❌

Normal view

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

12 August 2026 at 13:40
The UK's criminal records office, ACRO, has escaped a fine and received a regulatory reprimand after security failings potentially exposed highly sensitive data belonging to nearly 11,000 people. ACRO disclosed the "cybersecurity incident" in April 2023, and said at the time that it had no evidence to suggest that any data was compromised. However, it has now emerged that attackers maintained persistent access to ACRO's website and content management system for more than seven months, and staged sensitive data for possible exfiltration. According to the Information Commissioner's Office (ICO), which reprimanded ACRO rather than imposing a financial penalty, the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion. The watchdog said that while investigating an SQL injection attack that compromised 15 sets of credentials, most belonging to ACRO staff, investigators found evidence of separate intrusions dating back to July 8, 2021. The incidents fell into three categories, the ICO said. Some did not affect personal data, while others exposed only a small number of account credentials. The most serious involved ACRO's website and its Kentico content management system. The intrusion began on August 5, 2022, and the attackers maintained persistent access, without being detected, until March 14, 2023. The ICO found that ACRO ran version 12.0.0 of Kentico CMS from September 2019 until March 2023 without applying the patches and hotfixes released during that period, leaving known vulnerabilities unresolved. The ICO blamed poor communication between ACRO and its managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume that it was not required to monitor actively for security updates. "The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable," the ICO said. Further, ACRO did not have a documented policy that covered patching Kentico CMS, nor could it demonstrate how vulnerabilities were identified or prioritized. ACRO's Trend Micro antivirus generated alerts, but nobody appears to have been minding them. The records office told the ICO that, for reasons redacted from the postmortem, it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time." It also could not identify which roles were responsible for reviewing these alerts at the time, ultimately resulting in them going unread. ACRO's poor logging means that, despite an extensive investigation by a third-party cybersecurity outfit, it remains impossible to determine whether the affected data was exfiltrated. Investigators did establish that the attackers staged the data for possible exfiltration between February 15 and 16, 2023. The potentially exposed material included: Police Certificate Applications Subject Access Request (SAR) forms and International Child Protection Certificate forms Names Dates of birth Addresses National Insurance numbers Passport and driving licence details Bank account information Biometric data Highly sensitive criminal offence and special category information ACRO notified 84,048 people of the breach, although investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration. Of these, ACRO received 35 formal complaints citing personal distress and concern about the risk of identity theft and financial loss, according to the ICO's reprimand document [PDF]. "Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence." The ICO also received six complaints citing similar concerns. ACRO's saving grace was its network segmentation, which prevented the attackers from straying beyond the CMS into other systems, the ICO noted. Since the attack was discovered, ACRO has made a number of improvements to its security, including decommissioning the compromised infrastructure (although not until June 2023), implementing a SIEM, improving visibility, monitoring, and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud. Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information. "Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly. "The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology. "We welcome the improvements ACRO has made since these incidents. We hope other organizations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected." ACRO welcomed the reprimand from the ICO and highlighted the steps it has taken since to bolster its security. A spokesperson told The Register: "Since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards. "In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage." They went on to say: "We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future." ®

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

12 August 2026 at 13:00
An Akira ransomware affiliate rebooted a victim’s computer into Safe Mode to kill its security tools – and in the process sabotaged their own malware when the limited-function startup mode also broke their encryptor. “Akira's encryptor is engineered for speed, relying on concurrent worker threads and heavy memory mapping rather than simple sequential read-and-write operations. That high-performance design is likely what caused it to break in Safe Mode,” Huntress security operations analyst James Northey told The Register. “Safe Mode loads a minimal driver set, which can restrict storage controllers and pagefile availability,” he added. “A heavy, multi-threaded encryptor strains that constrained environment far more than the lighter, streamed-I/O designs used by other ransomware families.” But the ending wasn't entirely happy for the victim. The attacker had already stolen credentials and data from file shares before Safe Mode prevented the ransomware from doing its job. Northey detailed the incident in a Wednesday blog and cautioned that this was more likely a memory-configuration issue, and shouldn't be taken as a practical defense to prevent Akira ransomware from locking up valuable files. “Ultimately this could be a case of winning the battle, but not the war,” Northey wrote. “It’s possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode,” Northey added. “Akira’s developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.” Nonetheless, there's one big lesson here: For the love of all that is holy, turn on multi-factor authentication (MFA). Here’s a closer look at what happened, and how to prevent it from happening to you. How it started… In early August, Huntress responded to an incident that began, as most Akira intrusions do, with a SonicWall SSL VPN. On August 4, the VPN logged a credential-spray attack: a burst of failed logins using bad credentials that it denied. But then, seven minutes later, one of them succeeded when the attacker used a valid VPN account that wasn’t protected by MFA. Once they had gained access, the criminal accessed the domain controller via Remote Desktop Protocol (RDP) and queried Active Directory to hoover up detailed information about the network, users, groups, computers – essentially everything an attacker needs to know about who and what to target for lateral movement and mass encryption in a ransomware attack. “The enumeration was a full-property dump of every user and every computer in the domain,” Northey wrote. The Akira ransomware affiliate then moved to the application server to start collecting stolen data, downloading WinRAR and using that tool to archive mapped file shares before sending the stolen data to cloud storage using s5cmd, a fast S3 transfer utility. They also installed remote desktop software AnyDesk, configured to start with Windows, and abused this legitimate tool as a remote-access trojan, giving the attacker hands-on keyboard control. They also used it as a command-and-control channel to drop more malware, including the very cleverly named akira.exe ransomware binary – because no one would guess what that executable could be, right? Then came the Safe Mode reboot Here’s where things went sideways for the ransomware scumbag. About three hours into the intrusion, the attacker forced the computer to reboot into Safe Mode with Networking, a boot mode that only loads essential drivers and services, blocking most third-party software. Attackers, especially ransomware gangs, do this to disable endpoint detection and response products and other security tools that would otherwise detect and stop their malware from infecting victims’ machines. While some ransomware crews, including Snatch and AvosLocker, have abused Safe Mode for this purpose for years, Huntress has never seen Akira do it until now. In this case, the reboot stopped the Huntress agent and disabled Microsoft Defender's real-time protection, preventing Defender from quarantining the malicious file. “The attacker got their blind window,” Northey wrote. “What they didn't get was a clean detonation.” Thirteen seconds after the reboot, the computer started spewing memory errors. Safe Mode boots with constrained virtual memory, and it didn’t have sufficient memory to encrypt the endpoint. Essentially, Safe Mode not only acted as an EDR killer, but also borked the ransomware. In addition to the obvious recommendations – like make sure you receive alerts on bursts of failed VPN logins against multiple usernames from one source, and require MFA on every VPN account – Huntress suggests organizations keep an eye out for this Safe Mode play. Specifically, “alert on boot-configuration changes and Safe Mode boots: msconfig.exe / bcdedit activity, Kernel-Boot EID 27 with a SAFEBOOT load option, Kernel-General EID 12 BootMode=2, and third-party security services stopping (System EID 7036),” Northey wrote. Also, “watch for tooling being added to the Safe Mode minimal-service registry list.” ®

GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found

12 August 2026 at 12:00

Millions of gamers are counting down the days until this fall’s biggest releases. 

After more than a decade of anticipation, Grand Theft Auto VI is finally set to launch this November. Surprise indie hit Meccha Chameleon has exploded across Twitch and YouTube after selling millions of copies within days. And highly anticipated titles like Call of Duty: Modern Warfare 4, Minecraft Dungeons 2, Phantom Blade Zero, Marvel’s Wolverine, and dozens of others are keeping players glued to trailers, wishlists, Discord servers, and preorder pages. 

Scammers are watching those trends. 

Whenever millions of people rush to search for the same game, criminals quickly create fake downloads, unofficial mobile apps and servers, counterfeit storefronts, phishing pages, and cheat tools designed to steal money, credentials, or personal information. 

This year is no exception. 

Here’s how scammers are taking advantage of 2026’s biggest gaming moments, and how you can avoid becoming their next target, according to McAfee’s experts: 

The Most Common Gaming Scams and How to Avoid Them, According to McAfee 

Most gaming scams fall into a handful of predictable categories. Once you know what to look for, they’re much easier to spot. 

Here are some of the most common scams McAfee protection prevents 

Scam  What it looks like  Red flags  How to protect yourself 
Fake game downloads  “Free” copies, cracked launchers, unofficial installers  Unknown websites, requests to disable antivirus, ZIP files instead of official installers  Download games only from official publishers or trusted storefronts 
Fake early access  Too-good-to-be-true VIP access, beta invites, playable versions before launch that don’t exist   Cryptocurrency payments, countdown timers, “exclusive” offers, unofficial websites  Verify release dates , including early access dates, and preorder information directly with the publisher 
Cheats, mods, and trainers  Unlimited money, aimbots, unlock tools, auto-play software  Downloads shared through Discord, YouTube descriptions, file-sharing sites  Only use trusted community repositories and avoid executable files from unknown sources 
Fake mobile versions  Mobile apps for games that don’t officially exist on Android or iPhone  Different developer names, excessive ads, cloned screenshots  Confirm that the developer has actually released a mobile version before downloading 
YouTube and Discord scams  Videos claiming to have mods or secret builds  Shortened links, pinned download comments, Discord invite links  Visit the developer’s official website instead of getting mods or clicking links from comments or descriptions 
Fake giveaways and free skins  Free cosmetics, DLC, battle passes, or gift cards  Requests to sign in through third-party sites or enter account credentials  Only redeem offers through official game platforms 

 These tactics aren’t theoretical. They’re happening right now. 

Detected by McAfee Labs: Malware Campaigns, Malicious Downloads, and Suspicious Apps 

Earlier this year, McAfee Labs uncovered WeedHack, a malware campaign disguised as free Minecraft mods and game clients.  

Since January 2026, the campaign has infected more than 116,000 devices, averaging roughly 2,000 to 3,000 new infections every day. Attackers lured players through fake mod websites and convincing YouTube videos before installing malware capable of stealing passwords, cryptocurrency wallets, Discord credentials, Minecraft accounts, and more.  

Ultimately these gaming attacks can expose players to: 

  • Malware infections  
  • Account theft  
  • Password theft  
  • Data breaches  
  • Spyware monitoring cameras and microphones 
  • Spyware monitoring keyboard and mouse inputs 
  • Permanent game bans  

One of the campaign’s most concerning findings wasn’t just the malware itself, it was how inexpensive and accessible the tools had become. The malware was marketed almost like legitimate software, lowering the barrier for inexperienced attackers and helping spread scams throughout gaming communities. 

The lesson isn’t to avoid every cheat, unlock, or community-created project. It’s to be skeptical whenever someone promises something that seems too good to be true. 

Meccha Chameleon Shows How Quickly Scammers Embrace Viral Games 

Few people predicted Meccha Chameleon would become one of the biggest surprise gaming success stories of the year. 

The inexpensive indie title reportedly sold more than two million copies within days, fueled largely by livestreams, social media clips, and word of mouth. Unfortunately, that kind of overnight success doesn’t just attract new players. 

According to PC Gamer, players have already begun using automated “auto-paint” cheats that scan the environment and instantly camouflage characters, removing much of the creativity and skill the game was designed around. 

The game’s popularity has also created confusion about where players can safely download it. 

McAfee researchers recently identified multiple Android apps and an unofficial piracy site using the Meccha Chameleon name, despite the game’s independent developer not announcing an official Android release.  

Here’s how we saw it play out 

First a gamer might navigate to this piracy site to download a free game. The game may not come with malware, but malware is still distributed during the process. 

An example of fake steam Meccha Chameleon

Here we see steamgg[.]net, a piracy site to download free games. Here you see they offer a download of Meccha Chameleon (not malicious).

But when you click download, it opens a misleading new tab like this one below.

A popup claiming your download is ready

This new tab tricks the user into thinking they are downloading a game from steamgg[.]net. They are actually being redirected to a completely unrelated download.

In cases like this, unauthorized sites and apps trick users into giving unwanted access to their information and devices.

 

Google Play store apps showing Meccha Chameleon
Here we see examples of fake versions of Meccha Chameleon uploaded to the Google Play Store 

*Note: The unauthorized apps shown here have since been reported and taken down. While not confirmed to be malicious, hundreds of people had already downloaded and given security permissions to these apps.* 

“Repackaged or unauthorized apps and sites are a major risk with viral games,” says McAfee Threat Researcher and lifelong gamer Charles McFarland.  

“Because many players are unfamiliar with the original developer, it’s easier for unauthorized apps and copycat listings to blend into app stores,” McFarland explains. “Once installed, the app can have free access to your phone’s data, texts, contacts, and more.” 

Before downloading a newly popular game, especially on mobile, take a moment to verify that the developer has actually released it for your device. 

Is This GTA 6 Download Legit? How to Spot Fake Early Access Scams 

If there’s one game scammers are betting people will search for this fall, it’s Grand Theft Auto VI. 

Rockstar Games officially opened global preorders on June 25, and the game launches worldwide on November 19, 2026 for PlayStation 5 and Xbox Series X|S. Digital preorders can begin preloading on November 12. 

That hasn’t stopped scammers from advertising: 

  • “Play GTA 6 today”  
  • VIP Early Access  
  • Secret beta downloads  
  • Discounted preorder keys  
  • Cryptocurrency-only purchases  
  • “Exclusive” launchers 

The problem?  Those offers promise something Rockstar isn’t selling. 

If a website claims it can provide a playable version of GTA 6 before Rockstar’s official launch, treat it as a major warning sign. 

Scammers know players have waited more than a decade for the next Grand Theft Auto. They’re counting on excitement to outweigh skepticism. 

“Every major game launch brings a noticeable increase in gaming-themed scams. We regularly see McAfee protecting customers from malicious downloads, fake websites, and other threats that capitalize on the excitement around new releases,” McFarland says. 

“As a gamer myself, I know the excitement of jumping into a long-awaited game with my son, but it’s worth taking an extra minute to download from an official or authorized source instead of rushing to be first.” 

Whenever possible, verify preorder information directly through Rockstar Games or trusted digital storefronts rather than clicking links shared through social media posts, livestream chats, YouTube comments, or unsolicited messages and advertisements. 

Official storefront  Trending and Upcoming Games 
Steam  Meccha Chameleon, Dune: Awakening, Metal Gear Solid: Master Collection Vol. 2, Silent Hill: Townfall, Call of Duty: Modern Warfare 4, Phantom Blade Zero, No Rest for the Wicked, Planet Zoo 2, Kingdom Hearts Collections, Ace Combat 8, Gears of War: E-Day (PC), Minecraft Dungeons 2 and many other PC releases 
PlayStation Store  Grand Theft Auto VI, Marvel’s Wolverine, Phantom Blade Zero, Onimusha: Way of the Sword, Metal Gear Solid: Master Collection Vol. 2, Call of Duty: Modern Warfare 4, Dune: Awakening, Silent Hill: Townfall and other PlayStation releases 
Xbox Store  Grand Theft Auto VI, Gears of War: E-Day, Call of Duty: Modern Warfare 4, Dune: Awakening, Ace Combat 8, Kingdom Hearts Collections and other Xbox releases 
Nintendo eShop  Rhythm Heaven Groove, Splatoon Raiders, Fire Emblem: Fortune’s Weave, Harvest Moon: Echoes of Teradea, Nintendo Switch Sports Resort, The Legend of Zelda: Ocarina of Time Remake and other Nintendo titles 

 *Availability may vary by platform as publishers announce additional releases. 

If you can’t find a game on one of its official storefronts, that’s a good reason to pause before downloading it elsewhere. 

How McAfee Protects Gamers 

Gaming should be about exploring new worlds, not accidentally downloading malware. 

McAfee helps protect players before, during, and after they click. 

Web Protection helps block known malicious websites before fake downloads ever reach your device. 

Award-winning antivirus detects and blocks malware hidden inside suspicious installers, cheats, and unofficial software. 

If a file is flagged, Threat Explainer provides a clear, plain-language explanation of why it’s considered risky, helping you make informed decisions instead of guessing whether a warning is legitimate. 

And if you’re worried additional security will slow down your games, McAfee Total Protection has repeatedly scored first place in the AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance.  

McAfee earned the lowest overall impact score among the 20 products tested and received the highest possible rating, 3 Stars ADVANCED+. In other words, you get strong protection without sacrificing performance or slowing your game. 

Whether you’re preordering GTA 6, trying the latest indie hit, or installing a new Minecraft mod, slowing down long enough to verify where you’re downloading from remains one of the simplest, and most effective, ways to protect yourself. 

Frequently Asked Questions 

FAQs 
Q: Is GTA 6 early access real?

A: No. Rockstar Games has announced pre-orders and pre-loading ahead of launch, but there is no legitimate way to play GTA 6 early through unofficial websites. Be wary of any site claiming to sell “VIP access,” beta keys, or downloadable copies before the official release date. 

Q: Is it safe to pre-order GTA 6 from any website?

A: Stick to Rockstar Games or authorized retailers and digital storefronts like the PlayStation Store and Xbox Store. Avoid unfamiliar websites advertising deep discounts, exclusive editions, or cryptocurrency-only payments. 

Q: Does Meccha Chameleon have an official Android or iPhone app?

A: At the time of writing, the game’s developer has not announced an official mobile version. If you find Meccha Chameleon in an app store, verify that it’s published by the official developer before downloading. 

Q: Are game cheats and trainers safe to download?

A: Not always. While some cheats simply modify gameplay, others can contain malware, steal passwords, or compromise gaming accounts. Downloading cheats from unofficial websites or Discord servers carries additional risk. 

Q: Can Minecraft mods contain malware?

A: Yes. While many Minecraft mods are legitimate, cybercriminals have repeatedly used fake mods and clients to distribute malware. Download mods only from trusted community repositories or verified developer pages. 

Q: How can I tell if a game download is legitimate?

A: Download games directly from the publisher’s official website or trusted digital storefronts like Steam, PlayStation Store, Xbox Store, Nintendo eShop, or Epic Games Store. Avoid links shared through YouTube comments, Discord messages, or unofficial social media posts. 

Q: Why do scammers target popular game releases?

A: High-profile launches create excitement and urgency, making players more likely to click on fake download links, preorder scams, cheat tools, or unofficial apps without stopping to verify they’re legitimate. 

Q: What are the biggest gaming scams to watch for in 2026?

A: Common gaming scams include fake early access offers, counterfeit game downloads, unofficial mobile apps, cheat software bundled with malware, phishing pages posing as gaming platforms, and fake giveaways promising free games or in-game items. 

Q: Can antivirus slow down gaming performance?

A: Some security software can affect system performance, but independent testing has shown that solutions vary significantly. Look for products that perform well in third-party performance benchmarks while still providing strong protection against malware and phishing attacks. McAfee Total Protection recently took first place in the latest AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance. In other words, McAfee provides strong protection without sacrificing performance or slowing your game. 

Q: What’s the safest way to download new games this fall?

A: Buy or download games directly from official publishers and trusted storefronts, keep your operating system and antivirus up to date, avoid unofficial cheats or cracked versions, and verify any unexpected links before clicking. 

 

The post GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found appeared first on McAfee Blog.

Brit rail cops bring live facial recognition to the London Underground

12 August 2026 at 11:19
British Transport Police is expanding its trial of live facial recognition (LFR) to the London Underground, despite concerns about privacy and mistaken identification. The force, which polices railways across England, Scotland, and Wales, will begin its Tube deployments at Victoria Underground station. The cameras will then rotate between Underground and Network Rail stations until the trial ends in November. The trial began at London Bridge railway station in February and is intended to assess how the technology performs in a railway setting. It follows deployments by the Metropolitan Police, which says it will start using face-scanning cameras in London's West End and Soho by the end of this year after a six-month pilot in the south London borough of Croydon. Live facial recognition scans faces within a camera's field of view and compares them with a police watchlist. A possible match generates an alert that an officer must review before deciding whether further action is warranted. According to the railway bobbies, the technology deployed relies on the NEC NeoFace M40 algorithm, which appears to be the same across several forces. "Expanding deployments into London Underground stations will help us assess the technology in a different transport environment while continuing to refine how it is used across the railway network," said the officer responsible for the project, chief superintendent Chris Casey. Critics describe the technology as dystopian and intrusive, and errors have already resulted in innocent people being mistaken for criminals and detained. Members of ethnic minorities appear to be more at risk of being mistaken for someone else by facial algorithms. "This is a disturbing and dystopian expansion of live facial recognition that will capture millions of innocent people's faces. Far from reserving this for exceptional cases, British police are now using live facial recognition routinely in the sort of pervasive way you might expect in China, but not in a democracy," says Silkie Carlo, director of civil liberties group Big Brother Watch. The London Underground network is estimated to handle more than 3.7 million passenger journeys a day on weekdays. A recent Opinium survey of 2,000 UK adults, commissioned by facial recognition biz Face Int, found that 69 percent believed the public should have a say in how the technology is used. It also found that 61 percent worried errors could get people into trouble for things they had not done, while 57 percent were concerned about how facial images were stored. Britain's railway fuzz says images of anyone who does not match the authorized watchlist are deleted immediately and permanently. Whether that remains the policy in future is another matter, of course. We asked the British Transport Police to comment regarding public concerns about the use of facial recognition technology. A spokesperson for the force referred to us to the comments made in the announcement by chief superintendent Casey, who said: "Our focus remains on protecting the public, preventing crime and bringing offenders to justice, while ensuring the technology is used lawfully, proportionately and transparently." ®

‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware

12 August 2026 at 10:00
Experts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and other gear meant for data centers.

Weekly Update 516: Live From Vietnam

12 August 2026 at 08:16
Weekly Update 516: Live From Vietnam

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to actually answer most of the questions?! Being conscious that they're the target of criminal extortion and are genuinely the victims here, I still struggle to grasp how simple incident response questions can be so lawyer-speaked as to remove all sensible meaning from the responses. But this is how these things tend to play out these days (speaking generically, yet to be seen fully for Brinks): hacker gets data by just calling up and asking for it (vishing -> OAuth), hacker demands money, hacker gets no money so dumps the data, company gets a gazillion class actions overnight and lawyers up to the hilt, customers get notified "where legally required" (which it usually isn't) 🤷‍♂️

Weekly Update 516: Live From Vietnam
Weekly Update 516: Live From Vietnam
Weekly Update 516: Live From Vietnam
Weekly Update 516: Live From Vietnam

Signal adds an extra layer of security to make sure you're actually chatting with the right person

11 August 2026 at 21:45
Signal has introduced a new layer of security to help make sure no one has secretly interfered with your encrypted chats. The chat app is favored by diplomats, activists, and journalists for its security. It uses end-to-end message encryption and “safety numbers” – cryptographic fingerprints associated with the keys securing a conversation – which users can compare to verify they have the expected encrypted connection with a contact. But in theory, someone could still intercept messages by corrupting the centralized directory of accounts and posing as somebody else – a classic "man in the middle" attack. Everything would still be encrypted, just going to the wrong place. To fight this possibility, Signal announced a new feature called Automatic Key Verification (AKV) on Tuesday. From a user perspective, AKV is easy: Tap on a Signal contact’s profile, navigate to the “View Safety Number” screen, and tap on the “Verify automatically” button. It will then show a green checkmark to verify that the contact’s public encryption key matches what Signal’s key transparency system expects. Behind the scenes, however, Signal has developed a new architecture for detecting whether someone has tampered with the public keys associated with an account to intercept messages, as that would require a change to the public encryption key and, in turn, the safety number that a user might not recognize. Ledgers and trees and third parties, oh my! Signal described the new system as serving as a ledger of public keys in which every change a user makes to their information (e.g., linked phone number) leads to a new iteration of the ledger. Accompanying that ledger is an index, allowing Signal users to verify the information in the ledger about themselves or their contacts to make sure it hasn’t been altered by a malicious third party seeking to intercept messages. This ledger lives on an “open-source key transparency server” Signal created for the AKV process, the company said. “When Signal users register, change their phone number or username, or re-create their account, Signal records the changes in a log tree ('the ledger') and facilitates searching through the log tree with prefix trees ('the index books'),” Signal said in the announcement. Digging through an index is hardly automatic, however, so Signal combs the index on the user's behalf to verify the information they’re retrieving about a contact is the most up-to-date. Up-to-date doesn’t mean it’s accurate, however, which is where third-party auditors come in. Cloudflare and security firm Trail of Bits serve as Signal’s AKV third-party auditors, according to the announcement. Their role in the whole thing is to verify that Signal’s own key transparency server isn’t compromised. Per the announcement, third-party auditors check the index to ensure entries don’t appear to have been altered. If those checks come out clear, the auditor signs the response to indicate that the keys being provided are the same for both users, thus eliminating the possibility of a man-in-the-middle attack. Yet again we have a security shortcoming, as auditors can guarantee the index and key transparency server hasn’t been tampered with, but can’t verify the accuracy of the data they contain, which is where the final part of the puzzle comes in: Monitoring. “There are two ways for customers to interact with the ledger: looking up someone else’s address, and looking up their own,” Signal explained. “Monitoring requires Alice and Bob [your usual cryptographic placeholders] to do both of these things on a regular basis, each detecting a different kind of tampering.” Alice and Bob are each able to monitor their own ledger entries via the Signal app, which periodically checks it automatically, and they can verify their connection’s data is correct through the View Safety Number “Verify Automatically” button we mentioned earlier. “These two kinds of monitoring, combined with third-party auditing, form a complete detection system: auditing guarantees that Alice and Bob are looking at the same data, and monitoring guarantees that both of them are regularly checking that data for accuracy,” Signal explained. Security is never simple AKV still ultimately leaves Signal users on the hook for their security: If you want to be truly sure your contact is who they say they are, you’ll need to hit that verify button every time you want to chat. It’s also worth pointing out that this won’t always work for all Signal users. “Your Signal app automatically verifies your own phone number and username data in the log,” the announcement said. “But to verify this for someone else, you need to have their phone number.” In other words, if you don’t have your contact’s phone number through Signal or a matching entry in your phone’s address book, you can’t use AKV to verify the encryption key associated with that contact. AKV can also be disabled for users who don’t want a third party involved in verifying their identity, in which case Signal recommends relying on good old fashioned safety number or QR code verification. Nothing in the cryptographic verification space is ever easy, is it?®

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

11 August 2026 at 21:31
This is an epic month for Microsoft patches, though not a record-setting one. Redmond addressed 421 bugs in its own products this month - about 200 fewer CVEs than last month, but likely the new norm with AI-assisted vulnerability disclosures and fixes. The big news is that North Korea’s Lazarus Group (and possibly other miscreants) found and attacked one of these flaws as a zero-day in early June. The bug, tracked as CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition,” Redmond warned, adding that successful exploitation could allow an attacker to execute code with SYSTEM-level privileges, and with no user interaction required. Microsoft credited Check Point researchers Moshe Marelus and David Driker with finding and reporting CVE-2026-68820, and the security shop’s threat intel lead told us that his analysts first observed attackers - namely North Korea’s Lazarus Group - battering this CVE at the beginning of June. “We are familiar with one successful implementation of the CVE - but we assume it was used widely in the campaign,” Sergey Shykevich, director of threat intelligence at Check Point, told The Register. He’s talking about Operation Dream Job, a long-running campaign targeting organizations worldwide, especially those in the defense sector, and attributed to Lazarus, an umbrella term for Pyongyang's government-sponsored goons who specialize in cryptocurrency theft, extortion attacks, and IT worker scams. It’s probably best known for the Sony Pictures Entertainment hack in late 2014 and the WannaCry ransomware outbreak in 2017, although the group has been active since at least 2009. Lazarus’ DreamJob campaigns have been around since 2020, and they use social engineering to lure job seekers with fake offers for high-profile positions, then trick the victims into clicking on malicious links or opening malware-laced documents. The goal in these attacks involves stealing IP and other sensitive data, conducting cyber spying missions, and collecting financial information. When Dream Job and Patch Tuesday collide This new wave of attacks focuses on the defense sector in Europe and India with dream jobs impersonating Lockheed Martin and privacy-tech firm Enveil. Attackers created at least three fake Enveil sites, and some even ranked as the top search result, making them even more believable to job seekers - and harder to spot a phish. “In this campaign, the threat actor expanded its delivery method by leveraging impersonation websites and search engine optimization (SEO) techniques to distribute the trojanized applications, increasing its credibility and helping it evade some phishing-based detections,” Check Point researchers said in a Tuesday blog. These attacks involve Lazarus distributing a modified PDF viewer called SecurityPDF designed to execute malicious payloads embedded within attacker-crafted PDF files when the user opens them. The PDFs, when opened, execute a never-before-seen backdoor that Check Point named Troy. And during the intrusions, the Norks exploited CVE-2026-68820 as a zero-day to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. “We will not be disclosing full technical details of the vulnerability in this article, as it was patched on the August 11 Patch Tuesday fix,” the researchers wrote. “At a high level, the exploit takes advantage of how afd.sys handles a socket is created when it is accessed concurrently by several threads at once.” Shykevich told us that “this campaign shows that this actor continues to develop new tools (like Troy), and finding and implementing new vulnerabilities in Windows to evade detection.” Best of the rest Redmond lists one of the other 421 Microsoft CVEs as publicly known. It’s CVE-2026-62832, an elevation-of-privilege flaw, and the Windows giant says exploitation is “more likely,” so patch this one sooner. “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive,” according to the security advisory. “Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required.” While CVE-2026-68820 and CVE-2026-62832 are the only vulnerabilities that Microsoft considers “notable” in its August patch cycle, Trend Micro’s Zero Day Initiative highlights five others, including one that came through ZDI’s bug reporting program and another that was successfully exploited at ZDI’s Pwn2Own contest in Berlin. All five of these should be considered notable and exploitable, so give those a read, too. CVE-2026-62893, a critical flaw in Windows Deployment Services TFTP Server that leads to remote code execution without user authentication or user interaction, is the one disclosed through ZDI. “TFTP has no auth mechanism and is available remotely vid UDP port 69,” ZDI bug boss Dustin Childs wrote. “UDP port 69 should be blocked at your perimeter, but this could easily be used by attackers for lateral movement within an enterprise. Again, test and deploy this one quickly if you’re using WDS for deployments in your enterprise.” Meanwhile, CVE-2026-62911, one of the many Exchange bugs in this month’s release, was demonstrated at ZDI’s Pwn2Own in Berlin. It allows a privilege escalation via an authentication bypass, and exploitation would allow an attacker to “take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments,” according to Microsoft, which oddly deemed “exploitation less likely.” Childs calls BS on this. “Ignore Microsoft’s exploitability and Exploit Code Maturity ratings,” he wrote. “We handed them working exploits, so this is a real threat.” ®

Microsoft Plugs Nearly 400 Security Holes

11 August 2026 at 21:28

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Image: Shutterstock, Mallika Home Studio.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.

Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.

The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.”

“This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”

CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly.

By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.

Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.

Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.

“AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”

Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.

“If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”

Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.

For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.

❌