‼️ LG monitors are silently installing adware on computers through an LG app because Windows allows to automatically fetch apps for connected devices with full system access.
Once an LG monitor is connected to a Windows PC, it triggers Windows Update to fetch the LG Monitor App Installer, an app whose store listing grants access to "All system resources," with no consent screen and McAfee trial ads following shortly after.
Microsoft's role deserves scrutiny too. The Windows feature was built for drivers and companion utilities, not for ad software with full-resource permissions.
The same behavior was found by YouTuber Gamers Nexus on monitors up to three years old, including ones already in use at its own office. LG has not publicly responded, and the first consent screen you ever see is the ad.
Let me blow your mind real quick:
When you use Remote Desktop (RDP), Windows secretly takes screenshots of what you are doing.
It’s called the RDP Bitmap Cache.
To make the connection faster, Windows saves small tiles (images) of the remote screen to your hard drive in a bin file.
Even if the session is over and the remote server is destroyed... your laptop still holds the cache files.
Forensics teams use tools like BMCViewer to stitch those tiles back together.
They won't just see logs but the literal email, document, or picture you were looking at.
💀
Meet Vutlharhi Valoyi, the Limpopo-born founder of Zulzi — the online grocery delivery startup that secured R30 million in funding from a JSE-listed company. 🇿🇦📈
From humble beginnings to processing over 2,000 orders a day, Zulzi was already doing nearly R1 million in sales per day back in 2019. Their innovation would later help shape the development of Checkers Sixty60, now one of South Africa’s biggest delivery platforms. 🚀
Zulzi founder and CEO Vutlharhi “Donald” Valoyi played a major role in building the future of on-demand grocery delivery in South Africa.
Black child, it’s possible. Build. Innovate. Dream bigger. And let’s support our own. ✊🏾
Does Encrypted DNS Keep Your Traffic Private?
Think HTTPS and custom DNS keep your browsing private? This Wireshark network tap experiment reveals how SNI leaks your data. See why a VPN might still be necessary to hide traffic.
A South African hosting company has been targeted by extortionists with a large-scale distributed denial-of-service (DDoS) attack for the second time in two weeks.
https://t.co/tVqRilu6fb
🇿🇦 Nando's Employee Database Allegedly Offered for Sale
* A threat actor is advertising what is claimed to be a database containing records of current and former Nando's employees
* The listing alleges approximately 87,000 employee records are included
* Advertised data fields include full names, job titles, supervisory groups, phone numbers, email addresses, and employment locations
* The seller claims the dataset contains both business and personal email addresses, mobile and landline phone numbers, employee role information, and workplace location details
* Additional information allegedly includes business locations, contact center information, and job listing data, including salary-related details
* According to the actor, the records primarily relate to employees located in the United Kingdom and Ireland
Analyst Note:
Employee databases are highly sought after by threat actors because they enable targeted phishing, business email compromise (BEC), social engineering, and impersonation attacks. Organizational hierarchy information, job roles, and direct contact details can significantly improve the effectiveness of attacks targeting both employees and the company itself. The authenticity of the dataset and the source of the alleged compromise remain unverified.
#DDW #Intelligence #DarkWeb #Nandos
The first cyberattack in history using prompt injection. Attackers used Meta’s chatbot as a tool to take over Instagram accounts belonging to well-known people, brands, and institutions. By manipulating Meta’s AI support system, they convinced it to perform a critical administrative operation: changing or adding an email address associated with the victim’s account.
Basic mistake: using LLM as a security boundary.
The attacker contacted Meta’s bot, provided the username of the account they wanted to take over, and asked it to link that account to a new email address controlled by the attacker. In practice, this meant that the person controlling the new email address could receive or provide the confirmation code, and then use the modified recovery channel to reset the password and take over the account.
AI support became a path for bypassing account security. If a chatbot can change an email address or initiate account recovery without independent verification of the owner, the attacker does not need to know the password or break through traditional security controls. It is sufficient to convince the automated support operator to perform an operation that the attacker should not normally be allowed to request.
https://t.co/Uy5DdWudJh
DELETED, BUT NOT ERASED: RECOVERING MESSAGES FROM NOTIFICATION LOGS
The FBI was reportedly able to recover copies of incoming Signal messages from a suspect's iPhone even after the Signal application had been removed few months ago. This was achieved through forensic analysis of the device's push notification database, where portions of message content had been stored.
So I decided to use that same methodology and it worked.
Importantly, this is not a failure of Signal's end-to-end encryption. Rather, it highlights a well-known mobile forensics artifact issue.
iOS uses write-optimized storage, meaning deleted data may persist on a device until it is eventually overwritten.
When a message is delivered to an iPhone via Apple's Push Notification Service (APNs), iOS may generate and display a notification preview, depending on the device's notification settings. These previews can be temporarily stored within system-level databases and notification logs.
As a result, even if the messaging application is deleted, residual artifacts containing portions of message content may remain on the device. Some digital forensic tools can identify and recover these artifacts during an examination, providing investigators with valuable evidence that may no longer be accessible through the application itself.
The underlying issue is that the iPhone caches items that appear as notifications on your lock screen.
I hope Apple will limit the time that messages are cached to minimize risk to users.
Turn off or disable notifications for secure messaging apps or other apps you think are sensitive.
My article "How To Investigate A Person Of Interest In 2026" is now available as a PDF.
A practical guide to digital footprint analysis – from email reconstruction to metadata mining and entity graphing.
Thanks @osintnewsletter for the mention.
PDF: https://t.co/86YlE9e2pB
@bozzie_t@RelebogileM U might find the total price of items on your cart to be R1200, but tem and shein would understate the price at customs so that they can use 20% import duty and 0% VAT, while the law states that all clothing items of a price greater than R500 have to be charged 45% import duty+va
@bozzie_t@RelebogileM Temu and Shein are allegedly exploiting import duty and tax loopholes. The de minimis rule allowed companies to get clothing parcels under R500 through customs with a 20% import duty and 0% VAT. Temu and Shein allegedly used the de minimis rule on clothing parcels >R500.
@JerryVanLamola@RelebogileM U might find the total price of items on your cart to be R1200, but tem and shein would understate the price at customs so that they can use 20% import duty and 0% VAT, while the law states that all clothing items of a price greater than R500 have to be charged 45% import duty+va
@JerryVanLamola@RelebogileM Temu and Shein are allegedly exploiting import duty and tax loopholes. The de minimis rule allowed companies to get clothing parcels under R500 through customs with a 20% import duty and 0% VAT. Temu and Shein allegedly used the de minimis rule on clothing parcels >R500......
@SintlePearl Good move by the government. The influx of cheap, mass-produced, imported clothes has a dire effect on SA's economy. Many local production facilities closed because they couldn't compete with the cheap imported clothing market. We have to protect our local clothing retail market
@NoxoloMrsA@SintlePearl The entire value chain must be in the country to stimulate the economy and create jobs. Most foreign e-commerce companies especially ones from Asia have long exploited import duty and tax loopholes.
@NoxoloMrsA@SintlePearl Good move by the government.The influx of cheap, mass-produced, imported clothes has a dire effect on SA's economy. Many local production facilities closed because they couldn't compete with the cheap imported clothing market. We have to protect our local industries and market.