Goto

Collaborating Authors

 spyware


The Secrets of the US Spyware King

WIRED

In an exclusive interview with WIRED, Paragon Solutions CEO Andrew Boyd reveals the limits of the company's promise to keep bad actors from abusing its powerful espionage tool. Spyware maker Paragon Solutions has long positioned itself as the good guy in an industry seemingly filled with bad ones, vowing to never sell its mobile spyware to authoritarian regimes or ones with poor human rights records. It also promises to cut off any customer caught misusing its products against journalists, dissidents, or other non-legitimate targets. Yet weeks after Paragon, then Israeli-owned, was acquired by the US equity firm AE Industrial Partners in December 2024 and merged with REDLattice--an American offensive cyber firm owned by AE that this week announced plans to go public --WhatsApp alleged that Paragon's Graphite spyware was used to infect the phones of more than 60 individuals in more than 20 countries, including journalists and activists. Most of the targets were not identified, but the University of Toronto's Citizen Lab named two journalists and two activists in Italy. Italian authorities denied misuse . Paragon and its new US owners, despite their zero-tolerance policy for customer abuse of their software, initially declined to comment on the allegations, and reportedly was exploring potential legal action against WhatsApp after the company sent a cease-and-desist letter to Paragon.


Apple spyware warning hits iPhones in 110 countries

FOX News

Apple sent mercenary spyware warnings to iPhone users in 110 countries, with alerts on Lock Screens. Targeted users should enable Lockdown Mode and update their software.


The Download: a smoking "endgame" and a new Elizabeth Bear story

MIT Technology Review

Plus: An EU lawmaker investigating spyware was hacked by that same spyware. The UK's generational tobacco ban might not work. As the parent of two little girls, I often think about how their childhood is different from mine. The seven-year-old is learning about AI at school. The five-year-old is given internet-based homework every week. And they are both absolutely repulsed by the idea of smoking.


US Investment in Spyware Is Skyrocketing

WIRED

A new report warns that the number of US investors in powerful commercial spyware rose sharply in 2024 and names new countries linked to the dangerous technology. The United States has emerged as the largest investor in commercial spyware --a global industry that has enabled the covert surveillance of journalists, human rights defenders, politicians, diplomats, and others, posing grave threats to human rights and national security . In 2024, 20 new US-based spyware investors were identified, bringing the total number of American backers of this technology to 31. This growth has largely outpaced other major investing countries such as Israel, Italy, and the United Kingdom, according to a new report published today by the Atlantic Council. The study surveyed 561 entities across 46 countries between 1992 and 2024, identifying 34 new investors.


Bitfinex Hacker Gets 5 Years for 10 Billion Bitcoin Heist

WIRED

In perhaps the most adorable hacker story of the year, a trio of technologists in India found an innovative way to circumvent Apple's location restrictions on AirPod Pro 2s so they could enable the earbuds' hearing aid feature for their grandmas. The hack involved a homemade Faraday cage, a microwave, and a lot of trial and error. On the other end of the tech-advancements spectrum, the US military is currently testing an AI-enabled machine gun that is capable of auto-targeting swarms of drones. The Bullfrog, built by Allen Control Systems, is one of several advanced weapons technologies in the works to combat the growing threat of cheap, small drones on the battlefield. The US Department of Justice announced this week that an 18-year-old from California has admitted to making or orchestrating more than 375 swatting attacks across the United States.


Roku Breach Hits 567,000 Users

WIRED

After months of delays, the US House of Representatives voted on Friday to extend a controversial warrantless wiretap program for two years. Known as Section 702, the program authorizes the US government to collect the communications of foreigners overseas. But this collection also includes reams of communications from US citizens, which are stored for years and can later be warrantlessly accessed by the FBI, which has heavily abused the program. An amendment that would require investigators to obtain such a warrant failed to pass. A group of US lawmakers on Sunday unveiled a proposal that they hope will become the country's first nationwide privacy law.


Textual analysis of End User License Agreement for red-flagging potentially malicious software

arXiv.org Artificial Intelligence

New software and updates are downloaded by end users every day. Each dowloaded software has associated with it an End Users License Agreements (EULA), but this is rarely read. An EULA includes information to avoid legal repercussions. However,this proposes a host of potential problems such as spyware or producing an unwanted affect in the target system. End users do not read these EULA's because of length of the document and users find it extremely difficult to understand. Text summarization is one of the relevant solution to these kind of problems. This require a solution which can summarize the EULA and classify the EULA as "Benign" or "Malicious". We propose a solution in which we have summarize the EULA and classify the EULA as "Benign" or "Malicious". We extract EULA text of different sofware's then we classify the text using eight different supervised classifiers. we use ensemble learning to classify the EULA as benign or malicious using five different text summarization methods. An accuracy of $95.8$\% shows the effectiveness of the presented approach.


Your Boss's Spyware Could Train AI to Replace You

WIRED

Corporations are using software to monitor employees on a large scale. Some experts fear the data these tools collect could be used to automate people out of their jobs.


Dozens of popular Minecraft mods are infected with malware

PCWorld

If you or your children like to run mods on the Windows or Linux version of Minecraft, you might want to check those installation folders. According to public disclosures from the popular CurseForge and Bukkit mod platforms, both were used to upload compromised versions of popular Minecraft mods infected with malware installation tools. The full extent of the damage has yet to be assessed. According to Bleeping Computer, popular individual mod developers' accounts on the platforms were targeted, after which the Fractureiser spyware was smuggled into updated versions of their user mods. API systems automatically updated some of the mods immediately, some of which have millions of recorded downloads.


Criminals Are Using Tiny Devices to Hack and Steal Cars

WIRED

Employees of the US Immigration and Customs Enforcement agency (ICE) abused law enforcement databases to snoop on their romantic partners, neighbors, and business associates, WIRED exclusively revealed this week. New data obtained through record requests show that hundreds of ICE staffers and contractors have faced investigations since 2016 for attempting to access medical, biometric, and location data without permission. The revelations raise further questions about the protections ICE places on people's sensitive information. Security researchers at ESET found old enterprise routers are filled with company secrets. After purchasing and analyzing old routers, the firm found many contained login details for company VPNs, hashed root administrator passwords, and details of who the previous owners were.