investigations

AppWizard
September 29, 2026
Motorola and Google are addressing an issue with Android Auto affecting users of clamshell foldable devices, specifically that outgoing calls cannot be made while the phones are closed. Incoming calls can be received without issues, but attempts to make outgoing calls result in no connection. This problem has been reported by owners of Motorola Razr and Samsung Galaxy Z Flip devices and appears to have arisen after the transition from Google Assistant to the new Gemini system. Reports of this malfunction have been ongoing for several months, with some claims dating back to September. No definitive solution has been announced yet, and users may need to keep their devices open to make calls while driving.
Tech Optimizer
September 25, 2026
Cybersecurity threats are on the rise, with Verizon’s 2026 Data Breach Investigations Report indicating that 48% of breaches involve ransomware and 31% arise from software vulnerabilities. A review of leading antivirus programs assessed their effectiveness against various threats. Top antivirus software includes: - Bitdefender: Best overall, effective against various threats, perfect score from AV-TEST. - Norton 360: Best all-in-one suite, includes VPN and parental controls, perfect score from AV-TEST. - McAfee+ Premium: Best for families, unlimited device coverage, full marks from AV-TEST. - Malwarebytes: Best for simple protection, user-friendly interface, rated 5.5/6 by AV-TEST. - ESET NOD32: Best for advanced users, lightweight and fast, includes Gamer Mode. - Avast: Best free option, offers various scanning options, straightforward upgrade path. - Microsoft Defender: Built-in for Windows, essential protection, perfect score from AV-TEST. - Intego ONE: Best for Mac users, includes firewall and VPN. - Surfshark Antivirus: Combines antivirus and VPN services, real-time protection. - TotalAV: Best for beginners, combines antivirus with web security tools. The evaluation process included lab data from AV-TEST and AV-Comparatives, hands-on experience, and criteria such as malware protection, false positives, system performance impact, phishing protection, ease of use, platform coverage, additional security features, and pricing. Key metrics from antivirus lab tests include protection scores, false positives, and performance impact. The choice between antivirus software and internet security suites depends on individual needs. Antivirus software remains necessary, especially for Windows PCs, to complement other security measures.
Winsage
September 22, 2026
Recent investigations have shown that a specific update to Microsoft Defender has caused performance issues for VLC Media Player, particularly a slowdown in startup times. Jean-Baptiste Kempf, a VideoLAN developer, attributed this sluggishness to a bug in the Microsoft Defender update, which quarantined VLC's plug-in cache. The problematic Defender signature update is version 1.455.50.0, linked to Windows Update KB5121003 released on August 11th. Users can reset the plug-in cache to improve performance by either reinstalling VLC or using the built-in functionality to regenerate the cache with vlc-cache-gen.exe. Alternatively, users can reset preferences and cache files by searching for "VLC" and selecting the reset option. Microsoft has not yet provided a fix for these issues, and users may need to set an exclusion in Microsoft Defender for VLC Media Player to prevent unnecessary scans, enhancing its performance.
AppWizard
September 19, 2026
Security researchers have identified an Android banking Trojan named RatHat, which utilizes artificial intelligence, accessibility features, and Android Debug Bridge (ADB) to steal financial credentials, PINs, and one-time passcodes. Unlike traditional malware, RatHat employs a live AI assistant that interacts with the Android accessibility tree, allowing it to make real-time decisions based on the victim's screen content. The infection typically starts with social-engineering tactics, leading victims to counterfeit download pages where they are tricked into sideloading a malicious APK. Once installed, RatHat prompts users to enable Android Accessibility Service permissions, which it exploits to navigate Developer Options and enable Wireless Debugging. This grants it shell-level ADB access, allowing it to bypass application sandbox restrictions. RatHat deploys two native binaries for executing commands and maintaining a connection to the attacker's infrastructure. It targets banking applications through credential-stealing overlays and can intercept SMS messages for transaction verification codes. Additionally, it can record touch coordinates to reconstruct PINs and unlock patterns. RatHat includes persistence mechanisms to restore itself after removal, and users are advised to perform a factory reset if they suspect compromise. To reduce infection risk, users should avoid sideloading apps from unknown links, deny unnecessary Accessibility Service requests, and refrain from enabling Developer Options or Wireless Debugging for unfamiliar applications.
Winsage
September 15, 2026
Iranian state cyber actors are targeting individuals through popular messaging applications, using surveillance and data-stealing malware known as "Chosen Brick," which has been in use since at least 2025. This malware is designed for Windows systems and enables the theft of personal data, allowing Iranian spies to monitor perceived threats such as dissidents, activists, and journalists. The attacks typically begin with messages sent via WhatsApp or Telegram, impersonating trusted contacts. Attackers conduct extensive research on their targets to craft convincing messages that encourage victims to download malicious files disguised as legitimate applications. Once executed, Chosen Brick operates stealthily, evading detection and establishing a connection for command-and-control communications. It can enumerate processes, capture screen and audio content, extract sensitive information, and even wipe infected systems. Organizations suspecting compromise are advised to engage IT providers for investigations and to inform staff about potential risks. Recent alerts follow cyberattacks on water and energy sectors linked to Iran, with ongoing concerns about the implications for cybersecurity amid escalating military tensions. Additionally, five US agencies have reported that attackers are using AI-generated scripts to exploit vulnerabilities in critical infrastructure systems.
Winsage
September 12, 2026
Windows 11 KB5124008, released on September 8, has caused various issues, including disruptions to WSL-based applications and Remote Desktop sessions. Users have reported problems with File History backups and instability in Explorer.exe, leading to system and GPU crashes. Microsoft confirmed a bug affecting applications using HCS-managed Linux virtual machines, particularly Claude Cowork, which is experiencing connectivity issues. Remote Desktop Services (RDS) are malfunctioning, leading to connection failures and sign-in problems. Additionally, some users face black screens upon sign-in due to Explorer.exe crashes. Reports indicate that File History is not recognizing external backup drives, and serious GPU issues have been reported on AMD Radeon systems, including driver timeouts and system freezes.
Tech Optimizer
September 12, 2026
If you hold Microsoft 365 E5, you already have access to Microsoft Defender for Endpoint, which provides enterprise-grade endpoint protection at no additional cost. For organizations without a dedicated security specialist, Sophos is recommended. CrowdStrike is suitable for those with a mature Security Operations Center (SOC) and sufficient budget. Other options include SentinelOne for mid-sized organizations needing automation, ESET for older hardware and virtual desktops, Avast Business for very small businesses without IT staff, VIPRE for budget-conscious organizations, and Expel for tool-agnostic managed detection and response. It is essential to assess your organization's current situation honestly when evaluating endpoint protection options. Antivirus and EDR are now essentially the same agent, and organizations should inquire about update staging processes and review independent tests for protection rates. Coverage for servers and Linux environments is often overlooked but crucial, as Linux servers are prime targets for ransomware. Key recommendations include: - Microsoft Defender for Endpoint for organizations already on Microsoft 365 E5. - Sophos for organizations with 25-500 staff relying on IT generalists. - CrowdStrike for enterprises with a well-funded security operations function. - SentinelOne for mid-sized organizations needing autonomous operation. - ESET for organizations with older hardware or virtual desktop infrastructure. - Avast Business for micro and small businesses. - VIPRE for budget-conscious organizations. - Expel for those seeking managed detection across various environments. During deployment, avoid running two real-time agents simultaneously, ensure prevention features are activated, and test on line-of-business applications first. Verify update staging and rollback procedures with vendors, and confirm whether Microsoft licensing covers your needs to avoid unnecessary purchases.
Tech Optimizer
September 10, 2026
If you hold Microsoft 365 E5, you have access to Microsoft Defender for Endpoint, which provides enterprise-grade endpoint protection at no additional cost. For organizations without a dedicated security specialist, Sophos is recommended for its user-friendly platform. CrowdStrike is suggested for those with a mature Security Operations Center (SOC) and sufficient budget. Other options include SentinelOne for mid-sized organizations needing automation, ESET for older hardware and virtual desktops, Avast Business for very small businesses, VIPRE for budget-conscious mixed estates, and Expel for tool-agnostic managed detection and response. Antivirus and EDR are now unified under a single agent, and organizations should inquire about update staging processes to avoid issues like those experienced in July 2024 with a major vendor's faulty content update. Independent tests from organizations like AV-Comparatives and AV-TEST are crucial for evaluating protection rates and false positives. Linux servers require attention as they are often targeted by ransomware. When deploying endpoint protection, avoid running two real-time agents simultaneously, activate prevention features promptly, and test deployments on critical applications first. Organizations should confirm their Microsoft licensing covers necessary features and ensure there is a plan for responding to alerts. Common pitfalls include neglecting identity management and failing to test response workflows before incidents occur.
Search