/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

@citizenlab

@citizenlab
54 posts
2024-10-16
WeChat messages are encrypted twice, yet, double encryption doesn't make it more secure. In #WeChat, messages are first encrypted with an old and vulnerable custom protocol called “Business-layer Encryption”, then encrypted again with MMTLS, which contains minor weaknesses. [image]
2024-10-16 View on X
The Citizen Lab

An analysis of WeChat's network protocol MMTLS finds that it is a modified version of TLS 1.3 and WeChat developers' changes to its cryptography add weaknesses

Key contributions  — We performed the first public analysis of the security and privacy properties of MMTLS … X: @citizenlab , @thegrugq , @jsrailton , and @citizenlab X: @citizenl...

💬NEW REPORT: The Citizen Lab takes a deep dive into the network encryption protocol used by #WeChat, an app with over one billion users. The app uses a custom #encryption protocol called “MMTLS” that introduces cryptographic weaknesses. Read the report: https://citizenlab.ca/...
2024-10-16 View on X
The Citizen Lab

An analysis of WeChat's network protocol MMTLS finds that it is a modified version of TLS 1.3 and WeChat developers' changes to its cryptography add weaknesses

Key contributions  — We performed the first public analysis of the security and privacy properties of MMTLS … X: @citizenlab , @thegrugq , @jsrailton , and @citizenlab X: @citizenl...

2024-10-04
UPDATE: @Microsoft's Digital Crimes Unit takes legal action to dismantle Russia-based threat actor COLDRIVER following our joint investigation with @accessnow. Read more: https://citizenlab.ca/...
2024-10-04 View on X
Bloomberg

The US and Microsoft seize 107 websites used by Russian intelligence agents and their proxies in the US operating under Star Blizzard, a group active since 2016

Today, the United States District Court for the District of Columbia unsealed a civil action brought … Ben Johnson : 👏 I'm very proud that today, it was unveiled that the NGO-ISAC,...

2024-08-15
🚨 NEW REPORT by @citizenlab in collaboration with @accessnow, @DeptFirst, Arjuna Team and https://resident.ngo/ uncovers a sophisticated and highly-personalized #phishing campaign targeting civil society members in the US and Europe, including Russian opposition in exile,
2024-08-15 View on X
Washington Post

Access Now and Citizen Lab: Russian spy agencies are using deep knowledge about opponents, reporters, and human rights groups to target them via phishing emails

Joseph Menn / Washington Post :

2024-08-14
🚨 NEW REPORT by @citizenlab in collaboration with @accessnow, @DeptFirst, Arjuna Team and https://resident.ngo/ uncovers a sophisticated and highly-personalized #phishing campaign targeting civil society members in the US and Europe, including Russian opposition in exile,
2024-08-14 View on X
Washington Post

Access Now and Citizen Lab: Russian spy agencies are using deep knowledge about opponents, reporters, and human rights groups to target them via phishing emails

Traditional phishing attacks aimed to break into organizations advocating for Russian dissidents, among others.

2023-10-30
This report, co-authored by Citizen Lab's Gary Miller and former senior research associate @caparsons is a field guide to the security risks around the mobile cellular ecosystem, with a focus on location disclosure [image]
2023-10-30 View on X
The Citizen Lab

Research details how vulnerabilities in signaling protocols used by mobile network operators for international roaming can be exploited to geolocate devices

Gary Miller / The Citizen Lab :

2023-09-13
🚨NEW INVESTIGATION by @citizenlab in collaboration with @accessnow reveals that award-winning Russian journalist Galina Timchenko's #iPhone was infected with the #Pegasus #spyware. Full statement➡️ https://citizenlab.ca/...
2023-09-13 View on X
Washington Post

Researchers: the iPhone of Meduza owner Galina Timchenko was infected with Pegasus in Germany, the first known case of the tool being used against a Russian

Unclear is who planted the spyware while the founder of the Meduza news outlet was in Germany  —  The iPhone of a prominent Russian …

2023-09-09
🚨🚨WE URGE EVERYONE TO UPDATE THEIR APPLE DEVICES AS SOON AS POSSIBLE. We have found an actively exploited #zero #click vulnerability that was used to deliver #NSO group's #Pegasus #spyware. https://citizenlab.ca/...
2023-09-09 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

2023-09-08
🚨🚨WE URGE EVERYONE TO UPDATE THEIR APPLE DEVICES AS SOON AS POSSIBLE. We have found an actively exploited #zero #click vulnerability that was used to deliver #NSO group's #Pegasus #spyware. https://citizenlab.ca/...
2023-09-08 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

Apple released software updates on Thursday to address two zero-day vulnerabilities that researchers said were used …

2023-08-10
🚨🚨➡️ NEW REPORT OUT > Imagine if someone read everything you type online. Our new report- “Please do not make it public”, analyzes Tencent's #Sogou Input Method, the most popular input app in #China has serious vulnerabilities in the encryption system. https://citizenlab.ca/...
2023-08-10 View on X
The Citizen Lab

Analysis: Tencent's Sogou Input Method, the top Chinese character inputting tool in China with 450M+ MAUs, had since-fixed data-leaking flaws in its encryption

2023-06-29
🚨NEW REPORT Should We Chat? Privacy in the WeChat Ecosystem. Report by @m0namon @2Pellaeon and Jeffrey Knockel finds #WeChat records user activity and usage when users launch Mini Programs. This is a privacy risk & unknown how data collected might be used https://citizenlab.ca/...
2023-06-29 View on X
The Citizen Lab

An analysis of WeChat's tracking ecosystem using reverse engineering: the app records and tracks user behavior when executing Mini Programs, a privacy risk

The Citizen Lab : Twitter: @citizenlab Twitter: @citizenlab : 🚨NEW REPORT Should We Chat? Privacy in the WeChat Ecosystem. Report by @m0namon @2Pellaeon and Jeffrey Knockel finds ...

2023-04-27
🚨NEW REPORT: MISSING LINKS ⛓️. Are you unable to get answers to your online searches? Multiple levels of #censorship affects eight #China accessible search platforms including #MicrosoftBing blocking all or some results. https://citizenlab.ca/...
2023-04-27 View on X
The Citizen Lab

An analysis of Baidu, Bilibili, Bing, Douyin, Weibo, and other Chinese search platforms finds 60K censorship rules, implemented differently by each service

This report has an accompanying FAQ.  —  Key findings  — Across eight China-accessible search platforms analyzed — Baidu …

2023-04-19
🚨NEW REPORT: NSO Group's #Pegasus #Spyware returns in 2022 with a trio of iOS 15 and iOS 16 zero-click exploit chains. The report finds NSO group clients deployed exploits against civil society members including two human right defenders in #Mexico https://citizenlab.ca/...
2023-04-19 View on X
Washington Post

Citizen Lab: in 2022, NSO Group deployed at least three new zero-click hacks against iPhones with iOS 15 and early versions of iOS 16; Apple fixed the flaws

This was an experiment by #apple around #iOS, without guarantees it would do anything.  —  But it did.  —  Concerned about security? … John Scott-Railton / @jsrailton@mastodon.soci...

2023-04-18
🚨NEW REPORT: NSO Group's #Pegasus #Spyware returns in 2022 with a trio of iOS 15 and iOS 16 zero-click exploit chains. The report finds NSO group clients deployed exploits against civil society members including two human right defenders in #Mexico https://citizenlab.ca/...
2023-04-18 View on X
Washington Post

Citizen Lab: NSO Group deployed at least three new “zero-click” hacks against iPhones with iOS 15 and early versions of iOS 16 in 2022; Apple fixed the exploits

SAN FRANCISCO — Israeli spyware maker NSO Group deployed at least three new “zero-click” hacks against iPhones last year …

2023-04-12
The suspected exploit appears to make use of invisible iCloud calendar invitations sent from the spyware's operator to victims. The report identifies victims of QuaDream exploits include journalists, political opposition figures and an NGO worker.
2023-04-12 View on X
TechCrunch

Citizen Lab and Microsoft detail mercenary spyware from Tel Aviv-based QuaDream used to hack iOS 14-based iPhones of journalists, politicians, and an NGO worker

why didn't Apple warn us? Wall Street Journal : New Spyware Firm Said to Have Helped Hack iPhones Around the Globe Phil Muncaster / Infosecurity : New Zero-Click iOS Exploit Deploy...

NEW REPORT: SWEET QUADREAMS: A first look at #spyware vendor QuaDream's spy tools, victims and customers. We identified traces of suspected exploit deployed against iOS versions 14.4 and 14.4.2 and possibly other versions as zero-day vulnerability. https://citizenlab.ca/...
2023-04-12 View on X
TechCrunch

Citizen Lab and Microsoft detail mercenary spyware from Tel Aviv-based QuaDream used to hack iOS 14-based iPhones of journalists, politicians, and an NGO worker

why didn't Apple warn us? Wall Street Journal : New Spyware Firm Said to Have Helped Hack iPhones Around the Globe Phil Muncaster / Infosecurity : New Zero-Click iOS Exploit Deploy...

Like other #spyware, the implant has a range of capabilities from hot -mix audio recording of calls to more advanced #surveillance capabilities 🍎📱👀 https://twitter.com/...
2023-04-12 View on X
TechCrunch

Citizen Lab and Microsoft detail mercenary spyware from Tel Aviv-based QuaDream used to hack iOS 14-based iPhones of journalists, politicians, and an NGO worker

why didn't Apple warn us? Wall Street Journal : New Spyware Firm Said to Have Helped Hack iPhones Around the Globe Phil Muncaster / Infosecurity : New Zero-Click iOS Exploit Deploy...

QuaDream is an Israeli company that specializes in development and sale of advanced digital offensive tech to governments. The map below is an illustration of suspected locations of QuaDream operations https://twitter.com/...
2023-04-12 View on X
TechCrunch

Citizen Lab and Microsoft detail mercenary spyware from Tel Aviv-based QuaDream used to hack iOS 14-based iPhones of journalists, politicians, and an NGO worker

why didn't Apple warn us? Wall Street Journal : New Spyware Firm Said to Have Helped Hack iPhones Around the Globe Phil Muncaster / Infosecurity : New Zero-Click iOS Exploit Deploy...

2023-03-21
First known case of an American national being targeted with a #cyberespionage #predator tool in the EU. We @citizenlab discovered the infection👇🏽. https://www.nytimes.com/... https://twitter.com/...
2023-03-21 View on X
New York Times

Sources: in 2021, the phone of a US and Greek national who worked on Meta's security and trust team was infected with Predator spyware from an Athens-based firm

2022-09-29
NEW: Read statement by director @rondeibert on the fatal flaws found by senior researcher @billmarczak in a defunct CIA covert communications system. We are not publishing the full findings at this time pending responsible disclosure process... https://citizenlab.ca/...
2022-09-29 View on X
Reuters

An investigation shows the CIA failed to secure its messaging system used by Iranian spies, often hidden within websites, leading to capture, torture, and death

The spy was minutes from leaving Iran when he was nabbed.  —  Gholamreza Hosseini was at Imam Khomeini Airport in Tehran in late 2010, preparing for a flight to Bangkok.