surveillance

AppWizard
August 20, 2026
Monomyth Games has announced its new title, Photo Roboto: A Timesnap Adventure, marking its first game since 2018's Need to Know. Players will take on the role of Peppino the Roboto, who operates a time-warp photography business on an Italian island. Key features include the Timewarp Camera for capturing images from different time periods, running a photography business, exploring the island of Pallacanezza, helping locals, experiencing a handcrafted narrative, trying new camera modes, and personalizing the shop and character. The game is set for release on PC via Steam in 2027.
Winsage
August 17, 2026
A suspected advanced persistent threat (APT) group linked to China exploited a newly patched vulnerability in VMware vCenter (CVE-2026-59310), which has a critical CVSS score of 9.8, allowing for arbitrary code execution and the deployment of Babuk-derived ransomware. A recently patched vulnerability in Apple macOS (CVE-2026-65400) has been exploited to deploy a cryptocurrency miner, granting unauthorized root access. The Lazarus Group from North Korea exploited a zero-day vulnerability in Microsoft Windows, targeting defense and aerospace sectors. GeoServer patched a critical SQL injection vulnerability that was actively exploited. A new macOS malware, Amnesia Stealer, targets users through ClickFix attacks, stealing data and allowing real-time access to authenticated sessions. A novel attack technique named GhostSplice can manipulate AI coding assistants. Research revealed a method exploiting Chromium's DevTools Protocol for data theft. Noteworthy CVEs this week include CVE-2026-68820, CVE-2026-58231, and multiple others across various platforms. A high-severity command injection flaw in FileRun allows remote code execution. An advanced ClickFix attack has been reported, deploying sophisticated malware. A heap overflow vulnerability in Citrix NetScaler was patched after indications of exploitation. A new malware loader targeting Portuguese-speaking users has been identified. A significant reduction in exposed Automatic Tank Gauge systems has been observed. A phishing campaign targeting Brazil has been detected, and an F.B.I. agent faces charges for unauthorized crypto withdrawals. Authorities in Ukraine dismantled fraudulent call centers, and a North Carolina man was sentenced for cyber extortion. Unauthorized access to sensitive data by the ExfilSquad group has been confirmed. LightSpy activity linked to China has been detected in over 13 countries. A supply chain attack exposed over 2,500 companies, and an Azure exfiltration campaign has exposed millions of enterprise records.
AppWizard
August 17, 2026
Developer Yesterday’s Sandwich has announced a new psychological thriller game titled The Watcher, set to launch on PC through Steam. The game utilizes Unreal Engine 5 and allows players to act as a voyeuristic observer, stationed across the street from an apartment building with binoculars and surveillance tools. Players can snap photos, record video, listen to conversations, acquire documents, create an evidence board, upgrade their surveillance headquarters, and submit reports on their findings. Decisions made by players impact the residents' fates, and the game presents complex narratives and ethical dilemmas, challenging players' perceptions of guilt and innocence. The Watcher is available for pre-order on PC via Steam.
AppWizard
August 14, 2026
Snowflake Volunteer is a newly launched Android app available on the Google Play Store, created by the Tor Project, that allows users to contribute to internet freedom by transforming their smartphones into proxies for the Tor Network. It is a collaboration between Bloco, the Tor Network, and Guardian Project, building on the original Snowflake initiative from 2019. The app connects users needing access to the Tor Network, particularly in regions with heavy internet restrictions, by simulating user traffic as a video call via WebRTC and using dynamic proxies. Users can customize settings such as enabling/disabling the app, charging preferences, Wi-Fi operation, background operation, and connection limits. The app is open-source and available on both Google Play and F-Droid. Testing indicates that it does not significantly drain battery life, showing only a gradual decline over three hours with multiple connections. The app aims to enhance the robustness of the Snowflake network, making it harder for oppressive regimes to impose restrictions.
AppWizard
August 9, 2026
Toronto has seen an increase in gunfire incidents aimed at the U.S. consulate, leading to the arrests of a 19-year-old and a 15-year-old. These incidents are linked to alleged gun-for-hire plots that also target Jewish schools, synagogues, and waste management facilities in the Greater Toronto Area. Investigators are facing difficulties in identifying the masterminds behind these operations, partly due to the use of encrypted messaging apps to recruit young individuals. The federal government's Bill C-22 aims to provide law enforcement with tools to address these challenges, but it has faced criticism for potential overreach and privacy concerns. Police Chief Myron Demkiw emphasized the need for effective tools to prevent violence facilitated through encrypted communication. Technology analyst Carmi Levy raised concerns about balancing law enforcement needs with privacy rights. Additionally, there is a societal responsibility to protect children from online recruitment by criminal networks, with calls for proactive conversations between parents and children and educational initiatives in schools.
AppWizard
August 5, 2026
Advertising companies provide software development kits (SDKs) for mobile app monetization, which often automatically transmit users' location data to ad systems and location data brokers, raising privacy concerns. Many developers and users may be unaware of this data sharing. When developers allow SDKs to collect location data, it poses risks beyond targeted ads, including potential misuse by agencies like ICE and global surveillance. Location data brokers harvest precise movements of individuals, often without their consent, through mobile applications. Some apps directly collaborate with data brokers, while others leak data through advertising SDKs during real-time bidding (RTB) auctions. An incident in 2025 revealed that many apps unknowingly contributed to a location data broker's database. Developers must understand their SDKs' location-sharing practices to mitigate risks. Advertising SDKs can collect location data automatically once users grant permission, without specific permissions for the SDKs themselves. Precise location data can be collected when apps have location permissions, leading to potential privacy violations. Several SDKs have been identified as collecting location data by default, increasing the risk of unintentional data leaks. The Electronic Frontier Foundation (EFF) found that four advertising SDKs collect users' location data by default when location permissions are granted. InMobi encourages location sharing for higher revenue, while BidMachine updated its documentation after EFF's inquiry, confirming precise location data collection. Verve's SDK also collects location data by default but presents a cautious narrative in its Play Store guidance. Huawei's SDK recommends obtaining location permissions to enhance revenue, with default location sharing occurring if permissions are granted. Location data can be shared without users' knowledge or meaningful consent, complicating informed consent issues. The focus on four SDKs does not imply that others adequately protect location data, as many have faced criticism for similar practices. Studies indicate that SDKs often encourage increased data collection through design and documentation, leading to minimal control for developers over data transmission. The EFF's analysis highlights that advertising SDKs incentivize location data sharing through default settings and unclear documentation. Developers should assess third-party SDKs and disable unnecessary data collection. Regulators must hold developers accountable for unlawful data sharing, while legislators should enact laws to protect location privacy and address online behavioral advertising, which drives data tracking.
AppWizard
August 5, 2026
Developers often rely on third-party software development kits (SDKs) for mobile app monetization, which can compromise user privacy due to invasive data-collection features. The Electronic Frontier Foundation (EFF) has raised concerns about these SDKs' default settings that collect sensitive location data without explicit user consent. Location data is valuable for advertisers, allowing targeted marketing, but permissions granted to apps often extend to SDKs, enabling data collection without informed consent. The EFF emphasizes that app-level location permissions do not signify meaningful consent for third-party SDKs. The location data collected has been used by intelligence agencies and law enforcement, raising ethical privacy concerns. The EFF recommends that developers prioritize user privacy, regulators hold app developers accountable for unlawful data sharing, and legislators consider enacting federal laws similar to the GDPR to protect user privacy and potentially ban behavioral advertising.
AppWizard
August 5, 2026
Recent research from the Electronic Frontier Foundation (EFF) has revealed that millions of Android users' location data are being inadvertently exposed to advertisers through third-party code libraries. This occurs when seemingly harmless applications, like weather services and fitness trackers, integrate third-party SDKs that collect user location information automatically upon permission approval, often without developers' awareness. Data brokers aggregate this location information to create detailed movement profiles sold to advertisers and government agencies. Despite privacy regulations like GDPR and CCPA, enforcement is inconsistent, and developers may claim ignorance regarding data practices they did not implement. Google has improved Android's privacy controls, but visibility into third-party libraries accessing data remains limited. Developers face challenges in auditing third-party code due to resource constraints, leading to a complex landscape where user information traverses multiple entities without clear accountability. Privacy advocates are calling for new technical standards to require SDKs to disclose their data practices.
Search