services

Tech Optimizer
September 16, 2026
Iranian state-affiliated cyber actors are targeting dissidents, activists, and journalists using fake AI applications, counterfeit antivirus tools, and fabricated MRI scan results, primarily through a spyware family known as CHOSEN BRICK, which is designed for Windows systems. This campaign has been active since at least 2025 and affects individuals globally, including in the UK, US, and Netherlands. The malware establishes persistence via the Windows Registry Run key and communicates through Telegram, utilizing unique Bot IDs for each victim. CHOSEN BRICK is capable of extensive data collection, including capturing screenshots, recording audio, and stealing email content. Personal information from victims has been found on pro-Iranian leak sites, increasing harassment risks. Security measures should include monitoring for suspicious Registry entries and unusual communications, while users are advised to avoid unsolicited software installations and keep their systems updated. The FBI refers to this malware family as HEAVYGRAM.
AppWizard
September 16, 2026
A new feature called "expert mode" is being introduced to enhance the "Advanced Protection" framework for Android users, allowing them to toggle specific security features individually. Users will be able to manage six distinct items within the Advanced Protection suite: Intrusion logging, USB protection, Block auto-connection to unsecured Wi-Fi, Unknown apps, Spam filter, and Suspicious links in Google Messages. The "expert features" will not replace "Advanced Protection" but will provide users with the option to enable all protections at once or selectively activate specific features. While "Block auto-connection to unsecured Wi-Fi" will debut with "expert features," the inclusion of "Unknown apps," "Spam filter," and "Suspicious links in Google Messages" in the final version remains uncertain. The relevant resource for updates is the "Google Play services" app, version v26.36, released on September 15, 2026.
Winsage
September 15, 2026
Microsoft announced on September 14 that the Windows 11 24H2 edition, including Home and Pro versions, has only 30 days of support remaining, with a deadline for updates set for October 13, 2026. Users are encouraged to upgrade to version 25H2 or later to continue receiving security updates. The Enterprise and Education editions will have support until October 12, 2027. Users have reported issues from September's security updates, particularly with the Office patch KB5002914, which disrupts the copy-and-paste function in Excel across multiple versions. Microsoft has acknowledged the issue but has not yet released a fix. A temporary workaround involves manually removing the problematic patch, though this also removes the associated security fixes. Additionally, users have experienced connection drops and unresponsiveness in Remote Desktop Services (RDS) across various Windows versions, including Windows 11 26H1 and Windows Server 2012. Microsoft confirmed that related tools may also stop responding, and restarting virtual machines may temporarily restore functionality. USB audio issues have been reported on certain USB Audio Class 1.0 devices across Windows 11 versions, with users experiencing loss of audio output and corrupted sound settings. Switching to 2-channel mode has helped some users, but Microsoft has not provided a timeline for a comprehensive fix. As Windows Server 2012 nears the end of its Extended Security Updates period on October 13, 2026, the RDS issues add pressure on administrators. Users on 24H2 need to prioritize migration to 25H2, while those with the latest updates should be cautious regarding Excel and Remote Desktop functionalities.
Winsage
September 15, 2026
Microsoft has released an out-of-band update to address issues from the September 2026 Windows 11 patch, which introduced new features and fixed nearly 1,000 security vulnerabilities. The update includes a movable taskbar, adjustable height, configurable Start menu layouts, enhanced Windows Search, and size indicators in File Explorer. However, users with AMD Radeon GPUs are experiencing crashes due to driver instability, and reinstalling drivers has not resolved the issue. Microsoft did not address these GPU concerns in its communication. The update also fixed instability issues with Remote Desktop Services, but users still report audio output and microphone input failures, which Microsoft has included a fix for in the emergency patch. Lenovo users have reported unexpected black screens or shutdowns linked to power management issues.
Winsage
September 15, 2026
Microsoft has released an out-of-band update to address issues from its recent Windows 11 patch, which introduced new features and fixed nearly 1,000 security vulnerabilities. The September 2026 update includes a movable taskbar, a transformed Start menu with configurable layouts, improved Windows Search, and updates to File Explorer showing file sizes in various units. However, users with AMD Radeon GPUs are experiencing crashes due to driver instability, and reinstalling the driver has not resolved the issue. Microsoft did not address AMD GPUs in its communication. Additionally, there are ongoing problems with audio output and microphone input, with some audio devices starting up with incorrect configurations. A temporary workaround for audio issues has been provided. Lenovo users are reporting black screens or sudden shutdowns linked to power management issues.
Winsage
September 15, 2026
Iranian state cyber actors are targeting individuals through popular messaging applications, using surveillance and data-stealing malware known as "Chosen Brick," which has been in use since at least 2025. This malware is designed for Windows systems and enables the theft of personal data, allowing Iranian spies to monitor perceived threats such as dissidents, activists, and journalists. The attacks typically begin with messages sent via WhatsApp or Telegram, impersonating trusted contacts. Attackers conduct extensive research on their targets to craft convincing messages that encourage victims to download malicious files disguised as legitimate applications. Once executed, Chosen Brick operates stealthily, evading detection and establishing a connection for command-and-control communications. It can enumerate processes, capture screen and audio content, extract sensitive information, and even wipe infected systems. Organizations suspecting compromise are advised to engage IT providers for investigations and to inform staff about potential risks. Recent alerts follow cyberattacks on water and energy sectors linked to Iran, with ongoing concerns about the implications for cybersecurity amid escalating military tensions. Additionally, five US agencies have reported that attackers are using AI-generated scripts to exploit vulnerabilities in critical infrastructure systems.
Search