Archive for June 11, 2025

Operation Secure disrupts global infostealer malware operations

Posted in Commentary with tags on June 11, 2025 by itnerd

An international law enforcement action codenamed “Operation Secure” targeted infostealer malware infrastructure in a massive crackdown across 26 countries, resulting in 32 arrests, data seizures, and server takedowns.

More than 20,000 malicious IP addresses or domains linked to information stealers have been taken down in an INTERPOL-coordinated operation against cybercriminal infrastructure.

During Operation Secure (January – April 2025) law enforcement agencies from 26 countries worked to locate servers, map physical networks and execute targeted takedowns.

Ahead of the operation, INTERPOL cooperated with private-sector partners Group-IB, Kaspersky and Trend Micro to produce Cyber Activity Reports, sharing critical intelligence with cyber teams across Asia. These coordinated efforts resulted in the takedown of 79 per cent of identified suspicious IP addresses.

Participating countries reported the seizure of 41 servers and over 100 GB of data, as well as the arrest of 32 suspects linked to illegal cyber activities.

Ensar Seker, CISO at SOCRadar had this comment:

“Operation Secure marks one of the most impactful international crackdowns on the infostealer ecosystem to date. What stands out is the breadth and coordination of the effort. Spanning 26 countries, seizing infrastructure, and actively notifying over 200,000 victims. This scale demonstrates a global acknowledgment that infostealers are no longer niche threats but form the backbone of modern cybercrime: from initial access brokers to identity theft, fraud, and nation-state reconnaissance.”

“These 32 arrests may seem small compared to the global volume of infections, but they’re strategically vital, targeting the operators and developers, not just low-level distributors. The seizure of 100 GB of stolen data also offers intelligence gold: victim telemetry, malware configuration, and affiliate network structures can now be analyzed to inform threat hunting and attribution efforts.”

“However, it’s important to understand that disruption is not dismantling. Just like with Lumma or RedLine, underground markets are resilient. We should expect forks, rebrands, and rebuilds. The effectiveness of Operation Secure will ultimately hinge on how well this law enforcement data is integrated into public-private threat intelligence sharing, and whether proactive takedowns continue especially in jurisdictions where cybercrime actors have historically operated with little risk.”

“For defenders, the key takeaway is clear: infostealer infections are persistent, silent, and damaging. Credential hygiene, endpoint telemetry, browser artifact scanning, and access management must be prioritized. And from a policy level, this shows the value of collaboration between cybersecurity companies, hosting providers, and global law enforcement. Something the industry must keep supporting if we want to stay ahead of evolving threats.”

Erich Kron, Security Awareness Advocate at KnowBe4 follows with this comment: 

“It’s always welcome news when countries work together to take down cybercrime infrastructure and bad actors. As this is a global problem, this sort of cooperation and coordination between law enforcement organizations and the private sector from around the world is incredibly important if we are going to protect our economies from cybercriminals.”

“The theft of and selling of information is big business for cybercriminal groups, and impacts organizations and individuals alike. From personal information of employees and others, to intellectual property with a significant cost to develop, the market for stolen information has never been greater.”

Takedowns like this one are a good thing. The real trick is ensuring that the threat actors never come back. But given how out of control things are. Any day where the good guys get a win is a good day.

First Zero-Click AI Vulnerability Enables Data Exfiltration From MS365 Copilot

Posted in Commentary with tags on June 11, 2025 by itnerd

Researchers have discovered the first zero-click AI vulnerability dubbed “EchoLeak” that allows attackers to automatically exfiltrate sensitive and proprietary information from M365 Copilot context, without the user’s awareness, or relying on any specific victim behavior. Termed “LLM Scope Violation,” the new exploitation may have additional manifestations in other RAG-based chatbots and AI agents representing a major discovery advancement in how threat actors can attack AI agents – by leveraging internal model mechanics.

More details here:  https://www.aim.security/lp/aim-labs-echoleak-blogpost

Ensar Seker, CISO at SOCRadar had this to say:

“The EchoLeak discovery by Aim Labs exposes a critical shift in cybersecurity risk, highlighting how even well-guarded AI agents like Microsoft 365 Copilot can be weaponized through what Aim Labs correctly terms an “LLM Scope Violation.” This attack, which allows zero-click data exfiltration from an AI assistant’s context simply by sending an email, breaks from traditional breach tactics as it doesn’t require any user action beyond receiving mail. The fact that it bypasses server-side classifiers and markdown redaction rules demonstrates how these vulnerabilities are baked into agent-level logic, not just surface UI flows. 

“This has serious implications for NATO, government, defense, healthcare, and anyone using enterprise AI assistants: attackers no longer need to compromise user credentials or rely on phishing. They can manipulate a trusted AI interface directly. The multi-step EchoLeak chain is both elegant and insidious: it leverages retrieval-augmented generation (RAG), content-security-policy quirks, and markdown behavior to funnel data out silently to attacker-controlled URLs. 

“What stands out especially is that this isn’t limited to Copilot. As Aim Labs warns, any RAG-based agent that processes untrusted inputs alongside internal data is vulnerable to scope violations. This signals a broader architectural flaw across the AI assistant space – one that demands runtime guardrails, stricter input scoping, and inflexible separation between trusted and untrusted content.

“Organizations deploying AI agents must act quickly: disable external email ingestion in Copilot, enforce DLP tags, and apply prompt-level filters that block structured output or suspicious links. They should also treat every AI deployment with the same scrutiny reserved for enterprise applications integrating AI-specific security controls into DevSecOps and threat modeling. Insecure guards at the model layer are now as critical a risk as insecure interfaces at the network layer.

“EchoLeak is a watershed moment. It shows that AI agents can be their own attackers, and secure-by-design principles must evolve just as AI shifts from assistant to agent.”

Well, this isn’t good given the fact that AI is being deployed everywhere for everything. I think it’s a safe bet that we’ll be seeing more of this type of exploit going forward, and the danger of these sorts of exploits will only quickly increase.

Elevate Father’s Day with Big Screen Innovations

Posted in Commentary with tags on June 11, 2025 by itnerd

Father’s Day is the ideal time to go big — big screens and big sound for big entertainment.

Innovation in TVs has been accelerating, producing ultra-large formats never before seen in home entertainment, with several options from which to choose based on the viewing experience desired and  space for comfortable viewing.

Panel TVs 100 inches and larger are relatively new to the marketplace, and are the pinnacle of the visual experience. Driven by Quantum Dot technology and the advanced AI Hi-View Engine PRO Chipset, these mammoth TVs leverage deep learning and innovative technologies to redefine viewing. Technology in the TV includes Dynamic Tone Mapping Pro, Face Detection, AI HDR Enhancement and AI Detail Enhancement, which precisely optimizes the display, creates lifelike skin tones, refines HDR detail and significantly improves image detail for a viewing journey unlike any that has come before it. With a 144Hz refresh rate — which is perfect for movies, sports and gaming — and cinematic audio from Dolby Atmos-powered 2.1.2 multi-channel audio, it brings heart-pounding action, intense gameplay and immersive sports viewing to life.

The other option for a large-format screen is a laser TV, the modern take on a projector. But unlike the old school platforms that required mounting from the ceiling halfway across the room and a complex network of wires snaking to and fro, modern laser projectors sit directly below the screen.

The Ultra-Short Throw technology is not only an easier and more aesthetically pleasing set up, it also produces a sharp, crystal-clear image accompanied by cinematic sound. Beyond the incredible quality of the image produced — smooth motion, razor-sharp contrast, a massive palette of more than a billion colours — the latest line of laser TVs takes the entertainment experience to the next level.

For a big screen on the go, laser projectors can be found in more portable formats. The Hisense C2 Ultra Mini Projector is a compact but powerful machine powered by a TriChroma Laser that exquisitely places more than a billion colours in consistently clear and vibrant images on screens from 65 inches up to 300 inches. Designed for use with Xbox, it boasts 4K resolution and an impressive refresh rate of up to HSR 240, ensuring fluid motion and sharp visuals for an immersive experience. The game mode detects when your gaming console is on and automatically adjusts the projector settings, delivering seamless, lag-free gameplay.

According to sales data from the first quarter of 2025, seven of every 10 laser TVs sold in the world are  Hisense products — upholding a stranglehold Hisense has had on the top spot in the laser TV segment for six years running. Hisense also maintains its dominance in panel TVs with a screen 100-inches or larger with a 56.7 per cent global volume share — extending its No. 1 ranking from 2023 and 2024 into Q1 2025. The sales data from industry research firm Omdia also places Hisense as the global leader in MiniLED TVs, with a 29.3 per cent market share.

There’s A New Ransomware Gang On The Block To Worry About

Posted in Commentary with tags on June 11, 2025 by itnerd

Warlock, a new ransomware gang, today claimed credit for a spate of cyber-attacks that hit several government agencies from around the world. The group claimed responsibility for 16 cyber-attacks in the past month, and about half those hit government agencies and departments. 

In a blog post reporting this news, Paul Bischoff, Consumer Privacy Advocate at Comparitech, wrote:

“Also known as Warlock Dark Army, Warlock is a newer ransomware strain operated by cybercriminals. Once infected, Warlock encrypts data to make it inaccessible, then demands a ransom for the decryption key. It also steals data that it can use to extort targets by threatening to release private information.”

“Warlock could be connected to another ransomware group called Black Basta, which stopped claiming new attacks in January 2025. Warlock took credit for two attacks that Black Basta previously claimed against Arch-Con Corporation and Lactanet.”

“Comparitech researchers have tracked 79 confirmed ransomware attacks on government entities worldwide in 2025 to date. In 2024, we logged 199 such attacks in total. The average ransom demand is just over $2.4 million.”

“Ransomware attacks on government agencies and departments can both steal data and lock down computer systems. The attacker then demands a ransom to delete the stolen data and in exchange for a key to recover infected systems. If the target doesn’t pay, it could take weeks or even months to restore systems, data could be lost forever, and people whose data was stolen are put at greater risk of fraud.”

My stories on ransomware gangs never seem to end. I say that because I just finished writing about these guys, and now there’s a new gang on the block. This illustrates how out of control ransomware is and why urgent action is needed to get things in a better place.

Dermatologists of Birmingham Is The Latest To Be Pwned By Qilin

Posted in Commentary with tags on June 11, 2025 by itnerd

Dermatologists of Birmingham this week confirmed it notified 86,414 people of a March 2025 data breach that compromised the following personal info:

  • Names
  • Social Security numbers
  • Addresses
  • Email addresses
  • Phone numbers
  • Dates of birth
  • Medical diagnoses and treatments
  • Health insurance info

Ransomware gang Qilin claimed responsibility for the attack, saying it stole 141 GB of data from the Alabama skin care practice, however the company has not verified Qilin’s claim.

In a blog post reporting this news, Paul Bischoff, Consumer Privacy Advocate at Comparitech, wrote:

“Qilin is a ransomware gang that began claiming responsibility for attacks on its data leak site in late 2022. Based in Russia, Qilin mainly targets victims through phishing emails to spread its ransomware. It launched in August 2022 and runs a ransomware-as-a-service business in which affiliates pay to use Qilin’s malware to launch attacks and collect ransoms.”

“Qilin took credit for 31 confirmed ransomware attacks in 2025 to date, plus 221 unconfirmed attack claims that haven’t been acknowledged by the targeted organizations. Hospitals and clinics are frequent targets for Qilin and other ransomware gangs. Last week, Next Step Healthcare confirmed it notified more than 12,000 people of a June 2024 data breach claimed by Qilin. The group also recently took credit for confirmed attacks on a hospital in Spain and an eye surgeon in Hungary.”

“Comparitech researchers have logged 27 confirmed ransomware attacks on US healthcare companies in 2025 so far, compromising more than 1.9 million records. Ransomware attacks on US hospitals, clinics, and other care providers can cripple critical systems and endanger the health, privacy, and security of patients. Hospitals must pay a ransom or face extended downtime, data loss, and putting patients and staff at increased risk of fraud. Hospitals and clinics might have to resort to pen and paper, cancel appointments, and divert patients elsewhere until systems are restored.”

Qilin is on a rampage as there’s this example, this example, this example, this example, this example, this example, this example, and this example. That’s a lot and it shows how dangerous this ransomware gang is. So organizations should consider themselves warned and take whatever measures are required to avoid being pwned by them.

DMZ brings startup incubator to Caledon

Posted in Commentary with tags on June 11, 2025 by itnerd

 DMZ, Toronto Metropolitan University’s world-leading startup incubator and startup ecosystem, announces its newest global hub in partnership with the Town of Caledon: the Humber River Centre Incubator Program, powered by DMZ

Built with Caledon’s entrepreneurs in mind, the program is designed to reflect the region’s unique economic landscape and fuel local business growth. Over the course of this multi-year initiative, the program aims to support up to 45 startups, helping founders scale their businesses through DMZ’s world-class entrepreneurial support and network. 

Powered by DMZ, the Humber River Centre Incubator Program offers a 12-week, hands-on curriculum tailored to the specific needs of participating entrepreneurs. The hybrid delivery model blends in-person programming at the state-of-the-art Humber River Centre in downtown Bolton with virtual components. Founders selected for the program will gain access to:

  • Workshops, training sessions and one-on-one mentorship from industry experts in areas like business strategy, sales support, business development, marketing and more.
  • Opportunities to connect and network at industry events with investors, business leaders and government stakeholders.
  • Access to 40+ specialized Experts-in-Residence from DMZ’s network.
  • A free coworking membership at the Humber River Centre.

Local entrepreneurs can get a firsthand look at the support offered through the program by attending peer-to-peer sessions at the Humber River Centre. These interactive workshops, led by DMZ Experts-in-Residence, cover a range of practical topics such as customer discovery, growth, marketing, pitching and business model validation – giving participants a preview of the hands-on guidance available through the incubator.  Learn more about the peer-to-peer sessions and register here.

The Town of Caledon and DMZ are also offering complimentary coaching sessions for local founders to learn more about the program and how it can help grow their business.  Interested entrepreneurs can book a session with DMZ’s Program Lead, Darren Shivraj here.

Applications for the Humber River Centre Incubator Program, powered by DMZ are now open. Caledon entrepreneurs can learn more and apply by visiting dmz.to/Caledon. Applications close July 10, 2025.

Fubo Launches “Cricket Elite” ​Plan​​ – Including Global Matches from Willow and ATN Cricket Plus

Posted in Commentary with tags on June 11, 2025 by itnerd

FuboTV today announced the launch of Cricket Elite in Canada. The comprehensive bundle includes over 500 live cricket matches annually from the world’s top leagues through leading content partners Willow and ATN.

Cricket Elite is now available as a Fubo standalone plan with product features including unlimited DVR and family sharing across three screens. Subscribers can stream extensive coverage of key events, including the ICC Men’s T20 World Cup, ICC Women’s World T20, ICC World Test Championship and The Ashes. Fans can also follow premier leagues such as the Indian Premier League, Pakistan Super League, Major League Cricket, European Cricket League, New Zealand Cricket, Cricket West Indies and SA20.

As cricket continues to gain momentum and fandom globally, Fubo is super-serving Canadian fans by offering unparalleled access to premium international live cricket. 

The Cricket Elite bundle on Fubo includes:

●      Willow TV: Willow is the premier destination for cricket in Canada, boasting the most comprehensive live, streaming, and on-demand cricket coverage available. The official broadcaster of various cricket Boards around the globe, it is the home of the new Major League Cricket.

●      Willow Sport: Willow Sports is the free home for cricket in North America. The best of live and on-demand action from around the world is available, from ICC World Cups to the IPL. Also, other action packed live sports that will have you on the edge of your seat.

●      ATN Cricket Plus: A 24/7 channel that features programming related to the sport of cricket, including LIVE and tape-delayed matches, news and highlight series. The channel also features other sporting events from South Asia, such as Kabbadi, Table Tennis and Field Hockey.

●      ATN NEWS: ATN News has a programming alliance with Republic TV, India’s first independent media venture. The channel is committed to providing original programming and delivering in-depth analysis on news that matters to the viewers across platforms and reaffirms the power and reach of independent media.

●      CBN: The channel primarily focuses on cricket programming, such as live and tape-delayed matches featuring Commonwealth nations, entertainment and Cricket-oriented talk shows.

In Canada, Fubo streams world-class sports including exclusive English Premier League coverage, MLB, the NBA, the NHL and more across over 100 live sports, news and entertainment networks.

Subscribers can stream Fubo programming in Canada anywhere and at any time, from their mobile device, connected TV or web browser. The Fubo app is available on Amazon Fire TV, Android, GoogleTV, Apple TV, Chromecast, Hisense, iOS, LG TV, Roku, Samsung, Vizio and Xbox One.

Hookup app leaked over 4M of private user data

Posted in Commentary with tags on June 11, 2025 by itnerd

Cybernews has uncovered a major data leak tied to Headero — a hookup app popular in queer and alternative dating circles — leaking over 4 million private records, including real-time GPS locations, sexual preferences, and explicit chats.

Over four million private records were found unsecured, including explicit chat logs, group messages, and detailed profile information, such as STD status and sexual preferences.

The most alarming part is that users’ precise GPS locations were also exposed, posing serious risks to personal safety, particularly for individuals in vulnerable communities.

How much data did the Headero app leak?

  • 352,081 user records
  • 3,032,001 chat records
  • 1,096,904 chat room records

What data did the Headero app expose?

  • Names 
  • Emails 
  • Social login IDs 
  • JWT tokens
  • Profile pictures 
  • Device tokens 
  • Exact GPS locations 
  • Sexual preferences
  • STD status

To read the full research report, please click here.

Food delivery platform GonnaOrder exposes customer names, addresses

Posted in Commentary with tags on June 11, 2025 by itnerd

The Cybernews research team has uncovered a data exposure involving GonnaOrder, a Europe-based food delivery and digital ordering platform. The misconfigured system exposed thousands of customers’ personal details, including food orders, home addresses, and contact information.

Most of the affected users are located in the UK, Belgium, Greece, Germany, and the Netherlands. The team believes that the leaky instance has been open since August 2022, due to how it was indexed on an IoT search engine.

“Throughout the whole time the exposed instance was open, malicious actors could have obtained millions of customers’ data, including names, phone numbers, home addresses, as well as order details, which can often contain private info such as access codes to enter the building,” the research team said.

What data was exposed?

  • Customer orders
  • Restaurant and hotels where orders were made
  • Customer phone numbers
  • Email addresses
  • Home addresses
  • Delivery notes
  • Payment methods used

What are the potential risks?

Exposed data can be used for identity theft, or sold on the dark web. Access codes in delivery notes may even enable physical crimes like burglary.

To read the full research report, please click here.

EnGenius Launches Cloud-Lite Switch Series:

Posted in Commentary with tags on June 11, 2025 by itnerd

EnGenius Technologies today announced the launch of its new Cloud-Lite Switch Series, introducing the ECS205L and ECS208L models. Designed to deliver enterprise-grade multi-gigabit performance at a price point that meets the needs of small to medium-sized businesses (SMBs), the new series offers unprecedented access to high-performance networking with flexible cloud management.

Available now, the 5-port ECS205L is priced at $119.99, and the 8-port ECS208L is priced at $169.99, making high-speed multi-gig networking more accessible than ever.

The EnGenius Cloud-Lite Switch Series delivers the advanced speed, stability, and scalability once reserved for large enterprises—now accessible to SMBs and startups looking to elevate their network infrastructure without breaking the bank. These compact switches provide high-speed connectivity and seamless integration into existing environments, all while ensuring a user-friendly setup and management experience.

Key Features and Benefits of the EnGenius Cloud-Lite Switch Series:

  • Multi-Gig Performance for Enhanced Efficiency
    Engineered for the demands of modern business operations, the Cloud-Lite Switch Series supports multi-gig connectivity, delivering high-speed data transfers, lag-free 4K and 8K video streaming, and optimized performance for daily SMB tasks. Whether supporting remote work, video conferencing, or bandwidth-intensive applications, these switches ensure network efficiency and responsiveness.
  • Flexible, Effortless Management
    The ECS205L and ECS208L offer plug-and-play simplicity with no software installation required. Businesses can choose from EnGenius Cloud for streamlined centralized management, Private Cloud for added security, or a standalone web user interface for direct device control—allowing complete flexibility to suit any IT strategy.
  • Auto-Voice VLAN & Auto-Surveillance VLAN for Simplified Setup
    To further streamline deployment, the switches support Auto-Voice VLAN and Auto-Surveillance VLAN. These intelligent features automatically detect and prioritize voice and video traffic, ensuring critical communications and surveillance systems receive the highest quality of service with minimal configuration effort.
  • Affordable, Space-Saving Design
    With an emphasis on cost-efficiency, the Cloud-Lite Switch Series provides premium networking features in a sleek, compact form factor, making it easy to deploy even in limited spaces. The combination of enterprise-grade performance with an affordable price point empowers businesses to scale their networks as needed without incurring high infrastructure costs.
  • Optimized Communication Quality
    Critical business communication is prioritized with features such as Voice VLAN, ensuring voice traffic takes precedence for clear, uninterrupted calls. Additionally, optimized QoS (Quality of Service) maintains smooth and stable communication for all networked devices and applications.

Fast, reliable, and built with SMBs in mind, the EnGenius Cloud-Lite Switch Series provides a future-ready network solution that grows with businesses, ensuring both performance and affordability.

The ECS205L ($119.99) and ECS208L ($169.99) are now available through EnGenius authorized partners and distributors.