It Takes 2 Minutes to Hack the EU’s New Age-Verification App
EU Age-Verification App Easily Compromised
The European Commission recently introduced an open-source app designed to confirm the ages of users on social and adult platforms. However, security experts quickly found that the app suffers from critical vulnerabilities. British consultant Paul Moore demonstrated that he could bypass the system in under two minutes, exposing how the PIN is stored in a way that makes user profiles easy to hijack. Another independent security researcher validated this flaw. Experts warn that the app could soon lead to a significant security breach if not fixed.
Major Data Breaches Hit European Businesses
Europe's largest gym chain, Basic-Fit, disclosed a data breach that compromised the bank details and personal information of about a million customers across multiple countries. In the travel industry, Booking.com also confirmed a breach, with hackers potentially accessing names, contact details, and booking information, though no financial data was reportedly leaked.
DDoS Attack Takes Down Bluesky
Decentralized social platform Bluesky faced substantial disruption after a distributed denial-of-service (DDoS) attack, causing outages across its core services. The platform reported no unauthorized data access but said users flocked to alternative servers during the incident.
Concerns Over ICE Hiring Practices
An investigation revealed that some recent hires at US Immigration and Customs Enforcement (ICE) were offered positions before completing full background checks. Some recruits had previous lawsuits or unpaid debts, raising concerns about the agency’s vetting process.
Grinex Crypto Exchange Breached
Russian cryptocurrency exchange Grinex halted operations after over $13 million was stolen in a cyberattack. The company blamed foreign intelligence services for the heist, citing sophisticated techniques targeting Russia’s financial infrastructure. Grinex had previously replaced another exchange that was subject to sanctions.
More Security Stories
- Telegram continues to host a large crypto scam black market despite international sanctions.
- Civil society groups are warning Meta about privacy risks involved with AI-enabled smartglasses.
- Researchers found deepfake nudes are increasingly targeting young girls at schools internationally.
- The AI field is spurring new cybersecurity models and strategies from major players like OpenAI and Anthropic.
For more details, see the full original article on WIRED.