Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

The Hacker News - 15 Červenec, 2026 - 17:30
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and
Kategorie: Hacking & Security

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

The Hacker News - 15 Červenec, 2026 - 17:30
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mak’s Weekly Security Roundup: Linux Updates You Shouldn't Ignore This Week

LinuxSecurity.com - 15 Červenec, 2026 - 16:21
Before the week gets away from you, take a look at what's landed across the Linux ecosystem.  The volume of security advisories hasn't slowed, and while not every update demands an emergency maintenance window, several deserve to move to the top of your patch queue. This week's updates span the kernel, remote desktop infrastructure, VPNs, containers, browsers, and the utilities Linux systems quietly depend on every day.  Individually, these look routine. Together they show how quickly attacke...
Kategorie: Hacking & Security

How to Configure Centralized Logging with Journald and Rsyslog

LinuxSecurity.com - 15 Červenec, 2026 - 16:04
Linux systems generate a steady stream of authentication, service, kernel, and application logs. On most systems, those logs never leave the machine that created them. If you're responsible for ten or twenty servers, that means checking each one separately. If one disappears before you can investigate it, its logs may disappear with it. Centralized logging solves that by sending log messages to another server as they're created. Instead of searching every machine, you have one place to review...
Kategorie: Hacking & Security

We built a vulnerability vending machine: AI tokens in, zero-days out

Bleeping Computer - 15 Červenec, 2026 - 16:01
Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure. [...]
Kategorie: Hacking & Security

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

The Hacker News - 15 Červenec, 2026 - 15:18
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navigation component "We are aware that exploit code for this is public, however we are not aware of
Kategorie: Hacking & Security

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

The Hacker News - 15 Červenec, 2026 - 15:18
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navigation component "We are aware that exploit code for this is public, however we are not aware of Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

The Hacker News - 15 Červenec, 2026 - 13:50
For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into
Kategorie: Hacking & Security

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

The Hacker News - 15 Červenec, 2026 - 13:50
For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

The Hacker News - 15 Červenec, 2026 - 13:07
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. "The PoC requires
Kategorie: Hacking & Security

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

The Hacker News - 15 Červenec, 2026 - 13:07
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. "The PoC requiresRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

The Hacker News - 15 Červenec, 2026 - 13:06
A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first. The Reality of the Approval Gap It's a pattern every
Kategorie: Hacking & Security

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

The Hacker News - 15 Červenec, 2026 - 13:06
A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first. The Reality of the Approval Gap It's a pattern every The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How to unionize your tech workplace

Computerworld.com [Hacking News] - 15 Červenec, 2026 - 13:00

The best time for tech workers to unionize was 20 years ago, when they had plenty of leverage. The second-best time is now, when they don’t.

Mass layoffs, AI-driven displacement, corporate surveillance, workplace disillusionment have created conditions that have made organizing compelling for tech professionals. But the federal labor board that has historically protected workers’ right to organize has been weakened, and the companies that once feared it are openly defying it.

Here’s how organizers and labor experts describe the pros and cons to organizing — and how you can get started.

This is Part 2 of a series on tech worker unionization. Also see Part 1: “A brewing battle: More IT workers want unions. The industry doesn’t.”

What unions can — and can’t — do for you

The single biggest benefit of a union contract for most tech workers isn’t pay — it’s protection against arbitrary termination, especially in the wake of recent mass layoffs in tech. In the United States, nonunion “at-will” workers can be fired at any time without a stated reason, while unionized workers negotiate protections written into their contracts.

“That fear of the company letting you go for anything at any time…with a union they just can’t do that,” says Zak Thompson, a senior software engineer at Kickstarter and union steward at Kickstarter United. Now that Kickstarter employees are unionized, people are less worried that saying something negative will result in termination.

“I’ve been shocked at the willingness of my co-workers to speak up against what they see as poor or controversial business decisions,” Thompson says.

width="972" height="972" sizes="auto, (max-width: 972px) 100vw, 972px">

Zak Thompson from Kickstarter United


Fee Christoph

Beyond job security, unions can deliver concrete material gains. Kickstarter United was formed in 2020, although getting there wasn’t easy: two employees were fired during the organizing campaign — which itself became a galvanizing event. And while the union hasn’t been able to prevent layoffs, it did negotiate better terms: four months of severance pay and four to six months of continued health insurance, versus the two to three weeks per year of work that management had initially proposed.

Other benefits include a four-day work week; AI protections; a minimum pay floor; and standards for raises, promotions, and time off for the company’s 59 employees.

Unions can give tech workers a voice in decisions that affect their daily work — including how AI tools are deployed. “Nobody I’ve spoken to is against new technology or getting trained in it,” says Max Belasco, a business systems analyst at the University of California Los Angeles School of Law and co-chair of the UCLA chapter of the University Professional and Technical Employees/Communications Workers of America (UPTE-CWA) Local 9119.

“But when new technology is being implemented, we want to know: what’s the five-year vision, the 10-year vision? Are we implementing this in a way that betters staffing, increases efficiency, or eases the lives of people already working? Or are we trying to take away jobs, automate people out of their pension or paycheck?” Belasco says.

The challenges are real. Tech professionals are less inclined to leave their jobs in the current market because wages haven’t been increasing as fast as they once were, and it can take longer to land another job.

“Tech moved from a very tight labor market in 2022 (1.85% unemployment rate) to a noticeably weaker one in 2024–2026 (3.49%),” although that’s still better than the national unemployment rate of 4.36% through May of this year, says Liya Palagashvili, senior research fellow and director of the Labor Policy Project at the Mercatus Center at George Mason University.

width="960" height="640" sizes="auto, (max-width: 960px) 100vw, 960px">

Liya Palagashvili of the Mercatus Center at George Mason University

Mercatus Center at George Mason University

Flexibility is a concern. The more substantive challenge, raised by economists including Palagashvili, is that traditional union contracts impose uniform terms across an entire bargaining unit, limiting the flexibility that many tech workers — and their employers —currently enjoy. Tech firms need to move fast, adjusting teams, products, and roles on the fly.

“Collective bargaining agreements can make those adjustments much more difficult, whether by making them slower, costlier, or inconsistent with the contract,” she says.

Workers skeptical of unions in a survey of 1,900 tech professionals conducted by the career site Blind cited specific concerns: that unions are “not meritocratic,” “prevent innovation,” and “hold back earnings of top performers.”

Thompson from Kickstarter United pushes back: “We have nothing in our contract about ‘you can’t bend down and pick up a piece of trash because that’s someone else’s job.’ The company is free to give bonuses and individual raises as much as they like. This is all just up to the people who are bargaining the contract from the union side.”

Organizing carries potentially serious personal risks. During negotiations for a second three-year contract in 2025, Kickstarter United went on strike for 42 days. A few months later, the company announced layoffs.

“They let go strong union leaders, including a person who had bargained our last contract,” Thompson says. The union appealed, and the issue is now going to arbitration.

If you form a union, don’t expect much support from the National Labor Relations Board, the agency that certifies US labor unions and protects workers’ right to organize, in terms of prosecuting complaints of unfair labor practices, Thompson warns. “We’re in a political moment in this country with a pretty weakened NLRB. You have to be ready to organize and withhold worker power without any guarantee of safety.”

Organizers are up against an enormous union avoidance industry. Organizers can expect fierce pushback as soon as the business discovers that organizing is underway.

“There’s a multi-billion-dollar industry in union avoidance,” says Alan McAvinney, a Google software engineer and organizing chair, Alphabet Workers Union-CWA, a 1,400-member minority union of Alphabet employees. (Google is a subsidiary of Alphabet.)

US employers spend roughly $1.7 billion a year on union avoidance consultants and law firms, according to a May 2026 report by the Economic Policy Institute and LaborLab.

Expect hardball tactics. Management may play hardball during the time between when organizers announce their intention to unionize and the actual vote. For example, management can threaten to fire foreign-born workers in the US on H-1B visas if they support the union. Those workers would then have just 60 days to find a new sponsoring employer or lose their H-1B status, according to a recent Tech Workers Coalition blog post.

And at venture capital-backed startups, investment agreements sometimes require management to attest there is no union activity — meaning a public organizing drive can trigger funding withdrawal. Or, if a unionized company is acquired, the new management can dissolve the union overnight by reclassifying unionized workers as new hires.

With these sobering facts in mind, here is how organizers who have done it describe the process of creating a union.

Step 1: Start a conversation with your co-workers

At the University of California, a two-tier system had evolved where some tech workers were unionized and some weren’t, Belasco says. Management created new titles that fell outside the union even though they had similar job descriptions and responsibilities to those in the union. Those nonunion employees received lower pay and benefits than their unionized peers, which created resentment and instability.

width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Max Belasco from the UCLA chapter of UPTE-CWA

Zac Goldstein

Belasco and other organizers wanted to eliminate that division by bringing everyone under the same contract. But when they began their unionization drive, “the biggest barrier we faced wasn’t management opposition — it was that people felt this was just the best-case scenario realistically available: ‘We have this job at the university, we have concerns about automation and layoffs, but what can we really do about it?'” he says.

The antidote to that fatalism, organizers say, is simple: “Just start talking to your immediate co-workers. Are they experiencing the same challenges you are experiencing?” says McAvinney. “There’s no need to start talking about a union at this point.”

Just get a consensus and start building a group of like-minded individuals, Thompson advises. “Always start with one-on-one conversations, and that’s what you should do the whole time. That’s the key to organizing,” he says.

Tech workers often think they’re a special case, says Thompson, and therefore that unionization isn’t a good fit. “You’re not special. You are a company of workers, you are organizing, and there is a playbook for that. Trust the process, because it tends to work pretty well,” he says.

Step 2: Who’s on board, and who’s not? Map your workplace, but keep it quiet

Once there’s a consensus, continue to grow your network. Keep a list of everyone you’ve spoken with and note their disposition: “Is this person union-friendly or anti-union? Would they be a strong organizer?” Thompson says.

Maintaining secrecy early on is essential, because anti-union tactics will start immediately, and that can stop union organizing before it can gain momentum.

“Generally, employers do not want to share power with their workforce,” McAvinney says. Employers will deploy every means at their disposal to stop organizing efforts and peel away potential yes votes.

width="1024" height="839" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Alan McAvinney from Alphabet Workers Union-CWA


Aran Per Ink

“If you look at historical examples, having 70% approval before the employer finds out about you results in a high percentage of wins when you actually cast the vote. Historically, that’s an effective buffer,” he says.

There’s a real threat of firing and layoffs. The traditional tech worker belief that job mobility makes collective action unnecessary is now being tested by a tighter job market, McAvinney says, noting that workers who many believe were fired for speaking out back in 2019 were a galvanizing factor in his union’s formation.

“You generally don’t want to be in a situation where the employer feels comfortable firing everyone. Part of that is thinking from a cynical standpoint about what the consequences would be to the employer if they did fire everyone,” he says.

One-on-one conversations that include personally asking co-workers to keep conversations confidential are key to keeping things quiet, Belasco says. When 2,100 UC tech workers voted to unionize in May, 96% voted in favor. To stay out of earshot of managers, avoid employee surveillance tools, and sidestep conference calls that could be recorded, organizers met with workers in their homes.

“That tactic is probably what made the difference between winning the election and getting the majority we got,” he says.

Step 3: Find the right union affiliation or go it alone

“Running a campaign against major employers requires the resources and expertise of the larger labor movement, even if workers publicly present as independent,” says Kate Bronfenbrenner, director of labor education research and senior lecturer emeritus at Cornell University’s School of Industrial and Labor Relations.

Options include the Communications Workers of America (CWA), Service Employees International Union (SEIU), and the Office and Professional Employees International Union (OPEIU), among others. Another resource, the Tech Workers Coalition (TWC), provides training on organizing tactics, AI-in-workplace issues, and contract negotiation, and can match workers to the right unions for their needs.

The Alphabet Workers Union decided early on to affiliate with CWA. “They gave us a bunch of support early on in our campaign with no strings attached,” McAvinney says.

Kickstarter is organized through OPEIU, Thompson says. “They’ll usually have resources and staff that can help you through the next steps: collecting signatures in support of a union, bringing that to management, holding a vote — the more formalized things that interact with US labor law. They’ll also help with organizing along the way,” he says.

For workers at institutions where a union already exists, there may be a faster path. Organizers at UCLA did what’s called a “unit modification,” aligning with UPTE. By organizing under UPTE, the workers didn’t have to negotiate a new contract from scratch — they joined an already-negotiated contract covering existing UPTE tech members, which put them in “a much stronger position” than starting fresh, Belasco says.

Step 4: Choose your union model: majority vs. pre-majority or minority

Assess what’s practical for your organizing effort. In a majority union, more than 50% of all workers in a defined bargaining unit must vote to join the union through an NLRB-supervised election in the private sector, or a Public Employment Relations Board (PERB)-supervised election for public sector workers.

The NLRB must certify the union, which then operates under its legal protections. This means, for example, that the employer must bargain, negotiated contracts are enforceable, violations must go to the NLRB or arbitration, and workers can’t be dismissed without just cause.

A pre-majority or minority union is a minority labor organization operating without NLRB protections or collective bargaining agreements. “Pre-majority means that workers are able to demonstrate majority support — through signed cards, petitions, a walkout, or everyone wearing solidarity T-shirts — without going through a formal election,” Bronfenbrenner says.

width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Kate Bronfenbrenner from the School of Industrial and Labor Relations, Cornell University


ILR School/Cornell University

The Alphabet Workers Union-CWA (AWU-CWA) formed as a pre-majority union because achieving majority status across a globally distributed workforce of over 100,000 was not a realistic near-term goal. “An underground model where you try to reach 70% support across a workforce of over 100,000 people isn’t realistic,” McAvinney says.

A pre-majority union can still make a difference, he says. For example, the Alphabet Workers Union-CWA convinced management to offer voluntary exit packages — buyouts — prior to announcing layoffs.

For smaller organizations, a majority union may be the more practical option — it’s more attainable, McAvinney says. “I don’t think [the pre-majority union model] is the correct thing to do in all situations. I certainly would not recommend it to a 200-person shop.”

Kickstarter, which had fewer than 100 employees, was able to form a majority union, with 55% voting to organize.

Ultimately, says McAvinney, “there’s no inflection point where you go from being able to win nothing to winning everything, even with a contract and a supermajority. But the more people you have who are willing and able to fight for what they want, the more you’ll be able to get.”

Step 5: Who should — and should not — be in your union?

Belasco’s situation at UCLA illustrates a broader strategic choice that every organizing campaign must make. He had been in a union position in educational technology when he was told his role would be reclassified as a non-union position.

“I was given a choice: apply to the new non-union position to continue doing the work I’d trained for, or stay in my union position doing service desk work I wasn’t used to,” he says. “Essentially, it was a choice between job security and career progression.”

Belasco joined a “wall-to-wall” union, which represents a broad range of university professional and technical employees across the UC system rather than a single job category, such as engineers or tech professionals.

Kickstarter United is another example of a wall-to-wall union. “It’s not just the engineers who are unionized, but also customer support, designers — everyone,” Thompson says.

Wall-to-wall unions are more powerful, but they’re also more difficult to achieve. Under US labor law, “professionals have to vote separately on whether they want to be combined with other workers,” says Bronfenbrenner. “You can never have a wall-to-wall unit without giving professionals the chance to decide whether they want to be separate.”

The law’s “professional employees” category includes roles like software engineers and developers but not necessarily others. For example, customer support specialists and QA analysts would fall into the “non-professional workers” category.

“For decades, the pattern was either to organize everybody except the engineers, or manage to organize the engineers and fail to bring in everybody else — neither of which builds real worker power,” says Simone Robutti, an organizer with Tech Workers Coalition Global, an international branch of TWC based in Berlin.

width="959" height="713" sizes="auto, (max-width: 959px) 100vw, 959px">

Simone Robutti from Tech Workers Coalition Global


TWC

Step 6: You won the vote. Get ready for what comes next

Winning a union vote means having a seat at the table, says Thompson. “Once the workers have come together and agreed they want that seat, you bring that to management, and they have a chance to voluntarily recognize a union,” he says.

But in most cases employers contest the results, which must be certified by the NLRB or PERB. That process, in which the employer uses various tactics to challenge the legitimacy of the outcome, can take weeks or months.

Unfortunately, the legal framework that is supposed to protect workers during this process has been significantly weakened in the last few years. In a potentially more ominous development, SpaceX, Amazon, Trader Joe’s, Starbucks, and the University of Southern California have in separate legal actions challenged the constitutionality of the NLRB, arguing that the agency’s structure violates the separation of powers. The Fifth Circuit Court of Appeals upheld injunctions against the NLRB in SpaceX’s case in August 2025 — a serious challenge to the agency’s authority.

In the meantime, some companies may disregard negotiated contracts, which can lead to lengthy legal appeals or extended arbitration.

“The NLRB can still force an election, but it can’t force a contract, and companies are saying they simply won’t comply,” Bronfenbrenner says. This is where the expertise and resources of affiliation with a major union can help, she adds.

As a result, contract negotiations can take far longer than workers might expect. At Kickstarter, for example, two years and four months elapsed from the time of the union vote to the first contract, and that was at a 59-person company with a relatively cooperative employer. At larger companies with more aggressive legal teams, the timeline will be longer.

Forming a union is hard work, Robutti says. “It’s not a service you pay for and they protect you. It doesn’t happen spontaneously, and it doesn’t happen magically. It’s the choice to take responsibility for improving your workplace.”

See Part 1: A brewing battle: More IT workers want unions. The industry doesn’t.

Kategorie: Hacking & Security

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

The Hacker News - 15 Červenec, 2026 - 12:55
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open. No prompt
Kategorie: Hacking & Security

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

The Hacker News - 15 Červenec, 2026 - 12:55
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open. No prompt Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OkoBot: new sophisticated malware framework targets cryptocurrency users

Kaspersky Securelist - 15 Červenec, 2026 - 12:00

Introduction

In January 2026, we identified multiple attacks involving unknown malware that captures the contents of cryptocurrency wallet windows. During the investigation, we reconstructed the complete infection chain, which consisted of four tightly linked stages initiated by the execution of the previously described malicious PowerShell script TookPS. However, this campaign differs from previous activity in that it uses a new framework to deliver all malicious modules and orchestrate them via an SSH tunnel. In total, the framework includes more than 20 malicious payloads and implants, covering a wide variety of functions. At the time of writing, the threat remains active.

Kaspersky’s products detect this threat as Trojan-Downloader.Win32.TookPS.*, Trojan.Win64.BypassUAC.*, Trojan-Banker.Script.Agent.gen, Trojan.Win32.Dllhijack.*, Backdoor.Win32.TeviRat.*, Trojan-PSW.Win64.Stealer.*, Trojan-Spy.Win64.Keylogger.*, Trojan-Spy.Win64.Agent.*, Trojan.Win64.Agent.*.

Background

TookPS is a downloader used for retrieving malicious commands and scripts from attacker-controlled servers to further propagate attacks. The first campaign using TookPS was discovered in March 2025. At that time, malicious scripts delivered a Python‑based infostealer along with a script that installed and configured an SSH tunnel on the victim’s machine. The next wave appeared in April 2025: the payload was changed, and TookPS was used to deliver the TeviRAT malware with the same SSH installer.

Then at the end of April 2025, TookPS underwent minor changes, yet its attack chain was completely redesigned. Unlike previous incidents, in this case, TookPS was used solely for the initial infection, with an automated SSH bot responsible for payload delivery. This new malicious campaign has multiple stages that cover the full attack lifecycle, from initial infection to persistence and data exfiltration. Among various malware strains, at one of the stages, the TeviRAT backdoor is delivered to the compromised host, ultimately fetching another version of a TookPS script.

We dubbed this updated TookPS campaign “OkoBot”.

Original OkoBot infection chain

We will break down this chain in greater detail later in the article. However, this is not the only version of OkoBot we were able to find. Already in March 2026, we discovered a new phase in the development of the framework, with Volume2 now being installed directly using TookPS. The HDUtil launcher → extl injector → Rilide chain was found to be abandoned in this newer version since it was replaced in full by the identical ext_daemon Volume2 plugin. TeviRAT was also removed, most likely because its functions were covered by the new plugins dispatcher.

New OkoBot infection chain

Initial infection

The initial infection is primarily delivered through two vectors: a ClickFix attack, and malware distributed through GitHub that masquerades as legitimate software. One such example is the fake SQL Server Management Studio (SSMS) package distributed through GitHub. In fact, it is actually the legitimate Audacity — a popular audio editor — compiled with a malicious implant embedded in one of its libraries. Because the repository was indexed by most search engines and appeared at the top of the results for the query SSMS, the malware looked legitimate and quickly earned users’ trust.

Malicious application distribution report

This repository was created at the end of March 2025 and existed until June of that year. It consisted of a single file, README.md, which provided a fake SSMS installation guide written in an official style and likely derived from excerpts of Microsoft’s documentation. However, the download link for the program, located at the beginning of the guide, pointed to the latest release in the same repository.

Both infection vectors trigger the execution of the malicious script TookPS, which installs SSH on the victim’s system, establishes a connection to the attacker-controlled SSH server and subsequently forwards the SSH daemon port. Following a delay, an automated SSH bot connects to the forwarded port.

Back connection

The automated SSH bot collects system information such as usernames, antivirus software installed, the IP address, and OS version. It harvests cryptocurrency wallet files, browser cookies, profiles, and other credentials through an SSH tunnel. For subsequent delivery of malicious modules, it disables Windows Defender notifications via a registry modification. Moreover, it gains access to the graphical session on the victim’s system using the following sequence:

  1. Open firewall ports for inbound RDP traffic
  2. Create a user in the “Remote Desktop Users” group
  3. Replace the legitimate termsrv.dll with a patched one to permit multiple concurrent RDP sessions
  4. Create a scheduled task named Apple Sync to maintain a reverse SSH tunnel that forwards the local RDP port every hour

After that, the SSH bot begins retrieving malicious modules over SFTP.

Launcher with advanced options

One of the deployed modules is HDUtil, an auxiliary utility protected with VMProtect and heavily obfuscated. This launcher is used by the SSH bot during an attack to deploy various malicious modules via the target command. Additionally, it implements three auxiliary commands that were not observed during the attacks we analyzed. Nevertheless, their presence and potential capabilities further demonstrate the high degree of integration among all components of the framework.

Active sessions

At startup, the launcher verifies its execution environment by checking the HWID in the contents of %PROGRAMDATA%\hwid.dat, a technique consistently employed throughout the framework. If the file is missing or contains invalid data, such as a non‑MD5 hash, the launcher terminates without performing any further actions. Otherwise, the specified commands are executed. For example, enumsessions provides a list of sessions along with detailed information, including the session type (Console, Services, RDP, and others), username, connection host, and domain. In turn, enumadapters returns the names of all graphics adapters present on the system.

Example output of HDUtil enumeration commands

UAC bypass

The most important command of the launcher is target, which enables payload execution on the system. An optional nouac argument enables automatic UAC bypassing via Windows RPC and an auto-elevated msconfig.exe program, allowing the payload to run with elevated privileges stealthily. This technique has been known for a long time, discovered and described in 2019 by the Project Zero team, who provided a full report with a detailed technical description.

Below is the list of all HDUtil commands.

Command Description target [nouac [user=<user>]] [noattach] <file> Starts file and prints its output.
If optional argument noattach passed, command to be executed in background.
If optional argument nouac passed, automatic UAC bypass to be performed.
If optional argument user passed, new process to be executed under , otherwise default local administrator to be chosen. pcopy <file> <dir_src> <dir_dst> Copies file <file> located in <dir_src> to <dir_dst>. Not used by SSH bot. enumadapters Prints names of graphical adapters on current system. Not used by SSH bot. enumsessions Prints all sessions on current system. Not used by SSH bot. Browser extensions loader

The first malicious module delivered to the infected system via SFTP is executed using the previously described launcher with the command .\HDUtil.exe target extl.exe. It is a heavily obfuscated DLL injector protected with VMProtect. At startup, the module enters an infinite loop and uses the EnumWindows and IsWindowVisible API methods to enumerate the PIDs of active windows and retrieve the corresponding executable filenames. For processes associated with widely used Chromium‑based browsers, the module invokes a routine that injects a specialized implant.

The injector opens a process, allocates a memory region, and writes the payload directly into this region as unencrypted raw bytes. Then it resolves two exported implant functions, LdrInitMain and LdrCallMain, based on a pre-specified hash derived from a modified version of DJB2 hash function. The first function performs the final PE unpacking, including rebase operations and the initialization of the import and exception tables. The second function directly initiates malware execution.

Setting up protections on the regions and launching the implant

This loader installs malicious browser extensions and hides them from the user. It uses an internal engine that resolves the addresses of stripped functions by analyzing the byte patterns of their calls using YARA-style syntax. This approach enables the malicious code to access critical Chromium engine functions required for extension installation and management. This functionality is also implemented for other browsers with appropriate modifications. For example, in the case of Microsoft Edge, the corresponding DLL msedge.dll is hooked using the specific patterns.

List of the functions hooked by the malware

Using the obtained address of the BrowserProcess object, the loader traverses the inheritance hierarchy and subsequently resolves a pointer to the function responsible for registering observers of browser‑window creation, specifically ProfileManager::BrowserListObserver::OnBrowserAdded. With a specialized built‑in engine, they are hooked using the attacker’s own implementations while preserving the original function’s address.

The loader replaces the functions it finds with its own

When a new Chromium window is opened, a hooked function is invoked that silently installs extensions. This routine scans the user’s %APPDATA% directory, loads all .crx files (Chromium-based browsers extension format), and records them in the ext_table. The extensions are then installed in the browser.

During installation, the extension is unpacked into a non‑default extensions directory, Local Extension Settings, and its manifest is dynamically modified. An object named custom_args is added, containing the fields hwid (the identifier of the infected system) and browser (the name of the browser in which the extension is installed). Then, using previously resolved internal functions of chrome.dll, the extension is installed and all requested permissions are granted.

Extensions are unpacked into a non-default directory

All extensions loaded in this manner are added to a special array to be subsequently identified among regular extensions and to remain hidden from the user.

The remaining patched functions are used to hide the installed malicious extensions from the user. When invoked with registered extensions as parameters, they perform no operation and return a constant value. This enables the threat actor to suppress notifications related to the malicious nature of the extensions and to exclude them from the displayed list of installed extensions. As a result, the behavior of other extensions remains unaffected.

Stub for hiding malicious extensions

During the attack, the Rilide extension was installed on the victim’s system using the previously described loader. Rilide is a stealer targeting Chromium-based browsers that has been frequently used by Russian-speaking threat actors since April 2023. The malware is designed to steal sensitive user data, including login credentials, cookies, and financial information, with a specific emphasis on cryptocurrency theft.

Plugins dispatcher

The final module delivered via SFTP is an open-source utility called Volume2, which is executed with elevated privileges using the command .\HDUtil.exe target nouac noattach Volume2.exe. The executable was linked with the malicious protobuf.dll library. Although the library seems identical to the legitimate DLL, it has been modified to include a malicious exported function, ProtobufGetVer2. This function decrypts and initiates a malicious implant. The payload is encrypted using AES GCM, initialized with a static 256‑bit key and a 96‑bit nonce. The GCM authentication tag is omitted, resulting in the absence of integrity verification. Starting in March 2026, the name of protobuf.dll was changed to version.dll, although its contents remained a modified ProtoBuf library.

Decrypting implant using AES GCM and subsequent mapping

The loaded implant functions as a malicious plugin dispatcher. Upon initialization, it reads and verifies the HWID before establishing communication with the C2 server via the HTTP protocol. Each request follows a predefined binary format: a 2-byte numeric bot identifier encoded in little-endian format, followed by an AES CBC-encrypted JSON object. By default, the BotID is set to 0, and the key and IV consist of 32 and 16 bytes of 0xff, respectively. The implant polls the server every 20 seconds to retrieve new commands. The request contains client data encoded in Base64, and the server may respond with a command containing three mandatory fields: TaskIndex (the command number from the dispatcher), TaskID (a unique task identifier), and HWID (the client identifier). The dispatcher supports four built-in commands:

Task index Action 1 Reconfigure client: update session keys, assign ID, switch to another C2 2 Load DLL implant into memory and run its entry point 3 Load plugin into process and register tasks with RegisterPlugin function 4 Restart dispatcher as new process x If the task number is none of the above, search for it among the registered plugins

Each plugin is required to export two functions: RegisterPlugin and PluginDispatch. These functions are used to manage and configure plugins. The RegisterPlugin function registers the plugin’s tasks with the dispatcher, whereas the PluginDispatch function is invoked when the plugin is called. Both these functions, as well as other external API functions, are located within the base libraries using one algorithm. This algorithm iterates through the export table and uses a specialized callback that calculates the MurmurHash3 hash and compares it against the target value to identify the appropriate function.

Resolving a plugin initialization function

During the analysis, we were able to discover five plugins that implement functions under their unique task identifiers.

  • CMD wrapper (10xx): allows running scripts and individual commands in cmd.
  • PowerShell wrapper (11xx): allows running scripts and individual commands in PowerShell.
  • Environment enumerator (12xx): gathers system information, active sessions, and processes.
  • Dropper (14xx): downloads an additional payload directly onto the system both from embedded Base64-encoded binary blob and via URL.
  • Process injector (16xx): launches additional malicious implants on the target system by injecting them into legitimate processes.

We identified four malicious implants that are delivered to the system via the process injector plugin.

ext daemon

The malware is functionally identical to the browser extensions loader (extl.exe) described above, but less obfuscated and not protected with VMProtect.

SeedHunter

Similarly to extl.exe, this malware monitors the list of active processes in the system and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live processes. The implant is malware that collects seed phrases of Ledger and Trezor cryptocurrency wallets. Initially, it verifies the HWID, and if it fails, it terminates immediately. Then, based on the value of BaseDllName, the malware determines the process context and uses the corresponding implementation for either Trezor or Ledger. It then utilizes the previously described technique to hook the internal Electron framework functions.

List of functions hooked by the malware

Then the malware communicates with the C2 (moonsand[.]store) over HTTPS, sending a Base64-encoded JSON request containing the fields Pid, HWID, and Build. In response, it receives a JSON payload containing the Wait flag. If this flag is set to true, the malware initiates periodic USB device scans filtered by VID and PID (Vendor and Product ID). Upon detecting a connected Trezor or Ledger hardware wallet, it invokes the hooked functions to display a hard‑coded phishing page designed for seed phrase recovery, with a distinct layout used for each identified wallet. If the Wait flag is set to false, the phishing page is displayed immediately.

When the seed phrase is entered and validated, the JavaScript code of the page outputs the phrase to the console prefixed with @:app:print. This prefix helps identify the malware messages in the hooked function mal_LogConsoleMessage.

Phishing pages for seed phrase recovery

The obtained seed phrase is subsequently sent to the C2 server within a JSON payload containing fields such as App (ledger or trezor), Build, DeviceName, DeviceHardwareId, and SeedData. Furthermore, an identical JSON, encrypted with the RC4 algorithm using the HWID as the key, is saved in a temporary directory under the filename sh_<ts>.json, where <ts> is the file creation timestamp.

MC Keylogger

This module is a keylogger that, in addition to recording user input, performs three malicious activities:

  1. Clipboard logging: periodically checks various clipboard formats, including CF_HDROP for files dragged between windows, CF_DIB for copied bitmap images, and CF_UNICODETEXT for Unicode text. Each format is handled appropriately, and all copy events are logged under the Clipboard section. Text data is written directly to the log, while copied files are recorded by their file paths. Images are saved as JPG files following the naming pattern bf_YYYY-MM-DD hh_mm_ss.jpg, and the path to the saved image is added to the log.
  2. Logging connected devices: logs information about USB devices connected to the system, including hardware characteristics like VID, PID, manufacturer, and other details.
  3. Screenshot creation: creates a screenshot every five minutes with a name in the format sc_YYYY-MM-DD hh_mm_ss.jpg. A corresponding message is recorded in the log under the Screenshot section, including the path to the screenshot.

Thus, the keylogger creates three types of different file artifacts, which are placed in a temporary directory. Below is an example of a log file generated by the keylogger.

Example of the keylogger log file

OkoSpyware

This module, which we dubbed OkoSpyware, captures both keystrokes and the video stream of the target application’s window. It first compiles a list of over 100 executable names, including cryptocurrency wallet applications (such as Exodus or Litecoin QT), password managers (such as KeePassXC or 1Password), and other widely used applications, to identify which processes should be monitored among all active system processes. For each identified process, the module uses a bundled FFmpeg instance to capture an MP4 video of the window while concurrently logging keystrokes within that window. The resulting video file is saved in %TEMP% as media_<ts> (where <ts> is the recording’s start timestamp). In the same folder, a JSON file named oko_<ts>.json is created, containing metadata about the captured stream, such as the process name, intercepted input, the stream’s MD5 hash, and additional details.

Example of an OkoSpyware metadata file

The malware also monitors the state of browsers, and when the window title matches a specified regular expression — for instance, a MetaMask or Tonkeeper wallet extension page — it performs video recording and input logging, adding the window title value to the corresponding field in the JSON metadata file.

Artifacts exfiltration

The TookPS script launched via a scheduled task receives a PowerShell exfiltration script as its payload from the C2. All files created by the MC Keylogger and OkoSpyware are sent to the C2 server to the endpoint ir-post.php. After that, the files are deleted from the victim’s system and a command history file, ConsoleHost_history.txt, is cleared.

Sequential exfiltration of artifacts from the temporary directory

Victims

At the time of writing, we have detected hundreds of victims of the OkoBot campaign in more than 25 countries, with the largest proportion of attacked end users found in Brazil, Vietnam, Canada, Mexico, and Türkiye.

Distribution of users attacked by OkoBot by country, April 2025–June 2026 (download)

Attribution

At the time of writing, we can’t attribute this malicious campaign to any known crimeware actor. However, during the analysis, we observed that the servers hosting the PowerShell scripts used in the initial infection stage implement server-side geoblocking. When attempting to retrieve the malicious script using an IP from Russia or CIS countries, the server returns an empty response. This technique is very popular among Russian-speaking threat actors.

It was previously mentioned that the campaign uses the malicious Rilide extension, an infostealer that is actively spreading on Russian-speaking, invitation-only cybercrime forums. Additionally, the source code of the SeedHunter phishing pages includes comments in Russian.

Conclusion

The framework described here has numerous modules — mostly written in C and C++ — that are obfuscated and use a variety of packing techniques. Across all stages, specific patterns and techniques can be identified that are borrowed and used in other modules, which allows us to conclude that there is a close interconnectedness among all stages, forming a full‑fledged high‑level framework. Overall, these modules enable a wide range of functions, such as collecting local files, executing remote commands, downloading arbitrary browser extensions, and stealing crypto wallets.

The OkoBot campaign has been ongoing for over a year, and it remains active at the time of publication. Moreover, it is adapting, which indicates that this framework is being maintained and distribution campaigns continue.

Indicators of compromise

Additional information about this threat, with a comprehensive IoC list and decryption scripts, is available to customers of the Kaspersky Threat Intelligence Reporting service. Contact: [email protected].

Dispatcher

B07D451EE65A1580F20A784C8F0E7A46 # protobuf.dll
187A1F68AE786E53D3831166DC84E6D2 # protobuf.dll
D84E8DC509308523E0209D3CD3544619 # protobuf.dll
83E6B8FCB92A0B13E109301F8FF649CF # version.dll

Plugins

7306885BB4C98F2A9F056104CF092BC9 # PowerShell wrapper
B4C2E16CDB513BE4DC798F88E2527334 # CMD wrapper
2157D2429124AD28DB7A26F2477CB985 # Environment enumerator
77CECF5E2A622AE07D8AE9913457AB57 # Dropper
E0C3BC27A65750E740C4F1719E531C7D # Process injector

Injector payloads

3D2B43F91F65BFBF36A9C71B6B418876 # ext_daemon.exe
70FEF9FD6E351F4D53CFEEE8DCDFCD99 # seedhunter_x64.exe
ACD31C9941B6C1CABD4E45E6877B9038 # keylog_x64.dll
DD52F5108A176C62AD807C327734AD12 # oko.dll

SSH bot utilities

AC93A821617AEA1F56D4BC0BEF4AF327 # HDUtil.exe
11DBC8A2BEA04B15F8F68F3F01E8FAF9 # extl.exe

File paths

%USERPROFILE%\.ssh\go.bat
%PROGRAMDATA%\HDVideo\HDUtil.exe
%PROGRAMDATA%\hwid.dat
%PROGRAMDATA%\oko_ver
%TEMP%\extl.exe
%APPDATA%\hwid.dat

Domains and IPs

2baserec2[.]guru          # TookPS
recavb22[.]online         # TookPS
kbeautyreviews[.]com      # TookPS
coffeesaloon[.]online     # TookPS
104.243.43[.]16           # SSH bot
104.243.32[.]213          # SSH bot
62.210.188[.]209          # SSH bot
livewallpapers[.]online    # Volume2 C2
thatwascringe[.]com        # Volume2 C2
moonsand[.]store          # SeedHunter C2

5 wild ways to make Android widgets more useful

Computerworld.com [Hacking News] - 15 Červenec, 2026 - 11:45

Widgets, widgets, widgets. Has there ever been an Android feature so full of promise that went unloved by Google for so very long?

Okay, so maybe there has been — erm, lots of times, actually. But even so, Android’s widgets system is a perfect example of an exceptional advantage that Google basically buried, abandoned, and left on the brink of extinction up until its overdue revival in 2021’s Android 12 update. (And that revival, by the way, happened for no apparent reason whatsoever. Just a totally random, unprompted change of heart after a decade of indifference. Riiiiiiiiight.)

Google may have given up on widgets for a while, but the good news is that (a) they’re back, baby — still now, more than ever, even in our overly AI-obsessed 2026 timeline — and (b) the Android developer community keeps chuggin’ along and coming up with ever-more creative new ways to embrace widgets beyond what Google itself sees fit to give us. That means no matter what Android version your favorite phone is running, you can step up your own Android widget game and give yourself some fresh and fruitful paths to make the most of your phone’s framework.

Here, my dear, are some fantastic beyond-the-basics ways to put your favorite Android widgets to use and change the way you get stuff done on your phone. 

[Psst: Love learning new things? Get my free Android Intelligence newsletter to get a tasty new tip in your inbox every Friday.]

Android widget enhancement #1: The on-demand home screen pop-up

Widgets are a wonderful way to interact with all sorts of info without ever having to open up apps, but having too many widgets can quickly lead to a cluttered and overwhelming home screen.

Well, here’s a neat way to give yourself the benefit of a widget while still maintaining a neat and minimal space for working: An excellent app called Popup Widget lets you create an on-demand pop-up widget (get it?!) that looks like a regular ol’ icon on your home screen but then loads any widget you want when tapped.

See?

Any widget, anytime — with Popup Widget on Android.

JR Raphael, Foundry

You can even get really wild and set up a single icon that opens multiple widgets at the same time — like your inbox and your calendar together:

Popup Widget can even let you summon two widgets together with a single tap.

JR Raphael, Foundry

Not bad, right?

Popup Widget costs two bucks and doesn’t require any special permissions or manners of access. And it’s pretty simple and self-explanatory to set up: Once you install and open the app, it’ll walk you through adding in whatever pop-up widgets you want. You can choose the name and even the icon associated with each one along with its precise placement on your screen and how much the screen behind it should dim when it’s loaded.

The app will offer to add the shortcut directly onto your home screen for you then, or you can also find all of your Popup Widget creations by pressing and holding the main Popup Widget icon in your app drawer.

Alternatively, if you’re already using a custom Android launcher like Smart Launcher or Niagara, you can find similar options for summoning widgets on demand within their settings — no separate apps even required.

And that, my widget-loving wallaby, is but our first winning widget possibility.

Android widget enhancement #2: The on-demand universal pop-up

If you like the idea of having a widget on demand but would rather have it be available to summon from anywhere instead of just from your home screen, this next wacky widget option is just the thing for you.

It comes from a spectacular app called Edge Gestures, which works in conjunction with Popup Widget to take that same concept and make it universally accessible. (I told ya it was wacky!)

When you first install Edge Gestures, the app will prompt you to enable it as a system accessibility service and to grant it the ability to display over other apps. These permissions sound scary — and they should! — but in the case of this specific utility, they’re absolutely appropriate and necessary in order for it to operate. The former is the only way an app is able to create a custom system-wide gesture, which we need for this setup to work its magic, and the latter is how your widget is able to be shown on top of whatever else you’re doing.

(If you’re at all worried, note that Edge Gestures doesn’t request any other significant system permissions. Beyond that, it’s reputable, it’s been around for quite a long while, and it has a large number of overwhelmingly positive reviews.)

Where were we? Oh, right: Once you’re inside the Edge Gestures configuration area, you’ll be able to select exactly what gesture you want to use for pulling up your widget. I’d think carefully about finding something that won’t interfere with anything else, like the system-level Android gestures, and that’ll be convenient to access without being a command you’re likely to trigger by mistake.

So, for instance, you might make the gesture a simple swipe downward along the left side of your screen. To do that, you’d find the “Swipe down” option within the app’s “Left” tab, and you’d set it to “Popup Widget” — and then create or select whatever Popup Widget item you want. And remember: You can select one widget or multiple widgets, too.

Prepare yourself for some serious oohing and ahhing:

Your favorite widgets are never more than a swipe away with Edge Gestures on Android.

JR Raphael, Foundry

As you can see, this opens up a whole new world of mobile multitasking potential. I mean, really: How could you not love that?!

The final thing worth doing is going into all the other gesture options in that same configuration area and tapping “Clear” for each of ’em to get rid of Edge Gestures’ default actions. I’d also go into whichever side of the screen you aren’t using — left or right — and tap the toggle to turn the gestures for that side off entirely. That way, you won’t inadvertently activate any gestures that you don’t actually want or need.

Edge Gestures costs $2 to use.

Android widget enhancement #3: The physical key call

Next, here’s an interesting twist on that same on-demand Android widget idea: You can make any widget especially easy to access from anywhere without even having to mess around with any on-screen swiping by setting one of your phone’s physical keys as a trigger for the widget’s appearance.

I’ll give you a second to catch your breath and process the sheer splendor of that sorcery.

Back? Cool. So, the key to this feat (har har) is the combination of the aforementioned Popup Widget and a handy Android contraption called Key Mapper — which makes it easy to map your phone’s physical keys to all kinds of crazy custom actions.

In this case, we’ll set it up so that pressing and holding one of your volume keys causes whatever widget you want to be summoned, like so:

Yes, your volume key can cause a widget to appear (whoa!).

JR Raphael, Foundry

Pretty nifty, no?

I’ve got step-by-step instructions for making this happen in this separate guide.

Android widget enhancement #4: The floating bubble

If you like the notion of having a widget always available but aren’t so keen on the hidden gesture concept, an app called Overlays will let you create a small floating bubble that you can position anywhere on your screen and then tap to pull any widget up when you want it — just like with Android’s recently revived Bubbles multitasking system, only compatible with any Android device and version and with the simplicity of a widget instead of the complexity of an entire app.

Check it out:

Overlays puts a floating icon on your screen for easy ongoing widget access.

JR Raphael, Foundry

By default, Overlays gives you a bunch of its own little widgets to choose from, but the real power comes from adding in widgets from the Android apps you actually rely on. To do that, tap the “Triggers” tab at the bottom of the Overlays configuration area, then tap the red plus button in the lower-right corner of the screen. Select “Manual,” then type in whatever name you want for your widget and tap the icon to pick any icon you like.

Tap “Save,” then select “Widget” and find the widget you want from the list. At that point, you’ll see a preview of the widget. Move or resize it if you like, then hit the arrow in the upper-left corner of the screen to exit out of that interface. Last but not least, tap the name of your newly made widget on the screen that comes up next to change its status to “Always on.”

As soon as you head out of the app and back to your home screen, your fancy new widget should pop right up. All you’ve gotta do is tap the little downward-facing arrow in its corner to minimize it down to a bubble, which you can then press and hold to move anywhere your widget-worshipping heart desires.

Overlays can also create widgets that automatically appear based on context — so you could have something show up every time you connect to a certain Bluetooth device or Wi-Fi network, for instance. To explore those options, just follow the same steps from above but pick “Event” instead of “Manual” when you reach the “Triggers” tab configuration.

Overlays is free with an optional $4 in-app upgrade that removes some ads from the configuration tool and unlocks a handful of advanced features.

Android widget enhancement #5: The widget stack

Last but not least in our collection of wacky Android widget possibilities is one of my favorite widget wonders — and that’s the ability to stack multiple widgets and then swipe between ’em on your home screen without having ’em take up any extra space.

Check it out:

The space-saving simplicity of stacked widgets, as seen in Smart Launcher.

JR Raphael, Foundry

This enhancement presents a bit of a choose-your-own-adventure-style path:

First, if you’re using a reasonably recent Samsung Galaxy gizmo, the option is should already be present and available in your standard Samsung home screen setup. Just press and hold any open space on your home screen and then select the option to add a widget — then, once the widget is added, press and hold it and look for the “Create stack” command.

With any other Android gadget — or even with a Samsung device, if you want extra options and flexibility — you can use a custom Android launcher like the aforementioned Smart Launcher or Niagara as well as the retro-geeky T9-themed Key Launcher I introduced to you earlier this summer.

Those launchers replace your phone’s entire home screen environment and give you all sorts of interesting new possibilities for optimizing your interface and making it especially well-suited for you. And the stacked widget feature is just one small sliver of what they offer and how they’ll transform your Android experience.

The setup interface for a widget stack within Smart Launcher.

JR Raphael, Foundry

So there ya have it: five wacky, wild, wonderful ways to make widgets even more wow-inducing. Some days, you’ve just gotta love Android and the endless customization, control, and power it provides.

Put even more Googley goodness in your noggin with my free Android Intelligence newsletter — one exceptional new thing to try every Friday!

Kategorie: Hacking & Security

CISA warns admins to patch actively exploited SharePoint flaws

Bleeping Computer - 15 Červenec, 2026 - 11:44
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. [...]
Kategorie: Hacking & Security

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

The Hacker News - 15 Červenec, 2026 - 11:16
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/[email protected] @asyncapi/[email protected] @asyncapi/[email protected] @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) "The
Kategorie: Hacking & Security
Syndikovat obsah