Zum Inhalt der Seite gehen

Suche

Beiträge, die mit tech getaggt sind


Teenagers Tell Us About Their Relationship With News

how and why media — online, in print, and on TV — treats news as a product, and how that shapes the way they think and feel. Some said that made them not want to be informed, but many others shared their strategies for navigating the noise

#teenagers #news #journalism #socialmedia #media #MediaLiteracy #LateralReading #technology #tech

https://www.nytimes.com/2024/10/23/learning/teenagers-tell-us-about-their-relationship-with-news.html


LiteSpeed Cache Plugin Vulnerability poses significant Risk to WordPress Websites.

The free version of the popular WordPress plugin LiteSpeed Cache has fixed a dangerous privilege elevation flaw on its latest release that could allow unauthenticated actors to gain admin rights.

[CVE-2024-50550 CVSS score: 8.1]

https://patchstack.com/articles/rare-case-of-privilege-escalation-patched-in-litespeed-cache-plugin/

#wordpress #litespeed #flaw #it #security #privacy #engineer #media #tech #news
LiteSpeed Cache is a popular site acceleration plugin for WordPress that, as the name implies, comes with advanced caching functionality and optimization features. It's installed on over six million sites.

The newly identified issue, per Patchstack, is rooted in a function named is_role_simulation and is similar to an earlier flaw that was publicly documented back in August 2024 (CVE-2024-28000, CVSS score: 9.8).

It stems from the use of a weak security hash check that could be brute-forced by a bad actor, thus allowing for the crawler feature to be abused to simulate a logged-in user, including an administrator.

The vulnerability, tracked as CVE-2024-50550 (CVSS score: 8.1), has been addressed in version 6.5.2 of the plugin.

<https://wordpress.org/plugins/litespeed-cache/>


[BEWARE!!!] Android Malware "FakeCall" now reroutes Bank Calls to Attackers. :androidalt:

Researchers have found new versions of a sophisticated Android financial-fraud Trojan that’s notable for its ability to intercept calls a victim tries to place to customer-support personnel of their banks.

https://www.zimperium.com/blog/mishing-in-motion-uncovering-the-evolving-functionality-of-fakecall-malware/

#android #fakecall #vishing #malware #it #security #privacy #engineer #media #tech #news
FakeCall (or FakeCalls) is a banking trojan with a focus on voice phishing, in which victims are deceived through fraudulent calls impersonating banks, asking them to convey sensitive information.

In addition to vishing (voice phishing), FakeCall could also capture live audio and video streams from the infected devices, allowing attackers to steal sensitive data without victim interaction.

The malware also exploits the Android Accessibility Service to capture screen content and manipulate the device’s display to create a deceptive user interface while mimicking the legitimate phone app.
[ImageSource: Zimperium]

Overview of latest FakeCall attacks.

The FakeCall malware typically infiltrates a device through a malicious app downloaded from a compromised website or a phishing email. The app requests permission to become the default call handler. If granted, the malware gains extensive privileges.

A fake call interface mimics the actual Android dialer, displaying trusted contact information and names, elevating the level of deception to a point that's hard for victims to realize.

What makes this malware so dangerous is that when a user attempts to call their financial institution, the malware secretly hijacks the call and redirects it to an attacker's phone number instead.


Today is the first day of the penultimate month of the year. It's a good day to read the newest Dev Weekly and share it with your friends!

https://blog.codeminer42.com/codeminer42-dev-weekly-35/

#blog #codeminer42 #tech #news #weekly


Apple creates Private Cloud Compute VM to let Researchers find Bugs. :apple_inc:

The company also seeks to improve the system's security and has expanded its security bounty program to include rewards of up to [$1 Million] for vulnerabilities that could compromise “the fundamental security and privacy guarantees of PCC”.

https://security.apple.com/blog/pcc-security-research

#apple #pcc #vm #securityresearch #bug #bounty #programming #ai #it #security #privacy #engineer #media #tech #news
Apple created a Virtual Research Environment to allow public access to testing the security of its Private Cloud Compute system, and released the source code for some “key components” to help researchers analyze the privacy and safety features on the architecture.

The company also makes available the Private Cloud Compute Security Guide, which explains the architecture and technical details of the components and the way they work.

<https://security.apple.com/documentation/private-cloud-compute>
[ImageSource: Apple]

Interacting with the Private Cloud Compute client from the Virtual Research Environment.

Apple provides a Virtual Research Environment (VRE), which replicates locally the cloud intelligence system and allows inspecting it as well as testing its security and hunting for issues.

“The VRE runs the PCC node software in a virtual machine with only minor modifications. Userspace software runs identically to the PCC node, with the boot process and kernel adapted for virtualization,” Apple explains, sharing documentation on how to set up the Virtual Research Environment on your device.

VRE is present on macOS Sequia 15.1 Developer Preview and it needs a device with Apple silicaon and at least 16GB of unified memory.

<https://security.apple.com/documentation/private-cloud-compute/vresetup>


‘Irish Data Protection Commission fines LinkedIn Ireland €310 million… following an inquiry into LinkedIn...
The inquiry examined LinkedIn’s processing of personal data for the purposes of behavioural analysis and targeted advertising of users who have created LinkedIn profiles (members)’
https://www.dataprotection.ie/en/news-media/press-releases/irish-data-protection-commission-fines-linkedin-ireland-eu310-million
#eu #law #gdpr #privacy #tech #advertising


TL;DR: The EFF Awards celebrated individuals and organizations fighting for digital rights, free speech, and privacy in a challenging global landscape. Honorees included 404 Media for fearless journalism, Connecting Humanity for aiding Gazans with connectivity, and Carolina Botero for her leadership in Latin America's digital rights movement. https://www.eff.org/deeplinks/2024/09/eff-awards-night-celebrating-digital-rights-founders-advancing-free-speech-and #law #tech #legaltech ⚖️ 🤖 #autosum


‘Ticketmaster’s ability to raise the price of concert tickets based on demand is being investigated by the European Commission, the Guardian has learned, as the UK’s competition watchdog launches an “urgent review” into the Oasis concerts fiasco.’

https://www.theguardian.com/money/article/2024/sep/03/european-commission-to-investigate-ticketmasters-dynamic-pricing
#law #tech #discrimination #economics


As a software engineer, I have wanted to see something like this happen FOR YEARS. It's long past time that makers of shitty software start being held accountable by their users.

https://www.cnbc.com/2024/07/29/delta-hires-david-boies-to-seek-damages-from-crowdstrike-microsoft-.html

#CrowdStrike #Tech #Microsoft #BSOD


Here's a brilliant article about the opaque and broken world of programmatic advertising.

These platforms truly are a cesspit.

They are causing billions of ad dollars from reputable brands to be pumped into disinformation sites.

Meanwhile, ads are systematically blocked from appearing on reputable news sites that have articles that include words like "Palestine", "black", or "gay".

And the biggest player in this industry? Google!

Just another way Google is enshittifying the internet for profit.

https://www.wired.com/story/death-of-truth-misinformation-advertising/

#tech #technology #marketing #adtech #Google #enshittification


Twitter passa oficialmente a usar endereço "x.com"
🔗 https://tugatech.com.pt/t60341-twitter-passa-oficialmente-a-usar-endereco-x-com
...
#elonmusk #internet #SEO #twitter #noticias #tech #tugatech


It’s April 2024 and journalists are still publishing stories about conversations they had with chatbots 🫠

https://www.wsj.com/lifestyle/chatgpt-ai-boyfriend-spicy-8ac6a6e9

#tech #ai #chatbot #chatgpt


In 2021, Elon Musk said the government should end all EV subsidies. Yet new data shows Tesla received more money from Biden’s grants to expand EV charging networks than anyone else — $17 million, or 13% of all EV charging awards.

https://www.politico.com/news/2024/02/27/tesla-biden-electric-car-charging-00143431

#tech #tesla #elonmusk #evs


"For decades, #tech #journalism and criticism has primarily consisted of glowing gadget reviews, laudatory profiles, and reprinted press releases, all of it colored by Silicon Valley’s self-aggrandizing vision of itself as a laboratory of a brighter future."

https://thebaffler.com/latest/the-miseducation-of-kara-swisher-ongweso


Security News This Week: Russian Hackers Stole Microsoft Source Code—and the Attack Isn’t Over

https://www.wired.com/story/russia-hackers-microsoft-source-code/

#technology #tech #hacked #hackers #microsoft #security #cybersecurity #datasecurity


The Sleepy Copyright Office in the Middle of a High-Stakes Clash Over AI

The attention stems from a first-of-its-kind review of copyright law in the age of artificial intelligence. The #technology — which feeds off creative content — has upended traditional norms around #copyright, which gives owners of books, movies and music the exclusive ability to distribute and copy their works.

#LibraryOfCongress #artificialintelligence #AI #intellectualproperty #IP #legal #tech

https://www.nytimes.com/2024/01/25/technology/ai-copyright-office-law.html


‘The Dutch Data Protection Authority (AP) is imposing a fine of €10 million on Uber. The fine is in response to the company's failure to disclose the full details of its retention periods for data concerning European drivers, or to name the non-European countries in which it shares this data. The DPA also found that Uber had obstructed its drivers’ efforts to exercise their right to privacy.’ https://autoriteitpersoonsgegevens.nl/en/current/uber-fined-eu10-million-for-infringement-of-privacy-regulations #uber #law #tech #gdpr #privacy #surveillance #dataprotection


@pluralistic brilliantly clarifying our modern world for us, as usual:

*We’re nowhere near the point where an AI can do your job, but we’re well past the point where your boss can be suckered into firing you and replacing you with a bot that fails at doing your job.*

https://doctorow.medium.com/i-assure-you-an-ai-didnt-write-a-terrible-george-carlin-routine-83d447bfbd72

#ux #design #media #uxdesign #hcd #HumanCenteredDesign #tech #technology #ai #aihype


I sat off-screen and listened to a peer's #layoffs at a major #tech company last week. I didn't even work there, and even with that distance, I am astounded and disgusted at the state of this industry, and the spinelessness of the proceedings.

If you haven't experienced one yet, let me tell you the playbook.


Me at home yesterday, holding my much buzzed about new O'Reilly book, Hacker Culture: A to Z. #tech
Me sitting on my couch at home, holding my book.
#tech


“What’s at stake here is literal human life. But Palestinian life matters so little, that spreading incendiary information that justifies Israeli war crimes isn’t a concern for those tasked to punch up to power by virtue of being journalists.”

https://theintercept.com/2023/10/11/israel-hamas-disinformation/

#tech #misinformation #gaza #israel


Genetic testing firm 23andMe has suffered a data breach.

1 million data points exclusively about Ashkenazi Jews have been advertised for sale on a cybercrime forum. There's also information about hundreds of thousands of users of Chinese descent.

It appears to be a credential stuffing attack—where previously leaked logins and passwords from other sites are tried on 23andMe—with the attackers then scraping data from profiles

@lhn's story has all the details we know so far:
https://www.wired.com/story/23andme-credential-stuffing-data-stolen/ #cybersecurity #news #tech #23andme #infosec


📚 #LibGen: publishers sue infamous 'shadow library' over pirated #books

"What's noticeable is the popularity of the site, as many social media users openly talk about their usage of the illegal sharing network."

#tech #copyright #bookstodon

https://howtobe247.com/libgen-publishers-sue-infamous-shadow-library-over-pirated-books/