AA
@aakl.bsky.social
160 followers 200 following 1.7K posts
Always questioning. Latest news focused on #cybersecurity, #privacy, #Apple, #Microsoft, #Google, #AI. Mainly posting on infosec.exchange: I post more here: https://infosec.exchange/@AAKL
Posts Media Videos Starter Packs
Reposted by AA
nymag.com
In only two years, ChatGPT has unraveled the entire academic project.

James D. Walsh writes for @intelligencer.com: nymag.com/intelligence....
Reposted by AA
macrumors.bsky.social
iPhone Users Now Able to Submit Claims in $95 Million Siri Spying Lawsuit
iPhone Users Now Able to Submit Claims in $95 Million Siri Spying Lawsuit
If you owned a Siri-compatible device and had an accidental Siri activation between September 17, 2014 and December 31, 2024, you could be eligible for a payment from Apple as part of a class action lawsuit settlement. Apple in January agreed to pay $95 million to settle a class action lawsuit involving ‌Siri‌ spying accusations, and a website to distribute the funds has now been set up and those eligible to submit a claim are starting to be informed via email. Between now and July 2, 2025, U.S. Apple device owners can submit a claim if they had an accidental ‌Siri‌ activation on a Siri-enabled iPhone, iPad, Apple Watch, Mac, HomePod, iPod touch, or Apple TV during the relevant period. Claims for up to five ‌Siri‌ devices can be submitted, as long as the claimant pledges that each device was part of an accidental ‌Siri‌ activation during a conversation that was meant to be confidential or private. Settlement class members that submit a valid claim will receive a portion of the net settlement amount, which is capped at $20 per ‌Siri‌ device. The amount that's ultimately awarded could increase or decrease based on the total number of valid claims submitted. Eligible Apple device owners will be receiving an email or postcard about the settlement, but those who feel they are eligible that did not receive a claim notice can still submit a claim form. The original lawsuit dates back to 2019, and it was filed after a report indicated that some private conversations of Apple device owners were overheard by contractors evaluating Siri when ‌Siri‌ was accidentally activated. Apple was not secretive about the fact that some ‌Siri‌ recordings were analyzed by humans, but the company's privacy terms at the time did not explicitly state that there was human oversight of ‌Siri‌, and that third-party contractors were being used. The initial lawsuit was actually dismissed because there wasn't enough data about the ‌Siri‌ recordings that Apple allegedly collected, but it was refiled with a claim that Apple used ‌Siri‌ recordings for "targeted advertising," and it moved forward. There is no evidence that Apple has ever provided ‌Siri‌ recordings or information from ‌Siri‌ recordings to advertisers. In a statement to MacRumors earlier this year, Apple confirmed that ‌Siri‌ data has never been used for marketing purposes. Siri has been engineered to protect user privacy from the beginning. Siri data has never been used to build marketing profiles and it has never been sold to anyone for any purpose. Apple settled this case to avoid additional litigation so we can move forward from concerns about third-party grading that we already addressed in 2019. We use Siri data to improve Siri, and we are constantly developing technologies to make Siri even more private. Apple settled the lawsuit in order to avoid further litigation fees, and as part of the settlement, Apple denied "any and all alleged wrongdoing and liability." Following the 2019 ‌Siri‌ scandal involving contractors listening to accidental ‌Siri‌ recordings, Apple temporarily suspended its ‌Siri‌ evaluation program, stopped using contractors, and implemented options that allow users to delete ‌Siri‌ recordings and block them from being listened to. In later updates, Apple moved some ‌Siri‌ processing on-device, limiting the data that is uploaded to Apple's servers. After the claim period ends on July 2, there will be a final approval hearing on August 1. At some point after that, the funds will be distributed to Apple customers.Tags: Apple Lawsuits, Siri This article, "iPhone Users Now Able to Submit Claims in $95 Million Siri Spying Lawsuit" first appeared on MacRumors.com Discuss this article in our forums
www.macrumors.com
Europol: DDoS-for-hire empire brought down: Poland arrests 4 administrators, US seizes 9 domains www.europol.europa.eu/media-press/... @europol-eu.bsky.social #cybersecurity #DDoS
Symantec: Ransomware Attackers Leveraged Patched Privilege Escalation Zero-day CVE-2025-29824 www.security.com/threat-intel... #cybersecurity #ransomware
Cisco has tagged PDF-XChange Co. Ltd for a zero-day report talosintelligence.com/vulnerabilit... #cybersecurity

Also - yikes.

Cisco has a ton of vulnerabilities listed - two pages of them sec.cloudapps.cisco.com/security/cen... @talosintelligence.com #cybersecurity #Cisco
Cofense: Using Blob URLs to Bypass SEGs and Evade Analysis cofense.com/blog/using-b... #cybersecurity
ESET: Beware of phone scams demanding money for ‘missed jury duty’ www.welivesecurity.com/en/scams/pho... @esetresearch.bsky.social #scam #cybersecurity
Reposted by AA
newsguy.bsky.social
“Bringing VOA out of a deep coma will require substantial time and a Herculean effort of our nearly 50 language services to try to reach some of our pre-shutdown total audience of 340 million,” VOA chief national correspondent Steve Herman told CNN.
www.cnn.com/2025/05/03/m... #WPFD2025 #SaveVOA
Voice of America’s fate still in flux after appeals court pauses back-to-work orders | CNN Business
About 1,400 Voice of America employees and contractors at its parent agency, the US Agency for Global Media, gained access to their email accounts and other systems on Saturday. But later in the day, ...
www.cnn.com
Reposted by AA
newsguy.bsky.social
"VOA is not to be the voice of left America nor the voice of right America," said Steve Herman, chief national correspondent for VOA. "USAGM cannot dictate [that] VOA run OAN content. It would be a violation of our fire wall and our charter, which are laws." https://www.washingtonpost.com/style/medi
Voice of America will carry One America News programming
Staffers at the government-funded broadcaster condemned the announcement from Kari Lake, given OAN’s right-wing slant and support of President Donald Trump.
www.washingtonpost.com
COLDRIVER is a Russian government-backed threat group.

Mandiant: COLDRIVER Using New Malware to Steal Documents From Western Targets and NGOs cloud.google.com/blog/topics/... #cybersecurity #malware
More about the exploitation of CVE-2025-29824: nvd.nist.gov/vuln/detail/...

Halcyon: Play Ransomware Group Exploits Windows CLFS Zero-Day Vulnerability www.halcyon.ai/blog/play-ra... #cybersecurity #Microsoft #Windows #ransomware
Huntress: "The latest version (21.1050.0) is vulnerable to a publicly available proof-of-concept (PoC). We have also observed exploitation in the wild impacting the latest version."

Huntress Rapid Response: Samsung MagicINFO 9 Server Flaw www.huntress.com/blog/rapid-r... #Samsung #cybersecurity
Kaspersky: State of ransomware in 2025 securelist.com/state-of-ran... @kasperskylab.bsky.social y #cybersecurity #ransomware
Reposted by AA
newhercules.bsky.social
Gift article: NY Times.

"Republican leaders sell the extension of the tax law as tax cuts “for everybody,” “the biggest bill in our history." But the reality is it’s no cut at all for most people. The rates preserved have been in place for more than 7 years now.
www.nytimes.com/2025/05/07/o...
Opinion | The Political Tariff Trap for Republicans
www.nytimes.com
Securonix: Hunting Kerbrute: Analysis, Detection and Mitigation of Kerberos Attacks in Active Directory www.securonix.com/blog/hunting... #cybersecurity #Microsoft
Trend Micro: Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal www.trendmicro.com/en_us/resear... @trendmicro.bsky.social #cybersecurity #ransomware
Unit42: Iranian Cyber Actors Impersonate Model Agency in Suspected Espionage Operation unit42.paloaltonetworks.com/iranian-atta... #cybersecurity #espionage
WatchTower: SysOwned, Your Friendly Support Ticket - SysAid On-Premise Pre-Auth RCE Chain (CVE-2025-2775 And Friends) labs.watchtowr.com/sysowned-you... #cybersecurity
Reposted by AA
Reposted by AA
charlesgaba.com
Marco Rubio, Human Swiss Army Knife.

He slices! He dices! He mashes! He smashes! He can cut through this tin can like it's made out of butter! Watch him be suspended in mid-air!
Swiss Army Knife
Security Week: Tech Giants Propose Standard For End-of-Life Security Disclosures www.securityweek.com/tech-giants-... @securityweek.bsky.social #cybersecurity
CBS: Tesla chair denies its board is looking to replace CEO Elon Musk www.cbsnews.com/news/tesla-c... @cbsnews.com #Musk