Following heightened worries that U.S. users' data had been accessed by TikTok engineers in China between September 2021 and January 2022, the company sought to assuage U.S. lawmakers that it's taking steps to "strengthen data security." The admission that some China-based employees can access information from U.S. users came in a letter sent to nine senators, which further … [Read more...] about TikTok Assures U.S. Lawmakers it’s Working to Safeguard User Data From Chinese Staff
user
New Unpatched Apple Safari Browser Bug Allows Cross-Site User Tracking
A software bug introduced in Apple Safari 15's implementation of the IndexedDB API could be abused by a malicious website to track users' online activity in the web browser and worse, even reveal their identity. The vulnerability, dubbed IndexedDB Leaks, was disclosed by fraud protection software company FingerprintJS, which reported the issue to the iPhone maker on November … [Read more...] about New Unpatched Apple Safari Browser Bug Allows Cross-Site User Tracking
Mozilla Says Google’s New Ad Tech—FLoC—Doesn’t Protect User Privacy
Google's upcoming plans to replace third-party cookies with a less invasive ad targeted mechanism have a number of issues that could defeat its privacy objectives and allow for significant linkability of user behavior, possibly even identifying individual users. "FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk," said Eric Rescorla, … [Read more...] about Mozilla Says Google’s New Ad Tech—FLoC—Doesn’t Protect User Privacy
China’s Baidu Android Apps Caught Collecting Sensitive User Data
Two popular Android apps from Chinese tech giant Baidu were temporarily unavailable on the Google Play Store in October after they were caught collecting sensitive user details. The two apps in question—Baidu Maps and Baidu Search Box—were found to collect device identifiers, such as the International Mobile Subscriber Identity (IMSI) number or MAC address, without users' … [Read more...] about China’s Baidu Android Apps Caught Collecting Sensitive User Data
MITRE ATT&CK: The Magic of User Training
October is National Cybersecurity Awareness Month, and this year the theme is “Do Your Part. #BeCyberSmart.” It reminds all of us — individuals and organizations alike — to be proactive and accountable. Cybersecurity is our shared responsibility, and we can do it together. At Cisco, we’re thrilled to contribute a monthlong roster of engaging events, activities, and educational … [Read more...] about MITRE ATT&CK: The Magic of User Training