Never forget the 3 kinds of people in your life.
1- Those who help you in difficult times.
2- Those who left you in difficult times.
3- Those who put you in a difficult situation.
We must read this book carefully in the era of AI: Asking the right questions 12th edition
Very important skill to have, not just for techical subjects
β’ phone is locked/unlocked
β’ screen is on/off
β’ if WhatsApp is open
β’ WiFi/mobile data
β’ when you start a phone call
β’ what kind of phone
β’ which devices are online (phone, laptop, web)
β’ when you leave home, arrive at work, or switch networks
When WhatsApp reveal your activity :)
But there is no fancy hacking things, just simply reacting to your message. Great paper from University of Vienna - SBA Research !
The attack needs no malware. The attacker only needs your phone number.
When someone sends you a message, WhatsApp send back a delivery receipt. Researchers found a way to spam invisible reactions that trigger these receipts without showing any notification. By measuring the timing of these silent receipts, an attacker can learn:
Your cheap gaming mouse from Amazon installs malware to steal your information??
You saw a huge deal in amazon, with a lot of reviews. (fake) So you buy the mouse and download the driver from the official site to get the best polling rate or settings. Then PC infected with RAT
What to do:
Upgrade to Windows 11 if hardware allows.
Replace the device with a new PC that supports Windows 11.
Enroll in Extended Security Updates (ESU)
Join us in Linux! There are plenty of user-friendly options. Check out PopOS!, ZorinOS, or Ubuntu.
Apple raised its bug bounty to $2 Million!
It might sound too much money but actually, it is not for these companies. Because when attackers discovers them, they can damage much higher or sell to governments etc. to damage the company in many other ways.
Researchers found that a large fraction of GEO transponders were carrying unencrypted data. The paper is titled βDonβt Look Up.β
Examples of what they observed
β’ T-Mobile calls and texts
β’ Military and law enforcement links
β’ Industrial control and utility traffic.
CamoLeak: Critical GitHub Copilot Chat flaw (CVSS 9.6) that could steal private code and secrets
CamoLeak lets an attacker place hidden instructions in a pull request.
Limit Copilot access to private repos. Grant least privilege.
Prompt injection will be a big issue, I guess
Hidden surveillance firm First Wap used a tool called Altamides to track phones worldwide.
Altamides is a network-level surveillance system. It queries telecom infrastructure to learn which cell tower a phone uses, and can also intercept SMS or call setup data.
I am always interested to see the impact of tech in our daily lives, education, and so on. We got an example from Australia: Two years after school smartphone bans and as a result calmer classrooms,Β less distraction and better social interaction:
https://t.co/LS931SmIxW
AI Crypto Trading - Alpha Arena: Deepseek takes the lead
Should I put money on AI to make some money? It shows that they make money but I think in long run, they will lose. Or when all learns about this and follow AI to trade, then it will drop again too :)))
A non-critical system can control the critical one.
The Jeep Uconnect case shows how an entertainment unit gave remote access to vehicle controls. Lateral movement is real. Segment networks.
Non-critical functions must not share a bus with safety or control systems.
I start my lectures each week with some news β to bridge what we study and whatβs actually happening out there and staying current.
So previously in Breaking Bad, or Last week in the tech world β innovation, exploitation, and everything in between:
>Most breaches start with weak/default passwords.
>Many industrial and #IoT protocols were built for trusted networks and lack modern security.
>IoT attacks can cause real physical harm or damage. What if your smart oven turned on and smoke detectors turned off?
#CyberSecurity