<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tips and Advice &#8211; Cyberwire Daily</title>
	<atom:link href="https://cyberwiredaily.com/category/tips-and-advice/feed/" rel="self" type="application/rss+xml" />
	<link>https://cyberwiredaily.com</link>
	<description></description>
	<lastBuildDate>Mon, 29 Jun 2026 13:47:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cyberwiredaily.com/wp-content/uploads/2025/09/icon-150x150.png</url>
	<title>Tips and Advice &#8211; Cyberwire Daily</title>
	<link>https://cyberwiredaily.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Why cybercriminals want to break into your email account</title>
		<link>https://cyberwiredaily.com/why-cybercriminals-want-to-break-into-your-email-account/</link>
					<comments>https://cyberwiredaily.com/why-cybercriminals-want-to-break-into-your-email-account/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 13:47:25 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/why-cybercriminals-want-to-break-into-your-email-account/</guid>

					<description><![CDATA[Your inbox is an identity system all of its own: whoever owns it may own a lot more Email is not just a means of communication, or yet another online account. In both our personal and work lives, it holds the keys to the kingdom: possibly even a mechanism to reset other account passwords and [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">Your inbox is an identity system all of its own: whoever owns it may own a lot more</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/06-26/inbox-hackers-target.jpg" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/06-26/inbox-hackers-target.jpg" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>Email is not just a means of communication, or yet another online account. In both our personal and work lives, it holds the keys to the kingdom: possibly even a mechanism to reset other account passwords and verify your identity. Email accounts are also the place where password-reset links arrive, account alerts are stored, bookings are confirmed, invoices are filed and identity checks begin.</p>
<p>The inbox may, therefore, contain years’ worth of detailed information about you, including what you own, which services you use, where you go, who you trust and how other accounts can be reached.</p>
<p>That’s why it’s also a prized target for cybercriminals.. If you want to protect your personal or business accounts and data, security must start with your inbox.</p>
<h2>Why attackers love inbox access</h2>
<p>Attackers have your inbox in their sights because it can give them leverage over the rest of your digital life. With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.</p>
<p>They may also try to stay hidden, setting up automatic forwarding rules so they can keep receiving your messages even after you think the immediate problem has been fixed. In other words, even if you perform a password reset, they’ll get sent the reset codes. Others may abuse access tokens, connected apps or active sessions to retain a foothold.</p>
<p>Hackers could access your photos for potential blackmail, and eavesdrop on your communications. That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with. It might ask for money, fee payments, or more personal information with which to carry out identity fraud. The more information (e.g., account details) they have on you, the more convincing the phishing attack will be.</p>
<blockquote>
<p>Broadly speaking, phishing as an acute threat clearly isn’t going anywhere. Quite the opposite: ESET telemetry showed a 36-percent increase in malicious emails in the second half of 2025 compared with the previous six months.</p>
<figure class="image"><img decoding="async" title="Figure 1. Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)" src="https://web-assets.esetstatic.com/wls/2026/06-26/email-threats-h1-h2-2025.png" alt="email-threats-h1-h2-2025" width="" height=""/><figcaption><em>Figure 1. Malicious email detection trend in 2025 (source: <a href="https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22025.pdf#page=29" target="_blank" rel="noopener">ESET Threat Report H2 2025</a>)</em></figcaption></figure>
<figure class="image"><img decoding="async" title="Figure 2. Top malicious email attachment types (source: ESET Threat Report H2 2025)" src="https://web-assets.esetstatic.com/wls/2026/06-26/top-malicious-email-attachment-types-in-h2-2025.png" alt="top malicious email attachment types in H2 2025" width="" height=""/><figcaption><em>Figure 2. Top malicious email attachment types (source: <a href="https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22025.pdf#page=29" target="_blank" rel="noopener">ESET Threat Report H2 2025</a>)</em></figcaption></figure>
</blockquote>
<p>The repercussions on your work life could be even worse. With access to your corporate email account, hackers could open cloud apps, access shared drives, peer into CRM, finance and HR systems, eavesdrop on your messages with colleagues and customers, and access customer data.</p>
<p>A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack. According to recent <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026">UK government statistics,</a> phishing (38%) was the most common form of cyber attack in the past year, followed by “people impersonating organizations in emails” (12%).</p>
<figure class="image"><img decoding="async" title="Figure 3. Phishing email delivering Win/PSW.Delf trojan, pretending to be from Fujifilm (source: ESET Threat Report H2 2024)" src="https://web-assets.esetstatic.com/wls/2026/06-26/cryptostealers-delf-fujifilm-campaign.png" alt="Cryptostealers_Delf Fujifilm campaign" width="" height=""/><figcaption><em>Figure 3. Phishing email delivering Win/PSW.Delf trojan, pretending to be from Fujifilm (source: <a href="https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22024.pdf#page=13" target="_blank" rel="noopener">ESET Threat Report H2 2024</a>)</em></figcaption></figure>
<h3>It’s getting harder to protect your inbox</h3>
<p>Email remains attractive to attackers because it sits at the intersection of technology, identity and human trust. Phishing targets what’s arguably the weakest link in the security chain: humans. We all use email every day under time pressure – to receive invoices, delivery updates, HR notices, customer requests, password resets, meeting invites and security alerts. Many of these messages ask us to click, approve, download, reply or pay. Attackers exploit that routine as even careful users can make mistakes when a message appears to come from a familiar sender, arrives at a busy moment or carries a sense of urgency. Using impersonation and social engineering techniques, hackers have a higher chance of success.</p>
<p>The human element was present in 62% of breaches last year, with social engineering the third most common breach pattern, representing 16% of all breaches, <a href="https://www.verizon.com/business/resources/T1f0/reports/2026-dbir-data-breach-investigations-report.pdf">according to Verizon</a>. And the bad guys are always looking for new ways to trick you. The report notes that the median rate of “successful” click rates in mobile phishing simulations is 40% higher than for email.</p>
<p>They’re also using more sophisticated tools to improve the success rates of email phishing campaigns. Generative AI (GenAI) can help threat actors write and scale phishing messages with faultless grammar and spelling.</p>
<h3>A case in point: BEC</h3>
<p>Some of the most damaging and costly cyber attacks ever recorded began with an inbox compromise. They include:</p>
<ul>
<li><strong>Facebook and Google:</strong> The tech duo <a href="https://www.infosecurity-magazine.com/news/tech-duo-stung-for-122m-by-bec-1/">were tricked out</a> of funds estimated at over $120 million after a hacker emailed them fake invoices impersonating a legitimate supplier and containing forged documents.</li>
<li><strong>Children’s Healthcare of Atlanta:</strong> After a construction firm publicly announced it had been named the general contractor for a new building project at the hospital, quick-thinking fraudsters sent a request for payment, impersonating the builder. <a href="https://www.kmbc.com/article/scammer-steals-million-from-atlanta-healthcare-provider-posing-as-kansas-city-je-dunn-construction-employees/39919121">They reportedly spoofed</a> the letterhead and email address of the company, in an email purporting to come from its CFO.</li>
<li><strong>Crelan Bank:</strong> The Cretan bank lost over $75 million after an employee was tricked into wiring the funds to a bank account controlled by fraudsters. In this instance the scammers <a href="https://www.bcs.org/articles-opinion-and-research/the-worlds-most-expensive-phishing-attacks/">reportedly hijacked the email account</a> of a high-level executive, before impersonating the firm’s CEO.</li>
</ul>
<h2>Protecting your inbox</h2>
<p>If you’re a home user, be sure to use a strong, unique password or passphrase for every account and store it in a reputable password manager. Alternatively, use a passwordless method such as a passkey. At any rate, do turn on multi-factor authentication – these days, it’s almost always available. Keep your recovery options up to date, and make sure an attacker can’t use an old phone number or forgotten backup email address to regain access.</p>
<p>It’s also worth checking your email settings from time to time. Look for unfamiliar forwarding rules, strange filters, unknown connected apps or devices you don’t recognize. If your inbox has been compromised, change the password, revoke suspicious sessions, review recovery details and check whether messages are being forwarded without your knowledge.</p>
<p>Other security best practices include:</p>
<ul>
<li>Be phishing aware. Treat any unsolicited email with caution. Hover over the sender name to check for a mismatch. Check the spelling of sender domains for any typos. Don’t click on any links or open attachments in unsolicited emails. Check separately with the sender if necessary.</li>
<li>Don’t approve any device code or MFA alerts (e.g., on your mobile) that you didn’t trigger, as it could be a hackers trying their luck.</li>
<li>Ensure your recovery options are clear and up to date.</li>
<li>If you’re an employee, treat any urgent wire transfer requests with caution, even if it looks like it&#8217;s from your CEO or IT department. Verify with a colleague/through a separate channel.</li>
<li>Treat employee security awareness training seriously, noting the latest phishing tactics and techniques that fraudsters are using.</li>
<li>Use a comprehensive security solution from a trusted provider to keep you safe from malware and suspicious messages.</li>
</ul>
<p>Virtually everyone uses email. That makes it an evergreen target for hackers. But not everyone’s inbox has to be exposed. Take suitable precautions to maximize your chances of staying safe online.</p>
<p><iframe title="" src="https://www.youtube-nocookie.com/embed/lkOtMJeP8LI"></iframe></p>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/cybersecurity/inside-inbox-cybercriminals-want-break-email-account/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/why-cybercriminals-want-to-break-into-your-email-account/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A phishing attack that doesn’t steal your password</title>
		<link>https://cyberwiredaily.com/a-phishing-attack-that-doesnt-steal-your-password/</link>
					<comments>https://cyberwiredaily.com/a-phishing-attack-that-doesnt-steal-your-password/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 12:54:14 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/a-phishing-attack-that-doesnt-steal-your-password/</guid>

					<description><![CDATA[A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages Much has been written about how the days of phishing emails laden with broken grammar and crude design are numbered, largely thanks to AI. Meanwhile, EvilTokens offers a somewhat different example of how far [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/06-26/eviltokens-device-token-theft.jpg" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/06-26/eviltokens-device-token-theft.jpg" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>Much has been written about how the days of phishing emails laden with broken grammar and crude design are numbered, largely thanks to AI. Meanwhile, EvilTokens offers a somewhat different example of how far the phishing craft has moved.</p>
<p>EvilTokens is a phishing-as-a-service (PhaaS) kit built to compromise Microsoft 365 accounts by abusing the <a href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code">OAuth 2.0 device authorization grant flow</a>. As attacks that use the kit rely on device code phishing, they sidestep the need for convincing replicas of genuine login pages where the victims would hand over their passwords. Instead, attackers get the victim to complete a legitimate authentication process – including two-factor authentication (2FA) – on a real Microsoft login page.</p>
<p>The toolkit has been advertised via Telegram channels and spotted in active attacks since at least February 2026. As documented by <a href="https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/">Sekoia</a> and others, the kit appears to have been quickly adopted by cybercriminals and deployed in a number of account takeover and business email compromise (BEC) attacks, including for a <a href="https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html">campaign</a> targeting more than 340 organizations in several countries in March 2026. Microsoft itself has also <a href="https://www.theregister.com/security/2026/04/07/hundreds-compromised-daily-in-microsoft-device-code-phishes/5222742">described</a> an AI-enabled campaign that used dynamic device-code generation and bespoke lures to increase the success rate of EvilTokens attacks.</p>
<h2>The inner workings of EvilTokens</h2>
<p>Here’s a brief overview of how attacks leveraging EvilTokens unfold:</p>
<ul>
<li>The attack itself is preceded by ‘reconnaissance’ where the ne’er-do-wells first verify that the target account is active. Microsoft has seen this reconnaissance run 10 to 15 days ahead of the actual phishing attempt.</li>
<li>The victim receives an email or message that’s often dressed up as an invoice, shared document, calendar invite, or SharePoint access request. The lure involves a decoy page impersonating a trusted brand or service, along with simple wording such as “Verify to view” or “Signature required.”</li>
<li>When the victim clicks through, the page requests a device code from Microsoft. The code is valid only for 15 minutes, hence time and timing are of the essence here. The page shows the victim the code along and points them to Microsoft’s genuine microsoft.com/devicelogin login portal. The catch is that the code belongs to the attacker’s session, hence the victim unknowingly authorizes the attacker’s device, not their own.</li>
<li>Seeing a valid sign-in, Microsoft issues access and refresh tokens to the session opened by the attacker. Once inside, the criminals can access corporate email, files, Teams, SharePoint, OneDrive, and other Microsoft 365 resources and exfiltrate data or prepare BEC attacks, which is why finance, HR, logistics, and sales accounts draw much of the attackers’ interest.</li>
</ul>
<h2>What makes EvilTokens dangerous</h2>
<p>The OAuth device code flow was designed for devices that may be awkward to sign into directly, such as smart TVs or printers. The device displays a short code that the user enters on a Microsoft page on another device, often a smartphone, and completes authentication there. Microsoft then issues access tokens to the device that requested access.</p>
<p>That separation is useful, but it leaves room for abuse. Attackers can generate the code and dupe the victim into entering it – all while Microsoft only sees a valid authentication flow. The company <em>does</em> warn users at the moment of sign-in via on-screen text telling them not to enter codes from sources that they don’t trust. However, a convincing decoy is sometimes enough to get the victim to read past any warnings.</p>
<p>Speaking of which, EvilTokens strips out many of the red flags that people have been taught to notice over the years, including misspelled domain names and fake login pages. The login page is real and, from the victim’s point of view, the entire authentication process can appear to work as expected.</p>
<p>The attack also ‘muddies the waters’ when it comes to safeguards provided by 2FA. While the second authentication layer has never been more important, it falls short when the victim approves the wrong session. In these attacks, attackers don’t subvert 2FA through any technical wizardry – rather, they simply dupe the victim into completing 2FA for them.</p>
<h2>How to reduce the risk</h2>
<p>Phishing protection tips clearly can’t stop at “check the link,” let alone “look for typos.” Those habits still help, of course, but they don’t hold up against modern attacks, especially those that abuse real authentication flows.</p>
<p>Here are a few tips for staying safe from EvilTokens:</p>
<ul>
<li>Think of any unexpected request for an authentication code as suspect. No document, invoice, email, or another platform should ask for a device code without a clear reason. If the request arrives out of nowhere, flag it to your employer’s IT or security team.</li>
<li>Context matters more than the page. Before approving any sign-in request, check which app is asking for access, which account is involved, and whether you actually started the action. A real Microsoft page doesn’t automatically make a request safe.</li>
<li>Organizations should restrict device code flow outright where it’s not needed. Microsoft recommends applying Conditional Access policies to block device code flow wherever it isn’t necessary and scope it to specific users, devices, locations, or operating systems.</li>
<li>Watch for unusual device-code authentication, unfamiliar devices, risky sign-ins, suspicious token use, and new inbox rules – any of these can point to trouble.</li>
<li>Security awareness training needs to catch up with the latest tricks up attackers’ sleeves. Employees should understand that modern phishing doesn’t always involve typing a password into a fake page. Sometimes the attacker could ask them to enter a real code on a real page – but for the wrong device.</li>
<li>Employees who receive an unexpected device-code request should notify their company’s IT or security teams, who may need to review sign-in logs, revoke sessions, invalidate refresh tokens, remove malicious inbox rules, and temporarily disable the compromised account.</li>
</ul>
<p>EvilTokens is a reminder that attackers don’t always need to break the front door or steal the key to it. Sometimes they only need to talk someone into opening it.</p>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/a-phishing-attack-that-doesnt-steal-your-password/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why children’s data is a long-term identity risk</title>
		<link>https://cyberwiredaily.com/why-childrens-data-is-a-long-term-identity-risk/</link>
					<comments>https://cyberwiredaily.com/why-childrens-data-is-a-long-term-identity-risk/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 11:35:56 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/why-childrens-data-is-a-long-term-identity-risk/</guid>

					<description><![CDATA[Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe. When we talk about cybersecurity and digital safety in the context of our children, it’s often framed in one of two ways. Either it’s about inappropriate or unsafe content – of the sort [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/06-26/children-identity-risk.png" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/06-26/children-identity-risk.png" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>When we talk about cybersecurity and digital safety in the context of our children, it’s often framed in one of two ways. Either it’s about inappropriate or unsafe content – of the sort that COPPA is meant to regulate in the US. Or it’s about managing the psychological and social impacts of excessive screen time. But there’s an elephant in the room.</p>
<p>Our kids are exposed to many of the same identity, privacy, and data security risks as their parents. In fact they may be even more at risk. Helping them understand how to protect their data and online accounts at an early age is an increasingly important parental responsibility.  </p>
<h2>Why do people want my kids’ data?</h2>
<p>Our children are digital natives. From an early age they might have logins to school accounts, gaming profiles, cloud photos, health records, and accounts with a variety of other apps. All of these contain potentially lucrative data for identity thieves.</p>
<p>Why is this information a popular target? Because from a fraud perspective it has a relatively long shelf life. That means, if it’s stolen and used by a scammer to open a new line of credit, it’s unlikely the victim would find out, until perhaps they apply for their first loan many years later. What’s more, it will have a pristine credit score, meaning the fraudulent application will likely sail through unchecked. Fraudsters might use it as is, or combine it with made-up information to create synthetic identities.</p>
<p>The emergence of AI tools has made it far easier to spin up these fake identities. They might be harder for companies to spot. But when they do finally flag fraud, the impact on your child’s credit history can be severe.</p>
<p>These are not theoretical risks. One <a href="https://www.ftc.gov/system/files/ftc_gov/pdf/csn-annual-data-book-2024.pdf">report reveals the</a> story of risk and compliance professional Renata Galvão, whose identity was stolen at the age of six and used to run up debt in excess of $400,000. It reportedly took her over two decades to clear her name and restore her credit rating. In another case, <a href="https://fortune.com/2024/11/28/parents-stealing-childrens-identities-access-debt-destroying-kids-credit-scores/">Axton Betz-Hamilton was 11</a> when her identity was stolen and used to rack up thousands of dollars in unpaid credit card bills. She only found out when applying to set up her first utility bill at college.</p>
<p>Current data is hard to come by, but the <a href="https://www.ftc.gov/system/files/ftc_gov/pdf/csn-annual-data-book-2024.pdf">FTC claims</a> that child identity theft increased by 40% between 2021 and 2024.</p>
<h2>What could go wrong?</h2>
<p>Children’s data is at risk in other ways. Kids might be digitally savvy enough to set up online accounts, but they’re not always security-smart. They may be more prone to fall for a phishing message; especially if it appears to be sent from a trusted authority or friend. Too-good-to-be-true offers, innocuous-looking quizzes and FOMO-type ads are all more likely to hit home if the target is a credulous 13-year-old rather than a skeptical adult. Kids are also more likely to unwittingly download malware onto their devices or share their passwords and personal info with their peers, compounding security risk.</p>
<figure class="image"><img decoding="async" title="Roblox gamers sharing their experiences after downloading fake versions of Solara. Source: YouTube" src="https://web-assets.esetstatic.com/wls/2026/06-26/roblox-hacked-accounts.png" alt="roblox-hacked-accounts" width="" height=""/><figcaption><em>Roblox gamers sharing their experiences after downloading fake versions of Solara. Source: <a href="https://www.youtube.com/watch?v=E7rFREQGFWo" target="_blank" rel="noopener">YouTube</a></em></figcaption></figure>
<p>But it’s not just our children who represent a potential weak link in the security chain. Research from the <a href="https://www.southampton.ac.uk/news/2025/09/researchers-campaign-to-raise-awareness-of-sharenting-dangers.page">University of Southampton</a> last year found that nearly half (45%) of parents regularly share information about their children online. Sharenting like this increases the risk of it falling into the hands of fraudsters. Around one-in-six children have already experienced at least one form of digital harm, including cyberbullying, privacy breaches, or identity misuse, the study claimed.</p>
<p>There’s also a growing risk that the edtech vendors, school platforms, gaming providers, smart toy makers, social media companies and other firms entrusted with your child’s data are themselves breached. The non-profit <a href="https://www.idtheftcenter.org/publication/2025-data-breach-report/">Identity Theft Resource Center</a> (ITRC) tracked 3322 data breaches in the US last year – an all-time high and a 79% increase from five years ago. Nearly 279 million victims had their data exposed, with the healthcare and education sectors among the top five for breaches.</p>
<p>The proliferation of AI apps is also a privacy risk. Kids may use AI tools with no understanding that they’re actually sharing sensitive information which could end up in the wrong hands if the provider is breached.</p>
<p>Gaming accounts are another attractive target for fraudsters. They contain highly prized assets such as:</p>
<ul>
<li>Your credit card/financial information, for use in fraud</li>
<li>Social graphs that can be used to spam/phish other kids in the same network</li>
<li>Skins, which can be stolen and cashed out</li>
<li>Private chats which may contain monetizable information</li>
</ul>
<p>All of which creates a large potential surface for your child’s personal information to be exposed.</p>
<h2>How to check if something’s gone wrong</h2>
<p>There are several ways to check if your child has had their identity or personal information (including credentials) stolen. The following should all be red flags:</p>
<ul>
<li>Passwords that suddenly don’t work, indicating someone has accessed their account and changed the logins</li>
<li>Missing skins, coins or other items in your child’s gaming account</li>
<li>Notifications about account changes, logins or resets</li>
<li>Purchases that you didn’t authorize</li>
<li>Friends and contacts reporting strange activity or messages from your child’s account</li>
<li>Your child is denied welfare benefits (because someone else is using their Social Security details)</li>
<li>They are denied a student loan or bank account due to a poor credit rating</li>
<li>Your child receives a government notice claiming unpaid taxes (because someone is using their details to register for new jobs)</li>
<li>You receive phone calls or correspondence claiming overdue bills run up by your child</li>
</ul>
<h2>It’s a shared responsibility</h2>
<p>In truth, there are multiple stakeholders involved in protecting your children’s identity data. Parents are the most obvious. But also your school, and the app developers and device makers they are often forced to share information with. No single party can manage and secure the entire data lifecycle.</p>
<p>So what can you do as a parent? Limit data sharing, securely configure account settings, and teach your child best practices.</p>
<p>Start with the data. Take a step back and consider whether it really is necessary to set up that new account, grant permissions to that school app, or “sharent” online. Data minimization is one of the core principles of the GDPR. The less personal information is out there, the lower the risk of it ending up in the wrong hands.</p>
<p>Next, for the accounts they do have, adjust the settings to minimize risk. That means long, strong and unique passwords for every account, stored in a family password manager. That will reduce the risk of brute-force attacks. Switch on multifactor authentication (MFA) where possible to mitigate phishing risks.</p>
<p>Review all the privacy settings on all their apps and social platforms to lock them down to the most secure version. That should mean location sharing/tracking is restricted or turned off. Restrict any in-app purchases so they require your approval. Keep all devices and apps updated so they’re less exposed to hacking attempts. And use in-app parental controls where available to monitor usage and minimize sensitive data sharing.</p>
<p>Apply for a credit freeze for your child’s identity with all three major credit bureaus. This will require some paperwork, but is worth it for the peace of mind that means no third party can apply for credit in their name.</p>
<p>Finally, it’s time to sit down with your kids and explain the importance of identity protection, what’s at stake, and how bad people can steal and use their data – including popular phishing tactics. Teach them the basics of good password management, and how to spot suspicious activity online. Above all, they should feel safe telling you anything.</p>
<p>Keeping your child’s identity safe should not be about restricting their digital world. It’s about giving them the confidence to traverse it safely – now and in the future.</p>
<p><iframe title="" src="https://www.youtube-nocookie.com/embed/RnPJVqMy_00"></iframe></p>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/kids-online/lessons-life-childrens-data-long-term-identity-risk/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/why-childrens-data-is-a-long-term-identity-risk/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What to consider before asking an AI chatbot for health advice</title>
		<link>https://cyberwiredaily.com/what-to-consider-before-asking-an-ai-chatbot-for-health-advice/</link>
					<comments>https://cyberwiredaily.com/what-to-consider-before-asking-an-ai-chatbot-for-health-advice/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Wed, 27 May 2026 11:04:01 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/what-to-consider-before-asking-an-ai-chatbot-for-health-advice/</guid>

					<description><![CDATA[Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe. For better or worse, chatbots are changing the way we think, learn and perceive the world around us. This kind of disruption is manifest in many areas of life, [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/05-26/health-ai-chatbots.jpg" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/05-26/health-ai-chatbots.jpg" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>For better or worse, chatbots are changing the way we think, learn and perceive the world around us. This kind of disruption is manifest in many areas of life, but perhaps one of the most sensitive and often concerning is the growing use of generative AI (GenAI) tools for healthcare. Alongside a number of freely available AI chatbots, major technology companies have moved into consumer-facing health AI with the launches of services such as <a href="https://microsoft.ai/news/introducing-copilot-health/">Copilot Health</a>, <a href="https://openai.com/index/introducing-chatgpt-health/">ChatGPT Health</a>, and <a href="https://www.aboutamazon.com/news/retail/amazon-health-ai-agent-one-medical">Amazon’s HealthAI</a> that models help users interpret their medical records and ask questions about their symptoms, lab results and treatment options.</p>
<p>But there are risks to expecting an AI tool to take on the role of your physician. Also, the risk is not only that users receive the wrong advice, but that they may share deeply sensitive personal information with systems whose privacy protections, data-sharing practices and legal obligations may differ from those of a doctor or hospital, as well as that their data may be exposed to unexpected entities. Misuse of AI chatbots in general is now the number one health technology hazard out there, according to one US patient safety <a href="https://home.ecri.org/blogs/ecri-news/misuse-of-ai-chatbots-tops-annual-list-of-health-technology-hazards">organization</a>.</p>
<h2>From theory to practice</h2>
<p>The reason why the model-builders are launching in this space is obvious: chatbots have become a hugely popular way to search for medical advice. According to <a href="https://microsoft.ai/news/health-check-how-people-use-copilot-for-health/">Microsoft</a>, people talk about their health and the health of their loved ones more than any other topic on their mobile devices. Chatbots are there 24/7 with an answer for everything, dispensed in a confident tone that helps to put nervous patients at their ease.</p>
<p>At a time when national healthcare systems are under growing strain, many individuals would probably self-diagnose with the help of AI before deciding whether to seek medical attention. The time, effort and potential cost of entering the labyrinthine health system rather than triaging at home makes this a popular way of doing things.</p>
<p>Yet concerns are already emerging. The first is of hallucinations or incorrect advice. An Oxford University <a href="https://www.ox.ac.uk/news/2026-02-10-new-study-warns-risks-ai-chatbots-giving-medical-advice">study</a> from February published in <a href="https://www.nature.com/articles/s41591-025-04074-y"><em>Nature Medicine</em></a> found:</p>
<ul type="disc">
<li>Users often didn’t know what information they should share with the LLM</li>
<li>LLMs provided very different answers, even if the questions posed to them varied only slightly</li>
<li>Models often provided both good and bad advice, but users struggled to distinguish between the two</li>
</ul>
<p>“Despite all the hype, AI just isn&#8217;t ready to take on the role of the physician,” warned the study’s lead medical practitioner, Dr Rebecca Payne. “Patients need to be aware that asking a large language model about their symptoms can be dangerous, giving wrong diagnoses and failing to recognize when urgent help is needed.”</p>
<h2>Uncovering the privacy risks</h2>
<p>There are also non-health related risks which should encourage individuals to pause for thought. The most obvious is that sharing sensitive medical information with a publicly available chatbot may mean that data is used to train the model and therefore gets regurgitated out to others. Even unintentionally, models <a href="https://www.bbc.co.uk/news/articles/cdrkmk00jy0o">have been known</a> to accidentally expose data typed in by their users.</p>
<p>Some providers may use data to improve their models unless users opt out, while others make stronger promises not to use health-related information for training. Either way, everybody should know what kind of service they’re dealing with before uploading anything sensitive. Your health data is not like a stolen credit card that can be frozen while the details are replaced and reissued. It’s yours for life, and once shared with an AI tool, it may become a permanent digital record.</p>
<p>On the other hand, most of the main health-focused chatbots promise not to use this data for training purposes. Still, training is only one part of the privacy picture, and the services may not make the same promises about third-party data sharing. Your personal medical information may up in the hands of a data aggregator, a third party that sits between the model provider and your healthcare provider. It might also be shared with advertisers, either directly or via one of these aggregators, although it will usually be anonymized prior to use. Even so, people should be cautious: health data is unusually sensitive, and anonymization doesn’t always remove every risk.</p>
<h3>When breach risk multiplies</h3>
<p>The problem with sensitive data traversing so many organizations is that there’s a greater chance it could be exposed to digital thieves and fraudsters. <a href="https://www.wired.com/story/data-broker-breaches-fueled-dollar209-billion-in-identity-theft-losses/">US lawmakers claim</a> to have identified $21 billion in losses tied to a handful of breaches at data broker firms. Health data is highly monetizable by fraudsters for several reasons:</p>
<ul>
<li>It retains its value for long periods of time, as it can’t usually be replaced or reissued</li>
<li>It could include insurance information with which to submit fake claims or receive medical services in your name</li>
<li>It could be used to blackmail you</li>
</ul>
<p>The more companies that hold this data, the more opportunities there are for hackers to compromise them and steal it. The challenge is that most healthcare AI tools are not regulated by HIPAA as they are classed as consumer rather than enterprise-grade services. That means the providers may not be subject to the kind of strict data protection rules you would normally expect.</p>
<h2>Advice for patients</h2>
<p>So how can you minimize your exposure to the risks of healthcare GenAI? If you are concerned about a medical condition, avoid general-purpose bots and look instead for ones specially designed for answering health-related questions. Review whether the service explains how it handles your data, whether it uses your prompts for training, whether it shares information with third parties, and whether it is covered by HIPAA or an equivalent privacy regime in your country.</p>
<p>Don’t blindly trust the output unless there are citation links to verify it. And even then, don’t take its answers as gospel: always check with a medical professional, and/or an official website (e.g., <a href="https://www.nhs.uk/symptoms/">NHS</a>, <a href="https://medlineplus.gov/">MedlinePlus</a>).</p>
<p>To protect your privacy, consider the following:</p>
<ul>
<li>Never share/upload medical documents, lab results or other sensitive documents with an AI tool unless you understand how the tool handles that data.</li>
<li>Avoid entering names, addresses, insurance details, patient numbers or other identifiers.</li>
<li>Ensure training and chat-history features are switched off.</li>
<li>Share only the minimum information needed for the task.</li>
<li>Assume everything you type in could be retained or exposed, and adjust your prompts accordingly.</li>
</ul>
<p>Ultimately, AI chatbots may be useful for brainstorming questions about a specific condition to ask your doctor, or for explaining a medical term you’re not familiar with. But there’s a big difference between using AI to prepare for care and using it as a substitute for care. Don’t treat a confident answer as a diagnosis, and don’t ignore urgent symptoms because a machine sounded reassuring.</p>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/privacy/what-consider-asking-ai-chatbot-health-advice/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/what-to-consider-before-asking-an-ai-chatbot-for-health-advice/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A stealthy RAT burrowing deep into Android devices</title>
		<link>https://cyberwiredaily.com/a-stealthy-rat-burrowing-deep-into-android-devices/</link>
					<comments>https://cyberwiredaily.com/a-stealthy-rat-burrowing-deep-into-android-devices/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 26 May 2026 10:59:17 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/a-stealthy-rat-burrowing-deep-into-android-devices/</guid>

					<description><![CDATA[The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise Our recent review of threat detections in Brazil surfaced BTMOB, an Android remote access trojan (RAT) that is less notable for detection volume than for the damage it can wreak. The combination of phishing-led delivery, ready-made app-building tooling [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/05-26/btmob-android-malware.jpg" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/05-26/btmob-android-malware.jpg" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>Our recent review of threat detections in Brazil surfaced BTMOB, an Android remote access trojan (RAT) that is less notable for detection volume than for the damage it can wreak. The combination of phishing-led delivery, ready-made app-building tooling and device takeover capabilities makes BTMOB a threat to watch well beyond Brazil or Latin America.</p>
<h2>BTMOB at a glance</h2>
<p><a href="https://malpedia.caad.fkie.fraunhofer.de/details/apk.btmob">First described</a> in February 2025, BTMOB has evolved from the SpySolr malware. Unlike banking trojans, which “only” aim to steal people’s financial credentials or intercept their financial transactions, BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it. The RAT is also sold with an APK builder interface, allowing anyone to generate new payloads and adapt phishing lures for specific regions at a rapid clip – and without writing any code.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/04-26/bt-mob-latam/imagem1.png" alt="Imagem1" width="" height=""/><figcaption>
<p><em>Figure 1. BTMOB APK creation tool</em></p>
</figcaption></figure>
<h2>How does BTMOB spread?</h2>
<p>Unsurprisingly, everything starts with ordinary social engineering. Operators send victims to phishing websites that pose as streaming services, cryptocurrency mining platforms or other familiar online services. From there, victims are pushed toward fake app stores that mimic legitimate repositories and prompt them to install a malicious APK. Bad actors have also been spotted tailoring their lures to specific regions.</p>
<p>Once installed, BTMOB seeks extensive access to the device. As is common these days, it abuses Android Accessibility Services to gain elevated permissions and grant itself further system access without additional user interaction.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/04-26/bt-mob-latam/imagem2.png" alt="Imagem2" width="" height=""/><figcaption><em>Figure 2. Fake app store and malicious apps. Source: <a href="https://x.com/Merlax_" target="_blank" rel="noopener">@Merlax_</a>)</em></figcaption></figure>
<p>Since it’s built for the malware-as-a-service (MaaS) economy, BTMOB is marketed as a software product, including through a promotional page on the open web that funnels prospective buyers to a Telegram operator. The sales pipeline extends across social media platforms, with a number of accounts on X and Instagram actively peddling the tool. </p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/04-26/bt-mob-latam/imagem3.png" alt="Imagem3" width="" height=""/><figcaption><em>Figure 3. BTMOB offer on the surface web</em></figcaption></figure>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/04-26/bt-mob-latam/imagem4.png" alt="Imagem4" width="" height=""/><figcaption><em>Figure 4. X profile linked to the malware</em></figcaption></figure>
<p>Once someone purchases the malicious kit, they can adapt its features, including the phishing lures so they impersonate the brand or agency most likely to lure victims in any given country. For example, researchers <a href="https://x.com/johnk3r">Johnk3r</a> and <a href="https://x.com/Merlax_">Merl</a> recently spotted campaigns that spread BTMOB while impersonating Argentina’s tax and customs authorities.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/04-26/bt-mob-latam/imagem5.jpg" alt="Imagem5" width="" height=""/><figcaption><em>Figure 5. BTMOB impersonating an Argentine government agency. (Source: <a href="https://www.linkedin.com/posts/%E1%BA%A1dmin_btmob-activity-7364063708106346496-1t5j/?originalSubdomain=es" target="_blank" rel="noopener">Germán Fernández Bacian</a>)</em></figcaption></figure>
<h2>Market dynamics and detection challenges</h2>
<p>Even where developers initially restrict the tool to paying customers, the economics remain favorable for attackers. A reported $5,000 lifetime license plus a monthly support fee is low compared with the returns a successful fraud operation can generate.</p>
<p>In addition, the MaaS model also lowers the barrier for less sophisticated adversaries. In January 2026, a dark web forum claimed to offer BTMOB-related files for free download. The forum later went offline, and our search didn’t recover the payload(s), but the episode points to a familiar risk with commercial malware: access rarely stays contained forever and the tool can move into secondary markets through resale, barter or sharing inside closed groups. Competing malware families can also copy some elements that make payload customization and campaign management easier for less skilled criminals.</p>
<p>As new variants can be generated quickly, defenders should expect rapid payload turnover rather than a stable set of threats. ESET products detect the primary tool as MSIL/BtmobRat, while related Android variants trigger detections such as Android/Spy.Agent.EED, Android/Spy.Agent.EIJ and Android/Spy.Agent.EIK. <a href="https://cyble.com/blog/btmob-rat-newly-discovered-android-malware/">Cyble’s report</a> from February 2025 noted that roughly 15 samples of BTMOB v2.5 had been spotted since late January of that year, i.e., in a mere two or so weeks.</p>
<h2>How to protect yourself</h2>
<p>A few basic tips will go a long way toward staying safe from BTMOB and other Android malware:</p>
<ul>
<li>Stick to the official app store: Attackers rely on fake app stores that mimic Google Play. Organizations should mandate that users download software exclusively from official repositories.</li>
<li>Treat links with suspicion: Be skeptical of unsolicited links delivered via email, messaging apps, social media, and targeted advertisements.</li>
<li>Use security software: Both individuals and organizations should use mobile security solutions and treat mobile devices with the same rigor as other machines and environments. Corporate security teams must make it clear to employees that a single rogue download could exposes the company’s crown jewels.</li>
</ul>
<h2>Indicators of compromise</h2>
<p>Because BTMOB ‘mutates’ quickly, many indicators may age rapidly. Nevertheless, specific infrastructure patterns often recur across different samples and aid in triage. </p>
<h3>IP addresses</h3>
<table border="1" width="100%" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td>74.125.202.103</td>
<td>142.251.183.138</td>
<td>173.194.193.138</td>
<td>173.194.206.106</td>
</tr>
<tr>
<td>178.156.177.192</td>
<td>191.101.131.250</td>
<td>195.160.221.203</td>
<td>104.21.64.137</td>
</tr>
<tr>
<td>173.194.194.94</td>
<td>191.96.224.87</td>
<td>191.96.225.241</td>
<td>191.96.78.172</td>
</tr>
<tr>
<td>191.96.78.28</td>
<td>191.96.79.133</td>
<td>191.96.79.179</td>
<td>191.96.79.41</td>
</tr>
<tr>
<td>192.178.209.95</td>
<td>200.9.155.153</td>
<td>74.125.132.95</td>
<td>78.135.93.123</td>
</tr>
<tr>
<td>79.133.57.141</td>
<td>arbsniper.com</td>
</tr>
</tbody>
</table>
<h3>Hashes &#8211; SHA256</h3>
<div style="overflow-x: auto; margin: 20px 0;">
<table style="width: 100%; border-collapse: collapse; min-width: 400px; font-family: 'Courier New', Courier, monospace;">
<thead>
<tr style="background-color: #f2f2f2; border-bottom: 2px solid #ddd;">
<th style="padding: 12px; text-align: left; font-weight: bold;">Hash Value</th>
</tr>
</thead>
<tbody>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">58AC130A8EBB09E37592AC69841483EDC5695D1545B1F04F23D5B760AC17CD94</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">0A542751724A432A8448324613E0CE10393E41739A1800CBB7D5A2C648FCDC35</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">A764D73795ABE47AE640BA09999A18C47B5340E5ECC7B897AFEBF34F3F37638F</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">26A2268281E8043125EF72B92F8980B42912048753D56894BC378FB54C7C188A</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">6AE94CE710016D86ED7457236DEEF2C4C51478587F3609B6E827A348828B3931</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">E5A9FDFF900DD502E8F3DCE52D2D1B69AA9AFAFB5094A28F9037E8770DB0E63B</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">C6199E175FB988CBBEACDF0F5ACDF9ED83F5BDAAE5C95B7A6C27EE72CD11B0B1</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">6BBA64FA9E8A7B11CB2476CD071DE08986DB44B0783EFF211C68FA5594EF8143</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">5AAAF972C8BF39A98F2748E526DE3CC0370BA831997D7D9765CDABA599645C0D</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">5AAAF972C8BF39A98F2748E526DE3CC0370BA831997D7D9765CDABA599645C0D</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">DDCE0219923D152B8FACD303F058A6286CF1F6924992B9FB9F5BF4D96436CC39</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">D55057CD9110D12A192281356F06B94F342B9FEBB305CF0A5898A7E6AF40758F</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">676CB2D0A60403AFC06CEA1B572CB7261F706365FAC65621B5A4907893E7AC0D</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">75DD4FB011ED598374A46FC0D9C0D1D64A298341C34AFC83A56A6983CFD27764</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">702261BA38B57ECC3A5407FED28B2F0611A74C2EC0C116AEA4F9E6DEF0899AED</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">998A7ED1572AD9DC11375BC25294E1954E606B7CFF9FABC5C120713E597CD274</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">244D81FD9908CD17815501D4EDADEB1BAF1C421AA25D8BD61C7CB481C939540E</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">512EDE9F2FA794907999F3C26165557FDFD383B7AAD71BA022CE2C8BA6C0019D</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">7AC974899E8E05AAACD417577C97E382D5E8C5F7F4A85632CFFB47EC2F6AE4E0</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">168F50BF9A87099094EF410E3AC33E676A6A8740A5437CD09E7B63D73DF8431A</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">2525D1E427A9983B0B4CA0906A4B44FFB9814B23D53FD8A2E3AB6512B027C733</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">6101D1E1811DB052F869F7EB3402DAD28DA7E92103D4A44EE43F95846A075012</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">1A60CB5F7E2FB7C09FC3DC8459108B26AC98EE73131F37A28CFDAD5FC75B7A7D</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">97A0497DE585D3BE6EC75064AB3BD0979CD85561193C1F0669CCF4DB31330687</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">02A52C4CC11748D44C9B49D508EE4E46425661981FA1406F30EC0830CB69DDC5</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">6F9832EBB4C3054BEE4A6CE5CCB69C00E2020053E1308353343097E6A4041109</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">F76B13040C634F82A8332FF9443D84C89A5BCED51AE9ADAD7FD15C05FADB4324</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">C99139B0053C4C698EA0246D26D747F2A984C7ABA4613DA818ECD9F97899EF3A</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">8F09274E808E0063D51F34CAC82A5770B3DF30C792E426DA2F6A80657F27AFFC</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">140A7F995B0336942691A2E93E2017FD575267C017C7D0728D69169306F91963</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">A1E457C52EAB430C20D48F2AC476E080386313F16EFB135A0471902CF68CE475</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">5A4E86BBCF0EBC455D2995DB225D9AD682E9B37B6BAD472A604A462099D988BD</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">A892F1EF2E530D67BF948A48C734DA3F27718EB8B883CA0B686DDB0A81071731</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">AA56F350882CE63429C6626567487B041F06168BB60F4FC371A262EABADFA660</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">752C1CFE783ED343E470AB95A4843A23872CDC98B7D3ED5633DD6C881C071A14</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">0628AD6D1FD836B13B22E75FA169502D8CE78B7AD20F0261EB5151DA98437BCA</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">6844CE1539014571360495C6FB50965E813C2721663BDD40D577D9E5163773C6</td>
</tr>
</tbody>
</table>
</div>
<h3>ESET detection names</h3>
<div style="overflow-x: auto; margin: 20px 0;">
<table style="width: 100%; border-collapse: collapse; min-width: 300px; font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif;">
<thead>
<tr style="background-color: #f2f2f2; border-bottom: 2px solid #ddd;">
<th style="padding: 12px; text-align: left; font-weight: bold;">Detection name</th>
</tr>
</thead>
<tbody>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">Android/Agent.FQK</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">Android/TrojanDropper.Agent.NES</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.EIJ</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.EIK</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">Android/TrojanDropper.Agent.NDK</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Spysolr.A</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.EUG</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.EWN</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.FFE</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.FFL</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.ELM</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.FFM</td>
</tr>
<tr style="border-bottom: 1px solid #ddd;">
<td style="padding: 10px; word-break: break-all;">Android/Spy.Agent.FEE</td>
</tr>
<tr style="border-bottom: 1px solid #ddd; background-color: #f9f9f9;">
<td style="padding: 10px; word-break: break-all;">Android/TrojanDropper.Agent.NBO</td>
</tr>
</tbody>
</table>
</div>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/a-stealthy-rat-burrowing-deep-into-android-devices/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Scams target soccer fans with fake World Cup tickets, merchandise</title>
		<link>https://cyberwiredaily.com/scams-target-soccer-fans-with-fake-world-cup-tickets-merchandise/</link>
					<comments>https://cyberwiredaily.com/scams-target-soccer-fans-with-fake-world-cup-tickets-merchandise/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Fri, 22 May 2026 10:23:09 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/scams-target-soccer-fans-with-fake-world-cup-tickets-merchandise/</guid>

					<description><![CDATA[Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data As the FIFA World Cup 2026™ in the United States, Canada, and Mexico draws closer, anticipation is building toward fever pitch. Many soccer fans may still be hunting for tickets, merchandise, travel and hospitality packages [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/05-26/sitios-falsos-word-cup-fifa/fake-fifa-websites.jpg" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/05-26/sitios-falsos-word-cup-fifa/fake-fifa-websites.jpg" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>As the FIFA World Cup 2026<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> in the United States, Canada, and Mexico draws closer, anticipation is building toward fever pitch. Many soccer fans may still be hunting for tickets, merchandise, travel and hospitality packages – and scammers know exactly how to exploit this demand. In other words, many people are already in the state of mind that scammers count on: interested, impatient and, indeed, maybe a little worried that the tickets or other goods will sell out. Which is ultimately what makes these scams so effective.</p>
<p>ESET researchers in Latin America recently spotted a number of websites that are built for this very moment. Posing as the FIFA association or the official World Cup website, the imposter sites target people looking for tickets and merchandise, then steer them through fake registration and payment flows that steal their money and personal data. The series of steps is often actually the same as on the genuine World Cup website: register, add tickets for a game, jerseys or other merchandise to the cart, and pay.</p>
<p>Some victims may reach these websites through sponsored search results, while others click on ads on social media or links in email messages forwarded by someone who didn’t check the address properly. Whatever the scenario, here’s what you should know about fake FIFA- and World Cup-themed websites – and how to avoid scoring an ‘own goal.’</p>
<h2>First sample</h2>
<p>One of the fake sites, hosted at <span style="font-family: courier new, courier, monospace;">https://***fifa26[.]shop</span>, uses a domain that looks close enough to FIFA and the 2026 World Cup to catch a hurried visitor. Indeed, many sites set up in the run-up to major events will rely on a common trick known as typosquatting, which involves on a domain name that closely resembles the legitimate one, but contains small additions or involves other changes in the domain name that the victim often won&#8217;t notice.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-1.jpg" alt="sitio-falso-fifa-mundial-26-1" width="" height=""/><figcaption><em>Figure 1. Fake site impersonating the official FIFA World Cup 2026<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> website</em></figcaption></figure>
<p>The trickery doesn’t stop there, however. The site also copies the look and feel of FIFA’s official site, including the colors, layout, navigation and ticketing flow, all in order to make the victim feel that the experience is legitimate.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-2.jpg" alt="sitio-falso-fifa-mundial-26-2" width="" height=""/><figcaption><em>Figure 2. This website is an imposter</em></figcaption></figure>
<p>And here, for comparison, is the legitimate website:</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-3.jpg" alt="sitio-falso-fifa-mundial-26-3" width="" height=""/><figcaption><em>Figure 3. Official FIFA World Cup 2026<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> website</em></figcaption></figure>
<p>But back to the fake website – here’s what happens if you want to “purchase” tickets or merchandise. Much like the official FIFA site, the imposter site also asks you to register. If you expect to create a FIFA ID before buying tickets, a fake registration form may not look strange at first. It also asks for the usual things such as your name, email address, and phone number. Nothing about that feels unusual if you believe you are on FIFA’s official website.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-4.jpg" alt="sitio-falso-fifa-mundial-26-4" width="" height=""/><figcaption><em>Figure 4. This site does not sell World Cup tickets</em></figcaption></figure>
<p>Meanwhile, Figure 5 shows the registration step on the official website.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-5.jpg" alt="sitio-falso-fifa-mundial-26-5" width="" height=""/><figcaption><em>Figure 5. User registration on the official FIFA website – noe the URL in the green rectangle</em></figcaption></figure>
<p>The bogus website also offers what appears to be official merchandise. The point is to keep you inside a familiar shopping routine long enough for the payment page to feel like the next expected step.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-6.jpg" alt="sitio-falso-fifa-mundial-26-6" width="" height=""/><figcaption><em>Figure 6. Fake FIFA website</em></figcaption></figure>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-7.jpg" alt="sitio-falso-fifa-mundial-26-7" width="" height=""/><figcaption><em>Figure 7. Bogus store offering team jerseys</em></figcaption></figure>
<p>It allows you to select any product and add it to the shopping cart:</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-8.jpg" alt="sitio-falso-fifa-mundial-26-8" width="" height=""/><figcaption><em>Figure 8. Fake shopping site posing as the official FIFA online store</em></figcaption></figure>
<p>Once you enter your card details, it goes straight to the people behind the fake site – and there’s no jersey coming from FIFA, of course.</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-9.jpg" alt="sitio-falso-fifa-mundial-26-9" width="" height=""/><figcaption><em>Figure 9. &#8220;Purchasing&#8221; a soccer jersey on the fake phishing site</em></figcaption></figure>
<p>The ticket flow works the same way. After registration, the bogus site lets you select supposed World Cup matches, move toward checkout, and reach a payment page. </p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-10.jpg" alt="sitio-falso-fifa-mundial-26-10" width="" height=""/><figcaption><em>Figure 10. Fake user registration form for World Cup tickets</em></figcaption></figure>
<p>You can choose the desired match, in any stage of the tournament:</p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-11.jpg" alt="sitio-falso-fifa-mundial-26-11" width="" height=""/><figcaption><em>Figure 11. Bogus payment gateway for World Cup tickets</em></figcaption></figure>
<p>And then, it leads to the shopping cart. Once entered into the form, your payments details would travel into the hands of the cybercriminal behind the bogus site. </p>
<figure><img decoding="async" title="" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/sitio-falso-fifa-mundial-26-12.jpg" alt="sitio-falso-fifa-mundial-26-12" width="" height=""/><figcaption><em>Figure 12. Fraudulent page requesting credit card details for a supposed ticket purchase</em></figcaption></figure>
<p>The obvious loss is money, but the quieter loss is financial and identity data. A full name, email address, phone number and reused password can be misused by attackers beyond any single fraudulent website. If the same password opens your email or social media account, the fake FIFA registration can become the first step in another, and quite possibly even more damaging, attack. </p>
<h2>Four more sites riffing on the same theme</h2>
<p>Another fake site, <span style="font-family: courier new, courier, monospace;">https://****26-fifa[.]com</span>, follows the same pattern. The domain is World Cup-themed, the site uses FIFA’s visuals, and the visitor is pushed toward registration before being offered purported tickets and merchandise.</p>
<figure class="image"><img decoding="async" title="Figure 13. Other fake sites impersonating the FIFA World Cup 2026 website" src="https://web-assets.esetstatic.com/wls/2026/05-26/sitios-falsos-word-cup-fifa/fake-world-cup-websites.jpg" alt="fake-world-cup-websites" width="" height=""/><figcaption><em>Figure 13. Some other fake sites</em></figcaption></figure>
<p>The fake World Cup websites in general, including the menu tabs and other visual cues, are designed to look as closely as possible the official one. The top-level domain names matter, too – a .shop or .store domain may make a fake website feel like a retail offshoot, especially when the rest of the URL address contains “fifa” and everything about the site looks polished.</p>
<h2>Tactics for staying safe</h2>
<p>Crucially, <a href="https://www.fifa.com/en/tournaments/mens/worldcup/canadamexicousa2026/articles/how-where-and-when-can-i-buy-tickets-hospitality">FIFA has made it clear</a> that World Cup tickets can only be bought via three official channels – <a href="https://www.fifa.com/tickets">fifa.com/tickets</a>, <a href="https://www.fifa.com/hospitality">fifa.com/hospitality</a>, and special Qatar Airways travel packages (which may actually be sold out by now). It follows then that you’re best off steering clear of various third-party sellers or social media listings.</p>
<ul>
<li>Go to <a href="https://www.fifa.com/en">FIFA’s official website</a> directly. Type the address yourself; i.e., start from FIFA.com or <a href="https://www.fifa.com/en/tickets">FIFA’s ticketing portal</a>, not from an ad, a social media post or a link someone has sent to you.</li>
<li>Look closely at the domain name before entering any information. Extra characters, words, odd endings and near-matches could be the only visible clue that the site is not what it claims to be.</li>
<li>Be careful with offers built around pressure: “limited tickets,” “VIP access,” “discounts,” “last chance,” or anything that rushes you into action and makes checking feel like a delay you can’t afford.</li>
<li>Avoid reusing passwords. If a fake registration page steals a password that you also use for your email, social media or banking account, the problem could follow you way beyond the fake site.</li>
<li>And don’t let a checkout flow reassure you. A working cart and a payment form don’t prove that the seller is legitimate.</li>
<li>Protect all your accounts with strong, unique passwords and two-factor authentication, as well as use security software on all your devices.</li>
</ul>
<p>The countdown to the World Cup gives criminals a ready-made audience: countless people hunting for tickets, merchandise and various last-minute opportunities. The fake FIFA sites show how that demand is being turned into a phishing flow, one familiar click at a time. Stay safe!</p>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-tickets/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/scams-target-soccer-fans-with-fake-world-cup-tickets-merchandise/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The quest for greater tech independence</title>
		<link>https://cyberwiredaily.com/the-quest-for-greater-tech-independence/</link>
					<comments>https://cyberwiredaily.com/the-quest-for-greater-tech-independence/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 19 May 2026 10:04:51 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/the-quest-for-greater-tech-independence/</guid>

					<description><![CDATA[The Trump administration’s shift in tone and approach toward traditional allies has understandably unsettled many nations, raising doubts about U.S. reliability and concerns over dependence on American technology. Many had become used to China and Russia&#8217;s often belligerent tone, flexing their economic and military muscles, but watching the world’s most powerful nation and flag bearer of [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p>The Trump administration’s shift in tone and approach toward traditional allies has understandably unsettled many nations, raising doubts about U.S. reliability and concerns over dependence on American technology. Many had become used to China and Russia&#8217;s often belligerent tone, flexing their economic and military muscles, but watching the world’s most powerful nation and flag bearer of liberal democracy reach for similar tactics against its friends has certainly been a wake-up call. </p>
<h2>Europe’s push for tech sovereignty </h2>
<p>In Europe, calls for greater tech sovereignty – the ability to choose and act independently, autonomously, and securely – have become almost deafening. The often rather philosophical debates about strategic autonomy or sovereignty have been ongoing within deliberations on defense and energy for several years now, most prominently following Russia’s full-scale invasion of Ukraine in February 2022. However, concern about an over-reliance on China as a market, a source of goods and a supplier of critical minerals had been bubbling away years before that.</p>
<p>In the last year or so, this concept has visibly seeped into a whole spectrum of industrial and economic policies, digital technologies notwithstanding. Conceptual policy ideas and approaches started to take the form of specific policy proposals and initiatives, currently culminating in a line of legislative measures being put on the table. However, reducing dependencies layered over decades will not be easy. Alternative sources of critical technologies and materials will need to be found or, ideally, developed locally, which requires a complex approach cultivating the right ecosystem more conducive to technological innovation in Europe. At a minimum, it has to facilitate digital infrastructure investments, retain and attract needed talent and nurture home-grown tech companies while giving them space to scale.</p>
<p>US firms dominate the tech space, with profits from their international business arguably helping cement their dominance, often through investment in R&amp;D, healthy marketing budgets, and acquisition – including of talent and emerging start-ups from around the globe, Europe not being the exemption.  And it makes sound business sense for them to do so. Additionally, when it comes to tech, early movers with large investment often stay first, which presents Europe with a two-fold challenge – unleashing the competitiveness on its market without reinforcing the position of established leaders.</p>
<p>In this context, the US has also been quick to robustly defend its tech industry in other nations, particularly against what it views as attempts to overregulate and/or seek to narrow the trade surplus in services that the US generally enjoys. Countries or bodies like the European Union taking a leaf out of the assertive US goods trade playbook and turning it against the US in services is not appreciated in D.C and US ringfencing remains.</p>
<p>The technology landscape is becoming increasingly political, and US technology firms are certainly not immune to growing domestic political pressures. For example, a Microsoft representative <a href="https://www.forbes.com/sites/emmawoollacott/2025/07/22/microsoft-cant-keep-eu-data-safe-from-us-authorities/">acknowledged</a> under oath in a French Senate inquiry that the company could not guarantee full digital sovereignty if US authorities requested access to data stored on Microsoft servers abroad, as permitted under the US CLOUD Act. It has also been <a href="https://apnews.com/article/icc-trump-sanctions-karim-khan-court-a4b4c02751ab84c09718b1b95cbd5db3" target="_blank" rel="noopener">reported</a> that Microsoft cancelled services to the International Criminal Court’s chief prosecutor following the decision to open an investigation into actions by <a href="https://www.ap.org/news-highlights/best-of-the-week/second-winner/2025/ap-exclusive-exposed-how-trump-sanctions-have-halted-the-work-of-the-international-criminal-court/">Israeli officials in Gaza</a>, to comply with US sanctions. Rumours of backdoors for intelligence agencies (who work with tech firms) and kill switches add to the concern.</p>
<h2>Assessing risks </h2>
<p>But of course, it is not just the US that uses trade as a geopolitical lever. Every continent (including Europe) has countries willing or inclined to use such methods, making it essential to factor in the political risk of alternatives. Over the last year in the EU, several groups of countries have coalesced around more or less political approaches to tech sovereignty. The emphasis on operational, technical and legal control over the technology is seemingly presented as being at odds with focusing primarily on the country or origin or geographical location of the infrastructure. On the other hand, the fears of a potential kill switch being used against Europe in a confrontation further fuel the political considerations of digital sovereignty, potentially impacting the quality of evidence-based policy debate rooted in legal and technical realities.</p>
<p>A further challenge arises from the differing cultural and regulatory approaches to technology governance. Despite America First, the US generally prioritizes market openness and international competitiveness, whereas the EU places stronger emphasis on consumer protection, public safety, competition enforcement and now digital sovereignty. Some worry that by accepting US tech, they are forced to accept a US approach that is at odds with their own values. Digital sovereignty is gaining traction beyond political and policy circles – with civil society groups, as well as nationalist narratives, precisely because it appears conducive to enforcing a European digital rulebook providing the usual safeguards on the market. Proponents of digital sovereignty therefore tend to stress the legal jurisdiction under which the tech operates. This bears the risk of hijacking the debate and getting carried away on an ideological wave to the detriment of the European innovation ecosystem. Without maintaining reasonable openness, home-grown technologies will struggle to thrive.</p>
<p>Political weaponization of tech is not the only concern. The CrowdStrike outage in 2024 affected several large businesses, including those in the important aviation sector. IT systems can fail and be vulnerable to attacks. Certainly, there seems to be a steady flow of vulnerabilities that can be exploited, including zero-days. This is where the EU’s enhanced focus on ICT supply chain security comes into foreground complementing the initiatives specifically aimed at tech sovereignty. The proposed framework for identifying high-risk vendors in ICT supply chains under the revised Cybersecurity Act aims to provide a comprehensive methodology merging political, legal and technical considerations for excluding high-risk suppliers. This approach aims to increase European control and jurisdiction over critical supply chains, as well as potentially create space for the growth of European alternatives replacing excluded vendors.</p>
<p>In response to growing demands for national tech sovereignty and protection of local competitiveness in various regions around the world, several US tech firms have begun offering “sovereign” solutions tailored to foreign jurisdictions. While these initiatives, such as those in Europe, are intended to address concerns over data governance and operational autonomy, some analysts note that such models may still rely heavily on US-based infrastructure, legal frameworks, and corporate oversight. Critics, including many Members of the European Parliament, call this “tech sovereignty washing”. Similar questions hang over certain domestic providers that market their services as sovereign solutions, yet continue to depend on US origin technology at the core of their platforms, creating uncertainty about the extent to which these offerings can genuinely deliver independent control. </p>
<p>While criticism is currently focused on the US (and China), we should also recognize that relationships between nations can shift over time. Membership in the same grouping, whether the EU, ASEAN, the African Union, or others, does not guarantee that one member might not use technological leverage against another during a dispute. Political leadership and policy priorities can change rapidly, and with them, the dynamics of trust and cooperation. Some may point to legal frameworks or contracts as reassurance, but arguably these matter little when nation states decide to use their own legal sway over their companies and those that want to operate in their market. The challenge for policymakers is to translate supportive words and sentiment on securing greater tech sovereignty and digital independence into meaningful action.</p>
<h2>Trusted cyber defenses made in Europe </h2>
<p>In cybersecurity, there are credible alternatives available – ESET is one strong example, though certainly not the only one. Many European firms are working hard to compete globally. Ultimately, organizations need to understand and reduce their exposure risks, adopting trusted solutions that are tailored to each case and that ensure strong compliance with strict data protection frameworks, such as the GDPR. </p>
<p>Across the EU, there is also a growing discussion about adapting public procurement processes and public funding schemes to favor such alternatives. Increasing the awarding of public contracts (rather than grants) could be an effective way to stimulate business growth while reducing costs for taxpayers. Switching providers should also be made easier through greater and built-in interoperability, mitigating “technical lock-ins” and easing switching costs. The European Cybersecurity Organisation (ECSO) has <a href="https://ecs-org.eu/ecso-uploads/2025/11/ECSOs-Strategic-Vision-European-cybersecurity-2030_v4.2.1.pdf">advocated</a> for a dedicated industrial strategy for cybersecurity, given its strategic importance. We await the details of the European Commission’s “Tech Sovereignty Package” due at the end of May, as well as the potential revision of public procurement rules under the Public Procurement Act to see tangible, realistic and hopefully practical measures aimed at nurturing and scaling European alternatives. </p>
<p>Primarily, it is critical to strike the right balance between fluid political and objective technical considerations when setting out criteria defining a “made in Europe” solutions. Sovereignty should not be reduced to the geographical origin of a provider. Greater weight should be placed on objective indicators of how a solution delivers operational autonomy and legal insulation from non-EU jurisdictions. Finally, given the complexity of the challenge and the vastness of the gap that the EU aims to close, it is also necessary to be realistic about timelines and certain specific types of technologies where achieving sovereignty is unlikely for Europe in a short or even medium term. In such cases, a reasonable share of EU-made components in the final product should be a sufficient step towards incrementally increasing domestic capacity. This could be coupled with the assessment of critical functions of a product which should be based (or at least majority of them) on EU-made technology.</p>
<p>The private sector also has a vital role to play by considering technological sovereignty, geopolitical risk and supply chain vulnerabilities within its procurement decisions. If the private sector also aligns itself to the cause, the take-up of alternatives and stimulus would be widely felt. One risk, however, is that support becomes concentrated on just one or two national/regional firms – a mistake that could undermine the sector. Healthy competition drives lower prices, greater innovation, and reduces strategic vulnerability should any single company fail or encounter difficulties. </p>
<p>The geopolitical landscape has shifted significantly. A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies. Risks that were barely considered only a few years ago must now be recognized, understood, mainstreamed and actively mitigated. </p>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/cybersecurity/quest-greater-tech-independence/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/the-quest-for-greater-tech-independence/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why geopolitical turmoil is a gift for scammers, and how to stay safe</title>
		<link>https://cyberwiredaily.com/why-geopolitical-turmoil-is-a-gift-for-scammers-and-how-to-stay-safe/</link>
					<comments>https://cyberwiredaily.com/why-geopolitical-turmoil-is-a-gift-for-scammers-and-how-to-stay-safe/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Fri, 15 May 2026 09:48:45 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/why-geopolitical-turmoil-is-a-gift-for-scammers-and-how-to-stay-safe/</guid>

					<description><![CDATA[Conflict is a boon for opportunistic fraudsters. Look out for their ploys. It didn’t take long for tensions in the Middle East to spill over into the cyber domain. There’s been significant disruption of a major US medtech provider, the compromise of OT assets in US critical infrastructure, and ongoing ransomware attacks on businesses by [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">Conflict is a boon for opportunistic fraudsters. Look out for their ploys.</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/05-26/geopolitical-turmoil-2.jpg" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/05-26/geopolitical-turmoil-2.jpg" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>It didn’t take long for tensions in the Middle East to spill over into the cyber domain. There’s been significant disruption of a major <a href="https://www.stryker.com/us/en/about/news/2026/a-message-to-our-customers-03-2026.html">US medtech provider</a>, the compromise of OT assets in US <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a?utm_source=IranPLC202604&amp;utm_medium=GovDelivery" target="_blank" rel="noopener">critical infrastructure</a>, and ongoing <a href="https://www.infosecurity-magazine.com/news/iranlinked-pay2key-ransomware/" target="_blank" rel="noopener">ransomware attacks</a> on businesses by Iran-nexus groups. But what about regular internet users? The truth is that geopolitical tension and conflict offers potentially rich pickings for opportunistic online scammers.</p>
<p>Fraudsters know that these events are a great way to grab the attention of potential victims, and exploit their fear and sympathy in equal measure. The backdrop of geopolitical turmoil, whether it’s Ukraine or Iran, adds weight to the stories they spin in order to achieve their goals.</p>
<h2>What scams prosper in times of turmoil?</h2>
<p>Whatever tactics they choose, the end goal is usually the same: to harvest your credentials and/or personal and financial data. Or to trick you directly into making payments to non-existent entities. These are not novel techniques. They’re tried and tested and could come via email, text, social media or phone call. What’s different is the lure; specially crafted for timeliness and maximum impact.</p>
<p>Watch out for the following scams:</p>
<h3>Fraudulent charges</h3>
<p>You receive a call or text from a bank or trusted company informing you of non-existent charges related to “Iran” on your account. According to the <a href="https://consumer.ftc.gov/consumer-alerts/2026/03/how-scammers-are-using-iran-conflict-try-steal-your-money-and-information" target="_blank" rel="noopener">FTC</a>, you might then be put on to a government official who convinces you to hand over your bank account details.</p>
<h3>Romance fraud</h3>
<p>Romantic-themed scams are a big money-maker for fraudsters. <a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">According to the FBI</a>, they generated over $929m in illegal profits last year. In this new take, a romantic contact you met online may claim to be a soldier deployed to the Middle East, who now needs cash to deal with an emergency.</p>
<h3>Fake charities</h3>
<p>Geopolitical turmoil often leads to human misery, which tends to pull at the heart strings. Legitimate charities may solicit donations to help their efforts to support innocent citizens caught in the crossfire. Scammers know this and will create their own fake charities – or impersonate legitimate ones – to collect donations. They may have professional-looking websites designed to add weight to their requests. Be in no doubt though, if you fall for these scams you’ll end up handing them your money, your card details, or both.</p>
<p><strong>Travel scams</strong></p>
<p>Military conflict can often result in sudden flight cancellations, border checks and other travel-related disruption. Scammers can take advantage of this by impersonating airlines and government agencies. They might offer streamlined visa processing or <a href="https://www.theguardian.com/money/2026/mar/15/travel-scam-airline-accounts-fake-refunds-iran-war-flight-disruption">refunds on booked flights and accommodation</a>. But all they’re after is your personal and financial details.</p>
<h3>Investment fraud</h3>
<p>Investment scams raked in more money than any other type of cybercrime last year: over $8.6 billion, according to the FBI. Sure enough, scammers can take advantage of geopolitics to further their goals here, perhaps by claiming to offer guaranteed returns as a hedge against inflation or market instability.</p>
<h3>Sensational (fake) news</h3>
<p>Political and social unrest usually generates a great deal of click-worthy content. The problem is that some of it is complete fake. Scammers use sensationalist ‘leaked videos’ and ‘breaking news’ stories to lure you into clicking on malicious links. The most likely end result is getting an infostealer on your phone or computers. This category of malware is designed to harvest passwords, record keystrokes and even steal session cookies to bypass multi-factor authentication (MFA) on your accounts.</p>
<h3>Advance fee fraud/419 scams</h3>
<p>This is perhaps one of the oldest scams in the book. You receive a message out of the blue from someone you’ve never met. They’ll proceed with a fantastical story about how they will let you share in their riches if you can only pay a small fee upfront for some kind of admin. This template is already being repurposed for the <a href="https://www.forbes.com/sites/emmawoollacott/2026/03/06/nigerian-prince-scams-evolve-to-exploit-war-in-the-middle-east/">current conflict</a> in the Middle East.</p>
<h3>How to spot scams like this</h3>
<p>Thanks to generative AI tools, it’s easier than ever for scammers to create highly convincing written content, videos and websites to further their goals. But there are some tell-tale signs that will keep you safe. Look out for:</p>
<ul type="disc">
<li>Offers of large sums of money that are too good to be true</li>
<li>Unsolicited contact via email, SMS, messaging app, phone call or social media</li>
<li>Requests for personal and financial information</li>
<li>Attempts to force you into making a decision in the scammer’s favor, either by ramping up urgency or appealing to your emotional side</li>
</ul>
<h2>Responding to conflict-fueled scams</h2>
<p>With the above in mind, it should be easier to spot the warning signs that something doesn’t quite look or sound right. A good rule of thumb is never to click on links or open attachments in unsolicited messages, even if they look convincing and appear as if sent from a trusted source. If you really want to know if it’s a genuine message or not, check independently with the sender; i.e., don’t reply directly or use contact details in the message itself. Or if it’s a news story, go direct to your favored news outlet.</p>
<p>Be cautious of social media accounts, especially those that appear to be customer service accounts for airlines and the like. These are easier than you’d think to set up and platform providers are always a step behind in taking them down. And it goes without saying that you should never hand over sensitive information over the phone.</p>
<p>The next bit of advice may be the most difficult. But try to suppress your instinct to react to emotional pleas from ‘charities’ or urgent requests for you to act. The reason fraudsters use these techniques is because they work. They’re designed to turn our humanity against us.</p>
<p>As an extra layer of defense, ensure all your computers and devices are protected with anti-malware, including anti-phishing capabilities from a trusted vendor. That should help to filter out the majority of the scams. The rest is down to you.</p>
<p>According to a new report from the <a href="https://globalinitiative.net/wp-content/uploads/2026/03/Kristina-Amerhauser-Alex-Goodwin-A-world-of-deceit-Mapping-the-landscape-of-the-global-scam-centre-phenomenom-GI-TOC-March-2026-1.pdf" target="_blank" rel="noopener">The Global Initiative Against Transnational Organized Crime</a>, “fraud is a crime that is not only economically driven, but politically shaped.” This is unlikely to change anytime soon. But it doesn’t have to be you that ends up a victim.</p>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/scams/geopolitical-turmoil-gift-scammers-how-stay-safe/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/why-geopolitical-turmoil-is-a-gift-for-scammers-and-how-to-stay-safe/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to mitigate the security and privacy risks of smart glasses</title>
		<link>https://cyberwiredaily.com/how-to-mitigate-the-security-and-privacy-risks-of-smart-glasses/</link>
					<comments>https://cyberwiredaily.com/how-to-mitigate-the-security-and-privacy-risks-of-smart-glasses/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Mon, 11 May 2026 09:19:17 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/how-to-mitigate-the-security-and-privacy-risks-of-smart-glasses/</guid>

					<description><![CDATA[Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk. Fashion and many other trends have a way of reappearing every few years. So we probably shouldn’t be surprised that smart glasses are doing the rounds once more, after a [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/05-26/smart-glasses-security.jpg" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/05-26/smart-glasses-security.jpg" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>Fashion and many other trends have a way of reappearing every few years. So we probably shouldn’t be surprised that smart glasses are doing the rounds once more, after a failed attempt by Google to popularize them over a decade ago. The difference this time round is that they’re not just more stylish – and arguably harder to tell from regular shades. They’re also packed with far more powerful technology, capable of tracking and recording their surroundings, and allowing the user to ask AI about the things they can see around them.</p>
<p>This presents significant security and privacy risks for both smart glasses users and the people they interact with.</p>
<h2>What are the privacy risks?</h2>
<p>Anyone who’s ever lived in a city will be used to being monitored. Germany and the UK have among the highest number of CCTV cameras in the world. But when that monitoring is targeted and not based around informed consent, it can quickly get out of hand. Smart glasses give anyone the ability to record or take photos of strangers surreptitiously. Although they feature a small LED light, this can be covered up, and in any case may be difficult for bystanders to spot.</p>
<p>But that’s not all. Harvard University researchers <a href="https://x.com/AnhPhuNguyen1/status/1840786336992682409?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1840786336992682409%7Ctwgr%5E322e663625990ff0e54288704071e5c340c91091%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.malwarebytes.com%2Fblog%2Fnews%2F2024%2F10%2Fnot-black-mirror-metas-smart-glasses-used-to-reveal-someones-identity-just-by-looking-at-them">have demonstrated </a>how video taken via smart glasses and livestreamed to Instagram can be connected to AI. Algorithms then work to identify faces and then pull information from the internet on those individuals. Suddenly that cool accessory becomes a powerful, portable surveillance device capable of empowering stalkers, bullies and fraudsters.</p>
<p>The bad news is that Meta may be looking to streamline the process with a<a href="https://www.engadget.com/big-tech/meta-warned-by-dozens-of-organizations-that-facial-recognition-on-its-smart-glasses-would-empower-predators-185000998.html"> controversial Name Tag feature</a>. The social media giant has also come under <a href="https://www.bbc.co.uk/news/articles/c0q33nvj0qpo">scrutiny from regulators</a> recently after <a href="https://www.svd.se/a/K8nrV4/metas-ai-smart-glasses-and-data-privacy-concerns-workers-say-we-see-everything">reports revealed</a> that some outsourced workers in Kenya were able to view highly sensitive images as part of their job to monitor users’ interaction with its AI platform. Even if users don’t have data monitored in this way, it might still be used to train AI models, according to an updated <a href="https://techcrunch.com/2025/04/30/if-you-own-ray-ban-meta-glasses-you-should-double-check-your-privacy-settings/#:~:text=AI-,If%20you%20own%20Ray%2DBan%20Meta%20glasses%2C%20you%20should%20double,Ray%2DBan%20Meta%20companion%20app.">Meta privacy policy.</a> And any voice recordings made after the “Hey Meta” wake word will be stored (along with transcripts) for up to a year by default.</p>
<h3>When privacy risk becomes a security problem</h3>
<p>This isn’t just about privacy. Any sensitive information shared with a public AI platform via a pair of smart glasses could theoretically be regurgitated to other users if prompted in the right way. That’s a potential security risk if they choose to use the information fraudulently. And then there are those outsourced workers and contractors who may stumble across information harvested by glasses, which they might decide to sell to scammers.</p>
<p>Information you might accidentally send to the cloud/AI model could include:</p>
<ul>
<li>Card PINs that you type in at the ATM or in–store payment terminals</li>
<li>Passwords typed in at your desk or on your phone which could be used to hijack accounts</li>
<li>Bank statements or bills with full details that could be used to impersonate you</li>
</ul>
<p>There’s also a risk of nefarious smart glasses users shoulder surfing behind you in public, in order to steal PINs, passwords and other secrets. Combined with facial recognition technology, this data extraction may allow them to build up a sizeable digital profile on their targets. With enough detail they could either launch convincing phishing attacks, hijack your accounts or impersonate you in new account creation attempts.</p>
<h3>Hacking the smart glasses ecosystem</h3>
<p>Like any smart device, glasses could also be hacked more conventionally, by:</p>
<ul>
<li>Exploiting the operating system/firmware</li>
<li>Hijacking connected apps/smartphones</li>
<li>Intercepting traffic/inject malicious content via fake Wi–Fi hotspots</li>
<li>Social engineering, such as sending a malicious QR code to scan</li>
<li>Malicious lookalike smart glasses apps</li>
</ul>
<p>These attack vectors could in turn enable bad actors to hijack your device for direct data theft, account takeover, or surveillance that could put you in physical danger.</p>
<h2>How to manage smart glasses risks</h2>
<p>Whether you are wearing them or being observed by someone else, there are a few steps you can take to mitigate the risks we’ve outlined above:</p>
<h3>For wearers:</h3>
<ul>
<li>Keep your firmware and software (apps) updated to minimize the risk of hackers compromising the device</li>
<li>Only download companion apps from trusted sources and check permissions before doing so</li>
<li>Use multi–factor authentication (MFA) and strong, unique passwords for your smart glasses apps and smartphone to minimize the risk of them being hijacked by hackers</li>
<li>Use strong PINs or biometrics to unlock your smart glasses and switch off pairing mode if not using</li>
<li>Never connect to public Wi–Fi hotspots unless you also use a virtual private network (VPN), as some public networks may be insecure or may even be rogue access points set up by hackers</li>
<li>Disable AI training/human review if possible to prevent leakage of recordings to the cloud and potential access by contractors</li>
<li>Keep your glasses in a case when not in use to minimize the risk of them accidentally capturing sensitive images or information</li>
<li>Regularly audit and delete any unwanted recordings stored in the companion app, to minimize risk exposure</li>
<li>Don’t be distracted by AR overlays. It might put you in physical danger if you lose track of your surroundings</li>
</ul>
<h3>For bystanders:</h3>
<ul>
<li>Keep your eyes peeled for anyone wearing smart glasses. Look for the LED light on the frame; it will pulse if recording video or flash once when taking a photo</li>
<li>Be mindful of shoulder surfing in crowded public spaces (e.g., on transport) or at ATMs</li>
<li>Challenge wearers if you feel uncomfortable</li>
<li>If you feel uneasy about usage in a business setting (e.g., a gym or high–street store) ask the wearer to remove their glasses or report it to management</li>
</ul>
<p>Meta isn’t the only tech giant rolling out smart glasses. Google, Apple, Amazon and a host of Chinese players are said to be developing similar products. Unfortunately, many prioritize competitive advantage over users’ rights. Keep a close eye on developments to ensure your security and privacy don’t suffer as a result.</p>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/privacy/eyes-wide-open-mitigate-security-privacy-risks-smart-glasses/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/how-to-mitigate-the-security-and-privacy-risks-of-smart-glasses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Fixing trivial passwords is as easy as 123456</title>
		<link>https://cyberwiredaily.com/fixing-trivial-passwords-is-as-easy-as-123456/</link>
					<comments>https://cyberwiredaily.com/fixing-trivial-passwords-is-as-easy-as-123456/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Thu, 07 May 2026 08:50:20 +0000</pubDate>
				<category><![CDATA[Tips and Advice]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/fixing-trivial-passwords-is-as-easy-as-123456/</guid>

					<description><![CDATA[How come it’s still possible to ‘secure’ an online account with a six-digit string? The most-used password globally is exactly what you think it is: ‘123456.’ That’s according to NordPass’s latest annual report on passwords exposed in data breaches globally. Other all-too-predictable choices, such as ‘123456789’, ‘12345678’, ‘12345’ and ‘admin’, also prove to have staying [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div>
<p class="sub-title">How come it’s still possible to ‘secure’ an online account with a six-digit string?</p>
<div class="hero-image-container">
        <picture><source srcset="https://web-assets.esetstatic.com/tn/-x266/wls/2026/05-26/world-password-day-weak-passwords.jpg" media="(max-width: 768px)"/><source srcset="https://web-assets.esetstatic.com/tn/-x425/wls/2026/05-26/world-password-day-weak-passwords.jpg" media="(max-width: 1120px)"/></picture>    </div>
</div>
<div>
<p>The most-used password globally is exactly what you think it is: ‘123456.’ That’s according to <a href="https://en.wikipedia.org/wiki/List_of_the_most_common_passwords">NordPass</a>’s latest annual report on passwords exposed in data breaches globally. Other all-too-predictable choices, such as ‘123456789’, ‘12345678’, ‘12345’ and ‘admin’, also prove to have staying power year after year.</p>
<p>My first instinct is to dismiss this as scaremongering fodder, especially given that poor password hygiene was also part of a community engagement session I presented at the recent RSAC conference, <a href="https://www.rsaconference.com/library/presentation/usa/2026/lets%20rant%204%20things%20that%20need%20to%20change%20in%20cybersecurity">Let&#8217;s Rant: 4 Things That Need to Change in Cybersecurity</a>.</p>
<p>But since today is World Password Day, I had to put this to the test: Can I still find a reasonably mainstream website that allows me to create an account using ‘123456’ as the password? Unfortunately, the answer is yes.</p>
<p>There are popular sites, such as ‘<a href="https://www.evite.com/" target="_blank" rel="noopener">evite</a>’, that still allow this exact six-digit string to be used as a password. You may dismiss it as just an e-invite service, until you realize that you’re sharing personal data on your invitations and potentially manage the responses of all your invitees through an account that is not secure. The shocking part of this very crude test is the finding that Evite was <a href="https://haveibeenpwned.com/Breach/Evite" target="_blank" rel="noopener">subject to a data breach in 2019</a> that affected the personal information of over 100 million people. The company should probably know better than to allow its users to have such weak passwords.</p>
<p>The situation isn’t drastically better on even more popular services. When I attempted to create a new account on Facebook, the platform did mandate an additional level of password complexity. But still, a string as simple as ‘1234567!’ turned out to be a permitted password. X offered a similar experience.</p>
<p>Now, Facebook, for example, does <a href="https://www.facebook.com/help/124904560921566" target="_blank" rel="noopener">offer some advice</a>, such as: “<em>avoid using common words such as ‘password’</em>’ and “<em>If your password isn’t strong enough, mix uppercase and lowercase letters. Make it more complex by using a longer phrase or series of words that you can remember but others won’t know</em>.” Yet, it permits ‘1234567!’ to be used, no letters, just a sequential pattern with a simple exclamation mark at the end, all easily guessable, especially by automated scripts that test accounts <em>en masse</em> for commonly used patterns and strings.</p>
<p>Meanwhile, <a href="https://www.collinsdictionary.com/" target="_blank" rel="noopener">Collins Dictionary</a>, which is home to far less sensitive content, forced me to create an eight-character password containing at least three of the following – lower case (a-z), upper case (A-Z), numbers (i.e. 0-9) and special characters (e.g. !@#$%^&amp;*).</p>
<p>NordPass’s data suggests that there are many more sites that set limited password policies and allow trivial passwords like ‘123456’. However, I think there may also be elements of legacy in the method used to calculate the most common passwords. For example, if a company has existed for 10 years and never deleted any dormant user accounts, then a breach would include outdated dormant account information, some of which may be from <em>before</em> any password policy was enforced. The motivation behind publishing headline-snatching data is also clear: the vendors that create the news story are set to potentially benefit as they provide password management software for a subscription.</p>
<h2>Breaking the cycle</h2>
<p>Now, how do we resolve this never-ending loop of negativity about passwords, along with the ridiculous situation that platforms still permit non-secure passwords?</p>
<p>I do not support the idea of legislators needing to mollycoddle citizens, but in this instance I think it’s time for lawmakers to step up to the mark and put a stop to the pattern of companies not implementing stringent authentication policies and allowing consumers to take the easy option. There is widespread privacy legislation stating that companies need to secure our personal data if they store it, using appropriate reasonable cybersecurity measures. A core part of these measures is the use of strong, complex passwords and multi-factor authentication (MFA), as required by any self-respecting cybersecurity framework. Yet, in many instances there are no cybersecurity requirements on authentication for customer-facing services.</p>
<p>On the other hand, some industries have been forced to update to modern authentication methods. In the finance industry, for example, there are several regulations, such as the Payment Services Directive 2 (PSD2), that mandate MFA for electronic payments and access to payment accounts online.</p>
<p>Legislation should extend to all industries: simply enforce MFA for all accounts created online regardless of the service being accessed, ditch the outdated use of passwords, and move to more appropriate security for today’s internet.</p>
<p>The potential hurdle to mandating this approach is the barrier to entry for people creating accounts. Companies reliant on advertising or the collection (and sale) of personal data for revenue will lobby significantly against the move, and companies with big budgets will be very demanding that nothing steps in the way of profit, especially something like securing customer accounts by requiring a complex password and/or MFA.</p>
<p>For most of my 30-plus-year career in the cybersecurity industry, the issue of weak passwords has been a staple message pushed out every day, at many events, and on a specially nominated day. There is a simple and effective way to resolve it: mandate complex passwords or, better yet, MFA. Can we please stop the conversation about ‘weak passwords’, once and for all?</p>
<div>
<blockquote>
<p><em>To generate strong passwords and learn more about online account security, head over to ESET’s <a href="https://www.eset.com/us/password-generator/">password generator</a> page.</em></p>
</blockquote>
</div>
</div>
<p><br />
<br /><a href="https://www.welivesecurity.com/en/cybersecurity/fixing-password-problem-as-easy-as-123456/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/fixing-trivial-passwords-is-as-easy-as-123456/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
