Zum Inhalt der Seite gehen

Suche

Beiträge, die mit Privacy getaggt sind


Salt Typhoon Hack Shows There's No Security Backdoor That's Only For The "Good Guys" - https://www.eff.org/deeplinks/2024/10/salt-typhoon-hack-shows-theres-no-security-backdoor-thats-only-good-guys #privacidad #privacy


उत्तराखण्ड निवास का निर्माण लगभग 120 करोड़ 52 लाख रुपए की लागत से किया गया - मुख्यमंत्री धामी।

https://aliyesha.com/sub/articles/news/display/uk_uttarakhand_niwas_in_delhi_inaugrated

#uttarakhand #dehradun #newdelhi #india #press #news #governance #government #bjp #cmdhami #uttarakhandniwas #culture

Enjoy tracker free reading with us. #privacy #privacymatters


Launch of 'SP Ko Bolo' App in Kangra District.

https://aliyesha.com/sub/articles/news/display/hp_launch_sp_ko_bolo_app_kangra

#himachal #dharamshala #india #press #news #government #governance #app #SPKoBolo #police

Enjoy tracker free reading with us. #privacy #privacymatters


दिल्ली के सरकारी स्कूलों के 30 बच्चे पढ़ाई करने फ्रांस गए, फ्रांसीसी दूतावास से हुआ था करार।

https://aliyesha.com/sub/articles/news/display/nd_delhi_government_school_going_to_france

#newdelhi #delhi #india #press #news #politics #aap #GovernmentSchool #school #education #france #french #language #skills #governance

Enjoy tracker free reading with us. #privacy #privacymatters


उत्तराखंड बस हादसा : 36 लोगों की गई जाने।

https://aliyesha.com/sub/articles/news/display/uk_bus_accident_takes_36_innocent_lives

#uttarakhand #dehradun #india #press #news #governance #government #bus #accident #tragedy

Enjoy tracker free reading with us. #privacy #privacymatters


💡 Proton VPN: arriva il supporto nativo per dispositivi Windows ARM

https://gomoot.com/proton-vpn-arriva-il-supporto-nativo-per-dispositivi-windows-arm

#arm #blog #laptop #microsoft #news #picks #privacy #protonmail #protonvpn #surface #tech #tecnologia #windows @ProtonPrivacy


LiteSpeed Cache Plugin Vulnerability poses significant Risk to WordPress Websites.

The free version of the popular WordPress plugin LiteSpeed Cache has fixed a dangerous privilege elevation flaw on its latest release that could allow unauthenticated actors to gain admin rights.

[CVE-2024-50550 CVSS score: 8.1]

https://patchstack.com/articles/rare-case-of-privilege-escalation-patched-in-litespeed-cache-plugin/

#wordpress #litespeed #flaw #it #security #privacy #engineer #media #tech #news
LiteSpeed Cache is a popular site acceleration plugin for WordPress that, as the name implies, comes with advanced caching functionality and optimization features. It's installed on over six million sites.

The newly identified issue, per Patchstack, is rooted in a function named is_role_simulation and is similar to an earlier flaw that was publicly documented back in August 2024 (CVE-2024-28000, CVSS score: 9.8).

It stems from the use of a weak security hash check that could be brute-forced by a bad actor, thus allowing for the crawler feature to be abused to simulate a logged-in user, including an administrator.

The vulnerability, tracked as CVE-2024-50550 (CVSS score: 8.1), has been addressed in version 6.5.2 of the plugin.

<https://wordpress.org/plugins/litespeed-cache/>


[BEWARE!!!] Android Malware "FakeCall" now reroutes Bank Calls to Attackers. :androidalt:

Researchers have found new versions of a sophisticated Android financial-fraud Trojan that’s notable for its ability to intercept calls a victim tries to place to customer-support personnel of their banks.

https://www.zimperium.com/blog/mishing-in-motion-uncovering-the-evolving-functionality-of-fakecall-malware/

#android #fakecall #vishing #malware #it #security #privacy #engineer #media #tech #news
FakeCall (or FakeCalls) is a banking trojan with a focus on voice phishing, in which victims are deceived through fraudulent calls impersonating banks, asking them to convey sensitive information.

In addition to vishing (voice phishing), FakeCall could also capture live audio and video streams from the infected devices, allowing attackers to steal sensitive data without victim interaction.

The malware also exploits the Android Accessibility Service to capture screen content and manipulate the device’s display to create a deceptive user interface while mimicking the legitimate phone app.
[ImageSource: Zimperium]

Overview of latest FakeCall attacks.

The FakeCall malware typically infiltrates a device through a malicious app downloaded from a compromised website or a phishing email. The app requests permission to become the default call handler. If granted, the malware gains extensive privileges.

A fake call interface mimics the actual Android dialer, displaying trusted contact information and names, elevating the level of deception to a point that's hard for victims to realize.

What makes this malware so dangerous is that when a user attempts to call their financial institution, the malware secretly hijacks the call and redirects it to an attacker's phone number instead.


It's infuriating how activists are so lax with #privacy and their use of #CorporateSocialMedia

It's like: Thanks for your support! Follow us of asshole Facebook and fascist Twitter!

No thanks.

Then you go on their websites and get blocked because you're using an adblocker!

I mean, I won't look at it if my adblocker is a problem to you.


Always ready to provide every possible assistance to farmers: Nitish Kumar.

https://aliyesha.com/sub/articles/news/display/bh_always_ready_to_help_farmers_nitish

#bihar #patna #india #news #press #politics #jdu #nitishkumar #farming #farmers #kharif #rice #CropProcurement #msp #governance #mandi

Enjoy tracker free reading with us. #privacy #privacymatters


Apple creates Private Cloud Compute VM to let Researchers find Bugs. :apple_inc:

The company also seeks to improve the system's security and has expanded its security bounty program to include rewards of up to [$1 Million] for vulnerabilities that could compromise “the fundamental security and privacy guarantees of PCC”.

https://security.apple.com/blog/pcc-security-research

#apple #pcc #vm #securityresearch #bug #bounty #programming #ai #it #security #privacy #engineer #media #tech #news
Apple created a Virtual Research Environment to allow public access to testing the security of its Private Cloud Compute system, and released the source code for some “key components” to help researchers analyze the privacy and safety features on the architecture.

The company also makes available the Private Cloud Compute Security Guide, which explains the architecture and technical details of the components and the way they work.

<https://security.apple.com/documentation/private-cloud-compute>
[ImageSource: Apple]

Interacting with the Private Cloud Compute client from the Virtual Research Environment.

Apple provides a Virtual Research Environment (VRE), which replicates locally the cloud intelligence system and allows inspecting it as well as testing its security and hunting for issues.

“The VRE runs the PCC node software in a virtual machine with only minor modifications. Userspace software runs identically to the PCC node, with the boot process and kernel adapted for virtualization,” Apple explains, sharing documentation on how to set up the Virtual Research Environment on your device.

VRE is present on macOS Sequia 15.1 Developer Preview and it needs a device with Apple silicaon and at least 16GB of unified memory.

<https://security.apple.com/documentation/private-cloud-compute/vresetup>


Resistance in the data-driven society https://policyreview.info/articles/analysis/resistance-data-driven-society #paper #privacy #privacidad


EFF Launches Digital Rights Bytes to Answer Tech Questions that Bug Us All https://www.eff.org/press/releases/eff-launches-digital-rights-bytes-answer-tech-questions-bug-us-all #privacy #consumer #consumo


‘Irish Data Protection Commission fines LinkedIn Ireland €310 million… following an inquiry into LinkedIn...
The inquiry examined LinkedIn’s processing of personal data for the purposes of behavioural analysis and targeted advertising of users who have created LinkedIn profiles (members)’
https://www.dataprotection.ie/en/news-media/press-releases/irish-data-protection-commission-fines-linkedin-ireland-eu310-million
#eu #law #gdpr #privacy #tech #advertising


Today is the 10 year anniversary of #CITIZENFOUR, the out-in-theaters release in the United States was 2014 October 24

if you've never seen it, i highly recommend it! much of the government surveillance that it highlights are either still in practice or are being done by other governments all around the world

here are some old photos i made back on the opening night at SIFF Cinema in Seattle

#LauraPoitras #Snowden #EdwardSnowden #privacy #surveillance #NSA #GCHQ #humanrights
walking into a movie theater with CITIZENFOUR written above the doorway, the left door is open and the right door is closed
a movie poster of CITIZENFOUR showing Edward Snowden in a green hue


Preemption Playbook: Big Tech’s Blueprint Comes Straight from Big Tobacco https://www.eff.org/deeplinks/2024/10/preemption-playbook-big-techs-blueprint-comes-straight-big-tobacco #privacy #privacidad


Un robot aspirador de la marca #Ecovacs no sólo era fácil de piratear, sino que también transmitía a la empresa muchos datos íntimos sobre los usuarios. La configuración de privacidad para evitar esto está bien oculta https://netzpolitik.org/2024/verbraucherschutz-saugroboter-von-ecovacs-als-spion-in-der-wohnung/ #privacy #privacidad #consumo


I’ve been saying this for more than a decade at this point. It’s about time government realised that protecting the #privacy of its citizens is vital for protecting national security. #auspol
https://www.abc.net.au/news/2024-10-03/ad-tech-data-breach-real-time-bidding-national-security-privacy/104416546