Chinese Government Asked TikTok for Stealth Propaganda Account - Bloomberg

https://www.bloomberg.com/news/articles/2022-07-29/chinese-government-asked-tiktok-for-stealth-propaganda-account

A Chinese government entity responsible for public relations attempted to open a stealth account on TikTok targeting Western audiences with propaganda, according to internal messages seen by Bloomberg.

iOS Privacy: Instagram and Facebook can track anything you do on any website in their in-app browser · Felix Krause

https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser

The Hacking of Starlink Terminals Has Begun - WIRED

https://www.wired.com/story/starlink-internet-dish-hack/

It cost a researcher only $25 worth of parts to create a tool that allows custom code to run on the satellite dishes.

FBI investigation determined Chinese-made Huawei equipment could disrupt US nuclear arsenal communications - CNN

https://edition.cnn.com/2022/07/23/politics/fbi-investigation-huawei-china-defense-department-communications-nuclear/index.html

Report: Mercenary spyware exploited Google Chrome zero-day to target journalists - The Record by Recorded Future

https://therecord.media/report-mercenary-spyware-exploited-google-chrome-zero-day-to-target-journalists/

A zero-day vulnerability in Google Chrome was discovered when attackers exploited it to target users in the Middle East, including journalists, cybersecurity firm Avast said Thursday. 

The company attributed the attacks to a secretive Israeli firm known as Candiru — named after a notorious parasitic fish — that sells spyware to governments. 

Ring Reveals They Give Videos to Police Without User Consent or a Warrant - Electronic Frontier Foundation

https://www.eff.org/deeplinks/2022/07/ring-reveals-they-give-videos-police-without-user-consent-or-warrant

Amazon’s Ring devices are not just personal security cameras. They are also police cameras—whether you want them to be or not. The company now admits there are “emergency” instances when police can get warrantless access to Ring personal devices without the owner’s permission. This dangerous policy allows police, in conjunction with Ring, to decide when access should be granted to private video.

Hackers Say They Can Unlock and Start Honda Cars Remotely

https://www.vice.com/en/article/z34xnw/hackers-say-they-can-unlock-and-start-honda-cars-remotely

The Honda models that Kevin2600 and his colleagues tested the attack on use a so-called rolling code mechanism, which means that—in theory—every time the car owner uses the keyfob, it sends a different code to open it. This should make it impossible to capture the code and use it again. But the researchers found that there is a flaw that allows them to roll back the codes and reuse old codes to open the car, Kevin2600 said.

Driverless Robotaxi Fleet Paralyzed for Hours in San Francisco

https://thelastdriverlicenseholder.com/2022/06/29/driverless-robotaxi-fleet-paralyzed-for-hours-in-san-francisco/

Apparently, the first system breakdown of a driverless robot taxi fleet occurred. In San Francisco, at least a dozen autonomous Chevrolet Bolts from GM Cruise Automation were spotted blocking the intersection at Gough Street and Fulton Street for a couple of hours

Google Says It Will Automatically Delete Location Data Collected From Visits to Health Facilities — Pixel Envy

https://pxlnv.com/linklog/google-location-data-health/

How mercenary hackers sway litigation battles

https://www.reuters.com/investigates/special-report/usa-hackers-litigation/

A trove of thousands of email records uncovered by Reuters reveals Indian cyber mercenaries hacking parties involved in lawsuits around the world – showing how hired spies have become the secret weapon of litigants seeking an edge.

Reuters identified 35 legal cases since 2013 in which Indian hackers attempted to obtain documents from one side or another of a courtroom battle by sending them password-stealing emails.

The messages were often camouflaged as innocuous communications from clients, colleagues, friends or family. They were aimed at giving the hackers access to targets’ inboxes and, ultimately, private or attorney-client privileged information.

Samsung caught cheating in TV benchmarks, promises software update - FlatpanelsHD

https://www.flatpanelshd.com/news.php

Samsung has been caught cheating by designing its TVs to recognize and react to test patterns used by reviewers

Why Passkeys Will Be Simpler and More Secure Than Passwords - TidBITS

https://tidbits.com/2022/06/27/why-passkeys-will-be-simpler-and-more-secure-than-passwords/

Apple has unveiled its version of passkeys, an industry-standard replacement for passwords that offers more security and protection against hijacking while simultaneously being far simpler in nearly every respect.

Woman accused of killing boyfriend using AirTag tracking • The Register

https://www.theregister.com/2022/06/14/airtag_tracking_murder_charge/

FTC Charges Twitter with Deceptively Using Account Security Data to Sell Targeted Ads - Federal Trade Commission

https://www.ftc.gov/news-events/news/press-releases/2022/05/ftc-charges-twitter-deceptively-using-account-security-data-sell-targeted-ads

The Federal Trade Commission is taking action against Twitter, Inc. for deceptively using account security data for targeted advertising. Twitter asked users to give their phone numbers and email addresses to protect their accounts. The firm then profited by allowing advertisers to use this data to target specific users.

Apple privacy features: What the company should add next

https://www.fastcompany.com/90745234/apple-security-features-2022

Datatilsynet gir Nav 5 mill. kroner i gebyr for CV-deling – NRK

https://www.nrk.no/norge/datatilsynet-gir-nav-5-mill.-kroner-i-gebyr-for-cv-deling-1.15976963

– Vi gir en smekk til Nav. De har krevd at arbeidssøkere har tilgjengeliggjort CV-en sin i en database hvor alle personopplysninger da er tilgjengelig for alle arbeidsgivere, sier Stang Dahl.

Tesla cars, Bluetooth locks, vulnerable to hackers, researchers say - Reuters

https://www.reuters.com/technology/tesla-cars-bluetooth-locks-vulnerable-hackers-researchers-2022-05-17/

Millions of digital locks worldwide, including on Tesla cars, can be remotely unlocked by hackers exploiting a vulnerability in Bluetooth technology, a cybersecurity firm said on Tuesday.

In a video shared with Reuters, NCC Group researcher Sultan Qasim Khan was able to open and then drive a Tesla using a small relay device attached to a laptop which bridged a large gap between the Tesla and the Tesla owner’s phone.

“This proves that any product relying on a trusted BLE connection is vulnerable to attacks even from the other side of the world,” the UK-based firm said in a statement, referring to the Bluetooth Low Energy (BLE) protocol – technology used in millions of cars and smart locks which automatically open when in close proximity to an authorised device.

NCC Group said such a vulnerability was not like a traditional bug which could be fixed with a software patch and added BLE-based authentication was not originally designed for use in locking mechanisms.

Driver must stand trial for deadly Tesla crash in California - AP News

https://apnews.com/article/technology-california-los-angeles-a8412a63a4e392e95a47da1b4a539a68

The driver of a Tesla operating on autopilot must stand trial for a crash that killed two people in a Los Angeles suburb, a judge ruled Thursday.

Advarer mot skreddersydd svindel etter datalekkasje – NRK

https://www.nrk.no/norge/advarer-mot-skreddersydd-svindel-etter-datalekkasje-1.15963551

Personopplysningene som er på avveie etter det store datainnbruddet mot Norkart, kan åpne for mer utspekulerte former for svindel, tror ekspert.

[…]

De neste månedene anbefaler han å være ekstra varsom for spesielle brev, e-poster og telefoner.

– Bruk god dømmekraft, og være skeptisk – hver eneste gang du får en henvendelse, hvor du ikke enkelt kan identifisere hvem som står bak, påpeker Jøsang.

Costa Rica declares national emergency after Conti ransomware attacks

https://www.bleepingcomputer.com/news/security/costa-rica-declares-national-emergency-after-conti-ransomware-attacks/

Conti published most of the 672 GB dump that appears to contain data belonging to the Costa Rican government agencies.