19 Followers
138 Following
58 Posts
Today: Software developer (write (code); research (malware););
Before that: Lawyer (47 U.S. Code § 230, the Israeli version).
Here mostly to read and learn, maybe post some rants about privacy, data protection or information security issues.
#privacy #databreach #dataprotection
personal / heb accounthttps://leftodon.social/@usabach
Time ZoneUTC + 02:00
codec, c++, c#, python
1st modelZX Spectrum
pronomhe/him
VICTORY! EFF’s clients just ended a dragnet government surveillance program that spied on Sacramento residents’ electricity data. https://www.eff.org/deeplinks/2025/11/victory-court-end-dragnet-electricity-surveillance-program-sacramento
Victory! Court Ends Dragnet Electricity Surveillance Program in Sacramento

For more than a decade, the Sacramento Municipal Utility District coordinated with police to sift through the granular smart meter data of residents without suspicion to find evidence of cannabis growing.

Electronic Frontier Foundation

RE: https://infosec.exchange/@BleepingComputer/115588709520660643

BleepingComputer says Crowdstrike has confirmed that an "insider" was caught sharing screenshots taken on internal systems. Bleeping reports that those ended up in the hands of Scattered Lapsus$ Hunters.

I'm guessing someone at Crowdstrike was responding to the group's recent posts on Telegram, where they said they were buying insider access to large companies. Here's the text of one recent solicitation:

"DM us to sell your IA on % locking with all major lockers depending on target; must be ready to run AD commands or Okta commands, or show /etc/openldap/ldap.conf /var/log and ip -a addr && ssh -i /home/$$/.ssh/*pem $$@(ip addr ip's) or anything else you find relevant to showing us

Rules:
- no companies under 500M revenue
- no RF/PRC/DPRK/Belarus companies

IA rates:
25% for any AD joined system.
10% for Okta, Azure portal, AWS IAM root, etc

were also recruiting employees/insider at the following!!!!

- Any company providing Telecommunications (Claro, Telefoinica, ATT, and other similar)
- Large software/gaming corporations (Microsoft, Apple, EA, IBM, other similar)
- Callcenter/BPM (Atento, Teleperformance, and other similar)
- Server hosts (OVH, Lcaweb, and other similar)

If you are not sure if you are needed then send a DM and we will respond!!!!
If you are not a employee here but have access such as VPN or VDI then we are still interested!!

You will be paid if you would like. Contact us to discuss that"

EFF teamed up with AV Comparatives to see how well anti-virus apps detect stalkerware on Android phones.

https://www.eff.org/deeplinks/2025/11/eff-teams-av-comparatives-test-android-stalkerware-detection-major-antivirus-apps

Friends, I’m in a bit of a tough spot.

My business is growing but not fast enough to pay the bills.

I need some kind of extra work to keep my family fed and my house over my head.

I’m an expert in #php, systems design, and WordPress. I do devops and development. My website is https://sarah-savage.com

Can you help me get #fedihired
? Please boost for reach.

Sarah Savage - A fusion of development and business

A fusion of development and business

Sarah Savage - A fusion of development and business

EFF, Access Now, Amnesty International, Human Rights Watch, Fight for the Future, and 7amleh recently wrote to Microsoft calling on the company to cease any further involvement in providing AI & cloud computing technologies for use in Israel’s ongoing genocide against Palestinians in the Gaza Strip.

https://www.eff.org/deeplinks/2025/10/eff-and-five-human-rights-organizations-urge-action-around-microsofts-role-israels

EFF and Five Human Rights Organizations Urge Action Around Microsoft’s Role in Israel’s War on Gaza

EFF, Access Now, Amnesty International, Human Rights Watch, Fight for the Future, and 7amleh sent a letter to Microsoft last month calling on the company to cease any further involvement in providing AI and cloud computing technologies for use in Israel’s ongoing genocide against Palestinians in the Gaza Strip.

Electronic Frontier Foundation
Remember when we found out that Russian intelligence services are funding several prominent right-wing media figures and then the story just blew away like a feather in the wind and no one ever talked about it again?
AI/LLM models intended to help with programming refuse to work when they encounter a forbidden word (gender, sex, trans and so on). It's important to develop methods to circumvent such truncations. Is it really reasonable to call such methods as 'abuse'? https://github.com/orgs/community/discussions/72603
Copilot stops working on `gender` related subjects · community · Discussion #72603

As some people already mentioned here or here, Copilot purposely stops working on code containing hardcoded banned words from Github such as gender or sex. I am labelling this as a bug because this...

GitHub
Russian cyber threat actor Turla hacked 33 infrastructure nodes of Pakistani cyber threat actor to attack other targets, to deploy own cyber tools (malware) for cy-espionage purposes in the Middle East, like India. It delays attribution. What's the most vulnerable sensitive authorization in the world? "nation-state and cybercriminal endpoints and malware especially vulnerable to exploitation since they are unable to use modern security tools for monitoring access" https://blog.lumen.com/snowblind-the-invisible-hand-of-secret-blizzard/
Snowblind: The Invisible Hand of Secret Blizzard - Lumen Blog

A prolinged espionage campaign by Russian threat group Turla to penetrate Pakistani targets and the Pakistanis themselves

Lumen Blog
It appears Google's Chrome browser has started disabling the popular ad blocker uBlock Origin. https://www.pcmag.com/news/googles-chrome-browser-starts-disabling-ublock-origin
OpenAI says Iran tried to influence US elections with ChatGPT

OpenAI has banned accounts from a covert Iranian influence operation using ChatGPT to generate articles and social media posts related to the US presidential election

The Verge