Agregátor RSS

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News - 22 Srpen, 2026 - 16:32
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million "upon entry of an order vacating a prior consent decree entered against
Kategorie: Hacking & Security

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News - 22 Srpen, 2026 - 16:32
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million "upon entry of an order vacating a prior consent decree entered against Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers infect Android car head units with proxy botnet malware

Bleeping Computer - 22 Srpen, 2026 - 16:14
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
Kategorie: Hacking & Security

Po Českých drahách testuje 3D tisk i U.S. Navy. Na vrtulníkové lodi vytiskli 12 dronů a 1000 náhradních dílů

Živě.cz - 22 Srpen, 2026 - 15:56
Námořnictvo má odjakživa problémy se zásobováním. Lodě, které operují dlouhé týdny a měsíce na světových oceánech se po nějakém čase chtě nechtě musejí vrátit domů. S nástupem skladného 3D tisku v posledních dekádách se teď ale nejspíše blýská na lepší časy. Pracuje na tom i americká společnost ...
Kategorie: IT News

Named Pipes Under Attack: Securing Windows Interprocess Communication

Bleeping Computer - 22 Srpen, 2026 - 15:00
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]
Kategorie: Hacking & Security

Lidl zavede Cvak – platební metodu, kterou chtějí Češi obejít platební karty

Živě.cz - 22 Srpen, 2026 - 13:45
Poprvé jsme o službě Cvak slyšeli v prosinci 2023 a znělo to skvěle – platba mobilem, která funguje na bázi přenosu z účtu na účet (Account-to-Account) bez nutnosti použít platební kartu. Výhodou je nižší provize, než požadují velké karetní společnosti. Na straně obchodníka není terminál, ale karta ...
Kategorie: IT News

eBPF Security Is Moving Beyond the Kernel Verifier

LinuxSecurity.com - 22 Srpen, 2026 - 02:05
eBPF security is often summarized in one sentence: Linux loads an eBPF program only after the kernel verifier accepts it under the safety checks the verifier performs. That description is useful, but it covers only one part of a larger system.
Kategorie: Hacking & Security

Kata Containers Flaw Weakens Container Security With Host-Chosen Mounts

LinuxSecurity.com - 22 Srpen, 2026 - 01:40
A flaw in Kata Containers weakened container security in some Confidential Containers deployments. It allowed a malicious host operator to make the protected guest use attacker-chosen files or content at approved mount locations.
Kategorie: Hacking & Security

Kata Containers Flaw Weakens Container Security With Host-Chosen Mounts

LinuxSecurity.com - 22 Srpen, 2026 - 01:40
A flaw in Kata Containers weakened container security in some Confidential Containers deployments. It allowed a malicious host operator to make the protected guest use attacker-chosen files or content at approved mount locations.
Kategorie: Hacking & Security

KVM’s TDX Control-Plane Blind Spot: When “Enabled” Does Not Mean Enforced

LinuxSecurity.com - 22 Srpen, 2026 - 00:50
Recent KVM work exposed a gap between what Linux says a TDX protection supports and what the TDX-specific code actually enforces.
Kategorie: Hacking & Security

this is a test

Kurzweil AI - 15 Červenec, 2026 - 23:45
this is some typing
Kategorie: Transhumanismus

Bypassing Windows Administrator Protection

Project Zero - 26 Leden, 2026 - 10:00
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary. This blog post will give a brief overview of the new feature, how it works and how it’s different from UAC. I’ll then describe some of the security research I undertook while it was in the insider preview builds on Windows 11. Finally I’ll detail one of the nine separate vulnerabilities that I found to bypass the feature to silently gain full administrator privileges. All the issues that I reported to Microsoft have been fixed, either prior to the feature being officially released (in optional update KB5067036) or as subsequent security bulletins. Note: As of 1st December 2025 the Administrator Protection feature has been disabled by Microsoft while an application compatibility issue is dealt with. The issue is unlikely to be related to anything described in this blog post so the analysis doesn’t change.
Kategorie: Hacking & Security

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

Project Zero - 14 Leden, 2026 - 20:01
While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and exploiting these vulnerabilities highlighted some broader issues in the Android ecosystem. This post describes the problems we encountered and recommendations for improvement. Audio Attack Surface The Dolby UDC is part of the 0-click attack surface of most Android devices because of audio transcription in the Google Messages application. Incoming audio messages are transcribed before a user interacts with the message. On Pixel 9, a second process com.google.android.tts also decodes incoming audio. Its purpose is not completely clear, but it seems to be related to making incoming messages searchable.
Kategorie: Hacking & Security

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

Project Zero - 14 Leden, 2026 - 20:00
With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using my DriverCartographer tool, I discovered an interesting device driver, /dev/bigwave that was accessible from the mediacodec SELinux context. BigWave is hardware present on the Pixel SOC that accelerates AV1 decoding tasks, which explains why it is accessible from the mediacodec context. As previous research has copiously affirmed, Android drivers for hardware devices are prime places to find powerful local privilege escalation bugs. The BigWave driver was no exception - across a couple hours of auditing the code, I discovered three separate bugs, including one that was powerful enough to escape the mediacodec sandbox and get kernel arbitrary read/write on the Pixel 9.
Kategorie: Hacking & Security

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

Project Zero - 14 Leden, 2026 - 19:59
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user. One such feature is audio transcription. Incoming SMS and RCS audio attachments received by Google Messages are now automatically decoded with no user interaction. As a result, audio decoders are now in the 0-click attack surface of most Android phones. I’ve spent a fair bit of time investigating these decoders, first reporting CVE-2025-49415 in the Monkey’s Audio codec on Samsung devices. Based on this research, the team reviewed the Dolby Unified Decoder, and Ivan Fratric and I reported CVE-2025-54957. This vulnerability is likely in the 0-click attack surface of most Android devices in use today. In parallel, Seth Jenkins investigated a driver accessible from the sandbox the decoder runs in on a Pixel 9, and reported CVE-2025-36934.
Kategorie: Hacking & Security

Kniha kryptologie, šifrování a tajná písma v prodeji !

Security News - 12 Květen, 2025 - 14:00
KYBERCENTRUM vydalo knihu ceského kryptologa a popularizátora Pavla Vondrušky, která dokazuje, jak muže veda o kódech a šifrách být fascinující a dobrodružná.
Kniha byla v drívejším vydání v edici OKO zcela vyprodána a nebylo ji možné získat.
Nyní je tedy možnost ji zakoupit v e-shopu KYBERCENTRA. Ale pozor k prodeji touto cestou bylo uvolnen pouze omezený pocet 200 kusu .
Kategorie: Aktuality

Sháníte knihu : Kryptologie, šifrování a tajná písma ?

Security News - 12 Květen, 2025 - 14:00
Kniha p?edního ?eského popularizátora kryptologie dokazuje, jak fascinující a dobrodružná m?že v?da o kódech a šifrách být.
Kniha vyšla v 2006 v nákladu 8000 ks a byla brzy zcela vyprodána.
Kniha nyní vyjde pomocí Crowdfundingu v rámci projektu Centra kybernetické bezpe?nosti, z. ú. (KyberCentrum).
Podpo?te tento projekt a stanete se vlastníci této knihy.
Kategorie: Aktuality

Kryptologie, šifrování a tajná písma

Security News - 12 Květen, 2025 - 14:00
Kniha P.Vondrušky - Kryptologie, šifrování a tajná písma op?t vyjde.
Knihu lze získat v rámci projektu Kybercentra (Crowdfunding).
Kategorie: Aktuality
Syndikovat obsah