Security News

Babylon mobile health app mixes up patient consultation videos
2020-06-10 12:48

Mobile health app Babylon, which states its company mission as putting "An accessible and affordable health service in the hands of every person on earth", has admitted to a software bug that went one step further than that. The user, named by the BBC as Rory Glover from Leeds in England, apparently used the app to check up on a prescription of his own, only to find that the "Consultation Replays" feature of the app contained a list of 50 videos for him to review.

TikTok Flaw Allows Threat Actors to Plant Forged Videos in User Feeds
2020-04-14 12:07

A security weakness in the popular TikTok video-sharing service allows a local attacker to hijack any video content streamed to a user's TikTok feed and swap it out with hacker-generated content. In their proof-of-concept attack, Mysk and Bakry demonstrated how popular TikTok users, using verified accounts, could have their video streams hijacked to show misleading videos downplaying the severity of the COVID-19 pandemic.

TikTok users beware: Hackers could swap your videos with their own
2020-04-14 09:39

Mobile app developers Tommy Mysk and Talal Haj Bakry just published a blog article entitled "TikTok vulnerability enables hackers to show users fake videos". We used a similar approach to Mysk and Haj Bakry to look at the network traffic produced by TikTok - we installed the tPacketCapture app on Android and then ran the TikTok app for a while to flip through a few popular videos.

Google Shared Private Videos With Wrong Users
2020-02-05 20:18

The bug, which Google describes as a technical issue, was triggered when users requested a Google "Download your data" export. In the notification sent to the impacted users, Google reveals that those who used Takeout to download their data might have ended up with someone else's videos in their Google Photos backups.

Someone else may have your videos, Google tells users
2020-02-05 11:58

During this time, some videos in Google Photos were incorrectly exported to unrelated users' archives. Conversely, being a two-way issue, affected users might notice any videos in their archive not belonging to them.

Google Takeout a bit too true to its name after potentially 1000s of private videos shared with complete strangers
2020-02-05 00:48

A bug in Google's Photo software caused potentially 100,000 or more netizens to have their personal videos exposed to complete strangers last Thanksgiving. The Chocolate Factory this week began notifying punters that a bug in its data-archiving tool Takeout was to blame for some accounts having their private videos shared with total strangers.

Google Accidentally Shared Private Videos of Some Users With Others
2020-02-04 15:59

Google might have mistakenly shared your private videos saved on the company's servers with other users, the tech giant admitted yesterday in a security notification sent quietly to an undisclosed number of affected users. According to a screenshot Jon Oberheide of Duo Security shared on Twitter, the issue reportedly remained active between 21st November and 25th November last year, during which "Some videos in Google Photos [service] were incorrectly exported to unrelated user's archives."

Google Accidentally Shared Private Videos of Some Users With Others
2020-02-04 07:59

Google might have mistakenly shared your private videos saved on the company's servers with other users, the tech giant admitted yesterday in a security notification sent quietly to an undisclosed number of affected users. According to a screenshot Jon Oberheide of Duo Security shared on Twitter, the issue reportedly remained active between 21st November and 25th November last year, during which "Some videos in Google Photos [service] were incorrectly exported to unrelated user's archives."

Baby's First Data Breach: App Exposes Baby Photos, Videos
2020-01-14 09:03

The logs record when someone uses the Peekaboo app and the specific action they took at a certain point in time, such as uploading data or content. Exposed data includes email addresses, detailed device data and often, links to photos and videos, all of which get stored on servers hosted by Singapore-based Alibaba Cloud.

TikTok on the clock, and the hacking won't stop: SMS spoofing vuln let baddies twiddle teens' social media videos
2020-01-08 18:01

TikTok, a mobile video app popular with teens, was vulnerable to SMS spoofing attacks that could have led to the extraction of private information, according to infosec researchers. If the user clicked that malicious link, the attacker could access the user's TikTok account and, so Check Point said, manipulate its content by deleting videos, uploading new videos and making private or "Hidden" videos public.