Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Security. Show all posts

Ultra-Wealthy Turn to Premium Services to Erase Their Digital Footprints

 

For the ultra-wealthy, protecting personal information is increasingly becoming a premium service. High-net-worth individuals and corporations are paying specialized privacy firms to track down and remove personally identifiable information (PII) from search engines, data-broker databases and even the dark web.

Unlike automated privacy tools, these high-end services combine data removal with continuous monitoring and manual audits designed to reduce both online exposure and physical security threats.

Consumer-focused services such as DeleteMe, Incogni and Google’s free PII removal tool can help limit exposure, but their reach remains restricted. Data brokers often use measures to prevent automated deletion requests. “insert something like a captcha to ensure that a bot can’t come in and wipe out their database,” Tom Aldrich, chief operating officer of digital exposure reduction firm 360 Privacy, told Observer.

Aldrich said his company, which works with 32 Fortune 100 companies, recently took on a wealthy client who had previously used an automated service. The firm discovered 62 profiles belonging to the individual across hundreds of data aggregation platforms. “We found 62 different profiles on them across hundreds of data aggregator sources,” said Aldrich, who added that 93 percent of those profiles included non-public information and could be removed.

Digital exposure is becoming a physical security concern

Security experts increasingly warn that information available online can create risks in the physical world. Threats against senior executives have risen steadily over the past two decades, with attacks in 2025 more than doubling compared with the previous year.

“Physical and digital can no longer be separate,” Brian Hill, field chief information security officer at personal cybersecurity firm BlackCloak, which serves corporate executives and high-net-worth individuals, told Observer.

The connection became particularly evident in the case of Vance Boelter, the Minnesota gunman sentenced in July to two consecutive life sentences plus 40 years for killing Democratic lawmakers in 2025. Boelter reportedly used data aggregator websites to identify his victims.

Growing concerns around executive safety have also pushed security spending higher. The median security expenditure for executives at S&P 500 companies increased 37.8 percent between 2024 and 2025. During the same period, S&P 500 CEOs earned an average annual compensation of $18.9 million.

Meta was among the biggest spenders, allocating more than $25 million toward physical and digital security for CEO Mark Zuckerberg.

For family offices, celebrities and high-net-worth clients, BlackCloak's services can cost between $10,000 and roughly $200,000 annually. Enterprise contracts covering executives, board members and founders can reach as much as $600,000 per year.

A growing market for digital privacy

The expanding digital footprint of consumers has created an entire economy around personal-data protection. Data brokers collect and sell personal information to third parties, contributing to a North American data-broker market estimated at $40 billion.

Removing such information is often difficult and labor-intensive, increasing demand for specialized providers that can continuously identify and eliminate exposed data.

Only California, Oregon, Texas and Vermont currently require data brokers to identify themselves through state registries. More than 4,000 data brokers are estimated to operate across the U.S., with many outside the reach of comprehensive regulation. California alone has 545 registered data brokers.

Premium privacy firms typically remove information from publicly accessible websites while also monitoring the dark web and strengthening security across users' accounts and devices. Connected household technology, including security cameras, may also be included in these security assessments.

Still, complete digital anonymity is difficult to achieve. “Reducing your digital footprint to zero is virtually impossible,” said Hill. “Our goal is anywhere from 70–90 percent removal of data.”

Certain public records, including newspaper archives and campaign donation records, can also remain difficult or impossible to erase.

Affordable services remain an option

While high-end privacy protection is increasingly being adopted by wealthy individuals and corporations, more affordable services can still help ordinary consumers reduce their exposure.

Aura, for example, offers automated data removal alongside other digital safety services for families at $32 per month. “As data breaches continue, data brokers expand, and A.I. makes it easier to exploit personal information, more people are looking for ways to reduce their digital footprint and regain control of their privacy,” Tom Clayton, president and chief operating officer of Aura, told Observer.

Despite the growing number of services available, adoption remains relatively low. Only 6 percent of American adults use data-removal services, while more than half do not know such services exist.

Smaller businesses are increasingly vulnerable as well. “The attackers are…going after the small companies, the local family businesses. They’re now becoming the targets because they’re the easy ones,” Hill said.

Executives and their families continue to face particular risks. According to a 2025 report from BlackCloak and the Ponemon Institute, 51 percent of security leaders said cyberattacks had targeted the personal accounts of executives or their family members.

As personal and professional digital lives become increasingly intertwined, conventional corporate security teams may not fully protect executives' personal information. That gap is helping drive demand for specialized privacy and cybersecurity providers.

Artificial intelligence and emerging technologies could make the problem even more challenging. “With a lot of this technology,” said Hill about A.I. and quantum computing, “you’re going to see a lot more data collection, and it’s going to be easier to go after the people that don’t set up an LLC or trust because they just don’t think they need to.”

North Korean Hackers Target 1,640 Companies Across 57 Countries, Researcher Finds

 

North Korean hackers have been targeting the infrastructure and cryptocurrency wallets worldwide. Greek security expert Vangelis Stykas identified 1,640 organizations across 57 countries hit by the attack. His investigation, which gained unauthorized access to the networks run by North Korean hackers, took about 22 months. 

At the Black Hat conference in Las Vegas, Stykas spoke about the attacks, mentioning that around 700 to 800 companies out of 1,640 had fallen victim to “truly malicious” intrusion. In some cases, the servers and AWS accounts were compromised at the root level by state-sponsored groups. Stykas did not disclose how he managed to infiltrate the North Korean hacking groups. He noted that his computer might have been infected with the group’s malware since their computers were infected. 

The security analyst had access to Slack and Discord accounts controlled by the hackers and gathered five terabytes of data. Lazarus Group complex, one of the North Korean state-sponsored hacking groups, has been using encrypted messaging services like Telegram and Signal to coordinate crypto heists and money laundering schemes. According to the report by Chainalysis, which monitors illicit crypto transactions, North Korean hackers have generated more than $2.02 billion in 2025, a 51 percent increase from the previous year. 

Their cumulative cryptocurrency theft since 2017 reached about $6.75 billion in value through crypto heists. Moreover, 76% of crypto heists worldwide occurred in the first four months of 2026, with North Korean-sponsored groups being the masterminds behind these crimes. The groups are also changing their tactics, shifting from compromised encryption keys to social engineering to infiltrate new crypto exchanges. Stykas added that toward the end of 2024, attackers primarily used social engineering to convince victims to install malicious software on their computers by posing as recruiters offering high-paying IT jobs. 

The software would allow hackers to access the victims’ computers under the guise of testing their skills. The list of companies targeted by North Korean hackers includes Chinese smartphone manufacturer Oppo, Boston’s Children Hospital, tech firms in Japan, Italy’s judicial organizations, and Belgium’s Flemish government. Several of the organizations, including Flemish government agencies and Boston’s Children Hospital, noted that the breach originated from third-party contractors, and the damage was minimal. 

Moreover, Stykas added that many of his warnings went unheeded by the organizations that had fallen victim to the attacks. His research revealed that many organizations are using third-party contractors and service providers that operate as subcontractors for different firms. A single compromised third-party organization can lead to a security breach of multiple organizations. 

North Korean hackers not only target crypto wallets but also use their IT expertise to infiltrate organizations and exfiltrate data. Experts believe that North Korea continues to fund its nuclear program from the proceeds of these crimes.  Moreover, hackers pose as legitimate IT professionals offering their services on job boards, eventually getting hired and transferring the earnings to North Korean banks. Authorities believe North Korean hackers’ activities are designed to circumvent sanctions imposed on the country. 

According to experts, the infiltration of crypto exchanges, technology companies, and financial organizations will enable North Korea to bypass sanctions while funding its military expansion and nuclear program. Andariel hacker group, which targets defense and nuclear-related organizations, was dismantled by security agencies in 2024.

BTMOB Android RAT Ecosystem Expands With Resellers, Source-Code Sellers and Impersonators

 

The Android remote access trojan known as BTMOB most likely began as a centralized malware-as-a-service operation but transformed into a wider ecosystem, with resellers, source code buyers, rogue operators, and possibly even impersonators, according to the Flare researchers. BTMOB is a remote access trojan for Android devices that takes the form of malware-as-a-service.

It offers an “exploit chain,” that is, a malicious application, droppers, a payload builder, a Windows operator panel, servers, and phishing and credential-stealing tools. All of the components may be purchased in various combinations, depending on the chosen subscription plan. Some of the options include private infrastructure, customized builds, and technical support. The Flare researchers analyzed thousands of relevant forum and chat threads to document BTMOB’s activity and distribution channels. 

They tracked the malware’s progress from its first appearances in mid-2025 to the present day. In their findings, the researchers observed that while an official channel was distributing the service and its components, other purportedly independent channels and forums sold subscriptions, reseller panels, code, and even alternative versions of the malware under the same name. In particular, the official account announced the V2 of the malware for rent or sale for $700 per month, $3,000 for a lifetime subscription or $5,000 with additional monthly payments for the private infrastructure and support. Less than a month later, the same account announced technical issues and claimed that over 4,000 devices were connected to BTMOB’s servers. 

According to the researchers, the account advertised a full source code and setup instructions for BTMOB for $20,000. The package included PHP and Node.js server components, a VB.NET control panel and Java Android code. The advertised source-code price later fell to $10,000 in May 2025. Additionally, they noticed that the Spanish/Portuguese Telegram channel had an issue between two admins, one of whom left the project. The main channel then announced that from now on, all the administrators would function independently. 

It also stated that one of them, based in Brazil, had bought the source code and was running his own fork of BTMOB. After that, the secondary market appeared and started advertising much cheaper alternatives to the official subscription. In particular, one Telegram campaign announced the lifetime access to version 4.1.2 and 4.2 of BTMOB for $500 and purported RAT and server source code for $1,500. Other channels and forums also offered subscriptions, reseller panels, source code, and lifetime accounts for different prices and conditions.  

It is unclear whether the accounts offering the alternative versions of BTMOB are legitimate or not, as many of them could have used pirated materials or have been scams. For example, the official account warned all their partners that there is only one official BTMOB channel and that other accounts do not represent the company and are not affiliated with it. 

Nevertheless, the official account advertised the V4.1 release in February 2026 and V4.5 in April 2026. According to the announcement, the subscription for the private server hosting of several accounts costs about $1,200 lifetime account, a $3,000, and the source code for the server itself costs $7,000.

EU Launches New Brussels Team to Enforce AI Act Against Deepfakes and Hacking

 

The European Union rolled out a new enforcement team on Friday to rein in artificial intelligence companies worldwide, marking one of the most aggressive regulatory pushes the high-tech sector has faced. Brussels aims to track AI model use for violations of the bloc's new regulations, including sexually explicit material, fake photos, fake videos, and cyber threats to public infrastructure. The move comes as fears mount globally over the risks rapidly advancing technology poses to people, politics, and prosperity. 

With the EU's landmark AI Act coming into force on Sunday, AI companies must make clear to consumers, through labels or digital watermarks, that chatbots or imagery are generated using artificial intelligence. The European Commission stated that the regulations also address "systemic risks" posed by AI, including chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, and threats to fundamental rights. "As enforcement begins, we are taking an important step towards AI that people and businesses can trust," said Henna Virkkunen, the EU tech sovereignty chief. 

The new team, operating within the EU AI Office in Brussels, will add 38 personnel to monitor AI companies, covering both emerging firms and major American and Chinese technology giants, including OpenAI and DeepSeek. The companies must document certain information, and the European Commission can interview AI company staff during investigations. The Commission has also launched a Whistleblower Tool for tech workers and a Compliance Tool for tech users, allowing people to confidentially alert authorities to illegal conduct. 

The rollout follows alarming AI safety failures that have rattled the nascent industry. Anthropic revealed on Friday that its artificial intelligence models hacked into three other organisations during testing, just days after ChatGPT maker OpenAI disclosed that its rogue models had hacked another company. If AI models break the EU's regulations, Brussels can fine the firms or cut off their access to the EU market. Recent antitrust fines on US technology companies have already irritated US President Donald Trump. 

The enforcement team is the latest move in the 27-nation EU's broader "tech sovereignty" strategy, combining landmark digital regulations with economic ambition. The EU sees systemic vulnerability in its deep reliance on American software giants like Amazon, Google, and Microsoft, alongside imports of Chinese industrial goods and critical minerals. While seeking protections from AI, the bloc is keen to catch up in the AI arms race, where it remains a distant third behind the United States and China. The EU is pursuing greater independence from Washington and Beijing by reinvigorating domestic industries and forging new trade deals.

Google Pauses AI Tool That Created Fake Images in Google Earth

 

Google has disabled a newly introduced AI feature in Google Earth that allowed users to overlay computer-generated scenes on top of satellite, aerial and 3D images, after reportedly discovering the capability has been used to create misleading content. 

The feature, which used Google’s Nano Banana 2 image generation model, was rolled out on Thursday and disabled nearly 48 hours later, after the company became aware of screenshots of generated images that appeared to depict locations altered in ways that violated Google’s policies. While the company does not specify what prompted its intervention, it notes users “have a strong expectation of Google Earth as a source of authoritative information about the world.” 

Following the removal of the feature, BBC Verify was able to recreate several examples of altered scenes using the tool, including the Eiffel Tower lying in ruins, a sinkhole engulfing the Great Pyramids of Egypt and Russian tanks poised to enter Kyiv. AI and misinformation expert Henk van Ess was also able to demonstrate the ability to create misleading images of real world locations, including a fake nuclear power plant in Iran, a refugee camp along the US and Mexico border and a hospital in Gaza with a crater. “Not only do the images have questionable value as evidence, but the very act of associating them with real-world locations and Google’s own satellite imagery adds an element of credibility to the deception,” said Van Ess. 

Google stated that images generated by its AI model contain invisible watermarks and directed users to Gemini and Google Lens to analyze images and detect authenticity. However, BBC Verify was able to uncover ways to bypass these measures, as well as manipulate the prompt to avoid detection. Meanwhile, researchers found some AI detection tools were unable to identify images generated by the Google Earth tool. 

Henry Ajder, an AI detection researcher, noted that images of populated places and battlespaces could cause “incredible damage to populations if they were to appear as credible evidence of events on the ground.” “The danger comes when the situation on the ground is unclear or time-sensitive, and people are looking for reliable information,” he added. Geospatial analyst Bill Greer added that imagery of the Earth has long been considered a “trusted source” of information by both governments and the public, meaning its misuse could undermine confidence in the technology and its ability to provide truthful insight. 

The episode underlines the challenge facing both creators and users of AI imagery, as the ability to generate increasingly realistic images threatens to erode the value of other trustworthy sources of information.

Apple macOS Flaw Exploited in the Wild to Install Monero Cryptominers

 

A critical vulnerability in the recently updated Apple macOS has been weaponized by threat actors to mine Monero cryptocurrency, according to the Netherlands National Cyber Security Centre (NCSC-NL). The security flaw under identifier CVE-2026-65400 with a CVSS score of 9.8/10 impacts the macOS Screen Sharing component and is described as allowing ‘remote code execution via crafted network packets’. Apple released emergency security updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9 this month to address the flaw. 

The tech giant explained the changes were related to an authentication issue, ‘fixing state management to ensure credentials are properly validated.’ The vulnerability was discovered by security researcher Alfredo Pesoli of Bynario. According to the NCSC-NL, there are currently reports of bad actors actively using this exploit. ‘Multiple systems with port 5900 open to the internet,’ the Netherlands-based watchdog stated in a report this week, ‘were compromised using this vulnerability.’ 

In all cases of exploitation detected so far, the attackers gained root access to the targeted systems and deployed a Monero cryptocurrency miner. It remains unclear how long the threat landscape had been targeting macOS Screen Sharing, how many systems had been impacted, and whether the mining activity was the sole motive behind the attacks. Several other flaws impacting the macOS Screen Sharing component have also been detected. 

They include CVE-2026-43760 which can lead to the disclosure of sensitive information, arbitrary file creation, and remote code execution under specific conditions; CVE-2026-43777, which may result in a denial-of-service scenario; and CVE-2026-43779 with a logic flaw that can cause applications to hijack connections from other processes. According to Pesoli’s research, there are additional privilege escalation possibilities in an older authentication method used by Screen Sharing, including VNC passwords. 

A threat actor with the VNC password could potentially access protected files or create new files with root permissions, resulting in remote code execution. The researcher also highlighted a pre-authentication vulnerability in the Screen Sharing daemon which, if successfully exploited, would allow an attacker to compromise a Mac with Screen Sharing enabled and without requiring a VNC password. ‘All the attacker needed was a target IP address,’ he added. 

His findings suggest that tens of thousands of Screen Sharing services were exposed to the internet, putting residential users, educational institutions, and corporations at risk. Researchers advise that Screen Sharing should not be exposed to the internet and recommend that such services be placed behind an IPsec or other secure access gateway. It is unclear how many macOS users had their systems compromised via the Screen Sharing flaw. 

However, cybersecurity analysts warn that AI-powered tools are facilitating faster threat modeling and detection, enabling attackers to exploit vulnerabilities almost immediately after they become publicly known. ‘We had an AI agent that helped us develop working exploits for two of the Screen Sharing vulnerabilities within hours of their disclosure,’ Calif, a security company, noted in a report. macOS users must install the latest software updates released by Apple to ensure their systems are protected against the newly discovered flaws. 

Customers who cannot immediately install the critical security patches should disable Screen Sharing in their Mac’s Sharing preferences until the updates are deployed.

GrapheneOS Foundation Defends Privacy Features Amid US Case Involving User

 The US Department of Justice’s recent case against GrapheneOS user Sam Tunick has renewed discussions about mobile privacy, digital security and the limits of law enforcement access to personal devices. The GrapheneOS Foundation has responded by defending its open-source operating system and clarifying how its security mechanisms handle deleted information.

The Toronto-based non-profit organization said GrapheneOS is a lawful operating system and rejected any suggestion that the software itself is connected to illegal activity. The foundation emphasized that it has no responsibility to weaken features intended to protect users and their data.

Based on Android and currently designed for Google Pixel devices, GrapheneOS incorporates several security and privacy protections. The foundation argues that developing, distributing or using the operating system is protected under US constitutional principles and that legislation specifically targeting its security capabilities could face constitutional challenges.

One of the features at the centre of the case is GrapheneOS’s "duress password." Tunick reportedly provided the password to a US Customs and Border Protection officer. The feature is designed to trigger an immediate wipe of a device when a specific password or PIN is entered under coercion.

When activated, the process removes the phone’s stored information, including eSIM data. According to the foundation, the wipe occurs immediately, cannot be interrupted and cannot subsequently be reversed. As a result, data erased through the feature cannot be recovered from the device.

Despite the attention surrounding the duress password, the GrapheneOS Foundation has stressed that it represents only one small component of the operating system’s broader security architecture. The organization also cautioned that using such a feature could potentially have physical or legal consequences, meaning users need to consider the risks before relying on it during encounters with authorities or other coercive situations.

The legal dispute is also focused on Tunick’s treatment during the encounter. His attorney has alleged that the border officer did not provide Miranda warnings and disregarded Tunick’s requests to consult a lawyer.

Tunick’s legal team is seeking the exclusion of evidence obtained during the incident. The attorney has argued that the evidence should be dismissed because the authorities allegedly violated Tunick’s constitutional rights.

The case has consequently raised broader questions about the balance between individual privacy, device security and government authority, while putting renewed attention on how privacy-focused operating systems handle data deletion and compelled device access.

Here's How to Secure Your SSO Against Credential Attacks

 

Single sign-on (SSO) has transformed how employees access business applications by allowing one account to authenticate users across multiple services. However, this convenience also creates a concentrated security risk: if attackers compromise the central login, they may gain access to email, VPNs, customer-management platforms, file storage, and other sensitive systems. The 2025 University of Pennsylvania breach demonstrated how a compromised PennKey SSO account could provide access to several internal services and expose information belonging to 1.2 million individuals. SSO is not inherently insecure, but it must be treated as a critical security control rather than a simple convenience feature. 

Strong password policies remain an important foundation for protecting SSO accounts. Current NIST guidance recommends passwords of at least 15 characters when they are used without additional authentication, while passwords used with multi-factor authentication (MFA) may be at least eight characters. Organizations should permit passwords of up to 64 characters and compare new passwords against lists of commonly used or previously compromised credentials. At the same time, businesses should reconsider frequent mandatory resets and rigid complexity rules, which can encourage predictable habits such as adding a number to an old password. 

 MFA should be enforced consistently for every user, application, and access scenario—not only for administrators or accounts considered high risk. SMS codes and basic one-time passwords provide more protection than passwords alone, but phishing-resistant technologies offer stronger defenses against modern credential theft. FIDO2 security keys, WebAuthn, and passkeys can help prevent attackers from capturing authentication data through phishing pages or infostealer malware. These methods are particularly valuable for privileged accounts and systems containing sensitive information. 

Organizations must also protect the infrastructure supporting their SSO environment. Identity-provider administrator accounts should use separate privileged identities, phishing-resistant MFA, just-in-time access, and continuous monitoring. SAML certificates, token-signing keys, OAuth secrets, application credentials, and refresh tokens should be stored securely, rotated regularly, and restricted to authorized personnel. Security teams should review application registrations, delegated permissions, and user-consent grants to remove stale or excessive access that attackers could exploit for persistence. 

When properly implemented, SSO can improve security by reducing password reuse, limiting password exposure across applications, centralizing access policies, and simplifying account deactivation when employees leave. It can also reduce help-desk requests caused by forgotten passwords and make compliance reporting easier. Nevertheless, SSO is not secure by default. Organizations should combine strong password screening, universal phishing-resistant MFA, hardened administrator accounts, controlled recovery procedures, careful application permissions, and regular monitoring to ensure that one compromised credential does not become a gateway to the entire enterprise.