FreshRSS

🔒
☐ ☆ ✇ WIRED

The UK’s GPS Tagging of Migrants Has Been Ruled Illegal

By Morgan Meaker — March 1st 2024 at 00:01
The UK’s privacy regulator says the government did not take into account the intrusiveness of ankle tags that continuously monitor a person’s location.
☐ ☆ ✇ The Hacker News

Meta Warns of 8 Spyware Firms Targeting iOS, Android, and Windows Devices

By Newsroom — February 19th 2024 at 13:14
Meta Platforms said it took a series of steps to curtail malicious activity from eight different firms based in Italy, Spain, and the United Arab Emirates (U.A.E.) operating in the surveillance-for-hire industry. The findings are part of its Adversarial Threat Report for the fourth quarter of 2023. The spyware targeted iOS, Android, and Windows devices. "Their various malware included
☐ ☆ ✇ The Hacker News

Iranian Hackers Target Middle East Policy Experts with New BASICSTAR Backdoor

By Newsroom — February 19th 2024 at 04:39
The Iranian-origin threat actor known as Charming Kitten has been linked to a new set of attacks aimed at Middle East policy experts with a new backdoor called BASICSTAR by creating a fake webinar portal. Charming Kitten, also called APT35, CharmingCypress, Mint Sandstorm, TA453, and Yellow Garuda, has a history of orchestrating a wide range of social engineering campaigns that cast a
☐ ☆ ✇ The Hacker News

Global Coalition and Tech Giants Unite Against Commercial Spyware Abuse

By Newsroom — February 7th 2024 at 09:45
A coalition of dozens of countries, including France, the U.K., and the U.S., along with tech companies such as Google, MDSec, Meta, and Microsoft, have signed a joint agreement to curb the abuse of commercial spyware to commit human rights abuses. The initiative, dubbed the Pall Mall Process, aims to tackle the proliferation and irresponsible use of commercial cyber intrusion tools by
☐ ☆ ✇ The Hacker News

U.S. Imposes Visa Restrictions on those Involved in Illegal Spyware Surveillance

By Newsroom — February 6th 2024 at 05:00
The U.S. State Department said it's implementing a new policy that imposes visa restrictions on individuals who are linked to the illegal use of commercial spyware to surveil civil society members. "The misuse of commercial spyware threatens privacy and freedoms of expression, peaceful assembly, and association," Secretary of State Antony Blinken said. "Such targeting has been
☐ ☆ ✇ The Hacker News

Pegasus Spyware Targeted iPhones of Journalists and Activists in Jordan

By Newsroom — February 5th 2024 at 07:37
The iPhones belonging to nearly three dozen journalists, activists, human rights lawyers, and civil society members in Jordan have been targeted with NSO Group's Pegasus spyware, according to joint findings from Access Now and the Citizen Lab. Nine of the 35 individuals have been publicly confirmed as targeted, out of whom six had their devices compromised with the mercenary
☐ ☆ ✇ The Hacker News

NSA Admits Secretly Buying Your Internet Browsing Data without Warrants

By Newsroom — January 29th 2024 at 06:59
The U.S. National Security Agency (NSA) has admitted to buying internet browsing records from data brokers to identify the websites and apps Americans use that would otherwise require a court order, U.S. Senator Ron Wyden said last week. "The U.S. government should not be funding and legitimizing a shady industry whose flagrant violations of Americans' privacy are not just unethical, but illegal
☐ ☆ ✇ The Hacker News

Experts Detail Multi-Million Dollar Licensing Model of Predator Spyware

By Newsroom — December 21st 2023 at 16:48
A new analysis of the sophisticated commercial spyware called Predator has revealed that its ability to persist between reboots is offered as an "add-on feature" and that it depends on the licensing options opted by a customer. "In 2021, Predator spyware couldn't survive a reboot on the infected Android system (it had it on iOS)," Cisco Talos researchers Mike Gentile, Asheer Malhotra, and Vitor
☐ ☆ ✇ The Hacker News

Indian Hack-for-Hire Group Targeted U.S., China, and More for Over 10 Years

By Newsroom — November 20th 2023 at 06:42
An Indian hack-for-hire group targeted the U.S., China, Myanmar, Pakistan, Kuwait, and other countries as part of a wide-ranging espionage, surveillance, and disruptive operation for over a decade. The Appin Software Security (aka Appin Security Group), according to an in-depth analysis from SentinelOne, began as an educational startup offering offensive security training programs, while
☐ ☆ ✇ The Hacker News

Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware

By Newsroom — October 4th 2023 at 15:09
New findings have identified connections between an Android spyware called DragonEgg and another sophisticated modular iOS surveillanceware tool named LightSpy. DragonEgg, alongside WyrmSpy (aka AndroidControl), was first disclosed by Lookout in July 2023 as a strain of malware capable of gathering sensitive data from Android devices. It was attributed to the Chinese nation-state group APT41. On
☐ ☆ ✇ Naked Security

S3 Ep147: What if you type in your password during a meeting?

By Paul Ducklin — August 10th 2023 at 13:34
Latest episode - listen now! (Full transcript inside.)

☐ ☆ ✇ Naked Security

Serious Security: Why learning to touch-type could protect you from audio snooping

By Paul Ducklin — August 8th 2023 at 18:51
Fast, quiet, smooth, consistent and low impact... why true hacker-grade touch-typing might keep you more secure.

☐ ☆ ✇ The Hacker News

Apple Threatens to Pull iMessage and FaceTime from U.K. Amid Surveillance Demands

By THN — July 22nd 2023 at 05:36
Apple has warned that it would rather stop offering iMessage and FaceTime services in the U.K. than bowing down to government pressure in response to new proposals that seek to expand digital surveillance powers available to state intelligence agencies. The development, first reported by BBC News, makes the iPhone maker the latest to join the chorus of voices protesting against forthcoming
☐ ☆ ✇ WIRED

The US Is Openly Stockpiling Dirt on All Its Citizens

By Dell Cameron — June 12th 2023 at 19:23
A newly declassified report from the Office of the Director of National Intelligence reveals that the federal government is buying troves of data about Americans.
☐ ☆ ✇ The Hacker News

GoldenJackal: New Threat Group Targeting Middle Eastern and South Asian Governments

By Ravie Lakshmanan — May 23rd 2023 at 15:30
Government and diplomatic entities in the Middle East and South Asia are the target of a new advanced persistent threat actor named GoldenJackal. Russian cybersecurity firm Kaspersky, which has been keeping tabs on the group's activities since mid-2020, characterized the adversary as both capable and stealthy. The targeting scope of the campaign is focused on Afghanistan, Azerbaijan, Iran, Iraq,
☐ ☆ ✇ The Hacker News

Hackers Exploiting 5-year-old Unpatched Vulnerability in TBK DVR Devices

By Ravie Lakshmanan — May 3rd 2023 at 07:30
Threat actors are actively exploiting an unpatched five-year-old flaw impacting TBK digital video recording (DVR) devices, according to an advisory issued by Fortinet FortiGuard Labs. The vulnerability in question is CVE-2018-9995 (CVSS score: 9.8), a critical authentication bypass issue that could be exploited by remote actors to gain elevated permissions. "The 5-year-old vulnerability (CVE-
☐ ☆ ✇ The Hacker News

BouldSpy Android Spyware: Iranian Government's Alleged Tool for Spying on Minority Groups

By Ravie Lakshmanan — May 2nd 2023 at 11:56
A new Android surveillanceware possibly used by the Iranian government has been used to spy on over 300 individuals belonging to minority groups. The malware, dubbed BouldSpy, has been attributed with moderate confidence to the Law Enforcement Command of the Islamic Republic of Iran (FARAJA). Targeted victims include Iranian Kurds, Baluchis, Azeris, and Armenian Christian groups. "The spyware
☐ ☆ ✇ The Hacker News

President Biden Signs Executive Order Restricting Use of Commercial Spyware

By Ravie Lakshmanan — March 28th 2023 at 08:55
U.S. President Joe Biden on Monday signed an executive order that restricts the use of commercial spyware by federal government agencies. The order said the spyware ecosystem "poses significant counterintelligence or security risks to the United States Government or significant risks of improper use by a foreign government or foreign person." It also seeks to ensure that the government's use of
☐ ☆ ✇ WIRED

They Posted Porn on Twitter. German Authorities Called the Cops

By Matt Burgess — March 27th 2023 at 06:00
Regulators are using an AI system to scan websites and messaging apps to find pornography. Creators face fines and potential prison sentences.
☐ ☆ ✇ The Hacker News

Armenian Entities Hit by New Version of OxtaRAT Spying Tool

By Ravie Lakshmanan — February 17th 2023 at 12:47
Entities in Armenia have come under a cyber attack using an updated version of a backdoor called OxtaRAT that allows remote access and desktop surveillance. "The tool capabilities include searching for and exfiltrating files from the infected machine, recording the video from the web camera and desktop, remotely controlling the compromised machine with TightVNC, installing a web shell,
☐ ☆ ✇ The Hacker News

Google Accuses Spanish Spyware Vendor of Exploiting Chrome, Firefox, & Windows Zero-Days

By Ravie Lakshmanan — December 1st 2022 at 14:32
A Barcelona-based surveillanceware vendor named Variston IT is said to have surreptitiously planted spyware on targeted devices by exploiting several zero-day flaws in Google Chrome, Mozilla Firefox, and Windows, some of which date back to December 2018. "Their Heliconia framework exploits n-day vulnerabilities in Chrome, Firefox, and Microsoft Defender, and provides all the tools necessary to
☐ ☆ ✇ The Hacker News

U.S. Bans Chinese Telecom Equipment and Surveillance Cameras Over National Security Risk

By Ravie Lakshmanan — November 26th 2022 at 04:52
The U.S. Federal Communications Commission (FCC) formally announced it will no longer authorize electronic equipment from Huawei, ZTE, Hytera, Hikvision, and Dahua, deeming them an "unacceptable" national security threat. All these Chinese telecom and video surveillance companies were previously included in the Covered List as of March 12, 2021. "The FCC is committed to protecting our national
☐ ☆ ✇ WIRED

How to Protect Yourself If Your School Uses Surveillance Tech

By Pia Ceres — October 10th 2022 at 11:00
Colleges and K-12 campuses increasingly monitor student emails, social media, and more. Here’s how to secure your (or your child’s) privacy.
☐ ☆ ✇ The Hacker News

Researchers Uncover Years-Long Mobile Spyware Campaign Targeting Uyghurs

By Ravie Lakshmanan — September 22nd 2022 at 17:03
A new wave of a mobile surveillance campaign has been observed targeting the Uyghur community as part of a long-standing spyware operation active since at least 2015, cybersecurity researchers disclosed Thursday. The intrusions, originally attributed to a threat actor named Scarlet Mimic back in January 2016, is said to have encompassed 20 different variants of the Android malware, which were
☐ ☆ ✇ WIRED

The Low Threshold for Face Recognition in New Delhi

By Varsha Bansal — August 21st 2022 at 11:00
Police in India's capital say they only require an 80 percent accuracy rate for matches, raising new alarm bells for civil liberty advocates.
☐ ☆ ✇ The Hacker News

Former Twitter Employee Found Guilty of Spying for Saudi Arabia

By Ravie Lakshmanan — August 10th 2022 at 15:12
A former Twitter employee has been pronounced guilty for his role in digging up private information pertaining to certain Twitter users and turning over that data to Saudi Arabia. Ahmad Abouammo, 44, was convicted by a jury after a two-week trial in San Francisco federal court, Bloomberg reported Tuesday. He faces up to 20 years in prison when sentenced. The verdict comes nearly three years
☐ ☆ ✇ WIRED

The DHS Bought a ‘Shocking Amount’ of Phone-Tracking Data

By Ashley Belanger, Ars Technica — July 20th 2022 at 20:00
The ACLU released a trove of documents showing how Homeland Security contracted with surveillance companies to scour location information.
☐ ☆ ✇ Naked Security

7 cybersecurity tips for your summer vacation!

By Paul Ducklin — July 15th 2022 at 18:23
Here you go - seven thoughtful cybersecurity tips to help you travel safely...

☐ ☆ ✇ The Hacker News

State-Backed Hackers Targeting Journalists in Widespread Espionage Campaigns

By Ravie Lakshmanan — July 14th 2022 at 12:29
Nation-state hacking groups aligned with China, Iran, North Korea, and Turkey have been targeting journalists to conduct espionage and spread malware as part of a series of campaigns since early 2021. "Most commonly, phishing attacks targeting journalists are used for espionage or to gain key insights into the inner workings of another government, company, or other area of state-designated
☐ ☆ ✇ The Hacker News

TikTok Assures U.S. Lawmakers it's Working to Safeguard User Data From Chinese Staff

By Ravie Lakshmanan — July 2nd 2022 at 04:22
Following heightened worries that U.S. users' data had been accessed by TikTok engineers in China between September 2021 and January 2022, the company sought to assuage U.S. lawmakers that it's taking steps to "strengthen data security." The admission that some China-based employees can access information from U.S. users came in a letter sent to nine senators, which further noted that the
☐ ☆ ✇ The Hacker News

Google Says ISPs Helped Attackers Infect Targeted Smartphones with Hermit Spyware

By Ravie Lakshmanan — June 24th 2022 at 11:40
A week after it emerged that a sophisticated mobile spyware dubbed Hermit was used by the government of Kazakhstan within its borders, Google said it has notified Android users of infected devices. Additionally, necessary changes have been implemented in Google Play Protect — Android's built-in malware defense service — to protect all users, Benoit Sevens and Clement Lecigne of Google Threat
☐ ☆ ✇ The Hacker News

NSO Confirms Pegasus Spyware Used by at least 5 European Countries

By Ravie Lakshmanan — June 23rd 2022 at 11:08
The beleaguered Israeli surveillanceware vendor NSO Group this week admitted to the European Union lawmakers that its Pegasus tool was used by at least five countries in the region. "We're trying to do the right thing and that's more than other companies working in the industry," Chaim Gelfand, the company's general counsel and chief compliance officer, said, according to a report from Politico.
☐ ☆ ✇ WIRED

The Power and Pitfalls of AI for US Intelligence

By Alexa O'Brien — June 21st 2022 at 20:14
Artificial intelligence use is booming, but it's not the secret weapon you might imagine.
☐ ☆ ✇ The Hacker News

Researchers Uncover 'Hermit' Android Spyware Used in Kazakhstan, Syria, and Italy

By Ravie Lakshmanan — June 17th 2022 at 14:12
An enterprise-grade surveillanceware dubbed Hermit has been put to use by entities operating from within Kazakhstan, Syria, and Italy over the years since 2019, new research has revealed. Lookout attributed the spy software, which is equipped to target both Android and iOS, to an Italian company named RCS Lab S.p.A and Tykelab Srl, a telecom services provider which it suspects to be a front
☐ ☆ ✇ Naked Security

Murder suspect admits she tracked cheating partner with hidden AirTag

By Paul Ducklin — June 14th 2022 at 18:49
O! What a tangled web we weave, when first we practise to deceive.

☐ ☆ ✇ WIRED

How to Protect Your Digital Privacy if Roe v. Wade Falls

By Lily Hay Newman — May 5th 2022 at 22:02
Reproductive rights are still largely guaranteed in the United States. Here are some key privacy concepts to adopt in the event that they're not.
☐ ☆ ✇ Naked Security

Clearview AI face-matching service set to be fined over $20m

By Paul Ducklin — November 30th 2021 at 19:13
Scraping data for a facial recognition service? "That's unlawful", concluded both the British and the Australians.

❌