Author: Gary Behan

Software engineer and video game uber-nerd.

Five Venezuelan nationals have pleaded guilty to a series of ATM jackpotting attacks across the United States, after surveillance cameras recorded their failed attempts to drain cash machines in two Kansas towns. The case is one thread in a much larger federal investigation that has now ensnared dozens of individuals linked to the Tren de Aragua criminal organisation. Luis Alberto Velasquez-Artigas, Royder Adrian Figuera-Perez, Javier Mejia Jr, Gabriel Alexjandro Corales-Garcia, and Italo Lizandro Corrales-Carrillo each pleaded guilty to one count of conspiracy to commit bank larceny. Velasquez-Artigas, 27, has already been sentenced to nine months in prison; the remaining four…

Read More

The Cronos blockchain has restarted following a Tectonic TONIC price manipulation attack that allowed a threat actor to borrow $74 million in assets from the decentralised finance (DeFi) lending protocol. Cronos confirmed the network is ‘producing blocks again as of 2026-08-30 23:49:01 UTC, starting from block 90,896,189.’Tectonic is a DeFi lending app that runs on Cronos, an Ethereum-like blockchain network associated with Crypto.com. Before the incident, Tectonic was Cronos’ largest lending protocol, holding $122 million in total value locked. After the exploit, that figure collapsed to just under $3 million, according to DeFiLlama.How the Tectonic TONIC price manipulation unfoldedThe attack…

Read More

Microsoft is investigating an Exchange Online authentication outage that is causing email failures, mailbox access problems, and search disruptions for users across its Outlook platform. The company acknowledged the incident, tracked internally as EX1464935, at 5:30 PM UTC, after a wave of reports surfaced on social media.Outage-tracking service Downdetector logged tens of thousands of affected users within hours of the first reports. According to CNET, the Downdetector data shows that 37% of those reporting problems cited difficulties receiving messages, 23% had trouble using the app, and 20% reported issues with the website itself. That spread suggests the disruption is touching…

Read More

A Chinese threat actor has repurposed Cisco routers into active surveillance platforms in what incident response company Sygnia describes as a pivot away from Fire Ant Cisco router spying techniques previously focused on virtualisation infrastructure. The group has deployed custom malware, captured live network traffic, and used compromised devices as covert bridges into connected high-value environments, including systems associated with critical infrastructure.From VMware to IOS XR: How Fire Ant Changed TargetsSygnia had previously tracked Fire Ant targeting VMware ESXi and vCenter environments, according to Cybersecurity Dive. The shift to Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts…

Read More

Microsoft has confirmed that the KB5120998 mouse reset bug is reverting cursor personalisation settings on Windows 11 systems, with Bleeping Computer reporting that the issue specifically targets non-English Windows 11 installations. For the users caught out, the situation is particularly frustrating: attempts to restore previous cursor settings after the revert are reportedly unsuccessful.Microsoft acknowledged the problem in a statement, explaining that ‘mouse cursor personalization settings are being changed or reverted to certain standard settings’ following the installation of updates released on 27 August 2026, including KB5120998. The company described the issue as causing ‘appearance regressions and intermittent animation changes,’ with…

Read More

Microsoft is telling customers to sit tight and ignore Defender Antivirus false alerts that incorrectly report the antivirus has been switched off, following the installation of recent Defender updates. The alerts are wrong: the antivirus is running fine. Microsoft says a fix is coming, but hasn’t said when.The erroneous notifications surface in the Windows Security app and prompt users to ‘Tap or click to turn on Microsoft Defender Antivirus.’ According to Microsoft’s Friday release health dashboard update, the alerts can appear when Windows starts and may recur intermittently throughout a session. They persist even when notification settings are turned off,…

Read More

The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer it took approximately 86 GB of data, and samples reviewed by the outlet suggest the exposed information goes considerably further than MAG’s own disclosure acknowledged. How the Manchester Airports Group Data Breach Unfolded According to TechTimes, Manchester Airports Group detected the unauthorised access on 25 August 2026 and went public two days later on 27 August, a 48-hour disclosure window. In that statement, MAG, the United Kingdom’s largest airport operator, said an unauthorised third party had stolen customer data tied to Manchester, London Stansted,…

Read More

Anthropic is making its Claude Code weekly limits permanent from 14 September, but the framing deserves a closer look: users who have enjoyed the current temporary boost will end up with less usage than they have right now, not more. The maths is straightforward once you strip away the positive spin. How the numbers actually stack up Claude Code has been running with a temporary 50% uplift on its standard weekly allowances. Anthropic announced on X that, from 14 September, it will permanently raise those standard limits by 25% for Pro, Max, Team, and seat-based Enterprise plans. That sounds generous…

Read More

Brave browser email aliases have arrived in version 1.94, giving users a way to hand over a disposable address when registering for a new service rather than exposing their actual inbox to whatever fate awaits that service’s database. It is a small feature with a pointed rationale: even a browser that isolates cookies and blocks cross-site tracking cannot stop a careless third party from leaking your email address to data brokers or phishing operators.The mechanism is straightforward. A user creates a free Brave Account, registers their primary email address with it, and can then generate up to five aliases at…

Read More

The McKesson ShinyHunters data breach came to light on 25 August 2026, the day the company says it discovered the incident, with the extortion group claiming it had already spent four days quietly siphoning roughly 1TB of data from McKesson’s cloud environments. McKesson disclosed the incident in a Form 8-K filing with the US Securities and Exchange Commission, stating that its investigation remains in the early stages and that it has not yet determined whether the incident is material to its financial condition or results of operations.In a separate notice to customers, McKesson confirmed that the attack involved third-party applications…

Read More