Archive for October 16, 2025

Microsoft Logo Used in Fake Browser Lock Tech Support Scam – SOCRadar’s CISO Comments 

Posted in Commentary with tags on October 16, 2025 by itnerd

Researchers have uncovered a new campaign that weaponizes Microsoft’s name and branding to lure users into fraudulent tech support scams. What makes this scam different from others is the use of social engineering, fake system alerts and deceptive UI overlays to execute the scam.

More details can be found here: https://cofense.com/blog/weaponized-trust-microsoft-s-logo-as-a-gateway-to-tech-support-scams

Ensar Seker, CISO at SOCRadar, provided the following comments:

“This scam is an advanced form of client-side browser manipulation that exploits both psychological and technical blind spots. By weaponizing the browser through JavaScript-based UI freezing, attackers simulate a system-level lock, often hijacking the mouse cursor, displaying modal pop-ups, and suppressing keyboard interactions. This creates a false sense of urgency and loss of control, coercing victims into calling a fraudulent support number.

“Technically, this scam evades email security layers by using CAPTCHA challenges and redirect chains to delay payload execution until after user interaction, which frustrates sandbox-based detection. It also mirrors tactics used in scareware and fake AV campaigns from a decade ago, now modernized with brand impersonation and responsive browser exploits.

“For defenders, it reinforces the importance of browser hardening, zero-trust browsing environments, and robust user awareness, especially training users to recognize fake urgency cues and never call unknown support numbers prompted by web pop-ups.”

Threat actors seem to be evolving faster than defenders can keep up. And this campaign illustrates that. That should make it clear that defenders need to evolve just as fast or bad things will happen to those they are protecting.

Centreon Launches a Scalable and Cost-Effective Observability Platform    

Posted in Commentary on October 16, 2025 by itnerd

Centreon today announces the launch of the Centreon Observability Platform, a portfolio of simple, scalable and cost-effective solutions designed to deliver extended visibility and make enterprise-grade observability accessible to all organizations.

Rising Demand for Observability

Modern organizations rely on increasingly complex digital infrastructure, from hybrid cloud environments to distributed applications and customer-facing services. Downtimes, performance degradation, and poor user experience directly impact revenue, brand reputation, and employee satisfaction. 

As Gartner highlights, observability platforms are now vital to ensure availability, resilience, and business continuity, with the market expected to reach $14.2 billion by 2028, growing at 11.1% CAGR. 

In this context, Centreon extends its leadership in IT infrastructure monitoring to deliver extended visibility, helping organizations keep digital systems always-on and high-performing. 

The Centreon Observability Platform

The Centreon Observability Platform combines IT infrastructure monitoring, log management, and digital experience monitoring in a simple, scalable, and cost-effective solution. 

Built on open-source standards and designed for flexibility, it empowers IT teams to detect incidents faster, resolve issues smarter, and operate with greater efficiency. Its modular design allows organizations to deploy each capability independently or as an integrated observability stack, ensuring maximum adaptability and optimized total cost of ownership.

Centreon Infra Monitoring

Since 2005, Centreon Infra Monitoring provides a single platform to monitor the entire hybrid IT stack, from cloud-native and containerized environments to legacy systems and OT/IoT infrastructures. With auto-discovery, 700 built-in connectors, and powerful visualization, Centreon Infra Monitoring empowers IT Ops and NOC teams to gain complete visibility across distributed infrastructures and detect issues faster. By reducing MTTR, ensuring SLA compliance—while integrating seamlessly with ITSM and automation tools and aligning IT performance with business outcomes, Centreon Infra Monitoring eradicates downtime and maximizes productivity. 

Centreon Infra Monitoring is available immediately as open source download, or commercial self-hosted or full SaaS offering. Visit Centreon Infra Monitoring overview, to learn more. 

Centreon Digital Experience Monitoring

Centreon Digital Experience Monitoring (DEM) helps e-commerce, digital businesses, and public organizations maximize user satisfaction, customer conversion rates and sustainability goals. By combining real-user monitoring (RUM), synthetic testing (STM), and financial impact insights, Centreon DEM provides a shared view across business, marketing, and IT teams of how performance drives both revenue and ESG outcomes. This ensures faster detection and resolution of issues, measurable ROI from optimization initiatives, and a direct link between digital performance and corporate sustainability strategies. 

Centreon DEM is available immediately for commercial purchase. To learn more visit Centreon DEM Overview.

Centreon Log Management

Centreon Log Management is a next-generation solution designed for simplicity, scalability, and compliance, accessible to every IT Operations team. Designed for simplicity, scalability, and speed, it combines OpenTelemetry standard with data enrichment to cut through log noise and surface what really matters. From real-time alerting to root cause analysis, every feature is built to reduce complexity and accelerate decision-making. Delivered as a sovereign, cloud-native platform, Centreon Log Management helps IT teams stay compliant, proactive, and always in control without the complexity, while managing cost effectively. 

Centreon Log Management is currently on Beta Release. Visit Centreon Log Management Overview, to learn more.

Over 850 New Phishing Sites Target US Taxpayers

Posted in Commentary on October 16, 2025 by itnerd

Ahead of the October 15th tax deadline extension, Netcraft researchers discovered at least 850 newly registered domain names in September and October with phishing links that use tax refunds as a lure. 

Fast Facts:  

  • Most of the websites are engineered to display in mobile browsers, meaning visitors typically arrive at the pages from smishing attacks targeting the messaging apps in their mobile phones.
  • Visitors to any of the sites are presented with pages that direct the target to enter personal financial information into a form, including the target’s name, home address, telephone number and email address, as well as payment card details. 
  • The attackers employ a ruse in which the explanation for the request for information is that it is needed to process a refund, or reimbursement, of taxes ostensibly overpaid by the target. 

Netcraft has a blog on this here: https://www.netcraft.com/blog/taxpayers-drivers-targeted-in-refund-and-road-toll-smishing-scams

More Dreamforce News: AWS, Google + Stripe Partnerships

Posted in Commentary with tags on October 16, 2025 by itnerd

Here’s a new update from Dreamforce 2025 —where Salesforce unveiled Agentforce 360, the world’s first platform designed to connect humans and AI agents in one trusted system.

The core message from Dreamforce is that AI’s real potential lies in deeply interwoven LLMs and enterprise software. Salesforce announced a series of partnerships with OpenAIAnthropic and more, putting it at the heart of delivering secure, interoperable AI at scale and strengthening the backbone of the $6T agent economy.

Noteworthy highlights from Dreamforce below (all fresh updates since our email on Tuesday):

  • Expanded Google Partnership – Salesforce and Google announced an expansion of their strategic partnership, introducing a new wave of AI innovations designed to transform the enterprise. This collaboration brings Google’s cutting-edge Gemini models to the new Agentforce 360 Platform. The expanded partnership places employee productivity at the forefront, integrating Agentforce 360 with Google Workspace for sales and IT service and expanding the Salesforce Gemini integration, already available in Gmail, to more Google Workspace tools.
  • Stripe Partnership – Salesforce announced a collaboration with Stripe and OpenAI to build an Instant Checkout integration, guided by the Agentic Commerce Protocol (ACP), allowing thousands of merchants using Agentforce Commerce to harness the power of conversational AI for a faster path to purchase and create seamless, intelligent shopping experiences that unlock new avenues of growth.
  • Salesforce and AWS announced how they are accelerating AI transformation for Agentic Enterprises across four core pillars — unified data, secure and interoperable AI agents, modernized contact centers, and streamlined customer procurement of AI solutions through AWS Marketplace.  This makes it easier, safer, and faster for customers like Toyota Motor North America and others, to harness powerful technologies without compromising security or trust.

OVHcloud launches next-generation of AI-powered cooling that balances performance and environmental responsibility in its datacenters

Posted in Commentary with tags on October 16, 2025 by itnerd

 OVHcloud today unveils a new cooling architecture for its datacenters. The OVHcloud Smart Datacenter combines new industrial designs with AI features, reducing both power and water consumption and enabling datacenters to intelligently react to their surrounding environments. Through this new technology, OVHcloud is able to reduce water consumption by up to 30% and cooling electricity consumption by up to 50%.

Cooling infrastructure electrical consumption reduced by 50%

In development for the past two years, the fifth generation of the OVHcloud server rack has been redesigned to host a new generation of servers and supercharge the Group commitment to a sustainable Cloud. The most significant change is the server layout where clusters of servers are connected in serial when it comes to their cooling, with servers for each cluster being still organized in parallel thus facilitating maintenance. This new design streamlines component layouts including the location of the inrack CDU and helps reduce power consumption at the rack level.

Smart and autonomous, the rack behaves in a “pull” hydraulic configuration so that each server has the right water flow and pressure for its cooling needs. Hardware components such as CPU and GPU are cooled through direct-to-chip waterblocks designed by OVHcloud, dissipating heat through a closed looped water circuit that extends to a single cooling loop across the whole datacenter.

The Cooling Module (also called CDU) is now approximately 50% more compact and is located outside the rack. It can cool down several rows of racks and features more than 30 sensors. These sensors monitor elements from the racks including pressure, speed and water temperature and can adjust cooling settings in real time. The sensors enable the rack to be ‘aware’ of its immediate surroundings and datacenter temperatures and the smart cooling module can automatically adjust to server workloads. This optimization greatly extends the lifespan of the equipment and helps to optimize infrastructure power consumption.

The Smart Dry Cooler, located on the outside, is the last cooling component of the closed water loop. It now takes up half the space and has half the number of fans as the previous generation of equipment. This helps reduce cooling power consumption by up to 50% while also reducing ambient noise level.

Reduced water consumption by up to 30% through AI

By constantly analyzing its surroundings and the behavior of key components, new OVHcloud Smart Racks not only regulate themselves but also collect operational data. Data coming from the racks, cooling modules and Dry Coolers are fed into a datalake so that complex algorithms can determine predictive behaviors, contributing to optimized maintenance. The system can also be connected to a local weather station to enrich the datalake. The new models can predict and inject the exact volume of water that is needed by the adiabatic cooling pads of the Dry Cooler to allow for outside heat exchange.

The new dry cooler design accounts for a 30% reduction of water consumption, which has the potential to significantly improve OVHcloud’s already-compelling WUE ratio. Unlike traditional adiabatic systems, the OVHcloud cooling pad does not feature a recirculation loop: complex hydraulic units such as pumps, tanks and level sensors have been eliminated, reducing infrastructure complexity and simplifying maintenance.

Predictive and adaptative AI for the datacenter and the environment

The OVHcloud Smart Racks’ predictive AI can now anticipate and react to operational dimensions at the infrastructure level including the pump speed (and thus the water flow), the speed of the fans and the opening of valves to optimize configuration rapidly.

Rack performances can also be adjusted based on external constraints such as noise limits, water scarcity or power cost. The algorithm can choose to consume more power to favor water preservation or adjust sound levels to adapt to urban environments.

Spearheading a sustainable Cloud for more than 25 years, OVHcloud leverages a vertically integrated industrial model that contributes to responsible digital technology. At the heart of the Group’s many innovations are the research and development department which now has a hundred cooling patents. OVHcloud R&D has shaped water cooling at scale since 2003 so that the Group datacenters benefit from PUE and WUE indices among the best in the industry.

These new developments follow the Group’s commitments to the coalition for sustainable AI in February 2025. The new infrastructure deployed by OVHcloud in its data centers demonstrate the use of artificial intelligence firmly committed to furthering sustainability across the globe.

Availability

New OVHcloud Smart Racks are currently being deployed at the Roubaix data center in a room filled with nearly 60 racks and 2,000 servers accompanied by its new cooling system. The entire system is expected to be rolled out across the Group’s data centers.

HiSense Announces The QD5N 98-inch QLED 4K Google TV

Posted in Commentary with tags on October 16, 2025 by itnerd

Driven by Quantum Dot technology that produces more than a billion vivid colour combinations, the all-new Hisense QD5N 98-inch QLED 4K Google TV pairs a life-like picture with smooth motion, cinematic sound and smart features.

As the latest addition to Hisense’s industry-leading ultra-big screen family, the QD5N delivers an immersive television experience, whether settling in for a movie night, watching your favourite sports or seeking adventure in video games.

The beauty of the QD5N starts with the quality of the picture. The QLED Quantum Dot wide colour gamut offers a wide spectrum of true-to-life colours, which is enhanced by a 4K AI Upscaler to restore fine details and reduce image noise and a Total HDR Solution (which includes Dolby Vision, HDR10, HDR10+ and HLG) to unlock contrast, highlight detail and provide depth. 

These features come together in an innovative and powerful television that is adaptable to the habits of any viewer or gamer.

  • For the Movie Buff — Filmmaker Mode feature ensures a movie is seen the way the director intended. It automatically restores original aspect ratio, colour and frame rate for an authentic experience.
  • For the Sports Fan — AI Sports Mode optimizes sports content, ensuring smooth motion and vibrant colours for an immersive viewing experience. Enhanced surround sound and commentator audio further elevate the enjoyment of sports programming.
  • For the Avid Gamer — The Game Mode PRO feature on the QD5N offers a 144Hz refresh rate, Low Latency MEMC, VRR (48-44Hz), AMD FreeSync™ Premium, Auto Low Latency Mode and Hisense’s proprietary Game Bar for an ultra-responsive, super smooth and crystal clear gaming performance — there is virtually no screen tearing or output lag.

No matter the mode, sound is critically important to overall enjoyment of watching movies, shows, sports or playing video games. Dolby Atmos Sound in the QD5N elevates the auditory experience with award-winning enhancements that unveil what you’ve been missing. Take your movie and gaming escapades to new heights with a 2.1 audio channel featuring a subwoofer, enhanced by Dolby Atmos for precise three-dimensional audio placement that breaks free from conventional channels.

The QD5N also features Google TV with access to shows and movies across more than 10,000 apps, hands-free voice control and built-in Bluetooth that supports wireless connection to headphones so you can enjoy your shows and games the way you want to without disturbing others in the home (it also supports wireless connection of other devices, like soundbars, speakers and keyboards).

The QD5N is now available in Canada at authorized retailers.

For more information, please visit hisense-canada.com.

Arelion launches built-in SecureConnect DDoS mitigation solutions for enterprise and wholesale customers amid rising AI threats

Posted in Commentary with tags on October 16, 2025 by itnerd

 Arelion today announced the release of its SecureConnect Dedicated Internet Access (DIA) and SecureConnect Transit solutions, providing automated DDoS mitigation to enterprise and wholesale customers. These products are bundled into Arelion’ global connectivity services, including IP Transit and DIA, making them simple add-ons for any IP or DIA customer. SecureConnect strengthens frontline security as AI-enabled network attacks increasingly target automotive, manufacturing, financial services and other critical industries, and the suppliers to those industries.

SecureConnect automatically detects common DDoS attack types, especially volumetric threats, then uses the Flowspec protocol to stop attacks at the network edge. This functionality provides Arelion’s customers with more granular DDoS mitigation than brute-force defenses, such as blackholing, without adding implementation complexity. SecureConnect can also improve companies’ chances of meeting International Organization for Standardization (ISO) certification requirements without major investment. With edge-based Flowspec defenses in SecureConnect and global scrubbing centers across Europe, the Americas and Asia strengthening its full DDoS mitigation service, Arelion protects customers against today’s increasingly weaponized internet, giving them greater confidence in their global connectivity evolution.

SecureConnect addresses rising risks across global networks, helping enterprises block AI-enabled threats that attempt to overwhelm defenses with smaller, higher-frequency attacks. Arelion’s network data shows that the average volumetric attack size increased by 97 percent from 2023 to 2024, reflecting attackers’ ability to leverage greater available capacities year-on-year. Another report shows that over 50 percent of automotive and manufacturing leaders see cybersecurity as their top network challenge, recognizing that AI-enabled threats facilitate an endless cycle of attack and defense.

For further information, visit the SecureConnect product page.

Government Ransomware Roundup: Q1-Q3 2025 stats on attacks, ransoms, and data breaches

Posted in Commentary with tags on October 16, 2025 by itnerd

This morning, Comparitech researchers published an in-depth look at the impact of government ransomware attacks globally for the period of Q1-Q3 2025. 

According to the study, during the first nine months of this year, there was a total of 276 attacks on government organizations, which was a 41 percent increase from the same period in 2024 (196).

This study dives into all things government ransomware attacks — including the average ransomware demand across these attacks, which ransomware gangs were the most prolific in this sector, which countries were most impacted, as well as which attacks were the largest in this period. 

Key Finding Include:

  • 276 attacks in total
  • 147 confirmed attacks
  • 129 unconfirmed attacks
  • 443,522 records are known to have been breached in the confirmed attacks
  • Average ransom demand across all attacks = $1.95 million
  • The US has seen an 8% increase in attacks (when compared to the same period of 2024)
  • The ransomware strains that claimed the most attacks against government agencies were Qilin (31), Babuk (26), INC (25), SafePay (13), Funksec (12), RansomHub (12), and Medusa (10)
  • Qilin took credit for the most confirmed attacks (19), followed by INC (12), RansomHub (8), and SafePay (6), and Medusa (6)

For full details, the study can be read here.

Nikon Expands DX Lens Lineup with Two New NIKKOR Lenses: The NIKKOR Z DX 16-50mm F/2.8 VR and the NIKKOR Z DX MC 35mm F/1.7

Posted in Commentary with tags on October 16, 2025 by itnerd

Today, Nikon Canada Inc. announced the release of two new APS-C/DX-format NIKKOR Z lenses, the NIKKOR Z DX 16-50mm f/2.8 VR standard zoom lens with a constant f/2.8 aperture, and the NIKKOR Z DX MC 35mm f/1.7 standard micro lens. Whether shooting portraits that pop, low-light street snaps, or extreme close-ups, both lenses grant immense versatility and extraordinary creative possibilities for Nikon DX-format mirrorless camera users.

A Brighter View: The NIKKOR Z DX 16-50mm f/2.8 VR

The new NIKKOR Z DX 16-50mm f/2.8 VR is a standard DX-format zoom lens that covers a focal length range that is equivalent to wide-angle to medium telephoto, with the benefit of a fast, constant maximum aperture of f/2.8. This focal range is similar to the popular 24-75mm full frame /FX-format equivalent, making it ideal for subjects of all kinds, including wide landscapes, intimate interiors and flattering portraits. With its large f/2.8 aperture, the lens excels in low light capture by allowing more light in and enabling creative shallow depth of field for emotive portraits with blurred backgrounds.

This lens is an excellent entry point to discovering the impressive optical performance of NIKKOR Z lenses. It delivers the large, natural bokeh characteristics of an f/2.8 maximum aperture, as well as high-resolution rendering of details when stopping down. The built-in lens-shift vibration reduction (VR) mechanism (5.0-stop compensation) reduces the effects of camera shake, even when slower shutter speeds are used in low-light conditions. For video and content creators, the lens also uses a stepping motor (STM) for exceptionally quiet autofocus and features an optical design that minimizes focus breathing.

Features of the NIKKOR Z DX 16-50mm f/2.8 VR Lens

  • The fast constant maximum aperture of f/2.8 throughout the zoom range allows for large, natural bokeh and reduces the effects of camera shake when shooting in low-light conditions.
  • Coverage for the 16mm to 50mm wide-angle to mid-range of focal lengths supports a wide variety of scenes and subjects.
  • A minimum focus distance of 5.9 in (0.15 m) at the wide-angle end and 9.8 in (0.25 m) at the long end allows users to get close to their subjects for dynamic shots.
  • Equipped with a lens-shift vibration reduction (VR) mechanism with camera-shake compensation equivalent to a 5.0-stop (at the centre) increase in shutter speed.
  • Portable and lightweight, with a total length of approximately 3.4 in (8.8 cm) and weight of approximately 11.6 oz (330 g) enables easy hand-held shooting.
  • Optimized for video recording with a design that suppresses focus breathing and incorporates a STM for quiet autofocusing.
  • Customizable Control Ring allows for direct control over focus, aperture, exposure compensation or ISO sensitivity.
  • One ED glass and two aspherical lens elements effectively minimize various lens aberrations.
  • Nine-blade aperture produces circular, natural bokeh.
  • When recording video using the Z50II, Hi-Res Zoom expands the zoom range to the equivalent of 16-100mm (6.25× zoom) while still maintaining a constant maximum aperture of f/2.8 with no loss in resolution.
  • Designed with consideration of dust and drip resistance.

Make the Everyday Extraordinary: NIKKOR Z DX MC 35mm f/1.7

The NIKKOR Z DX MC 35mm f/1.7 is a fast, lightweight standard micro lens. It pulls double duty as a capable lens for macro photography, as well as an everyday fast prime lens. It is the first APS-C-size/DX-format NIKKOR Z lens to achieve a maximum reproduction ratio equivalent to life-size, giving users the ability to get closer than ever to reveal intricate details. The very short minimum focus distance of 6.2 in (0.16 m) lets users explore the hidden world that exists in the ordinary. Familiar things like pets, flowers, insects, food, or textiles are all rendered in beautiful, sharp detail like never before.

With a fast f/1.7 aperture and a natural 35mm focal length similar to the field of view of the human eye, the lens also excels as a fast, go-anywhere companion prime lens. From tabletop photos to portraits, or snapshots to low-light cityscapes, this lens gives users the ability to shoot in minimal light and blur the background to draw attention to the subject.

Features of the NIKKOR Z DX MC 35mm f/1.7 Lens

  • A maximum reproduction ratio of 0.67×, which is life-size equivalent in FX/35mm [135] format, enables the capture of small subjects at a larger size.
  • The fast f/1.7 maximum aperture allows users to make the most of large bokeh and minimize noise in low-light conditions.
  • Users can get extremely close to their subjects with an approximately 2.8 in (7 cm) working distance from the front of the lens, and a minimum focusing distance of only 6.2 in (0.16 m) to reveal stunning up-close details.
  • Adoption of an aspherical ED glass element effectively minimizes chromatic aberration.
  • An internal focusing (IF) system eliminates any change in the total length of the lens.
  • Adoption of a STM realizes quiet autofocusing.
  • The customizable control ring allows for direct control over focus, aperture, exposure compensation or ISO sensitivity.
  • Designed with consideration of dust- and drip-resistance.

Price and Availability

The new Nikon NIKKOR Z DX 16-50mm f/2.8 VR Lens will be available in late October 2025 for a manufacturer’s suggested retail price (MSRP) of $949.95. The new Nikon NIKKOR Z DX MC 35mm f/1.7 Lens will be available in late October 2025 for an MSRP of $539.95.

For more information about the latest Nikon products, including the vast collection of NIKKOR Z lenses and the entire line of Z series cameras, please visit www.nikon.ca.

Arcitecta Joined by Leading Research Institutions and Technology Innovators at the Inaugural DATAKAMER 2025 Event

Posted in Commentary with tags on October 16, 2025 by itnerd

Arcitecta has recently joined leaders from prestigious research institutions along with technology vendors Spectra Logic, Wasabi, Cerabyte and IQM for DATAKAMER 2025. The inaugural DATAKAMER event was a collaborative setting where participants came together to chart a sustainable, AI-ready path for managing the world’s most important data. The Dana-Farber Cancer Institute hosted the event at its headquarters in Boston, Massachusetts.

DATAKAMER 2025 was a one-day, invite-only gathering of technologists, researchers, archivists, and system builders exploring the data systems and architectures fostering discovery and the growing challenges and critical needs in managing research data at scale. Research institutions are grappling with the duplication of files across labs, inconsistencies in metadata practices, budget pressure resulting from the exponential growth of data, and much more. Having a sustainable infrastructure, from power to cooling and media lifespans, is not just an IT concern; it’s a scientific necessity.

An event highlight was the Research Data Management roundtable, which compared real-world practices for balancing researcher agility with institutional discipline. It focused on how automating governance, integrating compliance checks early and adopting metadata-driven platforms could support researchers and minimize manual overhead.

DATAKAMER 2025 takeaways include:

  • Research institutions are curating datasets with standardized metadata, investing in platforms that make data discoverable and reusable, and designing governance to ensure reproducibility.
  • Quantum computing is already being implemented in pilot workloads to lower total costs by reducing workload size, time and energy consumption. Mainstream adoption is expected to be gradual but is anticipated to expand within this decade.
  • Long-lived media, such as ceramics, and automation of tape systems, as well as cloud models that eliminate egress penalties, show promise for reducing migration cycles by dramatically extending media lifespans.
  • New generations of LTO tape remain the most cost-effective long-term storage option, with automation making it a practical and sustainable solution.
  • Moving away from egress fees and unpredictable billing is critical. Predictable cloud pricing models are helping institutions plan more effectively.

The DATAKAMER name riffs on the Enlightenment kunstkammer, the cabinet of wonders where art, science, and invention collided. DATAKAMER follows that tradition: a living collection of ideas and technologies redefining how data is built, stored, shared and reimagined.