Email or username:

Password:

Forgot your password?
9 posts total
Zack Whittaker

NEW, by me: The check-in computers at several hotels around the U.S. are running a consumer-grade spyware app called pcTattletale.

pcTattletale was seen stealthily and continually capturing screenshots of the hotel booking systems, which contained guest information and reservation details.

This was discovered because a security researcher found a flaw in the spyware is exposing these screenshots to the internet, not just the spyware's intended users.

More: techcrunch.com/2024/05/22/spyw

NEW, by me: The check-in computers at several hotels around the U.S. are running a consumer-grade spyware app called pcTattletale.

pcTattletale was seen stealthily and continually capturing screenshots of the hotel booking systems, which contained guest information and reservation details.

This was discovered because a security researcher found a flaw in the spyware is exposing these screenshots to the internet, not just the spyware's intended users.

Ian Campbell

@zackwhittaker Suddenly the seemingly ubiquitous very-well-informed scam calls following hotel bookings make even more sense.

Wendy Nather

@zackwhittaker If I Recall correctly, this sounds really familiar …

Space Invader

@zackwhittaker I think you meant to write: “The check-in computers at several hotels around the U.S. are running a beta version of Microsoft Recall”

Zack Whittaker

For that absolute chef's kiss level of detail, the filenames of the screenshots posted by U.K. authorities on LockBit's dark web leak site read "oh dear.png", "doesnt_look_good.png" and "this_is_really_bad.png."

Zack Whittaker

Just my totally normal cat sleeping like he's been violently assassinated. Why, why sleep like this?

Show previous comments
PalmAndNeedle

@zackwhittaker We don't judge how you sleep :blobcat_grumpy:

/s

Daniel Reeders

@zackwhittaker oh my god the temptation to rub that belly must be irresistible

Zack Whittaker

New, by @Sarahp: A fake app that was masquerading as password manager LastPass on the App Store has been removed, whether by Apple or the fake app’s developer is yet unclear — Apple has not commented.

"That such an obviously fake app got through Apple’s App Review process is a bad look for the tech giant, which has been arguing against new regulations, like the EU’s Digital Markets Act, by claiming these laws would compromise customer safety and privacy."

More: techcrunch.com/2024/02/08/a-fa

New, by @Sarahp: A fake app that was masquerading as password manager LastPass on the App Store has been removed, whether by Apple or the fake app’s developer is yet unclear — Apple has not commented.

"That such an obviously fake app got through Apple’s App Review process is a bad look for the tech giant, which has been arguing against new regulations, like the EU’s Digital Markets Act, by claiming these laws would compromise customer safety and privacy."

Zack Whittaker

I hope everyone enjoys their evenings as much as my cat Toby enjoys basking in the evening sun.

Moira

@zackwhittaker I... may not have ever enjoyed anything as much as Toby enjoys basking in the evening sun.

Zack Whittaker

🚨 Google is sounding a rare alarm for users to *take action* to protect themselves against serious security flaws in Samsung chips found in dozens of popular Android handsets.

The flaws can be "silently and remotely" exploited over the cellular network.

Phones, tablets, wearables, and vehicles are all affected.

Samsung was given 90 days to patch the bugs, but hasn't yet.

More: techcrunch.com/2023/03/16/goog

Zack Whittaker

New, by @carlypage: LastPass parent company GoTo says intruders stole customer backups for several of its products, including Join.me and Remotely Anywhere. The hackers also obtained GoTo's encryption keys for scrambling customer data.

More: techcrunch.com/2023/01/24/goto

Zack Whittaker

New: LastPass said an "unauthorized party" gained access to customers' information stored in its cloud storage shared with its parent company, GoTo (formerly LogMeIn).

More: techcrunch.com/2022/11/30/last

Zack Whittaker

LastPass' CEO Karim Toubba, who was appointed in April, says the unauthorized party used information stolen from LastPass systems in August to access the cloud storage containing customer information.

Seems plausible that maybe stolen internal creds or keys weren't invalidated after the August breach, which allowed a second compromise?

More: techcrunch.com/2022/11/30/last

Go Up