Recent Posts

Pages: 1 ... 6 7 [8] 9 10
71
70+ fake sites are pushing malware right now



More than 70 popular Windows apps now have fake websites impersonating them, and some are already serving malware. The list includes widely used tools like PowerToys, CrystalDiskMark, EasyBCD, Lively Wallpaper, and Wintoys, all cloned onto lookalike domains that in most cases rank above the real project pages on Google.

Some apps on this list have already had their fake sites confirmed as active malware distributors. They may be pushing a trojanized installer that sets up a remote-access service on victims’ PCs.


Credit: u/Bogdan_X via Reddit

We strongly recommend downloading Windows apps only from the Microsoft Store or from the developer’s official website or GitHub page, and never from a random search result, however convincing it looks. If you’ve visited any of the following websites, treat your PC as compromised and scan it immediately:

Full list of fake websites impersonating Windows apps

The following domains were identified as impersonating legitimate Windows applications, all registered to the same owner through Epik Inc. before being moved to Dynadot LLC in July. Remember, not a single one of these is an official source for the apps it claims to represent, and please do not open these URLs. For testing, you can use Windows Sandbox.



Again, in case we are not clear already, steer clear of every domain on this list. They are not affiliated with the developers whose apps it claims to host.

How a developer discovered 70+ lookalike domains while checking his own app’s reviews

The developer behind Wintoys, a Windows optimization tool available on the Microsoft Store that lets users clean, repair, and tweak system settings without opening the terminal, habitually searches his app’s name on Google to see new reviews or user questions. During one of these searches, he found a domain he had not purchased showing up in the results (wintoys.app).



u/Bogdan_X explained on Reddit that the site was built on WordPress, with generic, inaccurate AI content, and used their old logo. Its download button surprisingly goes to the real Microsoft Store listing, which is likely why it hadn’t raised alarms yet.

He tried to trace ownership of the domain but couldn’t, since it was registered through Epik Inc., which bundles free WHOIS privacy into every domain, keeping the buyer’s identity hidden by default. What he did find was a troubling list of 72 domains.

Even Microsoft’s own PowerToys has a fake website!

These sites build trust first, then swap in malware later

According to Check Point Research, these impersonation sites have a three-stage playbook:

   1. They rank for a popular app’s name in search results

   2. Appear harmless at first by linking to real download sources

   3. Then quietly swap those links for malware after getting traffic and trust.


Impersonated websites of popular software tools (Source: Check Point Research)

Check Point found that some of these sites load a script from Amazon CloudFront that intercepts the click on a download button and reroutes it through a Traffic Distribution System, a filtering layer that decides where to send each visitor based on their location, browser, and whether they look like a bot or a security researcher.

Check Point traced malware families including RemusStealer, an infostealer targeting over 20 browsers and cryptocurrency wallets, and AnimateClipper, which swaps copied crypto wallet addresses for the attacker’s own. A cluster of these domains had been silently building search rankings since at least September 2025, with malware distribution that began in January 2026.


VirusTotal total submitters crossing 5,000 shows the scale of the operation (Source: Check Point)

Lively Wallpaper and SignalRGB confirm active attacks

Two developers on this list have already confirmed their impersonators are distributing real malware.

A GitHub issue filed against Lively Wallpaper describes a fake site at livelywallpaper.app serving a trojanized installer through a script hosted on giize.com. The installer bundled a legitimate DirectX setup file alongside a malicious, unsigned DLL, and installed a persistent remote-access service along with bandwidth-sharing software that likely resold the victim’s internet connection.



Lively’s developer confirmed the domain has no affiliation with the project and recommended users to the official Microsoft Store listing instead.

SignalRGB posted on Reddit about a fake site at signalrgb.io, which the team says has managed to rank near the top of some search engines, including Bing. The team later flagged a second impersonating domain, signal-rgb.net, and urged users who downloaded from either site to delete the file and run a full malware scan.

One commenter on the SignalRGB thread reported success getting a domain taken down after reporting it to Cloudflare with evidence, with Cloudflare confirming it had restricted access to the reported URL and forwarded the abuse report to the hosting provider.

Cloudflare flagged one domain within an hour, but most others are still unprotected

Cloudflare acted fast when the wintoys.app domain was reported, adding a “Suspected Phishing” interstitial warning that shows if a user visits the fake site, telling them the page has been reported for potential phishing. u/Bogdan_X confirmed the warning went up in under an hour of filing the report.



However, Cloudflare’s abuse form only accepts one domain per report, and u/Bogdan_X said that despite listing all 72 domains in his submission, the other 71 will likely be unprotected.

The 72 original domains have since been added to Hagezi’s DNS blocklist, a popular adblock list used by millions of people, which will now block those sites automatically for anyone running it. MKVToolNix, the popular video remuxing tool, has also been listed in this project.

Mica For Everyone, a Windows theming tool, is also being impersonated through a domain registered with Spaceship and hosted via Hetzner behind Cloudflare, the same registrar used for the fake Lively Wallpaper and SignalRGB sites. Its maintainer said the registrar’s abuse email went nowhere, and without a trademark on the app’s name, a formal takedown wasn’t an option, so the only workaround was asking Cloudflare to add a malware warning.

It isn’t confirmed if this is one operator spreading impersonation targets across multiple registrars to slow down takedowns, or several unrelated attackers copying the same playbook.

Windows apps aren’t uniquely at risk, but the platform makes them an easier target

This isn’t a Windows-specific flaw, and macOS isn’t inherently safe. The difference is scale. Windows is on a far larger share of desktop PCs than macOS, and a larger user base means more search volume for utility software, which makes Windows tools a bigger, more profitable target for this kind of operation.

Microsoft’s reputation adds to the problem. Years of ads, bloatware, and upsells in Windows 11 have left plenty of users skeptical of the Microsoft Store, so they turn to Google Search.


Fake Ghidra project website in Google search (Source: Check Point)

Ironically, searching the Microsoft Store first is still the safer move. If something goes wrong with an app sourced from the Store, at least Microsoft’s review and reporting systems give you a place to escalate.

Windows Security has also gotten considerably better at catching this kind of threat. We previously reported that Microsoft has quietly confirmed most Windows 11 users don’t need third-party antivirus software, since Windows Security already runs Microsoft Defender Antivirus, SmartScreen, Smart App Control, ransomware mitigation, and cloud-delivered protection as one stack.


Microsoft Defender SmartScreen Demo

Smart App Control can block unsigned or unrecognized executables from running, including installers downloaded from a fake site. SmartScreen also checks the reputation of files and URLs as you download them.

How to download Windows apps safely

• Always check the domain in your address bar before downloading anything, especially if you reached the site from a Google search.

• Use the Microsoft Store or the developer’s official GitHub releases page over a project’s standalone website when both exist.

• If you download an installer from a site you’re not fully sure about, scan it with VirusTotal before running it (Note that even VirusTotal is not foolproof).

• Check whether the file is digitally signed by right-clicking it, going to Properties, and looking at the Digital Signatures tab.



App development has increased drastically, and the internet still isn’t safe

Claude Code and Codex have drastically lowered the barrier to building software, and more developers means more targets for this kind of operation. We need to understand that not every developer has the budget or time to run brand-monitoring services.

However, there are a few things that devs must take care of. Listing an app on the Microsoft Store is the most effective step and it now costs nothing to do. Microsoft dropped its one-time developer registration fee for individual developers in 2025, and extended the same to company accounts in May 2026, removing what used to be a $19 to $99 barrier.

For developers who already run their own project website, investing a little time in basic SEO, clear page titles, proper meta descriptions, and submitting to Google Search Console, makes it harder for a fresh impersonation domain to outrank the real one.

Of course, none of this makes impersonation impossible, but it raises the cost of running the scam.

I know I’m repeating myself, but if you’re downloading a Windows app, check the Microsoft Store first. If a developer only distributes through their own website, verify the URL.

source
72
Scammers are impersonating popular Windows app websites, raising fears of a coordinated malware campaign targeting unsuspecting users.

Here at Neowin, we regularly cover first- and third-party Windows applications like Wintoys, PowerToys, Windhawk, Flyoobe, and more. We typically link to official download sources for these applications, such as the developer's own verified website, GitHub repository, or the Microsoft Store. However, it now appears that a coordinated operation is now underway through which scammers are impersonating websites of popular Windows applications to potentially distribute malware.

This discovery was made by Wintoys developer Bogdan_X on Reddit, who noticed a wintoys.app website set up for their popular customization app. This website was not configured by Bogdan_X, and according to the developer, it showcases inaccurate information, but interestingly, the download link points to the official app on the Microsoft Store. However, a disclaimer on the bottom of the page does indicate that it's not the official Wintoys website:

Quote
Not affiliated with Wintoys. This is an independent site providing documentation, guides and links to the official project repositories.

We visited the website in Chrome, and Cloudflare showed a warning that Wintoys.app is suspected of phishing. However, it's certainly interesting that the download link points to an official source and even contains an obscure disclaimer, likely to reduce chances of legal action.

Bogdan_X tried to trace the owner of the scam website and discovered that the contact email of the owner is associated with over 70 other websites, all posing as Windows applications. These include popular utilities like PowerToys, CrystalDiskMark, WinUtil, and more. Bogdan_X noticed that some websites are under construction, which indicates that this operation has recently kicked off. The complete list of discovered fake websites is as follows:

   • christitustool.com

   • droidkit.pro

   • easybcd.app

   • powertoys.app

   • shellmenuview.com

   • winexp.app

   • zhpcleaner.com

   • cursorslibrary.com

   • fakeflashtest.com

   • searchmyfiles.com

   • wintoys.app

   • themouseclicker.com

   • quickassistapp.com

   • move-mouse.com

   • movemouse.net

   • nircmd.net

   • crystaldiskinfo.app

   • freewheelofnames.com

   • productkeyscanner.com

   • power-toys.com

   • chatmate.info

   • usblogview.com

   • mouse-mover.com

   • mouse-cursors.com

   • mouse-clicker.com

   • mimalloc.com

   • mumuplayer.app

   • wushowhide.com

   • guiformat.app

   • freefilesync.net

   • winutil.app

   • spacesniffer.app

   • simplestickynotes.app

   • showmore.app

   • mousecape.app

   • hashcat.app

   • dshidmini.app

   • darktable.app

   • daijisho.app

   • wiblr.com

   • skse64.com

   • sageattention.com

   • rezygisk.com

   • pwndbg.com

   • ocrmypdf.com

   • notatnikonline.com

   • noisium.com

   • mousecape.net

   • mongosh.com

   • lspconfig.com

   • liveclockwithseconds.com

   • lax1dude.com

   • je2be.com

   • iso2god.com

   • hifiasm.com

   • hddsentinel.com

   • hakchi2.com

   • gliden64.com

   • furfsky.com

   • freeminutetimer.com

   • findoutdate.com

   • crystaldiskmark.net

   • bepisdb.com

   • beardlib.com

   • 10mintimer.com

   • pyjwt.com

   • moliyachi.com

   • arduinodroid.com

   • cxxdroid.com

   • kalkulyator.com

   • retraitedz.com

   •urlaubscountdown.com

It's unclear what the goal of this supposed scamming operation is, since the domains don't seem to be doing anything obviously malicious right now. It is possible that the fake websites are posing as official sources to gain trust and traffic before eventually injecting malware in their download links.

When Bogdan_X reported the fake domains to the registrar, the registrar terminated services for the scammer. However, this didn't really solve the problem as they migrated to another registrar.

It's unlikely that there is a long-term solution to this problem, but users and developers should report illegal activity to the cloud hosting provider and the domain registrar if they come across it. And as always, it is better to carefully vet a URL and essentially any portal hosting a download link before you click on it.

source
73
Apple has released iOS 26.6 and iPadOS 26.6. The updates bring no new features, but include a lengthy list of bug fixes and imrpovements.

Apple has just released iOS 26.6 and iPadOS 26.6 to the public. This is mainly a security update, as it brings no new features to the mix. On the other hand, the update fixes a large number of known bugs.

Apple’s release notes only say the following:

Quote
“This update includes bug fixes, security updates and optimizes the Spotlight index to prepare for iOS 27.”

Along with the bug fixes, the update also optimizes the Spotlight search index in preparation for iOS 27 and iPadOS 27, expected later this year. Still, it’s worth mentioning that the full capabilities of the optimized Spotlight search will only be available to users of iPhone 15 and later, as the feature is connected to Siri AI.

Additionally, a few of the fixes stand out. Apple patched a MediaRemote bug that could have let a malicious app gain root privileges on the device. There's also a fix that could have let a fake, tampered app slip past one of iOS's core security checks and a WebKit fix that addressed a privacy leak. That leak could’ve let websites detect what other webpages you visited before, and, in turn, compromise your browsing history.

This is the last update before iOS 27 and iPadOS 27 arrive this fall. So, it’s not surprising that this one doesn’t introduce any new features, as Apple has reserved all the novelties for the fall. You can check if your iPhone supports the upcoming iOS 27 update here.

Even though you’re not getting anything new, it’s still worth updating your iPhone or iPad to iOS 26.6 because of the sheer number of bug and vulnerability fixes. iOS 26.6 and iPadOS 26.6 can be installed from Settings >  > Software Update.

You can check the full list of bugs Apple has addressed in iOS 26.6 and iPadOS 26.6 updates here.

source
74
The official list of supported models for the new iOS 27 update goes all the way back to iPhone 11, which is also getting a new CPU Scheduler.



It's that time of year when we get to know about the latest operating system updates for Apple devices. For iPhone, Apple previewed the iOS 27 update at WWDC 2026, where the company finally introduced an upgraded version of Siri.

Apple typically supports iPhone models for up to five years. But it has been making exceptions in recent years (read iPhone 11). If you're wondering whether your iPhone is compatible with the iOS 27 update, here is the official list of devices:

   • iPhone 17 Pro Max, iPhone 17 Pro, iPhone 17, iPhone 17e, iPhone Air

   • iPhone 16 Pro Max, iPhone 16 Pro, iPhone 16, iPhone 16 Plus, iPhone 16e

   • iPhone 15 Pro Max, iPhone 15 Pro, iPhone 15 Plus, iPhone 15

   • iPhone 14 Pro Max, iPhone 14 Pro, iPhone 14 Plus, iPhone 14

   • iPhone 13 Pro Max, iPhone 13 Pro, iPhone 13, iPhone 13 mini

   • iPhone 12 Pro Max, iPhone 12 Pro, iPhone 12, iPhone 12 mini

   • iPhone 11 Pro Max, iPhone 11 Pro, iPhone 11

   • iPhone SE (2nd generation), iPhone SE (3rd generation)

So, you can download the iOS 27 developer beta on up to 31 different iPhone models. There has been no change to the list of supported iPhones since iOS 26. However, it will expand to include more devices when the iPhone 18 series arrives later this year.

To download the developer beta on your iPhone, go to Settings > General > Software Update > Beta Updates. Here, select "iOS 27 Developer Beta" from the list of choices to get the new update. In addition to iOS 27, you can try the developer beta versions of macOS 27, iPadOS 27, watchOS 27, tvOS 27, and HomePod software 27 on your supported devices.

iOS 27 comes with improved Liquid Glass, which you can adjust using a new transparency slider. Apple said during the keynote that iPhone apps now launch up to 30% faster, new photos appear in the Photos app up to 70% faster, and AirDrop transfers work up to 80% faster. The new update promises to improve performance on older iPhones by introducing a new CPU Scheduler that supports devices all the way back to the iPhone 11.

While iOS 27 is supported on older iPhones, it goes without saying that they'll lack several features due to hardware differences. For instance, iPhone 14/14 Plus and older models come with a notch instead of the Dynamic Island. Similarly, Apple Intelligence features are supported on iPhone 15 Pro/Pro Max and later models.

source
75
iPhone | iApps / iPhone Trick Can Eliminate Spam Calls for Good
« Last post by javajolt on July 28, 2026, 12:53:41 AM »
You don't have to put up with spam calls any longer.


Cole Kan/CNET/Apple/Getty Images

Spam calls are annoying. I always have my phone ringer on in case there is an emergency but that means my iPhone receives spam calls at least a handful of times a week. Spam calls can be stressful, especially if you’re trying to stay quiet so as not to disturb a napping baby. But thanks to iOS 26‘s call screening feature, spam calls haven’t bothered me for months.

Call screening isn’t an Apple Intelligence feature so any iOS 26-compatible iPhone, like the iPhone 14 Pro, can use it. I enabled the feature early in the beta process and my iPhone has diligently held back spam calls, like the Hoover Dam, ever since. But you have to enable it first.

Here’s how to enable call screening in a few easy steps and what to know about the new feature.

How to turn call screening on your iPhone

   1. Tap Settings.

   2. Tap Apps near the bottom of the menu.

   3. Tap Phone.

Under the section Screen Unknown Callers, you’ll see three options: Never, Ask Reason for Calling and Silence. Here’s what you should know about each of these options and which one is right for most people.


Apple/CNET

Which call screening option should you choose?

Choosing Never is the default option and lets calls from unsaved numbers come through and ring on your phone. It also documents missed calls in your Recents list in your Phone app, just like before call screening was available.

If you tap Ask Reason for Calling, your iPhone will ask anyone who calls you from an unsaved number why they are calling you without ringing your iPhone. After the caller answers a few questions, your iPhone will notify you with a transcript of the caller’s answers. Then you can decide whether you want to answer the call.

You can also pick Silence, which is the nuclear option for phone calls. Any unsaved numbers that call you will be silenced and sent to voicemail, no questions asked.

Ask Reason for Calling is the best option for most people who want to screen calls. I chose it, and while it notified me when scam callers answered some questions, which they rarely did, it also notified me when my doctor’s office called to go over some test results. If I had chosen Silence, I would have missed my doctor’s office (and choosing Never would mean checking every call if I was expecting something important).

If you choose Ask Reason for Calling and dislike it, you can always follow the steps above again and choose one of the other options. And remember, you can always silence your iPhone and not be bothered by any phone calls at all. My wife has not taken her phone off silent in months, and she remains blissfully unbothered by spam calls.

source
76
Don't let the most essential device in your life become a liability. Our one-hour wellness check will keep your phone secure for another year.


Qi Yang/ Moment via Getty Images

   ■ A quick cybersecurity wellness check is all it takes to protect your phone from disaster.

   ■ Check your app usage, permissions, and physical security settings.

   ■ An annual checkup reduces data exposure risk, improves privacy, and optimizes your device.



Enjoying the benefits and conveniences of life in our complex world requires daily diligence, from replacing batteries and tracking finances to keeping medical appointments and maintaining vehicles.

Here's another routine task we should all have on our calendars. Conduct an annual cybersecurity wellness check of what's likely the single most important device in your life: your smartphone.

We use our smartphones to communicate, work, shop, and stay connected and entertained -- but we don't always remember to keep them optimized or secure, which can turn these essential devices into serious liabilities.

While we always recommend you accept security updates on your smartphone as soon as they are available, there are other checks that, if performed even once a year, can hugely benefit you.

Take just one hour to give your smartphone a once-over that will tighten your security, refresh your memory on app permissions, and optimize your privacy settings. Our 10-step checklist makes it a breeze and could save you some major headaches down the line.



1: Make sure your device and apps are up to date


        Screenshot by Charlie Osborne/ZDNET

The first step in any annual cybersecurity checkup is to ensure that your operating system and any mobile applications installed on your smartphone are up to date. This means accepting any new OS and app versions, as well as security updates and patches.

Depending on the make, model, and version of your iOS or Android device, the location where you check your phone's status can vary. However, you can usually find updates under Settings > Security and Privacy > Updates, or Settings > System > Update. You may also be notified when a new software update is available.

To check the status of your smartphone's apps, you can visit Settings > Apps or the Update tab.



2: Check your app and device permissions


      Screenshot by Charlie Osborne/ZDNET

The next step in your yearly audit is to review your app and device permissions. Whenever you install a mobile application, you will be asked to grant or deny specific permissions, such as access to your files, control over your location services, and permission for the app to send you push notifications.

There is also a variety of settings on your smartphone that need to be managed -- particularly security and privacy settings.

There are plenty of options to explore, including whether you want your smartphone to automatically detect and block threats; screen locks and biometrics; lost device protection; and whether you are comfortable with personalized ads and sending diagnostic data.

On Android, you typically need to go to Settings > Security and privacy > More privacy settings > Permission manager. On iOS, you will likely find permissions management under Settings > Privacy and Security, or Settings > the specific app you want to examine. To explore your device settings, simply go to Settings.

"Never do attackers' jobs for them by giving access away unnecessarily," cautioned Rob Kehoe, chief technology officer of Smarttech247. "Once a year, go through every app on your phone and check what permissions it has. Look at the camera, microphone, location, and contacts. If an app has access it doesn't need, remove it. Set location access to 'only while using' for everything. And if an app isn't useful anymore, remove it completely. This only takes 10 minutes, and most people are shocked by what they find."



3: Delete any apps you no longer use


      Screenshot by Charlie Osborne/ZDNET

You should also audit the apps installed on your smartphone. (We recommend checking this more than once a year -- preferably every few months.) Old apps can pose a risk to your privacy; they may have been granted unnecessary permissions and may also consume your device's resources and power.

If you haven't used a mobile app in a few months, ask yourself: "Do I really need it?" If the answer is no, remove it. You can always reinstall apps later, but each one you remove reduces your potential attack surface.

While both Android and iOS will revoke permissions from apps you haven't used for several months, it's still advisable to run a check yourself every so often. Take a look at the Apps section in your handset's Settings tab to refresh your memory about which apps are installed. Alternatively, check your home screen and hold your finger down on any app you want to remove -- you should see the option to uninstall it.



4: Review and refresh your passwords


Charlie Osborne / Elyse Betters Picaro / ZDNET

Hardly a day goes by without a new data breach. The challenge of containing our data and protecting our accounts is now so vast that dedicated services warn consumers about data breaches affecting their accounts, and some companies now prevent users from reusing passwords found in online data leaks.

Reviewing your passwords and changing them frequently is essential to protecting your accounts and data, and this protection applies to any device you use to access them -- including your smartphone.

Passwords should be complex, made up of upper- and lower-case letters, numbers, and symbols, when possible. It's also important never to reuse the same credentials across multiple online services.

If you think you will have trouble remembering complex phrases, consider using a password manager.

Troy Hunt's Have I Been Pwned search engine is also an excellent resource for checking whether your accounts have been linked to a data breach. Simply by entering your email, you'll be able to see what data might have been leaked about you, and when. If you're ever in doubt, change your password.



5: Check 2FA, multi-factor authentication settings

After you've refreshed your passwords, you should check all two-factor authentication (2FA) and multi-factor authentication (MFA) settings for your online accounts and devices. Many of us rely on our smartphones for 2FA, receiving a code we need to use when 2FA is enabled on our accounts as a secondary layer of security, so it is important that this information is up to date and our phones are secure. Otherwise, attackers could intercept these codes and compromise our accounts.

If you have 2FA/MFA enabled on your online accounts, go to their privacy settings and verify that the phone number is correct and that you've selected your preferred authentication method. This could be a text message, an emailed code, an authenticator app, or a passkey. Prioritize Google, Apple, and Microsoft services, financial and banking apps, core email accounts, frequently-used shopping services if your details are stored, and work platforms.



6: Audit your physical device security


      Screenshot by Charlie Osborne/ZDNET

Checking our digital services, online accounts, and app usage is only part of an annual cybersecurity audit -- it's also important to review our physical handset security.

Estimates suggest that approximately 1.3 million phones were stolen in the US in 2023. Stolen handsets can be wiped and resold; if a device is not properly secured, it can lead to the loss of personal information, compromised accounts, lost files, and even financial damage.

You'll need to dive back into your settings again. Look for options including:

■ Lock screen: Do you have a way to lock your smartphone from the screen? Is a passcode or biometric identifier in place? It's best to have some form of lock to prevent data theft or eavesdropping.

■ Safety and emergencies: You can use your smartphone to share your location or notify emergency services when needed. Check that these settings are enabled if you want them. You can also enable alerts when unknown trackers are detected near your handset.

■ Biometrics: Your thumbprint or retina is also a valuable way to physically secure your device. Consider enabling these to keep others out of your smartphone, its apps, and its data.

■ Device encryption: On modern smartphones, encryption is often enabled by default when a lock screen is enabled, but you should check, as this helps protect your data on older models. Explore settings, security, and privacy to see if enabling device encryption is possible. 



7: Look for unexpected connected apps and devices

It's also important for you to audit your online accounts, services, and smartphone for any unexpected apps, devices, or active sessions.

For example, if you are logged into your email account only on your smartphone but a laptop connection has also appeared, it could mean someone has quietly gained access to your account. This can be a serious security issue due to eavesdropping, potential data theft, and even the acquisition of 2FA codes if your email is compromised.

Check for any unrecognized locations, access times, or devices -- including older smartphones you've sold or that have been stolen. If you find any, revoke access immediately and change your passwords. You should do the same for any associated online accounts, including e-commerce platforms, work apps, and social media.

You can usually find details on any connected apps or devices in settings, recent activity, sign-in activity, signed-in devices, and similar items.



8: Run a malware scan


      Screenshot by Charlie Osborne/ZDNET

Android and iOS smartphones have built-in antivirus protection, but it never hurts to run your own check -- preferably more than once a year.

There can be threats lurking on your mobile device, and most of these stem from malicious apps that are hiding information stealers, keyloggers, monitoring software, Trojans, and nuisanceware. Antivirus software can catch these apps before they run on your handset, and scans can give you peace of mind that your smartphone is clean.

Help yourself, too, by only downloading apps from trusted sources and refraining from jailbreaking your device.



9: Review your account and device recovery settings


      Screenshot by Charlie Osborne/ZDNET

Do you have Android's Find My Device, Find My Mobile, or iOS's Find Devices enabled?

As part of your annual audit, consider enabling features on your smartphone that may increase the likelihood of recovering it if it is lost or stolen.

On Android, the Find Hub lets you locate any registered device on a map, remotely lock it, or erase it, even if it is offline. You mark a device as "lost," and data gathered from a global network of Android devices is used to pinpoint its location. The same type of crowdsourcing is used on iOS, too, and you can access the same functionality if your device is lost -- tracking, locking, and wiping remotely in cases of loss or theft.

Be warned: You will likely need to enable these services and register your devices before such an event occurs.

Many smartphones also offer theft protection features, remote locks, and automatic screen locks when they detect potential theft. You can find these under Settings and menu options such as Lost Device Protection.



10: Start adopting these security habits

Now that your audit is complete, consider adopting the following five security habits to improve your personal security and privacy:

■ Take data breach notifications seriously: If you hear a news report or receive an alert about a breach at a company you are a customer of, change your account passwords immediately.

■ Review apps and permissions frequently: It's best to take a few moments every few months to review your apps, their permissions, and whether you still need them installed on your device.

■ Physically secure your devices: Get in the habit of supervising and protecting your devices at all times. It only takes a distracted moment for your laptop to vanish from your table at a coffee shop, or for your smartphone to disappear from your pocket.

■ Keep your devices updated: It's the simplest step and also one of the most important. Accept new security updates for your smartphone and apps as they become available to stay protected from emerging threats and vulnerabilities.

■ Stay suspicious: If you receive a suspicious SMS, WhatsApp call, or email, you might be getting phished. This is one of the most common threats we face today. Don't panic and don't click any links in the message. If a message looks official but you're unsure, go directly to the organization's website to contact them.

source
77
Microsoft released two new builds for Windows Insiders in the Release Preview channel. The new builds bring numerous new features and improvements.



Microsoft has released new Release Preview channel builds for Windows 11 Insiders on 24H2 and 25H2. Builds 26100.8942 and 26200.8942 bring a solid batch of new features, including Voice Isolation for Voice Access, new touchpad gesture controls, improved File Explorer and search behavior, and expanded Windows Hello Enhanced Sign-in Security support.

The full changelog is below:

Gradual rollout

This section covers new features and enhancements delivered gradually to Windows 11 PCs. Availability might vary by device.

• File Explorer

• File sizes in Details view now display appropriate units (KB, MB, and GB) instead of KB-only, making them easier to understand at a glance.

• Middle-click to open a folder in a new tab is now supported in the address bar and Home page for a more consistent and efficient tabbed navigation experience across File Explorer.

• This update eliminates a gray flash on load and unexpected scrolling to the top on the Home page in certain cases.

• This update improves the appearance of file thumbnails in the Recommended section on Home so they're crisper and  easier to read.

• Windows Search

• This update improves file finding across local, cloud, and connected content, including support for two-character file searches.

• This update improves app search to better handle typos and partial app names when finding installed apps.

• This update improves Settings relevance to surface more useful settings higher in search results.

• Voice Access New!

• This update adds Voice Isolation to Voice Access, helping it better recognize your voice by reducing interference from other speakers and background noise.

• Voice Access now offers three speech recognition modes under Voice Access settings > Improve speech recognition:

• Voice Isolation: Filters out other speakers and background noise (one-time voice setup required).

• Remove background noise only: Filters out non-speech sounds like typing or door slams (no additional setup required).

• No filtering: Uses default microphone input with no additional processing.

To set up Voice Isolation, go to Voice Access settings > Improve speech recognition and select Voice Isolation.

• New! This update adds Korean language support for Voice Access.

• Widgets New!

• Taskbar notification badges now use your Windows accent color instead of appearing red, helping reduce unnecessary attention-grabbing alerts.

• This update also simplifies the Lock screen Widgets experience. For new users, Weather is now the only widget shown on the Lock screen by default.

• Touchpad New! New gesture controls for precision touchpads are available in Settings > Bluetooth & devices > Touchpad:

• Scroll and zoom speed: Adjust the baseline speed for scroll and zoom gestures.

• Accelerated scrolling: Scroll faster the more you repeat the gesture, so you can move quickly through long documents.

• Start menu

• This update improves reliability of Start menu view preferences, ensuring your selected view is retained.

• This update improves keyboard navigation when keyboard focus is set to the apps list within Start menu.

• Voice typing Fluid dictation is now off by default for new users. A teaching tip is available when the feature is used for the first time.

• Input Improved persistence of mouse cursor size.

• Accessibility This update improves the Magnifier experience on touch-enabled devices. The horizontal and vertical touch bars used to pan the magnified view are now off by default, so they no longer obstruct magnified content. If you use touch to pan, you can turn the bars back on in Settings > Accessibility > Magnifier.

• Windows Hello New! Windows Hello Enhanced Sign-in Security (ESS) now supports peripheral fingerprint sensors. This extends this secure sign-in option beyond devices with built-in fingerprint sensors to include desktops and other Windows 11 PCs, including Copilot+ PCs. To get started, plug in a supported ESS fingerprint reader, go to Settings > Accounts > Sign in options, and follow the prompts to enroll. This feature was previously disclosed in January 2026 (KB5074105) and is now beginning to roll out.

• Fonts

• This update restores support for Unicode variation sequences in the Myanmar Text font.

• This update improves character shaping and rendering for Mongolian Baiti font, providing more accurate and consistent text display.

• Account Control This update refreshes the design of the Start menu account control and adds a badge that displays your subscription status. To view account control, open Start menu and select your account picture in the lower-left corner. This experience is available for users signed in with a Microsoft account.

• Taskbar This update improves reliability of loading the system tray area of the taskbar when using the taskbar on touch devices in a tablet posture.

• AI Component This update allows you to remove the Image Generation AI component from supported Copilot+ PCs where the component is installed.

• Windows Setup This update adds a parental controls notice during Windows setup that highlights available family safety features.

• Power and battery

• Changes to global power settings such as display, sleep, hibernate timeouts, power/sleep button actions, and lid-close actions from Settings are now applied to all power plans.

• This update improves reliability of power settings by applying changes made in Settings to all power plans so your preferences are consistently maintained.

• Windows Update

• This update improves calculation of update progress in Windows Update Settings.

• This update includes changes to update clean-up logic to improve system performance immediately following an update.

• Sounds This update improves system sounds when using Windows in dark mode.

• Date and time

• This update improves detection for triggering time zone change notifications.

• This update improves daylight saving time (DST) data accuracy for Middle East Standard Time (Beirut), Morocco Standard Time (Casablanca), Israel Standard Time (Jerusalem), and Greenland Standard Time (Nuuk).

• Network This update improves reliability of DHCP renewals in a few scenarios, particularly when NACKs are received from the DHCP server and on devices that use Modern Standby.

• Print This update improves print time performance (pages per minute) for IPPS (Internet Printing Protocol Secure) printers.

• Clipboard This update improves clipboard reliability in some Remote Desktop and Azure Virtual Desktop (AVD) scenarios.

• Battery This update restores the ability to set a threshold for when Energy saver should enable within Settings > System > Power & battery.

• General reliability

• This update improves explorer.exe reliability, including when opening jump lists and recent files, when sharing files and folders, and when using Task View and multiple desktops.

• This update improves reliability of the Windows sign-in and lock screens, especially when system memory is low.

• This update improves reliability of Start menu and taskbar during startup.

Normal rollout

This non-security update includes quality improvements. The following summary outlines key issues addressed by the KB update after you install it. The bold text within the brackets indicates the item or area of the change.

• Additional quality improvements are included with this update.

Feature availability varies by device and market.

You can find the blog post for builds Builds 26100.8942/26200.8942 here.

source
78
The Intel graphics driver doesn't have support for any new games or features, but it is carrying some important bug fixes.



Intel has a fresh driver for its Arc GPU lineup, and while it doesn't have support for any new games or features, it is carrying some important bug fixes. Assassin's Creed Black Flag Resynced, Assassin's Creed Shadows, Rainbow Six Siege, and LEGO Batman: Legacy of the Dark Knight are the focus of this 32.0.101.8864 non-WHQL driver.

The driver carries the following fixes on the Intel Core Ultra Series 3 and Intel Arc B-Series hardware:

• Assassin's Creed Black Flag Resynced (DX12) may experience a crash when upgrading driver if the shaders have been compiled with the previous driver.

• Assassin's Creed Shadows (DX12) may experience a crash when upgrading driver if the shaders have been compiled with the previous driver.

• Tom Clancy's Rainbow Six Siege (DX12) may experience a crash when upgrading driver if the shaders have been compiled with the previous driver.

Meanwhile, Arc A-Series, Intel Core Ultra Series 1, and Intel Core Ultra Series 2 hardware have all the above changes alongside a separate LEGO Batman fix:

   • LEGO Batman: Legacy of the Dark Knight (DX12) may exhibit corruption during cutscenes.

With the fixes out of the way, here are the known issues users can look out for:

Intel Core Ultra Series 3 with built-in Intel Arc GPUs:

• Mafia: The Old Country (DX12) may experience an application crash during gameplay.

• Marathon (DX12) may exhibit intermittent corruption on certain objects during gameplay when using Anisotropic Filtering.

• Borderlands 4 (DX12) may experience an intermittent application crash during gameplay.

• Hogwarts Legacy (DX12) may experience corruption when raytracing is turned on in certain scenes during gameplay.

• Forza Horizon 6 (DX12) may not exhibit expected visual quality with reflections.

• 007 First Light (DX12) may exhibit corruption across the screen in certain scenes during gameplay.

Intel Arc B-Series Graphics Products:

• Marathon (DX12) may exhibit intermittent corruption on certain objects during gameplay when using Anisotropic Filtering.

• Borderlands 4 (DX12) may experience an intermittent application crash during gameplay.

• Forza Horizon 6 (DX12) may not exhibit expected visual quality with reflections.

• 007 First Light (DX12) may exhibit corruption across the screen in certain scenes during gameplay.

• Echoes of Aincrad (DX12) may exhibit purple corruption during gameplay in the tutorial.

• PugetBench for Adobe Premiere Pro may experience an intermittent application crash while running the benchmark in the extended preset.

• PugetBench for Davinci Resolve Studio may experience an intermittent application crash while running the benchmark. Recommendation is to change the timeout slider to 1500 seconds or higher, to wait for each test to complete, in

• PugetBench benchmark settings.

Intel Arc A-Series Graphics Products:

• Marathon (DX12) may exhibit intermittent corruption on certain objects during gameplay when using Anisotropic Filtering.

• Borderlands 4 (DX12) may experience an intermittent application crash during gameplay.

• Forza Horizon 6 (DX12) may not exhibit expected visual quality with reflections.

• Echoes of Aincrad (DX12) may exhibit purple corruption during gameplay in the tutorial.

• PugetBench for Davinci Resolve Studio may experience an intermittent application crash while running the benchmark. Recommendation is to change the timeout slider to 1500 seconds or higher, to wait for each test to complete, in PugetBench benchmark settings.

Intel Core Ultra Series 1 with built-in Intel Arc GPUs:

• Marathon (DX12) may exhibit intermittent corruption on certain objects during gameplay when using Anisotropic Filtering.

• Borderlands 4 (DX12) may experience an intermittent application crash during gameplay.

• NBA 2K26 (DX12) may experience an application crash on first launch of the game.

• 007 First Light (DX12) may experience an intermittent application crash on first launch of the game.

Intel Core Ultra Series 2 with built-in Intel Arc GPUs:

• Marathon (DX12) may exhibit intermittent corruption on certain objects during gameplay when using Anisotropic Filtering.

• Borderlands 4 (DX12) may experience an intermittent application crash during gameplay.

The non-WHQL Intel graphics driver 32.0.101.8864 is now available from Intel's official download portal. Here's the official changelog (PDF).

source
79
The drops this time include Halo Studios' remake of the original Halo, Game Freak's upcoming RPG Beast of Reincarnation, and more.

It's time for a brand-new Xbox Game Pass wave announcement. Subscribers to the Microsoft service will be getting access to some high-profile titles this time too, and that includes Halo Studios' remake of the original Halo, Game Freak's upcoming RPG Beast of Reincarnation, and much more.

The sole first-party entry of the bunch, Halo: Campaign Evolved, is bringing back the Chief's original introduction on a brand-new engine, 4-player co-op, and some extra missions. Only multiplayer is missing from the package.

City building fans may also want to check out Corsair Cove, for which we did a preview a few months ago. This is a pirate-themed building and management game that lets you mainly utilize cliff walls for your constructions, unlike many other games in the genre.

Here are all the games that were announced today for Xbox Game Pass, their platforms, and arrival dates:

   • The Planet Crafter (Cloud, XBOX Series X|S, and PC) – July 21

   • Shift at Midnight (Cloud, XBOX Series X|S, and PC) – July 22

   • Hell is Us (Cloud, XBOX Series X|S, and PC) – July 23

   • Halo: Campaign Evolved (Cloud, Console, Handheld, and PC) – July 28

   • Mistfall Hunter (Cloud, XBOX Series X|S, and PC) – July 30

   • Corsair Cove (PC) – July 31

   • Heretic + Hexen (Cloud, Console, Handheld, and PC) – August 4

   • Beast of Reincarnation (Cloud, XBOX Series X|S, Handheld, and PC) – August 4



As new games arrive, these eight titles will be leaving Game Pass platforms on July 31, which unfortunately includes some big games like Crusader Kings 3, Celeste, and Mount & Blade 2: Bannerlord:

Quote
   • Back to the Dawn (Cloud, Console, and PC)

   • Celeste (Cloud, Console, and PC)

   • Crusader Kings 3 (Cloud, Console, and PC)

   • Mount & Blade 2: Bannerlord (Cloud, Console, and PC)

   • My Friendly Neighborhood (Cloud, Console, and PC)

   • Rain World (Cloud, Console, and PC)

   • Sniper Elite Resistance (Cloud, Console, and PC)

   • Whiskerwood (PC)

With the second announcement of July out of the way, expect the next Xbox Game Pass announcement to land in early August.

source
80


Obsidian is the first app I open each morning at the start of my work day. Not Word, not Notes, not even my email client. When I first discovered Obsidian, I didn't know much about it; it was just an app for taking notes, and I was toying with it because I was curious. I had no idea then that it would become my central command center for my workflow, with everything — to-do lists, stray ideas, daily logs, and more — all going into it.

Now, thanks to Obsidian's versatility, I hardly even open other apps. That's not to say I never use them; some file types just don't work as well in Obsidian, even with an army of plugins fueling my vault, so I'll use something like LibreOffice to edit Word documents, PDFs, and spreadsheets, but the actual writing? That's done in Obsidian. So is managing my to-do list and calendar. Here's how I do it.

I start with a centralized, functional dashboard
It opens when Obsidian does, and my day goes from there



I've built a homepage that serves as a jumping-off point for my workday. It shows me the time, the date (and I can click on the calendar to see if I have any meetings or events that day), my recently accessed files, an overview of my vault, my to-do list, and lets me open my daily note. Sure, it has a custom background and has been tweaked to suit the overall theme of my vault, but it's both aesthetic and functional.

I used the Hearth plugin for this, but it's entirely possible to create the same setup with other homepage-oriented plugins, or even just CSS. There's no right or wrong way to do it, and the style of homepage/dashboard that works for me might look entirely different for someone else. I have multiple vaults, and each one has a different dashboard depending on its purpose.

My tasks and my notes live in the same place
Obsidian has replaced numerous other apps



My work can be broken into either writing, researching, or editing. I spend a lot of time in the research phase, either looking for new and interesting software to try out or putting it through the wringer to ensure I know all there is to know about it before I start writing about it. Then there's the writing phase, which is self-explanatory (although I do, at times, break those tasks into multiple, smaller tasks — usually different drafts). And finally, there's the editing phase. After an article is written, I go back and give it a pass to check not only for grammatical issues but also for informational accuracy.

I can draft and edit a story without ever leaving Obsidian, and when I'm done with those tasks, I can mark them as completed and move on to what's next. Before Obsidian, I would have written the article in a word processor like MS Word, opened a to-do list app like Todoist to mark it as complete, and then copied and pasted the story into whatever CMS I'm using. While that last part remains a routine part of the workflow — although I could, in theory, log in to the CMS from the Obsidian web view — I've eliminated multiple apps by working inside Obsidian.

I don't miss word processors either. There are multiple editing toolbars that make writing in Obsidian feel as good as, if not better than, writing in Microsoft Word.

I can access external info without leaving my vault
Plugins are your friend



Obsidian can do a lot, but there's a fair amount it can't do. That said, I can also access external information without the need to leave Obsidian. The Obsidian Web Viewer is a core plugin that lets me surf the web from inside my vault, and it even has an adblocker built in. And with other plugins, I can display RSS feeds inside notes that update in real time, keeping me apprised of anything I need to know. The Obsidian Web Clipper lets me save entire web pages straight to my vault, and I can even embed YouTube videos to be referenced later. With the right workflow, there's hardly ever a need to leave Obsidian.

Obsidian is an amazing command center, but not always the best tool
Some jobs are better handled with dedicated apps



Here's the thing: Obsidian isn't meant to replace every app. While its plugins can grant a lot of the same functionality, they aren't a total replacement, and often lack the polish a dedicated app might have. There are some tasks I wouldn't even dream of attempting inside Obsidian, like editing a photo. A program like Photoshop or GIMP will do the job infinitely better than an Obsidian plugin, no matter how complicated it is.

The same goes for spreadsheets. While there are ways to work with them inside Obsidian, it's typically more of a pain than it's worth. I'd rather just open up Excel and get the job done rather than fight with quirks introduced by a plugin. I love staying in one app as much as possible, but sometimes it's just easier to open a secondary app to get the job done more quickly.

Obsidian functions like a command center for my workday

Due to the nature of my work, there's a lot I can do without ever leaving Obsidian, but that isn't the same for every field. For example, programmers could write code in Obsidian — and many do — but it isn't always the best choice. I appreciate how a dedicated homepage streamlines my workflow, and many other types of work can benefit from something similar, but it's not always the right call for everyone.



source
Pages: 1 ... 6 7 [8] 9 10