legal action

AppWizard
August 21, 2026
A new strain of Android malware has emerged, targeting automotive head units responsible for infotainment, connectivity, and navigation in vehicles. Discovered by Kaspersky in June, this is the first documented instance of malware affecting car head units, specifically within the firmware updaters of Android-based software developed by DoFun, a Hong Kong company. The malware, disguised as an application called JarService, infiltrates devices without user awareness. It is delivered through a legitimate system application called TWCore, which collects analytics and updates software. The malware aims to convert the head unit into a botnet, equipped with commands to download and execute code and display advertisements, potentially for online ad fraud. Kaspersky notified DoFun, which addressed the vulnerabilities, and noted similarities between this malware and a previous threat called BadBox, which affected various Android devices.
AppWizard
August 21, 2026
Google has agreed to a [openai_gpt model="gpt-4o-mini" prompt="Summarize the content and extract only the fact described in the text bellow. The summary shall NOT include a title, introduction and conclusion. Text: PHOENIX (AZFamily) — In a significant development for the tech industry, Google has agreed to a 0 million settlement regarding its practices in the Android app store market. This resolution comes as a result of a bipartisan coalition of attorneys general, spearheaded by Arizona’s Attorney General Kris Mayes, who have raised concerns about the company's monopolistic control over app distribution and in-app payment systems. Settlement Details Attorney General Mayes articulated the core issue, stating, “Google used its monopoly power over the app market to drive up prices.” The settlement serves as a clear message against anticompetitive behavior, emphasizing the importance of a fair marketplace that fosters lower prices, enhanced quality of goods and services, and increased choices for consumers. Mayes affirmed her commitment to combating illegal and unfair business practices to safeguard the interests of Arizonans. Individuals who made purchases on Google Play between August 2016 and September 2023 will be eligible to receive a portion of the settlement. Most recipients can expect to receive their share without the need to submit a claim form, with payments being processed through platforms like PayPal or Venmo. Changes to Business Practices As part of the settlement agreement, Google is required to implement several changes to its business operations. Over the next five years, app developers will gain the freedom to: Offer alternative payment options to users. Inform users about cheaper prices available outside of Google’s billing platform. Feature their apps on competing app stores without fear of retaliation. Moreover, Android users will have the ability to install applications from sources beyond the Google Play Store for a minimum duration of seven years. Arizona's involvement in this legal action dates back to 2021, when the state joined a coalition of attorneys general in suing Google for its alleged illegal dominance in Android app distribution and for imposing transaction fees of up to 30% on consumers. For those seeking further information about the settlement, additional details can be found on the designated website. See a spelling or grammatical error in our story? Please click here to report it. Do you have a photo or video of a breaking news story? Send it to us here with a brief description. Copyright 2026 KTVK/KPHO. All rights reserved." max_tokens="3500" temperature="0.3" top_p="1.0" best_of="1" presence_penalty="0.1" frequency_penalty="frequency_penalty"] million settlement regarding its practices in the Android app store market due to concerns about its monopolistic control over app distribution and in-app payment systems. The settlement allows individuals who made purchases on Google Play between August 2016 and September 2023 to receive a portion of the settlement without needing to submit a claim form. As part of the settlement, Google must implement changes allowing app developers to offer alternative payment options, inform users about cheaper prices outside of Google’s billing platform, and feature their apps on competing app stores without retaliation. Additionally, Android users will be able to install applications from sources beyond the Google Play Store for at least seven years. Arizona's involvement in the legal action began in 2021 when it joined a coalition of attorneys general suing Google for its alleged illegal dominance and high transaction fees.
Winsage
August 13, 2026
Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, which can bypass Microsoft's RoguePlanet patch (CVE-2026-50656) and allow attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit has been confirmed by security expert Kevin Beaumont, who provided detection methods for it. ShieldBreak is the tenth zero-day from Nightmare Eclipse since April and was released shortly after Microsoft's monthly Patch Tuesday. The exploit allows local privilege escalation and has a 100% success rate on the latest version of Windows 11 and Windows Server 2025, while Windows 10 remains vulnerable. Microsoft is aware of the vulnerability and is investigating it, emphasizing the importance of coordinated vulnerability disclosure. Previous exploits from Nightmare Eclipse include LegacyHive and GreatXML, with earlier vulnerabilities having been patched but recent ones still unaddressed. Microsoft had threatened legal action against Nightmare Eclipse in May but later reconsidered its approach to vulnerability disclosure.
Winsage
August 12, 2026
A security researcher named Nightmare Eclipse has discovered a vulnerability in Windows, called ShieldBreak, which allows hackers to gain system-wide access to users' devices and sensitive data by exploiting a flaw in Windows Defender. The vulnerability affects Windows 10, Windows 11 (including version 25H2), and Windows Server 2025. A proof-of-concept exploit has been provided, requiring users to run a Windows application to trigger the vulnerability. Security researcher Will Dormann confirmed that Windows Defender must be enabled for the exploit to work. Microsoft has not yet released a patch for ShieldBreak, which is classified as a zero-day vulnerability. This discovery follows previous vulnerabilities disclosed by Nightmare Eclipse, including RoguePlanet, for which Microsoft issued an inadequate patch. The situation has heightened tensions between the researcher and Microsoft regarding the handling of bug reports, especially after Microsoft threatened legal action against researchers disclosing zero-days outside established protocols. The disclosure of ShieldBreak occurred shortly after Microsoft's monthly security patch releases, which have been increasing in number.
AppWizard
August 5, 2026
Advertising companies provide software development kits (SDKs) for mobile app monetization, which often automatically transmit users' location data to ad systems and location data brokers, raising privacy concerns. Many developers and users may be unaware of this data sharing. When developers allow SDKs to collect location data, it poses risks beyond targeted ads, including potential misuse by agencies like ICE and global surveillance. Location data brokers harvest precise movements of individuals, often without their consent, through mobile applications. Some apps directly collaborate with data brokers, while others leak data through advertising SDKs during real-time bidding (RTB) auctions. An incident in 2025 revealed that many apps unknowingly contributed to a location data broker's database. Developers must understand their SDKs' location-sharing practices to mitigate risks. Advertising SDKs can collect location data automatically once users grant permission, without specific permissions for the SDKs themselves. Precise location data can be collected when apps have location permissions, leading to potential privacy violations. Several SDKs have been identified as collecting location data by default, increasing the risk of unintentional data leaks. The Electronic Frontier Foundation (EFF) found that four advertising SDKs collect users' location data by default when location permissions are granted. InMobi encourages location sharing for higher revenue, while BidMachine updated its documentation after EFF's inquiry, confirming precise location data collection. Verve's SDK also collects location data by default but presents a cautious narrative in its Play Store guidance. Huawei's SDK recommends obtaining location permissions to enhance revenue, with default location sharing occurring if permissions are granted. Location data can be shared without users' knowledge or meaningful consent, complicating informed consent issues. The focus on four SDKs does not imply that others adequately protect location data, as many have faced criticism for similar practices. Studies indicate that SDKs often encourage increased data collection through design and documentation, leading to minimal control for developers over data transmission. The EFF's analysis highlights that advertising SDKs incentivize location data sharing through default settings and unclear documentation. Developers should assess third-party SDKs and disable unnecessary data collection. Regulators must hold developers accountable for unlawful data sharing, while legislators should enact laws to protect location privacy and address online behavioral advertising, which drives data tracking.
AppWizard
July 30, 2026
Australia’s eSafety Commissioner, Julie Inman Grant, has filed a lawsuit against the encrypted messaging app Telegram for allegedly failing to detect and remove pro-terrorist and extremist content. This legal action follows a year-long investigation and is the first enforcement of online codes regarding unlawful material established a year ago. The lawsuit details multiple violations of the Online Safety Act 2021, including the failure to remove posts related to the Christchurch mosque attack and the Buffalo mass shooting, despite user reports. Telegram has claimed to have blocked over 150,000 terrorist-related communities and removed over 200 million pieces of terrorist content. If the lawsuit is successful, it could lead to penalties up to A.6 million and potentially a ban on the app in Australia.
AppWizard
July 30, 2026
Australia's eSafety watchdog has initiated legal proceedings against the messaging platform Telegram for allegedly failing to adequately remove extremist content, including footage related to mass shootings in Buffalo and Christchurch, as well as material linked to the Islamic State. The platform, with a user base of approximately 1 billion, could face fines of up to 54.6 million Australian dollars (around 38 million USD) if found guilty. eSafety Commissioner Julie Inman Grant emphasized that the content in question is tied to severe acts of extremist violence and remained accessible despite Telegram being notified of its existence. Following recent tragedies, Telegram channels have surfaced that celebrate attackers and circulate videos of their acts. Telegram has denied the allegations, claiming to block terrorist-related content and reporting the removal of over 150,000 terrorist-related communities this year. However, Inman Grant raised concerns about the platform's compliance and responsiveness to regulatory actions.
Search