The war on privacy and encryption goes on. This time in the UK. Under the “Children’s Wellbeing and Schools Bill”, lawmakers now want client-side scanning on every phone and tablet.
The lawmakers write: “Any relevant device supplied for use in the UK must have installed tamper-proof system software which is highly effective at preventing the recording, transmitting (by any means, including livestreaming) and viewing of CSAM using that device.”
Once again, they use “what about the children”, this time to install state spyware that would continuously scan every action on a phone or tablet and watch everything that is shown on the screen. This will effectively ban end-to-end encrypted communication and open source operating systems like GrapheneOS and forbid that people have administrator rights on their own devices.
The bill also seeks “Action to prohibit the provision of VPN services to children in the United Kingdom” and wants “all regulated user-to-user services to use highly-effective age assurance measures to prevent children under the age of 16 from becoming or being users.” In practice, this means identity checks for VPN users, making things like anonymous whistleblowing difficult.
The attack on secure and private communication is worldwide. Now is the time for resistance. Demand transparency from your politicians, and privacy for the people.
Today, we’re releasing watchTowr Labs’ @chudyPB’s BlackHat .NET research, owning Barracuda, Ivanti and more solutions.
Enjoy the read as Piotr explains a new .NET Framework primitive, used to achieve pre- and post-auth RCE on numerous enterprise appliances.
https://t.co/UvsetqL5yj
#React2Shell Someone asked which WAFs this bypass technique works on. AWS CloudFront be one answer. AWS recommends a rule that, with a bit of analysis, shows you can bypass using UTF-16 encoding.
Here’s an official AWS link for more details:
https://t.co/FmjAuvNL0P
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
Highly recommended to read the original but TLDR;
Stealth found a SSH 2 --> 1 downgrade that would not display the warning in case of a MITM. At CCC, German hacker conf, they MITM'd all SSH for 20 mins, getting SSH creds. Just before being discovered, they unplugged the cable.
Hacking prepaid cards for laundry: use vulnerabilities in MIFARE Classic to get unlimited credit.📟🛁💳🔀💸
More details on:
LinkedIn: https://t.co/mEhx5szRlI
Substack: https://t.co/NkWCOFoXek
Nvidia's fabled PCIe finger sells for under $25 in China, should you happen to break it — resuscitate your $10,000 GPU for less than a pair of fuzzy socks https://t.co/YQiuSCnrBZ
.@IceSolst made a satirical post about how their invention of "VSC" (Comma Separated Value, CSV backward) would improve LLM efficiency and replace JSON
People on LinkedIn took it serious. Some posts exceed 7,000 likes.
I'm going to kill myself
⚠️ EY Data Leak - Massive 4TB SQL Server Backup Exposed Publicly on Microsoft Azure
Read more: https://t.co/2U5pBNA6oN
A massive 4TB SQL Server backup file belonging to global accounting giant Ernst & Young (EY) was discovered publicly accessible on Microsoft Azure.
The file's naming convention screamed SQL Server backup (.BAK format), which typically contains full database dumps, including schemas, user data, and, crucially, embedded secrets such as API keys, credentials, and authentication tokens.
A simple HEAD request designed by researchers to retrieve metadata without downloading content revealed a massive size: 4 terabytes of data, which is equivalent to millions of documents or the contents of an entire library.
To Get Daily Security Updates, add Cyber Security News ® as your preferred source on Google -> https://t.co/N1wthFiEi3
#cybersecuritynews
��� Microsoft Teams to Auto-Set Work Location by Detecting the Wi-Fi Network
Read more: https://t.co/u6syCvbLmX
Microsoft is about to launch a new feature in Teams that will help hybrid workers stay connected. This feature will automatically find and update a user’s work location based on their organization's Wi-Fi network.
Set to roll out in December 2025, this opt-in capability aims to streamline collaboration by eliminating the hassle of manual location updates, helping teams better coordinate in-person interactions.
As remote and office-based work continues to blend, this update reflects Microsoft's push to make hybrid environments more intuitive and efficient.
#cybersecuritynews
🚨 Hackers just turned a Cisco zero-day (CVE-2025-20352) into a Linux rootkit dropper—hitting routers before the patch dropped.
The backdoor’s universal password was “disco.”
Learn more about the Operation Zero Disco ↓ https://t.co/gFtvlQyOLs
Today (4:00 PM GMT+2) @objective_see: Paweł Płatek shows a user-to-root exploit on modern macOS by chaining bugs in mDNSResponder and traceroute6. Learn new libmalloc exploitation techniques and PAC bypass methods.
https://t.co/Nrih1Dbm6n