Connect with us

Tech

Hackers are abusing unpatched Windows security flaws to hack into organizations

Hackers have broken into at least one organization using Windows vulnerabilities published online by a disgruntled security researcher over the last two weeks, according to a cybersecurity firm.

On Friday, cybersecurity company Huntress said in a series of posts on X that its researchers have seen hackers taking advantage of three Windows security flaws, dubbed BlueHammer, UnDefend, and RedSun. 

It’s unclear who the target of this attack is, and who the hackers are.

BlueHammer is the only bug among the three vulnerabilities being exploited that Microsoft has patched so far. A fix for BlueHammer was rolled out earlier this week. 

It appears that the hackers are exploiting the bugs by using exploit code that the security researcher published online. 

Earlier this month, a researcher who goes by Chaotic Eclipse published on their blog what they said was code to exploit an unpatched vulnerability in Windows. The researcher alluded to some conflict with Microsoft as the motivation behind publishing the code. 

“I was not bluffing Microsoft and I’m doing it again,” they wrote. “Huge thanks to MSRC leadership for making this possible,” they added, referring to Microsoft’s Security Response Center, the company’s team that investigates cyberattacks and handles reports of vulnerabilities.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

Days later, Chaotic Eclipse published UnDefend, and then earlier this week published RedSun. The researcher published code to exploit all three vulnerabilities on their GitHub page

All three vulnerabilities affect the Microsoft-made antivirus Windows Defender, allowing a hacker to gain high-level or administrator access to an affected Windows computer.

TechCunch could not reach Chaotic Eclipse for comment.

In response to a series of specific questions, Microsoft’s communications director Ben Hope said in a statement that the company supports “coordinated vulnerability disclosure, a widely adopted industry practice that helps ensure issues are carefully investigated and addressed before public disclosure, supporting both customer protection and the security research community.”

This is a case of what the cybersecurity industry calls “full disclosure.” When researchers find a flaw, they can report it to the affected software maker to help them fix it. At that point, usually the company acknowledges receipt, and if the vulnerability is legitimate, the company works to patch it. Often, the company and researchers agree on a timeline that establishes when the researcher can publicly explain their findings. 

Sometimes, for a variety of reasons, that communication breaks down and researchers publicly disclose details of the bug. In some cases, in part to prove the existence or severity of a flaw, researchers go a step further and publish “proof-of concept” code capable of abusing that bug.

When that happens, cybercriminals, government hackers, and others can then take the code and use it for their attacks, which prompts cybersecurity defenders to rush to deal with the fallout. 

“With these being so easily available now, and already weaponized for easy use, for better or for worse I think that ultimately puts us in another tug-of-war match between defenders and cybercriminals,” John Hammond, one of the researchers at Huntress who has been tracking the case, told TechCrunch. 

“Scenarios like these cause us to race with our adversaries; defenders frantically try to protect against ill-intended actors who rapidly take advantage of these exploits… especially now as it is just ready-made attacker tooling,” said Hammond.

source

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Cathie Wood’s ARK makes its first lead investment in startup Lucra — and it isn’t AI 

ARK Invest Venture Fund has made its first-ever lead investment in an early-stage startup called Lucra, firm founder Cathie Wood told TechCrunch.  

“We feel pretty excited about it,” Wood (pictured above) said in the recent interview regarding the investment in the startup.

Lucra developed a software platform that reimagines corporate loyalty programs into interactive, esports-like events such as tournaments where customers can play each other, even betting or winning cash or company giveaways. The startup said its customers include Five Iron Golf, Chess Kings, and Dave & Buster’s.

Lucra announced on Wednesday that it raised a $20 million Series B, led by the ARK fund, with participation from Alumni Ventures, Astralis Capital, Harlo Equity Partners, Simplex Ventures, SeventySix Capital, and WTI. 

There are a few reasons why the famed financial company has never led a startup deal before. For one, the ARK Invest Venture Fund is not a typical VC fund. It’s an SEC-regulated interval fund (also known as a closed-end mutual fund), meaning anyone can invest in it, for as little as $500. However, it is not traded on a public exchange, so investors cannot sell shares at will. They can sell limited shares on specific dates, quarterly.  

Wood also noted that the person running the fund, director of research Nick Grous, “is a tough sell,” leaving startups with the difficult task of getting him excited enough to advocate to lead a deal.

What’s even wilder is that ARK was particularly gun-shy about this sort of business because it got burned after investing in a somewhat similar company a few years ago.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

“We had actually owned a company called Skillz, which kind of operated in this space,” Grous said. “It didn’t work out well for us and many other investors.” 

Skillz was a once-hot public company that later became mired in troubles and lawsuits. The big difference, the investor said, is that Lucra is a B2B platform, selling interactive esports as a loyalty program, rather than trying to license and run games directly to consumers.

“Overcoming our initial hurdle, especially given our experience with Skillz, overcoming our reticence, having Nick overcome it, that was our first screen,” Wood said of how this startup convinced her company to write a big check. 

In this case, ARK Invest had participated in Lucra’s previous Series A round, and had grown familiar with its business model, its trajectory, and its founder and CEO Dylan Robbins, Grous told TechCrunch.  

“We had been in constant communication,” Grous said, adding that his venture-esq fund attempts to have quarterly conference calls with the startups in the portfolio, similar to how public companies report to investors quarterly. ARK mostly works in the public market, offering a slate of publicly traded EFT funds.  

ARK Invest Nick Grous
Nick GrousImage Credits:ARK Invest

Despite already being in the portfolio, Lucra’s founder was grilled numerous times when it came time to buy more shares — first by Grous and then ARK’s investment committee, both he and Wood described. 

During those calls, Robbins “had thought about all the things that went wrong” with similar companies like Skillz, as well as with Lucra, and had answers, Wood said. “No matter how many times we went at him, his conviction, there was just no let up,” she described. 

It also helped that this company’s financials were promising, it was in an area that ARK knew well, and this was not AI, aka the most hyped, most expensive area these days.

“We’ve been underwriting the sports-betting space, understanding the gamification aspects of entertainment,” Grous said, meaning that the investment firm could “really understand the opportunity here.” 

The ARK Invest Venture Fund holds shares of companies like Epic Games, Kalshi, and Discord, for instance. It also holds OpenAI, Anthropic, Replit, Grok, and Perplexity, so it knows the AI scene well.  

“We are all over AI, just like everyone else, because it is a massive revolution,” Wood explained. “But in the process, a lot of companies are being neglected.” This means that spotting such potentially neglected companies is “our opportunity because we are doing research in many other areas than AI,” she said.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

Cosmetics giant Rituals confirms data breach of customer membership records

Netherlands-based cosmetics giant Rituals has confirmed a data breach affecting customers’ personal information after hackers stole reams of data from its membership database.

The company disclosed the breach on Wednesday, according to an email sent to customers that TechCrunch has viewed and verified. 

Rituals said it identified an “unauthorized download” of members’ data in April that contained customers’ full name, date of birth, gender, postal and email address, and phone number, as well as their preferred Rituals store and account type.

When reached by TechCrunch, Rituals spokesperson Eline van Malssen said the hacker stole membership data about customers in Europe and the United Kingdom.

TechCrunch has learned that some customers notified by Rituals are based in the United States. The spokesperson confirmed the incident also affects some U.S. customers.

Rituals did not describe the nature of the cyberattack and the company said its investigation was underway to understand how the data breach happened. 

The cosmetics giant is the latest retailer to have customer membership data stolen in the past year, following a string of intrusions at U.K. grocery and shopping chain Co-op and Marks & Spencer, among others. Customer records can be attractive targets for hackers who steal the data and extort the company for a ransom in exchange for not publishing the information online.

When reached with questions about the incident, a Rituals spokesperson declined to comment on whether the company received any communication from the hackers, to share a more precise timeline of the breach, or to provide the exact number of affected members, citing unspecified “security reasons.”

According to its website, Rituals has over 41 million customers in its membership database. The retail giant made €2.4 billion euros ($2.8 billion) in revenue in 2025.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

Rivian R2 production has started despite tornado damage to factory

Rivian has rolled the first customer-ready R2 SUVs off the production line at its factory in Normal, Illinois, just days after it was hit by an EF-1 tornado that tore off part of the roof.

Despite the damage, founder and CEO RJ Scaringe told Bloomberg Television on Wednesday morning that Rivian doesn’t expect any delays to the R2’s rollout, which is crucial to the company’s survival.

“The tornado went through the south end of the plant, and ripped the roof off the building, and knocked down some of the plant as well, and so the last 72 hours have been around the clock,” he said. Scaringe explained that Rivian has had to change how and where it brings some materials into the factory to build the R2.

But “we’re not making any changes to the plan,” he said, referring to the company’s production roadmap.

Scaringe wasn’t asked when Rivian will make the first R2 deliveries during the interview. The company has previously said it will start shipping R2 SUVs before the first half of 2026 comes to an end.

Getting the R2 into production is a major milestone for the company. It’s the first production vehicle Rivian has made that has a chance to reach mass-market customers, as it costs far less than the company’s current R1 EVs. It’s also supposed to help the company finally reach profitability after years of losing money on every vehicle it sold.

The company has big expectations for the R2. Rivian told investors earlier this year that it expects to deliver between 20,000 and 25,000 of the SUVs by the end of 2026. If Rivian achieves that, it would become one of the fastest-scaling new EVs ever launched in the U.S., second only to Tesla’s Model Y.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

That said, Rivian is launching with a version of the R2 that costs nearly $13,000 more than the $45,000 price tag the company spent years promoting. The launch edition R2 starts at $57,990, with a slightly cheaper $53,990 variant coming by the end of this year. Rivian won’t sell an R2 for under $50,000 until the first half of 2027, and a true base model starting at $45,000 won’t hit the market until late 2027.

And that’s if the $45,000 R2 ever arrives at all. When Rivian announced pricing for the SUV in March, the company said the base model price will start “around $45,000” — not “at $45,000” as it had promoted on its website as recently as February.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading