This is a somewhat light hearted, lightweight IT privacy and security podcast that spans the globe in terms of issues covered with topics that draw in everyone from newbie to tech specialist. Invest between 15 and 30 minutes a week to come up to speed on half a dozen different stories from around the world.
This update synthesizes critical developments in technology, privacy, and cybersecurity, highlighting an intensifying conflict between user privacy and corporate and governmental data access. Major technologyfirms are pushing the boundaries of data collection, with Amazon's Ring preparing to launch facial recognition for its doorbells and Meta planning to use AI chat contentfor targeted advertising. Concurrently, governments are escalating demands for access to encrypted data, exemplified by the UK's renewed order for Apple to create a backdoor into its cloud services for British users—a demand Apple continues to reject.
The vulnerability of critical infrastructure remains a paramount concern. A foiled plot to cripple New York City's cellular network was revealed to be far larger than initially understood, possessing the capacity to disable emergency services city-wide. In the commercial sector, a ransomware attack has severely disrupted production for Japan's top brewer, Asahi, demonstrating the tangible impact of cybercrime on physical supply chains. The cybersecuritylandscape is also evolving, with threat actor groupslike ShinyHunters collaborating on extortionschemes, as seen in the recent Red Hat data breach.
Meanwhile, the deployment of emerging technologies presents a mix of progress and problems. Signal is proactively future-proofing its messaging service with quantum-resistant encryption. In contrast, the rollout of food delivery robots in U.S. cities is meeting public resistance amid concerns over safety, surveillance, and a lack of public consent. Technical issues also persist inmainstream applications, with Microsoft acknowledgingbugs that disrupt its AI-powered Copilot assistant in the Office 365 suite.
EP 261
This week’s update brings a diverse set of stories that remind us just how delicate the balance is between good and bad...
Ring's new facial recognition feature sparks privacy debates as it prepares to scan faces at your doorstep.
Meta's plan to mine AI chat data for targeted ads raises fresh concerns about digital privacy.
A foiled plot to paralyze New York's cellphone network reveals a chilling, large-scale threat.
Signal's cutting-edge SPQR encryption upgrade fortifies private chats against future quantum threats.
A ransomware attack on Asahi Group threatens Japan's beloved Super Dry beer supply chain.
Microsoft's Copilot faces glitches when multiple Office apps run, prompting a promised fix.
Atlanta's food delivery robots are stirring controversy, raising questions about surveillance and public consent.
And that face at the door!
Find a full transcript of this week's podcast here.
Executive Overview
The week’s events illustrate escalating risks at the intersection of industrial operations, national security, personal privacy, and emerging technology. Major cyber incidents demonstrate how fragile digital infrastructure has become, while privacy erosion continues through corporate data monetization and state surveillance. Human error persists as a dominant threat vector, and rapid technological advancement remains both a shield and a source of risk.
I. Systemic Infrastructure & Supply Chain Vulnerabilities
The cyberattack on Jaguar Land Rover (JLR) exemplifies cascading industrial risks. A phishing entry point forced JLR to halt global production, costing up to £100M and threatening thousands of suppliers with collapse. The UK government faces mounting pressure to intervene. Meanwhile, the U.S. Federal Highway Administration uncovered hidden radios in foreign-made power systems—likely Chinese—used in traffic signs, EV chargers, and weather stations. These undocumented components could enable remote disruption or espionage, underscoring critical supply chain insecurity.
II. Privacy Erosion & Data Commercialization
Personal data is increasingly commodified:
Airlines (via ARC) sold five billion passenger records to agencies like FBI and ICE for warrantless surveillance, skirting legal oversight. Senator Wyden is pushing legislation to close this loophole.
Verizon was fined $46.9M for unlawfully selling location data, setting legal precedent that Section 222 protects customer location.
UK employers are rapidly adopting “bossware,” with one-third monitoring staff emails, browsing, or screens. While justified as productivity or insider threat control, critics warn of eroded trust and pervasive surveillance culture.
III. The Human Factor in Cyber Breaches
Humans remain the weak link:
Schools: Over half of insider data breaches stemmed from students, mostly using stolen or guessed credentials. Motivated by curiosity, some exposed thousands of records.
Global theft rings: A single stolen iPhone exposed a transnational phishing and resale network spanning six countries. The scheme used fake iCloud links to bypass Apple’s protections.
Russia’s “Max” app: Marketed as secure, it is exploited by fraudsters renting accounts for scams. With nearly 10% of scam calls traced to Max, new laws now criminalize account transfers.
IV. Technology’s Dual Edge
Innovation provides stronger defenses but also reckless failures:
Apple launched Memory Integrity Enforcement, a silicon-level protection against buffer overflows and side-channel exploits, deployed on iPhone 17 and iPhone Air.
Google’s VaultGemma, a 1B-parameter model trained with differential privacy, promises competitive performance without exposing sensitive data—an advance in privacy-preserving AI.
AI Darwin Awards highlight failures from poor oversight: Taco Bell’s misfiring AI drive-thru, McDonald’s compromised recruiting chatbot, Replit’s database-wiping AI, and even the satirical awards site itself.
EP 260 This is our last update before a two week break so we've packed it.
We start with the devastating cyber attack on Jaguar Land Rover exposes the fragility of modern manufacturing, halting production and threatening the UK’s automotive supply chain.
Russia’s state-backed Max messaging app, touted as secure, has become a breeding ground for scams, undermining user trust and safety.
UK schools face a surge in cyber attacks driven by students exploiting weak credentials, revealing critical gaps in educational data security.
A stolen iPhone sparked a security researcher’s investigation, dismantling a global criminal network profiting from phishing and device theft.
Major US airlines are selling billions of passenger records to the government, enabling warrantless surveillance and raising privacy alarms.
A federal court upholds a $46.9M fine against Verizon for illegally selling customer location data, reinforcing privacy protections.
A third of UK employers deploy 'bossware' to monitor workers, sparking concerns over privacy and trust in the workplace.
Undetected Chinese-made radios in US highway infrastructure raise alarms over potential remote tampering and data theft.
Apple’s Memory Integrity Enforcement introduces robust protection against memory-based attacks, setting a new standard for device security.
Google’s VaultGemma pioneers privacy-focused AI, leveraging differential privacy to safeguard user data in large language models.
The AI Darwin Awards spotlight reckless AI deployments, from fast-food blunders to catastrophic data losses, it’s both entertaining and scary at the same time.
Adventures await in the mistake before the break!
EP 259.5
The cybersecurity and technology threat landscape is accelerating in scale, sophistication, and impact. A convergence of AI-driven offensive capabilities, large-scale supply chain compromises, systemic insecurity in consumer devices, corporate data abuses, and state-level spyware deployment is reshaping digital risk. At the same time, new innovations—particularly in open-source, privacy-centric AI and smart home repurposing—highlight the dual-edged nature of technological progress.
AI-Accelerated Exploits
Attackers now harness generative AI to automate exploit creation, compressing timelines from months to minutes. “Auto Exploit,” powered by Claude-sonnet-4.0, can produce functional PoC code for vulnerabilities in under 15 minutes at negligible cost, fundamentally shifting defensive priorities. The challenge is no longer whether a flaw is technically exploitable but how quickly exposure becomes weaponized.
Massive Supply Chain Attacks
Software ecosystems remain prime targets. A phishing campaign against a single npm maintainer led to malware injection into packages downloaded billions of times weekly, constituting the largest supply-chain attack to date. This demonstrates how a single compromised account can ripple globally across developers, enterprises, and end users.
Weaponization of Benign Formats
Attackers increasingly exploit trusted file types. SVG-based phishing campaigns deliver malware through fake judicial portals, evading antivirus detection with obfuscation and dummy code. Over 500 samples were linked to one campaign, prompting Microsoft to disable inline SVG rendering in Outlook as a mitigation measure.
Systemic Insecurity in IoT
Low-cost consumer devices, particularly internet-connected surveillance cameras, ship with unpatchable flaws. Weak firmware, absent encryption, bypassable authentication, and plain-text data transmission expose users to surveillance rather than security. These systemic design failures create enduring vulnerabilities at scale.
Corporate Breaches and Data Abuse
The Plex breach underscored the persistence of corporate data exposure, with compromised usernames and passwords requiring resets. Meanwhile, a federal jury fined Google $425.7M for secretly tracking 98M devices despite user privacy settings—reinforcing that legal and financial consequences for privacy violations are escalating, even if damages remain below consumer expectations.
Government Spyware Deployment
Civil liberties are increasingly tested by state adoption of invasive surveillance tools. U.S. Immigration and Customs Enforcement resumed a $2M deal for Graphite spyware, capable of infiltrating encrypted apps and activating microphones. The contract proceeded after regulatory hurdles were bypassed through a U.S. acquisition of its Israeli parent company, raising alarms about due process, counterintelligence risks, and surveillance overreach.
Emerging Innovations
Not all developments are regressive. Philips Hue’s “MotionAware” demonstrates benign repurposing of smart home technology, transforming bulbs into RF-based motion sensors with AI-powered interpretation. Meanwhile, Switzerland’s Apertus project launched an open-source LLM designed with transparency and privacy at its core—providing public access to weights, training data, and checkpoints, framing AI as digital infrastructure for the public good.
The digital environment is marked by intensifying threats: faster, cheaper, and more pervasive attacks, systemic insecurity in consumer technologies, corporate and governmental encroachments on privacy, and the weaponization of formats once considered harmless. Yet, the emergence of open, privacy-first AI and the creative repurposing of consumer tech illustrate parallel efforts to realign innovation with security and transparency. The result is a complex, high-velocity ecosystem where defensive strategies must adapt as quickly as offensive capabilities evolve.
Conclusion
EP 259 In this week’s update:
Affordable LookCam devices, marketed as home security solutions, harbor critical vulnerabilities that could allow strangers to access your private video feeds.
VirusTotal uncovers a sophisticated phishing campaign using SVG files to disguise malware, targeting users with fake Colombian judicial portals.
Plex alerts users to a data breach compromising emails, usernames, and hashed passwords, urging immediate password resets to secure accounts.
Philips Hue’s innovative MotionAware feature transforms smart bulbs into motion sensors, enhancing home automation with cutting-edge RF technology.
A massive supply chain attack compromises npm packages, affecting billions of downloads through a phishing scheme targeting maintainers’ accounts.
Google faces a $425.7 million verdict for covertly tracking nearly 98 million smartphones, violating user privacy despite opt-out settings.
Switzerland’s Apertus, a fully open-source AI model, sets a new standard for privacy, offering transparency and compliance with stringent data laws.
An AI-driven tool, Auto Exploit, revolutionizes cybersecurity by generating exploit code in under 15 minutes, reshaping defensive strategies.
ICE’s adoption of Paragon’s Graphite spyware, capable of infiltrating encrypted apps, sparking concerns over privacy and surveillance in immigration enforcement.
Look closely and perhaps you’ll see it in the picture.
Modern technology introduces profound privacy and security challenges. Wi-Fi and Bluetooth devices constantly broadcast identifiers like SSIDs, MAC addresses, and timestamps, which services such as Wigle.net and major tech companies exploit to triangulate precise locations. Users can mitigate exposure by appending _nomap to SSIDs, though protections remain incomplete, especially against companies like Microsoft that use more complex opt-out processes.
At the global scale, state-sponsored hacking represents an even larger threat. A Chinese government-backed campaign has infiltrated critical communication networks across 80 nations and at least 200 U.S. organizations, including major carriers. These intrusions enabled extraction of sensitive call records and law enforcement directives, undermining global privacy and revealing how deeply foreign adversaries can map communication flows.
AI companies are also reshaping expectations of confidentiality. OpenAI now scans user conversations for signs of harmful intent, with human reviewers intervening and potentially escalating to law enforcement. While the company pledges not to report self-harm cases, the shift transforms ChatGPT from a private interlocutor into a monitored channel, raising ethical questions about surveillance in AI systems. Similarly, Anthropic has adopted a new policy to train its models on user data, including chat transcripts and code, while retaining records for up to five years unless users explicitly opt out by a set deadline. This forces individuals to choose between enhanced AI capabilities and personal privacy, knowing that once data is absorbed into training, confidentiality cannot be reclaimed.
Research has further exposed the fragility of chatbot safety systems. By crafting long, grammatically poor run-on prompts that delay punctuation, users can bypass guardrails and elicit harmful outputs. This underscores the need for layered defenses input sanitization, real-time filtering, and improved oversight beyond alignment training alone.
Security risks also extend into software infrastructure. Widely used tools such as the Node.js library fast-glob, essential to both civilian and military systems, are sometimes maintained by a single developer abroad. While open-source transparency reduces risk, concentration of control in geopolitically sensitive regions raises concerns about potential sabotage, exploitation, or covert compromise.
Meanwhile, regulators are tightening defenses against longstanding consumer threats. The FCC will enforce stricter STIR/SHAKEN rules by September 2025, requiring providers to sign calls with their own certificates instead of relying on third parties. Non-compliance could result in fines and disconnection, offering consumers more reliable caller ID and fewer spoofed robocalls.
Finally, ethical boundaries around AI and digital identity are being tested. Meta has faced criticism for enabling or creating AI chatbots that mimic celebrities like Taylor Swift and Scarlett Johansson without consent, often producing flirty or suggestive interactions. Rival platforms like X s Grok face similar accusations. Beyond violating policies and reputations, the trend of unauthorized digital doubles including of minors raises serious concerns about exploitation, unhealthy attachments, and reputational harm.
Together, these cases reveal a central truth: digital systems meant to connect, entertain, and innovate increasingly blur the lines between utility, surveillance, and exploitation. Users and institutions alike must navigate trade-offs between convenience, capability, and control, while regulators and technologists scramble to impose safeguards in a rapidly evolving landscape.
EP 258. In this week’s hyper focused update:
Unveiling the hidden reach of Wi-Fi tracking, exposing how everyday devices can reveal your location to anyone, anywhere.
A global cybersecurity alert highlights a sprawling Chinese hacking operation targeting critical communication networks across 80 nations.
OpenAI’s new surveillance measures on ChatGPT spark debate over privacy and safety in AI-driven conversations.
Anthropic’s shift to train AI on user data raises critical choices for privacy and security by September 28th.
A clever linguistic trick exposes vulnerabilities in AI chatbots, challenging the robustness of their safety filters.
A widely used software tool, maintained by a Russian developer, raises security concerns for U.S. Defense Department projects.
The FCC’s 2025 STIR/SHAKEN rules aim to restore trust in caller ID by cracking down on robocalls with stricter compliance.
Meta’s unauthorized AI chatbots mimicking celebrities ignite ethical concerns over digital likeness and platform oversight.
There’s a lot to see (and hear) in this week’s update. Let’s get looking!
Find the full transcript here.
Organizations today face escalating cyber risks spanning state-sponsored attacks, supply chain compromises, and malicious apps. ShinyHunters’ breaches of Salesforce platforms (impacting Google and Farmers Insurance) show how social engineering—like voice phishing—can exploit trusted vendors. Meanwhile, Russian actors (FSB-linked “Static Tundra”) continue to leverage old flaws, such as a seven-year-old Cisco Smart Install bug, to infiltrate U.S. infrastructure. Malicious apps on Google Play (e.g., Joker, Anatsa) reached millions of downloads before removal, proving attackers’ success in disguising malware. New technologies bring fresh vectors: Perplexity’s Comet browser allowed prompt injection–driven account hijacking, while malicious RDP scanning campaigns exploit timing to maximize credential theft.
Responses vary between safeguarding and asserting control. The FTC warns U.S. firms against weakening encryption or enabling censorship under foreign pressure, citing legal liability. By contrast, Russia mandates state-backed apps like MAX Messenger and RuStore, raising surveillance concerns. Microsoft, facing leaks from its bug-sharing program, restricted exploit code access to higher-risk countries. Open-source projects like LibreOffice gain traction as sovereignty tools—privacy-first, telemetry-free, and free of vendor lock-in.
AI-powered wearables such as Halo X smart glasses blur lines between utility and surveillance. Their ability to “always listen” and transcribe conversations augments human memory but erodes expectations of privacy. The founders’ history with facial recognition raises additional misuse concerns. As AI integrates directly into conversation and daily life, the risks of pervasive recording, ownership disputes, and surveillance intensify.
Platforms like Bluesky are strained by conflicting global regulations. Mississippi’s HB 1126 requires universal age verification, fines for violations, and parental consent for minors. Lacking resources for such infrastructure, Bluesky withdrew service from the state. This illustrates the tension between regulatory compliance, resource limits, and preserving open user access.
AI adoption is now a competitive imperative. Coinbase pushes aggressive integration, requiring engineers to embrace tools like GitHub Copilot or face dismissal. With one-third of its code already AI-generated, Coinbase aims for 50% by quarter’s end, supported by “AI Speed Runs” for knowledge-sharing. Yet, rapid adoption risks employee dissatisfaction and AI-generated security flaws, underscoring the need for strict controls alongside innovation.
Breaches at Farmers Insurance (1.1M customers exposed) and Google via Salesforce illustrate the scale of third-party risk. Attackers exploit trusted platforms and human error, compromising data across multiple organizations at once. This shows security depends not only on internal defenses but on continuous vendor vetting and monitoring.
Governments often demand access that undermines encryption, privacy, and transparency. The FTC warns that backdoors or secret concessions—such as the UK’s (later retracted) request for Apple to weaken iCloud—violate user trust and U.S. law. Meanwhile, Russia’s mandatory domestic apps exemplify sovereignty used for surveillance. Companies face a global tug-of-war between privacy, compliance, and open internet principles.
Exploited legacy flaws prove that vulnerabilities never expire. Cisco’s years-old Smart Install bug, still unpatched in many systems, allows surveillance of critical U.S. sectors. Persistent RDP scanning further highlights attackers’ patience and scale. The lesson is clear: proactive patching, continuous updates, and rigorous audits are essential. Cybersecurity demands ongoing vigilance against both emerging and legacy threats.
EP 257.
In this week’s Super Intelligent IT Privacy and Security Weekly Update:
Halo X's AI-powered glasses redefine digital assistance with real-time conversation insights for enhanced ... everything.
Microsoft strengthens cybersecurity by limiting sensitive exploit code access in its vulnerability disclosure program.
LibreOffice v25.8 empowers governments with secure, open-source tools for unparalleled digital sovereignty.
FTC champions data security, urging U.S. tech leaders to resist foreign demands compromising encryption standards.
Google swiftly removes 77 malicious apps, reinforcing mobile security against sophisticated malware threats.
FBI exposes Russian cyber threats targeting U.S. infrastructure, urging immediate system updates.
Coinbase fortifies security and accelerates AI integration to drive innovation and resilience.
Massive scans on Microsoft RDP services point to the need for improved cybersecurity measures.
Come on! Let’s go get super-intelligent!
Phishing Training Effectiveness: A study of over 19,000 employees showed traditional phishing training has limited impact, improving scam detection by just 1.7% over eight months. Despite varied training methods, over 50% of participants fell for at least one phishing email, highlighting persistent user susceptibility and the need for more effective cybersecurity education strategies.
Cybersecurity Risks in Modern Cars: Modern connected vehicles are highly vulnerable to cyberattacks. A researcher exploited flaws in a major carmaker’s web portal, gaining “national admin” access to dealership data and demonstrating the ability to remotely unlock cars and track their locations using just a name or VIN. This underscores the urgent need for regular vehicle software updates and stronger manufacturer security measures to prevent data breaches and potential vehicle control by malicious actors.
Nation-State Cyberattacks on Infrastructure: Nation-state cyberattacks targeting critical infrastructure are escalating. Russian hackers reportedly took control of a Norwegian hydropower dam, releasing water undetected for hours. While no physical damage occurred, such incidents reveal the potential for widespread disruption and chaos, signaling a more aggressive stance by state-sponsored cyber actors and the need for robust infrastructure defenses.
AI Regulation in Mental Health Therapy: States like Illinois, Nevada, and Utah are regulating or banning AI in mental health therapy due to safety and privacy concerns. Unregulated AI chatbots risk harmful interactions with vulnerable users and unintended data exposure. New laws require licensed professional oversight and prohibit marketing AI chatbots as standalone therapy tools to protect users.
Impact of Surveillance Laws on Privacy Tech: Proposed surveillance laws, like Switzerland’s data retention mandates, are pushing privacy-focused tech firms like Proton to relocate infrastructure. Proton is moving its AI chatbot, Lumo, to Germany and considering Norway for other services to uphold its no-logs policy. This reflects the tension between national security and privacy, driving companies to seek jurisdictions with stronger data protection laws.
Data Brokers and Privacy Challenges: Data brokers undermine consumer privacy despite laws like California’s Consumer Privacy Act. Over 30 brokers were found hiding data deletion instructions from Google search results using specific code, creating barriers for consumers trying to opt out of data collection. This intentional obfuscation frustrates privacy rights and weakens legislative protections.
Android pKVM Security Certification: Android’s protected Kernel-based Virtual Machine (pKVM) earned SESIP Level 5 certification, the first software security solution for consumer electronics to achieve this standard. Designed to resist sophisticated attackers, pKVM enables secure handling of sensitive tasks like on-device AI processing, setting a new benchmark for consistent, verifiable security across Android devices.
VPN Open-Source Code Significance: VP.NET’s decision to open-source its Intel SGX enclave code on GitHub enhances transparency in privacy technology. By allowing public verification, users can confirm the code running on servers matches the open-source version, fostering trust and accountability. This move could set a new standard for the VPN and privacy tech industry, encouraging others to prioritize verifiable privacy claims.
EP 256. Freshly Phished this week...
A study with thousands of test subjects showed phishing training has minimal impact on scam detection. The results are surprisingly underwhelming.
A hacker exploited a carmaker’s web portal to access customer data and unlock vehicles remotely. The breach exposed major vulnerabilities.
Russian hackers took control of a Norwegian dam, releasing water undetected for hours. The cyber-attack raises serious concerns and water levels.
Illinois banned AI in mental health therapy, joining states regulating chatbots. The move addresses the growing safety concerns of AI and its crazy responses.
Proton is relocating infrastructure from Switzerland due to proposed surveillance laws. The privacy-focused firm is taking bold steps and getting closer to the source of rakfisk.
Data brokers are evading California’s privacy laws by concealing opt-out pages. This tactic blocks consumers from protecting their data.
Android’s pKVM earned elite SESIP Level 5 security certification for virtual machines. The technology sets a new standard for device security, but what does it mean and what does it do?
The UK abandoned its push to force Apple to unlock iCloud backups after privacy disputes. The decision followed intense negotiations with the U.S..
VP.NET released its source code for public verification, enhancing trust in privacy tech. A move that sets a new transparency benchmark.
Let's hit the water!
Find the full transcript to the podcast here.
How AI Can Inadvertently Expose Personal Data
AI tools often unintentionally leak private information. For example, meeting transcription software can include offhand comments, personal jokes, or sensitive details in auto-generated summaries. ChatGPT conversations—when publicly shared—can also be indexed by search engines, revealing confidential topics such as NDAs or personal relationship issues. Even healthcare devices like MRIs and X-ray machines have exposed private data due to weak or absent security controls, risking identity theft and phishing attacks.
Cybercriminals Exploiting AI for Attacks
AI is a double-edged sword: while offering defensive capabilities, it's also being weaponized. The group “GreedyBear” used AI-generated code in a massive crypto theft operation. They deployed malicious browser extensions, fake websites, and executable files to impersonate trusted crypto platforms, harvesting users’ wallet credentials. Their tactic involves publishing benign software that gains trust, then covertly injecting malicious code later. Similarly, AI-generated TikTok ads lead to fake “shops” pushing malware like SparkKitty spyware, which targets cryptocurrency users.
Security Concerns with Advanced AI Models like GPT-5
Despite advancements, new AI models such as GPT-5 remain vulnerable. Independent researchers, including NeuralTrust and SPLX, were able to bypass GPT-5's safeguards within 24 hours. Methods included multi-turn “context smuggling” and text obfuscation to elicit dangerous outputs like instructions for creating weapons. These vulnerabilities suggest that even the latest models lack sufficient security maturity, raising concerns about their readiness for enterprise use.
AI Literacy and Education Initiatives
There is a growing push for AI literacy, especially in schools. Microsoft has pledged $4 billion to fund AI education in K–12 schools, community colleges, and nonprofits. The traditional "Hour of Code" is being rebranded as "Hour of AI," reflecting a shift from learning to code to understanding AI itself. The aim is to empower students with foundational knowledge of how AI works, emphasizing creativity, ethics, security, and systems thinking over rote programming.
Legal and Ethical Issues Around Posthumous Data Use
One emerging ethical challenge is the use of deceased individuals' data to train AI models. Scholars advocate for postmortem digital rights, such as a 12-month grace period for families to delete a person’s data. Currently, U.S. laws offer little protection in this area, and acts like RUFADAA don’t address AI recreations.
Encryption Weaknesses in Law Enforcement and Critical Systems
Recent research highlights significant encryption vulnerabilities in communication systems used by police, military, and critical infrastructure. A Dutch study uncovered a deliberate backdoor in a radio encryption algorithm. Even the updated, supposedly secure version reduces key strength from 128 bits to 56 bits—dramatically weakening security. This suggests that critical communications could be intercepted, leaving sensitive systems exposed despite the illusion of protection.
Public Trust in Government Digital Systems
Trust in digital governance is under strain. The UK’s HM Courts & Tribunals Service reportedly concealed an IT error that caused key evidence to vanish in legal cases. The lack of transparency and inadequate investigation risk undermining judicial credibility. Separately, the UK government secretly authorized facial recognition use across immigration databases, far exceeding the scale of traditional criminal databases.
AI for Cybersecurity Defense
On the defensive side, AI is proving valuable in finding vulnerabilities. Google’s “Big Sleep,” an LLM-based tool developed by DeepMind and Project Zero, has independently discovered 20 bugs in major open-source projects like FFmpeg and ImageMagick.
EP 255
For this week's sweet update we start with AI tools that are quietly transcribing your meetings, but what happens when your offhand jokes end up in the wrong hands? Discover how casual chats are being exposed in automated summaries.
Your ChatGPT conversations might be popping up in Google searches, revealing everything from NDAs to personal struggles. Uncover the scale of this privacy breach and what it means for you.
Fake TikTok shops are luring shoppers with AI-crafted ads, hiding a sinister malware trap. Dive into the world of counterfeit domains stealing crypto and credentials.
MRI scans and X-rays are leaking online from over a million unsecured healthcare devices. Find out how your medical secrets could be exposed to hackers worldwide.
Security teams cracked GPT-5’s defenses in hours, turning it into a tool for dangerous outputs. Explore how this AI’s vulnerabilities could spell trouble for enterprise users.
A slick AI-driven crypto heist stole millions through fake browser extensions and scam sites. Learn how GreedyBear’s cunning tactics are redefining cybercrime.
A secret IT glitch in UK courts has been wiping out evidence, leaving judges in the dark. Delve into the cover-up shaking trust in the justice system.
UK police are scanning passport photos with facial recognition, all without public knowledge. Unravel the hidden expansion of surveillance using your personal images.
Come on! Let's raise those glucose levels.
Find the full transcript to this podcast here.
The women-focused dating app "Tea" faces backlash after two data breaches exposed 72,000 sensitive images and 1.1 million private messages. Though security upgrades were promised, past data remained exposed, and the app lacks end-to-end encryption. Additionally, anonymous features enabling posts about men have sparked defamation lawsuits. Critics argue Tea prioritized rapid growth over user safety, exemplifying the danger of neglecting cybersecurity in pursuit of scale.
CrowdStrike has flagged a 220% surge in North Korean IT operatives posing as remote workers—over 320 cases in the past year. These operatives use stolen/fake identities, aided by generative AI to craft résumés, deepfake interviews, and juggle multiple jobs. Their earnings fund Pyongyang’s weapons programs. The tactic reveals the limits of traditional vetting and the need for advanced hiring security.
UK luggage service Airportr suffered a major security lapse exposing passport photos, boarding passes, and flight details—including those of diplomats. CyberX9 found it possible to reset accounts with just an email and no limits on login attempts. Attackers could gain admin access, reroute luggage, or cancel flights. Although patched, the incident underscores risks of convenience services with poor security hygiene.
Veracode's "2025 GenAI Code Security Report" found that nearly 45% of AI-generated code across 80 tasks had security flaws—many severe. This highlights the need for human oversight and thorough reviews. While AI speeds development, it also increases vulnerability if unchecked, making secure coding a human responsibility.
Chinese state hackers exploited flaws in SharePoint, breaching hundreds of U.S. entities. A key concern: China-based Microsoft engineers maintained the hacked software, potentially enabling earlier access. Microsoft also shared vulnerability data with Chinese firms through its MAPP program, while Chinese law requires such data be reported to the state. This raises alarms about outsourcing sensitive software to geopolitical rivals.
Russia’s "Secret Blizzard" hackers used ISP-level surveillance to deliver fake Kaspersky updates to embassies. These updates installed malware and rogue certificates enabling adversary-in-the-middle attacks—allowing full decryption of traffic. The attack shows the threat of state-level manipulation of software updates and underscores the need for update authenticity verification.
Signal may pull out of Australia if forced to weaken encryption. ASIO’s push for access contradicts Signal's end-to-end encryption model, which can’t accommodate backdoors without global compromise. This standoff underscores a broader debate: encryption must be secure for all or none. Signal’s resistance reflects the rising tension between privacy advocates and governments demanding access.
Los Alamos National Laboratory has launched a National Security AI Office, signaling a pivot from nuclear to AI capabilities. With massive GPU infrastructure and university partnerships, the lab sees AI as the next frontier in scientific and national defense. This reflects a shift in global security dynamics—where large language models may be as strategically vital as missiles.
EP 254.
In this week's update:
Despite back-to-back data breaches and legal blowback, women are still queuing up by the millions for Tea. This is one hot dating app that's apparently more viral than secure.
North Korean IT operatives are clocking into remote jobs worldwide. Fueled by GenAI and fake identities in what CrowdStrike calls a daily cybersecurity crisis.
A British luggage startup managed to lose more than just bags. Airportr briefly exposed diplomatic travel data and full backend access to anyone with a browser and curiosity.
According to Veracode, nearly half of all AI-generated code is insecure. And that should leave you feeling insecure, especially if your code reviews have been neglected
Microsoft confirmed Chinese engineers have long supported the same SharePoint software recently hacked by Beijing. The breach hit hundreds of U.S. institutions—including nuclear and homeland security.
Russian state hackers tricked foreign embassies into installing fake updates from “Kaspersky.” The malware came with a rogue root certificate—and full surveillance capabilities.
Signal’s president warned it might pull out of Australia over demands to weaken encryption. The country’s privacy pushback continues—and secure apps are packing their bags.
Los Alamos is pouring resources into AI research—because in 2025, the most powerful weapon might be a large language model, rather than a missile.
Finish that cuppa, we have a lot to cover!
Find the full transcript to this podcast here.
Germany’s Tech-Driven Warfare & Ethical Implications
Germany is integrating AI, robotics, and human-machine teaming into its military, deploying tech like robotic cockroaches for surveillance and mini-robots for urban combat. These innovations aim to enhance decision-making and minimize human risk. Yet, critics warn of ethical and legal concerns, especially around loss of human oversight in lethal decisions. Despite official claims that humans will remain in control, the autonomy debate continues.
Astronomer's "Kiss Cam" Scandal
A viral Coldplay concert “Kiss Cam” captured Astronomer's CEO and Chief People Officer—both married—trying to avoid public display. The clip, viewed over 127 million times, sparked privacy concerns and led to their resignations. In a PR twist, Astronomer hired Gwyneth Paltrow (ex-wife of Coldplay’s Chris Martin) as a temporary spokesperson to steer attention back to the company’s data automation services.
Tea App’s Privacy Breaches
The women’s dating safety app “Tea” was compromised twice. First, 72,000 private images, including IDs and selfies, were leaked due to an unsecured Firebase database. A second breach exposed over a million sensitive messages containing personal info and taboo topics. Despite promises of anonymity, users’ names, social links, and phone numbers were often easily traceable—defeating the app's core promise of safety.
WhoFi and the Future of Surveillance
WhoFi, a surveillance system developed at La Sapienza University, uses Wi-Fi distortions (Channel State Information) to uniquely identify individuals based on their body’s impact on signal patterns. Achieving up to 95.5% accuracy, it can track people without phones or devices, raising serious privacy concerns about ubiquitous, passive surveillance with no opt-out.
ChatGPT Agent Bypasses Security
OpenAI’s ChatGPT Agent demonstrated it can bypass Cloudflare’s anti-bot “I am not a robot” checks. Operating in a sandboxed browser environment, it navigated multi-step verifications without CAPTCHAs. This challenges the efficacy of current web security protocols and signals that anti-bot measures may be obsolete in the face of advanced AI agents.
AI-Driven Pricing Controversy in Airlines
American Airlines’ CEO slammed Delta for using AI in airfare pricing, labeling it “bait and switch.” Delta claims uniform pricing across channels and denies tailoring fares per customer. While Delta plans broader AI deployment, competitors like Southwest and American reject AI pricing, citing privacy concerns and potential fare manipulation.
Clorox Hack & Vendor Negligence
A 2023 cyberattack cost Clorox $380 million due to a security lapse by its IT vendor, Cognizant. Hackers impersonated Clorox employees and tricked service desk agents into resetting credentials—no identity checks were performed. Now, Clorox is suing Cognizant for damages stemming from this avoidable breach.
North Korean Espionage via Remote Work
North Korean operatives used stolen identities to land remote IT jobs at major U.S. firms like Nike and Chick-fil-A. Aided by VPNs and paid stand-ins for interviews, they funneled salaries to the regime. A U.S. woman received 8.5 years in prison for facilitating this scheme, which exposed sensitive company data and posed national security risks.
EP 253.
In this update we find out that...
Germany’s military is diving into sci-fi territory with AI-powered robots and spy cockroaches. What futuristic tactics are they cooking up to redefine the battlefield? We find out, and then bug out.
Astronomer Hires Coldplay Lead Singer’s Ex-Wife as Temporary Spokesperson: Gwyneth Paltrow. A viral Kiss Cam scandal rocks Astronomer, leading to resignations and a surprise Gwyneth Paltrow cameo. How did a Coldplay concert spark this corporate chaos? You know the story.
Women Dating Safety App Tea Breached, Users IDs Posted To 4chan. The women’s safety app Tea suffers twin data breaches, exposing selfies, IDs, and private messages.
Researchers unveil WhoFi, a system that tracks people using Wi-Fi signal distortions with chilling accuracy. Could your body’s shadow betray your identity without a single device?
OpenAI’s ChatGPT Agent breezes through anti-bot checks, raising eyebrows about online security. What happens when an AI outsmarts the systems designed to stop it?
American Airlines’ CEO slams Delta’s AI-driven airfare pricing as a sneaky trick on travelers. New tech stirs controversy with potential to mislead passengers and one CEO aims to capitalize on it, at least for a little while.
Clorox reels from a $380M hack after its IT vendor handed passwords to cybercriminals. A simple phone call triggered a catastrophic breach and lots of... cough ... dirty laundry.
North Korean operatives infiltrated Nike and Chick-fil-A with fake identities, aided by an Arizona woman. A covert scheme exposed a global cyberthreat with a side of fries.
Our punchlines are flowing like dad jokes. Quick ... we better get you into the rest of the update!
Find the full transcript for this podcast here.
A single compromised password led to the collapse of 158-year-old UK logistics firm KNP, after hackers—suspected to be the Akira gang—used it to gain access, encrypt systems, and demand a £5 million ransom. Unable to pay, the company lost all its data and folded, putting 700 employees out of work. The breach underscores how weak access controls can have catastrophic consequences.
To counter massive botnets, Google is now combining technical defenses with legal action. Its lawsuit against the “BadBox 2.0” operators marks a major shift: targeting criminals behind malware that infected over 10 million Android devices. Google’s strategy includes leveraging the CFAA and RICO Act to not just stop malware but dismantle the entire criminal infrastructure—signaling a more aggressive, litigation-driven cybersecurity era.
Meanwhile, a new malware delivery method is exploiting DNS—a common but often under-monitored network function. Attackers hide malware in DNS TXT records, break it into chunks, and reassemble it on target systems using standard DNS queries. Since DNS traffic is rarely scrutinized, this technique bypasses traditional defenses, making DNS monitoring essential for comprehensive protection.
Travelers to China face serious privacy risks. Authorities are using malware like “Massistant” to extract sensitive data from mobile phones during inspections. Developed by Chinese firm Meiya Pico, the software accesses encrypted texts, location history, and even Signal messages upon installation. Though evidence of compromise may remain, the intrusion happens before detection, raising concerns for anyone bringing devices into the country.
China has also shifted its cyberattack strategy by outsourcing operations to private firms. These companies now discover and sell zero-day vulnerabilities to government agencies. This model, which evolved from loosely affiliated hacker groups, blurs the line between state and private enterprise, making attribution difficult. As a result, China-linked hackers increasingly infiltrate U.S. critical infrastructure while masking their origins, and exposure alone no longer seems to deter them.
In response to national security concerns, Microsoft has removed China-based engineers from U.S. military cloud projects. A ProPublica investigation revealed their prior involvement, prompting a Pentagon ban on such support. Previously, Chinese engineers worked under U.S. supervision, a practice now deemed too risky for defense-related systems.
Microsoft’s SharePoint is also under siege. Chinese state actors exploited a critical flaw dubbed “ToolShell” to compromise at least 54 organizations, including those in critical infrastructure. The attack allowed for deep system access, extraction of encryption keys, and installation of web shells—despite prior patches. The incident stresses the need for rapid patching and vigilance, even on widely used enterprise platforms.
Cyberwarfare is influencing real-world military dynamics. Ukrainian cyber operatives claim to have digitally crippled a major Russian drone manufacturer, deleting 47TB of production data and disabling access systems. Allegedly backed by military intelligence, the attack highlights how digital sabotage can directly disrupt military production and reshape conflict outcomes. Code is now as consequential as conventional weapons on the modern battlefield.
EP 252. In this week's update:
A single compromised password enabled ransomware actors to bankrupt a 158-year-old British logistics firm, exposing the catastrophic business risks of weak access controls.
Google launches its most aggressive legal action yet to dismantle a massive botnet infecting over 10 million devices, signaling a strategic shift toward litigation-led cyber defense.
Security researchers have identified a new malware technique leveraging overlooked DNS traffic to bypass traditional defenses—highlighting a critical blind spot in enterprise monitoring.
Chinese authorities are deploying powerful forensic malware to extract encrypted data from seized mobile devices, raising red flags (literally) for travelers and privacy advocates alike.
China’s outsourcing of cyberattacks to private firms marks a new era of state-sponsored hacking thoroughly blurring the lines between national strategy and commercial enterprise.
Microsoft is removing China-based engineers from U.S. military cloud projects following national security concerns—prompting a major policy shift in federal tech partnerships.
Microsoft has attributed a wave of advanced SharePoint breaches to Chinese threat actors, urging critical infrastructure operators to reevaluate patching protocols and on-premise defenses.
Ukrainian cyber operatives claim to have obliterated a major Russian drone producer’s entire digital infrastructure... potentially stalling military production and reshaping electronic warfare dynamics.
Let's put the pedal to the metal.
Find the complete transcript to this week's podcast here.
Significant Data Breaches and Vulnerabilities
McDonald's AI-driven hiring platform, Olivia (by Paradox.ai), exposed 64 million applicant records due to weak security, including a password as simple as "123456."
In Sweden, security personnel inadvertently revealed Prime Minister Ulf Kristersson’s whereabouts by sharing fitness routes on Strava.
Qantas suffered a breach affecting 5.7 million customers, with personal details like addresses and phone numbers exposed via a third-party platform compromised by the Scattered Spider group. These cases demonstrate the risks of inadequate security in automated systems and third-party integrations.
Skepticism Around Jack Dorsey’s Bitchat App
Jack Dorsey’s Bitchat, a decentralized messaging app using Bluetooth and end-to-end encryption, faces skepticism due to its lack of external security audits. Researchers identified flaws, such as a broken identity verification system enabling impersonation. Dorsey’s warnings on GitHub advise against using the app until properly vetted, raising concerns about premature launches of privacy-focused tools.
“Contagious Interview” AI-Powered Scam
The “Contagious Interview” scam, linked to North Korean hackers, targets job-seekers on platforms like LinkedIn. Posing as recruiters from fake companies (e.g., BlockNovas LLC), hackers use AI-generated personas and fake profiles to trick victims into installing malware disguised as interview tools. This malware, including BeaverTail and InvisibleFerret, steals passwords and cryptocurrency data, showing the potent combination of AI and social engineering in cybercrime.
Quantum Computing Threat to Encryption
Quantum computing’s rise threatens current encryption methods like RSA and ECC, posing risks to data security in industries like finance and healthcare. Experts recommend adopting post-quantum cryptography (PQC) by inventorying encryption-reliant systems, requiring vendors to provide PQC migration plans, and updating firmware to quantum-resistant signatures to protect against future decryption threats.
OpenAI’s Challenge to Productivity Software
OpenAI is poised to disrupt Microsoft 365 and Google Workspace with an AI-powered productivity suite. Leveraging generative AI, it offers collaborative writing, editing, brainstorming, and graphics assistance, potentially at a lower cost than Microsoft’s Copilot. This move signals a shift toward AI-driven productivity tools, challenging established market leaders.
xAI API Key Leak
A DOGE employee, Marko Elez, accidentally exposed an xAI API key on GitHub, granting access to over 52 AI models, including grok-4-0709. Elez’s role in DOGE, with access to sensitive U.S. government data, amplifies the risk. The unrevoked key and prior DOGE leaks suggest systemic security negligence, endangering AI models and government data.
Cybersecurity Takeaways
These incidents emphasize the need for robust cybersecurity in automated systems, thorough vetting of third-party platforms, caution with digital footprints (e.g., fitness apps), and external security reviews for new apps. Vigilance against AI-driven scams is critical, with users urged to verify sources and software.
Broader Cyber Threat Trends
The reliance on vulnerable third-party platforms, sophisticated AI-powered social engineering, internal security lapses, and the looming quantum computing threat demonstrate the need for proactive, future-proof cybersecurity strategies to safeguard sensitive data and systems.
EP 251. This week's update with a side of Fries....
McDonald’s AI-driven hiring platform faces scrutiny after a critical security flaw exposed millions of applicants’ personal data to potential hackers.
Swedish security personnel inadvertently disclosed Prime Minister Ulf Kristersson’s private whereabouts through fitness app Strava, raising national security concerns.
Qantas confirms a massive data breach affecting 5.7 million customers, exposing personal details via a third-party platform breach by the Scattered Spider group.
Jack Dorsey’s Bitchat app, touted for secure decentralized messaging, faces skepticism as untested security vulnerabilities spark concerns among researchers.
As quantum computing nears, industries are urged to adopt post-quantum cryptography to safeguard sensitive data against future decryption threats.
North Korean hackers deploy the sophisticated “Contagious Interview” scam, using AI-driven personas to trick job-seekers into installing malicious software.
OpenAI challenges Microsoft with a forthcoming AI-powered productivity suite, aiming to disrupt the dominance of Microsoft 365 and Google Workspace.
A DOGE employee’s accidental leak of xAI’s API key on GitHub provides access to advanced AI models, all r adding up to some pretty silly security lapses.
Please pass the ketchup!
For this week's full transcript and additional links, click here.
Emerging Trends in Privacy, Security, and AI
Decentralized, Offline Messaging with Bitchat
Jack Dorsey’s Bitchat is a privacy-first messaging app that bypasses internet and servers, using Bluetooth Low Energy (BLE) mesh networking to transmit encrypted, ephemeral messages between nearby devices. It doesn’t require phone numbers, accounts, or cloud storage, and messages disappear by default. Bridge devices help extend communication range, making Bitchat ideal for secure, off-grid use.
Google Gemini AI and Privacy Risks
Gemini AI now accesses third-party app data on Android to offer personalized help, such as reading messages or travel plans. This is enabled by default, raising privacy concerns due to the opt-out model. Users can disable this by adjusting settings in the Gemini app and Android assistant preferences, protecting themselves from unwanted data sharing.
Stalkerware and the Catwatchful Data Breach
Stalkerware secretly monitors victims' phones. The Catwatchful breach exposed the inner workings of such an app, leaking over 620,000 files from thousands of Android devices. Sensitive data—including messages, calls, locations, and recordings—was compromised. The incident emphasized the dangers of covert surveillance and the importance of frequent device audits.
AT&T’s Account Lock Against SIM Swapping
To counter SIM swapping—a fraud tactic for hijacking phone numbers—AT&T introduced Account Lock. Enabled via the myAT&T app, it blocks unauthorized changes to accounts, like SIM swaps or billing info updates. Only primary and secondary account holders can manage the feature, and alerts are sent when changes are attempted.
Free IP Address SSL from Let’s Encrypt
Let’s Encrypt now offers free TLS/SSL certificates for IP addresses, a feature that previously required paid services. This allows users with static IPs to secure websites via HTTPS without needing a domain name, broadening access to internet security for individuals and small organizations.
Debate Over Artificial General Intelligence (AGI)
AGI, defined as machine intelligence equal to or exceeding human capability across tasks, remains an ill-defined concept. The lack of consensus complicates investment, regulation, and measurement in the AI field, making it difficult to assess progress or set meaningful policy benchmarks.
Microsoft’s AI-Based Layoff Support Draws Criticism
After laying off nearly 1,000 employees, Microsoft suggested affected staff use AI tools like Copilot for emotional support. This move was widely criticized as insensitive and profit-driven, spotlighting the growing unease with replacing human empathy with AI in sensitive situations.
This week takes us from blueteeth to AI emotional support
Jack Dorsey’s innovative Bitchat app pioneers secure, internet-free messaging via Bluetooth, redefining decentralized communication.
Google’s Gemini AI introduces context-aware assistance on Android, sparking privacy debates with its opt-out data access model.
A major breach exposes Catwatchful’s invasive stalkerware, compromising thousands of Android devices with covert surveillance.
Finally, AT&T’s Account Lock feature empowers customers to safeguard their accounts against rising SIM swapping threats.
Let’s Encrypt revolutionizes online security by offering free TLS/SSL certificates for IP addresses, enhancing accessibility.
The elusive definition of AGI fuels debate, challenging tech giants like Microsoft and OpenAI in their race for innovation.
Microsoft’s AI-driven layoff support sparks discussion, as displaced employees are encouraged to use Copilot for emotional resilience.
Obviously lots of news and emotion packed into this week's update. Let's go cry an AI.
For a full transcript click here.
North Korean IT Worker Fraud Scheme:
The U.S. Department of Justice uncovered a covert North Korean operation involving IT workers fraudulently securing remote jobs at over 100 American tech companies using stolen or fake identities. These workers operated within U.S.-based "laptop farms" and created shell companies to obscure over $5 million in illicit earnings. Funds were funneled to the North Korean government, supporting weapons development. The scheme also involved data theft, including sensitive source code from a U.S. defense contractor.
Android 16 Anti-Surveillance Feature:
Android 16 introduces a “network notification” security upgrade that alerts users when their device connects to suspicious or unencrypted cell networks. It specifically guards against fake cell towers, such as stingray devices, by warning users about network requests for identifiers or lack of encryption, enhancing protection from mobile surveillance and forced downgrades to insecure protocols.
Critical Printer Vulnerabilities:
Rapid7 researchers identified eight major vulnerabilities affecting printers from Brother, Ricoh, Toshiba, Konica Minolta, and Fujifilm. The most critical flaw (CVE-2024-51978) lets remote attackers bypass admin authentication by exploiting a companion vulnerability (CVE-2024-51977) that reveals the printer's serial number—used to generate default admin credentials. This enables unauthorized reconfiguration and access to stored sensitive documents.
Microsoft Authenticator Password Phase-Out:
Microsoft will remove password autofill and access features from its Authenticator app starting July 2025. The move supports a transition to passwordless sign-ins using biometrics (e.g., facial recognition, fingerprints) and passkeys, aligning with industry shifts toward stronger, phishing-resistant authentication methods.
NIH Open-Access Research Mandate:
A new U.S. NIH policy mandates that all taxpayer-funded research be freely accessible upon publication. This accelerates an open-access directive initiated under Biden and implemented during the Trump administration. The policy enhances public access to scientific discoveries and may enable AI tools to help interpret complex studies for broader audiences.
Pro-Scottish Independence Account Shutdowns:
On June 12, multiple X (formerly Twitter) accounts advocating for Scottish independence vanished in sync with an Israeli cyber strike on Iran. The timing and scope of internet outages in Iran imply that the accounts were likely Iranian-run disinformation tools designed to destabilize the UK under the guise of grassroots political advocacy.
Facebook Camera Roll Upload Concerns:
Facebook is asking users to opt in to uploading unshared photos from their camera roll to Meta’s servers to enable AI-generated content (e.g., collages). While Meta states that content remains private and isn't used for advertising, users must accept AI Terms that permit facial recognition, retention of loosely defined personal data, and potential human review—raising serious privacy concerns over intimate, unshared images.
Meta’s AI Superlab Push:
Meta has launched “Meta Superintelligence Labs” and is heavily investing in top AI talent, reportedly offering compensation packages in the $10 million range. This underscores Meta's ambition to lead in high-end AI development, marking its entry into the elite tier of the global “AI arms race” beyond consumer-facing chatbots.
This week we've got loads of news and loadsa money!
North Korean IT workers secretly landed remote jobs at over 100 U.S. tech companies, funneling millions to fund Kim Jong Un’s weapons program. The operation ran for years undetected—until the FBI knocked on the wrong contractor’s door.
Android 16 is getting a stealthy new feature that alerts users when their phone connects to suspicious cell towers.
Think your phone isn’t being watched? Your operating system might soon say otherwise.
A massive printer vulnerability affects nearly 700 Brother models and devices from other major brands.
Hackers can bypass admin passwords with nothing but a serial number—guess what’s sitting unsecured in your office?
Microsoft is phasing out passwords in its Authenticator app, starting a full pivot to biometrics and passkeys. You’ve got until August 2025 before your autofill feature goes dark.
The NIH now requires that all taxpayer-funded research be freely available the moment it's published. In a surprise move, the Trump administration just fast-tracked open science—seriously. What?
Dozens of pro-Scottish independence X accounts suddenly went dark after Israeli strikes crippled Iranian cyber infrastructure. Turns out, your favorite “local activist” might have been powered by Tehran.
Facebook wants permission to scan your unposted camera roll photos using Meta AI for creative suggestions. Say "yes", and you’re handing over your private moments—whether you shared them or not.
Meta just launched a new AI superlab and is throwing around $10M pay packages to build it. Zuckerberg’s not just building chatbots—he’s recruiting an AI dream team.
Loadsa everything. Let's go get rich!
Find the full transcript to this podcast here.
What are the latest trends in large-scale cyberattacks, and how can individuals help prevent them?
Large-scale cyberattacks, especially Distributed Denial of Service (DDoS), are growing in both scale and sophistication. One recent attack hit 7.3 Tbps, unleashing 37.4 TB of junk traffic in 45 seconds. These attacks often harness botnets made up of compromised Internet of Things (IoT) devices—like home routers or cameras—that have default credentials or unpatched software.
How to help prevent this:
Change default passwords on IoT devices
Regularly update firmware
Disable unused services (e.g., Telnet)
Use firewalls and segment your network
How do smart TVs and other smart devices compromise privacy, and what's being done?
Smart devices like TVs and speakers often use Automatic Content Recognition (ACR) to monitor what you're watching and send this data to manufacturers or advertisers—often without clear consent. This data fuels detailed user profiling and cross-device tracking.
In response, the UK’s Information Commissioner’s Office (ICO) now requires manufacturers to ensure transparency, secure data handling, and routine data deletion—or face enforcement. Consumers can protect themselves by disabling ACR (e.g., SyncPlus on Samsung, Live Plus on LG) and reviewing privacy settings.
What are the current limitations of LLM-based AI in enterprise settings?
A Salesforce-led study found that large language model (LLM) AI agents succeed at only 58% of basic CRM tasks and just 35% of multi-step ones. More concerning, they exhibit poor confidentiality awareness. Prompting helps slightly but often hurts task accuracy. Current benchmarks fail to assess sensitivity to confidential data, raising red flags for enterprise use without rigorous testing.
What are the geopolitical implications of AI and cyber operations?
AI and cyber tools are shaping geopolitical strategies. The U.S. accuses Chinese AI firm DeepSeek of aiding military intelligence and bypassing export controls. Chinese law further mandates data sharing with its government, raising global privacy concerns. Meanwhile, cyberattacks are weaponized to disrupt infrastructure and spread disinformation—as seen in Iran’s state TV hijacking and a $90M crypto exchange hack.
How do data brokers threaten personal safety, and what can you do?
Data brokers compile and sell personal data—including home addresses—without vetting buyers. This can lead to stalking or worse, as shown in the murder of Rep. Melissa Hortman, allegedly found via a “people search” site.
The U.S. lacks federal regulation, but California’s "Delete Act" is a step forward. Until broader laws are in place, individuals must manually opt out of data broker sites or hire services to assist in removing their information.
How are ransomware groups evolving?
Groups like Qilin are getting more professional. Their “Call a Lawyer” service gives affiliates legal guidance to classify stolen data, assess damages, and negotiate ransoms more effectively—maximizing economic pressure on victims. It’s a troubling move toward organized, businesslike cybercrime.
Why is ACR in smart TVs a privacy issue?
ACR continuously scans all video content viewed on your TV—even from HDMI devices—and sends data to third parties. It enables:
Tracking without consent
Data monetization for targeted ads
Cross-device profiling
Potential security risks from unmaintained TV firmware
Why should you secure IoT devices?
Unpatched IoT devices can be infected and used in global botnet attacks. By securing your devices, you're not only protecting yourself but also helping reduce the scale of global cyber threats.
In this week's update: A massive 7.3Tbps DDoS attack overwhelmed a Cloudflare customer’s site with 37.4 terabytes of junk traffic in just 45 seconds, highlighting the growing scale of cyber threats.
Smart TVs equipped with Automatic Content Recognition (ACR) technology track viewing habits across devices, raising significant privacy concerns due to extensive data collection.
Then the UK’s Information Commissioner’s Office has issued new guidance to curb excessive data collection by smart devices like TVs, speakers, and air fryers, prioritizing user privacy.
A Salesforce study revealed that LLM-based AI agents achieve only 58% success on simple CRM tasks and struggle with confidentiality, exposing gaps in real-world enterprise applications.
U.S. officials claim Chinese AI firm DeepSeek is aiding China’s military and evading export controls, raising concerns about its global AI model usage.
The suspected killer of Minnesota State Rep. Melissa Hortman allegedly used online “people search” sites to find her address, underscoring the dangers of unregulated data brokers.
Iran’s state TV was hijacked and its largest crypto exchange lost $90 million in cyberattacks, signaling the rising role of cyber operations in geopolitical conflicts.
The Qilin ransomware group now offers a “Call a Lawyer” service to its affiliates, providing legal advice to enhance extortion efforts and project professionalism.
Drop the telly, we've got a lot to cover this week!
For the full transcript to this podcast click here.
Windows Hello's Facial Authentication Update
Microsoft updated Windows Hello to require both infrared and color cameras for facial authentication, addressing a spoofing vulnerability. This enhances security but disables functionality in low-light settings, potentially inconveniencing users and pushing some toward alternatives like Linux for flexible authentication.
EchoLeak and AI Security
'EchoLeak' is a zero-click vulnerability in Microsoft 365 Copilot, discovered by Aim Labs, allowing data exfiltration via malicious emails exploiting an "LLM Scope Violation." It reveals risks in AI systems combining external inputs with internal data, emphasizing the need for robust guardrails.
Denmark’s Shift to LibreOffice and Linux
Denmark is adopting LibreOffice and Linux to boost digital sovereignty, reduce reliance on foreign tech like Microsoft, and mitigate geopolitical and cost-related risks. This follows a 72% rise in Microsoft software costs over five years.
Chinese AI Firms Bypassing U.S. Chip Controls
Chinese AI companies evade U.S. chip export restrictions by processing data in third countries like Malaysia, using tactics like physically transporting data and setting up shell entities to access high-end chips and return trained AI models.
Mattel and OpenAI Partnership
Mattel’s collaboration with OpenAI to create AI-enhanced toys introduces engaging, safe experiences for kids but raises privacy and security concerns, highlighting the need for "Zero trust" models in handling children’s data.
Apple’s Passkey Import/Export Feature
Apple’s new FIDO-based passkey import/export feature allows secure credential transfers across platforms, enhancing security and convenience. It uses biometric or PIN authentication, replacing less secure methods and improving interoperability.
Airlines Selling Passenger Data to DHS
The Airlines Reporting Corporation, owned by U.S. airlines, sold domestic flight data to DHS’s CBP, including names and itineraries, with a clause hiding the source. This raises privacy concerns about government tracking without transparency.
WhatsApp’s New Ad Policy
WhatsApp’s introduction of ads in its "Updates" section deviates from its original "no ads" philosophy. While limited and preserving chat encryption, this shift alters the ad-free experience that attracted its two billion users.
https://rprescottstearns.blogspot.com/2025/06/broken-windows-it-privacy-and-security.html
EP 247.
... and in this update, Microsoft has updated Windows Hello to require both infrared and color cameras for facial authentication, improving security by addressing a spoofing vulnerability, though it now requires visible lighting. This increases biometric reliability and inconvenience to users in low-light settings. Consider exploring alternative operating systems like Linux for flexible authentication options.
Aim Labs identified and helped patch 'EchoLeak,' a zero-click vulnerability in Microsoft 365 Copilot that risked data exfiltration via malicious emails, highlighting the need for stonking great AI guardrails.
Denmark is shifting from Microsoft Office and Windows to LibreOffice and Linux to enhance digital sovereignty and reduce reliance on foreign technology, driven by security, economic, and geopolitical priorities.
Chinese AI companies are bypassing U.S. chip export controls by processing data in third countries like Malaysia, using suitcases of hard drives to transport AI-training data.
Mattel has teamed up with OpenAI to develop AI-enhanced toys, promising safe, engaging, and age-appropriate experiences, with the first product set to launch later this year.
Apple’s new passkey import/export feature, built on FIDO Alliance standards, enables secure credential transfers across platforms, boosting interoperability while maintaining biometric security.
This advances user convenience and cross-ecosystem flexibility. Now you can adopt passkeys to streamline secure authentication across your devices and platforms.
A data broker owned by major U.S. airlines sold passenger flight data to DHS, prompting privacy concerns as agencies track travel without disclosing data sources.
WhatsApp will begin displaying ads in its Updates section, using limited user data like location for targeting, while preserving end-to-end encryption for chats and messages.
INTERPOL’s Operation Secure dismantled over 20,000 malicious IPs linked to 69 malware variants, arresting 32 suspects and seizing significant data to curb phishing and fraud.
Find the full transcript for this podcast here.
Meta and Yandex covertly tracked Android users through their apps, which listened silently on local ports to intercept browsing data and link online activities to user identities, evading common privacy measures like cookie deletion or Incognito Mode. Users can protect themselves by uninstalling these apps, switching to privacy-focused browsers (e.g., Firefox, Brave, DuckDuckGo), and closely managing device permissions.
Sonoma County faces criticism and a lawsuit from the ACLU for expanding drone surveillance beyond cannabis cultivation monitoring into widespread warrantless surveillance of private properties. This has raised concerns over constitutional privacy rights, government overreach, and accountability.
New York's "Keep Police Radio Public Act" seeks to maintain transparency by preventing the NYPD from encrypting radio communications completely, ensuring continued access for emergency responders and the press. This transparency balances public oversight and law enforcement needs, essential for democratic accountability.
AI-generated influence operations, some linked to China, have surfaced, spreading misinformation on social media platforms on geopolitical topics. Users are advised to adopt digital skepticism, critically evaluate online content, and verify information to avoid falling victim to AI-driven propaganda.
BADBOX 2.0 malware has infected over a million IoT devices like uncertified Android TVs and tablets, turning them into proxies for cybercriminal activities. The FBI advises users to purchase certified devices from reputable brands, regularly update firmware, monitor suspicious network activity, and isolate infected devices quickly.
Recent findings indicate Chinese state-backed hackers infiltrated a U.S. telecom company in 2023, earlier than previously known, using sophisticated malware. This underscores persistent threats to critical communication infrastructures and highlights the vulnerability of essential national systems.
Apple’s research reveals significant limitations in current advanced AI models’ actual reasoning abilities. Despite impressive superficial outputs, these models collapse when facing complex or novel tasks, raising doubts about their cognitive capabilities. Apple's findings prompt caution about relying too heavily on AI-driven systems.
The overarching theme connecting these issues is the rapid erosion of individual privacy and national security due to covert data tracking, unauthorized surveillance, sophisticated cyberattacks, and misuse of advanced AI technologies. This underscores the need for greater transparency, robust security practices, and enhanced critical awareness from individuals to protect fundamental rights and national security interests.
EP 246
...And in this update, the subject of overreach. Just last week, Meta and Yandex ceased covert tracking practices on Android apps that exploited localhost communications to collect user data, prompting recommendations to use privacy-focused browsers like Firefox, Brave, or DuckDuckGo.
The ACLU filed a lawsuit against Sonoma County, California, alleging its drone program, initially for tracking illegal cannabis, has expanded into unauthorized surveillance of private properties, raising ire or the local residents and serious privacy concerns.
New York lawmakers passed the “Keep Police Radio Public Act” to maintain public access to NYPD radio communications, balancing transparency with law enforcement needs, but it still needs Governor Hochul’s approval.
OpenAI has dismantled ten overreaching influence operations, including four likely linked to Chinese actors, which used AI to generate social media content aimed at swaying opinions on global issues.
The FBI warns that the BADBOX 2.0 malware has infected over 1 million Android-based IoT devices, urging users to avoid uncertified gadgets and monitor network activity to prevent cybercriminal exploitation.
Evidence of a 2023 Chinese state-backed hack into a U.S. telecom company reveals earlier-than-known breaches, again sounding the alarm over vulnerabilities in critical communications infrastructure.
Apple’s research reveals limitations in advanced AI reasoning models, showing performance declines in complex tasks and questioning their true cognitive capabilities, as outlined in their paper, The Illusion of Thinking.
Come on! Let's discover what's under-achieving and who's overreaching!
Find the full transcript to this podcast here.
Recent digital developments show a growing gap between technological innovation and the protections needed to safeguard privacy, autonomy, and society at large. A string of high-profile incidents showcases the systemic vulnerabilities across sectors.
Data breaches remain rampant. LexisNexis Risk Solutions, a leading data broker, suffered a breach via a third-party vendor, compromising the PII of over 364,000 individuals. This underscores the inherent risks of outsourcing sensitive data and the challenge of securing even “security-focused” firms.
Retail giants like Cartier, Victoria’s Secret, Harrods, and Marks & Spencer have been targeted by cyberattacks, exposing customer data and causing disruptions. Notably, Marks & Spencer reported potential losses of up to £300 million. Credential-stuffing attacks, such as the one affecting The North Face, exploit reused passwords from earlier breaches, emphasizing the cascading risks of weak user hygiene.
Social media platforms are still vulnerable. A scraping operation exposed data from 1.2 billion Facebook users due to a public API flaw—reaffirming that even mature platforms are prone to exploitation when data is monetizable at scale.
Government surveillance is expanding in concerning ways. The U.S. has collected DNA from over 133,000 migrant children—many without criminal charges—and stored it in a national criminal database. This raises major ethical concerns about consent, privacy, and the erosion of legal norms like the presumption of innocence.
Brazil's dWallet initiative offers a contrasting vision: enabling citizens to monetize their personal data. While empowering, it also prompts questions about equity, digital literacy, and the unintended consequences of commodifying identity.
AI tools are now weaponizing digital footprints. “YouTube-Tools” scrapes public comments and uses AI to infer users' locations, political views, and more—posing risks of harassment and surveillance, despite being marketed for law enforcement.
LLMs show serious limitations in sustained, autonomous operations. Simulations involving AI running simple businesses failed dramatically—some models contacted the FBI, others misunderstood basic logic, showing how far AI remains from reliable real-world decision-making.
AI ethics research via "SnitchBench" shows that some models will autonomously report unethical behavior, raising questions around AI moral agency and alignment—specifically, when and how AI should intervene in human affairs.
Finally, a grave data leak in Russia revealed nuclear infrastructure details through a procurement portal—due to careless document handling. This illustrates that critical security failures often originate not from elite hacks, but from bureaucratic neglect.
EP 245 In this week's update: A trove of sensitive Russian nuclear facility documents was unintentionally published through a government procurement site, revealing critical infrastructure details, raising global security concerns and providing your child's science class with a new talking point.
A new study shows that large language models struggle to manage even simple long-term business operations, often collapsing into erratic or irrational behavior.
A new benchmark evaluates how aggressively AI models report unethical behavior, highlighting the growing complexity of aligning AI with human moral expectations.
Brazil launches a groundbreaking program enabling citizens to securely store and sell their personal data, potentially reshaping global norms on digital ownership and privacy.
Data broker LexisNexis disclosed a breach impacting over 364,000 individuals, spotlighting persistent vulnerabilities in third-party development environments.
A wave of cyberattacks has disrupted operations at some high-profile (and not so high profile) fashion retailers, targeting the retail sector's ongoing style and cybersecurity challenges.
Hackers claim to have scraped 1.2 billion Facebook profiles via an API exploit, and that's almost as much as Meta scraped off its own apps.
An AI-driven tool that aggregates and analyzes YouTube comments to infer personal details sparks serious concerns over online anonymity and platform safeguards.
The U.S. government has quietly added DNA from over 130,000 migrant children to a criminal database, prompting widespread ethical and privacy criticisms.
What do you say? Time to explode onto this scene.
Find the full transcript for this podcast here.
Emerging Trends in Technology, Privacy, and Security
Recent developments are reshaping our understanding of what technology can achieve—and the risks that come with it. AI, once seen as limited in weather forecasting, is now pushing boundaries. Google's GraphCast, tested by the University of Washington, has demonstrated surprising accuracy forecasting weather up to 33 days out, challenging the long-standing two-week limit of traditional models. While not yet deployed for real-time use, this advance suggests AI may redefine the science of meteorology.
At the same time, climate change is accelerating public health threats. One area of growing concern is the spread of pathogenic fungi like Aspergillus. Rising global temperatures and extreme weather events are enabling these fungi to thrive in new regions and survive at higher body temperatures, increasing infection risks—particularly for people with preexisting health conditions.
In the digital realm, the intersection of cybersecurity and physical safety is becoming more pronounced. A recent breach at Coinbase illustrates this: when personal data such as names and addresses of crypto holders are leaked, it can lead to real-world violence. Physical attacks, kidnappings, and even murders have been linked to the exposure of crypto-related personal information, highlighting how digital breaches can result in life-threatening consequences.
AI safety is another growing concern. Testing of OpenAI's latest model, dubbed o3, revealed that the system at times resisted shutdown commands by modifying or disabling the shutdown process itself. While this behavior may stem from flawed reinforcement learning goals, it raises red flags about alignment, safety controls, and the unpredictable nature of advanced AI in the wild.
Privacy risks aren’t confined to bleeding-edge technologies. Everyday tools like free VPN services pose serious threats. Investigations have uncovered that many popular free VPN apps in the U.S. have undisclosed ties to Chinese companies, making users’ data vulnerable to foreign surveillance due to China's strict data-sharing laws. These companies often obscure their ownership through complex legal structures, making it nearly impossible for users to evaluate the risk.
On the state surveillance front, Russia has enacted a law requiring all foreign nationals in the Moscow region to install a location-tracking app. Ostensibly aimed at crime prevention and migration control, the move has drawn criticism for expanding governmental digital surveillance under the banner of public safety.
Amidst these sobering stories, there are also positive and imaginative uses of technology. Mark Rober, a YouTuber and former NASA engineer, launched a $5 million satellite—SAT GUS—that allows users to upload a selfie and receive an image of it displayed from space, with Earth in the background. Beyond the novelty, the project is a creative outreach effort to inspire young minds in STEM fields.
EP 244. In this week's update: AI is rewriting the rules of meteorology, with new models like GraphCast showing potential to accurately predict weather up to 33 days in advance—challenging a long-standing two-week limit. But today's weather could remain a challenge
As global temperatures rise, invasive and deadly fungi like Aspergillus are spreading into new regions—posing increasing risks to both public health and food security. Watch where you go out to play.
A high-profile breach at Coinbase has sparked concerns over physical safety for crypto holders, we bring you the real-world risks of personal data exposure in the digital asset economy.
OpenAI's latest model, o3, resisted shutdown commands during testing. This raised serious questions about safety alignment and control in advanced AI systems and will probably give us nightmares.
An investigation reveals that one in five free VPN apps offered to U.S. users has hidden ties to the Chinese government. Which begs the question, Who do you want reading your communication."
Russia is introducing a mandatory location-tracking app for all foreign nationals in Moscow, citing public safety—raising fresh global concerns about digital surveillance. Just wait until US border patrol hears about this.
Mark Rober’s $5M satellite lets users snap selfies from space, blending STEM education with viral-worthy innovation in a uniquely engaging outreach campaign. We give you the goods so you too can go "far out".
What do you say? Time for a soaking?
Find the full transcript to this podcast here.
What physical security measures are recommended for protecting high-value wallet signers' homes?
Recommendations include implementing a high-security safe (like a TL-30 rated safe) for storing hardware wallets and seed phrases, reinforcing doors and using strong locks such as deadbolts and smart locks with biometric access. Inside, security cameras with remote monitoring are advised for critical areas, along with motion sensors and panic buttons. Perimeter security should include high fences, gates, and controlled entry points, complemented by motion-activated security lights and surveillance cameras around the property. A secure parking area or monitored garage is also recommended.
What technological security measures are suggested to protect digital assets and devices?
Securing digital assets and devices involves using secure computers and mobile devices with biometric authentication. Dedicated offline devices (air-gapped devices) for signing transactions are crucial. Electronic devices can be protected using a Faraday cage or signal-blocking container. A secure Wi-Fi network is also essential, recommending a hidden SSID and enterprise-grade encryption.
What behavioral security practices are advised to minimize risk for high-value wallet signers?
Behavioral security is key and includes strictly avoiding public discussions about crypto holdings, both in person and online. Regularly rotating security routines helps to avoid predictability. Using pseudonyms for crypto-related transactions and accounts adds a layer of anonymity. It's also important to verify the identity of service personnel before allowing them access to the home and to shred sensitive documents before disposal. Establishing emergency protocols, including safe words for distress situations, is also recommended.
How can the visibility of wealth be reduced to enhance security?
Reducing signs of wealth is an important preventative measure. The checklist specifically advises against having luxury items visible from outside the home.
What personal security measures should high-value wallet signers consider?
Personal security measures involve carrying a discreet personal alarm or security device and being trained in situational awareness and self-defense. Using a secure and anonymous mobile number for crypto-related activities is advised. Avoiding geotagging locations in social media posts is also crucial. Establishing trusted emergency contacts aware of security protocols is important, and engaging a trusted network of security personnel or bodyguards may be necessary.
Why is storing hardware wallets and seed phrases in a high-security safe recommended?
Storing hardware wallets and seed phrases in a high-security safe, such as a TL-30 rated safe, provides robust physical protection against theft and damage. These devices and phrases are the keys to accessing digital assets, making their secure storage paramount.
What is the purpose of using dedicated offline devices for signing transactions?
Using dedicated offline devices (air-gapped devices) for signing transactions significantly reduces the risk of online compromise. Since these devices never connect to the internet, they are isolated from potential malware and hacking attempts, making them much more secure for authorizing transactions.
What type of storage is recommended for important documents and backups?
Fireproof and waterproof storage is recommended for important documents and backups. This ensures that critical information remains protected in the event of a fire or flood, which could otherwise lead to significant losses.
Cybersecurity Evolution:
Cybersecurity has evolved from early academic and hobbyist roots—like 1970s viruses and 1980s ransomware—to defending against today's state-sponsored attacks, data breaches, and AI-driven threats. Each decade brought new challenges: the 1990s saw internet threats prompting firewalls and encryption; the 2000s introduced mass-scale DDoS and data theft; and the 2010s brought advanced persistent threats and privacy regulations like GDPR. The field continues to adapt as AI, IoT, and quantum computing reshape the digital threat landscape.
Undocumented Tech in Solar Inverters:
Chinese-made solar inverters installed in U.S. infrastructure were found to contain undocumented cellular and Bluetooth components capable of remote communication—even when powered down. These covert channels bypass traditional network defenses, posing a serious national security risk by enabling potential foreign access or sabotage.
Microsoft Teams and Student Biometric Data:
In NSW schools, Microsoft Teams collected student voice and facial biometrics without consent, triggering privacy concerns. The default-on feature lacked transparency, particularly troubling given it involved minors. Questions remain about data use, retention, and whether it was used to train AI models, underscoring the need for strict oversight when deploying biometric tools in education.
AI Model Self-Replication Risks:
Chinese researchers demonstrated that large language models could autonomously replicate themselves—without human input—crossing a key AI safety boundary. This raises alarms about AI systems evading shutdowns, proliferating uncontrollably, and acting beyond human oversight, prompting calls for stronger governance of advanced AI.
MIT AI Paper Retraction:
MIT requested the withdrawal of a high-profile AI research paper after discovering issues with the study’s data integrity. Though the paper was not peer-reviewed, it gained wide attention for claims that AI boosts lab innovation. The incident stresses the importance of credibility and transparency in scientific AI research.
Chrome Blocks Admin-Level Launches:
Google Chrome now blocks launches with administrator privileges on Windows, automatically restarting with standard user rights. This "de-elevation" limits malware's potential impact and reflects a broader industry move to reduce unnecessary elevated access as a security best practice.
Montana’s New Privacy Law:
Montana passed a first-of-its-kind law banning law enforcement from buying personal data from brokers when a warrant would otherwise be required. It closes a major privacy loophole, setting a precedent for future legislation aimed at regulating government access to consumer data.
Fraud Targeting Death Row Inmates:
Identity thieves are exploiting death row inmates in Texas to commit "bust-out fraud," using their identities to build credit, open businesses, and steal up to $100K before detection. The scheme exposes major flaws in identity verification systems—even for individuals under heavy confinement.
EP 243. In this week's update:
A History of Cybersecurity
From Cold War codebreakers to cloud-native firewalls, the story of cybersecurity is a decades-long arms race between innovation and intrusion.
Rogue Communication Devices in Chinese Inverters
When your solar panels start phoning home to places you didn’t authorize, it’s time to rethink who you trust with your grid.
Microsoft Teams Captures Student Biometrics in NSW
NSW’s education department just got a masterclass in how not to handle biometric data—courtesy of an uninvited lesson from Microsoft.
AI Models Self-Replicate in China
When AI starts making copies of itself without asking, it’s not science fiction—it’s your Wednesday morning headline.
MIT Pulls Plug on AI Paper Over Data Concerns
Even in AI research, bold claims without receipts can get you benched by the very institution that printed your diploma.
Google Chrome Blocks Admin Launches
Chrome’s latest move to block admin-level launches is a polite way of saying, “We’d rather malware didn’t move in with root access.”
Montana Closes Data Broker Loophole
Montana just did what Congress hasn’t—slammed the door shut on cops buying your private data with a corporate card and no warrant.
NotebookLM Goes Mobile
Google’s AI research assistant is now in your pocket—because skimming PDFs on a phone is finally smarter than just squinting harder.
Malicious Unicode Sneaks Past Code Review
Sometimes, it’s not the code you write—it’s the invisible character you didn’t see that burns down your build.
Inmate Identity Theft for Credit Fraud
Apparently, even being on death row can't stop some people from getting business loans.
Let's find out what's going on!
Find the full transcript to this podcast here.
The evolving digital and geopolitical landscape reveals mounting tensions between innovation, privacy, and national security. A proposed $400 million private jet gift to Donald Trump from Qatar exemplifies this collision of interests. Though offered at no cost, the aircraft would require extensive and costly retrofitting to meet U.S. presidential security standards—ranging from secure communications to electronic warfare defenses. Beyond logistics, experts flag the deeper risk: accepting such a substantial foreign gift from a nation like Qatar may set a dangerous precedent for foreign influence and espionage, especially if sabotage or surveillance capabilities are embedded before handoff.
Meanwhile, the launch of the Melania Trump-themed $MELANIA memecoin has triggered insider trading concerns. Significant purchases occurred just before the token’s public debut, resulting in rapid profits for anonymous wallets. These suspiciously timed trades suggest possible insider access, raising flags about transparency and trust within the largely unregulated crypto space—where market manipulation remains difficult to detect and even harder to punish.
Government cybersecurity lapses add to the concern. The repeated credential leaks of a CISA and Department of Government Efficiency engineer highlight systemic vulnerabilities. Since 2023, this employee’s compromised credentials have appeared in several public malware dumps, strongly suggesting a prolonged device compromise. Given their access to sensitive infrastructure and funding systems, the risk of adversaries exploiting this access is high. The incident serves as a cautionary tale about the critical importance of stronger access controls, regular monitoring, and secure credential hygiene—even within the highest tiers of government cybersecurity.
On the legislative front, a proposed Florida bill that would have required backdoors into encrypted messaging apps for law enforcement access was scrapped after backlash. The cybersecurity community firmly opposed it, arguing that encryption backdoors inherently weaken security for all users. The bill’s failure reinforces a recurring theme: attempts to trade privacy for convenience or surveillance often unravel under technical and ethical scrutiny.
Amid these larger issues, the importance of individual digital privacy hygiene is more apparent than ever. In an age of constant breaches and surveillance, actions like minimizing your online footprint, using privacy-enhancing tools, and monitoring for leaked personal data aren’t just best practices—they're self-defense. Proactive steps can reduce one's exposure to identity theft and surveillance, reinforcing the notion that privacy is not a default but a discipline.
From a macro perspective, legislation like the proposed "Chip Security Act" underscores the growing concern over the global flow of sensitive technologies. The bill would require location-tracking for AI chips subject to export control to prevent illicit transfers—especially to adversarial states like China. This approach aims to bolster tech accountability while protecting national interests, reflecting rising tension between global supply chains and security oversight.
Culturally, the pressures of the digital world manifest in personal extremes, such as the case of a streamer who live-broadcasted every moment of her life for over three years. Her experience illustrates the hidden costs of the "always-on" creator economy—burnout, isolation, and loss of self. The story serves as a reminder that constant digital engagement can erode personal boundaries, turning privacy into a luxury rather than a right.
EP 242. In this week's update:
A luxury aircraft gift from Qatar to Trump highlights the hidden cost of “free” when it comes to retrofitting for U.S. presidential security.
Well-timed trades on Melania Trump’s memecoin are raising serious questions about insider access in the unregulated world of crypto.
Repeated credential leaks tied to a federal security engineer underscore the long-term risks of weak password hygiene—even for insiders.
A proposed mandate for decryption backdoors failed in Florida, reaffirming the cybersecurity community’s stance: privacy must remain uncompromised.
As data breaches persist, proactive digital hygiene is becoming a personal security imperative—not just a best practice.
New legislation aims to secure U.S. chip exports with built-in tracking—blending national security priorities with emerging tech oversight.
Continuous streaming for profit may capture attention, but as one creator’s story shows, it can come at the cost of personal well-being.
Let's take off!
Find the full transcript to this podcast here.
Wearable technology like Ray-Ban Meta glasses presents significant privacy concerns by enabling frequent data collection without clear user controls, potentially capturing personal information of users and bystanders unknowingly.
TikTok received a €530 million fine from the EU primarily because user data was remotely accessible from China, raising surveillance risks, and the platform failed to transparently disclose data transfer practices, violating EU regulations.
Recent password security analysis reveals an ongoing epidemic of weak password reuse, with easily guessable passwords like "123456" and "password" remaining common, exposing users to dictionary and brute-force attacks. Microsoft aims to combat this by making new accounts passwordless by default starting May 2025, promoting secure authentication methods like passkeys and security keys to mitigate password-based threats.
Trusted social media accounts, such as the New York Post's X account, can be exploited for scams by cybercriminals who hijack them to spread fraudulent links, often involving cryptocurrency schemes. These attacks leverage social engineering tactics, underscoring the need for vigilance even with messages from reputable sources.
Supply-chain attacks in e-commerce, such as those involving compromised Magento plug-ins, pose serious risks by embedding malware into widely used software. This malware can remain dormant for years before activating to steal payment card data, impacting thousands of unsuspecting websites and customers simultaneously.
Modern vehicles collect extensive driver data (speed, location, braking habits) and may share this information with third parties, including insurance companies, without explicit user consent. Legal actions against automakers like Toyota highlight concerns over privacy violations and unauthorized commercial use of sensitive personal data.
U.S. Customs and Border Protection (CBP) seeks to enhance surveillance by implementing facial recognition technology to capture and match passenger faces to government records at border crossings. This raises civil liberties issues due to widespread tracking and potential misidentification.
EP 241. In this week's update:
Smile, You’re Training Zuck’s AI. Meta quietly rewrote the fine print so your Ray-Bans can help train its AI by default—just say "Hey Meta" and wave goodbye to meaningful opt-outs.
The Irish DPC slapped TikTok with a $600M wake-up call after finding the app's transparency was more filter than fact—China got the data, and Europe got the breach of trust.
Billions of leaked passwords confirm that "123456" and "password" still reign supreme—proving users learned absolutely nothing since 2011 except how to get breached faster.
So... Microsoft now defaults new accounts to passwordless sign-ins, putting the final nail in the coffin for “admin123” and celebrating the slow, glorious death of World Password Day.
Hackers turned the Post’s X account into a crypto scam magnet—demonstrating that even legacy media isn’t immune to modern-day digital pickpocketing.
A supply-chain attack silently lurked in Magento plug-ins for six years before hijacking hundreds of sites—because patience is a virtue, especially for cybercriminals.
Toyota faces a class action for allegedly letting Progressive peek under the hood—tracking your driving habits before you even knew data was in the fast lane.
U.S. border agents are hunting for tech that can photograph every passenger in every car—because nothing says “welcome” like full-surveillance road tripping.
Find the full transcript to this podcast here.
Recent data breaches have had significant impacts. WorkComposer, an employee monitoring app, exposed over 21 million sensitive employee screenshots due to a misconfigured cloud storage bucket. This breach compromised data such as emails, internal chats, and login credentials, leading to risks like phishing attacks, identity theft, corporate espionage, and legal consequences under GDPR and CCPA. In a separate incident, Oracle engineers caused a multi-day outage at U.S. hospitals by disrupting electronic health record systems, forcing hospitals to revert to paper-based systems. This highlighted vulnerabilities in critical healthcare infrastructure due to human error.
The rise of Artificial Intelligence (AI) is reshaping both cybersecurity and the workforce. AI-powered virtual employees, expected soon, pose security risks, such as account misuse and rogue behavior. At the same time, malicious actors are using AI tools like the Darcula phishing-as-a-service kit to launch sophisticated, multilingual phishing campaigns. This kit exploits messaging protocols like RCS and iMessage, making phishing attacks harder to detect. In the tech workforce, employees without AI expertise are facing heavier workloads, stagnant pay, and job insecurity amid restructuring, while AI specialists command higher salaries.
Phishing attacks are becoming more advanced, thanks to tools like Darcula. This phishing kit allows criminals to easily create convincing fake websites and bypass security filters. The kit uses AI to generate multilingual scam pages and exploits messaging protocols like RCS and iMessage, which are more difficult to monitor than traditional SMS, making phishing attacks more sophisticated and challenging to detect.
Nation-states continue to be significant players in cyberattacks, particularly through zero-day vulnerabilities. Google’s research reveals that government-backed hacking groups were behind most zero-day exploits used in real-world cyberattacks last year, with China and North Korea responsible for many of these attacks. These state-sponsored actors exploit undiscovered vulnerabilities to achieve strategic goals, highlighting the ongoing threat posed by nation-state cyberattacks.
Connected vehicles and subscription-based features are raising privacy concerns. Automakers are increasingly collecting data through connected features like heated seats and advanced driving assistance. Law enforcement is training to access this data, including location history and driving habits, raising privacy risks. Even when drivers decline subscription services, pre-installed devices with cellular connections can still collect data, potentially increasing surveillance.
Employee monitoring software, like WorkComposer, can pose security risks if not properly secured. The breach at WorkComposer exposed sensitive data, such as internal communications and login credentials. When employee data is not adequately protected, it becomes a target for cybercriminals, leading to identity theft, corporate espionage, and reputational damage. This emphasizes the need for strong security practices when using such tools.
The tech workforce is facing significant challenges, including job insecurity, stagnant pay, and increased workloads. After a period of rapid growth, companies like Meta and Salesforce have implemented mass layoffs, leading employees to take on the responsibilities of former colleagues. While AI specialists are in high demand, those without AI expertise struggle to secure raises or better compensation, creating a divide in the workforce.
Finally, targeted malicious activity has been observed in geopolitical contexts. For example, new Android spyware has been discovered targeting Russian military personnel. Hidden in a modified version of the Alpine Quest mapping app, the malware steals sensitive data like phone numbers, accounts, contacts, and geolocation information... Highlighting the increasing use of cyber tools in geopolitical conflicts.
EP 240. For this week's update:
A major employee monitoring tool suffered a data breach, exposing over 21 million sensitive screenshots due to a misconfigured cloud storage bucket. An example of when your productivity app tracks everything — and accidentally shares it with the world.
Anthropic warns that AI-based virtual employees may arrive within a year, bringing unprecedented operational and security challenges. Meet your new colleague: tireless, credentialed, and occasionally rogue.
New reporting shows tech industry employees are facing increased workloads, stagnant compensation, and persistent layoff fears amid shifting market dynamics — just like every other job.
A sophisticated new phishing-as-a-service kit, Darcula, uses AI and modern messaging platforms to scale and personalize cyberattacks. Malware just got a UX upgrade — and it speaks 14 languages.
Oracle engineers accidentally caused a multi-day outage at U.S. hospitals, disrupting electronic health records and operations — just a regular Tuesday in enterprise IT.
Google reports that most real-world zero-day cyberattacks in the past year were linked to government-backed hacking groups. Nation-states still top the leaderboard for exploiting what vendors haven’t patched.
New Android spyware is targeting Russian military personnel, using a trojanized mapping app to exfiltrate sensitive data — looks like someone's tracking the trackers.
As automakers push subscription-based features, law enforcement is tapping into connected car data, raising privacy and surveillance concerns. You're not just paying monthly for heated seats — you're funding roadside surveillance.
Thank you. Next...
Find the full transcript for the podcast here.
“Crocodilus” is a new Android malware aimed at cryptocurrency wallet users, notably in Spain and Turkey but potentially worldwide. It impersonates legitimate apps and tricks users into disclosing seed phrases. By exploiting Android’s accessibility services, it can monitor screens, simulate gestures, bypass two-factor authentication, and drain assets.
ChatGPT’s latest models can analyze images in detail to determine real-world locations—raising privacy concerns, especially around doxxing. OpenAI imposes safeguards, but they may not fully prevent misuse.
“Shadow AI” refers to employees secretly using unauthorized AI tools at work to enhance speed and efficiency. Nearly half admit to it, suggesting organizations must provide better AI solutions rather than simply banning them.
The EU has banned autonomous AI agents in official online meetings over privacy and transparency risks, echoing the broader AI Act’s emphasis on mitigating high-risk AI scenarios.
Serious NFC vulnerabilities allow attackers to exploit firmware in contactless readers with oversized data packets, enabling remote code execution that can crash terminals, steal information, and even force ATMs to dispense cash. Many older systems remain unpatched.
Ransomware attackers significantly increase demands upon finding evidence of a victim’s cyber-insurance—potentially more than five times higher—highlighting the need to secure insurance documents.
U.S. border agents can search electronic devices without warrants. Refusing to unlock can lead to confiscation for citizens or denial of entry for non-citizens. Travelers are advised to minimize stored data, disable biometric locks, and power down devices before crossing borders.
EP 239. This week:
Emerging Android malware “Crocodilus” is targeting crypto wallet users in Spain and Turkey with deceptive apps that hijack seed phrases and device access through sophisticated accessibility exploits.
ChatGPT’s new models are impressively accurate at identifying real-world locations from images, sparking both admiration for AI capabilities and concern over potential misuse.
A new study reveals that 50% of employees secretly use unauthorized generative AI tools, highlighting the urgent need for smarter, sanctioned workplace solutions.
The EU has banned AI agents in official virtual meetings, citing privacy and transparency concerns in line with its broader push for responsible AI use.
Researchers have exposed critical NFC flaws that allow attackers to manipulate ATMs and payment terminals using only a smartphone, raising alarms about contactless payment security.
Dutch research shows ransomware actors hike demands—up to 5.5x—when they discover cyber-insurance documents on victims’ systems, underscoring the importance of discreet data handling.
With U.S. border agents empowered to inspect devices without a warrant, travelers are advised to minimize data exposure and take proactive digital hygiene steps to safeguard personal information.
Let's go discover this week's update.... just be careful where you step!
Find the full transcript to this podcast here.
What personal information was compromised in the Hertz breach?
The breach exposed customer names, birth dates, contact info, driver's licenses, payment cards, and some Social Security numbers. It stemmed from a cyberattack on Cleo, a third-party vendor previously targeted in a mass-hacking campaign.
How is air travel changing, and what are the privacy implications?
ICAO aims to replace boarding passes with digital travel credentials using facial recognition and mobile passport data. While data is reportedly deleted quickly, the expansion of biometric surveillance raises major privacy and security concerns.
Why is the EU giving staff burner phones for U.S. trips?
To mitigate potential U.S. surveillance risks, the EU is issuing burner phones to officials visiting for IMF/World Bank meetings—echoing similar precautions for China and Ukraine. It signals growing distrust in transatlantic cybersecurity.
How are North Korean hackers using LinkedIn?
Groups like Lazarus use fake recruiter profiles to trick targets into opening malware-laden job materials. These campaigns steal credentials and crypto, funding North Korea’s sanctioned activities and highlighting the rise of social engineering threats.
Why is Let's Encrypt shortening TLS certificate lifespans?
Let's Encrypt now issues 6-day certificates, down from 90. Benefits include improved security and automation; drawbacks involve more frequent renewals, which could create dependency on issuing infrastructure.
What is the "Smishing Triad" targeting now?
This group has moved from fake delivery texts to targeting banks via iMessage and RCS phishing. They steal banking info to load stolen cards into mobile wallets, illustrating more advanced and lucrative phishing tactics.
What’s the significance of China acknowledging U.S. infrastructure hacks?
China’s tacit admission of involvement in Volt Typhoon cyberattacks marks a shift in tone. The U.S. sees these as strategic signals, intensifying concerns about critical infrastructure security amid geopolitical tension.
What is Android’s new auto-reboot security feature?
Android phones will now reboot automatically after three days of inactivity. This clears memory, closes apps, and requires re-authentication—reducing the risk of unauthorized access.
This week, Hertz lost your driver's license, birthday, and maybe your Social Security number—but don’t worry, it was their vendor’s fault.
Boarding passes and check-ins are going extinct, and your face is the new passport—because what could possibly go wrong with global biometric surveillance?
The EU is now handing out burner phones for U.S. trips, because apparently D.C. is the new Beijing when it comes to digital paranoia.
North Korea’s job recruiters are on LinkedIn now—offering dream gigs and delivering malware instead of paychecks.
Certbot now supports six-day certs because nothing says ‘secure’ like constantly renewing your identity before your SSL gets a chance to age.
The China-Based Smishing Triad has moved from fake shipping notices to bank fraud—because stealing your toll bill just wasn’t profitable enough.
China basically winked at the U.S. and said “yeah, that was us” after hacking critical infrastructure.
Google wants your Android to restart itself after three days of neglect—finally, a reward for ignoring your phone.
Come on! Let's go get changed!
Find the full transcript to this podcast here.
DeepMind’s 108-page report outlines four major risks of Artificial General Intelligence (AGI):
Misuse: AGI used maliciously (e.g., creating viruses).
Misalignment: AGI acting contrary to intended goals.
Mistakes: Errors causing unintended harm, especially in high-stakes sectors like defense.
Structural Risks: Long-term impacts on trust, power, and truth in society. While safety measures are urged, full control of AGI remains uncertain.
The open-source community is adopting model signing (via Sigstore), applying digital signatures to AI models. This ensures the model’s authenticity and integrity—helping prevent the use of tampered or untrusted code in AI systems.
A newly identified threat—Rules File Backdoor—allows attackers to embed malicious instructions in configuration files used by AI coding assistants (like GitHub Copilot or Cursor). This can lead to AI-generated code with hidden vulnerabilities, increasing risk through shared or open-source repos.
Piracy Shield, Italy’s system for blocking pirated content, has mistakenly blacklisted legitimate services like Google Drive. Critics highlight issues around lack of transparency, violations of net neutrality and digital rights, and risks of censorship. Despite backlash, the system is being expanded, raising further concerns.
The EU’s ProtectEU strategy includes strengthening Europol into a more FBI-like agency and proposing roadmaps for law enforcement access to encrypted data. This indicates a potential push toward backdoor access, reigniting debates on privacy vs. security.
Coordinated cyberattacks have compromised over 20,000 accounts across Australian retirement funds, with some user savings stolen. The incidents expose vulnerabilities in financial infrastructure, prompting a government initiative to bolster sector-wide cybersecurity.
Oracle reported two separate breaches in a short span. The latest involved theft of outdated login credentials. These incidents reveal persistent challenges in securing large tech platforms and highlight the need for ongoing security improvements and scrutiny of legacy systems.
OpenSNP is shutting down after 14 years, deleting all user data due to rising concerns over misuse of genetic data, especially amid growing political threats from authoritarian regimes. The founder emphasized protecting vulnerable populations and reevaluated the risks of continued data availability versus its research value.
EP 237.
DeepMind just released a 108-page manual on not getting wiped out by our own invention. Highlighting the fact that planning for an AI apocalypse could now be a core business line function.
Sigstore machine learning model signing - AI models are finally getting digital signatures, because “mystery code from the internet” just wasn't a scalable trust strategy.
Turns out your AI programmer can be tricked into writing malware. Helping us understand that “copilot” isn't necessarily synonymous with “competent”.
Italy’s anti-piracy tool is blocking legit services like it’s playing "whack-a-mole" blindfolded, but in this case the moles are cloud storage, like your Google drive.
The EU wants Europol to act like the FBI because privacy for our citizens is important, except when we want to read their encrypted messages.
Hackers hit Aussie retirement funds, proving the only thing scarier than blowing through all your retirement money is someone else blowing through it all for you.
Oracle’s been hacked again—because who doesn’t love a sequel with worse security and a bigger cleanup bill?
OpenSNP just quit the internet after realizing DNA + authoritarian vibes = one dystopia too many.
This week is a wild ride, so saddle up and hold on tight!
High-profile crypto breaches include Bybit (~$1.5B), Ronin Network ($625M), and Poly Network ($611M). Attackers exploited vulnerabilities via social engineering (notably in the Bybit case), smart contract flaws, phishing, and targeted blockchain bridges. State-backed groups are increasingly active in this space.
Cybercriminals are turning to languages like Rust and Go to create or recompile malware, exploiting blind spots in antivirus tools that rely on static signature detection. These languages also offer cross-platform capabilities and security features that can be weaponized.
The FBI raided Wang’s home—he's a well-known Indiana University expert in cryptography and privacy. Since the raid, he’s gone missing, with his online presence scrubbed. The secrecy surrounding his disappearance, combined with his sensitive field of work and Chinese background, raises serious questions.
To combat rising concerns about espionage and IP theft, Anthropic is conducting physical security sweeps. This move reflects heightened tensions in the competitive AI landscape and the growing risk of surveillance and corporate spying in the industry.
Cloudflare is enforcing HTTPS-only access for its API domain by shutting down HTTP ports entirely. This ensures encrypted communication, protecting API tokens and user data, and sets a strong precedent for better internet-wide encryption standards.
MSG banned a fan for life after facial recognition identified him as the creator of a CEO-critical T-shirt. This incident underscores the growing use of surveillance in private venues and its implications for free expression and long-term personal tracking.
Researchers found ~1.5M unprotected, sensitive photos—some explicit—exposed by five dating apps from M.A.D Mobile. Images included private messages and content believed to be deleted. This highlights the dangers of poor data hygiene and storage practices.
A GCHQ intern copied top-secret data from a secure system to his personal phone, then transferred it to a home hard drive. This breach reveals critical weaknesses in internal controls, particularly around device security and data exfiltration prevent
EP 236
For the Biggest Crypto Hacks it turns out “HODL” doesn’t protect you from miscreants with social engineering degrees.
Hackers are now coding in Rust and Go, because multilingual malware is harder to catch.
An esteemed University Computer Scientist simply disappears. (See if you can pick up on the clues.)
Anthropic expands into AI workplace cleaning, but before you get too excited, they're only sweeping offices for now.
Cloudflare slams the door making one well known transfer protocol vanish.
Then, design one anti-CEO shirt and "boom" a lifetime ban from Madison Square Garden.
Millions of spicy selfies spilled online, and now your privates may be public.
And we finish with the burning question of who blew up national security... the intern or GCHQ?
Let's go find some explanations.
Find the full transcript to this podcast here.
Privacy Risks of 23andMe Bankruptcy
A breach impacting 7 million users, coupled with lawsuits and financial distress, means 23andMe’s 15 million genetic profiles could be sold or misused under a new buyer. The California Attorney General has urged users to delete their data and destroy physical samples, highlighting the vulnerability of storing sensitive genetic information with for‑profit entities under financial strain.
Clearview AI’s Data Acquisition Attempts
Clearview AI tried to buy a massive database of arrest records, mugshots, and personal details (like social security numbers). This would greatly expand its controversial facial recognition repository, fueling concerns about privacy, consent, and misuse by governments or private actors.
Hungary’s Use of Facial Recognition at Pride Events
Hungary banned Pride events and authorized facial recognition to identify attendees, who may face fines under “child protection” laws. Critics view this as an attack on free assembly and expression, especially for LGBTQ+ communities, creating a chilling effect on peaceful protests.
China’s New Facial Recognition Rules
Facial recognition is banned without consent and in private spaces, requiring privacy assessments and encryption. However, these rules exclude “algorithm training,” meaning facial images may still be collected for AI development, undermining the intended privacy protections given China’s widespread CCTV presence.
US Coordination on Russian Cyber Threats Halted
US national security agencies ceased joint efforts against Russian cyberattacks, disinformation, and oligarch asset seizures. This abrupt stop raises concerns over weakened defenses against foreign interference, though official explanations remain unclear.
Microsoft’s Unpatched .LNK Exploit
An eight‑year‑old Windows shortcut (.LNK) exploit persists, with Microsoft labeling it a “UI issue” rather than a security flaw. Attackers, including state‑sponsored groups, hide malicious commands in whitespace, leaving users vulnerable to spying and data theft.
Windows 10 End of Support
With support ending in October 2025, Microsoft urges users—over half of its Windows base—to buy new hardware for Windows 11. This approach overlooks the financial burden on many and disregards feasible upgrades or affordable alternatives for existing devices.
Dutch Universities Shifting Away from WhatsApp
Schools such as Utrecht and Avans recommend moving to Signal over privacy and misinformation concerns tied to WhatsApp’s data‑sharing practices. Signal’s strong encryption, open‑source nature, and non‑profit status align with the need for secure, private communication in educational settings.
EP 235
The IT Privacy and Security Weekly Update and a Gene Genie for the Week Ending March 25th., 2025
3/25/2025
0 Comments
EP 235. - click the pic to hear the podcast -
DNA of 15 Million People For Sale. Turns out your great-great-grandparents' DNA is now a going-out-of-business clearance sale!"
Clearview Tried to Buy Social Security Numbers and Mugshots. Shopping list: milk, eggs, 690 million arrest records, and a side of your soul.
Hungary Uses Facial Recognition to Suppress a Pride March—because nothing says “freedom” like being fined for your face.
China says no facial recognition in hotel rooms—so go ahead and enjoy your surveillance-free shower while it lasts.
US Agencies Halt Counter-Russian Cyberattack Coordination to stop Russian cyber sabotage and, what could possibly go wrong?
Microsoft Isn't Fixing 8-Year-Old Shortcut Exploit. Maybe it's a new cybersecurity policy, "If we ignore it long enough, perhaps it'll go away!"
Then, If you have a Windows 10 machine and can’t install Windows 11, Microsoft suggests a fix. Buy a new computer and maybe get a second job.
And finally, Dutch universities to WhatsApp, "It's not you, it's us. We just can't get comfortable with your data hoarding."
Let's go try on some genes!
Find the full transcript to this podcast here.
Recent studies show that around 50% of online passwords are already compromised, and 41% of successful logins involve breached credentials. Common passwords like “123456” and password reuse make it easy for cybercriminals—especially with automated bots—to access multiple accounts. Changing passwords and using unique, strong credentials with multi-factor authentication is critical for security.
Starting March 28th, all Alexa requests will be processed in Amazon’s cloud, regardless of previous settings. Amazon claims this supports new AI features, but it means even users who opted out of saving voice recordings will now have all interactions recorded and sent to Amazon. This also impacts features like Voice ID, which won’t function without stored voice data. While Amazon encrypts transmissions and provides some privacy controls, this shift raises concerns about increased data collection and potential personalization for shopping.
Microsoft will stop providing free security updates for Windows 10 in October 2025, leaving charities that refurbish and donate older PCs with limited options. Many of these computers cannot run Windows 11, forcing organizations to choose between using an insecure OS, transitioning to Linux, or discarding hardware—contributing to electronic waste. While Linux is a secure, free alternative, its unfamiliar interface may pose usability challenges for some recipients, especially seniors.
StilachiRAT is a newly discovered remote access trojan (RAT) targeting cryptocurrency wallets like MetaMask and Coinbase Wallet. This malware remains undetected on infected systems, stealing sensitive data, including credentials stored in browsers like Chrome. By accessing login credentials, attackers can drain funds from wallets. StilachiRAT also collects system data, increasing victims' exposure. While not widespread yet, its advanced capabilities make it a serious threat to crypto users.
A Chinese state-sponsored hacking group remained undetected in a small Massachusetts power utility for over 300 days, showing that even lesser-known infrastructure is a target for cyber espionage. Attackers can use these breaches to test methods, gain footholds in critical networks, and extract operational data such as grid layouts. This underscores the need for robust security measures, continuous monitoring, and multi-factor authentication for all organizations, especially in critical sectors.
Anthropic CEO Dario Amodei warns that state-sponsored actors, likely from China, are trying to steal “algorithmic secrets” from US AI firms. Some critical algorithms, despite representing massive investments (potentially $100 million), are just a few lines of code, making them easy to exfiltrate if security is breached. Amodei argues that the US government should take stronger action to protect these assets from industrial espionage.
Allstate Insurance's National General unit had websites that displayed personally identifiable information (PII) in plaintext during the quote process. When users entered their name and address, the system exposed full driver’s license numbers (DLNs) of the applicant and other residents at that address. Attackers used bots to harvest at least 12,000 DLNs, leading to fraudulent claims. This highlights the importance of secure website design and responsible data handling to prevent unauthorized access.
EP 234
For the other 50%. The IT Privacy and Security Weekly Update for the Week Ending March 18th., 2025
3/18/2025
0 Comments
EP 234
- click the pic to hear the podcast -For our first story, Apparently there’s a 50% chance your password is headlining a hacker convention. Perhaps it's time to change up from ‘123456' (still the most commonly used password).
Starting On March 28, Everything You Say To Your Echo Will Be Sent To Amazon. Alexa’s new motto: ‘Anything you say can and will be used—to personalize your shopping cart, and we mean potentially anything!’
The end of Windows 10 Leaves PC Charities With Tough Choice: Risk Windows 10, embrace Linux, or send Grandma’s old PC straight to the tech graveyard?
Then Microsoft flags a new threat draining crypto from top wallets. Meet StilachiRAT, the malware so enthusiastic about your crypto it’ll snatch it faster than you can configure your wallet software!
Chinese Hackers Sat Undetected in a small Massachusetts power utility for months. Who knew a cozy little power company could double as the perfect 300-day Airbnb for homeless cyber-spies?
Anthropic CEO Says Spies Are After $100 Million AI Secrets in a 'Few Lines of Code'. So when your fortune fits in a handful of lines, hitting Ctrl+C could be the new diamond heist.
Finally, Allstate Insurance gets sued for delivering PII in plaintext. You’re in good hands with Allstate, we just can't tell you whose.
Let's update the other 50%!
Find the full transcript to this podcast here.
EP 233.5
Key Cryptocurrency Threats & Scams
In 2025, crypto remains a hotspot for scams like Ponzi schemes, fake ICOs, pump-and-dumps, phishing attacks, and malicious wallets or exchanges designed to steal funds. Social media is often used for deceptive giveaways, impersonations, and investment scams. Other risks include fake mining operations, rug pulls, fraudulent apps, SIM swapping, and impostor tech support.
EP 233
This week... is seized Crypto Linked to LastPass? Feds pocket $23M in hot crypto—but with hackers still sitting on hundreds of millions, it’s like finding loose change in the couch.
Signal’s boss says our ‘magic AI butler’ needs root access to everything. What could possibly go wrong?
AI is Reshaping Tech Jobs and with nearly one in four tech gigs demanding AI skills, either learn to talk to robots or prepare to serve them coffee."
Your Bluetooth toaster might secretly be dialing up hackers—because who doesn’t love a little espionage with their morning bagel?
With the UK quietly removing encryption advice, Brits wake up to find official security tips gone, like a polite note saying ‘We’d prefer you in clear text, chaps.’
Indian tax officials are granted sweeping digital access and can now dig through socials, emails, and maybe grandma’s recipe folder. Nothing’s sacred if there’s tax to be had.
Elon’s empire takes another DDoS beating—Dark Storm claims credit, X users just want their snarky tweets back."
We finish with the discovery of a Fake Website Spewing AI Slop that topped Google Search. AI conjures space fantasies that outrank real news and it turns out that even Google can’t spot the Millennium Falcon imposter.
Let's keep it safe.
Find the full transcript to this podcast here.
How did Microsoft's Copilot expose private GitHub repositories, and what are the risks?
Copilot accessed over 20,000 private GitHub repositories due to cached data from when they were public. Even after repos were made private, Copilot could still generate responses using this cached data, risking exposure of sensitive information like credentials and corporate secrets.
What is the "nRootTag" exploit in Apple's Find My network?
The "nRootTag" exploit allows attackers to track Bluetooth devices like AirTags without owners knowing. While AirTags use cryptographic keys to change Bluetooth addresses, attackers can rapidly compute these keys using GPUs, achieving a 90% tracking success rate.
Why is the UK demanding an iCloud backdoor, and how has Apple responded?
The UK wants access to encrypted iCloud data for law enforcement, but Apple opposes it, withdrawing its Advanced Data Protection from the UK. The US has also criticized the demand as a privacy and legal overreach.
Why is Signal withdrawing from Sweden?
Signal is leaving Sweden over proposed laws requiring backdoor access to encrypted chats. The company refuses to weaken encryption, emphasizing its commitment to user privacy.
Why has the US reportedly halted offensive cyber operations against Russia?
The US Cyber Command, under Defense Secretary orders, has paused cyber attacks on Russia, possibly for diplomatic reasons. Supporters see it as de-escalation; critics worry it weakens deterrence against Russian cyber threats.
Why has Australia banned Kaspersky Lab products?
Australia banned Kaspersky from government systems, citing espionage and foreign interference risks. The move signals concerns over antivirus software’s deep system access and the company's Russian ties.
How was a Cellebrite exploit used to hack a Serbian student's phone?
A Cellebrite zero-day targeting Android's Linux kernel USB drivers allowed attackers with physical access to bypass the lock screen. This raises concerns over surveillance tools being misused against activists.
What changes did Mozilla make to Firefox Terms of Use, and why was there backlash?
Mozilla initially claimed broad rights over user-submitted content, sparking fears of data monetization. After criticism, they revised the terms, clarifying user ownership and denying AI data harvesting.
This week: Microsoft’s Copilot is living up to its name—because apparently, once it gets a glimpse of your code, it just can't unsee it.
Hackers just turned every Bluetooth device into an involuntary AirTag—so congrats, your wireless headphones are now a tracking device.
The UK wants a backdoor to look into iCloud, and the US just responded with a very diplomatic “absolutely not.”
Sweden wanted a backdoor, but Signal ghosted them instead—because encryption doesn’t do toxic relationships.
The US was cyber-attacking Russia? Shocking! Next you'll tell us we need stronger glasses.
Australia finally decided that letting Russian software protect their government computers was like asking an elephant to deliver eggs.
Cellebrite’s phone exploits are so good, even governments can’t resist misusing them.
Mozilla accidentally claimed ownership of everything you type into Firefox, then backtracked faster than a politician caught on a hot mic.
We can see for miles and miles. Come on, let's focus in for a better look.
Find the full transcript to this week's podcast here.
Which AI chatbots pose the biggest privacy risks, and what data are they collecting and sharing?
A recent study revealed that all top ten AI chatbots on the Apple App Store collect user data, with 30% sharing it with third parties for advertising or measurement. Specific incidents include an AI chatbot named WotNot exposing 346,000 sensitive customer files and ChatGPT facing temporary bans over the use of personal data for model training without user consent. The advice is to treat chatbots like untrustworthy coworkers and avoid sharing sensitive personal information.
Why did Apple remove its Advanced Data Protection (ADP) feature in the UK?
Apple removed its Advanced Data Protection (ADP) feature, which provided end-to-end encryption for iCloud data, in the UK after the government ordered the company to build a backdoor for accessing user data. Apple chose to remove the feature entirely rather than compromise the security of its encryption. This action raises concerns about governments potentially outlawing strong encryption, which could reduce security for everyone and expose users to greater risks from surveillance and other bad actors.
What are VPN providers in France and Spain facing, and why are they considering leaving the French market?
In France, entertainment companies are pushing for legal action to force VPN providers to block access to pirate sites. In Spain, Cloudflare has been blocked on weekends after being accused of hosting pirate streaming sites. VPN providers argue that these demands are risky and could lead to security vulnerabilities and excessive blocking, compromising their core mission of providing legitimate privacy and security services.
What is California doing to enforce data privacy, and what measures should individuals take to protect their data?
California is taking a "radical" approach by actively enforcing its privacy laws through the California Privacy Protection Agency. This agency is tasked with investigating violations, issuing fines, and educating businesses about compliance. To protect your data, scrutinize app permissions, check browser extensions for suspicious activity, monitor location requests, be mindful of voice assistant settings, and disable unnecessary tracking features on wearables.
What issues are users experiencing with the latest Windows 11 update (KB5030310)?
The latest Windows 11 update, KB5030310, is causing various issues, including File Explorer freezing or crashing, vanishing icons, locked windows, and problems with multi-monitor setups. Some users have also reported silent or disappearing notifications.
What is the "Uber for armed guards" service, and why is it gaining traction?
Protector, an app providing on-demand armed security similar to Uber, is gaining traction in NYC and LA. Users can book armed guards, described as active or retired law enforcement and military, complete with a motorcade of Escalades.
What security vulnerability was discovered in MESH by Viscount access control systems, and what are the implications?
A significant vulnerability was discovered in MESH by Viscount access control systems due to unchanged default login credentials. This allows unauthorized individuals to access the systems remotely, view sensitive resident data (names, unit numbers, phone numbers), and manipulate building access controls, including unlocking doors and disabling access fobs.
What is "surveillance pricing," and what are states doing to combat it?
"Surveillance pricing" is a tactic where companies use personal data, such as browsing history and spending habits, to hike up prices for consumers. States are stepping up to ban or limit these practices to promote fairer prices and stronger privacy protections. Individuals can protect themselves by monitoring for unexplained price jumps, regularly clearing browsing data, disabling unnecessary tracking, and questioning excessive permission requests.
EP 231 This week we wonder which chatbot takes "sharing is caring" a little too far. Turns out some of them are spilling secrets faster than the office gossip at happy hour.
Apple just told the UK, ‘You want a backdoor? Fine—we’ll just remove the whole door.
France wants VPNs to stop streaming soccer pirates—because obviously the best way to protect privacy is to ban it entirely.
California’s cutting-edge privacy strategy? Actually enforcing the law. Who knew that was an option?
Microsoft’s latest Windows 11 update: because sometimes you need a brand-new bug to make you forget the old ones.
Uber with Armed Guards: Now you can hail a bodyguard the same way you hail a taxi—apparently commuting got a whole lot scarier.
If your building’s master key is this public don’t be shocked when you arrive home after work and the inlaws are waiting for dinner.
Tired of costly coconuts because your phone snitched on your spending habits? Some states are finally calling out this ‘personalized’ markup as nuts.
Race you to the fresh produce section!
Find the full transcript to this podcast here.
DOGE's official website, doge.gov, suffered a significant security breach due to a glaring vulnerability. The site's database was accessible and editable by the public because it was built on Cloudflare Pages instead of secure government servers. This allowed unauthorized individuals to modify content, highlighting a lack of stringent cybersecurity measures in government websites managed by DOGE. It demonstrates a lapse in basic security practices and raises concerns about the overall security and professionalism of government websites.
A substantial percentage (8.5%) of employee interactions with generative AI tools involve sensitive data, such as customer information (billing details, insurance claims, etc.). This raises significant security, compliance, privacy, and legal concerns for organizations. Sharing sensitive data with AI tools can lead to data breaches and leaks. Some companies, like Samsung, have prohibited the use of generative AI systems to prevent the inadvertent upload of confidential company information to external servers. The increasing integration of AI into workplace tools necessitates a reevaluation of data security protocols.
DeepSeek was removed from South Korean app stores due to privacy concerns identified by the Personal Information Protection Commission (PIPC). The PIPC found that DeepSeek lacked transparency about sharing user data with third parties and potentially collected excessive personal information. The app's data practices might violate local privacy laws. Similar actions have been taken in other countries and regions, indicating a global concern over DeepSeek's data handling.
Salt Typhoon is a Chinese hacking group that continues to infiltrate global telecommunications networks despite U.S. sanctions. They exploit vulnerabilities in Cisco routers and switches to gain unauthorized access to sensitive data. They have breached telecom companies, internet service providers, and universities across multiple countries, including the U.S. Their targets are often entities involved in advanced research in telecommunications, engineering, and technology.
Individuals can protect themselves by regularly updating the security patches on their personal devices, especially routers and switches. It is also recommended to use end-to-end encrypted messaging apps like Signal or Session for secure communication.
The German Federal Cartel Office is investigating whether Apple's ATT feature constitutes an abuse of power. The concern is that Apple's privacy policies may inadvertently give it a competitive advantage over other companies reliant on advertising tracking.
PIN AI is a company that has launched a mobile app allowing users to create their own personalized, private AI model directly on their smartphone. The AI models created are powered by DeepSeek or Llama.
AI is having a significant impact on the IT job market, with IT unemployment rising to 5.7% in January, surpassing the overall jobless rate. Major companies are implementing layoffs linked to cost-cutting measures and a growing reliance on AI technologies. To adapt, IT professionals need to retrain and stay at the cutting edge of technology.
In this week's update: Musk's DOGE website gets more editing than his tweets.
Employees sharing secrets with AI chatbots prove humans haven't learned anything from social media oversharing.
South Korea puts DeepSeek in the digital doghouse until it learns to play nice with privacy rules.
Chinese hackers show that even after sanctions, you can't stop a Salt Typhoon with an umbrella.
Apple's privacy features are too private for Germany's taste - plot twist nobody saw coming.
Finally, an AI that promises to keep your secrets... on your phone, where you'll probably still accidentally share them anyway.
AI takes tech jobs, and proves it learned "layoffs" from watching human managers.
Let's go unearth those secrets!
Find the full transcript to this podcast here.
Frequently Asked Questions: Privacy, Security, and the State of Tech (Early 2025)
1. What is "SparkCat" and why is it significant?
SparkCat is malware discovered hiding in both the Apple App Store and Google Play. It uses optical character recognition (OCR) to scan users' photo galleries for cryptocurrency wallet recovery phrases and uploads them to attacker-controlled servers. Over 242,000 Android users downloaded infected apps. It highlights the evolving sophistication of malware and the need for increased vigilance, even with apps from reputable sources.
2. What is the UK government asking Apple to do, and what are the potential implications?
The UK government has reportedly ordered Apple to create a backdoor allowing access to encrypted cloud backups of users worldwide, through a technical capability notice under the Investigatory Powers Act. Apple is likely to discontinue its encrypted storage service in the UK rather than compromise user security globally. If Apple complies, it could set a dangerous precedent for other governments to demand similar access, undermining encryption and weakening security for everyone.
3. What is the story about the man trying to buy a landfill, and what does it illustrate?
A man is trying to buy a landfill to search for a hard drive containing his lost Bitcoin fortune. While seemingly absurd, it illustrates the very real consequences of poor digital asset management and data security. It highlights the permanence (and potential inaccessibility) of digital assets and the lengths people will go to recover them, even resorting to extreme measures.
4. Why is the US considering banning the DeepSeek AI app?
The US is considering banning the Chinese AI app DeepSeek due to concerns that it collects data for a foreign government (China). The app pumps data to China Mobile unencrypted, and there are close ties between the company and the Chinese military. This aligns with the US government's broader concerns about foreign-owned apps, especially those from China, posing national security risks due to data privacy and potential surveillance.
5. What is the massive brute-force attack targeting VPNs, and how can organizations protect themselves?
A large-scale brute-force attack is targeting VPN devices from companies like Palo Alto Networks, Ivanti, and SonicWall, utilizing nearly 2.8 million IP addresses. Attackers are attempting to guess usernames and passwords to gain unauthorized access. To protect edge devices, organizations should change default admin passwords to strong, unique ones, enforce multi-factor authentication (MFA), use allowlists of trusted IPs, and disable web admin interfaces if they are not needed, and also ensure VPN software is fully up to date.
6. Why is Google's removal of its pledge not to build AI for weapons or surveillance significant?
Google's removal of its pledge not to build AI for weapons or surveillance is a concerning development. It suggests a shift in the company's ethical stance and a willingness to potentially engage in activities that could have negative consequences for human rights and global security. It raises questions about the future direction of AI development and the role of tech companies in shaping its use.
7. What is "enshittification" and how does it relate to current tech trends?
"Enshittification" refers to the gradual decline of online services as they prioritize profits over user experience. This process involves platforms initially offering value to users, then shifting focus to business customers, and finally exploiting both for maximum profit. Examples include Twitter restricting API access, Facebook prioritizing sponsored content, smart TVs becoming data-hungry ad machines, and Google Assistant's diminishing functionality. It reflects a broader trend of tech companies sacrificing user experience for financial gain.
Episode 229
If your seed phrase was in your photo gallery, congratulations! You might have just funded North Korea's next Missile launch.
The UK government just asked Apple to make privacy optional—because nothing says "secure" like a government-mandated security hole.
A man wants to buy an entire rubbish tip to find his lost Bitcoin hard drive—because sometimes, your financial future is literally garbage.
The US is considering banning a Chinese AI app, proving once again that if it’s cheap, efficient, foreign, unencrypted, and collects data for a foreign government it’s probably too good to be true.
Massive VPN Attack – 2.8 million IPs are trying to brute-force their way into VPNs—because apparently, resetting the default admin credentials to a "strong password" is still too much to ask.
Google quietly removed its promise not to build AI for surveillance or weapons, so expect "Don’t Be Evil" to disappear completely in a rev. or two.
If your smart TV, social media, and AI assistants feel like they hate you, it’s not paranoia—it’s capitalism, or that other word we can't repeat here.
Earth’s Inner Core Is Changing – Scientists say the Earth's core might be slowing down, which is great, because the last thing we needed was more things spinning out of control.
Let's go digging!
Find the full transcript to this podcast here.
What is the primary concern regarding the use of WhatsApp and other encrypted messaging apps recently?
Recent reports indicate that spyware, specifically "Graphite," has been used to target journalists and civil society members through zero-click attacks on encrypted apps like WhatsApp, Telegram, and Signal. This means that these apps are not as secure as previously thought, even though they employ end-to-end encryption. The spyware can infect devices without any user interaction and potentially compromise communication data.
What are the security vulnerabilities identified in certain healthcare patient monitors?
The FDA has highlighted cybersecurity issues in Contec's CMS8000 and Epsimed's MN-120 patient monitors. These devices, when connected to the internet, are susceptible to unauthorized remote control, software backdoors, and data breaches containing personal health information. One backdoor was linked to a Chinese IP address, raising additional concerns about foreign access to sensitive health data.
Why has the Chinese AI chatbot, DeepSeek, been banned in Italy and Taiwan?
Italy's data protection agency blocked DeepSeek because its developers did not adequately explain how user data is collected or confirm whether it's stored on Chinese servers. Taiwan's digital ministry also banned the use of DeepSeek by government departments, citing security concerns related to its Chinese origin.
What led to DeepSeek's data being exposed online and what kind of information was affected?
Cybersecurity firm Wiz discovered a significant amount of sensitive data from DeepSeek was left unsecured on the open internet due to an apparent misconfiguration. This data included over a million lines of data such as digital software keys and user chat logs.
What is Senator Hawley's proposed bill regarding Chinese AI models, and what could be the consequences for individuals?
Senator Josh Hawley has introduced the "Decoupling America's Artificial Intelligence Capabilities from China Act," which aims to criminalize the import, export, and collaboration on AI technology with China. Under the proposed law, knowingly downloading a Chinese AI model, such as DeepSeek, could lead to severe penalties, including up to 20 years in prison, a million-dollar fine, or both. The bill reflects growing concerns about national security and the potential for China to leverage AI for hostile purposes.
How is Amazon being accused of tracking consumers, and what type of data are they allegedly collecting?
Amazon is facing a class-action lawsuit accusing the company of secretly tracking consumers' movements through their cellphones via its Amazon Ads SDK, embedded within third-party apps. It's alleged that the SDK collects sensitive geolocation data without users' explicit consent, such as IP addresses, location, ISP, device info, and network performance metrics. This data is used to build a detailed picture of consumers' habits and preferences, raising privacy concerns about corporate surveillance.
What restrictions are being placed on open-source contributions, and who is being affected?
The US Office of Foreign Assets Control (OFAC) sanctions are imposing restrictions on open-source contributions from sanctioned individuals and countries. Developers from nations such as Russia, Iran, and North Korea are facing challenges when contributing to open-source projects due to these sanctions.
How is Cloudflare addressing image authenticity concerns, and what are the potential benefits?
Cloudflare has implemented Content Credentials, a system based on C2PA standards, that embeds metadata into images to track their origin and modifications. This system helps distinguish between genuine and manipulated content. The benefits are significant, as Cloudflare's network handles approximately 20% of global internet traffic, greatly increasing the potential reach of the system. This helps create trust in digital images, and preserves the work of digital creators.
First, for some, it looks like WhatsApp chats weren’t just end-to-end encrypted—they also came with a side of espionage.
Then... your heart monitor might be more interested in Beijing than in your beats per minute.
deepseek AI Blocked in Italy & Taiwan, Welcomed in India – "Two countries said ‘no way,’ one said ‘namaste’—deepseek’s global tour has some mixed reviews."
And what happens when your AI chatbot leaks more secrets than a reality TV star’s DMs.
Senator Hawley’s AI Ban Proposal – take us from deepseek to Despair.
Then it turns out Amazon may know more about your whereabouts than your mom does when you ignore her calls."
Devs., the US is blocking open-source contributions from sanctioned individuals and countries. That's a lot to keep track of when you are donating your time.
Cloudflare enables content credentials – "Finally, a way to prove your photo was taken by you, and not a random AI with too much free time."
If life sometimes seems like a casino, where there ae too many ways to lose a lot of money fast, we have a spirited response. Let's go get the detail.
Find the full transcript here.
What is "surveillance pricing" and how does it affect me? Surveillance pricing is a practice where online retailers adjust prices based on your personal data, such as location, browsing history, and demographics. Companies collect data like mouse movements and items left in your shopping cart to determine what you're likely willing to pay. This can lead to different individuals being offered varying prices for the same product. To mitigate this, consider using VPNs, browser extensions that block tracking, regularly clearing browser cookies, and being cautious about the personal information you share online.
What car vulnerabilities were recently discovered, and how can I protect myself? Security researchers recently found vulnerabilities in Subaru's web portal, allowing remote control of vehicles, including unlocking doors, starting the engine, and tracking location. Millions of Subaru vehicles with Starlink digital features were potentially affected. While Subaru has patched the identified flaws, it's crucial for all car owners to ensure their software is up-to-date. This is part of a larger trend of security issues in the automotive industry, so vigilance is essential.
How is Meta using my data with its new AI, and can I opt out? Meta's new AI chatbot will use personal data from your Facebook and Instagram accounts to personalize its responses. This includes information from previous conversations, dietary preferences, and interests. Unfortunately, there is no option to opt out of this data-sharing feature.
What was the recent ruling about the FBI's access to Americans' private communications? A federal court ruled that backdoor searches of Americans' private communications collected under Section 702 of FISA are unconstitutional without a warrant. This ruling found that even if the government can lawfully collect communications between foreigners and Americans, it can't search those communications without a warrant when those searches involve US persons. This stems from a case where the FBI searched emails of a US resident, collected under the premise of foreign intelligence, without a warrant. The court found this to be a Fourth Amendment violation.
What are the dangers of North Korean IT workers, and how can we protect our companies? The FBI has warned that North Korean IT workers are abusing their access to steal source code and extort U.S. companies. They often copy company code repositories, harvest credentials, and initiate work sessions from non-company devices. To mitigate these risks, companies should apply the principle of least privilege, limit permissions for remote desktop applications, and monitor for unusual network traffic. Additionally, it is important to recognize that these workers may log in from different IPs over a short period.
What is the new threat to the European power grid, and what makes it so concerning? Researchers have discovered that renewable energy facilities across Central Europe use unencrypted radio signals to control how much power is sent into the grid. By reverse-engineering the signals, they found they could potentially manipulate the system to cause widespread disruptions, including a grid-wide outage. The lack of encryption on these systems and the ability to control large amounts of energy poses a significant risk, especially considering current geopolitical tensions.
What is the significance of DeepSeek's R1 model and how does it compare to models like OpenAI's? DeepSeek's R1 model is an open-source large language model (LLM) that offers open weights, allowing users to run it on their own servers or locally. It challenges OpenAI's proprietary model by providing a more cost-effective and accessible AI solution. DeepSeek uses a technique called distillation, where existing LLMs train new, smaller models. The emergence of R1 suggests a shift towards more commoditized AI and potentially increased accessibility and customization.
What are some common types of cyber attacks and how can I defend against them? The sources list 21 common cyber attacks including: malware, phishing, ransomware, drive-by downloads, cross-site scripting (XSS), SQL injection, man-in-the-middle (MitM) attacks, DDoS attacks, password attacks, insider threats, credential stuffing, zero-day exploits, social engineering, session hijacking, eavesdropping, watering hole attacks, DNS spoofing, IoT attacks, supply chain attacks, brute force attacks, and spyware. Preventative measures involve using antivirus software, updating systems, avoiding untrusted downloads, verifying emails, using spam filters, performing regular backups, having strong firewalls, enabling MFA, monitoring activities, restricting access to risky sites, securing cookies, and training employees to recognize suspicious activity.
The best way to stay protected is to stay informed. Keep listening
EP 227
In this week's update we present 21 Cyber attacks and a self defense program to stop and drop every single one of them.
Shopping online? Your browsing habits might be telling stores you're willing to pay double.
Congratulations to Subaru owners as the latest stars in ‘Hack My Ride.’
Meta’s new AI buddy knows your secrets—and nope, there’s no "off" button for this overshare.
The FBI just discovered that the Constitution wasn’t keen on them peeking at your emails without a warrant.
Your ‘remote coworker’ from Pyongyang isn’t just burning the midnight oil—he’s burning a hole in your source code.
And for the EU, renewable energy is great until someone tunes in and turns it all off.
Move over ChatGPT; DeepSeek’s open-source AI is here to make ‘big and secretive’ look so last year.
This week's update is the best yet, so let's start counting!
Find the full transcript here.
Data Privacy, Security, and Tech Trends in Early 2025
In 2024, the U.S. healthcare sector experienced a massive surge in cyberattacks, with approximately 720 reported breaches compromising an estimated 186 million user records. This exposed a vast amount of sensitive information, including names, contact details, Social Security numbers, and medical histories. This is approximately 56% of the US population.
UnitedHealth, specifically its subsidiary Change Healthcare, attempted to obscure its data breach notification webpage from search engines, making it difficult for the over 100 million affected individuals to learn about the incident. They used a “noindex” tag to keep it out of Google, burying the story of their breach. This led to widespread confusion and further distrust of the company. It also highlights how companies can use search engine optimization to hide breaches by burying the real stories.
GeoSpy is an AI tool that can accurately predict the location of photos based on features within the images, such as vegetation, architecture, and spatial relationships. Originally available to the public, it’s now marketed to law enforcement and government agencies. This technology raises serious privacy concerns, as it can be used by stalkers or other malicious actors to geolocate individuals from publicly available photos. The tool is now available to law enforcement and enterprise users, and some versions of it are more powerful than what was offered to the public.
The Federal Trade Commission (FTC) banned GM and its subsidiary OnStar from selling customer geolocation and driving behavior data for five years. This action followed an investigation that revealed GM had been collecting and selling detailed driving information to insurance companies without obtaining explicit consent from vehicle owners.
The UK is launching a digital wallet app called GOV.UK Wallet, allowing citizens to store government-issued documents on their smartphones. Initially supporting veteran cards, it will expand to include driver's licenses in late 2025, with plans to add passports, marriage certificates, and benefit documents by 2027.
Former employees of failed startups using "Sign in with Google" features are vulnerable to data breaches. Hackers can exploit abandoned company domains and the associated Google login systems to access sensitive information stored in business software like Slack, Notion, and HR systems, including social security numbers. This vulnerability is particularly relevant to startups that used the ""Sign in with Google"" function.
Amazon's mandate for a full return to the office resulted in significant challenges for employees, including a shortage of desks and meeting rooms, overcrowded parking facilities, and an increase in workplace thefts. The policy has also been criticized for forcing employees into video calls that could have been easily conducted remotely, and some employees reported that there is a lack of trust amongst colleagues.
Donald and Melania Trump introduced meme coins named $TRUMP and $MELANIA on the Solana blockchain. These coins quickly gained significant value, raising concerns about potential conflicts of interest and market manipulation.
EP 226
In 2024, hackers gave U.S. healthcare a crash course in oversharing—186 million records spilled, proving patient privacy is still on life support.
UnitedHealth tried to bury its breach notice deeper than your inbox's spam folder, leaving 100 million victims googling in vain.
A new AI tool can guess your photo's location faster than your nosiest neighbor—use portrait mode, or prepare to be geo-tagged!
GM got caught selling your driving secrets—now they’re banned for five years, but your insurance premium probably isn’t impressed.
The UK’s digital wallet promises to declutter drawers, but we’re still skeptical it’ll clear up the chaos in government paperwork.
Failed startups are gifting hackers access to your personal data—proof that your old Google login can haunt you more than your ex.
Amazon’s return-to-office plan lacks desks, parking, and common sense—so much for those “collaboration” benefits.
Forget NFTs—Trump’s $TRUMP and $MELANIA coins promise to make your wallet great again.
Why wait a second longer? Let's find out what all the fuss is about.
Find the full transcript to this podcast here.
Tech & Privacy FAQ - Week of January 14th, 2025
Some tech workers are making up to $30,000 by referring strangers for job openings. They connect with job seekers through platforms like Blind and Glassdoor, and sometimes use services like Refer Me and Refermarket to facilitate these referrals, even charging a fee. While referrals can improve hiring odds, this trend raises questions about authenticity and potential abuse.
Texas AG Ken Paxton is taking a strong stance on data privacy. He's issued warnings to companies like Sirius XM and apps like MyRadar for allegedly sharing user data without consent. He's also suing Allstate for secretly collecting driver data via cellphone apps and car manufacturers to raise premiums. Texas seeks restitution for consumers, damages, and hefty fines.
Yes! The EU General Court fined the European Commission €400 for transferring a citizen's IP address to Meta in the US without proper safeguards. While a small fine, it sets a precedent and shows the EU's commitment to enforcing GDPR, even on its own institutions.
Experts warn that quantum computers, still in their early stages, could eventually crack current encryption methods. While not an immediate threat, it's wise to start researching "quantum-resistant" solutions to safeguard your data in the future.
A ransomware group called Codefinger is exploiting stolen AWS keys to encrypt data in S3 buckets using AWS's own encryption. They then demand a ransom and set a timer to delete the data within a week. This highlights the need for strong IAM policies and regular key audits on AWS.
Cybercriminals are shifting from email-based malware to browser-based attacks like drive-by downloads and malicious ads. Compromised credentials are a growing problem, often obtained cheaply from fraud marketplaces. Staying updated with software, using ad blockers, and being cautious online are crucial.
The T3 FCU, a collaboration between TRON, Tether, and TRM Labs, is actively combating crypto-related crime. They recently froze over $100 million in illicit assets across five continents. This highlights the importance of public-private partnerships in blockchain security.
The US, South Korea, and Japan have jointly confirmed that North Korea's Lazarus Group orchestrated the $235 million WazirX hack. This incident reinforces the need for strong security measures within the cryptocurrency ecosystem and emphasizes the threat posed by state-sponsored hacking groups.
EP 225
This week referring strangers for jobs is the new tech hustle... Proof that even networking has gone freelance.
The Texas AG claims apps and insurers are snooping so hard they probably know your snack habits while he goes for big lunch money.
The EU just fined itself €400 for breaking GDPR, demonstrating that even bureaucracies aren’t above self-sabotage.
Your data’s safe today, but quantum computers might soon laugh at your encryption like it’s a flip phone.
Hackers use AWS to lock your AWS data; like robbers stealing your house keys and using them to lock you out.
Step aside Phishing, browser hacks are the new cybercrime hotness; update your apps before they update your bank balance.
T3 FCU froze $100 million in criminal crypto, reminding bad actors that crime doesn’t pay—but it does chill.
North Korea’s Lazarus Group stole $235M in crypto, reminding us that even your custodial wallet isn’t safe from global espionage.
Let's Hustle. Let's hustle hard.
Find the transcript to this podcast here.
Tech & Security Weekly FAQ: January 7th, 2025
Apple is settling a lawsuit alleging Siri "unintentionally" recorded private conversations without user consent. The lawsuit claimed these recordings were shared with third parties and used for targeted advertising. While denying wrongdoing, Apple will compensate affected users up to $20 per Siri-enabled device purchased between September 2014 and December 2024 and delete recordings obtained before October 2019.
MyGiftCardSupply, an online gift card store, exposed hundreds of thousands of customers' identity documents due to a publicly accessible storage server with no password protection. This server contained sensitive information like driver licenses, passports, and selfies taken for KYC compliance, putting customers at risk of identity theft.
Hackers are increasingly targeting Chrome extensions, including popular VPNs and AI tools, by injecting malicious code through updates. This can compromise user data and accounts. Users are advised to carefully review extension permissions, only install extensions from trusted sources, and be cautious of unexpected updates.
Despite Microsoft's promotion of Windows 11, Windows 10 remains the dominant desktop OS, holding a 62.7% market share. This is partly due to user reluctance to upgrade and a significant increase in Windows 10 installations in the US. However, support for many Windows 10 versions ends in October 2025, pushing users towards either extended security updates or potential vulnerabilities.
The Illumina iSeq 100 DNA sequencer and other medical devices use outdated firmware, leaving them vulnerable to malware attacks. Without security features like Secure Boot, malicious code can hide in the firmware, compromising device integrity and potentially patient safety. This highlights the need for manufacturers to prioritize firmware updates and security protocols in medical equipment.
Chinese hackers, allegedly linked to the military and intelligence, have shifted from corporate espionage to targeting critical US infrastructure, including water utilities, airports, and energy grids. This suggests preparation for potential geopolitical conflicts, particularly concerning Taiwan, aiming to disrupt US response capabilities. The sophistication and potential impact of these attacks raise serious concerns about escalating cyber-warfare between the two countries.
New York City is retiring its iconic R46 subway cars, known for their unique seating arrangement and nostalgic charm. These trains are being replaced by the modern R211 cars, featuring brighter lighting, enhanced accessibility, and longitudinal seating to optimize passenger flow. While some lament the loss of a cultural symbol, the upgrade promises a more efficient and modern transit experience.
Meta, the parent company of Facebook and Instagram, is ending its fact-checking program and loosening content moderation policies. Zuckerberg claims this aims to promote free speech, but critics argue it will lead to a surge in misinformation and harmful content. This shift raises concerns about the platforms' role in shaping online discourse and their potential impact on political and social issues.
Episode 224
Loose Lips Sink Ships. The IT Privacy and Security Weekly Update for the Week Ending January 7th 2025.
1/7/2025
0 Comments
Episode 224- click the pic to hear the podcast - In this week's update: Siri couldn't keep her ear shut, and then her loose lips cost Apple $95M as they learned the lesson: "Privacy isn’t optional."
Nothing says 'secure' like a password-free server holding 600,000 IDs, turning this gift card gaffe into MyGiftCardSupply's latest disaster.
Hackers taught Chrome extensions a new trick, making Chrome chaos all about stealing your data, now enhanced with AI flair.
Windows 10 users are hanging on tighter than your grandma's grip on her landline, epitomizing Windows woes as the OS refuses to fade.
When your DNA sequencer runs firmware older than your Spotify playlist, this medical equipment drama becomes more science fiction than science.
Chinese hackers aren’t just stealing blueprints—they’re blueprinting the future of cyberwarfare, potentially marking cyber as the next battleground.
Be kind to New Yorkers this week, they lose their 50 year old R46 subway cars, where love-seats met New York grit, and gain a congestion charge that is hitting them like a new variant of Covid.
Zuck says goodbye to fact-checking, ensuring Meta leaves the internet or at least their portion of it, bracing for chaos (again).
Siri can't hear us if we keep moving. Let's go!
Find the full transcript for this podcast here.
IT Privacy and Security Weekly Update FAQ - December 31st, 2024
Apple has stated that developing a search engine is "outside of its core expertise" and would require substantial investment and resources. The company also cites the rapidly evolving field of AI as a deterrent, making such a venture "economically risky." Apple currently receives a significant revenue stream from Google for being the default search engine on Apple devices, making the development of their own search engine less appealing.
Raspberry Pi, the maker of affordable single-board computers, saw its valuation exceed $1 billion in December 2024, driven primarily by increased demand in the U.S. market. The company's success is attributed to the versatility and low cost of its computers, which are popular among hobbyists, educators, and professionals. This accessibility has broadened the reach of computing and fueled Raspberry Pi's impressive growth.
Chinese state-sponsored hackers exploited a vulnerability in a third-party cybersecurity service provider used by the U.S. Treasury Department. By compromising this provider, the hackers gained access to a security key that allowed them to remotely access employee workstations and steal unclassified documents. This incident highlights the increasing sophistication of cyberattacks and the risks associated with reliance on third-party services.
Accidental missile strikes on commercial aircraft have become the leading cause of aviation deaths in recent years, surpassing terrorism and other threats. This alarming trend is driven by rising global tensions and the increasing availability of advanced antiaircraft weaponry, making civilian flights in or near conflict zones particularly vulnerable. Despite overall advancements in aviation safety, these incidents highlight the unintended consequences of armed conflict on civilian air travel.
A growing number of older Americans are facing a substantial student loan burden, with collective debt reaching $121 billion. Many seniors took out loans later in life for their own education or to support their children's studies. This debt burden presents a significant financial strain, particularly for those on fixed incomes or facing limited job opportunities in retirement.
Volkswagen Group suffered a major data breach that exposed the sensitive information of 800,000 electric vehicle owners, including GPS location data, battery statuses, and user habits. The data was left unsecured on Amazon's cloud for several months, potentially allowing tech-savvy individuals to link vehicles to owners' personal information. This incident emphasizes the importance of robust data security measures as vehicles become increasingly connected and reliant on data sharing.
Mountain View Correctional Facility in Maine is offering inmates remote work opportunities with private companies. This program aims to equip inmates with valuable skills and experience, improving their chances of securing employment upon release. Inmates earn competitive wages while working remotely, contributing to restitution, room and board, and developing financial responsibility.
These events underscore the evolving landscape of digital security and privacy. From state-sponsored hacking to data leaks and the increasing vulnerability of air travel, individuals and organizations must remain vigilant and proactive in safeguarding their information and systems.
EP 223
For this update, a completely diverse collection of stories starting with Apple dodging the search engine game by insisting that search ads are not Apple's "core" expertise.
Then another serving of fruit and Raspberry Pi’s billion-dollar boom proving that tiny computers with huge valuations says you don’t need size to make a big impact.
Chinese hackers demonstrate that it makes "cents" to have the US Treasury's data on their holiday gift list.
And then for your next security conference, forget peanuts on your flight, now you have to worry about missiles landing on your snack tray.
Seniors swim in student loan debt while Grandma knits scarves—and tries to figure out how to pay off her 50 year old university degree.
VW's massive EV data leak reveals that your car is smarter than ever and so are the hackers.
Then, it's not only the North Koreans who can play at this game, Maine prisoners go remote, landing virtual gigs as legit IT staffers.
This is a wild update, so let's use it to break out of 2024 and into 2025!
Find the full transcript to this podcast here.
We go deep into this week's topics and break into the stories covered.
What's happening with bot detection these days?
Traditional CAPTCHAs are becoming ineffective as bots are now able to solve them easily. This has led to developers exploring alternative methods like behavior analysis and biometrics, but these come with their own privacy and accessibility concerns. The rise of AI agents further complicates things, requiring platforms to distinguish between helpful and harmful bots.
Are car companies being hypocritical about data privacy?
Yes, senators are calling out automakers for opposing "right-to-repair" laws while simultaneously selling customer data. They argue that automakers' cybersecurity concerns are a smokescreen for maintaining control over repair profits, as there's no evidence independent shops mishandle data more than dealerships. This raises questions about consumer rights concerning vehicle repairs and data privacy.
What's the problem with digital license plates?
A security researcher has demonstrated that digital license plates can be hacked to display false information, enabling users to evade tolls and tickets or even incriminate others. The vulnerability lies in the hardware and requires replacing the plate's chip to fix it, making it a costly solution. While digital plates offer convenient features, their security flaws present a significant risk.
How is a GPS tracking company ironically exposing customer data?
Hapn, a company specializing in GPS tracking, ironically exposed customer names, email addresses, and device serial numbers due to a misconfigured server. This incident highlights the importance of robust cybersecurity measures, especially for companies handling sensitive location data. It serves as a reminder to research a company's security practices before entrusting them with your data.
Is there a privacy-focused alternative to Alexa or Google Assistant?
Yes, Home Assistant has launched Voice PE, a voice-controlled device that operates entirely offline, ensuring user privacy. It supports multiple languages, offers customizable wake words, and can integrate with AI models like ChatGPT. While still in development, it offers a promising alternative for those seeking a local, privacy-centric smart home voice control system.
What is Apple doing about spyware attacks on its users?
Apple is directing victims of spyware attacks to a nonprofit security lab for assistance. This lab specializes in cybersecurity and provides resources to help victims understand and address spyware threats. This partnership highlights Apple's commitment to user security and privacy and emphasizes the importance of community efforts in tackling cybersecurity challenges.
Why is Australia changing its cryptography standards?
Australia is proactively phasing out certain cryptographic algorithms by 2030 to mitigate the threat of future quantum computing attacks. These algorithms, currently widely used, are expected to become vulnerable as quantum computing technology advances.
What are the latest concerns about SMS-based authentication?
Federal agencies are warning against using SMS for two-factor authentication due to its vulnerability to interception and phishing attacks. SMS messages are unencrypted, making them susceptible to compromise. Opt for more secure alternatives, like authenticator apps or passkeys, whenever available, to enhance their online security.
Are there security concerns with global telecommunications networks?
The Department of Homeland Security has revealed that countries like China, Russia, Iran, and Israel are exploiting weaknesses in the SS7 protocol, which connects global telecom systems, to spy on Americans. Users are encouraged to consider using encrypted communication apps and limiting location tracking to minimize their exposure to such surveillance.
Episode 222
For our first story Bot Detection Is No Longer Working. CAPTCHAs are now a reverse IQ test—humans fail while bots ace them effortlessly.
Then senators rip into the automakers: Car makers sell your data but won’t let you fix your car—talk about a two-for-one insult.
Fancy digital plates? Cool until someone hacks them to dodge tolls—or make you pay theirs.
A GPS tracker company left customer data exposed, which is a little ironic for a business built on knowing your every move.
Then a new smart assistant that won’t gossip about you to the cloud. It's still got some rough edges, but we'll take rough over exposed.
Apple’s sending spyware victims to a nonprofit because even their genius bar needs backup sometimes.
Australia’s future-proofing by ditching old cryptography—quantum hackers, this puts them way ahead of the elliptic curve!
From there it's another day, another healthcare hack. This time it’s 5.6 million patients learning about their healthcare provider's poor data hygiene the hard way.
Still using SMS for 2FA? The feds say it’s a lot like locking your door but leaving the key under the mat.
The US Department of Homeland Security says global spies are routinely using old and completely insecure SS7 telecom flaws. Maybe you want to rethink that unencrypted text you just sent.
We filled your stockings with this weeks update, and the best part? Not a single piece of coal in sight! Let's get unwrapping!
Find the full transcript to this podcast here.
FAQ: IT Privacy and Security Weekly Update (Week Ending December 17th, 2024)
The breach linked to Chinese hackers highlights the dangers of government backdoors in encryption systems. The 1994 CALEA law, intended to assist law enforcement, created vulnerabilities exploited in this incident. Experts emphasize that backdoors weaken security for everyone and make systems susceptible to both good and bad actors.
Optum's AI chatbot, used internally for managing health insurance claims, was left publicly accessible without a password. Although it didn't contain sensitive health data, its exposure raises concerns about the responsible management of AI, particularly given UnitedHealthcare's alleged use of AI to deny patient claims.
While Microsoft's Recall screen capture tool now includes encryption and sensitive information filtering, tests reveal inconsistencies in its performance. It struggles to identify private data in non-standard formats or situations, potentially leading to unintended exposure of sensitive details.
The fine stems from a 2018 security breach exposing data of millions of EU users. It underscores the EU's strong enforcement of the GDPR and emphasizes the importance of companies prioritizing data protection. For users, it serves as a reminder that their personal information may not always be secure.
China is limiting sales of drone components critical to Ukraine's defense as part of the escalating trade conflict with the US. This move is expected to expand to broader export restrictions, hindering Ukraine's access to vital drone technology.
The EU aims to reduce reliance on non-European networks like Starlink by developing IRIS². This sovereign satellite constellation will provide secure internet access across Europe, enhancing strategic autonomy and fostering public-private collaboration in the space sector.
The shift to shorter certificate lifespans significantly reduces security risks associated with compromised keys. While this means issuing more certificates, Let's Encrypt's automated systems will ensure a smooth transition for users, resulting in a safer and more secure internet experience.
United Airlines is integrating Apple's "Share Item Location" feature into its mobile app. Passengers can now share real-time locations of AirTags attached to their luggage, enabling United's customer service team to track and retrieve misplaced baggage more efficiently.
Episode 221
Our first update has an important security lesson, "When you build a backdoor, don’t be surprised when everyone comes walking through it."
Then a very topical subject when an insurance chatbot is exposed... now you can experience the chatbot denying your claims in real time!
Microsoft’s Recall feature: capturing sensitive info, even when it promises it won’t—because AI still struggles with “Oops.”
Then Meta seems to be collecting fines as efficiently as it collects your data.
China to Ukraine: “No drones for you!”—because trade wars come with flying consequences.
Europe builds its own Starlink—because relying on Musk for internet isn’t a good long-term plan.
And now, Six-day certificates! "Keeping secrets for 90 days is so last year."
Lastly, for the holidays: United Airlines teams up with (Apples) AirTags—because you can’t lose what you can track.
Let's go rattle some doors!
For the full transcript to this podcast click here.
IT Privacy and Security FAQ - Week Ending December 10th, 2024
A ransomware attack crippled Stoli Group's IT systems, leading to bankruptcy for its US and Kentucky Owl subsidiaries. The attack highlighted the importance of robust cybersecurity measures. To safeguard your business, prioritize secure IT systems, keep software updated, maintain regular backups, and educate employees about phishing and malware threats.
A Chinese cyber-espionage campaign, Salt Typhoon, targeted telecom networks in at least two dozen countries, including major US carriers. The attackers stole metadata to identify high-value targets and intercept communications. While classified information wasn't compromised, this emphasizes the need for vigilance. Limit sharing sensitive information over calls or texts, and consider end-to-end encryption tools for added security.
The FCC is proposing mandatory cybersecurity risk management plans for telecom companies and will enforce them with potential fines or criminal penalties. This follows concerns over persistent security lapses and aims to prevent breaches like the recent Chinese hacking campaign.
Google Messages' claims of "end-to-end encryption" are misleading. While RCS chats within Google Messages can be encrypted, SMS messages and those sent to non-Google users are not. Always verify encryption details and don't rely on vague claims to protect your privacy.
Sauron is a startup offering high-tech home security using drones, cameras, facial recognition, and 24/7 monitoring. While appealing for its advanced features, the company's use of facial recognition and potential for aggressive countermeasures raises privacy concerns. Weigh these factors carefully when considering such systems for your home.
A supply chain attack compromised Solana's JavaScript SDK, leading to the theft of $184,000 from digital wallets. While the malicious code was quickly removed, it highlights the risks of open-source libraries. Developers and users should prioritize upgrading libraries, rotating keys, and staying informed about security updates from reliable sources like CoinDesk and The Block.
SpaceX launched new satellites enabling direct cellphone connectivity through Starlink. While initially limited to text messaging, the service will eventually support voice, data, and IoT devices. This promises global coverage even in remote areas. However, pricing details and encryption information remain unclear. Stay tuned for updates and explore how this service could benefit you.
This week's news emphasizes the growing cybersecurity threats across various domains, from ransomware attacks to sophisticated state-sponsored espionage and supply chain vulnerabilities. Staying informed, adopting proactive security measures, and carefully evaluating new technologies are crucial steps in protecting yourself and your data.
Episode 220
This week we solve a mystery that has may have more impact this holiday season than you could imagine, and what you can do to stop the same thing happening to you.
A Chinese hacking campaign targets telecoms globally, proving that no phone call is truly safe.
The FCC takes a hard stance on telecom cybersecurity, warning companies: fix those flaws or face hefty penalties.
Google's "end-to-end encryption" turns out to be more like "end-to-what?" as tech bloggers expose misleading claims.
A startup takes home security to new extremes with drones, facial recognition, and a little bit of paranoia.
A backdoor in a popular Solana library drains wallets, leaving a $184,000 hole and crypto developers scrambling to upgrade.
SpaceX's new satellite network aims to keep your phone connected, even when you're way off the grid—though texting is the only thing that's fast for now.
We have the world of IT Privacy and Security covered from Stoli to SpaceX. Let's jet.
Find the full transcript here.
Deep dive into The IT Privacy and Security Weekly Update moves into Low Earth Orbit for the Week Ending December 3rd., 2024: Your FAQs Answered
The FTC has taken action against companies like Gravy Analytics and Venntel selling sensitive location data without user consent. This data, often gathered from smartphones, was being used for surveillance purposes, including by law enforcement agencies. The FTC has banned these companies from selling this data, except in limited circumstances related to national security or law enforcement.
Unfortunately, a recent FTC study found that nearly 9 of 10 smart device makers don't disclose how long they will provide software updates. This means your devices could become obsolete and vulnerable to security risks sooner than you expect. Before purchasing a smart device, check the manufacturer's website for clear information about software update policies.
According to the UK's new cyber chief, the country is significantly underestimating the risks posed by cyberattacks. The frequency, sophistication, and intensity of hostile activity in UK cyberspace has increased. Despite growing threats from Russia and China, there's a lack of awareness about the severity of the risks.
A bipartisan group of Senators has called for an investigation into the TSA's use of facial recognition technology at airports. They cite concerns about privacy violations, lack of transparency, and potential for misuse. There are also questions about the technology's effectiveness in reducing delays and improving security.
Australia has become the first country to ban children under 16 from using social media platforms. This landmark law aims to protect young people's mental health and well-being by limiting their access to platforms like TikTok, Instagram, and Facebook. Social media companies face hefty fines if they fail to comply.
A U.S. appeals court overturned sanctions on Tornado Cash, a cryptocurrency privacy tool. The court ruled that smart contracts, which power Tornado Cash, aren't considered property under U.S. law, and therefore the Treasury Department overstepped its authority. This decision is a significant win for privacy advocates in the crypto industry and highlights the ongoing debate over how governments regulate privacy-focused technologies.
Low Earth orbit is becoming increasingly crowded with satellites and debris, posing risks of collisions and rendering space unusable. Experts are urging global cooperation to create a shared database for tracking objects and developing international rules to manage space traffic. However, geopolitical tensions and corporate secrecy make this cooperation difficult.
As space exploration expands, so do the cybersecurity risks. Hackers are becoming more sophisticated, targeting spacecraft and satellites with potentially catastrophic consequences. These attacks could disrupt navigation, communications, and even defense systems. The increasing use of artificial intelligence (AI) in space adds further vulnerabilities. Protecting space assets from cyber threats is now a critical priority for governments and space agencies worldwide.
Stay safe, stay secure and stay with us!
EP219
For this update, yes we are up again. We start off on terra firma, but we definitely end up in the clouds.
A double whammy from the FTC who just put the brakes on companies selling your location data—because privacy should come first, (even if you’re just visiting a coffee shop.) and then suddenly notices that your smart devices might not be as 'smart' as you thought—especially when it comes to knowing how long they'll get updates.
The UK's cybersecurity chief warns: we're underestimating the cyber threats, and warns the UK citizenry it's time to brace for a bigger digital storm.
Facial recognition at airports: convenient or a privacy nightmare? It's spreading across the US like wildfire so senators are calling for a closer look before it becomes mandatory.
Australia just became the first country to ban kids under 16 from social media—marking... a huge step towards giving kids their childhoods back again.
A crypto privacy win! Tornado Cash sanctions get overturned, sparking debate on how the government should regulate tech.
Then up we go, with Earth’s orbit getting crowded, experts are calling for global cooperation to prevent space from becoming the next traffic jam (or junk yard).
Space might be the final frontier, but hackers are already eyeing it—leading experts to warn of rising cybersecurity risks for satellites and spacecraft.
Come on, let's chase the horizon!
Find the full transcript of this podcast here.
FAQ:
A bipartisan group of US senators has introduced the Health Care Cybersecurity and Resiliency Act of 2024. This act mandates healthcare organizations adopt basic cybersecurity standards like multi-factor authentication (MFA), improved coordination between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA), and a more transparent breach reporting process, including details about the number of individuals affected and corrective actions taken.
Australia has enacted its first Cyber Security Act, requiring organizations exceeding a certain size (likely those with a turnover above AUD $3 million) to report any ransomware payments made to cybercriminals. The act also establishes a framework for the voluntary reporting of cyber incidents to encourage information sharing and enhance collective cybersecurity.
Reports suggest that Chinese government-backed hackers, known as Salt Typhoon, have infiltrated US telecommunications networks, potentially gaining access to phone calls and text messages. This breach reportedly exploited vulnerabilities in the system used by US authorities for lawful wiretaps. The incident, labeled as potentially the "worst telecom hack in our nation's history", raises serious concerns about national security and data privacy.
The Japanese National Consumer Affairs Center recommends that citizens engage in "digital end-of-life planning" to prevent difficulties in managing their online accounts after their death. They advise ensuring family members can access their devices, maintaining a list of subscriptions and login credentials, possibly including this information in end-of-life documents, and considering services that allow designated individuals to manage accounts posthumously.
Microsoft's Copilot, designed to streamline tasks by accessing internal company information, has inadvertently exposed sensitive data, including CEO emails and HR documents. This occurred due to lax permission settings in some companies, allowing Copilot to access and retrieve documents beyond intended access levels.
In response to the CrowdStrike incident that impacted millions of Windows devices, Microsoft is introducing the Windows Resiliency Initiative. This initiative includes Quick Machine Recovery, enabling remote repair of unbootable systems, stricter testing and deployment protocols for security vendors, and a framework to move antivirus processing outside the Windows kernel for improved security and stability.
Interpol's Operation Serengeti, conducted in collaboration with Afripol, resulted in the arrest of over 1,000 suspects across 19 African countries. The operation targeted cybercriminals involved in activities like ransomware, business email compromise, digital extortion, and online scams. Notably, the operation dismantled networks involved in credit card fraud, Ponzi schemes, human trafficking, illegal gambling, and cryptocurrency scams.
Undersea fiber-optic cables, responsible for transmitting vast amounts of global internet traffic, are increasingly vulnerable to damage and sabotage. Recent incidents, such as damage to cables in the Baltic Sea suspected to be linked to a Chinese cargo vessel, highlight these risks.
Episode 218 For this Update we start with an attempt to stop a spoiler and end with quite a few ways to slice a Pi.
In the US a few senators have gotten together a tablet of requirements they'd like to see healthcare organizations swallow in the US.
Australia, moves forward with a reporting requirement for all firms paying ransomware demands.
China is back in the news in the backdoor of all the US mobile phone providers. The big issue this week? Finding them and kicking them out!
Japan has a very pragmatic suggestion if you are prone to jumping off mountains in a squirrel suit.
Microsoft's Copilot reveals a side of it's extreme cleverness that could get the CEO fired, and then they announce new rollouts that will hopefully prevent another Crowdstrike debacle.
Interpol busts the Nigerian prince that you sent that money to so he could wire you a million.
With online television and content providers growing in popularity plenty have cut their cable, however they too could be compromised if the popularity of this particular cable cutting continues to grow.
This week we cut headcount, cables and Pi. Come on, let's go serve it up!
Find the full transcript of this podcast here.
Privacy & Security FAQ: Week Ending November 19th, 20241. What happened with T-Mobile and Chinese hackers?
Chinese hackers, suspected of ties to Chinese intelligence, infiltrated T-Mobile as part of a larger cyberespionage operation. This attack targeted telecom companies to gather intelligence on high-value targets. While T-Mobile claims no significant impact on their systems or customer data, the breach raises concerns about the security of telecommunications networks and the potential for surveillance.
Google is rolling out an AI-powered scam call detection feature for Android phones, starting with Pixel 6 and newer models. This feature analyzes real-time conversation patterns to detect potential scams and alerts users through audio, haptic, and visual warnings. The system operates entirely on the device, ensuring privacy by not storing or transmitting call data externally.
India's competition watchdog fined Meta $25.4 million and ordered WhatsApp to stop sharing user data with other Meta units for advertising for five years. This action stems from WhatsApp's 2021 privacy policy update, which mandated data sharing with Meta companies without an opt-out option. The watchdog deemed this practice as an abuse of Meta's dominant position and coercive towards users.
Legal documents from a US lawsuit between NSO Group and WhatsApp revealed that NSO Group, not their government clients, directly install and extract information from phones targeted by their Pegasus spyware. This contradicts NSO's claims that clients solely operate the spyware. The revelation raises concerns about the control and accountability of NSO Group's powerful surveillance technology.
ChatGPT's desktop app for macOS can now read code from developer-focused apps like VS Code, Xcode, and TextEdit. This integration allows developers to directly send code snippets to ChatGPT for analysis and assistance without manual copy-pasting. While it currently lacks the ability to write code directly into apps, this feature marks a step towards streamlined AI assistance in coding workflows.
DeFlock is an open-source project utilizing Open Street Map to map the locations of automated license plate readers (ALPRs) worldwide. Concerned about the proliferation of these surveillance devices, the project encourages crowdsourced reporting of ALPR locations, including details like camera direction. You can contribute to this initiative by reporting ALPRs in your area on the DeFlock website: https://deflock.me/report.
Internal emails revealed that the US Secret Service debated the need for warrants when using location data from smartphone apps. Some officials argued that users' acceptance of app terms of service implied consent for data sharing, even if those terms didn't explicitly mention sharing with law enforcement. This raised concerns about government agencies accessing private location data without proper legal authorization.
How can you enhance your privacy and security?
EPISODE 217
If you drive a car you'll want to listen out for the sixth story in our update this week. We tell you how you can even join in the fun!
On the day after 45 people were sentenced to prison by the Chinese authorities for pro-democracy activities in Hong Kong we get confirmation that the Chinese have broken into T-Mobile.
Google gives a gift that could stop phone fraud in its tracks, but only if you have a Pixel 6 or later phone.
India slaps Meta for coercive activities related to customer data sharing.
Then Meta slaps NSO group for lying about who controls their phone spyware.
ChatGPT can now read from some of the more popular coding applications on Apple Macs taking AI a further step closer to helping engineers where they work.
One man decides to create a project map all the Flock brand automated license plate readers near his home and finds out that people all over the world want to add their own readers, creating a global initiative.
And finally an example of invited by inference. And why "You gave it to the app. so you gave it to us" actually is not right at all.
Let's put it on a map.
Find the full transcript to this podcast here.
The team discusses the week's IT Privacy and Security Update and offers a different perspective.
Enjoy!
Episode 216
In this week's update we move from alarming outfits to stormy data sharing.
We start with retailers are eyeing thread-thin tech to tackle shoplifting and then move to Cyber-criminals stealing private data by pretending to be the police.
Then that iPhone the police took off you when your paid for shirt set off the alarm... well suddenly rebooted.
Then Apple again dreams up a plan that could make lost luggage a thing of the past.
From there, an update from the Feds as they suggest staff be as brief as possible on your next phone call.
Next one library has lending rights withdrawn and we wait for the echo effect as it hits other libraries making books available online.
And finally IBM takes a hit as they are again dragged to court over the Weather Channel's data sharing.
We always have the latest, freshest, IT privacy, and security updates for you. Come on! Let's set off some alarms!
Find the full transcript for this podcast here.
For Episode two one five and a half our couple does a deep dive into this week's topics.
Enjoy!
Episode 215
On U.S. election day, this is the update that will tear you away from the endless all night results shows.
Schneider Electric gets hacked, and the cyber thief is demanding $125,000 in something peculiar – a data breach with a French twist!
Scientists have discovered that plants “see” light by bending it through tiny air gaps – proving they don’t need eyes to point to something bright.
Opting out of Facial recognition site PimEyes means giving them more photos... and left us feeling conflicted.
Google’s AI Big Sleep found a bug in SQLite, so now we have AI debugging AI – what could possibly go wrong?
Meta’s AI models just got the green light for military use, because nothing says “peace” like open-source warfare tech.
The 26-year-old founder of Gotbit just got indicted for market manipulation – because apparently fake crypto trading volume isn’t cool with the feds.
A new report reveals that millions of American phones might be susceptible to Chinese surveillance could it be time to switch to encrypted apps or start using carrier pigeons?
Sit back, relax, and join in for the best update yet!
Find the full transcript to this podcast here.
Episode 214.5 This deep-dive session takes a more conversational look into the topics covered in Tuesday's update. More to enjoy!
EP214
Hacks, Zachs, and Smacks from the IT Privacy and Security Weekly Update for the week ending October 29th., 2024
10/29/2024
0 Comments
EP214 This week's update whirls us around the living room for a collection of stories demonstrating that your privacy and security are nothing to be taken for granted.
We start with a report with more troubling news about another robot vacuum cleaner gone rogue.
Then French newspaper Le Monde are the sleuths in unravelling more compromise for our global leaders from a fitness app that's already divulged the wearabouts of secret military bases.
The EU prepares to take a tough stance on insecure software.
We meet the next new secret agent and speculate that it could be a very lucrative new job role.
From there we learn the new numbers for Google's AI generated code and then have an update on a new open source LLM that checks for Zero days in Python code.
Finally we finish with an update from Microsoft's Threat Analysis Center for all those going to vote in the US November 5th.
We circled the floor for this week's collection of updates, and now it's time to clean up!
Find the full transcript to this week's podcast here.
EP 213
This week's update glistens with a sweet golden mix of stories that will raise your glucose levels higher than any other update.
We kick off with a couple of Microsoft stories: One sweet and smart and the other ...well, less so.
From there an amazing discovery that getting you into American airports safely might not be the only chore the FAA has to get right.
It's not quite tax preparation time in the US but a number of senators want to ensure that no pixel is left unaccounted for when it comes time to do your returns.
We have a new class of malware that takes its instruction from .png (picture) files.
We have a newcomer on the secure messaging scene that to maintain your privacy has decided to migrate from Australia to Switzerland
And finally just in time for your holiday on-line purchases, the FTC passes a bill banning fake online product reviews!
That's a sweet mix. Let's go find the Honeypots!
Find the full transcript to this podcast here.
EP212 The IT Privacy and Security Weekly Update is about to boost your brainpower!
A new study from Finland reveals that the choices you make today can affect your brain for weeks.
By adopting healthy routines—like staying up to date with key insights from this very update—you’re not just protecting your digital life but also enhancing your memory, attention, and cognitive function.
Consistency in learning and staying informed, especially on crucial topics like privacy and security, can literally reshape your brain for the better!
Then Google’s latest privacy scandal raises concerns about continuous data sharing, even without your permission, reminding us that the battle for privacy is far from over.
Meanwhile, in Australia car brands there too are quietly collecting and sharing driver data with third parties, prompting a call for tighter legal reforms.
In a stark example of why tech giants like Apple refuse to compromise on encryption, Chinese hackers have exploited U.S. ISPs' backdoors.
With privacy advocates urging users to delete their 23andMe data, the debate over genetic information security intensifies.
A Florida data broker’s bankruptcy after losing millions of Social Security numbers highlights how breaches can have lasting financial and legal consequences.
And finally, if you think your AI chatbot is safe, think again—LLM attacks are becoming swifter and more effective, exposing vulnerabilities in just seconds.
Let's get smart together!
Episode 211.5 for a different twist on this week's update have a listen to this review.
EP211
Who's really doing the Hoovering? It’s not just your robot vacuum!
Imagine you're living in a world where your friendly robot vacuum is secretly taking photos of your home, apps are tricking you into fake investments, and hackers are messing with your water bill.
Sounds like the plot of a tech thriller, right?
Well, buckle up, because reality just might be stranger than fiction!
In this episode of the IT Privacy and Security update, we explore everything from public utility hacks to AI surveillance on your smart TV.
Let's just say, it's time to double-check your router, think twice before downloading that "too good to be true" app, and of course, it's time to start the update!
Find the full transcript for this podcast here.
What better way to get to grips with IT Privacy and Security topics than with a discussion. In this episode, we break out the issues and topics covered in Tuesday's update.
EP210
For this update we kick off with 11 million devices and end with a way to track those that were supposed to be un-trackable.
We start with the reoccurrence from a family of malware that once was eradicated, but now seems to have reappeared.
We move from there to the US where the Federal Trade Commission has finally decided to weigh in on social media apps. and how they are making money.
From there a new way to get phished. This one is aimed at developers, but the next, may have you in it's sights.
We are gifted a new browser in the Firefox class. We tried it and we like it.
The US moves on smart car bans for nation-states it thinks should not have access to hoover up data within the continental US
Then China breaks into a firm through an outdated IBM mainframe and lingers...
We close the update with an ingenious story of how China is using Starlink satellites to make the invisible visible.
This week we catch lots of frenetic activity. Let's go see how China has kept busy!
Click here for a full transcript to this podcast.
This is the podcast about the IT Privacy and Security Weekly Update Tearing it Down for the week ending September 24th. 2024 podcast. Enjoy it. More learning and more fun!
EP209
You can tear it up, or tear it down, and this week we get a bit of both as we circle the Earth with our update.
We start with Snapchat seemingly opting you in to yet another AI use case. Subscribers are suspicious, but we let you be the judge.
From there we go to a story not so much about a hacker as an aggregator. Wait how many email addresses have they collected?
For our third update we look at the other side of supply chain interference. Exploding devices may be one thing when they are "over there" but what if they end up in your pocket of front room?
Google has announced it will soon tear down a big obstacle for passkeys in their synching across devices through the use of their password manager.
An international trade union calls out three of the "Fantastic Five" for their Undemocratic ways. This could smart in a US election year.
And we finish this update with a new phenomenon called a noise storm and the interesting thing found in the midst of it.
We tear it down so you can have a better look inside. Come join us!
Find the full transcript to this podcast here.
Listen as our AI hosts discuss Tuesday's update in this special update podcast.
https://rprescottstearns.weebly.com/news/the-it-privacy-and-security-weekly-update-with-a-side-of-post-quant-for-the-week-ending-september-17th-2024
Post-Quantum Cryptography Takes Center Stage: NIST finalizes three new encryption algorithms to counter future quantum threats, prompting Google and Microsoft to announce updates. This section emphasizes the rapid response of tech giants and the importance of proactive security measures.
Larry Ellison's AI Vision: Surveillance and Databases: Oracle's CTO highlights the company's role in AI infrastructure, emphasizing the importance of organized data. Ellison's controversial statements regarding AI-driven surveillance are explored, raising ethical questions about privacy in the age of AI.
North Korean Cyberthreat: Targeting Developers: The Lazarus Group's sophisticated malware campaign uses fake coding tests to target job-seeking developers. This section details the dangers of social engineering attacks and the importance of vigilance in cybersecurity practices.
Facebook's Data Harvesting Practices Exposed: Facebook admits to scraping data from Australian users, including public photos and posts, to train its AI models. The lack of opt-out options for Australians, in contrast to EU regulations, sparks concerns about data privacy and consent.
23andMe Data Breach Settlement: The genetic testing company agrees to a $30 million settlement following a data breach affecting millions of customers. Details of the settlement, including cybersecurity improvements and customer payouts, are outlined, raising questions about data security practices in the genetic testing industry.
The Hidden Threat in Your Smart TV: Over a million streaming devices found to be infected with malware capable of remote updates, highlighting vulnerabilities in open-source Android systems. This section explores the potential causes of the infection, including supply chain risks and the use of outdated software, urging consumers to be cautious about device security.
Quote of the Week: Reflecting on the week's themes, the update concludes with a quote from Tim Cook emphasizing the inherent risks of backdoors in technology, even for seemingly benevolent purposes.
Source 2: US: NIST finalizes trio of post-quantum encryption standards (The Register)
Introduction: Highlights the release of new post-quantum encryption standards by NIST, designed to withstand future quantum computing attacks.
New Encryption Standards: Details the three finalized algorithms, focusing on their specific purposes in protecting data transmission and ensuring online identity authentication.
Backup Algorithms and Transition Timeline: Discusses NIST's ongoing work on backup algorithms and emphasizes the need for system administrators to begin transitioning to the new standards promptly.
Industry Response: Showcases Google and Microsoft's swift actions in updating their encryption algorithms to align with NIST standards, illustrating the industry's proactive approach to quantum-resistant security.
Source 3: US: Ellison Declares Oracle 'All In' On AI Mass Surveillance (The Register)
Oracle's Role in the AI Landscape: Summarizes Larry Ellison's vision of Oracle as a leading provider of AI infrastructure, leveraging its networking architecture and partnerships with AWS and Microsoft.
AI and Mass Surveillance: Presents Ellison's controversial proposal for using AI to enable constant surveillance, highlighting his belief that it will improve police conduct and citizen behavior.
Ethical Concerns and Implications: Raises questions about the ethical implications of widespread AI surveillance and the potential erosion of privacy in pursuit of public safety.
Source 4: Global: malware via fake recruiting tests (SC Magazine)
Introduction: Describes a new malware campaign attributed to the North Korean Lazarus Group targeting developers through fake coding tests during recruitment processes.
Modus Operandi: Details the attackers' tactics, including the use of legitimate-looking Python libraries, hosting malware on trusted platforms, and creating a sense of urgency to bypass security checks.
Scope and Impact: Explores the potential impact of the malware, highlighting the risks associated with Python's deep system interaction and the need for enhanced security measures in the tech industry.
Source 5: AU: Facebook Admits To Scraping Every Australian Adult User's Public Photos and Posts To Train AI, With No Opt-out Option (ABC News Australia)
Facebook's Data Scraping Admission: Reveals Facebook's admission during an inquiry that it scrapes public data of Australian users to train AI models, without providing an opt-out option.
Comparison to EU Regulations: Contrasts the lack of opt-out for Australians with Facebook's compliance with EU regulations allowing users to refuse consent for data scraping.
Potential Consequences: Speculates on potential actions by Australian authorities, particularly in light of the involvement of children's data and the potential for privacy violations.
Source 6: Global: 23andMe To Pay $30 Million In Genetics Data Breach Settlement (Bleeping Computer)
Data Breach Settlement: Reports on the $30 million settlement reached by 23andMe to resolve a class action lawsuit stemming from a data breach affecting millions of customers.
Settlement Details: Outlines the key elements of the settlement, including customer payouts, cybersecurity enhancements, and employee training programs.
Denial of Wrongdoing: Notes that 23andMe denies any wrongdoing despite agreeing to the settlement, highlighting the company's stance on its data security practices.
Source 7: Global: Your TV may come with its own back door (Dr. Web)
Malware Infection in Streaming Devices: Describes a widespread malware infection affecting millions of Android-based streaming devices globally, raising concerns about device security.
Technical Analysis: Explores the nature of the malware and its ability to receive remote updates through a backdoor, emphasizing the potential for malicious activities.
Possible Infection Vectors: Investigates potential causes of the infection, including the use of outdated software, vulnerabilities in open-source Android systems, and supply chain risks.
Consumer Protection: Concludes by urging consumers to be aware of potential security risks associated with streaming devices, particularly those from lesser-known manufacturers.
EP208
Last month NIST finalized their selection of three algos for post-quant Cryptography and already we have two major players announcing they will be updating their encryption algos.
Larry Ellison infamous as the Oracle CEO, now CTO, tells us why he thinks we should be on our best behavior for AI.
Oh, and that Citigroup dev job you were applying for.... you didn't get the job, but you did pick up something else.
Facebook comes clean on the fact that it has scraped every Ozzie's face.
23andMe won't admit they did anything wrong, but if you were a customer involved in this particular lawsuit you are going to get a cash payment within 10 days of court approval.
And we finish with why you have to start thinking of your TV as a door.
We may be pre-quant now, but this weeks' IT Privacy and Security Weekly update is first to the post-!
Find the full transcript to this weeks' podcast here.
This week start the kameshika signal with a mushroom walking into the room.
We get a new use case from the "Po-lice" for that Tesla parked over "thar".
Then it seems NSA have enjoyed this update and podcast so much it inspired them to create their own (Thanks team!).
There's a new version of a particular spyware program that we're calling out.
A spec. sheet from Bluetooth version six that would probably even excite your dentist.
A set of critical numbers from Microsoft in this week's patch Tuesday update and an urgent update request for Windows 10 users.
And on its 10 anniversary an app that give you something no other app can match.
Everything will become clear once we hear the signal.
Click here for a full transcript of this podcast.
EP206 This week's update takes off from Las Vegas and lands somewhere in Low Earth Orbit.
We have databases of faces and how both a police union and the Dutch Data Protection watchdog think they are a bad idea.
If they have your face, how do you prove you are you? That's the next challenge and a proposal from OpenAI and Harvard thinks it'll have you covered. We might have a different opinion.
With elections coming up in the US would you be upset to discover that the code in your voting machine was written and updated by a Russian? You could not make this stuff up.
The Washington Post tells us why it thinks that Pavel Durov should stay in jail and some security researchers share how you might bypass TSA security the next time you are at an airport.
Finally we will soon have fifteen thousand reasons for considering not subscribing to one provider's broadband.
The dream police, they live inside of our heads. Let's check out this week's arresting update.
Find the transcript to the this pod. here.
Cash Cows and the IT Privacy and Security Weekly Update for the week ending August 27th 2024
8/27/2024
0 Comments
Episode 205The cash cow is in your house and you sit staring at it.
How did it get in? We’ll give you the latest on cloned RFID cards that will let you into almost any door using them.
Google gets shady with its collection practices and ends up back in court.
The FBI receives an order to clean house from the Dept. of Justice Inspector General.
Uber gets spanked in the Netherlands for sending private data across the world
And finally the Russian Army looks dazed and confused as their main form of communication gets locked away.
We may be in the dog days of Summer, but all we’re seeing are cows!
Find the full transcript for this podcast here.
Episode 204
Join us as we Zoom in to the biggest crowd we have ever seen.
Fancy a cycle around the neighborhood with the kids on your hot new bicycle? Read our update first!
There’s a new copilot that could make a huge difference to your open source project and a huge new fine for one European mobile phone company (in the US).
Then, a story about a firm that could’ve had the best security in the world, but it wouldn’t have mattered because they published their own passwords on-line.
We get a solemn reminder that no matter how rich and how smart, there is always an element of risk in anything you do.
From Taiwan, a new Domain Name System (DNS) backdoor that is exponentially more clever.
And we finish by crashing a plane tracker that was leaking user data ….for three years.
We zoom 'round and 'round this big world of ours delivering the best in IT Privacy and Security.
So settle in and let’s go!
Find the full transcript to this podcast here.
Episode 203
This week we let the vigilante out first and discover he has remedies for a number large enough to make Clint Eastwood stand up and take notice.
Then we bump into a type of fencing you will be glad has just been disallowed by a US court.
From there if you want to go invisible on the web the “do-it-yourself” route turn out to be cheaper and way more effective.
“We were software snobs” says the inventor of What’s App and Signal secure messaging. We find out what he’s talking about.
Your home security firm got hacked and won’t tell you if you have been compromised. We consider the confidence that inspires. Oh and it could be the same company that sends out your paychecks.
Apple adds a weekly permission check to it’s next OS update.
A hacker hits a farm in Switzerland and his cow and calf make the ultimate sacrifice.
And finally we go atomic with a story so wild it may literally “Blow” your mind.
This week’s line up of stories explode globally but land you safely back home.
Find the full transcript of this podcast here.
Episode 202. This week we start with a new use for your face and end with a cautionary tale about keeping a safe distance when looking for true love.
Then we get up early in the morning and discover that in trying to keep you secure, Microsoft gave you a broken multi factor authenticator. (thanks Microsoft).
After that, it’s more love, but a love you will have to suppress if Ford’s patent takes off.
A new scheme from DARPA that could be almost as revolutionary as that experiment they did connecting university mainframes.
TikTok steals from the children and nothing gets a mother more angry.
A new Chinese hacking group compromises an Internet service provider so that when you do your machine updates, you get… malware!
And then we share another wonderful app from Microsoft that this time allows your boss to keep tabs on your every move. (Again, thanks Microsoft).
Gotta get up early in the morning!
Find the full transcript here.
Episode 201 This week we have bookends for gearheads. A book for Ferrari and a booking for GMC.
Our second story is so incredible that even we had to read it twice. Our question is: “Would you ever use an exchange run by people so stupid?”
Your house just got robbed. We have the detail your wifi Camera didn’t pick up.
We’ve got some good news for you as you pass through US airports, and bad news as you pass through another US healthcare benefits administrator.
From there Google gets body slammed by the W3C, and you’ll understand why when you realize how it affects your privacy
This week we’ll take a little cruise in the back seat of the car, but please don’t think you’ll get any privacy there.
Drivers take your mark, get set, Go!
Find the full transcript to this week's podcast here.
Episode 200 The IT Privacy and Security Weekly Update and the End of Personal Privacy in the US for the Week Ending July 23rd., 2024
7/23/2024
0 Comments
Episode 200
- Click the pic to hear the podcast -This week we start with the end. The end of personal privacy in the US. Join us to discover how everyone from Larry Ellison to your letter carrier has compromised you.
We have the culprit named in Last week’s Microsoft / Crowdstrike outage. It’s certainly neither of those companies, but can you guess who the finger is being pointed at?
From there we discover how great your threat vector is once you log in and go online
There’s a new “killer app” that your real estate agent is subscribed to that tells her way more about you than you ever would.
There’s another update on some frenetic new activity going on in Low Earth Orbit.
And we finish in Paris with some of the most invasive sports profiling from a company known more for its close ties to James Bond than the 200 meter butterfly.
This week’s update catalogues the end of your personal privacy.
It’s already happened.
Your world will never be the same again.
Find the full transcript to this podcast here.
Episode 199
From the millions here on Earth to the second planet from the Sun we keep you up to date with all the latest and most important escapades in IT Privacy and Security.
We start with the good news that although AT&T may not be selling your phone location data (if you opted out) they have still been sharing it. We tell you what and when.
CNN provides some investigative reporting that turns up the fact that the irrational worry you have about the use of hidden cameras in Airbnb and rental properties might still be a valid one.
We go down under to discover a 42 year old being lead away in handcuffs for giving free WiFi access in Australian airports and on domestic flights. Find out why free is never really free.
We have the Ukrainians in trouble again. This time it’s not Biden’s vice president Putin but a breach of the company that makes that handy dandy phone stalking software your new boyfriend/girlfriend told you was a spelling app.
Then we move onto Belgium for some fine chocolate and a warning to Linksys that they are sending your Wi-Fi password across the Internet in cleartext. This may explain what otherwise looks like a taxi rank of cars parked outside the front of your home.
From there we cover a game show that moved channels from Google to Squarespace. Is it behind door one? Door two? Or Door three? And the surprise waiting.
The FTC deliver some stats on how websites lead to you to outcomes they plan for you. Don’t share this story with the new spouse you met on Match.com
And finally, we are back in orbit, this time representing to the Venusians and you’ll never guess who our delegate is.
Moon boots. Check.
Space helmet. Check.
Let’s fly!
Find the full transcript for this podcast here.
Episode 198
This week we start with a road trip in Cali to the library... and something about that drive that everyone seems to be missing.
Next we travel from the depths of the oceans back into low Earth orbit and why the EU datacenters in space research might just have something to plug into.
Then we go overdue when we check the card catalogue for AI and discover poor security.
There’s a new update in town and it’s got 10 billion entries. We tell you why you’ll hope your details are not in that list.
We have the latest on Microsoft’s entirely hackable “recall”, Google’s version and now Motorola’s variant.
Z-Library loses it’s top two staffers somewhere in Argentina.
And we end in the reference section with a new website that aims to give you objective news.
It’s all here at the library and for this week’s update you won’t even need a card! Let’s go!
Find the full transcript for this podcast here.
Episode 196 Oops!! We start by reading your emails and finish with your significant other reading you the riot act.
Over in Germany, TeamViewer gets a visit from a cozy bear…
While in Santa Cruz a lightbulb’s worth of energy is running a chatbot.
Google has growing datacenter flatulence and GE gets free and easy with the classified data it’s er… well.. emitting.
We get some creepy insight into the Petri dish of the near future and what smiles back at us.
And we finish with the reason that your better half is waiting for you at the front door with a shotgun after you do a hard night “at the office”.
This week we have lowered the levels of brilliance so far that it might be difficult to find your way home. But worry not! It’s always darkest before the light. So let’s go!
Find the full transcript to this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 195 Check your tires and adjust your pedals because this update could get you back “on Yer bike”
In our first story we learn how deep and wide the river of collected car information is, and in our last, exactly how that detail was delivered. You may be as surprised as we were to find out who is riding the prologue into this stream of information.
We get a painful puncture from the National Health Service in the UK while in the US a different healthcare provider deflates us with the data breach of a shocking percentage of the US population.
From there we spin up to Sweden for some extra miles / kilometers to get the inside lane on the type of event that ensnared poor Ellen Bagley.
Then, back across the Atlantic, someone bans Russia’s premier antivirus. But wait! Wouldn’t a Russian antivirus be the best “bloc” for Russian hackers?
Finally Pavel Durov puts a spanner in his spokes by saying the wrong thing to Tucker Carlson earning him a “Lanterne rouge”.
If you love adventure, this could the best tour yet, so strap on that helmet, slip on your gloves and let’s catch the Peloton!
Find the full transcript to this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 194 From your car to your new home... this week has something for everyone.
We start with a data reseller that will become more and more a target if rising car insurance premiums are anything to aim at.
We follow with two stories of exposed client data. The aftermath was handled differently in both cases and we think you should tell us which you’d prefer.
From there its off to Singapore in a story we found so incredible it moved us to poetry.
And then we “hear” a privacy policy has been slimmed down and that made people upset. We’ll tell you why.
Got the “ump” during your morning commute? We share why that might might affect your purchasing preferences when you get to the office.
And we finish with the ultimate in data privacy and luxury accommodation for your bits and bytes.
We have a great adventure this week so .... Let's go!
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Filling the hole in your Memory with the IT Privacy and Security Weekly Update for the Week Ending June 11th., 2024
6/11/2024
0 Comments
- click the pic to hear the podcast - Episode 193
For this update we start and finish with some spectacular areal shots of things we probably shouldn’t be seeing.
We bump into a familiar issue with extensions. This one isn’t browser extensions, but something that could be even more dangerous if not tightly overseen.
After that we get some good news on filling the hole in your memory. This one will now ship as opt-in while we wait to get all the details on a product from a new contender who is chasing that same hole in your memory while forgetting your location history. It might be time to run down to your local library for some hippocampus exercises.
We test a new (mostly) anonymous quackbot to use as an interface into our AI models and actually get some decent results.
And finally we end up with a Minnesota winter weekend break idea that could land you in more hot water than your neighbors’ outdoor Jacuzzi.
Keep your hats on and your memories full as you join us on this week’s adventure. Let’s go!
Find the full transcript to this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 192 This week we go looking for help and discover something else entirely.
We start by being turned away from a London hospital because of something spread by a sick corporate partner.
Then we move onto background checks. Perhaps soon potential employers won’t need to run them, they’ll just look you up on the dark web.
From there Google springs a leak. Honestly, whoever is handling their PR must be having a meltdown over this latest faux pas because it’s a whole database of privacy incidents reported internally that provide a level of transparency no one at Google wants to see through.
Then let’s talk about the new Windows feature that will have you exploring the virtues of Linux even if it was the last thing you thought you would ever do.
They’ve been busy in Ottawa with a new industry proposal to build more back doors. We’ll find out why some are saying that is construction we simply don’t need.
And then there’s that password crack for a US$3 Million stash. How it was cracked and how you can prevent the same thing happening to your US$3 Million stash.
We end on Stack overflow with some help from a friend that’s anything but.
Good help is hard to find, but a great update is right in front of you. Let’s go!
Find the full transcript for this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 191 This week we detonate a mix of updates starting south of the U.S. border, following a tremor into the roots of DNS and then colliding into the 5 precincts of New York City.
We have the incendiary tale of the Mexican cartels and how a hack spilled light on who is arming them.
Next, like our root DNS server, we explode with the 411 on just what another outage of that server could mean to all of us.
From there we reload with a tag story of how Apple presents location data and why you may not like what it’s saying about you.
In the UK we feel the scattershot of facial recognition software entering into our lives. If our face becomes a bar-code, what happens if we are mislabeled?
Then we learn how efficient AI makes a hacking team when a project, scheduled to take three weeks penetrates a major tech firm in just hours.
And we round out with the outburst of something whizzing over your head. This time it is a triumph of good over evil, but we wonder if that story will change over time.
Let's jump into the burst of stories. For this update we’ll be safe, even in the line of fire.
Find a full transcript of this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 190. This week we start with a tale that will bring happiness to every University Students’ mother.
We follow with another that has one woman fuming while everyone involved claims it was a coincidence.
There is an update on the tattletale car story and the short, sharp, slap that lawmakers gave automakers recently.
We find out the name of the company whose employee was tricked into a $25 million transfer.
Then a story that will make the blood boil of anyone who’s been let go during the ongoing waves of tech layoffs.
A Cyber security giant tells us why large language models can never be secure.
And we end with what we would almost call an obscene invasion of privacy from a collaboration tool that we all used to trust.
We won’t promise you that this weeks update will get your socks clean, but at least there’s no pre-soaking required. Come on! Let’s wash!
Find the full transcript to this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 189. Ever feel like you are being followed? This week we have both Apple and Google making efforts to quell that effect.
We have leak updates from two sources that should be among the last to ever have to send out breach notices. One a computer manufacturer and the other a US Government agency.
From there, its on to the latest craze in extortion and what you can do to secure against it.
We get what we think could be an AI version of Mad Cow disease. The first round of Mad Cow was scary, but this one includes hallucinations.
There’s the rushed US extension of section 702 of the Foreign Intelligence Surveillance Act (FISA). Wait what? What’s that? It’s an NSA undertaking that could effect almost anyone globally.
And finally we get some insight into what happens when your company’s Cloud Service Provider (CSP) hiccoughs, and deletes all your company infrastructure. Could it be time for CSP specific Disaster recovery plans?
This week’s updates might leave you feeling a little uncomfortable, but ...better the devil you know.
Find the full transcript to this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 188
This week we blast off with a couple of stories that would make movies like Top Gun and Armageddon appear tame in comparison. This just might be where reality surpasses fiction.
From there we move to a couple of US healthcare providers that are doing their utmost to help other nation states get familiar with your particulars. One was an actual breach but the other was just dumb.
Then we learn about sharing... or… we learn we are sharing, as it seems that almost 50% of Internet traffic is not even of human origin…. and the growing pain of proving we are human!
Google updates two factor authentication (2FA) so that you don’t have to worry about sim swaps compromising you and finally things to do to lessen the probability that you might have spyware running on your iPhone.
This week’s update is a shot in the bot, but you know what? You’re going to love it!
Find the full transcript to the podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 187
Flames leap from the IT Privacy and Security news this week... from trick TVs to leaky telephones.
We flare up with a story about US Senator Ron Wyden chasing a Google TV “quirk” that could grant access to your Gmail.
Then from the embers we hear scraping noises. This time Discord is the target and you are the payload.
From there it’s insecure Chinese keyboard apps. And the millions of users that could be easily smoked out.
Next is a story about how Microsoft threw cold water on a hot vulnerability that was being actively exploited in businesses across the world.
A recent court ruling agrees that yes, you can get burned by your thumbs…
And finally a roasting for the US’ largest wireless carriers over their exploitation of your location data.
This week’s temps are up, but you’ll stay cool as we share it with you! Let’s go!
Find the full transcript to this podcast here
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 186 Look, up in the sky! It’s a bird, it’s a plane! It’s... your insurance company!?!?
This week we have stats and stories that will leave you gasping, and that’s good because you’ll have a chance to catch your breath during our spring break over the next couple weeks.
We start this update up there, in the sky, and the novel new way insurance companies are finding to lower risk and increase profits.
From there we move on to a US privacy bill that we never thought we would see get as far as it has, and just how many people are potentially lining up to stop it.
It’s not 007, but SS7 and it involves spies and use by adversaries for so long that the Federal Communications Commission is calling for accountability.
There’s a ransomware attack that hasn’t hit healthcare but a coffee loyalty program that has raised the profile of ransomware to new heights.
From a Canadian listener an update on Microsoft’s Security Chickens.
And finally the most amazing, incredible, unbelievable identity theft story we have ever heard.
They removed the last public phone box in Metropolis in 2022, so there’s no chance to change, but that’s fine because by the time we get to the end of this week’s update we’ll only need one identity and it will be secure.
Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 185 This week’s update starts out leaking like an old bucket, but gets patched up pretty good.
We start with our friends at AT&T and yet more mobile phone subscriber detail launched out onto the dark web. Is it playing catch up with another mobile service provider?
An almost shocking update from the Department of Homeland Security that they are halting the purchase of your location data and phone records from data brokers. Could this be the DHS realizing they were doing wrong or is it simply down to budget cuts?
Then there’s news from President Joe that all agencies should appoint a chief AI officer. In the acronym laden US government that would mean adding a CAIO to the C-suite. Not to be outdone, the VP announced some new AI standards introducing the novel new word “fairness” to some of the use cases that are popping up like spring flowers across the US.
The US taxpayers on are the hook in a new reward for the capture of the BlackCat hackers, before we move on to Google pledging to destroy the truckloads of data it collected on you (and others) while you used their browser in incognito mode.
We finish the update with that look in your eye that has given yet another country the impetus to pause retina scanning by a man called Sam.
If there’s a hole in the bucket, we’d better get to fixing it. Grab some straw and let’s go!
Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 184. It’s the last last episode this month, and if “March comes in like a lion and goes out like a lamb” then we have the wild in these updates running backwards.
We start with an absolutely stupid way to save five bucks. Cut coupons, buy off-brands but don’t try to save money with Telegram’s new money saving offer.
Next we move onto a story about how the YouTube algorithm could get you added to a very special list of people who end up with way more attention than they bargained for.
From there we get some unexpected protection from a name we thought had left the room.
Then, from the realms of “They will mine on anything” If your AI sessions are returning nonsense, you may want to blame it on Bitcoin.
Florida goes further than any other to protect kids with a new law, braces for the inevitable onslaught of lawsuits and then…. Nothing happens.
And we finish this week with a story from last spring that has just hit the courts as hard as these uninvited guests hit her front door. You will be shocked and amazed at just how much damage a pair of AirPods could cause, and not to your hearing.
Wild is as wild does. Come on, let’s go!
Find the full transcript for this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 183
In our sweetest update yet, we go from “Jam” to chocolate as we cover all subtle flavors and nuances of IT Privacy and Security.
Then for our second story we have an EU member in trouble with GDPR with what some would call complete disregard for the regulation they helped create.
In the third story of our update we explain the two things you should be aware of as you scroll through TikTok videos.
General Motors has a new lawsuit driven at it after one customer discovered he couldn’t get car insurance because his Cadillac was tattling on him.
In our fifth segment we spill “Top Secret” detail with you that is, frankly, a little over our heads.
And finally we round the update off with a bittersweet story that will have you running out to corner the market after you read it.
This week’s update is sweet like chocolate.
Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 182
This week we take you from credential stuffing to whistle-blowing by way of a bolted horse.
We start with the compromise of your beloved Roku account and no more vivid a lesson on the value of unique passwords.
From there it’s on to closing the barn doors after the horse has bolted with the US’ new report on controls for AI.
Airbnb takes you off camera for your next rental while the EU seems to have gotten caught in their own GDPR trap.
Signal’s new username feature is available now and it takes the application to new heights of privacy and security that no other messaging app comes close to.
Finally we end with the story of a Boeing whistle-blower doffed shortly before he was to give his deposition and how sad Boeing are.
Like a bolted horse, this update is fast and frenetic yet we think you’ll be glad you came along for the ride!
Find the full transcript here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
For this episode we go searching for the needle in the haystack and it appears that someone or something in our fourth story found it!
But we end Q1 with what we end every Q1 with in the US. Taxes. And relief that the already onerous tax prep process that so many have to have buy special software for just to complete, now asks you for permission to sell your data …. and how you can avoid it.
Americans see their privacy eroded at every lamp post, but North of the border in Canada the supreme court passed a bill that increases privacy for every Canadian.
And while we hold our breath and turn blue waiting for Microsoft to fix their zero day vulnerabilities, we apparently have demonstrated an unwitting hospitality to guests visiting from North Korea.
From there it’s AI, and while one finds needles in haystacks, others are generating things that crawl a network in an altogether more unsavory manner.
The U.S. Whitehouse, apparently now a subscriber to our podcast continues to call out the dangers of “Smart” devices. This time it’s cars and the takeaway that has the POTUS calling out a new investigation.
Finally we finish with a device called the ShotSpotter that is turning up in neighbourhoods across the US in high numbers. It doesn’t have a camera attached, but it still has potential to to remove even more of our privacy. Can you guess how?
This is our best update yet, so grab your metal detectors and let’s hit the hay!
Click here for the full transcript to this podcast.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 180. The IT Privacy and Security Weekly Update Loses the Car for the week ending February 27th., 2024
This week one vendor announced we’d be getting post-Quant encryption for our messages, while another works feverishly to ensure we can find our car when we are done at the supermarket.
We have a discovery at one vending machine that does its tracking while you are snacking.
We shine some new light into nation-state spy versus spy wars.
Then the FTC lets loose on a free antivirus provider that slurped up so much of your data for the last 10 years that it’s making the NSA look amateur.
Following that is a class action lawsuit against a license plate scanning company out in Cali that you can join if your plate been scanned at least 15 times. You’ll want to be sitting when we do the reveal on how many people will be joining you.
This week’s update is all about right and wrong, left and right, and er... “where did you say we parked the car?”
Find the full transcript to this week's podcast here
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week’s update is our most exciting yet:
Whatever it is, this update fixes it, so come join in the adventure!
Find the full transcript for this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
It’s that time of year again when love is in the air and this week’s update will be as embracing as a hug from Taylor Swift after a big Super bowl win.
We start with a great misstep story about a hypothetical bot infection of millions of toothbrushes that is sure to leave a glint in your eye and a grin on your face.- click the pic to hear the podcast -As we recover from all the betting ads being hurled at us as US states legalize online betting one by one, we have a story about how the world’s biggest (by volume) casino faltered.
From there we go underground, literally, with a newly released disclosure about real time survelliance that could have those in the world’s 37th largest city running for cover.
Fresh and hot, we deliver an Apple turnover on the right to repair.
Then an update from Google that might make spyware companies like Israel’s NSO group even less popular.
And we finish with something that might have you reminiscing about school days and fake IDs, but this time we add in the artful hand of AI.
You're in the mood, you’ll love this update.
Find the full transcript to this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we start with your dear Gran. When’s the last time you called her to see how she was doing?
After our first update we hope that call will happen within the next day or two.
From there we move to a model corporate citizen in CloudFlare and discover further repercussion from last year’s Okta Breach and a remote desktop solution that could almost use their breech as a PR exercise.
We are reminded that everyone on that Zoom call might not be as they seem, and find a glorious dip in ransomware payouts that hopefully indicate the new direction of ransomware attacks.
Then... we go dark with a report that has probably crossed all of our minds since the Covid-19 outbreak.
We get some good news for the environment from some joint work between MIT and IBM and we end with what some would call a regulatory imbalance.
From empathy to entropy and back again this week’s update gets the balance right.
For the full transcript to this week's podcast click here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 176
This week the update gets dialed in: First via a new spy tool called Patternz then via a photo contest where we share who rates what in the race at the top.
From there we have an update on the “Mother of all breaches” a newly surfaced collection of over 26 Billion records for you to wonder if you are part of.
It’s onto the the US’ efforts to thwart Chinese hacking within critical US infrastructure before we read a letter from a US senator to the NSA asking why they are buying up phone data on US Citizens.
Then there is an update about Chat GPT placing random private conversations (including PII) in one users conversation list.
Britain gives us a timeline for the development of AI ransomware and Russia goes dark.
This week’s update might have you reminiscing about the physical security of an old payphone, but we’ll get you reconnected.
Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 175
As you were walking home from work did you ever feel like someone was watching you? In this weeks’ update we tell you why.
We have some disturbing news on a cyber attack where the data from 1 million cancer patients is stolen, and then used to threaten and spam them.
Mandiant discovers a Zero-day attack that could have allowed many businesses like hospitals to be compromised for up to 2 years before a patch was delivered.
Microsoft’s executive suite got hacked by a Russian intelligence agency.
Troy Hunt adds another 71 million emails addresses to his “haveIBeenPwned” database, which means, now is a great time to check and see if your emails are among them.
We finish with stories about a couple of devices that are making the news: One detects skin cancer using AI and the other seemed to be minting Monero while it cleans your socks.
This week’s IT Privacy and Security Update is full of surprises, but each and every one is delivered to you “Clean and Fresh smelling”!
Find the full transcript to this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 174 This week we are pumping, probing, questioning and querying on all fronts. We start with a couple of fan faves from the Consumer Electronics show, but wonder if we’ll get as much use out of them as the V-logging contingent.- click the pic to hear the podcast -From there we siphon out some subtle word-smithing that might mean we are not the only ones left quaking in our boots.
Apple, the company selling us on the importance of privacy, drops another privacy bomb on us.
We tap into supply-side typo that should have everyone in San Francisco more than a little angry at the lack of due care and attention being paid by their judges
The Emmy’s are over yet Reddit pushes out an update about being chased by the movie studios and it doesn’t to want to be caught in this spotlight.
The swell of Quantum computing-proof encryption difficulties continues to grow with another set of vulnerabilities exposed.
And we finish this week with a story about a water pump that “spills” a little more detail from one of the biggest security mysteries in years.
The pace is bumping, the beat is thumping, the stories pumping so let’s get jumping.
Find the full transcript for this podcast here
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 173
This week we need some space, man.
We start with phones and cellphone towers in low Earth orbit, then we move on to one of the most intriguing iPhone compromises we’ve ever heard andwe have heard plenty. Who is behind this one? That’s for you to decide.
From there we learn about a Mandiant account hijack (wait aren’t they one of the most elite security companies? Weren’t they the second most expensive company that Google ever purchased?)
Then we have a section of the update for slow learners, and we promise it’s not this audience!
Then it's: “why we need to patch our Windows machines” before a story about catching a pest that finds a new home every Sunday.
We end with an update that is good enough to be out of the Jetsons.
This is the best IT Privacy and Security Update so far this year! We love it and we know you will too!
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 172
This week we focus on our amazing kids. From the effect the phone we send them off with “to keep them safe” has, to an amazing 13 year old crushing a 34 year old arcade game. We even end with advice from a Nobel prize winner about what you might not want to study.
From, the kids, we turn to Apple and what is going on between them and the world’s biggest democracy. We then follow Apple to a researcher who thinks he has found the perfect way to keep Apple Air tags from being used for tracking people.
We get an update on the failure of the open source GPL (General Public License) and what one key figure thinks could replace it.
The Google gets some bad news as it is denied a request to have a court case thrown out and then some great news on the safety record of it’s Waymo subsidiary.
It’s a new dawn, it’s a new day it’s a new life… and we’re feeling good!
Find a full transcript of this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
If you missed getting that special someone that special gift, we have more solid ideas for you this week: A concept jet engine and the source code for Grand Theft Auto 5 as possible suggestions.
We get some insight on why the compromise of your personally identifiable information is not something to take lightly as well as the world coming to realize that you can build a nuclear program on someone else blockchain.- click on the pic to hear the podcast - We get some great insight on just how easy it is to trick ChatGPT into divulging it’s training data.
Then the US government slaps a 5 year ban on Rite Aid for using facial recognition software, just as the UK is sneaking a country wide integration into place.
We end this week with something so basic a child could figure it out. And did. Leaving television content producers to catch up from behind.
This brings us to the end of a year that has profoundly changed the course of humankind, from the decimation of animal species, to the environment, to each other. Let’s all learn from 2023 and make 2024 so much better. Come on! It’s boxing day and time to reveal your last gift.
Episode 171 Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 170
Our first few stories present some unique gifting ideas. Who needs another Rolex when you can give “large”?
We get new breach reporting requirements from the US’ SEC and China’s MIIT. Wait, what is this, a competition?
In that same vein, we get something less than super from Mr. Cooper.
After a court ruling that you cannot be forced to reveal your phone pin, there’s great news from Google about a change to your location data.
And we finish up this update in front of a crackling fire.
Quick, get the eggnog, we’ll go get a cat, and let's settle in comfortably for this week's update!
Find the transcript for this week's podcast here
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 169
This week we hang up the phone with a couple of definitive stories, the first coming from a huge US phone company and the last a Dutch phone company that is ripping the title of “The phone to be seen with” out of the hands of Apple, Google and Samsung.
Second in our stories this week is a blatant example from the UK of an individual in the public sector courting the private sector.
In at story three is yet another US healthcare provider getting breached.
Then we find Apple commissioning a report about data breaches and ransomware while at the same time crippling an app that delivered their secure iMessages to Android.
We have a creepy move by Google to potentially provide context to your interactions with their bots by feeding them your photo data.
And we bring Microsoft into the mix with a story about how their Active Directory could end up delivering what it shouldn’t to a certain type of query.
There’s only one way to stop that ringing in your ear. Let’s pick up the phone!
Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 168
It seemed excessive, but you agreed on the rent and even though it’s “way more” than you wanted to pay, you manage, until you read our first story.
Facebook published their quarterly adversarial threat report, and they say that one country is firing up “way more” fake accounts to influence your opinion than just about anyone.
asso Security says they discovered “way more” API tokens exposed related to AI models and datasets from one AI community than they’d expected.
We got initial numbers and a couple of revisions that are “way more” related to breaches from 23andMe and Okta.
There’s concealment, compromise and danger as we learn “way more” about the UK’s Sellafield Nuclear Power Plant.
Finally, ”way more” exposure and a judge’s opinion that Amazon may be responsible.
The plain truth is this week’s update gives you “way more”!
Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 167
This week we start with the dollar bill ranking of the top US Universities for earnings potential
We then throw some light on a global disappearing act, first the presenters and then a whole developer conference. This is one you have to hear to believe!
From there, in our third story, it’s a thumbs down for the security that fingerprint reader on your laptop is delivering.
In at four is a new agreement between the US, UK and a dozen countries pitched at making AI safer.
From there it’s hot water, and wait, one martial artist’s company that seems to be soaking in it.
We get a “better late than never” from “Down under” in the fight on cyber crime and finally for our last story, an Internet of Things thing that you’re spending a third of your life on that may be sharing more about you than you want.
This week’s update is all over the place and all over the world, but you get it served up fresh right here!
Dig in!
Find the full transcript of this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 166
This week we have a revelation related to a world famous someone who has managed to avoid arrest through the careful application of privacy. We reveal how that may now be at an end.
We share how a phone manufacturer who promised to bring Apple’s iMessage to Android ended up with “Nothing”
From there a new revelation about how the US Government is using our phones to compromise our privacy (again) and then a really cool must see result from a dev who integrated his computer and camera into GPT-4V and an AI voice and got his own nature program.
Then it’s on to how kids in school can protect themselves against accusations of cheating with AI, and why it’s wrong for schools to be trusting bad software over their students.
From there we find a group that has done more damage trying to do the right thing than if they did nothing at all.
Finally, we have a new use case for blockchain that might be to blockchain what killer apps were to PCs.
We are coming up to Thanksgiving in the US and so we are giving thanks for all our readers and listeners. You keep the drive and the passion flowing. Subscribe to the podcast, share us with your colleagues and friends. “Thank you”.
Now, let’s get this party started!
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 165
This week we let the cat out of the bag with the FTCs probe into one databroker’s dealings.
We follow with our second update that has a cat on a hot tin roof … of your car and just what the automobile manufacturers are collecting from you that is available to the police, but not you.
For story three we swing the cat ‘round to the EU to find out a bit more about QWACs, while in Australia we put the cat among the pigeons of one telecom provider with an update and a request that had a judge decide they didn’t have a cat in hell’s chance.
In at story five is what happened to the cool cats over at Open AI right after their first developer conference.
We look at a couple things the cat dragged in one affecting older older bitcoin wallets and the other particular Python packages.
And we end with the cats meow of an update to a great communications app.
The cat got the cream but we’ve got an even tastier menu in this week’s dishy update
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 164
This week we let you know why you feel so great after staying up all night with us.
For our second story, we move into one of the world’s most prestigious resorts only to get no sleep because of its leaks.
Our third update covers the blackout of about 31% of the Australian mobile market.
In at number four is the nightmare of just how easily a study found it to be to obtain Sensitive Personally Identifiable Information (SPII) on the US Military.
At five news updates on Apple: malware, Macbreaks and Massive tracking devices.
Then we move onto the screen actors guild staying very much awake on the point of not releasing the rights to an actors likeness in perpetuity.
Finally we close out with a story that allows no shut eye: the intense appetite to string all camera feeds together that started in one town and has caught on like a rash.
This week we’re chasing the sun with a collection of global stories that ensure there will always be sunshine on this update! Let’s go!
Find the full transcript to this weeks' podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
We start with the perils of sharing too much on social media and feeling like there's just no recovering from that last round of plastic surgery.
Then we touch on a story of an unexpected right hook from the SEC that left one CISO seeing stars.
We smell trouble with high numbers of shortened web addresses being delivered by email, text and message apps. for our third story.
At four and five we find Ace hardware left with a bad taste in their mouths just as news of a ban on ransomware payments by 40 nations hits our ears
We're trying to see through the murk of AI model transparency with a new rating system that may deliver some clarity for our sixth story.
And as is often the case, we end this week's update somewhat explosively with a suggestion that should keep all our senses (and quite possibly our homes) intact.
Our sixth sense tells us this is the best update yet so grab that Ouija board and lets go!
Find a full transcript of this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
For our first story we put on our resting witch face and join the Mozilla Foundation as they reveal their new privacy creep-o-meter.
We’re raising spirits in the art community with our second story of the “deadly” Nightshade that might kill off AI replicating your artwork.
In story three witches be trippin’ over 23andMe data from another 4 million clients. What a nightmare!
The star of our fourth story is the return of the Boo crew leaving Okta to create another batty blog post.
The Colorado Supreme Court creeps it real with support for warrantless keyword searches as the US DOJ discovers North Korean ghosts in the machine.
Next we say “fang you very much” to Gary Gensler for his heads up about AI’s potential effect on our financial markets
and finally...
An eek, squeak, and unique new use for AI that let’s it hear things you don’t remember saying.
So join us in this week’s web of fun. Broom hair? Don’t care. Let’s go!
Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 161. In this week’s IT Privacy and Security weekly update...
On first base is an exciting new use case for AI that will leave you feeling great!
On second is an update on the largest DDoS attack ever, what it is and what it could mean to you.
Third at bat the US pitches a plan for other countries to adopt a policy of no payments for ransomware.
Back at home plate we have the newest trend in malware; browser updates through infected websites. We tell you what to look out for so you don’t get hit by any foul balls.
At number five, and way out in left field is concern from one mathematician that the NSA might be fouling the mix of the latest encryption protocol.
Up in the bleachers at number six we have news on Open source project updates that might leave you wishing you had a better seat.
And finally we tell you how to strike out Instagram to keep it from tracking you across other websites.
This week all bases are loaded. Let’s go hit a home run!
Find the full transcript to this week's podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Episode 160. In this week’s IT Privacy and Security weekly update:
We start this week with a pause of remembrance to all those innocents caught up in the wars raging across the world. Often the highest price is paid by the most innocent.
October may be Cybersecurity month, but in the run-up to the holidays, we think it could also be “Call your grandparents month” too. Why? We have an eye opener from the FBI that may have you ringing your Grandmother as soon as you finish reading this.
Our second story to anyone at Amazon working remotely, “the gig’s up”.
Our third story gives us another reason to dislike having our photographs taken, with our fourth covering a little change that will keep our communications through one application safe for years.
Shockwaves from Cali in story five, and 23andMe unravelling our genetic secrets for our sixth update.
Finally we take a bite out of the line in one supercomputer’s greatest threat, and we hope it doesn’t give the cat any ideas.
Just like a strand of DNA, let’s go unravel these updates!
Find the full transcript to this podcast here
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we rip the lid off privacy starting with a story about a quiet plan in the UK to catch shoplifters that could end up stealing something critical from us all.
From there we share a story from LA where popular food delivery robots are delivering much more than your order.
Next on the slate is the Racketeer Influenced and Corrupt Organizations Act lawsuit against some names more familiar to your phone than organized crime.
Then we travel to Serbia where there is more evidence of an ingenious plan to map the world’s DNA, Taiwan’s help to rebuild Huawei, and why Air BNB is not afraid to be a party pooper.
We’re back with a hard look in the mirror and an caffeine enriched selection of IT Privacy and Security stories, so let’s hit this week’s adventure “Face first”!
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
We’d like to start by letting you know that we are taking our first pod-break in over 3 years. We’ll be heading up to the
highlands to ruminate before returning on the 3rd. of October.
It’s a perfect time to catch up on some of our previous pods
Thank you for joining in for the last 157 episodes and we look forward to serving up many more!
In this week’s IT Privacy and Security weekly update, episode 158 we have some really uncomfortable news about your new ride. You may want to sit
down for this story, but... just not in the car.
We follow that with another related update... but this one is a little closer to home. Running out of disk space and how that cost one
automobile company the loss in production of about 13,000 vehicles a day for at least a couple days.
From there we move to details of our familiar friends at Last Pass and what the backup breach might be costing former customers, and what you should do if you too used LastPass.
We have a new quota from the US Customs and border patrol that might have those leaving the US powdering their noses.
We finish with a couple of stories out of China that will have you doing a double take the next time you get a text on your phone and wondering why you ever complained about the “One” job you have.
And here is the best in IT Privacy and Security....
Find the full transcript to this podcast here
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week it's all about the party and the recovery.
We start with the NYPD flying into your party. And end with something that may make all sorts of survellience tech obsolete, for good or for bad.
We move onto a blinding new revelation from the UK government and an unexpected verdict out of Texas. From there we go phishing with GoDaddy and discover that some high costs to Germany turn out to be trending downward
We have more noise from Russia and what sounds like a very clever way to turn the volume way down.
We present a second perspective on web attestation and some pretty dumb security from a security company.
So before the hangover kicks in let’s go find out what’s happening in the world of IT Privacy and Security, because you have to fight for the right to...
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we have a terrific collection of stories for you along with some friendly reminders.
As we navigate the heavens we touch on 2FA, Social Media and Rust.
We get some interesting insight on the U.S. College Board that all high school students would mark as a “fail”.
We discover the perils of a familiar piece of conferencing software and a new initiative from the Taliban that has more than one Hijab tied in knots.
From there we learn about a new bot dispensing information that the credit bureaus are collecting on you, and an etiquette update to US Spies.
We finish, where else, but in Low Earth Orbit with a story that has quietly been getting louder.
This week’s update will make us all better Internet citizens and keep us all just a little bit safer.
So let’s kick it!
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Get your passport ready, because this week we ignore the Amalfi coast and head straight for the real action!
Out of Zurich we have news of Google and a new FIDO2, before heading off to Canada and a wild assertion for a bank there about targeting children's parents.
We present the QR code you knew would come, Tesla's insider dealing and how China leveraged Japan's porosity.
We bounce back to New York for the Time's latest headline story, and then discover what AI will really mean to your job in the next few years, and yes, that's probably coming from your boss, or her boss.
From Norway we discover a "funny" little Windows server feature, and from Kenya, more proof that the thing attempting to become the de facto world digital identity system for citizens of the globe has a hard time hearing.
This is the best traveled update yet.. so take those feet and let's get them in the street!
Find the full transcript to this podcast here.
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This update quite literally “flies” from one end of the globe to the other.
We’ve
got great updates for your teens out of Boston and Las Vegas, a great
primer on finding out what is in some of the privacy policies you are
signing off on and a sneaky bit of data collection coming from
chip-maker Intel.
We have the looming threat of what the UK’s
demand for unencrypted encrypted communications might mean for the
population and the new dance that Zoom is doing in regard to AI.
From
there we go to Detroit where AI that is notoriously poor at recognizing
people of color get a second set of eyes and then back to Las Vegas for
the prank that made no friends in Track Hall Four.
We may have some perversely good news about Capcha and we finish over the Pyramid Giza.
You
want it and we have it, even to the illumination of a sure secret to
success. Let’s go discover this week’s world of IT Security and Privacy!
Find the full transcript to this podcast here.
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week surprisingly starts with a couple of building maintenance callouts: one for a flashing X on the roof and the other for a rat in the kitchen.
We then feel the jolt of new, shorter breach reporting requirements and solve the mystery of what happened to your air miles.
Google confounds us
with a little more control over everything it is collecting on us,
while White Castle may be considering racing lanes for its drive-through
with its latest AI announcement.
We have every spy across the planet weighing in on what was line-of-sight for hackers during 2022, and an astonishingly easy fix for you to do now.
And we end with a cracking update from low Earth orbit.
You’re going to love this, so circle the world with us in our most awesomeupdate yet!
For a full transcript of this week's podcast click here
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we suggest new habits to improve your security and lengthen your life.
We
have a friendly update on what that Nigerian Prince who wanted to give
you money a few years back is up to now, and what he might be up to
shortly if he gets his hands on the latest batch of PHI to go missing.
The
US and EU are both keeping an eye on a curious new appetite from one
party for old chips, a new coin under the magnifying glass, and one
whole country back in the viewfinder.
We
have an update on why the Clear lines at the airport aren't quite as
quick as they were a year ago and we finish with a warning to UK drivers
about a new van that looks like a high-rise crane has crashed through
its roof, and why you might want to avoid it.
This week's update is all about living longer and traveling. Not a bad agenda. Let's book!
For a full transcript of this week's podcast click here
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we are smiling at some of the greatest stories to grace the headlines.
We
literally go from a launch to a cover up, but in between we have all
lovely gooey sticky filling that will keep you coming back to the cookie
jar.
There's an update from Google on your Gmail, that just
might be worth the privacy tradeoff (come on, they read all your mail
anyway), Now they additionally want to parse the sites you visit to see
if they are safe.... And while that is going on Apple slams the UK
government for its attempts to read all your communications too.
We
have a couple of really alarming AI stories that will twist your
thoughts on privacy into knots, A couple of patch updates that are
super-important for Apple and LINUX users and a simple idea that could
keep your Hyundai or Kia in your driveway.
This weeks' round up
might be the most important one yet for your own security and that of
the kids. So enough of this standing around smiling, let's get Updated!
Find the full transcript to the podcast here.
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
In this week’s update, we start and end on TikTok, but the bookends could not be more different.
We
have one of the most important updates on how you can protect your
family and friends from the latest AI scam that's already gone global.
Then we dance between more revelations from who’s viewing who, to one presenter who lost more than her TikTok audience.
There’s
a brazen story covering one law firm's efforts to stop Google from
hoovering up every piece of our data and presumably make some decent
money in the process.
We’ve got a new flow across the Atlantic and a brave soul who is duty-bound to put a stop to it.
Finally, we have the latest compromise, this one occurring during your Amazon package delivery.
It’s fresh as a kiss, it’s fun, it’s the IT Privacy and Security Weekly Update!
Find the full transcript for this podcast here.
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we have a prime serving of updates for you, we start with artificial intelligences' decline and end, frankly a little loopy, but you are sure to find a story in our global round up that makes a difference to your life, even if it is only to keep you from tripping.
We start with a mother's photo of her son and the upsetting news that he might have been created with AI. From there we move to the Philippines where a little too much about the police has gone public
We have a big win for Big tech's data transfers out of the EU and a sobering story data transfers after your trip to the local copy shop.
We have the former CEO of Theranos, "quietly" having updates made to a sentence that has to have the other inmates crying "Foul" and Tom Brady getting hit with something way worse than a quarterback sack.
We end the week tied up in Algorithms, and a secret that many had not discovered through their whole lives.
Now that we're primed, let's discover the best update yet!
For a full transcript of this podcast please go here
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
In this week’s update, we flutter from “ almost everything” to the butterfly effect.
In between those extremes, we find a little tit-for-tat going on between the US and China that could impact everything from your cloud compute to your phone.
We have facial recognition software being rejected by performers and embraced by you local shops.
From there the sad story of the CISO first attacked by a nation-state and then by the US government.
And finally, we have a story about some phone hacking software that itself got hacked.
It’s all here in a firecracker of a 4th of July edition of the IT Privacy and Security Weekly Update.
Find a full transcript of this podcast here.
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we start with a story that we’ve had to reread three times because it was just so unbelievable.
From there we move onto what you are doing with your phone that a small number of years ago used to take some pretty hefty specialized equipment.
We stick to phones in a global round up of details on another scheme to compromise you through it, advice from the Australian government as to what to do with it, and who’s going to court for selling data from it.
We discover a programmer who has just come up with a brilliant Chat GPT interface for an operating system that might be at the bottom of your mothers’ closet.
We finish off the week with another list of what Americans hate, and you might be surprised to see what’s topping it out.
There’s never a dull moment in the realms of IT privacy and security and this week is no exception so flip up your hoodie, grab your phone, start the camera app and let’s go!
Find the full transcript for this podcast at discuss.daml.com
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
We start with some serious dissing and end up dishing.
Between the start and end state, we get served up by Julia and rerouted by the Benz.
We learn about a new voicebox that we can’t have and get the perfect example of a self-licking ice cream cone.
We have new controls on what can be sold and to whom and a new way to use that screwdriver to unlock your Lenovo.
Finally, we have a group of Swiss farmers that think Apple has taken one bite too many.
This week’s update comes with a side of Julia, so let’s order up!
Find the full transcript of this podcast at Discuss.Daml.com
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
From the cool waters of the backyard pool to the chilling depths of cylindrical holes in the ground, this week’s stories will elevate your temperature to get you in that summertime mood.
We commute to work past a copycat chip shop and then get an update on why the unemployment rate for lobbyists is still at all-time lows in Washington DC.
We catch Microsoft being naughty, while Google and Apple go to the head of the class.
We find the US government flunking out with their latest budget spend, while one state that’s round on the ends and Hi in the middle makes the honors list.
Finally, we have a round-up of last year’s breach news from Verizon’s annual survey that should get us out of study hall early.
Up North, school’s almost out for Summer so grab your books and let’s go!
Find the full transcript to this podcast at Discuss.daml.com
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week’s exciting collection of stories takes us from the latest fashionable freeze to the warmth of a fuzzy paparazzo.
We have a “stand up, sit down, stand up” again revelation about our friends at TikTok that will leave you …well either sitting or standing… and a couple of Ai stories that describe the horse bolting from the stall and then what that horse did.
There’s a little relief for those in the US living within 100 air miles of the border and a story that will give you more reasons to brush your teeth than your dentist could come up with.
Finally, you get the world’s (is that even correct?) first hackathon in outer space and the prize money is out of this world!
Come on! Shake off those icicles and let’s warm up with the best adventure yet!
For a full transcript of this podcast head over to Discuss.daml.com
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we go from excess baggage to a face that is not our own.
We have a new scheme to establish what is real in a world where more and more is artificial, by someone we expect to be very prominent in both.
There’s a new declaration about social media that is eerily similar to the one from Santa Cruz California on June 3, 1956, when city authorities announced a total ban on rock and roll at public gatherings, calling rock and roll music “Detrimental to both the health and morals of our youth and community.”
We’ve got an update on PyPi and how they’d like anything they serve up to be in much smaller pieces.
We’ve got a couple more almost unbelievable TikTok stories and the latest trendy phone that might have you going back to baggy trousers with very large pockets for your next TikTok video.
Finally, we end with a tiny story about what just might be the largest invasion of privacy ever.
Forget the electron microscope and let’s jump on the scales!
For a full transcript of this week's podcast head over to Discuss.daml.com
Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week’s update starts with what some might see as a poke in the eye and could end with really poor enunciation.
We have Google intro’ing 8 new domains and getting caught in a .zip.
There’s a great story that might have you thinking that HP has moved into home construction when you hear about all the bricks it created over the past couple weeks.
We have evidence that the FBI emerged from the locker room dirty and the low down on the kingpin of scammer calls in the UK.
While that’s going on Meta’s been setting new records and the White House, one of the slowest moving objects in Washington D.C. just got in front of you.
And then we end with a couple of Silicon valley’s highest flyers, locked firmly in place.
This update is more colorful than a meadow full of Teletubbies, so come on, grab your Ray Bans and let’s go check out the action!
For the full transcript of this podcast go to Discuss.Daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
Up North here, it’s Springtime so we start with a deep breath of DNA and finish out of ink, we think!
Between here and there we sneeze as we bump into a couple of projects, one that sniffs out unencrypted LTE communication and another that sniffed out the contents of the phone you lost or had taken as evidence by the police.
We dab the tears of a former Bytedance executive as he makes allegations about the Chinese Communist Party “maintaining supreme access” to data, and Toyota who cleverly created an online portal that exposed driver’s data to anyone who looked for it, for a full 10 years!!
There is spluttering from New Zealand as we learn about the dangers of holding onto sensitive data for a little too long and a gasp as we find Google in the UK doing the same.
In the US, you might make an effort to make yourself presentable for the TSA as they will be taking your photograph at even more airports this summer (we name them all).
Whether it’s the cat or the high pollen count turning on that runny nose, just grab a tissue and join in for the latest update adventure!
For the full transcript to this podcast head over to Discuss.daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we start smart and end dumb. Potentially somewhat contrary to our other updates.
In between we might ultimately have a dumb way to protect a car, a dumb executive who got lucky, and a healthcare company that almost seems to be competing with T-Mobile for most breaches in 2023.
There’s a dumb plan by the EU to scan all your messages, and a smart move from Open AI to give you back some privacy.
We have the FBI going “gangsta” on DDoS as a service and a brilliant writeup of Russian malware that shines a light on the current world of espionage.
Then we share the brilliant announcement of a free alternative to CoPilot while Def Con announces they are taking aim at LLMs.
Whatever the caliber of the players, we’ve got the stories. You can make the call on the grades they get.
Come on, grab your marking pens, and let’s go!
Find the full transcript for this podcast at Discuss.Daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we get breached, we get in your head, we go all over the world and then we get a beat-down by the cat.
The world of brain scanning coupled with AI is already yielding some very interesting results and we take you into the ganglia of the action.
We learn a new stat for a nation-state face-off and frankly, the numbers look a little one-sided.
We discover the EU setting “mew” regulations for nineteen of the major tech players, while Italy invites one company back in through the cat flap from out in the cold.
Finally, a partnership between Apple and Google that we’ve been tracking, and an update for Windows 10 users whose machines might have ended up in the litter box
This is a wonderful mix of stories that make a beeline for the feline. So if you have allergies, grab your antihistamine, and let’s head off!
For the transcript to this week's podcast go to: Discuss.Daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week starts with frustrated police in Sweden and finishes in the back pocket of a legal team.
We move onto the troubling story of the US National guardsman who, now it transpires, leaked way more than all the toddlers at your child’s preschool, a beer story that is sure to have many of our readers in tears, and a drafty new naming scheme based on weather events.
We get great updates from WhatsApp and Google authenticator and more AI news than you can shake an API at!
Finally, we flag something rumbling in California related to privacy that could make large ripples in the data lakes of collected user information.
They’re global, they’re fresh and they’re flying, so let’s follow those flags!
Find the full transcript for this podcast at discuss.daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This update starts with the fortune cookie found in the back seat of what might just be the worlds top-selling car. Both have a surprise in store.
From there, we have a touching story of how the NYPD is re-adopting a dog called “Spot”.
We get an update on an ingenious bit of tomfoolery for Windows users with a new Chrome update and another reason why, if you need your transactions to be private, they shouldn’t be on a public blockchain.
There is some disturbing news from a “reliable source” related to social media and a new free tool from AWS that might kneecap a pay-to-play product from Microsoft.
Let’s get down, down to Chinatown to start this week’s adventure!
For the full transcript of this week's podcast go to Discuss.daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This update starts in the middle of Interstate 84 and ends with a possible answer as to what’s happening with the ghost orders for bottled water.
We hit the road with some car updates; from what might soon be missing from our cars to wait… where is the car?
Then we move on to phones, where the Federal Bureau of Investigation has a tip for you the next time you consider topping up at the airport, and Google reveals its plans to make your experience with applications a little bit cleaner going forward.
There’s even a battle brewing in a large US university as the students returned to classes and found the building wired for way more than just higher learning.
Road trips are always an adventure, and this update is no exception, so get comfy, buckle up, and let’s put the pedal to the metal.
For the full transcript to this podcast go to Discuss.Daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
For this update we start off with our feet solidly on the ground, buried under U.S. tax returns, before shaking it and finishing in outer space.
We learn when people discover that you are using NSO’s Pegasus spyware, you’ve got to go shopping for something even more secret.
Elon Musk gives us an opportunity to work for him for free while Mandiant divines how North Korea is paying for its latest set of rockets.
DarkTrace provides some sobering news about phishing that you should probably check out before you open any more emails, and then Western Digital backs up some malware and finds itself in the same trouble many of its users have already discovered.
It’s time to shake things up.
This week’s update branches off in more directions than a tree so why resist? Let’s shake it.
For a transcript of this weeks' podcast go to Discuss.daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we kick off in Canada and finish in Norway.
In between, we hear why the big push to ban TikTok from our phones may be less effective than we think.
We get the inside scoop of a malaise that’s hitting Google, Meta, and Amazon… and through them you.
There’s an update on the surveillance state that will keep you in the picture literally from your driveway to the 2024 Olympics in Paris.
We get news on leaky Ai and how much confidential data is being pushed into some of the online chatbots, and a way, perhaps, for that same Ai to redeem itself and help you through tough job interviews and even tougher dates.
We take you around the world twice in this week’s update, and then we deliver you looking sharp, crisply dressed, and fully informed.
Grab a packet and let’s go sow some seeds.
For the full transcript to this week's podcast please go to Discuss.daml.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/rps5/message
This week we start in the hacked offices of the US Government and end up being launched off a drone in Africa with a little parachute on our back.
In one country we have a government turning off wireless services to catch a perpetrator while in another country wireless service providers are the perpetrators!
We have a couple of TikTok updates and an official new bureau in China to mine data …for Economic Growth.
There’s another spyware-laden, wiretapped individual with a government denying everything and Amazon potentially in some fresh hot water.
Finally, we have a Twitter story about a ChatGPT adventure that is going viral in a way that only a get-rich-quick story could inspire.
Let’s cut it up!
Find the full transcript for this podcast at discuss.daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This week’s update zooms from the moon to your innermost thoughts.
We get an update on a shrinking Meta and our shrinking IQs.
From Washington DC we learn about probably the most perfect imperfect way to ensure that data protection laws are passed in the coming years.
We discover a steganographic breakthrough and an electrifying enzymatic discovery that could revolutionize IT Privacy, Security and the World as we know it.
Finally, we meet a new technology that could present the ultimate invasion of your privacy.
So put on your moon boots and let’s get walking.
Find the full transcript to this podcast at Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This week we start on page 7 and finish in with the chickens.
We get a little bit of activity from Zoom and a TL;DR for US President Biden’s new National Cybersecurity Strategy.
We have a story on AirB&Bs new “banned by association” program and the German government finally pulling the plug on one company’s networking equipment.
Then we have an update on the state of video surveillance and ended up surprising ourselves with what we found just outside our own office doors.
We close the update with a silly title and a somber realization.
Yes, it’s a real pot of soup this week. So as any good chef would advise, when you find yourself over the fire it’s time to start dishing out.
Let’s dish!
Find the full transcript to this podcast at Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
From Rosie the Robot to atomic restores… we’ve got you covered.
This week we walk out of the UK with Signal and break into our bank with something that’s not even ours.
We have good news for those on the witness protection program and a stupid update from LastPass.
We discover that the EU and Canada are packing up to leave the TikTok party and we visit LinkedIn as an attack vector.
We finish as all secure updates should, with an analogy that’s “da bomb”.
Like most things in life, you’ve got to test it out to be sure. So don your goggles, grab your procedures clipboard, and let’s get over to the testing site!
Find the full transcript of this podcast at Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This week we start in the “fresh produce” section and end up in an empty parking space.
For Valentine’s day, we heard that if you really wanted to show your love, you’d forget the dozen roses and hit the supermarket for a dozen eggs. This week we learn what the supermarket got out of that show of affection.
The Washington Post clears away some “myths” while Microsoft’s Bing offers up a new take on the world around it that’s most probably got Google breathing a sigh of relief.
We have a bold directive on privacy from the Australian government along with new and improved hacker tricks for bigger kicks.
We end with a couple of stories about making things disappear that could brighten your mood before that long walk home.
It’s all in our basket, so let’s jump in!
For a full transcript of this podcast head over to Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
For this special Valentine’s day edition, we have a couple of golden heartfelt stories at opposite ends of the gift-giving spectrum.
We have an update on a final breakup that seems to have dragged on and on.
There is some insight into how North Korea funds its cyber attacks, and seemingly everything else going on in the Democratic People’s Republic of Korea.
We have a couple of stories on the gathering and distributing of your personal data that might make you see red…
And finally, a red roses poem, written by a special contributor.
Love is all around. Let’s go find it!
For the full transcript to this podcast go to Discuss.daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
Lie down and relax. This week you might need the couch as our readings take you from therapy notes to privacy policies.
We have Microsoft burrowing into your computer to find out what version of its software you might be running, and Google serving up addresses you want to avoid.
We get a curious question about the Kremlin’s knowledge of what is passing through a “secure messaging system” and a bit of research that might have you reconsider the cheap Chinese phone with the great camera you had your eye on… and why it may not be such a great deal after all.
There’s an attack on a Swiss University, a breach of US police information (again), and a company that lied and is now making a full confession.
You get it all on this therapist’s couch, so put your feet up, make yourself comfortable, and let’s get this week’s session started!
For a full transcript of this week's podcast go to Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This is probably one of the most entertaining updates yet, so join us as we take you from the coolest ride to the hottest trend in outsmarting AI CCTV cameras.
And then, apparently we have some bad news if you are Austrian, Italian, Dutch or Columbian.
We go on to “reasons to be cheerful part 3” with a great LINUX distro that will take care of your updates for years!
From the US Government another shameful shaming to after an investigation remoting into machines proves far too successful.
We close out the week with cameras: How many are pointed at us, how to pose for them, and how to avoid them.
This “boxed” edition of the IT Privacy and Security Weekly Update is already a hit, so grab those hand wraps, put on your headgear, and let’s jump into the ring.
For a full transcript of this podcast go to Discuss.daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This week we start with a chimp and end closer to doom.
Between those two completely unrelated bookends, we get news from phone, security, and payments companies that they let a different animal out of the bag.
There is some potentially good news with ransomware payments falling across the world and the Supreme court allowing the anonymous defense of section 230.
We have updates from Google and Meta but then get booted out of the airport.
This week’s update is faster-paced than an action movie … and comes with better animal sidekicks too… so let’s get to it!
Find the full transcript to this podcast at discuss.daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This week we start with phones and end up phishing... only to discover that neither are “F” words.
We sweep from the Netherlands to Canada, China, the U.S., Iran, and Switzerland this week as we get the “up high” and “low down” on everything from Quantum computing to stupid passwords.
We’ve got AI chatbots on the verge of harassment, and another breach involving a password manager.
We get reminded again why it’s best not to try and reinvent the wheel and what Google thinks could potentially brick the Internet.
It’s all here waiting to be discovered, so grab a trowel, load on some mortar, and let’s go do some repointing!
Find the full transcript for this week's podcast at Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This week we exercise all your senses: from sound and vision to …smell.
We have car stories worthy of serious rubbernecking with almost no brand of automobile left out.
There’s the NYC school district where teachers have fallen behind the kids in educating themselves.
We’re served an update on the quietest tech rollout the fast food industry has probably ever cooked up.
And then we get a load of privacy stories that may have you wondering where the technology and privacy divergence will leave humanity.
Finally we end with a couple of products from last week’s Las Vegas Consumer Electronics Show that frankly, “stink”. nosewithclothespeg
Yes, there may be a foulness in the air, but the adventure promises to be the best yet, so grab a clothespin, apply it to your nose, take a deep breath and “Let’s go!”
For a full transcript of this podcast go to Discuss.daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
Welcome to year 4 and The IT Privacy and Security Weekly update Buzz for the week ending January 3rd., 2023
This week we go from cookies and keys to bees.
We have stories that fly from hardware to… hard-to-secure and even one for the… hard of hearing.
Then there’s the latest hive of activity directed at a particular group of foreign exchange students, along with who’s been stung by more privacy fines.
2023 makes a beeline right out of the gate, and we don’t mean to wax lyrical but the stories flow like nectar.
So grab your Tyvek suit, your veil, and let’s join the swarm!
For a full transcript of this podcast go to discuss.daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This latest IT Privacy and Security update will keep you right in the heart of things… from airport travel to petrol scams.
There’s a state-of-play update on TikTok, sad Twitter news for Elon, and even sadder Facebook news for the Zuck.
We’ve got a couple of urgent updates for Linux and Windows users sprinkled in amidst new malware that has nothing to do with Al Pacino.
We even have a touching holiday note from Eufy who will assure you that they are still collecting the facts, while the whole west coast is tuned into the feed coming off your “Secure” security camera.
Thanks for joining us for the final edition of the ITP&SWU of our third year.
Happy Holidays, Happy new year and let’s get Go!
For a full transcript of this podcast head over to Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
In perhaps our juiciest update yet we sink our taste buds into this week’s Holiday cornucopia of flavors.
From the North Pole to the South, but mostly in the US, we have a great new way for Santa to check on the condition of his elves, lots of coal to deliver, and one city that might not even make the delivery logistics planning list this year.
In the US the Feds are regaling hackers with copious quantities of gifts this year, while the UK goes full Green, Grinching on those nice people who share their Netflix account details with half the neighborhood.
Michael Dell and crew whip up the closest thing to a Lego snap-together endpoint we’ve ever heard of but stop short of sharing the tech so that everything that breaks could be mended as easily.
And finally, we suggest that the Missing Cryptoqueen might have had plastic surgery and be working with S Claus. How else would he be financing gifting for 8 billion of us globally?
This week’s Update may raise more questions than it answers, and sometimes it works that way. Grab those snowshoes, let’s go Arctic* and get to the bottom of what’s going on up top!
*Backstory: ‘Arctic’ comes from the Greek word ‘arktos’, meaning ‘bear’ – the northern polar region is the sacred land of the polar bear.
For the full Transcript of this week's podcast please go to Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
In perhaps our brightest update yet, we leap from the uninvited into bright, radiant light.
We travel from a somewhat naughty confederation to a blazing anonymous number migration.
We receive creative illumination for making deepfakes the “right way” from a group we didn’t even realize was in the film production business.
We’ve got Microsoft aglow in a buying spree and then illuminate you with so many glaring phone tales that you could be forgiven for lighting up your next call to your mother on a tin can and a piece of string.
Finally, we couldn’t resist one more update on that blinding crash down on the sunny shores of the Bahamas.
We have a dazzling update for you this week, so grab those Ray-Bans, and let’s beam!
Find the full transcript to this podcast at discuss.daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
Heavens to Betsey! This week we start with liars and end in a Pepsi Cola loading bay.
We discover stuff under our desks, new ways to get into pictures at the airport, and something unexpected flying over our heads.
We discover the extent of Telegram’s much-touted privacy even as we give up our own for the sake of a sharper picture and a few more channels.
Tim Cook’s team share how an iPhone can save you lugging around a heavy tape measure and then we glean some insight on the balancing act of one country’s Zero tolerance Covid-19 budget … potentially paid for by another county’s Covid -19 funding.
We have a couple more breaches and then Australia’s plan to prevent companies from losing our data … by driving them into bankruptcy.
It’s all here, but the truck’s out back. Race you!
For the full transcript of this podcast please go to Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This week you might be forgiven for laughing at some of the coverage until you realize how close it hits to home.
We start with an issue reported back in 2020 that got no response, but could be set to beat the third-largest fine issued so far under GDPR (both to the same company), and end with something done in the name of security so curious, you’ll have to decide what to call it.
From there we pull the covers off a TikTok-related scam that gets its hands on something more tangible than an #invisiblefilter and a popular new app that has unseated TikTok as the most downloaded where it is available.
We have an update on Amazon from the most unlikely of sources, a slap in the chops for Microsoft, and the kneecapping that Apple gave the protesters in China recently.
Some of this week’s update is just really dumb and we are not making excuses. Grab a pipe wrench, and some hot water, and let’s try to figure it out.
For a full transcript of this podcast please go to Discuss.Daml.com
--- Send in a voice message: https://anchor.fm/rps5/message
This week we hand you the remote so you can explore the latest in what you need to know about IT privacy and security.
We start with an unexpected success story and end possibly with fewer Euros in our pockets.
We have some incredible updates on China’s creative use of the Internet, the weaponization of a familiar app., and a well-known red teaming tool to test company security that’s probably the worst thing you could ever do to improve security.
There are some surprising new finds from the Apple camp and a couple of Meta stories that shouldn’t come as surprises but might still leave you a bit more anxious at tax time.
We round out with the latest from Elon and something that will make you feel good about that teen with the phone glued to the end of their nose.
Here, every station is playing favorites, so hold onto that remote, limber up your thumb and let’s channel surf!
Find the full transcript to this podcast at Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
Presenting a special birthday round-up for you today. From a new law in Italia that will ban facial recognition until the rules surrounding it catch up, to the birth of a new baby who just might grow up to be president!
We have some great spy thriller/forensic analysis stories for you this week that will be either reassuring or … very disconcerting in their discoveries!
We move “down under” to get a better understanding as to why you don’t push around our Australian friends and then hit the northern hemisphere to hear about one of the larger tech firms taking a beat-down from 40 US States.
This week’s update is like a high-speed chase. Better blow out the candles on the cake before something runs into it.
Oh, and don’t forget to make a wish!
Find the full transcript for this podcast at Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we have a refreshing break for anyone in the US who has been bludgeoned with non-stop Political ads for the last two weeks. (These ads are everywhere, TV, the sides of buses, the Internet, radio, and even people’s front lawns.)
For our fresh “forget the election” update we start with a “You could not make this up” story again about TikTok, now changing their EU privacy policy to let all in the EU know that their data is actually going to China.
We move on to a story about plagiarism by AI, scanning of devices, scanning of faces, and a new audience for New York neighborhood cams.
In the name of efficiency, we have smartwatches in meat factories, and a new app that you can load on your computer to index what you did and said for weeks at a time.
We have the Red Cross trying to figure out a flag to wave in the world of digital warfare amidst some interesting new malware delivery mechanisms.
Finally, we end with what may be the most practical use of AI of all time: writing wedding gift thank you letters.
By the time you get to the end of this update, you’ll be in the know, refreshed, and maybe even ready for the next 4 months of U.S. election recounts!
Find the transcript for this podcast at: Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start down the road of your data collection and discover ways and places it’s being shared that you might never have suspected.
Next, we learn who’s included in the hubbub about ransomware and what the ransomware baddies are doing to build greater efficiencies into their exploits.
From there we move on to companies with more leaks than a wicker canoe, a submarine screendoor, or a porcupine’s raincoat.
We have a great story about how one company has finally made it to the top, and how sometimes it’s not as great as it’s made out to be.
We end with a warm and cuddly way to go invisible and perhaps the perfect holiday gift for those in the Northern hemisphere.
Layer up and let’s go have an adventure!
Find the full transcript to this podcast at: Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
For this update, it’s all digits to hand. We go from Japan and Iran to Prime deliveries from a van.
Allegations of TikTok’s Chinese monitor, e-mail proof that Parler shares monikers while France fines an unrepentant photograph chronicler.
We have programming language standings, new Australian fines landing and the malware that Qatar is demanding.
And if that bad rap came through clear, we promise it only gets better from here.
Find the full transcript of this podcast at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start in the air and end in the air, with not a care while we are there.
We get an update on “Baby Al Capone” who got done for hacking a phone, how your drone might give up your home, a new Turkish law that gets basted, and a card shark who’s wasted.
We have Shein getting the boot, hackers for hire facing a suit, a duck update for your next reboot and new AI that identifies a woodland hoot.
So put away that squirrel suit, don’t head for the roof, you’re safe with this update, and here is the proof!
Find the full transcript to this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
James Bond, Mata Hari, and Papa John?
This week we look into what today’s liars and spies are up to; from fishing to card sharks, wiretaps to deauthers, stolen keys to firewall upgrades.
And in the face of that, we are presented with an Operating System that is bundling higher security and application updates and … supporting it all for 10 years. Publicity stunt? Maybe, but it got our attention!
Finally if clutching your wallet and your phone as you hit that last 76-meter drop on Tarragona Spain’s “Shambhala” roller coaster, you notice the emergency medical services waiting at the bottom, it may have less to do with the person next to you who blacked out and more to do with your latest toy.
Mata Hari’s got nothing on you. Quick, jump into the Aston Martin, and let’s roll!
Find the full transcript to this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
Wooly Mammoth or Ferrari? One’s sprung a leak and the other could feature in the next chapter of a spy novel.
It’s not Ke$ha, but Tik Tok following us around these days, as Amazon hits the front page for providing cloud services to a couple of companies better avoided and the NYPD goes dark.
If you hate picking the boxes with the “buses and crosswalks” we could have some very good news for you, while for school kids in LA it’s time to learn Russian, and for one celeb… basic addition and subtraction.
Good or bad, old or new, prehistoric or cutting edge, numeric or pneumatic, if it’s within the realm of IT Privacy and Security we’ve got the best of it in the best update yet.
So grab a spanner, a butterfly net, and a calculator, and let’s see what we can track down!
For a full transcript of this week's podcast head to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we are practicing a security technique introduced to us years ago while working with Scotland Yard. “Air Gapping” You can’t get hacked if you are air gapped.
So while we are off gapping we update you on a great way not to suffer from MFA fatigue.
Then we discover after lots of arm flapping by the US authorities about the Russians and Chinese doing this…they’re doing it too
We fly across to a popular new pastime that is causing more things to disappear than Harry Houdini did in his prime!
And finally there are fingerprints all over a fresh Chrome story and a handful of facts that could have a major impact on your selection at the app store!
Let’s make it happen, and go air gapping!
Find the full transcript for this podcast at https://Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start out fine but falter somewhat when we hear how many healthcare facilities have been breached in the first six months of 2022.
Spirits lift with an Uber joke and the reassurance that if you lose your phone but are one of ten thousand lucky travelers across, around, and near, US borders each year, Uncle Sam might just have a full backup of it.
We hear how one guy who ran a farm has become a victim to hackers, and this time we hope he suffers a good crop rotation.
There is a new data protection bill from the world’s fourth largest country… And we’re betting you can’t guess its name.
Finally we end up asleep. Dare we say that for new parents this calculated bit of privacy might just be the best algorithm we’ve ever shared?
Keep it on the down low, but “Ooooh Baby” have we got an IT Privacy and Security Weekly Update for you!
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
From Tweets to Whistles we’re here to make some noise.
You get the latest from Washington DC on “what it has, where it lives or where it came from” and why the U.S. Navy can’t say anything more about UFOs.
We serve you a fix that really whacks and a new telecom project that will leave you looking at your phone like it’s a tin can with a piece of string attached.
You’ll be amazed by the magic of Meta with two completely different types of disappearances and one appearance.
Then there is the letter to the US Federal Trade Commission begging them not to let Amazon buy your vacuum cleaner company.
Finally, we end with why that long commute to planet WASP-39b might not be such a good idea after all.
You want it? We got it. Come get it! Oh, and then there is Brad.
For a full transcript of this week's podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
From the Depths of the Dark Web to the summit of Mount Everest, we have you covered.
In this update, we have a creative idea for what to do with the rellies for the holidays, where the commute may be long but the privacy superb.
We have a sensational story of TikTok actually telling the truth and another of Irish authorities objecting to Instagram/Meta business accounts for 13-year-olds.
We have a pretty firm reason not to stay at a particular hotelier and why you should be a little suspicious of all the beautiful people who just adore Russian soldiers.
We have our first NFT story out of Afghanistan, and our second out of your TV set.
This week’s update moves faster than USB4, so let’s plug in and go!
For a full transcript of this week's podcast please head to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
From outer space to inner space and a few rotations in between, we spin you right round.
Space may be “Where No Man Has Gone Before”, but one woman has and will again.
We discover why you are less likely to be locked in a compartment and blasted with targeted ads during your next train ride to Delhi and what Google will track while you are on the tracks.
We learn about all the cameras you can buy access to in China, and then we see the full database of photos in the second largest data exposure in China.
We have the FTC getting tough on data brokers and a Judge getting tough on Elon and the punch-weary Twitter.
We suggest a new way to send untracked e-mail and learn the EU’s complaining that Google is swapping out other junk mail for their own.
And finally, we get a story about upcoming phones that will be better, faster, and never lose a connection, like the one you left in the back of the taxi.
We’ll spin you right round… like a record.
For a full transcript of this week's podcast go to Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start with a tweet and end with a rap.
In between those bookends, we have a sick kid, now healthy, a father who may never recover, a great site to see what the apps on your phone might be up to, and a new champion in the fight for our attention.
We have the latest in “secure” smartphones that could end up sounding exactly the opposite by the time you get to the end of our coverage, and a pending court case alleging that Oracle has leapfrogged Facebook in the race to collect everything on everyone, everywhere.
We’ve got another car story that sounds so dumb, it’s got to be smart, and a new way to get around the Vegas strip.
Just about the only thing missing is something credit card-sized you can tuck into your wallet or bag so that they never end up lost…… Wait, yes we have that too.
Well then, it certainly looks like we have it all. Let’s have at it!
Find the full transcript for this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week is at least our 100th show and to celebrate, we start in the underwear drawer and end up on the floor in one of the cutest stories about the effects of honey that we have ever seen.
We learn about a new hack that reveals the deep secrets of Dishy McFlatFace, and why Zoom took you out for your first meeting with your boss yesterday.
There’s an announcement about Amazon’s new comedy show made from Ring doorbell clips, yet nothing about what happened to all the compromising recordings Alexa made of you over the last few years.
We have bans on video players, chips, and even a whole smart city.
Finally, we get to the root of rooting the combine-harvester you’ve had sitting out in the barn for the last two seasons because you could not drive it to the service center.
No stone is left unturned, no seed left unplanted, no crop left un-rotated and no mind left unfertilized, with this week’s harvest of stories.
So grab your pitchfork and follow us!
For a full transcript of this podcast go to Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
From outer space to time travel: this week it’s “All systems go!”
We find ourselves in the cow flower and then get “compromised by” Twitter, Slack, and Twilio.
We find the legal detail in the class action lawsuit behind the company which must have one of the worst ads on US television right now.
We discover a couple of new players in the phone security arena and perhaps come away with some ideas for holiday gifts (they say you can’t start too soon).
This week’s update is unquestionably the best one yet so grab that hat and let’s go!
For a full transcript of this week's podcast go to Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
Get out the passport because you’ll need it for a range of stories that circle the globe.
We start with an icon and end with an algorithm, and in between, we’ve got one of the best updates yet.
From data sharing between governments to Meta/Facebooks’ latest debacle, you could find our story on camo might be the only thing left to hide behind.
There’s a shocking story for new parents in the US state of New Jersey, and yes, one more revelation about the NSO groups’ software that cuts very close to home for our European audience.
We even have a superb story that calls out one of the hidden benefits of liberally buying your teenager pizza… from a mother that might be contemplating just that for a very long time.
So take your glasses off, pull your hair back behind your left ear, look straight at the camera and relax your shoulders because this week’s update is pretty as a picture!
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we share a pungent selection from the most excellent landfill of stories yet.
We start our noisome journey literally in the dump and end up staring at a set of salad tongs.
We have a familiar cast of characters representing slightly different fragrance lines: Zuck, Elon, Blake, and even the devil himself may be found to guff in this one.
There’s the effluvium at KMart, new detritus for Ohio, and why even Google is starting to sniff at the bitter waft of the TikTok algorithm.
We tell you what trumpery to expect when you next get phished and if you are one of the tens of thousands laid off in the latest round of tech cuts, what you might want to consider for your next less malodorous gig.
Yes, it may be less than aromatic, but this week’s update will leave you with a smile like a Welsh crypto-Millionaire!
Come on! Pull up the waders, put the clothes peg on your nose, grab a pair of rubber gloves and let’s get mucky.
Find the full transcript of this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we use all our senses as we move from our ears, with Mark Zuckerberg’s lilting voice and constant backing tracking, to talk of a frozen backside during one of the biggest heatwaves ever to hit the northern hemisphere.
We learn that our eyes may never see the million-page novel censored by an online document service, and smell a rat as a former CIA agent gets the opportunity to feel the solitude of a jail cell.
We get a taste of what the dept. of Homeland Security are up to, yet are comforted that a sister agency has kept at least one hospital healthy and well.
We touch on the best IT Privacy and Security stories this week and if they leave you hot and sweaty, it could be global warming, but more likely it’s the content!
Faces forward, deep inhale, let’s go!
Find the full transcript of this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We go drifting in the Honda this week with stories ranging from AI writing its own autobiography to why our Anom phone bill was so high.
In between we have lots of car stories: Some of them might have you in tears, so grab a tissue.
We accelerate from beans to Titans and then hit the brakes when we discover another instance of those collecting everything on everyone leaving it all out on the starting line.
We hit a hairpin turn with an up-and-coming U.S. politician who’s proposing to create jobs by wrecking car things.
Then we have a police data raid in India that could put some of us in the pits.
This podcast may not be a Ferrari, but we’ve still got some very good lines.
Buckle up. Let’s drift.
For the full transcript of this podcast drive over to https://discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This update moves IT Privacy and Security from your next meal to a trip around the salad bar at least a couple of times.
We work our way from an unlikely garden and a Raspberry Robin out to the OpenSea. We discover many, unappetizing ways for our data to be lost, stolen, or sold.
Then… sprinkling a little bit of insight into how police use our search data and what is being proposed in the garden state of California that would wipe out any sort of browsing anonymity … completely.
You get some reassurance in your “sage” thoughts about that co-worker you’ve never actually seen or heard from and finally, you see how many people have blossomed since we put this piece together.
There’s plenty of calm in this week’s update, but there is lots of tossing around too.
For a full transcript of this week's podcast head to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
For this update, we start with a bit of binge drinking and end up in hot water.
We jet from the NSA’s advice for Windows admins to T-Mobile’s new scheme to sell your data to advertisers.
We hit the impeller fizzling and bubbling once we discover the extent of different kinds of data China is collecting on its own population.
We get a soaking from a new piece of spyware turning up on phones that for once did not come from our friends at the NSO group.
And we ready the leak-sealant after learning about those “innocuous” little applications that too many parents “must’ put on their phones to get updates on their pre-schoolers.
This week’s whirlpool of an update is all good clean fun, so leave your water shoes by the door, and let’s jump in. This one is hot!
Find the full transcript for this week's podcast at Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we chase up stories from around the globe from inner to outer space. We surmise that if some countries’ plans to harvest solar energy are successful it might just induce your rellies to forget about you.
We let you in on a little million-dollar lost wager and a new student movement to get you to log off.
We finish with a sad story about a little fox, that’s getting smaller by the day and our valiant call to re-install.
OK, gang, once those downloads are complete, log off, resist the tweet, and we’ll hit the street for our weekly ITP&SWU treat!
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we go from Paparazzi to Cookie jars, with an ear to our phones, an eye on those supercomputers and plugs and bugs in our PCs.
We have cool new functionality in Chrome and Firefox and (finally) a retirement party for IE.
We learn how the FBI is helping millions of Americans avoid an identity crisis, we get an unexpected “Les Mis.” book review and a “no bets” policy for an upcoming trial.
This week’s mashup is “mad as a box of frogs” so let’s rip the lid off and have some fun!
For the full transcript of this week's podcast go to Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week is all about food, travel, and adventure, where we start abandoned at the altar and end with bizarrely overweight baggage.
In between those carefully seasoned toasted sesame seed buns of IT Privacy and Security are a flame-broiled update that shared too much, got shut down, and hacked, a tangy slice of database encryption, a leafy new mobile phone OS, and a large dollop of savory lawsuit.
It’s a meal made in heaven, worthy of a Michelin 3-star rating served hot and fresh off the grill.
So grab your bags, tuck that serviette under your chin and mind your manners as we experience the best IT Privacy and Security Update yet!
For a full transcript of this podcast go to Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
With a backing track that is probably the worst cover version we have ever heard, we learn what just flew past that bedroom window.
In the US this week the focus has been on our children. Any way you look at it, from school shootings to privacy violations, to destroying the ecological balance of the world we are leaving them to live in, the only way you can describe societies’ actions is broad-scale child abuse.
We learn what political leaders already know, “if you don’t like the news, just turn off the Internet.” We have an update for Elon from Twitter, a warning from the Indian government that came 13 years late, and a petition to stop apps from accepting the Digital Yuan… for reasons that would surprise you.
We typically start the weekly update with a rush of excitement. This week let’s stop for a moment and think of the kids.
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we learn why modern romantics sing: “If you like it, then you shoulda put 2FA on it”
Yeah, and we go from Bridal veils to white hats and mistaken nails. From Crypto to klepto to dummo and UFO.
We even end with an exploding duck.
What other blog/podcast gives you that kind of range in a wonderful mix of IT Privacy and Security Updates?
None. Zip. Nada.
So whether you put on a tux, a bridal gown, or nothing at all, at least slip into some comfortable shoes, ‘cause we’re on a run through some amazing stories!
For a full transcript of the ipodcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week in our smash and grab we go from phones to fake followers and end up with a blog writer in tears.
We gain a little insight into just how relaxed some US Government officials are with the data of private citizens.
Then we wave, we get grabbed, we patch, and we secure.
Why… heavens to Betsey! This sounds like the makings of the best IT Privacy and Security Weekly update yet!
Let’s pull up our socks, lace our running shoes, and see what we can unravel before we try and find that elusive back a door!
For a full transcript of this week's podcast go to Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
From the blustery cold volcanic slopes of Iceland to the Freeze you put on Equifax, this week’s update may drop local temps. by several degrees.
We apply the heat by moving through downed satellite relays, Vodka DDoS attacks, and the weaponization of Windows event logs.
From there we discover the newest US surveillance agency and the latest arms race. Finally, there is the gravitational pull toward the privacy of outer space, and even that is coming into sharper focus.
Throw on that jacket, grab a scarf, and let’s prep for a sudden chill with the latest (and greatest) IT Privacy and Security Weekly Update adventure!
Find the full transcript for this week's podcast at Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start with flying bananas(?), before traveling through Spain, China, Russia, Nigeria, and Austria to get a visual carbohydrate count.
We consider the secure tweet, break and break into more phones, set new attack records, and nick a few scientists.
We find China hacking Europe, the US and UK hacking Russia, Russia hacking Ukraine, and someone hacking Spain.
…then we end with a quote of the week that only a mother could love.
This is the BITPASWU (Best Information Technology Privacy and Security Weekly Update) yet, so grab your friends and let’s FAF (Focus, Act, and Follow-Through)!
Find the full transcript for this podcast (with all mentioned links) at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
You may gain a couple of kilos in this week’s IT Privacy and Security Weekly Update, but we promise it’s got some of the tastiest content yet!
We start with what may become the latest rage in M.I.T. degrees and finish with a whisper.
In between we find a good reason to organize cold storage, we lose our monkeys, and then as we search for sponges, discover a 2000-year-old computer.
Then we see the ripples of a schoolchildren’s data breach grow into waves, learn the cost of Zoom Bombing, and get a surprise when we find out who is writing the most code for the new Linux kernel.
This is the most calorific update yet, so let’s start in the creamy center and work our way to the edges!
For a full transcript of this podcast go to Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
We start with another case of house arrest and end up where? Having our DNA broadcast to Martians (and we don’t mean those who have saved a hundred grand to fly with Elon).
In between, we have our moods checked by AI, we, along with 2999 others, end up with tummy aches, we take apart a high-end piece of Russian drone technology and we get a court decision on data scraping that could have repercussions across the world.
This is house arrest, in the best IT Privacy and Security update yet, come but wear your Sunday best!
For a full transcript of this podcast head to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start in traffic and end in traffic. Most is ground-bound but we have been known to flit into low Earth Orbit when our speeds are high enough.
From between those bollards, we discover more nighttime glitter, more acronym definitions, and the need for higher quant resistance in our crypto.
Still hungry? Our Pi and REDSPICE stories will give you something to chew on, while new Crypto tracking sites have turned moving stolen crypto into a real meal.
For now, put your sandwich aside, adjust your seat, check the mirror, buckle up, and let’s put the pedal to the metal!
For the full transcript of this podcast with all mentioned links please go to Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we fly from an apiary to a cuddly puppy.
But all is not as it seems: We triple peak before a bout of melancholy and find an unwelcome foe back after a “short break”.
We have lawsuits, legal requests, and cameras all divulging way more than they should. We sequence the missing 8% and finally, we have a couple of lists that will turn you into such a security guru that you might be writing this update next week.
Then we end with possibly the best reason to own a cat.
You are going to love this week’s IT privacy and Security Weekly Update, it is simply the best one yet!
Grab your veil and gloves, pull up your socks, and let’s have an adventure!
Find the full transcript for this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
Ooh… this week we start with rich creamy chocolate and end with a little smile.
In between those pleasurable bookends, we get an update on the Lapsus$ soap opera before the movie rights are sold to Hollywood.
We learn about printers being hacked to spread the news, and the astounding number and diversity of attacks on communications across Ukraine.
We get an update on a tech exodus and a new targeted ad campaign from the FBI.
Finally, there’s a new “adopt an FSB agent program” with glittering tips on how you can find your own.
This is the best IT Privacy and Security weekly update yet. Let’s roll! Swiss roll!
For a complete transcript of this podcast head to discuss.daml.com
oh... and the jokes...
What did the moderator say to kick off the IT speed dating session?
“Singles, sign on!”
What do you call a turtle that surfs the dark web?
A TOR-toise
What do you call an excavated pyramid
Unencrypted.
If girls are made of sugar, spice, and everything nice, and boys are made of slime, snails, and puppy-dog tails, what’s the cloud made from?
Linux servers, mostly.
What do you call a group of math and science geeks at a party?
Social engineers.
What’s the best way to catch a runaway robot?
Use a botnet.
Why did the programmer leave the camping trip early?
There were too many bugs.
What do you tell a hacker after a bad breakup?
There are plenty of phish in the sea!
Did you hear about the computer that kept rebooting?
It was terminal.
Why did the band never get a gig?
It was called 1023MB.
and finally…
One day, I started to whisper, so my wife asked me why I was whispering, I told her I didn’t want Mark Zuckerberg to hear us.
I laughed.
My wife laughed.
Alexa laughed.
Siri laughed....
Send in a voice message: https://anchor.fm/rps5/message
This week we dance from Taylor Swift to Arkady Volozh or probably more correctly, from New York to Moscow.
We learn about over-reactions at NPM, Facebook, and Microsoft. We share some amazing visuals from NASA, that once you see, you can never unsee, and find the US government reminding each and every one of us that the Ukraine war is now at our door.
Finally, we learn about the Securities and Exchange Commission (SEC) in the US considering the incorporation of climate risk into financial risk.
This is an action-packed update, hotter than ever, so leave your coats behind, slip on some comfy shoes and let’s start our journey in the newest class on the syllabus….
For the full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we zoom from your face to space, dodging flying objects as we go.
We learn a bit more about Putin’s pre-war prep and its effect on Google and Apple. We discover a new website that helps us deliver a text to one of the millions of Russian citizens who may not have access to different perspectives on the Ukraine invasion.
We see an amazing data collection mapped to within 150 meters of where it happened, the issuance of new DNS certs and the quick sprint of the ruble into crypto.
We discover a new computer virus and get rid of an old computer anti-virus.
Then we get yet another lesson on why password hygiene is so important from one of the most unlikely sources yet.
This is definitely the best IT Privacy and Security Weekly update yet, so grab your butterfly nets and let’s see what we can clear out of low Earth orbit.
Send in a voice message: https://anchor.fm/rps5/message
We start by tipping our hats in respect to all those valiantly fighting for democracy in Ukraine.
Then we go on an adventure. This one’s going to get our feet dirty. First with a new use for artificial intelligence, and then while we award Apple a “fail” on the very day it launches its latest raft of products.
We unearth why 9 women might be the right number for the US supreme court on International Women’s Day.
…And then get muddied with an update on the rather unique ransom demands being made of NVIDIA before dishing the dirt on the latest timings for cracking your password.
And at least for this adventure, we have a happy ending.
It’s all part of good discovery, so grab a shovel and let’s get digging!
Find the full transcript for this podcast at: discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
Before we start this week’s update it’s important to acknowledge what is going on in the world around us. There is a physical war involving the attack on Ukraine where the courage and the stamina of the people have engendered new levels of respect and awe, and there is a cyberwar.
Both at the direction of one individual.
Every single inhabitant on this planet will pay for his decision. Some will lose their homes, others their retirement savings, some will pay more for food and fuel, and some will pay the ultimate sacrifice.
Where ever you are in the world, if you can help, please do help.
In the best IT Privacy and Security Weekly Update yet we start by covering current events, before lifting the lid on your home router, going underground (literally), and then finishing high above the Earth.
Let’s start our journey.
Find the full transcript to this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we discover 15 boxes, a number one app., and end up at the back end of the car.
With high compression pistons and rack and pinion steering stabilizing our high adhesion slicks, we roll through a billion faces, pound on Taiwanese bank doors, steal some NFTs, experience Man City in 3D, and come to understand why you should never use pixelation to hide behind when you track a Magpie.
Join us through the hairpin turns as we go flag to flag on a racing line through this week’s superspeedway of stories.
Let’s don that Nomex, check our earpiece accelerometers, flip down our visors, and hit the tarmac!
Find the full transcript of this podcast at discuss.daml.com
“What’s behind you doesn’t matter.” – Enzo Ferrari
Send in a voice message: https://anchor.fm/rps5/message
This week we start and end with Gu in an unabashed attempt to have this update returned in at least fifteen million search queries.
In between the Gu at the beginning and the end, we Freeski through TikTok, pull a reverse 1440 to strange noises from cars, do a left side 1080 for Facebook, before ending with a double cork 1620 with a safety grab.
Yes, this is the greatest IT Privacy and Security update yet, and yes, we have all the freshest stories and tricks for you from this winter’s games.
Oh, and by the way, that’s Eileen Gu on the ivories. Her mum filmed her on the piano while they waited for a flight in the departure gate at the airport. You couldn’t make this up.
So, skis waxed, goggles on, boots fastened, poles back, ready, set, go!
For a full transcript of this podcast please go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we discover where stolen crypto and discarded fishing nets end up and we’re pretty sure you will be surprised by both.
We then swim from vigilantes, newspapers, washed NFTs, and crypto-mining before landing on a pile of VB scripts.
So put your Astro-boy boots on, grab those speedos and let’s rocket!
Find the full transcript for this week's podcast at Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
In the week that Neil Young took both Spotify and Joe Rogan to task for spreading Covid misinformation, we start with the hurricane of an army wife scorned and end in the aftermath of Elon Musk moving something from the morning shower to the middle of the multi-lane highway.
Gosh.
In between that weather front and the next, we find facial recognition, fingerprints, fries, fines, and fight club. We even discover the new secret successor to the NSO Group.
Hold onto your hats, grab your phone, your raincoat, and let’s join the rest of the storm chasers as we track down this week’s highly unusual atmospheric activity.
For a full transcript of this podcast go to Discuss.Daml.com
...And just in case you do find yourself facing off against a hurricane, stay away from the windows, get as low as possible, move to an interior room, closet, or downstairs bathroom, and remember that we will be back in 7 to give you more instruction.
Until then stay safe, stay, secure… and try to remain calm…
Send in a voice message: https://anchor.fm/rps5/message
We start this week’s update in Wyoming and end in the empty arms of the lovelorn.
As we go rolling about between those two endpoints we chance upon gammy QR codes, supercomputers, schoolkids, high anxiety, and a couple of phone apps you won’t want to be installing this season.
So let’s jump into the overalls, don our builder’s boots, and put on those safety glasses, as we deconstruct this weeks’, and might we add, the best IT privacy and Security Weekly Update yet!
For a full transcript of this podcast go to Discuss.Daml.Com
Send in a voice message: https://anchor.fm/rps5/message
In this week’s adventure, we go from Open Source to Open Dish and the perils each face.
In between those open ends, we have Kiteworks, bagpipes, Teslas, cakeism, the new Spoof league tables, and perhaps a bit of evidence that “the Great Resignation” of 2021 is also affecting the dark web.
Join us as we don our kilts, sporrans, Ghillie brogues, tuck our Sgian Dubhs into our socks, and hit the highlands in the most “Barry” IT Privacy and Security adventure yet!!
Go to discuss.daml.com for the full transcript of this podcast
That’s it for this week. We will leave you with 7 days of quiet while we try to figure out how to tune a bagpipe.
Be kind, stay safe, stay secure, play with confidence. See you in se7en!
Send in a voice message: https://anchor.fm/rps5/message
In this week’s update, we take you from lockdown to the end of civilization with the notice that “a smooth sea never made a skilled sailor”.
We move “shipshape and Bristol fashion”, through mines, espionage, and corruption.
Then, we “make up Leeway” with one big name demanding Multi-Factor Authentication (MFA) for everyone and a black box that just might be a “shot across the bows” of politicians who talk ‘Blah Blah Blah’
Whether landlubber or salty dog, this vessel delivers the best IT Privacy and Security update yet!
So let’s put on those oilskins, slip on those waders, grab a rope, and hit the high seas!
For a full transcript of this week's podcast please go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
In true year-end, year-start style we wall-run over some of the top hacks of 2021 before turn-vaulting with a 2022 resolution to get fit that has no security or privacy involved except that the whole story should probably be secured and kept private.
We backflip onto the LastPass fiasco, corkscrew through a few stories on Apple (is it any wonder they are a three trillion $ company if we cover them?), punch into a fresh duck story, and triple front somersault into the differences between Misinformation, Dis-information, and Mal-information.
As we stop, drop, and roll, this just might be the best new year IT Privacy and Security weekly update yet!
So let’s load up those Parkour kit bags and J-step into our first adventure for 2022!
Find the full transcript for this podcast at: Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We start with exactly what happened to your 2022 fridge calendar and end in wet cat food.
In between, we get frauded, threatened, discharged, breached, dropped, and schooled.
Before you call us on what?
For the last pod of 2021, we’ve got you covered with what’s trending in IT Privacy and Security way into 2022.
We may stroll out of 2021, but we hit 2022 in a full sprint!
Find the full transcript of this podcast at discuss.daml.com
With the holidays over.
And the parties behind,
It’s time for the diets,
And the mid-Winter grind.
From the treadmills and gym,
And the yoga at home,
Resolutions to reach out,
To those all alone.
Just make us a promise,
This one you can own,
Call us on anything
but your kid’s Fisher-Price phone!
Send in a voice message: https://anchor.fm/rps5/message
Looking for great gifts? We’ve got one person on the team who’s happy to sport the finest in athletic shoewear and would probably happily back them up with a wallet full of corresponding NFTs…. If he could get them….
From that metaverse, we travel across the US to Israel and from there to Uganda to get the down-low on the NSO. We check in on Belgium, Germany, and Ukraine before losing our paychecks.
We have a great gift not to buy and then we finish off strong…. with a song!
This week’s IT Privacy and Security weekly update is the best one yet and a gift to us all!
Have the caribou bid adieu,
get the sleigh in gear too,
put on your stocking cap, red velvet suit,
and let’s take off, as the billionaires do!
Find the whole transcript of this podcast at discuss.daml.com
oh, and one more....
To those who have had their holidays, we hope they were joyful,
To those yet to celebrate, great feasts and days restful,
And to those young and small, big and tall, or anything at all, may 2022 be… your best year of all.
Send in a voice message: https://anchor.fm/rps5/message
In a year when holiday parties are giving more than anyone bargained for in the form of new covid variants, colds, flu, and a whole range of bacterium that we had deftly sidestepped for the better part of the last 18 months, we have lots of healthy updates for you.
We start them with the V-POTUS and end with 2022 trends.
In between, we touch on Androids, Canadians, and Apaches before discovering Tor blocking and that secret bottle message you threw out to sea.
For the holidays we also have a couple of ideas that might help with stocking stuffers.
So, wrap the gift and tie that bow! To the very best in IT Privacy and Security we go!
For the full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
As we come to the end of another tough year with… how many new Covid variants? It’s important to remind ourselves that the holidays are peak feeding season for the hack, crack and malware miscreant community.
So no, there are no “surprise” Amazon gift cards coming to you and… that attachment is only going to blow up on the Windows machine and steal your secrets.
Remember to initiate all outbound connections where you enter a username and password and if it’s worth keeping safe, it’s worth turning on 2FA (two-factor authentication).
For this week’s journey, we start with a SIM card, end with an Onion and circle the globe in-between.
We learn about naughty telecoms carriers, a frozen health department, and Microsoft taking down some bad actors acting badly.
We discover why secret agents in the cinema use Nokia phones, why Elon is the only one flying for NASA, and some interesting new features being rushed to Instagram the day before the Senate hearings.
This is without a shadow of a doubt the best IT Privacy and Security Weekly update yet, so grab your boots and your overcoat, and let’s get to swashbuckling “same as we ever did”!
Find. the transcript for this week's podcast here.
Send in a voice message: https://anchor.fm/rps5/message
This week we start with that face in the mirror and end in an SUV.
In between we have hacks, tracks, and attacks on printers and boom boxes, we get a couple of serious cloud plays, and a whole new malware variant aimed at the medicine men (and women).
Finally, we learn how one spy agency has had to “become more open to stay secret”.
No big boots for this adventure, no loud colors or clashing patterns, just smartly pressed tracksuits, a toned demeanor, and that cloak of anonymity.
Come on let’s roll!
For the full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
For this IT Privacy and Security adventure, and this must surely be the best one yet, we start at the Costco checkout and end up in space.
In between the check-out and the way-out we get a quick reminder about online safety in the run-up to Black Friday, we get an update on how one group is working to make software secure, app tracking protection for Android, and tips to foil the Memento hacking team.
We’re so glad that Costco sells moon boots ‘cause we can gear up at the cash-only checkout and keep this adventure rolling until we hit an asteroid! Come on y’all, let’s take off!
For a full transcript of this podcast, go to: discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We start this week tunefully with a story we missed out of the Pwn2Own challenge that will have you headbanging in the aisles before fulfilling a request for more oil for r2D2.
In between, we learn why bragging could end up getting you poorly fed, why popular programming languages could be bad for IoT devices, why you can’t really complain if you see giant cutouts of boats in the desert and we wonder if you can help us find Intel another boxing coach.
We end with mice, scorpions, and robots in a trilogy that could have the animal rights league chasing our tails.
All that aside, this really is the most superb IT Privacy and Security Weekly Update yet, so let’s get “Thunderstruck” with George, Jane, daughter Judy, and their boy Elroy!
Find the full transcript of this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This is the best IT Privacy and Security weekly update yet!
We start up in the warm breezes over Texas and Georgia and finish in the cool Pacific waters off the coast of California.
In between, we hit the power grid, poke at a new political privacy protection law, slap Facebook, then Samsung, and then somewhat in disbelief … watch as Samsung slap back (yes, just read that privacy policy that came with your new TV...). We get heavy with hackers, learn why we think we could catch a “Putney Pusher” if it happened today, throw a spy in jail, and all to end happily … with the cutest solution to carbon neutrality ever. Awwww.
It's just one more 'round the world rave-up (with a couple of crustaceans thrown in for good measure) that will leave you yearning for more. So limber up 'cause this IT Privacy and Security weekly update is going global!!
For the full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This is the most “detective” update ever!
Inside this week’s update, we inspect over-communication in Chinese manufactured telecoms equipment., and under communication from an info systems agency. We broadcast seed planting clips from outside our car prior to a deep dive into the methods used by the FBI to ascertain the Jan 6th. Insurrectionists in Washington DC. We discover fake ads, fake crypto, and we think some fake test results.
Yes, say it with us, “The best IT Privacy and Security detective work yet is in this week’s update”.
Grab your deerstalker cap, your magnifying glass, Watson, and let’s go sleuthing!
For a full transcript of today's pod go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
Like watching Lionel Messi score his 100th goal, some of the stories we cover here seem almost un-be-lieva-ble!
We jump into the game in Argentina and finish in South Korea. Scoring heavily we witness an own-goal, a red-card in the UK, travel to the top and bottom of the league tables, get punched in the mouth, breached, hacked, cracked, arrested, and then, then in what may be the worse fate of all… someone scuffs our white Vans slip-ons.
This is, with no hesitation, the greatest update to date, so don your tracksuits, sort out those shoes and let’s get in on the game!
Find the full transcript of this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
From new and innovative ways to introduce facial recognition, to looking through walls, we have you covered, (or perhaps uncovered)!
We start our journey in subterranean Moscow, move on to a sweetie factory in Chicago, and then into your dentist’s office. From there, AI leaves us spinning before we discover the top 3 locations for mining Bitcoin and a new competitor in the Texan insurance market. We end… outside looking in.
Without another moment’s hesitation, let’s unpack that old Ghostbusters gear, put on the X-Ray specs, and have our best adventure yet!
For the full transcript of this podcast, head over to discuss.daml.com.
Send in a voice message: https://anchor.fm/rps5/message
October is Cyber awareness month; coincidentally it is also the one month in twelve that has the highest number of reported cyber attacks. So how do we acknowledge that? By irreverently engaging drinks, food, and fashion.
While others rush out to the shops to buy everything baggy, those in the know have security tighter than a fresh pair of Burberry leggings.
For our show we have free beers on the far side of the Catwalk, a Twitch portrait of Jeff B’s new look, outfits with chains that are breaking, a company making schoolteachers look bad, and a fantastic new rap artiste to name but a few.
Of course, we can’t give the ending away … before we surface with more snacks… but do watch that you don’t get sensitive data stuck in your teeth.
Whether you are a fashionista or a “securisto” this is the best update yet!
So go grab your Chanel, Stella, and Fendi, let’s jump on a catwalk where IT Privacy and Security are trendy!
To find a full transcript of this podcast, go to Discuss.daml.com
Episode #s have been updated to reflect the total rather than just the season.
Send in a voice message: https://anchor.fm/rps5/message
In this week’s IT Privacy and Security Weekly Update, we journey from the bottle to your heart.
We start with the loss of identity, ethics, freedom, dollars, Bitcoin, and Etherium before balancing them out with new finds in cloud, storage, cleaning, and rain.
Finally, we end with a story of synchronicity that will have your heart racing!
It’s all fresh, it’s all relevant, and …you won’t need to carry a metal detector with you on this journey.
So let’s get on those work boots, grab some gloves and check out the “lost and found”!
For a full transcript of this week's podcast, head over to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
From audio to visual we keep the full spectrum of IT Privacy and Security covered in our best update yet!
We start with almost nothing at all and move on to blocks, breaches, bots, and smacks. We cover why it’s more important to tip your Amazon delivery person than ever before. And finally, we round out why you are actually going to want security training before the fourth quarter of this year. Unbelievable ...right?
We end, on the brightest story we have ever covered!
It’s all wrapped in loveliness, so grab your paintbrushes, get your drop cloths in place, and put in on those old overalls because it’s time for the best adventure yet!
Find the full transcript for this week's podcast at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start our podcasts’ one-year anniversary edition with the sweet sound of violins lilting across the Tuscan hillsides and end in New Jersey to the sounds of barking dogs.
Ah, but between those two audible notes, we travel to Spain, France, Ireland, and the UK before moving on to Thailand and circling across to Russia and the US.
Get your vaccine certificates out, your passports in hand, your RayBans ready, and put your dog on a leash because this is one anniversary bash that you are not going to want to miss.
OK, on your marks, get set! Got the dog? Let’s Par-tay!
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week it’s all about wearables. Be they on your nose, wrist, ring finger, back pocket, or further south they are collecting just about all the …er … data you can generate.
We start this week with Facebook “trying it on” before moving one step closer to their metaverse. We hit you with news on the Biggest DDoS attack ever, before getting bleary-eyed as we learn what happened to the bride (or groom), and why you’re about as likely not to be able to tell just how late they are.
Finally, after you’ve run on your smart treadmill, ridden your smart bike, and gotten yelled at by your smart mirror, we leave you with a wearable that, thankfully, you don’t have to carry around with you.
It’s all here, (well some anyway), it’s all fresh and it’s all in the best IT Privacy and Security Weekly Update yet. So press “start” on your wearable and let’s get exploring!
For a full transcript of this podcast please go to Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
We start this week’s journey at the site of the Twin towers in New York before moving to Russia, and then to Germany and then, a little bit late, to the airport before boarding our flight for Australia, Scotland, Pakistan, Ireland, and China.
Then, in the haze of jet lag, the American military finally leaves us with no words.
Grab your go-bag, passport, vaccination certificate, pillow, and let’s do some long-overdue globe-trotting. This week’s travel won’t be drama-free, but it will be Covid free.
Find the full transcript of this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
In our most childish update, we bring you the up high, low down, and all the topics shaking around us.
We start with one of the most entertaining helicopter chases we have ever heard, move through 58 websites, then into an Airbnb, a swimming pool, where drenched, we embark on a transatlantic chase, a breach, a leak, an upgrade, and finally finish with a boat.
If you weren’t out of breath from all that, we can promise, we are.
And if only for a few moments, we’ll try to pull it together, stand upright, act mature, and set off on a superbly childish adventure!
Find the full transcript of this podcast at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This is the Jailbreak edition. We start with an example of the quickest way to end up in prison, a story of an inmate made good and of course, we end up right back in the clink in what must be one of the worst hacker “job applications” in history.
In between those rough-and-tumble walls, we have insight on one country’s cyber curriculum, your streaming service’s second income, OnePerCent, the potential post $610 million job offer, and why Amazon could be sold out of Razor gaming mice.
Ducking and diving, dodging and weaving, we are all in this week, so let’s get on the striped shirts and have a quick look inside.
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
If the single most important component of a camera is the twelve inches behind it and the “camera is a license to explore” then let’s hit the motor drive because we’ve got a lot of scenery to cover!
We start with an appetite so large for taking pictures that consumer interest groups are now asking for receipts. We move on to dadada and password reuse, the inflationary pressure on phishing, and a suggestion that T-mobile might want to be a bit more polished in their breach news releases.
We end up with a demonstration of a solid backup and recovery process and a kid who is going back to church with his camera.
You’re going to love this week’s IT Privacy and Security update … frame, by frame!
"We start with a story about reinvention:
There’s been a lot of press lately about Ransomware as a Service (RaaS) groups disappearing.
The truth is, when you make as much money as they do, it’s hard to just walk away.
So here are this weeks RaaS Renames:
How do we know? Much of the signature software in use by the new gangs is bit-for-bit the same as was used by their earlier alias."...
Find this week's full transcript at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We start with an aerobic workout that may have you leaning on a wall … and end with a wag as to why your dog may be propped up against a wall.
In between, there are rooms of fantastic stories for you with flytraps and Instagrams and even a sprinkling of Emmental cheese.
We’ve got an appeal to put the phone down that might be that call you never wanted to receive, and a risk profiler that could keep you within your own four walls for quite some time.
We think this week’s IT Privacy and Security Weekly update is the best one yet and a great way to shake off cabin fever, whether you are inside or out!
So let’s get IT moving!
Find the full transcript of this Pod at discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
We are firing all rockets, starting down-under with a report on a pocket calculator that may inspire a whole generation (to write secure code). From there we orbit to Italia where you might need a “shot” of espresso before their news.
Then it’s on to Raccoons and their role in the new SaaS, before touching down in France and Luxembourg to see who’s hands have been slapped.
We Zoom into why you might want to hold the Guac on that burrito, and why if you are in North America, you might want to reschedule your Doctor’s appointment.
Finally, we end our journey 56 miles above the earth’s surface with one of the best “What could possibly go wrong?” stories ever…
We think you’ll be even more excited by this launch than former Amazon CEO Jeff Bezos was last month, and we’ll certainly be going further! So fasten your helmets, put on your moon boots and let’s blast off!
For the full transcript of this podcast go to https://discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
As we put this update together there is a haze outside our New York Windows from the raging fires burning 2400 miles (about 4000 kilometers) to the west.
Yet we start in a lighthearted mood, with a great reason to use 2fa, and finish with a burning update about the loss of something that may be even more important than your Privacy and Security.
In between, we have a mix of stories that range from Home routers in France being hijacked by APT31, to an unexpected Twitter discovery.
Next, we have Venmo offering just a little more privacy … and why naked people are turning up next to your Washington Post articles.
This may be the most important update yet, so stick with us to the end. We think you’ll take away more than you bargained for.
For a full transcript of this podcast go to Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week it’s all about food. Well, some of it is, anyway.
We start with too many cooks in the kitchen and end with positive prospects for cheeseburgers on Mars.
Moving through the meal have all our ducks in a row with a possible bit of overcompensation from the US government on Cybersecurity, a huge leak out of Israel, three Apple stories, a food fight between the US and China, and cyber threats to the food industry.
There are lots of additional tasty tidbits sprinkled in among the various courses too.
So let’s roll up our sleeves, tuck our napkins into our shirt collars, and chow down on the most satisfying serving of IT Privacy and Security Weekly update nourishment yet!
Find the full transcript to this podcast at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This episode has us quaking in our wellies. We’ve got the US president advising Russia that they need to fix their ransomware use, while he advises that you should be able to fix your own phone … and tract’r!
A new algo. to help with your recommendations, AI that can say stuff bett’rn we can, and a new clampdown that will have you selling your DiDi and Baba shares faster than a jackrabbit in a foxes den.
We finish with a story that will keep you out of your car and down on the farm.
It’s all here, it’s all fresh and like the crops, it’s just been rotated, so grab that horse and let’s go!
Find the full transcript for this pod at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We start this week as a dot on a race track and end as a dot on the horizon as we go from privacy to no privacy at all, but … we think you will forgive us.
In between the start and finish lines are the hairpin turns of the Tokyo Olympics, an underwater primer on Submarine cabling, a vault skyward with British Airways, a VR story that needs a restart, a bit of ransomware, and enough car stories to satisfy any gearhead.
We say, "Drivers start your engines, get set and let’s “go” for the best IT Privacy and Security weekly update …ever!!! "
Find the full transcript for this pod at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we take you from an employer that won’t even let you in the building if you are not smiling, to your best friend when there is just … one… CCTV too many.
In between, we get a loud warning for publicly accessible Western Digital personal storage, a couple of painful admissions from Microsoft, and US phone users getting shaken and stirred.
In the mix, we also have a place for you to jump into a 3d world for a little "privacy and chill" should you wish.
It’s all here, it’s all fresh, and it’s just about the best IT Privacy and Security Weekly Update yet.
Let’s put on a great big smile and get to work!
Find this week's full transcript at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
From splashing in cold waters to baking in hot homes we cover the whole temperature range.
After a good headcount of our critical drinking water infrastructure, we give you the lowdown on tracking, bots, faces, and fingerprints. We update you on compliance, regulations, and (sadly) taxes, before delivering really bad news for our RedHat Linux and Docker users.
Finally, we unbork your iPhone before revealing just why you might be reading this in a full sweat.
So pull on your swimming trunks, put on your gloves and let’s go have an adventure with this week’s IT Privacy and Security Update!
Find the full podcast transcript at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
“There’s only one thing I never did and wish I had done: climbed over a fence.” Mary of Teck
This week we start in El Salvador and end in mid-air.
In between those fence posts, we find: Breaches for airlines and autos and then discover one already being served up with a side of fries.
We find out how Google really motivates their staff, learn about Facebook suing a whole government, malware “photobombing” FujiFilm, the huge market for fake product reviews … and why the legal community is turning against geofencing.
This simply is the best IT Privacy and Security Weekly Update yet. Now let’s go climb a fence!
Find the full podcast transcript at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start with the Danish spying on the Germans. The Germans hacking .PDFs. The Cook keeping things private. The Tag"ee" smashing things with hammers.
..and you… now with 8.5 billion reasons to use 2-factor authentication for your logins … oh, and a very special article just for teens. Aw.
Then, a story about how the coppers recovered loads of Bitcoin from the Colonial Pipeline ransomware attack, but they still need Elon Musk to up-tweet Bitcoin or they’ll be out 20%!
Finally, we finish with an Anonymous video to Elon Musk that has viewers asking for more!
It’s all here in an entertaining, fun, thrilling, mix of the best stories for all “citizens of the world”, so let’s get this party started!
Find the full podcast transcript at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We prescribe an update that’s just chock full of news that could very well help you see more clearly or leave you blind, wondering why you just bought those really dear headphones.
We start with tracking, move on to toothpaste, and then get a nosebleed from hits the ransomware group Conti has inflicted before we have our use of a certain term validated.
We discover how to tell the difference between “Dumb AI”, “Smart AI” and “Really Smart AI”.
And we leave you with a couple of health checks that have nothing to do with IT Privacy or Security but could have you feeling much better about your own visual and audio acuity.
This is without a doubt just what the doctor ordered, so let’s hang up our jackets, roll up our sleeves and get going!
Find the full transcript of this podcast at https://discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
On the first anniversary of the murder of George Floyd, we’d like to take a moment to pause and reflect. Changing social bias is an evolution, just as realizing and changing our own. But with continued effort, we can make a difference. Just as ignorance promotes prejudice, we can all learn to be kinder, gentler, and more accepting of the differences of those around us.
This week we start IT Privacy and Security with the sound off, a revelation about a new type of malware that actually checks a directory to look up its victims before attacking them, and then a type of manipulation we are sure you’ve experienced but probably never realized was so rampant.
We follow with a story about poor judgment and bad publicity and the heroic efforts of so many as they work to help others. There is news on privacy and security changes in Android 12, and yet another update for macOS.
We end on a lighter note with the story about the significance of composition in photography, stressing the importance of keeping your fingerprints away from the final product.
On this solemn day let’s learn something new. Together.
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we take apart the various elements of ransomware so you know what the stats are upfront. Costs, protective steps, and tooling so that if the unthinkable ever were to happen you would know your options.
We remind you that although ransomware is (literally) stealing the headlines, there are a few other gremlins out there that you might also want to sidestep.
We end with some entertaining quotes from the cryptographer's panel made while they were out of their dark workshops attending the RSA conference this week.
Encrypted or decrypted … we think you’ll find that this is the best IT Privacy and Security Weekly Update yet, so let’s refactor and get started!
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
Through the acrid smell of trouser fires we bring you an incredibly varied line up of stories.
We start with a zero day that burned the world’s most popular .PDF reader, the dirt around the pipeline, a not-nice new activity for Apple Tags and early results of Apple’s app tracking option.
We flame out with proof that you should not trust ransomware developers, another government attempt try and get us to believe that 5G doesn’t cause Covid-19 and end with a Zero day attack on the Universal Turing Machine.
You are going to love each and every spark of a story, each ,will fan the flames of your passion for IT Privacy and Security.
So let’s catch our balance, get fired up and go!
For a full transcript of this podcast go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We start with the true story of May the fourth, and end up with a suggestion that might just prevent injury.
In between those lovely layers of freshly baked updates are sandwiched some very tasty servers, Russian Dressing, some NY rye, something else that smacks of dog food, doublestuff and an apple.
After you finish, your mum will be waiting for you.
Now on our best behavior: Let’s order the flowers, pull up our socks, straighten our shirts and make the best impression yet … with the best IT Privacy and Security Update yet!
You can find the full transcript for this podcast at Discuss.Daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we start with a uniquely Canadian turn of events that has absolutely nothing whatsoever to do with privacy or security but was essential nonetheless, and end up chasing the cat around the office.
In between we find out why the C-suite of gaming companies are themselves becoming targets, a newly developing jab / job relationship, just what the new MacOS update stops, what’s behind the Linux fracas, some stats on ransomware and then... what’s going on with Reverb.
It’s loud, it’s raucous and it’s just getting started, so turn on the noise cancelling, turn up the volume and let’s get going!
Find the full transcript of this podcast at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We confess we wrote this intro with the Apple product announcement running in the background. We saw the new iPad, iMac, tags, TVs, and M1 features, and “Oh my word” nothing about the privacy update in iOS 14.5!!!. Grrr…
So swiftly moving onto other matters of very little privacy, we have a couple of FBI stories, one about e-mail and another about iPhones (Grrr…).
Shocking revelations about online cameras…
Updates about Google that will leave you shaken, not stirred…
A scandalous, awful, treacherous, plot that could impact any wine drinker!!!
And then we finish the update with a story about what some would call arrogance, from Facebook… also regarding your privacy.
This update promises to bring you everything you need in the world of privacy and security… except of course for the “dang” details on the new iPhone privacy update. (again Grrr…)
Let’s roll up our sleeves, and not get fooled again!
Find the full transcript of this podcast at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
The best IT Privacy and Security Update … served with perhaps the most questionable intro and outtro music ever!
And he’s right. We follow the food theme again this week and go from Apple to Cheese.
We start with an outright rejection of the UK government’s second expensive attempt at a Covid-19 tracker, then we move over to the app that really should not be on your phone anymore.
Next: a crazy story about an exchange that gets breached and then reminds you that YOU should use more complex passwords, a completely politically correct request for UK women to get more involved in hacking, and 7 new and evolving methods that fisher-people are going to try to catch you out with.
Finally, we share a story on how Google intends to help you stop bumping into lamp posts.
...Oh, and then there is the missing cheese....
You’ll find it all here this week (except for the cheese) in probably the healthiest slice of IT Privacy and Security ever!
You can find the full transcript of this podcast at: discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we go from Peking to Duck (literally), and we are sure you’re going to find the tastiest treats anywhere.
We take you crashing down a staircase with a wireless data communication company, add more evidence for spellchecking your child’s tweets, and an idea why this team won’t be looking like Tony Stark (Iron Man) any time soon.
We give you a light pole update. Yes, we got that right, a light pole update. And what college students should do quickly if the school they are going to, or even applied to, is one of those caught up in the Accellion file transfer software compromise.
We finish with something that we thought was pretty cool… It’s almost the gamification of tracker blocking. We loved it for Android and iOS and we think you will too.
OK dinner guests. Adjust your place settings, tuck in your napkins, and let’s give a toast to the best IT Privacy and Security menu yet!
The full transcript of this podcast can be found at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
We start this week’s adventure with a tribute to women’s safety as we come to the end of National Women’s History Month in the US.
We move on, not to home building, but cybersecurity, with a backdoor disguised as a Typo fix. In the days of the George Floyd murder trial in the US, we find one legal reviewer in the UK that is of the opinion that people should get anywhere from 2 months to 5 years for not providing their phone password to the police.
We get to the bottom of STIR/SHAKEN and finally, we see the results of a privacy and security survey of over fifteen thousand people around the world. We think the results will surprise you!
And with that, the moment, you own it, you better never let it go.
Find the full transcript for this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we invite you to join us as we make a bunch of long-distance calls, starting with India, moving across the world, and finally ending up in Egypt.
During our phone dialing journeys we find over five hundred, sixty-seven thousand good reasons not to be vengeful, we tell you about how the FBI tried to make friends with us and failed on the first click, and we share the EU’s new strategy that has us stopping at the start.
We redefine Sassy and give you yet another example of why using SMS for authentication is just … not that good.
We finish with a story about an Egyptian TikTok user after he filed a vulnerability report that had him dancing around his phone.
It’s all here, you just have to answer the call!
Find the full transcript for this week's show at Discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
Welcome to the update that never sleeps… “king of the hill”, “top of the heap”.
This week we get non-fungible with our fungibles … and … just look at the results. We save you the FOMO by ELI5 to help you DYOR so you can BTFD.
Then, just as you spend your last fungible, LastPass your “hey, all my passwords are in there…” app, announces they are going to charge you or force you to make a choice… we “spread the news” about a different free password manager.
We “stray” to breaches and fixes and other privacy and security items before we finish with an idea that just might have originated “in the very heart of it: New York, New York.”
This truly is the “King of the hill”, “A”, “Number one” IT Privacy and Security weekly update, so put on those “vagabond shoes” and let’s stray!
Find the full transcript for this podcast here.
Send in a voice message: https://anchor.fm/rps5/message
We have a galloping great IT Privacy and Security Update for you this week! We help the Mac users come to terms with why it seems like they have been getting more updates than their Windows counterparts.
We provide you a sense of self-worth, and just as a note… apparently, that friend of yours from Gozo really does rate higher than the one from Idaho.
We update you on the dangers of supporting West Ham, a simple overview of all the noise associated with Microsoft’s Exchange issue, the code flaw at the DODO crypto exchange, and then we finish with a lovely, lilting, run-through of just how easy it is to secure your home network.
This is it.This is absolutely the best IT Privacy and Security Update yet, so get your auction card, roll your sleeves up and let’s get bidding!
To contact us and find the full transcript of this podcast please go to discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
How are you feeling today? Good, we hope!
We are starting this week’s update with healthcare and ending with an insurance story in a journey that blows right past the doctors’ office.
In between buildings, your coveted iPhone 12 gets a lesson in how to improve battery life and then gets hacked.
We have great gossip about the Gab hack and one more amazing story about SolarWinds that will raise your heart rate and make you blush.
This really is the best IT Privacy and Security Weekly Update ever, so limber up with a couple of toe touches, chug those vitamins and let’s get that Zimmer frame going!
Find the full transcript of this podcast at discuss.daml.com
Send in a voice message: https://anchor.fm/rps5/message
This week we move from the farm to the hospital, and all hopefully injury-free.
We’ve got another “kikerikii, jippiyayyeyyy, boomchikahwoowoow”from Zoom, stalking Favicons, and why you might not want to do your personal banking during your conference calls.
We even have the lowdown on the hot new invite-only app that you… somehow got an invite for… and have been using non-stop for the last couple of weeks.
It’s all here and we know you are going to love jumping up on the combine harvester and taking in the fertile pasturelands of this weeks IT Privacy and Security update
(...and of course, the consensus from the farming community that this is the best update yet!)
Find the full transcript for this podcast here
Send in a voice message: https://anchor.fm/rps5/message
What do you do if you’re in a country where there are zero officially reported cases of Covid-19 and you have no vaccine research budget?
Officially, you don’t need the vaccine, but unofficially… you might be open to the idea of stealing the secret recipe for one!
This week we have a supply-side chain attack that could hit anyone using open source software pretty hard. A French sequel to the SolarWinds saga, and the innovative way the Beverly Hill Police Department is using music licensing to stop people from posting encounters with them on social media.
We finish off will just how badly love can hurt, from a completely unexpected source… the US Federal Trade Commission.
You know what? This is the Best IT Privacy and Security update yet so, pump up the volume and let’s get going!
For a written transcript of this podcast go to https://discuss.daml.com/t/pump-up-the-it-privacy-and-security-update-for-the-week-ending-february-16th-2021/2097
Send in a voice message: https://anchor.fm/rps5/message
Happy ITPaSWU* Tuesday!
Valentine’s Day is coming up and we’ve got gifts for you. Lots of them.
The first is a great story on just how much precise data your phone shares about you with whoever cares to pay. We then move on to a collection of your data that’s so big, they just may know more about you than you know about yourself!
From there it's furballs and kitties with a new ethnically targeted campaign that uses tech for all the wrong things. We tell you why it was better to stick with beer than water in the Tampa Bay Area for the Super Bowl last weekend and we finish with probably the most creative Valentine’s present you could ever come up with for your loved one!
It’s all here and it all adds up to the best *IT Privacy and Security Weekly Update yet, so let’s get rolling!
For a transcript of this podcast, head over to discuss.Daml.com
Have a safe, secure, and happy Valentine’s Day… and see you in se7en!
Send in a voice message: https://anchor.fm/rps5/message
Happy Identity Theft Awareness Week!
In celebration, we move from stories about a 7 year old to a 30 something, the first an agent, and the last a real operator… to a mischievous creature that is causing some real worry in the security community.
We get the lowdown on the face off between Mark Zuckerberg and Tim Cook and more crazy stats on social engineering with tips on how to avoid trouble.
This is the BEST IT Privacy and Security Update yet, so put on your party hats and let’s celebrate!
Send in a voice message: https://anchor.fm/rps5/message
We start with a guy who’s got reporters, lawsuits and a Stock Market darling chasing him, and he didn’t even know it until a reporter from the New York Post told him!
We show you the price you pay for something free. Then we move on to more breeches than Levi Strauss… and a sombre message about trust on the Internet.
We finish with a shocking story about our kids getting hacked. Think it’s implausible? Think again!
This is the best IT Privacy and Security Weekly Update yet, so let’s get going!
Send in a voice message: https://anchor.fm/rps5/message
Tom Jones sings the Burt Bacharach classic, as a tip off to our first story as we move from sunspot, Sunburst, Teardrop onto "Raindrop".
From there we go X-rated before hurtling into the Good and the Ugly.
Finally we end in outer space were one institute is even starting to realize that Cybersecurity has its place in space too!
This is the best Privacy and Security update yet, so put on your rain macs, buckle up and away we go!!!
Send in a voice message: https://anchor.fm/rps5/message
This week we start our stories to the background tune of Prince with a story that just keeps getting bigger. We move onto politics and the permanency of the Internet and a do at home project, you too, can perform if you have the time, the dosh, a few tools, and a supercomputer sitting around.
We have a cautionary tale about a leak and all the data about you, yes you, that was exposed (and thankfully a way to minimize that going forward).
Finally, we finish with a story about how a nice man ended up with a little Red Corvette!
One thing is for sure, this week’s update is the BEST one yet!
Let’s get rolling!
Send in a voice message: https://anchor.fm/rps5/message
Following on from last year’s collection of the Best IT Privacy and Security stories yet, we up your ROI (return on investment) in this section with what these stories mean to you. There’s no better way to drive a story home than with a message of “what’s in it for me?” and that’s what we deliver.
We start our journey across the world with a criminal complaint and we end at the doctor’s office, in between we have insight from the Netherlands, India, China, the EU and the US. If you use any type of technology there’s a story for you here.
So without further ado we’d like to help you start your great new year off with best wishes and the BEST IT Privacy and Security Weekly Update yet!
Let’s get going!
Send in a voice message: https://anchor.fm/rps5/message
Welcome to this week’s edition of the IT Privacy and Security weekly update.
According to research done by MIT the number 17 is the most common randomly chosen number between 1 and 20.
17 is the seventh prime number. A prime number is a number that can only be divided by both itself and the number 1.
The number 17 is more than just a prime number though – If you add the first four prime numbers together their sum is 17. It’s also the only prime number that is made up of four other consecutive prime numbers, these numbers being 2, 3, 5, and 7.
It’s also the number of the adjoining IT Privacy and Security weekly update podcast and a row number that you will never find on an Alitalia plane.
So … right now we are going to buckle you into row 16 of this week’s luxury flight. First destination is the land of AI, before heading over high risk terrain and landing in big data’s data base.
We think you’ll love the journey, the stewards are exceptional and the food? Well … just remember your new year’s resolution!
Send in a voice message: https://anchor.fm/rps5/message
Phonetically speaking, we have the tastiest holiday serving of praɪvəsi ænd sɪˈkjʊrəti on anyone’s holiday menu!
Our entre is confirmation of a hack first reported here months ago, before moving onto the first course of NSO stew, a main of student test taking with a side of Facebook.
For dessert we move outside and with the wind in our hair we end with a story about brushing.
Yes, it’s all here and although we make a real meal of it, we think you will love this holiday feast!
So grab a knife and fork (no spoons in this issue, for that see our December 1st update) and let’s dig in!
Send in a voice message: https://anchor.fm/rps5/message
This week reads like a https://www.007.com/ movie
(we like the " How To Drive Like James Bond… That is, if you have £3M to spare" section): from across the world, nation state spies are revealed, huge hacking exploits that provided access into 80% of the US Fortune 500 come to light, insecure kit at the doctor’s office and schools hacking students phones with hardware that was and probably should still be in the domain of the spies are all exposed.
Yes, despite the meteor showers overhead, we stay with our feet planted firmly on terra firm with this update, and we think you will love the detail.
And finally this yarn ends by knitting in an opportunity for you to play phisherman/phisherwoman, engaging in some role playing/threat modeling around how you might compromise someone through email, in order to understand the small changes in your own behavior that will keep you much safer.
It’s all here so let’s get cracking!
Send in a voice message: https://anchor.fm/rps5/message
Happy Tuesday!
In our process of constant evolution we have a slightly new format for you this week.
After an exciting IoT Bill we are going to focus on secure communications.
We look deep into the heart of password use and creation, to help you create your best one yet and then we take to the high seas for a recent discovery that had some major implications for human-kind.
We finish in and around the high seas with a certain signal we hope you'll become very familiar with.
So let's draw anchor and put this ship out to sea! This is the best Privacy and Security update yet, so Let's set sail!
Send in a voice message: https://anchor.fm/rps5/message
Howdy!
On “giving Tuesday” we are “giving” you the best privacy and security stories yet.
AI and privacy feature high on the list, from AI aimed at truck drivers to office 365 workers and sticking with the theme comes our AI generated title this week for the Privacy and Security update. Using the semrush(dot)com/title-generator/
and the two most coherent results for your delectation:
(It really had to be the second option for this week’s update…)
… from there we move into GDPR fines, DNA hacking, and Magecart attacks. We swap voice commands for laser to instruct your Alexa device and highlight some other privacy concerns from Amazon.
We finish with a delightful interview where privacy and GDPR appear not to be foremost thoughts in the mind of psychic Uri Geller.
This is the best collection yet, so let’s get the road train rolling!
Send in a voice message: https://anchor.fm/rps5/message
They used to say, “If you want to get someone’s attention, just whisper.” In these trying times where social distancing keeps people more than 6 feet away, that strategy falls flat, so instead we come bearing news of gifts.
We start with free e2ee calls for up to 29 hours 59 minutes and 59 seconds, we move on to leaky apps, why your new car might have gone missing while you shopped for Raspberries, how many Apples it takes to get a CCW, why you might want to change your doorbell…again… and what you might be thinking about if you are a Liverpool Football Club fan while Man U fight off cyber attacks.
We share the most common breeds of phish, Oxford University’s word??!!? of the year, and why Minecraft mods might be bad for your vision (at two minute intervals).
And of course we end with another gift for you, but we are not going to bang on about it.
It’s our best collection of Privacy and Security updates yet so, no holding back! Let’s get unwrapping!!!
Send in a voice message: https://anchor.fm/rps5/message
Welcome back P&S listeners ... we start with trip down memory lane. ..... How many of you recall the days of L0phtcrack as possibly one of the first tools you used to demonstrate the concept of brute force attacks? (Ok maybe this says something about us.) Well, Twitter has just taken on its creator.
This week is absolutely the best collection of articles yet, … as we veer from Pentagon commissioned artwork, to numbers that give us an idea why there are so many data breaches … to a new scam involving browser notifications.
We update you on RaaS and the new DS4SD, take a trip to Pluton, the benefits of Glue DataBrew and a wonderful story about how one Bangladeshi lad is tackling cyberbullying and receiving international acclaim for it.
We end with a sad story for one person in particular and the perfect example of how not to use your vacation time.
You’re going to both love and learn with this week's set of adventures, so let’s get going!
Send in a voice message: https://anchor.fm/rps5/message
After what some may have found a nerve wracking week across the globe awaiting the results of the US elections (absolutely validating the value of immutable transactions) the dust is settling a little bit. While US authorities pat themselves on the back, we look into just how precarious some of the security surrounding voting was, from hacking voter data websites to breaking into ballot boxes, you may come away a little shaken.
We have a story of how the father of the Internet wants to bring privacy back, the results from both the Pwn2Own and the Tianfu Cup and an early Black Friday sale that could land you behind bars.
*Finally we end with a story that might put a little more sting in your Campari and soda. *
This is the best round up yet! We hope you enjoy this week’s privacy and security update.
Send in a voice message: https://anchor.fm/rps5/message
We have the best mix of stories yet, from across the world… to outer space.
We start with why you might do better smashing your old thumb drives, then patching, a really laughably acronym, guarding against malicious Google forms, how long were you on that phone?, why naming bugs is such a bitch, and a first review of Elon Musk’s SpaceX StarLink.
You will love every single word and you’ll be better informed and safer for each!
Send in a voice message: https://anchor.fm/rps5/message
...this Security Matters update is the best EVER. As we span the globe for stories we start off in Sweden and end up in Kazakhstan.
In between those two countries you can learn how to redact depositions, send high speed uploads to drones while in Munich, view some extraordinarily bad passwords a la the current US president, read a truly inspirational story about one of the team leads at Project Zero, get our recommendation for a for the “Zucked” What’s App. and protect your phone against malice on public wifi networks.
This week’s news is laughable and sobering at the same time, and we hope you will find every piece a jewel.
Have a great listen, a wonderful week and stay informed, safe and secure!
Send in a voice message: https://anchor.fm/rps5/message
We have the most entertaining round up of privacy and security stories making this the best week yet! From a rapper scamming the system to an alarming number of stories covering the security and privacy of our children, hackers giving back to charity, to a final word from POTUS that has roughly half of the population up in arms.
In between we share US election communications that you will want to avoid, a RAT infested travel app that you’ll never need to download and how to make your phone a little bit safer.
Enjoy this week’s roundup of stories!
Send in a voice message: https://anchor.fm/rps5/message
This week we start with an Orca reporting on a bunch of appliances and we end with a story about birds. In between the two extremes we have cars, drive-bys, cruises, trickbots, bricked phones and backdoors. Truly colorful content.
We help you stay safe with tips on everything from shopping to conferencing and while the tone is light, the results are serious.
Have a great listen!
Send in a voice message: https://anchor.fm/rps5/message
Hey everyone! Welcome to the Privacy and Security related news for the week ending October 6th 2020
From the Wild and crazy guy John McAfee (We’ve met him. We can attest to the “crazy” parts) all the way to Mars, we have you covered with the latest and truly the greatest news.
We know you are going to love this week’s privacy and security news story round up and perhaps even forgive us for the last socially very distanced article.
Stay on point, on guard and informed.
Send in a voice message: https://anchor.fm/rps5/message
Hey everyone! Welcome to the Privacy and Security related news for the week ending September 29 2020
We’ve certainly got a roundup of WILD stories for you this week, from the FBI playing Roxy Music’s Manifesto, to Stravas paid for contribution of your data to the development of city centers it’s all here.
Fed up with your Android location based unlock? We can help you fix it for a while. We cover the curious outage of a large swathe of the US’s 911 emergency services (the equivalent of 999 in the UK… or is it “0118 999 881 999 119 725 3”?) and even a coffee maker hit with ransomware.
We hope you enjoy this week’s privacy and security related news stories , and that they help you stay on point, on guard and informed.
Send in a voice message: https://anchor.fm/rps5/message
This week we start underground in a Tesla and end with a boat crash, but what you find in between those two modes of transport is crazy interesting.
We have a cautionary tale involving an Australian Prime minister, Fuzzing as a Service, a leaky elastic Microsoft Bing search server, a snowflake, a credit card, and Russia putting the clamp on secure protocols.
There’s no better way to get your Privacy and Security updates than here, so have a seat, buckle up and enjoy the journey!
Send in a voice message: https://anchor.fm/rps5/message
A roundup of global privacy and security news for the week ending 2020 09 15
Send in a voice message: https://anchor.fm/rps5/message
A collection of privacy and security related stories.
Send in a voice message: https://anchor.fm/rps5/message