Layer 8½

@mbrookspetersen.eurosky.social

Cybersecurity Awareness & Culture Specialist. Posting about #infosec and related people stuff.

An EFF investigation has found that some advertising SDKs enable location data collection by default. The findings aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app.

Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy

An EFF investigation identified several advertising software development kits (SDKs) that publicly acknowledge collecting and sharing users’ location by default when embedded in apps granted location ...

eff.org

I wrote a very deep-dive for subscribers about how ad blockers work, and why they're so effective at preventing web tracking, location surveillance, and blocking ads that serve malware. I also offer my favorite ad-blocker suggestions, including browser extensions and network-level ad-blockers.

Why ad blockers are a top security and privacy defense for everyone

Ad blockers can help defend against some of the top hacks, scams, and surveillance today. Here are some of the best ad blockers that you can use.

this.weekinsecurity.com

Leaflet is the new† Substack‡, you heard it here first folks! ✍️ 🍃 💸 †not just new — better — b/c no platform lock-in, great Bluesky integration…and now, monetization too! ‡actually even bigger than that; not just us but a whole open ecosystem replacing Substack! here if you have any q's!

Piloting paid memberships for the open social web!

Lab Notes 035: building monetization features for Leaflet creators, starting with paid memberships — tell us if you'd like to be the first to try, and what else you need!

lab.leaflet.pub

Folks fighting for ad blockers in your orgs: ifin-intel.org/blog/ad-bloc...

Just Deploy the Ad Blocker | IFIN

Enterprises sometimes shy away from free tools without support contracts. An ad blocker browser extension should not be one of them.

ifin-intel.org

Zack Whittaker@zackwhittaker.com · yesterday

By me at this.weekinsecurity.com: A major online ads company that claims to serve 1.5 billion ads a day was hacked and began serving malware designed to steal a person's crypto. This is the latest perfect example why you should use an ad-blocker.

Much of my career boils down to: All code is liability. Minimize it. Feedback loops are everywhere. Speed them up; do them more. We're bad at predicting the future. Avoid it. More tests. Hire smart, motivated people, then get out of their way. Find the right thing to turn off and on again.

A small army of volunteer security experts has spent the past few years helping rural water utilities with cybersecurity. How has it gone? What have they learned? And what's next? Read my (timely!) new story about DEF CON Franklin: www.cybersecuritydive.com/news/water-c...

How volunteer cyber experts are helping protect rural water systems

A first-in-the-nation program is seeing promising results as it charts a path for supporting the U.S.’s most vulnerable infrastructure.

cybersecuritydive.com

A new ransomware group (who I'm not giving the publicity of naming) is brazenly offering journalists early access to their data leak site in order to increase pressure on victims to make an extortion payment. I'm unaware of other recipients but the message looks mass-sent.

Bild

The majority of corporate IT is now off premises for the first time #cybersecurity #infosec

The majority of corporate IT is now off premises for the first time

IT is going remote while sucking up more power. Most corporate IT is now off-premises for the first time, according to Uptime Institute, while the average rack power density has crested above 11 kW for the first time as server fleets are gradually replaced with more powerful hardware. Uptime’s Global Data Center Survey 2026 reveals how the industry is managing to adapt to challenging circumstances, with the usual evergreen concerns over rising costs plus staffing and skills shortages. The survey polls more than 800 datacenter owners and operators across multiple countries, with more than half (52 percent) in North America and Europe. Off premise dominates: Every year, Uptime asks its enterprise respondents to estimate what percentage of their IT workloads are run in-house versus in third-party facilities. For the first time, third-party sites have the larger share, accounting for 46 percent of IT workloads, compared with 44 percent residing in enterprise-owned corporate server farms. Those figures don’t add up to 100 percent, as some respondents (10 percent) say they are using IT rooms and server cabinets rather than a dedicated facility. Uptime’s experts estimate that, by 2028, the proportion of workloads in self-owned server halls will remain the same, while those running in third-party sites will expand to 48 percent, eating away at those currently based in IT rooms and server cabinets. More power: While the headlines have featured AI infrastructure pushing IT infrastructure power density to 120 kW per rack or even higher, the reality is that most datacenters and servers operate at a much lower level than that. This year, the average of the most typical rack densities now surpasses 11 kW, as a gradual ongoing shift toward higher-powered hardware was compounded by a small number of new high-density facilities with racks above 30 kW. Without those few high-density facilities skewing the average, it sits at 7.8 kW, just slightly up from 7.5 kW in 2025. The majority of facilities still do not have any racks of 30 kW or above, Uptime finds, but more respondents (24 percent) now say they have some of these, compared with 19 percent last year. The increase was mostly in the 50-plus kW ultra-high-density range, including some respondents deploying AI and GPU servers into racks configured for above 100 kW. The trend for rising rack density will continue as organizations upgrade their infrastructure with newer hardware. Updated servers boost both workload capacity and energy performance, but maximizing these benefits means a corresponding rise in overall system power, Uptime states. Refresh shortened: Some operators are also pursuing more aggressive technology refresh timelines of less than 4 years, the report claims. If true, this would be the reverse of what some hyperscalers such as Microsoft, Google and Meta have been doing in recent years, extending lifecycles out to 6 or 7 years to save on depreciation expenses. Outages: When it comes to outages, this year’s report shows improvement for the sixth year in a row, with the number of respondents who experienced an outage in the past three years down by three percentage points. But Uptime warns against complacency, noting that many of the factors behind outages, such as reduced or unstable power availability, local grid reliability, supply chain constraints, and extreme weather, are on the increase. The flip side is that the costs of any outages that do occur continue to rise. This is because organizations have become more dependent on digital infrastructure, the report says, and so outages may have more financial impact than in the past. Overall, 71 percent of survey respondents reported that their most damaging outage cost at least $100,000, compared with 57 percent a year ago. Staffing shortage: Staffing has long been an issue for datacenter operators, and this year the greatest skills gaps reported were in electrical (38 percent of respondents), junior level operations (38 percent), operations management (35 percent) and mechanical roles (34 percent). However, more than half (53 percent) of operators report difficulties finding qualified candidates for vacant roles, up from 46 percent a year ago. Finally, Uptime found that financial pressure and resource constraints continue to grow among operators. In fact, the high prices of power, staff, and equipment, particularly for AI-related infrastructure, is the primary issue. Alongside that are escalating concerns over capacity forecasting, power availability and supply chain disruptions. ®

theregister.com

Thüringen will den IT-Grundschutz in allen Kommunen einführen. Der Aufhänger mit den Millionen abgewehrten Spam-Mails ist lapidar. Spannender ist die eigentliche Ankündigung. ✅️ Die Zieldefinition ist durchaus ein Fortschritt und keineswegs selbstverständlich. #ITGrundschutz #Kommunen #Thüringen

Sicherheit: Hohe Gefährdung: IT-Grundschutz soll Cyberattacken abwehren

Hier finden Sie Informationen zu dem Thema „Sicherheit“. Lesen Sie jetzt „Hohe Gefährdung: IT-Grundschutz soll Cyberattacken abwehren“.

zeit.de

Germany to ban Meta’s Pervert Glasses? ​Hamburg’s Data Protection Office warns that recording people in public with smart glasses violates privacy laws. The tiny LED indicator light isn't prominent enough to prevent secret filming in public spaces. 1/2 www.tagesschau.de/inland/innen...

Hamburger Datenschutzbeauftragter: Verbot von Meta Glasses möglich

Der Hamburger Datenschutzbeauftragte Fuchs warnt vor Meta Smart Glasses: Die Brillen, die kaum von normalen Brillen zu unterscheiden sind, ermöglichen heimliches Filmen. Ein Verbot sei nicht ausgeschl...

tagesschau.de