Tor Vigesdal

74 Followers
67 Following
69 Posts
InfoSec Professional working as Advisor and CISO. GIAC GSLC, GDSA and GDAT. Scripter, architect, awareness, governance, risk and compliance. ISO2700x/NIST etc.
Twitter@dotBATman
I really should not be left to deal with my thoughts

tell all your neighbors

ring is gonna start feeding your video feeds to their AI

https://www.theregister.com/2025/06/25/amazons_ring_ai_video_description/

I learned something today: Google's Gemini "AI" on phones accesses your data from "Phones, Messages, WhatsApp" and other stuff whether you have Gemini turned on or not. It just keeps the data longer if you turn it on. Oh, and lets it be reviewed by humans (!) for Google's advantage in training "AI" etc.

But this only came to my attention because of an upcoming change: it's going to start keeping your data long-term even if you turn it "off": "#Gemini will soon be able to help you use Phone, #Messages, #WhatsApp, and Utilities on your phone, whether your Gemini Apps Activity is on or off."

This is, of course, a #privacy and #security #nightmare.

If this is baked into Android, and therefore not removable, I'd have to say I'd recommend against using Android at all starting July 7th.

https://www.extremetech.com/mobile/gemini-ai-will-soon-access-calls-and-messages-on-your-android-even-if-you

#spyware #AI #LLM #Google #spying #phone #Android #private #data

The system cannot.
John Oliver's Last Week Tonight mentions #Mastodon and #PixelFed as alternatives that are "not as desperate to fall in line with trump".
MITRE shares 2024's top 25 most dangerous software weaknesses

MITRE has shared this year's top 25 list of the most common and dangerous software weaknesses behind more than 31,000 vulnerabilities disclosed between June 2023 and June 2024.

BleepingComputer

Big, big oof: this report is a brutal must-read. Public-facing RCEs, pre-existing web shells, and feckless EDR. Defenders, we need to step up the game.

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-326a

UK Prime Minister Keir Starmer and Prince William deepfaked in investment scam campaign.

Read more in my article on the Bitdefender blog: https://www.bitdefender.com/blog/hotforsecurity/uk-prime-minister-keir-starmer-and-prince-william-deepfaked-in-investment-scam-campaign/

#cybersecurity #deepfake #keirstarmer #princewilliam #cryptocurrency #scam

UK Prime Minister Keir Starmer and Prince William deepfaked in investment scam campaign

Scammers are once again using deepfake technology to dupe unwary internet Facebook and Instagram users into making unwise cryptocurrency investments.

Hot for Security
Bike component maker Shimano issued a software update to the pro cycling teams who use its wireless gear shifters after researchers found that hackers can spoof or jam the shifters' signals to sabotage riders. Consumers get the patch later this month. https://www.wired.com/story/shimano-wireless-bicycle-shifter-jamming-replay-attacks/
Want to Win a Bike Race? Hack Your Rival’s Wireless Shifters

Please don’t, actually. But do update your Shimano Di2 shifters’ software to prevent a new radio-based form of cycling sabotage.

WIRED
Somehow I don’t think this is a crime committed by people that are trying to feed their family another day. #greed #despicable https://www.cnn.com/2024/06/14/business/faa-probe-counterfeit-titanium-boeing-airbus/index.html
Problematic titanium was found in Boeing and Airbus jets. The FAA is investigating how it got there

Titanium that was distributed with fake documentation has been found in commercial Boeing and Airbus jets. Now the Federal Aviation Administration, the aircraft manufacturers and supplier Spirit AeroSystems are investigating whether those components pose a safety hazard to the public.

CNN