#CybersecurityRisks
Linda Roberts is calling on CalPERS to take a stand against AI-driven cybersecurity threats that endanger our financial systems—are lawmakers listening?

Click to read more!

#CA #CitizenPortal #CybersecurityRisks #AIEthics #PolicyEngagement
Members urge CalPERS to press lawmakers on AI and cybersecurity risks
A CalPERS member asked whether the board plans to address AI-related cybersecurity threats to member records and finances and to advocate publicly; Yvonne Walker said the board had a substantial discussion, is monitoring developments and recognizes the need for guardrails and broader policy engagement.
citizenportal.ai
September 25, 2026 at 1:09 PM
A new proposal in Congress aims to centralize the federal custody of Bitcoin, but critics warn that a 20-year holding period could expose taxpayers to significant risks and conflicts of interest.

Get the details!

#US #CitizenPortal #CybersecurityRisks #FinancialAccountability #WisconsinCrypto
Committee moves bill to centralize federal custody of seized Bitcoin and create 20-year reserve; Democrats raise ethics, risk concerns
HR 89 57 would centralize custody of federally held Bitcoin and require Treasury to hold seized Bitcoin for 20 years in a strategic reserve. Supporters argued it improves accountability and cybersecurity; critics warned the long hold is risky, cited quantum-computing concerns, and raised conflict-of-interest questions linked to the president's family.
citizenportal.ai
September 26, 2026 at 11:43 AM
AI's Role in Cybersecurity: Threats and Opportunities

https://buff.ly/4g0nK1j

#AIandCyberThreats #CybersecurityRisks #ArtificialIntelligence
November 22, 2024 at 5:04 PM
Windows 10 security risks are now more of a reality for users #Technology #Cybersecurity hashtag 1: #Windows10Security 2: #CybersecurityRisks 3: #TechNews
Windows 10 security risks are now more of a reality for users
Stats indicate that more users are switching from Windows 10 to Windows 11 at this time, as the October 14 end-of-life date for the legacy operating system approaches.
puretech.news
March 12, 2025 at 1:45 PM
NYC's mayoral inauguration banned devices like Flipper Zero and Raspberry Pi over hacking concerns, highlighting growing fears around portable tech and cybersecurity at public events. #CybersecurityRisks
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices
New York City's 2026 mayoral inauguration of Zohran Mamdani has published a list of banned items for the event, specifically prohibiting the Flipper Zero and Raspberry Pi devices.
www.bleepingcomputer.com
January 2, 2026 at 11:05 AM
Noble County's IT director has issued a stark warning about the urgent need for a costly migration to Microsoft 365, raising concerns over security risks and staffing shortages.

Click to read more!

#NobleCounty #IN #CybersecurityRisks #StaffCapacity #NobleCountyIT #CitizenPortal #CloudMigration
IT director warns of looming Microsoft 365 migration costs and staffing risks
County IT reported its on-premises email system is out of vendor support and estimated a first-year migration cost of roughly $50,000 and recurring licensing for about 400 users at roughly $250 per user per year (~$100,000). The IT director urged hiring and retention to preserve in-house capability.
citizenportal.ai
August 5, 2026 at 2:17 AM
Sha1-Hulud Malware Returns With Advanced npm Supply-Chain Attack Targeting Developers #CyberAttacks #cybersecurityrisks #Developers
Sha1-Hulud Malware Returns With Advanced npm Supply-Chain Attack Targeting Developers
 A new wave of the Sha1-Hulud malware campaign has unfolded, indicating further exacerbation of supply-chain attacks against the software development ecosystem. The recent attacks have hit the Node Package Manager, or npm, one of the largest open-source package managers that supplies JavaScript developers around the world. Once the attackers compromise vulnerable packages within npm, the malicious code will automatically be executed whenever targeted developers update to vulnerable versions, oblivious to the fact. Current estimates indicate nearly 1,000 npm packages have been tampered with, thereby indirectly affecting tens of thousands of repositories.  Sha1-Hulud first came into light in September 2025, when it staged its first significant intrusion into npm's ecosystem. The past campaign included the injection of trojanized code into weakly-secured open-source libraries that then infected every development environment that had the components installed. The malware from the initial attack was also encoded with a credential harvesting feature, along with a worm-like mechanism intended for the proliferation of infection.  The latest rendition, seen in new activity, extends the attack vector and sophistication. Among others, it includes credential theft, self-propagation components, and a destructive "self-destruct" module that aims at deleting user data in case interference with the malware is detected. The malware now demonstrates wide platform compatibility, running across Linux, macOS, and Windows systems, and introduces abuse of GitHub Actions for remote code execution.  The infection chain starts with a modified installation sequence. Inside the package.json file, the compromised npm packages bear a pre-install script named setup_bun.js. Posing as a legitimate installer for the Bun JavaScript runtime, the script drops a 10MB heavily obfuscated payload named bun_environment.js. From there, malware begins searching for tokens, API keys, GitHub credentials, and other sensitive authentication data. It leverages tools like TruffleHog to find more secrets. After stealing the data, it automatically gets uploaded into a public repository created under the victim's GitHub account, naming it "Sha1-Hulud: The Second Coming," thus making those files accessible not just to the attackers but to actually anyone publicly browsing the repository.  The malware then uses the stolen npm authentication tokens to compromise new packages maintained by the victim. It injects the same malicious scripts into those packages and republishes them with updated version numbers, triggering automatic deployment across dependent systems. If the victim tries to block access or remove components, the destructive fail-safe is initiated, which wipes home directory files and overwrites data sectors-this significantly reduces the chances of data recovery.  Security teams are encouraged to temporarily stop updating npm packages, conduct threat-hunting activities for the known IoCs, rotate credentials, and reevaluate controls on supply-chain risk. The researchers recommend treating any system showing signs of infection as completely compromised.
dlvr.it
December 5, 2025 at 3:19 PM
Residents are sounding the alarm over privacy and cybersecurity risks tied to the proposed Flock camera agreement, demanding clearer data deletion guarantees before the council makes a decision.

Learn more here!

#GlenrockConverseCounty #WY #CitizenPortal #CybersecurityRisks #GlenrockDataPrivacy
Residents urge stricter data-deletion guarantees as council reconsiders Flock camera contract
Residents and councilors raised security and privacy concerns about a proposed Flock camera contract during public comment and the police chief said the town obtained a 30‑day extension to review terms, moving the notification deadline to Oct. 16.
citizenportal.ai
September 18, 2026 at 8:36 PM
Regulators are demanding answers from labs about their biosafety plans and the rising cybersecurity risks that come with advanced technology—are they ready to protect patient data?

Get the details!

#US #BradfordLabs #CybersecurityRisks #CitizenPortal #BiosafetyProtocols #PublicHealthSafety
CMS asks labs about biosafety, biosecurity and growing cybersecurity risks
Regulators sought examples of biosafety plans, training approaches and cybersecurity protocols as labs adopt more integrated information systems and remote technologies.
citizenportal.ai
September 12, 2026 at 11:38 AM
Residents in Robinson are raising alarm bells over automated license-plate readers, citing serious privacy concerns and urging local regulations to protect citizen data.

Click to read more!

#RobinsonMcLennanCounty #TX #CivicAccountability #CybersecurityRisks #RobinsonPrivacy #CitizenPortal
Residents urge Robinson council to end Flock license‑plate readers, citing privacy and security risks
Multiple residents told the council that ALPRs posed privacy, misuse and cybersecurity risks, urged local ordinance and asked members to decline contract renewal; commenters described national incidents, local examples and technical vulnerabilities.
citizenportal.ai
September 2, 2026 at 6:52 AM
A local resident is sounding the alarm on Lafourche Parish's urgent need to upgrade to NextGen 9-1-1, warning that cybersecurity gaps could pose life-threatening risks.

Get the details!

#CrescentIbervilleParish #LA #CybersecurityRisks #CitizenPortal #EmergencyResponse #PublicSafety
Resident urges parish to accelerate NextGen 9‑1‑1 upgrade, calls cybersecurity gaps 'life‑threatening serious'
Ramon Barrera, a telecommunications/cybersecurity professional, urged the council to evaluate Lafourche Parish's progress on migrating to NextGen 9‑1‑1, citing security risks and pointing to federal funding opportunities; the parish president agreed to seek a report from the regional board and director.
citizenportal.ai
August 30, 2026 at 5:01 PM
An engineer warns Lafourche Parish that its outdated emergency network poses serious cybersecurity risks and urges immediate upgrades to NextGen 9-1-1 before it's too late.

Learn more here

#LafourcheParish #LA #CybersecurityRisks #CitizenPortal #PublicSafety #EmergencyServices
Engineer warns parish to accelerate NextGen 9-1-1 upgrades, cites cybersecurity risks and federal funding
Raymone Barrera, a communications engineer, told the council Lafourche Parish may be behind on NextGen 9-1-1 migration and recommended a status audit; he noted federal grant funding exists and urged council engagement with the 9-1-1 board and sheriff's office.
citizenportal.ai
August 28, 2026 at 3:17 PM
A Caldwell resident built a $28 device that can hijack automated license-plate reader feeds, raising serious alarms about privacy and security risks in the community.

Read the full story

#CaldwellCanyonCounty #ID #TechnologyEthics #CybersecurityRisks #CaldwellPrivacy #CitizenPortal #PublicSafety
Resident demonstrates how inexpensive equipment can compromise ALPR camera feeds, urges council to act
A Caldwell resident told council he built a low‑cost device that can intercept ALPR (Flock) camera feeds and argued the technology poses privacy and security risks; he urged the city to take steps — including possibly taking systems offline — to protect residents.
citizenportal.ai
August 20, 2026 at 9:42 PM
OpenAI is hitting pause on rapid model upgrades, citing rising cyber‑threats. New safeguards like Astra and a Preparedness Framework aim to curb AI‑driven attack vectors. Curious how this shift could reshape alignment research? Dive in. #OpenAI #CybersecurityRisks #ReinforcementLearning

🔗
August 18, 2026 at 8:44 PM
Livonia's Finance Committee celebrates a clean audit with a $2.1 million boost in the general fund, but warns of a troubling decline in the cable television fund that needs urgent attention.

Learn more here!

#LivoniaWayneCounty #MI #CybersecurityRisks #LivoniaFinance #CitizenPortal
Finance committee receives clean audit; city fund balance up, cable fund flagged for decline
Plant Moran presented an unmodified (clean) audit opinion for fiscal year ending Nov. 30, 2025, reporting a $2.1 million increase to the general fund balance (now ~$20.2 million) and highlighting a concerning decline in the cable television fund; auditors recommended continued attention to federal cash‑management policies and IT cybersecurity.
citizenportal.ai
July 16, 2026 at 11:25 AM
A lawmaker is calling out Democrats for blocking crucial funding for the Department of Homeland Security, emphasizing that our national security—and cybersecurity—are at risk amid rising tensions in the Middle East.

Learn more here

#US #DepartmentOfHomelandSecurityFunding #CybersecurityRisks
Lawmaker urges passage of Homeland Security funding bill, cites cybersecurity and Middle East risks
A lawmaker accused House and Senate Democrats of blocking Department of Homeland Security funding and urged passage, saying the bill funds the Coast Guard, TSA and cybersecurity efforts and warning of heightened risks tied to conflict in the Middle East and recent cyber activity.
citizenportal.ai
March 7, 2026 at 5:06 AM
Representative Loudermilk warns that the federal government poses a greater risk to your data privacy than you might think, urging a much-needed reevaluation of existing laws.

Learn more here

#US #CitizenPortal #DataPrivacy #CybersecurityRisks #ConsumerRights #USFinancialServices
Representative Loudermilk critiques government data security amid GLBA discussion
Loudermilk emphasizes federal government's privacy risks during GLBA consumer rights discussion.
citizenportal.ai
June 7, 2025 at 7:28 PM
A staggering $40 billion in U.S. investments has flowed into Chinese AI firms, raising alarming questions about national security and the future of global tech competition.

Click to read more!

#US #USNationalSecurity #AIInvestment #CitizenPortal #GlobalThreats #CybersecurityRisks
Georgetown Center reveals $40B US investments in Chinese AI companies from 2015 to 2021
Georgetown Center highlights $40 billion US funding for PRC AI firms in six years.
citizenportal.ai
March 31, 2025 at 5:24 AM
Bengaluru Developer’s Viral AI Tool Shows the Power of One Click Decisions #Accesscontrol #AILayoffs #cybersecurityrisks
Bengaluru Developer’s Viral AI Tool Shows the Power of One Click Decisions
  As artificial intelligence continues to transform software development workflows and corporate staffing strategies, discussions regarding automation-driven job displacement have gained increasing prominence across the technology sector. Against this backdrop, a Bengaluru software engineer has captured widespread attention online with a satirical hardware project combining workplace anxiety with developer joking.  Designed as a "I GOT FIRED" emergency button, the device humorously claims to initiate a series of catastrophic actions, including exposing source code repositories and publishing sensitive environment variables. As a technical themed commentary on modern tech culture and the uneasy relationship between AI, employment, and corporate trust, the book transforms a growing industry concern into a commentary on this growing industry concern.  The project was presented with the intention of responding humorously to the growing discussion regarding AI-driven layoffs and shrinking engineering teams, as a response to workplace uncertainty.  In an interview with Pankaj Tanwar, a software engineer who is popular online as @the2ndfloorguy, Pankaj Tanwar described the device as a "I GOT FIRED" button capable of initiating a fictional chain of retaliatory actions upon pressing.  Using the satirical scenario described in his post, this button would publish a company's codebase, store sensitive .env configuration secrets, delete the staging database, and notify his lawyer. There is a compact programmable keypad attached to his laptop that has labels, including "Gaslight Them," "Decode Corporate BS," and a prominent red button that reads "I Got Fired.".  On-screen notifications, emphasizing the joke's technical undertones, displayed messages claiming environment secrets had been released to the public and that the user was "out of office." It was evident that the post was intended as developer satire rather than a functional cyber sabotage tool, however it received widespread attention on social media, generating a mix of amusement, curiosity and debate from technology professionals who appreciated the humour and frustrations embedded within it.  Besides its novelty, the rapid spread of the post was mainly driven by its author's reputation as a Bengaluru-based developer known for designing unconventional technology projects combining engineering concepts with internet humour. Many members of the software community, however, were particularly affected by this satire in this instance.  The button was described as a fictional last-resort mechanism that could launch a cascade of catastrophic actions as a response to mounting concerns about the reduction of workforce through automation. It can expose proprietary code, expose sensitive environment variables, delete a staging database and alert legal counsel to a multitude of catastrophic events. Using a compact programmable keypad alongside a laptop that was running a workflow ominously titled "I Got Fired," the accompanying images enhanced the dramatic narrative by creating the visual impression of an emergency shutoff switch for developers. Despite the obvious exaggeration in the scenario for comedic effect, the post was resonating because it expressed familiar industry anxieties in a technically recognisable manner.  The responses varied from users asking for information about similar programmable keys available in India to others imagining humorous scenarios driven by artificial intelligence in which a decision-making system would determine whether to press a button.  The project has been dismissed by critics as nothing more than engagement bait, while others have pointed out that any attempt to carry out the actions outlined would come with severe legal and professional consequences. There was some lighthearted joke that activating the switch would result in a salary being traded for prison accommodation, with some comparing the concept to a developer-oriented “dead man’s switch.” The joke revealed a deeper sentiment, though, beneath the humour. It resonated with many technology professionals as it reflected a common concern about employees feeling replaceable amid continuous restructuring, automation initiatives, and artificial intelligence-driven efficiency initiatives. Therefore, the device functioned less as a fictional tool and more as a satirical tool for discussing the industry’s growing concerns about job security, workplace pressure and the future role of human talent in software development. Its popularity underscores a broader reality faced by today's technological workforce despite its intended purpose as satire.  Not only did the joke resonate due to the fictional cyber sabotage it portrayed, but it also tapped into a genuine concern regarding automation, organisational restructuring, and employee uncertainty. From a cybersecurity perspective, the scenario also reminds us the importance of strong access controls, credential management, insider risk monitoring, and clearly defined offboarding processes.  AI is reshaping the workplace, so organizations will need to maintain a balance between technological efficiency and transparency, trust and workforce resilience to ensure innovation does not undermine security and culture, but rather strengthens it instead of becoming a source of anxiety for employees.
dlvr.it
June 1, 2026 at 3:47 PM
Apple Reinforces Digital Privacy for Users Without Restricting Law Enforcement Oversight #ApplePrivacy #cybersecurityrisks #Dataprotection
Apple Reinforces Digital Privacy for Users Without Restricting Law Enforcement Oversight
  The company has long positioned its privacy architecture as a defining aspect of its ecosystem, marketing it as more than a feature, but a fundamental right built into its products as well. However, the latest disclosures emerging from US legal proceedings suggest that privacy boundaries are neither absolute nor impermeable, and that a more nuanced reality emerges.  It is the "Hide My Email" function that is under scrutiny, a tool designed to hide users' real email addresses from third-party apps and websites. Despite its success in minimizing commercial tracking and unsolicited exposure, recent legal revelations indicate that this layer of anonymity can be effectively reversed under lawful authority to ensure effectiveness.  Moreover, the development highlights the important distinction between consumer privacy assurances and judicial obligations imposed by technology companies, reframing conditional anonymity as a controlled filter operating within clearly defined legal limits rather than as a cloak of invisibility.  Subsequent disclosures from investigative proceedings provide additional insight into how this conditional anonymity works in practice. Apple has received a request from federal authorities, including the Federal Bureau of Investigation, for subscriber information regarding a threatening communication directed at Alexis Wilkins, a person who was reported to have been associated with FBI Director Kash Patel. According to the warrant application, Apple was able to correlate the anonymized "Hide My Email" alias to a specific user account by providing details on subscriber identification along with a wider dataset that contained over a hundred additional aliases created under the same profile. It was found that Homeland Security Investigations investigated an alleged identity fraud operation in a similar manner, in which multiple masked email identities were linked to Apple accounts under underlying identity fraud schemes, allowing investigators to consolidate disparate digital footprints into one framework for attribution.  Collectively, these examples reveal an important structural aspect of Apple's ecosystem: while certain layers of iCloud services are protected by end-to-end encryption, a portion of account and communication information is still accessible under valid legal processes. Despite the fact that subscriber information, including names, billing credentials, and associated identifiers, remains within the compliance boundary rather than a cryptographic boundary, which does not contain end-to-end encryption of the content.  The delineation reinforces an issue of broader significance to the industry, in which conventional email infrastructure is built without pervasive encryption safeguards, making it inherently vulnerable to lawful interception by its users. It is against this backdrop that privacy-conscious individuals are increasingly turning to platforms such as Signal, which offer default end-to-end encryption and minimal data retention.  As for Apple, it has not responded directly to these developments, although the disclosures have prompted a review of how privacy assurances are communicated and understood within technologically advanced and legally obligated environments. A sustained increase in government access requests against major technology providers is reflective of the context in which these disclosures are made.  According to Apple's transparency data, it processed more than 13,000 such requests for customer information during the first half of 2025, with email-related records contributing significantly to account attribution, threat analysis, and criminal investigations due to their evidentiary value. Nevertheless, this dynamic is not limited to Apple's ecosystem. Similar constraints exist among providers such as Google and Microsoft, where legacy email protocols - architected in an era before modern encryption standards - continue to limit the amount of privacy protection inherent within their systems. Although niche services such as Proton have attempted to address this issue by implementing end-to-end encryption by design, their adoption remains marginal relative to the global email user base, which underscores the persistence of structurally exposed communication channels within this environment.  Apple’s position is especially interesting in light of the divergence between its privacy-oriented messaging and its email infrastructure's technical realities. Hide My Email provides demonstrably reduced exposure to commercial tracking and data aggregation, however it does not alter the underlying compliance model governing lawful data access.  The distinction has re-ignited an ongoing policy debate around encryption, a controversy Apple has previously encountered with the use of iMessage and other Apple services. Regulations and law enforcement agencies contend that inaccessible communications impede legitimate investigations, and extending comparable end-to-end encryption to iCloud Mail may result in renewed friction. In contrast, privacy advocates contend that any lowering of encryption standards introduces systemic security risks. Thus, email privacy remains a compromise governed both by legal frameworks as well as engineering decisions at present.  It is common for users seeking stronger privacy to rely on specialized encryption platforms, but such platforms present usability constraints and interoperability challenges with the larger email ecosystem. There is an important distinction to be drawn from recent federal requests: privacy controls designed to limit the visibility of corporate data do not automatically ensure that government access is restricted.  The implementation of Apple's products is within this boundary, balancing user expectations with statutory obligations. However, there remains a considerable gap between perceptions and operational realities that calls for reevaluation. It is unclear if the company will extend its end-to-end encryption model to email services, particularly in light of the political and regulatory implications of such a shift.  It is important to note that privacy is not a binary guarantee, but rather a layered construct that is shaped by both technical design and legal jurisdiction as a result of the developments. As such, organizations and individuals alike should reassess their threat models, identifying clearly between protections required for sensitive communications as opposed to protections against commercial data exposure.  In cases where confidentiality is extremely important, standard email services may be insufficient, which necessitates selective adoption of stronger encryption techniques, secure communication channels, and disciplined data handling procedures. As a result of clear, and often misunderstood, boundaries within which privacy features operate, informed usage remains the most reliable safeguard in an environment where privacy features operate within clearly defined boundaries.
dlvr.it
April 9, 2026 at 5:13 PM
A Year of Unprecedented Cybersecurity Incidents Redefined Global Risk in 2025 #CyberSecurity #Cyberattacks #cybersecurityrisks
A Year of Unprecedented Cybersecurity Incidents Redefined Global Risk in 2025
 The year 2025 marked a turning point in the global cybersecurity landscape, with the scale, frequency, and impact of attacks surpassing anything seen before. Across governments, enterprises, and critical infrastructure, breaches were no longer isolated technical failures but events with lasting economic, political, and social consequences. The year served as a stark reminder that digital systems underpinning modern life remain deeply vulnerable to both state-backed and financially motivated actors.  Government systems emerged as some of the most heavily targeted environments. In the United States, multiple federal agencies suffered intrusions throughout the year, including departments responsible for financial oversight and national security. Exploited software vulnerabilities enabled attackers to gain access to sensitive systems, while foreign threat actors were reported to have siphoned sealed judicial records from court filing platforms. The most damaging episode involved widespread unauthorized access to federal databases, resulting in what experts described as the largest exposure of U.S. government data to date. Legal analysts warned that violations of established security protocols could carry long-term legal and national security ramifications.  The private sector faced equally severe challenges, particularly from organized ransomware and extortion groups. One of the most disruptive campaigns involved attackers exploiting a previously unknown flaw in widely used enterprise business software. By silently accessing systems months before detection, the group extracted vast quantities of sensitive employee and executive data from organizations across education, healthcare, media, and corporate sectors. When victims were finally alerted, many were confronted with ransom demands accompanied by proof of stolen personal information, highlighting the growing sophistication of data-driven extortion tactics.  Cloud ecosystems also proved to be a major point of exposure. A series of downstream breaches at technology service providers resulted in the theft of approximately one billion records stored within enterprise cloud platforms. By compromising vendors with privileged access, attackers were able to reach data belonging to some of the world’s largest technology companies. The stolen information was later advertised on leak sites, with new victims continuing to surface long after the initial disclosures, underscoring the cascading risks of interconnected software supply chains.  In the United Kingdom, cyberattacks moved beyond data theft and into large-scale operational disruption. Retailers experienced outages and customer data losses that temporarily crippled supply chains. The most economically damaging incident struck a major automotive manufacturer, halting production for months and triggering financial distress across its supplier network. The economic fallout was so severe that government intervention was required to stabilize the workforce and prevent wider industrial collapse, signaling how cyber incidents can now pose systemic economic threats.  Asia was not spared from escalating cyber risk. South Korea experienced near-monthly breaches affecting telecom providers, technology firms, and online retail platforms. Tens of millions of citizens had personal data exposed due to prolonged undetected intrusions and inadequate data protection practices. In one of the year’s most consequential incidents, a major retailer suffered months of unauthorized data extraction before discovery, ultimately leading to executive resignations and public scrutiny over corporate accountability.  Collectively, the events of 2025 demonstrated that cybersecurity failures now carry consequences far beyond IT departments. Disruption, rather than data theft alone, has become a powerful weapon, forcing governments and organizations worldwide to reassess resilience, accountability, and the true cost of digital insecurity.
dlvr.it
December 30, 2025 at 2:53 PM
CountLoader and GachiLoader Malware Campaigns Target Cracked Software Users #CyberAttacks #CyberDefender #cybersecurityrisks
CountLoader and GachiLoader Malware Campaigns Target Cracked Software Users
 Cybersecurity analysts have uncovered a new malware campaign that relies on cracked software download platforms to distribute an updated variant of a stealthy and modular loader known as CountLoader. According to researchers from the Cyderes Howler Cell Threat Intelligence team, the operation uses CountLoader as the entry point in a layered attack designed to establish access, evade defenses, and deploy additional malicious payloads.  CountLoader has been observed in real-world attacks since at least June 2025 and was previously analyzed by Fortinet and Silent Push. Earlier investigations documented its role in delivering widely used malicious tools such as Cobalt Strike, AdaptixC2, PureHVNC RAT, Amatera Stealer, and cryptomining malware. The latest iteration demonstrates further refinement, with attackers leveraging familiar piracy tactics to lure victims.  The infection process begins when users attempt to download unauthorized copies of legitimate software, including productivity applications. Victims are redirected to file-hosting platforms where they retrieve a compressed archive containing a password-protected file and a document that supplies the password. Once extracted, the archive reveals a renamed but legitimate Python interpreter configured to run malicious commands. This component uses the Windows utility mshta.exe to fetch the latest version of CountLoader from a remote server.   To maintain long-term access, the malware establishes persistence through a scheduled task designed to resemble a legitimate Google system process. This task is set to execute every 30 minutes over an extended period and relies on mshta.exe to communicate with fallback domains. CountLoader also checks for the presence of endpoint protection software, specifically CrowdStrike Falcon, adjusting its execution method to reduce the risk of detection if security tools are identified.  Once active, CountLoader profiles the infected system and retrieves follow-on payloads. The newest version introduces additional capabilities, including spreading through removable USB drives and executing malicious code entirely in memory using mshta.exe or PowerShell. These enhancements allow attackers to minimize their on-disk footprint while increasing lateral movement opportunities. In incidents examined by Cyderes, the final payload delivered was ACR Stealer, a data-harvesting malware designed to extract sensitive information from compromised machines.  Researchers noted that the campaign reflects a broader shift toward fileless execution and the abuse of trusted, signed binaries. This approach complicates detection and underscores the need for layered defenses and proactive threat monitoring as malware loaders continue to evolve.   Alongside this activity, Check Point researchers revealed details of another emerging loader named GachiLoader, a heavily obfuscated JavaScript-based malware written in Node.js. This threat is distributed through the so-called YouTube Ghost Network, which consists of hijacked YouTube accounts used to promote malicious downloads. The campaign has been linked to dozens of compromised accounts and hundreds of thousands of video views before takedowns occurred.  In some cases, GachiLoader has been used to deploy second-stage malware through advanced techniques involving Portable Executable injection and Vectored Exception Handling. The loader performs multiple anti-analysis checks, attempts to gain elevated privileges, and disables key Microsoft Defender components to avoid detection. Security experts say the sophistication displayed in these campaigns highlights the growing technical expertise of threat actors and reinforces the importance of continuously adapting defensive strategies.
dlvr.it
December 20, 2025 at 3:21 PM
Chat Control Faces Resistance from VPN Industry Over Privacy Concerns #ChatControlRegulation #ClientSideScanning #cybersecurityrisks
Chat Control Faces Resistance from VPN Industry Over Privacy Concerns
  The European Union is poised at a decisive crossroads when it comes to shaping the future of digital privacy and is rapidly approaching a landmark ruling which will profoundly alter the way citizens communicate online.  A final vote on October 14 is expected to take place on September 12, 2025, as Member States will be required to state their position on the proposed Child Sexual Abuse Regulation — commonly referred to as "Chat Control" — in advance of its final vote. Designed to combat the spread of child abuse content, the regulation would place an onus on the providers of messaging services such as WhatsApp, Signal, and iMessage to scan every private message sent between users, even those messages protected from being read by third parties.  The supporters of the legislation argue that it is a necessary step for ensuring the safety of children, but critics argue that it would effectively legalise mass surveillance, thereby denying citizens access to secure communication and exposing their personal data to the possibility of being misused by government agents or exploited by malicious actors.  Many observers warn that this vote will set a precedent that could have profound implications for the privacy and democratic freedoms of the continent as a whole if its outcome were to turn out favorably.  The proposal is called “Chat Control” by its critics, since it requires all messaging platforms operating in Europe to actively scan user conversations, including those that are protected by end-to-end encryption, in search of child sexual abuse material that is well-known and previously unknown.  In their opinion, such obligations threaten to undermine the very foundations of secure digital communication, creating the possibility of unprecedented levels of monitoring and abuse, which advocates argue could undermine the very foundations of secure digital communication. The VPN Trust Initiative (VTI), an organisation which represents a group of major VPN providers, has been pushing back strongly against the draft regulation, stating that any attempt to weaken encryption would erode the very basis of the Internet's security. VTI co-chair, Emilija Beranskait, emphasised that "encryption either protects everybody or it doesn't," imploring governments to preserve strong encryption as a cornerstone of privacy, trust, and democratic values, urging them to adopt stronger encryption.  According to NordVPN's privacy advocate, Laura Tyrylyte, while client-side scanning is indeed a safety and security concern, it is not an acceptable compromise between an organisation's safety and security, contending that solutions must not be compromised in the interest of addressing a single issue alone.  Moreover, NymVPN's CEO, Harry Halpin, condemned the proposal as “a major step backwards for privacy” and warned that, once normalised, such surveillance tools could be used against journalists, activists, or political opponents. In addition, experts have raised significant technical concerns with the introduction of mandatory scanning mechanisms, stating that such mechanisms will fundamentally undermine the technology underlying online security.  Moreover, they are concerned that client-side scanning infrastructure could be repurposed so that surveillance is widened far beyond what it was originally intended to do, which runs counter to the European Union's own commitments under initiatives such as the Cyber Resilience Act and efforts to prepare for quantum cryptography in the future.  However, a deeply divided political debate is ongoing in the EU. Eight member states have formally opposed the proposal, including Germany and Luxembourg, while fifteen others, including France, Italy, and Spain, are still in favour of the proposal.  There is still some uncertainty regarding the outcome of the October vote because only Estonia, Greece, and Romania have not decided. In addition to the pressure being put on the EU Council, more than 500 cryptography experts and researchers have signed an open letter urging it to reconsider the risks associated with introducing what they consider a dangerous precedent for the future of the digital world in Europe.  It has been suggested that under the Danish-led proposal, messaging platforms such as WhatsApp, Signal, and ProtonMail would have to scan private communications without discrimination. In their current form, the proposal would violate end-to-end encryption in an irreparable way, according to experts.  A direct analysis of links, photos, and videos is part of the system that will run directly on the users' devices before messages are encrypted.  Only government and military accounts are exempt from this analysis, with the draft regulation last circulated to EU delegations on July 24, 2025, claiming to safeguard encryption. Still, privacy specialists are of the opinion that true security cannot be maintained using client-side scanning.  Laura Tyrylyte, NordVPN's privacy advocate, observed that "Chat Control's client-side scanning provisions create a false choice between security and safety." The solution to one problem, even a serious one like child safety, cannot be at the expense of creating systemic vulnerabilities that are more dangerous to everyone."  Several other industry leaders expressed similar concerns as well, including Harry Halpin, CEO of NymVPN, who condemned the measure as “a significant step backwards for privacy.” He explained that the indiscriminate scans of private communications are disproportionate in nature, creating a backdoor that could be exploited if it is normalised.  There is a risk that such infrastructure could easily be redirected towards attacking journalists, political opponents, or activists while also exposing ordinary citizens to hostile cyberattacks. In Halpin's view and the opinion of others, it is more effective to carry out targeted, warrant-based investigations, to take down illegal material swiftly, and to use properly resourced specialist teams rather than universal surveillance as a means of detecting illegal activity.  However, despite the simple concessions made in the latest draft, such as restricting the detection to visual contents and excluding audio and text, the scientific community has remained steadfast in its criticism regardless of the concessions made.  The researchers point out that there are four critical flaws to the system: the inability to scan billions of messages accurately; the inevitable weakening of encryption through the monitoring of devices on-device; the high risk that surveillance can expand beyond its stated purpose due to "function creep"; and the danger that mass monitoring in the name of child protection will erode democratic norms.  While the EU has promised oversight and consent mechanisms, cryptography experts claim that secure and reliable client-side scanning cannot be performed at scale, despite promises of EU oversight and consent mechanisms. This proposal, therefore, is technically flawed as well as politically perilous.  VPN providers are also signalling that they will not stand on the sidelines if the regulation is passed. Several leading companies, including Mullvad, a popular privacy-focused service, have expressed concern about the possibility of withdrawing from the European market altogether if the proposed legislation is passed.  If this happens, millions of users will be impacted, and innovation in this field may be curtailed. Similar advocacy groups, including Privacy Guides, have sounded the alarm in the past weeks, warning that the new regulations threaten to undermine the privacy of all citizens, not only those suspected of wrongdoing, and they urge all citizens to take notice before the September 12 deadline.  A growing number of social media platforms are also being criticised, and voices like Telegram founder Pavel Durov have pointed out that comparable laws have failed in the past, as determined offenders have simply moved to smaller applications or VPNs to avoid these weaker protections, which leaves ordinary users to bear the brunt.  The debate carries significant economic weight. The Security.org website indicates that more than 75 million Americans already use VPN services to keep their privacy online. As Chat Control advances, this demand is expected to grow rapidly in Europe. As per Future Market Insights, by 2035, the VPN industry is expected to grow to a value of $481.5 billion; however, experts caution that heavy regulation may fragment the market and stifle technological development. Denmark has continued to lobby for the proposal despite mounting opposition from civil society groups, technology companies, and several member states as the EU Council prepares to vote on October 14, as tensions are increasing. In recent weeks, citizens have taken to online platforms such as X to voice their concerns about the proposed legislation, warning that Europeans would not have fundamentally secure digital privacy.  Analysts point out that in order to adapt to this changing environment, VPN providers may need to use quantum-resistant technologies faster or explore decentralised models, as highlighted in recent forward-looking studies, which point to the existential stakes of the industry.  However, one central fear remains across all debates: once surveillance infrastructure is embedded in the environment, its scope is unlikely to be limited to combating child abuse. In their view, it could create a framework for broad and permanent monitoring, reshaping the global norms of digital privacy in a way that undermines both the rights of users and technological innovation in the process.  A key question to be answered before the EU's vote on October 14 is whether it can successfully balance child protection with its longstanding commitments to privacy and digital rights while maintaining a sense of security.  It is noted that decisions made in Brussels will have a global impact, potentially setting global standards for how governments deal with encryption, surveillance, and online safety, as experts warn. For legislators, the challenge is to devise effective solutions that protect vulnerable groups without dismantling the secure infrastructures that rely on modern communication, commerce and civic participation.  One possible path forward, according to observers, could be bolstering cross-border investigative collaboration, strengthening rapid takedown protocols for harmful material, and building specialised law enforcement units which are equipped with advanced tools that are able to target perpetrators rather than citizens collectively, to achieve a better outcome.  In addition to the fact that private measures would prove better at combating criminal networks, privacy advocates argue that they would also preserve the trust and innovation that Europe has championed for decades, as well as the sense of security that Europe has promoted for decades.  There will be a clear indication of the EU's global leadership position in safeguarding both child safety and civil liberties through this decision, or whether it will serve as a model for other nations to emulate in terms of surveillance frameworks to maintain secure neighbourhoods.
dlvr.it
September 20, 2025 at 2:43 PM