Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Meta's AI Agent Read 187,000 Private Messages. Now Apple Is Changing the Rules

Apple has announced plans to overhaul one of macOS's most powerful privacy settings, citing security risks posed by AI agents that have ...

All the recent news you need to know

AI Spam Surge Forces Google to Pause Open Source Bug Bounty Program


OSS VRP (Open Source Software Vulnerability Rewards Program) has temporarily been suspended after a sharp increase in automated reports that were found to be valid. Since October 1, security teams and open-source maintainers have been facing an increasing number of low-quality vulnerability reports generated via artificial intelligence. 


The pause, which took effect on October 1, is in response to increasing volumes of low-quality vulnerability reports. Google announced the OSS VRP in August 2022 as a means of rewarding researchers who identifies and responsibly discloses security flaws in open-source software maintained by the company. 

The program covers projects such as Golang, Angular, Bazel, Protocol Buffers and Fuchsia, along with selected third-party dependencies. Security concerns regarding GitHub Actions, application configurations, repository settings, and access control rules are also covered by this program. There was initially a range of rewards available from $100 to $31,337 under the program, with particular emphasis placed on vulnerabilities that could potentially pose significant risks for software suppliers. 

As a result of the company's wider vulnerability rewards program, millions of dollars have since been awarded to researchers, making the OSS VRP an important means of identifying security vulnerabilities in widely used open-source projects. An increase in automated submissions was responsible for the current suspension, according to the company, with the majority failing to identify valid security issues. 

Although the use of artificial intelligence-assisted tools has made the generation of vulnerability reports at scale easier, the resulting volume may also include incorrect findings, duplicate claims, and reports concerning vulnerabilities that do not exist. OSS VRP is currently being reviewed by Google to address the issue and determine how the program should handle the growing number of automated submissions. 

A further update is anticipated in the first quarter of 2027. Additionally, the company clarifies that the change does not affect outstanding reports or product vulnerabilities submitted prior to October 1. The impact of the AI-driven reporting surge extends beyond Google's program as well. 


It has not been the company's first time experiencing a sharp increase in low-quality vulnerability submissions that have been generated by automated tools. This raises concerns about the time security teams will need to spend validating reports that do not identify genuine vulnerabilities. The Google Patch Rewards Program continues to offer incentives to researchers for submitting high-impact open-source security patches that qualify for rewards of up to $15,000. 

Google Cloud's Cloud Vulnerability Reward Program provides a means of reporting security vulnerabilities affecting open-source repositories related to Google Cloud products. Google's decision follows similar developments elsewhere in the security industry. In January, the curl project maintainer terminated its HackerOne bug bounty program in response to a significant number of low-quality, artificial intelligence-generated vulnerability reports. 

As part of its Intigriti bug bounty program, Intel also removed financial rewards in September, though the company did not provide a publicly stated reason for the change. As the use of artificial intelligence tools increases in speed, potential vulnerabilities are identified and reported more rapidly, while the review process remains the responsibility of security researchers and maintainers. 

Earlier this year, Microsoft warned that AI-assisted vulnerability discovery could increase the number and scale of security discoveries, potentially increasing the operational demands on security teams. Google has not yet confirmed that the Open Source OSS VRP will be permanently discontinued. The company is reviewing the program and anticipates making changes in the first quarter of 2027. 

For now, the temporary suspension reflects a growing challenge for bug bounty programs, namely, how to handle a large volume of automated reports without allowing invalid findings to overwhelm genuine security issues. 

The decision of Google highlights the difficulty of vulnerability reward programs as AI-assisted security research increases submissions. It will become increasingly important for these programs to distinguish genuine findings from automated and inaccurate reports in order for them to be effective.

South Korea Orders Financial Sector Probe After Series of Data Breaches

 

South Korea is gearing up to respond to a string of cyber disruptions that targeted financial institutions, with the President demanding a thorough inquiry about the recent personal data breaches and protection of future incidents.  

The Financial Services Commission (FSC) is leading the response and is holding meetings with industry bodies, regulators, and officials from impacted financial institutions to discuss the next steps. FSC Chairman Lee Eog-weon warned that finance companies must remain on high alert as the authorities trace the source of the cyberattack. The security breach investigation was initiated after Shinhan Bank notified the FSC about the incident on September 30. 

Following that, regulators opened on-site inspections and expanded the probe as more financial institutions reported a cyberattack. Shinhan Bank and KB Kookmin Bank were the two financial firms named by the FSC, while Yonhap News Agency reported that Hana Bank and Woori Bank also experienced data leaks. FSC decided to call an emergency meeting of senior officials to review the situation, moving it from its original date, October 7. 

According to Korean media, the main reason for the emergency meeting was related to the fact that more financial institutions became victims of cyberattacks, and that additional breaches at secondary financial institutions were also suspected. Regulators are also considering the possibility that AI might be involved in the cyberattack. Lee warned that the involvement of AI in the cyberattack cannot be ruled out and that the response should be based on AI-driven cybersecurity solutions. 

In addition, the FSC is considering implementing enhanced cybersecurity measures for the finance sector. Among the first steps taken by the FSC is a recommendation that financial institutions conduct a cyber hygiene review. FSC urged finance companies to implement stricter access controls, reduce the exposure of their systems, and introduce additional measures to protect consumers from potential data abuse. Furthermore, the FSC is pressuring financial institutions to share information about the cyber incidents. 

The information exchange process should include attack methods, internet protocol (IP) addresses, and other details. It would enable financial companies to develop a joint response and recognize other potentially impacted entities. The cyberattack might have been targeting financial hubs rather than the single institution, according to one scenario produced by South Korean regulators and reported by Yonhap. The unnamed regulators believe that the cyber attackers targeted several financial institutions in an attempt to scan the system to find weaker areas.  

According to the information provided by the banks to the National Assembly, the cyberattack came from various IP addresses. Those locations spanned across several countries, including the US, Japan, Singapore, Vietnam, and the UK. South Korea’s opposition People Power Party is demanding that the government investigate whether North Korea was behind the cyberattack. 

The cyberattack could be a retaliation for decades of cyber espionage and economic sabotage by Pyongyang, according to the party. The response from the FSC is to keep investigating the cyber incidents and urge financial institutions to boost their cybersecurity measures and share information about the cyber incidents.

Denmark Population Registry Breach Exposes 8.8 Million Citizens

 

Denmark is grappling with one of the most significant data breaches in its history after unauthorized actors gained access to the Central Population Register (CPR), exposing the personal information of approximately 8.8 million individuals. The breach, discovered in early October 2026, affects not only current residents but also includes data on people who have moved abroad and even deceased individuals. The CPR serves as Denmark's national civil registry and contains highly sensitive information including names, addresses, dates of birth, marital status, and unique CPR identification numbers that are integral to daily life in the Scandinavian nation. 

The attack was carried out through a sophisticated method involving a private Danish company that had legitimate access to the registry system. According to authorities, threat actors misused this company's credentials to extract data from the CPR database. The Danish Data Protection Agency revealed that the attackers employed brute-force techniques to enumerate valid CPR numbers before systematically extracting associated personal data from each entry. This method allowed them to harvest information on a massive scale, impacting roughly 80% of the 11 million registered citizens currently in the CPR system, making it one of the largest population registry breaches ever recorded in Europe. 

Security officials detected the breach on October 2, 2026, though the actual incident occurred earlier in September. Once the CPR administration became aware of the compromise, they immediately blocked the private company's access to the registry and launched a comprehensive investigation with police assistance. Minister for Research, Education and Digitalization Christina Egelund described the incident as extremely serious and promptly informed Parliament's Business and Digitalization Committee. The government has since implemented additional security measures to prevent similar incidents and is working with all relevant authorities to establish the full extent of the damage caused by this unprecedented security failure.

In response to the breach, Danish authorities have established a dedicated cyber hotline to assist potentially affected individuals and provide guidance through the website sikkerdigital.dk. Officials are urgently warning citizens to remain vigilant against unsolicited communications, emphasizing that criminals may use the stolen data to craft convincing phishing attempts. The government specifically cautioned that people should never disclose passwords or confidential information in response to telephone calls, emails, or similar communications, even if the caller appears to know their name, address, and CPR number. This warning is particularly critical because the exposed data could enable highly targeted social engineering attacks that would be difficult for ordinary citizens to identify as fraudulent. 

The Denmark CPR breach represents a stark reminder of the vulnerabilities inherent in centralized population databases and the catastrophic consequences when such systems are compromised. As investigations continue, questions remain about how the private company's credentials were obtained and whether additional security lapses contributed to the scale of the breach. For millions of Danes, the incident means living with heightened risk of identity theft, financial fraud, and privacy violations for years to come. The breach also raises broader concerns about data protection practices across Europe and may prompt other nations to reassess the security of their own civil registry systems in an increasingly dangerous digital landscape where personal information has become a valuable commodity for cybercriminals worldwide.

Belarusian Hackers Compromised Russian Healthcare Network for Two Years


A Belarusian hacktivist gang allegedly maintained access to the network of a Russian healthcare organization for almost two years, potentially gaining access to sensitive medical information, cybersecurity researchers have reported.

Researchers from Russian cybersecurity company Solar said they discovered the intrusion in December 2025. However, their investigation found evidence suggesting that the attackers had entered parts of the organization’s infrastructure as early as 2024.

Attack details

The attack was attributed to the Belarusian Cyber Partisans, a group known for cyber operations against Belarusian and Russian government organizations and businesses.

Despite remaining inside the network for an extended period, the attackers did not appear to destroy systems or cause major disruption. Researchers believe maintaining access may have been more valuable to the attackers than immediately carrying out destructive activity. 

Intrusion details

Solar researchers identified several tools associated with the intrusion, including an updated version of the Vasilek Windows backdoor.

Vasilek was previously documented by Kaspersky as malware used by the Cyber Partisans. The backdoor can communicate with attackers through the Telegram Bot API and receive commands through a Telegram group. It can collect information from infected computers, execute Windows commands, transfer files, capture screenshots and record keystrokes. 

Attack tactic 

Solar said the newer version found during its investigation was version 1.5.8. Researchers also identified techniques for maintaining persistence inside the victim’s environment. These included Windows services and the replacement of the vmtools.dll library associated with VMware Tools.

The attackers also used other communication and tunnelling tools, including DNS tunnels and proxy chains. This gave them alternative methods of communicating with compromised systems if one channel became unavailable. 

Telegram restrictions in Russia affected Vasilek’s communications, but researchers said the attackers could use other methods to maintain their access.

What next?

The compromised organization was not publicly identified. However, researchers said it operated a large infrastructure connected to multiple other healthcare organizations.

This created a potential trusted-relationship attack risk. Once attackers gained control of one organization, its connections with other trusted healthcare entities could potentially provide opportunities to reach additional networks.

The researchers said the attackers accessed sensitive medical data but did not destroy the victim’s systems. The long period of access suggests that espionage, intelligence gathering and maintaining future access may have been more important than immediate disruption. 

CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS

Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS. 

Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It is initiated by the use of a disk image that is made to resemble the Zoom installer. When a package is opened, it appears as a volume titled Zoom and uses familiar installation elements to create the impression that the application is genuine. 

As part of the installation process, the fake installer displays a password prompt as part of the fake installer, which bypasses macOS Gatekeeper, permitting the ad-hoc signed application to run despite the operating system's security checks. CloudSyncD checks the credentials entered against the local account before the malware continues. Instead of transmitting the password immediately, CloudSyncD stores it locally within a fake configuration file in lieu of transmitting it to a third party. 

Through a normal inspection of the file, it may be difficult to identify the password because it is concealed using encoded data and invisible zero-width Unicode characters. The stolen password is then used as a means of executing the malware's second stage with elevated privileges. Within the dropper, CloudSyncD is packaged as a universal Mach-O binary capable of being executed on Intel as well as Apple silicon Macs. 

The malware attempts to execute the payload using an anonymous file descriptor as a first step, avoiding conventional file writing methods. It is possible to write the payload to disk temporarily and execute it by using sudo using the captured password, if that method fails as a result of macOS security protections. 

Instead of stealing information conventionally, the second stage functions as a backdoor. It establishes communication with the attacker's infrastructure and receives additional executable files or compressed archived archives. CloudSyncD's second-stage implant is relatively quiet after it has been injected. It provides a way for the operator to deliver further malware or tools after the initial compromise. 

By creating a working directory and maintaining encrypted activity logs, the malware avoids the need for a visible persistence mechanism. Check-ins occur every 8 to 16 seconds and include a hardware identifier, suggesting a periodic check-in is occurring. Compared to a simple command shell, the C2 channel provides the attackers with greater flexibility. 

Using CloudSyncD, the compromised Mac can be supplied with compressed archives or executables, which can then be used to run the supplied content. Jamf Threat Labs identified multiple later builds of the backdoor communicating with two live domains following the initial infection. This enables the backdoor to serve as a delivery mechanism for additional malware or tools. They use the same URI structure, which was designed to resemble a request for a jQuery script. 

Both domains were registered with the same registrar in 2011 and were protected by Cloudflare. As of the time of the researchers’ analysis, neither domain was flagged by a security service. A number of technical similarities were also observed between the different samples, including similar string-obfuscation schemes, installation paths, daemon names, and process disguise schemes. 

More importantly, the builds shared the same C2 encryption key and initialization vector, which means network traffic captured from different versions could potentially be decrypted using recovered configuration material. According to the findings, CloudSyncD had moved from an unfinished test build to a functional backdoor utilizing social engineering, while maintaining a relatively simple infection route. 

Researchers distinguish the malware from a conventional infostealer despite the fact that it collects system and user information for reconnaissance. Rather than being sent to the attackers, the captured password is used locally to obtain elevated privileges, while the backdoor's primary function is to provide access and facilitate the execution of additional payloads.

California Court Dismisses El Faro Journalists' Pegasus Spyware Lawsuit Against NSO Group for Second Time

 



A California federal judge has once again dismissed a lawsuit brought by journalists from Salvadoran investigative outlet El Faro against NSO Group, the Israeli company behind the Pegasus spyware allegedly used to surveil their phones for nearly two years. The ruling, issued Wednesday, marks the second time the case has been thrown out on jurisdictional grounds, though the journalists' legal team at the Knight First Amendment Institute at Columbia University has said it intends to appeal.

The case, Dada v. NSO Group, was the first lawsuit against NSO filed in any U.S. court when the Knight Institute took it on in November 2022 on behalf of 18 current and former El Faro journalists and staff. Between June 2020 and November 2021, Pegasus spyware was deployed against the outlet's employees at least 226 times, according to the Institute. Digital forensic analysis eventually confirmed that 22 members of El Faro's staff had their phones infected. The attacks were not random. Surveillance peaked during significant political moments and in the run-up to major investigations, including reporting on the Bukele administration's secret negotiations with criminal gangs, the theft of pandemic food relief, back-channel Bitcoin dealings, and the financial holdings of government officials.

The lead plaintiff, Carlos Dada, is the co-founder and director of El Faro, one of Central America's most prominent independent news organizations. El Faro was founded in El Salvador in 1998 and has built a reputation for independent investigative reporting. The outlet has paid a steep price for that journalism. Beyond the spyware attacks, El Faro says it has faced physical surveillance, advertiser harassment, and public defamation from government officials and ruling-party legislators. In 2023, the newsroom relocated its administrative and legal operations out of El Salvador entirely.

The core question before the court was whether Northern California was the right place to try this dispute. Dada and the plaintiffs argued it was, pointing to compromised U.S.-based infrastructure that was used as part of the attack chain. The judge was not persuaded. The court noted that there was no allegation Apple's California servers were actually exploited in delivering the Pegasus infections, even where the plaintiffs alleged the attacks moved through Apple's iMessage or iCloud systems. The same argument had failed once before: in March 2024, a California federal judge threw out the same lawsuit, saying the case was "entirely foreign" and that the journalists had no standing to sue in the U.S.

That first dismissal did not hold. The Ninth Circuit Court of Appeals reversed the March 2024 ruling in July 2025 and sent the case back to the Northern District of California, finding that the lower court erred in its analysis. The Ninth Circuit had concluded that the district judge failed to properly account for allegations that NSO created Apple ID accounts and engaged with California-based servers as part of the attack infrastructure. One factor that also came into play was a recent acquisition of NSO Group by a group of American investors, which El Faro's lawyers cited as further reason for trying the case on U.S. soil. After the Ninth Circuit's reversal, Dada called the outcome "good news." That window has now closed again.

The journalists had wanted specific remedies from the court. They asked the court to require NSO Group to identify, return, and delete all information obtained through the attacks, to prohibit the company from deploying Pegasus against them again, and to name the government client that commissioned the surveillance. That last demand was perhaps the most politically charged. NSO has never publicly identified its clients. The company maintains it sells Pegasus exclusively to government agencies for use against criminals and terrorists, subject to Israeli government authorization. El Salvador's government has repeatedly denied being an NSO client or playing any role in the surveillance.

With Apple having dropped its own case against NSO in September 2024, and WhatsApp having won a $167 million judgment against the company earlier in 2025, the El Faro lawsuit had become the last active case against NSO Group in U.S. courts. That distinction is now moot, at least temporarily.

The Knight First Amendment Institute plans to appeal. El Faro's director Carlos Dada said when the original lawsuit was filed that the outlet turned to the U.S. court system because justice in El Salvador was not possible. With the case now dismissed a second time and the appeal road still open, that search for accountability continues.

NSO Group did not respond to a request for comment.



Featured