Agregátor RSS

North Korea's fake job interviews infected 30,000 devices

The Register - Anti-Virus - 18 Září, 2026 - 18:53
North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters to infect more than 30,000 devices and steal over $10 million, according to an international advisory. Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued an update on the campaign on Thursday. They said the attackers had compromised more than 7,000 cryptocurrency wallets and stolen funds that ultimately supported the North Korean regime. The agencies track the activity collectively as WaterPlum. Its operators target web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicants' computers and installs malware. Once inside, the attackers deploy remote access trojans (RATs) and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview ends. In some cases, the compromised machines may later provide a route into corporate systems when the jobseekers secure legitimate employment. WaterPlum operators use that access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory [PDF] said. "Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion." The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang. The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western and allied companies. The scheme has been extensively documented and has generated revenue for North Korea for years. Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Some are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired. The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state. The sprawling IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million a year. The scale of the operation means some applicants inevitably succeed, although employers are becoming more familiar with signs of fraudulent North Korean candidates. Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview. Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency. Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins. The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised. ®
Kategorie: Viry a Červi

Vybrali jsme nejlepší myši a klávesnice. Do kanceláře, domů i na hraní

Živě.cz - 18 Září, 2026 - 18:45
I do pětistovky koupíte dobré periferie k počítači. • S Logitechem soupeří i privátní značka od Alzy. • Víte, že existují opravdu tiché myši?
Kategorie: IT News

FBI: Fake cop and government impersonation scams cost victims $1.6B

The Register - Anti-Virus - 18 Září, 2026 - 18:19
Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s Internet Crime Complaint Center (IC3) received close to 61,000 complaints of this type between January 2025 and July 2026, putting the average per-complaint loss at more than $26,000. The most common type of scam is one involving criminals convincing targets to pay a sum of money to remove charges the fraudsters claim were filed against them. Typically contacting targets via unsolicited phone calls, the scammers usually claim that the target has committed or is connected to a crime, and threaten consequences such as arrest and prison time if a payment is not made. Accounting for roughly 11 percent of the complaints is a different type of scam, which involves alleging victims did not fulfill their assigned jury duty or missed a court date, then threatening them with a fine or arrest unless they pay. Of these 6,833 complaints, scammers caused losses amounting to nearly $36 million. A more profitable variant involves a more targeted approach. Scammers will complete some due diligence on a target, such as ascertaining their profession, and tailor the scam to their job. The IC3 has seen cases in which scammers contact medical practitioners, for example, claiming their medical license is expiring or that it was used in the commission of a crime. Payment is then demanded either under the guise of renewing the license or as part of an extortion attempt to "protect their professional reputation." Victims reported 3,322 instances of this kind of targeted scam, with total losses exceeding $37 million. A far less common tactic, deployed in 496 of the total complaints, saw scammers claim that documents such as driver's licenses or passports had expired and demand payment to renew them. Despite accounting for a minority of cases, criminals still netted $348,000 using this method. Finally, and arguably the most elaborate tactic the IC3 outlined, was the targeting of Americans from different ethnic communities, foreign nationals, and international students in the US. The nature of the targeting was not the aspect the criminals invested the most effort in. The general procedure was also similar to the other examples: Scammers impersonate foreign law enforcement or US-based foreign diplomatic officials, threatening to cancel the victim’s home-country passport or have them extradited. However, these scams sometimes involve video calls. The criminals are known to don a country’s law enforcement uniform, or in some cases even take the calls in movie-style sets they create to mimic real government facilities. The IC3 said that it received 1,809 complaints of this kind of targeted scam during the 19-month reporting period, with total losses exceeding $140 million. It means nearly 10 percent of the overall losses stemmed from one scam that accounted for less than 3 percent of the total complaints. Law enforcement impersonation scams are common across the world, although they may take different shapes from country to country. In the Netherlands, for example, police received more than 7,200 reports of fake police officer scams in the first half of 2026 alone, although the criminals behind them don’t hide behind a phone or keyboard. Scams in the Netherlands see fraudsters approach victims at their homes, usually targeting the elderly population, offering to safeguard their valuables while posing as a trusted authority. In reality, the criminals simply steal the jewelry, money, bank cards, and other valuables they are entrusted to protect. Cases like these have surged across the country in recent years, and aspiring crooks as young as 14 have tried to cash in on the trend. Police have invested more in public awareness campaigns as a result. The FBI reminded the public that neither it nor any other law enforcement agency will call an individual and demand payment or request personal or sensitive information. Citizens should remember to ask for credentials and make attempts to independently verify the identity of the caller, such as calling the relevant office using publicly available details and asking for the caller by name. The IC3 recently reported its most damaging year for internet scams. It released 2025’s data in April, covering all types of cybercrime, pegging total losses at $20.87 billion – the first time it has reported annual losses exceeding the $20 billion threshold. ®
Kategorie: Viry a Červi

Gyazo server flaw exploited to steal 23.6 million user records

Bleeping Computer - 18 Září, 2026 - 18:00
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
Kategorie: Hacking & Security

Paměti pro telefony rekordně zdražují. Příští generace iPhonů tak může být ještě dražší

Živě.cz - 18 Září, 2026 - 17:45
Apple přistoupil na výrazně vyšší ceny paměťových čipů od Samsungu • Výrobci čipů upřednostňují paměti pro serverová datová centra a umělou inteligenci • Zdražení komponent nevyhnutelně zasáhne trh s iPhony i konkurenčními Androidy
Kategorie: IT News

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Hacker News - 18 Září, 2026 - 17:24
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

Bleeping Computer - 18 Září, 2026 - 17:19
 An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
Kategorie: Hacking & Security

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Computerworld.com [Hacking News] - 18 Září, 2026 - 17:16

Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026.

The kit abuses Microsoft’s OAuth 2.0 device authorization grant flow, a legitimate mechanism designed to enable authentication from IoT devices, smart TVs, printers, or other devices that cannot easily support a conventional browser-based login. The technique, known as device-code phishing, has been seen in other attacks before. As part of the flow, the device displays a code for the user to enters in a browser on another device to complete authentication.

GhostCode poses as one such device, gets Microsoft’s OAuth to generate a device code and then convinces the victim to enter it on Microsoft’s authentication page. The victim then signs in and completes multifactor authentication as normal — but the authentication is for the attacker-controlled device, allowing them to obtain the resulting authentication tokens. These tokens are then used to register attacker-controlled devices, obtain additional credentials and establish persistence in the victim’s Microsoft environment.

In the campaign observed by eSentire, the attack involved a social-engineering setup where attackers pose as procurement officers through a web contact form before moving conversations to an NDA-themed HTML file. Opening the file took the victim to the device-code phishing page.

Stolen tokens allow persistence

GhostCode’s post-authentication activity is focused on turning the stolen access into persistence inside the Microsoft environment. Once access was granted, eSentire recorded nine successful API calls over a 78-second period, involving Microsoft Intune Enrollment, the Device Registration Service, Azure Active Directory and Microsoft Graph.

Three devices were registered during that time, at 28, 53 and 77 seconds after authentication, a sequence eSentire said was automated.

The third device was also successfully enrolled into Intune, Microsoft’s cloud-based device management service. eSentire noted that Intune enrollment survived token revocation: The attacker-created device remained in the tenant until it iwas explicitly removed.

The attackers also obtained a Primary Refresh Token (PRT), which eSentire called “one of the most powerful” credentials in a Microsoft identity environment.

“Obtaining a PRT via device code abuse gives the threat actors essentially SSO-equivalent access to the victim’s entire M365 environment for the PRT’s lifetime — including any service not explicitly protected by a Conditional Access policy requiring a compliant device,” eSentire said, adding that the token persists 14 days by default.

The attackers also employed multiple evasion techniques, including padding and obfuscating the HTML code in their lure, encrypting redirects, checking for bots, and using Cloudflare Turnstile to keep security tools away from the phishing page.

What defenders can do

To defend against attacks like this, eSentire’s researchers recommend restricting Microsoft’s device-code authentication flow through Conditional Access and disabling it for users who do not need it. It also advises monitoring the Device Registration Service for multiple device registrations from a single non-interactive session, and looking for activity involving the user agent python-requests following device-code authentication.

Auditing Entra ID for devices matching GhostCode’s naming pattern and correlating successful device-code authentication with subsequent Python-based requests, should be able to catch an attack in progress, the company said. It shared a list of indicators of comprise related to the campaign to aid detection.

GhostCode adds to a growing number of attacks abusing device-code phishing to target Microsoft’s OAuth authentication flow. Recent examples include attacks using the “EvilTokens” phishing-as-a-service (PhaaS) kit, a campaign reported by KnowBe4 in February 2026, and activity observed in December 2026 involving multiple clusters, including both financially motivated and state-sponsored actors.

Kategorie: Hacking & Security

With Siri Recap, Apple threw a punch at OpenAI no one saw coming

Computerworld.com [Hacking News] - 18 Září, 2026 - 17:08

John Ternus’ Apple threw a curveball at OpenAI with Siri Recap on Apple Watch, accelerating a conversation about privacy and data protection in an AI-augmented digital era. It’s a move that may yet contribute to finding a balance between scary surveillance and digital convenience.

Think of it this way: Apple operates on such a big scale that it must have expected the feature to face regulatory and legal investigation. We know Apple has tried to stay on the right side of existing data protection and privacy laws by ensuring that its system doesn’t keep personal data, audio recordings, or transcripts, but one thing it doesn’t do is achieve consent from everyone who may be exposed to the feature. That’s a big no-no in some places, and it’s logical to think Apple expects some pushback to that.

Apple thought it through

From where I sit, it looks like Apple has thought about this. You only need to look to Apple Worldwide Marketing VP Greg Joswiak’s recent comments on the matter to see this, as he very swiftly tried to position Recap as little more than the digital equivalent of notebook and pen, or a smartphone set to record. The difference is that using the latter still technically requires consent in some places, while using a pen and paper does not. 

But if Apple has thought about it and anticipates oversight, then there are benefits to be had. Apple is not the only company seeking to use ambient data monitoring and AI tech to create new product families. Meta, OpenAI, and others also seem to be exploring ambient monitoring with AI, possibly with less of a commitment to privacy.

While it’s true as a general rule that your rights in a public place are weaker, they are not nonexistent, and both Apple and OpenAI must expect to face regulatory pushback on what they make.

This could be why Apple has accelerated regulatory conversation concerning such tools by introducing Siri Recap. The argument is that by forcing legislatures to make decisions on such matters, Apple is effectively throwing a punch at competitors who must also work within the law. (Though with data encryption such a huge piece of the privacy jigsaw, it’s fair to say that some nations may yet mess things up.)

Because it isn’t just about Apple

It makes sense for international lawmakers to create a harmonized framework of legislation to govern such products, particularly as they clamber headlong into so many different layers of protected personal existence. Apple’s decision to create this product at this time means regulators will now have to decide where to draw the line. 

We can surmise where Apple thinks that line will be on the basis of what Joswiak said and the actions the company has taken with a variety of guardrails to maintain privacy and data security. The idea it seems to be moving toward is that by stripping out the stuff we want kept private, it has effectively built the digital equivalent of writing a few notes in your book with a pen while a conversation takes place.

If Apple’s argument prevails, then those will become the regulatory-approved principles to define what other companies must do with their devices in this space. Including Meta and OpenAI.

Caught in a trap

That’s going to be fine for some entities, but companies that want to build businesses on your data will be disadvantaged by those decisions. Apple’s approach is that by defining the space, it also knows precisely what it must do to compete within it. That’s going to make for a far more equal playing field as AI hardware reaches the market.

A second outcome Apple may also be looking at is that by challenging regulators to sit down and declare what data and privacy rights consumers should enjoy in an AI digital age, it also identifies terms of reference to inform how its future AR glasses handle and process external video. Right now, it’s plausible to imagine a similar arrangement in which actual video is never stored, just classified and summarized like audio in Siri Recap.

And, of course, one final potential outcome might be that if Apple manages to convince the EU that its system provides an appropriate balance between consumer privacy and security and third-party product design, then it may forge a path through the impasse that currently stops Apple Intelligence from working in the EU. This could be a blueprint of the intermediary architecture Apple originally proposed to the EU when it first introduced Apple Intelligence. We’ll have to see if Europe accepts that.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Unicode 18.0

AbcLinuxu [zprávičky] - 18 Září, 2026 - 16:59
Unicode Consortium, nezisková organizace koordinující rozvoj standardu Unicode, oznámila vydání Unicode 18.0. Přidáno bylo 13 007 nových znaků. Celkově jich je 172 808. Přibylo 9 nových Emoji.
Kategorie: GNU/Linux & BSD

Firefox 156 je rychlejší a v prvních zemích zavádí reklamu

Živě.cz - 18 Září, 2026 - 16:45
Oživeno 18. 9. 2026 | Mozilla najela na dvoutýdenní cyklus vydávání nových verzí, ale i tak dokázal Firefox 156 přinést překvapivé množství funkčních novinek. Integrovaný prohlížeč PDF nyní startuje až o 45 % rychleji než dřív. Zefektivnění se dočkal i dekodér obrázků v JPEGu. Pokud se velká ...
Kategorie: IT News

Secure enterprise sharing with access reviews for Microsoft 365

Bleeping Computer - 18 Září, 2026 - 16:00
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]
Kategorie: Hacking & Security

Microsoft Teams will let admins block custom file extensions

Bleeping Computer - 18 Září, 2026 - 15:58
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]
Kategorie: Hacking & Security

More and more people believe that AI will take away jobs rather than create new ones

Computerworld.com [Hacking News] - 18 Září, 2026 - 15:58

A new survey from the Pew Research Center shows that a majority of people worldwide now expect artificial intelligence to lead to fewer jobs rather than more. The survey is based on responses from 37 countries. In 34 of these countries, it is more common to believe that AI will result in fewer jobs over the next 20 years. Concerns are greater in wealthier countries.

In Sweden, for example, there are signs of growing skepticism toward the technology. The proportion of Swedes who are more concerned than enthusiastic about the increased use of AI has risen by nine percentage points in one year. This is the largest increase among the countries compared over time. Concerns have also increased among both younger and older Swedes.

In the US, 71% of respondents said they think AI will lead to fewer jobs over the next 20, compared to 5% who say it will lead to more jobs. Most pessimistic were the Australians, with 76% predicting fewer jobs because of AI. The most optimistic groups were in Nigeria and the Philippines, where just 26% of respondents predicted AI-induced job losses outweighing gains.

Globally, many also fear that AI will widen economic disparities. In none of the 37 countries do more than a quarter of respondents believe that AI will reduce inequality.

However, views on the technology are not entirely negative. The median for the 37 countries shows that 41% say they feel roughly equal amounts of concern and enthusiasm about the technology. People who have heard and read a lot about the technology also tend to have a more positive view of it.

This article was originally published on Computer Sweden.

Related:

Kategorie: Hacking & Security

Česko na jaře vyrobilo 21 % elektřiny z OZE a konečně není nejhorší. Je předposlední v EU

Živě.cz - 18 Září, 2026 - 15:43
Země EU v prvním čtvrtletí letošního roku vyrobily 46 % elektřiny z obnovitelných zdrojů. Česko se tehdy umístilo hned za Slovenskem a Maltou na 27. místě, a tak jsme byli zvědaví, jestli se něco změní v druhém kvartálu. Tou dobou se už totiž naplno rozjížděly fotovoltaické farmy, kterých je u nás ...
Kategorie: IT News

Webinar: Which Google Workspace security controls actually matter?

Bleeping Computer - 18 Září, 2026 - 15:10
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. [...]
Kategorie: Hacking & Security

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

The Hacker News - 18 Září, 2026 - 14:47
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network," Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Na světě je devět nových emoji. Už můžete poslat gumu, meteor nebo nakládanou okurku

Živě.cz - 18 Září, 2026 - 14:45
Po roce vyšla nová verze nejrozšířenější znakové sady. Unicode 18.0 přidal 13 007 nových znaků a tři nové druhy písem – protoklínové, džürčenské a pečetní. Především ale rozšířil sadu emoji o dalších devět kousků. Letošní sestava přidává praskající obličej, palec směřující napravo a nalevo, ...
Kategorie: IT News

Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

Bleeping Computer - 18 Září, 2026 - 14:16
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]
Kategorie: Hacking & Security
Syndikovat obsah