Someone in my neighborhood decided to use their full street address as their SSID.
So much for NSO's repeated claim that they don't know who is being targeted by their spyware. #cososec
Israel's Mossad used Pegasus spyware to hack cellphones unofficially - Israel News - Haaretz.com
https://archive.ph/2022.02.13-130736/https://www.haaretz.com/israel-news/.premium.HIGHLIGHT-israel-s-mossad-used-pegasus-spyware-to-hack-cellphones-unofficially-1.10608145
I Used AirTags, Tiles and a GPS Tracker to Watch My Husband’s Every Move
A vast location-tracking network is being built around us so we don’t lose our keys: One couple’s adventures in the consumer tech surveillance state.
With the growing threat of large-scale cyber attacks, you should consider what would happen if your cloud storage providers are offline for an extended period of time.
Make sure you have local copies of anything you care about. Ideally, have multiple copies of important data in different locations.
My preferred media are BD-R discs, as they are non-magnetic, non-mechanical. They will last for decades if stored properly, and if you use HTL media.
https://blu-raydisc.info/licensee-list/discmanuid-licenseelist.php
Dark patterns strike again.
Google Maps now requires WiFi scanning to use navigation | Hacker News
https://news.ycombinator.com/item?id=30167865
nosanitize
🚨 Linux #cososec 🚨
Linux system service bug gives root on all major distros, exploit released
"An exploit has already emerged in the public space, less than three hours after Qualys published the technical details for PwnKit. BleepingComputer has compiled and tested the available exploit, which proved to be reliable as it gave us root privileges on the system on all attempts."
FBI warns of malicious QR codes used to steal your money
https://www.bleepingcomputer.com/news/security/fbi-warns-of-malicious-qr-codes-used-to-steal-your-money/
Russian Cybersecurity Firm Draws U.S. Federal Scrutiny, Concern from National Security Experts - Forensic News
https://forensicnews.net/russian-cybersecurity-firm-infotecs-draws-u-s-federal-scrutiny-concern-from-national-security-experts/
The new brand name encompassing FireEye and McAfee is going to get confused with a famous EDM artist. That's all I can think of when I see that name.
//
McAfee Enterprise-FireEye relaunches as Trellix, aims to be 'market leader' in XDR | VentureBeat
https://venturebeat.com/2022/01/18/mcafee-enterprise-fireeye-relaunches-as-trellix-aims-to-be-market-leader-in-xdr/
Israel's justice minister on Wednesday pledged a full investigation into allegations that the controversial Pegasus spyware was used on Israeli citizens, including people who led protests against former premier Benjamin Netanyahu.
Israel probes alleged Pegasus use to spy on citizens | Daily Mail Online
https://www.dailymail.co.uk/wires/afp/article-10417957/Israel-probes-alleged-Pegasus-use-spy-citizens.html
Remember when Zoom bought Keybase?
Same energy. #cososec
WhatsApp Co-Founder Is the New Acting CEO of Signal
https://www.vice.com/en/article/4awamd/whatsapp-co-founder-brian-acton-signal-ceo
"For a nascent product category with such PR liability potential, it’s hard to see how Apple justifies continuing to sell AirTags. It’s a unique error from Apple in that the company delivered exactly what they initially promised but failed to consider the full scope of that initial promise’s direct consequences."
Apple’s biggest scandal of 2022 is already happening | TechCrunch
https://techcrunch.com/2022/01/08/apples-biggest-scandal-of-2022-is-already-happening/
Do any Cosonauts use the Session messenger? I like what I'm reading in their FAQ. It appears to be what I was hoping Signal would be: A secure messenger with no phone number or anything else tied to your IRL identity.
Just installed the app, and it looks well-designed. My ID is in my CoSo profile if anyone wants to try it.
See how your web browsers perform in a wide array of privacy tests. Click each category, test name, and result for more info. #cososec
PrivacyTests.org: open-source tests of web browser privacy
https://privacytests.org/
Announcing performance analyzer for Microsoft Defender Antivirus
We are excited to announce performance analyzer for Microsoft Defender Antivirus (available with the Defender platform update 418.2108.7+). This new PowerShell command-line tool assists in the collection of performance recordings on an individual endpoint and reports information for top scans, processes, files, and file extensions most affected by Microsoft Defender Antivirus.
This RedLine malware may not just affect one of your accounts, so be sure to check if you are in the database.
This post also includes commentary from the researcher who discovered LastPass credentials in the RedLine logs.
Have I Been Pwned adds 441K accounts stolen by RedLine malware
https://www.bleepingcomputer.com/news/security/have-i-been-pwned-adds-441k-accounts-stolen-by-redline-malware/
This article goes through all of the possible explanations for the LastPass matter password incident. I encourage you to read the entire thing, not just the TL;DR near the beginning.
How did LastPass master passwords get compromised? | Almost Secure
https://palant.info/2021/12/29/how-did-lastpass-master-passwords-get-compromised/
Big Data May Not Know Your Name. But It Knows Everything Else | WIRED
https://www.wired.com/story/big-data-may-not-know-your-name-but-it-knows-everything-else/
Have you considered switching to a safer web browser?
I have been very pleased with LibreWolf, a security and privacy-hardened Firefox fork. It is now my main desktop browser. No mobile version, but runs on Win, macOS, Linux, and BSD.
https://librewolf.net/
On mobile, I use Bromite (Android only), a privacy-focused Chromium fork.
https://www.bromite.org/
I wonder how many #cososec pros here have received requests like this?
Teach Me How To Hack
https://teachmehowtohack.tumblr.com/
Musician | Teacher | Nerd
𝘐 𝘢𝘮 𝘩𝘪𝘵𝘵𝘪𝘯𝘨 𝘮𝘺 𝘩𝘦𝘢𝘥 𝘢𝘨𝘢𝘪𝘯𝘴𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴, 𝘣𝘶𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴 𝘢𝘳𝘦 𝘨𝘪𝘷𝘪𝘯𝘨 𝘸𝘢𝘺.
- 𝘎𝘶𝘴𝘵𝘢𝘷 𝘔𝘢𝘩𝘭𝘦𝘳