Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

Fake Claude app promoted by Bing ads pushes SectopRAT malware

Published

on

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.

At least 29 organizations were compromised between July 21-22 during the malicious operation, which researchers call FakeAgent.

The attacker uses a malicious Claude Artifact hosted on Claude’s legitimate domain, which is a common tactic that has been used 

image

The attackers used a malicious Claude Artifact hosted on Claude’s legitimate domain, a tactic that has been used at the beginning of the year to push macOS malware via ClickFix lures.

Researchers at managed security company Huntress found that the malicious Claude Artifact, downloaded 7,100 times before Anthropic removed it, directed visitors to websites that hosted a fake installer named ClaudeDesktop.exe.

Advertisement
The malicious artifact resembling a download portal
Phishing page hosted as a Claude artifact
Source: Huntress

However, the file is a legitimate JetBrains Chromium component that sideloads a malicious DLL (libcef.dll) to deliver the SectopRAT remote access trojan with info-stealing capabilities.

Persistence on the system is achieved through another executable named DockerDesktop.exe, which installs a scheduled task.

Huntress says that the various loaders and staging components used in the infection chain feature anti-analysis mechanisms, including VMProtect packing, shader timing checks, GPU and VRAM checks, and virtual machine (VM) detection.

The SectopRAT malware was recently observed being distributed via CastleLoader campaigns and ClickFix attacks.

The malware uses the EtherHiding technique to retrieve a working command-and-control (C2) address via Ethereum BNB Smart Chain transactions.

Advertisement

SectopRAT, also known as ArechClient2, has been active since 2019 and is an information-stealer with HVNC (Hidden Virtual Network Computing) functionality. It allows remote hands-on operations and real-time interaction with the compromised system.

The malware targets user passwords, credit card data, files, browser logins and cookies, FTP credentials, data from various messaging clients, including Discord and Telegram, Steam, and VPN products.

The malicious Bing search results
Malicious Bing search results
Source: Huntress

In an interesting twist, Huntress reports it used Claude Opus 4.8 to assist with shader emulation, cryptographic reconstruction, and .NET code analysis.

Analysis of the decrypted .NET payload (SectopRAT) helped attribute the attacks to SectopRAT operations, or a closely related fork, and opened the path to infrastructure analysis.

At that stage, the researchers found 10 domains registered to the same email address since December 2025, with one of them previously linked to the StealC distribution and seized during Operation Endgame.

Advertisement

Huntress does not have enough evidence to attribute the FakeAgent campaign to a specific, known threat cluster.

Users looking for software should trust official websites and download portals, instead of search results, especially sponsored ones.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Scientists made robots curious like toddlers, and it helped them learn language twice as fast

Published

on

Scientists have been trying to figure out how kids pick up language so fast for decades, and a new study out of the Okinawa Institute of Science and Technology (OIST) might have cracked part of the puzzle: curiosity.

Researchers built a virtual robot with a brain-inspired neural network and set it loose in a simulated 3D world full of shapes, colors, and simple commands like “push left magenta dumbbell.” 

Some robots were rewarded only for completing tasks correctly. Others got an extra reward for curiosity, essentially getting a little internal high whenever they encountered something that challenged their existing understanding of the world.

How does curiosity help a robot learn language?

The curious robots didn’t just edge out their indifferent counterparts; they blew past them. According to the study, published in Science Advances, curious robots reached a genuine understanding of language in about half the time. 

Advertisement

Study author Theodore Tinker compared it to trying white chocolate for the first time even though you already love dark chocolate. You take the risk anyway, and you walk away knowing more about chocolate in general.

Things got even more interesting halfway through training. The curious robots started knocking things over and experimenting with actions nobody asked for, basically playing. Nobody programmed that behavior in. It just showed up on its own.

Do robots really make the same mistakes as toddlers?

The robots also mimicked a well-known quirk in how children learn language. Kids often get certain verb forms right at first, then start applying grammar rules too broadly and make mistakes on verbs they’d previously used correctly, before eventually sorting out the exceptions and correcting themselves. The robots followed the same U-shaped dip in performance.

Advertisement

It’s also a nice contrast to how today’s chatbots learn. Large language models like ChatGPT train on massive datasets and spit out the statistically likely next word. This robot’s brain works more like ours, prioritizing accuracy while trying to keep its beliefs intact, only updating them when something surprises it enough to be worth the trouble.

None of this means robots understand language the way we do. But it does suggest that curiosity paired with a wide variety of experiences might be a big part of how toddlers crack the language code with so little to go on.

Source link

Advertisement
Continue Reading

Tech

AMD is investing $5 billion in Anthropic and deploying 2 gigawatts of Helios GPUs to run Claude

Published

on

TL;DR

AMD will invest up to $5B in Anthropic and deploy 2GW of MI450 GPUs. Claude will accelerate ROCm development. First GW ships H1 2027. Anthropic already uses MI355X GPUs.

AMD and Anthropic announced a strategic partnership on Tuesday that commits AMD to invest up to $5 billion in Anthropic and deploy up to 2 gigawatts of AMD Instinct MI450 Series GPUs in Helios rackscale solutions to run Claude. Deployment of the first gigawatt begins in the first half of 2027. Anthropic is already using AMD’s MI355X GPUs and will now scale to MI455X accelerators paired with EPYC “Venice” CPUs and Pensando networking.

The engineering collaboration may matter more than the hardware. AMD and Anthropic will use Claude to optimise workloads for AMD Instinct GPUs and accelerate ROCm software development. AMD will also adopt Claude broadly across its engineering and product development teams. ROCm is AMD’s answer to Nvidia’s CUDA, and its software gap has been the primary reason AI developers default to Nvidia hardware even when AMD’s specs are competitive. If Claude can materially improve ROCm’s developer experience, AMD addresses the problem that has held it back for years, using its customer’s AI to fix its own software.

Anthropic’s compute strategy is now genuinely multi-vendor. Anthropic signed its biggest compute deal with Google and Broadcom, and has separate arrangements with Amazon (Trainium chips, 5GW), CoreWeave (Nvidia GPUs), and SpaceX (Colossus data centres). Adding 2GW of AMD Helios gives Anthropic what Tom Brown, its chief compute officer, called the ability to “map the right workloads to the right hardware.” Diversifying away from any single chip vendor reduces dependency risk at a time when compute is the binding constraint on frontier model development.

Advertisement

For AMD, the $5 billion equity investment mirrors Nvidia’s playbook. Nvidia invested $2 billion in Nebius and has taken stakes in multiple AI infrastructure companies to lock in hardware demand. AMD is doing the same: investing in a customer to guarantee that its chips, not Nvidia’s, run a meaningful share of the world’s most capable AI models. Lisa Su called it “a major platform for the next generation of AI infrastructure.” Whether Helios can compete with Nvidia’s NVL72 at production scale is the question the first gigawatt will answer.

Source link

Advertisement
Continue Reading

Tech

Kalanick raises $1.7B for Atoms, and Uber invests too

Published

on

Travis Kalanick is back, and Uber is helping to fund him. The founder Uber forced out in 2017 has raised $1.7 billion for Atoms, an industrial-AI and robotics company he has built in near-total stealth for years.

Andreessen Horowitz led the round. Its co-founder Ben Horowitz is joining the board. And among the investors sits Uber, the company Kalanick started in 2009 and left under a cloud.

That exit still shadows the story. Uber pushed Kalanick out as chief executive in 2017 after complaints of sexual harassment, discrimination and a toxic workplace. Nine years on, his old company is writing him a cheque. Kalanick, never one for understatement, calls the round “unfinished business”.

The equity comes with serious debt. Alongside a16z, Bain Capital, Fifth Wall and others, Atoms lined up credit facilities from JPMorgan, Goldman Sachs, Bank of America, Wells Fargo and Barclays. The company did not disclose a valuation. That is the kind of firepower needed to build heavy machines, not apps.

Advertisement

Bits to atoms

Kalanick’s pitch is a single idea he has chased for 16 years: turning the physical world into something software can run. In his framing, manufacturing is the processor, real estate is the storage, and transport is the network. Uber digitised transport for the masses.

CloudKitchens, his ghost-kitchen venture, did the same for food. Atoms is meant to do it for whole industrial sectors. He calls the result an “atoms-based computer.”

The target is the unglamorous heart of the economy: mining, construction, heavy transport and food. His term for the toolkit is Industrial AI, a mix of software, sensors, robotics and models aimed at automating entire sectors. He calls the wider shift the “Age of Atoms.”

Not a humanoid in sight

Here Kalanick parts ways with much of the field. While rivals pour billions into general-purpose humanoid robots, Atoms builds specialised machines for specific jobs. Horowitz argues that purpose-built hardware copes with brutal industrial environments far better than a humanoid could. It is a pointed bet against the hottest trend in physical AI.

Advertisement

Atoms is split into three parts, according to reports. Atoms Food folds in CloudKitchens and its cooking and delivery software. Atoms Mining puts autonomous machines to work at extraction sites, built on Atoms’ acquisition of Pronto, a startup run by former Uber and Google engineer Anthony Levandowski.

Atoms Transport is what Kalanick calls a “wheelbase for robots.”

Levandowski’s presence adds intrigue. He sat at the centre of a self-driving trade-secrets case involving Google and Uber, and later received a presidential pardon. Kalanick has also flirted with buying the US arm of China’s Pony AI, with Uber’s help, though those talks ended earlier this year.

Comeback, with caveats

The mood around the deal is euphoric. One a16z partner called it the largest cheque the firm has ever written. Another investor predicted Atoms would be worth a trillion dollars within a decade. Horowitz put it more simply: “Travis is back.”

Advertisement

Some scepticism is warranted. Atoms has revealed a grand vision and a very large bank balance, but little in the way of deployed industrial robots at scale. The valuation is a mystery, the claims are sweeping, and Kalanick’s Uber record is not easily forgotten. Yet the bet is coherent.

He turned the movement of people into a software business once. Now, with $1.7 billion and his old adversary alongside him, he wants to do the same to the machines that grow, dig and haul the physical world.

Source link

Advertisement
Continue Reading

Tech

Mobileye CEO Amnon Shashua to step aside as company pushes into robotaxis, robotics

Published

on

Mobileye founder and CEO Amnon Shashua plans to step down from the top leadership post after nearly three decades, just as the company pushes into robotaxis and humanoid robots.

Shashua will remain CEO until Mobileye hires a replacement, according to a regulatory filing Thursday.

Mobileye got its start making computer vision chips based on Shashua’s academic research at Hebrew University in Israel, and grew into a major supplier of the chips that power automotive safety and driver-assistance features. It had the largest IPO in Israel’s history, was acquired in 2017 by Intel for $15.3 billion, then spun back out as a publicly traded company in 2022, though Intel remains its largest shareholder.

Under Shashua, Mobileye also moved beyond selling chips to automakers and began building its own systems that handle autonomous driving, which it now supplies to Volkswagen and its MOIA subsidiary.

Advertisement

In January, the company acquired Shashua’s humanoid robotics startup Mentee Robotics for $900 million, which Shashua called part of “Mobileye 3.0,” the next phase of the business focused on robotics and automotive AI.

Mobileye also said in June it would expand beyond its supplier status to launch its own robotaxi service in a U.S. city in 2027.

Source link

Advertisement
Continue Reading

Tech

Microsoft commits $60M to ‘Genesis Mission’ to help power Dept. of Energy’s AI-for-science push

Published

on

(GeekWire File Photo / Todd Bishop)

Microsoft is putting $60 million behind the U.S. Department of Energy’s Genesis Mission, a push to use artificial intelligence to speed up scientific research across the government’s 17 national labs.

The company’s investment is split into two pieces: $40 million in Azure cloud computing and AI credits over three years, and $20 million for engineering and deployment help to get DOE researchers actually using the tools, Microsoft said in a blog post Wednesday.

Microsoft is also launching a new internal group called SPARK — Scientific Partnership Advancing Research & Knowledge — to serve as the single point of contact between the company and DOE on Genesis Mission work. It’s meant to combine Microsoft’s program management, engineering, security and research teams into one coordinated effort, instead of leaving individual labs to navigate Microsoft on their own.

President Trump created the Genesis Mission through an executive order in November 2025, directing DOE to build a unified computing and data platform — since named the American Science and Security Platform — that connects the national labs’ supercomputers, AI tools and scientific datasets.

The order likened the effort’s urgency and ambition to the Manhattan Project, and the White House said it’s expanded into a whole-of-government initiative involving more than 15 federal agencies, backed by more than $5 billion in commitments.

Advertisement

Microsoft named four initial projects taking shape under the partnership, including work with Pacific Northwest National Laboratory in Richland, Wash., to speed up the discovery of new energy storage materials — cutting analysis that used to take years down to weeks — and autonomous lab work with Lawrence Livermore National Laboratory aimed at detecting biological threats earlier.

“We move faster together,” Chris Barry, president of Microsoft’s U.S. Public Sector business, wrote in the blog post announcing the commitment, framing the investment as both a “national security imperative” and economic opportunity for the U.S.

Microsoft isn’t the only Seattle-area cloud giant courting the Genesis Mission. Amazon Web Services was recognized by DOE as a Genesis Mission supporter in December, highlighting its work with Idaho National Laboratory on AI tools for nuclear reactor design, and the company launched its own Genesis Accelerator Initiative in February, offering up to $50 million in cloud credits for DOE-related research over three years.

Google also announced Wednesday that it was committing $40 million of AI tokens and cloud credits for researchers in support of the Genesis Mission.

Advertisement

Source link

Continue Reading

Tech

Google Is Expanding Access To Its Gemini Spark Agentic AI Assistant

Published

on

More Google AI Pro and Ultra users will now have access to Spark.

Google is making Gemini Spark, the agentic AI assistant it announced at this year’s I/O developer conference, available to more people. Unfortunately, they still don’t include free users. In the US, Spark is rolling out to everyone paying $20 a month for Google AI Pro. It’s also rolling out globally to Google AI Ultra users, who are paying between $100 to $200 a month for their subscription…unless they’re in the European Economic Area, Switzerland, the UK and Nigeria. Those who can now access Spark with this expansion may want to check if it also comes with local language support. 

Spark is powered by Gemini 3.5 and is deeply integrated into Google’s Workspace apps. Users can assign tasks to it by going to the Spark page, either via the sidebar on a computer or by tapping on the option under menu on mobile. From there, they can type in the tasks they want Spark to do. They can tell Spark, for instance, to check their emails and calendar schedules every morning and then let them know what to prioritize. Spark can also automatically create draft responses for when emails from a particular person hit the user’s inbox, or summarize lengthy email threads. Users can use Spark to create detailed reports in Google Docs from meeting notes and emails, as well. As these are only a few possible tasks for Spark, users can check out Google’s support pages for more information. 

Advertisement

Source link

Continue Reading

Tech

Tails Download Free – 7.10

Published

on

Tails helps you to use the Internet anonymously and circumvent censorship almost anywhere you go and on any computer but leaving no trace unless you ask it to explicitly.

Tails is a complete OS designed to be used from a DVD, USB stick, or SD card independently of the computer’s original operating system. Start on your Tails USB stick instead of starting on Windows, macOS, or Linux. Tails leaves no trace on the computer when shut down.

Tails helps you to:

  • Use the Internet anonymously and circumvent censorship
  • All connections to the Internet are forced to go through the Tor network
  • Leave no trace on the computer you are using unless you ask it explicitly
  • Use state-of-the-art cryptographic tools to encrypt your files, emails and instant messaging

Tails includes a selection of applications to work on sensitive documents and communicate securely. It comes with several built-in applications pre-configured with security in mind: web browser, instant messaging client, email client, office suite, image and sound editor, etc.

If you are interested in giving Tails a try on your current computer without running any risk, please check out our Guide: Running Linux From a USB Drive As a Virtual Machine or Bootable Disk.

Advertisement

What is Tails?

Tails is a portable Linux distribution based on Debian that combines the Tor network, the GNOME desktop and several other tools to offer a secure and anonymous computer experience.

How safe is Tails?

Tails is very safe as long as you do not run it on an infected machine. Tails is designed to run from a USB stick on any computer as a completely independent OS. However, if the host computer is infected with malware such as a keylogger your privacy would be at risk.

How does Tails ensure privacy?

Tails is set up out of the box to run from your computer’s memory and never stores information locally unless you configure it to. This means that every time you shut down Tails, the memory is wiped clean, deleting all traces of your work and every new session starts as a blank slate.

Can I use Tails to circumvent censorship?

Yes, you can use Tails to circumvent internet censorship and browse the web anonymously. All the applications that come with Tails (email, browser, messaging client, office suite) use the Tor network to connect to the internet, so all your activity can be hidden.

Advertisement

Online anonymity and censorship circumvention with Tor

Tails relies on the Tor anonymity network to protect your privacy online:

  • all software is configured to connect to the Internet through Tor
  • if an application tries to connect to the Internet directly, the connection is automatically blocked for security.

Tor is free software and an open network that helps you defend against a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security known as traffic analysis.

Tor protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody watching your Internet connection from learning what sites you visit, and it prevents the sites you visit from learning your physical location.

Using Tor you can:

Advertisement
  • be anonymous online by hiding your location
  • connect to services that would be censored otherwise
  • resist attacks that block the usage of Tor using circumvention tools such as bridges

Detection of problems with Wi-Fi hardware

Problems with Wi-Fi are unfortunately quite common in Tails and Linux in general.

To help troubleshoot hardware compatibility issues with Wi-Fi interfaces, the Tor Connection assistant now reports when no Wi-Fi hardware is detected.

What’s New

New shutdown procedure

Tails now uses the standard shutdown procedure from GNOME.

Advertisement

The standard shutdown procedure is a bit slower, but better prevents data loss.

For example, the Power Off confirmation dialog informs you if an application needs to be closed or an open document needs to be saved before shutting down.

Even without confirming or saving the open documents, Tails will shut down after 60 seconds.

You can still use the faster emergency shutdown as before.

Advertisement

Celluloid video player

We replaced GNOME Videos with Celluloid, a more modern and reliable video player.

For added security, Celluloid cannot access the network. You can either:

  • Open online videos, like MP4 and AVI files, in Tor Browser.
  • Open online streaming addresses, like IPTV and HLS addresses, in VLC, installed as additional software.

Celluloid doesn’t work on some computer from 2011 or earlier.

  • You can use VLC instead, installed as additional software.

Changes and updates

  • Update Tor Browser to 15.0.19.
  • Update some firmware packages. This improves support for newer hardware: graphics, Wi-Fi, and so on.

For more details, read our changelog

Tails 7.6 changelog

Advertisement
  • Automatic Tor bridges
  • You can now learn about Tor bridges directly from the Tor Connection assistant in Tails.
  • Tor bridges are secret Tor relays that hide that you are connecting to Tor. If connecting to Tor is blocked from where you are, you can use a bridge as your first Tor relay to circumvent this censorship.
  • In Tails 7.6, choose Connect to Tor automatically when opening Tor Connection. If access to the Tor network is blocked, the bridge configuration screen offers a new option called Ask for a Tor bridge based on your region.

  • This feature uses the same technology as the connection assistant in Tor Browser outside of Tails, which was introduced in Tor Browser 11.5 (July 2022).
  • Tails downloads information about bridges that are most likely to work in your region from the Moat API of the Tor Project. To circumvent censorship, this connection is disguised as a connection to another website using domain fronting.

GNOME Secrets

  • In Tails 7.6, the Secrets password manager replaces KeePassXC.
  • Secrets has a simpler interface and is better integrated in the GNOME desktop. For example, accessibility features, such as the screen keyboard and cursor size, are working again with Secrets.
  • Secrets offers to unlock your previous KeePassXC database automatically, because both Secrets and KeePassXC use the same file format to store passwords.
  • If you miss more advanced features from KeePassXC, you can install KeePassXC as additional software.

Tor Browser 7.4.2 Changelog

Changes and updates

  • Update the Linux kernel to 6.12.69, which fixes DSA 6126-1, multiple security vulnerabilities that could allow an application in Tails to gain administration privileges.
  • For example, if an attacker was able to exploit other unknown security vulnerabilities in an application included in Tails, they might then use DSA 6126-1 to take full control of your Tails and deanonymize you.
  • This attack is very unlikely, but could be performed by a strong attacker, such as a government or a hacking firm. We are not aware of this attack being used in practice.
  • Update Thunderbird to 140.7.1.

Fixed problems

  • Fix opening the Wi-Fi settings from the Tor Connection assistant. (#18587)
  • Fix reopening Electrum when it was not closed cleanly. (#21390)
  • Fix applying the language saved to the USB stick in the Welcome Screen. (#21383)

Tails 7.4.1

Included software

  • Update the OpenSSL library to 3.5.4, which fixes DSA 6113-1, a set of vulnerabilities that could be critical. Using this set of vulnerabilities, an malicious Tor relay might be able to deanonymize a Tails user. We are not aware of these vulnerabilities being exploited in practice.
  • Update the Tor client to 0.4.8.22.
  • Update Thunderbird to 140.7.0.

Fixed problems

  • Fix Gmail authentication in Thunderbird. (#21384)
  • Add a spinner when opening the Wi-Fi settings from the Tor Connection assistant. (#18594)

Tails 7.4 Changelog

  • Update Tor Browser to 15.0.1.
  • Tor Browser 15.0 is based on Firefox 140 and inherits from it several new features that are particularly useful if you use many tabs:
    • Vertical tabs
    • Tab groups
    • New address bar with improved search
  • Update Thunderbird to 140.4.0.
  • Update the Linux kernel to 6.12.57.
  • Remove Root Console.
  • To open a root console, you can execute the following command in a Console. sudo -i
  • Show Don’t ask again notifications only after the clock has been synchronized.

Tails 7.1 Changelog

Changes and updates

  • Change the home page of Tor Browser in Tails to an offline page, very similar to the home page of Tor Browser outside of Tails, instead of an online page from our website.
  • Improve the message when an administration password is required to open an application but no administration password was set in the Welcome Screen.
  • Update Tor Browser to 14.5.8.
  • Update the Tor client to 0.4.8.19.
  • Update Thunderbird to 140.3.0.
  • Remove the package ifupdown.

Fixed problems

  • Hide the message “Your connection to Tor is not being managed by Tor Browser” in new tabs of Tor Browser. (#21215)

Tails 7.0 Changelog

Tails 7.0 is dedicated to the memory of Lunar (1982 – 2024). Lunar was a traveling companion for Tails, a Tor volunteer, Free Software hacker, and community organizer.

Advertisement

Lunar has always been by our side throughout Tails’ history. From the first baby steps of the project that eventually became Tails, to the merge with Tor, he’s provided sensible technical suggestions, out-of-the-box product design ideas, outreach support, and caring organizational advice.

Outside of Tor, Lunar worked on highly successful Free Software projects such as the Debian project, the Linux distribution on which Tails is based, and the Reproducible Builds project, which helps us verify the integrity of Tails releases.

Lunar will be deeply missed, both in our community and in the many other communities he participated in.

Faster startup

Advertisement

Tails 7.0 starts 10 – 15 seconds faster on most computers.

We achieve this by changing the compression algorithm of the Tails USB and ISO images from xz to zstd. As a consequence, the image is 10% bigger than it would be with the previous algorithm.

While testing this change, we noticed that Tails on USB sticks of poor quality can also start 20 seconds slower than on quality USB sticks.

If you are in a place where counterfeit electronics are common, we recommend that you buy your USB stick from an international supermarket chain, which should have a more reliable supply chain.

Advertisement

Included software

  • Replace GNOME Terminal with GNOME Console.
  • Replace GNOME Image Viewer with GNOME Loupe.
  • Update Tor Browser to 14.5.7.
  • Update the Tor client to 0.4.8.17.
  • Update Thunderbird to 128.14.0esr.
  • Update Electrum from 4.3.4 to 4.5.8.
  • Update OnionShare from 2.6.2 to 2.6.3.
  • Update KeePassXC from 2.7.4 to 2.7.10.
  • Update Kleopatra from 4:22.12 to 4:24.12
  • Update Inkscape from 1.2.2 to 1.4.
  • Update GIMP from 2.10.34 to 3.0.4.
  • Update Audacity from 3.2.4 to 3.7.3.
  • Update Text Editor from 43.2 to 48.3.
  • Update Document Scanner from 42.5 to 46.0.

Changes in GNOME

  • Many sections of the Settings utility have been redesigned, for example Accessibility, Sound, and Mouse & Keyboard in GNOME 44
  • Accessibility settings also include new accessibility features, such as Overamplication and Always Show Scrollbars.
  • The Activities button has been replaced with a dynamic workspace indicator in GNOME 45.
  • The Screen Reader has been improved in different ways, for example, with better table navigation and a sleep mode in GNOME 46.
  • A new option to preserve battery health is available in the power settings in GNOME 48.

Removals

  • Remove the Places menu.
  • You can access the same shortcuts from the sidebar of the Files browser.
  • Remove Kleopatra from the Favorites menu.
  • To start Kleopatra, choose Apps ▸ Accessories ▸ Kleopatra.
  • Remove unar.
  • The File Roller utility still opens most RAR archives.
  • Remove the aircrack-ng package.
  • You can still install aircrack-ng using the Additional Software feature.
  • Remove the Power Statistics utility.
  • Remove the sq package.
  • Remove the obsolete Network Connection option from the Welcome Screen.

Hardware support

  • Update the Linux kernel to 6.12.43.
  • This improves support for newer hardware: graphics, Wi-Fi, and so on.
  • Increase the memory requirements from 2 GB of RAM to 3 GB. (#21114)
  • Tails 7.0 displays a notification when the RAM requirements are not met.
  • We estimate that less than 2% of users are affected.

Previous release notes

  • Update Tor Browser to 14.5.6.
  • Update the Tor client to 0.4.8.17.
  • Update Thunderbird to 128.13.0.

Changes and updates

  • Add a Show Password option when setting the screen locking password.

Fixed problems

  • Remove irrelevant error message when configuring bridges in Tor Connection.
  • Display an empty page instead of the homepage of Tor Browser when opening new tabs in the Unsafe Browser. (#21004)
  • Remove duplicated CPU microcode to reduce image size. (#21001)

Source link

Continue Reading

Tech

Hackers abuse Notepad++ plugins to stealthily install malware

Published

on

Hackers abuse Notepad++ plugins to stealthily install malware

Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.

The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm.

The attackers do not exploit any vulnerability or a supply-chain compromise impacting the popular software.

image

Notepad++ attack chain

CERT-UA observed that UAC-0099 changed their modus operandi recently and now delivers a ZIP archive with a VBS script disguised as a PDF document. When launched, the PDF retrieves another compressed file named Evernote.zip.

The second archive contains a complete copy of the legitimate editor Notepad++ version 8.8.3, a malicious plugin (NppExport.dll), a password-protected archive (updater.rar), and the legitimate WinRAR executable.

Advertisement
Overview of the UAC-0099 attack
Overview of the UAC-0099 attack
Source: CERT-UA

The VBS script installs the package into a randomly named directory, launches Notepad++, and then loads the malicious NppExport.dll via the application’s normal plugin-loading mechanism.

CERT-UA explains that this DLL is LunchPoke, a tool that creates a scheduled task on Windows and extracts the contents of the RAR file, including RemoteLibUpdater.exe and InitTest.dll.

The executable in the RAR file is BurnyBear, a loader for the DLL file that is the MatchBoil V2 malware loader.

MatchBoid v2 code
MatchBoid v2 code
Source: CERT-UA

BurnyBear also features a fallback mechanism in case launching RemoteLibUpdater.exe fails, triggering a resource exhaustion attack targeting the host’s RAM and CPU.

The latter creates another scheduled task, updates its configuration and command-and-control (C2) address, and then uses WinRAR to extract downloaded programs.

CERT-UA does not mention the final payloads delivered in the observed attacks, the purpose of the campaign, or the targeted organizations.

Advertisement

The researchers mention CVE-2025-56383, a DLL hijacking flaw in Notepad++ v8.8.3, the exact version used in these attacks, but note that the Notepad++ team has disputed this issue, claiming that plugin loading is standard functionality.

CERT-UA advises system administrators to update Notepad++ to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23, to prevent hackers from exploiting known flaws in existing products and enabling stealthy attacks.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

There are more entry-level jobs than graduates in S’pore. So why are they still struggling to be hired?

Published

on

There are over 32,000 entry-level PMET jobs available for Singapore’s fresh graduates

How is it possible that a graduate, who is the top of his cohort from a local university, equipped with four internships at companies like DBS Bank, attended 10 career fairs and networking events, and sent out more than 300 resumes in the finance sector, still hasn’t landed a full-time job?

The question is especially puzzling given the latest figures from Singapore’s Ministry of Manpower (MOM), which show there were 32,800 entry-level professional, managerial, executive and technician (PMET) vacancies available for new graduates.

Each year, around 25,000 to 30,000 degree holders enter the workforce—fewer than the more than 32,000 entry-level PMET vacancies that have been available in recent quarters. In other words, there are, at least on paper, more entry-level jobs than fresh graduates to fill them.

Yet, despite what the numbers suggest, some graduates are seemingly still struggling to secure full-time employment.

Advertisement

Some industries offer more opportunities

singapore jobs graduatessingapore jobs graduates
Image Credit: Nanyang Technological University

While vacancy numbers fluctuate quarter to quarter with hiring timelines and recruitment cycles, the share of entry-level roles within each sector has stayed broadly consistent.

Public administration and education, as well as health and social services, are the most fresh-graduate-friendly sectors, where more than half of the vacancies are suitable for applicants with little to no work experience.

Coming in next are the manufacturing, construction, transportation and storage, food and beverage services, and administrative and support services sectors, where there are many engineering and quantity-surveying jobs. In these sectors, more than four in 10 vacancies are open to entry-level applicants.

On the other end of the spectrum, the infocomm and financial and insurance services are two industries that graduates aspire to join for higher starting pay, attractive perks and strong career prospects. Yet, only 22.2% of infocomm vacancies and 25.3% of financial services roles are entry-level, per MOM’s Q1 2026 data.

For fresh graduates set on these sectors, breaking in is significantly harder.

Advertisement

Derrick Teo, chief executive of manpower consultancy Elitez Group, told The Straits Times: “The graduate job market is still active, but it is more uneven and selective compared with two or three years ago.” 

More graduates are having to take up temporary or contract roles as stepping stones towards a full-time gig, the publication wrote.

The mismatch between job openings & degree holders

singapore jobs graduatessingapore jobs graduates
Image Credit: Shadow_of_light/ depositphotos

“The issue is not that there are no jobs. It is that there is a mismatch between where graduates want to work, where employers are hiring, and the skills employers now expect from fresh graduates,” Teo added. 

The mismatch is particularly evident in the infocomm sector, where the post-pandemic hiring boom has cooled. There were 4,600 vacancies in Q1 2020, before it surged to 11,700 in Q1 of 2022, and fell to around 5,300 in the first quarter of 2026.

Of those 5,300 vacancies, only about 1,200 are suitable for entry-level applicants.

Advertisement

In 2020, that would have been almost enough to accommodate the 1,367 information technology graduates. But by 2024, the number of IT graduates had almost doubled to 2,694, according to data from the Ministry of Education, making competition much more intense.

The tables have turned. Employers now hold the power that graduates once commanded.

Computing students used to land multiple job offers before graduation. Now, many take longer to secure their first role, said Li Xiaoli, head of the Information Systems Technology and Design Pillar at Singapore University of Technology and Design (SUTD).

With a larger pool of candidates to choose from, companies have the “luxury of selecting the very best,” he said. 

Advertisement

Internships are a prerequisite, but there just aren’t enough

singapore jobs graduatessingapore jobs graduates
Image Credit: Mechanobiology Institute, National University of Singapore

One recent computer science graduate, Gary, whom the Straits Times spoke to, said that employers have become far more selective even when hiring interns.

As internships are increasingly being a prerequisite for full-time jobs, more students are stacking multiple stints to bolster their resumes.

This makes competition stiffer for everyone. 

Final-year students who need internships to fulfil graduation requirements now vie not just with peers, but juniors chasing the same spots.

“Quite a number of students did capstone projects in place of internships because they couldn’t find one,” Gary said, referring to final-year projects where students apply what they have learnt.

Advertisement

He felt his coursemates’ lack of real-world experience would put them at a further disadvantage in the job hunt.

Gary explained that was why he decided to “bite the bullet” and grab any internship opportunity that came his way, even if it was an SME or a company with discouraging Glassdoor (job and recruiting platform) reviews. 

Employers are increasingly looking for candidates who can “demonstrate practical experience, specific skills, adaptability and readiness to contribute from the outset,” said Susanna Leong, deputy president (academic) and provost at Singapore Institute of Technology.

Prasanthi Guda, Acting Director of Career and Employability Services at Singapore Management University’s (SMU) Dato’ Kho Hui Meng Career Centre, said that employers are also hiring more cautiously in response to economic uncertainty, geopolitical developments and rapid technological change.

Advertisement

Graduates are also picky amid a tougher job market

singapore jobs graduatessingapore jobs graduates
Image Credit: Muhamad Iqbal Akbar/ Unsplash

But employers aren’t the only ones being choosy. Even in a tougher market, many graduates remain selective about where they apply.

Some prefer a more targeted approach, relying on personal connections for job leads and applying only for positions they genuinely want. Others are taking their time with applications, and choosing alternative paths like furthering their studies. 

Some are even holding out for a better job with higher pay, despite qualifying for other sectors. 

Calvin Chung, JTC’s assistant chief executive for engineering and operations, told the Straits Times that attracting fresh graduates to the built environment sector—construction, engineering, and related fields—remains challenging, especially as enrolment in these courses declines.

“The perception problem is real, as younger students see the sector as traditional, physically demanding and slow to change, especially when compared with industries like tech and finance,” he said.

Advertisement

“The reality is actually different, where engineers today work with sophisticated digital tools on impactful projects,” he added.

Unrealistic expectations?

singapore jobs graduates moneysingapore jobs graduates money
Image Credit: jpldesigns/ depositphotos

A 2025 MOM School-to-Work Transition Study of 2,500 recent graduates found most expected higher starting salaries than the actual median in their fields. Only law, education, and fine and applied arts graduates had realistic expectations.

The mismatch was especially pronounced among graduates in information technology, business, and the natural and mathematical sciences.

Many had looked at the Graduate Employment Survey—based on self-reported earnings—and expected over S$5,000 for their first job. But recent postings suggest employers are offering around S$4,000, Gary said.

SUTD’s Li said it is common for students, especially the most competent and ambitious ones, to aim for high-paying jobs at companies such as Google or OpenAI. But he added that they should be “realistic” as tech multinational companies are becoming more cautious about their headcount.

Advertisement

Shamim Akhtar, course chair at Temasek Polytechnic’s School of Informatics and IT, urged students to broaden their job search. “We should not be fixated on tech companies,” he said, noting that financial institutions, government agencies, and healthcare organisations also need tech talent.

Recent data from Infocomm Media Development Authority’s Singapore Digital Economy Report 2025 supports this, projecting faster growth in demand for tech professionals at non-tech firms than at tech firms.

Worries about AI

singapore jobs graduates aisingapore jobs graduates ai
Image Credit: Summit Art Creations via Shutterstock

Competing against hundreds of graduates is tough enough. Now, many young job seekers face another worry: rapid AI adoption.

Except for sectors like health and social services, where jobs are believed to be “human-centric” and less prone to automation, concerns about AI replacing junior roles are looming, especially in knowledge-based industries. 

AI adoption is the highest in infocomm at 74.1%, followed by professional services at 57.5% and financial and insurance services at 56.4%, per MOM’s latest survey.

Advertisement

But the same survey suggests AI is, for now, reshaping work rather than eliminating jobs. Just 6.2% of adopting firms reported reducing headcount or hiring because of the technology.

Some industry watchers’ observations corroborate this.

“Not yet a market where recent graduates need to compromise

singapore jobs graduatessingapore jobs graduates
Image Credit: Shadow_of_light/ depositphotos

Callam Pickering, Indeed’s senior APAC economist, said graduate demand picked up considerably in the first five months of 2026 versus the same period in 2025. Around 80% of those opportunities sit in occupations highly exposed to AI-driven transformation.

“This is not yet a market where recent graduates need to compromise,” he said.

Moreover, Sharon Tan, Vice-Dean (Industry Relations) at the National University of Singapore’s School of Computing, said AI adoption will create “a strong need for professionals who can design, build, evaluate and deploy these systems responsibly and effectively”.

Advertisement

“While hiring conditions may be more subdued now than during the recent technology boom, Singapore’s continued digitalisation and significant investments in AI research, innovation, infrastructure and enterprise adoption are expected to sustain demand for computing talent over the longer term,” she added.

Still, universities are increasingly weaving AI into existing curricula or launching AI-focused degrees to future-proof their students’ careers.

For students, demonstrating proper and effective AI use is critical, said Temasek Polytechnic’s Akhtar. They should learn to build applications using large language model APIs, document their process on platforms like GitHub, and show employers how AI enhances their work.

“Employers are looking at how you augment your thinking, rather than let AI replace your thinking,” he said.

Advertisement

In actuality, for many graduates, the bigger frustration right now isn’t AI taking their jobs—it’s AI deciding whether they even get an interview.

Several told the Straits Times that AI-driven resume screening has made hiring feel more opaque, with applications vanishing into what feels like a “black hole.” They agreed that waiting for responses that never come has become common. 

Some graduates, like Gary, have accepted that hearing back from a recruiter is no longer guaranteed.

Out of the 150 applications he has sent since Jan, he has received only one verbal offer, but has not heard from the company for almost two months.

Advertisement
  • Read other articles we’ve written on Singapore’s job landscape here.

Featured Image Credit: 2p2play via Shutterstock

Source link

Advertisement
Continue Reading

Tech

Russian hackers exploit Zimbra zero-click flaw for email theft

Published

on

Phishing

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.

According to CISA, Laundry Bear has targeted and compromised users in organizations associated with the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology.

The attackers exploit the Zimbra CVE-2025-66376 flaw, a cross-site scripting (XSS) vulnerability affecting Zimbra Collaboration Suite’s Classic UI.

image

The flaw allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message, enabling attackers to steal account data without requiring the user to click a link or visit a phishing site.

According to CISA, Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers. The vulnerability was later tagged by CISA as actively exploited in attacks.

Advertisement

CISA says Laundry Bear’s exploit is used to automatically collect and send the victim’s last 90 days of emails, email address, password, Global Address List (GAL), and two-factor authentication (2FA) tokens.

The attackers also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows. Using a passcode allows the attackers to retain access to the email account while bypassing MFA.

According to CISA, the malware exfiltrates stolen information over both DNS and HTTPS to an actor-controlled server running the group’s “Flowerbed” collection framework.

Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers.

Advertisement

In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies, allowing the attackers to gain access to targets’ email accounts.

CISA released IOCs that show the campaign used sites that impersonate Zimbra infrastructure, using domain names like ‘mailnalysis.com’, ’emailanalytics.com.ua’, ‘zimbrastat.com’, ‘zimbra-metadata.com’, ‘istc-cloud.com’, and ‘zmailanalytics.com’.

The advisory recommends that organizations using Zimbra:

  • Update to the latest version of the software to install all available security updates.
  • Review the published indicators of compromise.
  • Investigate systems for connections to the identified domains and IP addresses.
  • Monitor for suspicious authentication activity.
  • Revoke any unauthorized application passcodes, especially those with the ‘ZimbraWeb’.
  • Review accounts for unauthorized mailbox access.

CISA also recommends implementing phishing-resistant multi-factor authentication where possible.

Laundry Bear targeted governments, police, and Ukraine

The Laundry Bear hacking group was first attributed to cyberespionage attacks in May 2025 by the Dutch intelligence agencies.

Advertisement

The Dutch agencies publicly attributed the group to a 2024 compromise of the Dutch National Police that exposed the personal information of police personnel and led to the identification of a previously unknown Russian espionage group.

Microsoft tracks the same group under the name Void Blizzard.

Since at least 2024, the group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.

Microsoft has also documented successful compromises of organizations supporting Ukraine, including entities in the defense, transportation, and aviation sectors.

Advertisement

Earlier this year, BleepingComputer reported on a separate Laundry Bear campaign targeting Ukraine’s military using charity-themed phishing emails to deliver malware disguised as donation requests.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025