Joseph

@eflags.bsky.social

Forensic Analyst, Reverse Engineer. Opinions mine

Applying for a government job shouldn't trigger a nationwide location tracking search. Yet EFF identified multiple law enforcement agencies in Missouri, Texas, Mississippi, and Illinois using Flock ALPR networks to run background checks. www.eff.org/deeplinks/2...

More License Plate Reader Mission Creep: School Residency

An EFF analysis of millions of searches of Flock Safety automated license plate reader (ALPR) data by police has uncovered a troubling pattern: in the absence of a warrant requirement to search ALPR

eff.org

In addition, literal stacks of M4000 chemical bombs, used by the Assad regime to drop sarin on civilians in 3 recorded incidents, were found and photographed. Yet more evidence everything we published at Bellingcat based on our open source investigations of chemical attacks was accurate.

Bild
Gregory Koblentz@gregkoblentz.bsky.social · 2mo ago

☠️Biggest find by OPCW since fall of the Assad regime: "dozens of undeclared chemical munitions such as aerial bombs and rockets as well as separately found chemicals and related equipment" at undeclared locations in northern coastal and central regions. www.opcw.org/sites/defaul...

Here is a look at all the special security features that Apple, Google, and WhatsApp offer to protect you from spyware all in one place. We looked at what these features do, and how to turn them on. We highly recommend them for anyone who's worried about government spyware.

These special phone and app features can help protect you from spyware | TechCrunch

Apple, Meta, and Google offer special security modes that provide your devices more secure against targeted spyware attacks. Here are how those modes work, what they do, and how to switch them on.

techcrunch.com

To help protect Signal users from phishing and social engineering attacks, we’ve introduced additional confirmations and educational messaging in the app to help people better detect fraudulent profiles, especially message requests from scammers posing as Signal. More changes are on the way.

New changes to help you stay safe in Signal. Look out for the name not verified notice. Signal can't verify profile names.Screenshot showing an additional confirmation step for accepting message requests.A screenshot showing more detailed safety tips.A screenshot showing a reminder to never respond to a chat pretending to be Signal.

🚨 BREAKING: Mini Shai-Hulud has spread to Packagist. We detected a malicious intercom/intercom-php@5.0.2 package artifact tied to this campaign. This is the third supply chain attack we've reported on today, and we're continuing to monitor the campaign: socket.dev/blog/mini-sh...

Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP...

Socket found a malicious Intercom PHP package on Packagist using Composer plugin execution to steal credentials and spread across ecosystems.

socket.dev

When DOGE arrived at the Nuclear Regulatory Commission, the operatives had no real background in nuclear issues. They boxed out experienced hands, forcing resignations and massive exodus of talent. Over 400 people have since left or been forced out. Our full story: https://propub.li/3OBQMwk

Graphic displaying how hundreds of staff who do work related to nuclear reactors and their safety have left and not been replaced. The data is categorized into six sections: Nuclear Reactor Regulation, Nuclear Material Safety and Safeguards, Nuclear Regulatory Research, Nuclear Security and Incident Response, Regional offices, and Other offices. Each orange square underneath a category represents a loss in staff, while each gray square represents an addition of staff. The graphic shows that there have been 443 losses and 57 arrivals across all six of these categories. Note: The data is from the week ending Jan. 24, 2025, through Feb. 13, 2026. Source: Weekly Information Reports from the Nuclear Regulatory Commission.

We are very happy that today Apple issued a patch and a security advisory. This comes following 404 Media reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted.

🚨 Breaking: Namastex Labs, the team behind Automagik[.]dev, hit with a supply chain attack affecting its npm packages. The malicious versions replicate TeamPCP-style Canister Worm tradecraft, including secret theft, exfiltration, and self-propagation. socket.dev/blog/namaste...

Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm...

Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

socket.dev

We published technical analysis of the Checkmarx compromise, including how malicious extensions silently fetched a second-stage payload from Checkmarx’s own GitHub repo. Our analysis also shows the malware stole developer credentials and used them for exfiltration and propagation.

Socket@socket.dev · 4mo ago

🚨 BREAKING: Socket and @docker.com uncovered what appears to be a broader Checkmarx supply chain compromise affecting official KICS Docker images and recent Checkmarx VS Code extension releases. More details: socket.dev/blog/checkma...

“If you criticise Palantir’s platform one more time, you are going to lose your job.” Solidarity to all NHS workers opposing this toxic corporation. Shame on those bullying them. But they won’t stop us. We’re going to ditch Palantir. www.ft.com/content/ff70...

Senior NHS officials warned staff over criticising rollout of Palantir platform

Ethical objections and uneven adoption have made the tech group’s contract a divisive issue within English health service

ft.com