Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Homebrew 7.0.0 Ships With Fixes for Eight Security Advisories

  Homebrew, a popular package manager for installing command-line tools and desktop apps on macOS and Linux, released version 7.0.0 on Sunda...

All the recent news you need to know

A $159 Circuit Board Just Broke Cloud Computing's Strongest Security Guarantee

 




Security researchers have found a way to defeat the memory protections that Intel and AMD sell to cloud customers as their last line of defense against an untrusted host. The tool required costs less than a decent pair of headphones.

A team from KU Leuven, ETH Zurich, Durham University, and Google published details Sunday of an attack called DDRop, which exploits a fundamental design flaw in the memory encryption hardware powering confidential computing services at Amazon, Microsoft, and Google. It breaks protections in Intel Trust Domain Extensions (TDX), Intel Scalable SGX, and AMD Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP), the three technologies that allow cloud customers to run workloads that even the cloud provider cannot read.

The method does not require a software exploit. It requires a small custom-built circuit board, a brief window of physical access to the server, and knowledge of how DDR5 memory commands work. The researchers built their device for $159 in parts.


The Gap Nobody Patched

Confidential computing encrypts a server's working memory at all times. Even a cloud provider's own administrator sees only scrambled data. The problem DDRop exposes is that encryption is not the same thing as freshness. The processor can confirm that data in memory is encrypted. It cannot confirm that data is current. Stale data, so long as it was encrypted legitimately at some point in the past, will still decrypt correctly and raise no alarm.

DDRop turns that gap into an attack. A small interposer board sits between the processor and a DDR5 memory module. When the attacker wants to cancel a specific memory write, the interposer forces a parity error on the command bus. The memory module silently discards the write. The interposer then cuts the wire used to report that error, so the processor is never notified. Old data stays in memory. The system has no way to know the latest update never arrived.

This is the first active interposer attack to run on DDR5 at full bus speed. Earlier DDR5 research required slowing the memory bus down and could only listen passively. Previous active attacks that altered memory contents only worked on older DDR4 hardware, DDR5's redesigned command format blocked them. DDRop routes around that entirely by dropping writes rather than redirecting them.


What the Researchers Pulled Off

On an Intel TDX server, the team demonstrated four outcomes. By dropping writes to page tables during setup, they mapped an attacker's virtual machine onto any physical memory address, then read a victim machine's private memory in full. They also flipped a victim machine into debug mode, copied its memory in plaintext, and restored everything afterward with no trace of tampering.

The most consequential result was attestation forgery. Attestation is the mechanism a hospital or bank uses to verify that the virtual machine handling their data is the one they approved and has not been altered. With DDRop, an attacker's machine can pass that check as though it were a trusted one. A customer could be convinced they are talking to a secure, verified environment when they are not.

On AMD SEV-SNP, results were narrower the researchers copied the contents of one victim memory page into another but the underlying exposure is the same. Neither platform checks whether memory is fresh.


No Patch, No Timeline

Both Intel and AMD acknowledged DDRop through coordinated disclosure before publication and issued security advisories on September 14. Neither offered a mitigation timeline. Both drew the same line: because the attack requires physical access, it falls outside their published threat model for confidential computing. Intel said it will not assign a CVE.

The researchers are direct about why a software fix cannot solve this. The freshness check was deliberately left out. Scalable memory encryption trades freshness for the ability to protect the large amounts of memory that cloud servers require. A lasting fix would need new memory-encryption hardware capable of providing both integrity and freshness at scale. Intel has discussed a future proposal called cache-line versioning, but has not committed to a timeline and researchers say it is unclear whether it would stop DDRop anyway.

Short-term software measures restricting the memory management interfaces DDRop abuses, checking that critical writes completed, scanning for interposers at boot, can raise the bar without removing the root cause.


The researchers have no evidence DDRop has been used outside a lab. But the significance is what it proves is possible. Confidential computing is the technical promise that certain workloads stay private regardless of who owns the physical hardware. DDRop shows that promise has a physical boundary that can be crossed with $159 in components, a few minutes of access, and knowledge that a rogue data center employee, supply chain tamperer, or government compulsion order could all plausibly provide.

The full paper is scheduled for presentation at ACM CCS 2026 in November. Hardware designs, firmware, and proof-of-concept code are already on GitHub.

Pro-Ukraine Hacking Cat Group Deploys New Malware Against Russian Targets

 

A pro-Ukraine hacktivist group known as Hacking Cat has significantly escalated its cyber operations against Russian targets by deploying newly developed malware, marking a strategic shift from simple website defacements to sophisticated data destruction campaigns. Researchers at Kaspersky uncovered two previously undocumented malware families—Gorilla RAT and Monkey Ransomware—being used in coordinated attacks that exploit server vulnerabilities and encrypt critical files across compromised networks. This evolution demonstrates how hacktivist groups are becoming increasingly capable of mounting technically advanced and sustained campaigns in the ongoing cyberwar between Ukraine and Russia. 

Hacking Cat first emerged around February 2024, initially focusing on low-impact operations such as defacing Russian websites and leaking stolen documents to embarrass adversaries and spread pro-Ukraine messaging. However, by summer 2025, the group began executing more destructive campaigns designed to encrypt and permanently destroy data on targeted systems rather than merely exposing information. This tactical evolution reflects a broader trend among Ukraine-aligned hacktivists, who are increasingly collaborating and sharing custom-built tools to maximize disruption against Russian infrastructure, state-linked organizations, and entities supporting Moscow's war efforts. 

The newly identified Gorilla RAT serves as a remote-access trojan that can tunnel network traffic, enabling attackers to move laterally within victim networks after exploiting vulnerabilities in Microsoft Exchange servers. Monkey Ransomware, which appends a ".monkey" extension to encrypted files, has appeared in multiple variants written in different programming languages since its debut in late 2025. Kaspersky researchers noted that the unusually rapid iteration of the ransomware could suggest the use of generative AI tools to accelerate malware development, though the hackers may also be experimenting with different coding approaches to evade detection and improve effectiveness against diverse targets. 

Joint operations and shared toolkits

Hacking Cat frequently coordinates with other pro-Ukraine groups, including the Cyber Anarchy Squad and the Ukrainian Cyber Alliance, to execute high-impact attacks that cause maximum disruption. In March 2026, the group claimed responsibility for breaching a contractor working for Rosatom, Russia's state nuclear energy corporation, demonstrating its ability to penetrate sensitive industrial networks. Later, in June, it participated in a destructive operation against Donbassteploenergo, a heating provider in Russian-occupied Donetsk, using Nemo Wiper—a tool designed specifically to erase data and disrupt critical infrastructure rather than collect ransom payments from victims. 

The sharing of malware among hacktivist collectives has complicated efforts to attribute specific attacks to individual groups, as multiple organizations now use identical multi-stage infection chains and custom-developed tools. Kaspersky's report linked several tools to Hacking Cat, but the group pushed back in a Telegram statement, acknowledging ownership of "a couple of the tools" while denying responsibility for the ransomware variants. Hacking Cat accused the cybersecurity firm of incorrectly associating unrelated malware with its operations and criticized the quality of its reverse-engineering analysis, highlighting the challenges researchers face in tracking decentralized hacktivist ecosystems. 

Despite these attribution disputes, the overlap in toolkits underscores a maturing cyberwar ecosystem in which Ukraine-aligned hackers are pooling resources, expertise, and custom malware to sustain pressure on Russian targets. The deployment of AI-assisted development tools, coordinated joint operations, and increasingly destructive capabilities signal that hacktivist groups are no longer peripheral actors but integral components of Ukraine's broader resistance strategy. As the conflict continues, cybersecurity experts warn that similar collaborations could emerge elsewhere, reshaping how non-state actors participate in modern warfare through digital means.

Japan Digital Agency Data Breach Linked to VPN Vulnerability


Government Solution Service (GSS) of Japan's Digital Agency was compromised by a vulnerability in a VPN device, resulting in unauthorized access to the shared government platform through an exploit of a vulnerability in the VPN device. In this incident, 246,000 records containing information regarding employees, public officials, contractors, and other individuals connected to organizations using the service may have been exposed. 

Upon discovering unusually large-scale access to files on a server through an account belonging to a maintenance and operations staff member on June 25, the agency first detected the breach. Following an investigation, the agency determined that the account activity was linked to an unauthorized access to a network-connected VPN device. 

By July 9, the agency determined that an external party had accessed the system by exploiting a vulnerability in the VPN equipment. Immediately after the incident, the maintenance account was suspended, and communication between the equipment and external networks was restricted to prevent further access. 

The investigation, conducted with the assistance of an external security company, revealed that some files that contained personal information could have been transferred outside the system. The VPN product used and the specific vulnerability that was exploited have not been disclosed by the agency. Through shared IT infrastructure, 23 Japanese ministries and government agencies are served by the affected GSS environment, which can have a greater impact on the incident. 

The exposed information consists of approximately 236,000 names, 231,000 e-mail addresses, 94,000 telephone numbers, and 1,000 physical addresses. The records relate to personnel and officials who work with GSS user organizations, as well as businesses and individuals who support those organizations. 

Data containing information belonging to the general public was not included in the affected data, according to the agency. Additionally, the compromised dataset is lacking My Number identification numbers, bank account information, or pension number information. Despite the fact that no confirmed cases of misuse have been identified, the exposed contact information could still be used for impersonation, phishing, or other forms of social engineering. 

VPN exposures were categorized as medium severity and were not zero-day vulnerabilities; however, the agency has failed to provide details regarding when the vulnerability was fixed or why the device was still exposed at the time of the intrusion. 

Known VPN Flaw Left Unpatched

Due to the fact that the Digital Agency was already aware of a VPN flaw when the breach occurred, but had not applied the required patch, the incident raises concerns about vulnerability management. According to the agency, the vulnerability has a medium severity and has been confirmed as not a zero-day, indicating that attackers exploited a known vulnerability rather than a newly discovered vulnerability. 

The information accessed is approximately 246,000 records. Over 189,000 of these people are government employees, public officials, or other personnel working for GSS-related organizations, while approximately 57,000 are private companies and individuals involved in government-related activities. 

A total of 236,000 names, 231,000 emails, 94,000 telephone numbers, and 1,000 physical addresses were included in the data. In addition, duplicate entries may be present in the data. More sensitive identifiers are not included in the dataset, such as My Number information, bank account details, and pension information.

Investigation Finds No Confirmed Misuse

The Digital Agency has not received any confirmations of misuse of the exposed information, however, the combination of names and contact information could facilitate targeted phishing or impersonation attempts against affected employees. Messages or phone calls from individuals pretending to represent the government have been warned by the agency, and official personnel will not contact affected parties via email or telephone for passwords or payment information. 

Japan's Personal Information Protection Commission was made aware of this incident on July 15. During the investigation, the agency determined that potentially affected information was likely to be identified and the individuals and organizations involved required a considerable amount of time, which contributed to the delay in public disclosure. 

Digital Agency officials indicated the impact was limited to the affected GSS environment with no evidence of other government systems being compromised or disrupted. As part of its effort to strengthen vulnerability management and review how external connections to the system are handled, the agency is also expected to provide direct notifications to the affected individuals. 

To prevent unauthorized access to sensitive government information and limit unauthorized access, VPN patches should be implemented on time, strict access controls should be implemented, continuous monitoring should occur, and rapid isolation should be instituted.

$13 Billion in Losses Since 2023, Treasury Asks Banks to File Cyber Scam Reports


The federal government has asked financial organizations to be more careful in detecting and reporting scams done by overseas scammers. 

The Treasury Department’s Financial Crimes Enforcement Network (FinCEN) launched and alert to the financial industry besides a detailed study of over 33,000 cyber fraud cases reported between September 2023 and December 2025. According to the report, around $12.7 billion was stolen in a cryptocurrency investment scam from American victims in the US.

As per Treasury Department official Gene Lange, “The transnational criminal organizations behind these scams exploit both emerging technologies and human vulnerabilities, resulting in devastating financial losses for innocent American victims.”

The report is prepared on the basis of reports given by around 1,300 financial organizations and is linked to a 2023 alert from the Treasury about pig butchering scams. FinCen discovered that the rate of scam operations is rising as the schemes go beyond centers in Laos, Myanmar, and Cambodia. 

Scammers use distinct profiles, from financial adviser to romantic partner, and force people into sending money, either via cryptocurrency or with traditional bank transfers.

Significant reports were received from cryptocurrency firms, which found around $5.5 billion in suspicious scam activity. 

Traditional banks reported around $6.4 billion in possible friends, saying they “often detected schemes when a victim sent funds to an [financial institution] in the digital asset sector to purchase digital assets, or when a customer sent a wire transfer to a scam-affiliated beneficiary, frequently referencing digital asset investments.”

The report finds that few victims sent applications for second mortgages and loans as part of their involvement in a scam.

More financial institutions note thousands of incidents where targets liquidated their investment accounts to try wiring transfers or fund digital assess to scammer-related accounts. According to the report, “[A financial institution] involved in the digital assets sector reported an older adult victim transferred nearly $640,000 from her retirement fund to send to a suspected scammer in connection with an apparent digital asset investment scheme.”

“The victim stated she met an individual over social media who instructed her to invest in an apparently fictitious digital asset-related company.”

Another victim took out around $150,000 from his retirement account, withdrew credit on his home, and withdrew a personal loan to send the money to a scammer who pretended to be his digital romantic partner, and wanted to invest the money in a venture.

The filings noted the use of coins like USD Coin (USDC), Ethereum, and Tether (USDT), but 18 more coins were found in the reports.

Your Company's Phishing Tests Are Measuring the Wrong Thing

 



When a phishing simulation returns a low click rate, security teams tend to relax. Leadership checks a compliance box. The program gets renewed. But a major new study suggests that sense of relief may be completely misplaced.

Oslo-based cybersecurity firm Pistachio released its Phishing Behaviour Report 2026 this week, built from 2.47 million simulated phishing attacks sent to more than 123,000 employees across 1,200-plus organizations between June 2025 and May 2026. The finding that runs through all of it: the click rate, which most phishing programs live and die by, is the wrong thing to measure.

"A low click rate can create a false sense of security," said Joe Jones, CEO and co-founder of Pistachio. "What matters more is what happens next: does the employee hand over credentials, recognize the attack and stop, or report it so the wider business can act?"

A click alone does nothing. Credentials do.

Clicking a phishing link causes no damage on its own. The actual risk begins when an employee submits a password or other sensitive information into a fake login page after clicking. That is the moment a simulated test becomes a real-world breach scenario, and it is largely what most phishing programs do not track.

On their very first simulated phishing exercise, more employees in the Pistachio study reported the suspicious email than clicked it. That sounds like good news. The problem is that 1.57% handed over their credentials anyway. In a company with 500 employees, that works out to roughly eight people who will submit login details to a convincing enough lure with zero prior exposure. Click rate metrics would not flag any of them.


Tech workers are not the safe bet they are assumed to be

One of the more uncomfortable findings in the report concerns employees who are expected to know better. Tech development workers clicked at least one simulated phishing attempt at a rate of 30.27%. IT workers were not far behind at 28.53%.

The assumption that technical employees carry lower phishing risk because they understand how attacks work does not hold up against the data. Understanding how phishing operates and catching a convincing one under inbox pressure are two different things.

Construction carries the most risk. Financial services carry the least.

The gap between industries was wider than most organization-wide risk scores would suggest. Construction workers showed the highest click rate of any department at 41.31% and the highest credential leak rate at 16.47%. Design workers, by contrast, clicked at just 26.35%.

Financial services employees topped every resilience category in the study, which carries some irony. Financial services accounted for 27.7% of all observed phishing attempts in 2025, making it one of the most targeted sectors on the internet. That sustained pressure, combined with strict regulatory requirements and mandatory security training, appears to have produced genuinely more vigilant employees at the individual level.

Health workers showed the lowest reporting rate of any department at 13.17%, despite a relatively low click rate. Logistics workers combined an above-average click rate with a below-average reporting rate of 17.11%. In both cases, the click rate alone would present a more reassuring picture than the full data supports.


Things get worse before they get better

Organizations running 12-month programs saw click rates and credential submission rates both rise through the first six months before declining. That initial rise reflects harder and more frequent testing rather than employees regressing. At the six-month mark, employees were receiving an average of 3.5 simulations per person, with 50.4% classified as hard difficulty.

From that six-month peak to the 12-month stage, clicks declined by 27% and credential leaks by 41%. The report-to-click ratio increased from 1.3 at three months to 1.8 at 12 months, indicating that suspicious messages were reported nearly twice as often as they were clicked by the end of the program. 

Organizations that run a single phishing simulation and judge the program from that result are drawing conclusions from the noisiest and least reliable moment in the entire training cycle.


What to track instead

The report does not argue that click rates should be dropped entirely. It argues they should sit alongside credential submission rates and reporting rates, which together give a far more accurate picture of actual resilience. Making it easy for employees to report suspicious emails, through one-click tools and fast confirmation, converts the workforce into an active detection channel rather than a passive one.

NIST research found that 72% of organizations use phishing simulation click rates to gauge training effectiveness. By that measure, nearly three quarters of corporate security awareness programs are optimizing for an incomplete signal, in a threat environment where AI-driven phishing has pushed click rates among untrained employees to a record high of 54% in 2026. 

The click rate was never the whole story. At this point, relying on it alone is a liability.

Lost Phone Reporting Flaws Could Let Hackers Block Any Mobile Device for $4


A new security investigation has revealed serious weaknesses in the systems used by mobile carriers to block lost or stolen phones. Researchers found that an attacker could exploit these flaws to disconnect another person’s smartphone—or even a cellular-connected home alarm—from mobile networks for as little as $2.50 to $4. The attack reportedly took between 20 and 80 seconds, raising concerns about the reliability of a process designed to protect phone owners. 

When a customer reports a phone as lost or stolen, the carrier records the handset’s unique International Mobile Equipment Identity (IMEI) number in an Equipment Identity Register, or EIR. Mobile networks then use this database to reject the device and prevent it from registering for calls, messages and data services. The system is also designed to discourage theft because a blacklisted phone may become unusable, even if someone replaces its SIM card. However, researchers discovered that the process contains weaknesses across multiple layers. 

The study identified six flaws affecting devices, carrier reporting systems and the infrastructure used by telecom companies to exchange blocked-device lists. These weaknesses could allow criminals to submit fraudulent reports or manipulate information without proving that they own the targeted handset. In addition to smartphones, the problem may affect connected security systems and other Internet of Things devices that rely on cellular networks. A malicious actor could potentially disrupt a home alarm, surveillance system or other connected equipment by falsely reporting its IMEI as stolen. 

The findings highlight the risks of trusting a single identifier as proof of ownership. Although IMEI-based blocking can be useful, carriers may need stronger verification, better monitoring and faster recovery procedures for legitimate customers. Providers could require additional account checks, detect unusual reporting patterns and notify owners before permanently adding a device to a blacklist. They should also make it easier for customers to challenge fraudulent blocks and restore service quickly. 

For phone owners, the investigation is a reminder to secure accounts and keep evidence of ownership. If a device disappears, users should immediately activate Android’s Find My Device or Apple’s Find My service, remotely lock the handset and contact their carrier to suspend the SIM or eSIM. They should change important passwords, monitor banking accounts and report suspected theft to the police. Customers who discover that their device has been wrongly blocked should contact the carrier, request an investigation and provide purchase records, account details and the handset’s IMEI number.

Featured