Skip to main content

Search

Items tagged with: security


What Happens When a #Romance #Writer Gets Locked Out of #Google Docs


source: https://www.wired.com/story/what-happens-when-a-romance-author-gets-locked-out-of-google-docs/?esrc=AUTO_PRINT

In March, an aspiring author got a troubling message: All of her works in progress were no longer accessible. What happened next is every writer’s worst fear.

Google never specified which of her 222,000 words was inappropriate.


...

Generally speaking, files containing #violence, #abuse, child sexual abuse material, and gore violate the terms of service for Google Drive and its associated products, like Docs and Sheets.


Now many of you will be thinking, who is stupid enough to store everything in the Google #cloud? The problem is we know that, but many people out there don't. We urgently need to do more educational work and warn people about companies like Google and their practices. Tell all your friends and acquaintances and don't use the clouds of the big corporations.


#news #problem #fail #warning #danger #service #customer #internet #economy #security #wtf #omg #disaster


In case you missed it, what's new in the latest release from SimpleX Chat, v5.7:

Quantum resistant end-to-end encryption enabled for all contacts, forward and save messages without revealing the source, in-call sound effects and switching sound sources, and better network connection management.

Details: https://simplex.chat/blog/20240426-simplex-legally-binding-transparency-v5-7-better-user-experience.html#forward-and-save-messages

Coming soon: UI improvements is a major priority.

#Privacy #Security #Messengers



If you use Dropbox you should probably change your password.

Headline: #Dropbox Hacked! Threat Actor Accessed Passwords and Phone Numbers

Snippet: A quick analysis revealed that a threat actor had broken in to access customer information such as emails, usernames, phone numbers and hashed passwords, as well as general account settings and certain authentication information (API keys, OAuth tokens, and multi-factor authentication).

https://www.bitdefender.com/blog/hotforsecurity/dropbox-hacked-threat-actor-accessed-phone-numbers-and-passwords/

#Privacy #Security #Cybersecurity


Dropbox Sign has been hacked https://sign.dropbox.com/blog/a-recent-security-incident-involving-dropbox-sign Customer's emails, usernames, phone numbers and hashed passwords, in addition to general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication data stolen by threat actors. #infosec #security


Oh, great. Computer security researchers have developed a proof-of-concept for a type of ransomware that would act when you try to *upload* a file. It would be able to encrypt any files in the folder you uploaded from, and any subfolders of it.

This is a proof-of-concept; the researchers have not seen any such attacks in the wild. But stay careful out there, okay?

Affects Chrome and Edge, but *not* Firefox or Safari!

https://theconversation.com/cybersecurity-researchers-spotlight-a-new-ransomware-threat-be-careful-where-you-upload-files-219560

#security #cybersecurity #malware #ransomware


Hackers claim to have infiltrated #Belarus’ main #security service


Source: https://apnews.com/article/belarus-cyberattack-kgb-dissent-efc7e6acd9dfe8a118e1d2f526c4d6fa

A Belarusian #hacker activist group claims to have infiltrated the network of the country’s main #KGB security agency and accessed personnel files of over 8,600 employees of the organization, which still goes under its Soviet name.


#hack #news #politics #cyberwar


For those who like to focus on #security an honest question: which other messenger has, like #deltachat in the last 13 months, received and addressed two independent security audits and one security analysis, all three from renowned auditors and researchers? CC @kuketzblog https://delta.chat/en/help#security-audits


#Safari on #iOS features device #tracking


source: https://mastodon.social/@mysk/112340023465073147

#Apple recently introduced a new URI scheme so that #iOS users in the #EU can install marketplace apps from the browser. #Safari handles the scheme insecurely leaving users exposed to tracking.


#surveillance #politics #europe #software #security #privacy #news #problem #fail #smartphone #warning


#Emergency slide falls off #Delta #plane after takeoff - yes it's a #Boeing


source: https://www.reuters.com/business/aerospace-defense/emergency-slide-falls-off-delta-plane-after-takeoff-2024-04-26/

Delta said that crew on the flight, which had 183 people on board, declared an emergency and returned to John F. Kennedy International #Airport, that it "supporting retrieval efforts."


#fail #security #news #problem #flight


Google is out of their mind. There are so many other options for a "more secure" browser. Especially one that doesn't have Google tied to it.

https://infosec.exchange/@happygeek/112337847581863603

#Privacy #Security #InfoSec


#Windows #vulnerability reported by the #NSA exploited to install Russian #malware


Source: https://arstechnica.com/security/2024/04/kremlin-backed-hackers-exploit-critical-windows-vulnerability-reported-by-the-nsa/

When Microsoft patched the vulnerability in October 2022—at least two years after it came under #attack by the Russian hackers—the company made no mention that it was under active exploitation.


#patch #update #exploit #Russia #security #CyberSecurity #news #os #software #hack #hacker


This is such a brilliantly simple flaw, I can't believe I didn't think of it.

Maybe because it is brilliant. And simple.

https://www.theregister.com/2024/04/22/edr_attack_remote_data_deletion/

#security #malware


#CVE-2024-20356: #Jailbreaking a #Cisco appliance to run #DOOM


In this adventure, the Cisco #C195 device family was jailbroken in order to run unintended code. This includes the discovery of a vulnerability in the #CIMC body management controller which affects a range of different devices, whereby an authenticated high privilege user can obtain underlying root access to the server’s #BMC (CVE-2024-20356) which in itself has high-level access to various other components in the system. The end goal was to run DOOM – if a smart fridge can do it, why not Cisco?


source: https://labs.nettitude.com/blog/cve-2024-20356-jailbreaking-a-cisco-appliance-to-run-doom/

#software #security #bug #network #game #news #vulnerability #exploit #hack #hacker


Friends don't let friends use Discord.

Message History of 600 Million Discord Users Can be Accessed For $5

#privacy #security

https://80.lv/articles/message-history-of-600-million-discord-users-can-be-accessed-for-usd5/


Advanced #Phishing Kit Adds #LastPass Branding for Use in Phishing Campaigns

Threat actors using phishing kits are pretending to be LastPass in phone calls and emails to steal user credentials.

Actual phishing site: “help-lastpass[.]com”

Shortened URL Embedded in Email: shorturl[.]at/glvT0

Phishing Email Subject Line: We’re here for you

Spoofed Sender: Shows as LastPass Support <support@lastpass>

#security #cybersecurity #passwords

https://blog.lastpass.com/posts/2024/04/advanced-phishing-kit-adds-lastpass-branding-for-use-in-phishing-campaigns


@anonymiss

to me, #biometric unlocking, is unsafe, you see a lot of unauthorised unlocking from restrained, sleeping, dead, or drunken people from either face or fingerprint to unlock a device.

it was established a few years ago that law enforcement in the usa do not need a warrant for biometric unlocking, but need warrant if a password is enabled, to unlock a device.

#phone #thumbprint #court #usa #justice #privacy #security #smartphone #mobile #technology #news #police #surveillance


Well, the topic I disliked the most is your plan to compromise the online safety, security and privacy of all 450 million Europeans with the plans to scan their devices. In addition, you are not open and transparent enough about these plans, as most of those 450 million do not know you are working on this. You know it does not work and that is in violation with human rights, yet you keep pushing. Why? #CSAM #CSS #Encryption #Security #Privacy #GDPR


'Apple pulls WhatsApp, Threads from China app store... after being ordered to do so by the Chinese government, which cited national security concerns.
Telegram and Signal - two other foreign messaging apps - were also removed from the store on Friday, according to app tracking firms Qimai and AppMagic.'
https://www.reuters.com/technology/apple-removes-whatsapp-threads-china-app-store-wsj-reports-2024-04-19/
#apple #tech #Facebook #politics #china #security


The #press is barred from covering aspects of the trial related to the #jury, for understandable #security reasons. At the same time, the judge is taking another 5 days to hold a hearing on whether #Trump has violated the #GagOrder that was placed on him w/ repeated social media posts about a key #witness & #jurors.

This is 1 of many ways in which despite Trump's complaints that he is being treated unfairly, the judge is bending over backwards to be fair to him in this #trial.

#criminal #law


the talk. credit ig https://www.instagram.com/peter.conrad.comics/ #infosec #security #microsoft #technology


If you use Discord, you might wanna know this.

A service called Spy Pet is scraping Discord servers, archiving and tracking users' messages and activity, and then selling access to that data.

Spy Pet scrapes more than 10,000 Discord servers, and besides selling access to anyone with cryptocurrency, it offers the data for training AI models or to assist law enforcement agencies, according to its website.

Spy Pet claims to be tracking more than 14,000 servers, 600 million users, and includes a database of more than 3 billion messages.

(The article is paywalled probably, etc but it's here) https://www.404media.co/a-spy-site-is-scraping-discord-and-selling-users-messages

#Discord #security #SpyPet #privacy #scams #scammers #crypto #cryptocurrency #AI


The #XZ #backdoor provide critical lessons about #opensource #security. 🛡️ Here's a brief rundown of our response at #openSUSE. We're also likely to have some sessions at this year's @opensuse Conference. https://news.opensuse.org/2024/04/12/learn-from-the-xz-backdoor/


We had the same problem in Canada.

Telehealth firm Cerebral fined $7 million over ‘careless’ privacy violations
🇺🇸
The FTC accused it of sloppy data handling and sharing patient data with third parties like TikTok without consent

#News #Healthcare #Security #Privacy

https://www.theverge.com/2024/4/16/24131881/ftc-fine-cerebral-telehealth


The Prime Ministers of Poland and Denmark discussed the idea of creating an "iron dome" over Europe to protect against air attacks in case of war. Poland's Prime Minister emphasized the importance of such defense system after Iran's attack on Israel. The "iron dome" is a mobile air defense system used by Israel to intercept and destroy short-range missiles, artillery shells, and drones. #EuropeanDefense #Security


A hacking #skimmer inside an #ATM machine

https://youtube.com/shorts/29Uc_7bGcRE


#hack #security #money #technology


ALL CLEAR for Fedora Rawhide and Fedora 40 Beta builds regarding the xz exploit. 👍

Things had stabilized soon after the initial security advisory, but we're now confirming that you can use Rawhide and Fedora 40 Beta safely as long as you have the latest updates or reinstall (which is not a bad idea to be safe).

Fedora 38 and 39 were never affected.

Learn more: https://fedoramagazine.org/cve-2024-3094-all-clear/

#Fedora #Security #Privacy #InfoSec #Linux #OpenSource


So, Microsoft is silently installing Copilot onto Windows Server 2022 systems and this is a disaster.

How can you push a tool that siphons data to a third party onto a security-critical system?

What privileges does it have upon install? Who thought this is a good idea? And most importantly, who needs this?

#infosec #security #openai #microsoft #windowsserver #copilot


Let's use @protonprivacy and @Tutanota products.
Encryption is the single best hope against surveillance.

https://www.wired.com/story/house-section-702-vote/

#security #cybersecurity #infosec #nationalsecurity #nsa #fbi #section702 #privacy #government #surveillance #e2ee #tech #proton #protonmail #tuta #tutanota #bigtech #degoogle


Microsoft says it’s starting to test ads inside the Start menu on Windows 11. The software maker will use the Recommended section of the Start menu, which usually shows file recommendations, to suggest apps from the Microsoft Store. Trillion dollar corporation is so poor. They need more money by selling your data to the highest bidder. wtf? #privacy #security https://www.theverge.com/2024/4/12/24128640/microsoft-windows-11-start-menu-ads-app-recommendations


###
#Microsoft employees exposed internal passwords in #security lapse

source: https://techcrunch.com/2024/04/09/microsoft-employees-exposed-internal-passwords-security-lapse/

Security researchers Can Yoleri, Murat Özfidan and Egemen Koçhisarlı with #SOCRadar, a #cybersecurity company that helps organizations find security weaknesses, discovered an open and public storage server hosted on Microsoft’s #Azure #cloud service that was storing internal information relating to Microsoft’s #Bing search engine.


#fail #password #leak #problem #news