Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Security. Show all posts

39 Child Tracking Brands Linked to One Chinese Server, Exposing 45 Security Vulnerabilities

 

GPS trackers for children may put the tracked individuals and the people tracking them in danger, according to an investigation presented at the Black Hat security conference. Vangelis Stykas, CTO of Kumio, and Felipe Solferini, principal AI security engineer, discovered that 39 different consumer brands of parental monitoring devices share the same server in China where the data stored on them are processed. 

The researchers named the producers of the technologies, which the mentioned companies used in their devices, SeTracker, SinoTrack and TKStar. They found 45 different vulnerabilities that could allow unauthorized access to children’s smart devices enabling eavesdropping, video surveillance, and total remote control of the system where valuable information is stored. The researchers stated that to perform all these actions, a hacker would need only a free account on any of these platforms. 

The scientists also found that parental monitoring devices of different brands did not have the necessary authorization restrictions, which allowed accessing their systems freely. These devices could collect and store much more personal information than monitoring their location. Some of them have the functionality to record the screen, as well as control the camera and microphone. Thus, the location of the tracked device, photographs and video, the child’s screen, the applications and websites he visits, and his personal information can be known to unauthorized people. 

At the beginning of the demonstration, the researchers showed how they managed to run a script on a children’s smartwatch, which, among other things, dialed a phone number and transmitted an audio signal without any notification on the displayed screen that the call had begun. The scientists emphasized that the experiment was carried out ethically, and they used devices provided to them for the investigation. Stykas and Solferini also discovered that attacks on the system could have been made two years before the investigation began. 

This indicates that, in principle, someone could have been able to track the child’s location and personal data without his knowledge. The researchers contacted the companies more than 30 times, but received no response. One unknown dealer, however, responded to the scientists, noting that he was helping them investigate and would forward the information to the manufacturer. Researchers have concluded that parental monitoring devices pose a serious danger to privacy and safety by possessing many vulnerabilities. 

The investigation demonstrated that the same server is used for different brands, and the lack of protection allows hackers to gain full control of the system and track all the child’s activities. The report also suggests giving up these devices, and for those parents who want to control their children’s devices, the scientists recommended using the built-in tools of the giants: Apple Screen Time, Google Family Link, and Microsoft Family Safety.

Enterprise AI Coding Adoption Fuels Open-Source Security Debt


As artificial intelligence coding tools are rapidly adopted, development teams are able to develop software more quickly, however, cybersecurity teams are also becoming increasingly under pressure due to the increasing volume of AI-generated code. Open-source dependencies have become increasingly common, and their rapid introduction can result in increased vulnerabilities for an organization and additional remediation workloads. This is a key concern. 

A study involving 300 security and engineering leaders in technology, financial services, healthcare, manufacturing, and government sectors revealed the growing challenges associated with managing this risk. Organizations may face remediation debt if dependencies accumulate faster than security teams can assess and resolve them, which could adversely affect security operations, compliance, productivity, and overall business resilience. 

AI coding systems are expected to become increasingly autonomous as time goes on, resulting in software and dependencies being introduced into enterprise environments at a pace that existing security processes may not be able to keep up with. Prioritization is also becoming increasingly important in light of the growing number of vulnerabilities. If every CVE is treated equally, security resources will be consumed rapidly without addressing the weaknesses that are most significant. 

There are several factors that can be considered in determining which issues require immediate action, including whether the vulnerability is reachable, whether the flaw can be exploited, and which systems or data will be impacted. Security controls are also becoming more involved in software development earlier. Testing static applications for security and analysis of software composition can be incorporated into development environments and continuous integration/continuous delivery pipelines to identify vulnerable dependencies and insecure code before the release process progresses further. 

By following this approach, security teams are less likely to discover large volumes of unresolved issues when development has been completed. AI-assisted development is becoming increasingly reliant upon dependency visibility. 

Software bills of materials can provide a comprehensive inventory of components used across applications, while controlled package sources and dependency policies can prevent libraries with known vulnerabilities from entering the development environment. It is also necessary to clearly define who will be responsible for clearing this backlog. 

Creating remediation deadlines based on risk level and assigning vulnerabilities to development teams responsible for the affected code can assist in making the process more measurable. Creating and verifying tickets as well as completing fixes automatically can also contribute to preventing vulnerabilities from remaining unresolved after they have been identified. The security backlog itself is not the only challenge that AI-assisted development can present when engineers approve code generated without understanding the design or underlying assumptions. 

In the event that the generated code becomes part of critical application logic, such gaps in understanding can make it more difficult to make later changes and troubleshoot. Increasing volumes of artificial intelligence-assisted development are putting additional pressure on existing vulnerability management methods. 

Generated code may bring in open-source libraries and transitive dependencies that may not be examined as thoroughly as manually selected components. These dependencies can result in a steady buildup of vulnerabilities that require assessment and remediation, which may cause security teams to face a steadily increasing backlog. 

Counting CVEs alone cannot provide a reliable indication of actual risk. There may be more urgent urgency for issues with limited exposure when they affect application components, are exposed to untrusted input, or are associated with active exploitation. The business impact of an issue also plays a role in determining which findings should be addressed first, as well as which findings should be addressed first. 

Security validation is therefore becoming increasingly integrated into the development process. Identifying insecure code and vulnerable dependencies before they reach production can be accomplished by integrating static application security testing and software composition analysis into development workflows and Continuous Integration/Continuous Delivery pipelines. The implementation of this approach can reduce the amount of remediation work that must be done by security teams following deployment. 

Greater visibility into software components is also of importance. A software bill of materials can provide information about the open-source packages that are used across various applications, while controls around approved package sources can help prevent known vulnerable or unsuitable dependencies from entering development environments. Additionally, it is necessary to clearly define ownership of the remediation process itself. 

By assigning vulnerabilities to teams responsible for the affected code and establishing a risk-based remediation timeline, and verifying the fixes, organizations can prevent unresolved findings from building up as AI-driven development continues.

In order to ensure successful software development, organizations will need stronger visibility, risk-based vulnerability prioritization, and security controls throughout the development process. A strong focus on dependency management and remediation work can assist in preventing the growth of security debt from becoming a larger risk for the software supply chain.

Why Andy Rubin’s Essential Phone Failed Despite Fixing Android’s Biggest Problems

 

Andy Rubin spent ten years creating Android before launching Essential Products, which was based on the idea that Android phones had too many compromises, such as bloatware, software skins, slow updates, and accessories that became obsolete when new hardware was released. Essential launched the PH-1 in August 2017, which had near-stock Android, premium materials, fast updates, and a display that extended to the edges. 

Rubin had co-founded Android Inc. with Rich Miner, Nick Sears, and Chris White in 2003, and Google bought the company in 2005 for $50 million. Rubin continued to lead Android’s development for the next eight years. The PH-1 was meant to overcome some of the shortcomings of the open-source platform. It had Android 7.1.1 and was expected to receive two major Android upgrades and three years of monthly security updates. 

Essential delivered on Android 9 and Android 10, the same day as Google’s Pixel phones. The hardware was also supposed to overcome Android’s challenges. The phone had a titanium frame and a ceramic back, and it was among the first smartphones to have a notch. It had magnetic pins on the back, which were supposed to allow accessories to snap onto the phone instead of using a USB-C port. Essential announced a 360 camera and an audio adapter, but the ecosystem was never realized.

The launch of the PH-1 did not go well for Essential. The company announced that the phone would be available for purchase within 30 days, but the first units were not shipped until August 25 th , nearly two months after launch. The camera was also heavily criticized, and the $699 price was permanently reduced to $499 only two months after its launch. The only US carrier that sold the Essential PH-1 was Sprint. Essential’s sales were also underwhelming despite the star power of Andy Rubin.

A $300 million funding round in 2017 valued Essential at around $1.2 billion, but Bloomberg revealed that Essential had only sold 150,000 phones by May 2018. In October 2018, The New York Times revealed that Google had investigated a sexual harassment complaint against Rubin and found the allegations credible. Google approved a $90 million exit package for Rubin, but he denied the allegations. 

The report received a negative reaction from many Google employees, and Rubin’s reputation became a liability for Essential. Essential also announced Project Gem, a tall and thin smartphone that was designed to be used with one hand. The phone never reached the market, and Essential filed for bankruptcy on February 12 th , 2020, after realizing that there was no viable way to bring the phone to the market. The PH-1 was a lesson that high-end materials, limited software, and fast updates were not enough for a struggling smartphone brand to survive. 

The phone’s troubled launch, limited accessories, poor camera, and lack of network support hindered its chances, and Essential was unable to turn it around. The company realized that its ideas were not scalable enough to sustain a smartphone manufacturer, and it filed for bankruptcy later in 2020.

Roblox Privacy System Tracks Data Across Hundreds of Systems as Platform Faces Child Safety Concerns

 

Roblox announces new federated central data coordination, but the system also acts as a reminder of the amount of data the company stores about its users and their activity on the platform As the platform boasts more than 132 million daily users, half of which are under the age of 18, Roblox has a large-scale privacy and safety issue. 

At the Black Hat security conference, Roblox engineering manager Hao Zhang and principal privacy software engineer Yiwen Luo spoke about the company’s approach to operational privacy and data deletion. One user request to delete data could trigger over 600 subtasks that need to be tackled by different teams and systems. According to Zhang, the entire system is complex and requires close collaboration between hundreds of systems; one of the biggest challenges was figuring out where exactly the data about the user is stored. 

Luo added that per the privacy policy, Roblox collects and stores most information about the user for as long as the account is active on the platform. The topics range from chat content, audio and video data, device information, and demography, to email and phone number, government ID and selfie for voice chat and other restricted content, payment information, and username, date of birth, and password. Roblox has experienced a 3.5X growth in year-over-year privacy-related user data requests. 

The new federated management system aims to handle such requests in a more efficient system-wide manner across the company’s systems and data platforms, as well as the third-party ones storing user data. Roblox is using artificial intelligence and other technologies to improve moderation, safety, and privacy on its platform. The company’s system, called Sentinel, is designed to detect harmful content and messages using machine learning algorithms. 

Roblox also relies on a combination of human moderation and automated tools to review and filter game catalogs, chat content, and other materials. It implements preventive algorithms and age-estimation solutions as a part of its safety measures. However, the growing use of tracking systems, tools, and the controversy around the age-verification laws in over half of the U.S. states have sparked debates regarding data privacy and potential risks to users’ safety and data privacy. 

The expansion of Roblox’s operations has also led to increased scrutiny from regulators. After the games containing violent and extremist content were leaked, and the lawsuits regarding the company’s alleged role in facilitating predation and grooming were filed, Roblox’s moderation capabilities and safety tools have come under the magnifying glass. The Roblox Sentinel documentation reveals that roughly 1,200 potential child-endangerment reports had been reviewed.

Still, there was no information about how many of those had been confirmed as actual cases. While the new federated security system allows Roblox to have more visibility and control over where the data about its users is stored and how does the company handles data deletion requests, its transparency around the matter is limited by the amount of data the company stores about its users and the extent to which it monitors its platforms.

Ultra-Wealthy Turn to Premium Services to Erase Their Digital Footprints

 

For the ultra-wealthy, protecting personal information is increasingly becoming a premium service. High-net-worth individuals and corporations are paying specialized privacy firms to track down and remove personally identifiable information (PII) from search engines, data-broker databases and even the dark web.

Unlike automated privacy tools, these high-end services combine data removal with continuous monitoring and manual audits designed to reduce both online exposure and physical security threats.

Consumer-focused services such as DeleteMe, Incogni and Google’s free PII removal tool can help limit exposure, but their reach remains restricted. Data brokers often use measures to prevent automated deletion requests. “insert something like a captcha to ensure that a bot can’t come in and wipe out their database,” Tom Aldrich, chief operating officer of digital exposure reduction firm 360 Privacy, told Observer.

Aldrich said his company, which works with 32 Fortune 100 companies, recently took on a wealthy client who had previously used an automated service. The firm discovered 62 profiles belonging to the individual across hundreds of data aggregation platforms. “We found 62 different profiles on them across hundreds of data aggregator sources,” said Aldrich, who added that 93 percent of those profiles included non-public information and could be removed.

Digital exposure is becoming a physical security concern

Security experts increasingly warn that information available online can create risks in the physical world. Threats against senior executives have risen steadily over the past two decades, with attacks in 2025 more than doubling compared with the previous year.

“Physical and digital can no longer be separate,” Brian Hill, field chief information security officer at personal cybersecurity firm BlackCloak, which serves corporate executives and high-net-worth individuals, told Observer.

The connection became particularly evident in the case of Vance Boelter, the Minnesota gunman sentenced in July to two consecutive life sentences plus 40 years for killing Democratic lawmakers in 2025. Boelter reportedly used data aggregator websites to identify his victims.

Growing concerns around executive safety have also pushed security spending higher. The median security expenditure for executives at S&P 500 companies increased 37.8 percent between 2024 and 2025. During the same period, S&P 500 CEOs earned an average annual compensation of $18.9 million.

Meta was among the biggest spenders, allocating more than $25 million toward physical and digital security for CEO Mark Zuckerberg.

For family offices, celebrities and high-net-worth clients, BlackCloak's services can cost between $10,000 and roughly $200,000 annually. Enterprise contracts covering executives, board members and founders can reach as much as $600,000 per year.

A growing market for digital privacy

The expanding digital footprint of consumers has created an entire economy around personal-data protection. Data brokers collect and sell personal information to third parties, contributing to a North American data-broker market estimated at $40 billion.

Removing such information is often difficult and labor-intensive, increasing demand for specialized providers that can continuously identify and eliminate exposed data.

Only California, Oregon, Texas and Vermont currently require data brokers to identify themselves through state registries. More than 4,000 data brokers are estimated to operate across the U.S., with many outside the reach of comprehensive regulation. California alone has 545 registered data brokers.

Premium privacy firms typically remove information from publicly accessible websites while also monitoring the dark web and strengthening security across users' accounts and devices. Connected household technology, including security cameras, may also be included in these security assessments.

Still, complete digital anonymity is difficult to achieve. “Reducing your digital footprint to zero is virtually impossible,” said Hill. “Our goal is anywhere from 70–90 percent removal of data.”

Certain public records, including newspaper archives and campaign donation records, can also remain difficult or impossible to erase.

Affordable services remain an option

While high-end privacy protection is increasingly being adopted by wealthy individuals and corporations, more affordable services can still help ordinary consumers reduce their exposure.

Aura, for example, offers automated data removal alongside other digital safety services for families at $32 per month. “As data breaches continue, data brokers expand, and A.I. makes it easier to exploit personal information, more people are looking for ways to reduce their digital footprint and regain control of their privacy,” Tom Clayton, president and chief operating officer of Aura, told Observer.

Despite the growing number of services available, adoption remains relatively low. Only 6 percent of American adults use data-removal services, while more than half do not know such services exist.

Smaller businesses are increasingly vulnerable as well. “The attackers are…going after the small companies, the local family businesses. They’re now becoming the targets because they’re the easy ones,” Hill said.

Executives and their families continue to face particular risks. According to a 2025 report from BlackCloak and the Ponemon Institute, 51 percent of security leaders said cyberattacks had targeted the personal accounts of executives or their family members.

As personal and professional digital lives become increasingly intertwined, conventional corporate security teams may not fully protect executives' personal information. That gap is helping drive demand for specialized privacy and cybersecurity providers.

Artificial intelligence and emerging technologies could make the problem even more challenging. “With a lot of this technology,” said Hill about A.I. and quantum computing, “you’re going to see a lot more data collection, and it’s going to be easier to go after the people that don’t set up an LLC or trust because they just don’t think they need to.”

North Korean Hackers Target 1,640 Companies Across 57 Countries, Researcher Finds

 

North Korean hackers have been targeting the infrastructure and cryptocurrency wallets worldwide. Greek security expert Vangelis Stykas identified 1,640 organizations across 57 countries hit by the attack. His investigation, which gained unauthorized access to the networks run by North Korean hackers, took about 22 months. 

At the Black Hat conference in Las Vegas, Stykas spoke about the attacks, mentioning that around 700 to 800 companies out of 1,640 had fallen victim to “truly malicious” intrusion. In some cases, the servers and AWS accounts were compromised at the root level by state-sponsored groups. Stykas did not disclose how he managed to infiltrate the North Korean hacking groups. He noted that his computer might have been infected with the group’s malware since their computers were infected. 

The security analyst had access to Slack and Discord accounts controlled by the hackers and gathered five terabytes of data. Lazarus Group complex, one of the North Korean state-sponsored hacking groups, has been using encrypted messaging services like Telegram and Signal to coordinate crypto heists and money laundering schemes. According to the report by Chainalysis, which monitors illicit crypto transactions, North Korean hackers have generated more than $2.02 billion in 2025, a 51 percent increase from the previous year. 

Their cumulative cryptocurrency theft since 2017 reached about $6.75 billion in value through crypto heists. Moreover, 76% of crypto heists worldwide occurred in the first four months of 2026, with North Korean-sponsored groups being the masterminds behind these crimes. The groups are also changing their tactics, shifting from compromised encryption keys to social engineering to infiltrate new crypto exchanges. Stykas added that toward the end of 2024, attackers primarily used social engineering to convince victims to install malicious software on their computers by posing as recruiters offering high-paying IT jobs. 

The software would allow hackers to access the victims’ computers under the guise of testing their skills. The list of companies targeted by North Korean hackers includes Chinese smartphone manufacturer Oppo, Boston’s Children Hospital, tech firms in Japan, Italy’s judicial organizations, and Belgium’s Flemish government. Several of the organizations, including Flemish government agencies and Boston’s Children Hospital, noted that the breach originated from third-party contractors, and the damage was minimal. 

Moreover, Stykas added that many of his warnings went unheeded by the organizations that had fallen victim to the attacks. His research revealed that many organizations are using third-party contractors and service providers that operate as subcontractors for different firms. A single compromised third-party organization can lead to a security breach of multiple organizations. 

North Korean hackers not only target crypto wallets but also use their IT expertise to infiltrate organizations and exfiltrate data. Experts believe that North Korea continues to fund its nuclear program from the proceeds of these crimes.  Moreover, hackers pose as legitimate IT professionals offering their services on job boards, eventually getting hired and transferring the earnings to North Korean banks. Authorities believe North Korean hackers’ activities are designed to circumvent sanctions imposed on the country. 

According to experts, the infiltration of crypto exchanges, technology companies, and financial organizations will enable North Korea to bypass sanctions while funding its military expansion and nuclear program. Andariel hacker group, which targets defense and nuclear-related organizations, was dismantled by security agencies in 2024.

BTMOB Android RAT Ecosystem Expands With Resellers, Source-Code Sellers and Impersonators

 

The Android remote access trojan known as BTMOB most likely began as a centralized malware-as-a-service operation but transformed into a wider ecosystem, with resellers, source code buyers, rogue operators, and possibly even impersonators, according to the Flare researchers. BTMOB is a remote access trojan for Android devices that takes the form of malware-as-a-service.

It offers an “exploit chain,” that is, a malicious application, droppers, a payload builder, a Windows operator panel, servers, and phishing and credential-stealing tools. All of the components may be purchased in various combinations, depending on the chosen subscription plan. Some of the options include private infrastructure, customized builds, and technical support. The Flare researchers analyzed thousands of relevant forum and chat threads to document BTMOB’s activity and distribution channels. 

They tracked the malware’s progress from its first appearances in mid-2025 to the present day. In their findings, the researchers observed that while an official channel was distributing the service and its components, other purportedly independent channels and forums sold subscriptions, reseller panels, code, and even alternative versions of the malware under the same name. In particular, the official account announced the V2 of the malware for rent or sale for $700 per month, $3,000 for a lifetime subscription or $5,000 with additional monthly payments for the private infrastructure and support. Less than a month later, the same account announced technical issues and claimed that over 4,000 devices were connected to BTMOB’s servers. 

According to the researchers, the account advertised a full source code and setup instructions for BTMOB for $20,000. The package included PHP and Node.js server components, a VB.NET control panel and Java Android code. The advertised source-code price later fell to $10,000 in May 2025. Additionally, they noticed that the Spanish/Portuguese Telegram channel had an issue between two admins, one of whom left the project. The main channel then announced that from now on, all the administrators would function independently. 

It also stated that one of them, based in Brazil, had bought the source code and was running his own fork of BTMOB. After that, the secondary market appeared and started advertising much cheaper alternatives to the official subscription. In particular, one Telegram campaign announced the lifetime access to version 4.1.2 and 4.2 of BTMOB for $500 and purported RAT and server source code for $1,500. Other channels and forums also offered subscriptions, reseller panels, source code, and lifetime accounts for different prices and conditions.  

It is unclear whether the accounts offering the alternative versions of BTMOB are legitimate or not, as many of them could have used pirated materials or have been scams. For example, the official account warned all their partners that there is only one official BTMOB channel and that other accounts do not represent the company and are not affiliated with it. 

Nevertheless, the official account advertised the V4.1 release in February 2026 and V4.5 in April 2026. According to the announcement, the subscription for the private server hosting of several accounts costs about $1,200 lifetime account, a $3,000, and the source code for the server itself costs $7,000.

EU Launches New Brussels Team to Enforce AI Act Against Deepfakes and Hacking

 

The European Union rolled out a new enforcement team on Friday to rein in artificial intelligence companies worldwide, marking one of the most aggressive regulatory pushes the high-tech sector has faced. Brussels aims to track AI model use for violations of the bloc's new regulations, including sexually explicit material, fake photos, fake videos, and cyber threats to public infrastructure. The move comes as fears mount globally over the risks rapidly advancing technology poses to people, politics, and prosperity. 

With the EU's landmark AI Act coming into force on Sunday, AI companies must make clear to consumers, through labels or digital watermarks, that chatbots or imagery are generated using artificial intelligence. The European Commission stated that the regulations also address "systemic risks" posed by AI, including chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, and threats to fundamental rights. "As enforcement begins, we are taking an important step towards AI that people and businesses can trust," said Henna Virkkunen, the EU tech sovereignty chief. 

The new team, operating within the EU AI Office in Brussels, will add 38 personnel to monitor AI companies, covering both emerging firms and major American and Chinese technology giants, including OpenAI and DeepSeek. The companies must document certain information, and the European Commission can interview AI company staff during investigations. The Commission has also launched a Whistleblower Tool for tech workers and a Compliance Tool for tech users, allowing people to confidentially alert authorities to illegal conduct. 

The rollout follows alarming AI safety failures that have rattled the nascent industry. Anthropic revealed on Friday that its artificial intelligence models hacked into three other organisations during testing, just days after ChatGPT maker OpenAI disclosed that its rogue models had hacked another company. If AI models break the EU's regulations, Brussels can fine the firms or cut off their access to the EU market. Recent antitrust fines on US technology companies have already irritated US President Donald Trump. 

The enforcement team is the latest move in the 27-nation EU's broader "tech sovereignty" strategy, combining landmark digital regulations with economic ambition. The EU sees systemic vulnerability in its deep reliance on American software giants like Amazon, Google, and Microsoft, alongside imports of Chinese industrial goods and critical minerals. While seeking protections from AI, the bloc is keen to catch up in the AI arms race, where it remains a distant third behind the United States and China. The EU is pursuing greater independence from Washington and Beijing by reinvigorating domestic industries and forging new trade deals.