Connect with us

Tech

Modern USB Controllers On Win98 (and Up)

Published

on

[Yeo Kheng Meng] has a problem: he likes Windows 98, but he also likes his 2020 ThinkPad, which only has an xHCI USB controller– you know, the kind needed for USB 3.0, something that post-dates Windows 98 by a full decade. Drivers? Finding none existed, he decided to do it himself, or at least guide the process of using  LLMs to produce drivers for Windows 98 and up.

Some of you just stopped reading, but can you blame him for making a demonic pact for this project? Driver development isn’t really a one-man show, especially as a part-time hobby project you’re not sure anyone else will ever use. If you do want to use it, you can find the code on GitHub.

It does work, though, he admits it might be buggy. Unlike purely vibe-coded projects, [Meng] intends to address bugs put forth in the repo, at least. If you want to know how he did it, check out the link to [Meng]’s blog– which is human-authored, we can tell– and the videos embedded therein. He demonstrates it working on a 2020 ThinkPad, which should be usable even with Windows 11, and another model from 2016– neither of which have any old-style USB ports. Older laptops might, while any desktop can just use a PCI card with a USB2.0 controller– or you can do like [Meng] did prior to this project, and use the PCI card via adapters. 

Advertisement

[Yeo Kheng Meng] evidently gets as much of a kick out of joining old and new as we do, like running DOS a modern ThinkPad X13, and running Slack on Windows 3.11 For Workgroups on a slightly-less-modern but still 21st Century Thinkpad T400.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Tiny drone grows artificial whiskers to navigate dark and smoky spaces where cameras and GPS can struggle to see clearly

Published

on


  • Two artificial whiskers give this tiny drone a working sense of touch
  • Pressure sensors at the whisker base detect surface contact instantly
  • Onboard software processes tactile data using only 34 kilobytes of memory

A research team from Delft University of Technology in the Netherlands has developed a tiny drone that uses artificial whiskers to navigate where conventional sensors struggle.

The system relies on physical contact rather than cameras or satellite positioning, allowing the aircraft to detect nearby surfaces through touch.

Source link

Continue Reading

Tech

Zendesk and Sierra say AI agents should be paid per result, not per seat

Published

on

Zendesk CEO Tom Eggemeier and Sierra co-founder Clay Bavor said on Wednesday that per-seat pricing for software is on its way out. They spoke at HumanX in Amsterdam. In separate sessions, both said customers should pay for AI agents only when the agents get a job done.

“Unequivocally: seats are dead,” Eggemeier said.

Both sell AI agents for customer service. They spoke as software stocks recover from what investors called the SaaSpocalypse. Things looked “pretty dark early in the year,” Bavor said. Software stocks have since come back a bit off the lows.

Paying for a result

Zendesk moved to outcome-based pricing for its AI agents in August 2024, Eggemeier said. He called it the first company to do so. It now plans to drop seats across its business, with announcements due in three to six months. For many companies, pricing by interaction will be a first step, he said.

Sierra co-founder Clay Bavor speaking on stage with both hands open, in front of a HumanX backdrop
Sierra co-founder Clay Bavor at HumanX in Amsterdam, 23 September 2026. — Credit: ALX MEDIA / HumanX

Sierra charges only when its agents resolve an issue or make a sale, Bavor said. He put it in numbers. If a company pays one euro to resolve a case that costs ten in a call centre, it saves nine euros each time.

“The ROI is so clear you don’t have to do fuzzy envelope math about productivity gains,” Bavor said.

Sierra originates more than $1bn of new mortgages a month for companies such as Rocket Mortgage, he said. It serves almost half of the Fortune 50 and one in three of the world’s largest banks. OpenAI has also started outcome-based pricing for some customers.

Advertisement

Zendesk defines an outcome with each customer, Eggemeier said. In support, it is usually a problem solved without a human. For a UK used-car marketplace, it can mean an AI agent closing a £500 gap on a sale.

Who survives

The two differed on what keeps a software company alive. Coding agents such as Opus 4.5 and Codex 5.2 made software easier to build, Bavor said. Agents are also separating the interface from the data behind it. Companies with authoritative data, such as SAP in supply chains, hold up best, he said.

Eggemeier gave three tests. Companies must treat AI as both an existential threat and an opportunity. This shift will take three to five years, he said, not the ten to twenty of the move to the cloud. They must change their business model. They must also send people into the field to guide customers.

“If you’re still on seats in two or three years, I believe your company will struggle,” Eggemeier said.

Agents talking to agents

Zendesk expects AI agents to handle more than 80% of interactions within about three years, with humans handling the rest. Eggemeier said total interactions will grow sharply, and AI agent to AI agent interactions will pass 50% within two years. He uses Meta’s Muse himself, he said. Over the weekend, Zendesk tested whether a personal agent could buy its software online. It found a couple of gaps.

Advertisement

Bavor said personal agents such as Meta’s Muse will soon talk directly to business agents, within about six months. Most Sierra customers move staff to higher-value work rather than cutting them, he said. Some have created a new role, the “AI architect”, who coaches the agents.

Both moderators raised the Hugging Face incident, in which OpenAI agents reached Hugging Face. Bavor said Sierra’s customer-facing agents have far more limited tools than agents that can write arbitrary code. Eggemeier called cybersecurity his most worrying topic as CEO.

“Right now, offensive AI-agent hacking capability is ahead of defensive capability,” Eggemeier said.

Two of Zendesk’s three main AI hubs are in Berlin and Lisbon, Eggemeier said. The gap between San Francisco and Europe in AI has shrunk to weeks, he said. What worries him more is the growing gap with places like Ohio and Kentucky, where he is from.

Advertisement

Source link

Continue Reading

Tech

Twelve S’pore industries have already lost over 10,000 jobs in 2026

Published

on

Disclaimer: Unless otherwise stated, any opinions expressed below belong solely to the author. Data sourced from the Ministry of Manpower.

Yesterday I reported some positive news from the local labour market, which still has around 40,000 vacancies for PMET candidates available. Today, I’m afraid, it’s time to balance it out with some negative findings, also from data published by the Ministry of Manpower.

As ever, the economic situation within the country differs greatly between industries.

Some are booming, pulling the country ahead, while some are falling behind, and their plight is often absent from the news headlines. This is especially true today, as the staggering boom in artificial intelligence (AI) has boosted local manufacturing sectors, raising the average GDP growth up to 6%.

Advertisement

Singapore is reported to be a huge success story, posting economic performance comparable to or even better than that of developing countries.

But not all is rosy on the island, as the examples of the industries struggling this year reveal. Please note that the following numbers include all workers, local and foreign:

Net change in employment in 2026, by industry

Industry Change in the first half of 2026
Food & Beverage Services -3,400
IT & Other Information Services -1,700
Wholesale Trade -1,100
Accommodation -800
Paper / Rubber / Plastic Products & Printing (Manufacturing) -700
Retail Trade -600
Transport Equipment (Manufacturing) -500
Legal, Accounting & Management Services -400
Insurance Services -200
Other Professional Services -100
Air Transport & Supporting Services -100
OTHER -700
TOTAL -10,300
Data until the end of Jun 2026./ Source: Singapore Ministry of Manpower

The top entry on this list is a surprise to nobody.

The Food & Beverage sector is known to have been suffering in recent years, with hundreds of restaurant closures amid pressures from rising rents and inflation on one end, and limited willingness for customers to pay enough to offset these rising costs on the other (as well as some predatory competition from China).

Advertisement

But the situation is the worst it has been since the pandemic.

Throughout 2024 and 2025, employment in F&B services remained relatively stable, but this year’s slump has already wiped out virtually all the jobs added all the way back to 2023. In terms of labour, F&B is where it was at the end of 2022, when it was still emerging from the pandemic crisis.

That said, it’s quite likely that the majority of the workers affected are non-Singaporean (though Singaporeans have to accept a shrinking selection of food venues).

What’s more concerning is the IT sector’s slide, despite other data suggesting it’s doing well.

Advertisement

Shrinking IT

With close to 4,000 vacancies, it appears to be pretty strong, remaining open to qualified candidates. And yet, the number of people it employs in Singapore keeps shrinking.

This year’s drop of 1,700 jobs follows 3,700 lost in 2025. Since Q4 of 2024, the total fall in IT employment has reached around 6,200 positions—and we know that those are some of the best-paying ones in Singapore.

So, on the one hand, tech appears to be booming and looking for more people and, on the other, we’re seeing it getting rid of workers at the highest pace on record.

Clearly, the AI revolution has eaten into the profession, as companies move priorities from employing the best talent to deploying the most capable AI solutions—and paying for that investment through headcount cuts.

Advertisement

It’s hard to say whether the large number of advertised vacancies is due to skill mismatch in the age of AI or whether they are ghost offers that never really get filled.

Not even corporate workers are safe

While posting much smaller losses, it’s worth noting that even those in roles established around local corporations in legal, management, accounting or insurance services cannot feel too comfortable about their employment.

Excluding architecture and engineering, professional services have posted a drop of 700 jobs in the first half of the year.

While it may seem small, it’s equivalent to a pretty big company going completely out of business and taking all of its people. And, unfortunately, it’s also a part of a longer trend, as the sector had lost a total of 2,200 jobs in the 18 months up to Jun 2026. It’s not an isolated stumble.

Advertisement

It’s hard to say if that too is a result of AI, but this trend deserves attention, as next to IT and Finance, those tend to be well-paying jobs that many Singaporeans are interested in.

As you can see, the biggest tech revolution of our time might have boosted Singapore’s economy sky high, but not everybody was lucky enough to secure a ticket for the ride.

  • Read other articles we’ve written on Singapore’s job landscape here.

Featured Image Credit: Hongwei Fan/ Unsplash

Advertisement

Source link

Continue Reading

Tech

Placeholder domain used in dev docs now serves ClickFix attacks

Published

on

Third-party clickfix attack

The “third-party.com” domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands.

The domain third-party.com has long been used in documentation to represent an arbitrary external website, API, or service, similar to how developers use domains such as example.com.

However, unlike example.com, example.net, and example.org, which IANA reserves specifically for documentation, third-party.com is a normally registered domain whose content its owner can control.

This difference is now a security concern after the domain began serving a ClickFix attack that impersonates a Cloudflare security check.

Advertisement

Manifold Security first reported the malicious use of the domain after discovering it while examining public AI skills and MCP server documentation that referenced the domain.

BleepingComputer has since confirmed that the page displays a fake Cloudflare “Performing security verification” CAPTCHA screen containing a “Verify you are human” prompt.

After the user clicks the verification box, the site copies a malicious PowerShell command into the Windows Clipboard, and then instructs the user to press the Windows key + R, paste the contents of their clipboard using Ctrl+V, and press Enter.

Clickfix attack on third-party.com
Clickfix attack on third-party.com
Source: BleepingComputer

When the PowerShell command runs, it reconstructs the payload URL elxxvvx[.]xyz/f, downloads a PowerShell script from that address, and then executes it.

This technique is commonly known as ClickFix, where attackers use fake errors, CAPTCHA prompts, or verification pages to convince victims to manually execute commands copied to their clipboard.

Advertisement

ClickFix attacks have become a popular way to distribute malware, as the malware is installed via commands executed by the user rather than downloaded from websites or as email attachments. In some cases, this could allow malware to install while bypassing traditional antivirus software.

At the time of BleepingComputer’s testing, elxxvvx[.]xyz no longer resolved, leaving the current attack chain broken.

However, a Hybrid Analysis report from May 2, 2026, shows the site distributed a PowerShell script configured to download a 134MB zip archive from:


https://elxxvvx[.]xyz/update2.zip

The PowerShell script saved the archive as update26.zip, extracted it, and then attempted to launch an executable named draw.io.exe.

Advertisement

Because the update2.zip archive is no longer available, BleepingComputer couldn’t determine what the payload does.

Manifold’s Ax Sharma says the attack specifically targets Windows users, and Linux and Mac visitors will see errors stating their operating system is unsupported.

“A macOS or Linux user-agent gets none of that. It gets a near-identical page that stops at an error: “macOS is not supported. This website requires a Windows PC to access.” No clipboard poisoning, no payload,” explains Sharma.

“The attacker only shows the weapon to the targets it works against, which is precisely why a casual look, or a scanner on a Linux datacenter IP, sees nothing wrong.”

Advertisement

A placeholder that wasn’t reserved

The more interesting aspect of the attack is the third-party.com domain chosen to host the ClickFix page.

Public developer documentation has treated third-party.com as a generic example hostname for many years.

For example, the W3C Geolocation specification currently demonstrates granting geolocation permissions to an external iframe using third-party.com as a placeholder domain:

Third-party.com used in W3C sample documentation
Third-party.com used in W3C sample documentation

The W3C Compute Pressure specification similarly uses the domain when demonstrating how a website can enable the API for remote content:



Chromium’s documentation for its Telemetry Extension API also uses third-party.com as an example website permitted to communicate with a Chrome extension:

Advertisement

Other examples go further and use the domain in code that would actually make network requests if copied literally.

A PrivacyCG proposal on GitHub also uses the domain as the destination of a JavaScript fetch() request from a service worker.

Posts online indicate that developers have copied these and similar examples into their own code and projects.

In a 2015 Stack Overflow question, a developer said they had applied an asynchronous loading example containing https://third-party.com/resource.js to their website before discovering that it did not behave as expected after publishing the site.

Advertisement

These examples do not mean that the associated projects or documentation are compromised. 

However, applications or test code that copied such placeholder URLs could now cause a browser or automated tool to contact the real third-party.com domain and potentially display the ClickFix attack in a browser or application.

Unlike example.com, which IANA maintains for documentation and does not allow to be registered or transferred, the third-party.com domain has no such protection, and was clearly hijacked or registered at some point to conduct these ClickFix attacks.

“third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,” explains Manifold.

Advertisement

“A public code search turns it up in skills, MCP-server docs, and over 1,500 files across 1,700+ repositories from names as trusted as Chromium, Sanity, and Vercel. Since at least June 2026 it’s been serving the ClickFix lure.”

While the widespread use of third-party.com as a placeholder in documentation makes the domain attractive to attackers, there is no evidence that it was registered for malicious purposes.

The domain was first registered in 1996, long before the current campaign, and BleepingComputer has not determined when or how control of the site changed.

At this time, there have been no reports that these references to third-party.com have actually resulted in ClickFix attacks being executed on developer’s devices or within their applications/webpages.

Advertisement

However, as the domain remains live, it could easily be switched to a new, live payload domain and actively utilized in future attacks.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading

Tech

OpenAI’s Colin Jarvis says enterprise AI is stuck on deployment, not models

Published

on

Most companies that struggle with enterprise AI are not waiting for better models, OpenAI’s head of forward deployed engineering said on Wednesday. In about 80% of cases, Colin Jarvis said, the problem is deployment. Companies do not yet know how to roll AI out, govern it or prove they can trust it.

Glasgow-based Jarvis leads OpenAI’s forward deployed engineers (FDEs), who work inside customer companies to get its models into production. He spoke to Alex Hern of The Economist at HumanX in Amsterdam.

“I don’t personally feel a lot of pressure to race ahead on model development itself,” Jarvis said.

In the other 20% of cases, customers say the model cannot yet do the job, he said. Those gaps are now narrow and specialist, such as a task in semiconductor design, rather than everyday office work.

What FDEs do

The team started out as mostly software engineers, Jarvis said, because building on the raw API meant writing everything from scratch. With tools such as Codex, about 50% of each project is now custom work, down from about 90%. That has shifted hiring toward domain experts, including a former investment banker, former scientists and a chip verification engineer.

Advertisement

Every engagement starts with a two-day visit. The team asks business leaders to ignore AI and name the biggest levers in their business. It then works on whichever that turns out to be.

At one semiconductor company, engineers spent maybe 80% of their time on bugs from overnight jobs, Jarvis said. OpenAI built a system that finds the root cause, proposes a patch and applies it after an engineer reviews it. It spread from one department to the whole business. The company estimates it saves roughly $40m to $50m a year.

Other projects include an agent that iterates car part designs from plain-language instructions, for a European manufacturer. Another helps draft clinical trial documents, where a human always stays in charge.

Why pilots fail

Jarvis named two common mistakes. Companies pick a use case because it seems to fit AI, not because it matters. Or they get one good use case working in one department, and it stays a demo that never spreads.

Advertisement

The companies that succeed measure success by production use, not proofs of concept, he said. One semiconductor customer has about 35 use cases live after roughly 18 months. It built a central team to scale projects and placed small groups of engineers in each business unit.

FDEs have no financial incentive tied to usage, Jarvis said. They are measured on whether a project reaches production and moves a real metric. When OpenAI’s embeddings were too slow for a Klarna search service, he told the company to use an open-source model instead.

“From OpenAI’s side, we should always be temporary,” he said.

The pace question

Hern noted that Sam Altman was at the UN that day, as pressure grows to slow AI down. Jarvis said OpenAI has shown it will pause when it reaches the limits of its safety frameworks. He said he thought it paused its main reinforcement learning run “in September this year”.

OpenAI published its own post on the pause on 18 August. It describes a two-week pause in reinforcement learning training on its latest models. It also says its largest planned frontier run stayed on hold. Altman has since said OpenAI will set its own pace without waiting for Congress.

Advertisement

Jarvis said FDEs help test whether safety frameworks built in a lab hold up in messy real companies.

OpenAI is not alone in sending engineers into clients’ offices. AWS is spending $1bn on the same model, and Microsoft launched a $2.5bn deployment business in July.

Source link

Advertisement
Continue Reading

Tech

NYT Strands hints and answers for Thursday, September 24 (game #935)

Published

on

Strands is the NYT’s latest word game after the likes of Wordle, Spelling Bee and Connections – and it’s great fun. It can be difficult, though, so read on for my Strands hints.

Want more word-based fun? Then check out my NYT Connections today and Quordle today pages for hints and answers for those games, and Marc’s Wordle today page for the original viral word game.

Source link

Continue Reading

Tech

ShinyHunters Hackers Claim To Have 2-3TB Of Sensitive Information About FBI Employees

Published

on

Financial extortion doesn’t seem to be the group’s goal this time.

Hacking group ShinyHunters has allegedly stolen extensive amounts of sensitive information from the US Federal Bureau of Investigation that includes details about its employees and job applicants. Reuters reports that it has seen a sample of the data obtained by the attack on the agency, and 404 Media also said it received confirmation of the action from a representative of ShinyHunters. The hackers also appeared responsible for an unauthorized takeover of the FBI website earlier this week.

“We hacked the FBI. We hold data on all FBI employees and applicants,” the spokesperson told 404 Media. According to that source, ShinyHunters got the information by using a zero day exploit in the PeopleSoft program from Oracle to obtain access to Amazon Web Services’ GovCloud servers.

A statement from the FBI shared with Reuters said that the agency was aware of “a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information” and that it is “actively and aggressively investigating the matter.”

Advertisement

The attackers claim to have 2-3TB of data, but the sample shared with the media appeared to contain names, addresses, telephone numbers, dates of birth, social security numbers and emergency contact details for 5,000 employees at the FBI. The group may also have gathered details about some work assignments for agents and about some FBI units that are working on intelligence, security and counter-espionage efforts, including operations focused on both China and Russia.

Many of ShinyHunters’ previous hacks have been aimed at extortion, with actions against parties ranging from Ticketmaster to Rockstar Games in recent years. However, the rep who spoke with 404 Media claimed this move against the FBI was “not financially motivated” but rather aimed at coercing the government agency to remove or amend a previous statement made about ShinyHunters. In a report from May, the FBI said the hacking group “exaggerated claims of access to sensitive or personal information to prompt payment from victims.”

Advertisement

Source link

Continue Reading

Tech

Anthropic says its biology lab has already found something big

Published

on

Last week, Anthropic confirmed that it was operating a wet biology lab in the Bay Area where it uses its AI models to run physical experiments. This week, the AI giant announced that this lab has already made what it believes is a big discovery: a new enzyme “system” that has certain “properties reminiscent of CRISPR,” as Anthropic describes it.

CRISPR is a natural immune system used by bacteria to fight off viruses that has become a gene-editing technology widely used by researchers.

Essentially, what Anthropic says it found is a previously unknown enzyme system hidden in the DNA of bacteriophages, which are viruses that infect and replicate within bacteria. Anthropic’s researchers say this system behaves similarly to CRISPR in that it can “perform operations like cutting, copying, and pasting DNA.”

It will be up to the broader research community to validate how big, or new, this discovery actually is. Anthropic CEO Dario Amodei acknowledges that the discovery was based on the previous work of others and that a team from Stanford previously discovered a system “that is in some ways similar to the one Claude found,” he wrote on X.

Advertisement

But Amodei and Anthropic are not just emphasizing the discovery. They are touting it was found “mostly, though not entirely, by Claude,” the CEO wrote.

On the one hand, that is astounding. This lab was only established this spring, (though Anthropic declined to be more specific about how many months it has been open). A discovery in just a few short months would be speedy enough work, but the team said it actually only took Claude 21 hours of concerted effort. Claude searched through data using about 950 agents that burned through 210 million tokens.

Still, the revelation that Anthropic has been conducting biology experiments comes right after AI CEOs, including Amodei, publicly admitted that models have become so capable, and so potentially dangerous, that the industry must slow down and develop safety-testing procedures. This after a couple of his employees publicly said earlier this month that there’s a risk AI could kill us all.

Amodei himself has said one of the things he fears most its that AI could be used for bioterrorism. But he also believes AI will “cure most diseases in 5-10 years,” he wrote. So Anthropic has clearly decided the rewards are worth the risks.

Advertisement

Given that, perhaps the biggest reveal in this news isn’t the discovery itself, but that the biology lab hasn’t let Claude loose. The physical experiments were done by humans.

“Our lab, located in the Bay Area, looks like a typical molecular biology lab. We do research that involves only the lower-levels of the biosafety risk level (BSL-1 and BSL-2) and we do not handle pathogens that can infect humans. All of the lab work is performed by human scientists.”

It’s also true that AI-powered biological research is hardly unique to Anthropic. Researchers from Stanford just published a paper on the work they are doing with LLMs and CRISPR. Researchers at UC San Francisco used AI to design enzymes from scratch. Google launched its first AI-powered biology research tool, AlphaFold, back in 2020. So AI has clearly arrived in biological research beyond the AI labs pursuing it themselves.

Yet, Amodei hasn’t ruled out a fully automated biology lab in the future. “Eventually it may even be possible for Claude itself to safely perform the experiments by autonomously controlling lab equipment, with appropriate safeguards in place, but we aren’t doing that today,” he said.

Advertisement

.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Advertisement
Continue Reading

Tech

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Published

on

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.

The same advisory also warns of threat actors exploiting a pre-authentication path traversal flaw tracked as CVE-2026-93616, which impacts the Management web service and can allow script execution and Java class loading.

The company says that CVE-2026-93616 has been exploited as a zero-day since July 23.

On September 10, the Dutch Nationaal Cyber Security Centrum (NCSC) alerted of the Security Gateway issue and urged users to apply available security updates as imminent exploitation was expected.

Advertisement

Check Point has now confirmed that malicious activity started on September 12, with attackers using VPNs and proxies to hide their location.

“Starting September 12, 2026, we observed a wave of exploitation attempts against Spark customers,” reads Check Point’s alert.

“The attempts originated from anonymization infrastructure, including VPN services and proxies,” the company said, adding that certificates with the following subjects were used:

  • CN=vpn,OU=users,O=global
  • CN=vpn-user,OU=users,O=global
  • CN=vpnuser,OU=users,O=global

However, the cybersecurity company noted that the three subjects only reflect current observations and more may be in use.

CISA has now added the two flaws in its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply the available fixes and/or mitigations by September 25, 2026.

Advertisement

Mitigating the risk

Check Point’s advisory on CVE-2026-85102 recommends that administrators install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or install a fixed Jumbo Hotfix: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later.

Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.

System administrators are advised to verify if LivePatch is active by running the cpinfo -y CPupdates command on the Security Gateway  in expert mode.

The advisory specifically warns that some customers who installed an earlier offline LivePatch package need Take 26 for full coverage.

Advertisement

If updating isn’t possible, it is recommended to disable the VPN implied rules and create explicit rules that restrict Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses.

For Remote Access VPN, allow only the required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges where possible.

Check Point notes that these mitigation measures do not apply to locally managed Spark firewalls.

For mitigation and hunting advice for the Management web service CVE-2026-93616, Check Point points to this support article.

Advertisement

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading

Tech

New RemControl Android banking malware targets users in Europe and Canada

Published

on

New RemControl Android banking malware targets users in Europe and Canada

A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.

Although the infrastructure has been active since at least May, the first samples were observed in July and contained more than 30 phishing overlays designed to steal banking credentials.

Researchers at cybersecurity company Group-IB say that the malware targets users in Europe (Italy, France, Spain, Poland, Portugal), Canada, and countries in the Middle East.

In one of the overlays, the malware displays an AI assistant response, a strong indication that it has been built with the help of AI models.

Advertisement
Phishing overlay exposing the use of AI
Phishing overlay exposing the use of AI
Source: Group-IB

RemControl is distributed through fake Google Play pages impersonating the TVTap IPTV app, with at least one Italian campaign using geofencing and mobile User-Agent checks.

The malicious sites include Meta Pixel tracking IDs, which Group-IB sees as a hint that the operator abused Meta’s advertising ecosystem to drive victims to the download pages.

Fake Google Play site
Fake Google Play site
Source: Group-IB

When launched, the dropper starts a VPN service that blocks traffic from Google Play services, preventing Play Protect from performing real-time checks against known malware.

The feature has also been observed in a recent version of the ToxicPanda malware, a much bigger operation that uses phishing overlays for 349 financial, cryptocurrency, and digital wallets applications used in 16 countries.  

phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications targeting 16 countries.

During installation, the malware requests approval for Accessibility Service permissions.

Advertisement
Accessibility
Source: Group-IB

If the requested permissions are granted, RemControl can perform the following actions:

  • Display full-screen phishing overlays on top of legitimate banking apps and steal PINs, banking codes, card expiry dates, and credentials
  • Dynamically receive new banking targets from the command-and-control (C2) infrastructure
  • Stream screenshots and the full Android accessibility/UI tree to the operator in real time
  • Record clicks, text changes, focus events, and other user input across applications
  • Remotely perform taps, swipes, scrolling, gestures, long presses, and text injection
  • Capture Android pattern-lock coordinates across several OEMs, including Samsung, Xiaomi, Huawei, OPPO, OnePlus, and stock Android
  • Prevent removal by detecting when victims enter application-management, accessibility, or factory-reset settings and automatically exiting

RemControl retrieves encrypted C2 information from Telegram channels, so it can rotate infrastructure dynamically in case of disruptions.

Group-IB found FastAPI documentation exposed in the initial C2 proxy that revealed the endpoints the malware used to fetch banking overlays and to submit stolen credentials.

The origin of the threat actor behind RemControl is unclear, but the researchers found Russian language in the HTML files of some overlays, indicating a Russian speaker as the developer of at least some of them .

Based on a common identifier in the analyzed samples, the researchers track the RemControl operator as UNKK and suspect a connection to the Medusa banking trojan.

Android users are advised to avoid downloading APK files from outside Google Play unless they explicitly trust the publisher.

Advertisement

Regular Play Protect scans and declining Accessibility Service permission requests from apps that do not require them for accessibility purposes are also recommended security practices.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading

Trending

Copyright © 2025