News
‘I Am Not a Robot’, CAPTCHAs Being Used to Spread Malware, HP Warns

Today at its annual Amplify Conference, HP Inc. (NYSE: HPQ) issued the latest HP Threat Insights Report, highlighting rising usage of fake CAPTCHA verification tests which allow threat actors to trick users into infecting themselves. The campaigns show attackers are capitalizing on people’s increasing familiarity with completing multiple authentication steps online – a trend HP calls ‘click tolerance’.
With analysis of real-world cyberattacks, the HP Threat Insights Report helps organizations to keep up with the latest techniques cybercriminals are using to evade detection and breach PCs. Based on data from millions of endpoints running HP Wolf Security1, notable campaigns identified by HP threat researchers include:
CAPTCHA Me If You Can: As bots get better at bypassing CAPTCHAs, authentication has grown more elaborate – meaning users have become more accustomed to jumping through hoops to prove they are human. HP threat researchers identified multiple campaigns where attackers crafted malicious CAPTCHAs. Users were directed to attacker-controlled sites, and prompted to complete a range of fake authentication challenges. Victims were tricked into running a malicious PowerShell command on their PC that ultimately installed the Lumma Stealer remote access trojan (RAT).
READ ALSO: HP Report Uncovers South African Youth’s Growing Interest in Gaming Careers Amid Awareness Gap
Attackers Capable of Accessing End-Users’ Webcams and Microphones to Spy on Victims: A second campaign saw attackers spreading an open source RAT, XenoRAT, with advanced surveillance features such as microphone and webcam capture. Using social engineering techniques to convince users to enable macros in Word and Excel documents, attackers could control devices, exfiltrate data, and log keystrokes – showing Word and Excel still present a risk for malware deployment.
Python Scripts Used for SVG Smuggling: Another notable campaign shows how attackers are delivering malicious JavaScript code inside Scalable Vector Graphic (SVG) images to evade detection. These images are opened by default in web browsers and execute the embedded code to deploy seven payloads—including RATs and infostealers—offering redundancy and monetization opportunities for the attacker. As part of the infection chain, the attackers also used obfuscated Python scripts to install the malware. Python’s popularity – which is being further boosted by rising interest in AI and data science – means it is an increasingly attractive language for attackers to write malware, as its interpreter is widely installed.
Patrick Schläpfer, Principal Threat Researcher in the HP Security Lab, comments:
“A common thread across these campaigns is the use of obfuscation and anti-analysis techniques to slow down investigations. Even simple but effective defence evasion techniques can delay the detection and response of security operations teams, making it harder to contain an intrusion. By using methods like direct system calls, attackers make it tougher for security tools to catch malicious activity, giving them more time to operate undetected – and compromise victims endpoints.”
READ ALSO: HP Revolutionizes Large Format Printing With The New 36-inch DesignJet Portfolio
By isolating threats that have evaded detection tools on PCs – but still allowing malware to detonate safely inside secure containers – HP Wolf Security has specific insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on more than 65 billion email attachments, web pages, and downloaded files with no reported breaches.
The report, which examines data from calendar Q4 2024, details how cybercriminals continue to diversify attack methods to bypass security tools that rely on detection, such as:
At least 11% of email threats identified by HP Sure Click bypassed one or more email gateway scanners.
Executables were the most popular malware delivery type (43%), followed by archive files (32%).
Dr. Ian Pratt, Global Head of Security for Personal Systems at HP Inc., comments:
“Multi-step authentication is now the norm, which is increasing our ‘click tolerance.’ The research shows users will take multiple steps along an infection chain, really underscoring the shortcomings of cyber awareness training. Organizations are in an arms race with attackers—one that AI will only accelerate.
To combat increasingly unpredictable threats, organizations should focus on shrinking their attack surface by isolating risky actions – such as clicking on things that could harm them. That way, they don’t need to predict the next attack; they’re already protected.”
News
Xenophobic Attacks: Oshiomhole Tells FG To Retaliate Against South African Companies In Nigeria

Senator Adams Oshiomhole has called on the Federal Government to retaliate against South African businesses operating in Nigeria following the recent attacks on Nigerians in South Africa.
Speaking during plenary on Tuesday, Oshiomhole said the Federal Government should consider revoking the working license of South African owned companies such as MTN and DSTV.
He argued that Nigeria must respond firmly to what he described as persistent hostility against its citizens.
READ ALSO:South Africa To Investigate ‘Mystery’ Of Planeload Of Palestinians
“I am not going to shed tears. If you hit me, I hit you. I think it is appropriate in diplomacy. It is an economic struggle,” Oshiomhole said.
He argued that while some South Africans accuse Nigerians of taking their jobs, Nigerians should return home and take over employment opportunities created by major South African companies operating in the country, including MTN and DSTV.
“When we hit back, the President of South Africa will not only talk but will also go on his knees to recognise that Nigeria cannot be intimidated.
READ ALSO:South African Ambassador Found Dead Outside Paris Hotel
“We will not condone any life being lost. If a crime has been committed under the South African law they have the right to bring any such person to justice, but to kill our people as if we are helpless, we will not allow that,” Oshiomhole added.
DAILY POST reports that several Nigerians in South Africa have reportedly been attacked, and their businesses destroyed, in ongoing xenophobic attacks in the country.
News
IGP Orders Officers Display Name Tag On Uniform, Gives Update On State Police

The Inspector General of Police, IGP, Tunji Disu, has ordered all police personnel to always have their name tags on their uniforms for easy identification.
Disu disclosed that only police personnel who are undercover are exempted from displaying their name tags.
Speaking on Tuesday, Disu said: “All police officers should have their name tags. All of us on the high table have our names apart from the undercover among us so if you look at all the Commissioners of Police we have our name tags, so it’s not our standard.
READ ALSO:
“All the Commissioners of Police are here and that is why we called this meeting, we have list of things like this that we will want to discuss with the Commissioners of Police, we have told them earlier and we will still let them know that every that happens within their area of jurisdiction falls under their control.”
On the issue of state police, the IGP said: “Since we got the signal that the Federal Government of Nigeria intend to establish State Police and since we are the federal police, we decided to take the bull by the horn and put down our own side of what we believe on how the state police should be run.
“A lot of things were taken into consideration, a lot of comparative analysis was done and it has been transmitted to the National Assembly.”
News
Court Orders SERAP To Pay DSS Operatives N100m For Defamation

The High Court of the Federal Capital Territory has ordered a non-governmental organization, the Socio-Economic Rights and Accountability Project, SERAP, to pay N100 million as damaged to two operatives of the Department of the State Services, DSS, for unjustly defaming them in some publications.
The court also ordered SERAP to tender public apologies to the defamed officers,
Sarah John and Gabriel Ogundele, in two national newspapers, two television stations and its website.
Besides, the organization was also ordered to pay the two operatives N1 million as cost of litigation and 10 percent post-judgment interest annually on the judgment sum until it’s fully liquidated.
Justice Yusuf Halilu of the High Court of the Federal Capital Territory gave the order on Tuesday while delivering judgment in a N5.5 billion defamation suit instituted against SERAP by the DSS operatives.
The judge found SERAP liable for unjustly defaming the two DSS operatives with allegations that they unlawfully invaded its Abuja office, harassed and intimidated its staff, in September 2024.
READ ALSO:How We Arrested Terror Suspect Who Threatened To Kill Students, Teachers In Abuja — DSS
In the offending publication on its website and Twitter handle, SERAP alleged that the two operatives unlawfully invaded and occupied its office with sinister motives.
The judge held that the publication was in bad taste especially from an organization established to promote transparency and accountability, as nothing in the publication was found to be truthful.
The DSS staff had listed SERAP as 1st defendant in the suit marked CV/4547/2024. SERAP’s Deputy Director, Kolawole Oluwadare, was listed as the 2nd defendant.
In the suit, the claimants – Sarah John and Gabriel Ogundele – accused the two defendants of making false claims that they invaded SERAP’s Abuja office on September 9, 2024..
Counsel to the DSS, Oluwagbemileke Samuel Kehinde, had while adopting his final address in the mater urged the judge to grant all the reliefs sought by his client in the interest of justice.
READ ALSO:DSS Arrests Suspected Gunrunner, Recovers 832 Rounds Of Ammunition
He admitted that although the names of the two claimants were not mentioned in the defamation materials, they had however established substantial circumstances that they are the ones referred to in the published defamation article by SERAP on its website.
The counsel submitted that all ingredients of defamation have been clearly established and the offending publication referred to the two officials of the secret police.
However, SERAP, through its counsel, Victoria Bassey from Tayo Oyetibo, SAN, law firm, asked the court to dismiss the suit on the ground that the two claimants did not establish that they were the ones referred to in the alleged defamation materials.
She said that SERAP used “DSS officials” in the alleged offending publication, adding that the two claimants must establish that they are the ones referred to before their case can succeed.
Similar arguments were canvassed by Oluwatosin Adefioye who stood for the second defendant, adding that there was no dispute in the September 9, 2024 operation of DSS in SERAP’s office.
READ ALSO:Alleged Cyberstalking: DSS Plays Video Evidence In Sowore’s Trial
He said that since SERAP in the publication did not name any particular person, the claimants must plead special circumstances that they were the ones referred to as the DSS officials.
Besides, he said that there is no organization by name Department of State Services in law, hence, DSS cannot claim being defamed adding that the only entity known to law is National Security Agency.
The claimants had in the suit stated that the alleged false claim by SERAP has negatively impacted on their reputation.
The DSS also stated, in the statement of claim, that, in line with the agency’s practice of engaging with officials of non-governmental organisations operating in the FCT to establish a relationship with their new leadership, it directed the two officials – John and Ogunleye – to visit SERAP’s office and invite them for a familiarization meeting.
The claimants added that in carrying out the directive, John and Ogunleye paid a friendly visit to SERAP’s office at 18 Bamako Street, Wuse Zone 1, Abuja on September 9 and met with one Ruth, who upon being informed about the purpose of the visit, claimed that none of SERAP’s management staff was in the country and advised that a formal letter of invitation be written by the DSS.
READ ALSO:DSS, Police Partner NCCSALW To End Terrorism, Mop Up Illegal Arms
John and Ogundele, who claimed that their interactions with Ruth were recorded, said before they immediately exited SERAP’s office, Ruth promised to inform her organisation’s management about the visit and volunteered a phone number – 08160537202.
They said it was surprising that, shortly after their visit, SERAP posted on its X (Twitter) handle – @SERAPNigeria – that officers of the DSS are presently unlawfully occupying its office.
The claimant added, “On the same day, the defendants also published a statement on SERAP’s website, which was widely reported by several media outfits, falsely alleging that some officers from the DSS, described as “a tall, large, dark-skinned woman” and “a slim, dark skinned man,” invaded their Abuja office and interrogated the staff of the first defendant (SERAP).
John and Ogundele stated that “due to the false statements published by the defendants, the DSS has been ridiculed and criticised by international agencies such as the Amnesty International and prominent members of the Nigerian society, such as Femi Falana (SAN)”.
“Due to the false statements published by the defendants, members of the public and the international community formed the opinion that the Federal Government is using the DSS to harass the defendants.”
READ ALSO:SERAP To Court: Stop CBN From ‘Implementing ‘Unlawful, Unjust ATM Fee Hike’
They added that the defendants’ statements caused harm to their reputation because the staff and management of the DSS have formed the opinion that the claimants did not follow orders and carried out an unsanctioned operation and are therefore, incompetent and unprofessional.
The claimants therefore prayed the court for the following reliefs: “An order directing the defendants to tender an apology to the claimants via the first defendant’s (SERAP’s) website, X (twitter) handle, two national daily newspapers (Punch and Vanguard) and two national news television stations (Arise Television and Channels Television) for falsely accusing the claimants of unlawfully invading the first defendant’s office and interrogating the first defendant’s staff.
“An order directing the defendants to pay the claimants the sum of N5 billion as damages for the libellous statements published about the claimants.
“Interest on the sum of N5b at the rate of 10 percent per annum from the date of judgment until the judgment sum is realised or liquidated.
“An order directing the defendants to pay the claimants the sum of N50 million as costs of this action.”
Politics4 days ago2027: Tinubu’s Re-election May Put An End To Nigeria — Baba Ahmed Warns
Metro5 days agoI’m A Street Girl’ – Bimbo Ademoye Clashes With Area Boys [VIDEO]
Politics5 days agoSenatorial Seat: Ogbakha-Edo Warns Against Imposition Of Candidates In Edo South
Politics4 days agoBREAKING: 2027: Former Adamawa APC Guber Candidate, Aishatu Binani Defects To NDC
Business3 days agoJUST IN: Nigerian Filling Stations Reduce Fuel Price After Hike
Entertainment4 days agoActress Eniola Badmus Gets New Federal Appointment
News5 days ago10 African Countries With Highest Petrol Prices In Prices In April 2026
News2 days agoBREAKING: Wike Picks Alabo George For Rivers Governorship
News3 days agoOPINION: Why South Africans Murder Nigerians In Cold Blood
News4 days ago2027: Pastor Adeboye Speaks On Nigeria’s Next President














