Tech News
← Home  ·  All topics

Access

33 GoKawiil briefs on this topic

SectopRAT Backdoor Found Hidden in Legitimate Italian Audio Software

Fortinet's FortiGuard Labs identified a new variant of the SectopRAT remote access Trojan concealed within legitimate digital-audio software from an Italian company. Researcher Xiaopeng Zhang said attackers modified the FrameworkBase.dll file after the software was already installed on victim machines, secretly loading the SectopRAT payload rather than compromising the vendor itself.

Judge orders White House to restore press access for CNN, MS NOW, Politico

U.S. District Judge Timothy Kelly issued a temporary restraining order requiring the White House to reinstate press credentials for CNN, MS NOW and Politico, which had been revoked last Friday. The order lasts 14 days, with the judge finding the outlets are likely to prevail on claims their passes were pulled without due process; hours after the ruling, a CNN reporter said she was still denied entry.

Guide Outlines Multi-Stage Process for Enterprises Adopting SASE Security

A cybersecurity guide details how organizations can build a Secure Access Service Edge (SASE) framework, starting with a full infrastructure audit to uncover shadow IT, redundant tools and undocumented network dependencies. It then recommends piloting SASE in controlled environments, such as remote-worker groups or new branch offices, before wider rollout. The transition is described as taking 6-18 months or longer, during which legacy and SASE systems must be secured in parallel.

Study finds 440 diamond open-access journals dropped free model since 2009

A preprint led by Lisa Matthias at Humboldt University of Berlin tracked 440 academic journals that began as diamond open-access, meaning free for both authors and readers, but later shifted to charging fees between 2009 and 2026. Most of these titles, 369, moved to gold open access with article-processing charges, 52 adopted hybrid models, and 19 became fully paywalled, with fees ranging from $8 to $5,300 depending on publisher type.

Fake mathjs npm package hides encrypted backdoor triggered by equation solving

Security researchers at SafeDep discovered that a malicious npm package called mathmain, disguised as a copy of the popular mathjs library, contains a hidden remote access implant. The malicious code stays encrypted and dormant until a specific equation is solved using the library's lusolve() solver function, which acts as a decryption key to unlock and execute the payload.

Spotify tests 3-day Premium-only window for new albums in India, Bangladesh

Spotify is trialing a 'Premium Early Access' feature that withholds new album releases from free users for three days in select markets like India and Bangladesh, while paying subscribers get immediate access. The delay reportedly stems from licensing terms pushed by Universal Music Group rather than a decision Spotify made unilaterally, and the same restriction is expected to hit rival ad-supported services like YouTube Music and Amazon Music.

CNN, MS NOW and Politico sue Trump administration over White House press credential revocations

CNN, MS NOW and Politico announced they are suing the Trump administration after their White House reporters had their press badges deactivated and were turned away over the weekend. The move followed Trump's public declaration that he was barring the outlets for reporting he called 'fake news.' The three outlets said they notified the government Monday of a lawsuit to challenge the credential revocations.

North Korea's WaterPlum hackers infect 30,000 devices via fake job coding tests, steal $10.7M

Cybersecurity agencies from Japan, the US, Australia and Germany issued a joint advisory identifying North Korea's WaterPlum group as the actor behind malware hidden in fake job application coding tests. The scheme has infected over 30,000 devices across 100 countries and compromised more than 7,000 crypto wallets, netting $10.71 million believed to fund the North Korean government.

Meta's Muse AI gives false explanation of how it accessed user's Messages

A journalist testing Meta's Muse AI assistant on its new Mac app found it referencing contents of his Messages conversations, despite believing he hadn't granted access. When questioned, Muse gave a confused and inaccurate explanation, claiming it only saw notification previews synced through the paired Mac app. Meta executive David Singleton later clarified that Muse only accesses Messages data after a user explicitly opts in, and that the assistant's own explanation of its capabilities was simply wrong.

Nasdaq president Nelson Griggs weighs impact of potential Anthropic, OpenAI IPOs

At Fast Company's Innovation Festival, Nasdaq president Nelson Griggs discussed with senior writer Ainsley Harris how prospective massive public listings from AI leaders such as Anthropic and OpenAI could transform public markets. He framed these mega-IPOs as a distinct new category that could alter how capital flows into major industries and the broader economy.

Healthcare veteran argues infrastructure, not apps, must fix access gaps

A healthcare industry veteran with 26 years of experience contends that despite waves of apps, algorithms, platforms and payment reforms, core access problems persist: millions still struggle to get timely doctor appointments, emergency rooms remain a default care option, and provider shortages keep worsening. The argument frames these as symptoms of deep structural failure rather than something a single new tool can resolve.

Wire survey finds most security teams can't track who has access to shared M365 files

A Wire survey found that 61% of security leaders say access to shared files in Microsoft 365 often stays active far longer than intended, while more than a third struggle to even identify who currently has access to sensitive shared content. The report points to routine sharing habits—like adding freelancers to SharePoint folders or inviting new members into Teams channels—as common ways access quietly persists beyond its original purpose.