Skip Navigation
From Samsung to HTC: The worst Android phones ever made
  • 2 headphone jacks, SD card expansion, USB-C, a micro USB port and removable battery.

    Sounds overkill but sounds great to me.

    i really don't know how they would make other apps work with this though.

    Interesting to see if this design is better for one handed operations though.

  • can I opt out of credit agencies?
  • I don't think you can. A credit score and a credit report is what companies use to determine if you can get credit from them and at what terms.

    If you are in the USA, freeze your credit. So many data breaches happen to millions of people regularly. Be safe.

  • An IRC client for Android
  • Email is message exchange with a person or group of people. They can reply at any time.

    IRC is a chatroom. You go to it when you want to chat. A lot of software have support channels. You probably don't know most of these people. Unless you are saving them somehow, you don't have a history of the chat room.

    I've never used Matrix but it's a instant messaging protocol that allows voice and video.

  • Security News @infosec.pub IllNess @infosec.pub
    CISA Plan Aligns Cybersecurity Across Federal Agencies
    www.darkreading.com CISA Plan Aligns Cybersecurity Across Federal Agencies

    The FOCAL plan outlines baselines to synchronize cybersecurity priorities and policies across, as well as within, agencies.

    CISA Plan Aligns Cybersecurity Across Federal Agencies
    3
    Security News @infosec.pub IllNess @infosec.pub
    Global infostealer malware operation targets crypto users, gamers

    > The threat actors use a variety of distribution channels, including malvertising, spearphishing, and brand impersonation in online gaming, cryptocurrency, and software, to spread 50 malware payloads, including AMOS, Stealc, and Rhadamanthys.

    > Victims are lured into downloading malicious software by interacting with what they are tricked into believing are legitimate job opportunities or project collaborations.

    > On Windows, HijackLoader is used for delivering Stealc, a general-purpose lightweight info-stealer designed to collect data from browsers and crypto wallet apps, or Rhadamanthys, a more specialized stealer that targets a broad range of applications and data types.

    > When the target uses macOS, Marko Polo deploys Atomic ('AMOS'). This stealer launched in mid-2023, rented to cybercriminals for $1,000/month, allowing them to snatch various data stored in web browsers.

    0
    ‘It scared them off’, Kansas City shoppers report less crime thanks to security robot patrolling strip mall
  • I agree with you that it sucks and is horrible. I wish there were more laws to protect us.

    Everything I stated is just a quick summary of why these robot really don't do much for data collection and is more of a money saving matter to not hire more security personal.

  • ‘It scared them off’, Kansas City shoppers report less crime thanks to security robot patrolling strip mall
  • They are already data mining you without these robots.

    They use facial recognition on cameras. They use OCR on your license plate and scan your toll pass. They use your phone location if you connect to their "free" wifi. They track your bluetooth devices that's constantly looking to connect. They track you foot traffic and see what stores, what aisle, what product you picked it up and how long you had it in your hands.

    Google "Target loss prevention" stories of frequent shoplifters that had profiles on them for months and stop them when they can charge for grand larceny rather than petite larceny. There is a reason why Westfield malls are everywhere. It's easier for them to control their own data than to constantly buy or contract out data from other companies.

    These bots are probably getting more data but they are more for security. A moving camera is more of criminal deterrent just because it is moving. These bots are so they don't have to pay for more security guards than anything else.

  • Qualcomm approached Intel about acquisition, report claims
  • Intel is about 5 times the size of Qualcomm in terms of equity.

    i found this article:

    Intel's shares closed up 3.3%, while Qualcomm fell 2.9%. Qualcomm, with a market capitalization of $188 billion, is worth about twice as much as Intel.

    source

    So based on Intel's shitty stock price, Qualcomm can buy a good chunk of Intel which is enough for voting power I guess. Someone please correct me or add insight to this.

  • Security News @infosec.pub IllNess @infosec.pub
    Bug Left Some Windows PCs Dangerously Unpatched – Krebs on Security
    0
    Security News @infosec.pub IllNess @infosec.pub
    Transport for London staff faces systems disruptions after cyberattack

    >Transport for London, the city's public transportation agency, revealed today that its staff has limited access to systems and email due to measures implemented in response to a Sunday cyberattack.

    0
    Security News @infosec.pub IllNess @infosec.pub
    North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams
    thehackernews.com North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams

    North Korean hackers target developers via LinkedIn job scams, spreading malware to infiltrate Web3 and crypto firms.

    North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams

    >"After an initial chat conversation, the attacker sent a ZIP file that contained COVERTCATCH malware disguised as a Python coding challenge," researchers Robert Wallace, Blas Kojusner, and Joseph Dobson said.

    >The malware functions as a launchpad to compromise the target's macOS system by downloading a second-stage payload that establishes persistence via Launch Agents and Launch Daemons.

    0
    Car rental giant Avis discloses data breach impacting customers

    >American car rental giant Avis disclosed a data breach after attackers breached one of its business applications last month and stole customer personal information.

    1
    Security News @infosec.pub IllNess @infosec.pub
    Malvertising Campaign Phishes Lowe's Employees
    www.darkreading.com Malvertising Campaign Phishes Lowe's Employees

    Retail employees are being duped into divulging their credentials by typosquatting malvertisements.

    Malvertising Campaign Phishes Lowe's Employees
    0
    Security News @infosec.pub IllNess @infosec.pub
    Apache fixes critical OFBiz remote code execution vulnerability

    Tracked as CVE-2024-45195 and discovered by Rapid7 security researchers, this remote code execution flaw is caused by a forced browsing weakness that exposes restricted paths to unauthenticated direct request attacks.

    0
    Security News @infosec.pub IllNess @infosec.pub
    VMWare releases Fusion vulnerability with 8.8 rating
    cyberscoop.com VMWare releases Fusion vulnerability with 8.8 rating

    The company issued a patch for the high-severity bug that allows arbitrary code execution.

    VMWare releases Fusion vulnerability with 8.8 rating
    1
    Security News @infosec.pub IllNess @infosec.pub
    Hackers Use Fake GlobalProtect VPN Software in New WikiLoader Malware Attack
    thehackernews.com Hackers Use Fake GlobalProtect VPN Software in New WikiLoader Malware Attack

    Hackers are spoofing GlobalProtect VPN software using SEO poisoning to deliver WikiLoader malware in a new cyberattack.

    Hackers Use Fake GlobalProtect VPN Software in New WikiLoader Malware Attack

    >The malvertising activity, observed in June 2024, is a departure from previously observed tactics wherein the malware has been propagated via traditional phishing emails, Unit 42 researchers Mark Lim and Tom Marsden said.

    Definitions:

    Malvertising - Internet advertising whose real intention is to deliver malware to the PC when the ad is clicked.

    -wordnik

    0
    Security News @infosec.pub IllNess @infosec.pub
    FTC: Over $110 million lost to Bitcoin ATM scams in 2023

    >The U.S. Federal Trade Commission (FTC) has reported a massive increase in losses to Bitcoin ATM scams, nearly ten times the amount from 2020 and reaching over $110 million in 2023.

    >Bitcoin ATMs are typically located in convenience stores, gas stations, and other busy areas, but instead of dispensing cash like the traditional ATMs they resemble, they allow you to buy and sell cryptocurrency.

    7
    Security News @infosec.pub IllNess @infosec.pub
    New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access
    thehackernews.com New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access

    Eight vulnerabilities in Microsoft macOS apps allow attackers to bypass permissions, gaining unauthorized access to sensitive data.

    New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access
    1
    Security News @infosec.pub IllNess @infosec.pub
    New Rust-Based Ransomware Cicada3301 Targets Windows and Linux Systems
    thehackernews.com New Rust-Based Ransomware Cicada3301 Targets Windows and Linux Systems

    Cicada3301 ransomware targets SMBs, shares code with BlackCat, exploits vulnerabilities in Windows, Linux, and ESXi systems.

    New Rust-Based Ransomware Cicada3301 Targets Windows and Linux Systems

    > Written in Rust and capable of targeting both Windows and Linux/ESXi hosts, Cicada3301 first emerged in June 2024, inviting potential affiliates to join their ransomware-as-a-service (RaaS) platform via an advertisement on the RAMP underground forum.

    2
    Security News @infosec.pub IllNess @infosec.pub
    D-Link says it is not fixing four RCE flaws in DIR-846W routers

    >Though D-Link acknowledged the security problems and their severity, it noted that they fall under its standard end-of-life/end-of-support policies, meaning there will be no security updates to address them.

    0
    Security News @infosec.pub IllNess @infosec.pub
    Docker-OSX image used for security research hit by Apple DMCA takedown

    >The popular Docker-OSX project has been removed from Docker Hub after Apple filed a DMCA (Digital Millennium Copyright Act) takedown request, alleging that it violated its copyright.

    1
    Security News @infosec.pub IllNess @infosec.pub
    Researchers find SQL injection to bypass airport TSA security checks

    >Researchers Ian Carroll and Sam Curry discovered the vulnerability in FlyCASS, a third-party web-based service that some airlines use to manage the Known Crewmember (KCM) program and the Cockpit Access Security System (CASS). KCM is a Transportation Security Administration (TSA) initiative that allows pilots and flight attendants to skip security screening, and CASS enables authorized pilots to use jumpseats in cockpits when traveling.

    Definitions:

    SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution.

    -Wikipedia

    8
    Security News @infosec.pub IllNess @infosec.pub
    North Korean hackers exploit Chrome zero-day to deploy rootkit

    >North Korean hackers have exploited a recently patched Google Chrome zero-day (CVE-2024-7971) to deploy the FudModule rootkit after gaining SYSTEM privileges using a Windows Kernel exploit.

    >Citrine Sleet targets financial institutions, focusing on cryptocurrency organizations and associated individuals, and has been previously linked to Bureau 121 of North Korea's Reconnaissance General Bureau.

    2
    Security News @infosec.pub IllNess @infosec.pub
    Commercial Spyware Vendors Have a Copycat in Top Russian APT
    www.darkreading.com Commercial Spyware Vendors Have a Copycat in Top Russian APT

    Russia's Midnight Blizzard infected Mongolian government websites to try to compromise the devices of visitors, using watering-hole tactics.

    Commercial Spyware Vendors Have a Copycat in Top Russian APT

    >In the watering-hole attacks, threat actors infected two websites, cabinet.gov[.]mn and mfa.gov[.]mn, which belong to Mongolia's Cabinet and Ministry of Foreign Affairs. They then injected code to exploit known flaws in iOS and Chrome on Android, with the ultimate goal of hijacking website visitors' devices.

    Definitions:

    Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects one or more of them with malware. Eventually, some member of the targeted group will become infected.

    -Wikipedia

    Whereas zero-days are a class of vulnerability that is unknown to a software developer or hardware manufacturer, an N-day is a flaw that is already publicly known but may or may not have a security patch available.

    -Dark Reading

    0
    FBI: RansomHub ransomware breached 210 victims since February

    cross-posted from: https://infosec.pub/post/16863645

    > This relatively new ransomware-as-a-service (RaaS) operation extorts victims in exchange for not leaking stolen files and sells the documents to the highest bidder if negotiations fail. The ransomware group focuses on data-theft-based extortion rather than encrypting victims' files, although they were also identified as potential buyers of Knight ransomware source code. > > Since the start of the year, RansomHub has claimed responsibility for breaching American not-for-profit credit union Patelco, the Rite Aid drugstore chain, the Christie's auction house, and U.S. telecom provider Frontier Communications. Frontier Communications later warned over 750,000 customers their personal information was exposed in a data breach.

    0
    Security News @infosec.pub IllNess @infosec.pub
    FBI: RansomHub ransomware breached 210 victims since February

    This relatively new ransomware-as-a-service (RaaS) operation extorts victims in exchange for not leaking stolen files and sells the documents to the highest bidder if negotiations fail. The ransomware group focuses on data-theft-based extortion rather than encrypting victims' files, although they were also identified as potential buyers of Knight ransomware source code.

    Since the start of the year, RansomHub has claimed responsibility for breaching American not-for-profit credit union Patelco, the Rite Aid drugstore chain, the Christie's auction house, and U.S. telecom provider Frontier Communications. Frontier Communications later warned over 750,000 customers their personal information was exposed in a data breach.

    0
    InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)IL
    IllNess @infosec.pub
    Posts 115
    Comments 418