Threat actors are using a new technique called βphantom squattingβ to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networksβ Unit 42.
Since AI models frequently hallucinate phony information, they sometimes point users to websites that donβt exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.
MakerDAO governance has executed a new set of parameter adjustments under the broader Sky transition, including changes tied to Sky Spreads, staking reward normalization, and the offboarding of an older real-world asset vault.
The July 20 governance update shows how Makerβs Endgame-era structure continues to move from broad strategic design into ongoing operational changes.
The details are technical, but the theme is straightforward: Maker and Sky governance is still actively tuning the system behind USDS, vaults, spreads, rewards, and legacy assets.
That matters because Maker is no longer just a single stablecoin protocol in the old DAI sense. It is now a more complex governance and yield infrastructure stack, with the Sky brand, USDS, real-world asset exposure, and multiple moving parts that need regular adjustment.
TL;DR
MakerDAO governance executed new Atlas and settlement-cycle changes on July 20.
The update included Sky Spread reductions, LSSKY-SKY reward normalization, and RWA001-A offboarding.
The changes show the Sky transition is still being actively managed through governance.
Makerβs Governance Work Is Becoming More Operational
Maker governance has always been detailed, but the Sky transition has made it even more operational.
The protocol now needs to manage legacy Maker components, Sky-branded products, stablecoin demand, savings rates, vault parameters, and real-world asset exposure. Each of those pieces can affect liquidity, revenue, user behavior, and risk.
That is why these executive changes matter even when they do not look dramatic from the outside.
A spread adjustment can influence the economics of a product. A staking reward change can affect incentives. Offboarding an RWA vault can simplify risk exposure or retire older structures. None of those items is a full protocol reinvention on its own, but together they show governance actively shaping the system.
Makerβs Endgame roadmap was always ambitious. The harder part is implementation.
This kind of governance update is where that implementation happens.
Sky Spreads And USDS Economics
Sky Spreads are part of the economic machinery around the Sky ecosystem.
For users, the visible side of the system may be USDS, savings products, and yield opportunities. Underneath, governance has to set parameters that determine how value moves through the system and how different products remain aligned.
Reducing spreads can make certain activity more attractive, depending on the specific product and market context. It can also reflect governanceβs attempt to keep the system competitive as stablecoin users compare yields across DeFi and traditional markets.
That is a difficult balance.
If incentives are too low, users may leave for higher-yield alternatives. If they are too generous, protocol economics can become less durable. Maker and Sky governance therefore has to keep adjusting as rates, demand, and liquidity conditions change.
The July 20 execution fits that pattern.
Real-World Asset Offboarding Is Also Important
The offboarding of RWA001-A is another reminder that real-world asset exposure is not set-and-forget.
Maker became one of DeFiβs most important RWA-linked protocols because it used real-world collateral and yield sources to support the system. That helped stabilize revenue and connect the protocol to broader interest-rate conditions.
But RWA exposure also requires ongoing management.
Assets mature. Structures change. Risk preferences evolve. Governance may decide that certain vaults no longer fit the current strategy. Offboarding older vaults can help simplify the system and reduce unnecessary complexity.
For readers, the key point is that RWA growth is not only about adding new assets. It is also about removing or adjusting older ones when they no longer serve the protocol well.
That is part of mature balance-sheet management.
Maker And Sky Still Need Clarity
The biggest challenge for Maker may not be governance activity. It may be communication.
The Maker-to-Sky transition introduced new branding, new product names, and new governance language. Existing users may understand DAI and MKR, but Sky, USDS, Endgame, Atlas edits, spreads, and settlement cycles can feel dense.
That complexity can make it harder for outsiders to understand what is changing and why.
At the same time, the protocolβs underlying direction is clear enough. Maker/Sky is trying to build a more scalable stablecoin and yield ecosystem, supported by governance-controlled parameters, real-world asset exposure, and long-term revenue mechanisms.
The July 20 execution is one more step in that process.
It does not mark the end of the transition. It shows the transition is still active, technical, and governance-driven.
For DeFi, that matters. Maker remains one of the sectorβs most important experiments in decentralized monetary infrastructure. Its daily governance details may be dry, but they shape how billions of dollars in stablecoin liquidity, collateral, and yield ultimately behave.
Whether or not your smart TV is spying on you, LG wants to make sure the apps aren't part of the problem. The tech giant is banning webOS apps that use residential proxies to rent out your TV's internet connection to third parties.
Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called βARTokenβ thatβs built on the EvilTokens phishing platform. ARToken focuses on targeted social engineering attacks, allowing operators to customize phishing attempts for each victim.
Standby mode is both a blessing and a curse. Fast startup times and background processes are convenient, but have you ever stopped to ask how much these services are worth to you per year?
Smart home assistants were supposed to get better over time. More natural, more reliable, better integrated with everything else you already use. Google had every reason to lead that charge.
Part of our work involves supporting red team engagements. We review completed tests, size up the risk tied to each vulnerability and build out recommendations for shoring up the infrastructure. This time around, we wanted to pull back the curtain on something special. Itβs ATM security.Β
This article is written to help with security assessments on ATMs, showing possible vulnerabilities you may find. It covers many things, from running malware bought off a forum, to an insider on the bankβs payroll, to a service technician who understands the machineβs internals and has been handed broad access to the equipment. We also look at whether a hacker could get into the bankβs broader network simply because the perimeter wasnβt locked down well enough.
Nothing here is meant as a tutorial. Weβre documenting weaknesses hackers could exploit so that defenders know what to fix, not handing anyone a blueprint. We take no responsibility for how this information is used.
With that out of the way, letβs start with where ATMs came from.
The History of ATMs
London got the worldβs first working ATM on June 27, 1967. It was primitive by todayβs standards, incapable of checking a balance, which is exactly why withdrawals topped out at 10 pounds, and it dispensed cash only against special vouchers rather than reading a card.Β
Source: Barclays Bank
Nearly six decades later, ATMs look nothing like those early cash dispensers. Now they are multifunctional devices, but the hackers never stopped circling. Part of the appeal is obvious. An ATM sits on a pile of cash and offers quick access to it, and there are simply too many machines scattered across too many places to guard them all closely. A lot of them sit in isolated, low traffic spots that run unattended around the clock, think gas stations. That has shaped decades of security investment, most of it aimed at physical hardening. Todayβs units can weigh over half a ton and come loaded with sensors tracking position, internal temperature, and whether a compartment has been pried open.
Hereβs the catch, though. The safe holding the cash is genuinely hard to crack, but the compartment housing the control electronics is a different story, and in our assessment, it remains poorly defended. That gap opens the door to logical attacks, ones that skip the crowbar entirely and go after the software instead, and that category has been gaining ground fast.
Cisco Talos has tracked a steady climb in new ATM malware variants since 2009. The raw sample count still looks small next to other malware families, but donβt let that fool you. Europe alone saw logical attacks on ATMs jump 269% in 2020 versus the year prior, and the average payout per incident ballooned nearly a thousandfold across that same window, climbing from roughly a thousand euros to well over a million.
What changed the game was availability. ATM malware used to be a rare, closely guarded tool. Once it started circulating more freely on underground markets, prices fell and so did the skill required to use it. Cutlet Maker, which surfaced in 2017, is a good illustration. It came bundled with a Russian language manual complete with troubleshooting notes for running it against different ATM models.
Screenshot of the troubleshooting guide for Cutlet Maker. The author describes the ATMβs USB port location, along with advice on how to devise a stick for attaching the USB cable and accessing the internal USB port. Source: TrendMicro
Fast forward to 2024, and vendors on those same markets were offering ATM malware through subscription pricing, monthly plans included.
Logical attacks have always had one real weakness. They take skill and patience to pull off. Thatβs why cheap, well documented malware kits have had such an outsized impact on the trend. Their upside for hackers is just as real. Theyβre far quieter than smashing a machine open, and they often let the same person come back to a compromised ATM again and again. Manufacturers have started fighting back on the hardware side too, with tamper protected cassettes that flood the cash inside with indelible ink the moment someone tries to force them open, ruining the bills instantly.
Brief Attack Statistics
The numbers tell their own story. ATM related crime climbed 600% between 2019 and 2022, with 165% of that increase packed into 2021 and 2022 alone. Physical break ins, which have always driven the bulk of ATM crime, contributed alongside the rise in logical attacks. Germany had 496 ATM explosions recorded in 2022, a record for the country. Zoom out globally, and incidents of that kind blew past 18,000 in 2023.
Losses have kept pace. Banks worldwide absorbed $2.4 billion in direct losses from ATM fraud by the close of 2023. Europeβs share came to 173 million euros, with 67 million of that tied specifically to skimming. The United States handles just 25.29% of global transaction volume yet accounts for 42.32% of global losses. Skimming remains a big part of why, showing up in 45% of all ATM fraud cases in 2023 and costing North America over $900 million, with more than 315,000 cards compromised across at least 3,000 financial institutions.
None of this is happening in a vacuum. The market for ATM protection has grown right alongside the threat. Still, priorities inside most banks remain lopsided. Physical security tends to get the lionβs share of attention, while the operating system, drivers, and control software logic running underneath often get treated as an afterthought. That imbalance carries real consequences. A 2022 RTM Group study found that hackers could breach an ATMβs housing without setting off an alarm in one out of every two attempts, giving them free rein to tamper with the equipment inside.
How an ATM Is Built
Making sense of how these attacks work starts with understanding what happens inside the machine during an ordinary transaction. Weβll walk through that process using one representative configuration, illustrated in the diagram below.
The diagram reflects one specific setup weβre using for illustration, not a universal default, since real world configurations vary by device.
1. User Layer
From where the customer stands, using an ATM is simple. They need to present a card and pick a transaction. That wasnβt always the whole story. Inserting a physical card into a reader used to be the only entry point, and that reliance on the magnetic stripe made skimming and shimming, techniques aimed at stealing card data to produce counterfeit copies, a persistent problem for years.
Contactless cards changed the entry point itself. NFC readers now sit alongside traditional card slots on most machines.Β
A PIN code layers on additional protection against someone using a stolen card. Entry happens through an encrypting PIN pad, a combination of physical keypad and cryptographic module that ensures the PIN never travels or gets stored anywhere in plain text. Verification of the resulting encrypted PIN block happens back at the processing center.Β
Once identity checks clear, you can withdraw cash, check your balance, transfer funds, and so forth. Thereβs a full computer running inside the housing, but customers never get anywhere near it directly. Every interaction they have flows through a single banking application running in kiosk mode, locked to full screen.
2. OS Layer
That computer we just mentioned lives inside whatβs called the service zone, and this section covers what happens there, setting the cash handling hardware aside for the moment. Physically, the service zone is protected by a thin door and a basic lock. Machines from the same product line frequently share an identical key too, one thatβs often available for purchase online with minimal effort.
Beyond the system unit itself, the service zone also houses the ATMβs networking equipment and its wired connections to the card reader, contactless reader, PIN pad, and dispenser, typically running over USB, Ethernet, PCI, or COM interfaces depending on the device.
Windows powers most of these systems, historically through Windows Embedded and increasingly through Windows IoT, a Windows 10 variant built for embedded use.
The kiosk application isnβt the only thing running on that OS. Alongside it sits the ATMβs control software plus a handful of security tools. That can be antivirus protection, Windows AppLocker that keeps unauthorized programs from executing, and a VPN client that maintains a secure tunnel back to the bankβs internal network.
Control software is arguably the most important piece at this layer. Core responsibilities for the control software boil down to managing peripherals and communicating with the processing center, though specific implementations often add more on top of that. Some bundle in software for a monitoring server, letting technicians manage an entire network of self service machines remotely. Others are built in a supervisor mode meant purely for technical staff, offering quick access to diagnostic tools through a hidden menu to simplify physical maintenance visits.
3. Network Layer
Selecting a transaction sets off a verification process handled entirely by the processing center, a server living on the bankβs internal network. That server confirms the card data is legitimate, checks the PIN again before letting the transaction through, rules out any restrictions on the account, and verifies thereβs enough balance to cover the request.
Everything exchanged between the ATM and the processing center travels encrypted, usually through a VPN tunnel, protecting against interception or tampering along the way. NDC and DDC are the most common messaging protocols in this exchange, functioning as something of an informal industry standard even before multi-vendor control software became widespread. ISO 8583 and its various offshoots see heavy use as well.Β
The processing center isnβt the only thing an ATM talks to. Many machines also maintain a connection to a monitoring server used for remote management, health checks, and pushing updates, and unlike the processing center link, this channel frequently runs without any encryption at all.
4. Firmware Layer
Once the processing center signs off, the control software hands things over to the dispenser for a withdrawal, or the deposit module if cash is going in. These components typically sit inside the most fortified section of the ATM, the safe zone, built from tougher materials and secured with its own dedicated key separate from the service zone.Β
The dispenser counts out the required banknotes from the ATMβs cassettes, moves them into position at the dispensing tray, then opens the shutter, the physical flap that blocks access to the cash until itβs ready. Data moving between the control software and the dispenser can be encrypted, and both sides authenticate one another before any exchange begins, a safeguard against device spoofing. All of that encryption and authentication logic lives directly in the dispenserβs own firmware.Β
Deposits work differently. Incoming banknotes pass through a validator that checks their authenticity.
ATM Attacks
With the mechanics of an ATM covered, we can turn to the threats themselves. Every attack against these machines falls into one of two broad camps, physical or logical, depending on what the hacker is going after and how they approach it.
Physical attacks go straight after the machine or its components, aiming to extract cash or knock the device out of normal operation without touching a line of code. These predate targeted malware by decades and donβt require much specialized skill. Some donβt even target the machine itself, focusing instead on the people standing in front of it.
Logical attacks operate on a different level entirely. They demand genuine technical skill and preparation, built around exploiting weaknesses in the ATMβs software and network layers. They draw less public attention than physical attacks despite posing a bigger threat to banks, largely because theyβre quieter and let a hacker return to the same compromised machine to cash in more than once.
System attacks go after functionality or logic running at the ATMβs OS layer, typically aiming to extract cash or sidestep security controls outright. Black box attacks deserve special attention, where a hacker skips gaining OS access altogether and instead wires their own device directly into the dispenser to control it externally. The same technique can target other peripherals, like the banknote validator.
Network attacks aim at the ATMβs networking components instead, with hackers looking to intercept, forge, or otherwise abuse data in transit, or to seize remote control of the machine. With weak enough safeguards in place, a hacker can forge the responses coming back to the ATM and push through a cash withdrawal even after the processing center rejected it.
Not every attack in this framework ends with cash in hand. A hacker might, say, work to gain remote network access first, then pivot into an OS layer attack from there.Β
We have seen cases where compromising a single ATM meant compromising the entire bank because there was no network segmentation in place. Conversely, gaining access to the bankβs internal network could provide a path to ATMs and other critical systems connected to it. Credential reuse and a lack of understanding of Active Directory security can lead to devastating consequences in environments like these.
Summary
ATMs have evolved from simple cash dispensers into complex and networked systems. Their security has evolved unevenly alongside them. Physical hardening has made the cash safe itself genuinely difficult to crack, but the service zone housing the control electronics remains comparatively exposed, and that gap has fueled a steady rise in logical attacks. These attacks demand more skill than a physical break-in, but theyβre increasingly accessible because of well-documented malware kits.
Cybersecurity is a vast field, and we offer courses covering a wide range of topics, including Active Directory Hacking, Wi-Fi Hacking, Web Application Hacking, SCADA Security, and much more. Our course library is constantly growing as we continue to add new training, all of which is available through our Member Gold plan. If you want unlimited access to our entire training library, including our most advanced courses, consider upgrading to Subscriber Pro.
Cybercrime used to have a β"tell."Β It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelt links and suspicious attachments that screamed βphishingβ.
Flavor-packed lentil dip comes together fast with serious protein and fiber punch! Lentils, roasted corn, veggies and crispy capers with herby pepper lime dressing is perfect for parties, potlucks, cookouts, and snacking! (gluten-free, soy-free, nut-free) High fiber, protein and iron!
This is the perfect lentil dip for summer. I was inspired by a lentil dip that went viral on TikTok, where you just take some lentils, add bruschetta and feta, Instead of those flavors, weβre adding a load of veggies and a fantastic dressing, and also crisp capers! All these flavors and textures have made this my fave this summer! Thereβs also kale in the dip, hidden along with some herbs, so itβs a great way to sneak in kale. Thereβs just so much amazing flavor and texture overall in this lentil dip.
Thereβs the protein from the lentils. There are the fresh, crunchy veggies, jalapeΓ±o, and onion. Thereβs sweetness from the corn and the apple, the tart freshness from the cherry tomatoes, and refreshing vibrancy from the lime zest.Β
The nutritional yeast adds a bit of cheesiness and protein, while the hemp seeds bump up the protein and texture even more. And all of that balances out with a hint of spice from the jalapeΓ±o and the pepper flakes and a savory burst of flavor from the crispy capers.
This lentil dip is a great source of protein, fiber, vitamin C, B vitamins, potassium, magnesium, and iron because of all the plant-based ingredients in it. You can use whichever veggies you have on hand. If you donβt like lentils, you can use chickpeas or white beans and add some more spices to the dressing.Β
Make this dip and serve it with tortilla chips, crispy crackers, garlic bread or baguette slices. You can also use it to make wraps with pita bread or tortillas. Itβs a versatile lentil dip that will disappear in no time.Β
Why Youβll Love this Lentil Dip
protein- and veggie-packed dip with amazing flavors and textures
quick and easy herb-lime dressing comes together in 1 jar
crispy capers add a little crunch and a ton of umami
From powerful air movers and whisper-quiet pedestal models to options that double as misters, lamps, and air purifiers, these are the fans that impressed us most.
Your smart home sometimes requires your attention in the same way that your brick-and-mortar home does. Remembering these tasks can help you avoid problems later on.
As predominantly indoor creatures, itβs important to maintain a healthy habitat for the hacker. [Kishan Pratap Singh] designed a clever solution in AirSense, an ESP32-powered air filter.
If youβre thinking of cleaning the air in your environment, you might also want to know some properties about the air coming out of the filter. AirSense measures PM2.5 dust concentration, Air Quality Index (AQI), temperature, humidity, and atmospheric pressure. The various sensors are mounted along the exhaust path of the filter, which lets your know what kind of air itβs pumping out.
The system drives a 150 mm exhaust fan mounted in a 3D printed cap that pulls air through a cylindrical Xiaomi HEPA filter inside a perforated metal trash can enclosure. The ESP32 and an LCD readout of the environmental data also live in the cap, giving the device a sleek look. While [Singh] chose to run the filter continuously, we wonder if it might be interesting to set it up to only filter the air if air quality drops below a certain level to conserve power, especially if youβre on a time-of-use power plan. That would require redesigning the sensor assembly (or running the unit in reverse), so maybe itβs over-complicating things?
Google has released a Chrome security update that addresses 12 high-severity vulnerabilities affecting various components, including WebAudio, ANGLE, Chromecast, extensions, Skia, the V8 JavaScript engine, certificate handling, the user interface, and GPU elements. Many of these vulnerabilities involve memory corruption issues, such as out-of-bounds reads and writes, use-after-free bugs, stack buffer overflows, and type confusion. [β¦]
Jupiter Passes $1T In Cumulative Solana Swap Volume
Jupiter has passed $1 trillion in cumulative routing volume, cementing its role as one of the most important DeFi applications in the Solana ecosystem.
The milestone reflects aggregate swap volume routed across connected Solana liquidity pools. Jupiter is not just a single exchange pool. It is an aggregator, meaning it searches across venues to find better pricing and execution for users.
That role makes it central to Solana trading.
When users swap tokens on Solana, Jupiter is often part of the route. Passing $1 trillion in cumulative volume shows how much trading activity has flowed through the platform and how important aggregation has become for low-cost, high-speed DeFi.
TL;DR
Jupiter has passed $1 trillion in cumulative Solana routing volume.
The platform aggregates liquidity across connected Solana pools.
The milestone reinforces Jupiterβs role as a core Solana DeFi venue.
Liquidity is spread across pools, AMMs, order books, and protocols. If users have to manually search for the best route, trading becomes inefficient. Aggregators solve that problem by routing trades through the best available path.
Jupiter has become Solanaβs most recognizable example of that model.
It helps users access deeper liquidity without needing to understand every underlying venue. That is especially useful on Solana, where low fees make smaller and faster trades more practical.
The $1 trillion milestone shows that users are not just experimenting with Jupiter. They are relying on it as part of Solanaβs core market structure.
That matters because DeFi ecosystems are often judged by their liquidity layer.
If swaps are cheap, fast, and well-routed, the entire ecosystem becomes easier to use.
Solana DeFi Keeps Maturing
Solanaβs early DeFi story was often overshadowed by meme coins and retail trading.
That attention brought volume, but it also made some investors question how much activity was durable. Jupiterβs cumulative volume milestone gives Solana a stronger infrastructure story.
A trillion dollars in routed volume does not happen without repeated use.
It suggests a large amount of trading activity has moved through Solanaβs DeFi rails over time. That strengthens the argument that Solana is not only a speculative chain but also a serious venue for decentralized trading.
The launch of Jupiterβs Offerbook lending market adds another layer.
If Jupiter can expand from routing swaps into lending and broader market infrastructure, it may become even more central to Solanaβs DeFi stack.
Cumulative Volume Needs Context
The number is impressive, but it should be understood properly.
Cumulative volume is not the same as current daily volume. It reflects all historical routing activity across connected pools. It does not mean $1 trillion is locked in the protocol, and it does not mean that every trade produced equal revenue or user value.
Still, cumulative volume is a useful adoption marker.
It shows that Jupiter has processed meaningful activity over a long period. For users, that can reinforce trust. For developers, it shows where liquidity is flowing. For Solana, it supports the networkβs claim to be one of cryptoβs leading trading environments.
The next question is how Jupiter maintains that position.
Competition in DeFi is constant. Aggregators need to keep routes efficient, interfaces clean, integrations broad, and execution reliable. If they fall behind, users can move quickly.
Jupiter Is Becoming More Than A Swap Router
The broader story is Jupiterβs evolution.
The platform started as a critical swap aggregator, but it has increasingly expanded into other Solana-native financial products. Offerbook is part of that shift, pointing toward a wider DeFi role beyond simple token swaps.
That matters for Solana.
A strong ecosystem needs anchor applications. Ethereum has Uniswap, Aave, Lido, and Curve. Solana needs its own set of core venues that users return to repeatedly. Jupiter is clearly one of them.
Passing $1 trillion in cumulative routing volume reinforces that position.
For traders, it shows where Solana liquidity is moving. For SOL supporters, it gives a concrete metric supporting the networkβs DeFi maturity. For Jupiter, it raises expectations.
The platform now has to prove that it can keep growing beyond aggregation while maintaining the execution quality that made it important in the first place.
For now, the milestone is a strong signal: Solana DeFi has real volume, and Jupiter remains one of its main arteries.
This article is based on Jupiterβs public statement and platform data.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released in official primary source disclosures at primary source documentation.
Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns.