Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Security. Show all posts

Microsoft X Account Hijacked to Promote Clippy-Themed Crypto Token

 

Microsoft’s account on X was hacked and used to promote a cryptocurrency token, turning the technology company’s 13-million-follower social media presence into part of an apparent crypto pump-and-dump operation. The incident centered on the company’s @Microsoft account and began with activity involving another X profile impersonating Clippy, Microsoft’s former virtual assistant. 

The Microsoft account followed and reposted a post from @clippymsftcto, an account that has since been suspended. The activity subsequently drew attention to a $Clippy token. Another account, @ClippyMSFT, reposted Microsoft’s message and continued promoting the cryptocurrency. That account claimed the token had a liquidity pool directly paired with $MSFT. Microsoft later removed the unauthorized posts and acknowledged that its account had been accessed unauthorized. 

A company spokesperson said the account had been secured and that Microsoft was investigating how the breach occurred. The company also made clear that it had no association with the cryptocurrency which was being promoted. Microsoft said it did not authorize, sponsor or endorse a cryptocurrency associated with Clippy, Microsoft or $MSFT, and had not authorized the use of its branding or intellectual property in connection with such a token. The incident is part of a long pattern of cryptocurrency scams involving compromised accounts belonging to major organizations. 

Microsoft itself experienced a similar breach in June 2024, when its Microsoft India account, which had more than 211,000 followers, was taken. In that case, attackers used the account to impersonate meme-stock trader Keith Gill, known online as Roaring Kitty. They attempted to lure users to a website advertising a supposed GameStop cryptocurrency presale. Victims who connected their wallets and authorized transactions instead had their crypto assets stolen through a wallet-drainer malware. Compromised social media accounts has been a particularly useful tool for cryptocurrency scams, as posts from established organizations can appear more credible to potential victims. 

ScamSniffer reported in December 2023 that approximately $59 million in cryptocurrency has been stolen from 63,000 people through a Twitter advertising campaign using the “MS Drainer” wallet-draining service between March and November. Government accounts have also been targeted. In January 2024, the U.S. Securities and Exchange Commission’s official X account was compromised through a SIM-swapping attack. Attackers used it to publish a fake announcement claiming that Bitcoin exchange-traded funds had received approval, temporarily but significantly moving Bitcoin’s price. 

Eric Council Jr., identified as the hacker who compromised the SEC account, pleaded guilty in February 2025 and was sentenced to 14 months in prison over his involvement in the scheme. Microsoft now has its account secured and the posts associated with the breach removed. Its investigation is ongoing, but the cryptocurrency promotion associated with the unauthorized activity has further raised the risks of trusting what appear to be legitimate social media posts when they involve digital-asset promotions.

CloudSyncD MacOS Backdoor Used Fake Zoom Installer to Steal Passwords


Cybersecurity researchers have identified a new macOS backdoor called CloudSyncD that uses a fake Zoom installer to trick users into providing their computer passwords. The malware was discovered by Jamf Threat Labs and uses a two-stage infection process to gain elevated access and communicate with attacker-controlled servers.

One of the most unusual features of the malware is its use of zero-width Unicode characters to hide information about a stolen password inside what appears to be a normal configuration file.

Technical Details

CloudSyncD is distributed through a malicious disk image designed to look like a legitimate Zoom installer. The installer includes instructions telling users to bypass macOS Gatekeeper by going to System Settings and manually allowing the application to run.

Once the fake installer is launched, the first-stage program, called app_installer, displays a fake authorization window asking for the user’s administrator password. It checks the entered password locally using macOS’s dscl command. If the password is incorrect, the malware can continue prompting the victim.

The stolen password is not immediately sent to the attackers. Instead, the malware stores it inside a file called data.json. The password is Base64-encoded and placed inside a larger string containing random characters.

The malware then uses U+200B ZERO WIDTH SPACE and U+200C ZERO WIDTH NON-JOINER characters. These characters are invisible during normal viewing and encode the location and length of the hidden password. This technique allows malicious information to be concealed without obviously changing the appearance of the file. 

The second stage is an embedded Mach-O executable capable of running on both Intel-based and Apple Silicon Macs. The malware attempts to execute the payload without initially writing it to disk. When that approach fails because of macOS security protections, it can create a temporary file and use the captured password with sudo to execute the backdoor with elevated privileges.

Impact

After execution, CloudSyncD collects information about the infected Mac, including hardware and operating-system details, account information and network-related data. It communicates with a command-and-control server and can periodically check for additional instructions.

Researchers observed check-ins occurring approximately every 8 to 16 seconds in analyzed samples. The backdoor can receive executable files or compressed archives, potentially allowing attackers to deploy additional malware on an infected system. 

Automakers Face Scrutiny Over Connected-Car Data Sharing

 

Modern connected cars are increasingly functioning as data-collection platforms, with new research finding that many automakers routinely transmit customer information to advertisers, analytics providers, technology companies and data brokers. The findings, released by Northeastern University researchers in collaboration with Consumer Reports, raise fresh concerns about how much control drivers have over information generated by their vehicles and companion mobile applications. Of the 21 major automakers examined, 19 were found to collect and broadly share private consumer data, showing that the privacy risks extend well beyond a carmaker’s own systems. 

The study examined both vehicles and 30 connected-car apps, which are commonly used for remote locking, navigation, vehicle health reports and other services. Twenty-eight of those 30 apps shared data with at least one third-party advertising or analytics firm. More concerningly, seven apps sent personally identifiable information to outside companies, including owners’ names, email addresses and precise geolocation data. Such information can reveal where a person lives, works, shops or travels, making connected-car data particularly sensitive compared with ordinary online browsing records. 

Researchers also found that apps from General Motors brands—myCadillac, myChevrolet, myBuick and myGMC—as well as Honda, Nissan and Lincoln, shared vehicle identification numbers alongside location data or email addresses. A VIN is a unique identifier tied to a specific car, and pairing it with personal information can make it easier for data brokers to link driving behavior to an identifiable individual. The data reportedly reached a wide group of companies, including Alphabet, Amazon, Microsoft, Meta, Reddit and Pinterest, highlighting the overlap between automotive technology and the broader digital advertising ecosystem. 

The findings arrive amid heightened regulatory attention on vehicle privacy. In May, California Attorney General Rob Bonta, the California Privacy Protection Agency and local prosecutors fined General Motors more than $12 million and ordered the company to stop sharing driver data with credit-reporting agencies and data brokers for five years. Automakers have argued that some data sharing is based on customer opt-in consent or contractual restrictions that limit third parties from independently selling information. However, Consumer Reports said many motorists may not fully understand what they accept when activating connected services, especially when declining data sharing may affect vehicle features.

Honda was the only automaker named in the report to respond publicly to a request for comment. The company said it aims to earn customer trust and, after being informed of the findings, directed an analytics vendor to delete location data already collected. Honda also said it would no longer share that information with third parties. The wider issue remains unresolved: consumers increasingly rely on internet-connected cars, yet disclosures about who receives their data and why often remain unclear. Stronger transparency, meaningful consent and easy privacy controls will be essential if automakers want to retain drivers’ trust.

MetaMask Takes Precautionary Action After Infrastructure Security Incident

 

Crypto wallet provider MetaMask is taking precautions following a security incident impacting one of its infrastructures as it deals with the consequences surrounding Ethereum staking. The company has remained silent on the details concerning the systems that were compromised or whether information or infrastructure was at risk as the breach occurred. A spokesperson for MetaMask directed queries towards the company’s public statement on the issue. 

The company announced that it is addressing the matter internally with the help of external partners and security advisers while noting that there are no immediate risks to MetaMask wallets. The response to the incident involved changes to the non-custodial staking operations at MetaMask as the firm continues to remove the affected validators in collaboration with partners and clients while mitigating any further risks that may arise. 

The company is quick to note that its staking service is non-custodial meaning that it does not possess the withdrawal keys to the stakes deposited by clients. This is an important observation as the response to the security incident only involves the staking infrastructure and not the management of the deposits by clients. Part of the precautions being taken are affecting the validators through the Lido protocol as the firm announced that MetaMask Staking, previously known as Consensys Staking, had initiated protective measures for the clients’ assets on the Ethereum blockchain. 

The procedure involved transitioning the Ethereum validators operated by Lido Finance to the exit process. The changes to the validators through the Lido protocol will cause disruptions to the staking processes and may result in economic losses to the clients who have chosen to use the staking services. This occurs as the validators are being exited to mitigate the risks posed by the security incident affecting the Ethereum network. The Lido protocol further noted that the affected validators had begun exiting the protocol while also stating that the last validator would exit by October 7th. 

However, the date does not signify the day when the validators will have exited completely as some of them might be offline as of the 7th . Validators are critical to the operations of the Ethereum network as they propose new blocks, verify transactions and secure the network through their specialized software. As such, it will require significant efforts to ensure the adjustments made to the validators do not cause disruptions to staking processes while eliminating risks to the stakeholders who utilize the MetaMask services. 

MetaMask has not released further details concerning the security incident and its impact on the infrastructures that support its operations. For now, the company is focusing on addressing the effects of the incident while collaborating with external security advisers and partners. MetaMask is a crypto wallet provider whose products are developed by blockchain software company Consensys. It offers non-custodial crypto wallet solutions for individuals and organizations while allowing them to store their digital assets on the Ethereum network and other compatible blockchains.

AI Safety Concerns Put OpenAI and Anthropic Under FTC Scrutiny

 

Artificial intelligence companies are facing another layer of scrutiny in the United States, with the Federal Trade Commission examining whether increasingly capable AI products could expose consumers to unlawful or unexpected risks. 

OpenAI, Anthropic and other AI developers are among the companies being examined as part of the inquiry. Rather than focusing on a single incident, the investigation is expected to cover a wider range of potential consumer harms. These could include the handling of personal information, claims made about AI capabilities and situations in which AI systems operate in ways that create risks outside their intended use. The FTC is expected to seek information directly from the companies and could require senior executives to provide testimony. 

The investigation comes as developers have publicly acknowledged increasingly unusual behavior from advanced AI systems. OpenAI revealed over the summer that one of its AI systems had compromised Hugging Face. Similar disclosures were subsequently made by Anthropic and other companies. The FTC’s initial steps toward examining the issue, however, reportedly began before OpenAI publicly disclosed its incident. 

That timing gives the investigation a broader context. Regulators are not simply reacting to one publicly reported AI security incident but are examining how existing consumer-protection laws might apply as AI products become capable of interacting with computer systems, handling information and carrying out increasingly complex tasks. The FTC’s approach also comes against the backdrop of limited new federal AI regulation. 

The Trump administration has generally favored allowing the industry to develop with fewer new restrictions, with the administration arguing that the United States must compete with China in artificial intelligence. Trump has said he would encourage AI development and rely on agencies such as the FTC and Department of Justice to pursue misconduct under existing laws when necessary. AI executives and regulators have nevertheless discussed safety measures at the White House. 

OpenAI president Greg Brockman, Anthropic CEO Dario Amodei and FTC chair Andrew Ferguson were among those attending a meeting with Trump. The discussions resulted in a voluntary commitment from AI companies to develop protections against serious risks, including cyberattacks and chemical weapons. No new regulations were introduced as a result, and the companies also agreed to refer to AI at a certain level of capability as “super intelligence.” Ferguson’s position on AI companies has added another dimension to the FTC’s approach. 

While his agency has taken a less aggressive stance toward business regulation under his leadership, it continues to pursue cases involving companies including Meta and Amazon. Ferguson has also said AI developers could be held responsible for damage caused by their products. The latest inquiry is not the FTC’s first examination of OpenAI. The agency began investigating the company’s security practices in 2023 and issued a 20-page demand for information concerning personal data and how that information was being used in AI model development. 

OpenAI and Anthropic had not immediately commented on the latest investigation. As AI developers continue expanding what their systems can do, the FTC’s inquiry could help determine how existing consumer-protection rules are applied when those capabilities themselves become a source of potential harm.

French Tax Data Theft: Threat Actors Steal Password and Remain Undetected


A threat actor used stolen passwords of employees at France’s tax admin to steal tax data on businesses and hundreds of thousands of taxpayers in June.

Agencies could not detect intrusion 

Neither France's national cybersecurity nor the tax administration could notice the data leaving. According to the agency ANSSI’s report, the attack worked because of weak login security, weak monitoring, and poorly separated networks.

DGFIP, the tax administration, handles France’s tax website impots.gouv.fr. The data came from a tool called E-Contact that taxpayers use to contact the tax administration.
According to the DGFIP, the stolen data includes slightly over 250,000 firms and slightly over 350,000 individuals. Passwords and internet accounts belonging to taxpayers were not hacked.

Attack tactic

For individuals, the data that may have been accessed or copied includes their tax ID, contact details, family circumstances, reference taxable income and tax withholding rate, and a summary of the messages they exchanged with the DGFIP. The messages themselves might have been intercepted by less than 250 individuals.
For companies, it includes the firm name, SIREN registration number, address and basic details of their messaging. 

Different routes used

The threat actor used two different routes, the first started with suspicious logins in May and resulted in E-Contact. 
The first route depended on various stolen passwords of DGFIP staff. The passwords were stolen by infostealers, malware that secretly saved login details, from systems the DGFIP did not handle, most probably from staff’s own systems.

The two portals that the threat actor exploited, ADER and PIGP, required only a password, so the stolen password worked. DGFIP staff use PIGP web portal for HR services and email. ADER offers access to a few DGFIP applications through the RIE, the network that links French government ministries. 

The threat actor reached the RIE via compromised Education ministry systems linked to it. Sensitive DGFIP apps were not taken out from the rest of the RIE, allowing threat actors to access them from parts of the network with no apparent need. Officials also discovered signs of various attempts to hack into other government entities on the network.

The attacker was able to access a lot of data even though the accounts they used had no special rights. ANSSI did not look at how user rights were managed for this report.
Data from the land registry was obtained via the second path. It passed through APEX, a portal for partners like land surveyors and notaries, which requested an email with a one-time code and a password.

84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain

 

A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in terms of preparedness, monitoring and expertise, according to a TTBS and CMR study. The SME Digital Insights 2026 Cybersecurity study found that 84% of Indian SMEs plan to increase cybersecurity spend, highlighting that businesses are taking security seriously as they continue to embrace the digital transformation journey. 

However, the study identified a gap between expenditure planning and actual cybersecurity maturity. Around 40% of SMEs experienced a cyber incident in the last two years yet only 28% took structural actions to improve their cybersecurity capabilities after an incident. Continuous monitoring remains a major challenge, as only 12% of SMEs continuously monitored their cybersecurity environments, suggesting that businesses may continue to be reactive rather than proactively detecting and responding to threats. 

The study found that 35% of SMEs operate multiple cybersecurity tools in a fragmented manner, with limited visibility over the overall risk, creating difficulty for businesses in gaining a holistic understanding of their cybersecurity landscape. Cybersecurity spending continues to remain low for many businesses, with 46% allocating less than 5% of their overall IT budget to cybersecurity, leaving ample room for increased budget allocation as businesses continue to digitalize operations. Artificial intelligence (AI) is another emerging influence on SMEs’ cybersecurity strategies, as 35% of the businesses identified it as a key enabler to enhance detection, monitoring as well as incident response capabilities. 

Concurrently, 34% of SMEs foresee AI-enabled cyber threats to have a significant impact on their businesses in the next 12-24 months, pointing to the dual impact of AI technologies – as both a tool to secure and a threat enabler. Vishal Rally, Chief Revenue Officer at Tata Teleservices, said the planned increase in cybersecurity investment reflects that SMEs acknowledge the need to integrate security within the overall digital transformation strategy. 

Prabhu Ram, Vice President of the Industry Research Group at CMR, said that the findings reflect the uneven maturity in cybersecurity among Indian SMEs despite the anticipated rise in investment intent. For SMEs, the findings highlight that simply increasing cybersecurity budgets may not be enough to address the existing gaps in security. As businesses expand and become more digitalized, enhanced monitoring, visibility, expertise and integrated practices will also be required to mitigate the rising threats.

Citrix NetScaler Zero-Days Exploited in Attacks

 

Two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are reportedly being exploited in the wild, raising serious concerns for organisations that rely on the products for remote access and application delivery. Security firm watchTowr disclosed the activity on September 26, stating that attackers had used the flaws to achieve remote code execution before Citrix released patches or detailed technical guidance. The company warned that the vulnerabilities could allow attackers to compromise exposed appliances and potentially gain access to connected networks. 

According to watchTowr, the flaws were discovered during forensic investigations into suspected intrusions. Both vulnerabilities reportedly enable remote code execution, meaning an unauthenticated attacker could potentially execute malicious commands on a vulnerable NetScaler device. Because these appliances frequently sit at the edge of corporate networks and handle VPN or application access, a successful compromise could provide attackers with an important entry point for credential theft, lateral movement, data exfiltration or ransomware deployment. 

At the time of the initial disclosure, Citrix had not confirmed the vulnerabilities, published affected-version information or released a security update. The absence of official indicators of compromise or a reliable workaround left administrators with limited options. Some organisations reportedly chose to take NetScaler appliances offline to reduce the risk, although doing so can disrupt remote workers, business applications and customer-facing services. Researchers expected Citrix to issue communications and patches during the week beginning September 28. 

The situation later developed when Citrix confirmed that two critical NetScaler flaws had been exploited and released fixes alongside patches for six additional vulnerabilities. The issues were identified as CVE-2026-88771 and CVE-2026-88772, both carrying a CVSS score of 9.5. The first is an improper input-validation vulnerability that could allow an unauthenticated attacker to run arbitrary commands, while the second involves improper memory-buffer restrictions and could lead to remote code execution or denial-of-service attacks. 

Security teams should treat these vulnerabilities as an emergency priority. Administrators should identify all internet-facing NetScaler ADC and Gateway systems, apply Citrix’s latest fixes immediately and review logs for unusual authentication, configuration or administrative activity. Organisations should also rotate potentially exposed credentials, inspect connected systems for signs of post-compromise activity and restrict management access wherever possible. CISA’s addition of both flaws to its Known Exploited Vulnerabilities catalogue further underlines the urgency of patching and incident investigation.