Privacy + Secure Tech Corner Channel πŸ›‘οΈ
90 subscribers
6.66K photos
579 videos
530 files
16.1K links
Here you can find all about GSI's, ROM's, GKI Kernel's, Tech NEWS, Updates, Root methods, Magisk Module, Overlay's, Hacker things, FLOSS, FOSS, Privacy + Secure Stuff and many more!
Download Telegram
Forwarded from The Hacker News
🚨 Critical bugs in HPE StoreOnce | 9.8 CVSS flaw allows auth bypass + RCE as root.

πŸ‘€ One bug (CVE-2025-37093) lets attackers skip loginβ€”then chain others for full takeover.

Patch now if you're running pre-4.3.11 versions.

πŸ”— Full details: https://thehackernews.com/2025/06/hpe-issues-security-patch-for-storeonce.html
Forwarded from The Hacker News
🚨 New wave of supply chain attacks hits npm, PyPI & RubyGems.

Hackers are hiding malware in popular open-source packages to:

πŸ”» Steal crypto wallets
πŸ—‘οΈ Delete entire codebases
πŸ•΅οΈ Exfiltrate Telegram bot data

Full story & package list β†’ https://thehackernews.com/2025/06/malicious-pypi-npm-and-ruby-packages.html
Forwarded from Winaero
Facebook and Yandex used their Android apps to deanonymize users. They were found secretly bypassing user privacy tools like incognito mode and cookie-clearing features on Android devices. They used hidden communication links between mobile apps (e.g., Facebook, Instagram, Yandex Maps) and browsers to track users by linking browser activity with device identifiers like Facebook accounts or Android Advertising IDs. This allowed them to identify users even in incognito mode or after deleting cookies. Additionally, open network ports created risks for malicious apps to exploit user data.

Chrome blocked the exploited WebRTC feature on May 17, prompting Meta to stop using localhost requests in Facebook Pixel scripts. Yandex had been using similar methods since 2017. These techniques worked in Chrome, Edge, and partially in Firefox but were blocked or restricted in DuckDuckGo and Brave. To prevent such abuses, new specifications like PNA and LNA are being developed to enhance private network security.
No deleted account found from 54 scanned users from this group πŸš«πŸ‘»
Forwarded from The Hacker News
🚨 70% of data leaks now happen in-browser.

Legacy DLP tools can’t see what your employees are copy-pasting into AI tools, Slack, or Gmail.

The browser is the new security perimeter.

Read why browser-centric DLP is now a must β†’ https://thehackernews.com/2025/06/your-saas-data-isnt-safe-why.html
Forwarded from The Hacker News
🚨 New Chaos RAT variant targets Linux & Windows users

Masquerading as a Linux network tool, the malware spreads via phishing to deploy crypto miners, steal data, and gain full device control.

πŸ”— Full report: https://thehackernews.com/2025/06/chaos-rat-malware-targets-windows-and.html
Forwarded from The Hacker News
Do you know how and where AI is running in your org? That customer service agent isn't just an LLMβ€”it's system prompts, tool calls, RAG data, user logs, and MCP servers.

Every untracked component = a breach waiting to happen.

Why AI asset sprawl goes way beyond model discovery β†’ https://thn.news/ai-assets-sprawl
Forwarded from The Hacker News
🚨 Google warns: Fake IT calls breaching Salesforce accounts.

Hackers from UNC6040 trick staff into approving a malicious β€œData Loader” app to steal data.

πŸ”— Learn how the scam works: https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html
πŸ“΄ Here's how Android 16 QPR1 may let you double tap your Pixel's screen to turn it off

I previously reported that Google is working on a double tap screen off gesture. Google is still working on this, and they've now added settings.

More detailsπŸ‘‡

πŸ”— https://www.androidauthority.com/double-tap-to-turn-off-pixel-screen-android-16-qpr1-3563905/
πŸ“ΉI made 25 videos using Google’s Veo 3. Here’s how it went.

Veo 3 certainly isn't perfect, but it's crazy how easy it is to produce insanely realistic looking videos of people and animals in unreal scenarios!

Check out the videos I madeπŸ‘‡

πŸ”— https://www.androidauthority.com/ai-videos-made-by-veo-3-3563271/
Here's another look at Android 16 QPR1's upcoming 'Ambient AOD' feature that brings your wallpaper to the always-on display!

You can activate this feature in Android 16 QPR1 Beta 1, but I don't recommend it because it's buggy (causes screen flickering on the AOD) and is likely intended for the Pixel 10 series!

πŸ“ΉFIRST LOOK: Always-On Display wallpapers for Pixel coming to Android 16!
GreaseMilkyway

GreaseMilkyway is an Android accessibility service designed to help people with attention-related conditions (such as ADHD) manage their digital environment. By allowing users to block distracting content in apps, it helps create a more focused and less overwhelming digital experience.

πŸ”— Links:
- Download
- Screenshots
- Features
- Purpose
- Source code
Developer: Konrad Kollnig

πŸ«‚ Special thanks to @nachonekoneko for recommending!

❀️ Support the Project

If this project makes your life easier, here are a few quick ways to show some love:

⭐ Star the repo/app
β˜• Buy a coffee for the developer
πŸ›  Contribute code, issues, or pull-requests


🏷 Tags:  #Android #Productivity
Emoji Kitchen

A standalone Android app for Emoji Kitchen that doesn't need Gboard.

πŸ”— Links:
- Download
- Demo video
- Source code
Developer: jeeneo

❀️ Support the Project

If this project makes your life easier, here are a few quick ways to show some love:

⭐ Star the repo/app
β˜• Buy a coffee for the developer
πŸ›  Contribute code, issues, or pull-requests


🏷 Tags:  #Android #Utilities
Android 16 QPR1 Beta 1.1 is rolling out!

It has the build ID BP31.250502.008.A1 and the following bug fixes:

* Fixed an issue where the navigation buttons would become unresponsive in the app drawer or task switcher (Issue #418395419)
* Fixed an issue where the progress bar in the media player on the lock screen doesn't reflect the place in media (Issue #419142109)
* Fixed a crash when trying to open effects in wallpaper (Issue #419063857)
* Fixed an issue where the settings app would crash after trying to open the battery menu (Issue #419125330)
* Fixed an issue where the lock screen date could get cut off when using a wide clock style (Issue #419145518)
* Fixed an issue where the search button has a different color when scrolling (Issue #419130323)
* Fixed an issue where the approve button in Device Admin settings is missing (Issue #419144521)
* Fixed an issue where dark album labels appeared in the photo picker when in dark mode, impacting readability (Issue #419159231)
* Fixed an issue where the date wasn't appearing on the homescreen
* Fixed a fingerprint authentication failure on a multi-user Android device in certain low-power conditions
Media is too big
VIEW IN TELEGRAM
⚑️Apple’s Siri Listens To Your Drug Deals and Sex Life

Apple just settled a $95M lawsuit after a whistleblower revealed Siri was recording private convosβ€”think drug deals, medical info, even sexβ€”without consent. 😳

You can’t delete Siri. You can’t remove it. And turning it off? Doesn’t always mean it’s off.

⚠️ If you’ve used a Siri-enabled device since 2014, you might qualify for the class-action.

πŸ‘‰ Full story + solutions on Substack.

Watch the full episode
Follow the #TBOT Show
Get privacy gear!