1
6

"Billions of people worldwide use private messaging platforms like Signal, WhatsApp, and iMessage to communicate securely. This is possible thanks to end-to-end encryption (E2EE), which ensures that only the sender and the intended recipient(s) can view the contents of a message, with no access possible for any third party, not even the service provider itself. Despite the widespread adoption of E2EE apps, including by government officials, and the role of encryption in safeguarding human rights, encryption, which can be lifesaving, is under attack around the world. These attacks most often come in the form of client-side scanning (CSS), which is already being pushed in the EU, UK, U.S., and Australia.

CSS involves scanning the photos, videos, and messages on an individual’s device against a database of known objectionable material, before the content is then sent onwards via an encrypted messaging platform. Before an individual uploads a file to an encrypted messaging window, it would be converted into a digital fingerprint, or “hash,” and compared against a database of digital fingerprints of prohibited material. Such a database could be housed on a person’s device, or at the server level.

Proponents of CSS argue that it is a privacy-respecting method of checking content in the interests of online safety, but as we explain in this FAQ piece, CSS undermines the privacy and security enabled by E2EE platforms. It is at odds with the principles of necessity and proportionality, and its implementation would erode the trustworthiness of E2EE channels; the most crucial tool we have for communicating securely and privately in a digital ecosystem dominated by trigger-happy surveillance."

https://www.accessnow.org/why-client-side-scanning-is-lose-lose-proposition/

#CyberSecurity #Encryption #ClientSideScanning #E2EE #Privacy #DataProtection #Surveillance

2
2

#ChatGPT creates phisher’s paradise by recommending the wrong URLs for major companies

https://www.theregister.com/2025/07/03/ai_phishing_websites/

#phishing #AI #cybersecurity

3
2

Local Privilege Escalation via chroot option

https://www.sudo.ws/security/advisories/chroot_bug/

#sudo #cybersecurity #Linux #FOSS

4
2

Could the aviation industry be the next big target for hacking groups like Scattered Spider? And if so, why?

That was the question I got from Lauren Baulch and the team at ITV News yesterday. See what I had to say here: https://www.itv.com/news/2025-07-03/could-airlines-be-the-new-target-for-hacking-group-scattered-spider

#cybersecurity #ransomware

5
2

#Grafana releases critical security update for #ImageRenderer plugin

https://www.bleepingcomputer.com/news/security/grafana-releases-critical-security-update-for-image-renderer-plugin/

#cybersecurity

6
2

#LetsEncrypt rolls out free security certs for IP addresses

https://www.theregister.com/2025/07/03/lets_encrypt_rolls_out_free/

#cybersecurity

7
2

#IdeaLab confirms data stolen in #ransomware attack last year

https://www.bleepingcomputer.com/news/security/idealab-confirms-data-stolen-in-ransomware-attack-last-year/

#cybersecurity #privacy #DataBreach

8
2

#HuntersInternational #ransomware shuts down, releases free decryptors

https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-shuts-down-after-world-leaks-rebrand/

#cybercrime #cybersecurity

9
3

Hacker with ‘political agenda’ stole data from #Columbia, university says

https://therecord.media/hacker-political-agenda-columbia-cyberattack

#cybersecurity #DataBreach #privacy #politics

10
2

A Group of Young Cybercriminals Poses the ‘Most Imminent Threat’ of Cyberattacks Right Now

https://www.wired.com/story/scattered-spider-most-imminent-threat/

#ScatteredSpider #cybercrime #ransomware #cybersecurity

11
8

#Ubuntu Disables #Spectre/#Meltdown Protections

https://www.schneier.com/blog/archives/2025/07/ubuntu-disables-spectre-meltdown-protections.html

#Linux #FOSS #cybersecurity

12
1

#NimDoor #crypto-theft #macOS #malware revives itself when killed

https://www.bleepingcomputer.com/news/security/nimdoor-crypto-theft-macos-malware-revives-itself-when-killed/

#cybersecurity

13
4

#DataBreach reveals #Catwatchful ‘#stalkerware’ is spying on thousands of phones

https://techcrunch.com/2025/07/02/data-breach-reveals-catwatchful-stalkerware-spying-on-thousands-android-phones/

#spyware #cybersecurity #privacy

14
2

#Cisco warns that #UnifiedCM has hardcoded root #SSH credentials

https://www.bleepingcomputer.com/news/security/cisco-removes-unified-cm-callManager-backdoor-root-account/

#cybersecurity

15
2

#Citrix warns of login issues after #NetScaler auth bypass patch

https://www.bleepingcomputer.com/news/security/citrix-warns-of-login-issues-after-netscaler-auth-bypass-patch/

#cybersecurity

16
3

#Qantas hack results in theft of 6 million passengers’ personal data

https://techcrunch.com/2025/07/02/qantas-hack-results-in-theft-of-6-million-passengers-personal-data/

#Australia #travel #cybersecurity #privacy #DataBreach #airlines

17
2

#Microsoft:# DNS issue blocks delivery of #Exchange Online #OTP codes

https://www.bleepingcomputer.com/news/microsoft/microsoft-links-dns-issue-to-exchange-online-otp-delivery-failures/

#cybersecurity #2FA

18
1

#Forminator plugin flaw exposes #WordPress sites to takeover attacks

https://www.bleepingcomputer.com/news/security/forminator-plugin-flaw-exposes-wordpress-sites-to-takeover-attacks/

#cybersecurity

19
5

#Google fixes fourth actively exploited #Chrome zero-day of 2025

https://www.bleepingcomputer.com/news/security/google-fixes-fourth-actively-exploited-chrome-zero-day-of-2025/

#cybersecurity

20
1

#Qantas discloses #cyberattack amid #ScatteredSpider #aviation breaches

https://www.bleepingcomputer.com/news/security/qantas-discloses-cyberattack-amid-scattered-spider-aviation-breaches/

#cybersecurity #travel

21
1

#ATT rolls out "Wireless Lock" feature to block #SIMswap attacks

https://www.bleepingcomputer.com/news/security/atandt-rolls-out-wireless-lock-feature-to-block-sim-swap-attacks/

#cybersecurity

22
1

#AezaGroup sanctioned for hosting #ransomware, #infostealer servers

https://www.bleepingcomputer.com/news/security/aeza-group-sanctioned-for-hosting-ransomware-infostealer-servers/

#Russia #malware #cybersecurity #politics

23
3

Senator Chides #FBI for Weak Advice on Mobile Security

https://krebsonsecurity.com/2025/06/senator-chides-fbi-for-weak-advice-on-mobile-security/

#cybersecurity

24
2

#Switzerland says government data stolen in #ransomware attack

https://www.bleepingcomputer.com/news/security/switzerland-says-government-data-stolen-in-ransomware-attack/

#cybersecurity #DataBreach #Radix #privacy

25
2

Over 1,200 #Citrix servers unpatched against critical auth bypass flaw

https://www.bleepingcomputer.com/news/security/over-1-200-citrix-servers-unpatched-against-critical-auth-bypass-flaw/

#cybersecurity

view more: next ›

Cybersecurity

2 readers
12 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS