Etienne - Tek
@tek.randhome.io
Technologist @ Human Rights Watch (previously Amnesty, Citizen Lab)
Malware, Threats, Online Investigations, Disinformation, Human Rights and silly memes.
On Mastodon: tek@todon.eu
Also on https://maynier.eu/
Malware, Threats, Online Investigations, Disinformation, Human Rights and silly memes.
On Mastodon: tek@todon.eu
Also on https://maynier.eu/
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library. The spyware was embedded in malicious DNG files.
unit42.paloaltonetworks.com
November 10, 2025 at 4:36 PM
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/
Israeli Spyware Maker NSO Gets New Owners, Leadership and Seeks to Mend Reputation https://www.wsj.com/tech/israeli-spyware-maker-nso-gets-new-owners-leadership-and-seeks-to-mend-reputation-166ac50e
November 10, 2025 at 4:06 PM
Israeli Spyware Maker NSO Gets New Owners, Leadership and Seeks to Mend Reputation https://www.wsj.com/tech/israeli-spyware-maker-nso-gets-new-owners-leadership-and-seeks-to-mend-reputation-166ac50e
Reposted by Etienne - Tek
NEW, by me: Researchers have discovered an Android spyware that specifically targeted Samsung Galaxy phones during a nearly year-long hacking campaign. The spyware relied on a zero-day bug triggered by sending a victim a malware-laced photo via a messaging app. Victims are likely in the Middle East.
'Landfall' spyware abused zero-day to hack Samsung Galaxy phones | TechCrunch
A newly identified Android spyware targeted Galaxy devices for close to a year, including users in the Middle East, researchers exclusively tell TechCrunch.
techcrunch.com
November 7, 2025 at 12:13 PM
NEW, by me: Researchers have discovered an Android spyware that specifically targeted Samsung Galaxy phones during a nearly year-long hacking campaign. The spyware relied on a zero-day bug triggered by sending a victim a malware-laced photo via a messaging app. Victims are likely in the Middle East.
EFF Teams Up With AV Comparatives to Test Android Stalkerware Detection by Major Antivirus Apps | Electronic Frontier Foundation https://www.eff.org/deeplinks/2025/11/eff-teams-av-comparatives-test-android-stalkerware-detection-major-antivirus-apps
EFF Teams Up With AV Comparatives to Test Android Stalkerware Detection by Major Antivirus Apps
EFF has, for many years, raised the alarm about the proliferation of stalkerware—commercially-available apps designed to be installed covertly on another person’s device to exfiltrate data from that device without their knowledge. We’ve teamed up with the researchers at AV Comparatives to test the most popular anti-virus products for Android to see how well they detect the most popular stalkerware products in 2025
www.eff.org
November 7, 2025 at 10:19 PM
EFF Teams Up With AV Comparatives to Test Android Stalkerware Detection by Major Antivirus Apps | Electronic Frontier Foundation https://www.eff.org/deeplinks/2025/11/eff-teams-av-comparatives-test-android-stalkerware-detection-major-antivirus-apps
A.I. Is Making Death Threats Way More Realistic https://www.nytimes.com/2025/10/31/business/media/artificial-intelligence-death-threats.html
November 7, 2025 at 4:40 AM
A.I. Is Making Death Threats Way More Realistic https://www.nytimes.com/2025/10/31/business/media/artificial-intelligence-death-threats.html
Legal groups sue Trump administration over use of Israeli spyware on immigrants https://prismreports.org/2025/11/06/ice-cbp-israeli-spyware-immigrants/
Legal groups sue Trump administration over use of Israeli spyware on immigrants
Civil rights attorneys are seeking documents disclosing details on the extent of ICE’s use of invasive Israeli spyware to target immigrants
prismreports.org
November 7, 2025 at 1:30 AM
Legal groups sue Trump administration over use of Israeli spyware on immigrants https://prismreports.org/2025/11/06/ice-cbp-israeli-spyware-immigrants/
Italian political consultant says he was targeted with Paragon spyware | TechCrunch https://techcrunch.com/2025/11/06/italian-political-consultant-says-he-was-targeted-with-paragon-spyware/
Italian political consultant says he was targeted with Paragon spyware | TechCrunch
WhatsApp notified the consultant, who works for left-wing politicians, that his phone was targeted with spyware made by Paragon.
techcrunch.com
November 6, 2025 at 6:25 PM
Italian political consultant says he was targeted with Paragon spyware | TechCrunch https://techcrunch.com/2025/11/06/italian-political-consultant-says-he-was-targeted-with-paragon-spyware/
I have been doing trainings to journalists on digital investigations with @gijn.org since 2023, and they just published a article on several investigations that used skills journalists learned in these sessions
gijn.org/stories/inve...
gijn.org/stories/inve...
How Digital Threats Training Has Powered Innovative Cyber Investigations Around the World
Alumni of GIJN's four Digital Threats training courses have produced a number of exposés on online scams and political disinformation, from India to Kenya to the Philippines.
gijn.org
November 4, 2025 at 8:44 PM
I have been doing trainings to journalists on digital investigations with @gijn.org since 2023, and they just published a article on several investigations that used skills journalists learned in these sessions
gijn.org/stories/inve...
gijn.org/stories/inve...
Reposted by Etienne - Tek
ICYMI: Court documents and interviews with former staff reveal how ex-L3Harris Trenchant boss Peter Williams was able to steal and sell highly sensitive exploits to a Russian buyer for years.
"No one had any supervision over him at all," one former Trenchant employee told @lorenzofb.bsky.social.
"No one had any supervision over him at all," one former Trenchant employee told @lorenzofb.bsky.social.
How an ex-L3Harris Trenchant boss stole and sold cyber exploits to Russia | TechCrunch
Peter Williams sold eight exploits to a Russian zero-day broker by smuggling them from his employer’s highly secured air-gapped network. A court document, plus exclusive reporting by TechCrunch and in...
techcrunch.com
November 4, 2025 at 1:43 PM
ICYMI: Court documents and interviews with former staff reveal how ex-L3Harris Trenchant boss Peter Williams was able to steal and sell highly sensitive exploits to a Russian buyer for years.
"No one had any supervision over him at all," one former Trenchant employee told @lorenzofb.bsky.social.
"No one had any supervision over him at all," one former Trenchant employee told @lorenzofb.bsky.social.
Reposted by Etienne - Tek
It's Friday and you've probably had enough cyber... but I'm re-upping my story on this.weekinsecurity.com about how AI browsers are shipping with security bugs that put your private data (saved passwords, credit cards, browsing history) at risk.
Here's why AI browsers aren't safe for general use.
Here's why AI browsers aren't safe for general use.
AI browsers are a hot mess of security risks
AI-enabled web browsers are putting their users' data, security, and privacy at risk from rudimentary prompt injection attacks.
this.weekinsecurity.com
October 31, 2025 at 8:37 PM
It's Friday and you've probably had enough cyber... but I'm re-upping my story on this.weekinsecurity.com about how AI browsers are shipping with security bugs that put your private data (saved passwords, credit cards, browsing history) at risk.
Here's why AI browsers aren't safe for general use.
Here's why AI browsers aren't safe for general use.
Criminal complaint against facial recognition company Clearview AI https://noyb.eu/en/criminal-complaint-against-facial-recognition-company-clearview-ai
Criminal complaint against facial recognition company Clearview AI
Clearview AI is known for scraping billions of photos of people around the world on the internet – and selling its facial recognition system to law enforcement and state actors
noyb.eu
October 31, 2025 at 8:18 PM
Criminal complaint against facial recognition company Clearview AI https://noyb.eu/en/criminal-complaint-against-facial-recognition-company-clearview-ai
Reposted by Etienne - Tek
New incredible detail here: ICE says a match in its facial recognition app Mobile Fortify is a "definitive" determination of a person's status, and that this overrides birth certificates. This is an app ICE is using in the field to scan people
www.404media.co/ice-and-cbp-...
www.404media.co/ice-and-cbp-...
October 29, 2025 at 3:03 PM
New incredible detail here: ICE says a match in its facial recognition app Mobile Fortify is a "definitive" determination of a person's status, and that this overrides birth certificates. This is an app ICE is using in the field to scan people
www.404media.co/ice-and-cbp-...
www.404media.co/ice-and-cbp-...
Reposted by Etienne - Tek
NEW: ICE is planning to build a shadow deportation network in Texas. A proposal outlines a 24/7 transport operation run by armed contractors—turning Texas into the logistical backbone of an industrialized deportation machine.
My latest @wired.com: www.wired.com/story/ice-is...
My latest @wired.com: www.wired.com/story/ice-is...
October 30, 2025 at 4:52 PM
NEW: ICE is planning to build a shadow deportation network in Texas. A proposal outlines a 24/7 transport operation run by armed contractors—turning Texas into the logistical backbone of an industrialized deportation machine.
My latest @wired.com: www.wired.com/story/ice-is...
My latest @wired.com: www.wired.com/story/ice-is...
Former L3Harris Trenchant boss pleads guilty to selling zero-day exploits to Russian broker | TechCrunch https://techcrunch.com/2025/10/29/former-l3harris-trenchant-boss-pleads-guilty-to-selling-zero-day-exploits-to-russian-broker/
Former L3Harris Trenchant boss pleads guilty to selling zero-day exploits to Russian broker | TechCrunch
Prosecutors confirmed Peter Williams, the former Trenchant boss, sold eight exploits to a Russian buyer. TechCrunch exclusively reported that the Trenchant division was investigating a leak of its hacking tools, after another employee was accused of involvement.
techcrunch.com
October 29, 2025 at 8:06 PM
Former L3Harris Trenchant boss pleads guilty to selling zero-day exploits to Russian broker | TechCrunch https://techcrunch.com/2025/10/29/former-l3harris-trenchant-boss-pleads-guilty-to-selling-zero-day-exploits-to-russian-broker/
Internet disrupted in Tanzania on election day as ruling party seeks to extend decades in power https://apnews.com/article/tanzania-election-samia-suluhu-hassan-d897483abe5a34c1b02422e7adc5891a
Internet disrupted in Tanzania on election day as ruling party seeks to extend decades in power
Internet connectivity has been disrupted across Tanzania during an election marked by human rights concerns and opposition detentions.
apnews.com
October 29, 2025 at 1:17 PM
Internet disrupted in Tanzania on election day as ruling party seeks to extend decades in power https://apnews.com/article/tanzania-election-samia-suluhu-hassan-d897483abe5a34c1b02422e7adc5891a
Grokipedia is racist, transphobic, and loves Elon Musk | The Verge https://www.theverge.com/ai-artificial-intelligence/808514/grokipedia-wikipedia-comparison
Grokipedia is racist, transphobic, and loves Elon Musk
xAI’s version of Wikipedia, Grokipedia, frames the world’s history from Elon Musk’s perspective.
www.theverge.com
October 29, 2025 at 1:08 PM
Grokipedia is racist, transphobic, and loves Elon Musk | The Verge https://www.theverge.com/ai-artificial-intelligence/808514/grokipedia-wikipedia-comparison
CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware | TechCrunch https://techcrunch.com/2025/10/28/ceo-of-spyware-maker-memento-labs-confirms-one-of-its-government-customers-was-caught-using-its-malware/
Exclusive: CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware
Security researchers found a government hacking campaign that relies on Windows spyware developed by surveillance tech maker Memento Labs. When reached by TechCrunch, the spyware maker's chief executive blamed a government customer for getting caught.
techcrunch.com
October 29, 2025 at 1:08 PM
CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware | TechCrunch https://techcrunch.com/2025/10/28/ceo-of-spyware-maker-memento-labs-confirms-one-of-its-government-customers-was-caught-using-its-malware/
Reposted by Etienne - Tek
On Election Day, Tanzania is experiencing a near total Internet shutdown.
Follow connectivity in Tanzania in near realtime:
https://ioda.inetintel.cc.gatech.edu/country/TZ?from=1761655255&until=1761741655&view=view1
#keepiton
Follow connectivity in Tanzania in near realtime:
https://ioda.inetintel.cc.gatech.edu/country/TZ?from=1761655255&until=1761741655&view=view1
#keepiton
October 29, 2025 at 12:45 PM
On Election Day, Tanzania is experiencing a near total Internet shutdown.
Follow connectivity in Tanzania in near realtime:
https://ioda.inetintel.cc.gatech.edu/country/TZ?from=1761655255&until=1761741655&view=view1
#keepiton
Follow connectivity in Tanzania in near realtime:
https://ioda.inetintel.cc.gatech.edu/country/TZ?from=1761655255&until=1761741655&view=view1
#keepiton
Microsoft sued for allegedly misleading millions of Australians with its AI pricing | The Guardian https://www.theguardian.com/australia-news/2025/oct/27/microsoft-sued-allegedly-misleading-millions-australians-ai-pricing-ntwnfb
Microsoft sued for allegedly misleading millions of Australians with its AI pricing
Tech giant faces hefty fines from consumer watchdog for allegedly trying to convince customers to pay more than needed for their Microsoft 365 subscription
www.theguardian.com
October 27, 2025 at 2:55 PM
Microsoft sued for allegedly misleading millions of Australians with its AI pricing | The Guardian https://www.theguardian.com/australia-news/2025/oct/27/microsoft-sued-allegedly-misleading-millions-australians-ai-pricing-ntwnfb
How we linked ForumTroll APT to Dante spyware by Memento Labs | Securelist https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/
Mem3nt0 mori – The Hacking Team is back!
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
securelist.com
October 27, 2025 at 12:51 PM
How we linked ForumTroll APT to Dante spyware by Memento Labs | Securelist https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/
Cameroon's Internet access disrupted as election protests continue | Reuters https://www.reuters.com/world/africa/internet-connectivity-cameroon-is-significantly-disrupted-netblocks-says-2025-10-23/
October 23, 2025 at 5:51 PM
Cameroon's Internet access disrupted as election protests continue | Reuters https://www.reuters.com/world/africa/internet-connectivity-cameroon-is-significantly-disrupted-netblocks-says-2025-10-23/
U.S. government accuses former L3Harris cyber boss of stealing trade secrets | TechCrunch https://techcrunch.com/2025/10/23/u-s-government-accuses-former-l3harris-cyber-boss-of-stealing-trade-secrets/
U.S. government accuses former L3Harris cyber boss of stealing trade secrets | TechCrunch
The U.S. Department of Justice accused Peter Williams, former general manager of L3Harris’ hacking division Trenchant, of stealing trade secrets and selling them to a buyer in Russia.
techcrunch.com
October 23, 2025 at 4:44 PM
U.S. government accuses former L3Harris cyber boss of stealing trade secrets | TechCrunch https://techcrunch.com/2025/10/23/u-s-government-accuses-former-l3harris-cyber-boss-of-stealing-trade-secrets/
Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers | Brave https://brave.com/blog/unseeable-prompt-injections/
Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers | Brave
AI browsers remain vulnerable to prompt injection attacks via screenshots and hidden content, allowing attackers to exploit users' authenticated sessions.
brave.com
October 22, 2025 at 3:48 AM
Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers | Brave https://brave.com/blog/unseeable-prompt-injections/
How ICE Spies On WhatsApp | Forbes https://www.forbes.com/sites/the-wiretap/2025/10/21/ice-spies-on-whatsapp/
How ICE Spies On WhatsApp
ICE’s HSI division gets contacts from the WhatsApp account of a fake ID dealer and has little trouble identifying them, according to warrant.
www.forbes.com
October 21, 2025 at 7:57 PM
How ICE Spies On WhatsApp | Forbes https://www.forbes.com/sites/the-wiretap/2025/10/21/ice-spies-on-whatsapp/
AI-generated ‘poverty porn’ fake images being used by aid agencies | The Guardian https://www.theguardian.com/global-development/2025/oct/20/ai-generated-poverty-porn-fake-images-being-used-by-aid-agencies
AI-generated ‘poverty porn’ fake images being used by aid agencies
Exclusive: Pictures depicting the most vulnerable and poorest people are being used in social media campaigns in the sector, driven by concerns over consent and cost
www.theguardian.com
October 21, 2025 at 7:02 PM
AI-generated ‘poverty porn’ fake images being used by aid agencies | The Guardian https://www.theguardian.com/global-development/2025/oct/20/ai-generated-poverty-porn-fake-images-being-used-by-aid-agencies