Privacy + Secure Tech Corner Channel 🛡️
90 subscribers
6.66K photos
584 videos
550 files
16.2K links
Here you can find all about GSI's, ROM's, GKI Kernel's, Tech NEWS, Updates, Root methods, Magisk Module, Overlay's, Hacker things, FLOSS, FOSS, Privacy + Secure Stuff and many more!
Download Telegram
Forwarded from Treble GSI's | Privacy + Secure
AMD’s trusted execution environment blown wide open by new BadRAM attack
https://arstechnica.com/information-technology/2024/12/new-badram-attack-neuters-security-assurances-in-amd-epyc-processors/

Attack bypasses AMD protection promising security, even when a server is compromised.
Google is rolling out the Identity Check feature it announced last week.

When Identity Check is enabled, biometric authentication will be required for sensitive actions like:

- Accessing saved passkeys and app passwords
- Changing the PIN, pattern, or password, and turning off Find My Device

...whenever your phone is in an untrusted location. This makes it harder for someone to compromise your Google Account. Turning off the feature requires either your biometrics or your Google Account and can only be done when your phone has Internet access.

Identity Check works on Android 15 and later and is available through a beta version of Google Play Services.

Thanks to Matthew Rawling on my Telegram group for the screenshots!
The November 2024 Google Play System Update adds support for letting you see the past 7-days worth of permission access data through Android's Privacy Dashboard, as reported by 9to5Google.

This is already enabled in Android 16 DP1, but as I mentioned before, Google originally planned for this feature to roll out in Android 13.
Forwarded from NoGoolag
ISO 20022: The New Language Of Payments (Digital Currency Scheme Goes Live Nov. 2025)

In October, 2021, the Fed spread the word that all Fed banks are going to implement the ISO 20022 system for Fedwire Funds Service (FFS). In July, 2023, they launched FedNow, a precursor to CBDCs for us every day working Americans.

Curiously enough, Ripple's blockchain-based payments (XRP) were already compliant with ISO 20022 before the Fed made their announcement as tweeted by Ripple's senior vice president of product, Asheesh Birla in 2020.

HSBC will be delivering a series of high value major payment scheme migrations to achieve full ISO 20022 compliance by November 2025, when the existing payment format will be discontinued.

Payment Market infrastructures (PMIs) of all major currencies are either live or in the process of adopting ISO 20022 by November 2025 for cross border payments.Adoption plans are still evolving in each market and further clarity will be provided over time.


Things are moving real fast.

SOURCE
Forwarded from The Hacker News
🔥 Critical Security Alert! Ivanti uncovers a CVSS 10.0-rated vulnerability allowing unauthenticated attackers to gain admin access in their Cloud Services Application.

This flaw isn’t alone—Ivanti has patched multiple critical vulnerabilities in its Connect Secure and CSA products.

🔗 Don't wait—explore the critical details and ensure your systems are secure: https://thehackernews.com/2024/12/ivanti-issues-critical-security-updates.html
Forwarded from The Hacker News
U.S. has unsealed charges against a Chinese hacker for exploiting a zero-day #vulnerability in 81,000 Sophos firewalls, enabling the infiltration of critical systems, the theft of sensitive data, and targeting U.S. infrastructure.

Learn more: https://thehackernews.com/2024/12/us-charges-chinese-hacker-for.html
Forwarded from The Hacker News
💻 Microsoft’s final Patch Tuesday of 2024 fixed 72 vulnerabilities, including one actively exploited in the wild: CVE-2024-49138.

Ensure your systems are updated now.

🔗 Read more: https://thehackernews.com/2024/12/microsoft-fixes-72-flaws-including.html
Forwarded from The Hacker News
Discover how Zero Trust, immutable backups, and encryption can secure Microsoft365—starting with Zero Trust, where every access request is verified.

Learn key strategies to protect your environment.

Read the full article now: https://thehackernews.com/expert-insights/2024/12/5-strategies-to-combat-ransomware-and.html
Forwarded from The Hacker News
🚨 A new surveillance tool, EagleMsgSpy, has been exposed as a powerful spyware linked to Chinese police departments, secretly collecting vast data from mobile devices since 2017.

🔗 Read full details here: https://thehackernews.com/2024/12/chinese-eaglemsgspy-spyware-found.html
Forwarded from The Hacker News
🔒 ZLoader #malware is back—with a stealthy upgrade. The latest version employs DNS tunneling for encrypted communication, raising the stakes for detection efforts.

This isn’t just an update; ZLoader now includes an interactive shell capable of executing over a dozen commands, a game-changer for #ransomware attacks.

Dive into the details. https://thehackernews.com/2024/12/zloader-malware-returns-with-dns.html
Forwarded from The Hacker News
🚨 A security flaw, dubbed AuthQuake, in Microsoft’s Multi-Factor Authentication (MFA) allowed attackers to bypass protection within an hour – no alerts, no interaction required.

Get the full story here: https://thehackernews.com/2024/12/microsoft-mfa-authquake-flaw-enabled.html