Stealing user credentials with evilginx
A malevolent mutation of the widely used nginx web server facilitates Adversary-in-the-Middle action, but there’s hope
Noindex workflow category for imported/news content.
A malevolent mutation of the widely used nginx web server facilitates Adversary-in-the-Middle action, but there’s hope
Sophos X-Ops uncovers a recent campaign from an Android RAT first seen in 2019 – now infecting users in Taiwan
You all already know the story about national security leaders, Signal, and The Atlantic by now. But to summarize in one sentence: a top U.S. official accidentally added the editor-in-chief of The Atlantic to a group chat on the secure messaging app Signal, and members of the group chat then discussed plans for striking Houthi…
This week we start with the bankruptcy of commercial DNA company 23andMe, and what it means for its users’ genetic data. Probably not good things! After the break, Joseph and Jason explain what ‘Dogequest’ is, and how people allegedly vandalizing Tesla locations have been caught. In the subscribers-only section, Emanuel tells us about some fake…
A newly introduced bill in Texas would require online sellers to show a photo ID before buying a dildo. SB 3003, introduced by Senator Angela Paxton (wife of Texas Attorney General Ken Paxton), would criminally charge online retailers for selling “an obscene device” without verifying the buyers’ age. Sellers would have to require customers to…
Over the weekend, AI-generated audio of vice president JD Vance saying Elon Musk is “cosplaying as a great American leader” who is making the administration “look bad” circulated widely on social media. On Sunday, Vance’s communications director William Martin said on X that “This audio is 100% fake and most certainly not the Vice President.”…
23andMe filed for Chapter 11 bankruptcy Sunday, leaving the fate of millions of people’s genetic information up in the air as the company deals with the legal and financial fallout of not properly protecting that genetic information in the first place. The filing shows how dangerous it is to provide your DNA directly to a…
‘Dogequest,’ the recently launched website which is doxing some Tesla owners and members of the Department of Government Efficiency (DOGE) and putting their personal information on a searchable map along with the location of Tesla charging stations, has published a version of its site on the dark web, potentially making it harder to shut down…
The Mozilla Foundation is calling upon 30 technology companies, social networks, and websites to block web scraping by an ICE surveillance contractor called ShadowDragon after 404 Media published a list of sites that the contractor pulls data from. “The thorniest concern here is the meticulous targeting such data enables—putting the lives of protesters, researchers, immigrants,…
This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss doxed Teslas, the concept of “amplification,” and how we’d much rather be looking at cooking videos than all this mess. EMANUEL: This week I published one of…