Facebook, Instagram now mine web links you visit to fuel targeted ads
- Reference: 1704698832
- News link: https://www.theregister.co.uk/2024/01/08/security_in_brief/
- Source link:
The latest attempt to extract more sellable data comes in the form of link history, which lists the webpages you've visited using the browser built into Meta's apps. Link history stores records for 30 days, can be used to recall pages previously read, and excludes links sent in messages. This could be convenient, to be sure.
Less prominently mentioned on help pages describing the feature on [1]Facebook and [2]Instagram is, of course, perhaps the real reason for the capability: "We may use link history information from our browser to improve your ads across Meta technologies."
[3]
And there we have it: A new feature that's actually a way to boost targeted advertising after [4]changes by Apple and others hobbled Meta's ability to collect info on its users. If you don't want to be hit with adverts tailored to your browsing habits, see the above links to opt out.
Critical vulnerabilities: A very patchy new year
There's no rest for security teams heading into 2024, with the past week bringing us several security fixes for critical vulnerabilities, including several newly-reported issues in Chrome.
The latest stable channel release for Chrome Desktop includes six security fixes, four of which Google singled out for [5]recognition in the release notes. Two issues in ANGLE were addressed, as were use after free issues in WebAudio and WebGPU. Patch asap!
Elsewhere:
CVSS 9.8 - [6]Multiple CVEs : Rockwell Automation FactoryTalk Activation Manager software v4.00 contains a couple of out-of-bounds write bugs that could give an attacker full system control.
CVSS 9.8 - [7]CVE-2023-6448 : Unitronics Vision Series PLCs and HMIs are being shipped with default administrative passwords that need changing and CISA warns it's under active exploitation.
CVSS 9.6 - [8]CVE-2023-39336 : Ivanti Endpoint manager 2022 SU4 and all prior versions are vulnerable to SQL injection from anyone with access to the same network as a vulnerable machine.
A couple of new exploits have been detected being used in the wild this week, too:
CVSS 8.8 - [9]CVE-2023-7024 : We [10]reported on this Chrome heap buffer overflow at the end of last year
[11]CVE-2023-7101 : There's no CVSS score available for this newly-discovered vulnerability in Spreadsheet::ParseExcel, a Perl module used to parse Excel files. Input isn't being validated properly, opening up an RCE window.
Watch out for Twitter hijackings
If you missed it, Google-owned security firm Mandiant embarrassingly had its Twitter account [12]hijacked this past week for a short while and turned into a pitch machine for cryptocurrency scams.
Another victim, web3 firm CertiK, was hit by a [13]similar group of miscreants as well. As in Mandiant's case, the CertiK's hijackers tried to trick the firm's crypto-conscious followers into falling for scams.
[14]
[15]
It's not entirely clear how either incident happened. Mandiant noted: "As you likely noticed ... Mandiant lost control of this X account which had 2FA enabled. Currently, there are no indications of malicious activity beyond the impacted X account, which is back under our control. We'll share our investigation findings once concluded."
Consider the hijacks to be a reminder: Don't just [16]check to be sure 2FA is still enabled on your X account, take steps to make sure these tokens can't be phished or obtained along with login credentials.
Apropos of nothing, we couldn't help but notice the chief exec of a collapsed crypto fund [17]seemingly never existed in the first place...
Nigerian not-a-prince cuffed over BEC
A Nigerian national has been arrested and is awaiting extradition to the US on charges he defrauded two American charities out of more than $7.5 million via a business email compromise scheme.
[18]According to the US Justice Department, Olusegun Samson Adejorin allegedly purchased a credential-stealing tool and used it to harvest details for the two charities, one in Maryland and the other in New York.
[19]
Using the stolen credentials, Adejorin allegedly asked the Maryland charity's bank to release large sums of cash to the New York charity. This isn't immediately suspicious, as the New York charity used the Maryland one for investment services. Withdrawals over $10,000 required approval from the Maryland charity, which Adejorin, allegedly having a foothold in both firms, was happy to provide. The bank details, of course, weren't for the New York charity, but controlled by Adejorin, it is claimed.
It's not clear how Adejorin was caught, but if convicted, his sentence could be considerable. Facing eight counts, the Nigerian could do up to 20 years for each of five wire fraud charges, five years for unauthorized access to a protected computer, and two years each for two counts of identity theft. ®
Get our [20]Tech Resources
[1] https://m.facebook.com/help/1980001549003872/how-to-turn-your-link-history-in-facebook-on-or-off/?helpref=platform_switcher&cms_platform=iphone-app
[2] https://help.instagram.com/426880382237026/?cms_platform=android-app&helpref=platform_switcher
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZvV2BFYancHB1hCMqrpAAAAAIc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2022/09/06/apple_app_transparency_ad_revenues/
[5] https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop.html
[6] https://www.cisa.gov/news-events/ics-advisories/icsa-24-004-01
[7] https://www.cisa.gov/news-events/ics-advisories/icsa-23-348-15
[8] https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US
[9] https://nvd.nist.gov/vuln/detail/CVE-2023-7024
[10] https://www.theregister.com/2023/12/23/iranian_cyberspies_target_us_defense/
[11] https://nvd.nist.gov/vuln/detail/CVE-2023-7101
[12] https://www.theregister.com/2024/01/04/mandiant_restores_hijacked_x_account/
[13] https://twitter.com/malwrhunterteam/status/1743257775491191210
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZvV2BFYancHB1hCMqrpAAAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZvV2BFYancHB1hCMqrpAAAAAIc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://help.twitter.com/en/managing-your-account/two-factor-authentication
[17] https://www.theguardian.com/technology/2024/jan/04/chief-executive-of-collapsed-crypto-fund-hyperverse-does-not-appear-to-exist
[18] https://www.justice.gov/usao-md/pr/nigerian-national-arrested-ghana-facing-federal-charges-alleged-75-million-business
[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZvV2BFYancHB1hCMqrpAAAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[20] https://whitepapers.theregister.com/
Re: Nothing more annoying
That rather misses the point that the bastards using surveillance capitalism as a business model are desperately trying to normalize it.
Re: Nothing more annoying
Does it bother me that some computer in a far away country stores information about me? No! If it did, I wouldn't use the services its owner provides.
Well, it bothers me.
More Yank Sentencing
Facing eight counts, the Nigerian could do up to 20 years for each of five wire fraud charges, five years for unauthorized access to a protected computer, and two years each for two counts of identity theft
So, 109 years in chokey. Obviously there may be parole after 80 years. And before people point it out, these are maximums etc. etc., yet why do these buffoons have such ludicrous sentencing ?
Re: these are maximums
Yeah, and the suspect is black and he robbed charities. Somehow I don't have the impression that either judge or jury are going to be lenient.
As for the sentencing, you need to understand that law enforcement throw everything they can in hope that something, anything, will stick and remain after the tireless efforts of the attorney to remove charges on whatever basis he can conjure from the rulebook and from prior sentencing. That explains their tendancy to go somewhat overboard with the charges, it's likely most will be dismissed (maybe not in this case, though).
That is also how the police press innocent people into admitting a crime they never committed. Stick someone in a windowless room for 24 hours, subject them to endless questioning and impress them with all the maximum sentences the police can try to dream up (carefully avoiding the sentence "I want my lawyer"), and many people fold just to get rid of the pressure.
Don't forget : it's the best justice money can buy.
I'm OK with this
I didn't need any more reasons to avoid facebook like the plague it is.
Nothing more annoying
... than untargeted advertisements.
If I pick up a magazine about, say, canoeing then I expect it to have advertisements for canoes, paddles and the like. I don't want to see advertisements for bleach, lawnmowers or dog food.
Does it bother me that some computer in a far away country stores information about me? No! If it did, I wouldn't use the services its owner provides.