<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/26/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>Microsoft wants AI to read your browser history &#x2014; but there's one reason not to worry</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-wants-ai-to-read-your-browser-history-%E2%80%94-but-theres-one-reason-not-to-worry-r29630/</link><description><![CDATA[<h3>
	A new feature in Edge will let you search your browser history with the assistance of AI.
</h3>

<p>
	A future update for <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/microsoft-edge" href="https://www.windowscentral.com/tag/microsoft-edge" rel="external nofollow">Microsoft Edge</a> will allow the browser to use <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/artificial-intelligence" href="https://www.windowscentral.com/tag/artificial-intelligence" rel="external nofollow">AI</a> to look through your browser history. The feature will make it possible to find sites you have visited even if you can't remember the exact URL, site name, or have a typo in your search query. It is also a feature many may want to disable right away.
</p>

<p>
	 
</p>

<p>
	It's important to note that AI-powered History search uses an on-device model. It's trained using your data, but that data never leaves your device and isn't sent to Microsoft. But some are leery of AI.
</p>

<p>
	 
</p>

<p>
	<a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/windows-11/windows-recall-general-availability-2025-copilot" href="https://www.windowscentral.com/software-apps/windows-11/windows-recall-general-availability-2025-copilot" rel="external nofollow">Windows Recall</a>, which passively captures screen activity, also keeps your data on your device and runs locally, but the feature has drawn criticism since its initial announcement. Microsoft had to <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/windows-11/microsoft-postpones-windows-recall-after-major-backlash-will-launch-copilot-pcs-without-headlining-ai-feature" href="https://www.windowscentral.com/software-apps/windows-11/microsoft-postpones-windows-recall-after-major-backlash-will-launch-copilot-pcs-without-headlining-ai-feature" rel="external nofollow">delay Recall</a> and add several security features in response to questions and concerns.
</p>

<p>
	 
</p>

<p>
	The new AI-powered History search could run into similar skepticism from users. Luckily, just like Recall, the new browser feature can be disabled. Admins can also control the feature through a policy.
</p>

<p>
	 
</p>

<p>
	AI-powered History search is in testing in Microsoft Edge version 138.0.3351.14, which is now in testing among Edge Beta.
</p>

<p>
	 
</p>

<p>
	That same update adds a media control center similar to the one found in <a data-analytics-id="inline-link" data-auto-tag-linker="true" data-before-rewrite-localise="https://www.windowscentral.com/tag/google-chrome" href="https://www.windowscentral.com/tag/google-chrome" rel="external nofollow">Google Chrome</a>. Microsoft outlines the changes in a set of <a data-analytics-id="inline-link" data-hl-processed="none" data-url="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-beta-channel" href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-beta-channel" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">release notes</a>.
</p>

<h3 class="article-body__section" id="section-feature-updates">
	<span>Feature Updates</span>
</h3>

<ul>
	<li>
		<strong>Use Primary work profile as default profile to open external links</strong>. Microsoft Edge currently opens external links using the “Last Used” profile by default. While for enterprise users, the Primary Work Profile (signed in with a Microsoft Entra ID for enrolling the device) is normally the best profile for opening external links. With this feature, for Windows, Edge will check if it the Primary Work Profile exists and make it the default profile for opening external links if available. For Mac and Linux, if only one work profile signed in with a Microsoft Entra ID account is found, it’s treated as the Primary Work Profile. Admins can control availability to this feature using the <a data-hl-processed="none" data-url="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/edgeopenexternallinkswithprimaryworkprofileenabled" href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/edgeopenexternallinkswithprimaryworkprofileenabled" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled</a> policy. <strong>Note:</strong> This is a controlled feature rollout. If you don't see this feature, check back as we continue our rollout.
	</li>
	<li>
		<strong>Media control center</strong>. With media control center in Microsoft Edge, users can easily manage and control multiple media sources from any website, all in one place. Quickly access videos in picture-in-picture mode, cast media to other devices, and control music, video, or any other sounds playing in Edge. Simply click on the media control center icon, depicted as a music note icon, found to the right of the address bar when media with sounds are playing to get started.
	</li>
	<li>
		<strong>New Autofill Personal Information Settings Configuration</strong>. A web form field collection consent toggle will be available in Autofill settings (edge://settings/autofill/personalInfo). This will allow users to consent to Microsoft Edge collecting web form field labels (e.g., "First Name," "Email") to improve Autofill suggestion accuracy. Only field labels are collected and not user-entered data. The web field labels are stored securely per Microsoft's <a data-hl-processed="none" data-url="https://www.microsoft.com/privacy/privacystatement" href="https://www.microsoft.com/privacy/privacystatement" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">privacy standards</a>.
	</li>
	<li>
		This new setting is manageable via existing policies in Autofill e.g., <a data-hl-processed="none" data-url="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/autofilladdressenabled" href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/autofilladdressenabled" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">AutofillAddressEnabled</a>, <a data-hl-processed="none" data-url="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/edgeautofillmlenabled" href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/edgeautofillmlenabled" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">EdgeAutofillMlEnabled</a>. <a data-hl-processed="none" data-url="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/autofilladdressenabled" href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/autofilladdressenabled" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">AutofillAddressEnabled</a> is the parent setting for EdgeAutofillMlEnabled. The EdgeAutofillMlEnabled policy is the parent of this new setting, thus turning off the <a data-hl-processed="none" data-url="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/autofilladdressenabled" href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/autofilladdressenabled" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">EdgeAutofillMlEnabled</a> policy will turn off this setting. <strong>Note:</strong> This feature is a controlled feature rollout. If you don't see this feature, check back as we continue our rollout.
	</li>
	<li>
		<strong>AI-powered History search</strong>. Enhanced search finds sites in your History even when you use a synonym, phrase, or typo. After this feature is turned on, sites you visit will be shown in enhanced history search results. An on-device model is trained using your data, which never leaves your device and is never sent to Microsoft. Admins can control availability to this feature using the <a data-hl-processed="none" data-url="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/edgehistoryaisearchenabled" href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/edgehistoryaisearchenabled" referrerpolicy="no-referrer-when-downgrade" target="_blank" rel="external nofollow">EdgeHistoryAISearchEnabled policy</a>. <strong>Note:</strong> This is a controlled feature rollout. If you don't see this feature, check back as we continue our rollout.
	</li>
	<li>
		<strong>Adding support for viewing Sensitivity labels applied to a Microsoft Information Protection (MIP) Protected PDF</strong>. Enterprise customers can view sensitivity labels applied to MIP protected PDF to be well informed of the data classification to enable them to handle such sensitive documents. This change is available in the new Microsoft Edge built-in PDF reader. <strong>Note:</strong> This is a controlled feature rollout. If you don't see this feature, check back as we continue our rollout.
	</li>
	<li>
		<strong>Microsoft 365 Copilot Chat Summarization in Microsoft Edge Context Menu</strong>. Microsoft Edge is introducing a Microsoft 365 Copilot Chat summarization menu item to our context menu. This feature will help users quickly unpack and ask questions about their open page. <strong>Note:</strong> This feature is a controlled feature rollout. If you don't see this feature, check back as we continue our rollout.
	</li>
	<li>
		<strong>Improvements to surfacing performance notifications</strong>. Microsoft Edge is making improvements to how users can learn about and improve their browser's responsiveness. Performance and Extensions Detector notifications may appear in the <strong>Settings and more menu</strong> when Edge's performance slows. <strong>Note:</strong> This feature is a controlled feature rollout. If you don't see this feature, check back as we continue our rollout.
	</li>
</ul>

<h2 id="running-ai-locally-3">
	Running AI locally
</h2>

<p>
	As <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/laptops/best-copilot-pc" href="https://www.windowscentral.com/hardware/laptops/best-copilot-pc" rel="external nofollow">Copilot+ PCs</a> with dedicated <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/what-is-npu-vs-gpu" href="https://www.windowscentral.com/hardware/what-is-npu-vs-gpu" rel="external nofollow">Neural Processing Units (NPUs)</a> become common, you should expect to see more AI features that run locally. There are also some AI features that can run on-device even if a PC lacks an NPU.
</p>

<p>
	 
</p>

<div id="slice-container-newsletterForm-articleInbodyContent-PDNp2GKsSjkbhwaBryYGb">
	<div data-hydrate="true">
		<p>
			Running AI locally has several benefits, including the ability to use features when your PC is offline. But perhaps most importantly, AI that runs on-device can operate without sending data to servers.
		</p>

		<p>
			 
		</p>

		<p>
			<a href="https://www.windowscentral.com/software-apps/browsing/microsoft-wants-ai-to-read-your-browsing-history-but-theres-one-reason-not-to-worry" rel="external nofollow">Source</a>
		</p>

		<hr class="ipsHr">
		<p>
			<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
		</p>

		<p>
			<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
		</p>
	</div>
</div>
]]></description><guid isPermaLink="false">29630</guid><pubDate>Mon, 09 Jun 2025 17:37:14 +0000</pubDate></item><item><title>Europe just launched DNS4EU, a public DNS resolver with privacy and security options</title><link>https://nsaneforums.com/news/security-privacy-news/europe-just-launched-dns4eu-a-public-dns-resolver-with-privacy-and-security-options-r29616/</link><description><![CDATA[<p>
	DNS is one of the cornerstones of the Internet. Put simply, it is designed to turn domain names, say ghacks.net, into IP addresses. This process is usually handled by the Internet service provider, but it is often not the best option.
</p>

<p>
	 
</p>

<p>
	ISPs may sell DNS data, they may offer services that do not offer good performance, or they may block access to certain content.
</p>

<p>
	 
</p>

<p>
	<a data-wpel-link="internal" href="https://www.ghacks.net/2015/04/03/the-fastest-public-dns-providers-in-2015/" rel="external nofollow">Public DNS servers</a> promise to do better. There are plenty out there, and while many promise better performance, they too may be used to collect and sell data, or use data otherwise.
</p>

<h2>
	DNS4EU
</h2>

<p>
	DNS4EU is a new DNS resolver that has been co-funded by the European Union. It is privacy-compliant. The IP address of the user is "fully anonymized" and no "private data is collected anywhere". This means that it aligns fully with the GDPR and other European data protection regulations.
</p>

<p>
	 
</p>

<p>
	One downside is that it supports locations in Europe only, from Spain to Greece, and Ireland to Poland. That is fine if you connect from one of these locations, but performance may suffer if you connect from other locations.
</p>

<p>
	 
</p>

<p>
	With that out of the way,  here are the five IP addresses that you may set up:
</p>

<p>
	 
</p>

<ol>
	<li>
		<strong>Protective Resolution</strong> - IP address <strong>86.54.11.1</strong>
	</li>
	<li>
		<strong>Protective + Child Protection</strong> - IP address <strong>86.54.11.12</strong>
	</li>
	<li>
		<strong>Protective + Ad blocking</strong> - IP address <strong>86.54.11.13</strong>
	</li>
	<li>
		<strong>Protective + Child Protection + Ad blocking</strong> - IP address <strong>86.54.11.11</strong>
	</li>
	<li>
		<strong>Unfiltered Resolution</strong>-  IP address <strong>86.54.11.100</strong>
	</li>
</ol>

<p>
	 
</p>

<p>
	The unfiltered resolution is the only option that does not block anything. Protective resolution adds threat intelligence and protections to the DNS. Put plainly, it blocks known malicious IP addresses, and thus sites, automatically.
</p>

<p>
	 
</p>

<p>
	Connections fail automatically, if an IP address is on the blacklist. It features threat intelligence and real-time updates, makes use of artificial intelligence, and has a focus on regional threat intelligence to better protect European users.
</p>

<p>
	 
</p>

<p>
	Child protection and ad blocking are the two content filtering options.
</p>

<p>
	 
</p>

<p>
	Child protection aims to block access to child-inappropriate content such as sexual content, weapons, drugs, terrorism, racism, or violence.  Ad-blocking blocks advertisement, similarly to how <a data-wpel-link="internal" href="https://www.ghacks.net/2018/12/31/a-look-at-adguard-dns/" rel="external nofollow">AdGuard DNS</a> does it.
</p>

<p>
	 
</p>

<p>
	The website includes instructions that explain how to change the DNS on devices. It covers Windows, macOS, Linux, Android, iOS, home routers, and browsers.
</p>

<h2>
	How fast are the DNS4EU DNS servers?
</h2>

<p>
	I downloaded the latest version of the free <a data-wpel-link="internal" href="https://www.ghacks.net/2011/10/18/dns-benchmark-speed-test-dns-servers/" rel="external nofollow">DNS Benchmark</a> software by Gibson Research, added the five DNS server IP addresses to it, and ran the test.
</p>

<p>
	 
</p>

<p>
	Here is the result.
</p>

<p>
	 
</p>

<p>
	<img alt="DNS Benchmark" class="ipsImage" decoding="async" height="720" width="720" src="https://www.ghacks.net/wp-content/uploads/2025/06/dns-benchmark.png">
</p>

<p>
	 
</p>

<p>
	The unfiltered DNS server finished in second place, the protective and child protection server in fourth. That is a good result, but you need to remember that your mileage may vary if you connect from outside the EU.
</p>

<h3>
	Closing Words
</h3>

<p>
	DNS4EU adds another option for Internet users when it comes to switching from their ISP's DNS servers to better ones. While it works best from a European location, it does allow connections from locations outside of the European Union. Performance suffers then, however, so that most users may want to pick a better performing DNS server instead.
</p>

<p>
	 
</p>

<p>
	Tests need to show how well the content blocking, child protecting, and malware blocking really works. You can skip all of that if you use the unfiltered server though.
</p>

<p>
	 
</p>

<p>
	<em>Now you: what is your take on this? Would you use the DNS server from the EU, or do you favor another one? Feel free to leave a comment down below.</em>
</p>

<p>
	 
</p>


<div id="div-gpt-ad-1524862513262-0">
	 
</div>

<p>
	<a href="https://www.ghacks.net/2025/06/08/europe-just-launched-dns4eu-a-public-dns-resolver-with-privacy-and-security-options/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29616</guid><pubDate>Sun, 08 Jun 2025 07:15:59 +0000</pubDate></item><item><title>FBI: BADBOX 2.0 Android malware infects millions of consumer devices</title><link>https://nsaneforums.com/news/security-privacy-news/fbi-badbox-20-android-malware-infects-millions-of-consumer-devices-r29586/</link><description><![CDATA[<p data-end="682" data-start="273">
	The FBI is warning that the BADBOX 2.0 malware campaign has infected over 1 million home Internet-connected devices, converting consumer electronics into residential proxies that are used for malicious activity.
</p>

<p>
	 
</p>

<p>
	The BADBOX botnet is commonly found on Chinese Android-based smart TVs, streaming boxes, projectors, tablets, and other Internet of Things (IoT) devices.
</p>

<p>
	 
</p>

<p>
	"The BADBOX 2.0 botnet consists of millions of infected devices and maintains numerous backdoors to proxy services that cyber criminal actors exploit by either selling or providing free access to compromised home networks to be used for various criminal activity," <a href="https://www.ic3.gov/PSA/2025/PSA250605#fn2" rel="external nofollow" target="_blank">warns the FBI</a>.
</p>

<p>
	 
</p>

<p>
	These devices come preloaded with the BADBOX 2.0 malware botnet or become infected after installing firmware updates and through malicious Android applications that sneak onto Google Play and third-party app stores.
</p>

<p>
	 
</p>

<p>
	"Cyber criminals gain unauthorized access to home networks by either configuring the product with malicious software prior to the users purchase or infecting the device as it downloads required applications that contain backdoors, usually during the set-up process," explains the FBI.
</p>

<p>
	 
</p>

<p>
	"Once these compromised IoT devices are connected to home networks, the infected devices are susceptible to becoming part of the BADBOX 2.0 botnet and residential proxy services4 known to be used for malicious activity."
</p>

<p>
	 
</p>

<p>
	Once infected, the devices connect to the attacker's command and control (C2) servers, where they receive commands to execute on the compromised devices, such as:
</p>

<p>
	 
</p>

<ul>
	<li>
		<strong>Residential Proxy Networks:</strong> The malware routes traffic from other cybercriminals through victims' home IP addresses, masking malicious activity.
	</li>
	<li>
		<strong>Ad Fraud:</strong> BADBOX can load and click ads in the background, generating ad revenue for the threat actors.
	</li>
	<li>
		<strong>Credential Stuffing: </strong>By leveraging victim IPs, attackers attempt to access other people's accounts using stolen credentials.
	</li>
</ul>

<p>
	 
</p>

<p>
	BADBOX 2.0 evolved from the original BADBOX malware, which was <a href="https://www.bleepingcomputer.com/news/security/android-tv-box-on-amazon-came-pre-installed-with-malware/" rel="external nofollow" target="_blank">first identified in 2023</a> after it was found pre-installed in cheap, no-name Android TV boxes like the T95.
</p>

<p>
	 
</p>

<p>
	Over the years, the malware botnet continued expanding until 2024, when Germany's cybersecurity agency <a href="https://www.bleepingcomputer.com/news/security/germany-blocks-badbox-malware-loaded-on-30-000-android-devices/" rel="external nofollow" target="_blank">disrupted the botnet</a> in the country by sinkholing the communication between infected devices and the attacker's infrastructure, effectively rendering the malware useless.
</p>

<p>
	 
</p>

<p>
	However, that did not stop the threat actors, <a href="https://www.bleepingcomputer.com/news/security/badbox-malware-botnet-infects-192-000-android-devices-despite-disruption/" rel="external nofollow" target="_blank">with researchers saying</a> they found the malware installed on 192,000 devices a week later. Even more concerning, the malware was found on more mainstream brands, like Yandex TVs and Hisense smartphones.
</p>

<p>
	 
</p>

<p>
	Unfortunately, despite the previous disruption, the botnet continued to grow, with HUMAN's Satori Threat Intelligence stating that <a href="https://www.bleepingcomputer.com/news/security/badbox-malware-disrupted-on-500k-infected-android-devices/" rel="external nofollow" target="_blank">over 1 million consumer devices had become infected</a> by March 2025.
</p>

<p>
	 
</p>

<p>
	This new larger botnet is now being called BADBOX 2.0 to indicate a new tracking of the malware campaign.
</p>

<p>
	 
</p>

<p>
	"This scheme impacted <strong>more than 1 million consumer devices</strong>. Devices connected to the BADBOX 2.0 operation included lower-price-point, "off brand", uncertified tablets, connected TV (CTV) boxes, digital projectors, and more," <a href="http://www.humansecurity.com/learn/blog/satori-threat-intelligence-disruption-badbox-2-0/" rel="external nofollow" target="_blank">explains HUMAN</a>.
</p>

<p>
	 
</p>

<p>
	"The infected devices are Android Open Source Project devices, not Android TV OS devices or <a href="https://www.android.com/certified/" rel="external nofollow" target="_blank">Play Protect certified Android devices</a>. All of these devices are manufactured in mainland China and shipped globally; indeed, HUMAN observed BADBOX 2.0-associated traffic from <strong>222 countries and territories worldwide</strong>."
</p>

<p>
	 
</p>

<p>
	Researchers at HUMAN estimate that the BADBOX 2.0 botnet spans 222 countries, with the highest number of compromised devices in Brazil (37.6%), the United States (18.2%), Mexico (6.3%), and Argentina (5.3%).
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="BadBox 2.0 Global Distribution" class="ipsImage" height="431" width="720" src="https://www.bleepstatic.com/images/news/security/b/badbox/FBI-psa/badbox2-global-breakdown.jpg">
		<figcaption>
			<strong>BADBOX 2.0 Global Distribution</strong><br>
			<em>Source: HUMAN Satori</em>
		</figcaption>
	</figure>
</div>

<p data-end="682" data-start="273">
	In a joint operation led by HUMAN's Satori team and Google, Trend Micro, The Shadowserver Foundation, and other partners, the BADBOX 2.0 botnet was disrupted again to prevent over 500,000 infected devices from communicating with the attacker's servers.
</p>

<p>
	 
</p>

<p data-end="682" data-start="273">
	However, even with that disruption, the botnet continues to grow as consumers purchase more compromised products and connect them to the Internet.
</p>

<p>
	 
</p>

<p data-end="682" data-start="273">
	A list of devices known to be impacted by the BADBOX malware are listed below:
</p>

<p>
	 
</p>

<table border="1px solid black;">
	<tbody>
		<tr>
			<td>
				<strong>Device Model</strong>
			</td>
			<td>
				<strong>Device Model</strong>
			</td>
			<td>
				<strong>Device Model</strong>
			</td>
			<td>
				<strong>Device Model</strong>
			</td>
		</tr>
		<tr>
			<td>
				TV98
			</td>
			<td>
				X96Q_Max_P
			</td>
			<td>
				Q96L2
			</td>
			<td>
				X96Q2
			</td>
		</tr>
		<tr>
			<td>
				X96mini
			</td>
			<td>
				S168
			</td>
			<td>
				ums512_1h10_Natv
			</td>
			<td>
				X96_S400
			</td>
		</tr>
		<tr>
			<td>
				X96mini_RP
			</td>
			<td>
				TX3mini
			</td>
			<td>
				HY-001
			</td>
			<td>
				MX10PRO
			</td>
		</tr>
		<tr>
			<td>
				X96mini_Plus1
			</td>
			<td>
				LongTV_GN7501E
			</td>
			<td>
				Xtv77
			</td>
			<td>
				NETBOX_B68
			</td>
		</tr>
		<tr>
			<td>
				X96Q_PR01
			</td>
			<td>
				AV-M9
			</td>
			<td>
				ADT-3
			</td>
			<td>
				OCBN
			</td>
		</tr>
		<tr>
			<td>
				X96MATE_PLUS
			</td>
			<td>
				KM1
			</td>
			<td>
				X96Q_PRO
			</td>
			<td>
				Projector_T6P
			</td>
		</tr>
		<tr>
			<td>
				X96QPRO-TM
			</td>
			<td>
				sp7731e_1h10_native
			</td>
			<td>
				M8SPROW
			</td>
			<td>
				TV008
			</td>
		</tr>
		<tr>
			<td>
				X96Mini_5G
			</td>
			<td>
				Q96MAX
			</td>
			<td>
				Orbsmart_TR43
			</td>
			<td>
				Z6
			</td>
		</tr>
		<tr>
			<td>
				TVBOX
			</td>
			<td>
				Smart
			</td>
			<td>
				KM9PRO
			</td>
			<td>
				A15
			</td>
		</tr>
		<tr>
			<td>
				Transpeed
			</td>
			<td>
				KM7
			</td>
			<td>
				iSinbox
			</td>
			<td>
				I96
			</td>
		</tr>
		<tr>
			<td>
				SMART_TV
			</td>
			<td>
				Fujicom-SmartTV
			</td>
			<td>
				MXQ9PRO
			</td>
			<td>
				MBOX
			</td>
		</tr>
		<tr>
			<td>
				X96Q
			</td>
			<td>
				isinbox
			</td>
			<td>
				Mbox
			</td>
			<td>
				R11
			</td>
		</tr>
		<tr>
			<td>
				GameBox
			</td>
			<td>
				KM6
			</td>
			<td>
				X96Max_Plus2
			</td>
			<td>
				TV007
			</td>
		</tr>
		<tr>
			<td>
				Q9 Stick
			</td>
			<td>
				SP7731E
			</td>
			<td>
				H6
			</td>
			<td>
				X88
			</td>
		</tr>
		<tr>
			<td>
				X98K
			</td>
			<td>
				TXCZ
			</td>
			<td>
				 
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<p>
	Symptoms of a BADBOX 2.0 infection include suspicious app marketplaces, disabled Google Play Protect settings, TV streaming devices advertised as being unlocked or able to access free content, devices from unknown brands, and suspicious Internet traffic.
</p>

<p>
	 
</p>

<p>
	Furthermore, this malware is commonly found on devices not Google Play Protect certified.
</p>

<p>
	 
</p>

<p>
	The FBI strongly advises consumers to protect themselves from the botnet by following these steps:
</p>

<p>
	 
</p>

<ul>
	<li>
		Assess all IoT devices connected to home networks for suspicious activity.
	</li>
	<li>
		Never download apps from unofficial marketplaces offering "free streaming" apps.
	</li>
	<li>
		Monitor Internet traffic to and from home networks.
	</li>
	<li>
		Keep all devices in your home updated with the latest patches and updates.
	</li>
</ul>

<p>
	 
</p>

<p>
	Finally, if you suspect your device is compromised, you should isolate it from the rest of the network and restrict its Internet access, effectively disrupting the malware.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/fbi-badbox-20-android-malware-infects-millions-of-consumer-devices/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29586</guid><pubDate>Fri, 06 Jun 2025 05:45:56 +0000</pubDate></item><item><title>Court orders Apple to keep web links in the App Store, eroding its iOS payment monopoly</title><link>https://nsaneforums.com/news/security-privacy-news/court-orders-apple-to-keep-web-links-in-the-app-store-eroding-its-ios-payment-monopoly-r29577/</link><description><![CDATA[<p>
	Apple has been ordered to continue permitting web links and external payment options in the App Store after its bid to halt court’s ruling was declined today by a higher court.
</p>

<p>
	 
</p>

<p>
	Earlier this year, in April, a federal judge decreed that Apple must allow developers to include web links in their iOS apps, remove restrictions on link formatting, and enable external payment methods without taking a commission on transactions. Apple immediately appealed and sought an injunction to delay implementation of the order while the case progressed.
</p>

<p>
	 
</p>

<p>
	However, the United States Court of Appeals has now refused Apple’s emergency request to stay the district court’s order. In its decision, the panel held that Apple had not demonstrated a sufficient likelihood of success on appeal, nor that it would suffer irreparable harm if the order were enforced. The court also considered potential prejudice to other parties and the public interest, concluding that an immediate suspension was not warranted. This ruling makes it much harder for Apple to overturn the April decision, which came from a lawsuit initiated by Epic Games.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/apple-kicks-fortnite-out-of-the-app-store/" rel="external nofollow">Epic first sued Apple’s App Store policies in 2020</a>, claiming that the company’s restrictions harmed competition. While Epic did not prevail on every count, the court did rule that Apple must allow developers to inform users of alternative purchasing options at better prices. Despite that narrow victory, <a href="https://www.neowin.net/news/us-judge-rules-apple-willfully-violated-and-ignored-courts-2021-decision/" rel="external nofollow">Apple repeatedly failed to conform to the terms</a> from the <a href="https://www.neowin.net/news/court-epic-games-breached-contract-but-apple-must-allow-external-payment-methods/" rel="external nofollow">original 2021 ruling</a>, prompting the judge in April to issue a more detailed order outlining precisely how the App Store must be “opened up”.
</p>

<p>
	 
</p>

<p>
	In response to the April ruling, prominent third-party apps have swiftly implemented web-based purchasing links. Both <a href="https://www.neowin.net/news/in-response-to-court-ruling-spotify-submits-new-app-update-to-apple-app-store/" rel="external nofollow">Spotify</a> and Amazon’s Kindle app now include buttons directing users to purchase subscriptions via their websites, bypassing Apple’s in-app payments. Additionally, <a href="https://www.neowin.net/news/apple-kicks-fortnite-out-of-the-app-store/" rel="external nofollow">Fortnite has made a comeback on iOS after around five years</a>, presenting users with the choice between Apple’s in-app payment system and Epic’s own payment and rewards mechanism. According to Epic CEO Tim Sweeney, there is presently a 60:40 split in usage favouring Apple’s system over Epic’s, though the gap appears to be narrowing.
</p>

<p>
	 
</p>

<p>
	An Apple spokesperson, Olivia Dalton, issued a statement expressing the company’s disappointment:
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		We are disappointed with the decision not to stay the district court’s order, and we will continue to argue our case during the appeals process. As we have said before, we strongly disagree with the district court’s opinion. Our goal is to ensure that the App Store remains an outstanding opportunity for developers and a safe, trusted experience for our users.
	</p>
</blockquote>

<p>
	For now, Apple must comply with the existing injunction. Unless the Appeals Court later overturns the ruling, developers can continue to include web payment links, and Apple’s longstanding monopoly over iOS payment processing may continue to erode. The ultimate resolution will depend on the outcome of the ongoing appeals, which could set a significant precedent for how app marketplaces operate in the future.
</p>

<p>
	 
</p>

<p>
	Source: <a href="https://www.theverge.com/news/679946/apple-rejected-court-attempt-to-stop-app-store-web-links" rel="external nofollow">The Verge</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/court-orders-apple-to-keep-web-links-in-the-app-store-eroding-its-ios-payment-monopoly/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29577</guid><pubDate>Thu, 05 Jun 2025 19:11:17 +0000</pubDate></item><item><title>Germany fines Vodafone $51 million for privacy, security breaches</title><link>https://nsaneforums.com/news/security-privacy-news/germany-fines-vodafone-51-million-for-privacy-security-breaches-r29576/</link><description><![CDATA[<p>
	The German data protection authority (BfDI) has fined Vodafone GmbH, the telecommunications company's German subsidiary, €45 million ($51.4 million) for privacy and security violations.
</p>

<p>
	 
</p>

<p>
	"Due to malicious employees in partner agencies who broker contracts to customers on behalf of Vodafone, there had been fraud cases due to fictitious contracts or contract changes at the expense of customers, among other things," BfDI said on Thursday.
</p>

<p>
	 
</p>

<p>
	BfDI imposed a €15 million fine on Vodafone GmbH for failing to monitor partner agencies whose employees made unauthorized contract changes or tricked customers into signing fictitious contracts.
</p>

<p>
	 
</p>

<p>
	The British multinational telecommunications company was hit with a second €30 million fine for authentication vulnerabilities of its MeinVodafone ("My Vodafone") and the company's hotline, which allowed attackers to access customer eSIM profiles.
</p>

<p>
	 
</p>

<p>
	"Where data breaches take place, sanctions must be imposed. However, with my work, I also want to ensure that data breaches do not occur in the first place. Companies that want to comply with data protection law must be empowered to do so," <a href="https://www.bfdi.bund.de/SharedDocs/Pressemitteilungen/EN/2025/06_Geldbu%C3%9Fe-Vodafone.html?nn=355282" rel="external nofollow" target="_blank">added</a> Prof. Dr. Louisa Specht-Riemenschneider, the Federal Commissioner for Data Protection and Freedom of Information.
</p>

<p>
	 
</p>

<p>
	"I would like to point out that Vodafone has cooperated with me continuously and without restriction throughout the entire proceedings and has also disclosed circumstances that have incriminated the company."
</p>

<p>
	 
</p>

<p>
	Vodafone has updated its processes and systems, replacing some of them to mitigate future risks. The company has also updated procedures for selecting and auditing partner agencies, and it has severed ties with partners linked to fraudulent activities.
</p>

<p>
	 
</p>

<p>
	The telecom giant has already paid the fines and donated several million euros to organizations that promote data protection, media literacy, and combating cyberbullying, the BfDI said.
</p>

<p>
	 
</p>

<p>
	Vodafone offers mobile and fixed services to over 330 million customers in 15 countries across Europe, Asia, Africa, and Oceania. Its financial technology businesses also serve nearly 83 million customers in seven African countries.
</p>

<p>
	 
</p>

<p>
	A Vodafone spokesperson was not immediately available for comment when contacted by BleepingComputer today.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/germany-fines-vodafone-51-million-for-privacy-security-breaches/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29576</guid><pubDate>Thu, 05 Jun 2025 19:10:23 +0000</pubDate></item><item><title>Microsoft offers free cybersecurity programs to European governments</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-offers-free-cybersecurity-programs-to-european-governments-r29565/</link><description><![CDATA[<p>
	Microsoft has unveiled its cybersecurity initiative for European governments, which includes a program to boost their national <a href="https://www.neowin.net/news/microsoft-shares-detailed-guidance-for-ai-scams-that-are-nearly-impossible-to-not-fall-for/" rel="external nofollow">defense against AI-driven cyber threats</a> from hostile nations and criminals.
</p>

<p>
	 
</p>

<p>
	As reported in <a href="https://blogs.microsoft.com/on-the-issues/2025/06/04/microsoft-launches-new-european-security-program/" rel="external nofollow">Microsoft Blog</a>, the program aims to bolster the European government's ability to repel cyber attacks, especially those driven by generative AI. This cybersecurity enhancement program is said to be free of charge. However, such collaborations could improve Microsoft's relationship with European governments and enhance the company's footprint in European cyber defense programs.
</p>

<p>
	 
</p>

<p>
	While the <a href="https://www.neowin.net/news/microsoft-warns-of-600m-daily-cyberattacks-with-rising-ai-sophistication/" rel="external nofollow">surge in weaponizing AI for malicious activities</a> is concerning, Microsoft believes in the potential of AI as a defense tool. The company also proactively monitors and addresses any malicious use of its AI models and tools.
</p>

<p>
	 
</p>

<p>
	The Microsoft's European Security Program aims to increase AI-based threat intelligence sharing with European governments, bolster cybersecurity capacity and resilience, and expand partnerships to disrupt cyberattacks.
</p>

<p>
	 
</p>

<p>
	Microsoft also says it has worked with European law enforcement agencies to take down <a href="https://www.neowin.net/news/microsoft-warns-new-windows-1110-installation-iso-downloads-must-have-this-defender-update/" rel="external nofollow">Lumma infostealer malware</a>, which is used to steal passwords, financial data, and crypto wallets. According to Microsoft, Lumma could infect nearly 400,000 devices globally in just two months, and many of its victims were in Europe. The company added the operation could seize or block over 2,300 command-and-control domains.
</p>

<p>
	 
</p>

<p>
	Over the past few years, there has been a massive surge in AI-driven cyber attacks, with criminals employing generative AI and commercial AI tools to target users and organizations. Large Language Models (LLMs) are modified for malicious purposes, allowing bad actors to exploit vulnerabilities with less effort.
</p>

<p>
	 
</p>

<p>
	Scammers and criminals even leverage AI tools like ChatGPT to create phishing emails, impersonate companies and individuals, and make deepfake videos. In another case, <a href="https://www.neowin.net/news/authorities-say-the-las-vegas-cybertruck-bomber-used-chatgpt-to-plan-the-attack/" rel="external nofollow">ChatGPT was used to plan the attack on Trump Hotel</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-offers-free-cybersecurity-programs-to-european-governments/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29565</guid><pubDate>Wed, 04 Jun 2025 19:51:51 +0000</pubDate></item><item><title>Two certificate authorities booted from the good graces of Chrome</title><link>https://nsaneforums.com/news/security-privacy-news/two-certificate-authorities-booted-from-the-good-graces-of-chrome-r29564/</link><description><![CDATA[<h3>
	Chunghwa Telecom and Netlock customers must look elsewhere for new certificates.
</h3>

<p>
	Google says its Chrome browser will stop trusting certificates from two certificate authorities after “patterns of concerning behavior observed over the past year” diminished trust in their reliability.
</p>

<p>
	 
</p>

<p>
	The two organizations, Taiwan-based Chunghwa Telecom and Budapest-based Netlock, are among the dozens of certificate authorities trusted by Chrome and most other browsers to provide digital certificates that encrypt traffic and certify the authenticity of sites. With the ability to mint cryptographic credentials that cause address bars to display a padlock, assuring the trustworthiness of a site, these certificate authorities wield significant control over the security of the web.
</p>

<h2>
	Inherent risk
</h2>

<p>
	“Over the past several months and years, we have observed a pattern of compliance failures, unmet improvement commitments, and the absence of tangible, measurable progress in response to publicly disclosed incident reports,” members of the Chrome security team <a href="https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html" rel="external nofollow">wrote Tuesday</a>. “When these factors are considered in aggregate and considered against the inherent risk each publicly-trusted CA poses to the internet, continued public trust is no longer justified.”
</p>

<p>
	 
</p>

<p>
	According to Ryan Hurst, a researcher with over two decades of experience working with certificate authorities, such certificate distrust events occur about <a href="https://unmitigatedrisk.com/?p=850" rel="external nofollow">once every 15 months</a>. The reasons for the revocations vary widely.
</p>

<p>
	 
</p>

<p>
	Hurst provided the following graph tracking the frequency of reasons for past events:
</p>

<figure class="ars-wp-img-shortcode id-2098711 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="Pie chart showing reasons for distrust" class="center medium" decoding="async" height="480" loading="lazy" sizes="auto, (max-width: 640px) 100vw, 640px" srcset="https://cdn.arstechnica.net/wp-content/uploads/2025/06/distrust-6-640x480.png 640w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/distrust-6-1024x768.png 1024w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/distrust-6-768x576.png 768w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/distrust-6-1536x1152.png 1536w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/distrust-6-980x735.png 980w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/distrust-6-1440x1080.png 1440w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/distrust-6.png 2048w" width="640" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/distrust-6-640x480.png">
				<div class="pswp-caption-content" id="caption-2098711">
					<em>Data from Ryan Hurst </em>

					<div class="ars-gallery-caption-credit">
						<em><em>Credit: Ars Technica </em></em>
					</div>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	Google cited no specific incidents. Hurst, however, said past offenses included:
</p>

<p>
	 
</p>

<ul>
	<li>
		Netlock failing to disclose an intermediate CA Certificate to the Common CA Database over a span of <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1904041" rel="external nofollow"> more than one year.</a>
	</li>
	<li>
		Netlock <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1947691" rel="external nofollow">failing to revoke</a> a misissued certificate.
	</li>
	<li>
		Netlock failing to provide <a href="link" rel="">mandated weekly updates</a> concerning a security incident.
	</li>
	<li>
		Chunghwa Telecom <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1892419" rel="external nofollow"> delaying revocation</a> of a misissued certificate.
	</li>
	<li>
		Chunghwa Telecom misissuing 247 certificates with <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1916392" rel="external nofollow">incorrect subject domain name structures.</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	Chrome will stop trusting all certificates issued by Chunghwa Telecom and Netlock after July 31. Certificates issued after that date will, by default, display an <a href="https://untrusted-root.badssl.com/" rel="external nofollow">error page</a> on Chrome. The delay is designed to give those organizations' customers time to find new certificate authorities. Representatives from both organizations didn't respond to emails requesting comment.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/06/chrome-boots-2-certificate-authorities-citing-a-lack-of-trust-and-confidence/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29564</guid><pubDate>Wed, 04 Jun 2025 19:50:44 +0000</pubDate></item><item><title>Google patches new Chrome zero-day bug exploited in attacks</title><link>https://nsaneforums.com/news/security-privacy-news/google-patches-new-chrome-zero-day-bug-exploited-in-attacks-r29539/</link><description><![CDATA[<p>
	Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year.
</p>

<p>
	 
</p>

<p>
	"Google is aware that an exploit for CVE-2025-5419 exists in the wild," the company warned in a <a href="https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html" rel="external nofollow" target="_blank">security </a><span style="box-sizing:border-box; margin:0px; padding:0px"><a href="https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html" rel="external nofollow" target="_blank">advisory</a></span> published on Monday.
</p>

<p>
	 
</p>

<p>
	This high-severity vulnerability is caused by an out-of-bounds read and write weakness in Chrome's V8 JavaScript engine, reported one week ago by Clement Lecigne and Benoît Sevens of Google's Threat Analysis Group.
</p>

<p>
	 
</p>

<p>
	Google says the issue was mitigated one day later by a configuration change the company pushed to the Stable channel across all Chrome platforms.
</p>

<p>
	 
</p>

<p>
	On Monday, it also fixed the zero-day with the release of 137.0.7151.68/.69 for Windows/Mac and 137.0.7151.68 for Linux, versions that are rolling out to users in the Stable Desktop channel over the coming weeks.
</p>

<p>
	 
</p>

<p>
	While Chrome will automatically update when new security patches are available, users can speed up the process by going to the Chrome menu &gt; Help &gt; About Google Chrome, letting the update finish, and clicking the 'Relaunch' button to install it immediately.
</p>

<p>
	 
</p>

<p>
	<img alt="Chrome 137.0.7151.69" class="ipsImage" height="228" width="720" src="https://www.bleepstatic.com/images/news/u/1109292/2025/Chrome%20137_0_7151_69.png">
</p>

<p>
	 
</p>

<p>
	While Google has already confirmed that CVE-2025-5419 is being exploited in the wild, the company will not share additional information regarding these attacks until more users have patched their browsers.
</p>

<p>
	 
</p>

<p>
	"Access to bug details and links may be kept restricted until a majority of users are updated with a fix," Google said. "We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed."
</p>

<p>
	 
</p>

<p>
	This is Google's third Chrome zero-day vulnerability since the start of the year, with two more patched in March and May.
</p>

<p>
	 
</p>

<p>
	The first, a high-severity sandbox escape flaw (CVE-2025-2783) discovered by Kaspersky's Boris Larin and Igor Kuznetsov, was <a href="https://www.bleepingcomputer.com/news/security/google-fixes-chrome-zero-day-exploited-in-espionage-campaign/" rel="external nofollow" target="_blank">used to deploy malware</a> in espionage attacks targeting Russian government organizations and media outlets.
</p>

<p>
	 
</p>

<p>
	The company released another set of emergency security updates in May to patch a Chrome zero-day that could let attackers <a href="https://www.bleepingcomputer.com/news/security/google-fixes-high-severity-chrome-flaw-with-public-exploit/" rel="external nofollow" target="_blank">take over accounts</a> following successful exploitation.
</p>

<p>
	 
</p>

<p>
	Last year, <a href="https://www.bleepingcomputer.com/news/security/google-tags-a-tenth-chrome-zero-day-as-exploited-this-year/" rel="external nofollow" target="_blank">Google patched 10 zero-days</a> that were either demoed during the Pwn2Own hacking competition or exploited in attacks.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29539</guid><pubDate>Tue, 03 Jun 2025 19:44:46 +0000</pubDate></item><item><title>Mozilla launches new system to detect Firefox crypto drainer add-ons</title><link>https://nsaneforums.com/news/security-privacy-news/mozilla-launches-new-system-to-detect-firefox-crypto-drainer-add-ons-r29538/</link><description><![CDATA[<p>
	Mozilla has developed a new security feature for its add-on portal that helps block Firefox malicious extensions that drain cryptocurrency wallets.
</p>

<p>
	 
</p>

<p>
	According to a recent blog post, Mozilla's new security system creates risk profiles for each submitted wallet extension and triggers automated risk alerts if a pre-defined threshold is exceeded.
</p>

<p>
	 
</p>

<p>
	These alerts will prompt human reviewers to take a closer look and remove malicious extensions from the store before they're used to drain more victims' crypto wallets.
</p>

<p>
	 
</p>

<p>
	"To help protect Firefox users, the Add-ons Operations team developed an early detection system designed to identify and stop crypto scam extensions before they find traction with unsuspecting users," Mozilla <a href="https://blog.mozilla.org/addons/2025/05/30/crypto-wallet-scams-thwarting-a-new-threat/" rel="external nofollow" target="_blank">said</a>.
</p>

<p>
	 
</p>

<p>
	"The first layer of defense involves automated indicators that determine a risk profile for wallet extensions submitted to AMO. If a wallet extension reaches a certain risk threshold, human reviewers are alerted to take a deeper look. If found to be malicious, the scam extensions are blocked immediately."
</p>

<p>
	 
</p>

<p>
	Crypto wallet drainers that steal cryptocurrency or other digital assets from a victim's wallets are now being delivered to potential victims' systems via malicious browser extensions designed to masquerade as legitimate add-ons from trusted crypto wallets.
</p>

<p>
	 
</p>

<p>
	This attack vector ensures that threat actors can quickly empty their targets' crypto wallets after stealing their private keys and credentials, making the lost funds likely impossible to recover.
</p>

<p>
	 
</p>

<p>
	While not all are directly tied to malicious extensions, cybercriminals stole<a href="https://www.bleepingcomputer.com/news/security/cryptocurrency-wallet-drainers-stole-494-million-in-2024/" rel="external nofollow" target="_blank"> $494 million worth of cryptocurrency</a> last year in wallet-draining attacks from more than 300,000 wallet addresses.
</p>

<p>
	 
</p>

<p>
	Andreas Wagner, the Add-ons Operations Manager who also leads addons.mozilla.org (AMO) content security and review efforts, says his team has discovered and removed hundreds of such extensions, including scam crypto wallets, over the last few years.
</p>

<p>
	 
</p>

<p>
	"It's a constant cat and mouse game, as developers try to work around our detection methods," Wagner explained.
</p>

<p>
	 
</p>

<p>
	"Check your crypto wallet's website to see if they have an official extension, and only use the one they link to," he added, advising Firefox users to use the official extensions provided by their crypto wallet services whenever possible.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/mozilla-launches-new-system-to-detect-firefox-crypto-drainer-add-ons/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29538</guid><pubDate>Tue, 03 Jun 2025 19:43:15 +0000</pubDate></item><item><title>Meta and Yandex are de-anonymizing Android users&#x2019; web browsing identifiers</title><link>https://nsaneforums.com/news/security-privacy-news/meta-and-yandex-are-de-anonymizing-android-users%E2%80%99-web-browsing-identifiers-r29537/</link><description><![CDATA[<h3>
	Abuse allows Meta and Yandex to attach persistent identifiers to detailed browsing histories.
</h3>

<p>
	Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, <a href="https://localmess.github.io/" rel="external nofollow">researchers have discovered</a>. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.
</p>

<p>
	 
</p>

<p>
	The covert tracking—implemented in the <a href="https://www.facebook.com/business/tools/meta-pixel/" rel="external nofollow">Meta Pixel</a> and <a href="https://ads.yandex/metrica" rel="external nofollow">Yandex Metrica</a> trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. <a href="https://source.Android.com/docs/security/app-sandbox" rel="external nofollow">Android sandboxing</a>, for instance, isolates processes to prevent them from interacting with the OS and any other app installed on the device, cutting off access to sensitive data or privileged system resources. Defenses such <span style="box-sizing: border-box; margin: 0px; padding: 0px;">as <a href="https://developer.mozilla.org/en-US/docs/Web/Privacy/Guides/State_Partitioning" rel="external nofollow" target="_blank">state</a></span><a href="https://developer.mozilla.org/en-US/docs/Web/Privacy/Guides/State_Partitioning" rel="external nofollow"> partitioning</a> and <a href="https://privacysandbox.google.com/cookies/storage-partitioning" rel="external nofollow">storage partitioning</a>, which are built into all major browsers, store site cookies and other data associated with a website in containers that are unique to every top-level website domain to ensure they're off-limits for every other site.
</p>

<h2>
	A blatant violation
</h2>

<p>
	“One of the fundamental security principles that exists in the web, as well as the mobile system, is called sandboxing,” Narseo Vallina-Rodriguez, one of the researchers behind the discovery, said in an interview. “You run everything in a sandbox, and there is no interaction within different elements running on it. What this attack vector allows is to break the sandbox that exists between the mobile context and the web context. The channel that exists allowed the Android system to communicate what happens in the browser with the identity running in the mobile app.”
</p>

<p>
	 
</p>

<p>
	The bypass—which Yandex began in 2017 and Meta started last September—allows the companies to pass cookies or other identifiers from Firefox and Chromium-based browsers to native Android apps for Facebook, Instagram, and various Yandex apps. The companies can then tie that vast browsing history to the account holder logged into the app.
</p>

<p>
	 
</p>

<p>
	This abuse has been observed only in Android, and evidence suggests that the Meta Pixel and Yandex Metrica target only Android users. The researchers say it may be technically feasible to target iOS because browsers on that platform allow developers to programmatically <a href="https://bugs.webkit.org/show_bug.cgi?id=279249" rel="external nofollow">establish localhost connections</a> that apps can monitor on local ports.
</p>

<p>
	 
</p>

<p>
	In contrast to iOS, however, Android imposes fewer controls on local host communications and background executions of mobile apps, the researchers said, while also implementing stricter controls in app store vetting processes to limit such abuses. This overly permissive design allows Meta Pixel and Yandex Metrica to send web requests with web tracking identifiers to specific local ports that are continuously monitored by the Facebook, Instagram, and Yandex apps. These apps can then link pseudonymous web identities with actual user identities, even in private browsing modes, effectively de-anonymizing users’ browsing habits on sites containing these trackers.
</p>

<p>
	 
</p>

<p>
	Meta Pixel and Yandex Metrica are analytics scripts designed to help advertisers measure the effectiveness of their campaigns. Meta Pixel and Yandex Metrica are estimated to be installed on <a href="https://trends.builtwith.com/websitelist/Facebook-Pixel%20" rel="external nofollow">5.8 million</a> and <a href="https://trends.builtwith.com/analytics/Yandex-Metrika" rel="external nofollow">3 million</a> sites, respectively.
</p>

<p>
	 
</p>

<p>
	Meta and Yandex achieve the bypass by abusing basic functionality built into modern mobile browsers that allows browser-to-native app communications. The functionality lets browsers send web requests to local Android ports to establish various services, including media connections through the <a href="https://en.wikipedia.org/wiki/Real-time_communication" rel="external nofollow">RTC protocol</a>, file sharing, and developer debugging.
</p>

<p>
	 
</p>

<figure class="ars-wp-img-shortcode id-2098444 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="meta-yandex-websites-app-ID-sharing-1024" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-yandex-websites-app-ID-sharing-1024x361.png">
				<div class="pswp-caption-content" id="caption-2098444">
					<em>A conceptual diagram representing the exchange of identifiers between the web trackers running on the </em>
				</div>

				<div class="pswp-caption-content">
					<em>browser context and native Facebook, Instagram, and Yandex apps for Android. </em>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	While the technical underpinnings differ, both Meta Pixel and Yandex Metrica are performing a “weird protocol misuse” to gain unvetted access that Android provides to <a href="https://stackoverflow.com/questions/1946193/whats-the-whole-point-of-localhost-hosts-and-ports-at-all" rel="external nofollow">localhost ports</a> on the 127.0.0.1 IP address. Browsers access these ports without user notification. Facebook, Instagram, and Yandex native apps silently listen on those ports, copy identifiers in real time, and link them to the user logged into the app.
</p>

<p>
	 
</p>

<p>
	A representative for Google said the behavior violates the terms of service for its Play marketplace and the privacy expectations of Android users.
</p>

<p>
	 
</p>

<p>
	“The developers in this report are using capabilities present in many browsers across iOS and Android in unintended ways that blatantly violate our security and privacy principles,” the representative said, referring to the people who write the Meta Pixel and Yandex Metrica JavaScript. “We've already implemented changes to mitigate these invasive techniques and have opened our own investigation and are directly in touch with the parties.”
</p>

<p>
	 
</p>

<p>
	Meta didn't answer emailed questions for this article, but provided the following statement: "We are in discussions with Google to address a potential miscommunication regarding the application of their policies. Upon becoming aware of the concerns, we decided to pause the feature while we work with Google to resolve the issue."
</p>

<p>
	 
</p>

<p>
	In an email, Yandex said it was discontinuing the practice and was also in touch with Google.
</p>

<p>
	 
</p>

<p>
	"Yandex strictly complies with data protection standards and does not de-anonymize user data," the statement added. "The feature in question does not collect any sensitive information and is solely intended to improve personalization within our apps."
</p>

<h2>
	How Meta and Yandex de-anonymize Android users
</h2>

<p>
	Meta Pixel developers have abused various protocols to implement the covert listening since the practice began last September. They started by causing apps to send HTTP requests to port 12387. A month later, Meta Pixel stopped sending this data, even though Facebook and Instagram apps continued to monitor the port.
</p>

<p>
	 
</p>

<p>
	In November, Meta Pixel switched to a new method that invoked WebSocket, a protocol for two-way communications, over port 12387.
</p>

<p>
	 
</p>

<p>
	That same month, Meta Pixel also deployed a new method that used <a href="https://en.wikipedia.org/wiki/WebRTC" rel="external nofollow">WebRTC</a>, a real-time peer-to-peer communication protocol commonly used for making audio or video calls in the browser. This method used a complicated process known as <a href="https://webrtchacks.com/not-a-guide-to-sdp-munging/" rel="external nofollow">SDP munging</a>, a technique for JavaScript code to modify Session Description Protocol data before it’s sent. Still in use today, the SDP munging by Meta Pixel inserts key _fbp cookie content into fields meant for connection information. This causes the browser to send that data as part of a <a href="https://en.wikipedia.org/wiki/STUN" rel="external nofollow">STUN request</a> to the Android local host, where the Facebook or Instagram app can read it and link it to the user.
</p>

<p>
	 
</p>

<p>
	In May, a <a href="https://groups.google.com/g/discuss-webrtc/c/PIJZN5MTZF4/m/JHVmmn8yDgAJ?pli=1" rel="external nofollow">beta version</a> of Chrome introduced a mitigation that blocked the type of SDP munging that Meta Pixel used. Within days, Meta Pixel circumvented the mitigation by adding a new method that swapped the STUN requests with the <a href="https://en.wikipedia.org/wiki/Traversal_Using_Relays_around_NAT" rel="external nofollow">TURN requests</a>.
</p>

<p>
	 
</p>

<figure class="ars-wp-img-shortcode id-2098254 align-">
	<div>
		<img alt="meta-pixel-transmitting-fbp-cookie-640x1" class="medium" decoding="async" height="187" loading="lazy" sizes="auto, (max-width: 640px) 100vw, 640px" srcset="https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-pixel-transmitting-fbp-cookie-640x187.jpg 640w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-pixel-transmitting-fbp-cookie-1024x299.jpg 1024w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-pixel-transmitting-fbp-cookie-768x224.jpg 768w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-pixel-transmitting-fbp-cookie-1536x448.jpg 1536w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-pixel-transmitting-fbp-cookie-2048x598.jpg 2048w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-pixel-transmitting-fbp-cookie-980x286.jpg 980w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-pixel-transmitting-fbp-cookie-1440x420.jpg 1440w" width="640" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-pixel-transmitting-fbp-cookie-640x187.jpg">
	</div>
</figure>

<p>
	 
</p>

<p>
	In a <a href="link" rel="">post</a>, the researchers provided a detailed description of the _fbp cookie from a website to the native app and, from there, to the Meta server:
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		1. The user opens the native Facebook or Instagram app, which eventually is sent to the background and creates a background service to listen for incoming traffic on a TCP port (12387 or 12388) and a UDP port (the first unoccupied port in 12580–12585). Users must be logged-in with their credentials on the apps.<br>
		2. The user opens their browser and visits a website integrating the Meta Pixel.<br>
		3. At this stage, some websites wait for users' consent before embedding Meta Pixel. In our measurements of the top 100K website homepages, we found websites that require consent to be a minority (more than 75% of affected sites does not require user consent)...<br>
		4. The Meta Pixel script is loaded and the _fbp cookie is sent to the native Instagram or Facebook app via WebRTC (STUN) SDP Munging.<br>
		5. The Meta Pixel script also sends the _fbp value in a request to <a href="https://www.facebook.com/tr" ipsnoembed="false" rel="external nofollow">https://www.facebook.com/tr</a> along with other parameters such as page URL (dl), website and browser metadata, and the event type (ev) (e.g., PageView, AddToCart, Donate, Purchase).<br>
		6. The Facebook or Instagram apps receive the _fbp cookie from the Meta JavaScripts running on the browser and transmits it to the GraphQL endpoint (https://graph[.]facebook[.]com/graphql) along with other persistent user identifiers, linking users' fbp ID (web visit) with their Facebook or Instagram account.
	</p>
</blockquote>

<figure class="ars-wp-img-shortcode id-2098253 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="fbp-cookie-transfer-flow-1024x878.jpg" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/fbp-cookie-transfer-flow-1024x878.jpg">
				<div class="pswp-caption-content" id="caption-2098253">
					<em>Detailed flow of the way the Meta Pixel leaks the _fbp cookie from Android browsers to it's Facebook and Instagram apps. </em>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	The first known instance of Yandex Metrica linking websites visited in Android browsers to app identities was in May 2017, when the tracker started sending HTTP requests to local ports 29009 and 30102. In May 2018, Yandex Metrica also began sending the data through HTTPS to ports 29010 and 30103. Both methods remained in place as of publication time.
</p>

<p>
	 
</p>

<figure class="ars-wp-img-shortcode id-2098252 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="yandex-id-sharing-1024x560.jpg" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/yandex-id-sharing-1024x560.jpg">
				<div class="pswp-caption-content" id="caption-2098252">
					<em>An overview of Yandex identifier sharing </em>
				</div>
			</div>
		</div>
	</div>
</figure>

<figure class="ars-wp-img-shortcode id-2098089 align-center">
	<div>
		<div class="ars-lightbox">
			<div class="ars-lightbox-item">
				<img alt="meta-yandex-tracking-timeline-1024x458.j" class="ipsImage" decoding="async" height="720" width="720" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/meta-yandex-tracking-timeline-1024x458.jpg">
				<div class="pswp-caption-content" id="caption-2098089">
					<em>A timeline of web history tracking by Meta and Yandex </em>
				</div>
			</div>
		</div>
	</div>
</figure>

<p>
	Some browsers for Android have blocked the abusive JavaScript in trackers. DuckDuckGo, for instance, was already blocking domains and IP addresses associated with the trackers, preventing the browser from sending any identifiers to Meta. The browser also blocked most of the domains associated with Yandex Metrica. After the researchers notified DuckDuckGo of the incomplete blacklist, developers added the missing addresses.
</p>

<p>
	 
</p>

<p>
	The Brave browser, meanwhile, also blocked the sharing of identifiers due to its extensive blocklists and existing mitigation to <a href="https://brave.com/privacy-updates/27-localhost-permission/" rel="external nofollow" target="_blank">block requests</a> to the localhost without explicit user consent<span style="color: #bfbfbf;">.</span> Vivaldi, another Chromium-based browser, forwards the identifiers to local Android ports when the default privacy setting is in place. Changing the setting to block trackers appears to thwart browsing history leakage, the researchers said.
</p>

<p>
	 
</p>

<figure class="ars-wp-img-shortcode id-2098090 align-center">
	<div>
		<img alt="vivaldi-setting-300x300.png" class="center thumbnail" decoding="async" height="300" loading="lazy" sizes="auto, (max-width: 300px) 100vw, 300px" srcset="https://cdn.arstechnica.net/wp-content/uploads/2025/06/vivaldi-setting-300x300.png 300w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/vivaldi-setting-500x500.png 500w, https://cdn.arstechnica.net/wp-content/uploads/2025/06/vivaldi-setting-1000x1000.png 1000w" width="300" src="https://cdn.arstechnica.net/wp-content/uploads/2025/06/vivaldi-setting-300x300.png">
	</div>

	<figcaption>
		<div class="caption font-impact dusk:text-gray-300 mb-4 mt-2 inline-flex flex-row items-stretch gap-1 text-base leading-tight text-gray-400 dark:text-gray-300">
			<div class="caption-content">
				<em>Tracking blocker settings in Vivaldi for Android. </em>
			</div>
		</div>
	</figcaption>
</figure>

<h2>
	There’s got to be a better way
</h2>

<p>
	The various remedies DuckDuckGo, Brave, Vivaldi, and Chrome have put in place are working as intended, but the researchers caution they could become ineffective at any time.
</p>

<p>
	 
</p>

<p>
	“Any browser doing blocklisting will likely enter into a constant arms race, and it's just a partial solution,” Vallina Rodriguez said of the current mitigations. “Creating effective blocklists is hard, and browser makers will need to constantly monitor the use of this type of capability to detect other hostnames potentially abusing localhost channels and then updating their blocklists accordingly.”
</p>

<p>
	 
</p>

<p>
	He continued:
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		While this solution works once you know the hostnames doing that, it's not the right way of mitigating this issue, as trackers may find ways of accessing this capability (e.g., through more ephemeral hostnames). A long-term solution should go through the design and development of privacy and security controls for localhost channels, so that users can be aware of this type of communication and potentially enforce some control or limit this use (e.g., a permission or some similar user notifications).
	</p>
</blockquote>

<p>
	Chrome and most other Chromium-based browsers executed the JavaScript as Meta and Yandex intended. Firefox did as well, although for reasons that aren't clear, the browser was not able to successfully perform the SDP munging specified in later versions of the code. After blocking the STUN variant of SDP munging in the early May beta release, a production version of Chrome released <a href="https://developer.chrome.com/release-notes/137" rel="external nofollow">two weeks ago</a> began blocking both the STUN and TURN variants. Other Chromium-based browsers are likely to implement it in the coming weeks. A representative for Firefox-maker Mozilla said the organization prioritizes user privacy and is taking the report seriously
</p>

<p>
	 
</p>

<p>
	"We are actively investigating the reported behavior, and working to fully understand its technical details and implications," Mozilla said in an email. "Based on what we’ve seen so far, we consider these to be severe violations of our anti-tracking policies, and are assessing solutions to protect against these new tracking techniques."
</p>

<p>
	 
</p>

<p>
	The researchers warn that the current fixes are so specific to the code in the Meta and Yandex trackers that it would be easy to bypass them with a simple update.
</p>

<p>
	 
</p>

<p>
	“They know that if someone else comes in and tries a different port number, they may bypass this protection,” said Gunes Acar, the researcher behind the initial discovery, referring to the Chrome developer team at Google. “But our understanding is they want to send this message that they will not tolerate this form of abuse.”
</p>

<p>
	 
</p>

<p>
	Fellow researcher Vallina-Rodriguez said the more comprehensive way to prevent the abuse is for Android to overhaul the way it handles access to local ports.
</p>

<p>
	 
</p>

<p>
	“The fundamental issue is that the access to the local host sockets is completely uncontrolled on Android,” he explained. “There's no way for users to prevent this kind of communication on their devices. Because of the dynamic nature of JavaScript code and the difficulty to keep blocklists up to date, the right way of blocking this persistently is by limiting this type of access at the mobile platform and browser level, including stricter platform policies to limit abuse.”
</p>

<h2>
	Got consent?
</h2>

<p>
	The researchers who made this discovery are:
</p>

<p>
	 
</p>

<ul>
	<li>
		Aniketh Girish, PhD student at <a href="https://networks.imdea.org" rel="external nofollow">IMDEA Networks</a>
	</li>
	<li>
		Gunes Acar, assistant professor in <a href="https://www.ru.nl/en/institute-for-computing-and-information-sciences" rel="external nofollow">Radboud University’s</a> Digital Security Group &amp; iHub
	</li>
	<li>
		Narseo Vallina-Rodriguez, associate professor at IMDEA Networks
	</li>
	<li>
		Nipuna Weerasekara, PhD student at IMDEA Networks
	</li>
	<li>
		Tim Vlummens, PhD student at <a href="https://www.esat.kuleuven.be" rel="external nofollow">COSIC, KU Leuven</a>
	</li>
</ul>

<p>
	 
</p>

<p>
	Acar said he first noticed Meta Pixel accessing local ports while visiting his own university's website.
</p>

<p>
	 
</p>

<p>
	There's no indication that Meta or Yandex has disclosed the tracking to either websites hosting the trackers or end users who visit those sites. Developer forums show that many websites using Meta Pixel were caught off guard when the scripts began connecting to local ports.
</p>

<p>
	 
</p>

<p>
	“Since 5th September, our internal JS error tracking has been flagging failed fetch requests to localhost:12387,” one developer <a href="https://developers.facebook.com/community/threads/317050484803752/" rel="external nofollow">wrote</a>. “No changes have been made on our side, and the existing Facebook tracking pixel we use loads via Google Tag Manager.”
</p>

<p>
	 
</p>

<p>
	“Is there some way I can disable this?” another developer encountering the unexplained local port access <a href="https://developers.facebook.com/community/threads/937149104821259/" rel="external nofollow">asked</a>.
</p>

<p>
	 
</p>

<p>
	It's unclear whether browser-to-native-app tracking violates any privacy laws in various countries. Both Meta and companies hosting its Meta Pixel, however, <a href="https://arstechnica.com/tech-policy/2022/09/lawsuits-say-meta-evaded-apple-privacy-settings-to-spy-on-millions-of-users/" rel="external nofollow">have</a> <a href="https://arstechnica.com/tech-policy/2022/11/major-tax-filing-websites-secretly-share-income-data-with-meta/" rel="external nofollow">faced</a> a <a href="https://arstechnica.com/tech-policy/2023/07/meta-wont-say-what-happened-to-taxpayer-data-it-may-have-illegally-collected/" rel="external nofollow">raft</a> of <a href="https://arstechnica.com/tech-policy/2024/02/amc-to-pay-8m-for-allegedly-violating-1988-law-with-use-of-meta-pixel/" rel="external nofollow">lawsuits</a> in recent years alleging that the data collected violates privacy statutes. A <a href="https://arxiv.org/pdf/2208.00710" rel="external nofollow">research paper</a> from 2023 found that Meta pixel, then called the Facebook Pixel, "tracks a wide range of user activities on websites with alarming detail, especially on websites classified as sensitive categories under GDPR," the abbreviation for the European Union's General Data Protection Regulation.
</p>

<p>
	 
</p>

<p>
	So far, Google has provided no indication that it plans to redesign the way Android handles local port access. For now, the most comprehensive protection against Meta Pixel and Yandex Metrica tracking is to refrain from installing the Facebook, Instagram, or Yandex apps on Android devices.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/security/2025/06/meta-and-yandex-are-de-anonymizing-android-users-web-browsing-identifiers/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29537</guid><pubDate>Tue, 03 Jun 2025 19:41:49 +0000</pubDate></item><item><title>Google confirms more ads on your paid YouTube Premium Lite soon</title><link>https://nsaneforums.com/news/security-privacy-news/google-confirms-more-ads-on-your-paid-youtube-premium-lite-soon-r29510/</link><description><![CDATA[<p>
	It is no secret that YouTube has been trying to make it harder and harder for users to block ads on its app. Back in March, earlier this year, we reported on problems users, including us, noticed across various browsers <a href="https://www.neowin.net/news/google-not-letting-youtube-videos-play-with-opera-firefox-adblockers-chrome-is-slow/" rel="external nofollow">including the likes of Chrome, Opera, and Firefox</a>.
</p>

<p>
	 
</p>

<p>
	Later in the same month, Google released its new paid subscription tier called "<a href="https://www.neowin.net/news/google-launches-youtube-premium-lite-in-the-us-with-no-ads-on-most-videos/" rel="external nofollow">YouTube Premium Lite.</a>" However, this is not a completely ad-free service as users are still served adverts during their YouTube sessions, although the number of ads is far lower than what a user would see on the free app. The idea is quite similar to <a href="https://www.neowin.net/news/netflixs-cheapest-ad-based-plan-now-has-40-million-subscribers-worldwide/" rel="external nofollow">Netflix's Basic with Ads plan, which</a> was released back in 2022.
</p>

<p>
	 
</p>

<p>
	Besides a non-ad-free experience, the $7.99 Premium Lite subscription also removed several other cool features like the ability to download videos for offline viewing and background play, which can be quite convenient for listening to music on the app. Speaking of music, YouTube Premium Lite also does not include access to YouTube Music.
</p>

<p>
	 
</p>

<p>
	Unfortunately, Google is tweaking this plan for the worse, as it will soon add adverts to short videos. The company has seemingly started sending emails to customers who are using the Premium Lite tier, informing them about the change that begins later this month, on 30 June.
</p>

<p>
	 
</p>

<p>
	Here is what the mail says:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Thank you for being a Premium Lite member. Premium Lite offers fewer interruptions so you can watch more of the YouTube you love.
	</p>

	<p>
		 
	</p>

	<p>
		We are writing to let you know that beginning 30 June 2025, ads may appear on Shorts, in addition to music content and when you search or browse. Most videos will continue to remain ad-free.
	</p>
</blockquote>

<p>
	The above was shared by user <a href="https://www.twit.community/t/youtube-premium-enshitification/18537" rel="external nofollow">big_D</a> on the TWiT.community forum. German outlet <a href="https://www.deskmodder.de/blog/2025/05/31/youtube-premium-lite-ab-30-6-mehr-werbung/" rel="external nofollow">Deskmodder</a> also reported on this, which suggests that the rollout might be happening globally on the same June 30, 2025 date.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/google-confirms-more-ads-on-your-paid-youtube-premium-lite-soon/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29510</guid><pubDate>Mon, 02 Jun 2025 19:25:35 +0000</pubDate></item><item><title>Breaking down why Apple TVs are privacy advocates&#x2019; go-to streaming device</title><link>https://nsaneforums.com/news/security-privacy-news/breaking-down-why-apple-tvs-are-privacy-advocates%E2%80%99-go-to-streaming-device-r29490/</link><description><![CDATA[<h3>
	Using the Apple TV app or an Apple account means giving Apple more data, though.
</h3>

<p>
	Every time I write an article about the escalating <a href="https://arstechnica.com/gadgets/2024/08/tv-industrys-ads-tracking-obsession-is-turning-your-living-room-into-a-store/" rel="external nofollow">advertising and tracking</a> on <a href="https://arstechnica.com/gadgets/2024/12/buying-a-tv-in-2025-expect-lower-prices-more-ads-and-an-os-war/" rel="external nofollow">today's TVs</a>, someone brings up Apple TV boxes. Among smart TVs, streaming sticks, and other streaming devices, Apple TVs are largely viewed as a safe haven.
</p>

<p>
	 
</p>

<p>
	"Just disconnect your TV from the Internet and use an Apple TV box."
</p>

<p>
	 
</p>

<p>
	That's the common guidance you'll hear from Ars readers for those seeking the joys of streaming without giving up too much privacy. Based on our research and the experts we've consulted, that advice is pretty solid, as Apple TVs offer significantly more privacy than other streaming hardware providers.
</p>

<p>
	 
</p>

<p>
	But how private are Apple TV boxes, really? Apple TVs don't use <a href="https://www.flatpanelshd.com/news.php?subaction=showfull&amp;id=1730444985" rel="external nofollow">automatic content recognition</a> (ACR, a user-tracking technology leveraged by nearly all smart TVs and streaming devices), but could that change? And what about the software that Apple TV users do use—could those apps provide information about you to advertisers or Apple?
</p>

<p>
	 
</p>

<p>
	In this article, we'll delve into what makes the Apple TV's privacy stand out and examine whether users should expect the limited ads and enhanced privacy to last forever.
</p>

<h2>
	Apple TV boxes limit tracking out of the box
</h2>

<p>
	One of the simplest ways Apple TVs ensure better privacy is through their setup process, during which you can disable Siri, location tracking, and sending analytics data to Apple. During setup, users also receive several opportunities to review Apple's data and privacy policies. Also off by default is the boxes' ability to send voice input data to Apple.
</p>

<p>
	 
</p>

<p>
	Most other streaming devices require users to navigate through pages of settings to disable similar tracking capabilities, which most people are unlikely to do. Apple’s approach creates a line of defense against snooping, even for those unaware of how invasive smart devices can be.
</p>

<p>
	 
</p>

<p>
	Apple TVs running tvOS 14.5 and later also make third-party app tracking more difficult by requiring such apps to request permission before they can track users.
</p>

<p>
	 
</p>

<p>
	"If you choose Ask App Not to Track, the app developer can’t access the system advertising identifier (IDFA), which is often used to track," <a href="https://support.apple.com/en-us/102420" rel="external nofollow">Apple says</a>. "The app is also not permitted to track your activity using other information that identifies you or your device, like your email address."
</p>

<p>
	 
</p>

<p>
	Users can access the Apple TV settings and disable the ability of third-party apps to ask permission for tracking. However, Apple could further enhance privacy by enabling this setting by default.
</p>

<p>
	 
</p>

<p>
	The Apple TV also lets users control which apps can access the set-top box's Bluetooth functionality, photos, music, and HomeKit data (if applicable), and the remote's microphone.
</p>

<p>
	 
</p>

<p>
	"Apple’s primary business model isn’t dependent on selling targeted ads, so it has somewhat less incentive to harvest and monetize incredible amounts of your data," said RJ Cross, director of the consumer privacy program at the Public Interest Research Group (<a href="https://pirg.org/about/" rel="external nofollow">PIRG</a>). "I personally trust them more with my data than other tech companies."
</p>

<h2>
	What if you share analytics data?
</h2>

<p>
	If you allow your Apple TV to share analytics data with Apple or app developers, that data won't be personally identifiable, <a href="https://www.apple.com/privacy/features/" rel="external nofollow">Apple says</a>. Any collected personal data is "not logged at all, removed from reports before they’re sent to Apple, or protected by techniques, such as differential privacy," Apple says.
</p>

<p>
	 
</p>

<p>
	Differential privacy, which injects noise into collected data, is one of the most common methods used for anonymizing data. In support documentation (<a href="https://cdn.arstechnica.net/wp-content/uploads/2025/05/Differential_Privacy_Overview.pdf" rel="external nofollow">PDF</a>), Apple details its use of differential privacy:
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		The first step we take is to privatize the information using local differential privacy on the user’s device. The purpose of privatization is to assure that Apple’s servers don't receive clear data. Device identifiers are removed from the data, and it is transmitted to Apple over an encrypted channel. The Apple analysis system ingests the differentially private contributions, dropping IP addresses and other metadata. The final stage is aggregation, where the privatized records are processed to compute the relevant statistics, and the aggregate statistics are then shared with relevant Apple teams. Both the ingestion and aggregation stages are performed in a restricted access environment so even the privatized data isn’t broadly accessible to Apple employees.
	</p>
</blockquote>

<h2>
	What if you use an Apple account with your Apple TV?
</h2>

<p>
	Another factor to consider is Apple's privacy policy regarding Apple accounts, formerly Apple IDs.
</p>

<p>
	 
</p>

<p>
	Apple support documentation <a href="https://support.apple.com/guide/tv/set-up-apple-tv-atvb73e46488/tvos" rel="external nofollow">says</a> you "need" an Apple account to use an Apple TV, but you can use the hardware without one. Still, it's common for people to log into Apple accounts on their Apple TV boxes because it makes it easier to link with other Apple products. Another reason someone might link an Apple TV box with an Apple account is to use the Apple TV app, a common way to stream on Apple TV boxes.
</p>

<p>
	 
</p>

<p>
	So what type of data does Apple harvest from Apple accounts? According to its <a href="https://www.apple.com/legal/privacy/en-ww/" rel="external nofollow">privacy policy</a>, the company gathers usage data, such as "data about your activity on and use of" Apple offerings, including "app launches within our services...; browsing history; search history; [and] product interaction."
</p>

<p>
	 
</p>

<p>
	Other types of data Apple may collect from Apple accounts include transaction information (Apple says this is "data about purchases of Apple products and services or transactions facilitated by Apple, including purchases on Apple platforms"), account information ("including email address, devices registered, account status, and age"), device information (including serial number and browser type), contact information (including physical address and phone number), and payment information (including bank details). None of that is surprising considering the type of data needed to make an Apple account work.
</p>

<p>
	 
</p>

<p>
	Many Apple TV users can expect Apple to gather more data from their Apple account usage on other devices, such as iPhones or Macs. However, if you use the same Apple account across multiple devices, Apple recognizes that all the data it has collected from, for example, your iPhone activity, also applies to you as an Apple TV user.
</p>

<p>
	 
</p>

<p>
	A potential workaround could be maintaining multiple Apple accounts. With an Apple account solely dedicated to your Apple TV box and Apple TV hardware and software tracking disabled as much as possible, Apple would have minimal data to ascribe to you as an Apple TV owner. You can also use your Apple TV box without an Apple account, but then you won't be able to use the Apple TV app, one of the device's key features.
</p>

<p>
	 
</p>

<h2>
	Data collection via the Apple TV app
</h2>

<p>
	You can download third-party apps like Netflix and Hulu onto an Apple TV box, but most TV and movie watching on Apple TV boxes likely occurs via the Apple TV app. The app is necessary for watching content on the Apple TV+ streaming service, but it also drives usage by providing access to the libraries of many (<a href="https://www.theverge.com/news/613307/netflix-apple-tv-app-support-mistake" rel="external nofollow">but not all</a>) popular streaming apps in one location. So understanding the Apple TV app’s privacy policy is critical to evaluating how private Apple TV activity truly is.
</p>

<p>
	 
</p>

<p>
	As expected, some of the data the app gathers is necessary for the software to work. That includes, according to the app's <a href="https://www.apple.com/legal/privacy/data/en/apple-tv-app/" rel="external nofollow">privacy policy</a>, "information about your purchases, downloads, activity in the Apple TV app, the content you watch, and where you watch it in the Apple TV app and in connected apps on any of your supported devices." That all makes sense for ensuring that the app remembers things like which episode of <em>Severance</em> you're on across devices.
</p>

<p>
	 
</p>

<p>
	Apple collects other data, though, that isn't necessary for functionality. It says it gathers data on things like the "features you use (for example, Continue Watching or Library)," content pages you view, how you interact with notifications, and approximate location information (that Apple says doesn't identify users) to help improve the app.
</p>

<p>
	 
</p>

<p>
	Additionally, Apple tracks the terms you search for within the app, per its policy:
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		We use Apple TV search data to improve models that power Apple TV. For example, aggregate Apple TV search queries are used to fine-tune the Apple TV search model.
	</p>
</blockquote>

<p>
	This data usage is less intrusive than that of other streaming devices, which might track your activity and then sell that data to third-party advertisers. But some people may be hesitant about having <em>any</em> of their activities tracked to benefit a multi-trillion-dollar conglomerate.
</p>

<p>
	 
</p>

<h2>
	Data collected from the Apple TV app used for ads
</h2>

<p>
	By default, the Apple TV app also tracks "what you watch, your purchases, subscriptions, downloads, browsing, and other activities in the Apple TV app" to make personalized content recommendations. Content recommendations aren't ads in the traditional sense but instead provide a way for Apple to push you toward products by analyzing data it has on you.
</p>

<p>
	 
</p>

<p>
	You can disable the Apple TV app's personalized recommendations, but it's a little harder than you might expect since you can't do it through the app. Instead, you need to go to the Apple TV settings and then select Apps &gt; TV &gt; Use Play History &gt; Off.
</p>

<p>
	 
</p>

<p>
	The most privacy-conscious users may wish that personalized recommendations were off by default. Darío Maestro, senior legal fellow at the nonprofit Surveillance Technology Oversight Project (<a href="https://www.stopspying.org/programs" rel="external nofollow">STOP</a>), noted to Ars that even though Apple TV users can opt out of personalized content recommendations, "many will not realize they can."
</p>

<p>
	 
</p>

<p>
	Apple can also use data it gathers on you from the Apple TV app to serve traditional ads. If you allow your Apple TV box to track your location, the Apple TV app can also track your location. That data can "be used to serve geographically relevant ads," according to the Apple TV app privacy policy. Location tracking, however, is off by default on Apple TV boxes.
</p>

<p>
	 
</p>

<p>
	Apple's tvOS doesn't have integrated ads. For comparison, some TV OSes, <a href="https://arstechnica.com/gadgets/2024/04/roku-ad-push-continues-with-plans-to-put-video-ads-in-os-home-screen/" rel="external nofollow">like Roku OS</a> and<a href="https://arstechnica.com/gadgets/2024/09/lg-tvs-continue-down-advertising-rabbit-hole-with-new-screensaver-ads/" rel="external nofollow"> LG's webOS</a>, show ads on the OS's home screen and/or when <a href="https://arstechnica.com/gadgets/2025/04/cheap-tvs-incessant-advertising-reaches-troubling-new-lows/" rel="external nofollow">showing screensavers</a>.
</p>

<p>
	 
</p>

<p>
	But data gathered from the Apple TV app can still help Apple's advertising efforts. This can happen if you allow personalized ads in <em>other</em> Apple apps serving targeted apps, such as Apple News, the App Store, or Stocks. In such cases, Apple may apply data gathered from the Apple TV app, "including information about the movies and TV shows you purchase from Apple, to serve ads in those apps that are more relevant to you," the Apple TV app privacy policy says.
</p>

<p>
	 
</p>

<p>
	Apple also provides third-party advertisers and strategic partners with "non-personal data" gathered from the Apple TV app:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		We provide some non-personal data to our advertisers and strategic partners that work with Apple to provide our products and services, help Apple market to customers, and sell ads on Apple’s behalf to display on the App Store and Apple News and Stocks.
	</p>
</blockquote>

<p>
	Apple also shares non-personal data from the Apple TV with third parties, such as content owners, so they can pay royalties, gauge how much people are watching their shows or movies, "and improve their associated products and services," Apple says.
</p>

<p>
	 
</p>

<p>
	Apple's policy notes:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		For example, we may share non-personal data about your transactions, viewing activity, and region, as well as aggregated user demographics[,] such as age group and gender (which may be inferred from information such as your name and salutation in your Apple Account), to Apple TV strategic partners, such as content owners, so that they can measure the performance of their creative work [and] meet royalty and accounting requirements.
	</p>
</blockquote>

<p>
	When reached for comment, an Apple spokesperson told Ars that Apple TV users can clear their play history from the app.
</p>

<p>
	 
</p>

<p>
	All that said, the Apple TV app still shares far less data with third parties than other streaming apps. Netflix, for example, <a href="https://help.netflix.com/legal/privacy" rel="external nofollow">says</a> it discloses some personal information to advertising companies "in order to select Advertisements shown on Netflix, to facilitate interaction with Advertisements, and to measure and improve effectiveness of Advertisements."
</p>

<p>
	 
</p>

<p>
	Warner Bros. Discovery <a href="https://www.max.com/privacy/en-us#howwedisclose" rel="external nofollow">says</a> it discloses information about Max viewers "with advertisers, ad agencies, ad networks and platforms, and other companies to provide advertising to you based on your interests." And Disney+ users have Nielsen tracking on by default.
</p>

<h2>
	What if you use Siri?
</h2>

<p>
	You can easily deactivate Siri when setting up an Apple TV. But those who opt to keep the voice assistant and the ability to control Apple TV with their voice take somewhat of a privacy hit.
</p>

<p>
	 
</p>

<p>
	According to the privacy policy accessible in Apple TV boxes' settings, Apple boxes automatically send all Siri requests to Apple's servers. If you opt into using Siri data to "Improve Siri and Dictation," Apple will store your audio data. If you opt out, audio data won't be stored, but per the policy:
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		In all cases, transcripts of your interactions will be sent to Apple to process your requests and may be stored by Apple.
	</p>
</blockquote>

<p>
	Apple TV boxes also send audio and transcriptions of dictation input to Apple servers for processing. Apple says it doesn't store the audio but may store transcriptions of the audio.
</p>

<p>
	 
</p>

<p>
	If you opt to "Improve Siri and Dictation," Apple says your history of voice requests isn't tied to your Apple account or email. But Apple is vague about how long it may store data related to voice input performed with the Apple TV if you choose this option.
</p>

<p>
	 
</p>

<p>
	The policy states:
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Your request history, which includes transcripts and any related request data, is associated with a random identifier for up to six months and is not tied to your Apple Account or email address. After six months, you request history is disassociated from the random identifier and may be retained for up to two years. Apple may use this data to develop and improve Siri, Dictation, Search, and limited other language processing functionality in Apple products ...
	</p>

	<p>
		 
	</p>

	<p>
		Apple may also review a subset of the transcripts of your interactions and this ... may be kept beyond two years for the ongoing improvements of products and services.
	</p>
</blockquote>

<p>
	Apple promises not to use Siri and voice data to build marketing profiles or sell them to third parties, but it hasn't always adhered to that commitment. In January, Apple agreed to <a href="https://arstechnica.com/tech-policy/2025/01/apple-agrees-to-pay-95m-delete-private-conversations-siri-recorded/" rel="external nofollow">pay $95 million</a> to settle a class-action lawsuit accusing Siri of recording private conversations and sharing them with third parties for targeted ads. In 2019, contractors <a href="https://arstechnica.com/tech-policy/2019/08/apple-will-stop-storing-your-siri-voice-recordings-by-default/" rel="external nofollow">reported</a> hearing private conversations and recorded sex via Siri-gathered audio.
</p>

<p>
	 
</p>

<p>
	Outside of Apple, we've seen voice request data <a href="https://arstechnica.com/gadgets/2025/03/everything-you-say-to-your-echo-will-be-sent-to-amazon-starting-on-march-28/" rel="external nofollow">used questionably</a>, including <a href="https://arstechnica.com/tech-policy/2018/11/amazon-must-give-up-echo-recordings-in-double-murder-case-judge-rules/" rel="external nofollow">in criminal trials</a> and<a href="https://arstechnica.com/tech-policy/2019/04/amazon-admits-that-employees-review-small-sample-of-alexa-audio/" rel="external nofollow"> by corporate employees</a>. Siri and dictation data also represent additional ways a person's Apple TV usage might be unexpectedly analyzed to fuel Apple's business.
</p>

<h2>
	Automatic content recognition
</h2>

<p>
	Apple TVs aren't preloaded with <a href="https://www.flatpanelshd.com/news.php?subaction=showfull&amp;id=1730444985" rel="external nofollow">automatic content recognition</a> (ACR), an Apple spokesperson confirmed to Ars, another plus for privacy advocates. But ACR is software, so Apple could technically add it to Apple TV boxes via a software update at some point.
</p>

<p>
	 
</p>

<p>
	Sherman Li, the founder of Enswers, the company that first put <a href="https://www.broadbandtvnews.com/2014/04/25/samsung-invests-in-content-recognition-provider-enswers/" rel="external nofollow">ACR in Samsung TVs</a>, confirmed to Ars that it's technically possible for Apple to add ACR to already-purchased Apple boxes. Years ago, Enswers retroactively added ACR to other types of streaming hardware, including Samsung and LG smart TVs. (Enswers was acquired by Gracenote, which Nielsen now owns.)
</p>

<p>
	 
</p>

<p>
	In general, though, there are challenges to adding ACR to hardware that people already own, Li explained:
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Everyone believes, in theory, you can add ACR anywhere you want at any time because it's software, but because of the way [hardware is] architected... the interplay between the chipsets, like the SoCs, and the firmware is different in a lot of situations.
	</p>
</blockquote>

<p>
	Li pointed to numerous variables that could prevent ACR from being retroactively added to any type of streaming hardware, "including access to video frame buffers, audio streams, networking connectivity, security protocols, OSes, and app interface communication layers, especially at different levels of the stack in these devices, depending on the implementation."
</p>

<p>
	 
</p>

<p>
	Due to the complexity of Apple TV boxes, Li suspects it would be difficult to add ACR to already-purchased Apple TVs. It would likely be simpler for Apple to release a new box with ACR if it ever decided to go down that route.
</p>

<p>
	 
</p>

<p>
	If Apple were to add ACR to old or new Apple TV boxes, the devices would be far less private, and the move would be highly unpopular and eliminate one of the Apple TV's biggest draws.
</p>

<p>
	 
</p>

<p>
	However, Apple reportedly has a growing interest in advertising to streaming subscribers. The Apple TV+ streaming service doesn't currently show commercials, but the company is rumored to be exploring a potential ad tier. The suspicions stem from a reported meeting between Apple and the United Kingdom's ratings body, Barb, to discuss how it might track ads on Apple TV+, according to a July report from <a href="https://www.telegraph.co.uk/business/2024/07/27/apple-tv-plots-uk-adverts/" rel="external nofollow">The Telegraph</a>.
</p>

<p>
	 
</p>

<p>
	Since 2023, Apple has also hired several <span style="box-sizing: border-box; margin: 0px; padding: 0px;"><a href="https://www.businessinsider.com/apple-hired-nbcu-tv-exec-video-ad-ambitions-2024-3" rel="external nofollow" target="_blank">prominent names in advertising</a>, including a former head of advertising at NBCUniversal</span> and a new head of video ad sales. Further, Apple TV+ is one of the few streaming services to remain ad-free, and it's reported to be <a href="https://arstechnica.com/gadgets/2025/03/apple-tv-reportedly-loses-1-billion-a-year-and-thats-okay-for-now/" rel="external nofollow">losing Apple $1 billion per year</a> since its launch.
</p>

<p>
	 
</p>

<p>
	One day soon, Apple may have much more reason to care about advertising in streaming and being able to track the activities of people who use its streaming offerings. That has implications for Apple TV box users.
</p>

<p>
	 
</p>

<p>
	"The more Apple creeps into the targeted ads space, the less I’ll trust them to uphold their privacy promises. You can imagine Apple TV being a natural progression for selling ads," PIRG's Cross said.
</p>

<p>
	 
</p>

<p>
	Somewhat ironically, Apple has marketed its approach to privacy as a positive for advertisers.
</p>

<p>
	 
</p>

<p>
	"Apple’s commitment to privacy and personal relevancy builds trust amongst readers, driving a willingness to engage with content and ads alike," Apple's <a data-saferedirecturl="https://www.google.com/url?q=https://support.apple.com/guide/adguide/advertising-on-apple-news-and-stocks-apd97a18bafa/1.0/icloud/1.0&amp;source=gmail&amp;ust=1746821587542000&amp;usg=AOvVaw1C4k66jlBEX8_yhwGysN7r" href="https://support.apple.com/guide/adguide/advertising-on-apple-news-and-stocks-apd97a18bafa/1.0/icloud/1.0" rel="external nofollow" target="_blank">advertising guide</a> for buying ads on Apple News and Stocks reads.
</p>

<h2>
	The most private streaming gadget
</h2>

<p>
	It remains technologically possible for Apple to introduce intrusive tracking or ads to Apple TV boxes, but for now, the streaming devices are more private than the vast majority of alternatives, save for dumb TVs (which are incredibly hard to find these days). And if Apple follows its own policies, much of the data it gathers should be kept in-house.
</p>

<p>
	 
</p>

<p>
	However, those with strong privacy concerns should be aware that Apple does track certain tvOS activities, especially those that happen through Apple accounts, voice interaction, or the Apple TV app. And while most of Apple's streaming hardware and software settings prioritize privacy by default, some advocates believe there's room for improvement.
</p>

<p>
	 
</p>

<p>
	For example, STOP's Maestro said:
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Unlike in the [European Union], where the upcoming Data Act will set clearer rules on transfers of data generated by smart devices, the US has no real legislation governing what happens with your data once it reaches Apple's servers. Users are left with little way to verify those privacy promises.
	</p>
</blockquote>

<p>
	Maestro suggested that Apple could address these concerns by making it easier for people to conduct security research on smart device software. "Allowing the development of alternative or modified software that can evaluate privacy settings could also increase user trust and better uphold Apple's public commitment to privacy," Maestro said.
</p>

<p>
	 
</p>

<p>
	There are ways to limit the amount of data that advertisers can get from your Apple TV. But if you use the Apple TV app, Apple can use your activity to help make business decisions—and therefore money.
</p>

<p>
	 
</p>

<p>
	As you might expect from a device that connects to the Internet and lets you stream shows and movies, Apple TV boxes aren't totally incapable of tracking you. But they're still the best recommendation for streaming users seeking hardware with more privacy and fewer ads.
</p>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/gadgets/2025/06/all-the-ways-apple-tv-boxes-do-and-mostly-dont-track-you/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29490</guid><pubDate>Sun, 01 Jun 2025 18:48:49 +0000</pubDate></item><item><title>Ubuntu's apport affected by core dump vulnerability, here's how to patch</title><link>https://nsaneforums.com/news/security-privacy-news/ubuntus-apport-affected-by-core-dump-vulnerability-heres-how-to-patch-r29484/</link><description><![CDATA[<p>
	When programs crash on Linux, they usually create a core dump containing the program’s memory at crash time to help developers resolve problems. This is crucial for developers so they can address bugs, but right now, the program responsible for creating core dumps in Ubuntu and <a automate_uuid="fdcd2871-efe7-4585-a369-aca808fed89b" href="https://www.neowin.net/news/anduinos-linux-major-updates-for-windows-11-clone---whats-new-and-how-to-install/" rel="external nofollow">Ubuntu-based distributions like AnduinOS</a>, are also vulnerable to a new exploit.
</p>

<p>
	 
</p>

<p>
	The bug has been tagged with the CVE number <a automate_uuid="250b7b28-fde6-4507-ac30-36d427514dcf" href="https://ubuntu.com/security/CVE-2025-5054" rel="external nofollow">CVE-2025-5054</a> and has a CVSS score of 4.7 (MEDIUM). This bug is inherently harder to exploit because it requires local access to the victim’s computer. Furthermore, Qualys, <a automate_uuid="043b97c4-e337-415f-892f-04c134169c29" href="https://ubuntu.com/blog/apport-local-information-disclosure-vulnerability-fixes-available" rel="external nofollow">which discovered the fault</a>, showed off a demo where it was able to leak hashed user passwords. While this isn’t great, the real-world impact is limited.
</p>

<h3>
	How the vulnerability works
</h3>

<p>
	Qualys found that when apport analyzes application crashes, it has a look if the process was running inside a container before performing consistency checks on it. If an attacker can manage to crash a program within a privileged process and quickly replaces it with the same process ID and residing in both a mount and PID namespace, they can get apport to forward the core dump to them via the namespace. The core dump may contain sensitive information from the privileged process.
</p>

<p>
	 
</p>

<p>
	Aside from the attacker only being able to perform this locally, they must also have significant permissions to carry out the attack, limiting the damage that the issue can cause.
</p>

<h3>
	What to do about it
</h3>

<p>
	Thankfully, Canonical’s security team has already published updates for apport to fix this issue on all affected Ubuntu releases, including Ubuntu Desktop and Ubuntu Server. If you have unattended upgrades switched on, you may already be patched, but if you’re not sure, just check for and apply the latest updates with this command:
</p>

<p>
	 
</p>

<p style="margin-left: 40px;">
	<code>sudo apt update &amp;&amp; sudo apt upgrade</code>
</p>

<p>
	 
</p>

<p>
	If you can’t apply all available updates for whatever reason, then you can run these commands to just update apport:
</p>

<p>
	 
</p>

<p>
	<a automate_uuid="78547dfe-3cdf-44dd-b22d-cc7eec91ca4a" href="https://www.neowin.net/guides/how-to-enable-extended-security-maintenance-on-ubuntu-2004-lts-before-it-dies/" rel="external nofollow">Ubuntu 20.04</a> and newer:
</p>

<p>
	 
</p>

<p style="margin-left: 40px;">
	<code>sudo apt update &amp;&amp; sudo apt install --only-upgrade apport python3-apport</code>
</p>

<p>
	 
</p>

<p>
	<a automate_uuid="25507725-0678-4557-8859-3e9baffded5a" href="https://www.neowin.net/news/canonical-now-offers-live-kernel-patching-for-ubuntu-1604-lts-users/" rel="external nofollow">Ubuntu 16.04</a> and <a automate_uuid="d40d945f-8afa-4d69-a358-543a75681f65" href="https://www.neowin.net/news/canonical-pushes-fourth-point-release-for-ubuntu-1804-lts/" rel="external nofollow">Ubuntu 18.04</a>:
</p>

<p>
	 
</p>

<p style="margin-left: 40px;">
	<code>sudo apt update &amp;&amp; sudo apt install --only-upgrade apport python3-apport python-apport</code>
</p>

<h3>
	Do you need to rush to install this update?
</h3>

<p>
	Given the limited impact of this vulnerability, you’re likely to be fine if you don’t patch right away. With that said, it only takes a couple of minutes to perform the update and it’s good for peace of mind. You may also have more critical updates ready to install to that you haven’t noticed so updating promptly is recommended to catch those too.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/ubuntus-apport-affected-by-core-dump-vulnerability-heres-how-to-patch/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29484</guid><pubDate>Sat, 31 May 2025 19:48:09 +0000</pubDate></item><item><title>Latest VeraCrypt update blocks screenshots and screen recordings</title><link>https://nsaneforums.com/news/security-privacy-news/latest-veracrypt-update-blocks-screenshots-and-screen-recordings-r29479/</link><description><![CDATA[<p>
	The initial announcement of the AI feature <a data-wpel-link="internal" href="https://www.ghacks.net/2024/06/03/microsoft-needs-to-make-windows-11s-recall-feature-opt-in/" rel="external nofollow">Recall for Windows</a> caused quite an uproar in the security community. Microsoft's idea was to introduce an AI tool in Windows that would take a snapshot of the desktop every five seconds, analyze what it displayed to allow the user to interact with the AI about it.
</p>

<p>
	 
</p>

<p>
	Problem was, in its hurry to get the AI feature out in the open, Microsoft forgot security. It turned out, that Recall was set to run by default, that the database that Recall used was not all that well protected. Additionally, despite Microsoft reassuring that Recall would not capture sensitive data, it turned out that it did (<a data-wpel-link="internal" href="https://www.ghacks.net/2024/12/13/the-revised-recall-on-windows-11-is-still-recording-information-that-it-should-not/" rel="external nofollow">and still does</a>).
</p>

<p>
	 
</p>

<p>
	Third-party developers of security software have started to introduce anti-screenshot functionality into their apps. The latest to introduce such a feature are the developers of VeraCrypt, an open source encryption software.
</p>

<p>
	 
</p>

<p>
	VeraCrypt 1.26.24, <a data-wpel-link="external" href="https://veracrypt.io/en/Release%20Notes.html" rel="external nofollow" target="_blank">released on May 30th, 2025</a>, introduces several changes and improvements. One of them is the new protection against screenshots and screen recordings on Windows.
</p>

<p>
	 
</p>

<p>
	Any attempt to capture the VeryCrypt program window after installation of the update hides the program window on the desktop. I have tested this with several screen capturing options, including my favorite tool <a data-wpel-link="internal" href="https://www.ghacks.net/2018/05/24/picpick-is-a-professional-screen-capture-tool-for-windows/" rel="external nofollow">PicPick</a>, the Snipping Tool, pressing the Print-key, and several more.
</p>

<p>
	 
</p>

<p>
	This is the new default behavior. Windows users who do not want this may turn it off again. I had to turn the feature off to screenshot the new option in the VeryCrypt settings. Most users may want to keep it turned on, as it may also protect against malware running on the system that is designed to take screenshots.
</p>

<p>
	 
</p>

<p>
	<img alt="VeraCrypt Screenshot and Recording protection" class="ipsImage" decoding="async" height="720" width="720" src="https://www.ghacks.net/wp-content/uploads/2025/05/veracrypt-screenshot-protection.png">
</p>

<p>
	 
</p>

<p>
	Here is how you disable the screenshot protection in VeraCrypt:
</p>

<p>
	 
</p>

<ol>
	<li>
		Open the main VeraCrypt interface on the Windows system.
	</li>
	<li>
		Go to Settings &gt; Performance / Driver configuration.
	</li>
	<li>
		Uncheck "Disable protection against screenshots and screen recording".
	</li>
	<li>
		Restart the PC.
	</li>
</ol>

<p>
	 
</p>

<p>
	A restart is required to complete the process. Similarly, if you want to turn on the protection again, you need to restart the PC after checking the box in the settings to complete the process.
</p>

<p>
	 
</p>

<p>
	The default behavior, the blocking of screenshots and screen recordings, can be changed with installation parameters. Just run the installer with the parameter DISABLESCREENPROTECTION=1 to disable the security feature.
</p>

<h3>
	Closing Words
</h3>

<p>
	The new screen protection feature is a welcome addition to VeraCrypt. Most users are not affected by the change, at least not negatively. Those who are can turn off the security feature at any time to restore the old status quo.
</p>

<p>
	 
</p>

<p>
	<em>Now You: what is your take on apps implementing screenshot protections? Good security feature or something that you do not find useful? Feel free to leave a comment down below.</em>
</p>


<div id="div-gpt-ad-1524862513262-0">
	 
</div>

<p>
	 
</p>

<p>
	<a href="https://www.ghacks.net/2025/05/31/latest-veracrypt-update-blocks-screenshots-and-screen-recordings/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>
<iframe allowfullscreen="" class="ipsEmbed_finishedLoading" data-controller="core.front.core.autosizeiframe" data-embedauthorid="56074" data-embedcontent="" data-embedid="embed7539834033" src="https://nsaneforums.com/topic/472744-veracrypt-12624/?do=embed&amp;comment=1868220&amp;embedComment=1868220&amp;embedDo=findComment#comment-1868220" style="overflow: hidden; height: 334px; max-width: 502px;"></iframe>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of May): 2,377</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong>
</p>
]]></description><guid isPermaLink="false">29479</guid><pubDate>Sat, 31 May 2025 19:36:00 +0000</pubDate></item><item><title>Microsoft Authenticator users: Your password auto-fill is dying soon - this is what to do</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-authenticator-users-your-password-auto-fill-is-dying-soon-this-is-what-to-do-r29460/</link><description><![CDATA[<p>
	Earlier this month, <a automate_uuid="d22debde-d90f-4954-8dff-e7321f579ce7" href="https://www.neowin.net/news/microsoft-is-killing-its-password-manager-in-authenticator-to-make-everyone-use-edge/" rel="external nofollow">Neowin reported</a> that the password manager in Microsoft Authenticator would start being phased out from June 2025. The plan is that from June, Microsoft Authenticator will no longer let you save new passwords, in July the app will stop auto-filling your data in websites and apps and delete your payment information, and in August, all passwords will disappear.
</p>

<p>
	 
</p>

<p>
	To prepare users for the end of auto-filling, the app, according to <a automate_uuid="9b297535-e37f-4bf8-acb9-d8cdc80472ac" href="https://www.bleepingcomputer.com/news/security/microsoft-authenticator-now-warns-to-export-passwords-before-july-cutoff/" rel="external nofollow">Bleeping Computer</a>, is now showing warnings and explaining how to turn on autofill in Microsoft Edge.
</p>

<p>
	 
</p>

<p>
	These changes to Microsoft Authenticator are set to affect millions of users around the world. On the Google Play Store, the app has over 100 million downloads and 2.1 million reviews, while on the Apple App Store, it has over 505,000 ratings. In just a few days, according to the plan, no new passwords will be savable in Microsoft Authenticator, making it almost useless as a password manager.
</p>

<p>
	 
</p>

<p>
	Microsoft’s move to force users over the Edge password manager makes sense and gets it inline with other companies like Google and Mozilla, which offer <a automate_uuid="9896566a-7d1f-4578-9000-e0fe4a689af4" href="https://www.neowin.net/news/google-password-manager-passkey-support-added-to-ios-and-ipados-17-and-newer/" rel="external nofollow">password managers baked into their browsers</a>. The password manager in Edge also complements Edge’s other security features such as SmartScreen, Password Monitor, and InPrivate search.
</p>

<p>
	 
</p>

<p>
	Microsoft Authenticator password manager users have a choice to make regarding their passwords. If you're invested in the Microsoft ecosystem and are fine using Microsoft Edge, pressing the “Turn on Edge” button in the Authenticator app notification is the best choice. If this isn’t for you, then head to the Authenticator settings and export your passwords to a CSV file and then import them into your choice browser.
</p>

<p>
	 
</p>

<p>
	It’s important to note that this change only affects the password manager component of Microsoft Authenticator, not the whole app. You will still be able to use the app for your one-time passwords. Cynics says this is yet another move by Microsoft to foist its Edge browser onto users.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/microsoft-authenticator-users-your-password-auto-fill-is-dying-soon---this-is-what-to-do/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29460</guid><pubDate>Fri, 30 May 2025 08:11:12 +0000</pubDate></item><item><title>Discord lures users to click on ads by offering them new Orbs currency</title><link>https://nsaneforums.com/news/security-privacy-news/discord-lures-users-to-click-on-ads-by-offering-them-new-orbs-currency-r29445/</link><description><![CDATA[<h3>
	Discord moves further away from being ad-free.
</h3>

<p>
	Discord is further distancing itself from its ad-free beginnings by offering users a new virtual currency for clicking on in-platform advertisements.
</p>

<p>
	 
</p>

<p>
	Acoording to a <a href="https://discord.com/blog/checkpoint-3-leveling-up-discord-quests-with-orbs-and-advanced-measurement" rel="external nofollow">blog post</a> this week by Peter Sellis, Discord’s SVP of product, a “small group” of Discord users around the globe can now earn "Orbs" through <a href="https://arstechnica.com/gadgets/2024/04/discord-starts-down-the-dangerous-road-of-ads-this-week/" rel="external nofollow">Play Quests</a>, which Discord announced in March 2024 and let users earn in-game rewards by getting people to watch a stream of them playing a sponsored game. With enough Orbs, Discord users can purchase items in Discord's shop, including customization options for their profiles and credits for Nitro, a subscription add-on that offers features like 500MB uploads and HD resolution streaming.
</p>

<p>
	 
</p>

<p>
	The goal is to fuel Discord’s advertising business by making clicking on ads more appealing. Advertisers also benefit by associating their ads with the ability to get desirable rewards.
</p>

<p>
	 
</p>

<p>
	“This means that users will have the flexibility to use Orbs on many different rewards, making Quests even more relevant,” Sellis wrote. "This is particularly great for users who want to try Nitro without a current subscription."
</p>

<p>
	 
</p>

<p>
	Sellis said that Orbs will be available to “many more” Discord users “soon” but didn’t specify when.
</p>

<p>
	 
</p>

<p>
	“We will continue to add new ways for users to claim rewards using Orbs in the future and for Nitro subscribers to continue to receive better rewards and deals across our ecosystem,” Sellis wrote.
</p>

<p>
	 
</p>

<p>
	Sellis also announced that Discord is working with brand measurement firm Kantar to help advertisers track ad success. With Kantar technology, advertisers can measure things like “awareness, recall, and intent,” Sellis said. The partnership further underscores Discord's growing reliance on advertising revenue.
</p>

<p>
	 
</p>

<p>
	“Our partnership with Discord is helping marketers better understand Discord as an advertising platform for new generations,” Nicole Jones, Kantar’s chief commercial lead, said on Discord’s blog.
</p>

<h2>
	Rethinking ads
</h2>

<p>
	Discord also announced this week that it will soon sell Play Quests to more advertisers. The announcement follows the company's introduction of <a href="https://arstechnica.com/gadgets/2025/03/discord-heightens-ad-focus-by-introducing-video-ads-to-mobile-apps-in-june/" rel="external nofollow">video ads to the Discord mobile app</a> in June. Video Quests, as they’re called, allow advertisers to show trailers, announcements, and other types of content.
</p>

<p>
	 
</p>

<p>
	Overall, Discord’s new ad-friendly approach to business is very different than its previous strategy, which kept Discord ad-free from its 2015 launch until last year. Because the company is expected to <a href="https://arstechnica.com/gaming/2025/03/report-discord-partners-with-jp-morgan-chase-goldman-sachs-for-a-2025-ipo/" rel="external nofollow">go public soon</a>, its leaders have determined that it’s no longer sufficient to rely completely on premium add-ons and subscriptions. Discord isn’t profitable, forcing the firm to reconsider its use of ads, which cofounder and CEO Jason Citron felt were too intrusive as recently <a href="https://www.wsj.com/tech/a-social-network-without-ads-discord-defies-convention-11615199401" rel="external nofollow">as 2021</a>.
</p>

<p>
	 
</p>

<p>
	Currently, Discord’s ads are limited to clickable sidebars within the platform and offer direct benefits to users. Introducing ads can be a slippery slope, though, especially for social media companies that prioritize ad revenue to please investors. On the other hand, another social media company, Reddit, has seen success by boosting its ad business. <a href="https://arstechnica.com/tech-policy/2024/02/report-75k-loyal-redditors-can-snag-shares-before-reddit-goes-public/" rel="external nofollow">Reddit went public</a> in March 2024 and <a href="https://arstechnica.com/gadgets/2024/10/amid-controversial-changes-reddit-is-getting-more-popular-and-profitable/" rel="external nofollow">became profitable</a> in October 2024 after reporting a 60 percent year-over-year increase in ad revenue. Reddit has <span style="box-sizing: border-box; margin: 0px; padding: 0px;">hinted at plans to introduce <a href="https://arstechnica.com/tech-policy/2025/03/new-reddit-controls-let-you-block-your-most-hated-advertisers-for-a-year/" rel="external nofollow" target="_blank">new and more types of ads</a>, and we can expect Discord to consider the same after its IPO, which a <a href="https://www.bloomberg.com/news/articles/2025-03-26/chat-app-discord-is-said-to-work-with-goldman-jpmorgan-on-planned-ipo" rel="external nofollow" target="_blank">March Bloomberg report</a> suggested could happen</span> as soon as this year.
</p>

<p>
	 
</p>

<div class="post-content post-content-double">
	<p>
		<em>Advance Publications, which owns Ars Technica parent Condé Nast, is the largest shareholder in Reddit.</em>
	</p>
</div>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/gadgets/2025/05/discord-lures-users-to-click-on-ads-by-offering-them-new-orbs-currency/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29445</guid><pubDate>Thu, 29 May 2025 18:14:14 +0000</pubDate></item><item><title>Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor</title><link>https://nsaneforums.com/news/security-privacy-news/botnet-hacks-9000-asus-routers-to-add-persistent-ssh-backdoor-r29424/</link><description><![CDATA[<p>
	Over 9,000 ASUS routers are compromised by a novel botnet dubbed "AyySSHush" that was also observed targeting SOHO routers from Cisco, D-Link, and Linksys.
</p>

<p>
	 
</p>

<p>
	The campaign was <a href="https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers" rel="external nofollow" target="_blank">discovered by GreyNoise</a> security researchers in mid-March 2025, who reports that it carries the hallmarks of a nation-state threat actor, though no concrete attributions were made.
</p>

<p>
	 
</p>

<p>
	The threat monitoring firm reports that the attacks combine brute-forcing login credentials, bypassing authentication, and exploiting older vulnerabilities to compromise ASUS routers, including the RT-AC3100, RT-AC3200, and RT-AX55 models.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Observed brute-forcing attempts" class="ipsImage" height="210" width="401" src="https://www.bleepstatic.com/images/news/u/1220909/2025/May/bruteforce.jpg">
		<figcaption>
			<em>Observed brute-forcing attempts<br>
			Source: GreyNoise</em>
		</figcaption>
	</figure>
</div>

<p>
	Specifically, the attackers exploit an old command injection flaw tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39780" rel="external nofollow" target="_blank">CVE-2023-39780</a> to add their own SSH public key and enable the SSH daemon to listen on the non-standard TCP port 53282. This modifications allow the threat actors to retain backdoor access to the device even between reboots and firmware updates.
</p>

<p>
	 
</p>

<p>
	"Because this key is added using the official ASUS features, this config change is persisted across firmware upgrades," explains another <a href="http://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/" rel="external nofollow" target="_blank">related report</a> by GreyNoise.
</p>

<p>
	 
</p>

<p>
	"If you've been exploited previously, upgrading your firmware will <strong>NOT</strong> remove the SSH backdoor."
</p>

<p>
	 
</p>

<p>
	The attack is particularly stealthy, involving no malware, while the attackers also turn off logging and Trend Micro's AiProtection to evade detection.
</p>

<p>
	 
</p>

<p>
	Characteristically, GreyNoise reports logging just 30 malicious requests associated with this campaign over the past three months, though 9,000 ASUS routers have been infected.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Malicious requests targeting ASUS routers" class="ipsImage" height="508" width="720" src="https://www.bleepstatic.com/images/news/u/1220909/2025/May/timeline(1).jpg">
		<figcaption>
			<em>Malicious requests targeting ASUS routers<br>
			Source: GreyNoise</em>
		</figcaption>
	</figure>
</div>

<p>
	Still, three of those requests were enough to trigger GreyNoise's AI-powered analysis tool that flagged them for human inspection.
</p>

<p>
	 
</p>

<p>
	The campaign likely overlaps with the activity Sekoia tracks as "<a href="https://blog.sekoia.io/vicioustrap-infiltrate-control-lure-turning-edge-devices-into-honeypots-en-masse/" rel="external nofollow" target="_blank">Vicious Trap</a>," disclosed last week, though the French cybersecurity firm reported that threat actors leveraged CVE-2021-32030 to breach ASUS routers.
</p>

<p>
	 
</p>

<p>
	In the campaign seen by Sekoia, the threat actors were observed targeting SOHO routers, SSL VPNs, DVRs, and BMC controllers from D-Link, Linksys, QNAP, and Araknis Networks. 
</p>

<p>
	 
</p>

<p>
	The exact operational goal of AyySSHush remains unclear, as there are no signs of distributed denial of service (DDoS) or using the devices to proxy malicious traffic through the ASUS routers.
</p>

<p>
	 
</p>

<p>
	However, in the router breaches observed by Sekoia, a malicious script was downloaded and executed to redirect network traffic from the compromised system to third-party devices controlled by the attacker.
</p>

<p>
	 
</p>

<p>
	Currently, it appears the campaign quietly builds a network of backdoored routers to create the groundwork for a future botnet.
</p>

<h2>
	Protect your ASUS routers
</h2>

<p>
	ASUS has released security updates that address CVE-2023-39780 for the impacted routers, though the exact time of availability varies per model.
</p>

<p>
	 
</p>

<p>
	Users are recommended to upgrade their firmware as soon as possible and look for suspicious files and the addition of the attacker's SSH key (<a href="https://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/" rel="external nofollow" target="_blank">IoCs here</a>) on the 'authorized_keys' file.
</p>

<p>
	 
</p>

<p>
	Also, GreyNoise lists four IP addresses associated with this activity, which should be added to a block list.
</p>

<pre><code>101.99.91[.]151
101.99.94[.]173 
79.141.163[.]179   
111.90.146[.]237</code></pre>

<p>
	If a compromise is suspected, a factory reset is recommended to clean the router beyond doubt and then reconfigure it from scratch using a strong password.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/botnet-hacks-9-000-plus-asus-routers-to-add-persistent-ssh-backdoor/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29424</guid><pubDate>Wed, 28 May 2025 17:43:14 +0000</pubDate></item><item><title>MATLAB dev confirms ransomware attack behind service outage</title><link>https://nsaneforums.com/news/security-privacy-news/matlab-dev-confirms-ransomware-attack-behind-service-outage-r29408/</link><description><![CDATA[<p>
	MathWorks, a leading developer of mathematical computing and simulation software, has revealed that a recent ransomware attack is behind an ongoing service outage.
</p>

<p>
	 
</p>

<p>
	Headquartered in Natick, Massachusetts, and founded in 1984, MathWorks now has over 6,500 employees in 34 offices worldwide. MathWorks develops the MATLAB numeric computing platform and the Simulink simulation, which are used by over 100,000 organizations and over 5 million customers.
</p>

<p>
	 
</p>

<p>
	"MathWorks experienced a ransomware attack. We have notified federal law enforcement of this matter. The attack affected our IT systems," the company <a href="https://status.mathworks.com/incidents/h1fjvcr72n87" rel="external nofollow" target="_blank">disclosed</a> in an incident report published on its official status page.
</p>

<p>
	 
</p>

<p>
	"Some of our online applications used by customers became unavailable, and certain internal systems used by staff became unavailable, beginning on Sunday, May 18."
</p>

<p>
	 
</p>

<p>
	While ongoing outages resulting from this incident still affect many of its online services, including the cloud center, file exchange, license center, and MathWorks store, the company has since brought some back online.
</p>

<p>
	 
</p>

<p>
	For instance, after multiple days of signing issues preventing users from accessing their accounts, MathWorks restored multi-factor authentication (MFA) and account SSO (Single Sign On) on May 21st.
</p>

<p>
	 
</p>

<p>
	Despite this, since Friday, some customers have continued experiencing issues preventing them from creating new accounts, while others who haven't signed in since 11 October 2024 haven't been able to log in at all.
</p>

<p>
	 
</p>

<p>
	MathWorks has yet to reveal additional information regarding this incident, including the name of the ransomware operation behind the attack and whether any customer data was stolen during the breach.
</p>

<p>
	 
</p>

<p>
	Even though the company tagged this incident as a ransomware attack, no ransomware gang has claimed the breach, suggesting that MathWorks has either paid the ransom demanded by the attackers or is still negotiating.
</p>

<p>
	 
</p>

<p>
	A MathWorks spokesperson was not immediately available for comment when contacted by BleepingComputer.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/mathworks-blames-ransomware-attack-for-ongoing-outages/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29408</guid><pubDate>Tue, 27 May 2025 17:38:26 +0000</pubDate></item><item><title>Adidas warns of data breach after customer service provider hack</title><link>https://nsaneforums.com/news/security-privacy-news/adidas-warns-of-data-breach-after-customer-service-provider-hack-r29407/</link><description><![CDATA[<p>
	German sportswear giant Adidas disclosed a data breach after attackers hacked a customer service provider and stole some customers' data.
</p>

<p>
	 
</p>

<p>
	"adidas recently became aware that an unauthorized external party obtained certain consumer data through a third-party customer service provider," the company said on Friday.
</p>

<p>
	 
</p>

<p>
	"We immediately took steps to contain the incident and launched a comprehensive investigation, collaborating with leading information security experts."
</p>

<p>
	 
</p>

<p>
	Adidas added that the stolen information did not include the affected customers' payment-related information or passwords, as the threat actors behind the breach only gained access to contact.
</p>

<p>
	 
</p>

<p>
	The company has also notified the relevant authorities regarding this security incident and will alert those affected by the data breach.
</p>

<p>
	 
</p>

<p>
	"adidas is in the process of informing potentially affected consumers as well as appropriate data protection and law enforcement authorities consistent with applicable law," <a href="https://www.adidas-group.com/en/data-security-information" rel="external nofollow" target="_blank">it added</a>.
</p>

<p>
	 
</p>

<p>
	"We remain fully committed to protecting the privacy and security of our consumers, and sincerely regret any inconvenience or concern caused by this incident."
</p>

<p>
	 
</p>

<p>
	Adidas has yet to reveal further details regarding this incident, including the name of the impacted service provider, when the incident was detected, how many individuals were affected, and if its own network was compromised during the attack.
</p>

<p>
	 
</p>

<p>
	When BleepingComputer reached out to Adidas with questions about the incident, a spokesperson said the company had "no further update" and "the statement from Friday is still valid."
</p>

<p>
	 
</p>

<p>
	Earlier this month, Adidas disclosed data breaches impacting customers in <a href="https://www.hurriyetdailynews.com/adidas-turkiye-unveils-data-breach-affecting-customer-information-209384" rel="external nofollow" target="_blank">Turkey</a> and <a href="https://www.businesskorea.co.kr/news/articleView.html?idxno=242481" rel="external nofollow" target="_blank">South Korea</a> who contacted the company's customer service center in 2024 or earlier. The stolen information in these breaches includes names, email addresses, phone numbers, birthdates, and addresses.
</p>

<p>
	 
</p>

<p>
	In June 2018, Adidas <a href="https://www.bleepingcomputer.com/news/security/adidas-announces-data-breach/" rel="external nofollow" target="_blank">disclosed another breach</a> after unknown attackers stole contact information, usernames, and encrypted passwords of "a few million" shoppers who used the sportswear company's U.S. website.
</p>

<p>
	 
</p>

<p>
	<em>Update May 27, 11:18 EDT: Added Adidas statement.</em>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/adidas-warns-of-data-breach-after-customer-service-provider-hack/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29407</guid><pubDate>Tue, 27 May 2025 17:37:13 +0000</pubDate></item><item><title>184 million records data leak: Google, PayPal and Netflix passwords leaked online</title><link>https://nsaneforums.com/news/security-privacy-news/184-million-records-data-leak-google-paypal-and-netflix-passwords-leaked-online-r29400/</link><description><![CDATA[<p>
	Security researcher Jeremiah Fowler stumbled upon a large database of login information and passwords containing over 184 million records recently. He mentioned the discovery in an article on <a data-wpel-link="external" href="https://www.websiteplanet.com/news/infostealer-breach-report/" rel="external nofollow" target="_blank">Website Planet</a>.
</p>

<p>
	 
</p>

<p>
	The data was not encrypted in any form and stored publicly, which meant that anyone with knowledge of its existence could download the data.
</p>

<p>
	 
</p>

<p>
	The sheer size of the database, more than 47 gigabytes of data, makes it one of the largest leaks in recent history. In early 2024, a <a data-wpel-link="internal" href="https://www.ghacks.net/2024/01/18/70-million-account-credentials-were-leaked-in-a-massive-password-dump/" rel="external nofollow">70 million records password dump</a> was discovered.
</p>

<p>
	 
</p>

<p>
	A preliminary sampling of the data unveiled emails, usernames, passwords, and also links to login or authorization pages. Fowler found login information and passwords for a wide range of services in the dump. Notable products and services include Facebook, Instagram, Snapchat, Microsoft products, Google, Discord, and NHS.
</p>

<p>
	 
</p>

<p>
	Fowler discovered the database in early May 2025 and reported it to the web hosting company, which blocked public access shortly after to prevent further spreading of the data. He wrote to several of the email accounts found in the database to verify the authenticity of the data and was able to confirm it based on the replies that he received.
</p>

<p>
	 
</p>

<p>
	The security researcher suspects that it could be an infostealer's dump. Infostealer malware is designed to copy sensitive information, including passwords, cookies, recovery keys, credit card numbers, on infected systems.
</p>

<h3>
	The potential risks
</h3>

<p>
	Cybercriminals may use exposed credentials and other sensitive data for various attacks or gains:
</p>

<p>
	 
</p>

<ul>
	<li>
		<strong>Credential stuffing</strong>: this refers to trying found username and password combinations on popular sites. Many Internet users use the same username and passwords on sites. Gain access to one, gain potential access to all.
	</li>
	<li>
		<strong>Account takeovers:</strong> changing the password of the account may block the original owner from signing in, especially if identification information, such as linked email addresses or phone numbers, are also changed.
	</li>
	<li>
		<strong>Corporate / government espionage:</strong> gain access to corporate or government networks through the accounts of employees.
	</li>
	<li>
		<strong>Phishing and social engineering:</strong> attacks may be run against emails or mobile phone numbers found in the dump.
	</li>
</ul>

<h3>
	How to protect your accounts
</h3>

<p>
	The database is no longer available online and it has not been integrated into a tool like Have I Been Pwned yet. Users may improve the security of their online accounts as a precautionary measure.
</p>

<p>
	 
</p>

<p>
	Here are our suggestions:
</p>

<p>
	 
</p>

<ul>
	<li>
		<strong>Make sure that each online account uses a secure, unique password</strong>. Avoid dictionary words and names in passwords and combine numbers, upper- and lower-case letters, and special characters. Password managers are your friend.
	</li>
	<li>
		<strong>Enable two-factor authentication</strong>, especially for high-value accounts, e.g., PayPal, your email account, bank accounts and so on.
	</li>
	<li>
		<strong>Alternative</strong>: passkeys or <a data-wpel-link="internal" href="https://www.ghacks.net/2023/11/16/google-launches-updated-titan-security-keys-with-fido2-support/" rel="external nofollow">security keys</a> for extra security.
	</li>
	<li>
		<strong>Protect sensitive data,</strong> e.g. financial documents, tax information, medical documents, private photos and videos. Encryption is key.
	</li>
	<li>
		<strong>Don't store sensitive information in email accounts or online</strong>.
	</li>
	<li>
		<strong>Use good antivirus</strong> and keep it up to date to protect against the bulk of threats online.
	</li>
</ul>

<p>
	 
</p>

<p>
	<em>Now you: have any tips on staying secure online? Feel free to share them with everyone in the comment section below.</em>
</p>


<div id="div-gpt-ad-1524862513262-0">
	 
</div>

<p>
	 
</p>

<p>
	<a href="https://www.ghacks.net/2025/05/26/184-million-records-data-leak-google-paypal-and-netflix-passwords-discovered/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29400</guid><pubDate>Mon, 26 May 2025 18:04:42 +0000</pubDate></item><item><title>Google claims users find ads in AI search 'helpful'</title><link>https://nsaneforums.com/news/security-privacy-news/google-claims-users-find-ads-in-ai-search-helpful-r29399/</link><description><![CDATA[<p>
	Google AI mode and AI Overviews now have ads, which, according to the search engine giant, are "helpful."
</p>

<p>
	 
</p>

<p>
	At the Google Marketing Live event last week, Google <a href="https://blog.google/products/ads-commerce/google-marketing-live-2025/" rel="external nofollow" target="_blank">confirmed </a>it has started rolling out ads to AI mode and AI Overviews in the US, which create new "opportunities for customers."
</p>

<p>
	 
</p>

<p>
	While I haven't seen ads in AI Overviews, some users <a href="https://x.com/brodieseo/status/1925413497250488334" rel="external nofollow" target="_blank">spotted</a> them last week, and these ads appear below the AI Overviews, followed by the traditional blue links.
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Google AI ads" class="ipsImage" height="405" width="720" src="https://www.bleepstatic.com/images/news/u/1097497/AI/Google-AI-ads.jpg">
		<figcaption>
			<em>Ads in Google AI overviews (Desktop)</em>
		</figcaption>
	</figure>
</div>

<p>
	In a <a href="https://support.google.com/google-ads/answer/16297775#:~:text=Google%20internal%20data%20shows%20that%20people%20have%20been%20finding%20the%20ads%20within%20AI%20Overviews%20helpful" rel="external nofollow" target="_blank">support document</a> spotted by <a href="https://www.seroundtable.com/google-ads-help-doc-ai-overviews-39469.html" rel="external nofollow" target="_blank">SER</a>, Google described ads in AI search results as a new way to find information on the web.
</p>

<p>
	 
</p>

<p>
	SEO consultant <a href="https://x.com/gaganghotra_/status/1926972729674125546" rel="external nofollow" target="_blank">Gagan Ghotra</a> pointed out an interesting excerpt in the document that claims users find ads in these AI search results helpful.
</p>

<p>
	 
</p>

<p>
	"Google internal data shows that people have been finding the ads within AI Overviews helpful because they can quickly connect with relevant businesses, products, and services to take the next step at the exact moment they need them," the company wrote in the document.
</p>

<p>
	 
</p>

<p>
	Google won't share the numbers or methodology of its "internal data," but it wants you to believe that ads are helpful, especially in AI search results.
</p>

<p>
	 
</p>

<p>
	Ads aren't necessarily bad, but they're certainly not helpful when they mislead users or appear above the actual content and disrupt the flow.
</p>

<p>
	 
</p>

<p>
	Google <a href="https://www.emarketer.com/content/google-posts--96-5-billion-q4-revenue--ad-growth-only-half-of-meta-s#:~:text=Advertising%20revenues" rel="external nofollow" target="_blank">reported </a>$72.5 billion in advertising revenue in its last quarterly report, and it's expected to increase as ads expand beyond the blue links.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/google/google-claims-users-find-ads-in-ai-search-helpful/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29399</guid><pubDate>Mon, 26 May 2025 18:00:50 +0000</pubDate></item><item><title>Ubuntu 25.10 to provide security boost by securely fetching the time</title><link>https://nsaneforums.com/news/security-privacy-news/ubuntu-2510-to-provide-security-boost-by-securely-fetching-the-time-r29365/</link><description><![CDATA[<p>
	Canonical has announced that it’ll begin using a piece of software called chrony for more secure time management, starting with Ubuntu 25.10. End users don’t need to worry about this change too much, but it will result in strengthened system security, especially for cryptographic operations and certificate validation.
</p>

<p>
	 
</p>

<p>
	Once implemented, Ubuntu will use chrony instead of systemd-timesyncd. The trouble with systemd-timesyncd is that it uses the Network Time Protocol (NTP), instead of the improved Network Time Security (NTS). While NTP is good at keeping time, it doesn’t authenticate the time source; this could lead to your system getting the wrong time from a malicious server, which could mess with security checks when visiting a secure website.
</p>

<p>
	 
</p>

<p>
	Getting a little bit technical, NTP uses port 123/UDP to send and receive data. UDP (User Datagram Protocol) is capable of sending data quickly but it doesn’t guarantee delivery or order. If data is lost, it doesn’t matter since updates are frequent.
</p>

<p>
	 
</p>

<p>
	With NTS, before the time is fetched, your computer starts by performing a secure handshake with the NTS server, similar to how websites using HTTPS establish a secure connection. NTS does this handshake over a different port, 4460/TCP. TCP, or Transmission Control Protocol, is more reliable for sending data as it ensures all data arrives in the correct order.
</p>

<p>
	 
</p>

<p>
	Once the connection is established, then the time synchronization happens over the NTP port, but each time, it’s cryptographically signed meaning the time information is authentic and hasn’t been altered.
</p>

<p>
	 
</p>

<p>
	The switch to chrony will take place on June 5, according to the <a automate_uuid="d8c9bfe4-c16b-4efe-8ce9-11c92ede82ec" href="https://discourse.ubuntu.com/t/questing-quokka-release-schedule/36462" rel="external nofollow">current schedule</a>. So, if you decide to try the daily image of Ubuntu 25.10 after this date, you should be running Ubuntu with chrony fetching the time securely.
</p>

<p>
	 
</p>

<p>
	Source: <a automate_uuid="df514788-31b2-4b6a-a127-0fd70f2503fb" href="https://lists.ubuntu.com/archives/ubuntu-devel/2025-May/043355.html" rel="external nofollow">Ubuntu Mailing List</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/ubuntu-2510-to-provide-security-boost-by-securely-fetching-the-time/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29365</guid><pubDate>Fri, 23 May 2025 17:22:53 +0000</pubDate></item><item><title>Mysterious Database of 184 Million Records Exposes Vast Array of Login Credentials</title><link>https://nsaneforums.com/news/security-privacy-news/mysterious-database-of-184-million-records-exposes-vast-array-of-login-credentials-r29350/</link><description><![CDATA[<h3>
	A trove of breached data, which has now been taken down, includes user logins for platforms including Apple, Google, and Meta. Among the exposed accounts are ones linked to dozens of governments.
</h3>

<p>
	<span class="lead-in-text-callout">The possibility that</span> data could be inadvertently exposed in a <a href="https://www.wired.com/story/amazon-s3-data-exposure/" rel="external nofollow">misconfigured</a> or <a href="https://www.wired.com/story/confidant-health-therapy-records-database-exposure/" rel="external nofollow">otherwise unsecured</a> <a href="https://www.wired.com/story/ntmc-bangladesh-database-leak/" rel="external nofollow">database</a> is a longtime privacy nightmare that has been difficult to fully address. But the new discovery of a massive trove of 184 million records—including Apple, Facebook, and Google logins and credentials for accounts connected to multiple governments—underscores the risks of recklessly compiling sensitive information in a repository that could become a single point of failure.
</p>

<p>
	 
</p>

<p>
	In early May, longtime data-breach hunter and security researcher Jeremiah Fowler discovered an <a class="external-link" data-event-boundary="click" data-event-click='{"pattern":"ExternalLink"}' data-in-view='{"pattern":"ExternalLink"}' data-include-experiments="true" data-offer-url="https://www.websiteplanet.com/news/infostealer-breach-report/" href="https://www.websiteplanet.com/news/infostealer-breach-report/" rel="external nofollow" target="_blank">exposed Elastic database</a> containing 184,162,718 records across more than 47 GB of data. Typically, Fowler says, he is able to gather clues about who controls an exposed database from its contents—details about the organization, data related to its customers or employees, or other indicators that suggest why the data is being collected. This database, however, didn’t include any clues about who owns the data or where it may have been gathered from.
</p>

<p>
	 
</p>

<p>
	The sheer range and massive scope of the login details, which include accounts connected to a large array of digital services, indicate that the data is some sort of compilation, possibly kept by researchers investigating a data breach or other cybercriminal activity or owned directly by attackers and stolen by <a href="https://www.wired.com/story/infostealer-malware-password-theft/" rel="external nofollow">infostealer</a> <a href="https://www.wired.com/story/lumma-stealer-takedown-disrupted/" rel="external nofollow">malware</a>.
</p>

<p>
	 
</p>

<p>
	“This is probably one of the weirdest ones I’ve found in many years,” Fowler says. “As far as the risk factor here, this is way bigger than most of the stuff I find, because this is direct access into individual accounts. This is a cybercriminal’s dream working list.”
</p>

<p>
	 
</p>

<p>
	Each record included an ID tag for the type of account, a URL for each website or service, and then usernames and plaintext passwords. Fowler notes that the password field was called “Senha,” the Portuguese word for password.
</p>

<p>
	 
</p>

<div>
	<div aria-hidden="true" class="ConsumerMarketingUnitThemedWrapper-iUTMTf jssHut consumer-marketing-unit consumer-marketing-unit--article-mid-content" role="presentation">
		<div class="consumer-marketing-unit__slot consumer-marketing-unit__slot--article-mid-content consumer-marketing-unit__slot--in-content">
			 
		</div>

		<div class="journey-unit">
			 
		</div>
	</div>
</div>

<p>
	In a sample of 10,000 records analyzed by Fowler, there were 479 Facebook accounts, 475 Google accounts, 240 Instagram accounts, 227 Roblox accounts, 209 Discord accounts, and more than 100 each of Microsoft, Netflix, and PayPal accounts. That sample—just a tiny fraction of the total exposure—also included Amazon, Apple, Nintendo, Snapchat, Spotify, Twitter, WordPress, and Yahoo logins, among many others. A keyword search of the sample by Fowler returned 187 instances of the word “bank” and 57 of “wallet.”
</p>

<p>
	 
</p>

<p>
	Fowler, who did not download the data, says he contacted a sample of the exposed email addresses and heard back from some that they were genuine accounts.
</p>

<p>
	 
</p>

<div class="AdWrapper-dQtivb fZrssQ ad ad--in-content">
	<div class="ad__slot ad__slot--in-content" data-node-id="nwt7m">
		 
	</div>
</div>

<p>
	Aside from individuals, the exposed data also presented potential national security risks, Fowler says. In the 10,000 sample records there were 220 email addresses with .gov domains. These were linked to at least 29 countries, including the United States, Australia, Canada, China, India, Israel, New Zealand, Saudi Arabia, and the United Kingdom.
</p>

<p>
	 
</p>

<p>
	While Fowler could not identify who had put the database together or where the login details originally came from, he reported the data exposure to World Host Group, the hosting company it was linked to. Access to the database was quickly shut down, Fowler says, although World Host Group did not respond to the researcher until after it was contacted by WIRED.
</p>

<p>
	 
</p>

<p>
	Seb de Lemos, CEO of World Host Group, tells WIRED in a statement that the company operates systems for more than 2 million websites. The database Fowler found, though, is “an unmanaged server” hosted on World Host Group’s infrastructure and fully controlled by a customer.
</p>

<p>
	 
</p>

<p>
	“It appears a fraudulent user signed up and uploaded illegal content to their server,” de Lemos wrote in the statement. “The system has since been shut down. Our legal team is reviewing any information we have that might be relevant for law enforcement.”
</p>

<p>
	 
</p>

<p>
	De Lemos says that the company is in touch with Fowler and has made improvements to its reporting system. “Whilst we cannot share customer-specific details with WIRED, we will fully cooperate with the appropriate law enforcement authorities and, where appropriate, share all relevant customer data with them.”
</p>

<p>
	 
</p>

<p>
	Though the database has now been secured—and ultimately taken down entirely—it is not clear whether anyone other than Fowler accessed the trove while it was still live. As with any exposed database, the concern is that sensitive data could be stolen and abused. And in this case, there is a particularly urgent risk of logins being exploited in fraud, to steal additional information, or even to breach other organizations.
</p>

<p>
	 
</p>

<p>
	Fowler says that while he does not know for certain, he suspects that the data was compiled by attackers using an <a href="https://www.wired.com/story/infostealer-malware-password-theft/" rel="external nofollow">infostealer</a>.
</p>

<p>
	 
</p>

<p>
	“It is highly possible that this was a cybercriminal,” he says. “It’s the only thing that makes sense, because I can’t think of any other way you would get that many logins and passwords from so many services all around the world.”
</p>

<p>
	 
</p>

<p>
	<a href="https://www.wired.com/story/mysterious-database-logins-governments-social-media/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29350</guid><pubDate>Thu, 22 May 2025 16:37:50 +0000</pubDate></item><item><title>Police arrests 270 dark web vendors, buyers in global crackdown</title><link>https://nsaneforums.com/news/security-privacy-news/police-arrests-270-dark-web-vendors-buyers-in-global-crackdown-r29349/</link><description><![CDATA[<p>
	Police arrested 270 suspects following an international law enforcement action codenamed 'Operation RapTor' that targeted dark web vendors and customers from ten countries.
</p>

<p>
	 
</p>

<p>
	National authorities in Europe, South America, Asia, and the United States have also seized over €184 million ($207M) in cash and cryptocurrency, more than 2 tonnes of drugs (including amphetamines, cocaine, ketamine, opioids, and cannabis), and over 180 firearms.
</p>

<p>
	 
</p>

<p>
	"A global law enforcement operation coordinated by Europol has struck a major blow to the criminal underground, with 270 arrests of dark web vendors and buyers across ten countries," <a href="https://www.europol.europa.eu/media-press/newsroom/news/270-arrested-in-global-dark-web-crackdown-targeting-online-drug-and-criminal-networks" rel="external nofollow" target="_blank">Europol said</a> on Thursday.
</p>

<p>
	 
</p>

<p>
	"Known as Operation RapTor, this international sweep has dismantled networks trafficking in drugs, weapons, and counterfeit goods, sending a clear signal to criminals hiding behind the illusion of anonymity."
</p>

<p>
	 
</p>

<p>
	Law enforcement identified the suspects (many linked to thousands of sales on illicit platforms) using intelligence collected after the takedowns of multiple dark web marketplaces, including <a href="https://www.bleepingcomputer.com/news/security/darknet-marketplace-nemesis-market-seized-by-german-police/" rel="external nofollow" target="_blank">Nemesis</a>, Tor2Door, <a href="https://www.bleepingcomputer.com/news/legal/dutch-police-arrest-admin-of-bohemia-cannabia-dark-web-market/" rel="external nofollow" target="_blank">Bohemia</a>, and <a href="https://www.bleepingcomputer.com/news/security/german-police-takes-down-kingdom-market-cybercrime-marketplace/" rel="external nofollow" target="_blank">Kingdom Market</a>.
</p>

<p>
	 
</p>

<p>
	Most of the arrested suspects were apprehended in the United States (130), Germany (42), the United Kingdom (37), France (29), and South Korea (19), while 13 others were detained in the Netherlands, Austria, Brazil, Spain, and Switzerland.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" frameborder="0" height="113" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube-nocookie.com/embed/T10brrj8kPg?feature=oembed" title="FBI Search Targets Darknet Drug Networks" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	"Operation RapTor shows that the dark web is not beyond the reach of law enforcement," added Edvardas Šileris, the Head of Europol’s European Cybercrime Centre.
</p>

<p>
	 
</p>

<p>
	"Through close cooperation and intelligence sharing, officers across four continents identified and arrested suspects, sending a clear message to those who think they can hide in the shadows. Europol will continue working with our partners to make the internet safer for everyone."
</p>

<p>
	 
</p>

<p>
	The U.S. Department of Justice's Joint Criminal Opioid and Darknet Enforcement (JCODE) team and Europol's European Cybercrime Centre (EC3) <a href="https://www.justice.gov/opa/pr/law-enforcement-seize-record-amounts-illegal-drugs-firearms-and-drug-trafficking-proceeds" rel="external nofollow" target="_blank">are still analyzing evidence</a> collected in previous operations to trace and apprehend other suspects linked to dark web crime.
</p>

<p>
	 
</p>

<p>
	This joint action follows <a href="https://www.bleepingcomputer.com/news/security/police-operation-spector-arrests-288-dark-web-drug-vendors-and-buyers/" rel="external nofollow" target="_blank">Operation SpecTor</a> in 2023, which led to the arrest of 288 other dark web vendors and buyers and the seizure of €50.8 million ($55.9M) in cash and cryptocurrency.
</p>

<p>
	 
</p>

<p>
	In 2020, another international sting dubbed "DisrupTor" targeted dark web vendors and led to 179 arrests, while <a href="https://www.bleepingcomputer.com/news/security/police-arrest-150-dark-web-vendors-of-illegal-drugs-and-guns/" rel="external nofollow" target="_blank">Operation Dark HunTOR</a> resulted in busting 150 more high-volume darknet vendors.
</p>

<p>
	 
</p>

<p>
	In April 2022, German police and U.S. authorities <a href="https://www.bleepingcomputer.com/news/legal/germany-takes-down-hydra-worlds-largest-darknet-market/" rel="external nofollow" target="_blank">shut down Hydra</a>, the world's largest dark web marketplace dedicated to selling drugs and money laundering, with over 19,000 seller accounts that were serving more than 17 million customers worldwide.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/police-arrests-270-dark-web-vendors-buyers-in-global-crackdown/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29349</guid><pubDate>Thu, 22 May 2025 16:36:19 +0000</pubDate></item><item><title>FYI: Google ads are coming to AI Mode, testing started</title><link>https://nsaneforums.com/news/security-privacy-news/fyi-google-ads-are-coming-to-ai-mode-testing-started-r29341/</link><description><![CDATA[<p>
	One reason Google is able to offer some of its products and services for free like its Search is by displaying ads in order to earn revenue. The significance of online ads can't be downplayed, and it is visible in the fact that even services like Netflix turned to <a href="https://www.neowin.net/news/netflix-to-launch-lower-cost-ad-supported-plan-in-november/" rel="external nofollow">ad-supported plans</a> to keep their ship afloat.
</p>

<p>
	 
</p>

<p>
	We are already used to seeing ads and commercials in services <a href="https://www.neowin.net/news/youtube-improving-viewer-experience-by-showing-fewer-disruptive-mid-roll-ads/" rel="external nofollow">like YouTube</a>, Gmail, and Search. <a href="https://www.neowin.net/news/tags/google_io_2025/" rel="external nofollow">At I/O 2025</a>, the search giant announced it is starting to test ads in AI Mode, its generative AI experience inside Google Search that offers detailed answers to queries in a conversational-style interface. The company said in a <a href="https://blog.google/products/ads-commerce/google-search-ai-brand-discovery/" rel="external nofollow">blog post</a> that ads may appear below and integrated into AI Mode responses where they are relevant.
</p>

<p>
	 
</p>

<figure class="image image--expandable">
	<img alt="Google Ads in AI Mode" class="ipsImage" height="404" width="720" src="https://cdn.neowin.com/news/images/uploaded/2025/05/1747892735_google_ads_in_ai_mode.jpg">
</figure>

<p>
	Someone using AI Mode to search “how to build a website for a small business with limited resources” will see a detailed answer that includes a step-by-step guide on choosing a product, connecting with their audience, testing, and launching. In this case, Google may insert an advertisement for a related product, such as a website builder.
</p>

<p>
	 
</p>

<p>
	AI Mode has started rolling out to everyone in the US, powered by a custom version of Gemini 2.5. In the coming weeks and months, the generative AI experience will receive a <a href="https://www.neowin.net/news/these-are-the-new-ai-features-coming-to-google-search/" rel="external nofollow">platter of new features</a>.
</p>

<p>
	 
</p>

<p>
	Google Ads have been available for AI Overviews since last year, and shopping-related ads show up in Google Lens when it's used to identify products. Revealing some stats during Google I/O 2025 keynote, CEO Sundar Pichai said that AI Overviews now has <a href="https://www.neowin.net/news/google-ai-overviews-reaches-15-billion-monthly-users-expanded-to-200-countries/" rel="external nofollow">over 1.5 billion monthly users</a>. In top-performing markets like the US and India, Google usage has increased 10% for queries that show AI Overviews.
</p>

<p>
	 
</p>

<p>
	According to its internal data from January 2025, the company saw "the volume of commercial queries is increasing," which can lead to "more opportunities for advertisers as people turn to Search to discover new brands and products." It announced that Search and Shopping ads in AI Overviews are now expanding to desktop users in the US. Google will bring ads in AI Overviews (English) to some countries on mobile and desktop.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/fyi-google-ads-are-coming-to-ai-mode-testing-started/" rel="external nofollow">Source</a>
</p>

<hr class="ipsHr">
<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of April): 1,811</em></span>
</p>

<p>
	<strong><span style="font-size:12px;"><a href="https://nsaneforums.com/topic/459202-remember-matrix/" rel="">RIP Matrix</a> | Farewell my friend  </span></strong><img alt=":sadbye:" data-emoticon="true" loading="lazy" src="https://nsaneforums.com/uploads/emoticons/default/sadbye.gif" title=":sadbye:">
</p>
]]></description><guid isPermaLink="false">29341</guid><pubDate>Thu, 22 May 2025 07:37:00 +0000</pubDate></item></channel></rss>
