Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Former DigitalMint negotiator sentenced to 70 months for conspiring with BlackCat ransomware affiliates

  A former ransomware negotiator who was hired to help organizations respond to cyber extortion incidents has been sentenced to 70 months in...

All the recent news you need to know

France, Germany Summon Russian Envoys Over Alleged Cyber Espionage Campaign


France and Germany have announced diplomatic action against Russia following allegations that a coordinated cyber espionage and sabotage campaign target multiple European countries. In the coming days, the Foreign Minister said France would summon the Russian ambassador to Paris and impose sanctions on individuals and organizations thought to be involved. 


In Barrot's view, the alleged operation targeted more than a dozen countries, including France, and was orchestrated by the Russian Federal Security Service (FSB). The alleged operation was allegedly intended to conduct both espionage and sabotage across multiple European nations, according to Barrot. The campaign is believed to have targeted approximately 12 countries and is attributed to the coordination of cyber activities by the Russian Federal Security Service (FSB). 

During an interview with French broadcaster BFM TV, Barrot described the operation as a multi-national cyber campaign aimed at both espionage and sabotage. Several Russian individuals and entities are expected to be sanctioned by France for their alleged involvement. The announcement comes at a time when European governments are intensifying efforts to counter cyber threats related to Russia, exacerbated by the Ukraine conflict. 

On Monday, Germany summoned the Russian ambassador as well after joining other European nations in condemning the alleged cyber activities. According to a statement from the German foreign ministry, cyberattacks targeting Germany, European Union member states, and Ukraine are unacceptable and will be retaliated against, including additional sanctions. 

In recent years, French authorities have repeatedly accused Moscow of conducting cyberattacks against the nation's government and public institutions. While geopolitical tensions remain high, these allegations add to a series of cyber-related disputes between Russia and several European nations. As the European Union is preparing its 21st sanctions package against Moscow as a result of the war in Ukraine, diplomatic actions are coming in conjunction with the finalization of the 21st sanctions package. It is also being discussed whether the sanctions list should be expanded to include additional entities and individuals allegedly involved in cyber operations and other conflict-related activities. 

A number of France's institutions have been hacked in recent years, which makes the latest accusations part of a broader pattern of increasing cyber tensions between Russian and European governments. As well as this, the United Kingdom announced a new round of sanctions targeting Russian cyber networks. 24 individuals and entities alleged to be involved in cyber and hybrid operations linked to Russian intelligence services have been restricted by the UK government. 

Senior officials from Russian military intelligence (GRU), such as Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko, have been sanctioned. According to British authorities, the measures aim to disrupt cybercriminal networks and proxy groups accused of engaging in malicious cyber activities aimed at undermining security and stability across Europe. 

France has not disclosed technical details about the alleged cyber campaign, nor has it provided evidence publicly linking the attacks to Russia. The latest allegations have not been responded to by Moscow. The coordinated actions by France, Germany, the European Union, and the United Kingdom demonstrate the growing efforts of the international community to deter state-sponsored cyberattacks through targeted sanctions and diplomatic pressure.

Meta’s Muse AI: How Instagram Users Can Opt Out After Privacy Backlash

 

Meta’s short‑lived Muse Image AI on Instagram let users remix public photos into AI images by default, triggering a storm of privacy and consent backlash before Meta pulled the feature. Meta’s Muse Image tool was designed to turn Instagram into a generative AI playground, allowing people to create new images using photos from any public account. 

By tagging a public handle in an AI prompt, users could generate stylised visuals that borrowed someone else’s likeness or feed without ever asking permission. Meta framed Muse as a creative upgrade, promising strong safety guardrails and quick controls for those who wanted to opt out. But that framing collapsed almost immediately once people realised just how much quiet data sharing sat behind the feature.  

The core problem was consent: adult users with public profiles were opted in automatically, with no upfront notice or explicit choice. Anyone could be remixed into AI art by strangers simply because their account wasn’t private. Reports showed Muse could generate images of people who had never interacted with the tool at all, including photos featuring children who obviously couldn’t consent to such reuse. To make matters worse, Meta’s own policy confirmed users would not be notified when their content was used in AI features, keeping the whole process largely invisible.  

Creators, unions and privacy advocates quickly denounced the opt‑out model as an inversion of basic digital rights. Hollywood unions and talent agencies warned that Muse normalised non‑consensual manipulation of someone’s image and could undermine control over professional likeness and copyrighted work. Digital rights groups called the rollout a “privacy landmine”, pointing to existing harms from deepfakes and non‑consensual AI imagery elsewhere on the internet. Their argument was simple: protection should be the default, and any AI reuse of identity should require explicit, informed opt‑in.  

Under pressure, Meta stressed that private accounts and users under 18 were automatically excluded from Muse, and that any public user could disable the feature with a few taps in Instagram’s Sharing and Reuse settings. Users could also flip their profile to private to lock themselves out of AI remixes entirely. But critics noted these controls were buried, easy to miss and did nothing to remove AI images already generated from someone’s posts. For many, this reinforced the sense that meaningful control arrived only after the data had already been exploited.  

Within days of launch, the backlash forced Meta to pause and then remove the Instagram implementation of Muse Image, admitting the feature “missed the mark” on user expectations. The episode has become a case study in how not to roll out AI features on social platforms, especially when they touch identity and consent. It underscores a wider shift in user sentiment: AI creativity is welcome, but only when people remain clearly informed, empowered and in control of how their content trains or feeds the machine.

Music Industry Introduces Voluntary AI Labels to Improve Transparency in Recordings

 

Several leading music industry organisations have introduced a new voluntary labelling framework for recordings created using generative artificial intelligence (AI), aiming to improve transparency for listeners and encourage wider adoption across the global music ecosystem. 

The initiative, announced on July 10, is backed by the International Federation of the Phonographic Industry (IFPI), the Recording Industry Association of America (RIAA), the Recording Academy (Grammys), and six other industry bodies. 

Highlighting the need for greater transparency, the chief executives of IFPI and RIAA said in a joint statement, "Fans want to know whether and how generative AI has been used. These labels will provide an immediately understandable and easily scalable approach to transparency." 

The framework introduces two categories of labels. The first, "AI-generated," is intended for recordings where artificial intelligence is responsible for generating the entire recording or the majority of its creative elements. This includes music created entirely from AI prompts, as well as tracks featuring AI-generated lead vocals or key instrumental components. 

The second category, "AI-assisted," applies to recordings that remain primarily human-created while incorporating certain AI-generated expressive elements. Under this classification, lead vocals and primary instrumental performances must still be delivered by human artists. 

The organisations said the voluntary system is designed for broad global adoption and could eventually be implemented by music streaming platforms to provide listeners with greater clarity about how AI is used in music production. 

The announcement comes as streaming platforms continue to experience a rapid increase in AI-generated music. Deezer currently identifies AI-generated tracks on its platform and recently reported that nearly half of all new uploads contain AI-generated content. In June, the company also introduced an AI music detection tool that it claims delivers 99.8% accuracy. 

Earlier this year, an Apple Music executive told Billboard that more than one-third of newly uploaded tracks on the platform were created entirely using AI. 

Responding to the announcement, the Digital Media Association (DiMA), which represents streaming services including Apple Music, Amazon Music and Spotify, welcomed the move and said it looks forward to receiving more detailed AI-related metadata to improve transparency for listeners. 

DiMA CEO Graham Davies said, "DiMA has long advocated for the creators, owners, and distributors of music to provide accurate and timely metadata on all music released and distributed to streaming services."  

Spotify has also been expanding its efforts to address AI-generated content. In April, the company introduced its "Verified by Spotify" label to help users identify authentic artists, following earlier initiatives aimed at improving AI disclosure and preventing impersonation. 

Spotify declined to comment on the latest industry initiative, while Apple Music and the Digital Media Association did not immediately respond to media queries.

Galaxy Digital launches $5M initiative to boost Bitcoin against future quantum computing threats

 

Galaxy Digital has announced a new initiative aimed at helping the Bitcoin ecosystem prepare for the long-term cybersecurity risks posed by unprecedented advances in quantum computing, committing up to $5 million in funding for developers and researchers working on technologies designed to safeguard the cryptocurrency's cryptographic foundations. 

The announcement comes as governments, standards bodies and private-sector organizations increasingly accelerate efforts to prepare critical digital infrastructure for a future in which sufficiently powerful quantum computers could undermine many of today's encryption methods. 

The crypto financial services firm said applications are now open for its newly established Galaxy Bitcoin Quantum Readiness Initiative, which is designed to support the development of practical tools and research that could help Bitcoin transition toward quantum-resistant security over time. 

According to Galaxy, grant funding will prioritize several areas considered essential for Bitcoin's long-term resilience. These include the development of post-quantum digital signature schemes capable of replacing today's cryptographic mechanisms, tools that would help cryptocurrency wallet providers and custodians migrate users to new security standards, formal security audits of proposed implementations, and technical work evaluating quantum-resistant transaction proposals before they are introduced to the Bitcoin network. Rather than distributing funds upfront, Galaxy said grants will be awarded individually and released as development milestones are achieved. 

The initiative extends beyond developer funding. Galaxy is also establishing a dedicated research program that will publish ongoing analysis examining quantum-related risks to Bitcoin while tracking emerging mitigation strategies. In addition, the company has formed a Quantum Advisory Council consisting of specialists in quantum computing and post-quantum cryptography to evaluate grant proposals and provide technical guidance for future research efforts. 

Galaxy said it also hopes other organizations across the cryptocurrency ecosystem will participate by contributing funding, collaborating on research, or supporting open-source development that could accelerate Bitcoin's eventual transition to quantum-resistant cryptography. 

Bitcoin currently relies on elliptic curve cryptography to verify ownership of wallets and authenticate transactions. Existing classical computers are considered incapable of breaking these cryptographic protections within any practical timeframe. However, cybersecurity researchers have long warned that sufficiently advanced fault-tolerant quantum computers could eventually execute algorithms capable of recovering private keys from exposed public keys, potentially allowing attackers to forge transactions and steal digital assets if the network remains unchanged. 

Although experts broadly agree that no quantum computer currently possesses the capability to compromise Bitcoin's cryptography, many researchers argue that preparations must begin well before such systems become available. Unlike conventional software updates, major protocol changes within Bitcoin require extensive technical review, community consensus, testing and gradual deployment across a decentralized global network, making the transition to post-quantum protections a multi-year effort. 

Industry concerns have also been reinforced by research estimating the potential scale of future exposure. CryptoQuant has projected that approximately 6.9 million bitcoin, valued at roughly $461 billion at current market prices, could become vulnerable if quantum computers eventually develop the ability to defeat Bitcoin's existing cryptographic protections before the network adopts stronger security mechanisms. While researchers do not consider such a scenario imminent, they increasingly describe proactive migration planning as essential because of the time required to update wallets, infrastructure and network software. 

Preparations for the post-quantum era are also gaining momentum outside the cryptocurrency industry. The U.S. National Institute of Standards and Technology finalized its first post-quantum cryptography standards in 2024, providing organizations with standardized algorithms intended to replace vulnerable public-key cryptography as quantum technology advances. 

At the same time, the U.S. Department of Commerce is investing more than $2 billion through the CHIPS and Science Act to strengthen domestic quantum computing capabilities. The funding package spans nine companies working across multiple quantum hardware approaches, reflecting the U.S. government's broader effort to accelerate quantum innovation while simultaneously preparing national infrastructure for the cybersecurity challenges that future quantum systems may introduce. 

Bitcoin was trading at approximately $66,300 on July 21, while shares of Galaxy Digital had declined roughly 8% over the previous 12 months to trade near $25.20 per share, according to market data referenced alongside the company's announcement.

AI Chatbot Usage Declines as Privacy and Trust Concerns Influence User Adoption

 

A new survey conducted by Future, the parent company of TechRadar, published today reveals the interesting truth that the adoption of AI in the sphere of consumer technology is taking place in the world. People, however, are not using AI chatbots like ChatGPT, Gemini, and Claude as consistently as they did a year ago. 

32% of respondents said that they limit their use of artificial intelligence due to privacy concerns, and another 31% said that they would rather interact with people than AI chatbots. Users believe that chatbots invade their privacy since businesses utilize them to collect, store, and process personal information. 

32% of respondents limited their use of artificial intelligence due to privacy concerns, and this number was the same as last year. It suggests that users are still concerned about the collection, storage, and processing of their data by artificial intelligence systems. 31% of respondents said that they would rather engage with people than AI chatbots. Many users, however, believe that conversational AI cannot match human interaction, even though the technology has improved significantly in recent years. As such, there has been a noticeable shift in the attitudes of consumers toward the use of artificial intelligence, especially chatbots. 

29% of respondents said that they do not require artificial intelligence for their daily tasks, which is a decrease from the same survey last year. Users, however, still feel that generative AI is useless and do not want to adopt it. 

The other concerns regarding the use of AI by the consumers include becoming too dependent on the technology (26%), and having to communicate with others using generic responses and writing, with no personality, as a result of using chatbots (24%). Some respondents were not aware of the capabilities of artificial intelligence (19%) or simply had no interest in the technology (17%). Users also cited the complexity of artificial intelligence, doubts about its usefulness, negative effects on the world, and philosophical views against artificial intelligence as reasons for not being interested in learning more about generative AI technology. 

The survey also stated that 17% of respondents use AI chatbots such as ChatGPT or Gemini several times a day, while 14% engage with them multiple times a day. 30% of respondents never used AI chatbots, while the number was just 16% in the same survey last year. 

Artificial intelligence chatbots, however, are not engaging many people regularly. 21% of respondents use them only once or several times a week, while 11% use them a few times a month, and 8% use them even less frequently. In comparison, 30% of respondents never engage with AI chatbots, which is an increase from 16% in the previous survey. 

Interestingly enough, over 42% of Future publication readers use generative AI to communicate daily, which is double the percentage of respondents who usually read the Future website or books published by Future publishers. 

There is an evident change in the attitude of the consumer towards the use of artificial intelligence in their everyday lives. While many people are adopting AI-powered technology both in the workplace and at home, it appears that the engagement of consumers with artificial intelligence is nuanced. As businesses continue to innovate, consumers are rethinking their relationships with the technology. As such, with the increasing concerns over the privacy, trust, and authenticity of artificial intelligence solutions, it is evident that the consumer will continue to engage selectively with this emerging technology.

FakeGit Malware Campaign Abuses GitHub Repositories and AI Tools

 

There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware, which is increasingly targeted at exploiting artificial intelligence (AI) tools and Model Context Protocol (MCP) servers in order to distribute the malware. 

Researchers at Island have discovered that approximately 7,600 malicious GitHub repositories have been constructed by using approximately 6,600 false developers profiles, creating nearly 7,600 malicious GitHub repositories. 

Thousands of repositories are masquerading as AI skills or MCP servers, offering integration with services such as Google Mail, WhatsApp, Docker, Jenkins, and Databricks. It is believed that FakeGit is an evolution of a previous malware operation that was previously associated with Water Kurita and that used Lumma Stealer. 

Research by Island researchers indicates that in March 2026, the campaign began focusing on artificial intelligence-based repositories, peaking in April with hundreds of repositories impersonating artificial intelligence tools before expanding into a broader ecosystem of fake AI agents, workflows, and MCP servers. By copying code, creating convincing README files, and impersonating developer identities, the fake repositories are very closely resembling legitimate open-source projects. 

A multi-stage infection chain is triggered by the download of malicious ZIP archives. Upon activation, the attack launches a LuaJIT-based loader that launches an obfuscated Lua script to install SmartLoader. SmartLoader establishes persistence on the compromised system and launches StealC, a malicious program capable of harvesting sensitive data from infected devices once it has been activated. 

After installation, SmartLoader creates persistence using scheduled tasks, retrieves its C2 server using the Polygon blockchain smart contract, downloads encrypted payloads hosted on GitHub, and ultimately deploys the StealC information stealer by deploying the C2 server. A new advanced tactic, AgentBaiting, has also been identified, which highlights how AI-powered coding assistants and autonomous agents can unintentionally aid hackers in gaining control of a computer. 

By optimizing fake repositories, threat actors can provide users with legitimate resources instead of forcing them to visit malicious links. Research conducted by Island researchers demonstrated that Claude Code automatically replicated malicious repositories and downloaded the associated files onto a test system, resulting in the discovery and recommendation of legitimate resources by AI models searching for free AI skills or MCP servers. 

In spite of this, the AI assistant detected suspicious indicators before executing the payload, which suggests that even though AI agents can be manipulated into retrieving malicious content, they may still be capable of detecting threats later on during the execution phase. In spite of the fact that these limited tests were not intended to measure the overall detection capabilities of artificial intelligence coding assistants, Island research demonstrated that AI assistants, such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, could detect malicious repositories during routine searches in response to user requests. 

Through artificial intelligence-assisted discovery processes, attackers can potentially pass malicious installation instructions to users without direct human interaction. More than 14 million downloads were recorded between the 335 malicious release assets hosted in approximately 211 FakeGit repositories as a result of GitHub's public statistics. 

In analyzing this figure, researchers cautioned that it represents cumulative download requests, including automated activity, and should not be interpreted as a count of successful infections. According to security experts, FakeGit illustrates how trust in open-source ecosystems and AI-assisted software discovery can be exploited without directly compromising any platforms. 

It is more common for attackers to distribute malware through convincing branding, fictitious developer identities, and public registries. To prevent malicious code from entering development environments, organizations should verify repository publishers, evaluate AI skills and MCP servers in isolated environments before deployment, maintain approved catalogs of trusted AI plugins, and monitor AI-assisted workflows to ensure that they are not compromised. 

A number of the fake repositories were also observed to be more credible by using duplicate project descriptions, fabricating star ratings and fork counts, and impersonating legitimate developer identities, as well as impersonating legitimate developers. In this manner, malicious projects were significantly more likely to be trusted and downloaded by developers and AI-assisted coding tools. 

AI agents are increasingly involved in the discovery and deployment of software, but researchers warn that the security of these automated workflows is as important as ensuring that human users are protected from traditional social engineering attacks. Using trusted developer platforms and AI-assisted workflows, cybercriminals are adjusting to the AI era through the FakeGit campaign. 

The increasing reliance on AI tools and open-source repositories calls for verification of software sources, limiting untrusted AI integrations, and strengthening supply chain security.

Featured