Google has implemented a new passive sign-in feature on YouTube, allowing users to stay signed in to their Google account while using the platform without having to actively sign in each time.
Google has introduced a new feature for YouTube users called passive sign-in. This feature allows users to stay signed in to their Google accounts while browsing YouTube without having to actively sign in each time.
Researchers at Graz University of Technology discovered significant vulnerabilities in the file-notification subsystems of major operating systems: Linux, Windows, macOS, and Android. These flaws, present for decades, allow side-channel attacks that can infer sensitive information like keystrokes and visited websites. The vulnerabilities are rooted in components such as inotify (Linux, since 2005), FileObserver (Android, since 2008), ReadDirectoryChangesW (Windows, since 2000), and FSEvents (macOS, since 2007). Unprivileged users can exploit these subsystems to observe file events, potentially leading to keystroke timing attacks and credential theft. While Linux has implemented partial mitigations (CVE-2025-68788), Microsoft and Apple have acknowledged the issues but have not provided substantial patches.
A newly identified strain of Android malware, RatHat, utilizes generative AI to manipulate infected devices in real time. It is linked to threat actors believed to be operating out of China. RatHat serializes the device’s live Accessibility tree into XML format and communicates with a generative AI assistant to return screen coordinates, identify text, and issue navigation commands. The malware employs WebView-based HTML overlays to capture login credentials from banking and cryptocurrency applications and can infiltrate payment apps like WeChat and Alipay to extract PINs. It also features an SMS receiver and notification listener to intercept OTPs and 2FA codes.
RatHat is disseminated through smishing, malvertising campaigns, and misleading third-party forums. It employs anti-analysis techniques such as container tampering, manifest bombing, DEX bytecode poisoning, string encryption, and anti-debugging. Once installed, it gains Accessibility access, activates Developer Options, and enables Wireless Debugging, allowing it to connect to the device's local ADB service and launch control agents with shell-level privileges.
The malware captures raw touch coordinates to reconstruct PINs and unlock patterns, bypassing screenshot protections. It also includes persistence mechanisms that prevent uninstallation by presenting a fake Google Play failure overlay and automatically reinstalling itself if removed.
India's internet usage has rapidly evolved, with the Unified Payments Interface (UPI) transforming smartphones into banking hubs and daily tasks being conducted online. Despite this digital shift, many users rely on pre-installed security software, which may not be sufficient against increasing cyber threats. In 2025, nearly one in four internet users in India faced web-based cyber threats, with over 47.5 million threats blocked, averaging about 130,000 daily. Kaspersky's Safe Money feature provides real-time verification of banking and shopping sites, while its anti-phishing capabilities respond to rapidly changing scams. Scammers are using multi-channel approaches, prompting Kaspersky's system to flag suspicious activity across platforms. Credential theft increased by 20% in 2025, with over 225,000 attacks thwarted, and Kaspersky offers identity monitoring to alert users of data leaks. Additionally, Kaspersky Premium provides 24/7 human support for suspicious activities, addressing the limitations of standard antivirus tools in a complex digital threat landscape.
India's digital landscape has rapidly evolved, with the Unified Payments Interface (UPI) turning smartphones into banking hubs and shifting many routine tasks online. However, users often rely on basic pre-installed security software, underestimating online threats. In 2025, nearly one in four internet users in India faced web-based threats, with over 47.5 million incidents blocked. Kaspersky addresses five critical gaps in online security:
1. Real-Time Site Verification: Kaspersky’s Safe Money feature provides real-time verification of banking and shopping sites, which standard antivirus tools lack.
2. Live Anti-Phishing Protection: Kaspersky offers real-time anti-phishing capabilities with a continuously updated threat database, responding faster than traditional antivirus solutions.
3. Cross-Channel Threat Detection: Kaspersky flags suspicious activities across multiple channels, unlike single-channel antivirus tools.
4. Identity and Data-Leak Monitoring: Kaspersky alerts users when their information appears on the dark web, integrating this feature into its protection suite.
5. Round-the-Clock Human Support: Kaspersky Premium provides 24/7 human support for users facing suspicious transactions or alerts.
Credential theft targeting Indian networks increased by 20% in 2025, with over 225,000 attacks thwarted. The sophistication of digital threats in India has outpaced basic defenses, necessitating advanced protection layers.
Google has introduced a new feature called Passive Sign-In for YouTube users. This feature allows users to stay signed in to their Google accounts while using YouTube, making it easier to access videos and playlists without repeatedly entering login credentials.
Microsoft has discontinued its PC-to-PC transfer tool for Windows 11, which allowed file transfers over Wi-Fi or LAN without using OneDrive. The company has shifted its focus to the Windows Backup solution that relies on OneDrive for file storage. Users must now restore backups linked to their Microsoft accounts and retrieve synced files via OneDrive, which has a 5GB storage limit for free accounts. The PC-to-PC transfer tool, tested in July 2025, enabled users to transfer documents, photos, videos, and user settings locally, but did not support the transfer of saved passwords, credentials, or installed applications.
Google has introduced a new feature for YouTube called Passive Sign-In, which allows users to stay signed in to their Google account while using YouTube without having to actively sign in each time.