Security teams have spent years hardening authentication, with controls like multi-factor authentication (MFA) and conditional access now commonplace. While stronger authentication can make traditional credential theft less effective, it doesn’t solve every identity problem.
There are several points in the identity lifecycle where trust is established or re-established:
When a new employee joins.
When someone loses access to their account.
When a password or MFA factor needs to be reset.
When the service desk is asked to make a sensitive change to an account.
Rather than stealing credentials or bypassing MFA, an attacker can instead try to convince the service desk that they are the account holder, using social engineering to exploit legitimate processes.
That puts greater pressure on organizations to secure both the login as well as the processes around account creation and recovery.
How Attackers Exploit Identity at Onboarding and Recovery
In late July 2026, the US Department of State and allies including Japan, Canada and the UK issued a joint alert warning that North Korean IT workers were impersonating foreign nationals to secure employment.
Advertisement
Their tactics focus on falsifying identity documents, such as using images supplied by a third party based in another country to register accounts. The North Korean then carries out the actual work.
These workers typically target technology companies, so the important point is not that every organization should expect the same type of campaign. It is that onboarding creates a moment when trust is established for the first time.
If identity checks fail at that stage, the attacker can enter the environment with access that appears legitimate.
The same issue can occur during the recovery process. Threat actor groups like Scattered Spider are proficient at social engineering, impersonating employees and calling the service desk to reset passwords that gift access to an account.
Advertisement
This tactic was linked to the 2025 M&S ransomware breach, which contributed to an estimated $400 million hit to the retailer’s operating profit through lost sales.
The security question in these scenarios is the same: how confidently can the organization verify that the person making the request is who they claim to be?
Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches.
Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles!
Strong Authentication Still Depends on Strong Identity Checks
When someone calls the service desk claiming that they’ve forgotten their password or lost access to their authenticator, the agent needs to be able to confidently verify the person calling is the real account owner.
However, in many organizations identity checks can still rely on relatively weak signals. A service desk might ask for an employee ID or phone number. Security questions are still common, asking the caller the name of their first pet or where they went to school.
The problem is that many of these checks can be researched, stolen or manipulated. Attackers can find personal information through data breaches or social media.
Even in instances where stronger checks are in place, the North Korean remote worker campaigns demonstrate how documents and other identity evidence can be altered or fabricated.
Advertisement
AI is making impersonation more convincing, too. Attackers can use synthetic profiles, manipulated images, cloned voices and deepfake video to support a false identity or make a social engineering attempt more believable.
All of these make it harder for agents to act with confidence. As it’s vital for organizations to verify users during onboarding and recovery events, they need stronger measures to deliver that verification.
Strengthen Verification During High-Risk Identity Events
Solutions like Specops Verified ID add another layer of assurance and helps service desk agents confidently confirm identity before sensitive actions take place.
It does this by combining government document scanning and validation with biometric liveness detection.
Advertisement
Document checks help confirm that the ID being presented is legitimate, while liveness detection helps verify that a real, present person is completing the process rather than relying on a static image or other replayed evidence.
During onboarding, this gives organizations a stronger way to verify new employees before granting access to corporate systems. That can reduce the risk posed by fraudulent applicants and impersonation attempts, including tactics seen in North Korean remote worker campaigns.
The same approach can be applied when high-assurance verification is needed, such as password resets for privileged accounts.
Rather than adding complexity to every identity event, Specops Verified ID applies stronger verification where the consequences of getting it wrong are highest.
Advertisement
Protect Your Service Desk with Specops
Strong authentication remains essential, but attackers will continue looking for ways around the controls that are hardest to break. Increasingly, that means targeting the processes used to establish or recover identity rather than attacking the login itself.
Whether an organization is onboarding a new employee or helping an existing one recover their account, the challenge is ensuring the right person is granted access.
Specops Verified ID adds government ID validation and biometric liveness detection to these high-risk identity events, helping organizations make that decision with greater confidence.
If you’re interested in learning more about how Specops can strengthen identity verification at the service desk, contact us today to speak to an expert.
Mozilla plans to enable JPEG XL decoding by default in Firefox 157, which is due at the end of September. Phoronix reports: Firefox Nightly has JPEG-XL support enabled by default right now to help in vetting this support while Mozilla believes the support is in good enough shape for a stable debut with Firefox 157. This follows Chrome shipping JPEG-XL and Google Research developing jxl-rs as a Rust-based JPEG-XL image decoder that is both performant and secure.
In today’s Mozilla Hacks blog post they elaborate on JPEG-XL vs. AVIF image formats: “JPEG XL: Excels at lossless imagery, progressive rendering, and further compressing JPEGs without quality loss. AVIF: Excels at web-quality photographic images, and images that have a mix of sharp edges and flat surfaces. … Although AVIF tends to produce smaller files at web-quality than JPEG XL, AVIF only has basic progressive rendering support. So, for very large images, it may be worth taking the filesize hit with JPEG XL.”
This year, gluten-free dishes included a lemon-oregano shrimp with schug and feta—a lemony-herbal romp served over rice livened up with dried apricots. (Adding dried fruit to liven up rice is a favored trick by Green Chef, one I might plan to add to my normal cooking routines.) The American-fished shrimp were plump and hearty, with no briny fishiness.
Yemeni schug remains one of my favorite condiments in existence, though this version could have been spicier. And the rice could have been more plentiful, perhaps. But these are small quibbles on a light, bright meal with lovely layers of flavor from herbal schug to toasted cauliflower and kale and the lightly tart bite of apricot.
I would almost never bring together this many ingredients on a weekday night, were they not helpfully bagged up in single portions. Indeed, if I tried, I probably would end up spending more at the grocery store than on the meal kit, as I discovered after an experiment last year.
Photograph: Matthew Korfhage
But especially, I have been impressed with protein sourcing. A well-trimmed bavette steak last year came from a fourth-generation meat purveyor in Texas. So did my chicken breast this year, on a harissa chicken dish. Shrimp are Atlantic coast, not Southeast Asian coast. My salmon was wild-caught. My steelhead came from a fishery in Norway. Each is clearly and transparently marked—a rarity among proteins from meal delivery services.
Advertisement
That steelhead in particular was among my favorite home meals of the summer. The dish’s secret, again, was layering: earthy spice on the fish, citric accents and crispness on the gremolata. The pleasing chew of dates countered the soft give of ginger-spiced couscous.
While eating it, I actually felt proud of myself—though it only took a scant 40 minutes to make. If anything, this summer’s meals were more sophisticated, but lower effort, than the Green Chef meals I tried last year.
Quibbles
Green Chef’s recipe cards are thoughtfully designed, with helpful pictures guiding the way. But their format tends to separate out each prep step in full, carrying the entire step through to completion, whether veggie chopping or couscous cooking.
This makes sense, of course. But this does lead to a simple caution: Green Chef does not hold your hand as well as some meal kits as regards the best order of operations. Read through each recipe in its entirety before cooking, and decide your game plan.
We’ve all been there. You meet someone new on a dating app, start to envision a life together, only to wonder: Is the person actually who they say they are?
It’s an experience that has led many singles, sometimes out of concern or just genuine curiosity, to prescreen dates by tracing their digital footprint: scanning social media posts, browsing their LinkedIn profile for clues.
The platform Stud or Dud—not to be confused with stud’s use as a slang term for a masculine-presenting Black lesbian—wants to introduce even more transparency into that part of the dating process. According to its website, the platform uses “public records, publicly available information, and other permitted sources” to create a profile of your potential match. It launched today in the US and was created by the company behind PeopleFinders.com, the online data broker service that collects public records from multiple sources and makes them searchable to help clients locate individuals or run background reports.
Intended to help daters make informed decisions about the people in their life, like identifying possible warning signs, Stud or Dud aggregates courthouse documents, bankruptcy filings, tax liens, pre-foreclosure data, phone directories, social media posts, and more to create a snapshot of your potential suitor’s personal life. All daters need is the person’s name or phone number to run a search. The aggregated data is presented in a single report, where it is divided into four categories: finances, property or assets owned, employment history, and criminal background. Each report comes with an AI-generated overview.
Advertisement
The tool will also earmark what it determines to be red or green flags about the person. Criminal records—a DUI or time spent in prison, for example—signal a red flag, but PeopleFinders CEO Amber Higgins encourages users not to pass judgement even if the site does.
“We give enough information for the user to determine, is that really a red flag for them or not? And that all kind of speaks to your lifestyle expectations.” In this sense, the reports lean prescriptive since the company suggests what safety details to consider, calling attention to things like how many times you’ve been evicted or if your name is on a sex offender registry. There is also an AI assistant (“the dating detective”) users can chat with when they want more tips for first dates or general advice.
According to the company, one of the biggest historical use cases of PeopleFinders.com has been for online dating safety.
“Modern dating has changed dramatically, and the tools people have used to establish trust haven’t kept pace,” Higgins says. “People are meeting across dating apps, social media, DMs. They have very little context of who’s actually on the other side.”
Advertisement
While some might consider that the whole point of dating—the early talking stages, however awkward, are all about navigating the unknown when getting to know someone—Higgins adds that the site, which requires a subscription, was built to provide additional context on a potential match. She recommends that people use it as a “sidekick” to the apps. “This is meant to confirm your trust about a dating profile.”
Even as online vetting is a crucial safety measure and fully part of the modern dating process—daters in San Francisco, for example, lost more than $40 million to romance scams in 2025, according to the FBI—there also seem to be legitimate opportunities for bad actors to exploit the information gathered from the site. The platform assumes that the person doing the searching is the one at risk, but that may not always be the case.
No timeline to restore IT systems as probe remains ongoing
Medical device maker Boston Scientific’s global operations have been disrupted by an ongoing cyberattack, the company disclosed on Wednesday. According to an SEC filing, the “cybersecurity incident” affecting its IT systems started on Tuesday, and resulted in a “global disruption to the company’s operations.”
Advertisement
Upon detecting the digital intruders, the company began an investigation with third-party infosec experts who are working to contain the threat, the filing says.
The medtech firm did not immediately respond to The Register’s inquiries, including if this was a ransomware infection and what data, if any, the criminals stole after breaking into the IT systems.
“The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders,” Boston Scientific reported to federal regulators.
The company doesn’t have a timeline for full restoration, and noted the “full scope, nature and impacts, including operational and financial impacts” of the cyberattack remain unknown.
Advertisement
The news did, however, send Boston Scientific shares spiraling down more than 4% on Wednesday morning.
At press time, none of the usual suspects had claimed responsibility for the attack. In recent months, both ransomware/extortion gangs and government-backed hackers have disrupted other medtech firms’ operations and stolen sensitive data.
A month later, medical-device maker Medtronic disclosed a cyberattack in a filing with federal regulators. Notorious data-theft-and-extortion group ShinyHunters claimed to be behind this intrusion, and the company in July warned patients that their names, contact details, dates of birth, Social Security numbers, and health information was stolen in the breach. ®
ASCENDO Immersive Audio returns to CEDIA Expo in 2026 with something more ambitious than another conventional architectural loudspeaker. The company will debut its new Panoramic Surface On-Wall, an ultra-shallow speaker designed around ASCENDO’s proprietary full-range composite radiating surface technology for immersive home cinema systems.
The technology was developed specifically for surround and height-channel applications, where conventional loudspeaker dispersion can become a significant design challenge. As frequencies rise, traditional drivers tend to become increasingly directional, concentrating more acoustic energy in front of the speaker. Cone drivers, dome tweeters, compression drivers, and waveguides can all be engineered to control that behavior, but high-frequency beaming remains an inherent consideration in conventional loudspeaker design.
That becomes particularly important in an immersive cinema, where surround and height speakers are supposed to create a convincing acoustic environment rather than draw attention to individual boxes mounted on the walls or ceiling. Consistent dispersion can help maintain tonal balance, spatial cues, and perceived sound levels across multiple seats instead of delivering the best experience only to listeners positioned directly on-axis.
Solving Beaming Issues
The ASCENDO Panoramic Surface Speaker takes a different approach by replacing a conventional multi-driver arrangement with the company’s proprietary full-range composite radiating surface technology.
ASCENDO says the surface is engineered to distribute acoustic energy across a much broader area than a typical point-source loudspeaker while allowing the enclosure to remain exceptionally shallow. In practical terms, the design is intended to function more like a controlled acoustic surface than a conventional speaker with distinct high- and low-frequency radiators.
Advertisement
According to ASCENDO, the resulting radiation pattern approaches 180 degrees and maintains that broad dispersion into the high-frequency range, extending up to 20 kHz.
“Panoramic Surface follows a principle that has always driven ASCENDO: We don’t take an existing loudspeaker concept and force it into an application it was never designed to serve,” says Geoffrey Heinzel, ASCENDO Co-Managing Partner. “We start with what the acoustic environment actually requires and engineer the solution around those demands.”
Advantages For Listeners
For listeners, the Panoramic Surface Speaker is intended to deliver more consistent tonal balance across a wider seating area, with less audible variation between on-axis and off-axis positions. In an immersive system, that can also help surround and height effects feel more continuous and less dependent on a single ideal listening position.
ASCENDO also says the broad radiating behavior can reduce the level changes that listeners may experience when seated relatively close to a surround or height speaker. For installers, that could provide greater flexibility when arranging seating in rooms where individual channels cannot always be positioned far from every listener.
Advertisement
Wide dispersion, however, is only part of the equation. An immersive cinema loudspeaker still has to reproduce transient information, spatial cues, and dynamic changes with sufficient precision and control. ASCENDO says the Panoramic Surface design was engineered to combine its broad radiation pattern with the speed, clarity, and dynamic performance expected from the company’s cinema loudspeakers.
Designed to Work With Room Architecture
The Panoramic Surface also addresses another challenge in surround and height-channel installations: the interaction between a loudspeaker and the wall or ceiling on which it is mounted.
Advertisement. Scroll to continue reading.
Because the speaker is designed to operate very close to an architectural boundary, ASCENDO says it can greatly reduce front-boundary SBIR (speaker-boundary interference response). SBIR occurs when direct sound from a loudspeaker combines with sound reflected from a nearby boundary, potentially creating cancellations and uneven frequency response.
Advertisement
By minimizing the distance between the radiating surface and the mounting boundary, the Panoramic Surface is designed to reduce those problematic reflection paths and associated comb-filtering effects. The approach also reflects ASCENDO’s broader philosophy of engineering loudspeakers as part of the complete cinema environment rather than treating the speaker and room as separate elements.
Experience ASCENDO at CEDIA Expo 2026
ASCENDO will demonstrate its Panoramic Surface speakers and latest immersive audio technologies at CEDIA Expo 2026 in SR10 (Sound Room 10), where the company is integrating them into a scalable luxury home cinema system.
The demonstration will feature a 9.8.4-channel configuration, giving attendees an opportunity to hear how the Panoramic Surface speakers perform as part of a complete ASCENDO immersive cinema installation.
StormAudio: To provide the processing and amplification required for the demonstration, StormAudio is supplying its ISR Fusion 20 immersive AV receiver. The Fusion 20 is a 20-channel processor with 16 channels of built-in amplification, delivering up to 150 watts per channel into 8 ohms in single-ended operation.
AcustiMOD: Drawing on the heritage of Officina Acustica, AcustiMOD is outfitting the room with its modular acoustic architecture system. The approach is designed to provide a more engineered and repeatable path to room treatment, bringing elements of bespoke acoustic design to a broader range of installation budgets.
Christie and Seymour Screen Excellence: These companies are teaming up to provide the best possible visual experience with a yet-unnamed Christie 4K projector and Seymour Excellence reference Enlightor-Neo acoustically transparent, multi-format, patented screen.
madVR: The award-winning madVR Envy Core MK2 will be providing reference-level image processing, which includes patented HDR dynamic tone mapping, full HDMI 2.1 8K input support, AI-powered upscaling, Dynamic Subtitle Overlay, and advanced screen masking automation.
Advertisement
MadVR Envy Core
Moovia: A great home theater demo also needs comfortable seating. With that in mind, Moovia is providing Marbella media sofas for long-lasting audience comfort and style. The sofa is controlled by the new Moovia app, streamlining control and automation for integrators and their clients with a tactile new user interface.
Moovia Marbella Sofa
The Bottom Line
ASCENDO has built its reputation around solving specific installation and performance problems rather than simply adding more conventional speakers to the catalog.The DIRECTOR addressed placement challenges created by LED walls and non-acoustically transparent displays, while its Infrasonic Subwoofers pushed meaningful bass reproduction below 20Hz.
Advertisement. Scroll to continue reading.
For 2026, the Panoramic Surface applies that same philosophy to dispersion, targeting the narrowing radiation patterns and beaming behavior that can compromise surround and height-channel performance. CEDIA Expo attendees will be able to hear the technology in a complete 9.8.4-channel immersive cinema system in Sound Room 10, which is exactly where a claim like this should be evaluated: in a real room, with multiple seats, rather than on a spec sheet.
Who hasn’t dreamt of sitting on a green stool modeled like a thumbstick?
IKEA/Microsoft
It’s becoming increasingly difficult to keep up with what’s going on at Xbox on any given day, but at least you can now attempt to do so from the comfort of your IKEA-branded thumbstick stool, which is part of the new nine-piece YXSTABY collection.
As part of Xbox’s ongoing 25th anniversary celebrations, Microsoft and the Swedish furniture giant teased their upcoming collaboration last week, and IKEA has now unveiled the full collection at Gamescom in Germany. We’d already been treated to a sneak peek at the classic Xbox green D-pad cushion, but the two brands had a lot more to show off.
You can view the full collection here, but it’s a mix of more decorative pieces, like the stainless steel platter also modeled on a D-pad, and less obviously Xbox-y furniture that IKEA says is designed to “solve the small, familiar challenges that can come with playing at home.” This includes a rollable TV stand with a storage compartment at the back and a toolbox for controllers and cables that also doubles as a laptop stand. There’s also a controller display box in two colors and a side table on wheels with sliding doors. It’s all fairly minimalist and, dare I say it, even quite desirable.
Advertisement
IKEA/Microsoft
For my money, though, the real star of the YXSTABY collection has to be the thumbstick stool, which IKEA designer David Wahl said was designed to function as a stool while also feeling like a thumbstick you recognize from your Xbox pad when you sit on it. Wahl says it even “tilts with you while you play,” which admittedly sounds like an accident waiting to happen if you’re someone who gets a bit too into your drifting in Forza Horizon, but it’s definitely fun.
The YXSTABY collection will be available to buy in the US starting September 30. All prices are listed below.
Users have a little more time to migrate from Azure storage to OneDrive
Microsoft is giving customers who are still clinging to its doomed legacy Whiteboard technology a lifeline, and has pushed the deletion date to October 16, 2026.
Advertisement
The migration tooling for “legacy enterprise whiteboards” will be retired on September 25, 2026, and the standalone Microsoft Whiteboard app will be deprecated on November 30, 2026.
To be clear, Microsoft Whiteboard as a concept is not going away – this is more about migration for Azure-based files.
The original dates were August 22 for the migration tooling, September 5 for the permanent deletion, and September 14 for the app deprecation. Therefore, customers have been granted a little more time to make the transition to OneDrive-backed whiteboards.
Microsoft did not respond to a query about why it had moved the milestones. The lateness of the announcement suggests it either ran into technical problems or that enough customers were still on the legacy platform that Redmond uttered the computing equivalent of FINE! Have another month!
Advertisement
New whiteboard files for commercial customers have been in OneDrive rather than Azure since 2022. However, legacy whiteboards could still be stored in Azure and, if not migrated to OneDrive, will be deleted on October 16. Migration happens automatically when a whiteboard is opened in Whiteboard on the web, Teams desktop, Teams web, or using the Whiteboard Windows app (through to September 22, 2026). If migration doesn’t happen, then users have until October 16 before somebody at Microsoft hits the delete key.
However, only owners of Azure Whiteboards can trigger migration. Users on vacation, or who have left the organization, could also present a headache for administrators, who might need to transfer ownership to active users. In Microsoft’s original announcement, it promised a set of PowerShell cmdlets to ease the process.
The Microsoft Whiteboard app became generally available in 2018. It was a useful collaborative tool for Microsoft 365 subscribers (or could be used standalone with a Microsoft account, although these days organizations are the target). It is very much a relic of a past era at Redmond, when touch-based experiences were all the rage. Today, the company would likely prefer users to bark instructions at an AI assistant.
According to Microsoft, “Moving these files to OneDrive improves security, accessibility, revision history, eDiscovery, and access to current and future Whiteboard features.” ®
Instagram and Facebook’s parent company, Meta, has struck a deal with the 29 US states currently suing the tech giant for intentionally designing its social media platforms to be addictive and harmful to children and teens. Reuters first reported the settlement Wednesday, saying the company could pay up to $16.68 billion, which is less than 10% of its 2025 annual revenue ($201 billion).
The settlement allows CEO Mark Zuckerberg and the company to avoid a high-stakes trial, whose consequences could have remade how the tech industry operates. The proposed agreement will need to be approved by the court, but it brings 52 US attorneys general into the deal, not just those who were party to the original lawsuit.
Under the new rules, Meta will enforce default daily usage limits, including blocks during school hours and at nighttime. It will also implement more rigorous age-verification measures, court filings on Wednesday show.
“Today, we have secured a settlement with Meta that will make social media less dangerous for our kids and make a world of difference for children and their families,” California Attorney General Rob Bonta, who led the case, said in a statement Wednesday.
Advertisement
Social media giants like Meta and Google-owned YouTube have been under intense scrutiny in recent years for how well (or poorly) they protect their youngest users. In two separate landmark cases preceding this one, Meta was ordered to pay $375 million to the state of New Mexico after a jury ruled the company enabled child exploitation online. A day later, a Los Angeles court ordered Meta and Google to pay a combined $3 million in damages for similar claims.
In a blog post, Meta calls on TikTok and YouTube to join its efforts. “While this is an important step, the fact is that teens move fluidly between dozens of apps a day. All platforms should empower parents and support teens by putting the same measures in place, because we know that when teens are restricted on one app, they simply move to another,” the company wrote.
Meta did not immediately respond to a request for additional comment.
This is a developing story.
Advertisement
Katelyn Chedraoui
Reporter 2
Katelyn is a reporter with CNET covering artificial intelligence, including chatbots, image and video generators. Her work explores how new AI technology is infiltrating our lives, shaping the content we consume on social media and affecting the people behind the screens. She graduated from the University of North Carolina at Chapel Hill with a degree in media and journalism. You can reach her at kchedraoui@cnet.com.
See full bio
The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities.
Black Lotus Labs, the threat research arm of Lumen Technologies, has been tracking the infrastructure for the past year and discovered the components of the framework used in attacks against U.S. critical infrastructure.
According to the researchers, the provider offers a reusable service consisting of four distinct operational elements:
QScan: a reconnaissance component that identifies and profiles high-value targets, collecting open ports, application banners, operating-system fingerprints, and configuration data
Fast Labyrinth: an encrypted relay network that conceals communications to and from victim organizations
QTRouter: provides a preconfigured physical device that handles access to the proxy infrastructure and the node management system
QTProxy: a management tool that lets users select relays and configure custom routes through Fast Labyrinth
Overview of the quartermaster infrastructure Source: Lumen
The infrastructure was used to profile and steal data from U.S. military and defense organizations, government networks, universities and research institutions, aerospace and bioinformatics organizations, healthcare orgs, financial firms, critical infrastructure and energy companies, and enterprise software vendors.
“Lumen Technologies would like to commend the FBI and DOJ for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure,” reads the report.
Advertisement
“During our investigation, Black Lotus Labs shared threat intelligence to warn agencies across the U.S. Government of emerging risks that could impact our nation’s strategic assets.”
The researchers also note that they have disrupted the infrastructure by null-routing the traffic to known infrastructure points used by the quartermaster operators.
Building an evasive ORB network
Lumen says the “quartermaster” industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators.
ORBs are decentralized networks of compromised infrastructure, such as SOHO routers, IoT devices, VPS servers, and commercial proxy nodes, used for relaying malicious traffic and to obscure its true source.
In the case of the “quartermaster,” instead of building a conventional ORB network from thousands of compromised devices, the platform purchased premium access to selected nodes operated by the Chinese commercial proxy service fastlink.ws.
Fastlink nodes Source: Lumen
These nodes formed Fast Labyrinth, an ORB-style relay network that blended espionage traffic with legitimate consumer proxy traffic and automatically rotated its egress infrastructure.
The researchers highlight the overlap between QScan targets and organizations later contacted through Fast Labyrinth as the strongest piece of evidence connecting reconnaissance to follow-up operations.
QScan information pipeline Source: Lumen
Lumen assesses that the observed bidirectional connections from the proxy network likely represent attempted exploitation, lateral movement, persistent access, or data collection.
Although disrupting this provider is significant, Lumen warns that static blocking alone is unlikely to be effective in this case because the quartermaster’s traffic passes through dynamically rotating commercial proxy services.
Advertisement
Defenders are recommended to follow CISA and NCSC guidance for mitigating China-nexus threats and to keep routers, firewalls, and IoT devices up to date and securely configured.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Even before Trumpism, major papers just didn’t really like it when their writers (journalists or opinion columnists) expressed human opinions on social media. They feel it reflects poorly on the reputation and impartiality of the paper; that columnists and journalists somehow can’t separate their own beliefs from factual reality and should, in effect, display no meaningful personality while using social media.
It’s a very dated and silly idea; long-since made irrelevant by autocracy’s industrialized racism (why would a human journalist not be allowed to express an honest opinion on systemic, racist evil?), and the WaPo’s ownership’s clear goal of destroying the paper’s reputation all by themselves.
Advertisement
In this case it was clear Attiah, who hired Saudi-murdered columnist Jamal Khashoggi in 2017 and was central in shaping the former WaPo’s opinion pages, was fired for the cardinal sin of upsetting thin-skinned Republicans and rich people.
Unfortunately for the latter, Attiah took her complaint to binding arbitration and recently won, forcing WaPo to immediately reinstate her.
BREAKING: After the Washington Post fired me last year for speaking the truth in the wake of the Charlie Kirk killing, I fought back. And I’m happy to announce: I won my case against the Washington Post. They have been ordered to reinstate me immediately. www.nytimes.com/2026/08/24/b…
The arbitrator ruled that WaPo management’s decision wasn’t based on any actual, meaningful offense:
Advertisement
Sarah Miller Espinosa, the arbitrator, said in a written decision Thursday that The Post “did not have good and sufficient cause” to terminate Ms. Attiah and “violated” its labor agreement, according to a copy of the decision shared with The New York Times by Ms. Attiah’s lawyers.
“The Washington Post failed to establish the grievant engaged in gross misconduct,” Ms. Espinosa wrote.
That’s a real bummer for Bezos, who has tried to reshape the Post’s opinion columns so they focus exclusively on “personal liberties and free markets” (again that’s code for coddling Republicans, rich people, and corporations). Amusingly Attiah outlasted Adam O’Neill and Will Lewis, the two WaPo “leaders” who fired her for expressing human opinions about insufferable bigots.
You must be logged in to post a comment Login