Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

Published

on

Cisco

On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation.

The zero-day flaw impacts all deployment types, including On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).

In a Thursday advisory, Cisco said the issue stems from insufficient validation of user-supplied input, and it can allow local attackers with low privileges to execute arbitrary commands as root.

image

“An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user,” the company explained.

“To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods,” it added. “Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.”

Advertisement

Formerly known as SD-WAN vManage, this network management software helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard.

Cisco’s Product Security Incident Response Team (PSIRT) became aware of CVE-2026-20245 exploitation in June after Google Cloud cybersecurity subsidiary Mandiant reported the flaw but did not share any details.

However, it shared indicators of compromise (IOCs) warning admins to check their SD-WAN /var/log/scripts.log file for attempts to upload tenant configuration data to vSmart controllers to escalate privileges through legitimate commands, as in the following example:


Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0

“For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC,” the company added, advising admins first to generate an admin-tech file to help with the review.

Advertisement

Security patches not yet available

Last month, Cisco also tagged a maximum severity Catalyst SD-WAN Controller authentication bypass flaw (CVE-2026-20182) as actively exploited as a zero-day to gain administrative privileges on unpatched devices.

While Cisco has not yet released patches for CVE-2026-20245, it advised customers to upgrade to the software fixed for CVE-2026-20182 on May 14.

In February, Cisco patched another Catalyst SD-WAN Manager information disclosure security flaw (CVE-2026-20133), which CISA flagged as actively exploited in late April, and, two weeks later, warned that two more flaws (CVE-2026-20128 and CVE-2026-20122) were being abused in the wild.

In March, it also addressed and flagged a critical authentication-bypass vulnerability (CVE-2026-20127) that has been exploited in zero-day attacks since at least 2023.

Advertisement

Over the last several years, CISA has tagged 90 Cisco vulnerabilities as abused in the wild, four of them in Cisco Catalyst SD-WAN Manager and six others exploited by ransomware operations.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

God Of War Laufey Will Hit PS5 On February 16

Published

on

Venture through the afterlife of the gods while playing as Faye.

The next major installment in the God of War franchise, featuring Kratos’ wife Laufey, is set to be released on February 16 of next year. As confirmed during a San Diego Comic-Con panel and on PlayStation’s social media accounts, we’re less than a year away from playing God of War Laufey, which focuses on Laufey as she ventures through the afterlife of gods, following her death in God of War Ragnarok.

Instead of playing as the franchise’s eponymous protagonist, players will get to experience Laufey’s combat prowess, which has only been hinted at in previous games. The release date announcement comes about a month after a sneak peek of gameplay footage that showed off Laufey, also known as Faye, slicing and dicing enemies in the air and using magical abilities while fighting gods and creatures we haven’t seen in the franchise yet.

You can only add God of War Laufey to your wishlist for now, but there’s a lot more to look forward to in the franchise. During San Diego Comic-Con, Santa Monica Studio also confirmed that another Kratos-led God of War game will be coming after this installment featuring Faye, as reported by IGN.

Advertisement

Source link

Advertisement
Continue Reading

Tech

How to watch Liverpool vs Sunderland for FREE: pre-season friendly live streams

Published

on

Today’s Liverpool vs Sunderland live streams signal the start of a new era at Anfield, as Andoni Iraola takes charge of his first game as Reds manager in this pre-season friendly at Geodis Park, Nashville.

The Spaniard was appointed last month following a hugely successful three-year spell at Bournemouth, culminating in a club-record sixth-place finish in the Premier League that saw the Cherries qualify for Europe for the first time. However, expectations are very different at Liverpool, who ended last season one position above Bournemouth but still sacked previous manager Arne Slot, despite the Dutchman leading them to the title 12 months earlier. Iraola’s initial 31-man squad for the US tour, which also includes games against Wrexham and Leeds, features new signing Jeremy Jacquet and the 20-year-old centre back could get his first outing in red against Sunderland.

Source link

Continue Reading

Tech

Roku Streaming Player Prices Jump by Up to $50 as AI Memory Shortage Hits the Living Room

Published

on

Roku built its streaming player business around a simple proposition: spend relatively little money, plug one into an HDMI port and escape whatever miserable interface came installed on the television.

That escape route just became considerably more expensive.

Roku has raised the U.S. list prices of its entire standalone streaming lineup, with the Roku Ultra increasing from $99.99 to $149.99 and the Streaming Stick 4K climbing from $49.99 to $79.99. The hardware has not been redesigned, and Roku has not announced new features to soften the blow. You are paying more for the same streamer because the AI industry has apparently reached the television stand.

Roku Streaming Stick 4K and Ultra debut in 2025

New Roku Streaming Player Prices

The new U.S. list prices are:

Roku Product Previous Price New Price Increase
Roku Streaming Stick $29.99 $39.99 $10
Roku Streaming Stick Plus $39.99 $59.99 $20
Roku Streaming Stick 4K $49.99 $79.99 $30
Roku Ultra $99.99 $149.99 $50
Roku Streambar SE $99.99 $149.99 $50

The Streaming Stick 4K receives the largest percentage increase at approximately 60%, while the Ultra and Streambar SE each rise by 50%. 

Advertisement

Roku is temporarily discounting several products back to their previous prices through its online store, while Amazon, Best Buy and other retailers may continue selling remaining inventory at the older figures until it is replenished. That makes the current sale more useful than the usual countdown clock designed to create panic over a remote control. 

Why Is Roku Raising Prices?

A Roku executive told The Desk that shortages involving memory and other components forced the company to increase prices. Manufacturers have shifted more production capacity toward higher margin chips used by AI data centers, tightening supplies of the less glamorous components found inside streaming players, televisions and other consumer electronics. 

The timing is slightly awkward.

Only in May, Roku CEO Anthony Wood argued that Roku OS required less memory than competing platforms, giving the company a bill of materials advantage as component costs increased. Wood described the situation as “generally great for our business.” Less than three months later, the Roku Ultra costs another $50. 

Advertisement

Roku’s hardware business has never been the company’s largest source of profit. The devices place Roku OS inside more homes, where Roku earns money from advertising, subscriptions, transactions and The Roku Channel. Device revenue fell 16% during the first quarter of 2026, while the platform business generated more than 90% of company income. 

That makes these increases more surprising. Inexpensive hardware has always been the front door to Roku’s considerably more lucrative advertising business.

Advertisement. Scroll to continue reading.

The front door now has a cover charge.

Advertisement

Are Buyers Getting Anything New?

No.

The current Roku Streaming Stick 4K still supports 4K/60Hz video, Dolby Vision, HDR10+, HLG, long range dual band Wi Fi and Dolby encoded audio passthrough. It remains a compact and easy to use streamer, but the specifications are unchanged from the model that cost $49.99 last week. 

The Roku Ultra continues to offer HDMI 2.1, Wi Fi 6, Ethernet, USB playback, Dolby Vision, HDR10+, Dolby Atmos and the rechargeable Voice Remote Pro. Those features made sense at $99.99 and earned the Ultra a clear position above Roku’s sticks. At $149.99, the competition becomes much harder to ignore. 

roku-streaming-stick-4k-with-remote
Roku Streaming Stick 4K

How Do the New Prices Compare?

The $79.99 Roku Streaming Stick 4K now costs twice as much as Amazon’s $39.99 Fire TV Stick 4K Select, which supports 4K and HDR10+ but omits Dolby Vision. Amazon’s $34.99 Fire TV Stick HD also undercuts Roku’s new $39.99 HD model. 

Advertisement

The Google TV Streamer 4K costs $99.99, only $20 more than Roku’s Streaming Stick 4K. Google includes 32GB of storage, 4GB of memory, Dolby Vision, Dolby Atmos, Ethernet, smart home controls and Gemini for TV. It is not as small or portable, but it now looks like the stronger value for a primary home theater system. 

The Roku Ultra remains less expensive than the Apple TV 4K, which now starts at $199, but the gap has narrowed to $49. Apple offers a faster A15 Bionic processor, 64GB of storage, stronger gaming performance, HomeKit integration and tight compatibility with AirPods, HomePods and other Apple hardware. 

Roku still has important advantages. Its interface remains easier to navigate than Fire TV, the platform is broadly neutral about which service receives prominence, and its search and free television offerings are useful. Roku also supports Apple AirPlay, HomeKit, Alexa and Google Home.

The problem is that simplicity feels less persuasive when the simple box costs $150.

Advertisement

Who Should Buy One?

Existing Roku users who value the familiar interface and want another player for a bedroom or secondary television should look for remaining inventory at the old prices.

The Streaming Stick Plus remains the most sensible model for ordinary 4K televisions when discounted to $39.99. Buyers who need Dolby Vision should consider the Streaming Stick 4K, but $79.99 is difficult to recommend when the Google TV Streamer costs only $20 more.

The Ultra still makes sense for users who need Ethernet, USB playback, Wi-Fi 6 and Roku’s best remote. At $149.99, however, it is no longer the automatic premium Roku choice it was at $99.99.

Advertisement. Scroll to continue reading.
Advertisement

The Bottom Line

Roku has not ruined its streaming players. It has damaged the value proposition that made them so easy to recommend. The interface remains approachable, the app support is extensive and the hardware continues to work well. None of that changed when the price tags did.

The Streaming Stick 4K moving from $49.99 to $79.99 is the hardest increase to defend, while the $149.99 Ultra now sits uncomfortably between the more capable $99.99 Google TV Streamer and the considerably more powerful $199 Apple TV 4K.

Roku says component shortages are responsible, and there is ample evidence that AI infrastructure is consuming memory production that once supplied ordinary consumer products. That does not mean buyers need to accept the first new price they see.

Purchase remaining inventory at the old price, wait for the inevitable promotion or compare the alternatives carefully. Roku may still offer one of the cleanest ways to stream television, but cleanliness apparently costs another $10 to $50 now.

Advertisement
Roku Home Screen 2026
Roku on-screen menu

Price & Availability

The new Roku list prices are effective now in the United States.

Roku is currently offering temporary discounts on selected players that return them to their former prices. Amazon, Best Buy and other retailers may also have remaining inventory available at the previous prices.

Source link

Advertisement
Continue Reading

Tech

Top Online Sites Debate Cutting Off Google’s Crawlers

Published

on

Futurism reports:


[Some online publications] are now debating whether to cut Google off entirely, as the Wall Street Journal reports, illustrating an increasingly fraught relationship between the tech giant and the publishers that are creating content its AI models are regurgitating. According to the newspaper, prominent outlets including USA Today, Politico, the Economist, People, and Reuters are all reexamining their relationship with Google. Some are debating whether to continue to work with the tech giant at all… Even Reddit executives are reevaluating the company’s $60 million-a-year contract that allows Google to train its AI models on user-submitted content on the platform. They’ve similarly watched as Google’s AI features discourage users from navigating to Reddit…

Beyond pondering whether to cut Google off, other publishers have resorted to suing the company, accusing it of illegally rehashing their intellectual property via AI summaries.
It’s an extremely undesirable position for publishers. By severing ties with the search giant, they could face even steeper declines in traffic. At the same time, there’s seemingly little to gain from having Google’s AIs crawl their content — and in the long term, it could guarantee their destruction.
Two interesting data points from the article:

  • “Last month, Cloudflare CEO Matthew Prince noticed that automated bot traffic had overtaken human traffic for the first time in the internet’s history.”
  • USA Today has seen its traffic from US users drop by almost half over the last year.”

Advertisement

Source link

Continue Reading

Tech

TikTok risks massive EU fines over online child safety concerns

Published

on

TikTok might have failed to meet EU standards for child safety online.

Allowing content posted by minors to be pushed on TikTok’s ‘For You’ feed could be a violation of the Digital Services Act (DSA), the European Commission has said.

On TikTok, minors can choose to have a public-facing profile. According to EU preliminary findings, this setting enables content published by 16- and 17-year-olds to be algorithmically recommended worldwide.

Exposure like this could result in unwanted contact from bad actors or increase the risk of cyberbullying, the EU said.

Advertisement

The Commission launched formal proceedings into TikTok’s compliance with the DSA in early 2024, which also probed the platform’s potential addictive design and access to data, and resulted in negative preliminary results.

A different line of investigation into the company’s advertising transparency was closed through binding commitments last December.

Today’s (24 July) results are based on an analysis of TikTok’s interface, internal data and documents, as well as interviews with law enforcement officers and child protection experts, according to the Commission.

Content uploaded to the internet is rarely ever removed completely, and the EU said that minors risk lifelong consequences if their content is widely circulated online.

Advertisement

It further said that minors can be easily found through the ‘following’ and ‘followers’ lists of other users even when their accounts are set to ‘private’. Their profile photos also remain accessible to anyone on the internet, including users without a TikTok account.

Under the DSA, platforms accessible to minors must ensure a high level of privacy and safety. TikTok might be failing to meet these standards, the EU said.

The company is up for massive fines of up to 6pc of its global annual turnover if it is ultimately found to be in breach of the law.

The EU wants TikTok to adjust the default settings of minors’ ‘public’ accounts, so that their content is, by default, only visible to those who follow the minor user.

Advertisement

Older minors can have the option of a public-facing account, but their content should never be accessible to a global audience, the Commission warned, arguing that TikTok should not recommend minors’ content to other TikTok users through the For You feed.

“Minors deserve a safe experience from the moment they go online,” said Henna Virkkunen, the Commission’s executive vice-president for tech sovereignty, security and democracy. “A high level of protection should not be an opt-in – it should be the default.”

The investigation, now ongoing for more than two years, also covers the ‘rabbit-hole effect’ of TikTok’s recommender systems and the negative consequences of age-inappropriate experiences on the platform. These probes are still underway.

“Under-18 accounts are private by default and we are one of the only platforms where younger teens cannot use direct messaging or have their content eligible to appear in the For You feed,” a TikTok spokesperson told SiliconRepublic.com.

Advertisement

The ByteDance-owned company said it would continue to engage constructively with the Commission.

TikTok accounts of users under 18 are automatically set to private, the company said, noting that users must be at least 16 to use direct messaging or have their content eligible to appear in the For You feed.

The company also said that it does not recommend accounts belonging to teens to users over 18. It said that users can only find private accounts of minors using ‘followers’ lists if the minor has chosen to make the list public instead of private.

Governments worldwide are cracking down on social media platforms to protect children from online harms, with Australia becoming the first country to blanket-ban major platforms for children under 16.

Advertisement

The EU, has, for years, targeted social media giants for their addictive designs, recommender system feeds and child safety measures with its landmark DSA that carries a hefty penalty for offenders.

The bloc is now considering age-gating sites as a means to address the wider concerns surrounding social media usage by children. France, earlier this week, became the first EU country to ban social media for under-15s.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

Continue Reading

Tech

Qobuz Mobile App Adds Synchronized Lyrics, Translations and a Smarter Player

Published

on

Qobuz has never had much trouble convincing audiophiles that it sounds good. Convincing them that its app was equally polished has occasionally required a more generous interpretation of the word “polished.”

The latest Qobuz mobile update addresses that problem with a redesigned player for iOS and Android, adding synchronized lyrics, lyric translations, improved queue management and more direct access to recommendations, credits, artist biographies and album descriptions. Version 10.0 reached Apple devices this week, followed by version 10.0.1, while the same feature set is now listed through Google Play. 

What Is New?

The redesigned player adds:

  • Time synchronized lyrics
  • Lyric translations where available
  • Recommendations directly from the playback screen
  • Faster access to song credits
  • Artist biographies and album descriptions
  • Autoplay controls
  • Swipe gestures
  • Simplified queue management

The new interface keeps more of Qobuz’s editorial and metadata features close to the music rather than sending listeners through several menus to discover who played bass, produced the album or wrote the review. 

That may sound like routine housekeeping, but Qobuz users have waited a long time for built-in lyrics. Until now, anyone determined to follow along had to use a third-party service or remember the words, which becomes increasingly unreliable somewhere after the second verse.

Advertisement
qobuz-mobile-app-2026

Lyrics Are Not Unique, but the Context Is

Apple Music and Spotify already offer synchronized lyrics and translations, so Qobuz is not inventing a new category.

What makes the update more interesting is how lyrics now sit beside the service’s existing editorial material, detailed credits, album reviews, biographies and high-resolution playback. Qobuz is trying to create a richer listening screen rather than merely enlarging the album cover and placing another AI button underneath it.

That approach fits the platform. Qobuz has consistently emphasized human curation and music journalism, with more than 500,000 pieces of editorial content alongside a catalog of more than 100 million lossless and high-resolution tracks. 

Spotify remains stronger at social discovery and algorithmic recommendations. Apple Music integrates more naturally across Apple hardware. Qobuz’s advantage is that it still behaves as though listeners may want to know something about the album beyond whether the algorithm believes it is suitable for Tuesday afternoon.

Advertisement

Why Should Qobuz Users Care?

The new player reduces friction.

Listeners can examine lyrics, translations, credits, biographies and recommendations without constantly leaving the playback screen. Better queue controls and visible autoplay settings should also make it easier to understand what the app intends to play next, which has not always been one of streaming software’s great acts of transparency.

Advertisement. Scroll to continue reading.

The update becomes more useful when paired with Qobuz Connect. A phone or tablet can serve as the control interface while compatible streamers, amplifiers and powered speakers pull the lossless or high-resolution stream directly from Qobuz. The mobile app therefore matters even when the phone is not the device producing the sound. 

Advertisement

Qobuz Connect now supports more than 100 hardware and software partners, making the quality of the mobile control experience far more important than it was when listeners often had to use a manufacturer’s own app. 

Qobuz Connect Diagram

What Is Still Missing?

The update improves playback and discovery, but it does not solve every Qobuz weakness.

The service still trails Spotify and Apple Music in social features, collaborative listening and some forms of personalized discovery. Lyric availability and translations will also depend on the underlying catalog data, so users should not expect every obscure jazz pressing or regional release to suddenly become karaoke-ready.

Qobuz has also described this as a mobile redesign. Desktop and connected television users should not assume they are receiving the same interface immediately.

Advertisement
qobuz-app-explore-2026
New “Explore” section offers similar albums and artists, radio stations, and playlists, alongside content linked to the label or musical genre.

The Bottom Line

Qobuz did not need another audio-quality logo. It needed a better player.

Synchronized lyrics and translations bring the service closer to feature parity with Apple Music and Spotify, while the improved queue controls, credits and editorial access play directly to Qobuz’s actual strengths.

The update is not revolutionary, but it makes the app easier to use and gives subscribers more information without turning every listening session into a conversation with an AI assistant.

For a service that charges $12.99 monthly or an effective $10.83 per month with an annual Studio Solo subscription, that is a more convincing improvement than simply raising the price and blaming licensing costs. 

Advertisement

Availability

The redesigned Qobuz player is available now through the latest Qobuz apps for iOS, iPadOS and Android. Try Qobuz for free.

Source link

Advertisement
Continue Reading

Tech

Add Sensors To Everything! | Hackaday

Published

on

“You can’t control what you can’t measure” goes the old chestnut. But that’s a little bit negative, in my opinion. Instead, think of the benefits of sprinkling sensors around everywhere: you gain insight where you simply didn’t have it beforehand.

We were thinking about this in the context of the recent video on pressure advance in 3D printers. Essentially, the unmelted filament acts as a springy piston, and that springiness means that the pressure built up in the melted plastic lags the feedrate of new filament. We usually calibrate this out with a guesstimate constant, but it can be different for every different filament. Measuring that pressure directly with a strain gauge in the hot end makes more sense.

But then there are knock-on benefits of having a sensor in the hot end. You can use the strain gauge as Prusa does to run the nozzle gently into the bed and set the z-axis height. Or you can use over-pressure as a sign that the nozzle is clogged. It’s quite possible that you can use it to signal other things that can go wrong as well, but you can’t tell until you put the sensor on in the first place.

Advertisement

Of course, you don’t want to put a pressure sensor where you want to know the temperature, or vice-versa. But as a general rule, the more you can measure, the more you can discover about the way your system is running. How many strain gauges are too many?

Source link

Advertisement
Continue Reading

Tech

3D On The Playdate Handheld

Published

on

The Playdate is a small handheld console with a dedicated fanbase. Among them is [Cristina Ramos], who recently decided to try and push the limits of the hardware by implementing a 3D renderer for the platform.

[Cristina] began by implementing a raycaster. This is a very simple way to do 3D on limited hardware, and this technique was used by some early games like Wolfenstein 3D. However, for [Cristina], it was more a test to get an idea of the performance limitations of the Playdate. After getting her feet wet with that, she stepped up to implementing a renderer that relied on binary space partitioning, which could load map files in the same format used by the classic Quake engine. There was naturally plenty of work to do to handle things like texture mapping and lighting, too, particularly given the vagaries of working with the Playdate’s 1-bit monochrome screen. Using a simplistic, cel-shaded like approach for textures gave things a good look while preserving visual readability on the low-resolution screen.

The 3D engine and associated game remain a work in progress for [Cristina] — we look forward to seeing where the project goes next. We’ve seen similar projects on resource-limited platforms before, too.

Advertisement

I was told you couldn’t do 3D on the Playdate, so I did it.Then I was told there was no way I could create exterior levels like those in Mirror’s Edge, so I proved them wrong again.

Cristina Ramos (@saffroncr.bsky.social) 2026-07-22T08:57:09.594Z

Source link

Advertisement
Continue Reading

Tech

Facebook Verified is here to confirm whether your friend is AI

Published

on

Meta has announced Facebook Verified, a free badge that will be visible on a user’s profile and is designed to confirm whether that user is a real person or an AI without actually checking that a user is who they say they are.

The new badge is separate from Meta’s existing Meta Verified program and is available to eligible Facebook users who are 18 or older. Users must also be in good standing with Facebook’s community standards before they can be verified.

Alongside profiles, Facebook users will also be able to see a person’s verified status in the Marketplace, Facebook Dating, and Facebook Groups initially. However, Meta has confirmed that it intends to bring the badges to the main feed in the future.

Free, basic verification

Importantly, unlike Meta Verified, Facebook Verified doesn’t require a subscription and is available absolutely free. Users only need to complete the verification process once.

Advertisement

The verification process itself requires Facebook users to record a short selfie video. Facebook then uses the video to check the person’s appearance against their existing profile photos to confirm a match. The process should take just a few minutes.

However, it’s important to know what Facebook Verified actually verifies. Meta says that it means a profile belongs to a real person, not an AI.

Facebook Verified does not necessarily mean that the person is who they say they are. That’s an important distinction to remember when using Facebook from here on out.

Meta says that Facebook Verified will roll out in phases, starting with “select markets.” Unfortunately, it hasn’t confirmed which markets those are.

Advertisement

Source link

Continue Reading

Tech

Malicious sites use JavaScript to build malware in browser memory

Published

on

Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory.

The operation has been active since late 2024 and is localized to 25 languages in 12 countries, primarily in Asia Pacific and Latin America.

A filtering system ensures that only real targets (retail traders and crypto investors) land on the malicious pages, while researchers, scanners, and security bots are redirected to blank pages.

image

Ad security platform Confiant says that the campaign’s design stands out through its use of the web browser as “a local assembly pipeline” for the malware.

Although the fake portals feature a download button, a ReactJS library on the landing page prepares the browser for a managed download flow, a process typically used for handling various types of file transfers.

Advertisement
Fake Trading View site
Fake TradingView site
Source: Confiant

According to Confiant’s analysis, the page first registers a service worker, which acts as a download manager and helps build the malware file incrementally.

In the first stage, the page sets up a shared worker that acts as an engine that assembles the malware from components received in the next steps of the attack.

The researchers say that in the second stage “the landing page uses its SharedWorker to request itself for a ‘/config’ response” with seed and size parameters that are randomized and specific for each session.

By rotating these parameters, the threat actors make sure that the resulting malware file has a unique hash to bypass static detection.

Confiant explains that “‘/config’ is an assembly response rather than a normal download response. It returns a template and the inputs the browser needs to build the file locally.”

Advertisement

Remote components retrieved this way and the locally generated bytes are then used to create the malicious payload from a clean version of the Bun executable.

After building the final malware executable, the fake download page hands it to the service worker at the beginning of the process and triggers a same-origin download path.

“From the browser’s point of view, the user is downloading an executable from the landing page domain,” Confiant researchers say, and the mark-of-the-web tag is added, despite some of the components originating from a different source.

The advantage of this technique is that no finished file is transmitted over the network, making detection less likely, and analysis becomes more challenging.

Advertisement

Confiant says that earlier variants of the SourTrade campaign used the StreamSaver project on GitHub to deliver the malicious payload. Since April, though, the operation switched to the same-origin ServiceWorker delivery method.

While Confiant researchers do not reveal the nature of the payload, they found evidence supporting a Bitdefender report in 2025 about a resilient  malvertising campaign that used StreamSaver to distribute malware.

Bitdefender found that the payload had the following capabilities:

  • intercept all user network traffic (acting as a proxy)
  • collect cookie and password data
  • record keystrokes (keylogging) and take screenshots
  • steal cryptocurrency wallet data
  • establish long-term persistence

Since the SourTrade campaign targets retail traders and crypto investors, users engaged in these activities are advised to avoid downloading financial or cryptocurrency apps from social media advertisements or sponsored search results.

The researchers advise getting executable files from the company’s official website. As an added precaution, they should verify the installer’s digital signature and publisher before running it.

Advertisement

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Continue Reading

Trending

Copyright © 2025