1
 
 

EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major smart watches, rings, and bands makes the case plainly: these devices collect deeply personal health […]

2
 
 

Apple’s Biome framework is drawing fresh attention after researchers identified 84 data streams that can preserve detailed records of how an iPhone is used. The findings do not describe malware or an active intrusion. Instead, they show how built-in iOS services can retain behavioural evidence, including app activity, locations, notifications, messages, connectivity, and device-state changes. […] The post Researchers Find 84 Hidden iOS Data Streams Tracking Apps, Locations and Messages appeared first on Cyber Security News.

3
 
 

A newly uncovered ad fraud campaign is spreading Android apps that display full-screen ads every time you end a phone call.

4
 
 

Security researchers have successfully booted a jailbroken build of iOS 27 on an iPhone 11 Pro by combining the recently disclosed usbliter8 SecureROM exploit with a heavily modified custom firmware workflow. The demonstration targets Apple’s A13-powered iPhone 11 Pro. It shows how physical access to a device in DFU mode can be used to bypass […] The post Researchers Successfully Booted Jailbroken Version of iOS 27 on an iPhone 11 Pro appeared first on Cyber Security News.

5
 
 

Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]

6
 
 

Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates.

7
 
 

Comments

8
 
 

So much for Microsoft and CrowdStrike’s plans for consistent names across the industry

9
 
 

Accepting file uploads is basically inviting strangers to throw random objects through your front window and hoping your living room furniture catches them. Whether it's profile pictures, PDF invoices, or archive files, handling raw uploads means you're trusting external input to behave.

10
 
 

There are several reasons why Linux has such a good reputation and has become such a good standard across the world. It is the power behind most internet servers and cloud infrastructures as well as billions of Android devices. It is stable, has consistently high-performance levels, and remains very flexible. You don’t have to deal with expensive licenses, can view and share code, and can customize any part of the interface to suit your demands. In an age of data breaches and continuous malwa...

11
 
 

A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]

12
 
 

Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against

13
 
 

The Vatican’s official Click to Pray app has exposed the personal information of more than 700,000 users through an unauthenticated API flaw. The issue allowed anyone with a web browser to retrieve account data without needing to sign in. Click to Pray offers daily prayers and papal content through its website and mobile applications. Users […] The post Vatican’s Click to Pray App Exposes 700,000 Users Through Unauthenticated API Flaw appeared first on Cyber Security News.

14
 
 

Joseph speaks to Mike Yeagley about how he bought the world's location data, and what that means for everyone's privacy and security.

15
 
 

Anthropic’s Claude share links appeared in public search results, raising fresh privacy concerns for users who shared sensitive conversations. A Reddit post this weekend revealed that hundreds of Claude AI shared chats were publicly discoverable through Google. Users searching queries such as site:claude.ai/share could access conversations containing legal advice, engineering work, and personal discussions without […] The post Claude AI Shared Chats Reportedly Exposed in Google Search Results appeared first on Cyber Security News.

16
 
 

An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?

17
 
 

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]

18
 
 

Though that doesn't mean LG will stop auto-installing bloatware onto your PC.

19
 
 

A U.S. citizen has asked a court to throw out the government's claim that he gave over a passcode to border authorities that wiped his phone's data, opening up fresh questions about a person's constitutional rights at the U.S. border.

20
 
 

An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]

21
 
 

From phone location data, to social media monitoring, to online undercover tools, a document obtained by 404 Media lays out the surveillance tech available across ICE agency wide.

22
 
 

Roughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint. The post Despite multiple takedowns, botnets continue to grow appeared first on CyberScoop.

23
 
 

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]

24
 
 

Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves […]

25
 
 

A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser.

view more: next ›