<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:cf="https://www.futureplc.com/rss/content-flags" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="https://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:media="http://search.yahoo.com/mrss/" version="2.0">
    <channel>
                    <atom:link href="https://www.techradar.com/rss/news/computing" rel="self" type="application/rss+xml"/>
                            <title>TechRadar: latest computing news</title>
                <link>https://www.techradar.com/rss/news/computing</link>
        <description></description>
                                    <lastBuildDate>Tue, 14 Feb 2023 09:58:17 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ NYT Wordle today — answer and my hints for game #1893, Tuesday, August 25 ]]></title>
                                                                                                <dc:content><![CDATA[ <div  class="fancy-box"><div class="fancy_box-title">Looking for a different day?</div><div class="fancy_box_body"><p class="fancy-box__body-text">A new NYT Wordle puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. <strong>If you're looking for Monday's puzzle instead</strong> then <a data-analytics-id="inline-link" href="#section-yesterday-s-wordle-hints-game-1892">click here</a>.<br><br>Skip the hints and <a data-analytics-id="inline-link" href="#section-today-s-wordle-answer-game-1893"><strong>jump straight to today's column</strong>.</a></p></div></div><p>It's time for your guide to today's Wordle answer, featuring my commentary on the latest puzzle, plus a selection of hints designed to help you keep your streak going.</p><p>Don't think you need any clues for Wordle today? No problem, just skip to my daily column. But remember: failure in this game is only ever six guesses away.</p><p><em>SPOILER WARNING: Today's Wordle answer and hints are below, so don't read on if you don't want to see them.</em></p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-1-vowels"><span>Wordle hints (game #1893) - clue #1 - Vowels</span></h2><section class="article__schema-question"><h3>How many vowels does today's Wordle have?</h3><article class="article__schema-answer"><p><strong>•</strong> Wordle today has <strong>a vowel in one place</strong>*.</p></article></section><p><em>* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too). </em></p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-2-first-letter"><span>Wordle hints (game #1893) - clue #2 - first letter</span></h2><section class="article__schema-question"><h3>What letter does today's Wordle begin with?</h3><article class="article__schema-answer"><p><strong>• </strong>The first letter in today's Wordle answer is <strong>C</strong>.</p></article></section><p>C is a very common starting letter in Wordle – in fact, it's the second most common of all, behind only S.</p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-3-repeated-letters"><span>Wordle hints (game #1893) - clue #3 - repeated letters</span></h2><section class="article__schema-question"><h3>Does today's Wordle have any repeated letters?</h3><article class="article__schema-answer"><p><strong>•</strong> There are <strong>repeated letters</strong> in today's Wordle.</p></article></section><p>Repeated letters are quite common in the game, with 748 of the 2,309 Wordle answers containing one. However, it's still more likely that a Wordle <em>doesn't</em> have one.</p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-4-ending-letter"><span>Wordle hints (game #1893) - clue #4 - ending letter</span></h2><section class="article__schema-question"><h3>What letter does today's Wordle end with?</h3><article class="article__schema-answer"><p><strong>•</strong> The last letter in today's Wordle is <strong>K</strong>.</p></article></section><p>K is much more common at the end of a Wordle answer than at the start, and in fact ranks ninth overall in this regard.</p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-5-last-chance"><span>Wordle hints (game #1893) - clue #5 - last chance</span></h2><p>Still looking for more Wordle hints today? Here's an extra one for game #1893.</p><ul><li><strong>Today's Wordle answer is a button press.</strong></li></ul><p>If you just want to know today's Wordle answer now, simply scroll down – but I'd always recommend trying to solve it on your own first. We've got lots of <a href="https://www.techradar.com/news/how-to-win-wordle-every-day">Wordle tips and tricks</a> to help you, including a guide to the <a href="https://www.techradar.com/how-to/wordle-best-starting-word">best Wordle start words</a>.</p><p>If you <em>don't</em> want to know today's answer then DO NOT SCROLL ANY FURTHER BECAUSE IT IS PRINTED BELOW. So don't say you weren't warned!</p><div data-model-name="Dyson HushJet Mini Cool Fan,JBL Xtreme 5,LG OLED evo AI C6 55-inch TV (2026),DJI Lito X1,Dali Kupid,De'Longhi Dedica Duo" data-widget-type="multimodelreview" data-widget-title="TechRadar 5-star reviewed devices" class="hawk-root"></div><h2 class="article-body__section" id="section-today-s-wordle-answer-game-1893"><span>Today's Wordle answer (game #1893)</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DAx3aqxGbqLzXddM7rrvf3" name="TR-wordle-today-1893-answer" alt="NYT Wordle answer for game 1893 on a green background" src="https://cdn.mos.cms.futurecdn.net/DAx3aqxGbqLzXddM7rrvf3.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: New York Times)</span></figcaption></figure><ul><li><strong>NYT average score: 4.2</strong></li><li><strong>My score:</strong> 4</li><li><strong>WordleBot's score:</strong> 4</li><li><strong>My skill score: </strong>99</li><li><strong>My luck score: </strong>44</li><li><strong>My start word performance:</strong> SANER (304 remaining answers)</li><li><strong>WordleBot's start word performance:</strong> SLATE (50)</li><li><strong>Tomorrow's start word: SANER</strong></li></ul><p>Today's Wordle answer (game #1893) is… <strong>CLICK</strong>.</p><p>If ever you needed a clear demonstration of how much difference luck can make in Wordle, then consider my last two games. For each, I began with SANER and garnered a perfect skill score of 99/99 from WordleBot — but yesterday I scored a 2, today a 4.</p><p>Today's game is harder, sure — it has an average of 4.2, versus 3.8 for RUNNY yesterday — but it's not two whole guesses tougher. Again, there's a repeated letter, but here that's a C, which is slightly more likely to appear twice than an N is (29 appearances versus 23). </p><p>Both also had alternative words with only slightly different spellings, and this might be a bigger factor — you could have gone with FUNNY, BUNNY, SUNNY or PUNNY yesterday, FLICK, SLICK, CRICK, CHICK, CLOCK, CLUCK, CLACK or CLINK today. </p><p>In my case, I didn't have to pick between any of those options above; instead, my opening two guesses of SANER and CLOUT reduced my options to a trio of CLICK, CLIFF and CLIMB. </p><p>This left me a classic game theory dilemma: I had three equally likely choices, and could easily guarantee myself a 4 by playing a word such as FLICK — because if the F turned yellow, it would be CLIFF, if the K turned green it would be CLICK, and if neither changed color it would be CLIMB. </p><p>The other thing I could do, obviously, was to play one of the three actual possible answers. If I was right, on a 33.33% chance, I'd score a 3. If I was wrong, I'd then have a 50% chance to score a 4, and if that was wrong too I'd get a 5.</p><p>At the time, I thought that it might help if I could recall any of the three words having appeared before — but try as I might, I couldn't. Still, I checked after the game and all three had in fact been answers before: CLICK was game #134 in October 2021, CLIMB was #1020 in April 2024 and CLIFF was earlier this year, game #1680 in January. </p><p>If I'd have known that, maybe I would have gone with CLICK on the third guess; the other two seem too recent to have appeared again already. However, I chickened out and went with FLICK, and had to settle for that 4 instead.</p><iframe title="How did you do today?" description="Let's compare scores in the comments below!" minimumCommentCount="5" class="position-center" data-lazy-priority="high" data-lazy-src=""></iframe><h3 class="article-body__section" id="section-yesterday-s-wordle-hints-game-1892"><span>Yesterday's Wordle hints (game #1892)</span></h3><p>In a different time zone where it's still Monday? Don't worry — I can give you some clues for Wordle #1892, too.</p><ul><li>Wordle yesterday had<strong> a vowel in one place*</strong></li></ul><p><em>* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too). </em></p><ul><li>The first letter in yesterday's Wordle answer was <strong>R</strong>.</li></ul><p>R is a surprisingly uncommon starting letter. Despite ranking third overall in Wordle, it's merely the 11th most likely to begin an answer.</p><ul><li>There were<strong> repeated letters</strong> in yesterday's Wordle.</li></ul><p>Repeated letters are quite common in the game, with 748 of the 2,309 Wordle answers containing one. However, it's still more likely that a Wordle <em>doesn't</em> have one.</p><ul><li>The last letter in yesterday's Wordle was <strong>Y</strong>.</li></ul><p>Y is the second most common ending letter in the game, behind only E. In total, 364 Wordle answers end with a Y.</p><p>Still looking for more Wordle hints? Here's an extra one for game #1892.</p><ul><li><strong>Yesterday's Wordle answer is watery in consistency.</strong></li></ul><h2 class="article-body__section" id="section-yesterday-s-wordle-answer-game-1892"><span>Yesterday's Wordle answer (game #1892)</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="84ZxZJLjztxhTbz6kQmHcT" name="TR-wordle-today-1892-answer" alt="NYT Wordle answer for game 1892 on a green background" src="https://cdn.mos.cms.futurecdn.net/84ZxZJLjztxhTbz6kQmHcT.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: New York Times)</span></figcaption></figure><ul><li><strong>NYT average score: 3.8</strong></li><li><strong>My score:</strong> 2</li><li><strong>WordleBot's score:</strong> 3</li><li><strong>My skill score: </strong>99</li><li><strong>My luck score: </strong>86</li><li><strong>My start word performance:</strong> SANER (2 remaining answers)</li><li><strong>WordleBot's start word performance:</strong> SLATE (315)</li><li><strong>Tomorrow's start word: SANER</strong></li></ul><p>Yesterday's Wordle answer (game #1892) was… <strong>RUNNY</strong>.</p><p>Some days, Wordle can be a real slog. And then there are days like this one. I scored a 2 here, but barely had to work at all for it. In fact, the only decision I did have to make was one that I fluffed slightly — but I still managed to score that lovely 2.</p><p>This is my third in the past 30 days, together with eight 3s, 16 4s, two 5s and one 6, for an average over that period of 3.666; not terrible and in fact a <em>tiny</em> bit below my overall average of 3.678 — but not great either. Still, an unexpected 2 is always appreciated.</p><p>RUNNY's global average of 3.8 implies it's another middling Wordle, but I doubt too many other people got it on the second guess. Some popular start words were fairly successful, for instance TRAIN left only 23 options, but I imagine the majority of people got 4s, with a healthy smattering of 3s in there too.</p><p>It has that repeated N, of course, plus the -U--Y format we also saw for MURKY last week. These can be tricky to solve, so coupled with the repeat it was far from an easy one. </p><p>Well, unless you began with SANER as I did. That left only two possible answers, and I have no shame in admitting that I didn't think of one of those, RUNUP. Instead, I spotted only RUNNY, so played it swiftly without even considering whether there were alternative options. So, an undeserved but welcome — and relatively rare — success for me. Not a bad start to the week.</p><h3 class="article-body__section" id="section-wordle-answers-the-past-50"><span>Wordle answers: The past 50</span></h3><p>I've been playing Wordle every day for more than four years now and have tracked all of the previous answers so I can help you improve your game. Here are the last 50 solutions starting with yesterday's answer, or check out my <a href="https://www.techradar.com/news/past-wordle-answers">past Wordle answers</a> page for the full list.</p><ul><li>Wordle #1892, Monday 24 August: <strong>RUNNY</strong></li><li>Wordle #1891, Sunday 23 August: <strong>OLDEN</strong></li><li>Wordle #1890, Saturday 22 August: <strong>PRAWN</strong></li><li>Wordle #1889, Friday 21 August: <strong>TRACE</strong></li><li>Wordle #1888, Thursday 20 August: <strong>MURKY</strong></li><li>Wordle #1887, Wednesday 19 August: <strong>GRILL</strong></li><li>Wordle #1886, Tuesday 18 August: <strong>STRIP</strong></li><li>Wordle #1885, Monday 17 August: <strong>TRIBE</strong></li><li>Wordle #1884, Sunday 16 August: <strong>ASPIC</strong></li><li>Wordle #1883, Saturday 15 August: <strong>LOOSE</strong></li><li>Wordle #1882, Friday 14 August: <strong>GEODE</strong></li><li>Wordle #1881, Thursday 13 August: <strong>CRASH</strong></li><li>Wordle #1880, Wednesday 12 August: <strong>WIMPY</strong></li><li>Wordle #1879, Tuesday 11 August: <strong>FENCE</strong></li><li>Wordle #1878, Monday 10 August: <strong>SNIPE</strong></li><li>Wordle #1877, Sunday 9 August: <strong>CLUNK</strong></li><li>Wordle #1876, Saturday 8 August: <strong>PRIVY</strong></li><li>Wordle #1875, Friday 7 August: <strong>FEIGN</strong></li><li>Wordle #1874, Thursday 6 August: <strong>GRIPE</strong></li><li>Wordle #1873, Wednesday 5 August: <strong>POSIT</strong></li><li>Wordle #1872, Tuesday 4 August: <strong>MOTIF</strong></li><li>Wordle #1871, Monday 3 August: <strong>REPLY</strong></li><li>Wordle #1870, Sunday 2 August: <strong>PENAL</strong></li><li>Wordle #1869, Saturday 1 August: <strong>SLUSH</strong></li><li>Wordle #1868, Friday 31 July: <strong>PURSE</strong></li><li>Wordle #1867, Thursday 30 July: <strong>FLUME</strong></li><li>Wordle #1866, Wednesday 29 July: <strong>VALVE</strong></li><li>Wordle #1865, Tuesday 28 July: <strong>SONAR</strong></li><li>Wordle #1864, Monday 27 July: <strong>POSER</strong></li><li>Wordle #1863, Sunday 26 July: <strong>GRAPE</strong></li><li>Wordle #1862, Saturday 25 July: <strong>ALOHA</strong></li><li>Wordle #1861, Friday 24 July: <strong>PUTTY</strong></li><li>Wordle #1860, Thursday 23 July: <strong>ORBIT</strong></li><li>Wordle #1859, Wednesday 22 July: <strong>LORRY</strong></li><li>Wordle #1858, Tuesday 21 July: <strong>SHILL</strong></li><li>Wordle #1857, Monday 20 July: <strong>DIVER</strong></li><li>Wordle #1856, Sunday 19 July: <strong>CHURN</strong></li><li>Wordle #1855, Saturday 18 July: <strong>BOOTH</strong></li><li>Wordle #1854, Friday 17 July: <strong>LEGAL</strong></li><li>Wordle #1853, Thursday 16 July: <strong>BUTTE</strong></li><li>Wordle #1852, Wednesday 15 July: <strong>PSHAW</strong></li><li>Wordle #1851, Tuesday 14 July: <strong>STEAK</strong></li><li>Wordle #1850, Monday 13 July: <strong>STOUT</strong></li><li>Wordle #1849, Sunday 12 July: <strong>CLACK</strong></li><li>Wordle #1848, Saturday 11 July: <strong>AVIAN</strong></li><li>Wordle #1847, Friday 10 July: <strong>CANAL</strong></li><li>Wordle #1846, Thursday 9 July: <strong>AMEND</strong></li><li>Wordle #1845, Wednesday 8 July: <strong>DEMON</strong></li><li>Wordle #1844, Tuesday 7 July: <strong>SLING</strong></li><li>Wordle #1843, Monday 6 July: <strong>TODDY</strong></li></ul><h3 class="article-body__section" id="section-what-is-wordle"><span>What is Wordle?</span></h3><p>If you're on this page then you almost certainly know what Wordle is already, and indeed have probably been playing it for a while. And even if you've not been playing it, you must surely have heard of it by now, because it's the viral word game phenomenon that took the world by storm in 2022 and is still going strong in 2026.</p><p>We've got a full guide to the game in our <a href="https://www.techradar.com/news/wordle">What is Wordle</a> page, but if you just want a refresher then here are the basics.</p><section class="article__schema-question"><h3>What is Wordle?</h3><article class="article__schema-answer"><p>Wordle challenges you to guess a new five-letter word each day. You get six guesses, with each one revealing a little more information. If one of the letters in your guess is in the answer and in the right place, it turns green. If it's in the answer but in the wrong place, it turns yellow. And if it's not in the answer at all it turns gray. Simple, eh?</p><p>It's played online via the <a href="https://www.nytimes.com/games/wordle/index.html" target="_blank" rel="nofollow"><strong>Wordle website</strong></a> or the New York Times' Games app (<a href="https://apps.apple.com/us/app/new-york-times-crossword/id307569751" target="_blank" rel="nofollow">iOS</a> / <a href="https://play.google.com/store/apps/details?id=com.nytimes.crossword" target="_blank" rel="nofollow">Android</a>), and is entirely free. </p><p>Crucially, the answer is the same for everyone each day, meaning that you're competing against the rest of the world, rather than just against yourself or the game. The puzzle then resets each day at midnight in your local time, giving you a new challenge, and the chance to extend your streak.</p></article></section><section class="article__schema-question"><h3>What are the Wordle rules?</h3><p>The rules of Wordle are pretty straightforward, but with a couple of curveballs thrown in for good measure.</p><article class="article__schema-answer"><p><strong>1.</strong> Letters that are in the answer and in the right place turn green.</p><p><strong>2.</strong> Letters that are in the answer but in the wrong place turn yellow.</p><p><strong>3.</strong> Letters that are not in the answer turn gray.</p><p><strong>4a.</strong> Answers are never plural.</p><p><strong>4b.</strong> …unless they are. There have been a couple of plural words that don't end in an S or ES, including FUNGI (game #439), ATRIA (#1478) and TEETH (#1551). But S and ES plurals are definitely outlawed. </p><p><strong>5.</strong> Letters can appear more than once. So if your guess includes two of one letter, they may both turn yellow, both turn green, or one could be yellow and the other green.</p><p><strong>6.</strong> Each guess must be a valid word in Wordle's dictionary. You can't guess ABCDE, for instance.</p><p><strong>7.</strong> You do not have to include correct letters in subsequent guesses unless you play on Hard mode.</p><p><strong>8.</strong> You have six guesses to solve the Wordle.</p><p><strong>9.</strong> You must complete the daily Wordle before midnight in your timezone.</p><p><strong>10a.</strong> All answers are drawn from Wordle's list of 2,309 solutions…</p><p><strong>10b.</strong> …unless they are not. That's because the NYT has added in some of its own words which weren't in that list of 2,309 solutions. More will undoubtedly come over the next few years.</p><p><strong>10c.</strong> Plus, the NYT has now started repeating answers that have already appeared in Wordle. We have no idea how often it will do this, so you'll need to be on your guard. </p><p><strong>11.</strong> Wordle will accept a wider pool of words as guesses – some 10,000 of them. For instance, you can guess a plural such as WORDS. It definitely won't be right (see point 4a above), but Wordle will accept it as a guess.</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/news/wordle-today</link>
                                                                            <description>
                            <![CDATA[ Looking for Wordle hints? I can help. Plus get the answers to Wordle today and yesterday. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gVH9Tee5L9wGgEdPqXZmRm</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GRmNGYthK9oe5MY9rsRR7g-1280-80.jpg"/>
                                                                        <pubDate>Mon, 24 Aug 2026 23:00:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Websites &amp; Apps]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                <author><![CDATA[ marc.mclaren@futurenet.com (Marc McLaren) ]]></author>                    <dc:creator><![CDATA[ Marc McLaren ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6vwwHkvhCWrR3cyyfxqFYW.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Marc is TechRadar’s Global Editor in Chief, the latest in a long line of senior editorial roles he’s held in a career that started the week that Google launched (nice of them to mark the occasion).&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Prior to joining TR in September 2022, he was UK Editor in Chief on Tom’s Guide, where he oversaw all gaming, streaming, audio, TV, entertainment, how-to and cameras coverage. He also spent eight years at Stuff, where he was Production Editor, Managing Editor and ultimately Editor of the website. Other roles have included five years at the music magazine NME, where his duties mainly involved spoiling other people’s fun, and a couple of years editing a car website.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;He’s based in London, and has tested and written about phones, tablets, wearables, streaming boxes, smart home devices, Bluetooth speakers, headphones, games, TVs, cameras and pretty much every other type of gadget you can think of. He’s also been nominated for Content Strategist of the Year, which sounds like a made up award but actually exists, and is pretty handy with a spreadsheet.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;An avid photographer, Marc likes nothing better than taking pictures of very small things (bugs, his daughters) or very big things (distant galaxies). When he gets time, he also enjoys going to gigs, gaming (console and mobile), cycling (gravel or road), and beating Wordle (he authors the daily &lt;a href=&quot;https://www.techradar.com/news/wordle-today&quot;&gt;Wordle today&lt;/a&gt; page).&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GRmNGYthK9oe5MY9rsRR7g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A phone displaying the Wordle logo sitting on a table surrounded by paperclips, pens and notebooks]]></media:description>                                                            <media:text><![CDATA[A phone displaying the Wordle logo sitting on a table surrounded by paperclips, pens and notebooks]]></media:text>
                                <media:title type="plain"><![CDATA[A phone displaying the Wordle logo sitting on a table surrounded by paperclips, pens and notebooks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GRmNGYthK9oe5MY9rsRR7g-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <div  class="fancy-box"><div class="fancy_box-title">Looking for a different day?</div><div class="fancy_box_body"><p class="fancy-box__body-text">A new NYT Wordle puzzle appears at midnight each day for your time zone – which means that some people are always playing 'today's game' while others are playing 'yesterday's'. <strong>If you're looking for Monday's puzzle instead</strong> then <a data-analytics-id="inline-link" href="#section-yesterday-s-wordle-hints-game-1892">click here</a>.<br><br>Skip the hints and <a data-analytics-id="inline-link" href="#section-today-s-wordle-answer-game-1893"><strong>jump straight to today's column</strong>.</a></p></div></div><p>It's time for your guide to today's Wordle answer, featuring my commentary on the latest puzzle, plus a selection of hints designed to help you keep your streak going.</p><p>Don't think you need any clues for Wordle today? No problem, just skip to my daily column. But remember: failure in this game is only ever six guesses away.</p><p><em>SPOILER WARNING: Today's Wordle answer and hints are below, so don't read on if you don't want to see them.</em></p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-1-vowels"><span>Wordle hints (game #1893) - clue #1 - Vowels</span></h2><section class="article__schema-question"><h3>How many vowels does today's Wordle have?</h3><article class="article__schema-answer"><p><strong>•</strong> Wordle today has <strong>a vowel in one place</strong>*.</p></article></section><p><em>* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too). </em></p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-2-first-letter"><span>Wordle hints (game #1893) - clue #2 - first letter</span></h2><section class="article__schema-question"><h3>What letter does today's Wordle begin with?</h3><article class="article__schema-answer"><p><strong>• </strong>The first letter in today's Wordle answer is <strong>C</strong>.</p></article></section><p>C is a very common starting letter in Wordle – in fact, it's the second most common of all, behind only S.</p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-3-repeated-letters"><span>Wordle hints (game #1893) - clue #3 - repeated letters</span></h2><section class="article__schema-question"><h3>Does today's Wordle have any repeated letters?</h3><article class="article__schema-answer"><p><strong>•</strong> There are <strong>repeated letters</strong> in today's Wordle.</p></article></section><p>Repeated letters are quite common in the game, with 748 of the 2,309 Wordle answers containing one. However, it's still more likely that a Wordle <em>doesn't</em> have one.</p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-4-ending-letter"><span>Wordle hints (game #1893) - clue #4 - ending letter</span></h2><section class="article__schema-question"><h3>What letter does today's Wordle end with?</h3><article class="article__schema-answer"><p><strong>•</strong> The last letter in today's Wordle is <strong>K</strong>.</p></article></section><p>K is much more common at the end of a Wordle answer than at the start, and in fact ranks ninth overall in this regard.</p><h2 class="article-body__section" id="section-wordle-hints-game-1893-clue-5-last-chance"><span>Wordle hints (game #1893) - clue #5 - last chance</span></h2><p>Still looking for more Wordle hints today? Here's an extra one for game #1893.</p><ul><li><strong>Today's Wordle answer is a button press.</strong></li></ul><p>If you just want to know today's Wordle answer now, simply scroll down – but I'd always recommend trying to solve it on your own first. We've got lots of <a href="https://www.techradar.com/news/how-to-win-wordle-every-day">Wordle tips and tricks</a> to help you, including a guide to the <a href="https://www.techradar.com/how-to/wordle-best-starting-word">best Wordle start words</a>.</p><p>If you <em>don't</em> want to know today's answer then DO NOT SCROLL ANY FURTHER BECAUSE IT IS PRINTED BELOW. So don't say you weren't warned!</p><div data-model-name="Dyson HushJet Mini Cool Fan,JBL Xtreme 5,LG OLED evo AI C6 55-inch TV (2026),DJI Lito X1,Dali Kupid,De'Longhi Dedica Duo" data-widget-type="multimodelreview" data-widget-title="TechRadar 5-star reviewed devices" class="hawk-root"></div><h2 class="article-body__section" id="section-today-s-wordle-answer-game-1893"><span>Today's Wordle answer (game #1893)</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DAx3aqxGbqLzXddM7rrvf3" name="TR-wordle-today-1893-answer" alt="NYT Wordle answer for game 1893 on a green background" src="https://cdn.mos.cms.futurecdn.net/DAx3aqxGbqLzXddM7rrvf3.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: New York Times)</span></figcaption></figure><ul><li><strong>NYT average score: 4.2</strong></li><li><strong>My score:</strong> 4</li><li><strong>WordleBot's score:</strong> 4</li><li><strong>My skill score: </strong>99</li><li><strong>My luck score: </strong>44</li><li><strong>My start word performance:</strong> SANER (304 remaining answers)</li><li><strong>WordleBot's start word performance:</strong> SLATE (50)</li><li><strong>Tomorrow's start word: SANER</strong></li></ul><p>Today's Wordle answer (game #1893) is… <strong>CLICK</strong>.</p><p>If ever you needed a clear demonstration of how much difference luck can make in Wordle, then consider my last two games. For each, I began with SANER and garnered a perfect skill score of 99/99 from WordleBot — but yesterday I scored a 2, today a 4.</p><p>Today's game is harder, sure — it has an average of 4.2, versus 3.8 for RUNNY yesterday — but it's not two whole guesses tougher. Again, there's a repeated letter, but here that's a C, which is slightly more likely to appear twice than an N is (29 appearances versus 23). </p><p>Both also had alternative words with only slightly different spellings, and this might be a bigger factor — you could have gone with FUNNY, BUNNY, SUNNY or PUNNY yesterday, FLICK, SLICK, CRICK, CHICK, CLOCK, CLUCK, CLACK or CLINK today. </p><p>In my case, I didn't have to pick between any of those options above; instead, my opening two guesses of SANER and CLOUT reduced my options to a trio of CLICK, CLIFF and CLIMB. </p><p>This left me a classic game theory dilemma: I had three equally likely choices, and could easily guarantee myself a 4 by playing a word such as FLICK — because if the F turned yellow, it would be CLIFF, if the K turned green it would be CLICK, and if neither changed color it would be CLIMB. </p><p>The other thing I could do, obviously, was to play one of the three actual possible answers. If I was right, on a 33.33% chance, I'd score a 3. If I was wrong, I'd then have a 50% chance to score a 4, and if that was wrong too I'd get a 5.</p><p>At the time, I thought that it might help if I could recall any of the three words having appeared before — but try as I might, I couldn't. Still, I checked after the game and all three had in fact been answers before: CLICK was game #134 in October 2021, CLIMB was #1020 in April 2024 and CLIFF was earlier this year, game #1680 in January. </p><p>If I'd have known that, maybe I would have gone with CLICK on the third guess; the other two seem too recent to have appeared again already. However, I chickened out and went with FLICK, and had to settle for that 4 instead.</p><iframe title="How did you do today?" description="Let's compare scores in the comments below!" minimumCommentCount="5" class="position-center" data-lazy-priority="high" data-lazy-src=""></iframe><h3 class="article-body__section" id="section-yesterday-s-wordle-hints-game-1892"><span>Yesterday's Wordle hints (game #1892)</span></h3><p>In a different time zone where it's still Monday? Don't worry — I can give you some clues for Wordle #1892, too.</p><ul><li>Wordle yesterday had<strong> a vowel in one place*</strong></li></ul><p><em>* Note that by vowel we mean the five standard vowels (A, E, I, O, U), not Y (which is sometimes counted as a vowel too). </em></p><ul><li>The first letter in yesterday's Wordle answer was <strong>R</strong>.</li></ul><p>R is a surprisingly uncommon starting letter. Despite ranking third overall in Wordle, it's merely the 11th most likely to begin an answer.</p><ul><li>There were<strong> repeated letters</strong> in yesterday's Wordle.</li></ul><p>Repeated letters are quite common in the game, with 748 of the 2,309 Wordle answers containing one. However, it's still more likely that a Wordle <em>doesn't</em> have one.</p><ul><li>The last letter in yesterday's Wordle was <strong>Y</strong>.</li></ul><p>Y is the second most common ending letter in the game, behind only E. In total, 364 Wordle answers end with a Y.</p><p>Still looking for more Wordle hints? Here's an extra one for game #1892.</p><ul><li><strong>Yesterday's Wordle answer is watery in consistency.</strong></li></ul><h2 class="article-body__section" id="section-yesterday-s-wordle-answer-game-1892"><span>Yesterday's Wordle answer (game #1892)</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="84ZxZJLjztxhTbz6kQmHcT" name="TR-wordle-today-1892-answer" alt="NYT Wordle answer for game 1892 on a green background" src="https://cdn.mos.cms.futurecdn.net/84ZxZJLjztxhTbz6kQmHcT.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: New York Times)</span></figcaption></figure><ul><li><strong>NYT average score: 3.8</strong></li><li><strong>My score:</strong> 2</li><li><strong>WordleBot's score:</strong> 3</li><li><strong>My skill score: </strong>99</li><li><strong>My luck score: </strong>86</li><li><strong>My start word performance:</strong> SANER (2 remaining answers)</li><li><strong>WordleBot's start word performance:</strong> SLATE (315)</li><li><strong>Tomorrow's start word: SANER</strong></li></ul><p>Yesterday's Wordle answer (game #1892) was… <strong>RUNNY</strong>.</p><p>Some days, Wordle can be a real slog. And then there are days like this one. I scored a 2 here, but barely had to work at all for it. In fact, the only decision I did have to make was one that I fluffed slightly — but I still managed to score that lovely 2.</p><p>This is my third in the past 30 days, together with eight 3s, 16 4s, two 5s and one 6, for an average over that period of 3.666; not terrible and in fact a <em>tiny</em> bit below my overall average of 3.678 — but not great either. Still, an unexpected 2 is always appreciated.</p><p>RUNNY's global average of 3.8 implies it's another middling Wordle, but I doubt too many other people got it on the second guess. Some popular start words were fairly successful, for instance TRAIN left only 23 options, but I imagine the majority of people got 4s, with a healthy smattering of 3s in there too.</p><p>It has that repeated N, of course, plus the -U--Y format we also saw for MURKY last week. These can be tricky to solve, so coupled with the repeat it was far from an easy one. </p><p>Well, unless you began with SANER as I did. That left only two possible answers, and I have no shame in admitting that I didn't think of one of those, RUNUP. Instead, I spotted only RUNNY, so played it swiftly without even considering whether there were alternative options. So, an undeserved but welcome — and relatively rare — success for me. Not a bad start to the week.</p><h3 class="article-body__section" id="section-wordle-answers-the-past-50"><span>Wordle answers: The past 50</span></h3><p>I've been playing Wordle every day for more than four years now and have tracked all of the previous answers so I can help you improve your game. Here are the last 50 solutions starting with yesterday's answer, or check out my <a href="https://www.techradar.com/news/past-wordle-answers">past Wordle answers</a> page for the full list.</p><ul><li>Wordle #1892, Monday 24 August: <strong>RUNNY</strong></li><li>Wordle #1891, Sunday 23 August: <strong>OLDEN</strong></li><li>Wordle #1890, Saturday 22 August: <strong>PRAWN</strong></li><li>Wordle #1889, Friday 21 August: <strong>TRACE</strong></li><li>Wordle #1888, Thursday 20 August: <strong>MURKY</strong></li><li>Wordle #1887, Wednesday 19 August: <strong>GRILL</strong></li><li>Wordle #1886, Tuesday 18 August: <strong>STRIP</strong></li><li>Wordle #1885, Monday 17 August: <strong>TRIBE</strong></li><li>Wordle #1884, Sunday 16 August: <strong>ASPIC</strong></li><li>Wordle #1883, Saturday 15 August: <strong>LOOSE</strong></li><li>Wordle #1882, Friday 14 August: <strong>GEODE</strong></li><li>Wordle #1881, Thursday 13 August: <strong>CRASH</strong></li><li>Wordle #1880, Wednesday 12 August: <strong>WIMPY</strong></li><li>Wordle #1879, Tuesday 11 August: <strong>FENCE</strong></li><li>Wordle #1878, Monday 10 August: <strong>SNIPE</strong></li><li>Wordle #1877, Sunday 9 August: <strong>CLUNK</strong></li><li>Wordle #1876, Saturday 8 August: <strong>PRIVY</strong></li><li>Wordle #1875, Friday 7 August: <strong>FEIGN</strong></li><li>Wordle #1874, Thursday 6 August: <strong>GRIPE</strong></li><li>Wordle #1873, Wednesday 5 August: <strong>POSIT</strong></li><li>Wordle #1872, Tuesday 4 August: <strong>MOTIF</strong></li><li>Wordle #1871, Monday 3 August: <strong>REPLY</strong></li><li>Wordle #1870, Sunday 2 August: <strong>PENAL</strong></li><li>Wordle #1869, Saturday 1 August: <strong>SLUSH</strong></li><li>Wordle #1868, Friday 31 July: <strong>PURSE</strong></li><li>Wordle #1867, Thursday 30 July: <strong>FLUME</strong></li><li>Wordle #1866, Wednesday 29 July: <strong>VALVE</strong></li><li>Wordle #1865, Tuesday 28 July: <strong>SONAR</strong></li><li>Wordle #1864, Monday 27 July: <strong>POSER</strong></li><li>Wordle #1863, Sunday 26 July: <strong>GRAPE</strong></li><li>Wordle #1862, Saturday 25 July: <strong>ALOHA</strong></li><li>Wordle #1861, Friday 24 July: <strong>PUTTY</strong></li><li>Wordle #1860, Thursday 23 July: <strong>ORBIT</strong></li><li>Wordle #1859, Wednesday 22 July: <strong>LORRY</strong></li><li>Wordle #1858, Tuesday 21 July: <strong>SHILL</strong></li><li>Wordle #1857, Monday 20 July: <strong>DIVER</strong></li><li>Wordle #1856, Sunday 19 July: <strong>CHURN</strong></li><li>Wordle #1855, Saturday 18 July: <strong>BOOTH</strong></li><li>Wordle #1854, Friday 17 July: <strong>LEGAL</strong></li><li>Wordle #1853, Thursday 16 July: <strong>BUTTE</strong></li><li>Wordle #1852, Wednesday 15 July: <strong>PSHAW</strong></li><li>Wordle #1851, Tuesday 14 July: <strong>STEAK</strong></li><li>Wordle #1850, Monday 13 July: <strong>STOUT</strong></li><li>Wordle #1849, Sunday 12 July: <strong>CLACK</strong></li><li>Wordle #1848, Saturday 11 July: <strong>AVIAN</strong></li><li>Wordle #1847, Friday 10 July: <strong>CANAL</strong></li><li>Wordle #1846, Thursday 9 July: <strong>AMEND</strong></li><li>Wordle #1845, Wednesday 8 July: <strong>DEMON</strong></li><li>Wordle #1844, Tuesday 7 July: <strong>SLING</strong></li><li>Wordle #1843, Monday 6 July: <strong>TODDY</strong></li></ul><h3 class="article-body__section" id="section-what-is-wordle"><span>What is Wordle?</span></h3><p>If you're on this page then you almost certainly know what Wordle is already, and indeed have probably been playing it for a while. And even if you've not been playing it, you must surely have heard of it by now, because it's the viral word game phenomenon that took the world by storm in 2022 and is still going strong in 2026.</p><p>We've got a full guide to the game in our <a href="https://www.techradar.com/news/wordle">What is Wordle</a> page, but if you just want a refresher then here are the basics.</p><section class="article__schema-question"><h3>What is Wordle?</h3><article class="article__schema-answer"><p>Wordle challenges you to guess a new five-letter word each day. You get six guesses, with each one revealing a little more information. If one of the letters in your guess is in the answer and in the right place, it turns green. If it's in the answer but in the wrong place, it turns yellow. And if it's not in the answer at all it turns gray. Simple, eh?</p><p>It's played online via the <a href="https://www.nytimes.com/games/wordle/index.html" target="_blank" rel="nofollow"><strong>Wordle website</strong></a> or the New York Times' Games app (<a href="https://apps.apple.com/us/app/new-york-times-crossword/id307569751" target="_blank" rel="nofollow">iOS</a> / <a href="https://play.google.com/store/apps/details?id=com.nytimes.crossword" target="_blank" rel="nofollow">Android</a>), and is entirely free. </p><p>Crucially, the answer is the same for everyone each day, meaning that you're competing against the rest of the world, rather than just against yourself or the game. The puzzle then resets each day at midnight in your local time, giving you a new challenge, and the chance to extend your streak.</p></article></section><section class="article__schema-question"><h3>What are the Wordle rules?</h3><p>The rules of Wordle are pretty straightforward, but with a couple of curveballs thrown in for good measure.</p><article class="article__schema-answer"><p><strong>1.</strong> Letters that are in the answer and in the right place turn green.</p><p><strong>2.</strong> Letters that are in the answer but in the wrong place turn yellow.</p><p><strong>3.</strong> Letters that are not in the answer turn gray.</p><p><strong>4a.</strong> Answers are never plural.</p><p><strong>4b.</strong> …unless they are. There have been a couple of plural words that don't end in an S or ES, including FUNGI (game #439), ATRIA (#1478) and TEETH (#1551). But S and ES plurals are definitely outlawed. </p><p><strong>5.</strong> Letters can appear more than once. So if your guess includes two of one letter, they may both turn yellow, both turn green, or one could be yellow and the other green.</p><p><strong>6.</strong> Each guess must be a valid word in Wordle's dictionary. You can't guess ABCDE, for instance.</p><p><strong>7.</strong> You do not have to include correct letters in subsequent guesses unless you play on Hard mode.</p><p><strong>8.</strong> You have six guesses to solve the Wordle.</p><p><strong>9.</strong> You must complete the daily Wordle before midnight in your timezone.</p><p><strong>10a.</strong> All answers are drawn from Wordle's list of 2,309 solutions…</p><p><strong>10b.</strong> …unless they are not. That's because the NYT has added in some of its own words which weren't in that list of 2,309 solutions. More will undoubtedly come over the next few years.</p><p><strong>10c.</strong> Plus, the NYT has now started repeating answers that have already appeared in Wordle. We have no idea how often it will do this, so you'll need to be on your guard. </p><p><strong>11.</strong> Wordle will accept a wider pool of words as guesses – some 10,000 of them. For instance, you can guess a plural such as WORDS. It definitely won't be right (see point 4a above), but Wordle will accept it as a guess.</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hackers exploited trusted software updates to deliver malware directly into car head units</strong></li><li><strong>Kaspersky says this is the first campaign tailored specifically for vehicle head units</strong></li><li><strong>The malware can run silently without showing drivers any visible interface</strong></li></ul><p>Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.</p><p>A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.</p><p>According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.</p><h2 id="compromised-update-channels-deliver-malware-straight-into-vehicles">Compromised update channels deliver malware straight into vehicles</h2><p>Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.</p><p>The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.</p><p>Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.</p><p>Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.</p><p>Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.</p><p>The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.</p><p>Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.</p><p>The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.</p><p>BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.</p><p>Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.</p><p>According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.</p><h2 id="head-units-present-a-growing-and-largely-unprotected-attack-surface">Head units present a growing and largely unprotected attack surface</h2><p>Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.</p><p>Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.</p><p>This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.</p><p>Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.</p><p>However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.</p><p>That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.</p><p>The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/even-connected-car-head-units-are-being-targeted-by-hackers-now-experts-warn-in-car-systems-are-at-risk-of-being-hijacked-into-a-botnet</link>
                                                                            <description>
                            <![CDATA[ Kaspersky discovers Android malware targeting car head units through compromised updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m2NVLV93FhaPCF5tsL4x7Z</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg"/>
                                                                        <pubDate>Mon, 24 Aug 2026 18:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg">
                                                            <media:credit><![CDATA[Spotify]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spotify Car Thing]]></media:description>                                                            <media:text><![CDATA[Spotify Car Thing]]></media:text>
                                <media:title type="plain"><![CDATA[Spotify Car Thing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hackers exploited trusted software updates to deliver malware directly into car head units</strong></li><li><strong>Kaspersky says this is the first campaign tailored specifically for vehicle head units</strong></li><li><strong>The malware can run silently without showing drivers any visible interface</strong></li></ul><p>Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.</p><p>A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.</p><p>According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.</p><h2 id="compromised-update-channels-deliver-malware-straight-into-vehicles">Compromised update channels deliver malware straight into vehicles</h2><p>Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.</p><p>The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.</p><p>Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.</p><p>Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.</p><p>Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.</p><p>The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.</p><p>Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.</p><p>The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.</p><p>BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.</p><p>Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.</p><p>According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.</p><h2 id="head-units-present-a-growing-and-largely-unprotected-attack-surface">Head units present a growing and largely unprotected attack surface</h2><p>Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.</p><p>Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.</p><p>This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.</p><p>Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.</p><p>However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.</p><p>That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.</p><p>The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New malware targets Microsoft Teams users by posing as your company's IT helpdesk ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages</strong></li><li><strong>Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control</strong></li><li><strong>Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering</strong></li></ul><p>For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.</p><p>According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.</p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.</p><h2 id="this-is-not-sickkids-39-first-attack">This is not SickKids' first attack</h2><p>BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.</p><p>The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device. </p><p>The full list of Indicators of Compromise (IoC) can be found on <a href="https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/" target="_blank" rel="nofollow">this link</a>. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.</p><p>Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-malware-targets-microsoft-teams-users-by-posing-as-your-companys-it-helpdesk</link>
                                                                            <description>
                            <![CDATA[ Victims are being told to install a fake cleaner software which is nothing more than a backdoor framework. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gDENeCKMs9WruAKu7UsWj</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg"/>
                                                                        <pubDate>Mon, 24 Aug 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages</strong></li><li><strong>Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control</strong></li><li><strong>Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering</strong></li></ul><p>For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.</p><p>According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.</p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.</p><h2 id="this-is-not-sickkids-39-first-attack">This is not SickKids' first attack</h2><p>BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.</p><p>The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device. </p><p>The full list of Indicators of Compromise (IoC) can be found on <a href="https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/" target="_blank" rel="nofollow">this link</a>. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.</p><p>Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft's latest move to pay people to use Edge looks desperate — and an odd new Bing app is worrying too ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft has concocted another scheme to pay people to use Edge</strong></li><li><strong>It's a referral link that gives you reward points for every friend invited</strong></li><li><strong>A strange Bing app has also been spotted that switches some browsers to have Microsoft's search engine by default, and it's proving controversial</strong></li></ul><p><a href="https://www.techradar.com/computing/edge/fed-up-with-prompts-to-use-edge-windows-11-users-in-europe-wont-get-them-anymore-but-sadly-everyone-else-will">Microsoft is once again pushing Edge</a> — and <a href="https://www.techradar.com/computing/windows/microsoft-sinks-to-new-lows-with-bing-wallpaper-feature-in-windows-11-thatll-either-confuse-or-annoy-you">also Bing</a> — in promotional efforts that may elicit more than a few groans from Windows 11 users.</p><p>We're used to this kind of thing in Windows 11, mind, and I'll come back to Bing later, as this is an apparent plan that hasn't kicked into action yet. However, the latest Edge scheme is active, and as <a href="https://www.windowslatest.com/2026/08/23/microsoft-now-pays-you-in-microsoft-rewards-points-if-you-invite-your-friends-to-use-edge-browser-on-mobile/" target="_blank">Windows Latest reports</a>, it's offering financial incentives to get people to use Microsoft's web browser.</p><p>This is happening on the mobile version of <a href="https://www.techradar.com/reviews/pc-mac/software/utilities/other-software/microsoft-edge-1292485/review">Edge</a> where users are being offered a referral scheme. If you can get a friend to switch to Edge via a referral link, you'll receive 500 Microsoft Rewards points (with the ability to accumulate up to 7,500 points per month if you're feeling ambitious).</p><p>The person you invite can't be an existing Edge user (they must never have installed the mobile browser), and they will also earn 500 points for signing up. However, your invited friend must sign into Edge and use the browser for at least two days (web searching on Bing, too) within the first two weeks of being referred.</p><p>Windows Latest observes that there's no way to access this referral scheme should you be interested — you'll just have to keep using Edge mobile and wait until it's presented to you.</p><p>As well as the promotion of Bing in that offer (in terms of the requirement to use the search engine for a couple of days), there's a more brazen initiative to push Bing usage that <a href="https://www.windowslatest.com/2026/08/22/microsoft-built-a-dedicated-app-that-forces-bing-everywhere-on-windows-11-including-chrome-firefox-and-brave/" target="_blank">Windows Latest also spotted</a>.</p><p>This was highlighted in a <a href="https://x.com/XenoPanther/status/2090755450320916950" target="_blank">post on X</a> by leaker Xeno who discovered a small app called 'Microsoft Recommended Search' which has one sole and simple purpose: to change your default search engine to Bing.</p><p>When run, it offers up a simple slider to set Bing as the default engine, and if you allow this, the app switches to Microsoft's search engine across some of your installed browsers. That means Chrome and Firefox, and also apparently Brave and possibly others, via extensions which are added to these browsers. Apparently the experience is rounded off by sending the user to the Microsoft Rewards page.</p><p>Where is this app exactly? Thankfully it isn't something that's being deployed to Windows 11, and Windows Latest notes that it's just a standalone application hosted on Microsoft's official download servers (download.microsoft.com) — for the time being, anyway.</p><h2 id="analysis-an-ominous-sign">Analysis: an ominous sign?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tSejjmrgK46MgdhWqD5miC" name="2090349865.jpg" alt="Google Chrome icon is seen on an iPhone next to Edge and other web browser apps" src="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tada Images / Shutterstock)</span></figcaption></figure><p>Does this mean that the Bing switching application is something Microsoft intends to pipe out to Windows 11 at some point? That's the obvious worry, because you've got to wonder why Microsoft built this mini app in the first place. I'm guessing that this is something for use in testing, though, and not active deployment — although it could come to Windows 11 in theory (or something similar could).</p><p>I really hope not, and given that Microsoft is doing its level best to get everyone to <a href="https://www.techradar.com/computing/how-i-think-microsofts-campaign-to-fix-windows-11-is-going-so-far-the-verdict-now-were-3-months-in">appreciate its desktop OS this year</a>, it's obvious that anything along these lines would be highly counterproductive to that goal.</p><p>However, there's plenty of <a href="https://www.reddit.com/r/pcmasterrace/comments/1vuw005/microsoft_built_a_dedicated_app_that_forces_bing/" target="_blank">suspicion on Reddit</a> about Microsoft's intentions here, and chatter from those who've already switched to Linux, pointing out that this kind of thing is exactly why they migrated. As one <a href="https://www.reddit.com/r/pcmasterrace/comments/1vuw005/comment/p54h8gn/" target="_blank">Redditor put it</a>: "Every day is a Microslop news day, I'm so glad I quit Windows a while ago." There are quite a few others in that thread who see this as another reason to defect to Linux, despite the fact that nothing has happened with this Bing app yet.</p><p>As for the referral scheme to promote Edge, this isn't the first time Microsoft has effectively offered lowkey bribes to get people to switch to the browser. Indeed, the likes of million-dollar prizes have been thrown around recently (and the <a href="https://www.techradar.com/computing/search-engines/microsoft-is-so-desperate-for-people-to-drop-google-for-bing-its-offering-a-usd1-million-reward">same has been true of Bing in the past</a>). Not that there's anything wrong with this idea in principle, except it does show that Microsoft's getting rather desperate in its efforts to recruit folks to use Edge and Bing.</p><p>The most baffling part of all with Edge is that it's a <a href="https://www.techradar.com/best/browser">good web browser</a> which stands on its own merits, and I think it would benefit from <em>not</em> being promoted so much (as that activity only makes people suspicious, or determined not to use Edge as a reaction to being constantly cajoled about it).</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/edge/microsofts-latest-move-to-pay-people-to-use-edge-looks-desperate-and-an-odd-new-bing-app-is-worrying-too</link>
                                                                            <description>
                            <![CDATA[ An app has been spotted that makes Bing your default search, and some users see it as another reason to leave Windows 11. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4UyaUahEnyUDQFPtJArCkN</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T5tUn7q7ko5tgMxUjPnP8N-1280-80.jpeg"/>
                                                                        <pubDate>Mon, 24 Aug 2026 14:30:24 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Aug 2026 15:37:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Edge]]></category>
                                                    <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Browsers]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darren Allan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T5tUn7q7ko5tgMxUjPnP8N-1280-80.jpeg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Young woman using laptop, looking annoyed]]></media:description>                                                            <media:text><![CDATA[Young woman using laptop, looking annoyed]]></media:text>
                                <media:title type="plain"><![CDATA[Young woman using laptop, looking annoyed]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T5tUn7q7ko5tgMxUjPnP8N-1280-80.jpeg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft has concocted another scheme to pay people to use Edge</strong></li><li><strong>It's a referral link that gives you reward points for every friend invited</strong></li><li><strong>A strange Bing app has also been spotted that switches some browsers to have Microsoft's search engine by default, and it's proving controversial</strong></li></ul><p><a href="https://www.techradar.com/computing/edge/fed-up-with-prompts-to-use-edge-windows-11-users-in-europe-wont-get-them-anymore-but-sadly-everyone-else-will">Microsoft is once again pushing Edge</a> — and <a href="https://www.techradar.com/computing/windows/microsoft-sinks-to-new-lows-with-bing-wallpaper-feature-in-windows-11-thatll-either-confuse-or-annoy-you">also Bing</a> — in promotional efforts that may elicit more than a few groans from Windows 11 users.</p><p>We're used to this kind of thing in Windows 11, mind, and I'll come back to Bing later, as this is an apparent plan that hasn't kicked into action yet. However, the latest Edge scheme is active, and as <a href="https://www.windowslatest.com/2026/08/23/microsoft-now-pays-you-in-microsoft-rewards-points-if-you-invite-your-friends-to-use-edge-browser-on-mobile/" target="_blank">Windows Latest reports</a>, it's offering financial incentives to get people to use Microsoft's web browser.</p><p>This is happening on the mobile version of <a href="https://www.techradar.com/reviews/pc-mac/software/utilities/other-software/microsoft-edge-1292485/review">Edge</a> where users are being offered a referral scheme. If you can get a friend to switch to Edge via a referral link, you'll receive 500 Microsoft Rewards points (with the ability to accumulate up to 7,500 points per month if you're feeling ambitious).</p><p>The person you invite can't be an existing Edge user (they must never have installed the mobile browser), and they will also earn 500 points for signing up. However, your invited friend must sign into Edge and use the browser for at least two days (web searching on Bing, too) within the first two weeks of being referred.</p><p>Windows Latest observes that there's no way to access this referral scheme should you be interested — you'll just have to keep using Edge mobile and wait until it's presented to you.</p><p>As well as the promotion of Bing in that offer (in terms of the requirement to use the search engine for a couple of days), there's a more brazen initiative to push Bing usage that <a href="https://www.windowslatest.com/2026/08/22/microsoft-built-a-dedicated-app-that-forces-bing-everywhere-on-windows-11-including-chrome-firefox-and-brave/" target="_blank">Windows Latest also spotted</a>.</p><p>This was highlighted in a <a href="https://x.com/XenoPanther/status/2090755450320916950" target="_blank">post on X</a> by leaker Xeno who discovered a small app called 'Microsoft Recommended Search' which has one sole and simple purpose: to change your default search engine to Bing.</p><p>When run, it offers up a simple slider to set Bing as the default engine, and if you allow this, the app switches to Microsoft's search engine across some of your installed browsers. That means Chrome and Firefox, and also apparently Brave and possibly others, via extensions which are added to these browsers. Apparently the experience is rounded off by sending the user to the Microsoft Rewards page.</p><p>Where is this app exactly? Thankfully it isn't something that's being deployed to Windows 11, and Windows Latest notes that it's just a standalone application hosted on Microsoft's official download servers (download.microsoft.com) — for the time being, anyway.</p><h2 id="analysis-an-ominous-sign">Analysis: an ominous sign?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tSejjmrgK46MgdhWqD5miC" name="2090349865.jpg" alt="Google Chrome icon is seen on an iPhone next to Edge and other web browser apps" src="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tada Images / Shutterstock)</span></figcaption></figure><p>Does this mean that the Bing switching application is something Microsoft intends to pipe out to Windows 11 at some point? That's the obvious worry, because you've got to wonder why Microsoft built this mini app in the first place. I'm guessing that this is something for use in testing, though, and not active deployment — although it could come to Windows 11 in theory (or something similar could).</p><p>I really hope not, and given that Microsoft is doing its level best to get everyone to <a href="https://www.techradar.com/computing/how-i-think-microsofts-campaign-to-fix-windows-11-is-going-so-far-the-verdict-now-were-3-months-in">appreciate its desktop OS this year</a>, it's obvious that anything along these lines would be highly counterproductive to that goal.</p><p>However, there's plenty of <a href="https://www.reddit.com/r/pcmasterrace/comments/1vuw005/microsoft_built_a_dedicated_app_that_forces_bing/" target="_blank">suspicion on Reddit</a> about Microsoft's intentions here, and chatter from those who've already switched to Linux, pointing out that this kind of thing is exactly why they migrated. As one <a href="https://www.reddit.com/r/pcmasterrace/comments/1vuw005/comment/p54h8gn/" target="_blank">Redditor put it</a>: "Every day is a Microslop news day, I'm so glad I quit Windows a while ago." There are quite a few others in that thread who see this as another reason to defect to Linux, despite the fact that nothing has happened with this Bing app yet.</p><p>As for the referral scheme to promote Edge, this isn't the first time Microsoft has effectively offered lowkey bribes to get people to switch to the browser. Indeed, the likes of million-dollar prizes have been thrown around recently (and the <a href="https://www.techradar.com/computing/search-engines/microsoft-is-so-desperate-for-people-to-drop-google-for-bing-its-offering-a-usd1-million-reward">same has been true of Bing in the past</a>). Not that there's anything wrong with this idea in principle, except it does show that Microsoft's getting rather desperate in its efforts to recruit folks to use Edge and Bing.</p><p>The most baffling part of all with Edge is that it's a <a href="https://www.techradar.com/best/browser">good web browser</a> which stands on its own merits, and I think it would benefit from <em>not</em> being promoted so much (as that activity only makes people suspicious, or determined not to use Edge as a reaction to being constantly cajoled about it).</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Canadian SickKids hospital hit again by cyberattacks, more data stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>SickKids hospital in Canada hit by third‑party software vulnerability, exposing employee data</strong></li><li><strong>Clinical systems and patient records unaffected; patient care continued without disruption</strong></li><li><strong>Affected staff and applicants offered 24 months of free credit monitoring and identity protection</strong></li></ul><p>The Hospital for Sick Children, a major pediatric hospital in Canada, suffered a cyberattack that affected parts of its website, and resulted in the loss of some employee personal information.</p><p>In an announcement published on its website, the organization (also known as SickKids) said the unnamed attackers abused a “vulnerability in a third-party software application used by SickKids and other organizations.” The announcement did not say exactly which app was used in the attack, or what the vulnerability was, but stressed that clinical systems and patient information were not affected.</p><p>“Patient care has continued as usual”, it added.</p><h2 id="this-is-not-sickkids-39-first-attack-2">This is not SickKids' first attack</h2><p>After launching an investigation, SickKids learned that personal information of some former and current employees working at SickKids, Boomerang, and SickKids Foundation, as well as SickKids job applications, was exposed. It did not detail the nature of the exposed information, or how many people are affected.</p><p>Whatever that number is, those people have been offered 24 months of complimentary credit monitoring and identity protection services, for free.</p><p> “We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us,” the company concluded. Ironically, SickKids was also committed in late 2022 and early 2023, when it was struck by LockBit and had its systems locked down by the ransomware threat actor.</p><p>While, in that incident, LockBit apologized, gave the decryptor away for free, excommunicated the affiliate responsible, and did not mention any stolen data, by late 2022 double extortion attacks were standard practice, meaning data was likely exfiltrated then, as well. </p><p>At the time, LockBit was one of the most active and most dangerous ransomware operators. In early 2024, its operations were severely disrupted through Operation Cronos, but it seems the group is making a comeback. There are reports from late 2025 of <a href="https://www.techradar.com/pro/security/lockbit-malware-is-back-and-nastier-than-ever-experts-claim" target="_blank">LockBit 5.0 claims</a>, including a <a href="https://www.escudodigital.com/en/cybersecurity/lockbit-50-targets-us-bank-one-of-the-largest-banks-in-the-united-states.html" target="_blank" rel="nofollow">purported attack on U.S Bank</a>, but the news is yet to be confirmed. </p><p><em>Via </em><a href="https://therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/canadian-sickkids-hospital-hit-again-by-cyberattacks-more-data-stolen</link>
                                                                            <description>
                            <![CDATA[ Patient care has continued as usual following cyberattack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RoPQxVBr4RHbTeSwbCJytQ</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg"/>
                                                                        <pubDate>Mon, 24 Aug 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg">
                                                            <media:credit><![CDATA[Rawpixel / Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[healthcare]]></media:description>                                                            <media:text><![CDATA[healthcare]]></media:text>
                                <media:title type="plain"><![CDATA[healthcare]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>SickKids hospital in Canada hit by third‑party software vulnerability, exposing employee data</strong></li><li><strong>Clinical systems and patient records unaffected; patient care continued without disruption</strong></li><li><strong>Affected staff and applicants offered 24 months of free credit monitoring and identity protection</strong></li></ul><p>The Hospital for Sick Children, a major pediatric hospital in Canada, suffered a cyberattack that affected parts of its website, and resulted in the loss of some employee personal information.</p><p>In an announcement published on its website, the organization (also known as SickKids) said the unnamed attackers abused a “vulnerability in a third-party software application used by SickKids and other organizations.” The announcement did not say exactly which app was used in the attack, or what the vulnerability was, but stressed that clinical systems and patient information were not affected.</p><p>“Patient care has continued as usual”, it added.</p><h2 id="this-is-not-sickkids-39-first-attack-2">This is not SickKids' first attack</h2><p>After launching an investigation, SickKids learned that personal information of some former and current employees working at SickKids, Boomerang, and SickKids Foundation, as well as SickKids job applications, was exposed. It did not detail the nature of the exposed information, or how many people are affected.</p><p>Whatever that number is, those people have been offered 24 months of complimentary credit monitoring and identity protection services, for free.</p><p> “We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us,” the company concluded. Ironically, SickKids was also committed in late 2022 and early 2023, when it was struck by LockBit and had its systems locked down by the ransomware threat actor.</p><p>While, in that incident, LockBit apologized, gave the decryptor away for free, excommunicated the affiliate responsible, and did not mention any stolen data, by late 2022 double extortion attacks were standard practice, meaning data was likely exfiltrated then, as well. </p><p>At the time, LockBit was one of the most active and most dangerous ransomware operators. In early 2024, its operations were severely disrupted through Operation Cronos, but it seems the group is making a comeback. There are reports from late 2025 of <a href="https://www.techradar.com/pro/security/lockbit-malware-is-back-and-nastier-than-ever-experts-claim" target="_blank">LockBit 5.0 claims</a>, including a <a href="https://www.escudodigital.com/en/cybersecurity/lockbit-50-targets-us-bank-one-of-the-largest-banks-in-the-united-states.html" target="_blank" rel="nofollow">purported attack on U.S Bank</a>, but the news is yet to be confirmed. </p><p><em>Via </em><a href="https://therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Private equity giant Apollo confirms data breach saw personal info stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Apollo confirms July 2026 cyberattack via social engineering exposed PII in its cloud environment</strong></li><li><strong>Data included names, DOB, contact info, addresses, and Social Security numbers</strong></li><li><strong>Firm offers two years of identity protection; no evidence of dark web leaks yet</strong></li></ul><p>Apollo, one of the biggest private equity firms in the world, has confirmed it suffered a cyberattack which compromised some people’s personally identifiable information.</p><p>The company notified California’s Attorney General’s Office about the breach and shared a copy of the letter it is now sending out to affected individuals. It is impossible to discern from the letter if the victims are Apollo employees, customers, or someone else entirely, but the company did clearly explain what happened.</p><p>As per the letter, an unidentified threat actor tricked an Apollo employee into granting them access to the company’s cloud environment. The attackers used social engineering (usually phishing), which means the victim either tried logging in using a spoofed landing page, unknowingly installed an infostealer, or was convinced to grant the attackers access via remote monitoring and management software.</p><h2 id="was-there-really-a-hack">Was there really a hack?</h2><p>The company spotted the attack a few days later, and after activating its safety protocols (notifying the police, enhancing its security protocols, and bringing in third-party forensic experts), launched an investigation which showed that the attackers accessed its cloud platform between July 6 and 10. </p><p>“During our investigation, we learned on August 12, 2026 that the information potentially impacted by this incident included your name, date of birth, contact information, home address, and your Social Security Number (SSN),” the company said. This means that financial data such as credit card or bank account information, was not compromised. </p><p>Still, cybercriminals can make use of this type of information, as is often the case in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, business email compromise, and even wire fraud.</p><p>Apollo is now offering two years of free identity theft protection and monitoring for affected individuals through Cyberscout. </p><p>At press time, no threat actors claimed responsibility for the attack, and the data has not yet surfaced anywhere on the dark web.</p><p><em>Via </em><a href="https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/private-equity-giant-apollo-confirms-data-breach-saw-personal-info-stolen</link>
                                                                            <description>
                            <![CDATA[ We don't know how many people are affected, or if they're employees or customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DaLh3idyQngszsaBTPkBiE</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg"/>
                                                                        <pubDate>Mon, 24 Aug 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:description>                                                            <media:text><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:text>
                                <media:title type="plain"><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apollo confirms July 2026 cyberattack via social engineering exposed PII in its cloud environment</strong></li><li><strong>Data included names, DOB, contact info, addresses, and Social Security numbers</strong></li><li><strong>Firm offers two years of identity protection; no evidence of dark web leaks yet</strong></li></ul><p>Apollo, one of the biggest private equity firms in the world, has confirmed it suffered a cyberattack which compromised some people’s personally identifiable information.</p><p>The company notified California’s Attorney General’s Office about the breach and shared a copy of the letter it is now sending out to affected individuals. It is impossible to discern from the letter if the victims are Apollo employees, customers, or someone else entirely, but the company did clearly explain what happened.</p><p>As per the letter, an unidentified threat actor tricked an Apollo employee into granting them access to the company’s cloud environment. The attackers used social engineering (usually phishing), which means the victim either tried logging in using a spoofed landing page, unknowingly installed an infostealer, or was convinced to grant the attackers access via remote monitoring and management software.</p><h2 id="was-there-really-a-hack">Was there really a hack?</h2><p>The company spotted the attack a few days later, and after activating its safety protocols (notifying the police, enhancing its security protocols, and bringing in third-party forensic experts), launched an investigation which showed that the attackers accessed its cloud platform between July 6 and 10. </p><p>“During our investigation, we learned on August 12, 2026 that the information potentially impacted by this incident included your name, date of birth, contact information, home address, and your Social Security Number (SSN),” the company said. This means that financial data such as credit card or bank account information, was not compromised. </p><p>Still, cybercriminals can make use of this type of information, as is often the case in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, business email compromise, and even wire fraud.</p><p>Apollo is now offering two years of free identity theft protection and monitoring for affected individuals through Cyberscout. </p><p>At press time, no threat actors claimed responsibility for the attack, and the data has not yet surfaced anywhere on the dark web.</p><p><em>Via </em><a href="https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers uncover vast cybercrime ring running on computers and infected domains where outdated versions of WordPress were installed</strong></li><li><strong>The StopAndProtect investigation revealed the WordPress content management system was key to the ring’s success; both the core software and third-party plugins were subverted</strong></li><li><strong>Around 2,000 WordPress sites were hijacked by the cybercrime ring</strong></li></ul><p>Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains.</p><p>WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. It is also the most popular website builder, and is suitable for single page websites, basic blogs, vast news sites, and even online stores.</p><p>The researchers <a href="https://blog.checkpoint.com/research/the-mistake-that-exposed-a-global-cyber-crime-operation/" target="_blank">found</a> the crime ring had made some mistakes, which alerted them to their operation. These included screenshots and logs of victims, internal tools, and files referencing the hijacked domains. While reassuring, the StopAndProtect investigation raises questions about the security of WordPress sites.</p><h2 id="how-stopandprotect-did-it">How StopAndProtect did it</h2><p>WordPress has long been a target for hackers looking for an easy way to host malware and operate botnets, with several key incidents over the course of its history. However, the CMS remains free and open source, and is easy to setup thanks to installation scripts and web builder plugins.</p><p>While StopAndProtect was initially the name given to the ransomware uncovered by Check Point Research earlier in 2026, they decided to use the name for the whole operation, as they found it doesn’t only distribute ransomware.</p><p>Check Point Research’s Eli Smadja <a href="https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/" target="_blank">said</a>: “StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware.”</p><h2 id="can-any-wordpress-domain-be-hijacked">Can any WordPress domain be hijacked?</h2><p>Given the number of WordPress sites impacted by the crime ring uncovered by the investigation, and the platform’s prominence in the CMS and web builder market, the question has to be asked: is WordPress still safe?</p><p>“Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser," Smadja added.</p><p>Many small businesses rely on WordPress for their public-facing web presence, and in some cases for internal purposes too. The StopAndProtect investigation highlighted a particular WordPress-driven site running a five-year-old version of the CMS, compromised by around 40 vulnerabilities. </p><p>If concerns surround WordPress, the quickest solution is to ensure the website is running the most recent version, and that the plugins are not only running as intended, but also fully updated.</p><p>Maintaining a regular WordPress update cycle can avoid sites becoming hijacked, a strategy best used in conjunction with a web host that monitors for intrusions and suspicious activity.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-2-000-hacked-wordpress-sites-were-secretly-running-a-global-crime-ring</link>
                                                                            <description>
                            <![CDATA[ Compromised WordPress sites have been used by a global operation, using trusted websites to deliver malware, instruct infected devices, and even store stolen documents. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b4Zcbp8KYGsK87BPbpArpL</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg"/>
                                                                        <pubDate>Sat, 22 Aug 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers uncover vast cybercrime ring running on computers and infected domains where outdated versions of WordPress were installed</strong></li><li><strong>The StopAndProtect investigation revealed the WordPress content management system was key to the ring’s success; both the core software and third-party plugins were subverted</strong></li><li><strong>Around 2,000 WordPress sites were hijacked by the cybercrime ring</strong></li></ul><p>Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains.</p><p>WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. It is also the most popular website builder, and is suitable for single page websites, basic blogs, vast news sites, and even online stores.</p><p>The researchers <a href="https://blog.checkpoint.com/research/the-mistake-that-exposed-a-global-cyber-crime-operation/" target="_blank">found</a> the crime ring had made some mistakes, which alerted them to their operation. These included screenshots and logs of victims, internal tools, and files referencing the hijacked domains. While reassuring, the StopAndProtect investigation raises questions about the security of WordPress sites.</p><h2 id="how-stopandprotect-did-it">How StopAndProtect did it</h2><p>WordPress has long been a target for hackers looking for an easy way to host malware and operate botnets, with several key incidents over the course of its history. However, the CMS remains free and open source, and is easy to setup thanks to installation scripts and web builder plugins.</p><p>While StopAndProtect was initially the name given to the ransomware uncovered by Check Point Research earlier in 2026, they decided to use the name for the whole operation, as they found it doesn’t only distribute ransomware.</p><p>Check Point Research’s Eli Smadja <a href="https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/" target="_blank">said</a>: “StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware.”</p><h2 id="can-any-wordpress-domain-be-hijacked">Can any WordPress domain be hijacked?</h2><p>Given the number of WordPress sites impacted by the crime ring uncovered by the investigation, and the platform’s prominence in the CMS and web builder market, the question has to be asked: is WordPress still safe?</p><p>“Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser," Smadja added.</p><p>Many small businesses rely on WordPress for their public-facing web presence, and in some cases for internal purposes too. The StopAndProtect investigation highlighted a particular WordPress-driven site running a five-year-old version of the CMS, compromised by around 40 vulnerabilities. </p><p>If concerns surround WordPress, the quickest solution is to ensure the website is running the most recent version, and that the plugins are not only running as intended, but also fully updated.</p><p>Maintaining a regular WordPress update cycle can avoid sites becoming hijacked, a strategy best used in conjunction with a web host that monitors for intrusions and suspicious activity.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn expired credit cards can be brought back from the dead to make contactless payments ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers show how an expired contactless card can still complete a real purchase because the expiry date the terminal reads is not covered by its signature</strong></li><li><strong>The attack needs physical possession of the discarded card and two ordinary smartphones, and results vary per bank, with Visa cards being susceptible in testing</strong></li><li><strong>Existing EMV protections can detect the relay, but they are optional and were not enabled on any card or terminal tested, and neither Visa nor the notified banks have confirmed a fix is in the works</strong></li></ul><p>For a layman, the date printed on a credit card looks like a hard stop, but that might not always be the case.</p><p>Researchers at the University of Massachusetts Amherst <a href="https://www.usenix.org/conference/usenixsecurity26/presentation/anwar" target="_blank" rel="nofollow">found</a> that a 'zombie card' past its expiration date can be persuaded to complete a contactless purchase at a real checkout terminal, creating a real security threat.</p><p>The irony is that it is not that EMV cryptography is not bypassed in any way, but rather that card expiry is enforced in a different way for contactless payments, as a policy check between two parties rather than as a fixed property of the card itself, and interestingly, the parties do not always know who is the one checking.</p><h2 id="dead-plastic-can-still-be-used-to-pay-under-certain-conditions">Dead plastic can still be used to pay under certain conditions</h2><p>Building on the last part, a contactless transaction involves a card, a point-of-sale terminal, the merchant's bank, a card network, and the issuer. Each holds a fragment of the decision that eventually results in a successful or declined card transaction.</p><p>The EMV contactless flow is only selectively authenticated: some fields travel between the card and terminal in unencrypted text and are linked to cryptographic verification later, opening a potential attack vector for users with physical access to an expired card.</p><p>The exposure here is not that those fields can be read, since the expiry date is printed on the card anyway, but that it can be changed with relative ease. The Application Expiration Date that the terminal reads sits in the unprotected portion.</p><p>In the Visa configuration the team tested, that field is not covered by the card's digital signature and is subsequently not cryptographically bound to the expiry value the issuer sees in the online authorization request.</p><p>While this should not be the case, it opens an attack vector for a device between the card and the terminal that processes the charge by simply modifying the expiry value to one that is still valid. The issue is compounded by a second issue: cards carry an expiry date inside the digital certificate used to establish the card-to-terminal conversation, and researchers have found that the certificate outlasts the printed date on the plastic. In essence, a check that might have caught the problem is looking at a clock set further ahead.</p><p>The scope of the attack, however, is narrow: it affects Visa contactless cards only, with Mastercard, Discover, and American Express rejecting the altered expiry outright. It also requires physical access to the card and two smartphones to pull it off, making it a slightly more complex endeavor, to say the least.</p><p>The irony is that EMV does have a protection that would essentially undo such an attempt altogether: Relay Resistance Protocol, which measures timing to detect an inserted relay and can stop the transaction altogether, but it remains optional and was not enabled on any of the terminals or cards the researchers tested.</p><p>The team notified Visa and the relevant banks in May 2025 and again in December 2025, supplying a reproduction guide, transaction traces, and a video. Visa's report passed initial triage, and the company's red team was reproducing it. </p><p>However, as of publication, neither Visa nor the notified banks had confirmed a mitigation attempt, and Visa also did not respond to a <a href="https://www.theregister.com/security/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-payments/5289229" target="_blank">press request from <em>The Register</em></a> for comment.</p><p>The underlying failure, however, is based on how payment decisions have now spread across multiple players, including chip, terminal, network, and bank architectures, all of which assume that expiry is someone else's problem, an approach that could come back to haunt them and their customers. For now, the researcher's advice remains important until a fix is rolled out: stop treating dead plastic as harmless, destroy the underlying chip, and cut through the card numbers to prevent abuse.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-expired-credit-cards-can-be-brought-back-from-the-dead-to-make-contactless-payments</link>
                                                                            <description>
                            <![CDATA[ That expired card in your drawer might not be nearly as dead as you think: researchers made one pay $100 for a grocery run. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AGitkeYqa8AFsN6u8TZBRg</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fL8Ba8CiJjt2qsAVpr6UmK-1280-80.jpg"/>
                                                                        <pubDate>Fri, 21 Aug 2026 21:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fL8Ba8CiJjt2qsAVpr6UmK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A credit card passed between two hands]]></media:description>                                                            <media:text><![CDATA[A credit card passed between two hands]]></media:text>
                                <media:title type="plain"><![CDATA[A credit card passed between two hands]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fL8Ba8CiJjt2qsAVpr6UmK-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers show how an expired contactless card can still complete a real purchase because the expiry date the terminal reads is not covered by its signature</strong></li><li><strong>The attack needs physical possession of the discarded card and two ordinary smartphones, and results vary per bank, with Visa cards being susceptible in testing</strong></li><li><strong>Existing EMV protections can detect the relay, but they are optional and were not enabled on any card or terminal tested, and neither Visa nor the notified banks have confirmed a fix is in the works</strong></li></ul><p>For a layman, the date printed on a credit card looks like a hard stop, but that might not always be the case.</p><p>Researchers at the University of Massachusetts Amherst <a href="https://www.usenix.org/conference/usenixsecurity26/presentation/anwar" target="_blank" rel="nofollow">found</a> that a 'zombie card' past its expiration date can be persuaded to complete a contactless purchase at a real checkout terminal, creating a real security threat.</p><p>The irony is that it is not that EMV cryptography is not bypassed in any way, but rather that card expiry is enforced in a different way for contactless payments, as a policy check between two parties rather than as a fixed property of the card itself, and interestingly, the parties do not always know who is the one checking.</p><h2 id="dead-plastic-can-still-be-used-to-pay-under-certain-conditions">Dead plastic can still be used to pay under certain conditions</h2><p>Building on the last part, a contactless transaction involves a card, a point-of-sale terminal, the merchant's bank, a card network, and the issuer. Each holds a fragment of the decision that eventually results in a successful or declined card transaction.</p><p>The EMV contactless flow is only selectively authenticated: some fields travel between the card and terminal in unencrypted text and are linked to cryptographic verification later, opening a potential attack vector for users with physical access to an expired card.</p><p>The exposure here is not that those fields can be read, since the expiry date is printed on the card anyway, but that it can be changed with relative ease. The Application Expiration Date that the terminal reads sits in the unprotected portion.</p><p>In the Visa configuration the team tested, that field is not covered by the card's digital signature and is subsequently not cryptographically bound to the expiry value the issuer sees in the online authorization request.</p><p>While this should not be the case, it opens an attack vector for a device between the card and the terminal that processes the charge by simply modifying the expiry value to one that is still valid. The issue is compounded by a second issue: cards carry an expiry date inside the digital certificate used to establish the card-to-terminal conversation, and researchers have found that the certificate outlasts the printed date on the plastic. In essence, a check that might have caught the problem is looking at a clock set further ahead.</p><p>The scope of the attack, however, is narrow: it affects Visa contactless cards only, with Mastercard, Discover, and American Express rejecting the altered expiry outright. It also requires physical access to the card and two smartphones to pull it off, making it a slightly more complex endeavor, to say the least.</p><p>The irony is that EMV does have a protection that would essentially undo such an attempt altogether: Relay Resistance Protocol, which measures timing to detect an inserted relay and can stop the transaction altogether, but it remains optional and was not enabled on any of the terminals or cards the researchers tested.</p><p>The team notified Visa and the relevant banks in May 2025 and again in December 2025, supplying a reproduction guide, transaction traces, and a video. Visa's report passed initial triage, and the company's red team was reproducing it. </p><p>However, as of publication, neither Visa nor the notified banks had confirmed a mitigation attempt, and Visa also did not respond to a <a href="https://www.theregister.com/security/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-payments/5289229" target="_blank">press request from <em>The Register</em></a> for comment.</p><p>The underlying failure, however, is based on how payment decisions have now spread across multiple players, including chip, terminal, network, and bank architectures, all of which assume that expiry is someone else's problem, an approach that could come back to haunt them and their customers. For now, the researcher's advice remains important until a fix is rolled out: stop treating dead plastic as harmless, destroy the underlying chip, and cut through the card numbers to prevent abuse.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Took me months to work this out': Redditor explains how Windows 11 can end up stripping out the GPU driver on your gaming laptop ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Windows 11 can remove a discrete GPU driver as part of its clean-up routines, as shown on Reddit</strong></li><li><strong>This can happen if the laptop has been in Eco mode for an extended period</strong></li><li><strong>Because the GPU is effectively gated off from the system, the driver is marked as unused and therefore deleted by the OS during clean-up – but you can stop this from happening</strong></li></ul><p>Apparently, Windows 11 can end up stripping away the discrete GPU driver from your laptop in certain scenarios if the OS is left to run in Eco mode for a long time – and that's a distinct annoyance if you own a <a href="https://www.techradar.com/news/mobile-computing/laptops/best-gaming-laptops-top-5-gaming-notebooks-reviewed-1258471" target="_blank">gaming laptop</a>, as per a report on Reddit.</p><p><a href="https://wccftech.com/windows-deletes-dgpu-driver-gaming-laptop-eco-mode/" target="_blank">Wccftech spotted</a> a <a href="https://www.reddit.com/r/ZephyrusG14/comments/1vt5gdg/psa_if_your_laptop_gpu_turned_into_microsoft/" target="_blank">Redditor who posted</a> about their Asus ROG Zephyrus G14 gaming laptop with a discrete Nvidia RTX 5070 Ti, and how Windows turned off that GPU.</p><p>At this point, some of you may immediately be thinking: who runs their gaming laptop in Eco mode? And that's a fair point, and one raised in the Reddit thread – I'll come back to that.</p><p>First, let's look at the mechanics of how this works, based on the Redditor's investigation of what went on (they noted that it "took me months to work this out"). When the laptop is put into Eco mode, power is completely cut to the discrete GPU, effectively leaving it offline (just as if it were an unplugged USB stick, as the Redditor describes).</p><p>That's not a problem – obviously it's a power-saving measure – but the issue is that Windows 11 runs a driver clean-up process from time to time as part of routine system maintenance. By default, this happens every 30 days, though the Redditor notes their laptop was set to 15 days, and this can be modified.</p><p>What happens is that if the laptop has been in Eco mode for a long time, with the GPU effectively walled off and not present as far as the system is concerned, and the clean-up happens, it judges the driver to now be superfluous, and it's removed.</p><p>When Eco mode is subsequently switched off, the driver doesn't return – it remains ditched, and the GPU shows as a 'Microsoft Basic Display Adapter' instead of an Nvidia GPU in Windows 11's Device Manager.</p><p>The Nvidia graphics driver must then be reinstalled to get the GeForce graphics card functional again – and the same is reportedly true of AMD discrete GPUs.</p><h2 id="analysis-a-niche-problem-but-an-annoying-one-here-39-s-how-to-avoid-it">Analysis: a niche problem, but an annoying one – here's how to avoid it</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4032px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="k2vzUGq3RpjXbvcSFykv8" name="PXL_20250925_100502884" alt="Close-up of keyboard and touchpad on Asus ROG Zephyrus G14 (2025)" src="https://cdn.mos.cms.futurecdn.net/k2vzUGq3RpjXbvcSFykv8.jpg" mos="" align="middle" fullscreen="" width="4032" height="2268" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Let's return to that question: who runs a gaming laptop in Eco mode? No gamer really does this, at least not when they're regularly playing some of the <a href="https://www.techradar.com/news/best-pc-games">top PC games</a> on their notebook. However, someone might be a student cramming for finals and using the laptop for work, having given up gaming distractions for a few months. In this case, with Eco mode enabled to keep battery life up while studying, Windows <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458" target="_blank">11</a> could disable the GPU.</p><p>Okay, so it's something of a niche situation – and the Windows 11 clean-up routines are useful for keeping the system streamlined. But it's not an unthinkable scenario, and Microsoft's OS should be tuned to be more careful around GPU drivers – and it'd be useful if the system could give a warning of such a clean-up happening (so it could be avoided).</p><p>That said, this may not happen in all situations. Another Redditor notes that they have had their Zephyrus G16 in Eco mode for two months, and the Nvidia RTX 5070 Ti is still present and correct.</p><p>Whatever the case, if you run into this problem yourself, at least you know why it's happening. The fix is to simply reinstall the Nvidia driver, although the same thing could happen again if you're one of those people who regularly uses Eco mode on your gaming laptop.</p><p>You can apply a Registry fix to permanently stop the clean-up process, but I wouldn't recommend messing with those settings unless you're confident (see the Reddit post for instructions). Also note that you'll miss out on other clean-up duties, not just GPU-related activity.</p><p>A better solution is to simply remember to take your laptop out of Eco mode now and then (every couple of weeks), which will bring the discrete GPU back into play, and save the driver from being earmarked for removal.</p><p>The Redditor notes: "Or just keep the GPU visible now and then. Optimized mode in G-Helper turns the dGPU [discrete GPU] on whenever you plug in. Flipping to Standard [mode] every couple of weeks does the same thing. Resets the counter, no Registry editing."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/windows/took-me-months-to-work-this-out-redditor-explains-how-windows-11-can-end-up-stripping-out-the-gpu-driver-on-your-gaming-laptop</link>
                                                                            <description>
                            <![CDATA[ Windows 11 removed the driver for an Nvidia RTX 5070 Ti laptop graphics card, and you can blame Eco mode. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">heu2VceydhVutdLCffzc87</guid>
                                                                                                <enclosure length="0" type="image/png" url="https://cdn.mos.cms.futurecdn.net/nZ9MtUnriwdKNUAo7Dv4qM-1280-80.png"/>
                                                                        <pubDate>Fri, 21 Aug 2026 21:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Gaming Laptops]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Gaming Computers]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darren Allan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/nZ9MtUnriwdKNUAo7Dv4qM-1280-80.png">
                                                            <media:credit><![CDATA[Future / Isaiah Williams]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyberpunk 2077 on ROG Zephyrus G14 laptop]]></media:description>                                                            <media:text><![CDATA[Cyberpunk 2077 on ROG Zephyrus G14 laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Cyberpunk 2077 on ROG Zephyrus G14 laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nZ9MtUnriwdKNUAo7Dv4qM-1280-80.png"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Windows 11 can remove a discrete GPU driver as part of its clean-up routines, as shown on Reddit</strong></li><li><strong>This can happen if the laptop has been in Eco mode for an extended period</strong></li><li><strong>Because the GPU is effectively gated off from the system, the driver is marked as unused and therefore deleted by the OS during clean-up – but you can stop this from happening</strong></li></ul><p>Apparently, Windows 11 can end up stripping away the discrete GPU driver from your laptop in certain scenarios if the OS is left to run in Eco mode for a long time – and that's a distinct annoyance if you own a <a href="https://www.techradar.com/news/mobile-computing/laptops/best-gaming-laptops-top-5-gaming-notebooks-reviewed-1258471" target="_blank">gaming laptop</a>, as per a report on Reddit.</p><p><a href="https://wccftech.com/windows-deletes-dgpu-driver-gaming-laptop-eco-mode/" target="_blank">Wccftech spotted</a> a <a href="https://www.reddit.com/r/ZephyrusG14/comments/1vt5gdg/psa_if_your_laptop_gpu_turned_into_microsoft/" target="_blank">Redditor who posted</a> about their Asus ROG Zephyrus G14 gaming laptop with a discrete Nvidia RTX 5070 Ti, and how Windows turned off that GPU.</p><p>At this point, some of you may immediately be thinking: who runs their gaming laptop in Eco mode? And that's a fair point, and one raised in the Reddit thread – I'll come back to that.</p><p>First, let's look at the mechanics of how this works, based on the Redditor's investigation of what went on (they noted that it "took me months to work this out"). When the laptop is put into Eco mode, power is completely cut to the discrete GPU, effectively leaving it offline (just as if it were an unplugged USB stick, as the Redditor describes).</p><p>That's not a problem – obviously it's a power-saving measure – but the issue is that Windows 11 runs a driver clean-up process from time to time as part of routine system maintenance. By default, this happens every 30 days, though the Redditor notes their laptop was set to 15 days, and this can be modified.</p><p>What happens is that if the laptop has been in Eco mode for a long time, with the GPU effectively walled off and not present as far as the system is concerned, and the clean-up happens, it judges the driver to now be superfluous, and it's removed.</p><p>When Eco mode is subsequently switched off, the driver doesn't return – it remains ditched, and the GPU shows as a 'Microsoft Basic Display Adapter' instead of an Nvidia GPU in Windows 11's Device Manager.</p><p>The Nvidia graphics driver must then be reinstalled to get the GeForce graphics card functional again – and the same is reportedly true of AMD discrete GPUs.</p><h2 id="analysis-a-niche-problem-but-an-annoying-one-here-39-s-how-to-avoid-it">Analysis: a niche problem, but an annoying one – here's how to avoid it</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4032px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="k2vzUGq3RpjXbvcSFykv8" name="PXL_20250925_100502884" alt="Close-up of keyboard and touchpad on Asus ROG Zephyrus G14 (2025)" src="https://cdn.mos.cms.futurecdn.net/k2vzUGq3RpjXbvcSFykv8.jpg" mos="" align="middle" fullscreen="" width="4032" height="2268" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Let's return to that question: who runs a gaming laptop in Eco mode? No gamer really does this, at least not when they're regularly playing some of the <a href="https://www.techradar.com/news/best-pc-games">top PC games</a> on their notebook. However, someone might be a student cramming for finals and using the laptop for work, having given up gaming distractions for a few months. In this case, with Eco mode enabled to keep battery life up while studying, Windows <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458" target="_blank">11</a> could disable the GPU.</p><p>Okay, so it's something of a niche situation – and the Windows 11 clean-up routines are useful for keeping the system streamlined. But it's not an unthinkable scenario, and Microsoft's OS should be tuned to be more careful around GPU drivers – and it'd be useful if the system could give a warning of such a clean-up happening (so it could be avoided).</p><p>That said, this may not happen in all situations. Another Redditor notes that they have had their Zephyrus G16 in Eco mode for two months, and the Nvidia RTX 5070 Ti is still present and correct.</p><p>Whatever the case, if you run into this problem yourself, at least you know why it's happening. The fix is to simply reinstall the Nvidia driver, although the same thing could happen again if you're one of those people who regularly uses Eco mode on your gaming laptop.</p><p>You can apply a Registry fix to permanently stop the clean-up process, but I wouldn't recommend messing with those settings unless you're confident (see the Reddit post for instructions). Also note that you'll miss out on other clean-up duties, not just GPU-related activity.</p><p>A better solution is to simply remember to take your laptop out of Eco mode now and then (every couple of weeks), which will bring the discrete GPU back into play, and save the driver from being earmarked for removal.</p><p>The Redditor notes: "Or just keep the GPU visible now and then. Optimized mode in G-Helper turns the dGPU [discrete GPU] on whenever you plug in. Flipping to Standard [mode] every couple of weeks does the same thing. Resets the counter, no Registry editing."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ No driver, no problem — devs use Claude AI to craft native macOS tool for an 'obscure' Windows-only printer ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>India-based developer Kuber Mehta uses Claude Code to create a macOS driver for the HP Laser 1008a</strong></li><li><strong>Previously, only the official drivers for Windows and Linux were available for the relatively obscure 2023 laser printer</strong></li><li><strong>The AI-generated driver was created over a series of meticulous prompts, and is now available via GitHub</strong></li></ul><p>The days of avoiding hardware that is incompatible with your operating system could be over. A developer based in India has created a macOS driver for a largely unknown HP printer using <a href="https://www.techradar.com/pro/claude-code-comes-to-the-masses-and-its-a-game-changer">Claude Code</a>, the agentic command-line coding tool developed by Anthropic.</p><p>Released in 2023, the HP Laser 1008a was issued with drivers for Windows and Linux, but not macOS. By using AI to generate a driver for macOS, developer Kuber Mehta has demonstrated that incompatible hardware could soon be a thing of the past.</p><p>Mehta has shared the code on GitHub and has also posted about the process on social media, and also compiled a transcript of the exchange, which has been published online for reference.</p><h2 id="hp-s-samsung-printer">HP’s Samsung printer</h2><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2089377982536388964"><p lang="en" dir="ltr">just Claude writing a MacOS driver for my obscure HP printer built only for Windows support pic.twitter.com/ORjLugJiRF<a href="https://twitter.com/cantworkitout/status/2089377982536388964">August 17, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Describing the issue in the <a href="https://cdn.kuber.studio/chat/hp-laser-1008a-driver" target="_blank">introduction</a> to the transcript, Mehta explains that the HP Laser 1008a is a “rebadged Samsung, host-based printer that speaks a proprietary raster language (SPL3), and it has no macOS driver and no AirPrint.” </p><p>No SPL3 drivers have been published for macOS previously, so the process relied on a conversation with Claude Code and reference to the Windows and Linux drivers.</p><p>The <a href="https://github.com/Kuberwastaken/hp-laser-1008a-macos" target="_blank">GitHub</a> intro adds that the HP Laser 1008a and siblings in the series (1003 and 1006 a/w) have another problem: “They do not speak PostScript or PCL.” Anyone familiar with the world of printer drivers will recognize the challenge faced by Mehta, which makes the use of Claude Code even more impressive.</p><p>Using Claude Code with the Opus 4.8 model, the driver was compiled in 30-40 prompts. This might have been even quicker had the AI not made various assertions that required correcting. </p><p>The process moved through “install the drivers” to establishing the print language by analysing the printer’s error pages, via direct contact with the device and “running HP's real rastertospl codec inside a Linux container to produce genuine SPL3, to a reboot-safe background daemon.”</p><p>From here, Mehta and Claude Code moved to the published, MIT-licensed installer, which patches the macOS open-source printer driver package SpliX, adding support for the SPL3 printers (by default, SpliX handles SPL2 and SPLc drivers).</p><h2 id="building-from-ai">Building from AI</h2><p>While already a developer, Kuber Mehta <a href="https://x.com/kuberwastaken/status/2089721130127094071" target="_blank">admitted</a> learning about macOS drivers from the process, perhaps an unforeseen benefit of using generative AI tools for coding. </p><p>The GitHub repo outlines some revisions that have been made to the initial release, which is now “a tiny native IOKit helper” that dispenses with Python, pyusb, and libusb and can be swiftly installed from the Terminal.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/no-driver-no-problem-devs-use-claude-ai-to-craft-native-macos-tool-for-an-obscure-windows-only-printer</link>
                                                                            <description>
                            <![CDATA[ Developer uses Claude Code to create driver for the HP Laser 1008a, a 2023 printer that has Windows and Linux drivers, but no macOS driver – until now. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xv5Eoqv8F5X5c8d7biKqzi</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg"/>
                                                                        <pubDate>Fri, 21 Aug 2026 20:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Printers &amp; Scanners]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Peripherals &amp; Accessories]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/TippaPatt]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:description>                                                            <media:text><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:text>
                                <media:title type="plain"><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>India-based developer Kuber Mehta uses Claude Code to create a macOS driver for the HP Laser 1008a</strong></li><li><strong>Previously, only the official drivers for Windows and Linux were available for the relatively obscure 2023 laser printer</strong></li><li><strong>The AI-generated driver was created over a series of meticulous prompts, and is now available via GitHub</strong></li></ul><p>The days of avoiding hardware that is incompatible with your operating system could be over. A developer based in India has created a macOS driver for a largely unknown HP printer using <a href="https://www.techradar.com/pro/claude-code-comes-to-the-masses-and-its-a-game-changer">Claude Code</a>, the agentic command-line coding tool developed by Anthropic.</p><p>Released in 2023, the HP Laser 1008a was issued with drivers for Windows and Linux, but not macOS. By using AI to generate a driver for macOS, developer Kuber Mehta has demonstrated that incompatible hardware could soon be a thing of the past.</p><p>Mehta has shared the code on GitHub and has also posted about the process on social media, and also compiled a transcript of the exchange, which has been published online for reference.</p><h2 id="hp-s-samsung-printer">HP’s Samsung printer</h2><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2089377982536388964"><p lang="en" dir="ltr">just Claude writing a MacOS driver for my obscure HP printer built only for Windows support pic.twitter.com/ORjLugJiRF<a href="https://twitter.com/cantworkitout/status/2089377982536388964">August 17, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Describing the issue in the <a href="https://cdn.kuber.studio/chat/hp-laser-1008a-driver" target="_blank">introduction</a> to the transcript, Mehta explains that the HP Laser 1008a is a “rebadged Samsung, host-based printer that speaks a proprietary raster language (SPL3), and it has no macOS driver and no AirPrint.” </p><p>No SPL3 drivers have been published for macOS previously, so the process relied on a conversation with Claude Code and reference to the Windows and Linux drivers.</p><p>The <a href="https://github.com/Kuberwastaken/hp-laser-1008a-macos" target="_blank">GitHub</a> intro adds that the HP Laser 1008a and siblings in the series (1003 and 1006 a/w) have another problem: “They do not speak PostScript or PCL.” Anyone familiar with the world of printer drivers will recognize the challenge faced by Mehta, which makes the use of Claude Code even more impressive.</p><p>Using Claude Code with the Opus 4.8 model, the driver was compiled in 30-40 prompts. This might have been even quicker had the AI not made various assertions that required correcting. </p><p>The process moved through “install the drivers” to establishing the print language by analysing the printer’s error pages, via direct contact with the device and “running HP's real rastertospl codec inside a Linux container to produce genuine SPL3, to a reboot-safe background daemon.”</p><p>From here, Mehta and Claude Code moved to the published, MIT-licensed installer, which patches the macOS open-source printer driver package SpliX, adding support for the SPL3 printers (by default, SpliX handles SPL2 and SPLc drivers).</p><h2 id="building-from-ai">Building from AI</h2><p>While already a developer, Kuber Mehta <a href="https://x.com/kuberwastaken/status/2089721130127094071" target="_blank">admitted</a> learning about macOS drivers from the process, perhaps an unforeseen benefit of using generative AI tools for coding. </p><p>The GitHub repo outlines some revisions that have been made to the initial release, which is now “a tiny native IOKit helper” that dispenses with Python, pyusb, and libusb and can be swiftly installed from the Terminal.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Infoblox Threat Intel counted roughly 65,000 expired domains re-registered every day in the first half of 2026, close to one in five of all new registrations</strong></li><li><strong>An actor it calls Sable Squirrel controls more than 10,000 domains and is estimated, by extrapolation, to have spent over $7 million buying expired names for their inherited traffic and domain authority</strong></li><li><strong>Some of the domains are also used to function as command-and-control structures for existing malware that can be traced back to the same group</strong></li></ul><p>A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about.</p><p>New <a href="https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/" target="_blank" rel="nofollow">research</a> from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least one criminal operation has been buying it in bulk.</p><p>The study, published as a three-part series, focuses on what the industry calls dropcatch domains: names that lapsed, were released back to the registry, and were then re-registered by someone else entirely.</p><h2 id="a-dropcatch-domain-situation-a-gambling-business-with-a-malware-enabling-catch">A dropcatch domain situation: A gambling business with a malware-enabling catch</h2><p>Dropcatch domains aren't new; software has been primed to spot expiring domains for years, and it sometimes <a href="https://www.techradar.com/news/one-of-the-internets-most-infamous-domain-names-is-up-for-sale" target="_blank">snags the occasional massive win</a> for users who deploy such solutions. </p><p>This lets users start with domains that already have history that benefits them or flip certain domains for a price that is often a multiple of the domain's original purchase price.</p><p>Infoblox counted an average of 50,400 such re-registrations a day across generic top-level domains in the first half of 2026, rising to roughly 65,000 once country-code domains are added. That amounts to close to a fifth of all daily registrations. The rate is highest on .net and .xyz, where nearly three in ten newly observed names had a previous life, with .com behind them at 24.5%.</p><p>The problem is that not all of these are seemingly innocent or small-scale scalping operations: Infoblox has identified an entity it has labeled Sable Squirrel, part of a naming convention the company applies to domain hoarders. It controls more than 10,000 domains, most of which support a large Vietnamese-language sports piracy operation operating under brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom.</p><p>Infoblox estimates the actor's total spend on expired domains at north of $7 million, which it describes as the largest domain acquisition budget it has identified for a single actor in the industry. The bigger problem is that Infoblox also found that a subset of these streaming domains runs as malware command and control while continuing to serve live football to human visitors.</p><p>More than 31,000 samples identified called back to Sable Squirrel's infrastructure, spanning Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, plus samples carrying HiddenTear ransomware signatures. </p><p>Infoblox said the operator's carelessness made finding a link easier: many samples carry the actor's brand names in their Windows executable metadata, with fields reading socolive, xoilac, and 8xbet. Infoblox confirmed 405 domains as malware C2, which is roughly four percent of the total domains the organization controls, and the weaponization arrived as a single wave in late 2025 rather than as the operation's original purpose.</p><p>Sable Squirrel's core business is gambling, and while the entity tries to mask it as a streaming operation, it also doubles as an acquisition channel for the same. While law enforcement has not been silent here, it has had limited luck at best: Vietnamese authorities froze some of the flagship sites in February 2026 and charged 30 suspects in March. </p><p>They also seized assets Infoblox puts at roughly $12 million, but it seems to have survived and continues to expand, having acquired and run World Cup-centric domains since June, further expanding its footprint in a world where it has already identified and secured a large chunk of what is arguably a very important commodity: Domain authority.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/even-dead-websites-arent-safe-experts-warn-hackers-are-spending-millions-on-expired-domains-to-enable-malware-scams</link>
                                                                            <description>
                            <![CDATA[ Roughly 65,000 expired domains change hands every day, and researchers have found one crime group spending an estimated $7 million on them to inherit the trust that comes attached to them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xFP3YBdbcUzK5sEJVSyvSD</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg"/>
                                                                        <pubDate>Fri, 21 Aug 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:description>                                                            <media:text><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:text>
                                <media:title type="plain"><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Infoblox Threat Intel counted roughly 65,000 expired domains re-registered every day in the first half of 2026, close to one in five of all new registrations</strong></li><li><strong>An actor it calls Sable Squirrel controls more than 10,000 domains and is estimated, by extrapolation, to have spent over $7 million buying expired names for their inherited traffic and domain authority</strong></li><li><strong>Some of the domains are also used to function as command-and-control structures for existing malware that can be traced back to the same group</strong></li></ul><p>A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about.</p><p>New <a href="https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/" target="_blank" rel="nofollow">research</a> from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least one criminal operation has been buying it in bulk.</p><p>The study, published as a three-part series, focuses on what the industry calls dropcatch domains: names that lapsed, were released back to the registry, and were then re-registered by someone else entirely.</p><h2 id="a-dropcatch-domain-situation-a-gambling-business-with-a-malware-enabling-catch">A dropcatch domain situation: A gambling business with a malware-enabling catch</h2><p>Dropcatch domains aren't new; software has been primed to spot expiring domains for years, and it sometimes <a href="https://www.techradar.com/news/one-of-the-internets-most-infamous-domain-names-is-up-for-sale" target="_blank">snags the occasional massive win</a> for users who deploy such solutions. </p><p>This lets users start with domains that already have history that benefits them or flip certain domains for a price that is often a multiple of the domain's original purchase price.</p><p>Infoblox counted an average of 50,400 such re-registrations a day across generic top-level domains in the first half of 2026, rising to roughly 65,000 once country-code domains are added. That amounts to close to a fifth of all daily registrations. The rate is highest on .net and .xyz, where nearly three in ten newly observed names had a previous life, with .com behind them at 24.5%.</p><p>The problem is that not all of these are seemingly innocent or small-scale scalping operations: Infoblox has identified an entity it has labeled Sable Squirrel, part of a naming convention the company applies to domain hoarders. It controls more than 10,000 domains, most of which support a large Vietnamese-language sports piracy operation operating under brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom.</p><p>Infoblox estimates the actor's total spend on expired domains at north of $7 million, which it describes as the largest domain acquisition budget it has identified for a single actor in the industry. The bigger problem is that Infoblox also found that a subset of these streaming domains runs as malware command and control while continuing to serve live football to human visitors.</p><p>More than 31,000 samples identified called back to Sable Squirrel's infrastructure, spanning Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, plus samples carrying HiddenTear ransomware signatures. </p><p>Infoblox said the operator's carelessness made finding a link easier: many samples carry the actor's brand names in their Windows executable metadata, with fields reading socolive, xoilac, and 8xbet. Infoblox confirmed 405 domains as malware C2, which is roughly four percent of the total domains the organization controls, and the weaponization arrived as a single wave in late 2025 rather than as the operation's original purpose.</p><p>Sable Squirrel's core business is gambling, and while the entity tries to mask it as a streaming operation, it also doubles as an acquisition channel for the same. While law enforcement has not been silent here, it has had limited luck at best: Vietnamese authorities froze some of the flagship sites in February 2026 and charged 30 suspects in March. </p><p>They also seized assets Infoblox puts at roughly $12 million, but it seems to have survived and continues to expand, having acquired and run World Cup-centric domains since June, further expanding its footprint in a world where it has already identified and secured a large chunk of what is arguably a very important commodity: Domain authority.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Target may have suffered another damaging data leak as hackers claim 8.6GB haul ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hacker alias Xpl0itrs claims to have stolen 8.6GB of Target source code  </strong></li><li><strong>Researchers suspect it’s recycled data from January’s confirmed 860GB breach  </strong></li><li><strong>Xpl0itrs has a history of dubious leak claims, fueling skepticism about authenticity</strong></li></ul><p>Hackers are claiming to have breached Target in what would be the US supermarket giant's second breach of 2026 alone. </p><p>The attackers are threatening to release gigabytes of source code into the dark web unless the company pays up, but not everyone is sold on the idea that the US merchandise giant was actually hacked this time around. </p><p>Some security researchers believe this might just be a case of a lowly criminal piggybacking on someone else’s work.</p><h2 id="was-there-really-a-hack-2">Was there really a hack?</h2><p><a href="https://www.techradar.com/pro/security/hackers-claim-to-have-target-source-code-for-sale-following-recent-cyberattack" target="_blank">Target was first hit in January 2026</a>, when a threat actor posted a new thread in an underground hacking community to claim they were selling the company's data, and that this was the first of many datasets to go on auction. To support their claim, they created multiple repositories on Gitea, a self-hosted Git platform, and uploaded a small sample of the data.</p><p>The repositories, totaling around 860 GB in size, appeared to contain internal Target source code, configuration files, and developer documentation, while repository names were referencing internal systems such as wallet services, <a href="https://www.techradar.com/best/best-identity-management-software" target="_blank">identity management</a>, store networking tools, secrets documentation, and gift card systems.</p><p>Target later confirmed the authenticity of the breach.</p><p>This time around, however, a different threat actor - with an alias Xpl0itrs - created a new data leak site in mid-June 2026, and earlier this month added Target. They claim to have stolen 8.6GB of the company's source code and have given it two days to pay up or see the data leak into the dark web. </p><p>Xpl0itrs is not exactly a household name in the cybercriminal community, and they have not shared any samples of the data they are claiming to have nabbed - further fueling the idea that this data was already grabbed eight months ago. </p><p>Even some of their previous “work” is questionable. <a href="https://cybernews.com/security/target-data-breach-source-code-claim/" target="_blank"><em>Cybernews</em></a> reports that in June, they teased leaking data from Spotify, the US Department of the Treasury, OpenAI, and Trustpilot, which never happened. Before that, they claimed to have stolen documents from BMW, containing details about motorcycles and dealerships. This, too, was somewhat debunked, as it turned out that some of the data was already publicly available. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/target-may-have-suffered-another-damaging-data-leak-as-hackers-claim-8-6gb-haul</link>
                                                                            <description>
                            <![CDATA[ The claims came from a threat actor with a questionable track record. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qH8uTStXvBsfgjfPXrzpqX</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/34u7D3mDFFPiqboXQBth8f-1280-80.jpg"/>
                                                                        <pubDate>Fri, 21 Aug 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/34u7D3mDFFPiqboXQBth8f-1280-80.jpg">
                                                            <media:credit><![CDATA[Target]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Target may not be an option for last-minute shopping on Thanksgiving.]]></media:description>                                                            <media:text><![CDATA[A newly remodelled Target store]]></media:text>
                                <media:title type="plain"><![CDATA[A newly remodelled Target store]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/34u7D3mDFFPiqboXQBth8f-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hacker alias Xpl0itrs claims to have stolen 8.6GB of Target source code  </strong></li><li><strong>Researchers suspect it’s recycled data from January’s confirmed 860GB breach  </strong></li><li><strong>Xpl0itrs has a history of dubious leak claims, fueling skepticism about authenticity</strong></li></ul><p>Hackers are claiming to have breached Target in what would be the US supermarket giant's second breach of 2026 alone. </p><p>The attackers are threatening to release gigabytes of source code into the dark web unless the company pays up, but not everyone is sold on the idea that the US merchandise giant was actually hacked this time around. </p><p>Some security researchers believe this might just be a case of a lowly criminal piggybacking on someone else’s work.</p><h2 id="was-there-really-a-hack-2">Was there really a hack?</h2><p><a href="https://www.techradar.com/pro/security/hackers-claim-to-have-target-source-code-for-sale-following-recent-cyberattack" target="_blank">Target was first hit in January 2026</a>, when a threat actor posted a new thread in an underground hacking community to claim they were selling the company's data, and that this was the first of many datasets to go on auction. To support their claim, they created multiple repositories on Gitea, a self-hosted Git platform, and uploaded a small sample of the data.</p><p>The repositories, totaling around 860 GB in size, appeared to contain internal Target source code, configuration files, and developer documentation, while repository names were referencing internal systems such as wallet services, <a href="https://www.techradar.com/best/best-identity-management-software" target="_blank">identity management</a>, store networking tools, secrets documentation, and gift card systems.</p><p>Target later confirmed the authenticity of the breach.</p><p>This time around, however, a different threat actor - with an alias Xpl0itrs - created a new data leak site in mid-June 2026, and earlier this month added Target. They claim to have stolen 8.6GB of the company's source code and have given it two days to pay up or see the data leak into the dark web. </p><p>Xpl0itrs is not exactly a household name in the cybercriminal community, and they have not shared any samples of the data they are claiming to have nabbed - further fueling the idea that this data was already grabbed eight months ago. </p><p>Even some of their previous “work” is questionable. <a href="https://cybernews.com/security/target-data-breach-source-code-claim/" target="_blank"><em>Cybernews</em></a> reports that in June, they teased leaking data from Spotify, the US Department of the Treasury, OpenAI, and Trustpilot, which never happened. Before that, they claimed to have stolen documents from BMW, containing details about motorcycles and dealerships. This, too, was somewhat debunked, as it turned out that some of the data was already publicly available. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new malware can use Google passkeys even after a victim resets their password ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts  </strong></li><li><strong>Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access  </strong></li><li><strong>Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods</strong></li></ul><p>Security researchers have discovered a new <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.</p><p>iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new <a href="https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys" target="_blank" rel="nofollow">report</a> from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.</p><p>The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey. </p><h2 id="how-to-defend-against-iauthflow-v2">How to defend against iAuthFlow v2</h2><p>A passkey is an alternative means of authentication that is often touted as the “<a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN. </p><p>Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. </p><p>The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication. </p><p>However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.</p><p>Usually, when a threat actor compromises an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email account</a>, terminating all sessions and changing the password is usually enough.</p><p>In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.</p><p>They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-new-malware-can-use-google-passkeys-even-after-a-victim-resets-their-password</link>
                                                                            <description>
                            <![CDATA[ A newly discovered toolkit can deeply compromise Gmail, Microsoft, Apple, and LinkedIn accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XL5nrccyjA7YTcv5HwxC9C</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg"/>
                                                                        <pubDate>Fri, 21 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg">
                                                            <media:credit><![CDATA[Ascannio / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gmail app listing]]></media:description>                                                            <media:text><![CDATA[Gmail app listing]]></media:text>
                                <media:title type="plain"><![CDATA[Gmail app listing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts  </strong></li><li><strong>Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access  </strong></li><li><strong>Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods</strong></li></ul><p>Security researchers have discovered a new <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.</p><p>iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new <a href="https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys" target="_blank" rel="nofollow">report</a> from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.</p><p>The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey. </p><h2 id="how-to-defend-against-iauthflow-v2">How to defend against iAuthFlow v2</h2><p>A passkey is an alternative means of authentication that is often touted as the “<a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN. </p><p>Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. </p><p>The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication. </p><p>However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.</p><p>Usually, when a threat actor compromises an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email account</a>, terminating all sessions and changing the password is usually enough.</p><p>In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.</p><p>They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts targeted by fake crypto conference in scam to hand over details ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress spotted a ClickFix campaign targeting security pros via fake conference invites  </strong></li><li><strong>Victims tricked into pasting code that installs AMOS infostealer on macOS </strong></li><li><strong>If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets</strong></li></ul><p>Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have warned.</p><p>An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers <a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware" target="_blank">Huntress</a>, who were targets themselves. </p><p>The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim. </p><h2 id="follow-up-attack">Follow-up attack</h2><p>Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.</p><p>From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.</p><p>Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.</p><p>The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”. </p><p>“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/security-experts-targeted-by-fake-crypto-conference-in-scam-to-hand-over-details</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity pros attending conferences are being targeted with AMOS and other infostealers, experts warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4WM98xrduycbkQfG5f5Wdh</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg"/>
                                                                        <pubDate>Fri, 21 Aug 2026 13:20:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress spotted a ClickFix campaign targeting security pros via fake conference invites  </strong></li><li><strong>Victims tricked into pasting code that installs AMOS infostealer on macOS </strong></li><li><strong>If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets</strong></li></ul><p>Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have warned.</p><p>An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers <a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware" target="_blank">Huntress</a>, who were targets themselves. </p><p>The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim. </p><h2 id="follow-up-attack">Follow-up attack</h2><p>Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.</p><p>From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.</p><p>Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.</p><p>The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”. </p><p>“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are your PC games crashing after the latest Windows 11 update? Microsoft is investigating whether a nasty new bug is the cause — but there are workarounds ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Windows 11's August update has broken some PC games</strong></li><li><strong>Microsoft is investigating reports of crashes, but right now it's unclear what the root cause is</strong></li><li><strong>Theories point to security measures in the update potentially causing issues with certain drivers and conflicts with anti-cheat tools</strong></li></ul><p>Windows 11 has run into trouble with gamers (<a href="https://www.techradar.com/computing/windows/microsofts-new-windows-11-update-fixes-nasty-bug-that-left-gamers-staring-at-the-dreaded-black-screen-of-death">again</a>) after the latest monthly update for the OS, and Microsoft is investigating what's gone wrong.</p><p><a href="https://www.theregister.com/os-platforms/2026/08/20/microsoft-probes-reports-of-games-taking-exception-to-windows-11s-august-update/5290214" target="_blank">The Register noticed</a> that <a href="https://learn.microsoft.com/en-gb/windows/release-health/status-windows-11-25H2#3731msgdesc" target="_blank">Microsoft has posted</a> on the Windows release health dashboard about "reports of certain games becoming unresponsive" following its latest patch.</p><p>In some cases, games are either freezing and becoming unresponsive, as mentioned, or simply closing (crashing to the desktop), with an error ('Exception Access Violation') being displayed in some cases. There are also some reports of spontaneous reboots occurring after a game crashes.</p><p>Not all <a href="https://www.techradar.com/news/best-pc-games">PC games</a> are affected by any means, with Microsoft noting that reports are coming in from players of <a href="https://www.techradar.com/gaming/arc-raiders-is-a-perfect-mix-of-tension-drama-and-genuinely-human-moments-it-might-just-be-the-best-game-of-2025"><em>Arc Raiders</em></a>, <em>Marvel Tokon: Fighting Souls</em>, and <em>The Finals</em>.</p><p>Microsoft is currently trying to work out what's going on, saying: "Ongoing investigation indicates that this issue is related to peripherals or internal device components which have RGB lighting features. Such devices may install drivers or code components with file names similar to inpoutx64. In systems where these drivers are found, the issue is then triggered by launching certain games."</p><p>Microsoft adds that it's currently trying to "understand the relationship between these RGB components and the games which trigger this issue", and says it will update gamers when more information becomes available.</p><h2 id="analysis-theories-and-workarounds">Analysis: theories and workarounds</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3n5UC4FXvkeedwnALw8aW8" name="arc-raiders-arc-enemy-combat-1" alt="A Raider fires at a distant robotic spider-like enemy in a desert setting" src="https://cdn.mos.cms.futurecdn.net/3n5UC4FXvkeedwnALw8aW8.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Embark)</span></figcaption></figure><p>Microsoft is suggesting that this may be a driver-related issue of some kind, rather than a problem with Windows 11 itself. Of course, changes to Windows 11 could be the root cause, and the company admits that, and says it's still trying to "determine if this is an issue caused by Microsoft" on the release health dashboard.</p><p>As The Register points out, some on <a href="https://www.reddit.com/r/ArcRaiders/comments/1vmm7k3/comment/p3c7in3/" target="_blank">Reddit are theorizing</a> that this bug is to do with "tightened kernel handle validation" which was introduced with the latest patch for Windows 11. Essentially meaning that Microsoft has tightened aspects of security with the August update, and that this is causing driver glitches, ones that were previously ignored, to be picked up (and subsequently crashing games).</p><p>The mentioned driver (inpoutx64) isn't just used in software controlling RGB lighting, but also in some system utilities needing low-level system access (for hardware monitoring, for example, and one such tool is mentioned in the above Reddit post: ZenTimings). It seems that if this driver is present on the host PC, the game's anti-cheat probing it now throws up a problem (post-patch), and that leads to the crash.</p><p>If this bug is causing you grief — and there are a lot of Arc Raiders players out there in that particular boat — there are workarounds that can make the game playable again.</p><p>The first is the most obvious and easiest fix: remove the August update for Windows 11 (or roll back the OS to before it was installed). You can remove an update in Windows Update, in the Update History panel — just find the patch (KB5121003 in this case) and uninstall it. However, bear in mind that you will be without a bunch of security fixes (<a href="https://www.techradar.com/computing/windows/windows-11s-august-update-has-arrived-here-are-3-reasons-to-download-it-including-turbocharged-app-launching">and other features, including faster app launching</a>) if you don't have this update on your PC.</p><p>The other alternative is to remove the problematic driver file, which seemingly won't harm your system (that said, if you do so, it's at your own risk — I haven't tested this). Going by the advice in the above Reddit thread — and <a href="https://www.reddit.com/r/ArcRaiders/comments/1vombsk/embark_has_shared_a_temporary_potentialfix_for/" target="_blank">also from the developer of Arc Raiders</a> (Embark) — what you need to do is open the Command Prompt in Windows 11 by typing <strong>cmd</strong> in the search box, then right-click on Command Prompt and select 'Run as administrator'.</p><p>Once the prompt appears, type the following and press enter:</p><p><strong>sc stop inpoutx64</strong></p><p>Then type this second line and press enter: </p><p><strong>sc delete inpoutx64</strong></p><p>Now close the Command Prompt, open File Explorer, and find the following folder: C:\Windows\System32\drivers.</p><p>In that folder you should see the inpoutx64 file, it may be a SYS or DLL file (or both). Delete any of those files which are present.</p><p>That's the driver removed, and you should now be good to go, and you can still have the August update installed. But as I already noted, proceed at your own risk if you take this route.</p><p>The best bet for now may be to sit tight and wait for the results of Microsoft's investigation, and hopefully we'll hear something soon. However, this could be a somewhat thorny problem to untangle, and it rather sounds like a case of Microsoft dealing with a security issue — one which should be fixed — and that cure causing collateral damage due to driver wonkiness.</p><p>Whatever the case, on social media, a good many PC gamers are blaming Microsoft for this latest gaming-related issue in Windows 11.</p><p>One <a href="https://www.reddit.com/r/pcmasterrace/comments/1vti9ku/comment/p4ts0c4/" target="_blank">Redditor delivers the following barb</a>: "They can't even keep the one thing they had over Linux. If you have to worry about whether or not your games work anyway, why still use Windows?"</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1vti9ku/comment/p4trtpx/" target="_blank">Another observes</a>: "Since 2025 December update till today — EVERY single month the update breaks something! There was no single month without issues."</p><p>There's no shortage of shots fired at Microsoft for monthly update woes, accusations of this being the fault of vibe coding (AI), and threats to <a href="https://www.techradar.com/computing/software/sick-of-microslop-new-linux-distro-could-win-over-windows-11-haters">leave for greener Linux desktop pastures</a>. Business as usual, then.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/windows/are-your-pc-games-crashing-after-the-latest-windows-11-update-microsoft-is-investigating-whether-a-nasty-new-bug-is-the-cause-but-there-are-workarounds</link>
                                                                            <description>
                            <![CDATA[ Microsoft is investigating reports of a nasty bug that breaks some PC games following the latest Windows 11 update. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XEHBfcK6dfz86gfHgnKnb9</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b4BaqDTfZg32izULhgfJ2T-1280-80.jpg"/>
                                                                        <pubDate>Fri, 21 Aug 2026 11:45:37 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Aug 2026 12:19:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[PC Gaming]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Gaming]]></category>
                                                    <category><![CDATA[Consoles &amp; PC]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darren Allan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b4BaqDTfZg32izULhgfJ2T-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Upset young man plays computer games at home.]]></media:description>                                                            <media:text><![CDATA[Upset young man plays computer games at home.]]></media:text>
                                <media:title type="plain"><![CDATA[Upset young man plays computer games at home.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b4BaqDTfZg32izULhgfJ2T-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Windows 11's August update has broken some PC games</strong></li><li><strong>Microsoft is investigating reports of crashes, but right now it's unclear what the root cause is</strong></li><li><strong>Theories point to security measures in the update potentially causing issues with certain drivers and conflicts with anti-cheat tools</strong></li></ul><p>Windows 11 has run into trouble with gamers (<a href="https://www.techradar.com/computing/windows/microsofts-new-windows-11-update-fixes-nasty-bug-that-left-gamers-staring-at-the-dreaded-black-screen-of-death">again</a>) after the latest monthly update for the OS, and Microsoft is investigating what's gone wrong.</p><p><a href="https://www.theregister.com/os-platforms/2026/08/20/microsoft-probes-reports-of-games-taking-exception-to-windows-11s-august-update/5290214" target="_blank">The Register noticed</a> that <a href="https://learn.microsoft.com/en-gb/windows/release-health/status-windows-11-25H2#3731msgdesc" target="_blank">Microsoft has posted</a> on the Windows release health dashboard about "reports of certain games becoming unresponsive" following its latest patch.</p><p>In some cases, games are either freezing and becoming unresponsive, as mentioned, or simply closing (crashing to the desktop), with an error ('Exception Access Violation') being displayed in some cases. There are also some reports of spontaneous reboots occurring after a game crashes.</p><p>Not all <a href="https://www.techradar.com/news/best-pc-games">PC games</a> are affected by any means, with Microsoft noting that reports are coming in from players of <a href="https://www.techradar.com/gaming/arc-raiders-is-a-perfect-mix-of-tension-drama-and-genuinely-human-moments-it-might-just-be-the-best-game-of-2025"><em>Arc Raiders</em></a>, <em>Marvel Tokon: Fighting Souls</em>, and <em>The Finals</em>.</p><p>Microsoft is currently trying to work out what's going on, saying: "Ongoing investigation indicates that this issue is related to peripherals or internal device components which have RGB lighting features. Such devices may install drivers or code components with file names similar to inpoutx64. In systems where these drivers are found, the issue is then triggered by launching certain games."</p><p>Microsoft adds that it's currently trying to "understand the relationship between these RGB components and the games which trigger this issue", and says it will update gamers when more information becomes available.</p><h2 id="analysis-theories-and-workarounds">Analysis: theories and workarounds</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3n5UC4FXvkeedwnALw8aW8" name="arc-raiders-arc-enemy-combat-1" alt="A Raider fires at a distant robotic spider-like enemy in a desert setting" src="https://cdn.mos.cms.futurecdn.net/3n5UC4FXvkeedwnALw8aW8.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Embark)</span></figcaption></figure><p>Microsoft is suggesting that this may be a driver-related issue of some kind, rather than a problem with Windows 11 itself. Of course, changes to Windows 11 could be the root cause, and the company admits that, and says it's still trying to "determine if this is an issue caused by Microsoft" on the release health dashboard.</p><p>As The Register points out, some on <a href="https://www.reddit.com/r/ArcRaiders/comments/1vmm7k3/comment/p3c7in3/" target="_blank">Reddit are theorizing</a> that this bug is to do with "tightened kernel handle validation" which was introduced with the latest patch for Windows 11. Essentially meaning that Microsoft has tightened aspects of security with the August update, and that this is causing driver glitches, ones that were previously ignored, to be picked up (and subsequently crashing games).</p><p>The mentioned driver (inpoutx64) isn't just used in software controlling RGB lighting, but also in some system utilities needing low-level system access (for hardware monitoring, for example, and one such tool is mentioned in the above Reddit post: ZenTimings). It seems that if this driver is present on the host PC, the game's anti-cheat probing it now throws up a problem (post-patch), and that leads to the crash.</p><p>If this bug is causing you grief — and there are a lot of Arc Raiders players out there in that particular boat — there are workarounds that can make the game playable again.</p><p>The first is the most obvious and easiest fix: remove the August update for Windows 11 (or roll back the OS to before it was installed). You can remove an update in Windows Update, in the Update History panel — just find the patch (KB5121003 in this case) and uninstall it. However, bear in mind that you will be without a bunch of security fixes (<a href="https://www.techradar.com/computing/windows/windows-11s-august-update-has-arrived-here-are-3-reasons-to-download-it-including-turbocharged-app-launching">and other features, including faster app launching</a>) if you don't have this update on your PC.</p><p>The other alternative is to remove the problematic driver file, which seemingly won't harm your system (that said, if you do so, it's at your own risk — I haven't tested this). Going by the advice in the above Reddit thread — and <a href="https://www.reddit.com/r/ArcRaiders/comments/1vombsk/embark_has_shared_a_temporary_potentialfix_for/" target="_blank">also from the developer of Arc Raiders</a> (Embark) — what you need to do is open the Command Prompt in Windows 11 by typing <strong>cmd</strong> in the search box, then right-click on Command Prompt and select 'Run as administrator'.</p><p>Once the prompt appears, type the following and press enter:</p><p><strong>sc stop inpoutx64</strong></p><p>Then type this second line and press enter: </p><p><strong>sc delete inpoutx64</strong></p><p>Now close the Command Prompt, open File Explorer, and find the following folder: C:\Windows\System32\drivers.</p><p>In that folder you should see the inpoutx64 file, it may be a SYS or DLL file (or both). Delete any of those files which are present.</p><p>That's the driver removed, and you should now be good to go, and you can still have the August update installed. But as I already noted, proceed at your own risk if you take this route.</p><p>The best bet for now may be to sit tight and wait for the results of Microsoft's investigation, and hopefully we'll hear something soon. However, this could be a somewhat thorny problem to untangle, and it rather sounds like a case of Microsoft dealing with a security issue — one which should be fixed — and that cure causing collateral damage due to driver wonkiness.</p><p>Whatever the case, on social media, a good many PC gamers are blaming Microsoft for this latest gaming-related issue in Windows 11.</p><p>One <a href="https://www.reddit.com/r/pcmasterrace/comments/1vti9ku/comment/p4ts0c4/" target="_blank">Redditor delivers the following barb</a>: "They can't even keep the one thing they had over Linux. If you have to worry about whether or not your games work anyway, why still use Windows?"</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1vti9ku/comment/p4trtpx/" target="_blank">Another observes</a>: "Since 2025 December update till today — EVERY single month the update breaks something! There was no single month without issues."</p><p>There's no shortage of shots fired at Microsoft for monthly update woes, accusations of this being the fault of vibe coding (AI), and threats to <a href="https://www.techradar.com/computing/software/sick-of-microslop-new-linux-distro-could-win-over-windows-11-haters">leave for greener Linux desktop pastures</a>. Business as usual, then.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta smart glasses could soon be banned in cinemas, says UK trade body — but this time it’s more about piracy than privacy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>UK movie theatres considering smart glasses ban</strong></li><li><strong>The ban would be over privacy and piracy concerns</strong></li><li><strong>It's yet another instance of private bans restricting the tech</strong></li></ul><p>Privacy concerns have rocked Meta’s smart glasses business. They’re being ridiculed online as ‘perv glasses,’ and their use is banned in a growing number of spaces. In the UK, this could also <a href="https://www.theguardian.com/technology/2026/aug/20/piracy-fears-prompt-calls-for-ban-on-meta-smart-glasses-in-uk-cinemas">soon include cinemas</a>, though it’s for a very different p-word: piracy.</p><p>The main concern with camera glasses, like the ones Meta produces with its partners Ray-Ban and Oakley, is that people can record in a fairly secretive way. This is an issue for the general public as they don’t know when or if they’re being recorded, and for venues like cinemas and theatres as it allows movies and live shows to be subtly recorded by the audience.</p><p>With a stable enough internet connection, the viewing could even be live-streamed.</p><p>The ban hasn’t taken effect yet, but its consideration is another blow for smart glasses makers and users, who are finding it increasingly difficult to wear their specs because of their spy-camera capabilities.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MnvPPoY5gppgPFZCDqcabY" name="00-hero" alt="Meta Ray-Ban Gen 2" src="https://cdn.mos.cms.futurecdn.net/MnvPPoY5gppgPFZCDqcabY.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Meta)</span></figcaption></figure><p>Meta would argue that recording isn’t covert. There is a light that comes on and stays on while you record. Plus, Meta has taken <a href="https://www.techradar.com/computing/virtual-reality-augmented-reality/meta-just-fixed-a-privacy-vulnerability-with-its-ray-ban-smart-glasses-but-could-cameraless-designs-be-the-better-future" target="_blank">numerous steps</a> to disable recording capabilities if this light is tampered with — either via a simple cover or by fiddling with the hardware.</p><p>However, critics have argued the light is easy to miss if you don’t know to look for it, especially if you're outdoors during the day or in a bright place. </p><p>In a dark theatre or cinema, the recording light would arguably be a lot more noticeable, though the proposed ban would reduce the risk that bad actors sneak through — while also addressing privacy concerns the glasses raise for other patrons, and banning glasses that allow more covert filming.</p><p>Because while Meta is the most well-known smart glasses maker, and so is taking the heaviest share of the backlash, it isn’t the only player in town. Some glasses manufacturers aren't as strict about tackling modders who disable their recording indicator, while others make the indicator even less noticeable or don’t ship with one installed.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="6Typ7nR8ihpXFu4Foo3ggd" name="20260722_165154" alt="Meta Ray-Ban Scriber Optics" src="https://cdn.mos.cms.futurecdn.net/6Typ7nR8ihpXFu4Foo3ggd.jpg" mos="" align="middle" fullscreen="" width="4000" height="2252" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future / Hamish Hector)</span></figcaption></figure><h2 id="going-going-gone">Going, going, gone?</h2><p>Governments have also been considering action against smart glasses; however, we have yet to see much in the way of widespread bans. At this rate, we might not need to.</p><p>The court of public opinion has issued an overwhelmingly negative verdict on smart glasses. The privacy concerns for people wearing the glasses, and for passersby caught in their gaze who never consented to having their life captured by smart specs, </p><p>Even previous champions of the technology I’ve spoken with — journalists like myself who have used and tested, and loved these glasses — have stopped wearing them outside of our reviews. I’ve written before how I’m genuinely fearful I’ll get accosted in the street if I’m caught wearing these glasses.</p><p>Besides the threat of retaliation, the steady banning of these glasses across various venues makes them increasingly useless. That’s doubly true for folks who need prescription glasses — smart glasses bans often say that the glasses having prescription lenses is no excuse, meaning you could spend $500 / £500 / AU$750 plus on a pair of glasses you can’t wear anywhere. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:7741px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iiFqQCft9VRW7S5n7MH75R" name="Ray-Ban Meta - Lifestyle Still6.jpg" alt="The Ray-Ban Meta Smart Glasses Collection is stylish" src="https://cdn.mos.cms.futurecdn.net/iiFqQCft9VRW7S5n7MH75R.jpg" mos="" align="middle" fullscreen="" width="7741" height="4354" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Meta)</span></figcaption></figure><p>Is this the end of smart glasses then? A serious perception overhaul could help, though it’s unclear how that would be achieved without such major software changes or hardware alterations, such as removing the camera altogether — though, from experience, cameraless smart specs don’t impress me. It’s too useful a feature to lose out on.</p><p>To that end, it’s a lose-lose, and that’s a shame for a category I think is quite fun and cool when people aren’t being creeps with them. They’re also proving a handy tool for people with visual impairments as the glasses can see and describe the world for them.</p><p>We’ll have to wait and see what happens, but I expect it’ll continue to be a rocky road ahead for smart glasses.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/p8uFJZJ8pG0" allowfullscreen></iframe></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/virtual-reality-augmented-reality/meta-smart-glasses-could-soon-be-banned-in-cinemas-says-uk-trade-body-but-this-time-its-more-about-piracy-than-privacy</link>
                                                                            <description>
                            <![CDATA[ Movie theatres considering banning Meta Ray-Bans in the UK as businesses beat governments to the punch. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dGhasysWpQunrEbqPDibT4</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XtJ44n9wuV3FPNLm3Mrew8-1280-80.jpg"/>
                                                                        <pubDate>Fri, 21 Aug 2026 02:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Aug 2026 14:20:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Virtual Reality &amp; Augmented Reality]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ hamish.hector@futurenet.com (Hamish Hector) ]]></author>                    <dc:creator><![CDATA[ Hamish Hector ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ePxhxWMJAFXSVFL4333tHB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Hamish is a Senior Staff Writer for TechRadar and you’ll see his name appearing on articles across nearly every topic on the site from smart home deals to speaker reviews to graphics card news and everything in between. He uses his broad range of knowledge to help explain the latest gadgets and if they’re a must-buy or a fad fueled by hype. Though his specialty is writing about everything going on in the world of virtual reality and augmented reality.&lt;/p&gt;&lt;p&gt;He’s been writing about tech and gaming for over five years now, getting his start at the University of Warwick’s student newspaper The Boar as a writer and later Games Editor while studying for his BSc in Maths and Physics (and later an MSc in Biotechnology, Bioprocessing, and Business Management). After graduating from university in 2020 he wrote all about battle royale games for Gfinity Esports before joining the TechRadar team in February 2021.&lt;/p&gt;&lt;p&gt;In his free time, you’ll likely find Hamish lost in one of the latest VR games on his Meta Quest 3, watching a West End musical with his fiancee, playing Magic: The Gathering at his local game store, or planning the D&amp;D campaign he runs for his mates.&lt;/p&gt;&lt;p&gt;Want to get in touch? You can contact Hamish via his email.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XtJ44n9wuV3FPNLm3Mrew8-1280-80.jpg">
                                                            <media:credit><![CDATA[Meta]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[RayBan Meta Smart Glasses]]></media:description>                                                            <media:text><![CDATA[RayBan Meta Smart Glasses]]></media:text>
                                <media:title type="plain"><![CDATA[RayBan Meta Smart Glasses]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XtJ44n9wuV3FPNLm3Mrew8-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>UK movie theatres considering smart glasses ban</strong></li><li><strong>The ban would be over privacy and piracy concerns</strong></li><li><strong>It's yet another instance of private bans restricting the tech</strong></li></ul><p>Privacy concerns have rocked Meta’s smart glasses business. They’re being ridiculed online as ‘perv glasses,’ and their use is banned in a growing number of spaces. In the UK, this could also <a href="https://www.theguardian.com/technology/2026/aug/20/piracy-fears-prompt-calls-for-ban-on-meta-smart-glasses-in-uk-cinemas">soon include cinemas</a>, though it’s for a very different p-word: piracy.</p><p>The main concern with camera glasses, like the ones Meta produces with its partners Ray-Ban and Oakley, is that people can record in a fairly secretive way. This is an issue for the general public as they don’t know when or if they’re being recorded, and for venues like cinemas and theatres as it allows movies and live shows to be subtly recorded by the audience.</p><p>With a stable enough internet connection, the viewing could even be live-streamed.</p><p>The ban hasn’t taken effect yet, but its consideration is another blow for smart glasses makers and users, who are finding it increasingly difficult to wear their specs because of their spy-camera capabilities.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MnvPPoY5gppgPFZCDqcabY" name="00-hero" alt="Meta Ray-Ban Gen 2" src="https://cdn.mos.cms.futurecdn.net/MnvPPoY5gppgPFZCDqcabY.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Meta)</span></figcaption></figure><p>Meta would argue that recording isn’t covert. There is a light that comes on and stays on while you record. Plus, Meta has taken <a href="https://www.techradar.com/computing/virtual-reality-augmented-reality/meta-just-fixed-a-privacy-vulnerability-with-its-ray-ban-smart-glasses-but-could-cameraless-designs-be-the-better-future" target="_blank">numerous steps</a> to disable recording capabilities if this light is tampered with — either via a simple cover or by fiddling with the hardware.</p><p>However, critics have argued the light is easy to miss if you don’t know to look for it, especially if you're outdoors during the day or in a bright place. </p><p>In a dark theatre or cinema, the recording light would arguably be a lot more noticeable, though the proposed ban would reduce the risk that bad actors sneak through — while also addressing privacy concerns the glasses raise for other patrons, and banning glasses that allow more covert filming.</p><p>Because while Meta is the most well-known smart glasses maker, and so is taking the heaviest share of the backlash, it isn’t the only player in town. Some glasses manufacturers aren't as strict about tackling modders who disable their recording indicator, while others make the indicator even less noticeable or don’t ship with one installed.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="6Typ7nR8ihpXFu4Foo3ggd" name="20260722_165154" alt="Meta Ray-Ban Scriber Optics" src="https://cdn.mos.cms.futurecdn.net/6Typ7nR8ihpXFu4Foo3ggd.jpg" mos="" align="middle" fullscreen="" width="4000" height="2252" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future / Hamish Hector)</span></figcaption></figure><h2 id="going-going-gone">Going, going, gone?</h2><p>Governments have also been considering action against smart glasses; however, we have yet to see much in the way of widespread bans. At this rate, we might not need to.</p><p>The court of public opinion has issued an overwhelmingly negative verdict on smart glasses. The privacy concerns for people wearing the glasses, and for passersby caught in their gaze who never consented to having their life captured by smart specs, </p><p>Even previous champions of the technology I’ve spoken with — journalists like myself who have used and tested, and loved these glasses — have stopped wearing them outside of our reviews. I’ve written before how I’m genuinely fearful I’ll get accosted in the street if I’m caught wearing these glasses.</p><p>Besides the threat of retaliation, the steady banning of these glasses across various venues makes them increasingly useless. That’s doubly true for folks who need prescription glasses — smart glasses bans often say that the glasses having prescription lenses is no excuse, meaning you could spend $500 / £500 / AU$750 plus on a pair of glasses you can’t wear anywhere. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:7741px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iiFqQCft9VRW7S5n7MH75R" name="Ray-Ban Meta - Lifestyle Still6.jpg" alt="The Ray-Ban Meta Smart Glasses Collection is stylish" src="https://cdn.mos.cms.futurecdn.net/iiFqQCft9VRW7S5n7MH75R.jpg" mos="" align="middle" fullscreen="" width="7741" height="4354" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Meta)</span></figcaption></figure><p>Is this the end of smart glasses then? A serious perception overhaul could help, though it’s unclear how that would be achieved without such major software changes or hardware alterations, such as removing the camera altogether — though, from experience, cameraless smart specs don’t impress me. It’s too useful a feature to lose out on.</p><p>To that end, it’s a lose-lose, and that’s a shame for a category I think is quite fun and cool when people aren’t being creeps with them. They’re also proving a handy tool for people with visual impairments as the glasses can see and describe the world for them.</p><p>We’ll have to wait and see what happens, but I expect it’ll continue to be a rocky road ahead for smart glasses.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/p8uFJZJ8pG0" allowfullscreen></iframe></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using “evolved” capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale —  “active threat” currently hitting energy, water and agricultural industries ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture</strong></li><li><strong>Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool</strong></li><li><strong>The identity of the attackers is not known</strong></li></ul><p>A joint warning issued by federal agencies has warned that US critical infrastructure is facing an “active threat” in the form of AI-generated malware specifically targeting programmable logic controllers (PLCs).</p><p>PLCs are widely used across the energy, water and agricultural industries to control pumps and monitor systems. The attacks have been labelled as an “evolution” in attacker capabilities, with the AI systems capable of chaining exploitations to gain control of PLCs.</p><p>The warning comes from the National Security Agency (NSA) and FBI, alongside other federal agencies who said in an <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery" target="_blank" rel="nofollow">advisory</a> that, “This is not a theoretical risk — it is an active threat.”</p><h2 id="siemens-s7-series-plcs-under-active-attack">Siemens S7 Series PLCs under active attack</h2><p>The advisory warns that Siemens S7 Series PLCs are the chosen target of this latest campaign with the attackers leveraging “AI-assisted development” in their penetration.</p><p>“Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory warns.</p><p>The identity of the attackers has not been revealed, but critical infrastructure systems are a favorite target of state-sponsored groups looking to scout out potential targets to later cripple water treatment and disrupt energy supplies.</p><p>The hackers are locating vulnerable PLCs using internet scanning platforms and disguising the malware as monitoring tools in order to evade detection. To defend against this attack vector, the advisory said that PLCs should be isolated from the internet, with software updates performed as soon as they become available.</p><p>The advisory said that the attacks are “an evolution in threat actor capabilities,” with the AI generated scripts “dramatically reducing the technical expertise and time required to develop working exploitation scripts and malicious tools.”</p><h2 id="who-has-been-targeting-critical-infrastructure">Who has been targeting critical infrastructure?</h2><p>The US war with Iran has led to a significant increase in attacks against critical infrastructure.</p><p>In July 2026, an <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">attack against the operational technology of 30 Minnesota community water systems</a> showed indications of Iranian involvement. Shortly before the attack CISA updated an advisory warning that Rockwell Automation, Schneider Electric, and Siemens PLCs were under active attack.</p><p>April saw Rockwell Automation/Allen-Bradley-manufactured <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">PLCs were exploited in attacks against water and energy systems</a>, as well as to compromise Government Services and Facilities. </p><p><a href="https://www.techradar.com/pro/security/nsa-warns-that-cybercriminals-are-targeting-this-one-critical-component-that-the-energy-chemical-food-agriculture-and-transportation-sectors-rely-on-heres-what-we-know">Automatic Tank Gauge (ATG) systems have also been hit during attacks</a> targeting energy, chemical, food, agriculture, and transportation industries. These systems were also found to be largely internet-facing, and when compromised could allow attackers to turn off systems designed to monitor fuel levels, temperature and potential leaks.</p><p>Russia has also been involved in targeting critical infrastructure at a global scale. The <a href="https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide">attacks hit broken and poorly configured networking devices</a> such as routers that had passed their End-of-Life (EoL) and were no longer receiving updates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-evolved-capabilities-in-ai-generated-malware-to-hit-us-critical-infrastructure-at-an-unprecedented-scale-active-threat-currently-hitting-energy-water-and-agricultural-industries</link>
                                                                            <description>
                            <![CDATA[ The attackers are exploiting internet-facing Siemens S7 Series programmable logic controllers to scout for potential targets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QDfEDMhpgNJ3K4drrGKAGb</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg"/>
                                                                        <pubDate>Thu, 20 Aug 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/supimol kumying]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:description>                                                            <media:text><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:text>
                                <media:title type="plain"><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture</strong></li><li><strong>Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool</strong></li><li><strong>The identity of the attackers is not known</strong></li></ul><p>A joint warning issued by federal agencies has warned that US critical infrastructure is facing an “active threat” in the form of AI-generated malware specifically targeting programmable logic controllers (PLCs).</p><p>PLCs are widely used across the energy, water and agricultural industries to control pumps and monitor systems. The attacks have been labelled as an “evolution” in attacker capabilities, with the AI systems capable of chaining exploitations to gain control of PLCs.</p><p>The warning comes from the National Security Agency (NSA) and FBI, alongside other federal agencies who said in an <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery" target="_blank" rel="nofollow">advisory</a> that, “This is not a theoretical risk — it is an active threat.”</p><h2 id="siemens-s7-series-plcs-under-active-attack">Siemens S7 Series PLCs under active attack</h2><p>The advisory warns that Siemens S7 Series PLCs are the chosen target of this latest campaign with the attackers leveraging “AI-assisted development” in their penetration.</p><p>“Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory warns.</p><p>The identity of the attackers has not been revealed, but critical infrastructure systems are a favorite target of state-sponsored groups looking to scout out potential targets to later cripple water treatment and disrupt energy supplies.</p><p>The hackers are locating vulnerable PLCs using internet scanning platforms and disguising the malware as monitoring tools in order to evade detection. To defend against this attack vector, the advisory said that PLCs should be isolated from the internet, with software updates performed as soon as they become available.</p><p>The advisory said that the attacks are “an evolution in threat actor capabilities,” with the AI generated scripts “dramatically reducing the technical expertise and time required to develop working exploitation scripts and malicious tools.”</p><h2 id="who-has-been-targeting-critical-infrastructure">Who has been targeting critical infrastructure?</h2><p>The US war with Iran has led to a significant increase in attacks against critical infrastructure.</p><p>In July 2026, an <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">attack against the operational technology of 30 Minnesota community water systems</a> showed indications of Iranian involvement. Shortly before the attack CISA updated an advisory warning that Rockwell Automation, Schneider Electric, and Siemens PLCs were under active attack.</p><p>April saw Rockwell Automation/Allen-Bradley-manufactured <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">PLCs were exploited in attacks against water and energy systems</a>, as well as to compromise Government Services and Facilities. </p><p><a href="https://www.techradar.com/pro/security/nsa-warns-that-cybercriminals-are-targeting-this-one-critical-component-that-the-energy-chemical-food-agriculture-and-transportation-sectors-rely-on-heres-what-we-know">Automatic Tank Gauge (ATG) systems have also been hit during attacks</a> targeting energy, chemical, food, agriculture, and transportation industries. These systems were also found to be largely internet-facing, and when compromised could allow attackers to turn off systems designed to monitor fuel levels, temperature and potential leaks.</p><p>Russia has also been involved in targeting critical infrastructure at a global scale. The <a href="https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide">attacks hit broken and poorly configured networking devices</a> such as routers that had passed their End-of-Life (EoL) and were no longer receiving updates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers pose as ransomware recovery agents, but just go on to steal more from victims ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>GuidePoint observed “Ransom Busters” posing as recovery firms in ransomware incidents</strong></li><li><strong>Group claimed to hack RaaS panels, offering decryption keys for $20K–$60K</strong></li><li><strong>Researchers say it’s likely the same affiliates behind infections, not genuine rescuers</strong></li></ul><p>Ransomware operations have evolved again, and this time around the crooks are pretending to be the good guys.</p><p>Cybersecurity researchers GuidePoint Security were recently brought in to respond to multiple <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks against their clients. In some of those incidents, the victims were also contacted by a group calling themselves “Ransom Busters”, which offered to delete the stolen files from the attackers’ servers, while providing the victims with working decryption keys.</p><p>What made the offer suspicious was the fact that Ransom Busters reached out to the victims before the attackers had gone public. The crooks claimed to have hacked into the admin panels of multiple Ransomware-as-a-Service (RaaS) operations, including DragonForce, Settra, and Anubis, giving them not just insight into who was targeted, but also access to stolen data and the decryption keys.</p><h2 id="just-another-affiliate">Just another affiliate</h2><p>For their services, Ransom Busters ask between $20,000, and $60,000 - however, the researchers are saying this is all a ruse, and that Ransom Busters are, most likely, just affiliates of these ransomware services. Not only that, but they are also most likely the ones who infected these companies with ransomware in the first place.</p><p>They said that both the attackers and Ransom Busters are using the same software, same tactics, and same identifiers, leading to the conclusion that it’s the same group on both ends of the spectrum. </p><p>The good news is that no one seems to have paid Ransom Busters for their offer. The only thing GuidePoint observed was one victim paying the actual ransom demand, rather than the fake recovery firm. That firm, fortunately, did not have its name listed on the leak site, and its files remain secure for now.</p><p>Pretending to be a recovery firm is the next evolutionary step in the life of ransomware. </p><p>In its early days, ransomware was all about encrypting the computers and asking for payment in exchange for the decryption key. When companies responded by building out strong backups, the criminals moved to stealing files and threatening to release them to the public. Soon after, some added Distributed Denial of Service (DDoS) into the mix, blocking not just the back end but also the front-end, in an effort to force a payment.</p><p>Some criminals even called their victims on the phone for further intimidation.</p><p>These days, more and more groups are moving away from encryptors and focus solely on data theft, since it’s cheaper yet equally lucrative.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-pose-as-ransomware-recovery-agents-but-just-go-on-to-steal-more-from-victims</link>
                                                                            <description>
                            <![CDATA[ Ransom Busters are not an actual ransomware recovery firm - they're ransomware affiliates looking to steal your money, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3sbDoKf4V4v9EtMs8LXuvL</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg"/>
                                                                        <pubDate>Thu, 20 Aug 2026 15:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>GuidePoint observed “Ransom Busters” posing as recovery firms in ransomware incidents</strong></li><li><strong>Group claimed to hack RaaS panels, offering decryption keys for $20K–$60K</strong></li><li><strong>Researchers say it’s likely the same affiliates behind infections, not genuine rescuers</strong></li></ul><p>Ransomware operations have evolved again, and this time around the crooks are pretending to be the good guys.</p><p>Cybersecurity researchers GuidePoint Security were recently brought in to respond to multiple <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks against their clients. In some of those incidents, the victims were also contacted by a group calling themselves “Ransom Busters”, which offered to delete the stolen files from the attackers’ servers, while providing the victims with working decryption keys.</p><p>What made the offer suspicious was the fact that Ransom Busters reached out to the victims before the attackers had gone public. The crooks claimed to have hacked into the admin panels of multiple Ransomware-as-a-Service (RaaS) operations, including DragonForce, Settra, and Anubis, giving them not just insight into who was targeted, but also access to stolen data and the decryption keys.</p><h2 id="just-another-affiliate">Just another affiliate</h2><p>For their services, Ransom Busters ask between $20,000, and $60,000 - however, the researchers are saying this is all a ruse, and that Ransom Busters are, most likely, just affiliates of these ransomware services. Not only that, but they are also most likely the ones who infected these companies with ransomware in the first place.</p><p>They said that both the attackers and Ransom Busters are using the same software, same tactics, and same identifiers, leading to the conclusion that it’s the same group on both ends of the spectrum. </p><p>The good news is that no one seems to have paid Ransom Busters for their offer. The only thing GuidePoint observed was one victim paying the actual ransom demand, rather than the fake recovery firm. That firm, fortunately, did not have its name listed on the leak site, and its files remain secure for now.</p><p>Pretending to be a recovery firm is the next evolutionary step in the life of ransomware. </p><p>In its early days, ransomware was all about encrypting the computers and asking for payment in exchange for the decryption key. When companies responded by building out strong backups, the criminals moved to stealing files and threatening to release them to the public. Soon after, some added Distributed Denial of Service (DDoS) into the mix, blocking not just the back end but also the front-end, in an effort to force a payment.</p><p>Some criminals even called their victims on the phone for further intimidation.</p><p>These days, more and more groups are moving away from encryptors and focus solely on data theft, since it’s cheaper yet equally lucrative.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 11 is getting a much-needed change to privacy settings — but it's something Microsoft should have sorted a long time ago ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Windows 11 is getting per-app permissions for all desktop software</strong></li><li><strong>Previously this was limited to just apps from the Microsoft Store</strong></li><li><strong>Microsoft has also decided to drop an incoming interface addition called the drag tray, which had drawn complaints from some testers</strong></li></ul><p>Windows 11 is finally giving you a full range of options to <a href="https://www.techradar.com/computing/windows/windows-11-could-soon-get-a-nifty-new-privacy-feature-that-tells-you-when-people-are-sneakily-looking-at-your-laptop-screen">maintain your privacy</a> from potentially snooping apps, and the OS is being further improved as Microsoft is scrapping an unpopular addition for the interface which was in testing.</p><p>First up, let's look at the privacy move, which as <a href="https://www.windowslatest.com/2026/08/19/windows-11-is-getting-a-major-privacy-upgrade-blocks-apps-spying-on-your-camera-and-mic-with-new-controls/" target="_blank">Windows Latest reports</a> is the expansion of individual privacy controls for apps in Windows 11. This was first highlighted by <a href="https://x.com/jakub25050/status/2089676224197013705" target="_blank">Jakub on X</a>, who noted: "Huge changes are coming to Windows 11 privacy & security. In the latest Experimental Insider Build (26340.9212) you can now revoke access to the camera & microphone for specific Win32 apps!"</p><p>What this means is that in Settings you can allow or deny access to the camera and mic (as well as location access) for desktop apps on an individual basis. Couldn't you do that before, I hear you ask. Only for Microsoft Store apps, with other (Win32) applications having just one 'master switch' to either toggle all these permissions on or off (on a blanket basis).</p><p>Thankfully, in a new experimental test build of Windows 11, Microsoft has changed things so you have granular privacy controls over all apps, not just Microsoft Store software.</p><p>On top of that, testers are seeing smartphone-style app permission prompts for allowing access to the camera and mic, which is a feature <a href="https://www.techradar.com/computing/windows/these-updates-raise-the-bar-for-security-and-privacy-on-windows-microsoft-has-a-plan-to-toughen-up-windows-11s-defenses">Microsoft has said it's bringing in before</a>.</p><p><a href="https://www.windowslatest.com/2026/08/20/microsoft-is-killing-the-windows-11-feature-that-hijacked-your-drag-and-drop-its-called-drag-tray/" target="_blank">Windows Latest also noticed</a> that Microsoft has officially canned the drag tray, which was a new part of the interface in testing with Windows 11.</p><p>The idea here is that when you grabbed and dragged a file on the desktop, this tray would appear at the top of the screen, and if you moused the file over it, you'd get some quick sharing options (so you could simply drop the file to share via WhatsApp, or Outlook, or a bunch of other icons).</p><p>Tthe drag tray could be handy for users with a touchscreen, for example, as an easier method than going by the right-click menu sharing options. So, what was wrong with this feature?</p><p>The problem was for those users with busier desktops, perhaps crowded with folders, because in these situations — or when using a maximized folder window filling the display — if a file was dragged towards the top of the screen, the tray might appear and get in the way of the target folder (effectively blocking it).</p><p>These frustrations led to some complaints, and Microsoft has ultimately decided to drop the tray. </p><p>In the notes for the most recent Windows 11 preview build in the Experimental channel, <a href="https://learn.microsoft.com/en-us/windows-insider/release-notes/experimental-26-h1/preview-build-28120-2738#accessibility:~:text=%5B-,Drag%20Tray,-%5D" target="_blank">Microsoft told us</a>: "Thank you to Insiders who have provided feedback about the Drag Tray experience. Based on feedback, we're removing the experience in this build. We're continuing to explore improvements in this area and look forward to sharing more about a future replacement experience in a later update."</p><h2 id="analysis-a-real-drag">Analysis: a real drag</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6A3hkaPar4GTyXk5hM4Cnd" name="Microsoft laptop Surface Unsplash.jpg" alt="A person using a touchscreen Windows 11 laptop." src="https://cdn.mos.cms.futurecdn.net/6A3hkaPar4GTyXk5hM4Cnd.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Surface/Unsplash)</span></figcaption></figure><p>The drag tray had to go, then, at least in its current implementation, but as Microsoft noted, this isn't necessarily the end of the road for this concept. It may be brought back to testing in a different incarnation, and indeed that sounds like the plan here, so I'll be keeping an eye out for the feature's reemergence at some point.</p><p>As for the privacy options, this is a very welcome move, as it's pretty important to be able to pick and choose which apps have what permissions. The only real question here is: why wasn't this the case in the first place? Granted, there are technical reasons why it's a good deal trickier to implement a per-app system like this for Win32 software compared to applications from the Microsoft Store. However, it isn't like this was something Microsoft couldn't solve – clearly, as it's being done now.</p><p>There might be quite a lot of work involved, but really, that isn't an excuse, and this is another one of those long overdue changes for Windows 11. A bit like the streamlining and <a href="https://www.techradar.com/computing/windows/microsoft-is-massively-improving-windows-11s-right-click-menu-but-it-should-have-been-like-this-from-the-start">new customization options for the right-click (context) menu</a> in the OS, although admittedly that was a good deal more urgent. At any rate, at least both these changes are happening now, although this per-app privacy system is still in testing, and could end up looking somewhat different by the time it reaches release.</p><p>All of this is part of <a href="https://www.techradar.com/computing/how-i-think-microsofts-campaign-to-fix-windows-11-is-going-so-far-the-verdict-now-were-3-months-in">Microsoft's drive to fix Windows 11</a> while introducing a host of crowd-pleasing features that have long been requested, such as that context menu change. Note that the drag tray never actually arrived in the full release version of Windows 11, just to make that clear – it was only ever in testing, showing that not everything in preview makes the cut by any means.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/windows/windows-11-is-getting-a-much-needed-change-to-privacy-settings-but-its-something-microsoft-shouldve-sorted-a-long-time-ago</link>
                                                                            <description>
                            <![CDATA[ Microsoft is finally changing app permissions to make sense for all software. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hLabaCrBECvDvuVj84TdsD</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vH3uAMdVXGozQL59FQf8gm-1280-80.jpg"/>
                                                                        <pubDate>Thu, 20 Aug 2026 14:30:34 +0000</pubDate>                                                                                                                                <updated>Thu, 20 Aug 2026 22:34:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darren Allan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vH3uAMdVXGozQL59FQf8gm-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up of webcam on MSI Prestige 14 Flip AI+, with pink wall in background]]></media:description>                                                            <media:text><![CDATA[Close-up of webcam on MSI Prestige 14 Flip AI+, with pink wall in background]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up of webcam on MSI Prestige 14 Flip AI+, with pink wall in background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vH3uAMdVXGozQL59FQf8gm-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>Windows 11 is getting per-app permissions for all desktop software</strong></li><li><strong>Previously this was limited to just apps from the Microsoft Store</strong></li><li><strong>Microsoft has also decided to drop an incoming interface addition called the drag tray, which had drawn complaints from some testers</strong></li></ul><p>Windows 11 is finally giving you a full range of options to <a href="https://www.techradar.com/computing/windows/windows-11-could-soon-get-a-nifty-new-privacy-feature-that-tells-you-when-people-are-sneakily-looking-at-your-laptop-screen">maintain your privacy</a> from potentially snooping apps, and the OS is being further improved as Microsoft is scrapping an unpopular addition for the interface which was in testing.</p><p>First up, let's look at the privacy move, which as <a href="https://www.windowslatest.com/2026/08/19/windows-11-is-getting-a-major-privacy-upgrade-blocks-apps-spying-on-your-camera-and-mic-with-new-controls/" target="_blank">Windows Latest reports</a> is the expansion of individual privacy controls for apps in Windows 11. This was first highlighted by <a href="https://x.com/jakub25050/status/2089676224197013705" target="_blank">Jakub on X</a>, who noted: "Huge changes are coming to Windows 11 privacy & security. In the latest Experimental Insider Build (26340.9212) you can now revoke access to the camera & microphone for specific Win32 apps!"</p><p>What this means is that in Settings you can allow or deny access to the camera and mic (as well as location access) for desktop apps on an individual basis. Couldn't you do that before, I hear you ask. Only for Microsoft Store apps, with other (Win32) applications having just one 'master switch' to either toggle all these permissions on or off (on a blanket basis).</p><p>Thankfully, in a new experimental test build of Windows 11, Microsoft has changed things so you have granular privacy controls over all apps, not just Microsoft Store software.</p><p>On top of that, testers are seeing smartphone-style app permission prompts for allowing access to the camera and mic, which is a feature <a href="https://www.techradar.com/computing/windows/these-updates-raise-the-bar-for-security-and-privacy-on-windows-microsoft-has-a-plan-to-toughen-up-windows-11s-defenses">Microsoft has said it's bringing in before</a>.</p><p><a href="https://www.windowslatest.com/2026/08/20/microsoft-is-killing-the-windows-11-feature-that-hijacked-your-drag-and-drop-its-called-drag-tray/" target="_blank">Windows Latest also noticed</a> that Microsoft has officially canned the drag tray, which was a new part of the interface in testing with Windows 11.</p><p>The idea here is that when you grabbed and dragged a file on the desktop, this tray would appear at the top of the screen, and if you moused the file over it, you'd get some quick sharing options (so you could simply drop the file to share via WhatsApp, or Outlook, or a bunch of other icons).</p><p>Tthe drag tray could be handy for users with a touchscreen, for example, as an easier method than going by the right-click menu sharing options. So, what was wrong with this feature?</p><p>The problem was for those users with busier desktops, perhaps crowded with folders, because in these situations — or when using a maximized folder window filling the display — if a file was dragged towards the top of the screen, the tray might appear and get in the way of the target folder (effectively blocking it).</p><p>These frustrations led to some complaints, and Microsoft has ultimately decided to drop the tray. </p><p>In the notes for the most recent Windows 11 preview build in the Experimental channel, <a href="https://learn.microsoft.com/en-us/windows-insider/release-notes/experimental-26-h1/preview-build-28120-2738#accessibility:~:text=%5B-,Drag%20Tray,-%5D" target="_blank">Microsoft told us</a>: "Thank you to Insiders who have provided feedback about the Drag Tray experience. Based on feedback, we're removing the experience in this build. We're continuing to explore improvements in this area and look forward to sharing more about a future replacement experience in a later update."</p><h2 id="analysis-a-real-drag">Analysis: a real drag</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6A3hkaPar4GTyXk5hM4Cnd" name="Microsoft laptop Surface Unsplash.jpg" alt="A person using a touchscreen Windows 11 laptop." src="https://cdn.mos.cms.futurecdn.net/6A3hkaPar4GTyXk5hM4Cnd.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Surface/Unsplash)</span></figcaption></figure><p>The drag tray had to go, then, at least in its current implementation, but as Microsoft noted, this isn't necessarily the end of the road for this concept. It may be brought back to testing in a different incarnation, and indeed that sounds like the plan here, so I'll be keeping an eye out for the feature's reemergence at some point.</p><p>As for the privacy options, this is a very welcome move, as it's pretty important to be able to pick and choose which apps have what permissions. The only real question here is: why wasn't this the case in the first place? Granted, there are technical reasons why it's a good deal trickier to implement a per-app system like this for Win32 software compared to applications from the Microsoft Store. However, it isn't like this was something Microsoft couldn't solve – clearly, as it's being done now.</p><p>There might be quite a lot of work involved, but really, that isn't an excuse, and this is another one of those long overdue changes for Windows 11. A bit like the streamlining and <a href="https://www.techradar.com/computing/windows/microsoft-is-massively-improving-windows-11s-right-click-menu-but-it-should-have-been-like-this-from-the-start">new customization options for the right-click (context) menu</a> in the OS, although admittedly that was a good deal more urgent. At any rate, at least both these changes are happening now, although this per-app privacy system is still in testing, and could end up looking somewhat different by the time it reaches release.</p><p>All of this is part of <a href="https://www.techradar.com/computing/how-i-think-microsofts-campaign-to-fix-windows-11-is-going-so-far-the-verdict-now-were-3-months-in">Microsoft's drive to fix Windows 11</a> while introducing a host of crowd-pleasing features that have long been requested, such as that context menu change. Note that the drag tray never actually arrived in the full release version of Windows 11, just to make that clear – it was only ever in testing, showing that not everything in preview makes the cut by any means.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Healthtech firm CareCloud reveals March 2026 data breach impacted 3.7 million patients ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CareCloud confirmed March 16 2026 cyberattack exposed data of 3.7 million individuals</strong></li><li><strong>Attackers accessed one AWS environment, stealing personal records including names</strong></li><li><strong>Incident deemed non‑material but may incur remediation, legal, and reputational costs</strong></li></ul><p>The <a href="https://www.techradar.com/pro/security/healthcare-tech-firm-carecloud-admits-data-breach-says-hackers-accessed-patient-info-heres-what-we-know" target="_blank">March 2026 cyberattack on CareCloud</a> exposed sensitive data on 3.7 million people, the company has confirmed.</p><p>The American <a href="https://www.techradar.com/best/best-electronic-health-record-ehr-software" target="_blank">IT healthcare</a> company had told the US Securities and Exchange Commission (SEC) it experienced a “temporary network disruption” in its Health division which “partially impacted the functionality and data access to one of six electronic health record environments for approximately eight hours."</p><p>Initial investigation determined that the criminals accessed people’s personal records, but it was not said how many people were affected, what the nature of the files were, or if they were exfiltrated or just exposed.</p><h2 id="notifying-the-department-of-health">Notifying the Department of Health</h2><p>In late July 2026, the company started notifying its customers of the incident, saying the unidentified actors accessed one of CareCloud’s AWS environments and claimed to have stolen files found there. The company did not say which type of data was taken, other than people’s full names. </p><p>In a separate report with the US Department of Health and Human Services, the company confirmed the exact number of affected individuals as 3,756,469.</p><p>At press time, no hacking groups claimed responsibility for the attack, or shared details about the volume, nature, and type of data potentially stolen.</p><p>CareCloud is a publicly traded American healthcare technology firm providing <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud‑based software</a> and services to medical practices and health systems, including electronic health records (EHR), practice management, billing and revenue cycle solutions. It works with tens of thousands of healthcare providers across the United States in more than 70 specialties and across all 50 states, with over 40,000 providers on its platform.</p><p>In its initial report with the SEC, CareCloud said the incident did not have a material impact, but that it might incur expenses in remediation and response costs, legal, regulatory and notification-related matters, and could possibly affect patients, customers, counterparties, reputation and operations.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/healthtech-firm-carecloud-reveals-march-2026-data-breach-impacted-3-7-million-patients</link>
                                                                            <description>
                            <![CDATA[ Impacted CareCloud patients are being notified, but we don't know what information was taken. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YbMtuDcty3QHXHSSBtvpj7</guid>
                                                                                                <enclosure length="0" type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg"/>
                                                                        <pubDate>Thu, 20 Aug 2026 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg">
                                                            <media:credit><![CDATA[Rawpixel / Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[healthcare]]></media:description>                                                            <media:text><![CDATA[healthcare]]></media:text>
                                <media:title type="plain"><![CDATA[healthcare]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg"/>
                                                                                                                                                                    <content:encoded>
                            <![CDATA[
                            <article>
                                <ul><li><strong>CareCloud confirmed March 16 2026 cyberattack exposed data of 3.7 million individuals</strong></li><li><strong>Attackers accessed one AWS environment, stealing personal records including names</strong></li><li><strong>Incident deemed non‑material but may incur remediation, legal, and reputational costs</strong></li></ul><p>The <a href="https://www.techradar.com/pro/security/healthcare-tech-firm-carecloud-admits-data-breach-says-hackers-accessed-patient-info-heres-what-we-know" target="_blank">March 2026 cyberattack on CareCloud</a> exposed sensitive data on 3.7 million people, the company has confirmed.</p><p>The American <a href="https://www.techradar.com/best/best-electronic-health-record-ehr-software" target="_blank">IT healthcare</a> company had told the US Securities and Exchange Commission (SEC) it experienced a “temporary network disruption” in its Health division which “partially impacted the functionality and data access to one of six electronic health record environments for approximately eight hours."</p><p>Initial investigation determined that the criminals accessed people’s personal records, but it was not said how many people were affected, what the nature of the files were, or if they were exfiltrated or just exposed.</p><h2 id="notifying-the-department-of-health">Notifying the Department of Health</h2><p>In late July 2026, the company started notifying its customers of the incident, saying the unidentified actors accessed one of CareCloud’s AWS environments and claimed to have stolen files found there. The company did not say which type of data was taken, other than people’s full names. </p><p>In a separate report with the US Department of Health and Human Services, the company confirmed the exact number of affected individuals as 3,756,469.</p><p>At press time, no hacking groups claimed responsibility for the attack, or shared details about the volume, nature, and type of data potentially stolen.</p><p>CareCloud is a publicly traded American healthcare technology firm providing <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud‑based software</a> and services to medical practices and health systems, including electronic health records (EHR), practice management, billing and revenue cycle solutions. It works with tens of thousands of healthcare providers across the United States in more than 70 specialties and across all 50 states, with over 40,000 providers on its platform.</p><p>In its initial report with the SEC, CareCloud said the incident did not have a material impact, but that it might incur expenses in remediation and response costs, legal, regulatory and notification-related matters, and could possibly affect patients, customers, counterparties, reputation and operations.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>