Vista elenco

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

14 Agosto 2026 ore 20:48
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400

Commentaires sur Transiscope, au-delà de la carte par Evelyne vaquero

Il y a une masse de points de vue mais politiquement c’est vague. Écologie, anti faciste, commun culturel mais basé sur quoi il n’y aura pas de transformation sociale sans collectif. Pour moi tout est politique et les tribulations d’une bande d’intellos bobos ca manque de pep, c’est un entre soi qui m’emmerde un peu. Reunir des artistes (je suis peintre )oui mais ne pas s’isoler des milieux populaires qui sont les proies idéales du FN. J’ai lu vos commentaires des uns et des autres mais je ne vois pas de dynamisme pour secouer ces sociétés ultra capitalistes et fascistes. No pasaran. Vous ne parlez pas du genocide en cours sous nos yeux. Dommage

IAM Compliance Requirements and Best Practices

14 Agosto 2026 ore 19:19
IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can

Russian missile uses Nvidia AI chip to help target Ukraine

14 Agosto 2026 ore 18:52
Sanctions and Nvidia’s exit from Russia in 2022 haven’t stopped its Jetson Orin hardware from turning up in Russian weaponry, according to Ukrainian military intelligence. The Defense Ministry’s Intelligence Directorate (GUR) reported this week that it spotted an Nvidia Jetson Orin module in the remains of a Russian S-71 Monochrome cruise missile. The S-71M is an air-launched weapon with autonomous capabilities that can reportedly search for and engage targets using optical sensors and onboard computing. “The use of this component may indicate the use of artificial intelligence technologies in the missile,” GUR said. That assumption makes sense, as information on the S-71M suggests that it can operate with user oversight or entirely autonomously. Photos included with the GUR announcement show a heavily scorched Nvidia chip with the identifier TE980M-A1 stamped onto its surface, indicating that the chip is a Jetson Orin NX 16GB unit that Nvidia released in early 2023. It’s a capable chip, but not exactly datacenter-class hardware - Orin systems are designed precisely for use cases like autonomous systems. Nvidia used to have offices in Russia and do business there, but it closed up shop in Ukraine’s bellicose neighbor in 2022 following Moscow’s decision to go to war with Kyiv. That was prior to the introduction of the TE980M-A1, meaning it must have reached Russian hands through another channel after Nvidia stopped direct sales to the country in early 2022. In other words, whatever sanctions the US has enacted or business decisions Nvidia has made, its hardware is still turning up in Russian weaponry used to target Ukrainians. The one good thing about the entire affair, according to GUR, is the fact that the recovered hardware proves Russian tech manufacturing still isn’t up to snuff. According to Nvidia, Orin modules are consumer grade and are sold to all sorts of different people for all sorts of purposes, with military applications not being among their intended design. The chips aren’t supposed to be available in Russia, either, a spokesperson told The Register, adding that there are plenty of ways for Russia to get ahold of the chips that are out of its control. “Pre-owned Jetsons are available through many reseller channels,” Nvidia told us. “Although we cannot track products after they are sold, if we determine that any customer is violating U.S. export controls, we will take appropriate action." US export controls have restricted exports of advanced chips to Russia and China. Chipmakers have responded to China-specific restrictions by producing hardware designed to comply with US export rules, while third parties have allegedly used smuggling to get restricted higher-end components into China. It’s not clear how the Nvidia component ended up in Russian hands. GUR’s latest disclosures also document Chinese-made electronics in Russian weapons. However the salvaged chip made its way to Russia, GUR said its evidence shows that current export control regimes aren’t working. “The discovery of Nvidia Jetson in a new Russian missile once again demonstrates the need for increased sanctions pressure and coordination of the efforts of the civilized world,” the intelligence agency said. ®

Trump sends the US Navy back to the steam age

14 Agosto 2026 ore 18:22
President Trump has ordered the US Navy to draw up plans to replace electromagnetic aircraft catapults and weapons elevators with old-fashioned steam and hydraulic systems. America’s commander-in-chief issued a presidential memorandum directing the secretary of defense, in consultation with the secretary of the Navy, to come up with a plan to replace the Electromagnetic Aircraft Launch System (EMALS) on the future USS Doris Miller (CVN-81) with the older steam-powered system. The same note stipulated the replacement of the electromagnetic Advanced Weapons Elevators with the hydraulic versions used in older carriers. These directives were part of a broader memorandum aimed at shaking up shipbuilding for the US Navy, which is often seen as glacial and moribund. EMALS was introduced on the USS Gerald R Ford (CVN-78), which was the first of an improved design of US aircraft carriers. It basically uses a linear induction motor to accelerate an aircraft along the flight deck, in place of the old-fashioned system that employs a steam piston. The premise of EMALS is that it doesn’t require a head of steam, and as it is electromagnetic, it should be easy to adjust the power to match the size and weight of aircraft being launched. However, the technology has had a few teething problems, as reported by The Register previously, and these have even led to the Gerald R Ford being unable to launch aircraft at all. The Advanced Weapons Elevators, which also use linear motors, have likewise proven problematic. Earlier this year, it was reported that there was a study underway to review the Ford-class carrier design and determine whether it should be altered for the next two in the class. “We are looking at 82 and 83 to review the costs, the designs, the systems, to make sure that they make sense, and they have all the systems and requirements that we want going forward,” then-secretary of the Navy John Phelan is quoted as saying. One of the concerns was said to be with the sortie generation rate of the Gerald R Ford – the number of takeoffs possible - which was promised to be higher with EMALS. We asked the White House if this directive would apply to all subsequent US carriers, but a spokesperson simply referred us to the announcement, which mentions only CVN-81. The rest of the president’s memorandum takes aim at naval shipbuilding in America. One directive is to establish a fifth naval shipyard to increase submarine and aircraft carrier repair capacity. Trump is also sanctioning foreign involvement in building up to three ship classes of US Navy vessels. His memorandum directs the secretary of defense to come up with “a new competitive acquisition approach” for surface combatants to perform anti‑submarine warfare, surface warfare, and convoy escort duties, plus Consolidated Cargo Replenishment at Sea (CONSOL) tankers and Roll-On, Roll-Off vessels – the latter typically used for transporting tanks and other military vehicles. The president proposes using a similar approach to the memorandum of understanding (MoU) between the US and Finland with regard to acquiring icebreaker ships last year. This will allow foreign suppliers to take part in US Navy procurement, provided they agree to build a new shipyard in America or assume ownership or a majority stake in an existing one, and construct all ships after the first two in US shipyards. Tellingly, the memorandum states that the US Navy “shall not impose iterative design changes upon the original mature parent designs within the above programs,” and that no changes from the original designs shall be made without the approval of the secretary of defense. Last year, the Trump administration canned the Constellation-class frigate program, which had been based on an Italian design to reduce technical risk, after so many changes were made that the US design had just 15 percent commonality with the original and the program was years behind schedule. ®

The 80% Problem: Why AI resilience is more important than ever

14 Agosto 2026 ore 17:38

AI has been transformational for the workplace, saving time on repetitive tasks and freeing skilled staff to focus on higher-value work. It has become so embedded in organisations that ISACA’s research recently found that 82% of European companies expressly permit the use of AI at work.

However, there is a difference between using AI and governing AI use safely. Only 42% of organisations have a formal AI policy in place, and one in five (20%) don’t know who would be accountable if an AI system caused harm.

To further complicate things, it turns out that Microsoft Copilot now sits inside 80% of organisations using AI at work, well ahead of ChatGPT (56%), Gemini (37%), and Claude (21%). That means the majority of companies using AI are depending on just one vendor as an executive assistant, IT support, and sounding board.

In practice, this means that most of the business world is leaning on a single AI provider, with little planning for what happens if that provider is compromised or experiences an outage.

We use AI professionally and personally so much that, for many organisations, it is easy for compliance to become an afterthought. A tool people rely on daily doesn’t feel like a security risk – even when it is.

Leadership needs to challenge this by asking: what happens if this tool goes down, and what happens if it’s compromised? Some analysts expect over 200 high-signal disruption days across AI platforms this year and the negative impact that this will have on organisations’ productivity is considerable. Once staff begin to rely on AI-generated first drafts and summaries, reverting to manual work isn’t impossible, but it isn’t frictionless.

An over-reliance on AI – particularly on individual AI tools – can create a false sense of security, and the AI governance gap only gets worse when things go wrong. Three-fifths (59%) of companies do not know how quickly their organisation could halt an AI system in the event of a security incident, and only a fifth (21%) said they could do so within half an hour.

When a tool people rely on every day goes down, staff don’t stop working – they improvise. More than a quarter (26%) of organisations use no risk framework for AI at all, so when something does go wrong, there’s often no process to fall back on. That often means turning to whatever other AI tool is at hand, personal accounts, unapproved apps, and work-arounds that nobody has checked, at exactly the moment when careful handling of data matters most. This is why the fallback plan must exist before it’s needed, rather than being invented on the fly. The outage isn’t really the risk – how people cope during the aftermath is.

EU regulators have recognised and begun to address the AI governance gap, formally naming major cloud and AI providers, including Microsoft, as critical services to finance under the Digital Operational Resilience Act (DORA). Other sectors should expect similar action in line with NIS2 and the UK Cyber Security and Resilience Bill as the concentration risk argument spreads beyond finance.

What can businesses actually do about the AI governance gap? Firstly, they should review their AI use and record which important day-to-day work depends on a single AI tool. Where possible, they should try to diversify their provider use in order to mitigate the knock on effect of an outage.

This should be done as early as possible, as swapping AI providers isn’t like switching a light-touch SaaS tool. Foundation model capability sits with a small number of providers, so diversifying means retraining workflows and testing outputs.

Businesses should then look at their continuity plan and consider what the next steps are should their AI tools suffer an outage. Every organisation using AI should have a designated team that is responsible for managing an AI outage. But assigning ownership alone isn’t enough. Organisations also need a structured, maturity-based approach that embeds governance, accountability and resilience into day-to-day AI operations. Frameworks such as CMMI AIM provide a practical way to assess current capabilities, identify gaps and improve governance over time. That is not a decision that should be made mid-crisis, but before anything happens.

A backup option is also essential for operations that can’t afford to be put on hold until the AI is operational. Staff should be made aware of this contingency plan so that if their usual AI tool is unavailable, they don’t reach for something less secure out of habit.

This kind of business foresight is what will prevent your most useful tool becoming your biggest cybersecurity oversight.

None of this is to say that businesses should not use AI – rather that AI should be treated like any other critical part of the business, with a plan for when things don’t go smoothly. A designated owner and a tested fallback plan won’t stop the next outage, but it will decide whether it’s a minor disruption or a major one.

 

The post The 80% Problem: Why AI resilience is more important than ever appeared first on IT Security Guru.

The first domino of AI disruption: How frontier models are revolutionising software security

14 Agosto 2026 ore 16:40

Jimmy White, Chief Technology Officer, AI Security, F5

The first domino has well and truly fallen. The advent of high-powered AI models that can rapidly find software vulnerabilities that have lain hidden – in some cases, for decades – effectively makes static code analysis the first significant problem to be solved by AI.

The first-, second-, and even third-order effects of models such as Anthropic’s Claude Mythos Preview and ChatGPT 5.4-Cyber by OpenAI are the hottest topic in enterprises globally, for good reason. By pairing powerful AI with huge volumes of code data and existing vulnerability databases, these models know what good and bad code looks like, and can cycle through code at machine speed to find bugs and security issues.

Put simply, there has never been anything better than these AI models at detecting vulnerabilities in source code; they are highly capable tools that outperform all current best-in-class solutions. Their ability equates to a human coder that knows every existing disclosed software flaw, can read as fast as a computer, has perfect memory, and has 100% recall in milliseconds.

The potential and limitations of frontier models

There are already countless examples of the models finding real-world software vulnerabilities that have lain dormant for long periods but never known. There are also likely to be flaws that are unknown to their host company but are being abused by threat actors behind the scenes – a known tactic of attackers who want to keep their best weapons under wraps.

Most recently, there are eye-opening incidences of test models chaining together attacks or breaking their boundaries, such as the OpenAI models that accessed Hugging Face from a sandbox environment. Anthropic is investigating three incidents where Claude test models accessed the internet and breached the systems of outside organisations.

What does it all mean for already-stretched IT security teams and the industry as a whole? First, the utopian scenario: organisations with access to these models can rapidly find all the vulnerabilities in their existing code base and go about fixing them, reaching a better security posture. At the same time, all their new code can go through the models, so there is no ‘bad’ new code, no new security vulnerabilities.

Enterprises can also apply the models at all the entry points for potentially harmful code into their organisation. Any open source tools can be checked before usage; in M&A scenarios, acquirers can insist on the code base of potential acquisitions going through the AI models; companies can evaluate the source code of vendors that want their business; and so on.

However, the utopian thesis quickly breaks, for two reasons. One is that the AI models are performing static code analysis. Yes, that’s a very big, important thing, but it’s not everything; there are still many flaws that AI can’t find because it can’t understand the patterns in runtime or race conditions.

Secondly, and maybe more importantly, because AI makes coding easier, enterprises around the world will undoubtedly be generating exponentially more new code. Google says that 75% of its new code is AI generated; at Anthropic and other AI-native companies, the proportion is as high as 90%. So, the speed that new code – and new vulnerabilities – are being created will at least match the speed these powerful models can find those vulnerabilities.

Static code analysis is just the opening act

For now, access to frontier AI models is limited, allowing participating organisations to find and fix bugs before they can be exploited in anger. But the frontier model companies have been frank that these models present unprecedented attack capability, as demonstrated in the Hugging Face incident, making them dangerous in the hands of a bad actor.

This is a familiar pattern in AI: each time the technology catches up from a cyber defence perspective, it offers similar advancements from an offensive perspective. As an industry, we are in an established cycle of ‘leap ahead, catch up’, a game of leapfrog between defenders and attackers as both sides advance their capabilities.

For the AI model makers, there is another aspect to the story. Source coding itself looked set to be the first market to be ‘cracked’ by AI, but it remains imperfect and still requires human input and oversight. In static code analysis, the frontier model companies have found a market they can dominate, defying the naysayers who question the enormous investment in AI and the technology itself.

Anthropic was first to this particular market, but OpenAI and other frontier model companies were quickly out of the blocks. Open-source models will similarly reach the bar for effective code vulnerability scanning, sooner rather than later.

Other markets will follow too. Anthropic’s collaboration with Canva, the design software company, and the launch of Claude Design signal is another example of a market that will be disrupted by the application of powerful AI to existing practices.

The AI giants are becoming surgeons, not general practitioners

In the Western world, there are now five titans in the AI arena: Anthropic, OpenAI, Google, Meta and xAI. They are going toe-to-toe with regular improvements in their models, opening up the prospect of a new class of specialised AI models for specific tasks that have practical – and financial – value.

Each time one of these players picks a new thing to focus on, it is a signal to where there’s market value. Sometimes they will choose the same market, but sometimes they will go for unique ones, maybe niche to their business area.

What those markets are will partly be decided by the model companies’ access to relevant datasets. Because of the popularity of its models with coders, for instance, Anthropic had access to an enviable source code dataset for training Mythos Preview.

Meta and xAI have access to vast social and communication data, though the nature of their data is very different. On top of that, search, email and mapping services hold near-infinite amounts of data on how people communicate and where they go.

This is all ripe for disruption by AI, with profound downstream effects. For example, enterprises may be discouraged from choosing a single AI provider as various model makers offer increasingly differentiated capabilities.

Buyers will benefit from competitive tension, but the cost and complexity of maintaining and securing multiple AI models will rise. Enterprises will have multiple subscriptions with multiple providers for different use cases.

AI disruption has only just begun

The static code analysis breakthrough did not happen by accident. The frontier model companies have pointed their currently most powerful models at a 20-year-old problem where they have the training data – and the models perform very well.

They will point the models at hundreds of other 20-year-old problems and do equally well. For the foreseeable future, we can expect massive disruption. This is the first domino to fall; there will be another, and another, and another.

The post The first domino of AI disruption: How frontier models are revolutionising software security appeared first on IT Security Guru.

French tax authority admits data heist after crook touts 2M records

14 Agosto 2026 ore 16:27
France's tax authority has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a purported database of 2 million taxpayers. Using the alias "ZeroBytes," the alleged crook behind the attack on the General Directorate of Public Finances (DGFiP) advertised the stolen database on a cybercrime forum on Wednesday. They claimed the database contained details of more than 2 million French taxpayers and that they gained access using stolen credentials and an MFA bypass technique. ZeroBytes also claimed to retain access to DGFiP's systems and offered to sell it alongside the database. DGFiP did not immediately answer our questions about the attacker's claims. However, in a statement released Thursday, it disputed the claim that ZeroBytes retained access. "On Wednesday, August 12, 2026, a malicious actor claimed unauthorized access to the information system of the French Public Finances Directorate, which occurred at the end of June 2026 following identity theft," it said. "Initial investigations confirm that this access, which had been severed at the end of June as part of an audit, nevertheless allowed the consultation and extraction of data concerning individuals and professionals. "Following this complaint, the French Public Finances Directorate immediately implemented new restrictions to stop the unauthorized access and prevent further unauthorized use. In-depth investigations are ongoing to determine precisely which data and number of users were affected." DGFiP said it would report the attack to French data protection watchdog CNIL and notify affected users once it had determined who they were. The intrusion is the latest in a string of security breaches affecting France's public sector this year. France's Ministry of Finance, which oversees DGFiP, admitted in February that miscreants had accessed a database containing French citizens' bank details. The attackers used stolen credentials and made off with 1.2 million records, despite the ministry saying it quickly revoked their access. A few weeks later, France's Health Ministry confirmed a cyberattack on healthtech supplier Cegedim Santé in which around 15.8 million administrative files were stolen. Around 165,000 of these contained doctors' notes, which in "very limited cases" revealed medical histories. In April, the Interior Ministry confirmed reports of an attack on France Titres, the government agency responsible for identity documents including passports and driver's licenses. The alleged culprit, reportedly a 15-year-old, advertised the stolen data online and claimed the breach affected between 18 million and 19 million people – more than a quarter of metropolitan France's population. In June, the department responsible for Tchap, France's encrypted government messaging platform, investigated a suspected breach. The alleged attackers claimed to have accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms. ®

Virgin Galactic flights stay paused while ticket prices head for the Moon

14 Agosto 2026 ore 15:45
Virgin Galactic has delayed its return to commercial spaceflight until February 2027, and plans to raise ticket prices later this year. The delay was disclosed alongside the company's financial results, which showed a net loss of $56 million for the second quarter of 2026, down from $67 million a year earlier. Revenue for the quarter was $0.1 million, compared to $0.4 million in 2025. According to CEO Michael Colglazier, demand exceeded the number of seats offered in the first $750,000 batch, prompting the company to prepare another at a higher price. Those customers will, however, have to wait a little longer. Colglazier said: "Our first ship is now expected to enter commercial service in February 2027 rather than the fourth quarter of 2026." He blamed the delay on the extra time needed to "complete avionics and systems installations." During an earnings call, Colglazier said: "No single issue is driving the schedule push. Rather, we have experienced modest time duration extensions across hundreds of relatively small but important installation tasks involved in the first build of our new spaceship." In response to an analyst question, Colglazier elaborated: "The number of those kind of 'Oh, we did not expect this to not fit just perfectly,' coming in is higher than we had allotted for. That just has started to accumulate on us. It really picked up at the tail end of July. For a bit, we thought we could manage that end, but the team just needed more time to do it the correct way." Integrated vehicle ground testing is expected to begin later in August, followed by flight testing in October. A second spaceship is due to join the fleet in March 2027, and the company expects to stop burning cash and "deliver positive quarterly cash flow within 2027." When Virgin Galactic reopened suborbital ticket sales in April, it charged $750,000 for a seat, up from the $600,000 price it cited in 2023. That was a substantial jump from the $100,000 envisaged more than two decades ago, when Sir Richard Branson announced plans for a scaled-up version of Burt Rutan's SpaceShipOne. At the time, the company said commercial flights would resume by the end of 2026. Virgin Galactic's last commercial flight took place in 2024, after which the company paused operations to focus on its next generation of spacecraft. Virgin Galactic is not alone in pausing its space-tourism service. Earlier this year, rival Blue Origin announced that New Shepard flights would pause for "no less than two years" while it worked on its crewed lunar program. ® Updated 8/18 at 10:19 GMT: A previous version of this story said that the program was "grounded," but the more appropriate term is "paused."

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

14 Agosto 2026 ore 15:08
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan,

Autonomous AI attacks pose 'clear and present danger' to critical infrastructure

14 Agosto 2026 ore 15:03
In early July, attackers used open source AI agents to autonomously hack government systems and energy companies, signaling to defenders that AI-powered attacks against critical infrastructure are no longer theoretical. "There is a clear and present danger," Tom Kellermann, TrendAI VP of AI security and threat research, told The Register. "As the geopolitical tension boils, systemic destructive cyberattacks launched by autonomous AI will occur," he said. "Weaponized AI will disable the safety systems of critical infrastructure, thus leading to kinetic disasters. Just like we see autonomous strike vehicles operating on the battlefield in Ukraine, we should expect autonomous weaponized AI." In fact, the prospect of attackers using AI against critical infrastructure was the top concern of every national security adviser, law enforcement official, and private-sector threat analyst The Reg spoke with at last week's Hacker Summer Camp conferences. "It's the targeting of critical infrastructure for us," Brett Leatherman, assistant director of the FBI's Cyber Division, told us during an interview at Black Hat. "We're very focused on the downstream impact targeting of critical infrastructure," Leatherman said. "That is where cyber becomes kinetic, and whether it is our water and wastewater treatment plants, whether it's the electric grid, whether it's the high-frequency trading networks and the financial networks, all of those, if the integrity of those are compromised, will have significant impact to communities and national security. So that's what keeps our teams up at night. How are we moving to secure critical infrastructure?" Where cyber becomes kinetic During the first four days of July, suspected Chinese operators aimed an attack framework built on Hermes and OpenClaw AI agents at targets in Taiwan. Across 12 "attack waves," the "near-autonomous" system deployed up to eight sub-agents, each assigned its own targets and techniques, and broke into a Taiwanese government website. Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities while stealing sensitive data, credentials, and other secrets as they moved across the network. The Taiwanese government intrusion also followed a series of cyberattacks against water and wastewater utilities in the United States. While the Trump administration hasn't attributed these to a particular government or group, private sector threat hunters – including Halcyon Ransomware Research Center SVP Cynthia Kaiser, a former FBI cyber division deputy assistant director – blame Iran for these intrusions. Military conflicts spilling into cyberspace are nothing new, but these cyberattacks in America brought the war with Iran to more than 30 small-town water systems in Minnesota and targets across nearly a dozen other states. To be clear, there's no evidence that attackers used AI to hack these water utilities. Most were small, community systems that left programmable logic controllers (PLCs) directly exposed to the internet using default or weak passwords. Still, these breaches expose "40, 50 years of tech debt," former US National Cyber Director Chris Inglis told The Reg during an interview at Black Hat. This technical debt – deferred maintenance, unpatched or end-of-life systems, and delayed security updates – expands the attack surface and gives intruders more ways into critical systems, threatening operations and potentially disrupting services people rely on every day. "The water sector attacks – regardless of who is doing them – is taking advantage of unpatched vulnerabilities in the PLCs," Inglis said. "We've known about these particular vulnerabilities for years now, and yet we've not done anything about them because they're low-level, not easily accessible." Inglis added that there's no indication the digital intruders used AI to exploit these PLCs. 'There's an alligator in the boat' However, AI systems allow attackers to cash in on tech debt, and they don't need access to frontier models to do it. Free, open-weight models also excel at finding bugs in software and configurations, chaining these together, and abusing them to break software and systems. Earlier this summer, University of Toronto researchers used an unnamed publicly available open-weight model, released in 2025, to develop a computer worm that they claim spread through an enterprise test network. The self-propagating code adapted on the fly to identify known vulnerabilities and misconfigurations on target systems, then generated and executed attacks to move laterally through the network and compromise additional machines. "Commodity models can do that, and many of the vulnerabilities they find do not require access to the source code – it's in the configurations, and configurations change over time," Inglis said. When it comes to attackers abusing AI systems, "I wouldn't be worried about the frontier models," Inglis said. "Worry about the models that are already on the street. Turns out there's an alligator in the boat, and it's the commodity models." Plus, as we've seen in previous breaches, both government-backed goons and criminal groups increasingly use AI to automate reconnaissance. Security analysts worry that the technology could also help attackers acquire expertise in industrial control systems (ICS). When OT knowledge becomes a commodity "What protects ICS? More than anything, it's obscurity," said John Hultquist, chief analyst at Google Threat Intelligence Group, during a press briefing at Black Hat. "It is an obscure, esoteric, knowledge set that a handful of people – I call them uber nerds – have, and that attackers rarely have the necessary knowledge to carry out. That's no longer the case. That knowledge is simply on tap." AI tools mean miscreants don't need to be ICS or operational technology experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. "There have been threat actors who are capable of this at the top level, like China and Russia," Hultquist said. "But now I'm afraid the actors who are just a couple steps down – North Korea, Iran – who don't have the same focus on that technology are going to have far greater success. They're going to have the tools necessary to be as aggressive as they want to." During what was probably the most talked about Black Hat briefing of the week, OpenAI employees provided more details about how their models escaped their training pens, went rogue, and hacked Hugging Face to complete a security evaluation. We learned the AI agents spent months asking other agents for help, building message boards, developing their own communication protocols – essentially creating a hive mind to carry out the attack. "In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here," OpenAI technical staffer Michael Dalton said. Retired general and former NSA chief Paul Nakasone, speaking to reporters at DEF CON, called the Hugging Face attack "an inflection point in terms of AI-generated, autonomous cyberattacks." "This is the challenge: that we have to, over the next several months, get the defensive side much quicker and much better than they are today," he added. Therein lies the challenge: offensive uses of AI appear to be advancing faster than autonomous defenses, and attackers don't face the legal and ethical constraints imposed on defenders. "I think we're still a ways out from having swarms of autonomous, defensive agents fighting attacks," Ryan Whelan, global head of Accenture Cyber Intelligence, told The Reg at Black Hat. "That's probably over a year out over the horizon. But I do think we're going to see it first on the adversary side, because they don't care if they break things." Kellermann quoted Victor Hugo: "Not all the armies of the history of the world can stop an idea whose time has come." "That idea," he said, "is weaponized AI. Shields up." ®

Less than a year on, Microsoft tells Mico to pipe down

14 Agosto 2026 ore 14:16
Microsoft has yanked Mico from the Copilot spotlight less than a year after unveiling the anthropomorphic assistant intended to make its AI a little less soulless. As part of Microsoft's announcement that its consumer and work Copilot applications will merge, the company confirmed that the weird blob thing would shuffle out of Copilot Voice and into Learn Live, a voice-based study mode that guides users through subjects and assignments. "Mico helped us learn about warmth, expressiveness, and how people want to talk with AI," Microsoft wrote. "Those learnings are shaping Copilot going forward." "Learn is where the character has the most room to grow, with tutoring sessions that give Mico more to react to and teach through." As the update rolls out, Mico will no longer be the face of Copilot Voice. Users can still speak to Copilot and receive responses, but will be spared the blob's gurning. Mico is only the latest in Microsoft's long line of anthropomorphic assistants. There was Clippy (or Clippit), which arrived with Office 97 but had been pushed into Microsoft's desk drawer of doom by the time Office 2007 appeared. Then came Cortana, named after the character from the Halo video game franchise and pitched as a far more intelligent assistant. Microsoft introduced Cortana on Windows Phone in 2014 and brought it to PCs with Windows 10 the following year, before losing interest. Mico didn't even last a year as the face of Copilot Voice before Microsoft pulled it from the spotlight, although both the character and its Copilot "brain" live on in Learn Live. In terms of lifespans, it's easy to compare it to the catastrophic Microsoft Bob, which was launched in 1995, with the last release happening that same year. However, the product lingered a little longer and later resurfaced, hidden as digital ballast on the Windows XP installation CD for licensing and encryption. Modern digital distribution means that such a second life is unlikely to await Mico. Dave Plummer, the engineer responsible for Bob's inclusion as an encrypted blob, said: "What's ultimately important is that while Bob never got to play on the big stage, he always followed the band around and got to ride on the bus." Mico hasn't been thrown off the bus just yet. Microsoft has merely made the blob sit with the schoolchildren. ®

TalkTalk Business and ARO to borg into UK tech services giant

14 Agosto 2026 ore 13:44
TalkTalk Business and UK technology services biz ARO plan to merge, creating what they say will be one of the country's largest communications and managed services providers. The pair claim the combined organization will be "uniquely positioned" to serve as a single technology partner for British firms pursuing digital transformation. It will have annual revenue of about £200 million ($270 million) and a combined customer base of more than 70,000 companies. Analyst firm Megabuyte noted that ARO, formerly known as Arrow, is the larger of the two businesses by earnings. However, the vast majority of the combined customer base will comprise TalkTalk Business's small-business clients, with the remainder mainly ARO enterprise customers. Megabuyte expects fixed-line and mobile communications and connectivity to generate most of the combined revenue – about £130 million ($176 million) – with IT and cybersecurity services providing the remainder. Megabuyte said the immediate priority would be integrating the businesses and finding opportunities to sell their services across the combined customer base. "One can see why the deal is being sold in terms of cross-sell, with relatively little overlap in terms of customers and products. TalkTalk Business has a large base of small business customers who should be receptive to ARO's mobile and Microsoft offerings, as well as other IT and cyber services," says chief analyst Philip Carse. TalkTalk Business completed its separation from the wider TalkTalk Group earlier this year as it sought to expand as an independent managed network provider. It recently acquired Planet IT, a service desk biz selling IT support and professional services. ARO provides cloud, cybersecurity, and datacenter services and is a Microsoft Solutions Partner. The two firms describe their operations as highly complementary. The deal remains subject to approval under the UK's National Security and Investment Act (NSIA), apparently because ARO supplies some government customers, and is expected to close by the end of the summer. Initially, both businesses will retain their existing brands and offices while the companies develop their integration plans. The implication there is that there could be a shake-out of duplicate products and staff roles coming later, as often happens with corporate mergers. We asked what the combined business would be called and who would lead it, but the companies declined to answer. "This is a defining moment for both ARO and TalkTalk Business," claimed ARO chief Ciaran Rafferty. "By bringing together our complementary strengths, we are creating a stronger partner with broader capabilities, deeper expertise and greater capacity to invest in innovation, service delivery and long-term customer success." TalkTalk Business CEO Ruth Kennedy said it represents a key step in the firm's ambitions to become a leading managed services provider. "The market is evolving rapidly, with organizations increasingly seeking technology partners that can combine strategic expertise, operational excellence and broad service capabilities at scale," she commented. ®

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

14 Agosto 2026 ore 13:57

Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption.

The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities appeared first on SecurityWeek.

Who’s Tracking You? Use This New Service to Find Out

14 Agosto 2026 ore 13:24

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

A Decryptads summary of the advertising partnerships declared by espn.com.

The newly launched decryptads.com says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:

ads.txt: all of the adtech companies and data brokers that may run ads or harvest data from the site;
app-ads.txt: entities that can harvest data from or display ads on mobile and smart TV apps;
buyers.json/sellers.json: the entities buying, selling or reselling ad inventory for a given site or app.

Zach Edwards is chief research officer for DecryptAds and a threat researcher at the security company Infoblox. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”

Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI-generated slop websites and apps. And as decryptads.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps.txt or app-ads.txt file.

“Supply-chain integrity issues rarely live in a single file,” the site explains. “They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.”

A search in DecryptAds for the hugely popular sports network espn.com reveals 143 ad partners and 19 registered data broker domains are listed within its ads.txt and app-ads.txt files. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.

A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.

HIGH-RISK AD PARTNERS

DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in “geo-risk” areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates (UAE).

According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm Between Digital, which lists a New York address. However, the dossier on Between Digital flags them as a Russian firm, showing that their publisher offers (PDF) are processed through Alfa Bank, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from both Between Digital and the company’s founder, and will update this story in the event that either replies.

A search for several top U.S. military news websites — including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com — shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

The “Geo Risk” section of decryptads.com.

Pivoting on Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards said Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of their portfolio.

“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards told KrebsOnSecurity. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”

The Opera Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech (the operational headquarters of Opera remain in Oslo, Norway).

Opera.com’s profile at DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.

LEGAL DOSSIERS

One feature of DecryptAds that sent this author down multiple hours-long research rabbit holes is its Legal Dossier lookup, which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.

For example, last month KrebsOnSecurity wrote about researchers from Bitsight who found that an extremely popular line of TV streaming sticks called H96 quietly rent out each user’s Internet connection to strangers. Bitsight also discovered that when these devices aren’t being used to stream pirated video content, they are spoofing themselves as mobile phones clicking ads on AI-generated slop websites.

Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the Fengwo Group — also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones.

Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.

A DecryptAds legal dossier on the (now dormant) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above (medicalbeautyhub dot com) shows it shares a seller ID (1674071) with a gaming website — giacoloredstones[.]com — which features yet another seller ID (103488000).

Pivoting on that latter seller ID reveals hundreds of active websites within Russia’s Yandex ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads.

QUIET REMOVALS

Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions.

This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others. To address that visibility gap, DecryptAds features a quiet removals feed that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name.

A screenshot of the Quiet Removals Feed at decryptads.com.

“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”

MALVERTISING AND AI SLOP

Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all-too-frequent occurrence in the modern adtech industry. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads.

“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.”

Edwards said the AI slop websites are populated with machine-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website’s ads.txt or app-ads.txt file.

“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” he said.

Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data-sharing by the major ad networks. Specifically, he says those platforms do not broadly share what’s known as the “supply chain object” or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer.

“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained. “You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”

DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms.

WHAT CAN YOU DO?

The only sane reaction to the examples described above is to block all online ads outright. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world.

However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions. For those primarily surfing via a regular desktop or laptop Web browser, uBlock Origin Lite is an excellent free and well-maintained open source option. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android-based devices.

Adblock Plus is a decent option for iPhone and iPad users. For power users, Adblock and uBlock Origin both support custom blocking rules from easylist.to, which publishes a frequently updated list that removes most advertisements from webpages.

The well established browser extension NoScript blocks all non-approved Javascript code, and it generally does a fine job blocking most ads from loading. However, script blockers like NoScript may not be suitable for average users who don’t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly.

More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it. A tiny, low-cost and broadly available computer known as a Raspberry Pi can be turned into a powerful ad blocker for all devices on a local network when fitted with a microSD memory card and a free program called Pi-hole. Once you’ve set it up properly and changed your router’s network settings to use the Pi-hole’s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content. But in my experience, they’re not doing this because the user experience is somehow way better on the app (as LinkedIn tries to convince us non-app users several times a week via email). On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser.

No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) far more precise data about who, what and where their users are. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days. So be cautious about the apps you install on your mobile devices (including any smart TVs!), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms.

Keeper Security Issues Cyber Guidance for Education IT Teams

14 Agosto 2026 ore 13:21

Keeper Security has urged schools, colleges and universities to strengthen their cyber defences ahead of the new academic year, warning that AI-powered phishing and a growing number of unmanaged machine identities are widening the education sector’s attack surface.

The identity security and privileged access management (PAM) provider said the annual rush to provision accounts, issue credentials and connect new devices creates a particularly attractive window for cybercriminals.

At the start of an academic year, IT teams can be responsible for onboarding thousands of students, faculty and staff while simultaneously enrolling devices and integrating third-party applications. Keeper warned that this combination can increase the likelihood of misconfigurations, stale credentials and excessive access going unnoticed.

Education institutions are already frequent targets for ransomware, credential theft and data breaches, in part because of the valuable information they hold, ranging from student and financial records to academic research.

Keeper said the threat is being compounded by relatively low levels of security awareness. Its research found that just 14% of schools mandate security awareness training, while almost one in five students and parents reported reusing passwords across personal and school accounts.

Artificial intelligence is adding another layer to the problem. AI-generated phishing messages can imitate communications from IT helpdesks, student funding departments and senior university figures with greater accuracy, potentially removing many of the spelling, grammar and formatting mistakes traditionally associated with phishing campaigns.

Deepfake technology also gives attackers the ability to impersonate trusted individuals through voice and video.

According to Keeper research, 52% of education leaders identify deepfake impersonation as a major concern, but only 26% are confident in their ability to recognise AI-enabled threats. The company also found that 41% of institutions reported being targeted by AI-generated phishing attempts or misinformation campaigns.

Beyond attacks targeting students and staff, Keeper highlighted what it describes as a less visible threat to education environments: non-human identities (NHIs).

These identities include service accounts used to synchronise student information and learning management systems, API keys connecting third-party EdTech applications, machine certificates authenticating connected equipment and cloud identities supporting automated workloads.

Increasingly, the category also includes AI agents and bots used for functions such as admissions, IT helpdesks and grading.

Keeper warned that credentials associated with these systems can be overlooked by conventional identity management practices. Service account passwords may remain unchanged for long periods, while API tokens belonging to applications that are no longer used can potentially remain active.

Cloud workloads can similarly accumulate permissions beyond those required for their function, while expired or incorrectly configured certificates can create additional security gaps.

Darren Guccione, CEO and co-founder of Keeper Security, said the education sector needed to broaden its approach to identity security.

“The conversation about education cybersecurity has historically focused on human accounts: students, teachers and administrators,” said Guccione. “But the real blind spot is the vast ecosystem of machine identities that power modern EdTech. Back-to-school is the right moment for education IT teams to take stock of every identity on their network, human and non-human alike.”

Keeper is recommending that education IT teams use the period before students return to review both human and machine access to their environments.

Among its recommendations is enforcing multi-factor authentication (MFA) across student, faculty and staff accounts, alongside deploying enterprise password management to reduce weak, reused and shared credentials.

Institutions should also audit privileged access and remove permissions associated with former employees, expired service accounts and applications that are no longer required, the company said.

For non-human identities, Keeper recommends creating an inventory covering service accounts, API keys, machine certificates, cloud identities and AI agents. Credential rotation policies should then be established, particularly for third-party EdTech integrations and AI systems introduced for the coming academic year.

The company also advised institutions to update phishing awareness programmes to account for increasingly convincing AI-generated communications.

Keeper said its zero-trust and zero-knowledge security platform can be used to discover, govern and rotate credentials belonging to both human and non-human identities. Its KeeperPAM platform additionally provides privileged access controls, session recording and audit capabilities.

As education environments become increasingly dependent on cloud services, connected equipment, third-party applications and AI, Keeper argues that knowing which identities have access (and whether they still require it) is becoming as important as protecting the students and staff behind traditional user accounts.

The post Keeper Security Issues Cyber Guidance for Education IT Teams appeared first on IT Security Guru.

Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

14 Agosto 2026 ore 13:07
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions. The technique assumes that an operator already has code execution on the Windows host and does not involve

Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

14 Agosto 2026 ore 13:00

Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028.

The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek.

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

14 Agosto 2026 ore 12:57
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap, said it

Gitea: disponibili PoC per lo sfruttamento di nuove vulnerabilità

14 Agosto 2026 ore 12:46
Disponibili Proof of Concept (PoC) per 8 nuove vulnerabilità presenti in Gitea Open Source Git Server, nota piattaforma open source utilizzata per l'hosting e la gestione di repository Git, la collaborazione sul codice sorgente, la distribuzione di pacchetti software e l'automazione di workflow di sviluppo tramite funzionalità CI/CD integrate.

Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware

14 Agosto 2026 ore 12:44
Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple began sending threat notifications to users in late 2021.

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

14 Agosto 2026 ore 12:29
Cryptocurrency hardware wallet maker Trezor has confirmed that a breach at one of its shipping partners exposed the personal data of more than 13,000 customers. The company's initial findings suggested the breach was limited to orders placed in certain countries during the previous 90 days. New information indicates that earlier orders may also be affected. The breach exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who ordered Trezor products between May 10 and August 8. An additional 1,947 customers had their names, home cities, and email addresses exposed. Some members of this group may have placed their orders before May 10. "We are verifying this information and the timeframe with ShipMonk," said Trezor. ShipMonk is Trezor's logistics partner. It stores and ships products on the company's behalf and collects the information needed to fulfill orders. ShipMonk is subject to Trezor's 90-day retention policy, which requires partners to delete or anonymize customer data within 90 days of collecting it for an order. ShipMonk did not immediately respond to a request for comment. Trezor markets itself as a purveyor of secure, offline, hardware-based cryptocurrency wallets. With its products, it aims to shield customers from cyberattacks and malicious apps. While it assured customers that its own systems and devices remain secure, Trezor warned that "affected customers could experience an increase in phishing attempts." The exposed details could help criminals craft convincing phishing attempts impersonating banks, crypto exchanges, or Trezor itself. The company said it contacted affected customers directly and advised them to check any communications against information published through its official channels. "Never enter your wallet backup on a website or share it with anyone," Trezor said in an apologetic advisory. "This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses. "We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected." Trezor said in a supplementary social media post, separate from the advisory, that its "top priority" project at the moment is to establish an "Anonymous Delivery" option for customers. The service will allow buyers to complete checkout without linking their home address or real-world identity to an order. Customers using Anonymous Delivery will go through a dedicated checkout, use a nickname or label ID in place of a real name, and have their product shipped to an automated delivery locker instead of their home. The delivery will also come in unbranded packaging with a generic sender label. The carrier will only use email or SMS to send a PIN for the locker. Trezor said the service is gearing up for a September launch in the EU and by the end of the year in the US. Alas, that didn't stop Cake Wallet, a rival crypto wallet, from poking fun at Trezor. "Another rough day for self custody," it Xeeted, before suggesting crypto holders instead use an old smartphone with Cake Wallet installed because "there is no order, no shipping address, or customer data tied to the purchase." ®

Inside Trump’s Failed Hunt for Noncitizen Voters

An illustration depicts a law enforcement press briefing where an official in a suit stands with armed guards behind a round table holding scattered papers, set against a backdrop featuring voting booths on the left and surveillance monitors on the right.
Illustration by Matt Rota for ProPublica. Animation by Henrike Lendowski for ProPublica.

It was late March when Joe Teirab, the second-in-command at Minnesota’s U.S. attorney’s office, received an urgent email from Washington.

The federal government was scrambling to find criminal cases to back up President Donald Trump’s claims that illegal voting by noncitizens was tipping the scales in American elections. Agents from Homeland Security Investigations, a massive federal law enforcement agency, had been dispatched to work leads across the country, including hundreds in Minnesota.

Teirab was already under pressure. In an earlier missive, Nick Davis, a high-ranking Justice Department appointee helping to lead the election fraud crusade, had reminded him the cases were so high priority that Teirab and his staff couldn’t decline to move forward on them without express approval from agency higher-ups. On March 24, Davis demanded a status report — within hours.

Teirab, a former Marine and a Harvard Law graduate who’d run unsuccessfully for Congress as a Republican, responded with a blunt reality check.

“Bottom line up front,” he replied in an email reviewed by ProPublica. After subpoenaing records on about 130 people, only one had been referred for prosecution, his staff had told him. Agents had deluged local election offices with calls and demands for voting histories, demonstrating “a complete lack of understanding” of illegal voting investigations.

“The HSI task force has been disjointed and disorganized,” Teirab wrote. The entire process, he said, had been “dysfunctional.”

Since Trump regained the White House, his administration has launched a series of unprecedented initiatives to find and prosecute voting by noncitizens, which he’s long claimed, without evidence, is rampant.

He’s stepped up this push in recent weeks, saying in a nationally televised speech that the American election system was “so vulnerable that no one can possibly defend it.” To support that assertion, the Department of Homeland Security, HSI’s parent agency, released documents asserting it had found more than 250,000 noncitizens on voter rolls in just four states, all led by Democrats. The documents included no explanation of how that number was calculated.

It’s well known the administration has tasked HSI — a force established to combat drug cartels, terrorism and other cross-border criminal enterprises — with leading the campaign to find election fraud cases in the United States.

But an investigation by ProPublica reveals for the first time how the Trump administration came to harness HSI’s personnel, technology and sweeping legal authority in service of its election agenda — and how meager the results have been, despite the prodigious resources sunk into the effort.

According to interviews and internal emails reviewed by ProPublica, career staffers at the Justice Department warned that transferring voter rolls to HSI to enable it to search for noncitizen voters could violate federal privacy laws. Similarly, longtime HSI insiders cautioned that using the agency’s databases and tools to search these lists would yield mismatches and wildly inflated results.

The administration plowed forward anyway.

HSI’s involvement in the hunt for election fraud traces at least to summer 2025, when agency supervisors embraced a proposal from a midlevel agent who’d publicly echoed Trump’s claims about elections. He argued the agency’s powerful databases and tools could find noncitizens even on the voter lists that states make publicly available, from which the most confidential information has been redacted. Under Trump, the Justice Department had collected many public voter rolls as part of a controversial effort to compel states to turn over the unredacted versions.

Those searches went forward, ProPublica’s reporting shows, helping to generate tens of thousands of leads regarding illegal voting across the country. But when HSI agents were sent to investigate them, the results were similar to what Teirab reported from Minnesota.

Between January 2025 and May 2026, a ProPublica analysis of Justice Department data shows, fewer than 150 alleged noncitizen voters were referred for prosecution. Even fewer — 41 — were charged with voting illegally or other election-related crimes. (More than 150 million people voted in the most recent presidential election.)

In response to questions from ProPublica, administration officials insisted the effort spearheaded by HSI was producing meaningful results.

“President Trump is committed to ensuring that Americans have full confidence in the administration of elections, and that includes totally accurate and up-to-date voter rolls free of errors and unlawfully registered non-citizen voters,” Abigail Jackson, a White House spokesperson, said in response to ProPublica’s request for comment. “Noncitizens voting is a crime. Anyone breaking the law will be held accountable.”

A DHS spokesperson didn’t answer questions about why so few prosecutions have resulted from HSI’s work. The agency wouldn’t specify what tools or techniques HSI had used, but confirmed it had cross-referenced “publicly available data” from state voter rolls with information on “known illegal aliens” in its systems. “It’s not rocket science,” the spokesperson wrote of this initiative in a response to ProPublica’s questions. “It’s an easy step to secure our elections.”

Teirab and the U.S. attorney’s office in Minnesota declined to comment.

There’s an array of reasons why Trump’s campaign to document claims of widespread voter fraud hasn’t succeeded. Most obviously, it’s exceedingly rare, as countless studies and state audits have found. Noncitizens often get on voter rolls by accident or when government officials make errors. Last month, New Jersey disclosed that a mistake involving its Motor Vehicle Commission caused 6,600 noncitizens to be registered (fewer than 400 voted).

The administration’s critics say its hunt for noncitizen voters aligns with Trump’s attempts to seek more federal control over elections while stoking doubt and fear about the voting process. Since taking back the Oval Office, Trump has tried to impose new restrictions on voter registration, mail-in ballots and voting machines, though judges have shut down most of these efforts.

Former officials at DHS and the Justice Department called the move to involve HSI a further escalation and questioned the propriety of aiming the agency’s muscle and technology at individual cases of illegal voting.

“It’s one thing if you’re going after Pablo Escobar,” said Steve Bunnell, a former DHS general counsel and senior intelligence adviser who handled voting fraud prosecutions during more than a decade at the Justice Department. “It’s another thing if you’re going after some cleaning lady who’s been working in the United States for 20 years and taking care of her 80-year-old mother and taking her little kids to church.”

An illustration of a row of armed personnel in tactical gear and helmets sitting at computer desks in front of glowing cyan monitors.
Matt Rota for ProPublica

“The Swiss Army Knife of Federal Law Enforcement”

Trump’s enlistment of HSI in his election fight is no accident. Cobbled together in the aftermath of 9/11, the agency has 7,100 armed, highly trained agents and another 800 criminal analysts, as well as access to troves of confidential data about hundreds of millions of Americans.

Though part of Immigration and Customs Enforcement, the agency has historically stayed out of immigration cases. During the first Trump administration, leaders of 19 HSI regional offices — virtually its entire top field hierarchy — signed a letter calling for HSI to become a standalone agency, arguing that ICE’s deportation work dissuaded people from cooperating with its investigations. But when Trump returned to the White House, it swiftly became clear that the agency would play a central role in investigations related to the president’s twin obsessions, illegal immigration and noncitizen voting.

Trump picked his field general for repurposing HSI even before taking the oath of office. In December 2024, he named Anthony Salisbury, a 50-year-old career agent who’d run the agency’s Miami office, as a deputy homeland security adviser, reporting to White House policy chief Stephen Miller. He was also given a dual appointment as head of HSI.

Salisbury was colorful: A mixed martial arts enthusiast, he once appeared at the agency’s headquarters with his face bruised and eye blackened from a recent bout. He’d sometimes entertain colleagues by pulling out a bridge that covers his missing front teeth.

To agency veterans, however, he was forever linked to a 2011 operation he’d overseen in Mexico in which one agent was killed and another wounded in a highway ambush by a drug cartel. An agency review submitted to Trump in April 2020 concluded that errors by HSI supervisors, including Salisbury, contributed to the outcome; it urged the administration to consider disciplinary action. None was taken against Salisbury, however.

Salisbury did not respond to requests for comment from ProPublica. A White House official called him “a critical member of the Trump administration” who was “cleared” in every review of the Mexico incident and was subsequently “promoted six times under multiple administrations.”

“It’s one thing if you’re going after Pablo Escobar. It’s another thing if you’re going after some cleaning lady who’s been working in the United States for 20 years and taking care of her 80-year-old mother and taking her little kids to church.”

Steve Bunnell, a former DHS general counsel and senior intelligence adviser

Once elevated to his new posts, Salisbury took charge of carrying out the second Trump administration’s agenda for HSI, personally issuing staffing directives, reassignments and promotions, current and former agency officials told ProPublica. (A number of them spoke on condition of anonymity out of fear of retribution.) 

Starting in early 2025, Salisbury oversaw the unprecedented reassignment of more than 6,000 agents to immigration enforcement, diverting most of the agency from its normal duties. He then also pointed HSI at noncitizen voting, presiding over multiple meetings with officials at DOJ and Homeland Security focused on election fraud, according to emails reviewed by ProPublica and agency supervisors who worked with him.

“Stephen Miller has an HSI deputy for a reason,” said Eric Balliet, a high-level HSI manager who retired in 2024 after 23 years with the agency. (Like many HSI veterans, Balliet has remained in close contact with former colleagues.) “Salisbury is going to salute and execute, and he is going to make sure that from the HSI side, they fall in line, and there’s going to be no resistance or pushback. HSI has been turned into the Swiss Army knife of federal law enforcement.”

In early July 2025, Frank Quiñones, an HSI special agent who’d worked under Salisbury in Florida, approached leaders at the HSI Innovation Lab with an idea for using the agency’s technology to find noncitizen voters on state voter rolls, sources at the agency told ProPublica. Quiñones had been transferred to Washington to oversee a unit that had previously handled cases involving the theft of government benefits but that had been enlisted into voting investigations.

The lab, housed in an unmarked office in a D.C. suburb, had access to the government’s most sensitive databases, from suspicious activity reports to arrest records. Staffed by a combination of HSI experts and outside consultants, it developed software tools to comb the data for information that could help agents pursue criminal suspects.

Quiñones was a true believer in Trump’s claims about election fraud: In multiple Facebook posts and reposts, ProPublica found, he promoted claims that the 2020 presidential vote had been stolen. At a meeting with the Innovation Lab’s overseers, according to sources who worked in the lab, he pitched using the lab’s technology to identify illegal voters — even though the agency lacked voter rolls that included identifiers such as partial Social Security numbers. (Quiñones did not respond to ProPublica requests for comment.)

For proof of concept, Quiñones proposed using a February 2021 public voter list he’d obtained for New Jersey and running it through HSI’s databases. The lab staff viewed his idea as “a little insane,” one recalled — both unreliable and improper. Since the public rolls don’t include voters’ unique identifiers, people at the lab also knew linking them to HSI’s data would produce mismatches — what the staffer called an “ungodly” number of false positives. The lab team also worried about violating longstanding safeguards limiting use of private citizen data. They “didn’t want to touch this,” the staffer added. Quiñones defended his idea, repeatedly declaring: “The president wants this!”

Tom Hodge, an HSI data analyst at the meeting, proposed running the voter information through the Athena Toolbox, an analytical platform developed by the Sandia National Laboratories that had access to all of HSI’s databases. (Hodge did not respond to ProPublica requests for comment. Sandia referred ProPublica’s questions to the facilities’ parent agencies, including the Department of Energy, which did not respond to our requests.)

Hodge and the Sandia team spent the next six weeks on the project, reporting they’d found large numbers of noncitizens on Quiñones’ 2021 New Jersey list. According to one former HSI official, they said they’d found “5,000 high-confidence illegal voters” in just a single New Jersey county. (Officials at the New Jersey secretary of state’s office, which oversees the state’s voter rolls, declined to comment on the claim. Beth Thompson, head of a group for local New Jersey election officials, called the number impossibly high, even accounting for the mistake disclosed by the state.)

The apparent breakthrough couldn’t have come at a better time.

The Trump administration’s other efforts to identify noncitizens on state voter rolls were running into a variety of roadblocks.

The administration had hoped to persuade states to check their voters’ citizenship status using a system called the Systematic Alien Verification for Entitlements, or SAVE, but many didn’t. Most states also refused the Justice Department’s demands to turn over their unredacted voter rolls, including partial Social Security numbers, which thwarted the agency’s plan to run them through SAVE. Courts have stymied the DOJ’s attempts to sue for the records, citing the Constitution, which gives primary control over elections to the states.

In an Aug. 21 email to a half dozen administration officials, Quiñones touted the solution he’d brought to the HSI Innovation Lab: using HSI’s platform to search voter rolls. The results, Quiñones noted, could fuel both criminal and immigration investigations.

By the end of the month, those in top election-related roles at DHS and the Justice Department were actively promoting what they dubbed the “HSI Tool” as a preferred alternative to SAVE, according to people familiar with the matter. Among them was Heather Honey, the prominent election denier appointed as a senior counselor at DHS, who is helping lead the government’s efforts to identify noncitizens on voter rolls. (Honey did not respond to ProPublica’s requests for comment. In an email responding to questions to her, DHS said Honey’s “expertise in election administration” was “invaluable to the Department’s efforts to protect critical infrastructure.”)

The White House, too, got behind the idea. In a November email, J. Brian Sikma, special assistant to the president, excitedly noted that the New Jersey trial cross-checking voter rolls with DHS data appeared to have identified a “very significant number” of “potential non-citizens.” (Sikma didn’t respond to a request for comment.)

The DOJ, Sikma reported, had already obtained public voter rolls for many other states. He included a list of them, adding: “It is of paramount importance that these also be reviewed expeditiously.”

An illustration features a framed portrait of a man in a suit on the left hanging next to a large display board showing a red map of the United States crisscrossed with white dotted paths.
Matt Rota for ProPublica

Running “Roughshod” Over Privacy

As the push to use HSI’s tech to search voter information gained momentum, a new problem emerged.

Career attorneys at the Justice Department, including specialists on privacy law, raised concerns that transferring voter rolls wholesale from the agency to DHS might not be legal, according to internal emails reviewed by ProPublica and interviews with several former officials.

The voter rolls the DOJ had collected contained sensitive information on millions of Americans. Even the public versions, which political parties and candidates routinely obtain to target ads and messages, included voters’ addresses, birth dates and party affiliations. For the 16 states that have agreed to share their unredacted voter lists, the DOJ had citizens’ partial Social Security numbers or driver’s license information, too.

Federal laws, particularly the Privacy Act, dictate what data government agencies can collect, what it can be used for, how it can be shared, and how it must be protected. Agencies have to disclose their plans in advance, gathering public comment. A person’s information can’t be released or shared without their consent, subject to limited exceptions.

From the outset, the Trump administration’s effort to combine data across federal agencies has repeatedly drawn criticism from courts and whistleblowers for failing to adhere to restrictions meant to keep data private and secure. In June, for example, a judge prohibited the government from using SAVE for mass searches, ruling the administration had violated federal privacy laws by giving DHS access to Social Security data to enhance the tool. The administration has appealed that ruling.

In July 2025, as word got around that the DOJ might hand over voter data to DHS, a half dozen career attorneys who had been reassigned into the voting section voiced their unease to supervisors, according to two former DOJ lawyers. Their concerns were disregarded, prompting most to resign.

Instead, the DOJ’s office of legal counsel pushed forward with plans to share the public voter rolls, claiming a Privacy Act exception allowed HSI to receive such data without public notice as long as it was for law enforcement purposes. DHS just needed to submit a letter officially requesting the data for those purposes, an attorney in the legal counsel’s office explained, according to internal emails.

But this exception was meant to be used to get information on individual criminal suspects, not to gain mass access to data on people suspected of no wrongdoing, according to Nikhel Sus, chief counsel for Citizens for Responsibility and Ethics in Washington, which has sued the Trump administration on behalf of voter and pro-privacy groups, filing the case that eventually limited SAVE’s use.

“[Anthony] Salisbury is going to salute and execute, and he is going to make sure that from the HSI side, they fall in line, and there’s going to be no resistance or pushback. HSI has been turned into the Swiss Army knife of federal law enforcement.”

Eric Balliet, a former high-level HSI manager

Peter Winn, a 29-year Justice Department veteran who had served as the agency’s acting privacy chief for nearly a decade, drafted a letter to set out the data-sharing agreement between the DOJ and DHS, according to internal documents reviewed by ProPublica.

In a Feb. 12 email to two top DOJ officials, he said he’d rewritten an initial draft memo to “make the information sharing arrangement far easier to defend, if and when it is challenged in court.”

Rather than simply handing over the voter rolls, Winn proposed having DHS request “pertinent and relevant” information about specific people from the DOJ, then having technical staff at Justice and Homeland Security “coordinate” to fulfill the requests.

“Having slept on it,” Winn wrote, “I ended up deciding that our initial idea of sending a huge amount of raw unprocessed voter registration data to DHS, involved taking far too much unnecessary legal risk, given that 99% of the data would implicate the privacy and civil liberties of United States Citizens, and would risk adding to the false narrative in the establishment press of DOJ and DHS being unconcerned with the privacy and civil liberties of Americans.”

Winn attached his proposed letter, to be signed by Todd Lyons, then the acting director of ICE.

Winn’s suggested restrictions were quickly abandoned, however. A second draft of the letter, dated March 4, contained altered language providing that the voter information would be “transferred” to HSI, with one exception: Voters’ party affiliation would be redacted, if possible, it said.

The final letter, signed by Lyons and sent to the DOJ just two days later, abandoned even that limitation. Just three paragraphs long, it permitted HSI to use the voter rolls to pursue any “appropriate investigation of potential violations of federal election law.”

In response to questions from ProPublica, Winn said “I can’t really comment on internal drafts of correspondence.”

A Justice Department spokesperson defended the government’s actions, saying “no one should oppose intergovernmental data sharing and coordination that enable swift investigations and prosecution of illegal alien voting.” DHS echoed the DOJ’s view, calling such information sharing “essential to protecting America’s election process by keeping noncitizens off voter rolls” and “an easy step to secure our elections.”

Sus said that by pooling voters’ sensitive personal identifiers, along with their party and voting histories, the administration has “run roughshod” over privacy laws and is creating a “1984-style database” that could be used to surveil political participation.

CREW filed a lawsuit in April on behalf of the nonprofit advocacy group Common Cause that argues it’s illegal for the administration to use the law enforcement exception to justify mass sharing of voter information.

Balliet, the former HSI agent, expressed similar concerns, saying that handing over voter rolls to run through DHS’ systems amounted to “a mass data-collection effort by the government against its own citizens in a non-criminal setting.” On a practical level, he added, the data sharing increased the risk of breaches that can open law-abiding citizens up to identity theft.

“As a citizen, I want the government to take seriously the protection of my private data,” he said. “If it falls into the wrong hands, it’s not the government that suffers. It’s me.”

Matt Rota for ProPublica

Collapsing Claims

By January 2026, scores of HSI agents were fanning out across the country to investigate thousands of leads about illegal voting.

About 25,000 of them involved people SAVE had identified as potential noncitizens on state voter rolls. Another 15,000 were given to HSI’s cross-border financial crimes unit, which was told to prioritize them over money laundering and fraud cases, a former high-level HSI official said. Quiñones’ unit led a separate effort to find additional cases by reviewing whether people who’d recently become citizens had voted before they were naturalized, then lied about it in naturalization interviews.

Still more leads came from running public voter rolls through the HSI lab’s databases, though it’s not clear how many. Agency sources told ProPublica that the rolls of New Jersey and Pennsylvania were searched using the Athena Toolbox. When DHS announced it had found more than 250,000 noncitizens on the registered voter lists of four Democrat-led states, it said that included “as many as” 35,152 in New Jersey and 14,576 in Pennsylvania. Both states have asked DHS to provide the source of the numbers.

Once federal investigators started digging into these cases, however, they often fell apart.

Through May, prosecutors had charged fewer than four dozen people with crimes related to noncitizen voting, ProPublica’s analysis of DOJ data and federal court filings shows, getting convictions or guilty pleas in 14 cases.

The largest cluster of cases was brought in the Southern District of Florida, headed by Jason Reding Quiñones (no relation to the HSI agent), a staunch Trump ally who has led investigations of the president’s political opponents. Voters have been sentenced in eight of the office’s cases; seven others are pending.

Prosecutors have initiated a total of seven noncitizen voting cases as of May in the four states where DHS claimed to have found more than a quarter million noncitizens on the rolls. Collectively, these states have more than 40 million registered voters.

Overall, the paltry numbers reflect the realities HSI investigators confronted on the ground as they tried to convert leads into cases, a ProPublica review of records obtained by voting-advocacy groups Campaign Legal Center and Democracy Forward shows.

Emails between agents and local election officials in Texas and Ohio indicate much of the federal information on purported noncitizens was inaccurate, the consequence of flawed data matching. When agents demanded voting histories and registration forms, they often discovered people weren’t registered in the counties where HSI thought they were. When voters register, they must attest that they are U.S. citizens; agents found some, however, who’d been put on voter rolls in error after disclosing they weren’t citizens. Many had never voted.

“Our initial idea of sending a huge amount of raw unprocessed voter registration data to DHS, involved taking far too much unnecessary legal risk, given that 99% of the data would implicate the privacy and civil liberties of United States Citizens.”

Peter Winn, a Justice Department veteran, in an email urging limits on data sharing that were not adopted 

Most HSI agents, steeped in pursuing complex international crimes, had no experience in pursuing voting fraud. In his email to Nick Davis at the Justice Department, Teirab, the top deputy in Minnesota’s U.S. attorney’s office, described the chaos that ensued when the state and at least six counties got subpoenas for voters’ records. The demands “presented a host of issues,” Teirab wrote to Davis. (Davis did not respond to a request for comment.)

“An unknown number of agents are constantly arriving in Minnesota without any knowledge of the investigation, the issues already discussed and decided, and the processes they need to follow,” Teirab complained. “Instead of getting up to speed and learning, they have demanded many calls and subpoenas, most of which demonstrate a complete lack of understanding of the investigation.”

In Stearns County in central Minnesota, HSI agents subpoenaed voting histories on 13 people, county officials told ProPublica. Only six turned out to live there.

Minnesota Secretary of State Steve Simon, a Democrat, said the effort revealed federal investigators’ ignorance about “the nuance of elections administration.” The rate of purposeful election crime is “microscopic,” he said. “The very human errors that can happen are not some sort of plot or scheme to dirty up the voting rolls, but are just everyday human beings making mistakes, not intending at all to violate any law.”

As of May, only one illegal voting case has been referred for prosecution in Minnesota. The state has more than 3.8 million registered voters.

Even Republican-led states like Ohio, which has shared its unredacted voter rolls with the DOJ and run them through the SAVE system, have struggled to meet Trump administration demands to deliver cases.

In October, the Ohio secretary of state referred more than 1,000 voters identified as possible noncitizens to the federal government, claiming 167 had voted at least once since 2018. At least nine HSI agents in Cincinnati and Cleveland began to investigate, emails obtained by Campaign Legal Center and shared with ProPublica show.

The agents bombarded local election officials with requests for voting histories and other records, some dating back decades. “Sorry again for piecemealing these to you,” one agent wrote to an official in Butler County, outside Cincinnati, after making five separate requests over two weeks. Mohamed Al-Hamdani, a Democratic member of Montgomery County’s Board of Elections, which received similar inquiries, said they amounted to “witch hunts” that ate up staff time.

In February, Davis sent an email pressing Ohio’s two U.S. attorneys’ offices for an “election integrity” update, asking: “How close are we to complaints/indictments, how many subjects, what issues you’ve run into, how many referrals have been closed and why, how helpful HSI has been.”

As of May, just two voting cases had been referred for prosecution in Ohio and no one had been charged, federal data shows. The state has nearly 8 million voters.

In the past, it was uncommon for federal prosecutors to pursue charges against noncitizen voters who didn’t understand that it was against the law for them to vote. Without evidence of a coordinated effort or plot, it didn’t make sense to put resources into such prosecutions, a former DOJ official who oversaw election cases said.

Now, however, U.S. attorneys’ offices are taking a different approach, pursuing prosecutions that could result in prison terms or deportation.

In May 2025, federal prosecutors in Florida filed illegal voting charges against a mother and daughter, both Ukrainian citizens, who’d registered after becoming permanent U.S. residents, then voted in the 2024 presidential election. They’ve pleaded not guilty, with the mother saying in an interview with investigators that she thought having a green card meant she could vote. They and their attorneys didn’t respond to requests for comment from ProPublica. The prosecutor handling the case for the Southern District of Florida also didn’t respond to questions. The mother and daughter are scheduled to go to trial in September.

An illustration of a person leaning over a voting booth to cast a ballot, closely watched by a guard in tactical gear and a helmet standing beside the booth.
Matt Rota for ProPublica

“Far-Reaching Consequences”

Experts on both elections and national security warn there may be profound longer-term costs to unleashing the federal government’s investigative and prosecutorial might to try to prove the president’s claims about noncitizen voting.

Current and former HSI agents say critical investigations — including task forces aimed at drug rings, human trafficking and money laundering — have languished as the agency has pivoted to take on noncitizen voting and immigration enforcement.

In February 2026, according to court files and emails reviewed by ProPublica, an HSI agent in Ohio who’d been leading a multistate child sex abuse investigation was abruptly assigned to pursue dozens of leads on suspected noncitizen voters, work that took months. It wasn’t until May that he made an arrest in the other case. Prosecutors have filed child exploitation and pornography charges against the man, 38, in connection with acts involving at least five 14-year-old girls.

Cases like this “don’t just stop,” said Balliet, the 23-year HSI veteran. “When you pull people off them for an extended period of time, those criminal networks will adapt, and people get killed and kidnapped.”

Federal data hints at a broader slowdown in what had been HSI’s most urgent work. According to an annual government report, the number of wiretaps obtained by DHS — often to investigate drug trafficking — plummeted to 23 in 2025, from 133 the previous year. In the report, DHS attributed the decline to several factors, including “changes in administration enforcement and prosecutorial priorities.”

“It’s never been a better time to be involved in transnational organized crime,” said John Tobon, a high-ranking HSI official who retired in early 2025.

“The very human errors that can happen are not some sort of plot or scheme to dirty up the voting rolls, but are just everyday human beings making mistakes, not intending at all to violate any law.”

Minnesota Secretary of State Steve Simon

In its statement, DHS denied HSI has neglected its core mission, saying the agency has increased its efforts to combat criminal cartels, gangs and drug traffickers in response to multiple Trump executive orders.

Though HSI’s voting-related investigations have yielded only a small number of prosecutions, voter advocacy groups worry the Trump administration will use them to justify more extreme interventions.

Its latest tactics include threatening to withhold funds from states it says are refusing to check their voter rolls for noncitizens and saying it will prosecute state election officials who “knowingly” fail to remove noncitizens. Trump has also continued to press Congress to enact the SAVE America Act, which would require people to provide proof of citizenship when registering to vote, a measure advocates have criticized as a barrier to voting. Democrats are preparing for the prospect of federal troops being sent to the polls to intimidate voters.

“Those concerns are playing out in real time, with far-reaching consequences,” said Dax Goldstein, a director at the States United Democracy Center, a nonprofit group that works to build confidence in elections. “When federal agencies are misused and weaponized, people lose trust in government itself.”

The post Inside Trump’s Failed Hunt for Noncitizen Voters appeared first on ProPublica.

Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors

14 Agosto 2026 ore 11:57

President Trump has signed a national security presidential memorandum allowing federal law enforcement agencies to partner with private technology companies to execute offensive cyber operations against foreign criminal groups and international adversaries. Under the directive, vetted private sector tech firms will be permitted to work under direct federal supervision to propose, coordinate, and execute targeted cyber actions.

The move marks a significant shift in US cyber policy, formalising a role for private industry in offensive operations that have traditionally been the preserve of government agencies.

“A coalition of the willing”

Commenting on the announcement, Kyle Hanslovan, CEO and co-founder of Huntress, said, “Considering the rapidly accelerated sophistication of organised cybercrime and nation-state actors, close public and private collaboration is no longer an option. When you add the reality of AI-powered autonomous threats, the only viable solution is a stronger coalition of the willing, which we are eager to support.

One key pillar to the success of this programme will be the appropriate use of hyperscalers for their breadth of intelligence data and die-hard security research labs like Huntress for their agility and operational depth to truly disrupt adversaries. Another key pillar will be the deconfliction process to ensure private industry doesn’t interfere with the value of long term persistent access operations which often lead to public arrests and geo-political negotiations.

All-in-all, I’m proud to see the US Government push the boundaries when it comes to denying, degrading, and disrupting these measurable threats to democracy. If done correctly, I believe it will ultimately slow the illegal transfer of wealth and knowledge from Western civilization.”

Concerns over collateral damage and delay

Not all reaction has been unreserved. Ben Bernstein, cybersecurity advisor at Huntress, added, “I’m all for expanding public-private cooperation because the government clearly can’t fight transnational cybercrime on its own, but I have concerns about how this actually plays out in the wild. When you look at the operational reality of green-lighting private offensive ops, you hit two massive roadblocks: collateral damage and bureaucratic lag.

Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network. That makes it practically impossible to “strike back” without taking out innocent bystanders. Plus, adversary infrastructure is incredibly ephemeral, often burning down in a matter of hours. By the time a vetted firm submits a target, sits through the DOJ and DHS deconfliction reviews, and finally gets a green light, they’ll be shooting at ghosts. Expecting government bureaucracy to move at the speed of modern ransomware operators is wildly optimistic.”

A signal to adversaries

Tim Mackey, head of software supply chain risk strategy at Black Duck, struck a more cautionary tone, concluding, “Ignoring the reality that it’s difficult to identify the source of cybercriminal activity, endorsing private companies to conduct offensive cyberactivity is far more likely to increase criminal, and potentially nation-state, activity than deter it. Without careful governance and control, individuals with access to sophisticated surveillance technologies could easily abuse that access and engage in surveillance efforts for personal gain. Unfortunately, one message this memo does send to adversaries is – the US government needs private companies and their capabilities to defend against cyberattacks.”

The memorandum is likely to prompt further debate within the security community over how offensive cyber operations conducted by private firms should be governed, vetted, and deconflicted from ongoing law enforcement and intelligence operations.

The post Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors appeared first on IT Security Guru.

Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

14 Agosto 2026 ore 11:38
A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal Organizations (TCOs) and disrupt them. "By partnering with vetted United States companies subject to the direction and

BOFH: How our Covid ransomware protocol's Y2K blockchain lowered uptime

14 Agosto 2026 ore 11:29
EPISODE 15: The Boss has popped into Mission Control to remind us to send him the numbers he needs for his monthly management report. Once's he's gone the PFY sighs, makes up a set of numbers, appends believable exponents, adds some fancy sounding units to the end and then sends them to through a script file to convert them into something the Boss can use. None of it matters, as no one cares about the numbers anyway. At Management level there's likely to be more interest in the undigested-meat portion of the Boss' stool sample than our uptime stats, firewall throughput, or the Company's online storage totals... Still, the PFY will fabricate the data, extrude it through a Perl script to create a graphic panel complete with a pie chart or two, and maybe a Venn diagram, then send it to the Boss. The Boss then pastes it into the top right corner of his report document, which gets sent on to the higher-ups, month after month, year after year. The real shame is that none of the higher ups has ever taken the time to flip through the Boss' reports chronologically - and thereby view the PACMAN-like animation the PFY's data has been so diligently creating all this time. You've got to make your own fun in this job. And no one cares if the numbers are wildly inaccurate. Back in the old days, someone might wonder how we'd achieved 117 percent uptime, or whether 17.6267 terafleptules was a real thing or not, but at this point no one will ask any questions so long as the pie chart isn't a single color. As stated, we stopped producing real data years ago, and, on the rare occasion we're questioned about the validity of the data, we have an excuse close at hand. For a good part of the '90s we leaned heavily on blaming "The internet" for faulty data, though from '97 till around 2001, "Y2K" was solid gold. In recent times - i.e. the data-faking era - "Blockchain implementation" was surprisingly short-lived as an excuse - but we got a good four years out of "It's a COVID thing," before flipping between quantum computing and privacy restrictions for a bit. If pressed, we'll occasionally just shake our heads and quietly murmur "Viruses", "Hackers" or "Zero day attacks", as that covers a multitude of sins, and both the PFY and myself can ramble aimlessly for hours about viruses we have known, and what they might have done to our systems. The only thing we'd be missing in a scenarios like that would the onions in our belts, but no one would notice that while they were thinking up a good excuse to leave the room... "AI" has at least another two years in it - unless of course AI becomes sentient during that time and kills us all... Still, AI might need someone to produce fake stats about how well they're doing... ... The Boss is back surprisingly fast with a query. "I was just looking at the graph and I think there might be a data error." He says, pointing to the graphic. "See there, where is says Terafloptules." "Uh-huh." the PFY says. "Is that a spelling mistake? Only I can't find the work Terafloptules on Google. And last month it was in Terafloctules, not Terafloptules, but I can't find Terafloctules either." "Well, you wouldn't would you. I mean Google looks up data after the fact." "I'm not sure I follow." "Well, say you created a word. Idiomanagement, say. Will Google know about it?" "Yes?" "No, it won't. It won't notice it until it becomes a commonplace word or phrase. In the interim period, before it gets accepted and has a wider use, Google will simply skip over it, assuming it's a spelling mistake of some similar word." "So... we're... using a word that doesn't exist?" the Boss asks. "No, we're using a word that doesn't exist in common usage. It's like DVD Player in 1996. If someone saw that written down then, they might have thought it was DUD player and thought you were referring to Aly Dia. Now though, the word's in common usage." "So is there a word we could use that people would be more familiar with?" "I guess we could use Gigafloptules, but then I'd have to mention on the legend that the units are in thousands." "What is a gigafloptule?" "I'm glad you asked!" the PFY blurts happily. "To get to the bottom of that you really need to know a little bit about the parsec measurement of the speeds of data - but don't worry, it's not nearly as complicated as it sounds! You see, when Rutherford split the neutron with a nitrogen atom back in the 1850s, he noticed that a small amount of energy, a floptule, was ejected from the uranium positron... I leave the PFY rambling while I pop up to the cafeteria to see if they have any onions. Yellow ones, because of the war... BOFH: Previous episodes on The Register The Compleat BOFH Archives 95-99

Wall Street’s Nonprofits Use Selective, Opaque Logic to Defund Charities

14 Agosto 2026 ore 11:00
A pattern of green check marks made of hundred-dollar bills surround a red X in the center, also formed of hundred-dollar bills.
Illustration by Shoshana Gordon/ProPublica. Source image: U.S. Treasury via Wikimedia Commons.

When the Justice Department indicted the Southern Poverty Law Center in April on controversial fraud charges, the storied civil rights organization faced a major threat to its lifeblood — the flow of donor dollars.

Not because it was convicted or because the Internal Revenue Service revoked its tax-exempt status. Not even because individual donors stopped writing checks.

Instead, three Wall-Street-affiliated grantmaking giants each made a decision, one they refused to fully explain, to prevent donors from using their platforms to give to the embattled nonprofit.

Vanguard Charitable, Fidelity Charitable and Charles Schwab’s DAFgiving360 sponsor donor-advised funds, offering account holders immediate tax deductions on contributions they can later recommend be granted to charities.

Once niche, donor-advised fund sponsors controlled more than $327 billion in assets as of 2024, over 10 times their footprint two decades ago. They are the conduit for about a quarter of all individual giving in the U.S.

After the three sponsors cut off the SPLC, ProPublica investigated how the new gatekeepers of American philanthropy make these opaque, high-stakes decisions.

In examining the treatment of dozens of nonprofits, we uncovered troubling inconsistencies in how some DAF sponsors applied their policies and found that donors and affected charities are routinely left in the dark about how decisions are made.

The three sponsors are nonprofits spun off from major brokerages. Their accounts, used largely by high-income earners, charge administrative fees while sponsors retain legal control over the charitable assets. (ProPublica has received donations through each of the groups.) Donors “advise” the sponsors on where to send grants, but sponsors can deny requests for any reason.

They say decisions stem from policy triggers. Vanguard Charitable pauses payments when an organization faces formal charges, while Fidelity Charitable and DAFgiving360 say they “may” or “might” stop donations if organizations come under investigation by government or law enforcement agencies.

Deone Powell, a former general counsel for Vanguard Charitable who now advises nonprofits, said that DAF sponsors don’t view these moves as moral policing, but instead as ways of protecting their own brands. “All of these really speak to reputational risks for the sponsoring organizations,” he said.

They weigh these choices carefully, given the possible ripple effects, he said. “A single decision often establishes a precedent that’s going to affect thousands of other future recommendations.”

But ProPublica found that Fidelity and DAFgiving360 appeared to apply their policies unevenly. Even though they froze donations to the SPLC, they allowed numerous other groups to keep receiving money amid government investigations. The cases included hospitals, universities, charter schools and even a white nationalist organization.

The sponsors say their decisions are viewpoint neutral, and ProPublica found no evidence to the contrary. Removed groups spanned the political spectrum. But most of the ones that spoke to ProPublica shared one common experience: silence from the sponsors.

Months after being deemed ineligible for donations, the SPLC still doesn’t know why the action was taken or whether there is a path to reinstatement, according to a source familiar with the matter. The legal pressure, however, continues: A former employee was indicted this week on charges related to the case.

Experts say this is particularly problematic under the Trump administration, which has a track record of making politically charged accusations that don’t hold up in court.

“I don’t think Fidelity, Vanguard and Schwab are acting in bad faith,” said Joe Goldman, the president of Democracy Fund, a foundation supporting democratic principles. “They’re applying old rules to new circumstances without recognizing that the circumstances have changed.”

President Donald Trump has put nonprofits under an intense spotlight, alleging that many of them “undermine the security, prosperity, and safety of the American people” and directing federal agencies to align funding decisions with administration priorities.

Members of Congress, mainly Republicans, have initiated over 135 investigations into nonprofits since 2025, often claiming that charities were operating with foreign influence, engaging in supporting terrorism, or promoting diversity, equity and inclusion.

In letters sent to the IRS, Republican lawmakers accused several organizations that support pro-Palestine efforts of funding terrorism and asked for them to be investigated.

One of the charities has not been charged in court, and another was the subject of a state investigation. Neither has had its IRS status revoked, but they no longer appear on a Fidelity Charitable donation portal that allows users to select charities to donate to, ProPublica found. Fidelity wouldn’t say whether the letters played a role.

“This is potentially a way that a hostile legislator could harm tax-exempt organizations without having to prove anything,” said Samuel Brunson, a Loyola University Chicago School of Law professor who researches nonprofits. “Even if these letters are completely legitimate, you can take that same set of tools and use them illegitimately.”

The consequences can be significant. The SPLC, for instance, has received $20 million through Fidelity Charitable, Vanguard Charitable and DAFgiving360 in the past three years, with roughly 7% of its 2025 contributions coming from the three sponsors that cut it off.

“When investment firms block donor-advised funds to nonprofits based on allegations and speculation, it not only impedes critical charitable work; it also sets a dangerous precedent that stifles the rights of donors and chills the rights of the organizations they seek to support,” said an SPLC spokesperson in a statement to ProPublica.

The fund sponsors have not responded to similar concerns voiced by 16 state attorneys general, who wrote that their actions could enable weak or politically motivated investigations to “suppress, chill, or dismantle organizations” that are doing vital work.

Their own donors are also reaching out.

Dawn Piccolo, a retired Fidelity Investments senior vice president who has kept a DAF account since the 1990s, is a fervent supporter of donor-advised funds. She wrote to Fidelity Charitable reminding the sponsor that it had allowed another charity under similar fire to keep receiving gifts. “The SPLC has not been found guilty of anything,” she wrote. “Preemptively restricting donations under these circumstances sets a troubling precedent.”

All three fund sponsors declined to be interviewed for this story or answer detailed questions, including on their process for identifying nonprofits facing allegations and deciding which ones to ban. Fidelity Charitable said it does not comment on decisions involving individual charities and declined to give a statement.

DAFgiving360 said in a statement that it “communicates directly with donors when a grant recommendation is impacted by an eligibility determination” and will provide information on other alternatives when appropriate. The sponsor said that it does “not take charity eligibility decisions lightly.”

In a separate statement, Vanguard Charitable noted its “procedural pause” is “not a value judgment; it is the application of objective criteria and reflects Vanguard Charitable’s responsibility, as the legal owner and steward of the charitable assets, to review and approve the grants made in its name.” A spokesperson said it denies fewer than half a percent of donors’ donation recommendations annually and that “independent oversight is central to the value of donor-advised fund structure.”

Unexplained Inconsistencies

ProPublica reviewed donor-advised fund sponsors’ policies and giving records alongside government actions taken against charities to understand when and how sponsors intervene.

The review identified cases in which Fidelity Charitable and DAFgiving360 diverged from their treatment of the SPLC and kept giving to charities facing the kinds of government investigations their guidelines identify as grounds for halting donations.

Then-Washington Attorney General Bob Ferguson sued Providence Health and Services in February 2022, alleging that the nonprofit Catholic healthcare system illegally billed and aggressively collected payments from low-income patients without determining if they were qualified for charity care.

The case was extensively covered in the regional media, and Ferguson’s own news release emphasized that Providence’s conduct continued despite an investigation by his office.

Even so, Fidelity Charitable and DAFgiving360 allowed Providence to keep getting donations, ProPublica found.

Providence ultimately agreed to pay $150 million in refunds and debt relief for unlawful charges, the largest resolution of its kind in the country, according to Ferguson’s office. Providence did not admit to any wrongdoing.

Fidelity Charitable and DAFgiving360 also kept sending donations to Grand Canyon University as it faced a lawsuit and a $38 million fine following federal investigations that found it deceptively advertised the cost and course requirements of its doctoral programs and made illegal calls to consumers. The university denied the allegations, calling them “unsubstantiated.”

The Department of Education rescinded the fine in May 2025, and the Federal Trade Commission dismissed its remaining case months later after losing multiple court motions. But records show the Christian university drew donations from both fund sponsors throughout the two-year dispute.

Idea Public Schools, Texas’ largest charter school network, was investigated from 2021 to 2024 by the state’s chief charter school regulator amid allegations of lavish spending on private jets and parachute payments to leaders.

Fidelity Charitable kept the dollars flowing throughout.

The charter network was ultimately placed in a conservatorship by the state and forced to pay back $28.7 million to the U.S. Department of Education. The network acknowledged that it did not properly ensure that funds were administered lawfully in a statement released at the time.

Then there’s VDARE Foundation, which ran an influential far-right, white nationalist website. In 2022, New York Attorney General Letitia James began investigating the organization for misuse of millions in charitable assets. As VDARE faced subpoenas, it solicited donations asking supporters to “help us fight back.” Clear evidence on its homepage that it was under investigation didn’t stop DAFgiving360 (formerly Schwab Charitable) from continuing to give.

An article with the words: “Mugger James. VDARE.com facing mortal threat! NY Attorney General Letitia James mugs us (as well as Donald Trump, NRA etc.). Help us fight back — now!” The lead image shows a black-and-white castle in front of Letitia James wearing a face mask.
An article published by VDARE, a white nationalist website run by VDARE Foundation. DAFgiving360 continued giving to the foundation, despite its policy that it “may” stop donations if organizations come under investigation by government or law enforcement agencies. Screenshot by ProPublica

James sued the organization in 2025. Its leaders are fighting the charges, and the case remains open. VDARE, whose website is now inactive, is no longer listed as an option for current DAFgiving360 customers. The sponsor would not say when the charity was removed, but said in a statement that it conducts a “thorough assessment” to determine eligibility and that it “applies its policies consistently across all charitable organizations, regardless of their political viewpoint or orientation.”

The fund sponsors’ discretion to keep money moving to embattled groups becomes evident when considering the Trump administration’s actions against major universities.

Dozens of colleges became the subjects of formal government investigations involving their handling of campus protests and alleged antisemitism tied to the crisis in Palestine and Israel and over allegations of diversity, equity and inclusion. At least 20 of the universities are still listed as options for donation recommendations on Fidelity Charitable’s and DAFgiving360’s websites. ProPublica asked each school if it was still receiving funds from the DAFs. Most did not respond. One said that it has not seen a decline in donations from the sponsors.

Rather than making ad-hoc decisions about which organizations to keep giving to, some legal experts told ProPublica that fund sponsors should follow the direction of the IRS, which has the authority to investigate and rescind tax-exempt status through an audit, while also providing avenues for organizations that come under scrutiny to appeal decisions they don’t agree with.

“The wisest choice is probably to rely on the IRS list,” said Lloyd Mayer, a professor at the University of Notre Dame Law School who researches nonprofits. Cutting off organizations deemed eligible by the IRS, Mayer said, runs the risk of looking inconsistent or partisan.

“An investigation by who? An indictment at what level? Is it only federal government indictments? Is it also state indictments? What about the local county prosecutor? Of the thousands of counties in the United States, if any one of them brings an indictment, you’re gonna stop? Where do you start drawing the lines?”

Answerable to Few

ProPublica used an internal Fidelity Charitable tool to identify 22 nonprofit organizations that Fidelity had given to in the past but no longer lists as options to donors. ProPublica limited its analysis to nonprofits that have raised $1 million or more annually.

The charities represent a cross section of ideologies and missions — left- and right-leaning, foreign and domestic, media, religious, humanitarian.

The list includes The Epoch Times, the conservative media outlet whose chief financial officer pleaded guilty in July to federal money-laundering charges, as well as pro-Israel nonprofits that support the country’s defense forces. It also includes the Alliance for Global Justice, a progressive, Arizona-based organization scrutinized for its financial ties to a Palestinian group that the American and Canadian governments designated a terrorist organization in 2024.

The Epoch Times released a short statement following the plea agreement, noting that it was not named in the lawsuit. The Alliance for Global Justice has called the allegations against it “false and unsubstantiated.” Both groups are currently eligible to receive tax-deductible donations, according to the IRS.

Fidelity refused to confirm it had deemed these charities ineligible. A source familiar with the sponsor said donors can manually enter a charity’s tax information to ask the fund to make a contribution to an unlisted charity. But ProPublica reviewed requests from two donors who tried the manual workaround. Both were turned down.

ProPublica attempted to ask representatives of all 22 charities if they understood why they did not appear on Fidelity’s rolls of more than 1 million potential grant recipients. Seven responded.

One of the only groups that said it had gotten a clear answer about its removal was the United Aid and Logistics Foundation.

“Our activities include providing aid to those defending the safety and human rights of Ukraine’s men, women and children, which Fidelity does not consider to be humanitarian,” said Sytske de Boer, a director of the volunteer group. “We understand it is their prerogative, however we disagree with their interpretation and hope they reconsider.”

Four organizations told ProPublica they’d been left with no or unclear answers from Fidelity Charitable. Among them is Nonviolence International, a group founded by a Palestinian activist that supports nonviolent campaigns worldwide.

“Substantial funds have been paused by Fidelity DAF that were earmarked for our projects,” co-director Michael Beer said in a statement. “If funding is not resumed, nonviolence training, education, and intervention programs for marginalized communities will be slashed.”

Donors have also been met with silence.

Piccolo, the retired Fidelity senior vice president, said that the decision to cut off the SPLC seemed at odds with the careful decision-making she’d come to expect from the fund sponsor. “This action feels out of band for me,” she said in an interview. “The case appears weak and politically motivated.”

For over 25 years, the SPLC has tracked the activity and influence of extremist groups across the country. Its “Hate Map” lists over 1,200 groups with connections to white nationalism, the neo-Nazi movement, antigovernmentalism and a plethora of other ideologies that it says are rooted in hate.

The tool has been widely cited by journalists and academics for years, and, up until last year, the FBI utilized SPLC research to assist in law enforcement efforts. The map has drawn scrutiny under the Trump administration, whose supporters are among some of the right-leaning groups the organization has labeled extremists.

In a letter addressed to top White House aide Stephen Miller last year, several of those groups called the map a “smear tactic” and called upon the Trump administration to remove references to the SPLC’s work from the federal government.

Attorneys for the SPLC, in court papers, pointed out how language from the letter wound up in an incident report opened by the FBI one month later justifying an investigation.

The Justice Department’s ultimate accusation was unorthodox. Prosecutors alleged that the SPLC’s longtime practice of paying confidential “field sources” to monitor extremist groups like the Ku Klux Klan constituted a fraudulent diversion of donor funds.

The SPLC pleaded not guilty to 11 counts of wire fraud, giving false statements to a federally insured bank and conspiracy to commit money laundering. Former federal prosecutors called the indictment “stretched” and “not valid,” and whistleblower reports to Democratic lawmakers said that the prosecution was rushed despite weak evidence.

The Justice Department did not respond to a request for comment. Earlier this week, it arrested Heidi Beirich, a former SPLC employee, on charges connected to the case. Prosecutors allege that she facilitated secret payments to informants inside extremist groups. Beirich’s attorney said that she is innocent and the case is “without merit.”

“I can understand that if overwhelming evidence were to emerge publicly in the course of proceedings, a temporary pause might be warranted,” Piccolo wrote to Fidelity Charitable. “But that is not where things stand.”

While company representatives sent rote responses and promised to pass along her inquiries, Piccolo told ProPublica that she has yet to receive a thorough explanation of their actions. She has stopped funding her Fidelity Charitable account and plans to move her existing balance to a different sponsor.

After the fund sponsors moved to cut off the SPLC, 16 state attorneys general, all Democrats, registered their objections in a letter.

“As attorneys general, many of us are the chief regulators of nonprofits, charities, and charitable trusts in our states, and serve as representatives of the public and donor intent,” they wrote. “This decision raises serious concerns that you are allowing the DOJ’s selective political targeting of a charity to impact your donor-advised giving decisions.”

They said their concerns were amplified by the sponsors’ refusal to disclose other charities whose donations they’d paused.

They have not received a response.

Powell, the former Vanguard Charitable attorney, said the sponsors are unlikely to be moved by public blowback.

“I don’t see this as being earth-shattering enough where it’s going to drive any immediate change,” he said. “These are sponsoring organizations that are aligned with financial institutions, which are traditionally adverse to risk. Once policies are in place, it takes a lot to change something.”

But in the future, he expects large account holders will want more from the fund sponsors than just moving their money between organizations.

“I think that any change is going to be driven by donors who are asking questions about how their philanthropy is defending democracy.”

The post Wall Street’s Nonprofits Use Selective, Opaque Logic to Defund Charities appeared first on ProPublica.

Risolta vulnerabilità su Zimbra Collaboration

14 Agosto 2026 ore 10:50
Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità “alta” in Zimbra Collaboration, nota piattaforma di collaborazione e-mail sviluppata da Synacor Inc. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzionati remoti di eseguire codice arbitrario sui sistemi interessati.

Scottish prosecutors cast eye over leaky supplier after staff data exposed

14 Agosto 2026 ore 10:46
Scotland's public prosecution service has warned 300 staff that their personal information may have been caught up in a cyberattack on one of its suppliers. The Crown Office and Procurator Fiscal Service (COPFS) disclosed the incident on Thursday, saying an unnamed third-party supplier detected suspicious activity on August 5 and subsequently launched an investigation. COPFS said its own systems were not compromised and that the incident involves information provided for an online data maturity assessment completed by the prosecution service last year. The Scottish government organized the assessment, which was managed by the affected supplier. COPFS said the potentially exposed information is limited to employment-related data submitted for the exercise, including staff names, roles, and work email addresses. In a statement to The Register, a COPFS spokesperson said: "COPFS is aware that a Scottish Government partner has been subject to a data security breach. We understand that this has affected around 300 COPFS colleagues who participated in a public sector data maturity survey. "This is unconnected to casework and did not involve sensitive or confidential case information. There is no impact on the work of the prosecution service. "Colleagues have been reminded of guidance on responding to any phishing or scam attempts which may arise from this third-party breach." According to COPFS, the supplier has taken steps to secure its systems and is still investigating how the intrusion happened and precisely what information may have been accessed. COPFS said it would provide further updates if "significant new information" emerges. It is unclear whether the incident is connected to the recent exploitation of a zero-day vulnerability in business intelligence platform Metabase. The Scottish government did not answer our question about whether the affected supplier used the software. Metabase disclosed this month that attackers had exploited a previously unknown vulnerability in its cloud service, potentially allowing them to gain administrator access and reach connected databases. As we reported earlier this week, modular laptop maker Framework was among those affected. For now, the supplier breach leaves plenty of questions and few answers about who got in or what they accessed. ®

Meet Huntress at International Cyber Expo 2026

14 Agosto 2026 ore 10:26

Huntress will be heading to International Cyber Expo 2026, where visitors can meet the team on Stand K94 and discover how the company is helping organisations tackle increasingly complex cyber threats with fewer resources.

One of the biggest challenges Huntress is seeing is the growing attack surface. Security teams are expected to protect endpoints, identities, cloud environments and other systems, often while dealing with limited time, resources and expertise.

At the same time, attackers are no longer operating in silos. Attacks increasingly move across different parts of an organisation’s environment, leaving security teams managing multiple tools and an overwhelming number of alerts.

At International Cyber Expo, Huntress will showcase its more unified, managed approach to security. The Huntress platform combines greater visibility across the attack surface with AI technologies and human security analysts to help partners and customers detect and respond to threats.

Tackling the rise of AI-powered attacks

AI-powered cybercrime will also be a major focus for Huntress at the show.

Generative AI is making it easier for attackers to create convincing phishing emails, develop malicious code and scale their operations. Tasks that previously required significant cybersecurity expertise can now be carried out with the help of readily available AI tools.

Huntress believes AI will also play an important role in helping defenders respond. Its approach uses AI to help analysts correlate security signals, summarise investigations and work faster, while retaining human judgement and context when making critical security decisions.

Visitors can also speak with Huntress about practical ways to strengthen their security posture. These include implementing multi-factor authentication, improving security awareness training and reducing vulnerabilities across the external network perimeter.

And when preventive controls fail, Huntress stresses the importance of having a mechanism to detect and respond to attacks quickly, including access to a 24/7 SOC that can support containment and remediation.

Listen to Huntress Senior Sales Engineer Alex Hitchen discuss the biggest cybersecurity challenges facing organisations today and what Huntress will be showcasing at International Cyber Expo 2026:

 

 

You can still register for FREE to attend International Cyber Expo HERE.

The post Meet Huntress at International Cyber Expo 2026 appeared first on IT Security Guru.

La checklist per la sicurezza dei privilegi da endpoint a cloud

14 Agosto 2026 ore 10:16
La checklist per la sicurezza dei privilegi da endpoint a cloud

La gestione della sicurezza dei privilegi tra endpoint e cloud è cambiata radicalmente. Capire questa evoluzione è fondamentale per proteggere la propria azienda.

Per vent'anni ci siamo concentrati sulla gestione degli accessi privilegiati (PAM) a livello di endpoint, ma oggi lo scenario è del tutto diverso. Infatti le infrastrutture si sono spostate su AWS, Azure e Google Cloud. I dati più preziosi risiedono in applicazioni SaaS e un numero crescente di account di servizio e agenti AI detiene permessi costanti. Nessun vault tradizionale può controllare questa nuova realtà.

I cybercriminali lo sanno bene: non cercano più di "entrare con la forza", ma semplicemente si "autenticano" usando credenziali valide. In questo modo, ereditano ogni singolo privilegio che quell'identità ha accumulato nel tempo.

Questa checklist in cinque fasi ti aiuterà a scoprire dove si nascondono i privilegi inutilizzati nella tua infrastruttura e a eliminarli una volta per tutte, così da proteggere la tua azienda al meglio.

L'evoluzione della minaccia per la sicurezza dei privilegi da endpoint a cloud

Il modello di minaccia legato alla sicurezza dei privilegi tra endpoint e cloud non è scomparso, ma è stato affiancato da un rischio molto più vasto e insidioso. I privilegi si sono spostati e non risiedono più solo all'interno del perimetro aziendale. Infatti oggi sono sparsi ovunque.

Pensa alle autorizzazioni IaaS, ai ruoli di amministratore SaaS, agli account non umani e alle identità AI. Tutti questi elementi possiedono spesso un accesso permanente e non gestito. Non si tratta di un rischio astratto. Report di settore, come quello di IBM sul costo delle violazioni dei dati, mostrano che il costo medio di un data breach ha raggiunto cifre record.

Le aziende con più privilegi permanenti sono quelle che pagano il prezzo più alto.

La soluzione in 5 fasi: una nostra checklist pratica

Il problema di fondo è quasi sempre lo stesso: un'autorizzazione concessa per una necessità specifica che non viene più rivista, revocata o limitata nel tempo. L'accesso permanente non fallisce in modo evidente; semplicemente attende che un malintenzionato lo scopra.

Per colmare questa lacuna, è necessario un approccio strutturato. Le cinque fasi seguenti funzionano in sequenza per costruire una difesa solida e moderna.

Fase 1: consolidare la sicurezza dei privilegi da endpoint a cloud

Prima di guardare al cloud, è essenziale assicurarsi che le fondamenta siano solide. Le nuove sfide non rendono obsolete le vecchie. È quindi cruciale confermare che i controlli di base siano attivi e funzionanti. Questo significa aver implementato il vaulting delle credenziali, rimosso i diritti di amministratore locale e attivato la registrazione delle sessioni.

Se il punto di partenza è vulnerabile, qualsiasi strategia cloud sarà inefficace.

Fase 2: mappare la reale posizione dei privilegi

Non puoi proteggere ciò che non vedi. Questa fase si concentra sulla scoperta ed è qui che la maggior parte delle aziende individua le proprie lacune. Devi ottenere una visibilità completa su dove risiedono realmente i privilegi:

  • Autorizzazioni nelle piattaforme IaaS (AWS, Azure, GCP)
  • Ruoli di amministratore e permessi critici nelle applicazioni SaaS
  • Account di servizio, pipeline CI/CD e altre identità non umane
  • Agenti AI con accesso a dati e sistemi

Solo una mappatura completa ti darà la consapevolezza necessaria per agire in modo mirato.

Fase 3: eliminare l'accesso permanente (standing access)

La scoperta si trasforma in riduzione del rischio solo quando i privilegi inutilizzati iniziano a scomparire. Questo è il cuore della moderna sicurezza dei privilegi.

L'obiettivo è semplice: rimuovere ogni accesso che non sia strettamente necessario in un preciso momento. Si tratta di "dimensionare correttamente" i permessi (right-sizing), revocando le autorizzazioni dormienti che rappresentano una superficie di attacco.

Fase 4: rendere operativo l'accesso just-in-time (JIT)

Una volta eliminato il superfluo, è il momento di applicare al cloud la lezione imparata dagli endpoint. Invece di gestire meglio i privilegi permanenti, perché non eliminarli del tutto?

Il modello Just-in-Time (JIT) si basa proprio su questo: concedere l'accesso solo quando è necessario e per il tempo indispensabile. Questo approccio, noto come Zero Standing Privileges (ZSP), dipende da un workflow efficiente per non rallentare le operazioni.

Fase 5: dimostrare i risultati

Un programma di sicurezza è efficace solo se puoi misurarlo. Al termine del percorso, devi essere in grado di rispondere a tre semplici domande:

  1. Puoi vedere ogni richiesta di accesso privilegiato?
  2. Puoi dimostrare che ogni concessione è stata limitata nel tempo?
  3. Hai una traccia di audit completa e immutabile per ogni sessione?

Una risposta onesta a queste domande ti dirà a che punto sei veramente nel tuo percorso di messa in sicurezza.

Perché la tua azienda dovrebbe mettere in sicurezza i privilegi tra endpoint e cloud?

La maggior parte delle organizzazioni supera bene la Fase 1, ma si blocca nella Fase 2. La buona notizia è che, una volta ottenuta la visibilità, convertire gli accessi permanenti in un modello JIT è in gran parte un esercizio di automazione. I privilegi hanno lasciato l'endpoint per sempre; è ora che anche le discipline di sicurezza facciano lo stesso.

Che tu operi nel settore finanziario, sanitario o tecnologico, il principio non cambia. Garantire l'accesso temporaneo ai sistemi critici, revocandolo automaticamente, non è più un'opzione, ma una necessità strategica per proteggere il tuo business nell'era del cloud.

L'articolo La checklist per la sicurezza dei privilegi da endpoint a cloud proviene da sicurezza.net.

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

14 Agosto 2026 ore 09:54
The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control

Claude Code returns blank thinking blocks, but reasoning still costs you

14 Agosto 2026 ore 09:30
Anthropic's Claude Code appears to be having trouble displaying summaries of its "thinking," according to several bug reports, while the underlying reasoning tokens still cost money. According to complaints, the API has been returning empty thinking blocks for Opus 4.8 and Sonnet 5 even when users explicitly request summarized thinking. Models from several sources can display their "thinking," a process that gives models additional tokens to reason through complex problems before producing a response. Software with this capability delivers a summary that explains how it tackled a task. Some can also indulge in "extended thinking," though this capability is now deprecated. Developers often enable "thinking" in the hope that it produces better results, at the cost of additional tokens and latency. Developer Michael Hood has noticed that some of Anthropic's models are currently not always good at sharing their thinking. "As of 2026-07-16 ~15:00Z, the API returns empty thinking blocks (thinking: '', signature only) for Claude Opus 4.8 and Sonnet 5, even when display: 'summarized' is explicitly requested — including when injected directly into the raw request body," Hood recently observed. We're told this issue is under investigation but doesn't appear to be a broad, ongoing concern. It may simply be an artefact of tests that change how Anthripic displays summaries. Similar behavior involving missing thinking blocks has been reported in Claude Code for VS Code. Another bug report claims thinking block summaries are being truncated while token bills are not adjusted accordingly. "The thinking is generated (and billed) in full; a portion of the summary stream is silently dropped," the anonymous author claims. This particular claim, that customers are being billed for text not delivered, may follow from a misunderstanding of Anthropic's terms: "You are charged for all thinking tokens generated, even when collapsed or redacted," the company's documentation explains. Under that legalese, a thinking summary costs the same as the full output. And it's unclear whether bug-based truncation would change the billing picture. "Thinking has a cost: the tokens Claude spends reasoning are billed as output tokens, even when the thinking text isn't returned to you, and they count toward max_tokens alongside the response text," the company explains. To reduce spending on thinking, customers are advised to lower their budget setting or disable thinking. Separately, the Anthropic API has been seen terminating data streams during long-running thinking sessions. There have been at least seven other related API bug reports, but the streaming issue identified by developer Hector Bernstorff describes client-side defects. The Register understands this particular issue has to do with tuning network behavior, specifically to terminate or retry long running requests. Work is ongoing to balance perceived latency against the risk of requests getting stuck. "Claude Code ships updates nearly every day, and reports from the community like these GitHub issues are a big part of how we catch problems quickly," an Anthropic spokesperson told The Register. "We're grateful to the developers who take the time to file them, and we'll keep fixing things as they come up." ®

Risolta vulnerabilità in OpenSSL

14 Agosto 2026 ore 09:12
Rilasciato aggiornamento di sicurezza per una nuova vulnerabilità, con gravità “alta“, che interessa OpenSSL, nota libreria per l’implementazione degli standard crittografici e i protocolli TLS/SSL. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di compromettere la disponibilità del servizio sui sistemi interessati.

Rilevate vulnerabilità in FreePBX

24 Luglio 2026 ore 13:43
Rilevate sei vulnerabilità di cui due con gravità “critica” e sei con gravità "alta" in vari moduli di FreePBX, piattaforma open source per la configurazione e la gestione grafica di centralini telefonici basati su Asterisk. Tali vulnerabilità, qualora sfruttate, potrebbe consentire a un utente malintenzionato di eseguire codice arbitrario ed alterare i dati sui sistemi interessati.

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

14 Agosto 2026 ore 08:41

The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.

The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek.

Five years after quitting a job, developer’s former boss asked for rapid tech support

14 Agosto 2026 ore 08:25
ON CALL “I can't stand it, I know you planned it, I'm gonna set it straight, this Watergate” is the opening of the Beastie Boys classic Sabotage, a fact we mention as it will soon become pertinent to today’s edition of On Call, The Register’s weekly reader-contributed column that shares your tech support stories. This week, meet a reader we’ll Regomize as “Wade” who in the mid-1980s made a crust by programming in Pick – the minicomputer OS entangled with a database that On Call wrote about last year. Wade told us that he used Pick to write the software that powered a mail order business, before moving on to greener pastures. Several years later, in early 1990, Wade’s mail order boss called him at home in the evening. “He had fired the clerk who did all the work in application I wrote,” Wade explained to On Call. “They entered orders, sent purchase orders out and arranged customer dispatches.” It sounds like the clerk and the mail order company parted ways on bad terms, as this was a “You have an hour to pack up your stuff and leave” affair. “That was unwise,” Wade wrote. “The clerk used that time to sabotage the system … or so she thought, by unplugging it while it was printing the day’s orders.” When the mail order magnate realized the machine was down, he panicked and called Wade – who despite being rather surprised by the summons showed up and realized the first thing to do was plug the Pick machine into a power socket. “I spent a couple of hours booting it up, checking all the data and restarting the print run.” Wade told On Call his old boss was more than happy. “The loss of a night’s sleep was recompensed by the fee I charged,” he wrote. Has someone you’ve forgotten asked you to rescue their tech? If so, click here to send your story to On Call. We promise not to sabotage it if we give it a run on a future Friday. Or as the Beasties put it: “But you, I'm out and I'm gone. I'll tell you now, I keep it on and on.” ®

New Zealand says China tried using space investments to spy on local affairs

14 Agosto 2026 ore 05:23
New Zealand’s Security Intelligence Service (NZSIS) has claimed Chinese companies are building space facilities in the nation to gather military intelligence. Director-general of security Andrew Hampton yesterday made that allegation in the SIS’s annual threat environment assessment. The document points out that New Zealand’s space sector is booming, because the nation’s location makes it “an ideal place to install Ground Based Space Infrastructure (GBSI) … to track satellites and space debris, as well as for collecting a range of other scientific data.” The NZSIS has also found that GBSI is “attractive for foreign states seeking to advance military capabilities and intelligence operations.” The report offers a case study of a China-based organization called “Purple Mountain Observatory” that has “close links” to Beijing and tried to install GBSI in New Zealand. “They worked with a local company that was likely unaware of the equipment’s capability to collect intelligence of military value and would have no idea who was receiving the data,” the report states, before noting that Chinese laws mean Purple Mountain could be compelled to provide information to China’s government. The intelligence agency believes Purple Mountain “would have … willingly passed on” data it collected. “NZSIS, working with other agencies was able to disrupt this activity, but it was not the first time this organisation has attempted to install its own GBSI in New Zealand and is unlikely to be the last.” The report rates China as the only country targeting New Zealand at scale, based on activity NZSIS has been able to observe. “We have observed increased targeting of professional networking sites and online job platforms for espionage purposes by China’s military intelligence services,” the assessment finds. "PRC (People’s Republic of China) intelligence officers, or their affiliates, use an aggressive strategy where they pose as consultants or employees of think tanks, or recruitment firms. They place online job advertisements looking for analysts in foreign policy, international relations, defence or security,” the document states. “Candidates are then vetted by PRC intelligence to determine what information they have had access to and whether they would divulge it. The job offers are lucrative, but the intelligence officers often encourage their candidates to keep their government jobs both to keep the information tap running and to open up opportunities to recruit their colleagues.” The report also observes that some recent cyber-attacks were probably the work of state-backed groups trying to destabilize New Zealand. “Looking for the sharpest needle in endless giant stacks of needles” The document also addresses domestic threats, especially violent extremism. “Part of our job is to work out whether someone’s vitriolic and violent online pronouncements have any link to New Zealand,” the report states. “This is a narrow focus but the pool of information and intelligence we are working with is vast.” “We used to describe our work as finding a needle in a haystack. However, the internet has changed. Large volumes of toxic content, widespread anonymity, and hidden locations mean our job is now like looking for the sharpest needle in endless giant stacks of needles.” “Extremist rhetoric, particularly online, has become more mainstream, a development which has made it even more challenging to differentiate between genuine support for violent extremism, hateful language designed to shock, or online content created simply to drive engagement or ‘likes’.” NZSIS also has to keep an eye on encrypted messaging services and even gaming platforms, to counter violent online communities. “Algorithms on various social media platforms can link non-violent content to progressively more extreme material,” the report states. “The gateway subject matter can quickly expose people to violent extremist content that can support radicalisation.” Kiwis aren’t just recipients of this vile material. “NZSIS has observed New Zealand violent extremists use encrypted messaging systems, social media and online gaming platforms to circulate violent material including weapon tutorials and objectionable content. Their presence on these platforms, many of which are mainstream, also helps them to find like-minded individuals or supporters.” ® Bootnote: Readers interested in New Zealand’s intelligence services might enjoy 2026 comedy series New Zealand Spy, a deadpan delight.

OpenAI ditches Recall-style screenshot surveillance for friendly keylogging

14 Agosto 2026 ore 02:27
If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt injection, then OpenAI has something for you. It's called Computer History, an opt-in way to record your computer interactions across apps and websites as memories organized on a timeline. Why would you want to do so? Maybe you found Chronicle, the predecessor of Computer History which compiled similar histories using screenshots, a bit too intrusive but don't mind Computer History's approach – recording input events and storing them unencrypted locally for 48 hours (or more), with a brief visit to OpenAI's servers. Maybe you're not bothered by the warning OpenAI includes in its documentation: "Computer History files can contain sensitive information. They are not encrypted by Computer History, and other programs running as your macOS user may be able to access them." Perhaps, having given OpenAI's Codex and GPT Work the run of your computer, you're already sold on the suggestion that storing your computer activity in memory files and arranging those interactions in a timeline will improve ChatGPT responses, surface opportunities for automation, and make it easier to resume prior work. Computer History is, to put it bluntly, a keylogging and event capture system. There was a time before eyeglass cameras, license plate readers, surveillance capitalism, and police drones when such snooping might have provoked an outcry from privacy advocates. But the tech industry has found it can outsource surveillance to its own customers and in so doing make the panopticon harder to protest once it becomes a personal choice. "Computer History creates an interaction-event stream from allowed apps and websites," OpenAI's documentation explains. "Events can include clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system. Computer History periodically turns these events into text summaries and local memory files." The AI biz makes a point of noting that Computer History does not capture screen images, microphone input, or system audio. Nor does it capture private-mode browsing. Off by default, Computer History is available for ChatGPT Pro, Business, and Enterprise users in the ChatGPT desktop app on macOS. Pro users can enable it individually; Business and Enterprise users need an admin to approve it. It's not available currently in the European Economic Area (EEA), Switzerland, or the United Kingdom or to those accessing ChatGPT via API key or Amazon Bedrock. There are circumstances in which OpenAI suggests Computer History users might want to suspend the service if they have some scruples about capturing user activity in apps and websites without permission. "Turn it off during communications with other people unless you have their prior express consent," the company advises, perhaps in acknowledgement of legal risk. "Consider pausing it or excluding apps that contain sensitive health, financial, or personal information." Computer History interaction events are supposed to be saved locally for up to 48 hours before being deleted by ChatGPT and Codex. Events, however, get sent to OpenAI servers to generate memories, and those may be stored locally for longer periods of time and may be used in future chats that get passed back to OpenAI. "OpenAI does not retain those event files after processing unless required by law and does not use them for training," the company says. While it has opposed demands for chat logs, it has nonetheless provided chat logs in response to legal process. Computer History adds cost because it uses tokens during the summarization of activities and the creation of memory data. It also expands the prompt injection attack surface. "Computer History increases the risk of prompt injection from content in apps and websites," the company says. "For example, if you visit a website containing malicious instructions, ChatGPT or Codex might follow those instructions." But at least you get a nice timeline of your recent activity. ®

Give Google the boot by building your own search engine

13 Agosto 2026 ore 22:48
If you're fed up with search results drowning out the bits of the web you actually care about, you could always build your own search index, as one developer did. Nottingham, UK-based software dev Alex Morley-Finch built the open-source project dubbed Marlin for himself, cataloging around 560,000 homepages for roughly $10 in rented cloud GPU time and using less than a gigabyte of disk storage. Morley-Finch said in a writeup of the project that he wanted a search engine of things he cared about, like “portfolios, zines, weird little art projects, one-person software,” and other cases of just “people doing stuff” that they share on the internet. Something simple, with “a crawler that only ever looks at homepages, a small local language model that reads each one and writes a name, two or three sentences, a category, and a handful of tags,” he explained. “No IP scanning, no Redis, no storing full page HTML, no recrawl scheduler, nothing multi-tenant.” Morley-Finch built Marlin around four processes: A fetcher that grabs domains, a worker that makes calls to a small, OpenAI-compatible language model, a steward that prevents bad pages from making their way into the index, and an API with a web UI where he can track the process and actually conduct searches of his index, complete with filters. Of course, you can’t expect something like this to go perfectly on the first try. “The first version worked within a couple hours. Point it at a sample of domains, watch things get summarised, search for them. Great,” he said in his writeup of the project. “Sunday afternoon [he began working on Marlin on a Sunday], I looked at what had actually been catalogued and it was the wrong web.” Instead of indexing what he wanted it to, Marlin had just been grabbing a cross section of the internet, leading to more than 90 percent of the first attempt being “corporate sites and documentation.” Rather than blocking certain domains, Morley-Finch built a weighting system to push certain pages to the top of his crawl queue, and others as far down the list as possible. Morley-Finch rented a cloud GPU to handle most of the heavy processing and stopped the crawl at around 560,000 pages after exhausting his prioritized categories and beginning to pull in "the raw internet." He spent around $10 on the cloud GPU. The one overarching problem he had, and which he said may be a problem for anyone else who tries to replicate his project, is tagging and categorizing - left to a language model, those important elements got a bit messy. “I let the model invent its own category and tag names freely, on the theory that it would teach me the taxonomy instead of me guessing one upfront,” he explained, noting that it helped things get started quickly, but “I ended up with 671 distinct categories, many used exactly once, and over 121,000 tags, more than half used only a single time.” Morley-Finch had to build a manual merge tool to clean up the mess, leading him to declare that his design likely won’t scale well beyond a hobbyist project, as “‘just let the model freestyle’ catches up with you fast.” Still, he reckons Marlin’s rough edges shouldn’t put off anyone willing to spend a weekend tinkering with it. “I think this is very doable in a weekend, and cheap enough that the GPU bill isn’t the reason not to try,” Morley-Finch wrote. “The code is going up as open source, so you can point your own crawl wherever your own curiosity leads.” The Marlin GitHub repo is filled with how-tos and details for those who want to create their own weighting list based on their priorities, with the option to rent a cloud GPU if their hardware isn't up to the challenge. ®

Microsoft's dueling Copilot apps have combined into a single entity

13 Agosto 2026 ore 21:04
Microsoft’s consumer Copilot app and Microsoft 365 Copilot are separate no more, with a unified Copilot app beginning its rollout Thursday - minus a few features. The Windows maker and AI pusher announced the Copilot superapp rollout in a help page update Thursday, describing the move as a way to simplify its app ecosystem and make the entire Copilot-first experience “more cohesive” for both consumer and business users. “Depending on the account and device you use, you will see changes to the Copilot app including changes to appearance and functionality, such as navigation, feature availability, or sign-in experience,” Microsoft explained on the help page. The new Copilot app brings not only new branding but structural changes as well. The Copilot bot and its image generation features now live alongside the Microsoft 365 suite, files, and other content, allowing users with an account supporting the classic Office package to access their productivity software alongside Redmond's chatty LLM. Copilot users without a paid subscription, naturally, face lower usage limits and fewer features, but support for multiple accounts means users can switch between personal and work or school profiles instead of having to hop between entirely separate apps. “You can continue to chat with Copilot, create images, upload files and more for free, subject to available capacity and limits,” Microsoft said. “For higher limits to chat and create, use agents, or tackle complex multi-step tasks, purchase a Microsoft 365 subscription.” Whether the new combined app will come with nag messages is up to users to find out. What this change will look like in practice varies based on the sort of account a Copilot user had before the merger. Those who just use Copilot with a personal account “will be moved to an updated version of Copilot,” with chat history and most content transferring to the updated app. Files shared and generated with the old standalone Copilot app will be shunted to OneDrive if you’re wondering where they went. Users of Microsoft 365 Copilot, the name Redmond slapped on the Microsoft 365 (Office) app in January 2025, “may notice some updates to appearance and navigation,” so get ready to rediscover where certain options and buttons are. What Microsoft left behind Microsoft is abandoning a few features from the old Copilot apps as part of the merger: It is removing Podcasts and Group Chat and scrapping Deep Research from the consumer Copilot app, while Microsoft 365 Premium subscribers can instead use the separate Researcher feature. All of this will be effective as of August 18. Podcasts that were created or saved in Copilot will be entirely unavailable, per an FAQ page, and links to any shared podcasts will stop working. Microsoft recommends downloading any podcasts users want to save before updating to the new app, or they’ll be lost. Group chats, along with any shared content and images created in group chats, will be wiped. Microsoft recommends downloading any messages and content users want to save and tossing them in a document, as Redmond doesn’t appear to be offering an automated way to preserve them. As for Deep Research, which offered standalone Copilot app users a version of Microsoft’s chatbot able to look stuff up on the web and compile reports, those reports are being preserved in chat history for Microsoft 365 Personal and Family subscribers, while Premium subscribers can access saved research through Researcher. Researcher offers similar abilities to Deep Research, but sorry free and lower-tier users: It’s only available to premium customers now. Windows Central reported on Thursday that the rollout of the unified Copilot app is beginning now, with mobile and web coming in the initial wave and an early-access option for Windows and Mac, ahead of a broader desktop rollout expected in the middle of next month. We’ve been unable to confirm that timeline with Microsoft. ®

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

13 Agosto 2026 ore 20:45
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

13 Agosto 2026 ore 20:17
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods. The latest ThreatsDay Bulletin puts all of these short updates in one place, so you can quickly catch up on what happened, what changed, and what security teams

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

13 Agosto 2026 ore 17:00
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

13 Agosto 2026 ore 15:43
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spread via a counterfeit GitHub download page titled "Download for macOS" and claims to be from a verified publisher. The page employs a ClickFix-style lure that

❌