Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

California Court Dismisses El Faro Journalists' Pegasus Spyware Lawsuit Against NSO Group for Second Time

 



A California federal judge has once again dismissed a lawsuit brought by journalists from Salvadoran investigative outlet El Faro against NSO Group, the Israeli company behind the Pegasus spyware allegedly used to surveil their phones for nearly two years. The ruling, issued Wednesday, marks the second time the case has been thrown out on jurisdictional grounds, though the journalists' legal team at the Knight First Amendment Institute at Columbia University has said it intends to appeal.

The case, Dada v. NSO Group, was the first lawsuit against NSO filed in any U.S. court when the Knight Institute took it on in November 2022 on behalf of 18 current and former El Faro journalists and staff. Between June 2020 and November 2021, Pegasus spyware was deployed against the outlet's employees at least 226 times, according to the Institute. Digital forensic analysis eventually confirmed that 22 members of El Faro's staff had their phones infected. The attacks were not random. Surveillance peaked during significant political moments and in the run-up to major investigations, including reporting on the Bukele administration's secret negotiations with criminal gangs, the theft of pandemic food relief, back-channel Bitcoin dealings, and the financial holdings of government officials.

The lead plaintiff, Carlos Dada, is the co-founder and director of El Faro, one of Central America's most prominent independent news organizations. El Faro was founded in El Salvador in 1998 and has built a reputation for independent investigative reporting. The outlet has paid a steep price for that journalism. Beyond the spyware attacks, El Faro says it has faced physical surveillance, advertiser harassment, and public defamation from government officials and ruling-party legislators. In 2023, the newsroom relocated its administrative and legal operations out of El Salvador entirely.

The core question before the court was whether Northern California was the right place to try this dispute. Dada and the plaintiffs argued it was, pointing to compromised U.S.-based infrastructure that was used as part of the attack chain. The judge was not persuaded. The court noted that there was no allegation Apple's California servers were actually exploited in delivering the Pegasus infections, even where the plaintiffs alleged the attacks moved through Apple's iMessage or iCloud systems. The same argument had failed once before: in March 2024, a California federal judge threw out the same lawsuit, saying the case was "entirely foreign" and that the journalists had no standing to sue in the U.S.

That first dismissal did not hold. The Ninth Circuit Court of Appeals reversed the March 2024 ruling in July 2025 and sent the case back to the Northern District of California, finding that the lower court erred in its analysis. The Ninth Circuit had concluded that the district judge failed to properly account for allegations that NSO created Apple ID accounts and engaged with California-based servers as part of the attack infrastructure. One factor that also came into play was a recent acquisition of NSO Group by a group of American investors, which El Faro's lawyers cited as further reason for trying the case on U.S. soil. After the Ninth Circuit's reversal, Dada called the outcome "good news." That window has now closed again.

The journalists had wanted specific remedies from the court. They asked the court to require NSO Group to identify, return, and delete all information obtained through the attacks, to prohibit the company from deploying Pegasus against them again, and to name the government client that commissioned the surveillance. That last demand was perhaps the most politically charged. NSO has never publicly identified its clients. The company maintains it sells Pegasus exclusively to government agencies for use against criminals and terrorists, subject to Israeli government authorization. El Salvador's government has repeatedly denied being an NSO client or playing any role in the surveillance.

With Apple having dropped its own case against NSO in September 2024, and WhatsApp having won a $167 million judgment against the company earlier in 2025, the El Faro lawsuit had become the last active case against NSO Group in U.S. courts. That distinction is now moot, at least temporarily.

The Knight First Amendment Institute plans to appeal. El Faro's director Carlos Dada said when the original lawsuit was filed that the outlet turned to the U.S. court system because justice in El Salvador was not possible. With the case now dismissed a second time and the appeal road still open, that search for accountability continues.

NSO Group did not respond to a request for comment.



China-Aligned TA419 Uses Microsoft AitM Phishing Against U.S. AI Policy Experts

 

A China-linked cyber-espionage group is targeting Microsoft credentials belonging to U.S. policy and regulatory specialists in artificial intelligence, using highly focused social engineering techniques. 

TA419, the threat actor behind the campaign, has diversified its interest from defense, national security, energy, international relations and foreign policy to include those involved in the policy and regulation of AI, a Proofpoint analyst reported. The group has been targeting U.S. and Japan-based think tanks, defense contractors, universities and law firms through credential phishing since at least April 2025. 

One technique, deployed in a February 2026 campaign, involved impersonating prominent figures in economic and AI policy, as well as an Anthropic employee, in an email titled “Request for Feedback on Military Integration of Claude” to influence an AI policymaker at a U.S. think tank. Similarly, around July, the group began targeting individuals including a former White House Office of Science and Technology Policy (OSTP) leadership team member with an impersonation campaign. The attack chain is designed to appear to have come from a trusted source, not direct phishing. 

First, the victim receives an innocuous request designed to gain the confidence of their target by referencing a shared professional interest. If it gets a response, it then replies with a shortened URL. Once the link is clicked, the victim is directed to a Microsoft OneDrive-like adversarial in-the-middle phishing site after several redirections. The Cloudflare Turnstile Captcha is integrated into the attack chain, helping to lend credibility to the link. 

The credential harvesting component of the attack uses a technique called Frameless BitB, which uses a browser-in-the-browser approach to create the illusion of a separate window using only HTML, CSS and JavaScript. This differs from previous use of Bitb by this threat actor, which used an iframe. Proofpoint noted that TA419 has been modifying an open-source iteration of the attack to incorporate its own telemetry and automation components. The campaign uses an in-the-middle proxy to compromise Microsoft authentication by impersonating a legitimate login page.

It appears to be a legitimate login page; however, it is actually using the authentication token from the user’s Microsoft account to gain access to the account. This technique can be challenging to detect because the Microsoft logon page can appear to be authentic while the attacker’s application window is using some of the user’s session information. This allows the attacker to use the credentials to access the Microsoft account. Proofpoint noted that the activity supports Chinese intelligence interests by providing insight into the U.S. regulatory and policy environment around AI. 

The intensifying U.S.-vs-China strategic competition over AI, including issues around model distillation and export controls, appears to be a catalyst for the campaign. Entities should consider implementing phishing-resistant authentication factors such as passkeys, and individuals who received unexpected professional or professional correspondence should take steps to independently verify the request before responding or following any links.  

While the shift to AI policy experts represents a new focus area for TA419, it is not a significant change in the group’s interests. According to Proofpoint, this is an evolution, rather than a revolution, of the group’s current targeting.

China's Ministry Allegedly Funded Research Involving 100+ Academics


The U.K.’s domestic intelligence agency, MI5, has warned that more than 100 U.K.-linked academics have contributed to research projects allegedly funded by China’s Ministry of State Security (MSS).

Impacted areas

The research reportedly covered areas including artificial intelligence (AI), cybersecurity, covert communications and steganography.

The warning was issued in an MI5 Security Service Espionage Alert on September 30, 2026. According to MI5, the research funding was channelled through the China General Technology Research Institute (CGTRI), also known as the China Academy of General Technology (CAGT). 

About the warning

MI5 assessed that CGTRI is being used as a front for China’s MSS and claimed that its primary purpose is to fund research that can improve the Chinese intelligence service’s technical capabilities.

“The alert advises UK academic institutions to immediately review any ongoing or planned collaboration with CGTRI and advises academics to establish the ultimate funding source when conducting any research collaboration with Chinese institutions to ensure CGTRI are not involved,” reads the MI5 security alert.

Associated risks 

The areas of research identified by MI5 are particularly significant from a cybersecurity and intelligence perspective. Artificial intelligence can be used for data analysis, automation and surveillance, while cybersecurity research can contribute to offensive and defensive cyber capabilities.

The alert also revealed covert communications and steganography. Steganography involves hiding information inside another form of digital content, such as an image or audio file, making it potentially useful for concealing communications.

MI5 said that more than 100 academics linked to the U.K. had contributed to projects funded through CGTRI. The agency also said that some researchers may not have known that CGTRI was financially supporting the research they were involved in. 

MI5 further added, “It puts the fact that CGTRI has very strong ties to MSS in the public domain and states that academic institutions, staff and researchers should ensure they are aware of the National Security Act 2023.  Any institution or individual continuing to conduct research ultimately funded by CGTRI should take their own independent legal advice.”

Potential risks

MI5 warned that research developed through these collaborations could potentially strengthen Chinese intelligence capabilities. The agency particularly highlighted the risk to the U.K. because some of the technologies involved could have applications in cyber operations and intelligence gathering.

Chinese Embassy’s Response 

China has rejected the allegations. The Chinese Embassy in the U.K. described the claims as fabricated and baseless, arguing that academic exchanges between British universities and China are voluntary, lawful and mutually beneficial.

Polish Dental Software Firm Hit by Cyberattack

 

Polish dental software provider FELG Software has confirmed a cybersecurity incident affecting its FELG Dent cloud-based practice management platform. The company became aware of the attack on September 28, 2026, and publicly acknowledged it on October 1. A threat actor using the alias Horus reportedly contacted Polish cybersecurity news outlets, claiming to have accessed sensitive information stored in the system. FELG Software also confirmed receiving a ransom demand in exchange for preventing the disclosure of the allegedly stolen data. More than 16,000 dentists reportedly use the company’s tools, meaning one vendor breach could affect patients from numerous independent practices. 

The attackers claim to have obtained records linked to approximately 2.4 million patients and more than 700,000 medical professionals. The allegedly exposed information includes names, addresses, telephone numbers, national identification numbers known as PESEL, company details, medical records, electronic prescriptions, electronic sick-leave certificates and insurance-verification information. The group also claims to have accessed around 1.2 million prescriptions, visit documentation and diagnostic images. However, these figures have not been independently verified, and the company disputes the attackers’ assessment of the incident’s scale. 

FELG Software has reportedly said that the stolen information represents about 10 percent of its overall database, rather than the complete dataset claimed by Horus. Reports also indicate that the attackers threatened to publish or sell the information after the company refused to pay the ransom. One reported explanation for the intrusion involves an IDOR vulnerability, or Insecure Direct Object Reference flaw. Such weaknesses can allow unauthorized users to manipulate references in requests and retrieve records belonging to other accounts when access controls are not properly enforced. 

The incident is significant because FELG Dent operates as a shared platform for many healthcare organizations. A weakness in the central service can therefore create risks across multiple dental practices at the same time. The breach is also reportedly the third attack in three months targeting Polish healthcare software providers, following incidents involving MyDr in August and Medyc, operated by Qbusoft, in September. These repeated attacks highlight the risks created when sensitive medical information is concentrated in cloud systems without strong tenant isolation, monitoring and access controls. 

The exact scope of the FELG Dent breach remains under investigation. Dental practices using the service may need to review logs, identify affected patients and assess their legal notification responsibilities under applicable data-protection rules. Healthcare providers should also reset potentially compromised credentials, monitor suspicious activity and communicate carefully with patients without relying solely on unverified attacker claims. The case demonstrates why software vendors handling medical data require regular security testing, strict authorization controls, vulnerability disclosure processes and tested incident-response plans. Until forensic investigations are complete, the number of affected records and the precise information accessed should be treated as provisional.

ShinyHunters Hacker Reportedly Detained as FBI Seeks Cooperation


The FBI has reportedly detained a suspected ShinyHunters member known online as “Rey” and is cooperating with the government. Jordanian authorities captured a suspect identified as Saif al-Din Khader this week. According to two sources cited by Reuters, Khader is helping U.S. and international investigators identify other members of the hacking group. 


It is believed that Khader's cooperation will provide investigators with information regarding the group's activities and alleged co-conspirators, according to a source. He has shown investigators his electronic devices and digital communication to help locate other suspected members. The FBI has not responded to Khader's reported detention specifically, however it has stated that it is continuing to investigate the recent cyber incident allegedly involving ShinyHunters and is collaborating with international partners to resolve the matter. 

A series of law enforcement actions targeting individuals affiliated with ShinyHunters has led to this reported detention. Dutch authorities arrested a 24-year-old man in connection with an investigation into the group in September. Following the arrest, the FBI issued a warning encouraging other suspected members to surrender while they continued to investigate the matter. 

The developments are following the claim by ShinyHunters that a job portal breach had taken place. As claimed by the group, it obtained a significant amount of sensitive information from FBI systems. Particularly, it claimed to have acquired employee information, though the extent of the alleged theft has yet to be independently verified. During Khader's reported detention, the group's online activity was also disrupted. 

In addition to the disappearance of the group's data leak website, an account previously used to communicate with journalists no longer responded. Later, another ShinyHunters leak site appeared, indicating the group may continue to conduct activities. Moreover, Khader's reported cooperation strengthens the investigation, which has already been conducted by several individuals associated with the ShinyHunters network in general. 

Khader's identity was previously associated with the group until the latest detention was made. It has been reported that Brian Krebs identified Khader as a member of the Scattered Lapsus$ Hunters umbrella operation in 2025, which is affiliated with ShinyHunters, Lapsus$, and Scattered Spider. Aside from being linked to the HellCat leak site and BreachForums hacking forum, Khader had previously asserted that he was cooperating with law enforcement and had ceased all data theft and extortion activities. Those claims were not independently verified. 

While this was the case, ShinyHunters continued to conduct attacks in 2026, including attacks on Rockstar Games as well as Canvas, which disrupted schools across the country. Despite this, the group has continued to engage in data theft and extortion operations. ShinyHunters has recently begun targeting cloud-based services as well as third-party providers, resulting in incidents that are linked to organizations such as Google, Cisco, and Pornhub.

ShinyHunters has also been linked to the May 2026 breach involving Instructure Canvas, while previous investigations have resulted in arrests related to Snowflake-related attacks, PowerSchool and Breached hacking forums. It may be possible for investigators to gain a better understanding of how this loosely organized network operates and who remains active within it through the recent arrests. 

It has been reported that FBI agents have indicated that information obtained from arrests and seized infrastructure may be useful for identifying additional participants. However, the appearance of a new ShinyHunters leak site following the earlier closure indicates that the organization has not been completely dismantled. Furthermore, the case illustrates the difficulty of disrupting cybercrime groups that are built upon informal networks rather than a rigid organizational structure. 

According to Reuters, investigations and prosecutions can become complicated by the young age of some suspects, the fluid nature of related groups, and the limited cooperation of victims. While ShinyHunters' continued online activity suggests that law enforcement efforts are ongoing, the reported detention and cooperation may provide investigators with valuable insight into ShinyHunters' wider network.

Dell Patches Six Critical Flaws in Container Storage Modules, Some Scoring a Perfect 10

 




Dell has shipped security fixes for six critical vulnerabilities in its Container Storage Modules (CSM) that could allow unauthenticated attackers to seize full administrative control over an organization's storage infrastructure and every node in a Kubernetes cluster. Four of the six flaws carry CVSS scores of 9.6 or higher, two of which hit the maximum possible rating of 10.0.

The bugs affect every version of CSM prior to 1.17.0, and Dell patched them in version 1.18.0. The company says no workarounds or interim mitigations exist, which means organizations running the affected software are down to one option: update now.


What CSM Does, and Why These Bugs Matter

Dell Container Storage Modules are Kubernetes-native extensions that manage persistent storage for containerized workloads across Dell's storage product families, including PowerFlex, PowerStore, PowerMax, PowerScale, and Unity XT. Because CSM sits at the intersection of storage credentials and cluster-level access controls, vulnerabilities in the platform carry a particularly high blast radius. An attacker who compromises CSM does not just gain access to data; they gain the ability to manipulate who can access what across every tenant connected to the system.


A closer look at the Six Vulnerabilities

The most severe of the six, CVE-2026-63688, scored a perfect 10.0. The flaw lives in the csm-authorization-storage gRPC server and requires no authentication to exploit. An attacker on the network can send requests directly to this endpoint and pull the backend administrator credentials for every storage array registered with the system. Dell's own advisory described it as enabling "a complete bypass of the csm-authorization security model," handing an attacker full administrative control over storage spanning all five supported Dell storage product families.

The second maximum-severity flaw, CVE-2026-63692, also a 10.0, targets the authorization proxy and tenant service. Like its counterpart, it requires zero credentials to exploit. A successful attack gives an adversary administrative control over the entire authorization service and the ability to access or manipulate storage resources across all connected tenants.

CVE-2026-67269 scored 9.9 and introduces a different threat model. It is a privilege escalation flaw in the ContainerStorageModule Custom Resource reconciler. A low-privilege attacker, not even a full admin, can submit a single maliciously crafted custom resource to the cluster and walk away with root-level access on every node in the environment. The attack surface is as small as one API call; the damage is cluster-wide.

Two of the remaining flaws center on hardcoded secrets. CVE-2026-54472 (CVSS 9.8) buries a static set of credentials inside the CSM Authorization module, allowing any remote attacker to forge cryptographically valid administrative tokens and seize control of the Authorization proxy. CVE-2026-61421 (also 9.8) compounds the problem: the JWT authentication component in karavi-authorization uses a hardcoded signing key. Because the signing secret is publicly available, anyone who locates it, something that is not especially difficult when code repositories are involved, can mint valid authentication tokens and claim administrative privileges without going through any login flow whatsoever.

The final flaw, CVE-2026-67273, scored 9.6 and is a template injection vulnerability. A low-privilege attacker with remote access can manipulate input fed through the template engine to escalate their own privileges, read sensitive information, and tamper with role-based access controls at the cluster scope. Dell's advisory noted that exploitation yields the ability to "create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls."


Context: Dell's Track Record With Exploited Flaws

This batch of CSM vulnerabilities does not arrive in isolation. Dell has faced repeated problems with critical infrastructure flaws being turned against real targets in the field. Earlier this year, researchers at Mandiant and Google's Threat Intelligence Group documented how CVE-2026-22769, a hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines carrying a CVSS score of 10.0, had been actively exploited as a zero-day since mid-2024 before Dell published a fix in February 2026. CISA added it to its Known Exploited Vulnerabilities catalog the following day. Years earlier, CVE-2021-21551, an access control flaw in Dell's dbutil driver, made the same list after evidence of active exploitation emerged in the wild.

The pattern here is consistent: attackers increasingly go after enterprise infrastructure components that security teams tend to treat as inherently trusted. Storage management platforms and low-level system utilities rarely face the same scrutiny as public-facing applications, and that blind spot has proven to be consequential.


What to Do

Dell is directing all customers to upgrade CSM to version 1.18.0 immediately. For systems affected by CVE-2026-61421, the company is additionally recommending that JWT signing secrets be rotated post-upgrade, since those secrets were embedded in code that has been publicly accessible and should be treated as already compromised. No partial mitigations apply. The fix is available, and for organizations still running pre-1.17.0 versions, the exposure is active.



China Nexus Cyber Espionage Attacks Government Organizations


A China-nexus cyber-espionage campaign is targeting government and policy organizations across Asia with a previously undocumented Windows backdoor called Antino. Researchers at Cisco Talos are tracking the threat activity as UAT-11587.

Campaign details 

The campaign has targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. By July 2026, Talos had identified at least 16 affected or targeted institutional environments and approximately 350 compromised endpoints.

The campaign's lure theme and targeting provide additional contextual support. Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests,” Talos said.

The most notable feature of Antino is its use of legitimate Microsoft 365 services as command-and-control (C2) infrastructure. Instead of relying on a traditional attacker-controlled server, the malware communicates through Microsoft Outlook and OneDrive using Microsoft Graph.

About Antino

Antino is a Rust-compiled Windows backdoor capable of gathering information about infected systems, executing commands through Windows shell and PowerShell, transferring files, loading shellcode directly into memory and maintaining persistence.

About the infection 

The infection generally begins with a carefully prepared spear-phishing email. Attackers used government, diplomatic, maritime, legislative and foreign-policy themes designed to appear relevant to their intended victims.

Attack tactic

In some cases, the attackers recreated Gmail’s attachment-preview interface inside the email. When victims interacted with the fake attachment, they were directed to attacker-controlled infrastructure.

The attack then proceeds through multiple stages involving HTA or WSF files, JavaScript and a .NET-based downloader before ultimately installing Antino. The malware has also been deployed through DLL sideloading, using a legitimate Microsoft-signed executable to load the malicious DLL. 

Once installed, Antino uses Microsoft Graph to communicate with Microsoft 365. Outlook is used for receiving commands, while OneDrive handles heartbeat communications and file transfers. This allows malicious traffic to terminate at legitimate Microsoft infrastructure, potentially making conventional network-based detection more difficult.

Impact on systems

A successful Antino infection can provide attackers with persistent access to a Windows system, allowing them to conduct reconnaissance, execute commands, run PowerShell, access files and transfer data.

The targeting of government agencies, diplomatic organizations, universities, think tanks and policy groups suggests that the campaign is focused primarily on intelligence gathering and espionage rather than ordinary financial cybercrime.

Cisco Talos assessed UAT-11587 as China-nexus with high confidence, citing technical, language, infrastructure and targeting indicators. However, researchers noted that attribution to a specific Chinese group remains more complicated. 

Google's Android 17 Locks Accessibility Services to Verified Apps as Malware Threat Branches Out




Google is tightening restrictions on one of mobile malware's most persistent entry points. With Android 17, the company is limiting access to its AccessibilityService API to verified Accessibility Tools only, a change that takes effect the moment a user switches on Advanced Protection.

The move, announced Thursday, targets a problem that has haunted Android security for years. The AccessibilityService API was built to help people with disabilities use their smartphones. Screen readers, voice control apps, and motor-assistance tools all rely on it. But the privileges it carries are significant. Apps that tap into the API can run in the background, observe what appears on screen, intercept UI events, and take actions inside other applications on a user's behalf. That set of capabilities made it a target for malware developers almost immediately after it was introduced.

Google stated in its announcement that the new version automatically restricts AccessibilityService access to verified Accessibility Tool applications, closing off a major attack avenue while keeping genuine assistive technology functional.


A Clichéd Attack Path

Malware families have been weaponizing Android's accessibility services since at least 2017. The list of known offenders runs long: Vultur, SharkBot, Xenomorph, BianLian, Anatsa (also tracked as TeaBot), and more recently BTMOB RAT, a remote access trojan documented attacking banking customers across Brazil, Argentina, Spain, Portugal, and Mexico through 2025 and 2026. According to Kaspersky data, trojans accounted for 40 percent of Android malware infections in Q1 2025, with nearly 12 percent of malicious apps falling into the banking trojan category that specifically abused the Accessibility API, totaling around 154,000 apps.

The attack chain is well understood. A malicious app, typically distributed through sideloaded APKs or disguised as something routine, tricks a user into granting accessibility permissions. The Anatsa trojan, for instance, slipped onto Google Play as a PDF viewer update as recently as July 2025. Once the permission is granted, the malware operates without root access. It can monitor keystrokes, layer fake login pages on top of legitimate banking apps, approve system dialogs silently, and initiate fraudulent fund transfers from financial applications without the user noticing anything unusual on screen. Google noted in its announcement that this access also allows malware to block its own uninstallation, locking users out of any easy remedy.


What Changes in Android 17

The new restriction applies specifically when Advanced Protection is active, a device-level security mode introduced with Android 16 that consolidates multiple hardening features under a single toggle. When a user enables it, the system now automatically enforces that only verified, legitimate accessibility apps can request AccessibilityService access. Everything else is denied.

This is part of a gradual tightening that has been underway for several years. Android 13 made it significantly harder for sideloaded apps to acquire accessibility permissions. In-call protections, rolled out more recently, prevent users from granting those permissions during a phone call, cutting off a common social engineering scenario. Google also introduced the `accessibilityDataSensitive` flag to let developers mark UI elements as off-limits to third-party accessibility readers.


The Rest of Android 17's Security Updates

The accessibility change is one piece of a wider hardening effort in Android 17. Intrusion Logging, developed in collaboration with Amnesty International's Security Lab and other civil society organizations, creates a persistent, privacy-preserving forensic record of sensitive system events. Amnesty's team simultaneously updated AndroidQF and its Mobile Verification Toolkit to process the new log format, making it immediately useful for researchers investigating suspected spyware infections.

USB Protection blocks new data connections over a USB port while the device is locked, preventing physical access attacks where an attacker might attempt to extract data or push commands through a connected cable. Google has also included an option to disable WebGPU, a graphics API that has surfaced in sophisticated browser-based exploit chains. Failed Authentication Lock responds to repeated incorrect login attempts by locking the device entirely, making brute-force attempts against a stolen or seized phone substantially harder.

A fifth addition, View Supporting Apps, gives users a clear window into which installed applications have checked whether Advanced Protection is active on the device.

For developers, Google confirmed that applications can receive a notification when a user enables Advanced Protection, allowing them to switch on their own high-security features automatically for that audience.

Existing Advanced Protection users will receive a notification when the new capabilities land on their device. Intrusion Logging is not switched on by default and must be enabled manually from the Advanced Protection settings page.


AI Turns Into Both Threat and Shield in Supply-Chain Cyberattacks

 

Artificial intelligence is emerging as both a growing cybersecurity risk and a critical defence tool for supply-chain companies. As warehouses, factories and logistics networks adopt connected sensors, GPS tracking, tablets and automated equipment, every new digital connection can potentially give attackers another route into operational systems. 

Recent incidents underline the scale of the threat. Uber Freight disclosed unauthorized access to part of its systems and data in mid-August, while Ceva Logistics reported a breach affecting multiple companies and exposing customer information. Coca-Cola dairy brand Fairlife was also struck by ransomware, temporarily suspending its US operations. Such attacks can halt production, delay deliveries and cause time-sensitive products to spoil. 

The consequences can extend well beyond the directly targeted business. When Jaguar Land Rover suffered a cyberattack last fall, its production remained halted for six weeks, disrupting suppliers and reportedly contributing to the failure of some smaller companies. Software supply-chain attacks create an additional danger because compromised code can spread malware across many organisations using the same tools or automated systems. 

AI-powered security systems can help companies identify unusual activity, scan code for vulnerabilities and flag deviations from normal system behaviour. When a potential weakness is detected, organisations can deploy patches quickly before attackers exploit it. However, technology alone is not enough. Employees across offices, plants and warehouses need training to recognize phishing attempts, protect privileged access and use strong password-management practices. 

The challenge is becoming more difficult as criminals use AI to create convincing phishing emails, deepfake voice calls and fake videos that remove traditional warning signs such as poor grammar. Businesses are therefore reassessing supplier contracts, cybersecurity audits and third-party risk management. With more diversified supplier networks sharing inventory, operational and customer data, firms must ensure partners maintain comparable security standards and maintain incident-response plans. In an era when attackers can use AI to find weaknesses rapidly, using AI for defence is becoming essential.

Mayor Confirms Ransomware Incident Disrupted Mississippi City Systems


The city of Vicksburg, Mississippi, has taken its computer systems offline after a ransomware attack disrupted several city functions. Mayor Willis Thompson confirmed the incident and announced a temporary shutdown while officials investigate the incident and restore the affected systems. Due to this incident, residents will be unable to use online utility payment services and will experience delays making payments in person due to the incident. 

Even with the disruption, emergency response, police, fire, and utility services remain operational. In addition, residents of Vicksburg will not be subjected to late payments or termination of utility services while the systems remain offline, according to the city. As part of the recovery effort, Vicksburg has enlisted outside cybersecurity experts and is working with the FBI, Department of Homeland Security, and state officials. 

As part of the investigation, officials are examining whether personal or confidential information belonging to customers, contractors, vendors, employees or business partners has been accessed. As of this writing, officials do not know whether any information has been accessed or taken without authorization. Also, it has not been disclosed who the attackers are or whether a ransom demand has been placed. 

Although the investigation and system recovery are ongoing, technical details about the incident will remain withheld while questions remain regarding its exact nature and scope. Reporting has not been able to establish whether the incident involved the encryption of city systems typically associated with ransomware or whether the term was being used in connection with a ransom demand. 

There was no publicly asserted responsibility at the time of reporting, and the city did not disclose whether a ransom was demanded, or whether any communication with the attackers occurred. In addition, officials have withheld technical information that could impact the ongoing investigation. 

Investigations are aimed at investigating whether the incident exposed personal or confidential information of current and former customers, contractors, vendors, employees and affiliated business partners, as well as other parties involved. 

If a compromise is confirmed, officials have informed affected individuals that appropriate information and resources will be provided. However, a final determination has not been reached regarding whether such information was accessed or acquired without authorization.

The city is currently partnering with external cybersecurity specialists and other partners in order to secure the restoration of affected services, alongside the investigation. Some routine government operations, particularly utility payment processing, have already been affected by the shutdown, even though vital emergency and utility services have been provided. 

There are approximately 10,000 utility accounts that are serviced by the city's water and gas office, which means that the disruption may affect a significant proportion of the local community. Other ransomware attacks have also been reported in Mississippi following the Vicksburg incident. As part of its recovery process, the University of Mississippi Medical Center consulted with the FBI following a ransomware incident that caused parts of its systems to be unavailable for several weeks. 

In previous years, Mississippi saw ransomware affect an electric utility and a county government, highlighting that a number of public-sector and critical service organizations have experienced similar disruptions. However, Vicksburg is unsure whether the shutdown will last for a prolonged period of time. 

Investigations are currently underway to determine how the intrusion occurred, which systems were affected, and whether any sensitive information has been compromised. Further details will be provided once verified findings have been identified.

Microsoft X Account Hijacked to Promote Clippy-Themed Crypto Token

 

Microsoft’s account on X was hacked and used to promote a cryptocurrency token, turning the technology company’s 13-million-follower social media presence into part of an apparent crypto pump-and-dump operation. The incident centered on the company’s @Microsoft account and began with activity involving another X profile impersonating Clippy, Microsoft’s former virtual assistant. 

The Microsoft account followed and reposted a post from @clippymsftcto, an account that has since been suspended. The activity subsequently drew attention to a $Clippy token. Another account, @ClippyMSFT, reposted Microsoft’s message and continued promoting the cryptocurrency. That account claimed the token had a liquidity pool directly paired with $MSFT. Microsoft later removed the unauthorized posts and acknowledged that its account had been accessed unauthorized. 

A company spokesperson said the account had been secured and that Microsoft was investigating how the breach occurred. The company also made clear that it had no association with the cryptocurrency which was being promoted. Microsoft said it did not authorize, sponsor or endorse a cryptocurrency associated with Clippy, Microsoft or $MSFT, and had not authorized the use of its branding or intellectual property in connection with such a token. The incident is part of a long pattern of cryptocurrency scams involving compromised accounts belonging to major organizations. 

Microsoft itself experienced a similar breach in June 2024, when its Microsoft India account, which had more than 211,000 followers, was taken. In that case, attackers used the account to impersonate meme-stock trader Keith Gill, known online as Roaring Kitty. They attempted to lure users to a website advertising a supposed GameStop cryptocurrency presale. Victims who connected their wallets and authorized transactions instead had their crypto assets stolen through a wallet-drainer malware. Compromised social media accounts has been a particularly useful tool for cryptocurrency scams, as posts from established organizations can appear more credible to potential victims. 

ScamSniffer reported in December 2023 that approximately $59 million in cryptocurrency has been stolen from 63,000 people through a Twitter advertising campaign using the “MS Drainer” wallet-draining service between March and November. Government accounts have also been targeted. In January 2024, the U.S. Securities and Exchange Commission’s official X account was compromised through a SIM-swapping attack. Attackers used it to publish a fake announcement claiming that Bitcoin exchange-traded funds had received approval, temporarily but significantly moving Bitcoin’s price. 

Eric Council Jr., identified as the hacker who compromised the SEC account, pleaded guilty in February 2025 and was sentenced to 14 months in prison over his involvement in the scheme. Microsoft now has its account secured and the posts associated with the breach removed. Its investigation is ongoing, but the cryptocurrency promotion associated with the unauthorized activity has further raised the risks of trusting what appear to be legitimate social media posts when they involve digital-asset promotions.

CloudSyncD MacOS Backdoor Used Fake Zoom Installer to Steal Passwords


Cybersecurity researchers have identified a new macOS backdoor called CloudSyncD that uses a fake Zoom installer to trick users into providing their computer passwords. The malware was discovered by Jamf Threat Labs and uses a two-stage infection process to gain elevated access and communicate with attacker-controlled servers.

One of the most unusual features of the malware is its use of zero-width Unicode characters to hide information about a stolen password inside what appears to be a normal configuration file.

Technical Details

CloudSyncD is distributed through a malicious disk image designed to look like a legitimate Zoom installer. The installer includes instructions telling users to bypass macOS Gatekeeper by going to System Settings and manually allowing the application to run.

Once the fake installer is launched, the first-stage program, called app_installer, displays a fake authorization window asking for the user’s administrator password. It checks the entered password locally using macOS’s dscl command. If the password is incorrect, the malware can continue prompting the victim.

The stolen password is not immediately sent to the attackers. Instead, the malware stores it inside a file called data.json. The password is Base64-encoded and placed inside a larger string containing random characters.

The malware then uses U+200B ZERO WIDTH SPACE and U+200C ZERO WIDTH NON-JOINER characters. These characters are invisible during normal viewing and encode the location and length of the hidden password. This technique allows malicious information to be concealed without obviously changing the appearance of the file. 

The second stage is an embedded Mach-O executable capable of running on both Intel-based and Apple Silicon Macs. The malware attempts to execute the payload without initially writing it to disk. When that approach fails because of macOS security protections, it can create a temporary file and use the captured password with sudo to execute the backdoor with elevated privileges.

Impact

After execution, CloudSyncD collects information about the infected Mac, including hardware and operating-system details, account information and network-related data. It communicates with a command-and-control server and can periodically check for additional instructions.

Researchers observed check-ins occurring approximately every 8 to 16 seconds in analyzed samples. The backdoor can receive executable files or compressed archives, potentially allowing attackers to deploy additional malware on an infected system. 

Most Enterprises Are Unprepared for AI and Quantum Threats, PwC Survey Finds

 



Most organizations around the world are spending more on cybersecurity than at any point in their history. Very few are spending it on the threats that are actually coming for them. That is the central tension running through PwC's 2027 Global Digital Trust Insights report, which drew responses from nearly 4,000 business and technology leaders spanning more than 70 countries.

Artificial intelligence sits at the core of the report's findings, and not in the way most organizations would prefer. Leaders surveyed identified attacks targeting their own AI systems as the single cyber threat they feel least prepared to handle. Over half of respondents, 53 percent, said they are not adequately defended against autonomous botnet attacks, where AI drives the probe and compromise of networks faster than human teams can respond. Adversarial attacks and data poisoning followed at 52 percent each, pointing to a defensive gap that has widened as attackers have adopted the same tools organizations are still trying to implement on the defense side.

Prompt injection sits squarely at the heart of this problem. Unlike conventional exploits that target code vulnerabilities, prompt injection manipulates the AI model itself, tricking it into leaking data, executing unauthorized commands, or acting entirely outside its designed purpose. OpenAI acknowledged in late 2025 that prompt injection, much like social engineering before it, is a problem that cannot be fully engineered away. The Open Worldwide Application Security Project has ranked it number one on its threat list for LLM applications for three consecutive updates, a position it has held since the list first debuted. The persistence of that ranking reflects not a shortage of incidents, but the structural difficulty of closing an attack surface that is, in effect, the model's own reasoning process.

Despite all of this, AI is simultaneously the security tool leaders trust most. The survey found it ranked first for threat detection and alerting across the respondent pool. The contradiction is in what comes next. Only 22 percent of leaders said they would let AI agents operate in cyber defense without requiring human sign-off on their actions. Fifty-five percent attributed this reluctance to reliability and maturity concerns, while 44 percent pointed to a skills shortage in AI oversight and governance.

That hesitation is not irrational, but it carries a cost. AI-driven attacks operate at a pace that leaves human response cycles behind. Requiring manual approval for every automated defensive action is, in practice, fighting a faster adversary at a slower speed. At some point, fully autonomous defense may not be optional. What makes that shift harder is that organizations have not settled on who would be accountable for it. The survey found that 29 percent of leaders placed AI security accountability with the CIO or CTO, 26 percent with a dedicated AI leadership role, and only 17 percent with the CISO. Eleven percent said responsibility was shared across multiple functions, which in most organizations means it belongs to no one in particular.

Budget signals at least suggest that leaders recognize the scale of the problem. Eighty-four percent of security and finance leaders said they expect cyber budgets to increase, with 58 percent naming AI as their top spending priority for the coming year.

The second major warning in PwC's report concerns quantum computing, and the picture there is, if anything, more concerning. Quantum computers capable of breaking the encryption that currently secures financial records, government communications, and enterprise data are not yet commercially operational. But the attack strategy does not require them to be. State-sponsored threat groups and other sophisticated actors are already collecting encrypted data now, banking on the ability to decrypt it once quantum capability matures. Most cryptography researchers put that window between 2030 and 2035, and the timeline for migrating large-scale cryptographic infrastructure is measured in years, not months. The National Institute of Standards and Technology finalized its first three post-quantum cryptography standards in August 2024, covering quantum-resistant key exchange and digital signatures, and told organizations explicitly that there is no reason to delay. PwC's survey found that only 21 percent of respondents are currently implementing those standards.

What makes this more urgent than a theoretical risk is that the harvesting is already underway. The FBI confirmed in August 2025 that a Chinese state-sponsored group tracked as Salt Typhoon had compromised more than 200 organizations spanning more than 80 countries, with nine major US telecommunications carriers among the confirmed victims. In at least one documented case, the group maintained undetected access to a telecom network for three years, collecting communications data throughout. That data, encrypted under today's standards, sits in storage waiting for the decryption capability that quantum hardware will eventually provide. Governments are beginning to respond with deadlines rather than guidelines. In June 2026, President Trump signed executive orders requiring federal agencies to migrate high-value systems to NIST-approved post-quantum cryptography standards by 2030 and 2031 respectively, with government contractors expected to follow. The private sector has no equivalent mandate, and PwC's survey makes clear that most organizations are not filling that gap on their own.

"Technology is moving incredibly fast, but the fundamentals of cybersecurity haven't changed," said Morgan Adamski, PwC's cyber, data and technology risk leader. "You can invest heavily in AI and the latest security tools, but if you don't have secure data, operational continuity, clear accountability and strong cyber hygiene underneath them, you're building on a weak foundation. The goal isn't to slow innovation down. It's to make sure your organization is resilient enough to keep up with it."

What the survey documents, across both AI and quantum, is the distance between knowing what needs to be done and actually doing it. The tools exist. The standards are published. The gap is operational, and the cost of that gap is rising by the month.


Automakers Face Scrutiny Over Connected-Car Data Sharing

 

Modern connected cars are increasingly functioning as data-collection platforms, with new research finding that many automakers routinely transmit customer information to advertisers, analytics providers, technology companies and data brokers. The findings, released by Northeastern University researchers in collaboration with Consumer Reports, raise fresh concerns about how much control drivers have over information generated by their vehicles and companion mobile applications. Of the 21 major automakers examined, 19 were found to collect and broadly share private consumer data, showing that the privacy risks extend well beyond a carmaker’s own systems. 

The study examined both vehicles and 30 connected-car apps, which are commonly used for remote locking, navigation, vehicle health reports and other services. Twenty-eight of those 30 apps shared data with at least one third-party advertising or analytics firm. More concerningly, seven apps sent personally identifiable information to outside companies, including owners’ names, email addresses and precise geolocation data. Such information can reveal where a person lives, works, shops or travels, making connected-car data particularly sensitive compared with ordinary online browsing records. 

Researchers also found that apps from General Motors brands—myCadillac, myChevrolet, myBuick and myGMC—as well as Honda, Nissan and Lincoln, shared vehicle identification numbers alongside location data or email addresses. A VIN is a unique identifier tied to a specific car, and pairing it with personal information can make it easier for data brokers to link driving behavior to an identifiable individual. The data reportedly reached a wide group of companies, including Alphabet, Amazon, Microsoft, Meta, Reddit and Pinterest, highlighting the overlap between automotive technology and the broader digital advertising ecosystem. 

The findings arrive amid heightened regulatory attention on vehicle privacy. In May, California Attorney General Rob Bonta, the California Privacy Protection Agency and local prosecutors fined General Motors more than $12 million and ordered the company to stop sharing driver data with credit-reporting agencies and data brokers for five years. Automakers have argued that some data sharing is based on customer opt-in consent or contractual restrictions that limit third parties from independently selling information. However, Consumer Reports said many motorists may not fully understand what they accept when activating connected services, especially when declining data sharing may affect vehicle features.

Honda was the only automaker named in the report to respond publicly to a request for comment. The company said it aims to earn customer trust and, after being informed of the findings, directed an analytics vendor to delete location data already collected. Honda also said it would no longer share that information with third parties. The wider issue remains unresolved: consumers increasingly rely on internet-connected cars, yet disclosures about who receives their data and why often remain unclear. Stronger transparency, meaningful consent and easy privacy controls will be essential if automakers want to retain drivers’ trust.

Google Introduces Gemini 4 Argon With Guardrail-Free Access for Defenders

A new frontier artificial intelligence model, Gemini 4 Argon, has been introduced by Google through its Fairwind Program for initial distribution to trusted cybersecurity defenders. In addition to internal security teams using this model, the company expects wider access as it collects feedback from early users. 

As a software engineering, enterprise knowledge work, and cybersecurity operations solution, Argon is designed to handle complex software engineering and knowledge management tasks. A model developed by Google will be able to identify, validate and patch critical vulnerabilities independently in security environments, thereby expanding the use of artificial intelligence for vulnerability research and remediation. 

Argon will be available to trusted defenders and the company's own teams without cyber-specific guardrails, according to the company. As part of this approach, vetted security professionals will be given full access to the model's capabilities when investigating and addressing threats. In September, Fairwind, a limited access AI security tool for governments, Google Cloud customers and cybersecurity partners, launched.

A significant finding has already been made as a result of its early deployment, Wiz, which is using Argon as part of its Scan for Good initiative, reported that it identified a previously unknown critical vulnerability in healthcare software used by hospitals worldwide. The vulnerability may expose sensitive personal information, although Google has not disclosed the name of the affected software or whether the issue has been resolved. 

Google also reports significantly improved vulnerability detection performance compared with Gemini 3.8 Flash Cyber. A security test conducted by Argon on complex codebases identified security weaknesses, while a test conducted by Wiz on live web applications demonstrated improvements in attack surface discovery, vulnerability identification, and proof-of-concept generation. 

A phased approach is being taken by Google to the wider release, with the model currently restricted to internal teams and vetted defenders. Moreover, the company is participating in the U.S. government's voluntary pre-release process and will refine its safeguards after receiving feedback from early testers in order to broaden the availability to developers, enterprises, and individuals. 

Argon will be designed to reject requests attempting to support cyber or chemical, biological, radiological, and nuclear attacks as part of its broader rollout, while also preserving the support of legitimate dual-purpose research as part of its broader rollout. Additionally, Google is monitoring the model's internal activity for signs of misuse. Indirect prompt injection is also being investigated. 

In Google's opinion, Argon is protected against attempts to manipulate it through malicious instructions or external content. The Fairwind program provides another layer of control around access by monitoring the model’s reasoning and actions, and stopping execution when behavior goes beyond the intended task. 

Organizations participating in the program have been vetted and their use has been restricted to authorized defense activities such as threat simulation, reverse engineering, and malware analysis for research or security purposes. Partners are not permitted to share or distribute access to the model. Google has not provided a date of general availability yet. 

Upon initial deployment of Argon Defender, API customers and Google AI Ultra subscribers should have access, although the broader deployment of Argon will be dependent on the results of ongoing safety and security evaluations.

Federal Agencies Disrupt Ransomware Gang Involving A 16-Year Old Member


An international law enforcement operation known as "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, resulting in three arrests and identifying a 16-year-old as the group's alleged administrator.

Combined efforts in finding suspects

Europol and Eurojust, as well as cybersecurity companies Bitdefender and Group-IB, all contributed to the investigation.
"The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1,000 suspected attacks worldwide," according to Europol.
"Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds,” Europe stated.

About the investigation 

The inquiry started last year and assisted officials in finding suspects like negotiator, administrator, and associate of the cybercrime gang.
As per Europol, the suspected main operator and administrator of KillSec is 16 years old. 
Officials have also discovered members suspected of being an affiliate and a negotiator.
KillSec, also known as Kill Security or k1llsec, has reportedly been active since around 2024 and operated as a ransomware-as-a-service (RaaS) group. 

About the attack 

Investigators say the attackers gained access to organizations by exploiting software vulnerabilities and poorly secured access points, including systems associated with cloud storage.
After gaining access, the attackers allegedly stole sensitive corporate information and transferred it to infrastructure controlled by the group. They then used a dark-web leak site to pressure victims into paying ransom. Victims were threatened with the public release of stolen information if they refused to pay.

The impact 

Investigators have linked KillSec to approximately 1,000 suspected attacks worldwide, with around 500 currently identified as successful. Authorities stressed that these figures could change as they continue examining seized computers, servers and other evidence. At least 70 suspected attacks involved organizations in Germany, including 18 connected to Hamburg. 
Investigators also found that KillSec members allegedly used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.
By taking control of KillSec’s leak site and servers, authorities have prevented the group from continuing to use that infrastructure to publish stolen information. However, the seizure cannot necessarily remove copies of information that may already have been obtained by criminals or downloaded by others.
The investigation may also identify additional victims, attacks and individuals involved in the operation.
Authorities are now analyzing the seized evidence and tracing alleged criminal proceeds, including cryptocurrency.

MetaMask Takes Precautionary Action After Infrastructure Security Incident

 

Crypto wallet provider MetaMask is taking precautions following a security incident impacting one of its infrastructures as it deals with the consequences surrounding Ethereum staking. The company has remained silent on the details concerning the systems that were compromised or whether information or infrastructure was at risk as the breach occurred. A spokesperson for MetaMask directed queries towards the company’s public statement on the issue. 

The company announced that it is addressing the matter internally with the help of external partners and security advisers while noting that there are no immediate risks to MetaMask wallets. The response to the incident involved changes to the non-custodial staking operations at MetaMask as the firm continues to remove the affected validators in collaboration with partners and clients while mitigating any further risks that may arise. 

The company is quick to note that its staking service is non-custodial meaning that it does not possess the withdrawal keys to the stakes deposited by clients. This is an important observation as the response to the security incident only involves the staking infrastructure and not the management of the deposits by clients. Part of the precautions being taken are affecting the validators through the Lido protocol as the firm announced that MetaMask Staking, previously known as Consensys Staking, had initiated protective measures for the clients’ assets on the Ethereum blockchain. 

The procedure involved transitioning the Ethereum validators operated by Lido Finance to the exit process. The changes to the validators through the Lido protocol will cause disruptions to the staking processes and may result in economic losses to the clients who have chosen to use the staking services. This occurs as the validators are being exited to mitigate the risks posed by the security incident affecting the Ethereum network. The Lido protocol further noted that the affected validators had begun exiting the protocol while also stating that the last validator would exit by October 7th. 

However, the date does not signify the day when the validators will have exited completely as some of them might be offline as of the 7th . Validators are critical to the operations of the Ethereum network as they propose new blocks, verify transactions and secure the network through their specialized software. As such, it will require significant efforts to ensure the adjustments made to the validators do not cause disruptions to staking processes while eliminating risks to the stakeholders who utilize the MetaMask services. 

MetaMask has not released further details concerning the security incident and its impact on the infrastructures that support its operations. For now, the company is focusing on addressing the effects of the incident while collaborating with external security advisers and partners. MetaMask is a crypto wallet provider whose products are developed by blockchain software company Consensys. It offers non-custodial crypto wallet solutions for individuals and organizations while allowing them to store their digital assets on the Ethereum network and other compatible blockchains.

Half a Million GitHub Credentials Are Still Active, Most Have Been Sitting in the Open for Years





Researchers at Truffle Security tested 543,699 API keys, database passwords, and access tokens found in public GitHub repositories last July. Every single one authenticated. The median credential had been sitting in publicly readable code for 784 days.

The findings come from a scan of The Stack v3, a 224-million-repository snapshot of public GitHub code assembled to train large language models. The crawl closed on August 7, 2025. Eleven months later, when Truffle Security ran live verification against each issuing provider, more than half a million credentials still worked. That number is more than double the 221,303 live credentials the company found when it ran a similar scan against 7.6 petabytes of Hugging Face training data earlier this year.

The oldest credential in the dataset was last touched on June 13, 2009. It lives inside an Erlang web server configuration file, and it was still valid 16.1 years after it was committed. Behind it: an FTP login inside a GPS logger's C source code from September 2009, replicated across 62 repositories, and an AWS key tucked inside a Rails S3 config from November of that same year. Truffle Security declined to name the repositories because the credentials in them still work.


A Protection That Only Faces Forward

GitHub has progressively tightened its defenses around exposed credentials. The platform made secret scanning alerts free for all public repositories in February 2023. Push protection, which blocks a commit before it reaches the remote branch if it carries a recognised secret, became generally available in May 2023 and was switched on by default for all public repositories on February 29, 2024.

GitHub's secret scanning covers more than 200 token types and patterns from over 180 service providers. The rollout had a measurable effect on new leaks. Among credential shapes the system recognises and blocks, Truffle Security found a 53 percent drop in the rate of fresh exposures across the twelve months following the default rollout, compared to the twelve months before it. Slack tokens fell 64 percent, GitHub's own tokens and AWS access keys each fell 59 percent.

But push protection has no mechanism to reach the credentials already there. Of the 543,699 live credentials, 199,843 landed after push protection became the default in February 2024. Developers either bypassed the block or committed credential types the system does not recognise.

That second category is the larger problem. Truffle Security found that 51.8 percent of every live credential in the dataset is a shape that a default-configured public repository will accept without objection. Database connection strings, private keys, and Google API keys all fall outside the default block list. Push protection focuses on specific, highly identifiable secrets and misses generic ones. Connection strings and private keys are classified as generic patterns, and blocking them requires an organisation to go into settings and explicitly opt in.


The Gemini Problem

The Google API key situation illustrates the limits of pattern-based blocking in particularly sharp terms. The 33,343 live Google API keys in Truffle Security's dataset include 31,374 that authenticate specifically to Gemini, Google's AI model platform. Their median leak date is February 2025, meaning the entire population is younger than the push protection rollout.

Google API keys carry the prefix `AIzaSy` whether they were created for Google Maps, Firebase, or Gemini. GitHub's pattern list recognises the prefix but marks it as not push-protected, because a Maps key sitting in client-side JavaScript is not a secret by design. Google's own approach to API keys was historically built around the assumption that these keys would live in client-side code, exposed to anyone who opened a browser's developer tools. The problem is that Gemini runs on the same key format, turning what developers were trained to treat as a non-sensitive identifier into a billable AI credential. One pattern cannot distinguish between the two uses, so nothing gets blocked, and the keys that matter arrive alongside the keys that do not.


Revocation is the Deciding Variable

The most instructive comparison in the data is between providers that automatically revoke leaked tokens and those that do not.

npm committed 101,886 tokens to public code. One remains live. GitHub committed 73,048 tokens; 260 survived. Hugging Face committed 30,437; 15 are still valid. Each of these platforms runs an automated pipeline that kills a token the moment it is detected in public code.

The contrast with database credentials is stark. Of 12,985 Postgres connection strings in the dataset, 11,465 are still live, an 88 percent survival rate. MySQL connection strings survive at 75 percent. MongoDB, where the detector only reports a URI it successfully connected to, returned all 51,067 live.

Push protection blocks secrets at the door. Automated revocation kills them wherever they are. The Truffle Security data shows that the second mechanism is the one that changes the outcome, and for the majority of credential types sitting in public repositories right now, no provider is running it.

The practical guidance from the researchers: treat any committed credential as compromised regardless of whether anything flagged it, scan your own repository history rather than assuming the push-time block was sufficient, and favour credentials that expire automatically. Most of what Truffle Security found would have been harmless long ago if it had ever been given a finite lifetime.