Meanwhile, on Patch Tuesday. Solid Advise.
Category: Security & Privacy
-
Phones Open to Attack through WhatsApp Flaw
Meanwhile, another flaw from the Facebook universe. While it appears it’s not immediately related to data leakage, it gives great potential to 3rd parties, though. On the upside, nobody will attribute it to Facebook this time.
It’s a good opportunity to point out and recommend the alternatives to Whatsapp, in particular Signal and Threema.
A WhatsApp vulnerability left Android and iOS devices open to attack from sophisticated surveillance software. The Facebook-owned company said it hasn’t yet been able to determine how many people were impacted, and told users to ensure they’re running the latest version of the app.
Source: WhatsApp Flaw Left Phones Open to Attack From Sophisticated Spyware | Digital Trends
-
google.io 2019
News Coverage and liveblogs on Google I/O over on TechCrunch, The Verge and Engadget.
Most noteworthy, Google released a new, more affordable Pixel 3a, updates to Google Assistant, put more emphasis on security upgrades. In other announcements, Nest Hub has been pronounced the new name for Google Home Hub, along with a bigger ‘Max’ edition of the device. There are also announcements on Android 10 Q, which The Verge covered previously
-
Stealthy Microsoft Exchange backdoor discovered
The LightNeuron Microsoft Exchange backdoor can read, modify or block emails going through the compromised server, and even compose and send new emails.
Source: Researchers discover highly stealthy Microsoft Exchange backdoor – Help Net Security
-
Why Do Companies Need All That Personal Data They’re Collecting?
It’s the Tech perspective, but has the potential for a good debate. Under GDPR it’s not even compliant and still plenty of companies collect all data they can get hold of. Driven by Big Data vendors telling the narrative of Data Lakes, that only require you the data today, should you want to ask any question you don’t know yet in the future.
Only – have you ever come up with a question that you could not answer based on the data that is already available? Based on data that you collected in a Data Lake?
Big disclaimer: personally I don’t conclude with the assumptions made in the initial article, but the question is worth thinking about. In particular because most organizations I met until today are not metric driven in first place.
Source: Ask Slashdot: Why Do Companies Need All That Personal Data They’re Collecting? – Slashdot
-
Chinese woman carrying malware arrested at Trump’s Mar-a-Lago resort
In Mar-a-Lago, Donald Trump’s ganz eigenem Lieblings-Golfresort, ist eine Frau mit Malware auf einem USB Stick verhaftet worden. What a time to be alive. Es fehlt eigentlich nur noch, dass Sicherheitsdienste ausgebildete USB Spürhunde mitbringen.
A worrisome development for the US Tweeter-in-Chief
Source: Chinese woman carrying malware arrested at Trump’s Mar-a-Lago resort – The Verge
-
PEAR PHP gibt es noch
PEAR PHP ist Rechnologie, die schon im Einsatz war als ich noch PHP programmiert habe. Das war 1999. Schon damals hatte das keinen besonders guten Ruf. Offenbar gibt es das Repository immer noch. Und es scheint immer noch problematisch zu sein.
If you installed PEAR PHP in the last 6 months, you may be infected
Pear.php.net shuts down after maintainers discover serious supply-chain attack.
Source: Ars Technica


