Opens profile photo
Follow
Click to Follow zackwhittaker
Zack Whittaker
@zackwhittaker
Security editor • +1 646.755.8849 • he/him • zack.whittaker@techcrunch.com • mastodon.social/@zackwhittaker
New York, NYthis.weekinsecurity.comJoined August 2008

Zack Whittaker’s Tweets

New: A New York-based 'stalkerware' maker has agreed to notify individuals whose phones were compromised by its mobile surveillance software, including PhoneSpector and Highster, following a deal with the New York attorney general's office.
44
NEW: We obtained a private intelligence report on the hackers known as "0ktapus" or "Scattered Spider." After hitting 130 companies last year, the hackers are still active as of January, targeting Riot Games, Roblox, Salesforce, and Mailchimp and others.
2
38
Show this thread
NEW: Hackers hijacked the Coinbase account of a Google Fi customer. An interesting attack that's hard to explain right now. The hackers didn't take control of the Google account tied to the Fi account, but somehow took control of the phone number.
5
77
Show this thread
New: FTC has slapped GoodRx with a $1.5M penalty for sharing consumers' sensitive health information — including medications and health conditions — with advertisers like Facebook and Google, and ordered GoodRx to stop. w/ .
2
15
After twenty years, the ubiquitous, storied Stripperweb forum is shutting down on February 1. No one knows why. I wrote about how the community has come together to archive their collective history and attempt to track down the forum's elusive owner.
7
160
Show this thread
New: If you bought knock-off designer goods or apparel from these online stores, you might want to get yourself a new credit card. A database of 330,000 unencrypted customer credit card numbers and cardholder information exposed, thanks to no password.
1
30
New: A hack at ODIN Intelligence, which provides tech and apps — like SweepWizard — to police departments, has exposed a huge trove of police files, including tactical plans of police raids, surveillance, and use of facial recognition.
2
131
A file on SpyTrac's server contained AWS keys linked to cloud storage associated with Support King and GovAssist, both run by CEO Scott Zuckerman. Zuckerman denied links to SpyTrac, but couldn't explain how his AWS keys were found on SpyTrac's servers.
9
Show this thread
New: In 2021, the FTC banned SpyFone and its parent company Support King from the surveillance industry. But new data seen by TechCrunch links Support King to a new phone spying operation called SpyTrac, which has compromised over 1.3 million devices.
2
59
Show this thread
Apple says it's aware of exploitation targeting iPhone users running "versions of iOS released before iOS 15.1." But by who? Google TAG, which investigates nation state spyware and hacking, discovered the flaw. That's a big clue as to who's exploiting it.
22
Show this thread
New: Apple says an iPhone software update it released two weeks ago, iOS 16.1.2, contains a security fix for a WebKit zero-day flaw that is being "actively exploited." Apple also released the security fix for those still running iOS 15.
3
79
Show this thread
Xnspy spied on 60,000+ devices globally — mostly Android devices, but data we've seen also contained over 10,000 iCloud account passwords for accessing iCloud backups. Given the possibility of ongoing risk to victims, TechCrunch provided the list of compromised accounts to Apple.
1
16
Show this thread