Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data
US cyber agencies are warning critical infrastructure operators to patch their internet-facing kit after Gunra ransomware affiliates were spotted exploiting known vulnerabilities to break into networks.
Gunra first surfaced in 2025 and has wasted little time expanding. CISA, the FBI, NSA, Secret Service, and partner agencies in the US and South Korea say it now operates as ransomware-as-a-service, with affiliates attacking organizations worldwide.
Advertisement
Targets have included healthcare, financial services, government, professional services, nonprofits, and other critical infrastructure organizations.
The attackers have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet’s FortiOS and FortiProxy, to gain administrative access through internet-facing appliances.
Once inside, Gunra affiliates follow the now-familiar double-extortion playbook: steal data, encrypt systems, and demand payment for a decryptor and a promise not to publish the haul.
Negotiations take place through a Tor-based portal, according to the advisory, with victims typically given between five and seven days to cough up before their stolen data is published.
Advertisement
“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to US and international organizations,” said Chris Butera, CISA’s acting executive assistant director for cybersecurity.
Trend Micro first observed Gunra in April 2025, initially targeting Windows systems and borrowing elements from the Conti ransomware operation. The security shop later uncovered a Linux variant, broadening the range of systems its operators could scramble.
That Linux version can run as many as 100 encryption threads in parallel and supports partial encryption, allowing attackers to specify how much of individual files should be encrypted. It can also store RSA-encrypted keys in separate keystore files.
Trend Micro has seen Gunra activity in Turkey, Taiwan, the US, and South Korea. The gang’s own leak site casts the net wider, claiming victims in Brazil, Japan, and Canada as well, including manufacturers, healthcare providers, IT companies, and law firms.
Advertisement
The agencies are urging potential targets to patch known exploited vulnerabilities in internet-facing systems, secure VPN gateways and RDP access with multifactor authentication, segment networks, and maintain offline, immutable backups to make life harder for attackers who get through the front door. Âź
A German digital-rights group has filed a criminal complaint against Meta, Ray-Ban parent EssilorLuxottica, and several retailers over Meta’s AI smart glasses, arguing the devices can enable covert recording in violation of German privacy law. Prosecutors have begun a preliminary review, while Germany’s network regulator says smart glasses are legal “as long as the recording function is clearly visible.” Reuters reports: “There’s no place to escape from smart glasses. You have to expect at any moment to be filmed and then exposed on the internet,” said HateAid managing director Josephine Ballon. The organization reported the management of Meta, units of spectacles maker EssilorLuxottica including Ray-Ban, as well as retailers Fielmann, Apollo-Optik, Mister Spex and MediaMarkt to the Frankfurt-based digital crime prosecution unit ZIT. HateAid said its complaint was based on a federal digital data protection law that prohibits the sale of communication devices designed to film people without them noticing.
ZIT confirmed it received a complaint from HateAid invoking that law, saying it would routinely investigate on a preliminary basis whether there are grounds for a deeper probe. MediaMarktSaturn Retail Group said it was taking the complaint very seriously, adding that its suppliers had contractual obligations for all goods to be compliant with the law. Mister Spex said it had not been officially notified of a complaint and that it was taking protection of privacy very seriously.
The latest battle in the ongoing innovation war between Apple and Google is upon us. On August 12, 2026, Google announced its rival to the Apple AirTag: the Pixel Tag. It comes with a feature set that puts it in direct competition with Apple’s take. It basically works the same as an Apple AirTag (that is, to help people find their misplaced belongings), and both devices are priced the exact same, as well. The Pixel Tag costs $29 for one or $99 for a four-pack, which is identical to the pricing structure of Apple’s second-generation AirTag. But which has more features?
Given the fact that this is only the first iteration of the Pixel Tag, while the Apple AirTag just upgraded to its second, AirTag is the one with more features to offer. Sure, they both cover many of the same basics, but Apple’s tracker offers more precision finding, a better crowdsourced tracking network, and more unwanted-tracking protections than Google’s Pixel Tag. You also get support for sharing a lost item’s location with participating airlines and other trusted third parties. It’s simply a much broader feature set than what you get with this long-rumored first-gen Pixel Tag.
Advertisement
How the Google Pixel Tag compares to Apple AirTag
Wachiwit/Getty Images
That being said, the Pixel Tag still has plenty to offer. Its Find Hub network leverages the millions of Android devices out there to help locate a lost item when the tag is outside Bluetooth range. If you’re not an Apple user, that’s really nice to have. Not unlike the Apple AirTag, users can also ring the Pixel Tag. You also get Ultra-Wideband and Bluetooth Channel Sounding for more precise visual distance and directional information, plus Left Behind alerts to warn you when you’ve left an item behind. Uniquely, the Pixel Tag can also be shared with up to 10 people, which is nice for those belongings that get used by multiple people. Its button can ring a paired phone, while a paired Pixel Watch can pinpoint and ring the tag from the watch. Pixel Buds owners can also ask Gemini to ring it.
Still, the AirTag combines most of those capabilities with several additional features that the Pixel Tag doesn’t offer. The best example is the aforementioned Share Item Location, which lets you temporarily share the location of a misplaced item with a trusted third party to help you track it down (such as an airline, for example). AirTag also comes with free personalized engraving and works with existing AirTag accessories. You essentially get the same basic tracking tools found on the Pixel Tag, just with more recovery and sharing features.
Our tech expert David Ludlow has reviewed the Move 2 and found a speaker built around two angled tweeters instead of one, a redesign that widens the soundstage and fills a room with a less directional, more layered sound than its predecessor managed.
Advertisement
We also praised the mid-wooferâs punch when he pushed the volume on something like Rage Against the Machine, noting it threw out bass with real weight without ever letting the vocals get buried underneath it.
Battery life is where the upgrade really lands, with us clocking 24 hours of rated playback and still finding 54% left after an eight hour outdoor session, more than double what the original Move could manage on a single charge.
That endurance is backed by an IP56 rating, so David was comfortable leaving the speaker outside overnight without worrying about rain, dust or an accidental spill doing any damage.
Advertisement
Automatic Trueplay tuning adjusts the sound every time the Move 2 changes location, something we tested by moving it from a kitchen counter to a bookshelf to the garden and finding it balanced the output well in every spot.
Indoors, the Move 2 drops onto its charging base and behaves like any other Sonos speaker, joining an existing system over Wi-Fi for multi-room playback, while Bluetooth 5 takes over the moment you carry it out the front door.
What if the speaker already filling your living room with sound could just as easily follow you out to the garden, the same stereo depth and bass intact, for $100 less than it was selling for last week?
Over a decade has passed since Dolby Atmos launched in cinemas across the world, and arguably itâs unlocked another level in the audio space.
Since its inception, Dolby Atmos has moved from the silver-screen to areas such as TVs, soundbars, smartphones, headphones and in-car audio. Itâs supported by major streaming platforms such as Apple Music, Netflix and Disney Plus, as well as game consoles in the PS5, Xbox Series X and Series S. Dolby Atmos is everywhere, and its brought spatial audio to devices big and small.
Dolby Atmos has helped usher in an era of spatial audio, but how does it work, and whatâs the best way to experience it?
What is Dolby Atmos?Â
Dolby Atmos is a three-dimensional surround sound technology that adds height to audio, creating a more natural and immersive experience in the process.Â
Advertisement
With Dolby Atmos, sound is no longer limited to a particular channel as they are in 5.1 and 7.1 set-ups. Rather, sound engineers can specify where a sound originates, the direction it moves in and where it ends. These sounds are called audio objects.Â
Advertisement
There are up to 128 audio channels in total and 10 channels are used for ambient sounds. These 10 channels donât require any specific placement.
Image Credit (Dolby)
These sounds stick with the traditional channel-based approach used in other sound systems, while the other 118 channels are used for the audio objects that move position.
Audio objects are also compatible with any number of speakers, meaning Dolby Atmos can be heard on the big screen with a cinema-level 64 speaker set-up, or adapted to fit a pair of headphones.
Advertisement
Of course, Dolby isnât the only player in immersive audio market. DTS:X, Eclipsa Audio and Auro 3D all create a similar effect.
Advertisement
How can I listen to Dolby Atmos?
Image Credit (Trusted Reviews)
The best way to hear what Atmos is either in a cinema or a dedicated Atmos room.
You can, of course, upgrade your home audio set-up, but when it comes to upgrading your home cinema system, 64 speakers is a logistical challenge. Thatâs why thereâs a variety of products to help bring Dolby Atmos to your home.
Any pair of headphones is capable of playing Dolby Atmos as thereâs no specific tech required to get it up and running.
Advertisement
Soundbars can either feature upfiring speakers to produce the height channels, or they can use digital processing to trick the brain into thinking that sound is placed up high or out wide. Dolby Atmos FlexConnect can connect multiple speakers together that adapt to changes in room placement so no matter where theyâre placed, youâll get an immersive spread of sound.
Image Credit (Dolby)
Advertisement
If you have space for surround speaker set-up, this would be the best way of enjoying immersive object-based audio as youâll have rear speakers and height speakers to create a bubble of sound. A wireless soundbar system can do this on its own, but if you have a more traditional wired surround system, an AV receiver will be required to decode Atmos sound and send it to the speakers.
Home Atmos systems are capable of reproducing all 128 audio objects across from as few as seven speakers. For those who want to go all out, home Atmos systems support up to 34 speakers, but such a set-up is usually unnecessary.
But before you worry about speakers, thereâs some other information to be aware of. Firstly, you wonât need a new Blu-ray player. Standard Blu-rays are capable of containing the necessary Atmos data, as are 4K Ultra HD Blu-rays, so unless you feel like upgrading to UHD Blu-ray, there are no format issues to worry about.
TNT Sports has put its weight behind the format, too, with Premier League, Champions League and ruby matches broadcast in Atmos.
Advertisement
The broadest range of Atmos content is available to stream from services such as Netflix, Prime Video, Apple TV, Disney+, although youâll have to subscribe to the premium tier to access spatial audio.
Tidal, Amazon Music and Apple Music streaming services also support it, and Atmos is available through streaming boxes like the Apple TV 4K, Google TV 4K and Roku Streaming Stick.
Advertisement
Atmos in gaming has become more popular, whether through Windows 10 and 11 PC gaming, Sonyâs PlayStation 5Â and the Xbox Series S and Series X consoles.
Image Credit (Dolby)
What set-up do I need for Dolby Atmos?
For overhead speakers, you may wonder whether you need to drill holes in your ceiling to install the Atmos speakers. Thankfully, that isnât necessary.
If you have a traditional wired home cinema set-up, you can buy specially designed Dolby Atmos speakers that integrate forward-facing speakers with upward-firing versions, rebounding sound off the ceiling to mimic the effect of overhead speakers.
Advertisement
If you donât want to buy an entire new speaker set-up, there are speaker modules that can transform the existing set-up into Atmos-enabled one. Itâs a case of placing the modules on top of the speakers to add upward-firing drivers.
Advertisement
Image Credit (Klipsch)
Another way is to take the plunge and install actual overhead speakers. As mentioned, home Atmos systems will work with up to 34 speakers, so if you want a dedicated cinema space and have the budget, a custom installation is the way to go.
Before ruining the plasterboard, though, itâs worth bearing in mind that Dolbyâs guidance states that using only two overhead speakers will âprovide a convincing and powerful effectâ while four overhead speakers will give you the âoptimum sense of audio movement and precision.â This will depend on the size of your room,
Dolbyâs reference guides for the best Atmos speaker set-up recommend a 5.1.4 as the set-up for enjoying Atmos, and we think thatâs the minimum for having a good immersive experience.
Image Credit (Dolby)
Advertisement
Once youâve chosen your AV receiver, you can upgrade your existing 5.1 or 7.1 surround sound by adding two or four ceiling speakers and either a couple of speaker modules or Atmos-enabled speakers.
The rise of Atmos in the home has also coincided with the rise of Atmos-enabled soundbars as a cheaper, less obtrusive way of getting Atmos in the home.
Advertisement
These simpler solutions integrate upward-firing speakers with traditional soundbar tech to deliver an Atmos experience without the hassle. The Sonos Beam 2 uses digital processing to deliver Atmos for ÂŁ450.
Sennheiserâs Ambeo 3D Soundbar takes the Dolby Atmos codec and adds Ambeo 3D processing to create a massively immersive experience. It sounds fantastic, but itâs also one of the most expensive (and gigantic) soundbars on the market.
Atmos on mobile
Image Credit (Tidal)
Advertisement
Because Dolby Atmos is designed to adapt to whichever device youâre listening to, you can experience Atmos sound using your smartphone, tablet or headphones. Though with mobile devices, donât expect the sense of sound above or around you â think of it as just better quality sound through the speakers.
Atmos on mobile is made possible by combining traditional virtual surround technology with the object-based audio of Dolby Atmos, the combination of the two allows headphones to reproduce a convincing version of the 3D soundscape.
Advertisement
Dolby has said to Trusted Reviews that manufacturers can embed Atmos into both software and hardware, which means your device doesnât necessarily need specific hardware to use it, although weâve seen more headphone brands, from the likes of Apple with its Spatial audio with Dolby Atmos, to Boseâs Immersive Audio, Sennheiser, Shokz and Soundcore that have added support for Atmos with head-tracking.
What is Dolby Atmos Music?
Image Credit (Dolby)
Atmos isnât just for home cinema aficionados. Its presence has grown in the music industry too. Dolby Atmos Music does the same thing as Atmos did for cinema. Tidal, Amazon Music and Apple Music offer the biggest catalogues of Dolby Atmos Music.
The first Blu-ray audio disc with Atmos arrived in 2015 in the 25th anniversary edition of R.E.Mâs Automatic For The People.
Advertisement
We now see (and hear) Atmos music delivered through music services on a monthly basis, from new titles mastered in the format such as Sam Smithâs When Heâs Gone to classic titles to the likes of Paul McCartney/Wingâs Ban On The Run.
Advertisement
Spatial audio is very much part of the music landscape.
How does Dolby Atmos stack up against the competition?
Dolby isnât the only company to have its toes in the immersive waters.
Image Credit (DTS)
The DTS:X format was introduced in January 2015 and also uses an object-based system. Unlike Atmos, DTS:X was originally aimed at home use, before being targeted at cinemas.
In many ways DTS: X is the same as Atmos but the crucial difference is the speaker set-up. Whereas Atmos supports up to 34 speakers in the home, 64 in a cinema and requires new speakers/modules to work properly; DTS:X supports up to 32 speakers and will work with your current home speaker set-up. That means that while extra overhead speakers will enhance the DTS:X experience, theyâre not necessary.
Advertisement
Advertisement
Image Credit (Auro)
Another competing object-based, 3D audio system is Auro 3D. Developed by Belgium company Auro Technologies and officially introduced in 2006, the format is based upon a three-layer design: surround, height, and overhead.
The key difference between this system and Dolby Atmos comes down to the speaker layout. With Auro 3D, an additional row of speakers is placed above the traditional row found in 5.1 and 7.1 set-ups. This adds the height element. A single speaker is then placed on the ceiling to add the overhead dimension.
Although Auro 3D also creates a spatial sound field, the company doesnât use the term audio objects as Dolby does. Auroâs plugins allow sound designers to dictate where sounds should originate and move to, and the format can be used in cinemas, at home, and over headphones, just as with Dolby Atmos.
Films such as The Hunger Games, The Croods, and Red Tails have used Auro 3D in the cinema, but it isnât as popular as Atmos. It has announced that the technology is coming to more soundbar systems, as well as headphones and smart speakers.
Image Credit (Trusted Reviews)
Advertisement
The most recent challenger to Atmos is Eclipsa Audio. Itâs based upon the open-source Immersive Audio Model and Formats (IAMF), and as itâs open-source, itâs available for anyone to use without having to pay a royalty, as you would with the technologies mentioned above.
Advertisement
It was developed by the Alliance for Open Media, a consortium that includes Samsung Research, Google and Netflix as an alternative to Atmos, and you can find it supported in Samsung TVs and soundbars, as well as through YouTube and Windows 11.
LG TVs support, but LG Electronics is keen to say that it supports the IAMF codec rather than the Eclipsa Audio branding. It will be coming to TVs from Hisense, TCL, and Philips, strengthening its presence in the TV market.
Atmos and VR
Image Credit (Trusted Reviews)
With virtual reality (VR) able to recreate the way we hear sounds makes all the difference to how immersive a VR experience feels.
All the way back in 2015, Dolby worked with VR content creator Jaunt to add Atmos sound to three of the companyâs VR experiences: Black Mass, Kaiju Fury! and video from a Paul McCartney concert entitled Live and Let Die.
Advertisement
Advertisement
Since then, Atmos has been extended to support VR experiences on iOS, Android, OS X, and Windows. The Samsung Galaxy XR supports Atmos, and the Meta Quest 3 supports it through the Disney+ app, the web player and tools such as the HISPlayer for Unreal Engine.
Is Dolby Atmos worth it?
Dolbyâs surround sound format has done the heavy lifting in bringing immersive audio to pubic consciousness, but is it worth investing your time and money into the format?
It depends on what youâre going to use it for. In our experience, while itâs good for watching TV, films and playing games in the home, itâs best if youâve got the requisite equipment, which means having a capable soundbar and surround speakers â otherwise the Atmos effect is only half done.
If you can get surround sound speakers, then youâre getting close to the immersive experience that Dolby wants you have. If youâre not, then youâre only getting half of what Atmos can do. Itâs called immersive audio for a reason.
Although lighting 3D prints on fire is rarely the intended outcome, itâs possible that said print will at some point in its future come into contact with either an open flame or a significant source of heat. Once that happens, what will be the result and how worried should one be? This is basically the excuse behind [Makerâs Muse] recent decision to light some 3D prints on fire.
Crispy 3D printed combat robot. (Credit: NHRL)
Materials exposed to an open flame in this experiment included various types of PLA, PETG, ABS, ASA, TPU and PEBA. Since PLA filaments have a significant amount of carbon in them itâs little wonder that these burned quite readily, though an interesting difference was immediately visible between an Elegoo PLA+ test cone and a Prusa Galaxy Black PLA cone. The latter required a blow torch to properly ignite, after which it burned rather hot whilst melting, unlike the dirty yellow flame of the PLA+.
So-called âhigh temperatureâ PLA (HTPLA) seems to actively resist burning, self-extinguishing after a blowtorch treatment. Just these few samples of PLA already gave very different results, with very likely the additives being the defining factor since pure PLA is easy to burn as a way to dispose of it somewhat cleanly.
Moving on, black PETG didnât really want to ignite, while ABS and ASA absolutely love to burn with a sooty yellow flame. HIPS was also tested, burning in a similar sooty manner as well.
Advertisement
Of all the materials tested, TPU was the least flammable with even the blowtorch not able to start ignition and only melting the sample. Foam TPU did however burn the most aggressive, followed by ABS, ASA and HIPS. Overall PETG and regular TPU seem to be your best bet if you do not want your 3D print to turn into a happily burning candle and potentially a general fire hazard.
In a few hours, there is a solar eclipse that will be visible with a track that goes from Spain up through Greenland. Too late to travel for it, but thanks to [jonty], you can find all the webcams that will have a view.
This may be ideal. No funny glasses. No looking at a projected image on a card. Of course, many, if not all, of these cameras arenât looking directly at the sun, so it isnât clear if youâll be able to see the actual eclipse or just the effect it has on the surroundings.
If you prefer more science, try the NASA feed below.
Advertisement
Or, you could see what ESA is broadcasting from Javalambre, Spain:
Or, try the telescope view version:
Advertisement
Want to know what it might look like from a particular spot? Harvard has you covered. If you want to feel more realistic, try wearing some regular sunglasses while watching just for the fun of it.
We wish we could watch our eclipses from the lunar surface. Of course, you can always make your own eclipse.
Social engineering and malware combine to enable financial fraud before banks have time to act
A new social engineering and malware campaign targets Android users, stealing card details to make payments or withdraw cash. Group-IB discovered the campaign, calling it WindRelay, and found that several successful attacks were carried out on European victims within the space of a 13-minute phone call.
The attack relies on a skilled social engineer walking the victim through the process and two malware strains: An NFC relay malware called WindRelay, first discovered in August 2025, and SpyNote, a remote access trojan (RAT) that was leaked on cybercrime forums as far back as 2016.
Advertisement
It goes like this: The attacker calls the target while posing as a helpdesk employee at their bank, convincing the victim-in-waiting that there is a problem with their payment card.
While still on the phone, the attacker gets the target to install a version of SpyNote on their Android device. The file name includes the target’s name, which the researchers said could suggest that each target is singled out specifically, and a degree of reconnaissance has to be carried out prior to the attack.
Once installed, the attacker quickly uses the RAT’s remote access to quietly install WindRelay on the attacker’s device without their knowledge or input, all while the call was ongoing.Â
The attacker then instructs the target to tap their payment card on their NFC-enabled smartphone and, when prompted, enter their PIN.Â
Advertisement
WindRelay then captures the data from that interaction between the card’s chip and the reader, similarly to how genuine point-of-sale machines authorize contactless payments. This is known as a live EMV APDU exchange.
In order to fraudulently make payments using this data â without physical access to the payment card or the cardholder â the attacker must have a second device capable of using this data to authorize a payment.Â
This could be a second Android smartphone capable of loading this data and transmitting it to an attacker-controlled POS terminal, which is linked to a fraudulent merchant bank account, or an ATM.
The attacker then uses the captured live exchange data to execute fraudulent charges on the victim’s card, authorized using the PIN they entered during the call.
Advertisement
Group-IB said in its write-up: “In effect, the victim’s card and the real terminal are still talking directly to each other â the fraudster’s setup is just an invisible relay in between, passing the exchange back and forth across a distance.Â
“Because the terminal is genuinely completing a live handshake with a real card, the transaction goes through and processes the withdrawal or purchase as normal.”
Doubling down on their access, Group-IB also noted that the attackers in one instance used their RAT access to access the victim’s banking app and take out loans in their name.
The researchers also said they observed 23 WindRelay-related samples uploaded to VirusTotal between November 2025 and July 2026, with signs pointing toward targeting victims in Czechia, Slovakia, and Slovenia.Â
Advertisement
They were not able to pin down the attacker(s) behind the malware, although they said it was independently developed and the samples they saw uploaded to VirusTotal all contained unique UI elements, such as the victim’s name, just like with the RAT.
“This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims,” said Group-IB.
“This case shows that modern fraud rarely relies on one technique,” it added. “Here, the fraudster combined three capabilities in a single session â a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cash-out.Â
“The fraudster also used these capabilities to hit two separate payout channels â a digital loan and card-present purchases â before the bank or victim could react.”
Advertisement
The attack is similar to previous NFC relay-related campaigns, such as NGate in 2024 (and more recently in 2026), and Ghost Tap, the techniques involved in which closely align with WindRelay.
Ghost Tap, also discovered in 2024, relies on a Chinese malware sold throughout the country’s cybercrime Telegram communities, and according to Group-IB, it was responsible for losses exceeding $355,000 between November 2024 and August 2025 alone. Âź
Security researchers have disclosed new “Plug and Pwn” attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.
The research, presented at DEF CON 34 by security researchers Alejandro Hernando and Borja MartĂnez, exploits how Windows automatically identifies new connected hardware, locates matching driver packages, and installs vendor software as the NT AUTHORITY\SYSTEM account.
By using software to emulate USB devices, the researchers found they could force Windows to install signed vendor packages containing exploitable components or weaknesses that can be abused to gain SYSTEM privileges.
Some of the demonstrated attacks require no user interaction or logged-in user, while another can be performed remotely over RDP without any physical USB hardware being connected to the targeted computer. plugandpwn.com.
Abusing Windows Plug and Play
Windows supports a feature called co-installers, which automatically downloads and installs vendor software and drivers when a new USB device is inserted into a computer.
Advertisement
In 2021, BleepingComputer reported on how this feature was abused along with a Razer Synapse vulnerability to give a standard Windows user SYSTEM privileges simply by plugging in a Razer mouse or keyboard.
When a Razer device was connected, Windows automatically downloaded and launched the Razer Synapse installer with SYSTEM privileges. A flaw in the installer allowed a standard user to launch PowerShell from the installation interface, causing the shell to inherit the installer’s privileges.
BleepingComputer tested the vulnerability at the time and confirmed that it could be used to gain SYSTEM privileges in approximately two minutes.
At the time, vulnerability analyst Will Dormann previously warned that similar vulnerabilities were likely present in other software automatically installed through Windows Plug and Play.
Advertisement
Hernando told BleepingComputer that Plug and Pwn belongs to the same family of attacks, but the new research focuses more on the Windows device installation path itself.
“The Razer bug is the same family. The difference is that we went after the install path itself instead of one vendor’s installer,” Hernando told BleepingComputer.
“Some of our chains need no clicks and no logged-on session, and one of them runs over RDP with no hardware at all.”
The researchers say the main issue is that when Windows detects new hardware, it may automatically retrieve an associated signed package and execute vendor-supplied components as SYSTEM.
Advertisement
This privileged installation path can include co-installers, services, support executables, and drivers, with no UAC prompt displayed by the operating system.
From fake USB devices to remote RDP attacks
The researchers told BleepingComputer that they used FaceDancer with Cynthion and GreatFET hardware connected to a small Linux computer to emulate USB devices.
FaceDancer is a software framework for emulating USB devices, allowing researchers to define the descriptors, interfaces, device classes, and endpoints that a computer uses to identify connected devices.
Connecting hardware running FaceDancer to a computer can make the operating system behave as though a specific USB device had been plugged in.
Advertisement
Using FaceDancer, the researchers could make their hardware appear to Windows as specific USB devices, causing the operating system to recognize the emulated hardware and locate and install the associated vendor driver packages.
Some attack chains also require the emulated device to disconnect and then reappear as a different device identity.
“Several of our chains depend on presenting the device as composite so Windows loads usbccgp.sys and enumerates each interface on its own, which is what makes it match the vendor package instead of the inbox driver,” Hernando explained to BleepingComputer.
“We also need to re-enumerate on demand, dropping the device and coming back as a different identity.”
Advertisement
In their zero-click physical demonstration, the researchers exploited behavior in Sierra Wireless and Sony FeliCa installation packages.
The attack first impersonates a Sierra Wireless device, causing Windows to install software that can be abused to change the computer’s DNS settings.
The researchers then impersonate a Sony FeliCa device, which causes Windows to install additional Sony software that downloads files over an unencrypted connection.
By controlling the system’s DNS settings, the researchers can redirect those downloads to a server they control and exploit a flaw in the Sony software to place a malicious file on the system with SYSTEM privileges.
Advertisement
Finally, they impersonate the Sierra device again, causing Windows to load the malicious file and allow the attackers to open a reverse shell with SYSTEM privileges.
The researchers demonstrated this chain against a fully updated Windows 11 computer with nobody logged in, saying the complete attack takes approximately five minutes.
Plug and Pwn Facedancer attack emulating Sony and Sierra hardware Sââource: plugandpwn.com
When questioned if this attack can be conducted with small portable devices, Hernando said their research hardware is already portable enough to carry around and that a Raspberry Pi operating in USB gadget mode should theoretically be capable of conducting this attack as well.
However, he said the Flipper Zero cannot currently perform the FaceDancer attacks.
“Flipper Zero, no. There’s no FaceDancer backend for it and the framework won’t run on it,” Hernando said.
Advertisement
“Its BadUSB mode is fine for HID, but arbitrary composite descriptors and re-enumeration would be a firmware project.”
The researchers also demonstrated what they call “NoPlug & Pwn,” which requires no physical hardware emulation.
Instead, the attack abuses RDP USB redirection, a feature that allows USB devices attached to a user’s local computer to be available inside a remote Windows session.
Rather than redirecting an actual device, the researchers created a Python RDP client that sends specific USB descriptors over this USB redirection feature when connecting over RDP.
Advertisement
The remote Windows host then treats the fake descriptors as a legitimate USB device connected to the guest computer, creates the corresponding Plug and Play device on the host, causing the corresponding drivers and vendor software to be installed.
In the researchers’ demonstration, they impersonated an Intel RealSense camera whose Windows Update package contains a co-installer that can be abused through DLL hijacking to obtain SYSTEM privileges.
“The server’s USB hub driver enumerates our phantom device, and Windows PnP does exactly what it did in the physical demo: it matches the hardware ID and installs the driver, as SYSTEM,” the researchers explain on the Plug and Pwn site.
The RDP attack only works on systems where USB redirection is enabled, which Hernando says is common in virtual desktop environments.
Advertisement
Disabling co-installers helps, but does not stop Plug and Pwn
Will Dormann suggested that Windows administrators concerned about this type of attack can enable the ‘DisableCoInstallers’Â registry value, which prevents driver packages from executing co-installers during device installation.
To do this, open the Registry Editor and navigate to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Device Installer Registry key.
Under that key, add a DWORD-32 value named DisableCoInstallers and set it to 1, as shown below.
When BleepingComputer asked whether this would effectively block Plug and Pwn, Hernando said it would disrupt some of the demonstrated attacks, including the Sony FeliCa attack and the Intel RealSense RDP attack.
Advertisement
However, it does not eliminate the underlying attack surface.
“It helps, and it would break parts of what we showed,” Hernando told BleepingComputer.
“It doesn’t stop the class of attack, though. It leaves PnP enumeration, Windows Update resolution, driver staging, INF processing and INF-installed services untouched.”
The researchers illustrated this with another attack using Wacom and Atheros packages that exploits a vulnerability (CVE-2019-10617) in an Atheros driver service installed through an INF file rather than a co-installer. Â
Advertisement
Hernando recommends that organizations with sensitive systems use ‘DisableCoInstallers’Â along with additional device blocking.
“In anything sensitive I’d pair it with device installation restrictions or hardware-ID allow-lists, and turn off PnP device redirection on RDP and VDI hosts that don’t need it (`fDisablePNPRedir`),” Hernando told BleepingComputer.
The researchers have not reported all of the attack scenarios as new vulnerabilities to individual vendors, saying that many are not standalone security flaws and only become exploitable when combined with other functionality.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Looking ahead: Sunlight has been used to generate entangled photon pairs, offering an early look at how quantum technology could reduce its reliance on power-intensive lasers. Researchers at the University of Ottawa and the Max Planck Institute for the Science of Light in Erlangen, Germany, used focused sunlight to produce entangled photons, which are essential to many photonic quantum computing and quantum communications systems.
The research, which was published in Optica, does not suggest that sunlight can replace laser-based quantum sources. Those systems remain more precise and produce stronger results. But the study shows that the light used to create entangled photons does not necessarily have to come from a laser, challenging the long-standing assumption that it does.
Entangled photons are pairs of light particles with linked quantum properties. Measuring one particle can reveal information about the corresponding measurement of the other, even when the two are separated. That behavior makes entangled photons useful for quantum encryption and other forms of quantum information processing.
Most systems generate these pairs through spontaneous parametric down-conversion. In that process, a laser shines through a special crystal, producing photons with correlated quantum properties. Researchers have favored lasers because they generate coherent light, meaning the waves maintain a consistent phase and typically operate within a narrow range of wavelengths.
Advertisement
Sunlight is not coherent. It contains many wavelengths and reaches Earth from different directions, making it seem like an unlikely candidate for generating entangled photons.
The Ottawa and Max Planck researchers had previously explored the question through theoretical work and experiments using light-emitting diodes. Their work suggested that incoherent light could generate entanglement if the relevant quantum property did not depend on the light’s wavelength or direction.
Experimental setup for generating polarization-entangled photon pairs with sunlight. The solar concentrator is at right; the photon source and electronics are housed in a light-blocking tent at left. Inset: The source’s optical components and avalanche photodiodes.
For the solar test, the researchers needed to concentrate sunlight tightly enough to direct it into a small crystal. Hanieh Fattahi’s team at the Max Planck Institute built a glass, cone-shaped concentrator that collected light from a window-sized Fresnel lens and funneled it into a thin optical fiber.
Advertisement
The team tested the system outdoors at the institute over three days. The resulting photon pairs achieved about 94% fidelity with a perfectly entangled state. The experiment also violated Bell’s inequality, a test that helps establish whether correlations between particles are genuinely quantum rather than explainable by classical physics.
The Bell violation was limited, which the researchers partly attributed to weak seasonal sunlight and passing clouds. The entanglement quality also did not match the best results from laser-driven systems. Cheng Li, who co-led the research as a graduate student at the University of Ottawa and is now at Lawrence Berkeley National Laboratory, said the shortfall was likely caused by distortions in the optical components rather than the nature of sunlight itself.
He called it a proof of principle.
The researchers are now working to improve the brightness of the source and the quality of the entanglement. A more capable system could eventually be used outside the laboratory, including in remote locations or on satellites.
Advertisement
That prospect is part of the technology’s appeal. Laser-based systems require electricity, stabilization, and cooling, while much of their energy is lost as heat. A source powered directly by sunlight could eliminate the electrical-to-optical conversion step.
Li said satellite systems could one day use the sunlight already available in orbit to produce quantum encryption keys. The idea remains far from deployment, but the experiment points to a different approach to building quantum infrastructure.
When you’re thinking of purchasing a flashlight, you’re probably looking for a simple handheld device that can make a dark area visibly brighter. However, flashlights come in many different forms, for just about every part of the light spectrum. In addition to lights that shine in different colors like red or ultraviolet lights for finding stains, there are also infrared (IR) lights that shine in a light completely imperceptible to human eyes. On its own, such a device wouldn’t be especially helpful, but when paired with a pair of night vision goggles, an IR flashlight can suddenly become quite invaluable.
IR light is typically used as a means of connecting devices wirelessly, like the IR beam fired from your remote to your TV to send it signals. Because its wavelengths are longer than what human eyes can perceive on the visible spectrum, it can’t provide light on its own. This is why, rather than a “flashlight,” it may be more accurate to refer to an IR iteration of such a device as an “illuminator.” Rather than just shining a beam that you can see on its own, an IR flashlight “paints” your surroundings in IR light, which can then be picked up by light-sensitive equipment like night vision goggles.
Advertisement
Infrared light is normally invisible to the human eye, but can be seen with night vision
Dmitri Toms/Getty Images
The human eye is capable of perceiving light in the electromagnetic spectrum ranging from roughly 380 to 700 nanometers. This allows us to see, for example, the bright yellow light of the sun, as well as lights shining in cooler colors like green, blue, violet, and so on. However, infrared light’s band on the electromagnetic spectrum measures between 780 nanometers and 1 millimeter, which means a human eye can’t see it, at least on its own.
This is where equipment like night vision goggles come in. Night vision goggles can pick up a much wider band of light from the electromagnetic spectrum, including infrared light. Whatever light it picks up is then amplified a thousand-fold, brightening and sharpening it to a point that you can see it. However, the catch here is that infrared light needs to actually be present for night vision goggles to pick it up. If you’re in a spot where there’s not even trace amounts of light from the stars or a distant city, even night vision goggles will leave you in the dark. It’s in these specific situations that an IR flashlight becomes your secret weapon.
Advertisement
An IR flashlight paints an area with infrared light
Dmitri T/Shutterstock
Rather than merely creating a beam of light for the purposes of illumination, an IR flashlight instead covers the surfaces it shines on with infrared light particles. By painting your surroundings with infrared light. Even if you can’t see it with your naked eye, you create circumstances where a pair of night vision goggles can properly see things again.
An IR flashlight is a vital tool for various circumstances and professions. For example, search and rescue personnel can use them in caves or under dense forest canopies to search for missing people in a more efficient manner than a regular flashlight could provide. Law enforcement officers and SWAT teams can use them in nighttime sting operations, waving IR flashlights around to see figures in the dark with night vision without alerting anyone to their presence. It could even be used to help navigate out on the open ocean waters during a dense cloud cover over the moon. A combination of an IR flashlight and a night vision lens is also helpful for hunting or wildlife photography, as it allows you to see critters in the dead of night without scaring them off.
You must be logged in to post a comment Login