Feed aggregator
Discovery of Quina technology challenges view of ancient human development
CrushFTP Blames Security Firms for Fast Exploitation of Vulnerability
Shadowserver has started seeing exploitation attempts aimed at a CrushFTP vulnerability tracked as CVE-2025-2825 and CVE-2025-31161.
The post CrushFTP Blames Security Firms for Fast Exploitation of Vulnerability appeared first on SecurityWeek.
Python Polars: The Definitive Guide
Article URL: https://polarsguide.com
Comments URL: https://news.ycombinator.com/item?id=43545384
Points: 1
# Comments: 0
Intimate images from kink and LGBTQ+ dating apps left exposed online
A researcher found millions of pictures from specialized dating apps for iOS stored online without any kind of password protection.
The pictures, some of which are explicit, stem from dating apps that all have a specific audience. The five platforms, all developed by M.A.D. Mobile are kink sites BDSM People and Chica, and LGBT apps Pink, Brish, and Translove.
As we reported not too long ago, many iOS apps leak at least one hard coded secret. We consider hard coded secrets in the source code of the apps as exposed because they are relatively easy to find and abuse by cybercriminals. And those secrets can have serious consequences for the apps’ users
Cybernews’ Aras Nazarovas found the storage location (a Google Cloud Storage bucket) used by the apps by reverse engineering the code. To his surprise, he could access the unencrypted and otherwise unprotected photos without needing any password.
As soon as he saw the first image, he knew this storage should not have been public. Not only did it contain profile pictures, it also included pictures sent in private messages, including some removed by moderators.
In total, nearly 1.5 million user-uploaded images were available to anyone stumbling over the storage bucket. Although the images are not linked to any user accounts or other private information, it is not unthinkable that cybercriminals could figure out some of the identities by using commonly available face search engines.
Many of these search engines use Artificial Intelligence (AI) for facial recognition combined with reverse image search technology to find other photos of a person published online, based on a picture submitted by the user.
Although officially intended only for self-searches, many of them don’t bother to check whether that’s actually the case.
Coupled to the identity of the person in the picture, these images could expose users to extortion, as well as an increased risk of hostility. As if online dating isn’t nervewracking enough, especially for those looking in special categories, the last we need is to see our explicit images exposed.
M.A.D Mobile was warned about the leak in January, but didn’t take any action to protect the storage until the BBC contacted the company on Friday. The issue has now been fixed.
It’s important to stipulate that the apps are exclusive to iOS and do not have Android or web alternatives.
Check your digital footprintIf you want to find out what personal data of yours has been exposed online, you can use our free Digital Footprint scan. Fill in the email address you’re curious about (it’s best to submit the one you most frequently use) and we’ll send you a free report.
Think I implemented a unique feature in my feed reader
Article URL: https://andregarzia.com/2025/04/think-i-implemented-a-unique-feature-in-my-feed-reader.html
Comments URL: https://news.ycombinator.com/item?id=43545381
Points: 2
# Comments: 0
An e-bike that charges off USB-C
Article URL: https://www.theverge.com/news/639681/usb-c-charging-e-bike-ampler-nova-specs-price
Comments URL: https://news.ycombinator.com/item?id=43545378
Points: 4
# Comments: 0
CERN scientists find evidence of quantum entanglement in sheep
Article URL: https://home.cern/news/news/physics/cern-scientists-find-evidence-quantum-entanglement-sheep
Comments URL: https://news.ycombinator.com/item?id=43545349
Points: 2
# Comments: 1
Arm Introduces New Developer Initiative to Expedite Migration on Cloud Platforms
Was the historical Jesus talking about evolution? (You might be surprised)
Article URL: https://www.lesswrong.com/posts/FuAcX7oAk9qKG6P2x/was-the-historical-jesus-talking-about-evolution-you-might
Comments URL: https://news.ycombinator.com/item?id=43545344
Points: 3
# Comments: 1
HP Pavilion Plus 14 (2025) Review: Affordable OLED Laptop With a Fatal Flaw
I'm Sticking With Netflix and Max in April, and You Probably Should, Too
Best Internet Deals for April 2025
Best Smartwatch for 2025
Why multi-factor authentication is absolutely essential in 2025
Check Point Responds to Hacking Claims
Check Point has responded to a hacker’s claims of sensitive data theft, confirming an incident but saying that it had limited impact.
The post Check Point Responds to Hacking Claims appeared first on SecurityWeek.
Alan Turing Institute Plans Revamp in Face of Criticism and Technological Change
Billy 'The King of Kong' Mitchell Wins $237,000 in Defamation Lawsuit Victory
BitShifters by Hetzner
Article URL: https://www.hetzner.com/bitshift/
Comments URL: https://news.ycombinator.com/item?id=43545141
Points: 1
# Comments: 0