Security News

Experts Create Apple AirTag Clone That Can Bypass Anti-Tracking Measures
2022-02-28 02:01

Cybersecurity researchers have managed to build a clone of Apple Airtag that circumvents the anti-stalking protection technology built into its Find My Bluetooth-based tracking protocol. The result is a stealth AirTag that can successfully track an iPhone user for over five days without triggering a tracking notification, Positive Security's co-founder Fabian Bräunlein said in a deep-dive published last week.

Free Android app lets users detect Apple AirTag tracking
2022-02-26 15:07

An Apple AirTag is a Bluetooth-based device finder released in April 2021 that allows owners to track the device using Apple's 'Find My' service. Although Apple has implemented an intricate anti-stalking system to prevent cases of abuse, stealthy AirTag tracking continues to remain a problem.

DPD Group parcel tracking flaw may have exposed customer data
2022-02-07 22:30

An unauthenticated API call vulnerability in DPD Group's package tracking system could have been exploited to access the personally identifiable details of its clients. DPD Group is a parcel delivery service with a global presence, shipping around two billion parcels annually worldwide.

Unpatched Security Bugs in Medical Wearables Allow Patient Tracking, Data Theft
2022-02-01 21:32

The rush to roll out remote healthcare has also unleashed a universe of wearable medical devices to collect sensitive data, which researchers say are widely vulnerable to attack. Analysts with Kaspersky Labs reported finding 33 vulnerabilities last year in the most widely used data transfer protocol for internet of things medical devices, known as MQTT - that's 10 more than the previous year.

Tracking Secret German Organizations with Apple AirTags
2022-01-28 12:13

A German activist is trying to track down a secret government intelligence agency. Wittmann says that everyone she spoke to denied being part of this intelligence agency.

Google Drops FLoC and Introduces Topics API to Replace Tracking Cookies for Ads
2022-01-26 20:34

Google on Tuesday announced that it is abandoning its controversial plans for replacing third-party cookies in favor of a new Privacy Sandbox proposal called Topics, which categorizes users' browsing habits into approximately 350 topics. Subsequently, when a user visits a participating site, the Topics selects three of the interests - one topic from each of the past three weeks - to share with the site and its advertising partners.

New Unpatched Apple Safari Browser Bug Allows Cross-Site User Tracking
2022-01-16 19:34

A software bug introduced in Apple Safari 15's implementation of the IndexedDB API could be abused by a malicious website to track users' online activity in the web browser and worse, even reveal their identity. That's not the case with how Safari handles the IndexedDB API in Safari across iOS, iPadOS, and macOS. "In Safari 15 on macOS, and in all browsers on iOS and iPadOS 15, the IndexedDB API is violating the same-origin policy," Martin Bajanik said in a write-up.

Firefox Focus now blocks cross-site tracking on Android devices
2022-01-11 20:42

Mozilla's Firefox Focus web browser can now protect Android users against cross-site tracking while browsing the Internet by preventing cookies from being used for advertising and monitoring your activity. "We're bringing it to Firefox Focus on Android, our simple, privacy by default companion app. Firefox Focus on Android will be the first Firefox mobile browser to have Total Cookie Protection," Mozilla said today.

France Fines Google, Facebook €210 Million Over Privacy Violating Tracking Cookies
2022-01-06 23:35

The Commission nationale de l'informatique et des libertés, France's data protection watchdog, has slapped Facebook and Google with fines of €150 million and €60 million for violating E.U. privacy rules by failing to provide users with an easy option to reject cookie tracking technology. HTTP cookies are small pieces of data created while a user is browsing a website and placed on the user's computer or other device by the user's web browser to track online activity across the web and store information about the browsing sessions, including logins and details entered in form fields such as names and addresses.

New Gummy Browsers attack lets hackers spoof tracking profiles
2021-10-20 13:49

University researchers in the US have developed a new fingerprint capturing and browser spoofing attack called Gummy Browsers. The 'Gummy Browsers' attack is the process of capturing a person's fingerprint by making them visit an attacker-controlled website and then using that fingerprint on a target platform to spoof that person's identity.