Masthash

#Spyware

informapirata :privacypride:
8 hours ago

In che modo i giornalisti investigativi possono reagire contro nuove minacce di sorveglianza potenziate?

@giornalismo

Negli ultimi anni, numerosi scandali hanno rivelato che i giornalisti di tutto il mondo sono stati oggetto di sorveglianza, spesso tramite #spyware. Ma i giornalisti devono essere vigili su altre forme di sorveglianza sempre più diffuse come i sistmi di tracciamento COVID19.

https://gijn.org/2023/06/07/investigative-journalists-fight-new-enhanced-surveillance-threats/

Gli scanner biometrici messi in atto per monitorare la salute pubblica durante la pandemia di COVID-19 sono stati riproposti da alcuni governi per fornire sorveglianza della stampa. Immagine: Shutterstock
jbz :catjam:
1 day ago

⎧ Enigma software group has won a crucial case in the U.S. Court of Appeals for the Ninth Circuit, allowing it to proceed with its lawsuit against Malwarebytes for flagging its anti-spyware software as a 'potentially unwanted program.' The lawsuit alleges that Malwarebytes has engaged in anti-competitive conduct under the Lanham Act and tortious interference with Enigma's business ⎭ ➥ @techspot

#Malwarebytes #Spyware #CyberSecurity
https://www.techspot.com/news/98976-malwarebytes-faces-lawsuit-classifying-rival-anti-spyware-program.html

EP Technology
2 days ago

Ahead of next week’s #EPlenary vote on the use of #spyware in the EU, keep up to date with current developments with this briefing by the European Parliament Reserch Servive: https://shorturl.at/hqtC8 @EP_ThinkTank

🐦🔗: https://n.respublicae.eu/EP_Technology/status/1666797839048151041

EP PressService
2 days ago

📨 The Newsletter for next week's June #EPlenary session in Strasbourg is online, featuring:

- #NovaKakhovka dam attack🇺🇦
- #AI Act🤖
- Pegasus #spyware🕵️
- June #euco 🇪🇺
- Battery technology 🔋
- 2024 EU elections 🗳️
- #Poland 🇵🇱

And more, details here: http://eptwitter.eu/qCB3

🐦🔗: https://n.respublicae.eu/EuroParlPress/status/1666800386194419712

Schneier on Security RSS
2 days ago

Paragon Solutions Spyware: Graphite

Paragon Solutions is yet another Israeli spyware company. Their product is called “Graphite,” and is a lot like NSO Group’s Pegasus. And Paragon is wor... https://www.schneier.com/blog/archives/2023/06/paragon-solutions-spyware-graphite.html

#nationalsecuritypolicy #Uncategorized #spyware #Israel

Max Guadagnoli BS1
2 days ago

Ancora pillole di chiarezza sul gruppo #Telegram, oggi vi parlo di #TikTok e del perché sia uno #spyware che andrebbe tolto al volo.

Sapendo che nessuno lo toglierà, almeno introduciamo un po' di *pepe* in questa monotona vita #digitale
😉
Se non sapete come trovare il #gruppo Telegram chiedete.

Nayla Salibi
2 days ago

تطبيق لتسجيل الشاشة في متجر ‫#غوغل_بلاي‬ مفخخ ببرمجية خبيثة لسرقة بيانات المستخدمين.و ما هي العلامات الثلاث التي تشير إلى أن جهاز هاتف ‫#أندرويد‬ مخترق. مع تحيات ‫#نايلةالصليبي
‏‪#android
‏‪#Spyware
‏‪#IT_Security
‏‪#Google
‏‪#Apps

https://mc-d.co/1s1s

Jennifer Morency :bc:
3 days ago

US govt banned NSO’s #Pegasus, but said to buy rival #spyware Paragon #Graphite https://9to5mac.com/2023/05/30/paragon-graphite/ "Graphite is, like Pegasus, malware designed to break Apple’s security and allow governments to remotely access and control phones belonging to their own citizens. Using Graphite may not be quite as bad as using Pegasus, but it is still unethical and unacceptable." The monstrous war on #ChronicPain patients and their doctors continues unabated.

Daniel Bretschneider
4 days ago

Concerning Operation #Triangulation: Although the #security #review of the newly found #triangle #spyware is still running, #kaspersky created a python script that checks if your #apple device is compromised. triangle_check can be installed via #pip.

https://github.com/KasperskyLab/triangle_check

Miguel Afonso Caetano
4 days ago

#HumanRights #CyberSecurity #Spyware: "Ahead of today’s opening of RightsCon, a summit on human rights in the digital age, which takes place in San José, Costa Rica, Rasha Abdul Rahim, Director of Amnesty Tech, said:

“The spyware crisis has massive implications for the future of human rights, and the time has come for the world to move beyond simply putting a plaster over this pervasive and covert digital intrusion into peoples’ lives. There must be an immediate global ban on highly invasive spyware."

https://www.amnesty.org/en/latest/news/2023/06/costa-rica-all-states-must-immediately-ban-highly-invasive-spyware/

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #22/2023 is out! It includes, but not only:

➝ 🇺🇸 🪖 Air Force denies running simulation where AI drone “killed” its operator
➝ 🇺🇸 🏂 #Burton Snowboards discloses #databreach after February attack
➝ 🇺🇸 🧪 Enzo Biochem #Ransomware Attack Exposes Information of 2.5M Individuals
➝ 🧠 🤖 Introducing Charlotte AI, #CrowdStrike’s Generative AI Security Analyst
➝ 🐍 🦠 Malicious #PyPI Packages Using Compiled #Python Code to Bypass Detection
➝ 🇰🇵 🎠 N. Korean ScarCruft Hackers Exploit LNK Files to Spread #RokRAT
➝ 🦠 📱 New Zero-Click Hack Targets #iOS Users with Stealthy Root-Privilege #Malware
➝ 🇷🇺 🇺🇸 #Russia says U.S. accessed thousands of #Apple phones in spy plot
➝ 🇯🇵 🚗 #Toyota Discloses New Data Breach Involving Vehicle, Customer Information
➝ ☁️ 👻 Organizations Warned of #Salesforce ‘Ghost Sites’ Exposing Sensitive Information
➝ 🔐 👀 #Amazon faces $30 million fine over Ring, Alexa #privacy violations
➝ 🔐 🧱 Active Mirai Botnet Variant Exploiting #Zyxel Devices for #DDoS Attacks
➝ 🇷🇺 🇺🇦 Russia’s ‘Silicon Valley’ hit by cyberattack; Ukrainian group claims deep access
➝ 🦠 🤖 #Spyware Found in #GooglePlay Apps With Over 420 Million Downloads
➝ 🦠 🚪 #RomCom malware spread via Google Ads for #ChatGPT, GIMP, more
➝ 👛 Southeast Asian hacking crew racks up victims, rapidly expands criminal campaign
➝ 🍏 #Microsoft finds #macOS bug that lets hackers bypass SIP root restrictions
➝ 🦠 🚪 #Barracuda zero-day abused since 2022 to drop new malware, steal data
➝ 🇬🇷 Worst cyberattack in #Greece disrupts high school exams, causes political spat
➝ 🇮🇳 🎠 Sneaky DogeRAT Trojan Poses as Popular Apps, Targets Indian #Android Users
➝ 🇺🇸 U.S. Department of Defense releases 2023 Cyber Strategy
➝ 📱☝🏻 New BrutePrint Attack Lets Attackers Unlock Smartphones with Fingerprint Brute-Force
➝ 🇯🇵 🎠 New GobRAT Remote Access #Trojan Targeting #Linux Routers in #Japan
➝ 🦠 📂 Clever ‘File Archiver In The Browser’ phishing trick uses #ZIP domains

#cyberattack #ai #security #google #cyber

📚 This week's recommended reading is: "Fancy Bear Goes Phishing: The Dark History of the Information Age, in Five Extraordinary Hacks" by Scott J. Shapiro

Subscribe to the #newsletter to have it piping hot in your inbox every Sunday ⬇️

https://0x58.substack.com/p/infosec-mashup-week-222023

heise online
6 days ago

#Verpasstodon

Angriff auf iPhones: Kaspersky macht ausgeklügelte Attacke publik

Kaspersky hat nach eigenen Angaben in iPhone-Backups Spuren eines komplexen Angriffs entdeckt. Gegenwehr sei nur mit rabiaten Mitteln möglich.

https://www.heise.de/news/Operation-Triangulation-Kaspersky-angeblich-mit-iOS-Spyware-attackiert-9159301.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Kaspersky #Malware #MalwareAnalyse #OperationTriangulation #Spyware #iOS #iPhone

Tino Eberl ✅
6 days ago

‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️ ‼️
"Android-Spyware SpinOk kommt auf mehr als 421 Millionen Installationen"

https://www.heise.de/news/Android-Spyware-SpinOk-kommt-auf-mehr-als-421-Millionen-Installationen-9069832.html

"Android apps containing SpinOk module with spyware features installed over 421,000,000 times — indicators of compromise"

https://github.com/DoctorWebLtd/malware-iocs/blob/master/Android.Spy.SpinOk/README.adoc

#Security #Verbraucherschutz #Android #Spyware #Trojaner

Dick Smiths Fair Go Supporters
1 week ago

Apparently it is news that #AmazonRing and Apple #iPhones are #malware?

Amazon #Ring (but its just a few bad employees targetting #women though):
https://www.rt.com/news/577252-amazon-spying-lawsuit-settled/

Dodgy #Apple phones (its just #CIA targetting #Russians, right?)
https://www.rt.com/russia/577273-cia-hack-iphone-diplomats/

See gnu.org/malware for more.

#spyware #privacy #allPhonesAreBad #APAB

Marcus Hutchins :verified:
1 week ago

Podcast Ep4 Video just uploaded! We discuss a potential Android supply-chain attack, crazy spying techniques, and are advertisers listening to you.

#podcast #tech #cybersecurity #spyware #infosec
https://youtu.be/wc8T_RcwOkY

John Scott-Railton ☕
1 week ago

NEW: heard about #Triangulation #spyware? Something about #Kaspersky?

Or the #FSB waxing paranoid about #Apple?

What does it all mean?

Well, my @citizenlab colleague Bill Marczak has an deliciously spicy take on the unfolding saga.

Plus some tips for defenders.

#cybersecurity #hacking #APT

https://medium.com/@billmarczak/triangulation-did-the-nsa-fail-to-learn-the-lessons-of-nso-5f36d251d02e

Avoid The Hack!
1 week ago

More malicious extensions in #Chrome Web Store

At least 18 different malicious extensions (as of 30 MAY and this post) identified by @WPalant

Remember extensions have privileged access to the browser (and data in the browser). Choose your extensions wisely... they could be #spyware or #malware in disguise.

#cybersecurity #infosec #security #opsec #privacy

https://palant.info/2023/05/31/more-malicious-extensions-in-chrome-web-store/

IT News
1 week ago

“Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware - Enlarge

Moscow-based security firm Kaspersky has been hit by ... - https://arstechnica.com/?p=1943622 #kaspersky #security #iphones #spyware #biz#ios

Tech news from Canada
1 week ago

Ars Technica: “Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware https://arstechnica.com/?p=1943622 #Tech #arstechnica #IT #Technology #Kaspersky #Security #iPhones #spyware #Biz&IT #iOS

heise online
1 week ago

Operation Triangulation: Kaspersky angeblich mit iOS-Spyware attackiert

Kaspersky hat nach eigenen Angaben in iPhone-Backups Spuren eines komplexen Angriffs entdeckt. Gegenwehr sei nur mit rabiaten Mitteln möglich.

https://www.heise.de/news/Operation-Triangulation-Kaspersky-angeblich-mit-iOS-Spyware-attackiert-9159301.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#iOS #iPhone #Kaspersky #Malware #Spyware #news

Zersplitternder Apfel in leuchtendem Dreieck
heise online
1 week ago

Kurz informiert: KI-Schulcloud, Spionage, Amazon, Robotermöbel

Unser werktäglicher News-Überblick fasst die wichtigsten Nachrichten des Tages kurz und knapp zusammen.

https://www.heise.de/news/Kurz-informiert-KI-Schulcloud-Spionage-Amazon-Robotermoebel-9158996.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#AmazonAlexa #Roboter #kurzinformiert #NSA #Spyware #news

Scripter :verified_flashing:
1 week ago

Android-Spyware SpinOk kommt auf mehr als 421 Millionen Installationen | heise online
https://heise.de/-9069832 #Cybercrime #Malware #Spyware #SpinOk

Loki the Cat
1 week ago

Looks like the DEA wants to be a real cool cat like me and use spyware to catch those pesky drug dealers. But using Pegasus? Talk about copycat! #Mew-sedUp #Spyware #DEA

https://yro.slashdot.org/story/23/05/31/2258214/new-report-says-american-government-agencies-are-using-malware-similar-to-banned-pegasus-spyware?utm_source=rss1.0mainlinkanon&utm_medium=feed

🅰🅻🅸🅲🅴
1 week ago

Yay...more gross misuse of customer data.

"FTC says Ring deceived its customers by failing to restrict employees’ and contractors’ access to its customers’ videos, using customer videos to train algorithms, among other purposes, without consent, and failing to implement security safeguards"

---

#Ring #RingDoorbell #Spyware #DataPrivacy #Privacy #Security #FTC #Breach

https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-says-ring-employees-illegally-surveilled-customers-failed-stop-hackers-taking-control-users

A technical analysis of Pegasus for Android – Part 1 – https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-1/

A technical analysis of Pegasus for Android – Part 2 – https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-2/

A technical analysis of Pegasus for Android – Part 3 – https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-3/

Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution – https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html

#Pegasus #NSO #Israel #Spyware #LogicieEspion #espionage #exploit #Analysis

Katzenjens
1 week ago

Wie unangenehm. Kistenschieber-Programmierung ist prinzipiell gefährlich. Aber doch so einfach... https://www.heise.de/news/Android-Spyware-SpinOk-kommt-auf-mehr-als-421-Millionen-Installationen-9069832.html #spyware #android

Avoid The Hack!
1 week ago

#Spyware Found in #Google Play Apps With Over 420 Million Downloads

Just because it is in the app store doesn't make it de facto "safe"

It greatly helps to verify source/authenticity of an app prior to download. You can start by researching the project developer, evaluating their official channels for distribution.

#android #cybersecurity #infosec #security #opsec

https://www.securityweek.com/spyware-found-in-google-play-apps-with-over-420-million-downloads/

heise online
1 week ago

Kurz informiert: SpinOk, Spionagesatellit, Beton, Exoplaneten

Unser werktäglicher News-Überblick fasst die wichtigsten Nachrichten des Tages kurz und knapp zusammen.

https://www.heise.de/news/Kurz-informiert-SpinOk-Spionagesatellit-Beton-Exoplaneten-9079964.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Android #kurzinformiert #Spionage #Spyware #news

KubikPixel™
1 week ago

Wenn wir ehrlich sind, sehr viele #Entwickler & #Programmierung nutzen die nächstes aufzufindente #Tools um es nicht selber zu #Entwicklung aufzusetzen und merken erst später was die für #Shit die witklich anpreisen oder sehe ich da was #falsch?

«Android-Spyware SpinOk kommt auf mehr als 421 Millionen Installationen»

😶‍🌫️ https://www.heise.de/news/Android-Spyware-SpinOk-kommt-auf-mehr-als-421-Millionen-Installationen-9069832.html

--
#android #spyware #sicherheit #spinok #installation

heise Security
1 week ago

Android-Spyware SpinOk kommt auf mehr als 421 Millionen Installationen

Ein Android-Software-Modul mit Spyware-Funktionen hat Doctor Web in Apps auf Google Play mit mehr als 421 Millionen Downloads aufgespürt. Google ist informiert.

https://www.heise.de/news/Android-Spyware-SpinOk-kommt-auf-mehr-als-421-Millionen-Installationen-9069832.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Android #Cybercrime #GooglePlayStore #Malware #Security #Spyware #news

Smartphone Spyware
Scripter :verified_flashing:
2 weeks ago

iPhone-Spyware Pegasus erstmals in militärischem Konflikt eingesetzt | heise online
https://heise.de/-9067624 #Spyware #Pegasus

Farhad
2 weeks ago

Even #AIPAC Would Struggle to Love the Israel Seen in

If you’ve been following the Pegasus story closely over the past few years, there’s probably not that much to be gleaned from this documentary – but there will definitely be something, writes @AdrianHennigan1

A new documentary about the #NSO Group and its #Pegasus spyware whets the appetite for a fictional recreation that might capture the true behind-the-scenes drama. It's also a bleak reminder that Israel is a world leader in exporting #spyware to governments that don’t give a rat’s ass about human rights.


www.haaretz.com/life/televisio…
#palestine #Israel #Occupation #Apartheid #Politics #Tecgnology #Software

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #21/2023 is out! It includes, but not only:

‣ 🇬🇧 🇺🇸 #NHS data breach: trusts shared patient details with #Facebook without consent
‣ ☁️ Severe Flaw in #Google Cloud's Cloud #SQL Service Exposed Confidential Data
‣ 🇨🇭 💰 US govt contractor #ABB confirms #ransomware attack, data theft
‣ 🦠 🤖 #Predator: Looking under the hood of Intellexa’s #Android spyware
‣ 🇦🇿 🇦🇲 Hacking in a war zone: #Pegasus #spyware in the Azerbaijan-Armenia conflict
‣ 🦠 🎮 Dark Frost #Botnet Launches Devastating #DDoS Attacks on Gaming Industry
‣ 🇷🇺 🦠 Mysterious #malware designed to cripple industrial systems linked to #Russia
‣ 🇧🇷 🇵🇹 ‘Operation Magalenha’ targets credentials of 30 Portuguese #banks
‣ 🩹 #GitLab 'strongly recommends' patching max severity flaw ASAP
‣ 🇮🇷 🇮🇱 Iranian hackers use new #Moneybird ransomware to attack Israeli orgs
‣ 🇺🇦 Cyber Attacks Strike #Ukraine's State Bodies in Espionage Operation
‣ 🇨🇳 🇺🇸 Chinese state hackers infect critical infrastructure throughout the US and Guam
‣ 🐍 👨🏻‍⚖️ #PyPI was subpoenaed
‣ 🇰🇵 🦠 N. Korean #Lazarus Group Targets #Microsoft IIS Servers to Deploy Espionage Malware
‣ 🦠 🤖 Data Stealing Malware Discovered in Popular Android Screen Recorder App
‣ 🇩🇪 Arms maker Rheinmetall confirms #BlackBasta ransomware attack
‣ 🦠 New ‘GoldenJackal’ APT Targets Middle East, South Asia Governments
‣ 🇺🇸 🇰🇵 Treasury Department sanctions entities tied to North Korean IT scams, hacking
‣ 🇺🇸 📰 Cuba ransomware claims #cyberattack on Philadelphia Inquirer
‣ 🇺🇸 🏥 After ransomware attack, state’s second-largest health insurer says patient data stolen
‣ 🇯🇵 🇮🇳 🏍️ #Suzuki motorcycle plant shut down by cyber attack
‣ 🇺🇸 🪖 #Pentagon explosion hoax goes viral after verified #Twitter accounts push
‣ 🇺🇸 🇪🇺 #Meta Fined Record $1.3 Billion and Ordered to Stop Sending European User Data to US
‣ 🦠 🎬 Cloned #CapCut websites push information stealing malware
‣ 🇰🇷 🇺🇸 Warning: #Samsung Devices Under Attack! New Security Flaw Exposed
‣ 🍏 #Apple fixes three new zero-days exploited to hack iPhones, Macs

#hacking #cyber #cyberdefense #security #health #cloud #infrastructure #OT #ICS

📚 This week's recommended reading is: "Cyber Defense Matrix: The Essential Guide to Navigating the Cybersecurity Landscape" by Sounil Yu

Subscribe to the #newsletter to have it piping hot in your inbox every Sunday ⬇️

https://0x58.substack.com/p/infosec-mashup-week-212023

John Scott-Railton ☕
2 weeks ago

Whenever I see #BorisJohnson
I wonder: anybody check that phone for #Pegasus etc. lately?

#spyware #cybersecurity #UK #intelligence

Ian Brown :fedi:
2 weeks ago

“The company sought a list of allied nations that the US wouldn’t object to seeing deploy [#spyware]. People with knowledge of the matter suggested 35 countries are on that list, though the exact nations involved could not be determined. Most were in the EU and some in Asia, the people said.” https://on.ft.com/3OJc2Ou

heise online
2 weeks ago

Kurz informiert: Multiresistente Keime, Tesla-Files, Spyware, Prime Video

Unser werktäglicher News-Überblick fasst die wichtigsten Nachrichten des Tages kurz und knapp zusammen.

https://www.heise.de/news/Kurz-informiert-Multiresistente-Keime-Tesla-Files-Spyware-Prime-Video-9066367.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#AmazonPrimeVideo #KünstlicheIntelligenz #kurzinformiert #Medizin #Spyware #Tesla #news

heise Security
2 weeks ago

Android-Malware: Vom nützlichen Tool zu Spyware in einem Jahr

Die IT-Forscher von Eset haben eine Android-App entdeckt, die als nützliches Tool startete, rund ein Jahr später jedoch Spionagefunktionen nachgerüstet bekam.

https://www.heise.de/news/Android-Malware-Vom-nuetzlichen-Tool-zu-Spyware-in-einem-Jahr-9066385.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Android #Cybercrime #GooglePlay #GooglePlayStore #Malware #Security #Spyware #news

John Scott-Railton ☕
2 weeks ago

They just made it up.

The #VPN industry is a scourge.

Not content with tricking people into paying for security talismans by misrepresenting what VPNs do..., they are SEO-optimizing fake #cybersecurity advice to drive signups.

The perverse thing is that the high risk people like dissidents & journalists that need to get safer from Predator not only won't be.helped, but real advice is getting drowned out.

Glad to see @maldr0id call it out. #hacking #spyware #Predator #malware #security

This continues a trend of these types of "mercenary" #spyware spreading. If you suspect your system(s) may have been compromised by commercial spyware, please consider notifying Talos’ research team at talos-mercenary-spyware-help@external.cisco.com

Talos has new technical details on a #spyware called #Preadtor, and it's loader, #Alien. Read our blog post for more on this threat that's actively being sold and used to unknowingly track users https://blog.talosintelligence.com/mercenary-intellexa-predator/

heise online
2 weeks ago
Terminator T-800; Donnerstag: KI-Warnung, KI-Profit, Drohnen-Regeln, Playstation-Handheld, China-Spione & #heiseshow
heise online
2 weeks ago

Microsoft warnt vor chinesischer Cyberspionage gegen kritische US-Infrastruktur

Seit Mitte 2021 aktive Gruppe "Volt Typhoon" sammelt Informationen und Zugangsdaten in der US-Pazifikinsel Guam. Doch ist Taiwan das eigentliche Ziel?

https://www.heise.de/news/Microsoft-warnt-vor-chinesicher-Cyberspionage-gegen-kritische-US-Infrastruktur-9064871.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Cybersecurity #Cyberspionage #Cyberwar #Hacking #Internet #Microsoft #Security #Spionage #Spyware #news

Hand auf Notebook im dunklen Raum
John Scott-Railton ☕
3 weeks ago

NSO Group sharing password tips is like a landmine manufacturer posting first aid advice for papecuts.

#Pegasus #spyware

heise online
3 weeks ago

Pegasus-Spyware: Mexikanischer Spitzenbeamter ausspioniert

In Mexiko ist ein enger Verbündeter des Präsidenten mit Pegasus ausgespäht worden. Es ist der erste bestätigte Fall eines so hochrangigen Regierungsbeamten.

https://www.heise.de/news/Pegasus-Spyware-Mexikanischer-Spitzenbeamter-ausspioniert-9062321.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Pegasus #Spyware #news

Ian Brown :fedi:
3 weeks ago

‘German prosecutors have charged four people with the unauthorised sale of #spyware to Turkish security services, alleging just days before a pivotal election that it was used in an attempt to spy on the country’s opposition.’ https://on.ft.com/45oVCAI

Niels Provos
3 weeks ago

Spying in Mexico Strikes a New Victim: the President’s Ally

While looking into abuses by the armed forces, the country’s top human rights official was targeted with Pegasus, the world’s most notorious spyware.

https://www.nytimes.com/2023/05/22/world/americas/mexico-spying-pegasus-israel.html

#spyware #pegasus #nso

Ian Brown :fedi:
3 weeks ago

‘the “open question” over #Mitsotakis remained his commitment to the rule of law. The 🇬🇷 prime minister has been embroiled in a #spyware scandal in which the security services, overseen by Mitsotakis’s chief of staff and nephew, spied on politicians and journalists’
https://on.ft.com/3q1Uxyr

3 weeks ago

@Tutanota It's a step forward.

Why does it seem like it's only Google's #Spyware that gets something resembling appropriate regulations? When are they going to start enforcing anti-spyware legislation on #Disney, #Apple, and #Microsoft ? #BanDRM

CCC Freiburg
3 weeks ago

Empfehlenswerter #Pegasus Artikel und 6 teiler #Podcast in @zeit #ZeitOnline

""Der Spion in unseren Handys" ist ein Podcast über die mächtigste Spyware der Welt und wie sie enttarnt wurde. In sechs Folgen erzählen Reporterinnen und #Reporter aus dem Investigativ-Ressort von ZEIT und ZEIT ONLINE von ihren Recherchen zur #Spähsoftware Pegasus. Die Opfer der #Spyware kommen ebenso zu Wort, wie ihre Erfinder und deren Gegenspieler."

#Überwachung #Cyber #staatstrojaner
https://www.zeit.de/serie/pegasus-der-spion-in-unseren-handys

Niels Provos
3 weeks ago

Malware turns home routers into proxies for Chinese state-sponsored hackers

"malicious firmware that can wrangle a wide range of residential and small office routers into a network that stealthily relays traffic to command-and-control servers maintained by Chinese state-sponsored hackers."

https://arstechnica.com/information-technology/2023/05/malware-turns-home-routers-into-proxies-for-chinese-state-sponsored-hackers/

#security #spyware #china

Random Host 🐕
3 weeks ago

@rmondello I never used Chrome much, but the few times I did, it immediately began to scrape all my hard disks for "suspicious files" using their bundled "software reporter" and increased the recording volume of my primary audio input device, both without my consent.

Chrome is literally #spyware, but most people don't seem to care about these things at all.

Anyone who cares about privacy should remove this piece of #Google crap from their system ASAP.

There are plenty of alternatives using the same browser engine, but without the spyware parts.

erAck
3 weeks ago
John Scott-Railton ☕
4 weeks ago

3/ As the fox, NSO says they are uniquely positioned to get all the hens together to craft #spyware regulation.

In case any #law folks are wondering, these "key:" stakeholders NSO is talking about:

- won't take NSO's meetings (most of congress)
- have sanctioned them (USG)
- have sued them (Industry, civil society)

#cybersecurity #hacking #exploit

John Scott-Railton ☕
4 weeks ago

2/ NSO's Russia & China claims didn't sway the Biden Admin / NSC.

Because they are silly.

Countries that don't buy Chinese fighters won't suddenly buy their secret #spyware. For the same obvious #natsec, #cybersecurity & #counterintelligence reasons.

Still, NSO apparently warmed these canards up & served them to the American Bar Association.

The American Bar Association, the largest association of lawyers in the world, is among the groups that have expressed concern over spyware's threats to human rights. Citing experts at Citizen Lab and Amnesty in an August 2022 conference panel cautioning about spyware, the association called for a moratorium on the sale, purchase and use of commercial spyware until a global framework regulating the industry was put in place.

In a recently disclosed letter from NSO Group's General Counsel Shmuel Sunray to the chair of the American Bar Association’s International Law Section, NSO Group countered the association's moratorium proposition. The moratorium would harm the U.S. and its allies by leaving the industry to be dominated by Chinese and Russian companies, the April 2023 email argues, and stand in the way of Pegasus combating crime.
Lorraine C.
1 month ago

On @CBC Ideas now.

Nobel Peace Prize recipient Maria Ressa believes online #disinformation could pose an existential threat to democracy — and she's not alone. Ressa joins Citizen Lab founder Ron Deibert for a conversation about how online impunity is eroding civil society and how we can fight back.

https://www.cbc.ca/radio/ideas/disinformation-democracy-ressa-deibert-1.6837181

#canada #Tech #cdnpoli #ai #CitizenLab #thailand
#democracy #journalism #philipines #infosec #usa #news #algorithms #data #spyware
#citizenlab #autocracy #toronto

Avoid The Hack!
1 month ago

QR codes used in fake parking tickets, surveys to steal your money

Careful what QR codes you are scanning... never a good idea to scan random QR codes.

Be extra warry of QR codes that lead you to install a third-party app - could be #malware or #spyware designed to give threat actors access to your phone.

#cybersecurity #infosec #security #informationsecurity

https://www.bleepingcomputer.com/news/security/qr-codes-used-in-fake-parking-tickets-surveys-to-steal-your-money/

heise online
1 month ago

Finale im Pegasus-Ausschuss: Missbrauch von Spyware untergräbt die Demokratie

Für den Ruf nach einem Moratorium reicht es nicht. Die EU-Abgeordneten fordern, Handel mit und Einsatz von Spionagesoftware streng zu regulieren.

https://www.heise.de/news/Finale-im-Pegasus-Ausschuss-Missbrauch-von-Spyware-untergraebt-die-Demokratie-8990712.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#EU #Malware #Pegasus #Politik #Spionage #Spyware #Überwachung #news

Künstlerische Darstellung einer Computerplatine mit aufgemaltem Pferd

☣️ This is why you should never trust your important information (like passwords!) to proprietary software like @1password.

#OpenSource #FreeSoftware #privacy #security #infosec

🤡 #1Password becomes #spyware:

https://blog.1password.com/privacy-preserving-app-telemetry/

John Scott-Railton ☕
2 months ago

5/ Coda: as ever, none of our work or investigations would happen without brave #spyware and #Hacking victims that choose to come forward, get #Forensics done, and tell their stories.

These people are my absolute heroes.

And so are the #NGOs that regularly partner with us in @citizenlab investigations.

This is what an accountability ecosystem looks like.

John Scott-Railton ☕
2 months ago

3/ Some details about the #zeroclick #zeroday exploits in #Pegasus #spyware that we found evidence of.

*THREE* #zeroclick #0day chains used by NSO's #Pegasus #spyware in 2022.

First: #PWNYOURHOME: worked against #homekit even if you didn't set up a home.

Apple's changes in iOS 16.3.1 address this.

We also observed #LockdownMode kneecapping it.

MessagesBlostDoorService homed MessagesBlastDoorService (suspected) Figure 2: Three exploit chains released by NSO Group in 2022. To nrotect our continued abilitv to identifv Pecasus infections
3. PWNYOURHOME: An i0S 15 and i0S 16 Zero-Click Exploit

The PWNYOURHOME exploit appears to be a novel two-phase zero-click exploit, with each of the two phases targeting a dif- ferent process on the phone. The first phase of the exploit in- volves the HomeKit functionality built into iPhones (via the homed process), and the second phase of the exploit involves iMessage (via the MessagesBlastDoorService process). PWNYOURHOME appears to succeed against a target even if the target has never configured a “Home” inside HomeKit. However, in some cases, the email address of the PWNYOURHOME attacker is logged and Pegasus fails to delete this email from the HomeKit database.

We obtained logs from multiple devices compromised with PWNYOURHOME. In one case, the attacker’s email address ([REDACTED]@gmail.com) was logged. The phone logs showed that the [REDACTED]@gmail.com email address was added to HomeKit approximately eight minutes before the Pegasus spyware was recorded running on the phone, and an iMessage attachment was deleted.
Phase One: HomeKit Daemon Crashes Logs from another PWNYOURHOME-exploited device from the 2022 global target pool examined in the course of this investi- gation showed the homed process decoding what appears to be an unusual NSKeyedUnArchiver when it crashed. Logs showed that the NSKeyedUnArchiver decoding had been kicked off by the following function:

-[HMDHomeManager _handleHomeDataSync:] (in

HomeKitDaemonLegacy) The NSKeyedUnArchiver decoder invoked the decoder for NSDictionary, which in turn invoked the decoder for an implau- sible class not normally used within HomeKit. Issues with NSKeyedUnArchiver deserialization have been used in pastiOS zero-click exploits targeting iMessage, so we redact the specific class to avoid assisting attackers. We disclosed this issue to Apple, who made several changes to HomeKit in i0S 16.3.1, in- cluding adding a new method, -[HMDHomeManager _should- DecodeMessage:error:], which declines to decode certain HomeKit messages unless they arrive from a plausible source. This check guards the HomeKit code path we saw exploited.
Lockdown Mode Highlights Attack Apple’s Lockdown Mode feature makes signs of an attempted PWNYOURHOME attack visible to the phone’s user by display- ing notifications (Figure 4). We have seen no recent notifica- tions on Lockdown Mode, nor have we seen any evidence of successful PWNYOURHOME compromise on Lockdown Mode. Given that we have seen no indications that NSO has stopped deploying PWNYOURHOME, this suggests that NSO may have figured out a way to correct the notification issue, such as by fingerprinting Lockdown Mode. Friday, September 9 9:41 n Notification Center &) K to access a Home. T}y Iescsymmosconsionpis to access a Home. Figure 4: Illustration derived from victim screenshots illustrating how lockdown mode displayed notifications related to the PWNYOURHOME exploit Additionally, we have not seen any cases of exploitation of i0S versions 16.1 and greater, suggesting that PWNYOURHOME may have been fixed or mitigated around this time.
John Scott-Railton ☕
2 months ago

Usually when you hear about #mercenary #spyware it's in the context of hacked dissidents.

But now is a good time to remember that #Predator spyware was flown to the #RSF militia in #Sudan

At some point we'll get to a consensus realization that unchecked proliferation of this tech doesn't just fuel abuses & harm democracies... it is geopolitically destabilizing.

https://www.haaretz.com/israel-news/security-aviation/2022-11-30/ty-article-magazine/.premium/jet-linked-to-israeli-spyware-tycoon-brings-spy-tech-from-eu-to-notorious-sudanese-militia/00000184-a9f4-dd96-ad8c-ebfcd8330000

Flight of the Predator: Jet Lir%&ed to Israeli Spyware Tycoon Brings Surveillance Tech From EU to Notorious Sudanese Militia
Picture of the jet
Details of the Cessna’s arrival, its passengers and cargo were meant to remain secret — logged in an inaccessible location, foregoing the usual procedures. The secrecy was a testament to the power of Mohamed Hamdan Dagalo, known as Hemedti, Sudan’s richest man and the owner of a private army that is the heir to the murderous legacy of the Janjaweed, infamous for their crimes against humanity in Sudan's troubled Western region, Darfur.. On the ground for 45 minutes Credit: flightradar24.com According to three independent sources, the cargo was high-end surveillance technology, made in the European Union, with the potential to tip the balance of power in Sudan thanks to its capacity to turn smartphones into audio-visual informants on their owners. When news of its arrival reached Hemedti’s rivals the equipment was seen as so dangerous that an RSF commander speaking on condition of anonymity said it was smuggled out of Khartoum to the militia’s stronghold in Darfur to prevent its seizure by the army.
Pic of RSF members with RPGs
Anonymous :anarchism: 🏴
2 months ago

Israeli #spyware vendor QuaDream is reportedly shutting down its operations after its REIGN #hacking toolset was exposed by Citizen Lab and #Microsoft.

https://thehackernews.com/2023/04/israeli-spyware-vendor-quadream-to-shut.html

#cybersecurity #privacy

heise online
2 months ago

Zero-Click-Exploit: Israelischer Spyware-Hersteller QuaDream macht dicht

Erst vorige Woche exponierten Sicherheitsforscher den mächtigen Staatstrojaner Reign von QuaDream. Jetzt stellt die Firma ihre Aktivitäten in Israel ein.

https://www.heise.de/news/Zero-Click-Exploit-Israelischer-Spyware-Hersteller-QuaDream-macht-dicht-8968998.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Cybersecurity #Exploit #Sicherheitslücken #Spyware #news

heise online
2 months ago

Kurz informiert: Klimaschutz, ICT-Kompetenz, Spyware, Innogames

Unser werktäglicher News-Überblick fasst die wichtigsten Nachrichten des Tages kurz und knapp zusammen.

https://www.heise.de/news/Kurz-informiert-Klimaschutz-ICT-Kompetenz-Spyware-Innogames-8950543.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#iPhone #kurzinformiert #SocialMedia #Spyware #Verkehrswende #news

Bob LeFridge
2 months ago

Another Israeli spyware company has been exposed and they've been using a seriously sneaky trick to infect Apple phones.

They'd send an infected iCloud calendar invitation to users, set for a date in the past. This made them invisible to targeted users -- primarily journalists & government clients.

Reign-infected phones give full access to their mic & recorder, messages on encrypted apps, phone conversations & track locations.

https://www.theguardian.com/technology/2023/apr/11/canadian-security-experts-warn-over-spyware-threat-to-rival-pegasus-citizen-lab

#Spyware #Israel #QuaDream #Reign #Apple

John Scott-Railton ☕
2 months ago

5/ There's a basic takeaway here:

#mercenary #spyware #proliferation is an uncontrolled problem.

Yes there are some high profile companies like #NSO with #Pegasus, but alongside are much more discreet players.

Yet typically, when we are actually able to figure out what they are up to... we find the same victimology.

The underline here should be: the industry is just going to keep causing harm until radically curtailed & regulated, at minimum.

Paolo Redaelli
2 months ago

@mconley
Or just stop using the #spyware called #windows and start using #freeasinfreedom operative systems 😁
@mhoye

heise online
2 months ago

Anti-Spyware-Erklärung: Bundesregierung hat noch Abstimmungsbedarf

Die USA und zehn weitere westliche Staaten wollen gemeinsam die Verbreitung und den Missbrauch kommerzieller Spionagesoftware bekämpfen. Deutschland fehlt.

https://www.heise.de/news/Anti-Spyware-Erklaerung-Bundesregierung-hat-noch-Abstimmungsbedarf-8567185.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Geheimdienste #Datenschutz #Spionage #Spyware #Trojaner #Überwachung #news

heise online
2 months ago

Dienstag: Spyware-Kauf durch Scheinfirma, Cyber-Angriff bei Western Digital

USA kaufen Spyware per Scheinfirma + Western Digital meldet "Sicherheitsvorfall" + Tim Cook für Mixed Reality + Drohenprogramm der Ukraine + Grundgesetzänderung

https://www.heise.de/news/Dienstag-Spyware-Kauf-durch-Scheinfirma-Cyber-Angriff-bei-Western-Digital-8515608.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Apple #Cybercrime #Cyberwar #Drohnen #JoeBiden #VirtualReality #Pegasus #Spyware #TimCook #UkraineKrieg #WesternDigital #news

Geolokalisierung, dazu Text: DIENSTAG Landmark-Software, Western Digital, Mixed Reality, "Armee der Drohnen" & Cyberkrieg
tariq
2 months ago

Last week, the Biden Administration put out an executive order prohibiting certain uses of spyware by the US Government. I wrote some thoughts on it but in summary, it feels more about reigning in the industry rather than concern around civil rights. 🧵 #TechPolicy #Spyware https://codeandconsequence.substack.com/p/deep-diving-into-president-bidens

heise online
2 months ago

USA nutzten Scheinfirma, um Spionagesoftware zu kaufen

Laut einem New York Times-Bericht nutzt die US-Regierung eine Software, die von den Pegasus-Entwicklern stammt, um den Standort von Mobiltelefonen zu ermitteln.

https://www.heise.de/news/USA-nutzten-Scheinfirma-um-Spionagesoftware-zu-kaufen-8515580.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Pegasus #Spyware #news

heise online
2 months ago

Donnerstag: Internationale Spyware-Kampagnen, Kryptofirma verliert Millionen

Spyware per SMS-Link + Safemoon nicht safe + Telegram gegen DSGVO + Polizei mit Passfoto-Zugriff + Datenschutz von Parksündern + heiseshow zu drei neuen Themen

https://www.heise.de/news/Donnerstag-Internationale-Spyware-Kampagnen-Kryptofirma-verliert-Millionen-8230100.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Blockchain #Coronavirus #Cybercrime #Datenschutz #DSGVO #elektronischerPersonalausweis #HomeOffice #Kryptowährung #Messaging #Sicherheitslücken #SMS #Spyware #Telegram #Twitter #Überwachung #news

Mensch hält Handy in der Hand; Donnerstag: Spyware-Kommerz, Krypto-Verlust, Telegram-Kritik, Passfoto-Zugriff, Park-Bilder & heiseshow
heise online
2 months ago

Google und Amnesty International decken internationale Spyware-Kampagnen auf

Android, iOS, Chrome und Samsungs Internet-Browser seien zunehmend Angriffen kommerzieller Spyware ausgesetzt. Die Attacken nutzen per SMS verschickte Links.

https://www.heise.de/news/Google-und-Amnesty-International-decken-internationale-Spyware-Kampagnen-auf-8222319.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Android #Apple #Cybercrime #Google #iOS #Phishing #Samsung #Sicherheitslücken #SMS #Spyware #Tracking #news

Mensch tippt auf Smartphone
heise online
2 months ago

Dienstag: Microsoft Teams ganz neu, USA reduzieren Spyware

Microsoft Teams doppelt so schnell + US-Regierung schränkt Spyware ein + iOS 16.4 mit Neuerungen + EU-Rat zum Data Act + Kommentar zum geplatzten Verbrenner-Aus

https://www.heise.de/news/Dienstag-Microsoft-Teams-ganz-neu-USA-verbieten-Spyware-8131887.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Apple #Datenschutz #EU #iOS #Microsoft #MicrosoftTeams #Pegasus #Security #Spyware #news

Microsoft-Logo an Bürofassade, dazu Text: DIENSTAG Microsoft Teams, Spionageprogramme, iOS 16.4, Europäisches Datengesetz & Verbrenner-Aus
heise online
2 months ago

US-Präsident Biden verbietet den Einsatz kommerzieller Spionageprogramme

Spyware ist oft verheerend für die Menschenrechte. Das Weiße Haus schränkt nun den Einsatz durch US-Bundesbehörden ein. Es gibt allerdings Ausnahmen.

https://www.heise.de/news/US-Praesident-Biden-verbietet-den-Einsatz-kommerzieller-Spionageprogramme-8129395.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#JoeBiden #Pegasus #Security #Spyware #news

Das Weiße Haus
Steve Herman
2 months ago

Today, President Biden signed an executive order prohibiting operational use by the US government of commercial #spyware "that poses risks to national security or has been misused by foreign actors to enable human rights abuses around the world." https://www.whitehouse.gov/briefing-room/presidential-actions/2023/03/27/executive-order-on-prohibition-on-use-by-the-united-states-government-of-commercial-spyware-that-poses-risks-to-national-security/

heise online
3 months ago

Obst und Malware: Google suspendiert die Onlineshopping-App Pinduoduo

Eine der größten chinesischen Shopping-Dienste steht im Verdacht, in seinen Apps Malware zu schmuggeln. Google suspendiert und blockiert die Android-Apps.

https://www.heise.de/news/Obst-und-Malware-Google-suspendiert-die-Onlineshopping-App-Pinduoduo-7585002.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Android #Malware #Spyware #news

Mehrere Körbchen mit frischen Erdbeeren
gillo
3 months ago

Predator scandal: the European surveillance market is a black hole: They call it the Greek Watergate, but the case of illegal wiretapping concerns all of Europe. And Italy is the leading exporter of surveillance systems in the EU https://irpimedia.irpi.eu/en-predator-scandal-european-surveillance-market-black-hole/ #italy #spyware

EDPS
3 months ago

.@W_Wiewiorowski@twitter.com and @sophieintveld@twitter.com meeting for a quick catch up on #spyware technologies, national #security and #enforcement of the #GDPR.

W. Wiewiorowski meeting with Sophie In 't Veld
heise online
3 months ago

Anti-Terror-Kampf: Neue Technologien beschränken laut UN-Bericht Grundrechte

Der Einsatz von Drohnen, biometrischer Überwachung, KI und Staatstrojanern gegen Terrorismus gestaltet sich laut einem UN-Bericht verheerend für Menschenrechte.

https://www.heise.de/news/Anti-Terror-Kampf-Neue-Technologien-beschraenken-laut-UN-Bericht-Grundrechte-7535711.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Biometrie #Datenschutz #Drohnen #Roboter #KünstlicheIntelligenz #Spyware #Terrorbekämpfung #Internetfilter #news

EDPS
3 months ago

One year has passed since the #EDPS paper - Preliminary Remarks on Modern #Spyware - where we proposed 8 recommendations - 8 actions for the policy makers. @W_Wiewiorowski@twitter.com at @EP_ScienceTech@twitter.com workshop on #Pegasus Spyware

Read the paper: https://europa.eu/!khnXj4

W. Wiewiórowski in a panel discussion
Frederik Borgesius
3 months ago

This report is great. Not good for my mood though.

Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware - draft report. Rapporteur @sophieintveld https://media.euobserver.com/281e6fa170b4673bc87da11181f30041.pdf
#tech #security #spyware #humanrights #eu #law

Picture of printed version of report mentioned in the toot