Microsoft has identified an issue affecting Microsoft Teams and the new Outlook for Windows on Arm-based devices, such as the Surface Pro 11 and Surface Laptop 7, following the installation of Windows security updates released on or after August 11, 2026, specifically the KB5121003 update. The affected Windows 11 versions include 24H2, 25H2, and 26H1, causing these applications to fail to launch or close unexpectedly, while classic applications like Outlook, Word, and Excel remain unaffected. The issue is more prevalent on new or freshly imaged PCs that have not received updates from the Microsoft Store. Microsoft is working on a solution to be included in a future Windows update. In the meantime, users can mitigate the issue by updating to the latest version of the Auto Super Resolution Package (version 1.0.19.0 or later) via the Microsoft Store.
The Indian Cyber Crime Coordination Centre (I4C) has issued an advisory about malicious Android applications disguised as adult-content apps, which are promoted through social media and distributed outside official app stores. The National Cybercrime Threat Analytics Unit (NCTAU) warned that these apps can compromise mobile device security by requesting sensitive permissions and may install additional software without user consent, leading to unauthorized financial transactions. Users are advised to download apps only from trusted sources like the Google Play Store, avoid installing APK files from unverified sources, and refrain from granting accessibility permissions to untrusted applications. Recommendations include regularly reviewing installed apps, keeping Google Play Protect enabled, and monitoring bank accounts for unauthorized activities. Victims of cyber fraud are encouraged to report incidents via the national cybercrime helpline or the government’s reporting portal.
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital's Avast Antivirus, allowing attackers with local execution access to extract the Windows Security Account Manager (SAM) database and execute a shell with NT AUTHORITYSYSTEM privileges. The flaw is located in the Avast Sandbox component and could enable a complete local takeover of the system. The PoC is compatible with any version of Avast Antivirus and has been tested on fully patched versions of Avast and Windows 11 25H2. The repository does not provide a formal release, CVE identifier, or patch details. The vulnerability may also affect other GenDigital products like AVG and Norton. Security teams are advised to monitor for suspicious activities related to Avast services and restrict local administrator access. Organizations should inventory their deployed versions and apply vendor-provided updates as they become available.
The National Cybercrime Threat Analytics Unit (NCTAU) has reported a rise in financial fraud linked to deceptive Android applications that pose as pornography apps. These apps are advertised on social media platforms like Facebook and Instagram under names such as ‘Night Play’, ‘Reloop’, ‘Kyss’, ‘Vimo’, ‘Rivo’, ‘Nexo’, and ‘Vixa’. Users who click on these ads are redirected to websites promising adult content, where they are encouraged to download APK files. Once installed, these apps often request sensitive permissions, particularly Accessibility access, which can allow malware to take control of the device and facilitate financial fraud. Some malicious apps may also install a VPN, rerouting internet traffic through servers controlled by attackers and exposing sensitive data. The malware is primarily promoted through ads linked to pornographic content, redirecting users to phishing websites that prompt APK downloads from non-Google Play sources, often using the “.live” domain extension. After installation, the initial app may download a second malicious package disguised as an update, exploiting the permissions granted to the original app.
Microsoft is addressing an issue affecting users of Microsoft Teams and the new Outlook on ARM-based Windows devices, specifically the Surface Laptop 7 and Surface Pro 11, following updates released since the August 2026 Patch Tuesday. Users may experience crashes and launch failures after installing security updates from August 11, 2026, particularly update KB5121003. This issue primarily affects newly set up or freshly imaged PCs that lack the latest Microsoft Store updates, while classic Outlook, Word, Excel, and other applications remain unaffected. Microsoft recommends updating the Auto Super Resolution Package as a temporary workaround. A permanent fix is being developed and will be included in a future Windows update. Additionally, Microsoft has acknowledged other issues stemming from the August updates, including problems with printing and PDF exports in certain applications, and has been rolling out fixes for system crashes and gaming problems linked to peripherals with built-in RGB lighting. Customers are also advised to disregard alerts about Microsoft Defender Antivirus being disabled after the latest updates.
YouTube Premium Lite was launched in South Africa as a budget-friendly option at R49.99 per month, approximately 39% cheaper than the full YouTube Premium subscription. Users were disappointed to find that ads still appeared in various areas of the app, including recommended feeds and search results, despite the promise of an ad-free experience. The service lacks features such as offline video downloads, leading to a perception that users are not getting their money's worth. A survey indicated that many users opt out of YouTube Premium, often using ad blockers or tolerating ads instead. The demand for a more affordable ad-free experience remains unmet, and users feel that their subscriptions do not adequately support creators, especially as Alphabet reports record profits.
An active malware campaign is using counterfeit software-download websites to distribute malicious installers, primarily targeting users seeking popular software. This campaign has significantly affected China-based operations of multinational corporations and Chinese-speaking users. The malware, once executed, can establish persistence, undermine security measures, and communicate with attacker-controlled infrastructure. Victims span various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education.
Microsoft associates this campaign with a Chinese threat cluster called Silver Fox, known for using spoofed vendor download pages to spread Gh0st RAT and ValleyRAT. The malicious websites are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content. The downloaded files are dynamically generated, and upon execution, they deploy a wrapper installer that initiates the malware payload. The malware achieves persistence through scheduled tasks and interferes with Windows Update services.
The campaign establishes command-and-control communication over non-standard ports, with two identified domains linked to the activity. Microsoft Defender has detected the threat and initiated containment procedures. Kaspersky reported a related malicious installer exploiting a legitimate adware application to execute a backdoor, which captures keystrokes and clipboard contents. ValleyRAT, a sophisticated implant, can collect system information, reboot the computer, capture screenshots, and transmit logs.
The attackers are motivated by cyber espionage and financial gain, targeting organizations globally. A subgroup within GoldenEyeDog, known as CuboidalCanine, has also been linked to the use of ValleyRAT, particularly in the gambling industry. In June 2026, Chinese authorities addressed cybercrime cases involving a new variant of the Silver Fox trojan.
An ongoing malware campaign is targeting Windows devices through counterfeit download pages for well-known software brands like Microsoft Edge, Kaspersky, and Razer. The campaign affects various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. It utilizes high-fidelity fraudulent websites that closely mimic legitimate vendors, with observed lure domains such as app-microsoft-edge[.]com[.]cn and kaspersky-lab[.]hl[.]cn. Attackers employ evasion tactics like server-side payload regeneration and create multiple copies of the same archive in quick succession.
Victims are lured into downloading ZIP files that contain a bundled wrapper installer, which activates a stage-one executable in randomized directories. The malware often masquerades as legitimate software, with some payloads impersonating known applications. Persistence is achieved through scheduled tasks with unusual names, and the malware employs various evasion techniques, including deleting shadow copies and altering file permissions.
Microsoft Defender has identified activity across multiple stages of the attack, including delivery, execution, and command-and-control communications. To mitigate risks, organizations are advised to block downloads from unofficial sources, enforce Tamper Protection, and implement Attack Surface Reduction rules. Indicators of compromise (IOCs) include specific lure domains and URLs associated with the campaign.
Sony Music Publishing and Warner Chappell Music have filed a lawsuit against Anthropic, claiming that the company used pirated songbooks and song lyrics from "shadow libraries" to train its AI model, Claude. The lawsuit cites approximately 7 million books obtained through torrent downloads and web scraping, including unauthorized sheet music and songbooks. The plaintiffs are seeking statutory damages of up to 0,000 for each work that is found to have been willfully infringed. The lawsuit was filed on August 28, 2026, in the U.S. District Court for the Northern District of California, naming Anthropic and its co-founders as defendants. The plaintiffs allege that the data sources used for training included 5 million books downloaded from Library Genesis and 2 million from Pirate Library Mirror, as well as scraped song lyrics from licensed platforms Musixmatch and LyricFind. The use of BitTorrent for downloads introduces legal risks due to the simultaneous distribution of files. The lawsuit emphasizes the distinction between legally purchased and pirated materials, with prior cases indicating that downloads from pirate libraries constitute significant copyright infringement.