data

Winsage
September 4, 2026
Microsoft has identified a new malware campaign called TerminalFix that uses fake CAPTCHA prompts to trick Windows users into executing malicious commands. This campaign is a variation of ClickFix attacks and employs deceptive pages that impersonate reputable services like Cloudflare. Instead of traditional CAPTCHA challenges, users are instructed to open PowerShell or Command Prompt and paste in commands, allowing attackers to execute complex scripts more easily. TerminalFix initiates a multi-stage intrusion, granting attackers persistent proxy access to the infected machine, which can lead to further exploitation of the company's network. The campaign relies on social engineering tactics, requiring user compliance with counterfeit verification instructions. Microsoft has released mitigation guidance, recommending restrictions on PowerShell access, monitoring for DLL sideloading, blocking outdated Flash plugins, and enabling cloud-delivered protection in Microsoft Defender Antivirus. The campaign poses significant risks to enterprise networks, but individual users should also be cautious about executing commands requested by websites.
Tech Optimizer
September 3, 2026
Norton and Bitdefender both have a malware detection rate of 99.8%. Norton excels in phishing protection, blocking 95% of phishing attempts compared to Bitdefender's 89%. In terms of system impact, Bitdefender uses 11% CPU and 183 MB RAM during scans, while Norton uses 23% CPU and 384 MB RAM. Norton offers features such as cloud backup, parental controls, and unlimited VPN, whereas Bitdefender lacks cloud backup and has a limited VPN. Pricing for both is competitive, but Bitdefender generally has cheaper renewal costs. Norton provides faster customer support response times. In a comparison of nine categories, Norton won five and Bitdefender won three. For users needing backup and parental controls, Norton is preferred; for those with older laptops, Bitdefender is recommended.
AppWizard
September 3, 2026
Harvey Smith discussed the development of Deus Ex on the NoClip podcast, emphasizing the benefits of allowing extra time for game development, particularly in post-production. He noted that Ion Storm Austin received additional time, which enabled the team to refine the game and enhance the character Gunther Hermann, who initially had a limited role. Smith creatively integrated Gunther into a mission in a Paris cathedral, allowing for a more dynamic interaction and a dramatic moment where Gunther's presence added emotional weight to the gameplay. He highlighted the importance of providing game development teams with extra time to improve quality and creativity, suggesting that this approach could lead to greater success and recognition in the industry.
Winsage
September 3, 2026
OneDrive offers a minimum of one terabyte of online storage for Microsoft 365 subscribers and provides seamless backup of files and settings, particularly useful when transitioning to a new PC. However, its automatic backups can lead to excessive internet bandwidth usage and clutter with unnecessary files. Recent updates allow users to opt out of OneDrive backup entirely, although the specifics of this feature are unclear. Users can also manage their experience by selectively backing up folders and regularly reviewing stored files.
AppWizard
September 3, 2026
The National Cybercrime Threat Analytics Unit (NCTAU) has reported a rise in financial fraud linked to deceptive Android applications that pose as pornography apps. These apps are advertised on social media platforms like Facebook and Instagram under names such as ‘Night Play’, ‘Reloop’, ‘Kyss’, ‘Vimo’, ‘Rivo’, ‘Nexo’, and ‘Vixa’. Users who click on these ads are redirected to websites promising adult content, where they are encouraged to download APK files. Once installed, these apps often request sensitive permissions, particularly Accessibility access, which can allow malware to take control of the device and facilitate financial fraud. Some malicious apps may also install a VPN, rerouting internet traffic through servers controlled by attackers and exposing sensitive data. The malware is primarily promoted through ads linked to pornographic content, redirecting users to phishing websites that prompt APK downloads from non-Google Play sources, often using the “.live” domain extension. After installation, the initial app may download a second malicious package disguised as an update, exploiting the permissions granted to the original app.
AppWizard
September 3, 2026
Google's latest Android feature Drop introduces enhancements aimed at improving user experience, including aesthetic and functional improvements to messaging threads and the rollout of Motion Assist dots. A key feature is the expanded functionality of Gemini for Android 16 or higher, allowing users to log locations of items without tracker tags and store this information in Find Hub. Another addition is the Guided Vision feature within Gemini Live, which aids accessibility by helping users locate objects in the camera's view and extracting difficult-to-read information, such as text in low-light conditions. Guided Vision can be accessed through system Accessibility shortcuts and the TalkBack menu, compatible with Android devices starting from Android 9 Pie.
Winsage
September 3, 2026
Microsoft plans to automatically activate Memory Integrity on a broader range of eligible systems starting October 2026, rolling it out through standard Windows quality updates. Prior to activation, Windows will assess hardware, drivers, and performance to ensure compatibility. Memory Integrity, part of Virtualization-based Security (VBS), uses the Windows hypervisor to create a secure environment for integrity checks on kernel code. Compatibility with drivers is crucial, as many older applications may not meet the stricter standards required for HVCI. Potential compatibility issues may arise with anti-cheat solutions, third-party input methods, and banking protection programs, which could lead to software malfunctions or boot failures. A readiness check will evaluate hardware compatibility, with eligible systems including Intel processors from the 8th generation, AMD processors from Zen 2, and Qualcomm Snapdragon 8180 or newer, along with specific RAM and storage requirements. The rollout will be gradual, and users who previously disabled HVCI will not face unexpected reactivation. Microsoft recommends updating affected applications or drivers in case of compatibility issues.
Winsage
September 2, 2026
An active malware campaign is using counterfeit software-download websites to distribute malicious installers, primarily targeting users seeking popular software. This campaign has significantly affected China-based operations of multinational corporations and Chinese-speaking users. The malware, once executed, can establish persistence, undermine security measures, and communicate with attacker-controlled infrastructure. Victims span various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft associates this campaign with a Chinese threat cluster called Silver Fox, known for using spoofed vendor download pages to spread Gh0st RAT and ValleyRAT. The malicious websites are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content. The downloaded files are dynamically generated, and upon execution, they deploy a wrapper installer that initiates the malware payload. The malware achieves persistence through scheduled tasks and interferes with Windows Update services. The campaign establishes command-and-control communication over non-standard ports, with two identified domains linked to the activity. Microsoft Defender has detected the threat and initiated containment procedures. Kaspersky reported a related malicious installer exploiting a legitimate adware application to execute a backdoor, which captures keystrokes and clipboard contents. ValleyRAT, a sophisticated implant, can collect system information, reboot the computer, capture screenshots, and transmit logs. The attackers are motivated by cyber espionage and financial gain, targeting organizations globally. A subgroup within GoldenEyeDog, known as CuboidalCanine, has also been linked to the use of ValleyRAT, particularly in the gambling industry. In June 2026, Chinese authorities addressed cybercrime cases involving a new variant of the Silver Fox trojan.
Tech Optimizer
September 2, 2026
Gen Digital stock (ISIN US3687361044) traded at 30.02 dollars on September 1, 2026, reflecting a 3.2 percent decline from the previous close. The stock is within a 52-week trading range of 17.78 to 31.29 dollars, currently less than 4 percent below the 52-week high of 31.29 dollars. The intrinsic GF Value for the shares is estimated at 33.22 dollars, indicating the current price is 9.6 percent below this fair value. The stock has increased approximately 69 percent from its 52-week low of 17.78 dollars. Gen Digital introduced the Fearless Planet Index, showing North America with an average digital risk score of 29.6 percent, Europe at 28.5 percent, Asia-Pacific at 27.4 percent, the Middle East and Africa at 25.6 percent, and Latin America at 22.0 percent. The stock is quoted at 30.02 dollars on Nasdaq as of September 1, 2026.
Search