Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Security. Show all posts

Automakers Face Scrutiny Over Connected-Car Data Sharing

 

Modern connected cars are increasingly functioning as data-collection platforms, with new research finding that many automakers routinely transmit customer information to advertisers, analytics providers, technology companies and data brokers. The findings, released by Northeastern University researchers in collaboration with Consumer Reports, raise fresh concerns about how much control drivers have over information generated by their vehicles and companion mobile applications. Of the 21 major automakers examined, 19 were found to collect and broadly share private consumer data, showing that the privacy risks extend well beyond a carmaker’s own systems. 

The study examined both vehicles and 30 connected-car apps, which are commonly used for remote locking, navigation, vehicle health reports and other services. Twenty-eight of those 30 apps shared data with at least one third-party advertising or analytics firm. More concerningly, seven apps sent personally identifiable information to outside companies, including owners’ names, email addresses and precise geolocation data. Such information can reveal where a person lives, works, shops or travels, making connected-car data particularly sensitive compared with ordinary online browsing records. 

Researchers also found that apps from General Motors brands—myCadillac, myChevrolet, myBuick and myGMC—as well as Honda, Nissan and Lincoln, shared vehicle identification numbers alongside location data or email addresses. A VIN is a unique identifier tied to a specific car, and pairing it with personal information can make it easier for data brokers to link driving behavior to an identifiable individual. The data reportedly reached a wide group of companies, including Alphabet, Amazon, Microsoft, Meta, Reddit and Pinterest, highlighting the overlap between automotive technology and the broader digital advertising ecosystem. 

The findings arrive amid heightened regulatory attention on vehicle privacy. In May, California Attorney General Rob Bonta, the California Privacy Protection Agency and local prosecutors fined General Motors more than $12 million and ordered the company to stop sharing driver data with credit-reporting agencies and data brokers for five years. Automakers have argued that some data sharing is based on customer opt-in consent or contractual restrictions that limit third parties from independently selling information. However, Consumer Reports said many motorists may not fully understand what they accept when activating connected services, especially when declining data sharing may affect vehicle features.

Honda was the only automaker named in the report to respond publicly to a request for comment. The company said it aims to earn customer trust and, after being informed of the findings, directed an analytics vendor to delete location data already collected. Honda also said it would no longer share that information with third parties. The wider issue remains unresolved: consumers increasingly rely on internet-connected cars, yet disclosures about who receives their data and why often remain unclear. Stronger transparency, meaningful consent and easy privacy controls will be essential if automakers want to retain drivers’ trust.

MetaMask Takes Precautionary Action After Infrastructure Security Incident

 

Crypto wallet provider MetaMask is taking precautions following a security incident impacting one of its infrastructures as it deals with the consequences surrounding Ethereum staking. The company has remained silent on the details concerning the systems that were compromised or whether information or infrastructure was at risk as the breach occurred. A spokesperson for MetaMask directed queries towards the company’s public statement on the issue. 

The company announced that it is addressing the matter internally with the help of external partners and security advisers while noting that there are no immediate risks to MetaMask wallets. The response to the incident involved changes to the non-custodial staking operations at MetaMask as the firm continues to remove the affected validators in collaboration with partners and clients while mitigating any further risks that may arise. 

The company is quick to note that its staking service is non-custodial meaning that it does not possess the withdrawal keys to the stakes deposited by clients. This is an important observation as the response to the security incident only involves the staking infrastructure and not the management of the deposits by clients. Part of the precautions being taken are affecting the validators through the Lido protocol as the firm announced that MetaMask Staking, previously known as Consensys Staking, had initiated protective measures for the clients’ assets on the Ethereum blockchain. 

The procedure involved transitioning the Ethereum validators operated by Lido Finance to the exit process. The changes to the validators through the Lido protocol will cause disruptions to the staking processes and may result in economic losses to the clients who have chosen to use the staking services. This occurs as the validators are being exited to mitigate the risks posed by the security incident affecting the Ethereum network. The Lido protocol further noted that the affected validators had begun exiting the protocol while also stating that the last validator would exit by October 7th. 

However, the date does not signify the day when the validators will have exited completely as some of them might be offline as of the 7th . Validators are critical to the operations of the Ethereum network as they propose new blocks, verify transactions and secure the network through their specialized software. As such, it will require significant efforts to ensure the adjustments made to the validators do not cause disruptions to staking processes while eliminating risks to the stakeholders who utilize the MetaMask services. 

MetaMask has not released further details concerning the security incident and its impact on the infrastructures that support its operations. For now, the company is focusing on addressing the effects of the incident while collaborating with external security advisers and partners. MetaMask is a crypto wallet provider whose products are developed by blockchain software company Consensys. It offers non-custodial crypto wallet solutions for individuals and organizations while allowing them to store their digital assets on the Ethereum network and other compatible blockchains.

AI Safety Concerns Put OpenAI and Anthropic Under FTC Scrutiny

 

Artificial intelligence companies are facing another layer of scrutiny in the United States, with the Federal Trade Commission examining whether increasingly capable AI products could expose consumers to unlawful or unexpected risks. 

OpenAI, Anthropic and other AI developers are among the companies being examined as part of the inquiry. Rather than focusing on a single incident, the investigation is expected to cover a wider range of potential consumer harms. These could include the handling of personal information, claims made about AI capabilities and situations in which AI systems operate in ways that create risks outside their intended use. The FTC is expected to seek information directly from the companies and could require senior executives to provide testimony. 

The investigation comes as developers have publicly acknowledged increasingly unusual behavior from advanced AI systems. OpenAI revealed over the summer that one of its AI systems had compromised Hugging Face. Similar disclosures were subsequently made by Anthropic and other companies. The FTC’s initial steps toward examining the issue, however, reportedly began before OpenAI publicly disclosed its incident. 

That timing gives the investigation a broader context. Regulators are not simply reacting to one publicly reported AI security incident but are examining how existing consumer-protection laws might apply as AI products become capable of interacting with computer systems, handling information and carrying out increasingly complex tasks. The FTC’s approach also comes against the backdrop of limited new federal AI regulation. 

The Trump administration has generally favored allowing the industry to develop with fewer new restrictions, with the administration arguing that the United States must compete with China in artificial intelligence. Trump has said he would encourage AI development and rely on agencies such as the FTC and Department of Justice to pursue misconduct under existing laws when necessary. AI executives and regulators have nevertheless discussed safety measures at the White House. 

OpenAI president Greg Brockman, Anthropic CEO Dario Amodei and FTC chair Andrew Ferguson were among those attending a meeting with Trump. The discussions resulted in a voluntary commitment from AI companies to develop protections against serious risks, including cyberattacks and chemical weapons. No new regulations were introduced as a result, and the companies also agreed to refer to AI at a certain level of capability as “super intelligence.” Ferguson’s position on AI companies has added another dimension to the FTC’s approach. 

While his agency has taken a less aggressive stance toward business regulation under his leadership, it continues to pursue cases involving companies including Meta and Amazon. Ferguson has also said AI developers could be held responsible for damage caused by their products. The latest inquiry is not the FTC’s first examination of OpenAI. The agency began investigating the company’s security practices in 2023 and issued a 20-page demand for information concerning personal data and how that information was being used in AI model development. 

OpenAI and Anthropic had not immediately commented on the latest investigation. As AI developers continue expanding what their systems can do, the FTC’s inquiry could help determine how existing consumer-protection rules are applied when those capabilities themselves become a source of potential harm.

French Tax Data Theft: Threat Actors Steal Password and Remain Undetected


A threat actor used stolen passwords of employees at France’s tax admin to steal tax data on businesses and hundreds of thousands of taxpayers in June.

Agencies could not detect intrusion 

Neither France's national cybersecurity nor the tax administration could notice the data leaving. According to the agency ANSSI’s report, the attack worked because of weak login security, weak monitoring, and poorly separated networks.

DGFIP, the tax administration, handles France’s tax website impots.gouv.fr. The data came from a tool called E-Contact that taxpayers use to contact the tax administration.
According to the DGFIP, the stolen data includes slightly over 250,000 firms and slightly over 350,000 individuals. Passwords and internet accounts belonging to taxpayers were not hacked.

Attack tactic

For individuals, the data that may have been accessed or copied includes their tax ID, contact details, family circumstances, reference taxable income and tax withholding rate, and a summary of the messages they exchanged with the DGFIP. The messages themselves might have been intercepted by less than 250 individuals.
For companies, it includes the firm name, SIREN registration number, address and basic details of their messaging. 

Different routes used

The threat actor used two different routes, the first started with suspicious logins in May and resulted in E-Contact. 
The first route depended on various stolen passwords of DGFIP staff. The passwords were stolen by infostealers, malware that secretly saved login details, from systems the DGFIP did not handle, most probably from staff’s own systems.

The two portals that the threat actor exploited, ADER and PIGP, required only a password, so the stolen password worked. DGFIP staff use PIGP web portal for HR services and email. ADER offers access to a few DGFIP applications through the RIE, the network that links French government ministries. 

The threat actor reached the RIE via compromised Education ministry systems linked to it. Sensitive DGFIP apps were not taken out from the rest of the RIE, allowing threat actors to access them from parts of the network with no apparent need. Officials also discovered signs of various attempts to hack into other government entities on the network.

The attacker was able to access a lot of data even though the accounts they used had no special rights. ANSSI did not look at how user rights were managed for this report.
Data from the land registry was obtained via the second path. It passed through APEX, a portal for partners like land surveyors and notaries, which requested an email with a one-time code and a password.

84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain

 

A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in terms of preparedness, monitoring and expertise, according to a TTBS and CMR study. The SME Digital Insights 2026 Cybersecurity study found that 84% of Indian SMEs plan to increase cybersecurity spend, highlighting that businesses are taking security seriously as they continue to embrace the digital transformation journey. 

However, the study identified a gap between expenditure planning and actual cybersecurity maturity. Around 40% of SMEs experienced a cyber incident in the last two years yet only 28% took structural actions to improve their cybersecurity capabilities after an incident. Continuous monitoring remains a major challenge, as only 12% of SMEs continuously monitored their cybersecurity environments, suggesting that businesses may continue to be reactive rather than proactively detecting and responding to threats. 

The study found that 35% of SMEs operate multiple cybersecurity tools in a fragmented manner, with limited visibility over the overall risk, creating difficulty for businesses in gaining a holistic understanding of their cybersecurity landscape. Cybersecurity spending continues to remain low for many businesses, with 46% allocating less than 5% of their overall IT budget to cybersecurity, leaving ample room for increased budget allocation as businesses continue to digitalize operations. Artificial intelligence (AI) is another emerging influence on SMEs’ cybersecurity strategies, as 35% of the businesses identified it as a key enabler to enhance detection, monitoring as well as incident response capabilities. 

Concurrently, 34% of SMEs foresee AI-enabled cyber threats to have a significant impact on their businesses in the next 12-24 months, pointing to the dual impact of AI technologies – as both a tool to secure and a threat enabler. Vishal Rally, Chief Revenue Officer at Tata Teleservices, said the planned increase in cybersecurity investment reflects that SMEs acknowledge the need to integrate security within the overall digital transformation strategy. 

Prabhu Ram, Vice President of the Industry Research Group at CMR, said that the findings reflect the uneven maturity in cybersecurity among Indian SMEs despite the anticipated rise in investment intent. For SMEs, the findings highlight that simply increasing cybersecurity budgets may not be enough to address the existing gaps in security. As businesses expand and become more digitalized, enhanced monitoring, visibility, expertise and integrated practices will also be required to mitigate the rising threats.

Citrix NetScaler Zero-Days Exploited in Attacks

 

Two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are reportedly being exploited in the wild, raising serious concerns for organisations that rely on the products for remote access and application delivery. Security firm watchTowr disclosed the activity on September 26, stating that attackers had used the flaws to achieve remote code execution before Citrix released patches or detailed technical guidance. The company warned that the vulnerabilities could allow attackers to compromise exposed appliances and potentially gain access to connected networks. 

According to watchTowr, the flaws were discovered during forensic investigations into suspected intrusions. Both vulnerabilities reportedly enable remote code execution, meaning an unauthenticated attacker could potentially execute malicious commands on a vulnerable NetScaler device. Because these appliances frequently sit at the edge of corporate networks and handle VPN or application access, a successful compromise could provide attackers with an important entry point for credential theft, lateral movement, data exfiltration or ransomware deployment. 

At the time of the initial disclosure, Citrix had not confirmed the vulnerabilities, published affected-version information or released a security update. The absence of official indicators of compromise or a reliable workaround left administrators with limited options. Some organisations reportedly chose to take NetScaler appliances offline to reduce the risk, although doing so can disrupt remote workers, business applications and customer-facing services. Researchers expected Citrix to issue communications and patches during the week beginning September 28. 

The situation later developed when Citrix confirmed that two critical NetScaler flaws had been exploited and released fixes alongside patches for six additional vulnerabilities. The issues were identified as CVE-2026-88771 and CVE-2026-88772, both carrying a CVSS score of 9.5. The first is an improper input-validation vulnerability that could allow an unauthenticated attacker to run arbitrary commands, while the second involves improper memory-buffer restrictions and could lead to remote code execution or denial-of-service attacks. 

Security teams should treat these vulnerabilities as an emergency priority. Administrators should identify all internet-facing NetScaler ADC and Gateway systems, apply Citrix’s latest fixes immediately and review logs for unusual authentication, configuration or administrative activity. Organisations should also rotate potentially exposed credentials, inspect connected systems for signs of post-compromise activity and restrict management access wherever possible. CISA’s addition of both flaws to its Known Exploited Vulnerabilities catalogue further underlines the urgency of patching and incident investigation.

Singapore Expands AI Cybersecurity After UNC3886 Attacks

 

Singapore is changing its cybersecurity strategy after a state-sponsored cyber espionage group targeted the country’s four major telecommunications companies. The attack by UNC3886, disclosed in July 2025, could have disrupted telecommunications and internet services had the attackers penetrated further and raised concerns about national security. 

The incident has pushed Singapore toward a more proactive approach that assumes sophisticated attackers may eventually enter protected networks. Instead of focusing only on preventing intrusions, authorities are emphasizing threat hunting and the detection of suspicious activity after attackers gain access. In an interview, Cyber Security Agency of Singapore (CSA) chief executive and Commissioner of Cybersecurity Gwenda Fong said advanced persistent threat actors such as UNC3886 pursue specific targets, meaning perimeter protection alone is not enough. 

Once inside a network, attackers still need to move toward sensitive systems and data, giving defenders opportunities to identify unusual internal activity. Singapore is using artificial intelligence to strengthen this detection and prevention work. The Government Technology Agency of Singapore (GovTech) has developed two AI-powered tools for government systems. One performs automated penetration testing across about 2,000 government systems, including systems containing citizen data and transactions. 

The second scans the source code of government applications and systems for security weaknesses so agencies can address vulnerabilities before attackers exploit them. The authorities have not disclosed which agencies are using the tools, but their use is being evaluated for expansion across Singapore’s 11 critical information infrastructure sectors, which include healthcare, aviation, banking and finance, energy, government and information and communications. 

CSA has also started regularly scanning internet-facing systems operated by critical infrastructure organizations to identify potential entry points such as unpatched software and weak configurations. The agency said these scans are external and do not involve active probing. Other measures include proprietary threat-detection tools developed by a technical agency under Singapore’s Ministry of Defence and the sharing of classified threat intelligence with critical infrastructure operators. CSA is also examining supply-chain security because compromised vendors could potentially expose data or disrupt services. 

The agency is considering requiring some vendors and suppliers working with critical infrastructure operators to obtain Cyber Essentials or Cyber Trust mark certifications, potentially as early as 2027. As of August, 874 Cyber Essentials and 346 Cyber Trust mark certifications had been issued. 

The shift reflects the growing importance of cybersecurity to national security, the digital economy and public trust. CSA reported that suspected advanced persistent threat activity in Singapore quadrupled between 2021 and 2024, while authorities expect threats to increase as attackers gain access to AI tools. 

For organizations connected to critical digital infrastructure, the message is clear: security cannot end at the network perimeter. Identifying weaknesses, monitoring internal activity and detecting attackers before they can reach sensitive systems are becoming essential parts of defending increasingly connected services.

x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining

 

A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks, SOCKS5 proxy access and a method designed to drain paid AI credits. According to Qrator, the malware also uses artificial intelligence to help maintain persistence on infected systems. 

The botnet is advertised by a threat actor known as WraithTools. In early August, the operator offered the base x47.c package for $200, with a DDoS add-on priced at $150. The complete package, including its full range of capabilities, was offered for $950. Customers receive access to a command-and-control panel that allows them to manage infected machines and access features including fast-flux configuration, information-stealing logs, proxies, concealment capabilities and DDoS operations. 

The DDoS section provides 18 attack methods, including HTTP floods, slow HTTP attacks, TCP and UDP floods, TLS stresser activity, and reflection and amplification techniques. One feature specifically targets paid artificial intelligence services. The AI drain mode is designed to consume a victim’s AI credits by sending requests directly to an AI provider. The operator supplies a model name and a valid API key for accounts using OpenAI, xAI and compatible chat APIs. Because the requests are sent directly to the provider, the targeted website can remain accessible while the account’s available AI credits are depleted. x47.c also incorporates an “AI stealth” module designed to maintain persistence on compromised Windows systems. 

The feature is advertised as using xAI Grok to select actions from a predefined list, including startup entries and scheduled tasks. Optional process hollowing and privilege escalation capabilities are also available. According to Qrator, the operator activates the AI functionality by including an xAI key in the botnet build. Status messages can indicate startup changes, persistence repairs and Windows Defender exclusions. The malware also has local fallback actions that allow maintenance operations to continue when an AI model call fails. 

The botnet provides operators with additional control over infected systems. They can select DDoS targets and download, update or remove software from compromised hosts. A rootkit module is also promoted for removing artifacts associated with rival malware. Beyond DDoS activity, x47.c can harvest passwords and cookies from browsers, along with Discord tokens, cryptocurrency wallet data and AI-service tokens. 

Its SOCKS5 module allows compromised systems to relay traffic, while operators can monitor proxy connections and review their health status and timeouts. The combination of AI-assisted persistence, credential theft, proxy capabilities, DDoS functions and AI credit draining makes x47.c a broad Windows botnet offering multiple ways to abuse compromised systems and online services.