authorities

AppWizard
September 1, 2026
Cybercriminals are targeting Android users with deceptive advertisements for malicious applications disguised as pornographic content on platforms like Facebook and Instagram. The National Cybercrime Threat Analytics Unit (NCTAU) has reported that these ads lead users to phishing traps or malware downloads that can compromise banking credentials. Malicious applications linked to this threat include “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo,” and “Vixa.” The scam involves promoting these apps through enticing ads, redirecting users to websites offering pornographic content, and prompting them to download APK files directly from these sites, often using “.live” domains. The initial app may request users to download a second package disguised as an update, which can exploit permissions granted to the first app. This malware can gain extensive control over the device, potentially installing a VPN that routes internet traffic through attackers' servers. To protect against this threat, users should download apps only from trusted sources, avoid installing APK files from ads or suspicious links, refrain from granting Accessibility access to unknown apps, regularly review installed apps, keep Google Play Protect enabled, and monitor bank accounts for unusual activity. If a suspicious app cannot be uninstalled, users can try Safe Mode, remove special permissions, or perform a factory reset as a last resort.
AppWizard
August 31, 2026
India's cybercrime authorities have warned about the misuse of dating and adult-themed advertisements on social media platforms like Instagram and Facebook, which are being exploited by criminals to distribute malicious Android applications. These ads redirect users to external websites where they are prompted to download APK files, bypassing security measures of trusted app stores. The Indian Cybercrime Coordination Centre (I4C) has identified several malicious applications, including Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa, and cautions against installing unfamiliar applications promoted through unsolicited ads. These apps may request sensitive permissions, such as access to SMS messages, contacts, photos, device storage, and Accessibility Services, which can allow fraudsters to access valuable information. Compromised devices can lead to financial fraud by intercepting OTPs and other verification details. The I4C recommends using trusted app stores, keeping Google Play Protect active, reviewing app permissions, and being cautious with social media ads. If a suspicious app is installed, users should restart their phone in Safe Mode to uninstall it, disable its permissions if necessary, and consider a factory reset if removal fails. Users who suspect fraud are encouraged to report incidents promptly.
Winsage
August 29, 2026
A significant portion of new PCs is sold with Windows 11 pre-installed, causing frustration among Linux enthusiasts. The Refund4Freedom initiative, launched by the Italian Linux Society and the Free Software Foundation Europe, aims to provide consumers with the option to purchase laptops without being tied to a specific operating system and to avoid paying for unwanted software. The initiative has three main demands: 1. Freedom of Choice: Consumers should not be forced to use or pay for pre-installed software. 2. Transparent Pricing: Consumers should be able to purchase hardware without pre-installed software and see price differences. 3. Clear Refund Processes: Manufacturers must provide clear guidelines for requesting refunds for pre-installed software. The Refund4Freedom website details various brands' reimbursement practices, noting that Acer and Lenovo have established refund processes for Windows, while Asus has a less visible route primarily in Italy. Dell and HP currently do not offer reimbursement options. For those wishing to reject Windows, Refund4Freedom advises documenting contract clauses, contacting customer service, and using a pre-made form for refunds, which is tailored for Italy. The typical reimbursement amount for a Windows license is around €50, though it varies by region and manufacturer.
Winsage
August 24, 2026
Microsoft has issued an advisory to IT teams and software developers regarding significant changes in Windows code signing due to the expiration of the Windows Production PCA 2011 certificate in October 2026. The transition will involve stronger cryptographic algorithms, including RSA-3072 and SHA-384, which may cause compatibility issues for applications that rely on hardcoded certificate checks or outdated cryptographic standards. Microsoft plans to implement post-quantum cryptography by default for Windows code signing in 2027. IT administrators are encouraged to assess their software environments, confirm vendor compliance with supported trust-validation mechanisms, and ensure applications are tested against the new certificate hierarchy and signing algorithms. Organizations with private trust stores must establish processes for recognizing and deploying legitimate Microsoft certificate updates.
AppWizard
August 21, 2026
On August 18, an entity named "Cyberleek" shared what is believed to be authentic gameplay footage from Grand Theft Auto 6, featuring the protagonist Jason. The footage showcased typical GTA activities and was removed from social media due to copyright claims from Take-Two and Rockstar. Cyberleek's leaks were not from testers but indicated access to a segment of GTA 6. They expressed consumer rights grievances and made three demands: no more digital preorders, no selling DLC already included in base game files, and mandatory offline fallback states for single-player games. Cyberleek is also promoting a cryptocurrency token, $Cyberleek, with a market cap of .1 million, allowing token holders to vote on gameplay clips to release. The timing of the leaks suggests a possible European origin, and investigations link Cyberleek to past posts on a German cybersecurity forum. There are indications that Cyberleek is not affiliated with Rockstar Games, and if identified, they could face significant consequences. Rockstar's official gameplay reveal for GTA 6 is scheduled for August 27.
AppWizard
August 17, 2026
Ksenia Zubareva is the CEO of Asia Game Buzz, a company focused on promoting PC games in China. She discussed how Steam operates in the Chinese market, highlighting the challenges and opportunities present. Ksenia emphasized the importance of understanding local consumer behavior and using social media for game promotion without needing a license. She also shared her views on the potential leniency of Chinese authorities towards Russian projects regarding the issuance of ISBNs for game distribution.
Winsage
August 17, 2026
A suspected advanced persistent threat (APT) group linked to China exploited a newly patched vulnerability in VMware vCenter (CVE-2026-59310), which has a critical CVSS score of 9.8, allowing for arbitrary code execution and the deployment of Babuk-derived ransomware. A recently patched vulnerability in Apple macOS (CVE-2026-65400) has been exploited to deploy a cryptocurrency miner, granting unauthorized root access. The Lazarus Group from North Korea exploited a zero-day vulnerability in Microsoft Windows, targeting defense and aerospace sectors. GeoServer patched a critical SQL injection vulnerability that was actively exploited. A new macOS malware, Amnesia Stealer, targets users through ClickFix attacks, stealing data and allowing real-time access to authenticated sessions. A novel attack technique named GhostSplice can manipulate AI coding assistants. Research revealed a method exploiting Chromium's DevTools Protocol for data theft. Noteworthy CVEs this week include CVE-2026-68820, CVE-2026-58231, and multiple others across various platforms. A high-severity command injection flaw in FileRun allows remote code execution. An advanced ClickFix attack has been reported, deploying sophisticated malware. A heap overflow vulnerability in Citrix NetScaler was patched after indications of exploitation. A new malware loader targeting Portuguese-speaking users has been identified. A significant reduction in exposed Automatic Tank Gauge systems has been observed. A phishing campaign targeting Brazil has been detected, and an F.B.I. agent faces charges for unauthorized crypto withdrawals. Authorities in Ukraine dismantled fraudulent call centers, and a North Carolina man was sentenced for cyber extortion. Unauthorized access to sensitive data by the ExfilSquad group has been confirmed. LightSpy activity linked to China has been detected in over 13 countries. A supply chain attack exposed over 2,500 companies, and an Azure exfiltration campaign has exposed millions of enterprise records.
TrendTechie
August 13, 2026
The Kyoto Prefectural Police have arrested 56-year-old Masakazu Ono, a primary seed of the torrent site Nyaa, following a multi-year investigation led by the anti-piracy organization CODA. Ono was identified through an analysis of data movement on torrent sites, rather than direct monitoring of BitTorrent traffic. He is accused of uploading around one thousand NHK recordings, including content from the series "Midnight Taxi." The investigation began in 2021 as part of the Cross-Border Enforcement Project, which aimed to identify uploaders on Nyaa. Charges were also brought against three secondary uploaders from aggregator sites.
Search