theft

Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
Tech Optimizer
August 9, 2026
Generation Z is the most engaged demographic online, with 57 percent spending more time in the virtual realm than in the physical world. Smartphones are the primary tool for this generation, with 67 percent using them to access the internet. While 59 percent feel confident navigating the digital landscape, only 27 percent use antivirus software on their mobile devices. More than half (52 percent) have experienced cyber attacks, with 17 percent reporting hacking incidents on social media and 12 percent losing access to gaming accounts. Kaspersky recommends that Gen Z implement comprehensive security solutions, consider using a password manager, and utilize a trusted VPN for added online security.
AppWizard
August 9, 2026
Third-party advertising tools embedded in Android applications are automatically collecting location data, often without the app developers' awareness. Software development kits (SDKs) used for advertising come with location data collection enabled by default, unless developers actively disable this feature. Historical location data has been sold to military and intelligence agencies, including the FBI, and used in immigration enforcement actions in the US. The Electronic Frontier Foundation (EFF) reported that app-level location permissions do not provide meaningful consent for location collection by third-party advertising SDKs. The EFF identified four advertising SDKs—InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads—that collect and share location data by default. Two analyzed apps had been downloaded 60 million times without providing a privacy notice or seeking user consent for third-party location sharing. Users can manage location permissions through their device settings, but the EFF emphasizes that developers should ensure user data is not shared by default.
AppWizard
August 9, 2026
The PC versions of Grand Theft Auto: San Andreas, GTA 3, and Vice City have faced criticism for problematic ports due to code reuse and quality control issues. The modding community has created significant updates, including the SilentPatch, which addresses bugs and restores previously cut content. Notably, over 100 voice lines in GTA San Andreas have been restored, allowing players to access them while using a mouse and keyboard. These efforts reflect the dedication of the modding community to enhance the gaming experience and preserve the legacy of these classic games.
AppWizard
August 7, 2026
Strauss Zelnick, CEO of Take-Two Interactive, stated that physical game discs "don't really make sense" in today's digital market, especially with the upcoming release of Grand Theft Auto 6 exclusively in digital format. While PC gamers have largely adopted digital gaming, the console sector has traditionally relied on physical releases. However, the lack of a physical edition for Grand Theft Auto 6 and Sony's plan to stop disc production by 2028 indicate a shift in this trend. Zelnick noted that although the transition to digital is inevitable, Take-Two will still release physical editions "now and then." Ubisoft's CEO and industry analyst Daniel Ahmad support Zelnick's views, highlighting that the console ecosystem is becoming "nearly entirely digital." The release of Grand Theft Auto 6 on November 19 for PlayStation 5 and Xbox Series X/S raises questions about digital distribution and ownership in gaming.
Winsage
August 7, 2026
Security researchers from Huntress discovered a sophisticated SQL Injection (SQLi) attack that led to the deployment of a rare toolkit called Khunt. The attackers exploited a public-facing application backed by an Oracle database by failing to validate user input, allowing malicious SQL commands to be executed. The Khunt toolkit enabled activities such as executing operating system commands, stealing credentials, and exfiltrating registry hive data. Experts recommend robust defense mechanisms, including input sanitation, regular security audits, and the implementation of web application firewalls to protect against such attacks.
Tech Optimizer
August 6, 2026
Bitdefender Antivirus Plus is an award-winning security suite for Windows PCs that provides continuous system monitoring and real-time threat detection, effectively blocking viruses, ransomware, phishing attacks, and spyware. A one-year subscription includes features such as Advanced Threat Defense, anti-phishing and anti-fraud protection, ransomware defense, network threat prevention, a vulnerability scanner, anti-tracking tools, and Safepay for secure online transactions. It also offers a built-in VPN with 200MB of encrypted traffic daily. The subscription is available for both new and existing users in Canada and the United States. The current price for a one-year subscription is CAD, reduced from its original price of CAD.
Search