting: Apple is adopting a new processor design in the A20, a design that promises up to 20% additional performance and even more effective battery management. 

That’s thanks to Apple’s adoption of TSMC’s new Wafer-Level Multi-Chip Module (WMCM) packaging technology. What’s good about this tech is that it places the RAM alongside the SoC within the same package. 

The current design sees the RAM placed on top of the SoC, which is slightly less efficient and runs hotter. This informative image helps explain the difference between the two designs; essentially, the new architecture should reduce heat dissipation and speed up communication between the two components. 

That results in better performance and power efficiency and also means the vapor cooling system inside Apple’s upcoming pro iPhones can work more efficiently to reduce heat dissipation. While no one knows for sure, some estimates claim this new WMCM packaging should enable 15-20% performance boost, even before we consider the improved efficiency inherent in the new A20 chip.

A huge data heist

All of this information is carried within the 200,000+ files (630GB) World Leaks published on its dark web site. The data also includes confidential Apple supplier list info, detailed information concerning the circuit board, battery parts, and camera modules – even confidential information about which suppliers are competing to supply specific components. These are all confidential trade secrets the company is unlikely to want public, as they give rivals rare insight into how the company’s supply chain is structured.

Apple’s own crack team of security specialists is now involved in investigation of the attack, while Tata Electronics says it has restricted internal access and is engaged in a forensic investigation of the attack. 

Manufacturing is under attack

The scale of the attack is significant — so much so that it suggests the attackers engaged in extensive work to compromise the systems at Tata. This might have involved targeted attacks on employees, phishing, exploitation of weak access controls, the use of stolen credentials, and more. The attack point is unlikely to have been via Apple, but through a less protected supplier. 

There’s no doubt this leak is one of the worst to have hit the company, including the pre-release iPhone 4 left in a Redwood, CA nightclub that was then sold to a tech website. About the best thing to say about both leaks is that they help stoke up pre-release interest in an upcoming iPhone.

In truth, the story should be a wake-up call to business users that when it comes to system security, they are only ever as safe as the weakest link in their supply chain. This is particularly true in manufacturing. The IBM X-Force Threat Intelligence Index 2025 described manufacturing as the most targeted industry across four successive years.

Expect more such attacks with AI

Today’s sophisticated attackers are very accustomed to crafting multi-stop attack chains to get what they want, and World Leaks successfully attacked several larger enterprises, including Dell and Nike in recent months. 

Did this attack rely on AI? It’s not impossible, given Apple’s rush release of a security update designed to patch numerous vulnerabilities covering maliciously crafted web content and malicious web extensions, data exfiltration and sensitive data leakage, hijacked clipboard data, and more.

“It cuts both ways. The same AI helping researchers find these flaws is helping attackers exploit them faster, so expect more frequent updates, not fewer bugs, and the advantage shifts to whoever deploys the fix fastest,” said Adam Boynton, senior enterprise strategy manager for Jamf.

Please join me on social media at BlueSky,  LinkedIn, or Mastodon, and do subscribe my daily human-curated Apple news headline summary on Substack.

Kategorie: Hacking & Security

Network Security Monitoring: Common Linux Monitoring Gaps That Hide Threats

LinuxSecurity.com - 30 Červen, 2026 - 18:22
If you’re relying on standard network logs to protect your Linux infrastructure, you’re flying blind. Most organizations believe they have network security monitoring because they’re capturing traffic, but they’re actually just collecting noise. Real security—the kind that stops an attacker—happens in the gaps between the network, the process, and the host. When an attacker breaches a Linux server, they rarely reach for a custom zero-day. They use what’s already there: curl, bash, python, or ...
Kategorie: Hacking & Security

What Kali Linux 2026.2 Says About Today's Linux Security Priorities

LinuxSecurity.com - 30 Červen, 2026 - 18:18
Offensive Security just dropped Kali Linux 2026.2, and at first glance, it looks like a standard quarterly refresh. You’ve got the usual kernel bumps, desktop environment updates, and a handful of new utilities. But don't write this off as just another routine version update.  If you look past the changelog, this release highlights several capabilities that continue to be important in offensive security. From AI-assisted workflows to credential testing and mobile assessments, Kali Linux 2026....
Kategorie: Hacking & Security

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

The Hacker News - 30 Červen, 2026 - 17:47
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI)
Kategorie: Hacking & Security

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

The Hacker News - 30 Červen, 2026 - 17:47
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Fake Perplexity extension on Chrome Web Store tracked searches

Bleeping Computer - 30 Červen, 2026 - 17:46
A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]
Kategorie: Hacking & Security

Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses

The Hacker News - 30 Červen, 2026 - 17:40
Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocurrency clipper activity has been codenamed Silent Swap by McAfee Labs. "The campaign is delivered through unsigned installers – observed in both .NET and Golang variants – that
Kategorie: Hacking & Security

Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses

The Hacker News - 30 Červen, 2026 - 17:40
Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocurrency clipper activity has been codenamed Silent Swap by McAfee Labs. "The campaign is delivered through unsigned installers – observed in both .NET and Golang variants – that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks

The Hacker News - 30 Červen, 2026 - 16:26
The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of the eleven popular open-source coding and computer-use agents the firm tested. Only one, "Continue," was built to
Kategorie: Hacking & Security

GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks

The Hacker News - 30 Červen, 2026 - 16:26
The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of the eleven popular open-source coding and computer-use agents the firm tested. Only one, "Continue," was built to Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Raspberry Pi Official Magazine 166

AbcLinuxu [zprávičky] - 30 Červen, 2026 - 16:23
Nové číslo časopisu Raspberry Pi zdarma ke čtení: Raspberry Pi Official Magazine 166 (pdf).
Kategorie: GNU/Linux & BSD

Lessons from the Underground: How to Combat Business Email Compromise

Bleeping Computer - 30 Červen, 2026 - 16:00
Business Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks are planned and executed. [...]
Kategorie: Hacking & Security

This DNA Switch Could Control Molecular Machines

Singularity HUB - 30 Červen, 2026 - 16:00

Switches drive nearly every machine. A new one, made of folded DNA, does the same work at the scale of molecules.

Scientists have long dreamed of developing nanoscale machines, but building reliable mechanical components at the molecular scale has proved challenging. Researchers have now developed a DNA-based switch that can rapidly and repeatedly snap between two stable states, much like the components that underpin everyday electronics.

Ever since Richard Feynman’s visionary lecture “There’s Plenty of Room at the Bottom,” researchers have been enamored with the idea of engineering at the scale of atoms and molecules. But manipulating matter at the nanoscale is easier said than done.

Individual molecules are in constant motion and continuously jostled about by the thermal energy of their surroundings. This makes it extremely difficult to position and assemble larger structures and undermines control of the mechanical motion of components.

This is particularly true for switches—key components in many mechanical and electronic devices you might want to build. Getting a tiny structure to hold one position, flip cleanly to another, and then stay there has so far been an unsolved problem.

But now, a team at the Technical University of Munich has created a switch made from folded strands of DNA that remains stable for up to an hour and flips in milliseconds on the application of a brief electric field. Crucially, the device was able to switch back and forth repeatedly with no degradation in performance.

“Individual devices sustain hundreds of thousands of switching cycles over several hours and remain functional for actuation over several days,” the researchers write in a paper in Science Robotics. “As a nanoscale electromechanical interface, our device enables applications in molecular information processing, optical nanodevices, and the dynamic control of chemical reactions.”

The device borrows a principle from standard engineering known as a snap-through mechanism, which rests in either of two states and only flips when pushed hard enough, a bit like a light switch.

Scaling the idea down to a few tens of nanometers meant designing rigid arms linked by flexible molecular hinges, so the structure settles into one of two configurations and does not flick between them on its own. The team relied on DNA origami to accomplish this, where a long strand of DNA is folded into custom 2D and 3D shapes using hundreds of shorter “staple” strands.

One of the two arms features a longer “extension arm” that acts as a lever to push the switch between configurations. DNA carries negative charge, so when an electric field is applied to the device, it pushes the arm hard enough to flip the switch. Left alone, the team estimates that the structure stays in its resting state for roughly six hours, and they observed no spontaneous flips while monitoring 70 switches for an hour.

One of the device’s main strengths is its endurance. One switch survived more than 200,000 flips over five and a half hours, and a simplified version withstood a million switching cycles in three hours while still working about 85 percent of the time. Performance varied considerably from one device to the next, however, with some failing after a few thousand cycles and others continuing for days.

The researchers say failures likely stem from a combination of contaminants, surface wear, and chemical changes in the surrounding fluid. However, some inactive switches later started working again, which the team says suggests they are capable of self-repairing.

To test whether the switch could do anything useful, the researchers attached a gold nanorod to the moving arm, turning it into a microscopic light switch that changed how light scattered off the particle. In a second test, they used the switch to expose or hide a molecular binding site, allowing it to control whether DNA strands could attach.

That second capability could be particularly useful as it could make it possible to control chemical reactions—for instance by turning enzymes on and off. The authors suggest that this could be used to create “control knobs” for chip-based bio-factories that run sequences of reactions.

Considerable obstacles remain before the device can become genuinely useful. A single switch encodes just one bit of information, and the team acknowledges that wiring arrays of switches together to create something resembling a circuit remains a distant prospect.

But a workable switch is a fundamental component that can be used to create all manner of devices. While we’re still a long way from Feynman’s dream of molecular machines, this is a meaningful step in that direction.

The post This DNA Switch Could Control Molecular Machines appeared first on SingularityHub.

Kategorie: Transhumanismus

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

The Hacker News - 30 Červen, 2026 - 15:49
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend server that accepted requests with no key at all. Whoever grabs it can send model requests on the developer's account,
Kategorie: Hacking & Security

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

The Hacker News - 30 Červen, 2026 - 15:49
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend server that accepted requests with no key at all. Whoever grabs it can send model requests on the developer's account,Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Na Slovensku chystají spuštění čtvrtého bloku jaderné elektrárny Mochovce. Začalo zavážení ruského paliva

Živě.cz - 30 Červen, 2026 - 15:47
V jaderné elektrárně Mochovce začalo zavážení ruského paliva do čtvrtého bloku • Celkové náklady na dostavbu obou reaktorů dosáhly výše sedmi miliard eur • Slovensko se po spuštění nového zdroje stane významným vývozcem elektřiny
Kategorie: IT News

Moderní zálohování a odklad aktualizací až o 35 dní. Vyzkoušejte si další aktualizaci pro Windows 11

Živě.cz - 30 Červen, 2026 - 14:45
Aktualizace KB5095093 pro Windows 11 vyšla volitelně k instalaci. • Zavádí moderní obnovu systému nebo odklad aktualizací až o 35 dní. • Vývojový tým provedl řadu technických vylepšení pro bezdrátové audio.
Kategorie: IT News
Syndikovat obsah