News
‘I Am Not a Robot’, CAPTCHAs Being Used to Spread Malware, HP Warns

Today at its annual Amplify Conference, HP Inc. (NYSE: HPQ) issued the latest HP Threat Insights Report, highlighting rising usage of fake CAPTCHA verification tests which allow threat actors to trick users into infecting themselves. The campaigns show attackers are capitalizing on people’s increasing familiarity with completing multiple authentication steps online – a trend HP calls ‘click tolerance’.
With analysis of real-world cyberattacks, the HP Threat Insights Report helps organizations to keep up with the latest techniques cybercriminals are using to evade detection and breach PCs. Based on data from millions of endpoints running HP Wolf Security1, notable campaigns identified by HP threat researchers include:
CAPTCHA Me If You Can: As bots get better at bypassing CAPTCHAs, authentication has grown more elaborate – meaning users have become more accustomed to jumping through hoops to prove they are human. HP threat researchers identified multiple campaigns where attackers crafted malicious CAPTCHAs. Users were directed to attacker-controlled sites, and prompted to complete a range of fake authentication challenges. Victims were tricked into running a malicious PowerShell command on their PC that ultimately installed the Lumma Stealer remote access trojan (RAT).
READ ALSO: HP Report Uncovers South African Youth’s Growing Interest in Gaming Careers Amid Awareness Gap
Attackers Capable of Accessing End-Users’ Webcams and Microphones to Spy on Victims: A second campaign saw attackers spreading an open source RAT, XenoRAT, with advanced surveillance features such as microphone and webcam capture. Using social engineering techniques to convince users to enable macros in Word and Excel documents, attackers could control devices, exfiltrate data, and log keystrokes – showing Word and Excel still present a risk for malware deployment.
Python Scripts Used for SVG Smuggling: Another notable campaign shows how attackers are delivering malicious JavaScript code inside Scalable Vector Graphic (SVG) images to evade detection. These images are opened by default in web browsers and execute the embedded code to deploy seven payloads—including RATs and infostealers—offering redundancy and monetization opportunities for the attacker. As part of the infection chain, the attackers also used obfuscated Python scripts to install the malware. Python’s popularity – which is being further boosted by rising interest in AI and data science – means it is an increasingly attractive language for attackers to write malware, as its interpreter is widely installed.
Patrick Schläpfer, Principal Threat Researcher in the HP Security Lab, comments:
“A common thread across these campaigns is the use of obfuscation and anti-analysis techniques to slow down investigations. Even simple but effective defence evasion techniques can delay the detection and response of security operations teams, making it harder to contain an intrusion. By using methods like direct system calls, attackers make it tougher for security tools to catch malicious activity, giving them more time to operate undetected – and compromise victims endpoints.”
READ ALSO: HP Revolutionizes Large Format Printing With The New 36-inch DesignJet Portfolio
By isolating threats that have evaded detection tools on PCs – but still allowing malware to detonate safely inside secure containers – HP Wolf Security has specific insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on more than 65 billion email attachments, web pages, and downloaded files with no reported breaches.
The report, which examines data from calendar Q4 2024, details how cybercriminals continue to diversify attack methods to bypass security tools that rely on detection, such as:
At least 11% of email threats identified by HP Sure Click bypassed one or more email gateway scanners.
Executables were the most popular malware delivery type (43%), followed by archive files (32%).
Dr. Ian Pratt, Global Head of Security for Personal Systems at HP Inc., comments:
“Multi-step authentication is now the norm, which is increasing our ‘click tolerance.’ The research shows users will take multiple steps along an infection chain, really underscoring the shortcomings of cyber awareness training. Organizations are in an arms race with attackers—one that AI will only accelerate.
To combat increasingly unpredictable threats, organizations should focus on shrinking their attack surface by isolating risky actions – such as clicking on things that could harm them. That way, they don’t need to predict the next attack; they’re already protected.”
News
Trump’s Airstrikes: Halt Military Cooperation With US Immediately – Sheikh Gumi Tells Tinubu Govt

Islamic cleric, Sheikh Ahmad Gumi has called on the Federal Government to immediately halt all military cooperation with the United States following reported US airstrikes.
Gumi warned that American involvement could worsen Nigeria’s security challenges and undermine national sovereignty.
Gumi made the call in a statement posted on his Facebook page on Friday.
He said while Islam permits the fight against terrorism, such actions should only be carried out by what he described as “clean hands,” arguing that the United States lacks the moral authority to lead such efforts because of its global military record.
READ ALSO:US Dept Of War Shares Video Of Air Strikes In Nigeria
According to the cleric, Nigeria made a mistake by allowing foreign powers to play a role in its counterterrorism operations, insisting that “terrorists do not truly fight terrorists” and that such interventions often result in civilian casualties and hidden political motives.
Gumi warned that allowing Nigeria to become a theatre of war would attract anti-US forces into the country, further destabilising it.
He also cautioned that US involvement, particularly under claims of protecting Christians, could polarise the country along religious lines.
READ ALSO:Trump To Attend FIFA World Cup Finals Draw On Friday
The cleric further argued that airstrikes alone cannot defeat terrorism, stressing that effective counterterrorism requires strong ground operations, which he said Nigeria has enough personnel to carry out if properly organised.
“This is the mistake Nigeria has made. Terrorists don’t fight terrorists in truth; they may only kill innocent people and have ulterior motives behind the drama of fighting ‘terror’.
“As a principle, no nation should allow its land to be a theater of war. And no nation should allow its neighbors to be their enemies.
“If Nigeria wants military assistance, China, Turkey, and Pakistan can do the job effectively,” part of his statement reads.
News
Shehu Sani Reacts To Trump’s Military Strikes In Nigeria

Former lawmaker, senator Shehu Sani, has reacted to reports of United States military strikes on terrorist targets in Nigeria’s North-West, saying foreign powers cannot permanently handle the country’s security challenges.
Sani made the remarks on Friday via his X handle while responding to a post by the United States Africa Command, AFRICOM, which indicated that the strikes were carried out in coordination with Nigerian authorities.
According to him, if the reported strikes were indeed a joint operation with Nigerian security agencies, then such action was justifiable, given the threat posed by terrorist groups in the region.
READ ALSO:US Dept Of War Shares Video Of Air Strikes In Nigeria
He described terrorists operating in parts of northern Nigeria as “cancerous cells,” stressing that they survive through violence and should be confronted decisively.
Sani also dismissed narratives suggesting that terrorist attacks target only one religious group, describing such claims as false and misleading.
He said: “If actually, the military strikes against the terrorists targets in the North Western part of Nigeria were a joint operation with the ‘Nigerian Authorities’ as posted by the US AFRICOM on their verified X handle, then it’s a conscionable action.
READ ALSO:JUST IN: US Forces Bomb Terrorists Camps In Nigeria
“Terrorists have become cancerous cells in our part of the country.They live by the sword.The narrative that the evil terrorists only targets one faith, remains absolutely false and misleading.
“Again, the ultimate security and peace in our country lies with ourselves and not with the US or any foreign power. They can complimentarily or unilaterally strike, but they can’t eternally fight our battles.”
News
UKWU! Timaya Falls On Stage While Trying To Lift Plus-sized Woman During Performance [VIDEO]

Nigerian singer, Timaya fell on stage while trying to lift a plus-sized lady during performance.
The incident occurred during his ‘Ukwu’ performance at the Gbaramatu Christmas Carnival in Delta State.
READ ALSO:Saboteurs Against Presidential Amnesty Reforms – General Ndiomu
Timaya in a now trending video on social media collapsed after the plus-sized woman jumped on him midday into his performance.
The singer later got up and continued his performance amid cheers from the crowd.
Watch video here
https://x.com/hypetribeng/status/2004263337572684157?s=20
News4 days agoPHOTOS: New Era In Furupagha-Ebijaw As Okpururu 1 Receives Staff Of Office
News3 days agoUBTH CMD Marks 120 Days In Office, Expresses Commitment To Providing Conducive Working Environment
News4 days agoOPINION: Gumi And His Terrorists
News3 days agoFIRS Confirms NIN As Tax ID
News4 days agoFG Declares Public Holidays For Christmas, New Year Celebrations
Metro3 days agoFintiri Pardons Man Sentenced To Death For ‘Killing Herdsman In Self-defence’, Others
News4 days agoOPINION: Christmas And A Motherless Child
News3 days agoOPINION: My Man Of The Season
News2 days agoJUST IN: Kano Lawmaker, Sarki Aliyu Daneji, Dies Hours After Colleague’s Passing
News3 days agoKWAM 1 Withdraws From Awujale Race, Ends Court Challenge













