As of February 21, Apple device users in the UK began seeing a notice that the iCloud end-to-end encryption feature is no longer available in their region. That stems from a secret order recently issued by the Home Office, only made known to the public due to inside sources leaking it to the media, requiring Apple to start implementing backdoor access to encrypted cloud data and to begin complying immediately.
October is National Cyber Security Awareness Month and the time to focus on improving cyber security awareness training and boosting overall cyber security resilience.
Microsoft Azure Cosmos DB cloud databases have had their read-write keys exposed by a flaw that has been present since 2019, allowing an attacker to not just access the contents but also to change or delete them.
The new Apple IDFA terms will soon require apps that use ad tracking to obtain consent via a pop-up. Facebook is pre-empting it with their own pop-up that tries to convince the user to opt in.
China publicly accuses CIA of 11 years of cyber espionage however the report has little to offer as hard evidence and there is no previous reference on the alleged hacking group.
The head of Iran Civil Defense has accused Washington of the latest large-scale DDoS attack that targeted Iranian infrastructure, shutting down 25% of Iran's Internet.
Apple's new iOS 14 privacy labels will address data collection by displaying "data used to track you" and "data linked to you" for each app that is installed on a device.
Octo Tempest has gradually stepped up from data theft, to data extortion, and now to ransomware as of this summer (becoming an affiliate of the ALPHV/BlackCat group). The cybercriminals are entirely financially motivated and nearly always leads with either a phishing email/message or a social engineering call. It also looks to execute SIM swap attacks.
Several Android apps using misconfigured cloud services for storage, real-time communication and synchronization exposed sensitive information of over 100 million smartphone users.
Business users' billing information was inadvertently stored in the browser's cache, making it possible for the exposed data to be accessed by users who share computers.









