Category: Uncategorized

  • TikTok US denies claims it is censoring content

    TikTok US denies claims it is censoring content


    Liv McMahonand

    Kali Hays,Technology reporters

    Getty Images TikTok logo shown on a smartphone against a backdrop illustrating rising and falling reports with a red lineGetty Images

    TikTok has denied claims that its new US operations are heavily-controlling what users post after thousands reported glitches with the video streaming platform.

    In a response to the BBC, a spokesperson for TikTok US reiterated an earlier statement pointing to technical issues being the reason for issues since it became a separate American entity last week.

    “We’ve made significant progress in recovering our US infrastructure with our US data center partner,” they said. “However, the US user experience may still have some technical issues, including when posting new content.”

    They also pushed back on users’ claims they were not able to use the name “Epstein” on TikTok.

    It refers to Jeffrey Epstein, the dead convicted sex offender and financier. The Trump administration has continued to face fierce scrutiny for its handling of the Epstein case.

    TikTok said there are no rules against sharing the name “Epstein” in direct messages.

    While the company said problems identified with the platform are being addressed, California Governor Gavin Newsom has nevertheless announced an investigation into claims TikTok has censored content which is critical of the Trump administration.

    Last Thursday, a deal was concluded to split off the US operation of the app – three days later thousands of American users began reporting problems including seeing “zero views” on new posts.

    Many also reported being unable to see political posts, such as content criticising the shooting by federal agents of ICU nurse Alex Pretti in Minneapolis on Saturday.

    Newsom’s office said it has received confirmed reports of TikTok suppressing content critical of President Donald Trump.

    “Following TikTok’s sale to a Trump-aligned business group, our office has received reports – and independently confirmed instances – of suppressed content critical of President Trump,” wrote the California governor’s office on X on Monday.

    His post linked to another X user’s post containing a screenshot from TikTok, that appeared to show the video-sharing app flagging up a message they tried to send saying “Epstein”.

    It said Newsom would be “launching a review of this content” and probe whether the company had violated the state’s laws.

    Allow X content?

    This article contains content provided by X. We ask for your permission before anything is loaded, as they may be using cookies and other technologies. You may want to read  and  before accepting. To view this content choose ‘accept and continue’.

    The same flag seemingly appeared for other US TikTok users when they tried to message others with the Epstein surname, according to social media posts seen by BBC News.

    Many users are speculating that this, combined with some political content not displaying in the app’s For You feed or in search, may be censorship by TikTok’s new US owners – with investors and directors some believe have ties to Trump.

    Celebrities have also spoken out over similar concerns about the app.

    Hacks actress Meg Stalter told Instagram followers on Sunday she had deleted her TikTok account because the app was “under new ownership and we are being completely censored and monitored”.

    Similar views have been echoed across social media, with many US users questioning in posts whether the app is “cooked”.

    Allow X content?

    This article contains content provided by X. We ask for your permission before anything is loaded, as they may be using cookies and other technologies. You may want to read  and  before accepting. To view this content choose ‘accept and continue’.

    “Extremely slow”

    Users of the video-sharing app in the US have been posting on social media about problems throughout the outage, which began on Sunday.

    Platform outage monitor Downdetector told the BBC it had received 663,061 reports of issues from US users of TikTok between Saturday and Monday.

    “Okay so is anyone else’s TikTok being extremely slow, keeps showing you old videos, doesn’t show you what you what you actually search, and doesn’t load certain stuff….,” one X user asked on Sunday.

    Some users said they could not view creator monetisation tools on the app, with others noticing new videos they had uploaded to the platform did not have the same visibility as usual or were “stuck at zero views”.

    Allow X content?

    This article contains content provided by X. We ask for your permission before anything is loaded, as they may be using cookies and other technologies. You may want to read  and  before accepting. To view this content choose ‘accept and continue’.

    TikTok’s US owner said on Monday users may notice “multiple bugs, slower load times or timed-out requests” as it it worked to resolve issues triggered by a power outage at one of its data centre partner Oracle’s sites.

    “While the network has been recovered, the outage caused a cascading systems failure that we’ve been working to resolve together with our data centre partner.” it said.

    The company also sought to reassure users their data and content engagement “were safe”.

    As with the many other issues reportedly affecting the TikTok app and its sister app CapCut since Sunday, they appeared to be largely contained to the US.

    As part of Trump’s deal allowing TikTok to continue operating in the US, Oracle will inspect and retrain a separate version of its algorithm for American users.

    The cloud giant is one of three managing investors in TikTok USDS Joint Venture LLC, maintaining a 15% stake in the spun-off US entity.





    Source link

  • Carney denies walking back Davos speech in phone call with Trump

    Carney denies walking back Davos speech in phone call with Trump


    Canadian Prime Minister Mark Carney has told reporters he stands behind his speech in Davos calling out unconstrained super powers, after a Trump official said he had “aggressively” walked it back in a call with US President Donald Trump.

    “To be absolutely clear, and I said this to the president, I meant what I said in Davos,” Carney said on Tuesday, confirming he and Trump had spoken by phone.

    US Treasury Secretary Scott Bessent had told Fox News on Monday that Carney was “very aggressively walking back” some of the remarks to Trump.

    Carney made global headlines for his Davos speech, in which he indirectly called out the US president for a “rupture” in the postwar world order.

    Trump responded in his own Davos speech the following day by saying that “Canada lives because of the United States”.

    Speaking to reporters in Ottawa on Tuesday, Carney denied Bessent’s recollection of the phone call.

    He added that it was the US president who had called him on Monday, and that the two had a “very good conversation on a wide range of subjects”, including Ukraine, Venezuela, Arctic security and Canada’s recent trade agreement with China.

    Carney said the two also discussed the USMCA, a free-trade pact between Canada, the US and Mexico that is up for a mandatory review later this year.

    Carney said his speech in Davos clearly outlined how “Canada was the first country to understand the change in US trade policy that (Trump) had initiated, and we’re responding to that”.

    He added that the president understood Canada’s position.

    In the Fox News interview on Monday, Bessent criticised Canada’s decision to negotiate a trade deal with China. He added that he was “not sure what the Prime Minister was thinking” when he made his speech in Davos.

    “Canada depends on the US,” Bessent said. “There’s much more north-south trade then there could ever be east-west trade.”

    “The prime minister should do what’s best for the Canadian people rather than try to push his globalist agenda,” the treasury secretary added.

    His remarks came after Trump threatened Canada with 100% tariffs on its goods if it allows Chinese goods to flow freely to the US, skirting levies.

    The deal between Ottawa and Beijing would lower levies on Canadian canola oil from 85% to 15% by March, while Canada will tax a limited number of Chinese electric vehicles, or EVs, at the most-favoured-nation rate, 6.1% – down from 100%.

    Carney said that Canada is not pursuing a free-trade deal with China and has “never” considered it.

    Speaking to reporters on Monday, Carney added that he believed Trump’s latest tariff threat is a negotiation tactic ahead of talks on USMCA.

    “The president is a strong negotiator, and I think some of these comments and positioning should be viewed in the broader context of that,” he said.



    Source link

  • ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services

    ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services


    Cybersecurity researchers have disclosed details of a new campaign that combines ClickFix-style fake CAPTCHAs with a signed Microsoft Application Virtualization (App-V) script to distribute an information stealer called Amatera.

    “Instead of launching PowerShell directly, the attacker uses this script to control how execution begins and to avoid more common, easily recognized execution paths,” Blackpoint researchers Jack Patrick and Sam Decker said in a report published last week.

    In doing so, the idea is to transform the App-V script into a living-off-the-land (LotL) binary that proxies the execution of PowerShell through a trusted Microsoft component to conceal the malicious activity.

    The starting point of the attack is a fake CAPTCHA verification prompt that seeks to trick users into pasting and executing a malicious command on the Windows Run dialog. But here is where the attack diverges from traditional ClickFix attacks.

    The supplied command, rather than invoking PowerShell directly, abuses “SyncAppvPublishingServer.vbs,” a signed Visual Basic Script associated with App-V to retrieve and execute an in-memory loader from an external server using “wscript.exe.”

    It’s worth noting that the misuse of “SyncAppvPublishingServer.vbs” is not new. In 2022, two different threat actors from China and North Korea, tracked as DarkHotel and BlueNoroff, were observed leveraging the LOLBin exploit to stealthily execute a PowerShell script. But this is the first time it has been observed in ClickFix attacks.

    “Adversaries may abuse SyncAppvPublishingServer.vbs to bypass PowerShell execution restrictions and evade defensive counter measures by ‘living off the land,’” MITRE notes in its ATT&CK framework. “Proxying execution may function as a trusted/signed alternative to directly invoking ‘powershell.exe.’”

    The use of an App-V script is also significant as the virtualization solution is built only into Enterprise and Education editions of Windows 10 and Windows 11, along with modern Windows Server versions. It’s not available for Windows Home or Pro installations.

    In Windows operating systems where App-V is either absent or not enabled, the execution of the command fails outright. This also indicates that enterprise managed systems are likely the primary targets of the campaign.

    The obfuscated loader runs checks to ensure that it’s not run within sandboxed environments, and then proceeds to fetch configuration data from a public Google Calendar (ICS) file, essentially turning a trusted third-party service into a dead drop resolver.

    Cybersecurity

    “By externalizing configuration in this way, the actor can rapidly rotate infrastructure or adjust delivery parameters without redeploying earlier stages of the chain, reducing operational friction and extending the lifespan of the initial infection vector,” the researchers pointed out.

    Parsing the calendar event file leads to the retrieval of additional loader stages, including a PowerShell script that functions as an intermediate loader to execute the next stage, another PowerShell script, directly in memory. This step, in turn, results in the retrieval of a PNG image from domains like “gcdnb.pbrd[.]co” and “iili[.]io” via WinINet APIs that conceals an encrypted and compressed PowerShell payload.

    The resulting script is decrypted, GZip decompressed in memory, and run using Invoke-Expression, ultimately culminating in the execution of a shellcode loader that’s designed to launch Amatera Stealer.

    “What makes this campaign interesting isn’t any single trick, but how carefully thought-out everything is when chained together,” Blackpoint concluded. “Each stage reinforces the last, from requiring manual user interaction, to validating clipboard state, to pulling live configuration from a trusted third-party service.”

    “The result is an execution flow that only progresses when it unfolds (almost) exactly as the attacker expects, which makes both automated detonation and casual analysis significantly harder.”

    The Evolution of ClickFix: JackFix, CrashFix, and GlitchFix

    The disclosure comes as ClickFix has become one of the most widely used initial access methods in the last year, accounting for 47% of the attacks observed by Microsoft.

    Recent ClickFix campaigns have targeted social media content creators by claiming they are eligible for free verified badges, instructing them via videos to copy authentication tokens from their browser cookies into a fake form to complete the supposed verification process. The embedded video also informs the user to “not log out for at least 24 hours” to keep the authentication tokens valid.

    The campaign, active since at least September 2025, is estimated to have used 115 web pages across the attack chain and eight exfiltration endpoints, per Hunt.io. The main targets of the activity include creators, monetized pages, and businesses seeking verification, with the end goal being to facilitate account takeover following token theft.

    “Defending against the ClickFix technique is uniquely challenging because the attack chain is built almost entirely on legitimate user actions and the abuse of trusted system tools,” Martin Zugec, technical solutions director at Bitdefender, said in a report last month. “Unlike traditional malware, ClickFix turns the user into the initial access vector, making the attack look benign from an endpoint defense perspective.”

    ClickFix is also constantly evolving, utilizing variants like JackFix and CrashFix to deceive the victim into infecting their own machines. While operators use several methods to attempt to convince a target to perform command execution, the growing popularity of the social engineering technique has paved the way for ClickFix builders that are advertised on hacker forums for anywhere between $200 to $1,500 per month.

    The latest entrant to this threat landscape is ErrTraffic, a traffic distribution system (TDS) that’s specifically designed for ClickFix-like campaigns by causing compromised websites injected with malicious JavaScript to glitch and then suggesting a fix to address the non-existent problem. This technique has been codenamed GlitchFix.

    The malware-as-a-service (MaaS) supports three different file distribution modes that involve using fake browser update alerts, fake “system font required” dialogs, and bogus missing system font errors to trigger the execution of malicious commands. ErrTraffic is explicitly blocked from running on machines located in the Commonwealth of Independent States (CIS) countries.

    “ErrTraffic doesn’t just show a fake update prompt, it actively corrupts the underlying page to make victims believe something is genuinely wrong,” Censys said. “It also applies CSS transformations that make everything look broken.”

    ClickFix has also been adopted by threat actors behind the ClearFake campaign, which is known to infect sites with fake web browser update decoys on compromised WordPress to distribute malware. ClearFake’s use of ClickFix was first recorded in May 2024, leveraging CAPTCHA challenges for delivering Emmenhtal Loader (aka PEAKLIGHT), which then drops Lumma Stealer.

    The attack chain also makes use of another known technique referred to as EtherHiding to retrieve the next-stage JavaScript code using smart contracts on Binance’s BNB Smart Chain (BSC) and eventually inject the ClickFix fake CAPTCHA obtained from a different smart contract into the web page. At the same time, the final stage avoids re-infecting already infected victims.

    Cybersecurity

    Like in the case of the Amatera Stealer attack, the ClickFix command copied to the clipboard abuses “SyncAppvPublishingServer.vbs” to obtain the final payload hosted on the jsDelivr content delivery network (CDN). Expel’s analysis of the ClearFake campaign shows that as many as 147,521 systems have likely been infected since late August 2025.

    “One of many factors security products use to decide if behavior is malicious or not is whether said behavior is being performed by a trusted application,” security researcher Marcus Hutchins said. “In this case, ‘SyncAppvPublishingServer.vbs’ is a default Windows component, and the file can only be modified by TrustedInstaller (a highly privileged system account used internally by the operating system). Therefore, the file and its behavior alone would not normally be suspect.”

    “Organizations and EDR are unlikely to outright block ‘SyncAppvPublishingServer.vbs’ from launching PowerShell in hidden mode, as it would prevent the component from being used for its intended purpose. Consequently, by abusing the command line injection bug in ‘SyncAppvPublishingServer.vbs,’ attackers can execute arbitrary code via a trusted system component.”

    Expel also characterized the campaign as highly sophisticated and very evasive, owing to the use of in-memory PowerShell code execution, coupled with its reliance on blockchain and popular CDNs, thus ensuring that it does not communicate with any infrastructure that’s not a legitimate service.

    Censys has described the broader fake CAPTCHA ecosystem as a “fragmented, fast-changing abuse pattern that uses trusted web infrastructure as the delivery surface,” wherein Cloudflare-style challenges act as a conduit for clipboard-driven execution of PowerShell commands, VB Scripts, MSI installers, and even hand-offs to browser-native frameworks like Matrix Push C2.

    “This aligns with a broader shift toward Living Off the Web: systematic reuse of security-themed interfaces, platform-sanctioned workflows, and conditioned user behavior to deliver malware,” the attack surface management firm said. “Attackers do not need to compromise trusted services; they inherit trust by operating inside familiar verification and browser workflows that users and tooling are trained to accept.”



    Source link