domains

Winsage
July 31, 2026
In March, a commitment was made to enhance the quality of Windows, with a focus on several immediate changes including enhanced taskbar customization, meaningful AI integration, minimizing disruptions from Windows Updates, faster and more reliable File Explorer, greater control over widgets and feed experiences, a more straightforward Windows Insider Program, and improving the Feedback Hub experience. The core areas of focus are performance, reliability, and well-crafted experiences, with improvements already being rolled out to Windows Insiders and set to expand across Windows 11 PCs this fall. Recent updates include enhancements to the Windows Search Box, improvements for developers at Build 2026, advancements in WinUI 3, updates to the Taskbar and Start menu, simplified AI integration, foundational architecture enhancements for File Explorer, updates to widgets and feed experiences, the launch of the Driver Quality Initiative (DQI), memory efficiency improvements, enhanced reliability for Windows Hello, changes to reduce disruptions from Windows Updates, and a simplified Windows Insider Program. Looking ahead, the team plans to bring enhancements to general availability while focusing on onboarding and setup, memory optimization for PCs with 8GB and above, family features, and improved voice interactions. Engaging with Windows Insiders has been a highlight, and the team remains committed to ongoing improvements based on user feedback.
AppWizard
July 31, 2026
Bitsight's investigation revealed that inexpensive Android TV boxes are being shipped with applications that can change their hardware identity, allowing them to impersonate popular smartphone brands like Samsung and Huawei. This operation, named Fuyao, is linked to Zhejiang Fengwo IoT Technology Co., Ltd., a Chinese company established in 2019. The H96MAXV11 model was frequently reported among the affected devices. In one day, the operation received 65,957 reports from about 38,000 unique MAC addresses, with many devices misidentified as phones due to spoofed identifiers. Fengwo has also promoted over 120,000 "AI digital humans," though details on this marketing term are vague. The command-and-control server for Fuyao sends phone profiles to devices, masking their actual hardware specifications. The operation uses machine vision technology and a YOLOv8s object-detection model to identify advertisements. Bitsight documented 40 fraud tasks, 21 unique campaigns, and 166 modules across four devices. The operation's payout structure involves 144 operator-owned domains, with an estimated gross return of .25 per device daily, potentially leading to annual revenues in the millions. Attribution to Fengwo is supported by shared TLS certificate data and public patent records, although the patents do not directly address advertising. There is uncertainty about how the fraudulent apps were installed and at what point in the supply chain they were introduced. Device owners are advised to verify Play Protect certification and disconnect suspicious devices.
AppWizard
July 23, 2026
GitHub will reject command-line support bundle uploads from outdated versions of GitHub Enterprise Server lacking security patches starting August 18, 2026. The npm package @copilot-mcp/apex has been identified as a post-install dropper that installs a macOS infostealer, phishing for sensitive information and maintaining a connection to an attacker's server. A rogue extension on the Microsoft Visual Studio Code marketplace, "Markdown All Pro," impersonates a legitimate tool and opens a backdoor after installation. A phishing campaign targeting Portuguese users delivers the Lampion banking malware, which has been active since 2019. DoubleVerify reports a rise in "AfterCall" apps that exploit user permissions for ad fraud. The GhostCommit attack method hides malicious instructions within PNG images in pull requests. The U.S. government has updated its advisory on Iranian-affiliated cyber activity targeting operational technology devices. An Android app posing as a civil defense alert system has been found to contain malware for data harvesting. An Iranian threat actor is distributing MarkiRAT malware through fake applications. An analysis of 28 AI-coded applications revealed 434 vulnerabilities, prompting Cisco to introduce Antares to identify vulnerabilities in codebases. A Russian-speaking threat actor is dismantling guardrails on AI models to create offensive tools.
Search