Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
AppWizard
August 14, 2026
U.S. District Judge James Donato has ordered Google to simplify the installation process for rival Android app stores to eliminate barriers that discourage users from exploring alternative marketplaces. The judge criticized Google's practices as "anticompetitive friction" and mandated changes to ensure users can install alternative app stores as easily as any other Android application, giving Google one week to implement these changes. The ruling follows a previous antitrust victory for Epic Games, which found that Google maintained an illegal monopoly over Android app distribution and in-app billing services.
AppWizard
August 14, 2026
Samsung's One UI 9.5 will introduce an app lock feature that enhances user privacy by allowing applications to be secured with a PIN or biometric authentication. Users can activate the app lock by pressing and holding an app icon in the app drawer, where a padlock icon will appear. Accessing locked apps will require biometric verification or the device's screen lock, and once locked, the app's widgets and shortcuts will be removed from the home screen, with notifications concealed. However, content from locked apps will still be accessible to other applications with prior permissions. Currently, Samsung devices offer the Secure Folder feature, which has limitations, as it creates a cloned version of the app while leaving the original accessible. The new app lock feature is similar to the one introduced in Android Canary 2608, indicating a possible influence on Samsung's development.
Winsage
August 14, 2026
Microsoft has expanded its Low Latency Profile (LLP) feature to all Windows 11 applications through the KB5121003 update, which is part of this month's Patch Tuesday. This update temporarily boosts CPU frequency to speed up app launches and is now available for most applications and Win32 programs. Following the installation of the update, standard applications like Notepad, Calculator, and web browsers such as Chrome showed faster opening times. The LLP feature is being rolled out gradually via Microsoft's Controlled Feature Rollout system, and users can enable it early using the ViveTool program if it does not appear immediately. Critics have described LLP as a superficial enhancement, while Microsoft has defended it by comparing it to similar strategies used by Apple in macOS.
Tech Optimizer
August 14, 2026
Many enterprise teams are facing challenges in data governance, particularly concerning sandbox-level state, despite effective central warehouse governance. Databricks is addressing this issue proactively. CIOs should ask vendors how state is secured and managed within agents, not just in central databases. Distributing state across agent sandboxes increases security risks and complicates governance, requiring enterprises to extend access control, audit, and compliance frameworks beyond a single database to numerous local instances. Robust data governance strategies are essential for managing data security and compliance.
Tech Optimizer
August 14, 2026
Databricks has acquired ElectricSQL, a startup specializing in PostgreSQL database capabilities, to enhance its offerings by extending PostgreSQL functionalities to edge devices. The acquisition, announced on August 11, aims to streamline operations for AI agents by allowing local data access. ElectricSQL has developed PGlite, a lightweight WebAssembly version of PostgreSQL for faster data access and real-time synchronization. This acquisition follows Databricks' earlier integration of PostgreSQL capabilities through the acquisition of Neon in May 2025. The founders of Electric, James Arthur and Kyle Matthews, will join Databricks. PostgreSQL has become the most popular open-source database by 2024, recognized for its versatility in handling diverse data types. Databricks' acquisition strategy also includes previous acquisitions like Neon and MosaicML, aimed at enhancing its AI development tools.
AppWizard
August 14, 2026
Studycat has reported a significant increase in downloads for its Spanish language app on Google Play during the back-to-school season, reflecting a seasonal trend where parents seek educational tools as they establish new routines. The rise in downloads is attributed to increased searches and installations on Android devices, consistent with historical patterns of heightened interest in educational apps during this time. The Studycat Spanish app, designed for children aged two to eight, features interactive games, songs, and stories to teach vocabulary and pronunciation. It allows parents to create multiple learner profiles and includes a VoicePlay feature for real-time pronunciation feedback. Parents can monitor their children's progress through a dashboard that displays completed lessons and badges earned. Studycat develops language-learning apps for various languages and offers additional educational resources on its website.
AppWizard
August 14, 2026
Researchers have identified Skeleton 150, believed to be the first confirmed victim of a trebuchet, unearthed during excavations beneath Stirling Castle in Scotland in 1997. This skeleton is part of a collection dating back to the 1300s and shows signs of violent death, including distinct cut marks, puncture wounds, and blunt force trauma. Dr. Buckberry from Historic Environment Scotland presented findings indicating that the unusual burial location beneath the castle chapel suggests these individuals may have died during sieges in the late 13th century. Stirling Castle was a strategic stronghold that fell to Edward I's armies after a siege in 1304, during which the largest trebuchet, "The War Wolf," was used. Dr. Buckberry noted that the extensive damage to Skeleton 150 indicates the individual was likely killed by a siege engine.
AppWizard
August 14, 2026
In digital gaming, there is a desire for the tactile experience of traditional board games, creating a balance between the complexity of video games and the physical joy of board games. Some video games inspire players to take notes, which aids in understanding gameplay and adds an analog warmth to the digital experience. Players often jot down character names, skill sets, key highlights from matches, and create sketches that reflect the excitement of gameplay. These handwritten notes, including maps and lists of in-game suspects, have become valued artifacts that connect the digital and physical realms of gaming.
Winsage
August 14, 2026
Microsoft has rolled out its Low Latency Profile (LLP) technology to all Windows 11 users as part of the KB5121003 update, aimed at enhancing performance across the Windows graphical user interface, native OS applications, and third-party software using Win32 APIs. The LLP utilizes a "race to sleep" mechanism that temporarily elevates CPU frequency to expedite app launches. Following the update, users reported reduced loading times for applications like Notepad, Calculator, Chrome, and the Epic Games Store. The feature is being distributed through the Controlled Feature Rollout system, and can be force-enabled using the ViveTool program. While some critics view it as a superficial enhancement, Microsoft defends it by comparing it to similar strategies used by Apple in macOS and noting its commonality in Arm chips.
Winsage
August 14, 2026
Windows 11's August 2026 Patch Tuesday update has been released, addressing 421 security vulnerabilities, including 400 specific to the Patch Tuesday release. The update rectifies at least 37 remote code execution bugs and five elevation-of-privilege vulnerabilities. Microsoft advises users to implement the update within three days for security. The update includes fixes for other Microsoft products like Entra, Office, and Teams. Users should verify their Windows 11 build number, with recommended versions being 26200.9168 for 25H2 and 26100.9168 for 24H2. The update is identified as KB5121003 and may require up to two reboots to apply fully. Key areas of focus in the update include the kernel, Remote Desktop, DNS, DHCP, SMB, and Windows Defender Firewall. Microsoft emphasizes the importance of timely updates and recommends limiting the deferral period for quality updates to less than three days.
AppWizard
August 14, 2026
Judge James Donato criticized Google's "anticompetitive friction" in Android app distribution during a courtroom session. This follows a jury's ruling nearly three years ago that Google held an illegal monopoly over Android apps. Judge Donato previously mandated changes to promote a more open app distribution environment, including requiring Google to feature rival app stores and grant them access to its app catalog. Epic Games argued that Google complicates the installation process for alternative app stores, which Judge Donato agreed was unacceptable. He questioned the search results for "store for apps" yielding physical stores instead of third-party app stores and insisted on improving search result comprehensiveness. He also expressed dissatisfaction with the requirement for users to click a “view” button before installing a third-party app store, ordering a streamlined installation process. Epic noted that searches for "app store" or specific names led to banners instead of direct app lists, which could hinder new app stores' visibility. Judge Donato agreed and demanded the removal of unnecessary screens, urging Google to implement these changes within a week.
AppWizard
August 13, 2026
The digital landscape for purchasing PC games has evolved, offering various online stores for Linux, macOS, and Windows games, with some also featuring e-books, movies, and software. Notable platforms include Steam, Epic Games Store, Humble Bundle, and Xbox, each with diverse game libraries. Some publishers, like Blizzard and EA, initially required exclusive downloads but are now allowing games across multiple storefronts. Steam offers extensive titles and a Verified program for Steam Deck users, while GOG.com focuses on classic games and itch.io on indie titles. Consumers can purchase games from different platforms and use tools like CheapShark to compare prices and find deals.
AppWizard
August 13, 2026
Flat2VR Studios has announced an official VR port of the sci-fi shooter System Shock for Meta Quest, PlayStation VR2, and SteamVR. This announcement was made during the VR Games Showcase. Flat2VR is collaborating with Nightdive Studios, the original developer of System Shock, which was released in 2023 after a seven-year development period. The game has received continuous updates, with the latest in March 2023. Additionally, Flat2VR plans to port the first-person shooter High on Life and introduce new titles for PlayStation VR2, including Drop Dead: The Cabin. A funding initiative for developing larger gaming experiences is also being launched. System Shock VR is available for wishlisting on Steam, PS VR2, and Quest platforms.
AppWizard
August 13, 2026
Netflix has announced the closure of Night School Studios and its Helsinki-based Moonloot studio shortly after the launch of its latest title, Unhinged. Night School Studios, acquired in 2021, was known for its storytelling in games like Oxenfree and Afterparty. The closure follows the dissolution of Team Blue, indicating a strategic pivot for Netflix in its gaming operations. Additionally, Netflix is seeking a new Director of Generative AI for Games, offering a salary of up to 0,000, reflecting a trend towards integrating AI technologies in gaming. The company is also implementing broader cuts within its gaming division to streamline operations.
AppWizard
August 13, 2026
Marcus Lehto, the art director of Halo: Combat Evolved, has expressed concerns about the remake, Halo: Campaign Evolved, particularly regarding the portrayal of the Halo rings. He believes the rings appear overly polished and lack the character that comes from centuries of conflict, describing them as resembling "shiny new toys." Lehto criticized the main menu ring as "the most offensive thing we see every time we boot up the game," stating it should convey scale and mystery but instead looks like it was built recently. He emphasized the importance of detail, suggesting the rings should feel like "ancient tombs." Despite his critiques, he acknowledged improvements in gameplay, cinematics, and visuals, praising the lighting and movement mechanics while remaining optimistic about the overall experience.
AppWizard
August 13, 2026
Legion Was Here offers an immersive character creation experience, allowing players to customize avatars with extensive options, from facial features to expressions. The character creator is central to gameplay, pushing players to master character design for success in the game. A poorly crafted character can lead to challenges in survival, adding pressure to the creative process. Players can either replicate familiar faces or create new personas, with every detail impacting their character's fate.
Winsage
August 13, 2026
Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, which can bypass Microsoft's RoguePlanet patch (CVE-2026-50656) and allow attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit has been confirmed by security expert Kevin Beaumont, who provided detection methods for it. ShieldBreak is the tenth zero-day from Nightmare Eclipse since April and was released shortly after Microsoft's monthly Patch Tuesday. The exploit allows local privilege escalation and has a 100% success rate on the latest version of Windows 11 and Windows Server 2025, while Windows 10 remains vulnerable. Microsoft is aware of the vulnerability and is investigating it, emphasizing the importance of coordinated vulnerability disclosure. Previous exploits from Nightmare Eclipse include LegacyHive and GreatXML, with earlier vulnerabilities having been patched but recent ones still unaddressed. Microsoft had threatened legal action against Nightmare Eclipse in May but later reconsidered its approach to vulnerability disclosure.
Winsage
August 13, 2026
Security researcher Nightmare Eclipse has released a zero-day exploit named ShieldBreak that allows privilege escalation on Windows by targeting a vulnerability in Microsoft Defender. This exploit, designated as CVE-2026-50656, is categorized as a race condition vulnerability and affects the latest versions of Windows 11 and Windows Server 2025, with potential impacts on Windows 10. The exploit was disclosed on June 9, 2026, and Microsoft acknowledged the issue on June 16, rolling out fixes by July 9. The mechanics of ShieldBreak involve manipulating Defender’s scan path and executing a scheduled task to gain System-level privileges. Experts have noted differences between ShieldBreak and the previously known RoguePlanet exploit, emphasizing that ShieldBreak requires Defender to be active to function.
Search