{"id":22777,"date":"2018-12-22T03:02:44","date_gmt":"2018-12-22T03:02:44","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/"},"modified":"2018-12-22T03:02:44","modified_gmt":"2018-12-22T03:02:44","slug":"your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/","title":{"rendered":"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more"},"content":{"rendered":"<p><strong class=\"trailer\">Roundup<\/strong> If you&#8217;re reading this while on-call for IT support, network security, or what have you, then we salute you. If you&#8217;re reading this to avoid Christmas present wrapping or hobnobbing with awkward relatives, or similar, then, well, let us shake your hand.<\/p>\n<p>For you, here&#8217;s a rapid-fire roundup of infosec-related news to close out this week, in no particular order.<\/p>\n<p><strong>Gatwick drone arrests:<\/strong> Two people have been <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/news.sky.com\/story\/two-people-arrested-over-criminal-use-of-drones-at-gatwick-airport-11588565\">arrested<\/a> by cops probing the &#8220;criminal use of drones&#8221; that caused <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/12\/21\/gatwick_airport_reopens_drones_closure\/\">chaos<\/a> at Gatwick Airport for 100,000-plus air travelers this week.<\/p>\n<p><strong>No Russian vote hack:<\/strong> The US Director of National Intelligence, Dan Coats, <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/twitter.com\/jimsciutto\/status\/1076238109367586816\">concluded<\/a> on Friday that no hackers &#8220;prevented voting, changed vote counts, or disrupted the ability to tally votes,&#8221; although Russia, China and Iran &#8220;conducted influence activities and messaging campaigns &#8230; to promote their strategic interests.&#8221;<\/p>\n<p><strong>Amazon Alexa all bot and bothered:<\/strong> Since 2016, Amazon has <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2016\/09\/30\/talk_isnt_cheap_amazon_offers_25_million_for_chatty_bots\/\">dangled<\/a> hundreds of thousands of dollars in prizes in front of computer-science students to encourage them to develop conversational bots, accessed via its voice-controlled Alexa personal assistant. When people want to talk to one of these experimental chat bots, they ask Alexa to put them in touch with the software, the bot is loaded up, Alexa takes a back seat, and the chat code starts nattering with the user.<\/p>\n<p>Well, it&#8217;s emerged those bots have been <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.reuters.com\/article\/us-amazon-com-alexa-insight\/kill-your-foster-parents-amazons-alexa-talks-murder-sex-in-ai-experiment-idUSKCN1OK1AJ\">caught<\/a> telling folks to &#8220;kill your foster parents,&#8221; discussed sex acts, and so on, after the software went awry. At point, Amazon CEO Jeff Bezos ordered one of the errant bots to be shut down because it was too embarrassing, it is claimed.<\/p>\n<p>Worse, hackers in China were able to break into one of the students&#8217; bots and extract transcripts of people&#8217;s conversations sans usernames, according to Reuters.<\/p>\n<p>&#8220;These instances are quite rare especially given the fact that millions of customers have interacted with the socialbots,&#8221; an Amazon spokesperson said of the chat gaffes.<\/p>\n<p><strong>Windows zero-day drop:<\/strong> A bug-hunter this week popped online a proof-of-concept <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/sandboxescaper.blogspot.com\/2018\/12\/readfile-0day.html\">exploit<\/a> for another Windows zero-day, in that there is no patch available for this hole. This one allows any user to read the contents of a file that a system administrator can access, and abuses a bug in the operating system&#8217;s Readfile API call. It is <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/twitter.com\/0patch\/status\/1075774079876063232\">confirmed<\/a> to be a legit exploit.<\/p>\n<p>The FBI is also <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/sandboxescaper.blogspot.com\/2018\/12\/lol.html\">apparently sniffing<\/a> around the researcher, requesting her Google account records, perhaps in relation to <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/08\/28\/windows_zero_day_lpe\/\">earlier<\/a> <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/10\/24\/windows_0day_twitter\/\">zero-day<\/a> disclosures, or perhaps due to a tweeted threat against the US President.<\/p>\n<p><strong>Huawai, ZTE? Czech, mate:<\/strong> Software and hardware from Chinese tech giants Huawei and ZTE are a <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.govcert.cz\/en\/info\/events\/2682-software-and-hardware-of-huawei-and-zte-is-a-security-threat\/\">security threat<\/a>, the Czech government has warned. &#8220;Issue of this warning concludes our findings and those of our allies and security partners,&#8221; the Euro nation&#8217;s cyber-agency added.<\/p>\n<p><strong>Mass phone snooping \u2013 EFF&#8217;ing hell:<\/strong> Following a long-running freedom-of-information lawsuit, the EFF has succeeded in <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.eff.org\/deeplinks\/2018\/12\/and-after-what-we-learned-about-hemisphere-program-after-suing-dea\">obtaining<\/a> documents detailing <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2013\/09\/04\/att_dea_hemisphere_program\/\">project Hemisphere<\/a>: a system America&#8217;s drug cops used to &#8220;tap into trillions of of phone records going back decades,&#8221; with the help of AT&amp;T.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2018\/12\/20\/wanted_zhu_zhang.jpg?x=174&amp;y=115&amp;crop=1\" width=\"174\" height=\"115\" alt=\"FBI wanted poster of Zhu Hua and Zhang Shilong\"\/><\/p>\n<h2 title=\"Pair on cyber-espionage rap, HPE, IBM and their clients said to be among those hit\">Uncle Sam fingers two Chinese men for hacking tech, aerospace, defense biz on behalf of Beijing<\/h2>\n<p><a href=\"https:\/\/www.theregister.co.uk\/2018\/12\/20\/two_alleged_chinese_hackers\/\"><span>READ MORE<\/span><\/a><\/div>\n<p><strong>Denial-of-service-for-hire denied:<\/strong> On Thursday, US prosecutors <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.justice.gov\/opa\/pr\/criminal-charges-filed-los-angeles-and-alaska-conjunction-seizures-15-websites-offering-ddos\">seized and shut down<\/a> 15 websites that offered to launch distributed-denial-of-service attacks against companies and networks in exchange for dosh. These so-called booter for-hire sites would be tapped up by miscreants to take down stuff like gaming platforms and online retailers. Clobbering these booters means there&#8217;s less chance scumbags will use them to cause mischief or chaos over Christmas.<\/p>\n<p>In relation to this, charges have also been brought against Matthew Gatrel, 30, of St Charles, Illinois, and Juan Martinez, 25, of Pasadena, California, for allegedly conspiring to violate the Computer Fraud and Abuse Act, and against David Bukoski, 23, of Hanover Township, Pennsylvania, for allegedly aiding and abetting computer intrusions.<\/p>\n<p><strong>Mac spyware goes undetected:<\/strong> A strain of document-stealing macOS malware, dubbed Windshift, was <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/objective-see.com\/blog\/blog_0x3B.html\">detected<\/a> by just two antivirus packages \u2013 Kaspersky and ZoneAlarm \u2013 four months after the lid was blown off the software nasty, according to Objective-See&#8217;s Patrick Wardle. The spyware is being thrown at targets in the Middle East, but mind how you go, Apple fans elsewhere.<\/p>\n<p><strong>Hey Uncle Sam, reveal your device snoop rules:<\/strong> Rights warriors the ACLU and Privacy International, and friends, are <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.aclu.org\/blog\/privacy-technology\/internet-privacy\/were-suing-government-learn-its-rules-when-it-hacks-peoples\">suing<\/a> the US government to discover the rules and procedures in place for agents authorized to hack into targets&#8217; computers, phones, and other devices.<\/p>\n<p>&#8220;The lawsuit demands that the agencies disclose which hacking tools and methods they use, how often they use them, the legal basis for employing these methods, and any internal rules that govern them,&#8221; law student Alex Betschen explained. &#8220;We are also seeking any internal audits or investigations related to their use.&#8221;<\/p>\n<p><strong>&#8216;White hat&#8217; hacker&#8217;s Nest beg:<\/strong> A bloke in Arizona, USA, says a <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/hotforsecurity.bitdefender.com\/blog\/spooked-by-a-speaking-security-camera-polite-hacker-tells-owner-how-to-fix-his-iot-security-20673.html\">hacker<\/a> broke into his Nest security camera from afar and spoke to him, through the device, warning the fella his equipment was insecure. It appears the chap, Gregg, had secured his Nest using a password that he had reused on another website or service that had been hacked or spilled its credentials. Therefore, miscreants could reuse the leaked password to break into his Nest.<\/p>\n<p>In short, use a unique password for your IoT gear, and activate two-step authentication where possible.<\/p>\n<p><strong>Hands off, St Jules:<\/strong> The UK government should let Wikileaks supremo Julian Assange walk free from Ecuador&#8217;s London embassy without arrest or extradition, UN human rights gurus <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.reuters.com\/article\/us-britain-assange-un-idUSKCN1OK1UF?\">urged<\/a> on Friday. The UN is essentially reiterating its 2016 <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2016\/02\/05\/assange_press_conference\/\">declaration<\/a> that Assange is being effectively detained unlawfully in Blighty.<\/p>\n<p><strong>Big trouble in big China:<\/strong> Watch out, if you&#8217;re using <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/github.com\/top-think\">ThinkPHP<\/a>. Roughly 50,000 Chinese websites have been <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.zdnet.com\/article\/chinese-websites-have-been-under-attack-for-a-week-via-a-new-php-framework-bug\/\">attacked<\/a> after a proof-of-concept remote-code execution <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.exploit-db.com\/exploits\/45978\">exploit<\/a> for ThinkPHP versions 5.0.23 and 5.1.31 was made public this month.<\/p>\n<p><strong>And finally&#8230;<\/strong> Be aware that it is possible to <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.amnesty.org\/en\/latest\/research\/2018\/12\/when-best-practice-is-not-good-enough\/\">phish<\/a> your multi-factor authentication tokens, as phishing targets in the Middle East and North Africa found out. Make sure you&#8217;re visiting the real website of your email provider, bank, and so on, rather than something dodgy like protonemail dot-com that will pretend to be a legit site, automatically snaffling your username, password, and token, as you enter them.<\/p>\n<p>Keybase has <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/keybase.io\/docs\/secadv\/kb002\">fixed<\/a> a local privilege escalation bug in its Linux software. And the Go programming language maintainers have <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/groups.google.com\/forum\/#!msg\/golang-announce\/Kw31K8G7Fi0\/z2olKn-QCAAJ\">patched<\/a> a bunch of vulnerabilities \u2013 one allowed remote-code execution via <code>go get -u<\/code>.<\/p>\n<p>Take care out there, and merry Christmas. \u00ae<\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2018\/12\/22\/security_roundup\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some last-minute wrapping of security-related tips from this week Roundup\u00a0 If you&#8217;re reading this while on-call for IT support, network security, or what have you, then we salute you. If you&#8217;re reading this to avoid Christmas present wrapping or hobnobbing with awkward relatives, or similar, then, well, let us shake your hand.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":22778,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-22777","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-12-22T03:02:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"174\" \/>\n\t<meta property=\"og:image:height\" content=\"115\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more\",\"datePublished\":\"2018-12-22T03:02:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/\"},\"wordCount\":1080,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/12\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/\",\"name\":\"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/12\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg\",\"datePublished\":\"2018-12-22T03:02:44+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/12\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/12\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/","og_locale":"en_US","og_type":"article","og_title":"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-12-22T03:02:44+00:00","og_image":[{"width":174,"height":115,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more","datePublished":"2018-12-22T03:02:44+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/"},"wordCount":1080,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/","url":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/","name":"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg","datePublished":"2018-12-22T03:02:44+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/12\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/your-two-minute-infosec-roundup-drone-arrests-alexa-bot-hack-windows-zero-day-and-more\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/22777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=22777"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/22777\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/22778"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=22777"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=22777"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=22777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}