data protection

AppWizard
September 30, 2026
Russian cybersecurity firm Positive Technologies has identified 11 security vulnerabilities affecting Android and Apple devices, with nine related to Apple and two to Android, classified as high severity. The Android vulnerabilities include one that allows attackers to exploit an NFC tag to execute an app without owner approval and another that lets installed apps modify network settings without additional permissions. Google has addressed these issues in its September 2026 security patches. For Apple, vulnerabilities include a macOS flaw that allows malicious apps to gain the highest system privileges and another that exposes sensitive information. Apple has released patches for these vulnerabilities, but specific OS versions affected have not been disclosed. Users are advised to ensure their devices have the latest security updates to mitigate risks.
Winsage
September 19, 2026
Windows 11 Pro is available for .97, reduced from its regular price of 9. This limited-time offer is valid until September 27 at 11:59 p.m. PT. The operating system includes features such as Hyper-V, Windows Sandbox, BitLocker encryption, Azure AD integration, and Copilot, an AI-powered assistant.
Winsage
September 7, 2026
Switzerland's federal government plans to reduce its reliance on Microsoft 365 and is exploring alternative software solutions, reflecting a trend among European nations for digital sovereignty. The initiative includes transitioning 3,000 Swiss workstations away from Microsoft 365. Concerns about data protection and potential risks of data leaks from foreign systems are primary motivations for this shift, alongside rising license costs. Professor Matthias Stürmer has highlighted the risks of foreign access to sensitive data. Microsoft has introduced its Sovereign Cloud to address these concerns, but apprehensions remain among governments in Switzerland, Germany, and France regarding data sovereignty.
Winsage
August 24, 2026
Malware researcher Dominik Reichel has discovered a sophisticated Windows backdoor named Sleepwalker, which remains dormant in memory until activated by a specially crafted network packet. Sleepwalker uses a 23-instruction command language to execute tasks, including running code in memory and exfiltrating data. It activates through a proprietary activation packet that does not contain readable commands. The malware targets a VMware VMCI and disguises itself as Microsoft's dpapi.dll, mimicking its functions while redirecting calls to a non-existent file. Once it confirms its host process as ERAAgent.exe, it enters a dormant state to evade detection. Sleepwalker monitors for a specific pattern known as a magic packet to decrypt and interpret commands. Commands sent to it are encrypted with AES-256-CCM and must be read in a specific order. The backdoor includes functionalities for sending and concealing data, receiving tasks, and executing programs. Reichel has developed a toolkit to decode Sleepwalker’s bytecode and a mitigation guide for affected users. However, there are significant gaps in knowledge regarding the initial access method, victim identification, and the malware's operator.
Tech Optimizer
August 20, 2026
Surfshark VPN is offering an end-of-winter discount on their 2-year Surfshark One Plan, providing 87% off and three additional months free until September 7. The plan costs A.49 per month and includes features such as a secure VPN, ad blocker, email masking, a personal detail generator, advanced antivirus, and phishing protection. Surfshark also offers a 30-day money-back guarantee. PCMag reviewers awarded Surfshark VPN a 4.5-star rating, highlighting its strong data protection and innovative security tools.
AppWizard
August 5, 2026
Developers often rely on third-party software development kits (SDKs) for mobile app monetization, which can compromise user privacy due to invasive data-collection features. The Electronic Frontier Foundation (EFF) has raised concerns about these SDKs' default settings that collect sensitive location data without explicit user consent. Location data is valuable for advertisers, allowing targeted marketing, but permissions granted to apps often extend to SDKs, enabling data collection without informed consent. The EFF emphasizes that app-level location permissions do not signify meaningful consent for third-party SDKs. The location data collected has been used by intelligence agencies and law enforcement, raising ethical privacy concerns. The EFF recommends that developers prioritize user privacy, regulators hold app developers accountable for unlawful data sharing, and legislators consider enacting federal laws similar to the GDPR to protect user privacy and potentially ban behavioral advertising.
AppWizard
August 5, 2026
Recent research from the Electronic Frontier Foundation (EFF) has revealed that millions of Android users' location data are being inadvertently exposed to advertisers through third-party code libraries. This occurs when seemingly harmless applications, like weather services and fitness trackers, integrate third-party SDKs that collect user location information automatically upon permission approval, often without developers' awareness. Data brokers aggregate this location information to create detailed movement profiles sold to advertisers and government agencies. Despite privacy regulations like GDPR and CCPA, enforcement is inconsistent, and developers may claim ignorance regarding data practices they did not implement. Google has improved Android's privacy controls, but visibility into third-party libraries accessing data remains limited. Developers face challenges in auditing third-party code due to resource constraints, leading to a complex landscape where user information traverses multiple entities without clear accountability. Privacy advocates are calling for new technical standards to require SDKs to disclose their data practices.
Search