Target

AppWizard
August 14, 2026
Threema experienced significant disruptions due to large-scale DDoS attacks, rendering the service inaccessible for several hours on Tuesday and causing intermittent outages on Wednesday morning. The attacks targeted both Threema and its Swiss colocation partner, Nine, with service being unavailable from 7:30 p.m. to 11:30 p.m. CEST on Tuesday. By 12:23 p.m. on Wednesday, normal operations were restored. The security of Threema's systems and user data remained intact despite the service availability issues. The nature of the attacks made mitigation challenging, as attackers modified their methods rapidly. Threema's status page faced issues during the outage, and communication was conducted via email and social media. In response, Threema is implementing specialized upstream DDoS protection and plans to enhance its status page to provide monitoring for future disruptions.
Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
AppWizard
August 14, 2026
Researchers have identified Skeleton 150, believed to be the first confirmed victim of a trebuchet, unearthed during excavations beneath Stirling Castle in Scotland in 1997. This skeleton is part of a collection dating back to the 1300s and shows signs of violent death, including distinct cut marks, puncture wounds, and blunt force trauma. Dr. Buckberry from Historic Environment Scotland presented findings indicating that the unusual burial location beneath the castle chapel suggests these individuals may have died during sieges in the late 13th century. Stirling Castle was a strategic stronghold that fell to Edward I's armies after a siege in 1304, during which the largest trebuchet, "The War Wolf," was used. Dr. Buckberry noted that the extensive damage to Skeleton 150 indicates the individual was likely killed by a siege engine.
AppWizard
August 11, 2026
Star Wars Zero Company features turn-based combat and soldier management, drawing comparisons to the XCOM series. Developed by Bit Reactor, founded by former Firaxis staff, the game offers a tactical experience but lacks some depth found in XCOM 2. Early gameplay reveals concerns about its mechanics, with instances of frustrating misses during combat. The game emphasizes teamwork, with classes like astromech droids providing support roles. However, it lacks elements like fog of war and diverse combat arenas, and the enemy variety is limited. While inspired by Midnight Suns, the execution does not reach the same depth, and the game's base is smaller. Players can disable permadeath, and squad management systems allow for creative builds. Overall, while enjoyable, Zero Company has not yet met expectations for evolution in the tactics genre.
AppWizard
August 9, 2026
Minecraft will be released on the Nintendo Switch 2 on October 27, 2026. A closed beta is currently underway, with select players receiving notifications to download the beta version. The Nintendo Switch 2 version features support for Vibrant Visuals, allowing a maximum render distance of 16 chunks, while disabling this feature increases the render distance to 28 chunks. The performance target is set at 60 frames per second, with stable performance reported when Vibrant Visuals are off, though enabling them may cause fluctuations.
AppWizard
August 9, 2026
Toronto has seen an increase in gunfire incidents aimed at the U.S. consulate, leading to the arrests of a 19-year-old and a 15-year-old. These incidents are linked to alleged gun-for-hire plots that also target Jewish schools, synagogues, and waste management facilities in the Greater Toronto Area. Investigators are facing difficulties in identifying the masterminds behind these operations, partly due to the use of encrypted messaging apps to recruit young individuals. The federal government's Bill C-22 aims to provide law enforcement with tools to address these challenges, but it has faced criticism for potential overreach and privacy concerns. Police Chief Myron Demkiw emphasized the need for effective tools to prevent violence facilitated through encrypted communication. Technology analyst Carmi Levy raised concerns about balancing law enforcement needs with privacy rights. Additionally, there is a societal responsibility to protect children from online recruitment by criminal networks, with calls for proactive conversations between parents and children and educational initiatives in schools.
Search