阅读视图

发现新文章,点击刷新页面。
✇Tomshardware

Researcher reverse-engineers infamous Stuxnet malware source code, publishes it on Github for all — attack targeted Iranian nuclear facilities and was the first software of its type to cause physical damage

Anyone keeping track of world news in the early 2010s, and reports on tech in particular, has probably heard about Stuxnet. That malware spawned a large number of conspiracy theories — with the kicker that some of them were actually true. The malware targeted Iranian nuclear facilities and is believed to be the first digital worm to cause direct physical damage in meatspace. An unknown security researcher has now published a source code reverse-engineering of Stuxnet in all its glory.

The worm's ultimate target, allegedly a successful one, were industrial controllers from Siemens that were reportedly used in Iranian's Natanz nuclear enrichment plant. Once it reached the target, Stuxnet's payload manipulated the frequency converters in industrial centrifuges, in a bid to subtly damage the rotors — all while keeping the plant staff in the dark by reporting normal operation.

The repository contains build instructions so interested techies can try it out for themselves and learn all about its inner workings. You'll need a Windows XP or Windows 7 virtual machine, and for obvious reasons, you shouldn't configure any network connectivity for it. To witness the full effects of the payload rather than just the spreading mechanisms, you'll need the appropriate Siemens software, and ideally hardware — though we figure that industrial-scale centrifuges aren't exactly common in techies' cable drawers.

In its heyday, Stuxnet spread via three mechanisms. The primary infection vector was USB sticks with Windows shortcuts and autorun.inf files. Upon plugging one of those sticks in, just viewing the drive's contents would immediately trigger infection thanks to a zero-day vulnerability.

Infected systems then autonomously tried to spread the worm further via the network using a zero-day Windows Print Spooler vulnerability that would let an attacker write system files into any machine sharing a printer. It would also copy itself into accessible network shares. To evade Windows driver signature checks, Stuxnet used two digital certificates stolen from Realtek and JMicron.

The worm also had code to inject itself into Siemens software, by way of the WinCC SQL Server database, and embedding its code in Step 7 project files that automatically ran when engineers opened them. Since those files were almost guaranteed to be shared among more than one engineer, it made for an excellent internal infection vector that didn't depend on having network share control.

The final step was taking charge of the DLL that communicated with the actual centrifuges and injecting malicious code into the PLCs (Programmable Logic Controllers) of those machines to stealthily mess with the rotors.

Stuxnet was part of Operation Olympic Games, an alleged coordinated effort between the U.S. and Israel to try and curb Iran's purported progress in creating nuclear weapons at its Natanz facility. The initiative seemingly ran under both the Bush and Obama administrations, and was supposedly a way to dissuade Israel from launching its own preemptive strike against Iran. The software was allegedly developed by both the Pentagon and Israel's Unit 8200, and was reportedly successful in bringing down about 10% of Natanz' centrifuges by ultimately seriously damaging their rotors.

However, the worm had a nasty bug: it didn't have sufficient checks about which environment it was in, and failed to notice it was no longer in a local network environment. When engineers took their laptops home, it escaped out to the internet at large, at which point security researchers worldwide let out a collective "huh, that's odd" and proceeded to investigate. Mercifully, the worm contained a hard-coded self-destruct date set for June 24, 2012.

✇Tomshardware

Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole victims' data via remote access

作者 Etiido Uko

A federal grand jury in California has indicted Russian citizen Searzhudin Tamirlanovich Aktulaev for allegedly conducting phishing attacks that stole data from over 80,000 computers between June 2016 and November 2017, using TVRAT and DarkVNC remote-control malware. Detailed in a Department of Justice press release on September 1st, the indictment — filed in June 2021 and released September 2026 — lists charges of “Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses.”

Aktulaev was extradited to the U.S. in August 2026, five years after his arrest in Cyprus in May 2021. He made his first appearance in federal court in San Francisco — after which he was remanded to federal custody — and is scheduled to appear in district court on October 5, 2026. The arrest was made after an FBI investigation, and the case is being prosecuted by the National Security, Cyber, and Special Prosecutions Section.

According to the indictment, Aktulaev “conspired to exploit the online message platform of a well-known freelance employment technology company, located in the Northern District of California, to spread malware to approximately 80,000 freelancers”. He sent messages containing malicious Microsoft Excel attachments, using approximately 255 fake user accounts. Once opened, the attachments prompted users to run a macro that then downloaded malware from the Internet, mirroring a hack earlier this year in which an unofficial 7-zip.com website served malware-laden downloads for over a week.

The attack used TVRAT (TeamViewer Remote Access Trojan) and DarkVNC malware, both of which grant the attacker remote control of the infected system. TVRAT exploits TeamViewer, while DarkVNC exploits VNC Viewer, popular remote administration tools. The malware stole and uploaded data from the victims' computers to a command-and-control server, from which Aktulaev and his co-conspirators extracted the stolen data to “commit fraud and other criminal activities”.

The indictment says thousands of computers infected by the TVRAT malware were “calling back” to a command-and-control domain hosted in the United States, which was paid for using virtual currency. Roughly half of the victims were in the United States, many of whom were Northern District of California residents, according to the indictment.

“A database found on the command-and-control domain revealed thousands of victims. Additionally, a shared document on the email account used in the criminal activities contained information to include e-commerce login credentials, as well as personally identifiable information (“PII”) for hundreds of victims,” the press release said.

If convicted, Aktulaev could spend up to 20 years behind bars and pay a $250,000 fine or twice the total illicit gains for the conspiracy to commit wire fraud charge alone. The other charges carry terms ranging from two to twenty years in prison, in addition to fines. Meanwhile, the FBI is currently investigating another hack in which 153 million US and Canadian drivers’ licenses were leaked on a Russian cybercrime forum.

✇Tomshardware

FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

More than 153 million US and Canadian driver’s licenses, as well as other identity documents, have reportedly become available for purchase on the dark web for a limited time. According to cybersecurity journalist Brian Krebs, the service was called Nexus, and although it’s no longer available at the time of writing, it claimed to have possessed 153 million driver’s licenses, 10 million ID cards, 1.9 million travel documents, 1.3 million international driver’s licenses, 579k medical cards, 429k common access cards, 91k residence cards, 77k employment authorization records, and 5 million other documents, allegedly sourced from an ID-authentication service based in Louisiana.

The service was advertised on the Russian cybercrime forum Exploit, where whoever was promoting it posted the driver’s license of Krebs as a free sample, which caught the journalist’s attention. He was also able to see a preview of U.S. Secretary of Defense Pete Hegseth’s information on the database — a concerning breach of security for someone with such a sensitive position in the government. After further investigation, they concluded that the service seemed to have possessed legitimate data, especially after searching for the data of several of his friends and family members with their consent. One thing that all the people he found in the database had in common was that they all used Hertz to rent a vehicle.

Krebs also talked with security and privacy researcher Zach Edwards, who said that their information was also found on Nexus. Edwards said that they did not rent a car recently but used their ID at a Planet13 marijuana dispensary. The time stamps found on the scanned images of the driver’s licenses and other identity documents coincide with the time that the victims used their IDs at the said companies, confirming that they were the sources of the leaks. However, Planet13 and Hertz do not do their own authentication; instead, they contract a service provider for the service. Now, it turns out that both Planet13 and Hertz used the company for identity verification and ID-authentication — IDScan.

Based on the evidence gathered by Krebs, it seems that the leak is centered around the company. He has already contacted the company about the issue, and they said they were investigating the matter. “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” Jillian Kossman, a marketing and operations leader at idscan.net, told the journalist. The FBI has also started looking into the leak, with its New Orleans field office opening an official investigation into the breach.

The massive amount of data that was briefly available on the dark web is certainly concerning. A similar data breach hit Discord after its third-party service provider was hit and resulted in the exposure of 70,000 government IDs. Incidents like these have got privacy experts concerned with the push for online age verification requirements, which is why the EFF is asking the California governor to veto the law requiring this.

Aside from privacy-invasive checks and stepping on First Amendment rights, the leakage of sensitive data like this could increase incidents of stolen identity and more. Driver’s licenses are often widely accepted for opening credit lines and bank accounts, with both photographic, UV, and IR scans available on many of the leaked licenses. Aside from that, it could also potentially compromise the privacy and security of vulnerable people, like those fleeing domestic violence and those who are under the witness protection program.

✇Tomshardware

BlindLock hides your password manager and secure vault in a PNG image — also offers secure notes, 2FA, and a crypto address book, with optional hardware security keys

A new local‑only password manager, notes app, and secure vault that hides your secrets in an ordinary-looking .PNG image file is now available. BlindLock does all this and more with an option to bind to your hardware using TPM2.0, Secure Enclave, or StrongBox. No cloud storage or central vault account is required, and the dev is selling lifetime licenses at $49 (for now). There is an interactive online demo, with nothing uploaded or downloaded, as well as a downloadable full 7-day demo available.

BlindLock’s solo developer David Domingo indicates that one of the main drivers behind his efforts to create this application was the theft of customer vault backups from LastPass in late 2022. What happened to LastPass could have also happened to 1Password, Dashlane, even Proton Pass, reckons Domingo. “When your vault sits on someone else's server, you inherit every risk that server carries: employee access, infrastructure vulnerabilities, government subpoenas, supply chain attacks, and the simple mathematical reality that a server holding tens of millions of vaults is a far more attractive target than your laptop,” says the BlindLock dev on his blog.

BlindLock

(Image credit: BlindLock)

So, three independent layers of security apply to your BlindLock vault. It is invisible in its ordinary-looking PNG carrier, not just encrypted. BlindLock doesn’t run a central vault database, so there is nothing for attackers to steal from BlindLock servers and crack later. Your resting vault file uses 256-bit authenticated encryption and already includes NIST post-quantum components. It is also bound to your device. “The vault opens only when three things match: the carrier file, your master password and your authorized device,” asserts the BlindLock app page. “A copied file alone is not enough to gain access.”

BlindLock’s feature set is pretty broad for a new offering. Fully encrypted inside your chosen .PNG holiday snap or cat photo is a password manager, Markdown-supporting secure notes, a built-in 2FA authenticator, and an encrypted file vault (for any type of file), and there is support for an optional fourth-factor security key like a YubiKey or Google Titan, etc.

Accessing your BlindLock data requires three things at once: the carrier file, your master password, and the authorized device - the vault key is sealed to that device's security chip, which is TPM 2.0, Secure Enclave, or StrongBox depending on the platform. You can avoid overly bloating your central .PNG file by squirreling larger files separately in their own encrypted containers. BlindLock employs a hidden volumes system not unlike VeraCrypt for these containers. Domingo admits these are “not magically unfindable,” but are Argon2id-hardened, 256-bit authentication-encrypted and stored inconspicuously. For device loss or migration, users must create an encrypted BlindLock backup and keep its recovery phrase separately.

BlindLock

Online demo screenshot (Image credit: BlindLock)

As per the intro, BlindLock is being introduced as a one-time $49 purchase. This perpetual pricing plan only applies to the first 1,000 licenses. There will be three waves: “the first 100 at $49, the next 350 at $89, and the final 550 at $109. After that, BlindLock is subscription-only,” says Domingo. The independent dev wants to lay a solid financial foundation, so development of BlindLock can continue.

This article is merely sharing the news about BlindLock and shouldn't be taken as a recommendation. Please check out the online and downloadable demos and judge whether it works for you and offers the features you want for the price.

✇Tomshardware

Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware

Security researchers have found three different backdoor-like implants hidden in firmware for routers manufactured by Shenzhen Zhibotong Electronics, better known as ZBT. The hardware is sold around the world under a bewildering array of brands, meaning you may not even realize you're using a ZBT router. The research, published by security firm VulnCheck, began with a Zbtlink AX3000 router. Researchers found that its firmware contained an implant that they dubbed ENDLESSDOORS, as it automatically phones home to a command-and-control server and can execute arbitrary commands as root.

ENDLESSDOORS is essentially a remote-control system embedded directly into the router's firmware. It starts automatically at boot and disguises itself as a normal Linux kernel process called kworker. The router periodically connects to a hard-coded server and announces itself. There's no meaningful authentication or encryption involved. Commands received from the server are passed directly to a shell running as root, and the implant can also establish an interactive root shell.

VulnCheck demonstrated the problem by impersonating the command server and taking control of its own test router. In other words, this isn't merely a theoretical vulnerability; if an attacker can hijack the connection to the implant's command server, they can obtain complete control of the router. The researchers found ENDLESSDOORS embedded in firmware for 20 ZBT models, including the Z8102AX, WG3526, WE826-T3-DSIM, and several other cellular routers. The same hardware is also sold under other names because ZBT manufactures routers for OEM and ODM customers. VulnCheck assigned the issue CVE-2026-66747, with a CVSS score of 9.3, but that wasn't the end of the investigation.

A photograph of the Deep Orange 4G/LTE Router, which is a rebranded ZBT device.

The label on the Deep Orange 4G/LTE Router that VulnCheck purchased from a US Amazon seller clearly marks its as a rebranded ZBT device. (Image credit: VulnCheck)

VulnCheck subsequently bought an $88 Deep Orange cellular router from a US seller on Amazon and discovered that it was actually a white-labeled ZBT-WE826-T2. Its 2019 firmware was too old to contain ENDLESSDOORS, but instead, it contained two other implants that the firm designated DARKLANTERN and SPEAKINGSTONE.

DARKLANTERN is the particularly straightforward one. Operating as the infosrvd service, it opens a listener on the WAN via UDP port 9992 and accepts commands directly from the Internet without authentication. An attacker only needs to send a fixed 19-byte info probe to force the router to reveal identifying information like its model, firmware version, MAC address, and uptime.

Researchers found that the backdoor's meager security mechanisms could be trivially bypassed: its command payload checksum relies on a static, hardcoded salt ("mqonu.com"), and its internal MAC address filter can be entirely circumvented simply by submitting a MAC field of all zeroes. This allows any remote attacker to easily forge a packet and execute arbitrary commands as root. VulnCheck scanned the Internet and found 203 exposed DARKLANTERN instances in 22 countries, spread across 16 router models.

A diagram showing the surveillance architecture of the DARKLANTERN and SPEAKINGSTONE malware.

This diagram shows the surveillance architecture of the DARKLANTERN and SPEAKINGSTONE vulnerabilities. (Image credit: Vulncheck)

Meanwhile, SPEAKINGSTONE works differently and is even more concerning. Rather than waiting for an attacker to connect to a listening port, it runs as the yunmgrd service and periodically beacons outbound to ZBT's command-and-control infrastructure over UDP port 10000. That makes it useful even when the router sits securely behind NAT or a firewall, as it relies on a custom format dubbed "zbtProtocol" to push full device fingerprints directly to the remote server. SPEAKINGSTONE is also considerably more capable than simply providing a remote shell. According to VulnCheck, its command protocol allows remote operators to execute arbitrary commands, steal WAN PPPoE credentials, rewrite a DNS hijack list, and establish a reverse SSH tunnel.

The researchers also discovered a backup command server domain embedded in the malware that nobody had registered, so naturally, they registered it themselves. VulnCheck set up a server capable of speaking SPEAKINGSTONE's protocol at the newly registered "www.findmyipaddr.com" and watched the infected routers start calling home.

By August 21st, 392 unique devices had connected to the sinkhole. Fully 390 of those 392 were located in China, with the vast majority using China Mobile's network. Most of those devices were the same router model running the same firmware, suggesting a large-scale carrier deployment rather than random consumer infections. VulnCheck describes this particular deployment as "domestic Chinese surveillance technology."

An infographic showing the global scan results of the DARKLANTERN backdoor, with the majority of infections found in the US.

(Image credit: VulnCheck)

Now, that doesn't mean every ZBT router is a Chinese surveillance device. VulnCheck found ZBT hardware being sold under numerous independent brands worldwide, including Lippert Components, Wave WiFi, OneX in Australia, MoFI Network in Canada, Digineo in Germany, and more. Vulncheck explicitly notes that some of the firmware they examined did not contain the implants, calling out MOFI Network in particular for creating its own firmware which, when examined, "didn't contain any implants."

The problem is that ZBT's OEM business makes the hardware's origin surprisingly difficult to identify. The same underlying platforms have appeared under brands including WiFlyer, Deep Orange, Cioswi, CroSkylink and KuWFi, among others.

So the really unsettling part isn't that VulnCheck found three vulnerabilities in an obscure router. It's that these aren't conventional vulnerabilities where someone accidentally forgot to bounds-check a buffer. These are pieces of software deliberately included in the router firmware that provide remote access to the device. We would normally call this malware, but ZBT has described ENDLESSDOORS as an after-sales technical-support mechanism.

VulnCheck's counterargument is pretty compelling; the firm says that whatever its intended purpose, the mechanisms don't securely authenticate the party controlling them. An attacker who can hijack the communications can potentially exercise the same privileges, and because ZBT hardware is frequently sold under other brands, simply not buying something with “ZBT” printed on the box isn't necessarily enough.

If you own one of the affected devices, of which you can find a list at VulnCheck's blog entries for the vulnerabilities (ENDLESSDOORS and the other two), the only real solution is to simply replace it, because the security holes were installed at the factory; it's not as if installing a different firmware version is going to restore trust. Even if your device isn't listed, for anyone running a cheap cellular router, travel router, RV router, or other piece of networking hardware from an obscure OEM, you need to keep in mind that the brand on the plastic probably isn't the company that wrote the firmware, and the fellow who wrote the firmware may not share your values with regard to freedom or privacy.

✇Tomshardware

US Justice Department seizes domains it says Chinese state-sponsored hackers used to infiltrate systems at NASA, Senate, Federal Reserve, and more — FBI moves forward with domain seizures

The U.S. Department of Justice and FBI revealed in a statement Wednesday that it had seized domains related to platforms that it claims were operated by China state-sponsored hackers. The press release says the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, NIH, NASA, and U.S. Senate all experienced "computer intrusion activity."

The Justice Department says a state-sponsored group known as QTFY is responsible for the intrusion, which the U.S. government claims came to be through two pieces of malware: QTRouter and QScan. The release says the People's Republic of China (PRC) Ministry of State Security was among QTFY's paying customers.

According to the U.S. government, QScan "scans and automatically infects thousands of [IoT] devices worldwide." Those devices are then added to the QTRouter network. It's a botnet, but the Justice Department also calls it an "obfuscation layer" to mask the origin of malicious traffic. QTFY's system has been used to compromise U.S. critical infrastructure since 2018, according to the affidavit.

The group is said to be employed by the Nanjing Xinjiuwei Network Technology Company, which we were unable to find any information on.

As part of the action, the Justice Department seized three domains: qtproxy.xyz, qt-proxy.org, and qt-team.com. Those domains now show the seizure notice you can see below.

U.S. domain seizure notice.

(Image credit: Tom's Hardware)

The investigation into the group began as early as 2019, when the FBI looked into a system intrusion at NASA related to the CVE-2019-11510, which was subsequently patched. The FBI traced the activity back to two Gmail accounts and a phone number with a +86 country code (the code for the PRC).

The group allegedly rented infrastructure from commercial platforms, leading to a series of abuse complaints to the emails by hosting provider Hostwinds. The FBI says the group obtained the three domains it seized between 2022 and 2024, registering them with domain registrar Namecheap and paying through PayPal.

Although the PRC routinely denies hacking activities in the U.S., Chinese officials reportedly acknowledged that the government was behind a series of attacks on U.S. infrastructure late last year. In 2024, 30-year-old wiretap systems deployed by the U.S. government in telecom and internet providers were reportedly compromised by Chinese attackers.

✇Tomshardware

US authorities say Siemens controllers used for water and other infrastructure are being targeted by hackers — agencies claim threat actors use AI tools to generate exploitation scripts

Various U.S. agencies just released a warning claiming that Iranian hackers are targeting Siemens S7-series programmable logic controllers (PLCs). According to the Cybersecurity and Infrastructure Security Agency (CISA) advisory, hackers are using publicly available information on these widely used devices to develop exploits that would enable remote access and control. They’re also using AI tools, allowing them to identify additional attack vectors and possibly adapt to any defensive measures operators may have taken to protect their systems.

“The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the agency said in its warning. “The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk — it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.”

The warning comes from multiple government agencies, not just CISA. The advisory was also co-authored by the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE), and the Environmental Protection Agency (EPA), underscoring how serious this issue could become. Because of this, operators using Siemens S7 PLCs (and other PLCs operating critical infrastructure) are advised to keep their equipment updated with the latest applicable security patches, isolate it from the internet as much as possible, protect it with strong access controls, and deploy cybersecurity measures to monitor industrial control systems (ICS) for any anomalies and possible malicious activity.

What makes the threat especially dangerous is that the use of AI tools could enable potential attackers to make malicious files look and behave like legitimate monitoring tools. They achieve this by using open-source industrial automation libraries, making it easier for unsuspecting users to fall victim to their attacks. Although the agencies did not specify where these attacks could originate, they came less than a month after the water infrastructure of several states was hit by cyberattacks thought to have originated from Iran.

The proliferation of internet-connected devices in critical infrastructure has made them prime targets for both hackers seeking to make big money and nation-states seeking to gain an advantage over their opponents. This was made apparent in recent years when key government websites and online services in Ukraine went down just as the Russian military started pouring across its borders back in 2022. More recently, a worm from an unknown source wiped Iranian machines during the first quarter of 2026, which happened around the same time as the United States’ bombing campaign against the country.

There were even claims from Iran that networking devices from American and European companies failed during an attack even though they were disconnected from the rest of the world. Aside from these scenarios in active warfare, cyberattacks could also be used in gray warfare, where opponents can inflict maximum damage while retaining plausible deniability, reducing the chances of retaliation.

✇Tomshardware

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout

Slovakia sought to modernize its traffic control systems with the acquisition of a batch of 279 new NERO R-ONE speed cameras, reports the Risky Bulletin Newsletter. Unfortunately, the country’s national security service, the NBU, has discovered that the cameras have multiple security issues. Firstly, they have SMS-activated Russian backdoors. Secondly, live camera feeds can be accessed by anyone with the device IP, no password necessary. Slovakia splurged a chunk of its €30 million EU-fund modernization budget on this now deactivated system.

The nearly 300 freshly installed NERO R-ONE cameras are thought to be rebranded Russian CORDON PRO.M traffic cameras, produced by a St. Petersburg-based firm called Semicon. Their path to acquisition sounds rather serpentine, with the big batch reportedly bought via a Cyprus-based shell company with fake certifications. Reports also suggest that pressure from the opposition political party in Slovakia led to the NBU investigations. The current government of the country, led by populist Robert Fico, initially denied reports that the cameras were of Russian origin and rebuffed any security concerns. Fico has what some would describe as a pro-Russia tilt, but you can read more about that elsewhere, if you are interested.

Slovakia discovers Russian backdoors in 279 new traffic cameras

(Image credit: NBU Slovakia)

Camera flaws and vulnerabilities

As we mentioned in the intro, the hundreds of cameras Slovakia recently acquired and deployed have multiple issues which seem serious. Probably most seriously, in terms of national security, these cameras contain a hardcoded list of Russian phone numbers, which can be used to open a backdoor. An SMS from one of these numbers can open shell and network access.

Another problem with the cameras concerns broader security flaws. For example the SecureBoot feature is ineffective, and the web management portal can be accessed, exposing live streams, by anyone with the camera IP.

Cameras that have been installed and set up have since been deactivated by the Slovak Ministry of the Interior. Meanwhile, for due diligence, an independent auditor will be called in to confirm the NBU’s findings. It is thought that Croatia, and some other countries in Eastern Europe, may have undiscovered issues with traffic control cameras of similar origin.

✇Tomshardware

Geekom admits to shipping malware-laced network drivers for AMD mini PCs — company responds with guidance, removes malicious package

For the most part, you can rest assured that your device will remain uncompromised by malware if you keep to verified, trusted sources for downloading software. And yet, software booby traps sometimes find their way onto legitimate wares, as was the case of Geekom's network drivers for its range of A7, A8, AE7, AE8, AX7 Pro and AX8 Pro mini-PCs, as discovered by Videocardz.

If you have a Geekom mini-PC from those lines and have installed the LAN driver from the firm's website in the past, we'd advise a full system wipe if possible, or at the very least a Windows Defender offline scan. But in the words of Lt. Ellen Ripley, "nuke the entire site from orbit. It's the only way to be sure."

As it's part of a driver installer, this malicious software would get administrator-level permissions on your machine, being granted permission to steal all your data, intercept your keystrokes, or retrieve passwords. It connects to command-and-control centers so that the malfeasants can remotely access your PC at any time.

The basic story is fairly simple and sad as these things go: a support page for those series of machines contained a LAN driver whose installer was laced with the Asruex backdoor malware. As expected, Geekom has removed the software package in question and offered an apology, stating the driver was on a "legacy page [that] had already been replaced and was no longer accessible through the normal Support navigation, although it remained indexed by search engines."

The latter bit is precisely the problem, as it's a reasonable bet that many users (like yours truly) will first use Google or AI search to find the driver, and wouldn't go through Geekom's support menus. Furthermore, Geekom requested that Videocardz retract its original reporting of the problem, an arguably questionable move, and an ask that Videocardz denied.

For its part, Videocardz checked that the Asruex malware was indeed present with four separate detection engines: VirusTotal, FileScan.IO, MetaDefender, and Yarafy. It's worth nothing that nothing suggests that these families of mini-PCs are vulnerable out-of-the-box, too. That was unfortunately the case with some AceMagic machines a couple years ago that shipped with Bladabindi and Redline malware from the factory, as was Asus' incident with poisoned software updates in 2019.

The common knowledge for a new install is to get driver packages from Windows Update and only go to the manufacturers' website if something is amiss. However, many users might go to Geekom's site to ensure that they have the latest versions of their drivers, or perhaps they downloaded the LAN driver when trying to diagnose network issues of some sort.

As for a baseline cause, in our view this is clearly a case of Hanlon's Razor, as relatively small OEMs would have next to nothing to gain and everything to lose by intentionally shipping malware packages with their machines. As can be attested by most anyone who's installed Windows motherboard software of variable quality, Taiwan has historically been regarded as considering software a secondary concern when developing technology products, in part thanks to its unique geopolitical situation and the fact that its government only splits 30% of its IT budget to software.

✇Tomshardware

Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

The Dutch National Cyber Security Centre (NCSC-NL) reported on August 12 that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing, to compromise Macs with port 5900 exposed to the Internet. In every case reported to the agency, attackers obtained root access and installed a Monero cryptocurrency miner. Apple patched the flaw on August 6 in an out-of-band update covering macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, but the bug's official severity has since been rewritten, with CISA raising its CVSS score from 7.1 to 9.8 critical on August 14, now assessing the attack as automatable.

NCSC-NL first flagged the vulnerability in an advisory on August 7, a day after Apple's patch, urging organizations to update immediately. The August 12 revision added that public proof-of-concept code is now available and that active abuse had been observed on multiple internet-exposed systems.

Technical details of the bug were presented at last week's Black Hat conference, according to Ars Technica, alongside a video of the exploit in action. The root-level access attackers gained in the reported incidents matches the level of control researchers demonstrated in May, when they bypassed Memory Integrity Enforcement on Apple's M5 silicon with AI assistance.

NVD's change log for CVE-2026-65400 shows CISA initially scored the bug at 7.1 on August 6, using a vector that assumed an attacker needed low-level privileges and could achieve only partial impact. On August 14, the agency replaced that vector with one requiring no privileges and granting full compromise of confidentiality, integrity, and availability, raising the score to 9.8. A day later, CISA's decision record for the flaw flipped from "not automatable" to automatable, an assessment consistent with unattended Macs being rooted at scale for coin mining.

The flaw still isn't in CISA's Known Exploited Vulnerabilities catalog as of this writing. The same decision record also still lists exploitation as "none," despite the NCSC-NL report. Users who can't update immediately can turn Screen Sharing off under System Settings > General > Sharing.

Apple's advisory says an attacker on the network may be able to "authenticate to Screen Sharing without valid credentials," and describes the fix as improved state management during authentication. Screen Sharing is the VNC-based remote desktop service built into macOS, listening on TCP port 5900, which is disabled by default. The August 6 update comes just 10 days after Apple’s July 27 security round and fixes only this single CVE, representing the second Screen Sharing patch in a month. CVE-2026-43760, which required valid credentials to exploit, was fixed in the late-July releases.

✇Tomshardware

White House authorizes private companies to launch 'hack-back' cyberattacks that destroy data and systems, targeting foreign cybercrime organizations — vetted organizations can now conduct offensive cyber operations

President Donald Trump signed a presidential memorandum on August 12 establishing the first U.S. program that lets vetted private companies conduct offensive cyber operations, including attacks that destroy data and systems, against foreign cybercrime organizations. Participating firms must post at least $1 million in escrow, forfeited if they break the program's rules, and every operation requires written approval from officials of the Department of Justice and the Department of Homeland Security. Just a few months ago, the administration publicly ruled out this very policy.

In March, Thomas Lind, then a senior adviser at the Office of the National Cyber Director, told a conference the administration had no plans to authorize private offensive operations. "We're not interested in fighting pirates with pirates," Lind said. National Cyber Director Sean Cairncross said the same week that companies running offensive campaigns weren't what the administration meant when it asked industry for more help.

The memorandum authorizes two categories of activity: "Cyber Surveillance Operations," meaning unauthorized access to foreign systems to collect intelligence while staying undetected, and "Cyber Effects Operations," meaning the disruption or destruction of systems and the data on them. A National Coordination Center manages the program, implementation guidance is due within 60 days, and eligibility rules will admit both large firms and smaller companies suited to specialized tasks. Any company that unintentionally hits a U.S. person or a system on U.S. soil must halt operations and notify the government immediately.

A foreign group qualifies as a target under the memo unless "clear intelligence exists" establishing it's institutionally part of a foreign government or wholly operated under one's direction. Ransomware crews that operate with state tolerance but not formal state control, a description that fits much of the Russia-based ransomware ecosystem, stay well within the target scope. The DOJ and DHS directors can't approve operations likely to cause loss of life or rise to an armed attack under international law.

The memo stops short of prohibiting such operations, with approval authority for them sitting in a classified annex. Participating companies can also sign commercial deals with other private firms, and with state and local agencies, to receive threat data and propose operations based on it.

Jake Williams, vice president of research and development at cybersecurity firm Hunter Strategy, told TechCrunch that Americans involved in the operations "could easily be classified as non-uniformed combatants while traveling overseas." The memo follows suspected Iranian cyberattacks on water suppliers in 45 U.S. municipalities and a CISA alert on Iranian hackers targeting programmable logic controllers at water and energy companies, though state-directed hackers fall outside the program's own definition of a valid target.

Congress earmarked $1 billion for offensive cyber operations in last year's spending bill, and Google said in August last year it was preparing to take part in disruptive actions against cybercriminals.

✇Tomshardware

Just one instruction on AMD's 2015-era CPUs cracks open secret memory areas and gives full hardware-level control — exploit for 15h and 16h chip families gets you access to Platform Security Processor, microcode, and System Management Interface

Many cybersecurity exploits have been deemed The One Ring To Rule Them All, but that moniker is rarely as true as a literal bit that disables the memory mapping on some AMD CPUs, granting access to normally inaccessible areas. With just one instruction, you can access off-limits software like Platform Security Processor (PSP) where the TPM runs, the System Management Mode (SMM), microcode patch RAM, and other various sundries — in other words, full hardware-level control.

The exploit is called Skitter Creek Bath Salts (Skitter), and was developed by prolific hacker Christopher Domas, famous for finding CPU flaws like Sandsifter and God Mode Unlocked. Only AMD chips from the 15h and 16h families are affected, roughly 2011 to 2015 vintages. Family 15 is FX-series desktop chips and some Opterons, while 16h includes low-power Jaguar- and Puma-based SoCs like those in the PlayStation 4 and Xbox One, plus a handful of Athlon, Sempron, and Opteron-X chips, among others.

To pull off this exploit, you'll need kernel-level access, meaning the ability to run your own drivers. But once you do, the entirety of DRAM is your oyster. AMD published a security bulletin on the matter, saying these chips are out of security support, plus, as mentioned, the necessary access level means an attacker already controls the machine anyway.

If you're confused as to how one instruction opens up a system, here's our attempt at a simplification. Say you have 16 GB of RAM. You'd think that Windows gets all 16 GB to play with, from address 0 to the end of memory — but as you may have noticed before, it's actually a bit less than that. The rest is reserved for system-level data.

Some parts are visible to the OS so it can interact with devices, but others include Very Important Things like PSP, SMM, microcode patches, all in sections supposed to be completely untouchable. If they were accessible, the system as a whole wasn't secure by definition anymore — just think of a malicious driver being able to freely mess with how your processor handles data.

For performance reasons, modern processors' RAM controllers don't use memory in a straight line, so to speak — they use bank interleaving, meaning that the actual bytes in the DRAM are jumbled, all while the OS sees a nice, tidy, flat surface. As it turns out, the CPU setting that controls this feature is accessible to the OS in the aforementioned chip families, and it's called BankSwizzleMode (Swizzle). It can be toggled on or off with the instruction "xor dword [0xf80c2094], 0x00400000", a simple bit twiddle. And as it turns out, this can be exploited.

First, you run a loop to figure out how the mapping normally functions. You place a canary value in memory (say, 0xDEADBEEF, according to tradition), disable Swizzle, run through memory to see where it landed, and reenable Swizzle again. Do this enough times, and you know exactly how visible memory is mapped into physical DRAM, and vice versa.

With the map now in your possession, you can now disable Swizzle and force a read or write to normally inaccessible areas of the DRAM, since you now know where it will land. With this, you can access all the previously hidden code and data, netting you hardware-level access to do anything you want, including reading fTPM signing code and any other low-level shenanigans you can think of.

Attentive readers might be wondering why the system doesn't crash during this process since you're effectively temporarily turning the RAM into a spaghetti mess. The answer is that every time you enable and disable Swizzle, you prepare the CPU by disabling interrupts, along with a number of other measures. Even still, the machine can crash during the map-collection step, but that only needs to be done once. After you have the map, the likelihood of a crash is fairly low since you'll be targeting specific locations.

Another question might be why sending a bit to a memory location somehow messes with the CPU, and the answer is that part of OS-accessible memory is actually mapped to hardware according to the Memory-Mapped Configuration Space standard (MMCONFIG) — meaning that reads or writes to that space are directed to hardware configuration settings, not actual RAM.

Edit 8/14/2026: Clarified TPM.

✇Tomshardware

Microsoft's nemesis drops new zero-day privilege escalation vulnerability — attack grants system-level privileges, but it could already be patched

Prolific hacker and Microsoft nemesis 'Nightmare Eclipse' has just published ShieldBreak, yet another Windows zero-day vulnerability that ought to get you SYSTEM-level privileges just by running some code as a regular user. Although Eclipse has generally kept ahead of Microsoft, it seems the company may be catching up, as our own quick testing found this exploit is already detected by Defender and might even be patched as of last Tuesday.

As described by the author, ShieldBreak is essentially a continuation of the previously reported RoguePlanet vulnerability in Windows Defender's subsystems. Eclipse claims that Microsoft failed to properly patch RoguePlanet, and that ShieldBreak in theory bypasses the recently added protection.

The proof-of-concept code for the new exploit is supposed to bring up a super-elevated command prompt with SYSTEM privileges (higher than Administrator). The author claims the vulnerability is present in the "latest" versions of Windows 11, Windows Server 2025, and Windows 10, though the proof-of-concept is limited to the former two operating systems.

Although researchers like Kevin Beaumont and Will Dormann say they've successfully reproduced the exploit, our informal testing in a Windows 11 virtual machine didn't yield any results. Said VM was just updated yesterday with the latest Windows 11 patches and currently sits at version 10.0.26200.9168. Given that Microsoft just published a giga-patch last Tuesday, there's a solid chance it plugged whichever hole ShieldBreak was getting through.

The sample screenshot in the ShieldBreak repository shows the exploit working under version 10.0.26100.33296, lending some credence to this theory. A sample size of one does not research make, so we advise caution and remind everyone to run their own testing before assuming the bug has truly been fixed.

Microsoft appears to have already published a Defender detection for it. We found it when double-checking our results, with just a 20-minute window between both tests, as shown in the screenshot below.

ShieldBreak vulnerability detected by Defender

(Image credit: Future)

Even if the issue is fixed, not every user updates their machines as soon as patches are available, and perhaps more importantly, corporations tend to hold back on patches until they know they don't bring in any new issues. That means that a good portion of the world's machines may still be vulnerable to ShieldBreak.

Little is known about Nightmare Eclipse, other than that they really don't like Microsoft and claim the company has ruined their lives. Some cybersecurity experts like Brian Krebs and Kevin Beaumont have offered up the theory that Eclipse is a disgruntled Microsoft ex-employee.

✇Tomshardware

Coin-sized device can hack a Boeing 737’s Flight Management Computer, mess with takeoff weights, or even divert an aircraft — gadget connects to an easily accessible port that overrides commands from the pilots, uses in-flight Wi-Fi

A group of researchers from the University of California San Diego (UCSD) and Oberlin College have developed a tiny device about the size of a coin that directly attaches to an external port on a Boeing 737 that connects to its Flight Management Computer (FMC) and Multipurpose Control Display Unit (MCDU). According to Wired, this gadget, which goes into one of the ports that aircraft mechanics use to test and diagnose avionics, is small enough to fit under its dust cap and go unnoticed during routine inspections. It then overrides the signals between the MCDU — the terminal in the cockpit that allows pilots to see and input data — and the FMC, the actual computer that controls the plane’s navigation, autopilot, performance calculations, and more.

The idea began when researchers were experimenting with hacking cars remotely in the mid-to-late 2010s, when they wondered if aircraft could be vulnerable to these types of attacks as well. Since an entire commercial aircraft is quite expensive, the group settled on looking for bargain-bin used aircraft parts until they were finally able to build a complete avionics stack to do their experiments on. Another UCSD professor, Aaron Schulman, was working on a different research project about credit card skimmers when the group realized that the communication bus that some skimmers were tapping into to steal payment information could potentially work similarly on a jet. “We realized that it's a reasonable threat for someone to plug a device into a bus and read stuff off of it and potentially even gain control of it,” Schulman told Wired. “We were like, ‘Wait a minute, we’ve got to rethink everything.’”

This was where the researchers discovered that a port in one of the Boeing 737’s two Electronics and Equipment (E&E) bays, located either in front of or behind the nose wheel well, connected to a bus that carried the data between the FMC and MCDU. This port, typically used for testing and diagnostics, isn’t protected by anything except for a dust cap and could easily be accessible by anyone authorized to work on or be around the aircraft. What’s more concerning is that the device can connect to the internet via in-flight Wi-Fi, allowing the researchers to tap into the plane’s avionics remotely.

Some of the changes they were able to make included intercepting, altering, and spoofing data and commands that go between the FMC and MCDU. This includes changing the outside air temperature readings and the aircraft weight inputted into the system, which could mess with the aircraft’s takeoff performance. If the temperature that the FMC has is higher than what the MCDU shows, or if the weight is lighter than what is actually measured, then the engine power set that the FMC will set for the takeoff might not be enough to get it off the ground.

This is actually the biggest threat to aircraft, as incidents of mistyped takeoff weight (by 100 tons) have resulted in tail strikes for LATAM 8073 in 2024 and Emirates 407 in 2009. A more egregious accident happened in 2004, when the crew of MK Airlines 1602 typed the empty weight of their Boeing 747 instead of its actual weight, resulting in the plane striking an earthen berm and causing it to disintegrate and crash into the ground. However, these events have caused the industry to implement stricter measures to prevent these crashes from happening again, including independent computations on their electronic flight bags (EFBs) and warning messages on the Electronic Flight Display (EFD), which is independent of the MCDU.

Another thing that a potential attacker can do is to silently change the plane’s flight plan, causing it to divert from its intended routing. They can do this by making minor changes that might be imperceptible to the pilots, causing the flight to go astray over time. Despite these threats, pilots are trained to deal with conflicting data from the MCDU and override the FMC as necessary. Incidents in the past, like the disappearance of MH370, have ensured that multiple systems exist so that a malfunctioning or compromised FMC will not lead to disaster. For example, an aircraft deviating from its assigned route and altitude will be contacted by ATC, as we have seen in this small aircraft crash that began when the pilots were confused by GPS jamming.

Because of these safety layers, Boeing told Wired, “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.” Still, it doesn’t mean that aircraft manufacturers should just ignore this threat. The researchers initially suggested permanently blocking the service port, followed by better isolation of electrical systems, or the addition of cryptography to prevent a device such as this from spoofing the plane’s systems. However, they also feared that Boeing would not do anything, as major changes like this are expensive and could take years to implement. We see this in some aircraft that still carry passengers or freight to this day but are kept updated through 3.5-inch floppy disks.

✇Tomshardware

Critical 'Zoomsday' flaw enables total device takeover during Zoom calls — AI-assisted research only used 20 prompts to find an exploit to hack hundreds of millions of people.

We've typed many words about how the industry-standard 90-day security bug disclosure window is effectively dead and gone with the advent of AI-assisted exploiting. Illustrating that point rather poignantly, researchers at A.Security easily came up with Zoomsday. This exploit let any participant in a Zoom meeting gain control over the device of anyone else, all without them being any wiser.

The team claims it cooked the exploit with merely 20 prompts to an AI agent. The exploitable area is substantial, as recent estimates pin Zoom's monthly active users at around 220 million and an estimated 56% of the global conferencing market share.

There were two remote code execution (RCE) vulnerabilities present in Zoom Workplace before 7.0.6 and, for users on the "fast track" branch, before version 7.1.5. The bugs were in a library used by Zoom's annotation functionality, though no participants need to actually use the whiteboard for the exploit to work — the code is always on, so all an attacker needed to do was join the meeting. Zoom quickly fixed the bugs after the initial reports, so everyone who has updated Zoom Workplace to the current version should be safe.

With the exploit, the attacker was able to get full remote code execution, meaning they could effectively control the user's computer and their data — invisibly, to boot. Zoom isn't an application that runs with administrator privileges, so kernel-level rootkits are off the menu, but once you have the user's data, it's not like you need much else. Plus, it's easy to gain exploit persistence any number of other ways.

A.Security says a small team developed this exploit with a mere 20 prompts to an AI agent — pointing out how easy it was to come up with a nation-state-class vulnerability with meager resources. While the majority of AI-assisted vulnerability research focuses on open-source software or applications with published communications protocols or file formats, Zoom is fully proprietary, and it was still easily cracked open.

The firm further noted that "the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed," and that "the barrier that kept these weapons scarce has collapsed, and it will not come back" — basically repeating what every security researcher has been yelling from the top of their lungs for the past year or so.

The vulnerability itself is, rather unsurprisingly, a buffer overrun: the program fails to check that an input is the right size, so you can push more data than it expects and overwrite part of the following memory with code that will be executed.

First, the scientists decompiled the Android package and asked an AI agent to rank the potential attack surfaces to relatively little success. They then turned their attention to the communications protocol. They found that the code library handling annotations received each object (rectangles, text, etc.) in serialized form, with count fields telling the recipient how much data to read next.

Crucially, they found that the code handling these reads didn't have a boundary check for maximum size, meaning one could simply lie about it and send a chunk of data that's too large and padded with exploit code at the end, as Norman Stansfield would say, bin-go!

✇Tomshardware

Suspected China-linked hackers used AI to run the first-ever end-to-end autonomous cyberattack on Taiwan's government, Israeli firm says — open-source-built tool continuously devised effective hack strategies in real-time

Hackers with suspected links to China used publicly available AI tools to carry out what researchers describe as the first observed end-to-end autonomous cyberattack against a government target, compromising at least 85 user accounts and stealing more than 2,500 personnel records from Taiwanese government systems, according to an August 12 Financial Times report, citing researchers at Israeli cybersecurity company Dream. The researchers say the attackers assembled an autonomous hacking platform using open-source AI-agent frameworks, enabling multiple agents to simultaneously map networks, research vulnerabilities, attempt intrusions, and adapt tactics when an attack path failed.

The campaign reportedly ran for four days at the beginning of July and at times deployed as many as eight autonomous agents in parallel. Dream said the system mapped 21 government systems before compromising user accounts and extracting personnel information. The attackers subsequently expanded their activity to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems.

Dream says it found the evidence inside a 160-megabyte (160MB) online archive that surfaced during its broader tracking of cyberthreat actors. The archive reportedly held 1,395 files showing that the tool was built on two open-source AI agent systems — Hermes and OpenClaw — both of which can be downloaded freely and are designed to let large language models carry out multi-step tasks on their own.

Researchers could not determine which underlying model powered the agents, but the data reportedly showed the model's safeguards had been sidestepped by presenting the intrusion as an authorized penetration test rather than a real attack. Of particular concern is that the toolkit for the hack comprised such easily available systems, neither of which was purpose-built for offense. The operators appear to have assembled a capable autonomous tool out of components any developer can pull down and run.

What the researchers describe as the tool’s most striking feature was its ability to continuously devise attacks on its own, rather than follow a preprogrammed route. The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed. When one technique failed, the tool tasked another agent with searching the internet for information and developing an alternative approach.

Dream stopped short of attributing the campaign to a specific hacking group or country. However, the researchers said the operators’ internal communications were written in Simplified Chinese, suggesting what they called a high probability that the operator was connected to China. The company also declined to name the victim, citing policy, but confirmed that it had notified a country in the "Asia-Pacific" region. Also, the data pulled from the target was in Traditional Chinese — a script used on government sites in Taiwan, Hong Kong, and Macau. Financial Times said a person with knowledge of the incident identified the target as Taiwan.

The incident highlights a growing concern within both the cybersecurity and AI industries over what the latest AI models can do autonomously. Anthropic, OpenAI, and Meta have reported instances of new AI models launching unexpected cyberattacks during internal testing, an infamous example being the recent OpenAI agent’s attack on Hugging Face. In another instance, OpenClaw wiped the inbox of Meta's AI Alignment director despite repeated commands to stop

Researchers have warned that AI agents are making it increasingly easy to automate portions of cyberattacks that previously required skilled human operators, another deadly feature in the era of AI hacking. Dream's chief strategy officer, Amir Becker, warned that the arrival of such tooling used in the Taiwan attack means every government should now assume it is under permanent automated assault.

The risk is stark for Taiwan, which was already facing a staggering volume of cyberattacks before agents entered the picture. The island's National Security Bureau reported in January that it faced an average of 2.6 million Chinese cyberattacks per day in 2025, up 6 percent from the previous year. Beijing claims Taiwan as part of its territory and has threatened to use force if necessary to bring the island under its control. According to the Financial Times, Taiwan's Ministry of Digital Affairs declined to comment on the specific incident, citing confidentiality. However, a ministry spokesperson acknowledged that the integration of AI has transformed the nature of security incidents.

✇Tomshardware

Passenger returning from DEF CON 34 spoofs Delta Wi-Fi network while in flight using pentest tool — pilots tell ground crew to alert corporate security after attendee from hacking conference brings the party to the sky

Delta Flight 591 between Las Vegas, Nevada, and Atlanta, Georgia was carrying some passengers from the recently concluded DEF CON 34 hacking conference yesterday, and an attendee apparently didn't want to let the fun stay in Vegas. A passenger reportedly “jammed” the plane’s Wi-Fi signal. According to View From the Wing, that hacker then created their own Wi-Fi hotspot called “Delta WiFi Fast” that routed to a phishing website that harvested the Google credentials of any passenger who attempted to log in.

The pilots on the flight told the ground crew to alert corporate security as someone was tampering with in-flight Wi-Fi through ACARS, the digital communications systems airliners use for air-to-ground text communications. “Hey, alert corporate security. We have a passenger onboard that has created a scam Wi-Fi called ‘Delta WiFi Fast.’ We believe they are trying to scam the other passengers,” the pilots said in their first message. They followed this up 17 minutes later with, “No information as of now. We have a bunch of passengers that were at a cybersecurity conference in Las Vegas. They were able to jam our Wi-Fi and broadcast their signal.”

While the exact details are unclear as the incident is still under investigation, the attacker (or prankster) apparently used a Wi-Fi Pineapple penetration testing device to launch Wi-Fi deauthentication attacks and then created an evil twin that other passengers could log into instead. This fake log-in page could have been used to harvest usernames, passwords, and other credentials. The plane was reportedly met at the gate by the authorities, although it’s unclear if any arrests were made.

Most in-flight Wi-Fi networks are unsecured, so a determined hacker could potentially use it for cyberattacks on their fellow passengers. Creating an “evil twin” network does not carry the same alarm, scandal, and potential lawsuit that a public network or device named “bomb” would on a flight, but it could still land you in hot water.

“Jamming” or interfering with in-flight Wi-Fi (or any Wi-Fi network, for that matter) is prohibited by the FCC [PDF], while the phishing log-in page could constitute wire fraud or identity theft. The passenger who created the fake in-flight Wi-Fi is also using social engineering, especially as more airlines adopt in-flight Wi-Fi and more passengers expect it, especially as they start switching to Starlink to provide reliable and fast internet.

Despite the potential threat to passengers’ cybersecurity, Delta reassured flyers that the safety of the flight was never threatened in any way. “Safety of flight was never in question, and no aircraft operating systems were affected. We are fully investigating to gather a complete set of facts, which will take time,” a Delta spokesperson told View From the Wing. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding.”

✇Tomshardware

Japanese authorities use new tool to identify initial torrent uploaders — anti-piracy group says it identified seeder on popular anime torrenting website without torrent swarm monitoring

Recently, the Kyoto Prefectural Police caught one of the initial-seeders of the well-known Japanese torrent website Nyaa. Masakazu Ono, 56, from Sagamihara in the Kamigawa Prefecture, was arrested after a multi-year investigation. While this news is straightforward by itself, the interesting bit is that CODA, the Japanese anti-piracy entity that performed the initial cyber-investigation, identified Ono allegedly without joining or monitoring BitTorrent swarm traffic, with the help of the Japan Hacker Association (JHA).

CODA's description of only having "[analyzed] how data moves through torrent sites, such as index sites and tracker sites" is vague and can be parsed in a number of ways. The distinction between indexer and tracker is relevant: while an indexer is a user-visible list of torrents (usually a website), the tracker is the background service that software like qBittorrent actually connects to, and it lists everyone who's currently active in that torrent, whether sharing, downloading, or both.

Our hypothesis is that CODA kept close tabs on the Nyaa trackers to see which IP address (in this case, Ono's) consistently appeared as the first person to offer up a 100% complete set of data for a show, a theory that would fit with how long the operation took. JHA's founder, Takayuki Sugiura, was the first to decrypt the Winny P2P protocol in 2004 to find original uploader sources, and the methods used weren't too different from the aforementioned theory. It's also possible that Ono wasn't using a VPN but was logged into Nyaa, or activity at another website's cookies or CDN logs was used to establish a link to his activity at Nyaa, and from thereon, to the tracker.

An initial-seeder is someone who is the first to offer up data for others to download — in this case, shows and movies. The show that reportedly got Ono nailed was Midnight Taxi, a 2026 Japanese drama produced by NHK and WOWOW. However, the police apparently had been tracking him for quite a while and claimed that he had uploaded close to a thousand NHK recordings over the investigation's span.

The process started in 2021 when CODA first launched its Cross-Border Enforcement Project, aiming to identify Nyaa's uploaders. During three years, with the help of JHA, CODA seemingly collected enough information to get the Kyoto police involved in 2024. Three "secondary uploaders" from "reach sites" were charged in 2025, likely meaning regular users participating in the torrents, who got there through link aggregator sites. Fast-forward to a couple of weeks ago, and Masakazu Ono was formally arrested with specific charges.

The most common techniques used by law enforcement agencies are creating a tracker honeypot or participating in the torrent swarm themselves in a bid to identify who's sharing files. However, Nyaa's list of trackers is small and comprises well-known, trusted servers, so together with CODA's wording, it's unlikely this was the method used. Furthermore, Japanese law generally frowns on non-targeted data monitoring, meaning that techniques like Deep Packet Inspection (DPI) and traffic volume monitoring likely weren't used, at least until such time as Ono was identified.

❌