Google has implemented a passive sign-in feature for YouTube, allowing users to seamlessly access their accounts without actively entering credentials.
Organizations that rely on technology face evolving cyber threats that traditional antivirus software struggles to address. Traditional antivirus detects known malware through signature matching but is limited in its ability to catch new or modified threats. Modern cyberattacks utilize techniques like polymorphic malware and fileless attacks to evade detection.
Endpoint Detection and Response (EDR) tools have emerged as a solution, focusing on analyzing behavior rather than matching known threats. EDR continuously monitors endpoints, collects data on system activities, and uses behavioral analysis to identify suspicious actions. This allows for real-time responses to threats, such as isolating affected devices or rolling back changes made by ransomware.
EDR is essential for all organizations, including small businesses, which are often targeted by attackers. It should be part of a broader security strategy that includes traditional antivirus, regular updates, employee training, access controls, and backups. When considering EDR options, businesses should prioritize response speed, visibility, reporting capabilities, and integration with existing IT support.
Google has implemented a new passive sign-in feature on YouTube, allowing users to stay signed in to their Google account while using the platform without having to actively sign in each time.
A bundle is available that includes Windows 11 Pro and Microsoft Office Professional Plus 2019 for .99, reduced from a regular price of 9. The bundle provides lifetime licenses for both software, designed for a single Windows PC, and does not require a recurring Microsoft 365 subscription. Windows 11 Pro includes features like BitLocker, Hyper-V, and Windows Sandbox, while Office Professional Plus 2019 includes Word, Excel, PowerPoint, Outlook, OneNote, Access, and Publisher. Office 2019 will no longer receive support after October 2025, and Publisher will lose support by October 2026. Windows 11 Pro requires specific hardware compatibility, including TPM 2.0, which can be checked using Microsoft's PC Health Check tool.
Google has introduced a new feature for YouTube users called passive sign-in. This feature allows users to stay signed in to their Google accounts while browsing YouTube without having to actively sign in each time.
The operators behind RatHat have created an advanced Android banking trojan that allows control of infected devices through a web console. Since April 2026, nearly 100 instances of this console have been identified, indicating a malware-as-a-service model. The console collects sensitive data from compromised phones, including text messages and passwords. It uses Google's Gemini AI to assess victims' bank balances, categorizing them into high-value and mid-value segments, but does not facilitate financial transactions.
The malware has remained largely unchanged since late 2025, but the console has seen significant updates, leading to three new versions: BlackCat Remote Control Management, Panda Workshop V5, and V6. These versions serve as both control interfaces and build tools for creating and distributing malware. The latest version includes templates for deceptive download pages.
RatHat infiltrates devices via text messages and online ads, requesting Accessibility access to read screens and simulate user interactions. This access allows the malware to activate wireless debugging and connect to the Android Debug Bridge (ADB), giving operators elevated privileges to execute commands. A Go program can be deployed to maintain control, even after the app is uninstalled.
Cleafy has tracked console deployments through web code analysis, noting that many IP addresses originate from a Singapore-registered network. The initial console version allowed operators to choose AI providers, but the latest exclusively uses Gemini. RatHat also utilizes Gemini on infected devices to determine tap locations based on screen layouts.
Cleafy has compiled indicators related to the consoles' command-and-control servers, download links, and malware samples, including specific domains, IP addresses, and MD5 hashes. The consoles often use web addresses starting with "admin." and inexpensive top-level domains. Security tools are advised to monitor processes running under the shell user on affected devices.
Researchers at Graz University of Technology discovered significant vulnerabilities in the file-notification subsystems of major operating systems: Linux, Windows, macOS, and Android. These flaws, present for decades, allow side-channel attacks that can infer sensitive information like keystrokes and visited websites. The vulnerabilities are rooted in components such as inotify (Linux, since 2005), FileObserver (Android, since 2008), ReadDirectoryChangesW (Windows, since 2000), and FSEvents (macOS, since 2007). Unprivileged users can exploit these subsystems to observe file events, potentially leading to keystroke timing attacks and credential theft. While Linux has implemented partial mitigations (CVE-2025-68788), Microsoft and Apple have acknowledged the issues but have not provided substantial patches.
YouTube has introduced a streamlined user authentication process that allows for a more passive sign-in method, enhancing user experience by reducing barriers to access. This change is expected to increase engagement with content, benefiting both users and businesses that rely on the platform for marketing, as it can lead to higher viewership and interaction with branded content.
Windows 11 Pro includes advanced features such as BitLocker for full disk encryption, Hyper-V and Windows Sandbox for running virtual machines, and integration with Azure Active Directory for business connectivity. It also offers Snap layouts for multitasking, DirectX 12 Ultimate for gaming, biometric login options with TPM 2.0 for enhanced security, and a Copilot feature for productivity assistance. A lifetime license for Windows 11 Pro is available for .97 until October 4.