SwiftOnSecurity digs into the Apple CSAM scanning fiasco. Some of the points they touch on haven't been widely discussed before. #cososec
https://twitter.com/SwiftOnSecurity/status/1434179216044666880
TIL that the hak5 O.mg cable is based on tech the NSA has been using since at least 2009. I suppose I'm late to the party on this part of the Snowden leaks.
NSA ANT catalog - Wikipedia (see items 2-5 under Capabilities List)
https://en.wikipedia.org/wiki/NSA_ANT_catalog
Apple Delays Rollout of Controversial Child Safety Features to Make Improvements - MacRumors
https://www.macrumors.com/2021/09/03/apple-delaying-rollout-of-child-safety-features/
Google Chrome to remove detailed cookie and site data controls
https://lapcatsoftware.com/articles/chrome-cookie.html
TikToker Makes Script to Flood Texas Abortion 'Whistleblower' Site With Fake Info - VICE
https://www.vice.com/en/article/z3x9ba/tiktok-texas-abortion-law-bot-site-ios-shortcut
QNAP Working on Patches for OpenSSL Flaws Affecting its NAS Devices
https://thehackernews.com/2021/09/qnap-working-on-patches-for-openssl.html
If you care about personal privacy and oppressive regimes using extremely powerful spying tools against people they don't like, please listen to episodes 99 and 100 of Darknet Diaries.
Some of you might know about Black Cube, the NSO Group, and Pegasus. If not, you will be shocked by what you learn here.
It's a two-episode set and you really need to listen to both, as it comes full circle. Jack and his team really did an exceptional job on this one.
After Storms, Watch Out for Scams | Federal Communications Commission
"Natural disasters and severe weather can create opportunities for fraud in their wake, occurring at a time when people may be especially vulnerable, or targeting charitable intentions.
Scammers use phone, text, mail, email, and even go door to door to target residents of affected areas following hurricanes and damaging storms."
https://www.fcc.gov/consumers/guides/after-storms-watch-out-scams
Here is the latest reason to not blindly click links from your email. #cososec
Microsoft Warns of Widespread Phishing Attacks Using Open Redirects
Microsoft is warning of a widespread credential phishing campaign that leverages open redirector links in email communications as a vector to trick users into visiting malicious websites while effectively bypassing security software.
https://thehackernews.com/2021/08/microsoft-warns-of-widespread-phishing.html
Related to the Razr story posted the other day: Here is another peripheral from a different company that can get you privilege escalation in Windows.
It stands to reason there are devices from even more companies whose installers have similar loopholes.
0xsp | Local administrator is not just with Razer.. it is possible for ALL
http://0xsp.com/security%20research%20&%20development%20(SRD)/local-administrator-is-not-just-with-razer-it-is-possible-for-all
#cososec
nosanitize
GitHub - nuvious/pam-duress: A Pluggable Authentication Module (PAM) which allows the establishment of alternate passwords that can be used to perform actions to clear sensitive data, notify IT/Security staff, close off sensitive network connections, etc if a user is coerced into giving a threat actor a password.
https://github.com/nuvious/pam-duress
Installing Razr devices on Windows allows privilege escalation!
#cososec
//
Need local admin and have physical access?
- Plug a Razer mouse (or the dongle)
- Windows Update will download and execute RazerInstaller as SYSTEM
- Abuse elevated Explorer to open Powershell with Shift+Right click
Tried contacting @Razer, but no answers. So here's a freebie https://t.co/xDkl87RCmz
"With good intentions, Apple has paved the road to mandated security weakness around the world, enabling and reinforcing the arguments that, should the intentions be good enough, scanning through your personal life and private communications is acceptable."
If You Build It, They Will Come: Apple Has Opened the Backdoor to Increased Surveillance and Censorship Around the World | Electronic Frontier Foundation
https://www.eff.org/deeplinks/2021/08/if-you-build-it-they-will-come-apple-has-opened-backdoor-increased-surveillance
🚨 BREAKING #COSOSEC 🚨
Earlier today, I received the full source code for the suspect Dominion voting machines. I assured my source that this would only be shared with a select group of the most trustworthy cyber people.
Please use extreme discretion in your analysis.
🚨#cososec Home Router Alert 🚨
Millions Of Wi-Fi Routers Could Be Enslaved In Nasty Mirai Botnet, Check Your Model Here | HotHardware
https://hothardware.com/news/new-router-vulnerability-exploited-for-botnet
The creator of Foto Forensics goes into detail with the claims Apple is making about its new on-device CSAM scanning, including some potential legal problems with their approach.
#cososec
One Bad Apple - The Hacker Factor Blog
https://www.hackerfactor.com/blog/index.php?/archives/929-One-Bad-Apple.html
nosanitize
Apple Privacy Letter: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
https://appleprivacyletter.com/
This is a great thread from the person who broke the news yesterday about Apple doing client-side scanning on user devices.
Anyone who considers Apple to be a model of protecting their customer's data should consider the points he raises.
https://twitter.com/matthew_d_green/status/1423071186616000513
Musician | Teacher | Nerd
𝘐 𝘢𝘮 𝘩𝘪𝘵𝘵𝘪𝘯𝘨 𝘮𝘺 𝘩𝘦𝘢𝘥 𝘢𝘨𝘢𝘪𝘯𝘴𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴, 𝘣𝘶𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴 𝘢𝘳𝘦 𝘨𝘪𝘷𝘪𝘯𝘨 𝘸𝘢𝘺.
- 𝘎𝘶𝘴𝘵𝘢𝘷 𝘔𝘢𝘩𝘭𝘦𝘳