A cheap fake base station can still track 5G subscribers

Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G networks. On the… Continue reading A cheap fake base station can still track 5G subscribers→

DavMail 7.0.0 puts most of its work into Microsoft Graph

Anyone who wants to leave Outlook but still has a mailbox on Exchange needs a translator. DavMail is one: a Java gateway that converts the open protocols most mail, calendar and contact apps speak (IMAP, SMTP, CalDAV, CardDAV and LDAP) into requests Ex… Continue reading DavMail 7.0.0 puts most of its work into Microsoft Graph→

Google hit with €403 million GDPR fine over location tracking

Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months. The inquiry examined Google’s … Continue reading Google hit with €403 million GDPR fine over location tracking→

Product showcase: Helmit alerts parents when online conversations show signs of trouble

Helmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and safety alerts. It identifies potentially concerning interactions and surface the messages associated wi… Continue reading Product showcase: Helmit alerts parents when online conversations show signs of trouble→

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contri… Continue reading AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor→

Android apps can now check security patches down to individual device components

New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status of ind… Continue reading Android apps can now check security patches down to individual device components→

Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security G… Continue reading Hardcoded MCP credentials found in public GitHub files→

98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote intervi… Continue reading 98% of fraudulent hires have company credentials by the time they’re caught→