Show more

Cloudflare DDoS protections ironically bypassed using Cloudflare

To make matters worse, the only requirement for the attack is for the hackers to create a free Cloudflare account, which is used as part of the attack.

Certitude's researcher Stefan Proksch discovered that the source of the issue is Cloudflare's strategy to use shared infrastructure that accepts connections from all tenants.

certitude.consulting/blog/en/u

A China-linked hacking group, dubbed BlackTech, is compromising routers in the US and Japan, secretly modifying their firmware and moving around company networks, according to a warning issued by cybersecurity officials this week.

therecord.media/us-japan-say-c

Advisory helps organizations protect against PRC-linked actors hiding in router firmware

cisa.gov/news-events/news/cisa

A team of university researchers has devised a new optical-acoustic side channel attack dubbed ‘Side Eye,’ which can extract ambient sound from the environment at the time an image was taken.

restoreprivacy.com/side-eye-at

Is Side Eye a real threat?

Many attack concepts of this kind are limited to the theoretical realm. However, documenting them is crucial given the accelerated technological progress across various domains constantly opening up new practical capabilities

users beware

an HDMI adaptor that brazenly demands your location, browsing, photos, and spams you with ads. Used with a test phone but wild amount of data collection. Privacy policy straight up says it sends the data to "China"

404media.co/i-tested-an-hdmi-a

A deep dive into the Encrypted Client Hello, a standard that encrypts privacy-sensitive parameters sent by the client, as part of the TLS handshake.

blog.cloudflare.com/encrypted-

Sneak preview of the official Veilid chat app. Creating an account is just that easy. No phone numbers, no contact list imports- just the the things you want to share with the folks you want to chat with.

twitter.com/VeilidNetwork/stat?

those food delivery robots that are armed with cameras and driving all over sidewalks in LA? They're providing filmed footage to the LAPD, according to internal emails we got. Food delivery robots just became surveillance devices

404media.co/serve-food-deliver

Almost half of organizations have failed to report cyber-attacks to the appropriate authorities in 2023

🤫 🤫 🤫 seekrits 🤫 🤫 🤫

infosecurity-magazine.com/news

U.S. Counterintel Buys Access to the Backbone of the Internet to Hunt Foreign Hackers

Getting information from the NSA would take too long, according to internal documents from a counterintelligence agency. So it turned to Team Cymru to buy netflow data that can allow analysts to track activity through virtual private networks

404media.co/us-counterintel-bu

Today someone operating under the name "MajorNelson", a nod to the former Director of Programming for the Microsoft gaming network Xbox Live, asserts RansomVC is lying.

He then released all the content RansomVC claimed to have into the general public.

tl;dr another Sony leak?

-- VX-Underground

Chat v5.3 released: desktop app, local file encryption and improved groups with directory service

There are a lot of other improvements and fixes in this release:

simplex.chat/blog/20230925-sim

New: a TikTok account is using facial recognition to dox random people simply for clout with its millions of viewers.

- spoke to multiple victims, "violated"
- TikTok refuses to remove because says doesn't violate policies

404media.co/the-end-of-privacy

Who is peeking over your shoulder while you work, watch videos, learn, explore, and shop on the internet?

Enter the address of any website, and Blacklight will scan it and reveal the specific user-tracking technologies on the site—and who’s getting your data. You may be surprised at what you learn.

A Real-Time Website Privacy Inspector: Blacklight

themarkup.org/blacklight

Test your browser to see how well you are protected from tracking and fingerprinting:

coveryourtracks.eff.org/

Have you ever wondered how much of your personal information is available online?

Here’s your chance to find out.

we’ve used Hunt’s, have-i-been-pwned, database to help you:

Find out what data breaches you’ve been caught up in
See a visual summary of the potential scale of the leaked information out there about you
Understand how something known as “the mosaic effect” can increase the risks we all face online

abc.net.au/news/2023-05-18/dat

The EFF (Electronic Frontier Foundation) has announced the availability of a new version of ‘Privacy Badger’ that features better link-tracking blocks for Google services

the latest version released this week, EFF has overhauled link tracking protection for Google services such as Google Docs, Gmail, Maps, Images, and Search results, which are widely used and omnipresent on the internet.

eff.org/deeplinks/2023/09/new-

Proton Pass password manager follows the bad practice of keeping unencrypted usernames and passwords in the computer’s memory.

To make matters worse, this sensitive data is not wiped from the memory when the vault is locked post-login, making it susceptible to exfiltration by info-stealer malware or attackers with physical access to the target machine

Seems they promised this would be fixed BUT several updates later still no fix

restoreprivacy.com/proton-pass

The International Criminal Court (ICC) in The Hague has suffered a cyber attack. One source says a large trove of sensitive information has been stolen in the attack.

nos.nl/artikel/2491054-compute

oh Vilvaldi browser uses the "I don’t care about cookies" in it's settings to skip the cookie process

thing is that extension was purchased by Avast

i really wouldn't trust using that setting btw

theregister.com/2022/09/21/ava

instal "I still don't care about cookies" extension instead

Fork of the popular "I don't care about cookies" extension

github.com/OhMyGuus/I-Still-Do

Show more

⇄ Σ = Mᄃ² ⇆

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.