BlackBox (Security) Archiv
4.09K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
Egypt police ‘using dating apps’ to find and imprison LGBT+ people

In a brutal effort to “clear the streets” of the LGBT+ community, security forces are entrapping Egyptians using dating apps, throwing them into jail, and subjecting them to systematic torture and abuse, a new report has found.

Using social media and apps such as Grindr, Egyptian police are creating fake profiles that they use to meet gay, lesbian, bi and trans people, at which point they are picked up off the street and arbitrarily arrested, Human Rights Watch said on Thursday. Police then unlawfully search through the content of their phones to justify keeping them in detention and bring charges against them.

“Yasser”, 27, told the group he was arrested when he met another man in Giza Center City after chatting with him on Grindr, a same-sex dating app.

“When they came back with a police report, I was surprised to see the guy I met on Grindr is one of the officers. They beat me and cursed me until I signed papers that said I was ‘practicing debauchery’ and publicly announcing it to fulfill my ‘unnatural sexual desires’.”

While in detention, all of the fifteen people interviewed by the rights group said security forces subjected them to physical and verbal abuse, “ranging from slapping to being water-hosed and tied up for days”.

👀 👉🏼 https://www.independent.co.uk/news/world/middle-east/egypt-lgbt-gay-facebook-grindr-jail-torture-police-hrw-b742231.html

#egypt #lgbt #gay #imprison #datingapps #thinkabout #why
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
US Indicts Members of ‘Piracy’ Group Team-Xecuter, Two Arrested

The U.S. Government has indicted three members of the infamous group Team-Xecuter, the masterminds behind various Nintendo hacks. Two of the members have been arrested and are in custody., but the group's website remains online. According to the Department of Justice, Team-Xecuter is a criminal enterprise that profits from pirating video game technology.

Team-Xecuter is widely known for creating ‘hacks’ that bypass digital restrictions on Nintendo consoles.

The group has been chased by Nintendo for years, but today, their operation has become the center of a criminal case prosecuted by the US Government.

The US Department of Justice just announced that two members of Team-Xecuter were arrested recently. Max Louarn, a 48-year-old French national, and the 51-year-old Gary Bowser from Canada are in custody and charged in a criminal conspiracy. The indictments also name a third defendant, a Chinese man named Yuanning Chen (35), who remains at large.

The three indicted members are just a minority of the total group. According to the US authorities, there are more than a dozen Team-Xecuter members scattered around the world. These members help to code and create the Nintendo hacks, but they are also suspected of being involved in the production and sale of these devices.

The indictment portrays Team-Xecuter as a criminal enterprise and notes that its members did their best to evade law enforcement by using a variety of brands, websites, and distribution channels.

“These defendants were allegedly leaders of a notorious international criminal group that reaped illegal profits for years by pirating video game technology of U.S. companies,” said Assistant Attorney General Brian C. Rabbitt of the Justice Department’s Criminal Division.

👀 👉🏼 https://torrentfreak.com/us-indicts-several-members-of-piracy-group-team-xecuter-two-arrested-201002/

#usa #piracy #TeamXecuter #arrested
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
GHunt

GHunt is an OSINT tool to extract a lot of informations of someone's Google Account email.

👀 👉🏼 It can currently extract :

Owner's name
Last time the profile was edited
Google ID
If the account is an Hangouts Bot
Activated Google services (Youtube, Photos, Maps, News360, Hangouts, etc.)
Possible Youtube channel
Possible other usernames
Public photos
Phones models
Phones firmwares
Installed softwares
Google Maps reviews
Possible physical location

⚠️ Warning:
02/10/2020:
Since few days ago, Google return a 404 when we try to access someone's Google Photos public albums, we can only access it if we have a link of one of his albums.
Either this is a bug and this will be fixed, either it's a protection that we need to find how to bypass.
So, currently, the photos & metadata module will always return "No albums" even if there is one.

👀 👉🏼 https://github.com/mxrch/GHunt

#ghunt #google #account #tool
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Anonymous hacks 83 websites belonging to Azerbaijani government in support of Armenia

Anonymous Greece hacked 83 Azerbaijani government websites in solidarity with Armenia.

The hacktivist group Anonymous hacked 83 state websites of Azerbaijan government, including 73 sites in just an hour, in support of Armenia. The hacktivists not only hacked the websites, but also downloaded information, the group shared from their official page on Twitter.

👀 👉🏼 https://news.xiaomi-miui.gr/anonymous-greece-attacking-sites-from-azermpaitzan-51055-2/

👀 👉🏼 https://www.nuceciwan54.com/en/2020/10/03/anonymous-hacks-83-websites-belonging-to-azerbaijani-government-in-support-of-armenia/

#anonymous #hacktivist #hacking #greece #azerbaijan #armenia
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
🔥1
Media is too big
VIEW IN TELEGRAM
Saturday Night Live - Jim Carrey & Maya Rudolph As Joe Biden & Alec Baldwin as Donald Trump.

Yeah, I know. Again, this has nothing to do with the actual topic of this channel. But! Somehow I think, every now and then, we need something to smile about.

👀 👉🏼 This parody with star cast should not be missed!
https://www.youtube.com/watch?v=Kxhlf2m0rtY

#trump #biden #usa #parody #video #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Media is too big
VIEW IN TELEGRAM
The Internet's Own Boy: The Story of Aaron Swartz

The Internet's Own Boy follows the story of programming prodigy and information activist Aaron Swartz. From Swartz's help in the development of the basic internet protocol RSS to his co-founding of Reddit, his fingerprints are all over the internet. But it was Swartz's groundbreaking work in social justice and political organizing combined with his aggressive approach to information access that ensnared him in a two-year legal nightmare. It was a battle that ended with the taking of his own life at the age of 26. Aaron's story touched a nerve with people far beyond the online communities in which he was a celebrity.

📺 👉🏼 https://www.youtube.com/watch?v=M85UvH0TRPc

#swartz #internet #socialjustice #activist #docu #video
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Google removed 34 malware-infected apps from the Play Store, now you should delete them from your Android phone

The Joker malware steals money from users by subscribing them to the unwanted premium paid subscriptions without their consent. It first simulates interaction with ads without users’ knowledge and then uses the victim’s SMS messages including OTP to initiate payments.

In the period of two months between July and September, Google has removed 34 apps from the Google Play Store because they were inflected by the Joker malware that has been giving Android smartphone users nightmares. The Joker malware is not new but lately has been causing headaches for Android app developers as it is very hard to detect due to the little code it uses. Also, malware like these use a different technique called ‘Dropper’ to bypass Google’s security scan and sneak into the user’s device.

The most recent additions to the list of apps infected by Joker malware were revealed by Zscaler, a cybersecurity firm based in California. Here’s a look at the 34 apps infected by the malware you should remove from your smartphone if not done already.

👀 👉🏼 https://indianexpress.com/article/technology/tech-news-technology/34-apps-joker-malware-infected-android-uninstall-google-play-store-6701973/

#google #playstore #android #joker #malware
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
US official alleges big tech has started giving Hong Kong user data to China under new national security law

A senior US state official has alleged that big tech companies are already handing over Hong Kong user data to Chinese officials, The Guardian reports. Hong Kong has been drastically changed this year by a new national security law which firmly put Hong Kong in China’s vice grip. The official, whose anonymity The Guardian has maintained, explained why we might not have heard anything from tech giants like Facebook and Google:

There is a possibility that things are happening but because of the restrictions put on by the Hong Kong authorities, they [companies] would not be able to divulge this. The company would be told by mainland authorities ‘you will be breaking the [law] if you reveal the fact that I’m asking for this information.’

Facebook and Google declined to comment to The Guardian on the allegations. One Hong Kong activist who now lives abroad, Glacier Kwong, commented:

I don’t want to put it that way but I will. If Google or other technology companies comply with this national security law, it is actually helping indirectly the Hong Kong government, the Chinese government, to oppress or crack down on the civil society.

👀 👉🏼 https://www.privateinternetaccess.com/blog/us-official-alleges-big-tech-has-started-giving-hong-kong-user-data-to-china-under-new-national-security-law/

#hongkong #china #bigtech #userdata #national #security #law #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Sonos is spying on me… (and you)

I recently decided to get a wireless speaker for our Kitchen. Sonos seems like an obvious choice these days. The sound quality and aesthetics were very appealing. So I ordered a Sonos One SL speaker.

In terms of sound quality and looks, I was very pleased. I’m not an audiophile but the sound quality seemed superb and the speaker just looks fantastic. A very clean and unassuming look.

As I later discovered, a dirty beast hides under the cool exterior.

My concerns started to grow almost immediately as I was setting up the new speaker. I downloaded the app, and started the setup process, soon to realize that I need to register with my email just to set up the device on my network… And of course, I had to accept the terms and conditions …. hmmm… ok, I guess.

I was then asked to allow sharing my location as well, which raised another alarm bell. Why does my speaker need my location? I’m not 100% sure, but if I recall, I had to allow it to access my location, or else I couldn’t continue.

Once the device was finally set up, I went through the settings, to explore and see what else is there. I was rather disappointed to find that “Additional usage data” was turned on by default. I live in Europe, and I thought that the EU regulations should prevent this kind of behaviour. They should explicitly ask my permission to track my usage, especially if it isn’t necessary for the device to function.

I could opt-out of it luckily, but it didn’t feel right to me.

👀 👉🏼 What data is Sonos collecting, and why?
https://blog.gingerlime.com/2020/sonos-is-spying-on-me-and-you/

‼️ Digging into the Sonos privacy policy made my hair stand…
https://www.sonos.com/en/legal/privacy

#sonos #privacy #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Hacker Uploads Own Fingerprints To Crime Scene In Dumbest Cyber Attack Ever

Max Heinemeyer, director of threat hunting at Darktrace, thought it would be interesting to look back at the seven years since launching its AI-powered cybersecurity solution. Look back through the lens of some of the weirdest attacks that the AI cyber-brain had identified that is. You know what, he was right. I've been around cybersecurity for 30 years, but Heinemeyer revealed one of the dumbest cyber attacks I've ever encountered.

To be honest, as a 'greybeard' who has spent most of his working life in the cybersecurity space, I've seen some pretty weird hacking stuff go down. There was the time in 2010 that hackers replaced an image of the then Spanish Prime Minister with a picture of Mr. Bean on the EU presidency site. Or how about, in 2012, when an Iranian nuclear facility was reportedly hacked so as to play Thunderstruck by AC/DC at full volume? The Darktrace AI does, however, seem to have a knack of uncovering bizarre, unconventional, and undoubtedly original cyber attacks as they happen. The dumbest, though, has to be the hacker who uploaded their own fingerprints to the scene of the cybercrime.

👀 👉🏼 https://www.forbes.com/sites/daveywinder/2020/10/04/hacker-uploads-own-fingerprints-to-crime-scene-in-dumbest-cyberattack-ever

#cyberattack #hacker #truecrime #fingerprints #dumb
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Internet history can be used for “reidentification” finds study by Mozilla

A recent research paper has reaffirmed that our internet history can be reliably used to identify us. The research was conducted by Sarah Bird, Ilana Segall, and Martin Lopatka from Mozilla and is titled: Replication: Why We Still Can’t Browse in Peace: On the Uniqueness and Reidentifiability of Web Browsing Histories. The paper was released at the Symposium on Usable Privacy and Security and is a continuation of a 2012 paper that highlighted the same reidentifiability problem.

‼️ Just your internet history can be used to reidentify you on the internet ‼️

Using data from 52,000 consenting Firefox users, the researchers were able to identify 48,919 distinct browsing profiles which had 99% uniqueness.

This is especially concerning because internet history is routinely sold by your internet service provider (ISP) and mobile data provider to third party advertising and marketing firms which are demonstrably able to tie a list of sites back to an individual they already have a profile on – even if the ISP claims to be “anonymizing” the data being sold. This is a legally sanctioned activity ever since 2017 when Congress voted to get rid of broadband privacy and allow the monetization of this type of data collection.

This type of “history-based profiling” is undoubtedly being used to build ad profiles on internet users around the world. Previous studies have shown that an IP address usually stays static for about a month – which the researchers noted: “is more than enough time to build reidentifiable browsing profiles.”

👀 👉🏼 (PDF)
https://www.usenix.org/system/files/soups2020-bird.pdf

👀 👉🏼 https://www.cozyit.com/internet-history-can-be-used-for-reidentification-finds-study-by-mozilla/

#mozilla #study #research #internet #history #reidentification #thinkabout #pdf
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
💡 UPDATE💡- KuCoin: Hackers steal 150 million US dollars from Bitcoin stock exchange

A quick update since my last livestream on Sep 30.

After a thorough investigation, we have found the suspects of the 9.26 #KuCoin Security Incident with substantial proof at hand. Law enforcement officials and police are officially involved to take action.

👀 👉🏼 https://nitter.net/lyu_johnny/status/1312359615091277824

#KuCoin #bitcoin #exchange #hacker #hacked #attack
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Stop the EARN IT Bill Before It Breaks Encryption

The House and Senate are both pushing forward with the so-called “EARN IT” Act, a bill that will undermine encryption and free speech online. Attorney General William Barr and the DOJ have demanded for years that messaging services give the government special access to users’ private messages. If EARN IT passes, Barr will likely get his wish—law enforcement agencies will be able to scan every message sent online.

💡 The EARN IT Act (S. 3398) is anti-speech, anti-security, and unnecessary. It could come to the Senate floor this month—we need to tell Congress to reject this dangerous proposal.

👀 👉🏼 https://act.eff.org/action/stop-the-earn-it-bill-before-it-breaks-encryption-a7904e20-2083-4d5e-88ae-44ee5fef7a5d

#eff #earnit #bill #encryption #freespeech #usa #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Breaking News: Computer Anti-Virus Guru John McAfee Arrested in Spain on U.S. Tax Evasion Charges

Millionaire recluse McAfee has been arrested by authorities in Spain and is awaiting extradition to the US.

Computer Anti-Virus developer John Mcafee has been charged with tax evasion by federal prosecutors. They allege McAfee used nominee names to hide cryptocurrency, a yacht, and real estate as part of a conspiracy to evade taxes.

Authorities in Spain have been careful not to mention where Mcafee was detained. Mcafee is notorious for hiding his location and after being arrested over 22 times maybe this time the US justice system have their man.

👀 👉🏼 https://www.euroweeklynews.com/2020/10/05/computer-anti-virus-guru-john-mcafee-arrested-in-spain-on-u-s-tax-evasion-charges/

#mcafee #arrested #spain
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
ADB-Toolkit – A Tool for testing your android device (and hack "pentest" someones android phone)

ADB-Toolkit
is a BASH Script with 28 options and an METASPLOIT Section which has 6 options which is made to do easy penetration testing in Android Device. You can do pretty much anything with this script and test your android device is it safe or not. This script is made with the help of ADB (Android Debug Bridge) it’s a tool which is used for the developers for debugging the android device but as we know everything has it’s two side a good and a bad and I’m not telling you to do bad things but we don’t do illegal things or FBI will find you :D.

👀 👉🏼 https://copycookie.com/adb-toolkit-tool-for-hack-someone-android-phone/

#adb #android #pentest #script #metasploid #tool #thinkabout #knowledge
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Warning about using graphics from Clipartstation.com ‼️

Robert Kneschke charges 450 EUR for a children's drawing

One of our most active users, voluntarily maintains a homepage for a small elementary school. In the course of this he downloaded a children's drawing from clipartstation.com for a vacation article. The site advertises that all kinds of graphics can be used free of charge, so the user thought he had fulfilled his obligations to check the copyright. But the graphic is in truth by Robert Kneschke.

The problem is that the site does not have an imprint. The English language links about privacy and copyright also lead to empty pages. Cloudflare protects the location of the web servers from being discovered. And also the Whois query of the domain Clipartstation.com does not reveal any useful information, not surprisingly. Since everything is anonymous, thanks to GoDaddy, one must unfortunately assume that the operators do not usually take it so closely with copyright law. Whoever uses graphics from there should be prepared for possible disciplinary warnings!

👀 👉🏼 Translated with DeepL:
https://tarnkappe.info/robert-kneschke-verlangt-450-eur-fuer-eine-kinderzeichnung/

#warning #alert #fraud #kneschke #clipartstation #copyright
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Facebook’s latest “groups” disaster will only make it more toxic

Every single time Facebook could improve, it doubles down on causing more harm.

Facebook is pushing yet another set of new features and policies designed to minimize harm in the homestretch to Election Day while also increasing "community" for users. But these features will do nothing to mitigate existing problems—and they will likely cause new, more widespread harms to both users and to society.

The most recent issue is a frustrating set of changes to the way that Facebook handles groups. Last week, Facebook announced yet another new way to "help more people find and connect with communities," by putting those communities in your face whether you want to see them or not. Both the groups tab and your individual newsfeed will promote group content from groups you are not subscribed to in the hope that you will engage with the content and with the group.

These changes are new, small inconveniences piled atop frustrating user-experience decisions that Facebook has been making for more than a decade. But they are the latest example of how Facebook tries to shape every user's experience through black box algorithms—and how this approach harms not only individuals but the world at large. At this point, Facebook is working so hard to ignore expert advice on how to reduce toxicity that it looks like Facebook doesn't want to improve in any meaningful way. Its leadership simply doesn't seem to care how much harm the platform causes as long as the money keeps rolling in.

👀 👉🏼 https://arstechnica.com/tech-policy/2020/10/facebooks-endless-quest-for-engagement-is-dangerous-for-us-all/

#fb #facebook #DeleteFacebook #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
The #Epic @fedilab @k9mail cases have reinforced our strong stance that we must control the distribution channels of #FLOSS and no longer depend on the #PlayStore

A major threat to the adoption of an alternative is that users expect updates to be automatic but #Google made that possible only for the #PlayStore

Code Lutin will invest on @fdroidorg to make software update possible on non-rooted #Android devices thus, allowing people to adopt #FreeSoftware

#MécénatCodeLutin #DeleteGoogle #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Facebook, Twitter take action over Trump's misleading COVID-19 posts

(Reuters) - Facebook Inc and Twitter took action on posts from U.S. President Donald Trump on Tuesday for violating their rules against coronavirus misinformation by suggesting that COVID-19 was just like the flu.

Facebook took the post down but not before it was shared about 26,000 times, data from the company’s metric tool CrowdTangle showed.

“We remove incorrect information about the severity of COVID-19,” a company spokesman told Reuters.

The world’s largest social media company, which exempts politicians from its third-party fact-checking program, has rarely taken action against posts from the Republican U.S. president.

Twitter disabled retweets on a similar tweet from Trump on Tuesday and added a warning label that said it broke its rules on “spreading misleading and potentially harmful information related to COVID-19” but that it might be in the public interest for it to remain accessible.

During the 2019-2020 influenza season, the flu was associated with 22,000 deaths in the United States, according to estimates from the U.S. Centers for Disease Control and Prevention. (bit.ly/30ByG1m)

Since the first case of the novel coronavirus was recorded in the United States at the beginning of this year, more than 210,000 people in the country have died of the disease caused by the virus, the world’s highest death toll.

👀 👉🏼 https://uk.reuters.com/article/uk-twitter-trump/facebook-twitter-take-action-against-misleading-trump-comparison-of-covid-19-to-flu-idUKKBN26R2YQ

#trump #ToddlerTrump #twitter #facebook #corona #misinformation
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Awful AI

Awful AI is a curated list to track current scary usages of AI - hoping to raise awareness to its misuses in society

Artificial intelligence in its current state is unfair, easily susceptible to attacks and notoriously difficult to control. Often, AI systems and predictions amplify existing systematic biases even when the data is balanced. Nevertheless, more and more concerning the uses of AI technology are appearing in the wild. This list aims to track all of them. We hope that Awful AI can be a platform to spur discussion for the development of possible preventive technology (to fight back!).

➡️ Discrimination

➡️ Influencing, disinformation, and fakes

➡️ Surveillance

➡️ Social credit systems

➡️ Misleading platforms, and scams

➡️ Autonomous weapon systems and military

➡️ Awful research

👀 👉🏼 https://github.com/daviddao/awful-ai

#awful #ai #answers #guide #tool #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
US House subcommittee proposes imposing structural requirements on Google, Amazon, and others over anti-trust concerns

A US House of Representatives subcommittee issued a mammoth report urging curbs to the structure of Google, Amazon and other giant tech firms.

👀 👉🏼 pdf
https://fm.cnbc.com/applications/cnbc.com/resources/editorialfiles/2020/10/06/investigation_of_competition_in_digital_markets_majority_staff_report_and_recommendations.pdf

👀 👉🏼 https://www.zdnet.com/article/u-s-house-subcommittee-proposes-imposing-structural-requirements-on-google-amazon-et-al-over-anti-trust-concerns

#usa #report #digital #markets #google #amazon #antitrust #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag