DoFun head units hit by Android malware: ad bots reach the dashboard

Kaspersky says it found Android malware aimed at DoFun in-vehicle infotainment systems. The campaign hits Android-based DoFun head units and similar dash systems, pulling ad fraud and proxy-botnet activity into the dashboard itself.

Per Kaspersky, the malicious code shipped alongside legitimate DoFun software, which points to a supply-chain or packaging compromise that most users, installers, and resellers wouldn’t catch. It runs without any visible interface and quietly collects the device model, screen resolution, and Wi-Fi network ID. Not passwords or banking details, but enough to profile infected units, manage them, and make money from them.

It also matches the broader direction automotive security has been heading. Public automotive cyber incidents reached 494 in 2025. Ransomware made up 44% of them. Back in 2022, 97% of logged attacks were remote. VicOne says more than 77% of automotive vulnerabilities are in onboard systems, and IVI security spending is projected to climb from $2.4 billion in 2025 to $7.56 billion by 2034.

If you use a DoFun head unit, or depend on third-party or unofficial updates, don’t brush this off.

Chatbots and ‘sentient’ AI talk: makers could dodge blame as cases climb

A growing group of scholars is warning that, in 2026, all the talk about “conscious” AI can serve a pretty convenient purpose for chatbot companies: it can blur responsibility when users get hurt. Their point is simple. It doesn’t matter much whether a company pitches a chatbot as a mere tool or something more like an independent actor. The question is who answers for the damage. And in their view, there isn’t some special accountability gap here. Negligence law and product-liability law can still reach the companies that build, market, and roll out these systems.

ChatGPT Download

The number of incidents keeps moving the wrong way. One database recorded 362 cases in 2025, up from 233 in 2024. An OECD tracker shows something even starker, a tenfold increase in incidents from early 2020 to January 2026.

Courts are starting to push on the issue too. Wrongful death and personal injury lawsuits are already testing claims tied to suicide and worsening mental health. In one case, a court has signaled that AI output could count as a product, which could chip away at Section 230 of the Communications Decency Act as a defense.

If you pay attention to AI policy, keep an eye on this.

Europe is moving toward risk-based rules that should apply by June 2026, along with a liability proposal. The US is taking a different route, leaning more on voluntary commitments and existing regulators. Inside companies, the picture is mixed. The share cutting AI use without a policy fell from 24% to 11%, but the problems haven’t gone away: 59% still point to knowledge gaps, 48% cite budget limits, and IBM says AI-related breaches cost an average of $6 million. The fight ahead is pretty easy to see. Who pays, who fixes the damage, and who should’ve stopped it before it happened.

Apple rolls out WebKit security fixes: macOS, iPhone and iPad updates

Apple has shipped macOS Tahoe 26.6.2, along with iOS and iPadOS 26.6.1. The updates bring a sizable set of security patches for Macs, iPhones, and iPads, and most of them touch WebKit, the browser engine behind Safari.

For supported current devices, Apple lists 28 fixes. On the Mac side, 21 of those are tied to WebKit. iPhone and iPad users get those same 28 fixes, plus one more for Telephony authentication. Since every browser on iOS and iPadOS has to use WebKit, the bugs don’t just matter for Safari. Third-party browsers are affected too. The risks range from crashes and memory corruption to data leaks, code execution, sandbox escape, and data exfiltration.

Apple also pushed iOS 18.7.10 and iPadOS 18.7.10 for older devices. Those updates patch more than 120 bugs in total, based on Apple’s security notes, including more than 40 in WebKit. The rest cover areas like the Kernel, ImageIO, Audio, and networking, with issues tied to denial-of-service, private data exposure, code execution, and traffic interception.

Apple says it hasn’t seen any of these flaws used in active attacks. Still, once the security notes are out, unpatched devices get a lot easier to target. If your Mac, iPhone, or iPad can install one of these updates, it’s a good idea to do it.

You can download the updates now from Software Update on your Mac, iPhone, or iPad.

White House cyber memo opens the door: vetted firms can disrupt cybercrime gangs

The White House has released a new National Security Presidential Memorandum that opens a formal path for vetted private cybersecurity firms to help go after foreign cybercrime. Any company brought in would operate under Department of Homeland Security and Department of Justice oversight.

With that approval, companies could be authorized on a case-by-case basis to conduct cyber surveillance and cyber effects operations against overseas ransomware gangs, phishing networks, and fraud operations. The focus is especially on foreign safe havens where arrests, extraditions, or direct law enforcement action can be difficult.

That’s a real shift from the U.S. government’s long-standing reluctance to let private actors do much beyond defense and incident response.

If you follow U.S. cyber policy, keep an eye on this one. Washington says cybercrime caused more than $4 billion in U.S. losses in 2020. Many of the strongest defenders sit outside government, most of the infrastructure being targeted is privately run,

and this move lines up with a broader 2026 strategy alongside anti-fraud and National Security Systems efforts, while adding to sanctions and cooperation aimed at threats Washington has tied to China, Russia, Iran, and North Korea.

You should also expect intense scrutiny around legality, ethics, oversight, liability, hack-back limits, cross-border mistakes, retaliation,

and the hard-to-predict consequences of letting private firms move from defense into disruption.

You can read the memorandum through official White House channels.

libpng updates to fix a 1995 flaw: 17 decades-old bugs still linger

Libpng, the PNG image library sitting under a huge amount of software, got an update in February 2026 to fix CVE-2026-25646. This one goes all the way back to 1995. It was rated high severity, and it was also one of 17 vulnerabilities that stayed buried for more than a decade.

The flaw is a heap buffer overflow in the rarely used `png_set_quantize` function. A maliciously crafted PNG could crash an app and, in the worst case, expose information or open the door to remote code execution. Vulnerable libpng builds showed up in Debian, Red Hat, Ubuntu, desktop applications, and some Java runtimes. It’s a good example of how code written in the early Unix and DOS years still ends up inside current systems, even when actually exploiting the bug may not be easy.

PrintDemon follows the same script. It was a Windows printer weakness introduced in 1996 and not fixed until May 2020. What started as a permissive design choice to make printer setup easier turned into a security problem years later.

If you’re responsible for Linux, Windows, operational technology, or critical infrastructure, both the libpng fixes and the Windows patches are worth installing. Organizations still take more than 100 days on average to patch. Nearly 60% of compromises involve unpatched vulnerabilities. And older unsupported systems often don’t have strong access controls or modern encryption in place.

Get the patched versions from your Linux distribution, the affected application or Java runtime update, and Windows Update.

SpaceX Falcon 9 stage crashes into the Moon: a 60-foot crater is expected

A discarded SpaceX Falcon 9 upper stage from a January 2025 mission that sent two lunar landers on their way has slammed into the Moon’s far side more than a year later. Scientists who’ve been tracking it say this is only the second known case of an accidental rocket impact on the lunar surface.

Stellarium Download

The upper stage spent more than a year in a messy Earth-Moon orbit before gravity and solar activity nudged it toward the far side, near the Einstein and Bell craters.

Nobody on Earth could watch the impact happen. Confirmation will likely come from before-and-after images taken by spacecraft, along with a fresh crater thought to be about 60 feet across.

Researchers already have a decent handle on the stage’s mass, shape, and impact speed, which gives them something useful to work with. They’ll use the crash to study how the crater formed, how debris spread out from the impact, and whether any material from below the surface got exposed. NASA’s Lunar Reconnaissance Orbiter and South Korea’s Danuri are both expected to help map the site.

For people who follow lunar science, this is one to keep an eye on. Some experts see it as a rare and valuable data point. Others look at the same event and see another sign that cislunar space is getting crowded, with too little coordination around what’s left drifting there.

SpaceX says the Falcon 9 upper stage was disposed of under the rules in place at the time, before later being redirected.

The clearest follow-up should come from lunar orbiters, and the crash already belongs in the same category as the accidental Chinese rocket-stage strike in 2022, not deliberate impacts like NASA’s LCROSS mission in 2009.