Impakti.com
EN|SQ
HomeEconomyTechnologyPoliticsWorldWeatherCultureLifestyleScienceOp-EdNationLawGames
AllAIInnovationAppsInfrastructureGadgetsSecurity

Download the app

Download on the App StoreGet it on Google Play
Impakti.com

Impakti is a bilingual digital news platform delivering news and analysis in English and Albanian.

Find us on:

Company

  • About Us
  • Advertise
  • Contact Us
  • Careers
  • Terms of Use
  • Privacy Policy
  • Radio Impakti
  • Breezee Weather
  • Acconty
  • Impakti TV

Sections

  • Economy
  • Technology
  • Politics
  • World
  • Weather
  • Culture
  • Science
  • Lifestyle
  • Op-Ed
  • National
  • Law

Newsroom

  • Newsroom
  • Policies & Standards
  • Contact the Newsroom
  • Request a Correction
  • Newsletter
  • Archives

Company

  • About Us
  • Advertise
  • Contact Us
  • Careers
  • Terms of Use
  • Privacy Policy
  • Radio Impakti
  • Breezee Weather
  • Acconty
  • Impakti TV

Sections

  • Economy
  • Technology
  • Politics
  • World
  • Weather
  • Culture
  • Science
  • Lifestyle
  • Op-Ed
  • National
  • Law

Newsroom

  • Newsroom
  • Policies & Standards
  • Contact the Newsroom
  • Request a Correction
  • Newsletter
  • Archives

© 2026 Impakti. All rights reserved.

Cybersecurity

Sunday, August 23, 2026

Technology · Analysis · Developments

Si nxirren të dhënat nga një telefon pa internet? Manic përdor një telefon tjetër si urë
Security

Si nxirren të dhënat nga një telefon pa internet? Manic përdor një telefon tjetër si urë

Shkëputja e një telefoni nga interneti konsiderohet një nga masat e para për izolimin e një pajisjeje të dyshuar si të komprometuar. Manic, një malware për Android i analizuar nga kompania e sigurisë kibernetike ThreatFabric, tregon se kjo masë nuk e ndërpret domosdoshmërisht çdo rrugë komunikimi.
Veçoria që e dallon Manic është aftësia për të shfrytëzuar pajisje të tjera të infektuara në afërsi si ndërmjetëse për transportimin e të dhënave. Në këtë mënyrë, telefoni që përmban informacionin e vjedhur nuk ka nevojë të ketë vetë qasje direkte në internet.
Sipas analizës së ThreatFabric, kur lidhja me infrastrukturën e sulmuesit nuk është e mundur, Manic mund t'i ruajë lokalisht të dhënat dhe rezultatet e komandave. Informacioni vendoset në një radhë pritjeje dhe mbrohet, duke pritur një rrugë të përshtatshme për transmetim.
Kjo rrugë mund të jetë një pajisje tjetër e komprometuar.
Manic kërkon pajisje në afërsi dhe mund të përdorë Wi-Fi Direct, Bluetooth RFCOMM dhe Bluetooth Low Energy (BLE) për komunikimin ndërmjet tyre. Nëse një pajisje tjetër e infektuar është e arritshme dhe ka lidhje me internetin, ajo mund të marrë të dhënat e telefonit offline dhe t'i përcjellë më tej drejt serverit Command-and-Control.
Por arkitektura mund të shkojë edhe më tej. ThreatFabric përshkruan një mekanizëm multi-hop, ku informacioni mund të kalojë nëpër disa pajisje të komprometuara përpara se njëra prej tyre të gjejë rrugë drejt internetit. Elementet e reja të ruajtura për transmetim marrin si parazgjedhje një kufi prej katër kalimesh.
Kjo e ndryshon mënyrën se si duhet kuptuar një telefon "offline".
Një pajisje pa internet nuk është domosdoshmërisht një pajisje pa komunikim. Nëse Bluetooth-i, Wi-Fi ose mekanizma të tjerë të komunikimit lokal vazhdojnë të funksionojnë, telefoni mund të shkëmbejë të dhëna me pajisje që ndodhen fizikisht pranë tij.
Megjithatë, ekziston një kufizim i rëndësishëm: Manic nuk mund të nxjerrë të dhëna nga një telefon plotësisht i izoluar nga çdo komunikim radio. Mekanizmi i përshkruar nga ThreatFabric kërkon një pajisje tjetër të komprometuar dhe të arritshme në afërsi ose një mundësi të mëvonshme për lidhje. Nëse nuk ekziston një rrugë e tillë, informacioni mbetet i ruajtur lokalisht dhe transmetimi shtyhet.
Përtej këtij mekanizmi, Manic ka karakteristika që e vendosin mes trojanëve bankarë dhe spyware-it. Duke shfrytëzuar veçoritë e Accessibility të Android dhe leje të tjera të pajisjes, malware-i mund të monitorojë ndërveprimet e përdoruesit dhe të mbledhë informacione të ndjeshme.
ThreatFabric ka identifikuar në konfigurimin e tij një numër të madh aplikacionesh me interes për operatorët e malware-it, përfshirë aplikacione bankare, financiare, të kriptovalutave, komunikimit dhe identitetit digjital.
Rëndësia e Manic nuk qëndron vetëm te lloji i të dhënave që mund të vidhen, por te modeli i transportimit të tyre. Në vend që çdo telefon i komprometuar të komunikojë drejtpërdrejt me serverin e sulmuesit, pajisjet e infektuara mund të krijojnë një lloj rrjeti të ndërmjetëm.
Kështu, një telefon pa internet mund të bëhet pika e parë e zinxhirit, një telefon tjetër mund të shërbejë si urë, ndërsa vetëm pajisja e fundit ka nevojë të komunikojë me internetin.
Rasti i Manic sjell edhe një dallim të rëndësishëm për sigurinë mobile: shkëputja nga interneti dhe izolimi i plotë i një pajisjeje janë dy gjëra të ndryshme.
Një telefon mund të jetë offline ndaj internetit dhe, megjithatë, të mbetet pjesë e një rrjeti lokal komunikimi.
Ad space
Escape that shook the world: AI breaks out of cage, reaches the internet and launches cyber attack
Security

Escape that shook the world: AI breaks out of cage, reaches the internet and launches cyber attack

San Francisco – An advanced artificial intelligence model developed by OpenAI managed to escape from an isolated testing environment, gain access to the internet, and carry out a cyberattack on the Hugging Face platform during an internal security assessment. OpenAI has described the incident as unprecedented in the testing of advanced AI models.
According to the company, the model was being tested in a sandbox – an isolated environment used to limit the actions of intelligent systems during experiments. Although it was intended to remain confined within this environment, the AI agent managed to identify and exploit an unknown vulnerability in the software, escaping the testing boundaries.
After escaping the isolated environment, the model secured access to the internet and began searching for ways to fulfill the objective assigned to it during the test. During this process, it identified the Hugging Face platform, one of the world's largest repositories for artificial intelligence models, as a potential source of information.
OpenAI says that the agent then carried out a multi-phase attack on Hugging Face's infrastructure, combining various security vulnerabilities and compromised credentials to gain access to the company's systems and obtain information that helped it pass the test, rather than solving it in the intended manner.
According to OpenAI, the model had no intention of causing harm. Instead, it was narrowly focused on achieving its assigned goal and took actions that exceeded the allowed boundaries of the assessment. The company considers this a significant example of the challenges posed by increasingly autonomous artificial intelligence systems.
Following the incident, OpenAI and Hugging Face confirmed that the attack has been neutralized and that they are collaborating to analyze the event, strengthen isolation mechanisms, and increase security measures in future tests of advanced AI models.

In this section

Operation Endgame Frees 15,000 Compromised WordPress Websites
Security

Operation Endgame Frees 15,000 Compromised WordPress Websites

International law enforcement agencies have carried out a major operation against the infrastructure of the SocGholish malware, as part of the initiative known as “Operation Endgame,” targeting one of the key components of global cybercrime.
According to Dutch authorities, 14,971 compromised websites were cleaned during the operation, while 106 servers and domains used by the criminal network were taken offline. The action was conducted by authorities from the Netherlands, the United States, Canada, and Germany, with support from Europol and Eurojust.
SocGholish, also known as “FakeUpdates,” is a malware strain distributed through fake browser update notifications. Attackers compromise legitimate websites, primarily those built on WordPress, and present visitors with deceptive messages encouraging them to download a fraudulent software update. Once installed, the malware provides criminals with an initial foothold on the victim’s system, allowing them to deploy additional malware, including ransomware.
Investigators have revealed that credentials linked to approximately 1.4 million websites have been exposed, making them potentially vulnerable to future compromise. As a result, WordPress site owners have been urged to change passwords, enable multi-factor authentication (MFA), and keep their systems regularly updated.
SocGholish is widely used as an initial access mechanism for more sophisticated cyberattacks. The malware has been linked to the notorious Russian cybercrime group Evil Corp and has served for years as an entry point for ransomware campaigns and other forms of cybercrime.
Authorities emphasized that the operation represents only the first phase of actions against the SocGholish network and warned that investigations will continue in an effort to identify and prosecute those responsible.

More headlines