ZeroHour

Search: “Mantax”

28 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

New Android malware family Mantax OTAX combines ransomware, spyware, and OTP theft via sideloaded APKs, linked to Indonesian threat actors.

Researchers at zLabs and Zimperium analyzed Mantax OTAX, an aggressive Android malware strain distributed as sideloaded APKs through phishing and messaging lures on third-party file-sharing services. The malware requests device-administrator and Accessibility permissions to steal lock-screen PINs, intercept SMS one-time passwords, harvest contacts and history, capture screens via MediaProjection, and silently photograph victims, while encrypting files with AES and writing .enc files on Android 9 and older. Its C2 uses HTTPS at apimantax[.]otax[.]fun with the active domain fetched dynamically from a GitHub repository, and a newer version adds WebSocket communication, app blocking, video overlays, and text-to-speech harassment. A Firebase misconfiguration exposed extortion conversations and victim data, and Android 10+ Scoped Storage limits the encryption reach but not the surveillance capabilities.

GBHackersupdated · 5d agofirst · 5d agoMalware in the wild 6 sources1

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

People-search service ClarityCheck exposed a database with more than 9 million facial image files despite marketing its reverse lookup as private and secure.

WIRED reports that ClarityCheck, a people-search tool offering reverse image lookup, left a database containing more than 9 million image files of people's faces exposed. The company markets the service as private and secure. The exposure affects millions of individuals whose facial photos could be linked to their identities.

WIRED · Security · 28d agoData breach

Indonesia Hit by Android Banking App-Cloning Campaign

GoldFactory exploits Android Work Profile to deliver the Gigabud banking trojan to Indonesian users via cloned banking apps, with Mantax and Otax spreading separately.

The GoldFactory threat group is running an app-cloning campaign against Android banking customers in Indonesia, abusing the Android Work Profile feature to deliver its Gigabud trojan. The Mantax and Otax malware families are spreading through separate distribution channels. Abusing Work Profile to install or conceal cloned banking apps is a notable mobile technique, though the article reports no victim counts or loss figures.

Dark Readingupdated · 5d agofirst · 6d agoThreat actor in the wild 3 sources

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

Hackers stole personal and tax data of 678,000 individuals and businesses from France's tax agency DGFiP, prompting a Paris criminal investigation.

France's Directorate-General for Public Finances (DGFiP) confirmed a sophisticated cyberattack exposed data on 678,000 users of the tax system, including income figures, tax rates and family circumstances for individuals and SIREN registration data for businesses. The Paris prosecutor's cybercrime unit opened a probe and referred it to the French anti-fraud office OFAC after a threat actor claimed the breach in late June. Officials stressed the stolen data does not grant access to secure accounts on impots.gouv.fr, and taxpayer notification begins Monday with warnings about identity theft and fraudulent follow-up requests. The incident follows recent breaches at the ANTS documents agency and the INSEE statistics authority.

Security Affairs · Aug 16, 2026Data breach

France’s tax authority admits hackers made off with data on 678,000 individuals

An attacker used stolen credentials and an MFA bypass to steal tax data on 678,000 individuals from France's tax authority DGFiP.

France's General Directorate of Public Finances (DGFiP) disclosed that intrusions into its portals exposed tax data, including reference tax income, family quotient, withholding tax rate, and business identifiers such as company name and SIREN number, on 678,000 individuals and professionals. An attacker using the alias 'ZeroBytes' claimed credit on a cybercrime forum and offered a stolen database for sale, claiming the portal contains data on roughly 20 million citizens. DGFiP suspended the affected accounts, notified the CNIL, and is working with ANSSI and the finance ministry's security office; it said the main online tax portals and their login credentials were not compromised.

Help Net Security · Aug 17, 2026Data breach

LexFlip: A Dissociation Diagnostic for Legal Meaning Preservation Metrics

LexFlip releases 373 minimal perturbations of Quebec statutory French that reverse legal force while preserving tokens, exposing weaknesses in embedding-based meaning preservation metrics.

LexFlip provides 373 minimal perturbations of Quebec statutory French that reverse legal force while preserving 0.93 of tokens, creating dissociation items that break monotone token-overlap metric validation. The seven embedding and BERTScore metrics tested register only 0.022-0.039 of their identical-to-unrelated range on these edits, versus 0.670 for bidirectional NLI. Against FrJudge, with a measured human ceiling of r=0.597, a bare length feature outscores every semantic metric tested.

arXiv cs.AI / cs.LG / cs.CL · 12d agoAI research

Hiding Prompt Injection in Legal Filing

A judge banned a plaintiff from electronic court filings after hidden prompt-injection text was discovered planted in legal documents.

Bruce Schneier's blog discusses an incident in which hidden prompt-injection instructions were planted inside a legal filing, apparently targeting AI systems that might process court documents. Judge Walter Spader Jr. responded by banning the plaintiff from electronic filings, requiring all future submissions as printed hard copies. Commenters debate whether the tactic could affect future AI-based processing of court records and whether plain-text formats will regain favor.

Schneier on Security · 16d agoAI safety & security in the wild

U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States

UK Supreme Court ruled Bahrain not immune from spyware litigation, letting two dissidents pursue claims over FinSpy hacking; case returns to the High Court.

The UK Supreme Court ruled in The Kingdom of Bahrain v. Shehabi that Bahrain is not immune from litigation over its alleged use of FinSpy spyware against two Bahraini dissidents living in the UK. Citizen Lab researchers Siena Anstis, Natalia Krapiva, and Kate Pundyk, writing in Lawfare, called the decision a milestone for accountability in transnational repression. The case now returns to the UK High Court, where attribution, causation, and injury must be proven.

Citizen Lab · 14d agoPolicy & legal in the wild

US and Canadian Court Records Breached Following Thomson Reuters Incident

Thomson Reuters disclosed a breach of its C-Track court software exposing sensitive case records across Ontario courts and 11 US states.

Thomson Reuters detected unauthorized access to its C-Track case management product on June 30 and disclosed the incident on September 2. Files from three Ontario courts and appellate courts in 11 US states plus the US Virgin Islands were affected, potentially exposing names, Social Security numbers, driver's license numbers, medical information, dates of birth and health insurance data. The company said financial transaction systems were not impacted and found no evidence of misuse; the investigation into exact scope is ongoing.

Infosecurity Magazine · 13d agoData breach 2 sources

PrivAudit: A Dual-Lens Auditing Framework for Website Privacy Practices under the CCPA

PrivAudit framework audits 998 websites for CCPA compliance, finding stronger disclosures but pervasive, weakly responsive third-party cookie tracking.

PrivAudit is an automated dual-lens auditing framework combining LLM-based analysis of privacy policies grounded in CCPA provisions with automated browser measurements of cookie writes under diverse privacy configurations. Applied to 998 websites, it finds CCPA-subject sites disclose opt-outs, data sharing, and user rights more frequently, yet tracking remains pervasive: 6,392 targeting cookies, 49% third-party writes. Cookies show limited-to-moderate responsiveness to privacy signals and consent choices even when sites claim to honor them. The framework is open-sourced and shared with regulators.

arXiv cs.CR · 7d agoResearch

Cybercrooks trawl Fishbrain to net password hashes

Fishing app Fishbrain disclosed a breach exposing names, emails, and password hashes with salts for users of its 20-million-member platform.

Fishbrain AB disclosed to the California Attorney General's Office that attackers accessed user data on August 19, 2026, taking names, dates of birth, email addresses, phone numbers, usernames, country information, password hashes, and salts. The company said passwords were not stored in plaintext but some hashes may be susceptible to cracking; it patched the exploited vulnerability, reset all user passwords, and restricted access to the affected environment. Fishbrain, which claims more than 20 million users, did not disclose how many accounts were affected or which hashing algorithm was used.

The Register · Security · 13d agoData breach

American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials

A U.S. citizen is being prosecuted for using GrapheneOS's duress passcode to wipe his phone before border officials could search it.

Tunick entered a dedicated wipe passcode in GrapheneOS, a hardened Android alternative running on his Google Pixel, erasing the device's contents when demanded by border officials. His attorneys confirmed the software was in use, and the prosecution is proceeding even though he was not under arrest. The case raises unresolved constitutional questions about what rights apply at the U.S. border, which the government has long treated as outside U.S. soil until entry is authorized. GrapheneOS publicly asserted the feature is legal and that laws weakening its protections would be unconstitutional.

Schneier on Security · Aug 13, 2026Policy & legal

X says attackers are targeting user accounts after the launch of X Money

X is investigating a wave of unsolicited password reset emails targeting users after the X Money payments launch, with no confirmed breaches yet.

Numerous X users reported unsolicited password reset emails following the launch of X Money, the platform's new payments service with accounts held at FDIC-insured Cross River Bank. Product engineer Mridul Singhai said the company found no evidence of successful breaches or mass account takeovers, while the Grok chatbot confirmed attackers are mass-triggering resets using public usernames. Users are being advised to enable two-factor authentication and Password Reset Protect while the investigation continues.

TechCrunch · Security · 15d agoPhishing & fraud in the wild

Revoked but Still Authoritative: An Empirical Study of Revocation Enforcement in Agent-Memory Systems

An empirical study finds no major agent-memory system enforces fact revocation at retrieval, causing agents to act on superseded, unsafe information.

Researchers tested five agent-memory systems across nine policy scenarios, nine models, and six defense conditions, tracking whether revoked facts are returned and acted upon. No system enforces revocation by default: revoked records are returned whenever the revocation label is visible to the retrieval layer, outrank their replacements, and lead agents to unsafe actions. The authors propose a backend-agnostic guard that sits between the agent and any memory store and withholds revoked or conflicting records at retrieval time.

arXiv cs.CR · 8d agoAI safety & security

Revolut confirms customer data breach, falling for fake government requests

Revolut confirmed a breach of sensitive customer data after complying with forged government information requests.

Revolut confirmed that sensitive customer data was exposed after the fintech fell for fake government data requests, Reuters reported. The incident is a form of legal-process fraud in which attackers impersonate law-enforcement or government agencies to trick compliance teams into disclosing user data. The number of affected customers and specific data types were not detailed in the available text.

Hacker News · securityupdated · 2d agofirst · 4d agoData breach 3 sourcesHN 20↑ · 2 comments

Thomson Reuters reveals breach that exposed U.S. and Canadian court records

Thomson Reuters disclosed a C-Track breach exposing court records and personal data across at least 12 US states, US Virgin Islands, and Canada.

Thomson Reuters discovered unauthorized activity in its C-Track court case management platform on June 30, 2026, tracing the intrusion to March 2026. Affected systems include Ontario's three courts, Wyoming's entire state judiciary, and appellate and supreme courts across at least 12 US states plus the US Virgin Islands. Exposed records may include names, Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance details, with some sealed court information possibly affected. The company is offering 12 months of free credit monitoring and reports no evidence of fraud so far; attribution and access method remain unknown.

Help Net Security · 14d agoData breach

ClickFix Campaigns Abuse Legitimate Services for Persistent Access

Dark Reading reports two ClickFix social engineering campaigns abusing legitimate services to compromise organizations and maintain persistent access.

Dark Reading describes two separate attacks in which threat actors used the ClickFix social engineering tactic to compromise organizations. The campaigns abuse legitimate, trusted services to gain and maintain persistent access to victim environments. No specific victims, actors, or indicators were named in the available text.

Dark Reading · 8d agoThreat actor in the wild

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft details high-volume phishing campaign using ASCII smuggling (Unicode tag chars) for filter evasion, peaking at 2.3M messages.

Microsoft researchers observed a high-volume finance-themed phishing campaign using invisible Unicode tag characters (U+E0000–U+E007F), a technique known from AI prompt injection research as ASCII smuggling, to split lure words like 'funding' and evade email filters. Telemetry from Microsoft Defender for Office 365 showed signature hits jump from roughly 21,000 messages on February 8, 2026 to more than 1.3 million on February 9, peaking above 2.3 million on February 11, with elevated weekday activity lasting approximately three months. The discovery emerged from prompt injection protection research, showing AI-era evasion techniques crossing into traditional phishing. Most messages were flagged by layered Defender protections rather than a single Unicode-specific signal.

Microsoft Security Blog · 13d agoPhishing & fraud in the wild1

Once popular for attacking AI, ASCII smuggling is embraced by spammers

Spammers adopt ASCII smuggling—invisible Unicode tag characters—to evade email filters, with Microsoft Defender detections spiking to 2.5 million per day.

ASCII smuggling hides text in Unicode tag characters (e.g., U+E0041 for "A") that are invisible to humans but readable by LLMs and text processors. The technique gained attention as a stealthy prompt-injection vector and is now used by spammers to obfuscate keywords from email detectors. Microsoft reported Defender for Office smuggling detections jumped from roughly 21,000 per day to over 1.3 million in early February, reaching 2.5 million within four days, before falling sharply in mid-May.

Ars Technica · Security · 12d agoPhishing & fraud

Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

A ClickFix social engineering wave delivers a multi-stage attack that hides malware in PNG files and installs a custom reverse tunnel.

The Register reports a new wave of ClickFix social engineering attacks that trigger a multi-stage infection chain on victim machines. The attack reportedly conceals malware inside PNG image files and deploys a custom reverse tunnel tool for attacker access. Further technical details are limited in the available text.

The Register · Security · 16d agoMalware in the wild

HuggingFace: Security.txt

Hugging Face published a security.txt file, prompting limited Hacker News discussion of the RFC 9116 disclosure standard.

Hugging Face's security.txt file, which lists its security contact and disclosure channels per the RFC 9116 standard, drew attention on Hacker News. The RFC 9116 standard lets organizations publish where and how security researchers should report issues, but the submission received only one comment.

Hacker News · securityupdated · 5d agofirst · 5d agoIndustry 2 sourcesHN 22↑ · 1 comments

Russian suspect in bank account takeovers is extradited to US

Russian web developer Sergei Filimonov was extradited from Georgia to the US to face charges in a multimillion-dollar bank account takeover fraud.

Sergei Anatolyevich Filimonov, 36, appeared in an Atlanta federal court on September 4 and pleaded not guilty to bank fraud, wire fraud, access device fraud, and aggravated identity theft charges. Prosecutors say that from November 2023 to October 2025 his group bought sponsored search-engine links that diverted online banking customers to spoofed login pages, stole their credentials, and initiated unauthorized wire transfers. The FBI linked the scheme to the December 2025 seizure of the domain web3adspanels.org, identifying at least 19 victims, roughly $14.6 million in confirmed losses, and about $28 million in attempted losses.

The Record · 8d agoPolicy & legal

Mi-Ripple: Restoring Images Degraded by Iterative AI Editing

Mi-Ripple is a diagnosis-guided restoration workflow that removes digital ripple artifacts introduced by iterative AI image editing while preserving structure.

Iterative reference-conditioned image editing can introduce grid-like and granular textures known as digital ripple. Mi-Ripple separates periodic lattice artifacts from content-entangled granular texture, then applies selective spectral notching, structure-aware smoothing, and cleaned-reference regeneration. In fourteen notch-only executions, whole-image residual standard deviation was 0.08-0.44 in CIELAB lightness units, and reference cleaning reduced output debris density by 45% in a paired example.

Hugging Face daily papers · 7d agoAI research

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Unauthorized access to Thomson Reuters' C-Track court platform may have exposed SSNs and sealed records across 11 US states, USVI, and Ontario.

Thomson Reuters' West Publishing disclosed that an unauthorized party obtained files from the C-Track court case management platform starting in March 2026, with access to one environment running from March 1 through June 29, 2026 per Montana's account. Notices name roughly 24 court bodies across 11 US states, the US Virgin Islands, and Ontario, including appellate courts in Minnesota, Ohio, Montana, and Pennsylvania. Exposed data may include names, Social Security numbers, driver's license numbers, dates of birth, medical and health insurance information, and confidential or sealed court records. The company is offering 12 months of Experian or TransUnion monitoring, and courts disagree over whether the vendor's backup cloud environment or the production platform was accessed.

The Hacker News · 13d agoData breach in the wild

LinkedIn fights for the right to tell customers when the feds want their data

Microsoft's chief legal officer argues federal subpoenas for LinkedIn user data should carry narrower scope and that secrecy orders must become the exception.

Microsoft chief legal officer Jon Palmer said federal courts and Congress must curb overly broad US government subpoenas for LinkedIn user data that arrive with secrecy orders preventing customer notification. The company is asking courts to enforce meaningful limits on demand scope and secrecy, invoking Fourth and First Amendment arguments. Palmer cited House legislation passed August 31 to rein in secret surveillance, while LinkedIn simultaneously faces user privacy lawsuits, one dismissed with leave to amend by Judge Vince Chhabria.

CSO Online · 7h agoPolicy & legal

Product showcase: AI Paper Trail shows the privacy cost of talking to AI

Proton launched AI Paper Trail, a free tool that analyzes ChatGPT or Claude exports and reports what personal data can be inferred from AI conversations.

Proton released AI Paper Trail, a free web tool that analyzes the 200 most recent prompts from exported ChatGPT or Claude conversation histories and generates a privacy report with an AI Exposure Score, inferred personal data categories, and an estimated advertising value. In a hands-on test it identified 47 data points, returned a 58/100 exposure score, estimated $185 in advertising value, and flagged five red flags spanning location, interests, finances, and relationships. Proton states that uploaded data is deleted after analysis and is not stored on its Lumo servers.

Help Net Security · 24d agoAI industry

Risky Bulletin: Expired cards can be used for new transactions

Researchers show expired Visa contactless cards can be revived via NFC man-in-the-middle relay to run fraudulent transactions; roundup also covers major breaches.

University of Massachusetts Amherst researchers built an NFC man-in-the-middle rig that updates a card's expiration date in transit and relays the modified payment to POS terminals, reviving expired contactless cards; Visa terminals and the backends of all five banks studied failed to catch the manipulation. The same roundup reports Iranian hackers shut down a small UK power plant for four days, Lazarus breached South Korea's Presidential Office as part of a campaign exceeding 100 victims, and French telecom SFR suffered a breach affecting over 2.1 million customers.

Risky Business News · 23d agoResearch1