Cybersecurity - CISO360
81 subscribers
324 photos
2 videos
170 files
852 links
Everything about Cybersecurity, Data Protection, Data Governance and occasional non-technical banter
Download Telegram
French gov’t confirms hack of at least 18M records from ID document database

France’s government has confirmed that a database storing records of identity documents suffered a breach of millions of entries containing identity data.

The hack of France Titres’ infrastructure led to the theft of between 18 and 19 million records associated with identity credentials like biometric passports, national ID cards and driver’s licenses. The quantity of records covers about a third of France’s adult population.

Read more: https://www.biometricupdate.com/202604/french-govt-confirms-hack-of-at-least-18m-records-from-id-document-database

#databreach #hacking #cybersecurity #infosec #threatmanagement #data #dataprivacy #dataprotection #GDPR #PrivacyMatters #riskmanagement
As per news reports, Pennsylvania lawmaker Joe Ciresi has introduced a bill that would require smart glasses sold, used, or operated in the state to display a visible recording indicator.

The proposal would also ban users from disabling or covering the indicator light, which alerts others when audio or video is being recorded.

Most smart glasses, including Meta’s Ray-Ban smart glasses, already use a front-facing LED light while recording, but there is currently no legal requirement to include one.

The bill comes after reports that some people have been modifying Meta’s smart glasses to disable the recording light and secretly record others.

If the proposal passes, retailers would also be required to inform buyers about Pennsylvania’s recording laws.

Source: Fossbytes

#dataprivacy #dataprotectionlaws #dataprivacylaws #privacy #privacylaws #meta #smartglasses
Cybersecurity - CISO360
Photo
The scenario sounds like every privacy advocate's worst nightmare, straight out of a Black Mirror script that was supposed to stay fiction. Code uncovered by journalists revealed that Meta quietly embedded facial recognition technology into its AI-enabled smart glasses. The unreleased feature, internally dubbed NameTag, would transform faces captured by Meta's glasses into unique biometric signatures known as faceprints and check each one against faceprints stored on the user's phone, a database currently configured to receive updates from Meta. The code has been sitting inside the Meta AI app, which has been downloaded more than 50 million times, since as early as January. The feature is not activated yet and not accessible to consumers. But the core components are already in place, quietly waiting on millions of faces.

Meta's leadership responded to the revelation not with patient explanation but with visible fury. Andy Stone, Meta's VP of Communications, called the reporting shoddy, intellectually dishonest, and pure advocacy-driven click bait. Andrew Bosworth, Meta's longtime CTO, jumped in to call the reporting incredibly misleading and absolutely dishonest. The company insisted that the code is merely evidence of exploration and that nothing has shipped to consumers. It also promised that if it decides to roll something out, it will take a thoughtful approach and do so with full transparency. But this is not the first time NameTag has surfaced. In February, The New York Times published internal Meta memos discussing plans to install the feature, with one striking suggestion that it should launch during a dynamic political environment where many civil society groups that would attack Meta would have their resources focused elsewhere. In April, 75 organizations signed an ACLU letter calling NameTag a red line society must not cross.

The facial recognition code is not the only scandal plaguing Meta's smart glasses. In a separate investigation, Swedish newspapers revealed that human contractors in Nairobi, Kenya, were reviewing footage recorded by the glasses, including deeply private moments: people undressing, using the bathroom, and having sex. Contractors told reporters that they saw everything from living rooms to naked bodies and that Meta terminated the deal with the subcontracting firm only after the story broke. Two class-action lawsuits have been filed over the practice, with plaintiffs saying they had no idea their videos were being shared for human review. Meta's terms of service do allow for human review of AI interactions, but the language is buried deep, and most users have never read it.

Meanwhile, the glasses are selling better than ever, with more than 7 million pairs now in circulation. Mark Zuckerberg has boasted that they are some of the fastest-growing consumer electronics in history. On social media, users are posting candid videos of strangers recorded without their knowledge, often tagged as having been taken by Ray-Ban Meta glasses. The small LED light that activates during recording is easily missed in daylight, and modders have already figured out how to disable it entirely. One massage parlour owner in Toronto discovered weeks after the fact that a customer had recorded her entire interaction and posted it to Instagram, where it attracted hundreds of likes. Meta initially told her nothing was being violated here. The Electronic Frontier Foundation put it most bluntly: Despite the billions of reasons not to, Meta seems to have created the capacity to turn their customers into a distributed surveillance machine.

#MetaSmartGlasses #NameTag #FacialRecognitionBacklash
For the third month in a row, the disgruntled researcher timed the disclosure to coincide with Microsoft’s Patch Tuesday release.

Full article: https://cnews.link/nightmare-eclipse-rogueplanet-zero-day/

Researcher was removed from Github and Gitlab but responded by creating an independent hosting infrastructure while continuing to distribute code through alternative platforms.
🔥 A new exploit unlocks BitLocker-encrypted Windows drives.

No password. No cracking.

It's called GreatXML. Drop two XML files on the recovery partition, reboot into Windows Recovery, and a shell spawns with full access to the drive.

The bug ties to Windows Defender Offline Scan.

Details here: https://thehackernews.com/2026/06/new-greatxml-exploit-bypasses-windows.html