Forwarded from BlackBox (Security) Archiv
New Advanced Android Malware Posing as “System Update”
Another week, and another major mobile security risk. A few weeks ago, Zimperium zLabs researchers disclosed unsecured cloud configurations exposing information in thousands of legitimate iOS and Android apps (you can read more about it in our blog). This week, zLabs is warning Android users about a sophisticated new malicious app.
The new malware disguises itself as a System Update application, and is stealing data, messages, images and taking control of Android phones. Once in control, hackers can record audio and phone calls, take photos, review browser history, access WhatsApp messages, and more (a complete list is below).
https://blog.zimperium.com/new-advanced-android-malware-posing-as-system-update/
#android #malware #alert
📡@cRyPtHoN_INFOSEC_FR
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_DE
📡@BlackBox_Archiv
📡@NoGoolag
Another week, and another major mobile security risk. A few weeks ago, Zimperium zLabs researchers disclosed unsecured cloud configurations exposing information in thousands of legitimate iOS and Android apps (you can read more about it in our blog). This week, zLabs is warning Android users about a sophisticated new malicious app.
The new malware disguises itself as a System Update application, and is stealing data, messages, images and taking control of Android phones. Once in control, hackers can record audio and phone calls, take photos, review browser history, access WhatsApp messages, and more (a complete list is below).
https://blog.zimperium.com/new-advanced-android-malware-posing-as-system-update/
#android #malware #alert
📡@cRyPtHoN_INFOSEC_FR
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_DE
📡@BlackBox_Archiv
📡@NoGoolag
Zimperium
New Advanced Android Malware Posing as “System Update" - Zimperium
Another week, and another major mobile security risk. A few weeks ago, Zimperium zLabs researchers disclosed unsecured cloud configurations exposing
Forwarded from App Manager | CHANNEL
We're now hitting a major release (v2.6.0). This is going to be the first long term supported release, i.e. this will be the first version of app manager to receive patches until the next stable release is made.
App Manager is something I made for myself and never really thought that it would reach so much audiences. Now, I can feel that there are many people like me who were waiting for an app that would help them replace privacy invading, non-free apps as well as help those who're suffering from the guilt of using cracked software. The development of App Manager was so fast because I've spent a lot of time analysing other not-so-usable and, often abandoned projects which has given me insights on how to implement such features. I'm also working very hard to ensure security of the data because a rooting app itself is never fully secured (and you're welcome to find any security issues!).
Therefore, it's time to change the name of the app to something special so that it can be uniquely identified (the package name will still be the same though and the old repository will be redirected to the new one).
The best name will be chosen based on the apps functions and/or creativity, and the person will be credited in the about section!
Post your ideas here: https://github.com/MuntashirAkon/AppManager/issues/339
App Manager is something I made for myself and never really thought that it would reach so much audiences. Now, I can feel that there are many people like me who were waiting for an app that would help them replace privacy invading, non-free apps as well as help those who're suffering from the guilt of using cracked software. The development of App Manager was so fast because I've spent a lot of time analysing other not-so-usable and, often abandoned projects which has given me insights on how to implement such features. I'm also working very hard to ensure security of the data because a rooting app itself is never fully secured (and you're welcome to find any security issues!).
Therefore, it's time to change the name of the app to something special so that it can be uniquely identified (the package name will still be the same though and the old repository will be redirected to the new one).
The best name will be chosen based on the apps functions and/or creativity, and the person will be credited in the about section!
Post your ideas here: https://github.com/MuntashirAkon/AppManager/issues/339
https://twitter.com/XploitWizer/status/1376101628986630151
https://twitter.com/indyan/status/1376487300578766852
https://twitter.com/XploitWizer/status/1376101628986630151
https://twitter.com/indyan/status/1376487300578766852
Twitter
XploitWizer
https://t.co/D0zx8Y548Q Data Leak - 2021 Mobikwik has suffered a data breach which has exposed 99Million Indian Users details of total 8TB data which includes: • Email • Phone • Aadhar Card • Pan Card • Debit/Credit Card • Other KYC document Kindly change…
Forwarded from The Hacker News
A set of new vulnerabilities in Linux-based operating systems could allow attackers to bypass mitigations for speculative attacks like Spectre and obtain sensitive information from kernel memory.
Read details: https://thehackernews.com/2021/03/new-bugs-could-let-hackers-bypass.html
Read details: https://thehackernews.com/2021/03/new-bugs-could-let-hackers-bypass.html
The Hacker News
New Bugs Could Let Hackers Bypass Spectre Attack Mitigations On Linux Systems
New Linux Bug Could Let Attackers Bypass Spectre Side-Channel Attack Mitigations
James Corbett Interview - COVID-19 Censorship, Technocracy & The…
The Last American Vagabond: James Corbett Interview – COVID-19 Censorship, Technocracy & The Amazing Country Of Digital Gulag
Joining me today is James Corbett, here to discuss his recent censorship as well as ‘Digital Gulag’ being built around us, and the importance of why we must act now, today, in order to stop this rising technocratic state.
https://www.thelastamericanvagabond.com/james-corbett-interview-covid-19-censorship-technocracy-the-amazing-country-of-digital-gulag/
Mp3 download link
https://media.blubrry.com/last_american_vagabond/content.blubrry.com/last_american_vagabond/James_Corbett_Interview-COVID-19_Censorship_Technocracy_The_Amazing_Country_Of_Digital_Gulag-FINAL.mp3
#censorship #goolag #patreon #youtube
Joining me today is James Corbett, here to discuss his recent censorship as well as ‘Digital Gulag’ being built around us, and the importance of why we must act now, today, in order to stop this rising technocratic state.
https://www.thelastamericanvagabond.com/james-corbett-interview-covid-19-censorship-technocracy-the-amazing-country-of-digital-gulag/
Mp3 download link
https://media.blubrry.com/last_american_vagabond/content.blubrry.com/last_american_vagabond/James_Corbett_Interview-COVID-19_Censorship_Technocracy_The_Amazing_Country_Of_Digital_Gulag-FINAL.mp3
#censorship #goolag #patreon #youtube
Amazon started a Twitter war because Jeff Bezos was pissed
Snarky tweets targeting Senators Bernie Sanders and Elizabeth Warren came after the CEO told execs they weren’t pushing back hard enough on critics.
https://www.vox.com/recode/2021/3/28/22354604/amazon-twitter-bernie-sanders-jeff-bezos-union-alabama-elizabeth-warren
#amazon
Snarky tweets targeting Senators Bernie Sanders and Elizabeth Warren came after the CEO told execs they weren’t pushing back hard enough on critics.
https://www.vox.com/recode/2021/3/28/22354604/amazon-twitter-bernie-sanders-jeff-bezos-union-alabama-elizabeth-warren
#amazon
Vox
Amazon started a Twitter war because Jeff Bezos was pissed
Snarky tweets targeting Sens. Bernie Sanders and Elizabeth Warren came after the CEO told executives they weren’t pushing back hard enough on critics.
Forwarded from Rahul Patel
AuroraStore_Insecure_Anonymous.apk
5.3 MB
Hi all,
On public demand I added an optional
Which basically allows you to generate GSF ID on your own device rather than the dispenser server.
This would allow you to get apps & listing from your own country, similar to v3 and also opens up bridge for
The new preference is located at
Make sure you relogin & restart Aurora Store to apply these changes. Test it & let me know if it works fine for you.
Also, stop sending me bulk messages & emails 😒, you want something just create a Gitlab issue.
Enjoy!
@AuroraSupport
On public demand I added an optional
Insecure anonymous session, disabled by default.Which basically allows you to generate GSF ID on your own device rather than the dispenser server.
This would allow you to get apps & listing from your own country, similar to v3 and also opens up bridge for
Geo-Spoofing The new preference is located at
Settings > Networking > Insecure anonymous session
To apply geo-spoofing just use a VPN and set location for where ever you want to geo-spoof.Make sure you relogin & restart Aurora Store to apply these changes. Test it & let me know if it works fine for you.
Also, stop sending me bulk messages & emails 😒, you want something just create a Gitlab issue.
Enjoy!
@AuroraSupport
15 years ago, I co-led a team trying to give 100% free Internet access to all of San Francisco starting with the poorest neighborhoods first. The network would be anonymous, with no ads, no cookies, etc. Approximately a $20-25 million gift. The result? We were chased out of town.
https://threadreaderapp.com/thread/1375962440303661057.html
Noglu:
Nice story! Oddly Sacca only ever tells half the story. What he forgets to mention is that he wanted to realise this free internet access in 2007 with the support of Google. In return, Google demanded full legal control over the City's public utility and power poles. Furthermore, Google demanded that there should be no possibility for the users of this free access to refuse to hand over personal data. You can read about this in detail here.
https://web.archive.org/web/20091009152536/http://www.sfgov.org/site/budanalyst_page.asp?id=53280
Noglu:
It's interesting, but it doesn't seem as sinister as it sounds. The report mentions several things about privacy it had already negotiated with Google at that time
Though I only searched for google and read the sorrounding sections, I ain't gonna read this entire giant-ass document at this time of the night
#sf #usa #gov #why #freeinternet
https://threadreaderapp.com/thread/1375962440303661057.html
Noglu:
Nice story! Oddly Sacca only ever tells half the story. What he forgets to mention is that he wanted to realise this free internet access in 2007 with the support of Google. In return, Google demanded full legal control over the City's public utility and power poles. Furthermore, Google demanded that there should be no possibility for the users of this free access to refuse to hand over personal data. You can read about this in detail here.
https://web.archive.org/web/20091009152536/http://www.sfgov.org/site/budanalyst_page.asp?id=53280
Noglu:
It's interesting, but it doesn't seem as sinister as it sounds. The report mentions several things about privacy it had already negotiated with Google at that time
Though I only searched for google and read the sorrounding sections, I ain't gonna read this entire giant-ass document at this time of the night
#sf #usa #gov #why #freeinternet
Threadreaderapp
Thread by @sacca on Thread Reader App
Thread by @sacca: 15 years ago, I co-led a team trying to give 100% free Internet access to all of San Francisco starting with the poorest neighborhoods first. The network would be anonymous, with no ads, no cookies...…
Forwarded from BlackBox (Security) Archiv
Ban Surveillance Advertising
As leaders across a broad range of issues and industries, we are united in our concern for the safety of our communities and the health of democracy. Social media giants are eroding our consensus reality and threatening public safety in service of a toxic, extractive business model. That’s why we’re joining forces in an effort to ban surveillance advertising.
Surveillance advertising – the core profit-driver for gatekeepers like Facebook and Google, as well as adtech middlemen – is the practice of extensively tracking and profiling individuals and groups, and then microtargeting ads at them based on their behavioral history, relationships, and identity.
These dominant firms curate the content each person sees on their platforms using those dossiers – not just the ads, but newsfeeds, recommendations, trends, and so forth – to keep each user hooked, so they can be served more ads and mined for more data.
Big Tech platforms amplify hate, illegal activities, and conspiracism – and feed users increasingly extreme content – because that’s what generates the most engagement and profit. Their own algorithmic tools have boosted everything from white supremacist groups and Holocaust denialism to COVID-19 hoaxes, counterfeit opioids and fake cancer cures. Echo chambers, radicalization, and viral lies are features of these platforms, not bugs—central to the business model.
And surveillance advertising is further damaging the information ecosystem by starving the traditional news industry, especially local journalism. Facebook and Google’s monopoly power and data harvesting practices have given them an unfair advantage, allowing them to dominate the digital advertising market, siphoning up revenue that once kept local newspapers afloat. So while Big Tech CEOs get richer, journalists get laid off.
https://www.bansurveillanceadvertising.com/coalition-letter
#ban #surveillance #advertising #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_DE
📡@BlackBox_Archiv
📡@NoGoolag
As leaders across a broad range of issues and industries, we are united in our concern for the safety of our communities and the health of democracy. Social media giants are eroding our consensus reality and threatening public safety in service of a toxic, extractive business model. That’s why we’re joining forces in an effort to ban surveillance advertising.
Surveillance advertising – the core profit-driver for gatekeepers like Facebook and Google, as well as adtech middlemen – is the practice of extensively tracking and profiling individuals and groups, and then microtargeting ads at them based on their behavioral history, relationships, and identity.
These dominant firms curate the content each person sees on their platforms using those dossiers – not just the ads, but newsfeeds, recommendations, trends, and so forth – to keep each user hooked, so they can be served more ads and mined for more data.
Big Tech platforms amplify hate, illegal activities, and conspiracism – and feed users increasingly extreme content – because that’s what generates the most engagement and profit. Their own algorithmic tools have boosted everything from white supremacist groups and Holocaust denialism to COVID-19 hoaxes, counterfeit opioids and fake cancer cures. Echo chambers, radicalization, and viral lies are features of these platforms, not bugs—central to the business model.
And surveillance advertising is further damaging the information ecosystem by starving the traditional news industry, especially local journalism. Facebook and Google’s monopoly power and data harvesting practices have given them an unfair advantage, allowing them to dominate the digital advertising market, siphoning up revenue that once kept local newspapers afloat. So while Big Tech CEOs get richer, journalists get laid off.
https://www.bansurveillanceadvertising.com/coalition-letter
#ban #surveillance #advertising #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_DE
📡@BlackBox_Archiv
📡@NoGoolag
Bansurveillanceadvertising
Coalition Letter
Leaders across a broad range of issues and industries are united in our concern for the safety of our communities and the health of democracy.
#USA, Louis Rossman:
I'm crowdfunding a direct ballot initiative to bypass lobbyists/politicians & pass #Right to #Repair
https://www.youtube.com/watch?v=dWIF3ZRpf0I
I'm crowdfunding a direct ballot initiative to bypass lobbyists/politicians & pass #Right to #Repair
https://www.youtube.com/watch?v=dWIF3ZRpf0I
YouTube
I'm crowdfunding a direct ballot initiative to bypass lobbyists/politicians & pass Right to Repair
https://discord.gg/rossmanngroup
Let's get Right to Repair passed! https://gofund.me/1cba2545
https://www.gofundme.com/f/lets-get-right-to-repair-passed
If interested in donating outside of gofundme and wish to arrange bank transfer, check, etc, email me…
Let's get Right to Repair passed! https://gofund.me/1cba2545
https://www.gofundme.com/f/lets-get-right-to-repair-passed
If interested in donating outside of gofundme and wish to arrange bank transfer, check, etc, email me…
Forwarded from Hacker News
Electronic Frontier Foundation
Google Is Testing Its Controversial New Ad Targeting Tech in Millions of Browsers. Here’s What We Know.
Update, April 9, 2021 : We've launched Am I FLoCed, a new site that will tell you whether your Chrome browser has been turned into a guinea pig for Federated Learning of Cohorts or FLoC, Google’s
Forwarded from Hacker News
The Record
Google collects 20 times more telemetry from Android devices than Apple from iOS
Academic research published last week looked at the telemetry traffic sent by modern iOS and Android devices back to Apple and Google servers and found that Google collects around 20 times more telemetry data from Android devices than Apple from iOS.
Armv9: ARM Announces New Chip Architecture
Today, Arm introduced the Arm®v9 architecture in response to the global demand for ubiquitous specialized processing with increasingly capable security and artificial intelligence (AI). Armv9 is Arm's first new architecture in a decade, building on the success of Armv8, which today drives the best performance per watt
https://www.arm.com/company/news/2021/03/arms-answer-to-the-future-of-ai-armv9-architecture
#arm #armv9 #cpu #soc
Today, Arm introduced the Arm®v9 architecture in response to the global demand for ubiquitous specialized processing with increasingly capable security and artificial intelligence (AI). Armv9 is Arm's first new architecture in a decade, building on the success of Armv8, which today drives the best performance per watt
https://www.arm.com/company/news/2021/03/arms-answer-to-the-future-of-ai-armv9-architecture
#arm #armv9 #cpu #soc
Arm | The Architecture for the Digital World
Arm’s solution to the future needs of AI, security and specialized computing is v9
Arm introduced the Armv9 architecture in response to the global demand for ubiquitous specialized processing with increasingly capable security and artificial intelligence (AI).
Forwarded from BlackBox (Security) Archiv
What the hell is happening with Android One?
Google's once-pivotal program for exceptional yet affordable Android phones seems to be fading — and maybe for good reason.
Not long ago, a low-profile program called Android One looked like it could be just the one-two punch Android needed.
Android One, like lots of Google initiatives, has had a long and winding history with plenty of twists and turns. When Android One first came into the picture in 2014, it was described as an effort to "make high-quality smartphones accessible to as many people as possible." The focus was squarely on bringing affordable phones with exceptional experiences to emerging markets — places like Pakistan and India, where it could be "hard for people" to "get their hands on a high-quality smartphone," as Google put it at the time.
But that was just the start of Google's Android One ambitions. Three years later, in 2017, Google expanded the program with the launch of Android One phones in places like Japan, Taiwan, and eventually the United States. The company changed its description of the effort from that original small-scale focus to the much broader vision of a "collaboration between Google and [its] partners to deliver a software experience designed by Google," with a guarantee of reasonably timely ongoing operating system updates and an experience that'd be free from all the bloat and shenanigans baked into so many Android products.
http://telegra.ph/What-the-hell-is-happening-with-Android-One-03-31-2
via www.computerworld.com
#google #android1 #thinkabout
📡 @nogoolag @blackbox_archiv
Google's once-pivotal program for exceptional yet affordable Android phones seems to be fading — and maybe for good reason.
Not long ago, a low-profile program called Android One looked like it could be just the one-two punch Android needed.
Android One, like lots of Google initiatives, has had a long and winding history with plenty of twists and turns. When Android One first came into the picture in 2014, it was described as an effort to "make high-quality smartphones accessible to as many people as possible." The focus was squarely on bringing affordable phones with exceptional experiences to emerging markets — places like Pakistan and India, where it could be "hard for people" to "get their hands on a high-quality smartphone," as Google put it at the time.
But that was just the start of Google's Android One ambitions. Three years later, in 2017, Google expanded the program with the launch of Android One phones in places like Japan, Taiwan, and eventually the United States. The company changed its description of the effort from that original small-scale focus to the much broader vision of a "collaboration between Google and [its] partners to deliver a software experience designed by Google," with a guarantee of reasonably timely ongoing operating system updates and an experience that'd be free from all the bloat and shenanigans baked into so many Android products.
http://telegra.ph/What-the-hell-is-happening-with-Android-One-03-31-2
via www.computerworld.com
#google #android1 #thinkabout
📡 @nogoolag @blackbox_archiv
Telegraph
What the hell is happening with Android One?
Not long ago, a low-profile program called Android One looked like it could be just the one-two punch Android needed. Android One, like lots of Google initiatives, has had a long and winding history with plenty of twists and turns. When Android One first…
Forwarded from BlackBox (Security) Archiv
apple_google.pdf
1.4 MB
Mobile Handset Privacy: Measuring The Data iOS and Android Send to Apple And Google
We find that even when minimally configured and the handset is idle both iOS and Google Android share data with Apple/Google on average every 4.5 mins.
‼️ The phone IMEI, hardware serial number, SIM serial number and IMSI, handsetphone number etc are shared with Apple and Google. Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this.
💡 When a SIM is inserted both iOS and Google Android send details to Apple/Google. iOS sends the MAC addresses of nearby devices, e.g. other handsets and the home gateway, to Apple together with their GPS location. Currently there are few, if any, realistic options for preventing this data sharing.
https://www.scss.tcd.ie/doug.leith/apple_google.pdf
#apple #google #study #telemetry #data #mobilephones #pdf
📡 @nogoolag @blackbox_archiv
We find that even when minimally configured and the handset is idle both iOS and Google Android share data with Apple/Google on average every 4.5 mins.
‼️ The phone IMEI, hardware serial number, SIM serial number and IMSI, handsetphone number etc are shared with Apple and Google. Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this.
💡 When a SIM is inserted both iOS and Google Android send details to Apple/Google. iOS sends the MAC addresses of nearby devices, e.g. other handsets and the home gateway, to Apple together with their GPS location. Currently there are few, if any, realistic options for preventing this data sharing.
https://www.scss.tcd.ie/doug.leith/apple_google.pdf
#apple #google #study #telemetry #data #mobilephones #pdf
📡 @nogoolag @blackbox_archiv
This media is not supported in your browser
VIEW IN TELEGRAM
If You Care About Privacy, It’s Time to Try a New Web Browser
A new crop of internet browsers from Brave, DuckDuckGo and others offer stronger privacy protections than what you might be used to.
Most of us use web browsers out of habit.
If you surf the web with Microsoft Edge, that may be because you use Windows. If you use Safari, that’s probably because you are an Apple customer. If you are a Chrome user, that could be because you have a Google phone or laptop, or you downloaded the Google browser on your personal device after using it on computers at school or work.
https://www.nytimes.com/2021/03/31/technology/personaltech/online-privacy-private-browsers.html
#online #privacy #browsers #thinkabout
📡 @nogoolag @blackbox_archiv
A new crop of internet browsers from Brave, DuckDuckGo and others offer stronger privacy protections than what you might be used to.
Most of us use web browsers out of habit.
If you surf the web with Microsoft Edge, that may be because you use Windows. If you use Safari, that’s probably because you are an Apple customer. If you are a Chrome user, that could be because you have a Google phone or laptop, or you downloaded the Google browser on your personal device after using it on computers at school or work.
https://www.nytimes.com/2021/03/31/technology/personaltech/online-privacy-private-browsers.html
#online #privacy #browsers #thinkabout
📡 @nogoolag @blackbox_archiv