Tag: government
-
Hackers Are Exploiting Trimble Cityworks, CISA Warns
Tags: cisa, exploit, flaw, government, hacker, infrastructure, microsoft, remote-code-execution, tool, update, vulnerabilityFeds Order Agencies to Patch Critical Flaw in Widely Used Local Government System. Hackers are exploiting a critical vulnerability in Trimble’s Cityworks platform, an infrastructure management tool used by governments that enables remote code execution on Microsoft IIS web servers. CISA has ordered federal civilian agencies to patch a critical vulnerability by Feb. 28. First…
-
Privacy Roundup: Week 6 of Year 2025
Tags: access, ai, api, apple, backdoor, breach, browser, cctv, chrome, control, credit-card, cybersecurity, data, data-breach, encryption, exploit, firmware, framework, germany, government, group, leak, malware, monitoring, phishing, privacy, regulation, risk, router, scam, service, software, spy, technology, threat, tool, update, vpn, vulnerability, windowsThis is a news item roundup of privacy or privacy-related news items for 2 FEB 2025 – 8 FEB 2025. Information and summaries provided here are as-is for warranty purposes. Note: You may see some traditional “security” content mixed-in here due to the close relationship between online privacy and cybersecurity – many things may overlap;…
-
CISA warns of hackers targeting vulnerability in Trimble Cityworks to conduct RCE
The software is widely used in projects by local governments, utilities, airports and other facilities. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-hackers-vulnerability-trimble-cityworks/739681/
-
Global police operation seizes 8base ransomware gang leak site
The U.S. government previously said 8base indiscriminately targeted multiple sectors across the United States, including healthcare First seen on techcrunch.com Jump to article: techcrunch.com/2025/02/10/global-police-operation-seizes-8base-ransomware-gang-leak-site/
-
Out of 6,000 requests, Apple provided UK with iCloud data only four times since 2020
The figures suggest a potential motivation behind the British government’s reported legal order to require Apple to be capable of providing iCloud content upon receipt of a valid warrant. First seen on therecord.media Jump to article: therecord.media/requests-apple-provided-four-times
-
British military drops basic training to fast track recruitment of ‘cyber warriors’
The British government is dropping the traditional fitness and weapons training for specialist cyber military recruits in order to address a cyber skills shortage within His Majesty’s Armed Forces, including in its arm for offensive operations in the National Cyber Force. First seen on therecord.media Jump to article: therecord.media/british-military-drops-basic-training-to-fast-track-cyber-recruits
-
UK Gov demands backdoor to access Apple iCloud backups worldwide
UK secretly demands Apple create an iCloud backdoor via a Technical Capability Notice, raising privacy concerns over end-to-end encryption. The UK demands Apple to create a backdoor to access any iCloud backups, the request raises concerns about user privacy and undermines Apple’s security commitments. >>The British government’s undisclosed order, issued last month, requires blanket capability…
-
UK Is Ordering Apple to Break Its Own Encryption
The Washington Post is reporting that the UK government has served Apple with a “technical capability notice” as defined by the 2016 Investigatory Powers Act, requiring it to break the Advanced Data Protection encryption in iCloud for the benefit of law enforcement. This is a big deal, and something we in the security community have…
-
Secret Taliban records published online after hackers breach computer systems
The Taliban government of Afghanistan is reeling after unidentified hackers successfully carried out a massive cyber attack against its computer systems and published over 50GB of stolen documents and files online. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/taliban-records-online-hackers-breach
-
The Wall Street Journal: Lawmakers Push to Ban DeepSeek App From U.S. Government Devices
Bipartisan Effort Seeks to Protect National Security Amid Concerns Over Chinese Data Collection WASHINGTON”, A new bill set to be introduced Thursday was initiated based on an analysis by Ivan Tsarynny , CEO of Feroot Security, which uncovered serious security risks posed by the DeepSeek chatbot application. The findings by Feroot Security, first reported by…
-
Snoopers’ Charter: Großbritannien will Zugriff auf iCloud-Backups weltweit
Die britische Regierung verpflichtet Apple, eine Backdoor für verschlüsselte iCloud-Backups von Nutzern weltweit einzurichten. First seen on golem.de Jump to article: www.golem.de/news/snoopers-charter-grossbritannien-will-zugriff-auf-icloud-backups-weltweit-2502-193159.html
-
UK Secret Order Demands That Apple Give Access to Users’ Encrypted Data
Plus: Benjamin Netanyahu gives Donald Trump a golden pager, Hewlett Packard Enterprise blames Russian government hackers for a breach, and more. First seen on wired.com Jump to article: www.wired.com/story/uk-secret-order-apple-users-encrypted-data/
-
DeepSeek, data privacy on lawmakers’ radar
U.S. lawmakers are taking steps to ban DeepSeek from government devices, which should signal to enterprises the inherent risks of using the service. First seen on techtarget.com Jump to article: www.techtarget.com/searchcio/news/366619060/DeepSeek-data-privacy-on-lawmakers-radar
-
The SolarWinds $4.4 billion acquisition gives CISOs what they least want: Uncertainty
Tags: attack, breach, business, cisa, ciso, cyber, cybersecurity, finance, government, group, risk, risk-management, service, software, strategy, supply-chain, tool, updateWhen SolarWinds on Friday announced a $4.4 billion cash deal for it to be acquired by private equity (PE) firm Turn/River Capital, it delivered the last thing that nervous enterprise CISOs want: Uncertainty, to be followed by more uncertainty.”Whenever a security company gets acquired by private equity, you never want to throw a party,” said…
-
Hackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts
Federal civilian agencies have been ordered to patch a vulnerability impacting Trimble Cityworks, a popular tool used by many governments to manage public infrastructure. First seen on therecord.media Jump to article: therecord.media/hackers-exploiting-trimble-cityworks-bug-used-by-local-govs
-
U.S. CISA adds Trimble Cityworks flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Trimble Cityworks vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Trimble Cityworks vulnerability, tracked as CVE-2025-0994, to its Known Exploited Vulnerabilities (KEV) catalog. Trimble Cityworks is a GIS-centric asset management and permitting software designed for local governments, utilities, and…
-
Asian Governments Rush to Ban DeepSeek Over Privacy Concerns
Governments Are Skeptical of Chinese A1 Platform’s Data Security Controls. Countries across Asia are racing to ban government officials, national agencies and critical infrastructure organizations from using Chinese artificial intelligence company DeepSeek’s open-source chatbot application, citing data security and privacy risks. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/asian-governments-rush-to-ban-deepseek-over-privacy-concerns-a-27476
-
UK Government Reportedly Demands Access to Encrypted iCloud Files Worldwide
As reported by The Washington Post, Apple received notice of a possible request in March 2024, but the official ask occurred in January 2025. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/uk-apple-encryption-icloud/
-
US lawmakers move to ban DeepSeek AI tool
US politicians have introduced a bill seeking to ban the use of the DeepSeek AI tool on government-owned devices, citing national security concerns due to its alleged links to the Chinese state First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366619153/US-lawmakers-move-to-ban-DeepSeek-AI-tool
-
ACLU Warns DOGE’s ‘Unchecked’ Access Could Violate Federal Law
The ACLU says it stands ready to sue for access to government records that detail DOGE’s access to sensitive personnel data. First seen on wired.com Jump to article: www.wired.com/story/aclu-doge-congress-musk-data/
-
Treasury Curtails Musk-led DOGE’s Government Access
First seen on scworld.com Jump to article: www.scworld.com/brief/treasury-curtails-musk-led-doges-government-access
-
Yahoo Finance: U.S. Lawmakers Push to Ban China’s DeepSeek AI Over Security Risks Feroot Security Analysis
Washington, D.C. U.S. lawmakers announced a bill to ban DeepSeek, the Chinese AI chatbot app, from government devices following a security analysis by Feroot Security that revealed alarming privacy and national security risks. The research suggests that DeepSeek collects user data, including digital fingerprints, login credentials, and behavioral information, potentially sending it to servers…The post…
-
HPE begins notifying data breach victims after Russian government hack
Hackers with Russian foreign intelligence were blamed for the breach, which also targeted Microsoft. First seen on techcrunch.com Jump to article: techcrunch.com/2025/02/07/hpe-begins-notifying-data-breach-victims-after-russian-government-hack/
-
UK reportedly demands secret ‘back door’ to Apple users’ iCloud accounts
The British government has reportedly issued a secret legal demand to Apple to allow access to encrypted iCloud accounts. First seen on therecord.media Jump to article: therecord.media/uk-government-reportedly-demands-backdoor-apple-icloud
-
Encryption Debate: Britain Reportedly Demands Apple Backdoor
Secret Order Seeks to Compel Apple to Weaken Encryption, Washington Post Reports. The British government has unexpectedly reignited the long-running encryption debate, reportedly issuing a secret order to Apple requiring that it provide direct access to global users’ fully encrypted cloud backups and prohibited the technology giant from alerting any targeted accountholders. First seen on…
-
UK government demands Apple backdoor to encrypted cloud data: report
Apple is likely to stop providing its encrypted cloud service to U.K. users First seen on techcrunch.com Jump to article: techcrunch.com/2025/02/07/uk-government-demands-apple-backdoor-to-encrypted-cloud-data-report/
-
Taiwan’s DeepSeek Ban Reflects Global Concerns Over AI Security
The Taiwan government’s recent decision to implement a ban on the use of the DeepSeek artificial intelligence chatbot within its public sector has drawn significant attention to the growing global concerns regarding AI security. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/taiwans-deepseek-ban/
-
DeepSeek iOS App Leaks Data to ByteDance Servers Without Encryption
DeepSeek iOS app”, a highly popular AI assistant recently crowned as the top iOS app since its January 25 release”, has been discovered to transmit sensitive user data to ByteDance servers without encryption. The security flaws, uncovered by mobile app security firm NowSecure, have prompted swift reactions from governments, enterprises, and cybersecurity experts worldwide. The…
-
Will DOGE Access to CMS Data Lead to HIPAA Breaches?
Experts Cast Nervous Eye on Musk and Team’s Handling of Health-Related Info. Privacy experts are keeping a nervous eye on the potential for compromises involving Americans’ health and personal information resulting from the White House’s Department of Government Efficiency – led by Elon Musk – accessing government IT systems containing Medicare and health related data.…

