Microsoft Links Hotel Wi-Fi Attacks Stealing Microsoft 365 Accounts to Russian Hackers

Microsoft Links Hotel Wi-Fi Attacks Stealing Microsoft 365 Accounts to Russian Hackers

Microsoft has attributed a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard (APT29). The campaign, named CaptiveCrunch, manipulates DNS settings on hotel and conference Wi-Fi equipment to steal Microsoft 365 accounts. Microsoft links this activity to Storm-2945, a sub-cluster of Midnight Blizzard, and has identified two malware families, CornFlake and…

Read More
FaceTime Scammers Impersonate Banks and Support to Steal Money Through Video Calls

FaceTime Scammers Impersonate Banks and Support to Steal Money Through Video Calls

Scammers are increasingly turning to FaceTime video calls to impersonate banks, tech support agents, and government officials in order to steal money and sensitive information from victims, according to security researchers and consumer protection reports. The use of video calls makes these scams more convincing than traditional phone calls or emails because a live video…

Read More
Microsoft July 2026 Patch Tuesday Fixes Record 570 Flaws Including Three Zero-Days

Microsoft July 2026 Patch Tuesday Fixes Record 570 Flaws Including Three Zero-Days

Microsoft has released the July 2026 Patch Tuesday security updates, addressing a record 570 vulnerabilities. This includes two zero-day exploits used in attacks and one zero-day vulnerability that has been publicly disclosed. The update fixes 59 vulnerabilities rated as Critical. These include 48 issues related to remote code execution, nine privileges elevation flaws, one security…

Read More
Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing

Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing

Microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to Windows installations, in a federal complaint filed by US prosecutors against an alleged member of the Scattered Spider hacking group. The ID is generated when Windows is set up with a Microsoft Account, persists through Windows updates, and…

Read More
Google Tests Hand Gesture Verification CAPTCHA That Uses Webcam Biometrics, Already Bypassed With Stock Photos

Google Tests Hand Gesture Verification CAPTCHA That Uses Webcam Biometrics, Already Bypassed With Stock Photos

Google is exploring a new verification method for reCAPTCHA called hand gesture verification (HGV), according to Google Cloud documentation. The system uses access to the user’s webcam to record a video of their hand. It prompts users to wave or perform other gestures at the camera so that Google can analyze the video and extract…

Read More
China’s Z.ai claims it can match Mythos on cybersecurity

China’s Z.ai claims it can match Mythos on cybersecurity

China’s Zhipu AI (Z.ai) released its open-weight GLM-5.2, and some researchers have claimed that it matches Mythos in certain bug-finding and cybersecurity scenarios. While GLM lags behind models from Anthropic and OpenAI in other, more general tasks, it seems that China has dramatically reduced the gap in the capabilities between its models and those of…

Read More
Google to Use IP Addresses for Ad Personalization in UK and EU Starting August 3

Google to Use IP Addresses for Ad Personalization in UK and EU Starting August 3

Google has informed advertisers that starting on or shortly after August 3, 2026, it will begin using IP addresses for ad measurement and personalization in the European Economic Area, the UK, and Switzerland. This change assigns a new purpose to data that Google already collects, transitioning from network routing to device identification for advertising purposes….

Read More
Amazon security research reportedly led to the White House’s Anthropic Fable ban

Amazon security research reportedly led to the White House’s Anthropic Fable ban

According to the Wall Street Journal, the export control directive that led to Anthropic cutting off access to Fable 5 and Mythos 5 was triggered in part by cybersecurity research from Amazon and conversations between CEO Andy Jassy and the White House. According to the report, the paper from Amazon claims that, through a series…

Read More