Normal view

There are new articles available, click to refresh the page.
Today — 18 May 2024Main stream

‘I hope people wonder what the man is doing’: Carla Vermeend’s best phone picture

18 May 2024 at 05:00

The photographer and her husband came across an abandoned boat while out walking and took the opportunity to float a surreal idea

Every September, Carla Vermeend and her husband go on holiday to Terschelling island, in the Netherlands.

“It has lots of nature, right in the middle of the Wadden Sea, which is listed by Unesco as a world heritage site,” says Vermeend, a Dutch photographer. During their visit in 2014, the couple were walking by the sea together.

Continue reading...

💾

© Photograph: Carla Vermeend

💾

© Photograph: Carla Vermeend

Protesters, pop stars and pioneers: 38 images that changed the way we see women (for better and for worse)

Shocking, arresting and extraordinary photographs that shifted how women are seen in the world

• Author Anne Enright: ‘The lens has not lost its power to claim and possess’

By Sophy Rickett

Continue reading...

💾

© Photograph: Dan Wynn/© Dan Wynn Archive and Farmani Group, Co LTD

💾

© Photograph: Dan Wynn/© Dan Wynn Archive and Farmani Group, Co LTD

Yesterday — 17 May 2024Main stream

From If to Billie Eilish: a complete guide to this week’s entertainment

17 May 2024 at 19:00

John Krasinski and Ryan Reynolds go family-friendly in their new imaginary-friends comedy, while the singer swaps introspection for lust on her long-awaited new album

If
Out now
In what has to be one of the more enviable showbiz lives, John Krasinski has played Jim in The Office, married Emily Blunt, and written and directed acclaimed horror franchise A Quiet Place. Now he turns his hand to family entertainment, writing and directing this part-animated fantasy about imaginary friends made visible with a little help from Ryan Reynolds and Steve Carell.

Continue reading...

💾

© Photograph: Photo Credit: Jonny Cournoyer/Jonny Cournoyer

💾

© Photograph: Photo Credit: Jonny Cournoyer/Jonny Cournoyer

French post office releases scratch-and-sniff baguette stamp

‘Bakery scent’ added via microcapsules to postage stamp celebrating ‘jewel of French culture’

The French Post Office has released a scratch-and-sniff postage stamp to celebrate the baguette, once described by President Emmanuel Macron as “250 grams of magic and perfection”.

The stamp, which costs €1.96, depicts a baguette decorated with a red, white and blue ribbon. It has a print run of 594,000 copies.

Continue reading...

💾

© Photograph: Universal Postal Union/X

💾

© Photograph: Universal Postal Union/X

The week around the world in 20 pictures

17 May 2024 at 14:30

War in Gaza, the Russian offensive in Kharkiv, protests in Georgia, the Northern lights and the Cannes Film Festival: the last seven days as captured by the world’s leading photojournalists

Warning: this gallery contains images that some readers may find distressing

Continue reading...

💾

© Photograph: George Ivanchenko/Anadolu/Getty Images

💾

© Photograph: George Ivanchenko/Anadolu/Getty Images

British Museum says 626 items lost or stolen have been found

17 May 2024 at 09:05

Museum chair George Osborne hails ‘remarkable result’ as recovery effort continues with leads on another 100

The British Museum has located another 268 items that went missing or were stolen from its storerooms, bringing the total number recovered to 626.

About 2,000 items were found last year to be missing or lost, some of which had been sold on eBay.

Continue reading...

💾

© Photograph: Tim Ireland/AP

💾

© Photograph: Tim Ireland/AP

Thai high: the rise of a newfound cannabis culture – a photo essay

Photographer Dougie Wallace has been looking at the impact of the decriminalisation of cannabis in Thailand, from Khaosan Road to the beach resorts, such as Krabi and Phuket, that attract tourists

The decriminalisation of cannabis in Thailand in June 2022 has led to an explosion in marijuana shops across the country – especially in its tourist areas. It is sold at trendy dispensaries in Bangkok, at beachside bars across resort islands and even on river cruises. On bustling streets, green leaf logos glow in neon above shop fronts, and small stalls, set up with rows of glass jars, dot the pavement.

Tourists and street advertiser in Patong, Phuket

Continue reading...

💾

© Photograph: Dougie Wallace

💾

© Photograph: Dougie Wallace

Fragile Beauty review – Elton John and David Furnish’s photo collection goes from basic to brutal

17 May 2024 at 05:32

V&A, London
From glossy celebrity portraits through raw news shots to AI-driven abstracts, this epic show captures half a century of iconic images

The latest exhibition of works from Sir Elton John and David Furnish’s gargantuan photography collection is everything you’d expect it to be: spangly, iconoclastic – and a little bit basic. The entry point to the V&A’s largest ever exhibition of photography promises, as the title Fragile Beauty suggests, the frisson of danger in the pursuit of creating something beautiful: the first shot that greets us is a portrait of beekeeper Ronald Fischer, skin crawling with his beloved insects. Richard Avedon found Fischer by putting an ad in the American Bee Journal. He issued two instructions to his sitter: don’t smile and don’t move. Remarkably, Fischer was only stung four times.

The Avedon portrait smacks you in the face with the premise of this show: suffering for one’s art (or making others suffer for it). The seemingly never-ending exhibition unifies 300 works drawn from about 7,000 in the collection, but it is far more personal than the 2016 Radical Eye show at Tate, moving from the 1950s to now, and so spanning John’s own life, as well as the couple’s enduring interests.

Continue reading...

💾

© Photograph: © David LaChapelle

💾

© Photograph: © David LaChapelle

Another layer of mediation to an already loopy transmission

By: chavenet
17 May 2024 at 03:43
Though LSD was sometimes passed around in the 1960s on actual blotting paper, sheets of perforated ('perfed') and printed LSD paper do not come to dominate the acid trade until the late 1970s, reaching a long golden age in the 1980s and '90s. As such, the rise of blotter mirrors, mediates and challenges the mythopoetic story of LSD's spiritual decline. For even as LSD lost the millennialist charge of the 1960s, it continued to foster spiritual discovery, social critique, tribal bonds and aesthetic enrichment. During the blotter age, the quality of the molecule also improved significantly, its white sculptured crystals sometimes reaching and maybe surpassing the purity levels of yore. Many of the people who produced and sold this material remained idealists, or at least pragmatic idealists, with a taste for beautiful craft and an outlaw humour reflected in the design of many blotters, which sometimes poked fun at the scene and ironically riffed on the fact that the paper sacraments also served as 'commercial tokens'. from Acid media [Aeon; ungated]

Gold, garages and gardens: celebrating the female photographers of Photo London

17 May 2024 at 04:00

The annual showcase of the best in photography features an unprecedented number of women working across all genres – from impressive up and comers to establishment names such as Nan Goldin and Sarah Moon

• Photo London is at Somerset House, London, to 19 May

Continue reading...

💾

© Photograph: Chloé Jafé/Galerie Echo 119

💾

© Photograph: Chloé Jafé/Galerie Echo 119

The artist behind the short-lived portal linking New York and Dublin: ‘People got carried away’

17 May 2024 at 03:00

Benediktas Gylys admits he was surprised by the rowdy behavior that came from the exhibit connecting people in the two cities

The artist behind the controversial “Portal” art exhibit that visually linked New York and Dublin in real time, but was then closed due to rowdy and extreme behavior by the public using it, has admitted he was surprised by the reaction.

Benediktas Gylys also vowed to continue with his project, which has the aim of connecting people and communities all over the world and is hoped to reopen soon.

Continue reading...

💾

© Photograph: Brendan McDermid/Reuters

💾

© Photograph: Brendan McDermid/Reuters

Before yesterdayMain stream

‘Realities of apartheid’: South African artist wins Deutsche Börse photography prize

Lebohang Kganye blends oral traditions, family photos and theatre in a ‘new and fresh way’ to trace personal history of apartheid era

The South African artist Lebohang Kganye has won the prestigious Deutsche Börse Photography Foundation prize for her work that uses large-scale cutouts and elements of set design to trace and depict her family history during the apartheid era.

The Johannesburg-based artist took home the £30,000 prize for her winning exhibition, which is on display at the Photographers’ Gallery in central London and is called Haufi nyana? I’ve come to take you home.

Continue reading...

💾

© Photograph: Lebohang Kganye

💾

© Photograph: Lebohang Kganye

Beryl Cook/Tom of Finland review – ‘One’s trying to make you laugh, the other’s trying to make you horny’

16 May 2024 at 12:52

Studio Voltaire, London
From Tom’s pert-bottomed hunks to Cook’s curvacious ladies, both artists wanted to give pleasure

‘Hate the politics, love the uniform,” would pretty much sum up Touko Valio Laaksonen’s attitude towards the Wehrmacht soldiers he encountered as a young, conscripted anti-aircraft officer in the Finnish army, fighting alongside the Germans in the second world war. After the war, Laaksonen began signing his commercial drawings for physique magazines with the moniker Tom of Finland, and the very different uniform of the sexual outlaw, inspired by American biker culture (and in particular by Marlon Brando in the 1953 movie The Wild One), replaced field grey with leather and denim, a hyper-masculine look that developed in gay culture from the 1950s onward.

Pert-bottomed and conspicuously well hung, six-packed and nipples erected, poured into their jeans and their leather trousers, Tom of Finland’s groups of hunks and Muscle Marys indulge in all sorts of horseplay. They suck, they rim, they fist, they fuck. They pose and they cruise, they watch and, given half a chance, they join in. There’s a bit of lighthearted BDSM, but not much else to vary the routine. What a tiring round their days must be. Away from the magazine page or beyond the edge of the drawing they might complain, if they had the time, about their onerous moisturising regimes, the daily workouts and depilation routines. Never mind the same old outfits every day, or that as soon as one scene has ended another’s begun. Even when they’re tied to a tree and being thrashed with a belt they seem happy enough, and no one ever screams their safe word.

Continue reading...

💾

© Photograph: © 1973 Tom of Finland Foundation

💾

© Photograph: © 1973 Tom of Finland Foundation

Leonora Carrington painting auctioned for £22.5m in record for UK-born female artist

Les Distractions de Dagobert was the surrealist’s ‘definitive masterpiece’, says Sotheby’s expert in New York

She was worshipped as a muse by renowned surrealists including André Breton and Max Ernst, but the Lancashire-born artist Leonora Carrington quickly shrugged off the label to achieve an unprecedented level of mastery and freedom in her own painting.

Now, on the 100th anniversary of Breton’s publication of the Surrealist Manifesto, Carrington has become the most valuable British-born female artist at auction after one of her paintings sold for more than £22.5m.

Continue reading...

💾

© Photograph: Sarah Yenesel/EPA

💾

© Photograph: Sarah Yenesel/EPA

How the world could have looked: the most spectacular buildings that were never made

16 May 2024 at 08:13

A mega egg in Paris, a hovering hotel in Machu Picchu, an hourglass tower in New York, a pleasure island in Baghdad … we reveal the architectural visions that were just too costly – or too weird

Did you know that, if things had gone differently, the Pompidou Centre could have been an egg? In the 1969 competition for the Paris art centre – ultimately won by Richard Rogers and Renzo Piano, with their inside-out symphony of pipework – a radical French architect called André Bruyère submitted a proposal for a gigantic ovoid tower. His bulbous building would have risen 100 metres above the city’s streets, clad in shimmering scales of alabaster, glass and concrete, its walls swelling out in a curvaceous riposte to the tyranny of the straight line.

“Time,” Bruyère declared, “instead of being linear, like the straight streets and vertical skyscrapers, will become oval, in tune with the egg.” His hallowed Oeuf would be held aloft on three chunky legs, while a monorail would pierce the facade and circle through the structure along a sinuous floating ribbon. The atrium was to take the form of an enclosed globe, like a yolk.

Continue reading...

💾

© Photograph: no credit

💾

© Photograph: no credit

‘An incredible phallic landmark!’ The grain silo gallery, a gift from the trillion dollar man

16 May 2024 at 03:00

Le Corbusier called grain silos ‘the magnificent first fruits of the new age’. But what can be done with these soaring industrial cathedrals when they’re redundant? A Norwegian tycoon has the answer

If you’ve ever wondered what it would feel like to be as insignificant as a kernel of corn, you can now get a good idea in Kristiansand, a city in southern Norway. Standing on the fourth floor of its new Kunstsilo art museum, carved out of an old 1930s grain silo, you can peer down a vertiginous concrete tube that plunges towards huddles of ant-like people below. Or you can look up, through more concrete shafts, towards tiny circles of sky. You can mimic the journey of a grain by climbing a spiral staircase inside one of the cylinders, or test your nerves by walking on a glass-floored terrace suspended over another shaft, floating above a tubular abyss. It’s a dramatic spatial spectacle – and we haven’t even got to the art yet.

Once home to 15,000 tonnes of grain, this mighty concrete mountain is now a repository of the most important collection of Nordic modern art in the world. It is a 5,500-strong haul spanning paintings, drawings, ceramics, sculpture and full-size architectural installations, telling the story of the past century of abstraction, surrealism and expressionism across Norway, Sweden, Finland and Denmark – inside one of the ultimate symbols of modernity itself.

Continue reading...

💾

© Photograph: Alan Williams

💾

© Photograph: Alan Williams

Redone, hidden, burnt: seven famous subjects and the portraits they hated

16 May 2024 at 02:14

Mining tycoon Gina Rinehart has asked the National Gallery of Australia to remove her portrait, painted by Vincent Namatjira. Others have gone much further

Vincent Namatjira’s portrait of Gina Rinehart has found no favour with the subject, with the mining tycoon asking the National Gallery of Australia to remove the painting from an exhibition. But Australia’s richest woman is not the first person to take a painting of their likeness to task.

Here we take a look at seven notable examples.

Continue reading...

💾

© Photograph: Lukas Coch/AAP

💾

© Photograph: Lukas Coch/AAP

Bowled over: Photo London x Nikon best emerging photographers – in pictures

16 May 2024 at 02:00

From an AI that ‘creates’ family photos to images printed on glass – and then broken – these artists nominated for this year’s prize use radical methods to achieve groundbreaking results

Continue reading...

💾

© Photograph: Aisha Seriki - Doyle Wham gallery

💾

© Photograph: Aisha Seriki - Doyle Wham gallery

Charles The Carpathian

15 May 2024 at 10:20
Buckingham Palace has revealed King Charles III's first official post-coronation portrait, and the work by artist Jonathan Yeo has proven to be...divisive in its design.

The portrait, awash in a red that melds with the subject's uniform, has raised a good deal of commentary/snark about the design, as well as the sort of media that it fits into or was taken from.

Jonathan Yeo’s portrait of Charles III review – a formulaic bit of facile flattery

15 May 2024 at 09:34

A psychedelic sea of lurid reds and a clunking monarch butterfly cannot save this superficially observed and carelessly executed bland banality

It’s hard to be objective about an artist you like as a person. I recently met the painter Jonathan Yeo – whose portrait of King Charles has been unveiled in a storm of crimson hype – on a radio show and was instantly charmed. It’s easy to see why famous people enjoy being portrayed by Yeo. He’s intelligent, relaxed, unassuming. We talked about a studio visit. But then I had a look at his works online and cringed. And that was before I saw this right royal banality.

Yeo’s portrait of the king is replete with all his vices. It is technically superficial and unfelt. There’s no insight into the king’s personality here, just a weird allegory about a monarch butterfly that Yeo says is a symbol of his metamorphosis from prince to king.

Continue reading...

💾

© Photograph: Jonathan Yeo/AP

💾

© Photograph: Jonathan Yeo/AP

Steve McQueen: Bass review – ‘Like an underground shooting gallery of dub’

15 May 2024 at 08:32

Dia Beacon, New York State
Defying narrative, the artist mixes LED lights and colour with ricocheting music inspired by West Africa, resulting in a throbbing show that sucks the air from your lungs

There are neither images nor narrative in Steve McQueen’s newest work, Bass, at the Dia Art Foundation at Beacon, about an hour up the Hudson valley from New York. Nothing but three stacks of speakers standing in the low-lit gloom of a concrete basement, and a grid of 60 flat LED light boxes sitting flush with the ceiling, measuring out the space between the rows of pillars and providing the only illumination in the large, echoing space. The light boxes glow red then tangerine, through yellows and green, blues and magenta and back to red, slowly drifting round the spectrum like a dial being turned.

Along with the light, sounds hang in the air. Sometimes the reverb goes right through you, then it’s a ghost. Slick with dulled reflections, the concrete floor is scored with old cracks and worn-away markings. The throb of bass notes ricochet from the walls and pillars, an underground shooting gallery of dub. Aching and surging, tailing off and picking up again, the music creates a space in which riffs and licks come and go are lost in reverb and harmonics, like snatches of language being dragged out of nowhere. Notes pulse like a human heart or a rudder in a current. Enormous tonal weights slide like so much unmoored ballast, blues phrases shimmer in complaint and there’s a constant sense of the impending. At one point a low hollow sound tunnels through the air like disaster looming.

Continue reading...

💾

© Photograph: © Steve McQueen. Photo: Bill Jacobson Studio, New York. Courtesy Dia Art Foundation

💾

© Photograph: © Steve McQueen. Photo: Bill Jacobson Studio, New York. Courtesy Dia Art Foundation

Time traveller: one Senegalese man’s journey to the past – in pictures

15 May 2024 at 02:00

Whether it’s in segregated America or the glory days of postwar France, Omar Victor Diop appears in photographs of worlds he was previously shut out from

Continue reading...

💾

© Photograph: Omar Victor Diop & Lee Shulman

💾

© Photograph: Omar Victor Diop & Lee Shulman

See things differently: the best of Photo London – in pictures

14 May 2024 at 02:00

From naked bathing to restaged expeditions, drunks, drag, poets and horses, these fantastic images light up this year’s photography extravaganza

Continue reading...

💾

© Photograph: Gyldenpris Kunsthall, Bergen, Norway/Tonje Bøe Birkeland

💾

© Photograph: Gyldenpris Kunsthall, Bergen, Norway/Tonje Bøe Birkeland

public domain [book cover] atrocities

12 May 2024 at 16:12
[B]ooks in the public domain—books anyone with a digital file, a printer, and a dream can produce and sell—can be a sweet side hustle for people looking to make a quick buck, and they are free to make their own choices when it comes to the cover art they select, but this one cracked me up because it is not even close to representing the contents or the tone of the book. I decided to do a deep dive into the world of public domain publishing, to see what else was out there... (Karen T. Brissette) Bonus: 50 Very Bad Book Covers for Literary Classics (LitHub)

Cascading Style

By: Rhaomi
12 May 2024 at 15:35
CSS (Cascading Style Sheets) is a ubiquitous markup language for describing the layout and design of a webpage separate from the content, typically specifying things like text formatting, background color, page alignment, etc. But as with emoticons and ASCII art before it, CSS can be repurposed to become the content. Enter CSS drawing, an intricate art form that uses the conventions of the language to create illustrations and even animation using only standard design elements. Some standout examples from around the web: A Single Div, where every new illustration is contained within one <div> tag; designer Lynn Fisher also has a previous version along with a whole catalog of "weird websites, niche data projects, and CSS experiments" - Another collection of single-div projects - Start a digital bonfire - The Simpsons (animated!) in CSS - 173 CSS drawings on Dribble - How I started drawing CSS Images - css-doodle, a web component for drawing patterns with CSS - Creating Realistic Art with CSS - The CSS Zen Garden, a collection of beautiful CSS stylesheets - CSS previously on MeFi

The big picture: Huck Finn in 1970s New Jersey

By: Tim Adams
12 May 2024 at 02:00

Pioneering Black photographer Ming Smith captures four boys creating rafts from rubbish in New Jersey

Ming Smith photographed the four boys on their backdoor rafts on a pond in Hoboken, New Jersey, in 1972. She called the unlikely urban Huck Finn scene Setting Out to Sea, since that’s where one or two of the friends seemed to be aiming for, at least in their heads.

Smith was developing big plans of her own at that time. Detroit-born and raised in Columbus, Ohio, she had arrived in New York a year earlier after graduating from Howard University. Her first published pictures appeared in the inaugural, renowned Black Photographers Annual in 1973. The annual, with an introduction by Toni Morrison, featured the work of artists from the Kamoinge Workshop in Harlem, which was a prime mover in the Black Arts movement. Smith had become the first female member of that group. Her biography in the annual read: “New York amateur photographer Ming Smith has been taking pictures for less than a year. She is a self-taught photographer, who was first influenced by her father. ‘My photographs,’ she says, ‘attempt to open the passageway to my understanding of myself.’”

Ming Smith: On the Road is at the Nicola Vassell gallery, New York, until 15 June

Continue reading...

💾

© Photograph: © Ming Smith, Courtesy of Nicola Vassell Gallery, New York

💾

© Photograph: © Ming Smith, Courtesy of Nicola Vassell Gallery, New York

Dropbox Sign customer data accessed in breach

2 May 2024 at 16:44

Dropbox is reporting a recent “security incident” in which an attacker gained unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. During this access, the attacker had access to Dropbox Sign customer information.

Dropbox Sign is a platform that allows customers to digitally sign, edit, and track documents. The accessed customer information includes email addresses, usernames, phone numbers, and hashed passwords, in addition to general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication. The access is limited to Dropbox Sign customers and does not affect users of other Dropbox services because the environments are largely separate.

“We believe that this incident was isolated to Dropbox Sign infrastructure and did not impact any other Dropbox products.”

Even if you never created a Dropbox Sign account but received or signed a document through Dropbox Sign, your email addresses and names were exposed. In a government (K-8) filing about the incident, Dropbox says it found no evidence of unauthorized access to the contents of customers’ accounts (i.e. their documents or agreements), or their payment information. 

The attacker compromised a back-end service account that acted as an automated system configuration tool for the Dropbox Sign environment. The attacker used the privileges of the service account for the production environment to gain access to the customer database.

To limit the aftermath of the incident, Dropbox’s security team reset users’ passwords, logged users out of any devices they had connected to Dropbox Sign, and is coordinating the rotation of all API keys and OAuth tokens.

For customers with API access to Dropbox Sign, the company said new API keys will need to be generated and warned that certain functionality will be restricted while they deal with the breach.

Dropbox says it has reported this event to data protection regulators and law enforcement.

Recommendations

Dropbox expired affected passwords and logged users out of any devices they had connected to Dropbox Sign for further protection. The next time these users log in to their Sign account, they’ll be sent an email to reset the password. Dropbox recommends users do this as soon as possible.

If you’re an API customer, to ensure the security of your account, you’ll need to rotate your API key by generating a new one, configuring it with your application, and deleting your current one. Here is how you can easily create a new key.

API customers should be aware that names and email addresses for those who received or signed a document through Dropbox Sign, even if they never created an account, were exposed. So, this may impact their customers.

Customers who use an authenticator app for multi-factor authentication should reset it. Please delete your existing entry and then reset it. If you use SMS you do not need to take any action.

If you reused your Dropbox Sign password on any other services, we strongly recommend that you change your password on those accounts and use multi-factor authentication when available.

Protecting yourself from a data breach

There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.

  • Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened and follow any specific advice they offer.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of two-factor authentication (2FA) can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for fake vendors. The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims and verify any contacts using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online, and helps you recover after.

Check your digital footprint

Malwarebytes has a new free tool for you to check how much of your personal data has been exposed online. Submit your email address (it’s best to give the one you most frequently use) to our free Digital Footprint scan and we’ll give you a report and recommendations.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection

Dropbox Reports Breach of Sensitive Authentication Data for its Sign Product

Dropbox data breach

Cloud storage and file sharing company Dropbox disclosed a security breach that resulted in an unauthorized access to sensitive information, including passwords and other authentication information. Dropbox revealed that the breach targeted its production environment, specifically impacting Dropbox Sign, formerly known as HelloSign, a platform for digitally signing documents, in an 8-K filing with the U.S. Securities and Exchange Commission.
"The actor compromised a service account that was part of Sign’s back-end, which is a type of non-human account used to execute applications and run automated services. As such, this account had privileges to take a variety of actions within Sign’s production environment. The threat actor then used this access to the production environment to access our customer database.
The accessed information pertains to all Dropbox Sign users, encompassing account settings, names and emails. For some users, additional data such as phone numbers, hashed passwords and authentication information like API keys, OAuth tokens and multi-factor authentication were also compromised.
"From a technical perspective, Dropbox Sign’s infrastructure is largely separate from other Dropbox services. That said, we thoroughly investigated this risk and believe that this incident was isolated to Dropbox Sign infrastructure, and did not impact any other Dropbox products."
While forensic investigators are engaged and law enforcement notified, regulatory agencies are being informed based on the presumption of personal information access. Dropbox has initiated steps to mitigate the impact of the breach, including rotation of OAuth tokens and generating new API keys for customers with API access to Dropbox Sign. Certain functionalities will remain restricted until API keys are rotated, Dropbox said. User notifications are underway, with Dropbox reaching out to affected users and providing guidance on necessary actions. The company expects all notifications to be completed within the next week. Although Dropbox does not anticipate a significant impact on its operations or financial condition, it acknowledges potential risks, including litigation, changes in customer behavior and heightened regulatory scrutiny. This Dropbox data breach incident marks another security challenge for the file sharing giant, following a phishing campaign in 2022 that targeted its developers, resulting in unauthorized access to company GitHub accounts and sensitive information. Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

April’s Patch Tuesday Brings Record Number of Fixes

9 April 2024 at 16:28

If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.

Yes, you read that right. Microsoft today released updates to address 147 security holes in Windows, Office, Azure, .NET Framework, Visual Studio, SQL Server, DNS Server, Windows Defender, Bitlocker, and Windows Secure Boot.

“This is the largest release from Microsoft this year and the largest since at least 2017,” said Dustin Childs, from Trend Micro’s Zero Day Initiative (ZDI). “As far as I can tell, it’s the largest Patch Tuesday release from Microsoft of all time.”

Tempering the sheer volume of this month’s patches is the middling severity of many of the bugs. Only three of April’s vulnerabilities earned Microsoft’s most-dire “critical” rating, meaning they can be abused by malware or malcontents to take remote control over unpatched systems with no help from users.

Most of the flaws that Microsoft deems “more likely to be exploited” this month are marked as “important,” which usually involve bugs that require a bit more user interaction (social engineering) but which nevertheless can result in system security bypass, compromise, and the theft of critical assets.

Ben McCarthy, lead cyber security engineer at Immersive Labs called attention to CVE-2024-20670, an Outlook for Windows spoofing vulnerability described as being easy to exploit. It involves convincing a user to click on a malicious link in an email, which can then steal the user’s password hash and authenticate as the user in another Microsoft service.

Another interesting bug McCarthy pointed to is CVE-2024-29063, which involves hard-coded credentials in Azure’s search backend infrastructure that could be gleaned by taking advantage of Azure AI search.

“This along with many other AI attacks in recent news shows a potential new attack surface that we are just learning how to mitigate against,” McCarthy said. “Microsoft has updated their backend and notified any customers who have been affected by the credential leakage.”

CVE-2024-29988 is a weakness that allows attackers to bypass Windows SmartScreen, a technology Microsoft designed to provide additional protections for end users against phishing and malware attacks. Childs said one of ZDI’s researchers found this vulnerability being exploited in the wild, although Microsoft doesn’t currently list CVE-2024-29988 as being exploited.

“I would treat this as in the wild until Microsoft clarifies,” Childs said. “The bug itself acts much like CVE-2024-21412 – a [zero-day threat from February] that bypassed the Mark of the Web feature and allows malware to execute on a target system. Threat actors are sending exploits in a zipped file to evade EDR/NDR detection and then using this bug (and others) to bypass Mark of the Web.”

Update, 7:46 p.m. ET: A previous version of this story said there were no zero-day vulnerabilities fixed this month. BleepingComputer reports that Microsoft has since confirmed that there are actually two zero-days. One is the flaw Childs just mentioned (CVE-2024-21412), and the other is CVE-2024-26234, described as a “proxy driver spoofing” weakness.

Satnam Narang at Tenable notes that this month’s release includes fixes for two dozen flaws in Windows Secure Boot, the majority of which are considered “Exploitation Less Likely” according to Microsoft.

“However, the last time Microsoft patched a flaw in Windows Secure Boot in May 2023 had a notable impact as it was exploited in the wild and linked to the BlackLotus UEFI bootkit, which was sold on dark web forums for $5,000,” Narang said. “BlackLotus can bypass functionality called secure boot, which is designed to block malware from being able to load when booting up. While none of these Secure Boot vulnerabilities addressed this month were exploited in the wild, they serve as a reminder that flaws in Secure Boot persist, and we could see more malicious activity related to Secure Boot in the future.”

For links to individual security advisories indexed by severity, check out ZDI’s blog and the Patch Tuesday post from the SANS Internet Storm Center. Please consider backing up your data or your drive before updating, and drop a note in the comments here if you experience any issues applying these fixes.

Adobe today released nine patches tackling at least two dozen vulnerabilities in a range of software products, including Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate.

KrebsOnSecurity needs to correct the record on a point mentioned at the end of March’s “Fat Patch Tuesday” post, which looked at new AI capabilities built into Adobe Acrobat that are turned on by default. Adobe has since clarified that its apps won’t use AI to auto-scan your documents, as the original language in its FAQ suggested.

“In practice, no document scanning or analysis occurs unless a user actively engages with the AI features by agreeing to the terms, opening a document, and selecting the AI Assistant or generative summary buttons for that specific document,” Adobe said earlier this month.

The Not-so-True People-Search Network from China

20 March 2024 at 23:18

It’s not unusual for the data brokers behind people-search websites to use pseudonyms in their day-to-day lives (you would, too). Some of these personal data purveyors even try to reinvent their online identities in a bid to hide their conflicts of interest. But it’s not every day you run across a US-focused people-search network based in China whose principal owners all appear to be completely fabricated identities.

Responding to a reader inquiry concerning the trustworthiness of a site called TruePeopleSearch[.]net, KrebsOnSecurity began poking around. The site offers to sell reports containing photos, police records, background checks, civil judgments, contact information “and much more!” According to LinkedIn and numerous profiles on websites that accept paid article submissions, the founder of TruePeopleSearch is Marilyn Gaskell from Phoenix, Ariz.

The saucy yet studious LinkedIn profile for Marilyn Gaskell.

Ms. Gaskell has been quoted in multiple “articles” about random subjects, such as this article at HRDailyAdvisor about the pros and cons of joining a company-led fantasy football team.

“Marilyn Gaskell, founder of TruePeopleSearch, agrees that not everyone in the office is likely to be a football fan and might feel intimidated by joining a company league or left out if they don’t join; however, her company looked for ways to make the activity more inclusive,” this paid story notes.

Also quoted in this article is Sally Stevens, who is cited as HR Manager at FastPeopleSearch[.]io.

Sally Stevens, the phantom HR Manager for FastPeopleSearch.

“Fantasy football provides one way for employees to set aside work matters for some time and have fun,” Stevens contributed. “Employees can set a special league for themselves and regularly check and compare their scores against one another.”

Imagine that: Two different people-search companies mentioned in the same story about fantasy football. What are the odds?

Both TruePeopleSearch and FastPeopleSearch allow users to search for reports by first and last name, but proceeding to order a report prompts the visitor to purchase the file from one of several established people-finder services, including BeenVerified, Intelius, and Spokeo.

DomainTools.com shows that both TruePeopleSearch and FastPeopleSearch appeared around 2020 and were registered through Alibaba Cloud, in Beijing, China. No other information is available about these domains in their registration records, although both domains appear to use email servers based in China.

Sally Stevens’ LinkedIn profile photo is identical to a stock image titled “beautiful girl” from Adobe.com. Ms. Stevens is also quoted in a paid blog post at ecogreenequipment.com, as is Alina Clark, co-founder and marketing director of CocoDoc, an online service for editing and managing PDF documents.

The profile photo for Alina Clark is a stock photo appearing on more than 100 websites.

Scouring multiple image search sites reveals Ms. Clark’s profile photo on LinkedIn is another stock image that is currently on more than 100 different websites, including Adobe.com. Cocodoc[.]com was registered in June 2020 via Alibaba Cloud Beijing in China.

The same Alina Clark and photo materialized in a paid article at the website Ceoblognation, which in 2021 included her at #11 in a piece called “30 Entrepreneurs Describe The Big Hairy Audacious Goals (BHAGs) for Their Business.” It’s also worth noting that Ms. Clark is currently listed as a “former Forbes Council member” at the media outlet Forbes.com.

Entrepreneur #6 is Stephen Curry, who is quoted as CEO of CocoSign[.]com, a website that claims to offer an “easier, quicker, safer eSignature solution for small and medium-sized businesses.” Incidentally, the same photo for Stephen Curry #6 is also used in this “article” for #22 Jake Smith, who is named as the owner of a different company.

Stephen Curry, aka Jake Smith, aka no such person.

Mr. Curry’s LinkedIn profile shows a young man seated at a table in front of a laptop, but an online image search shows this is another stock photo. Cocosign[.]com was registered in June 2020 via Alibaba Cloud Beijing. No ownership details are available in the domain registration records.

Listed at #13 in that 30 Entrepreneurs article is Eden Cheng, who is cited as co-founder of PeopleFinderFree[.]com. KrebsOnSecurity could not find a LinkedIn profile for Ms. Cheng, but a search on her profile image from that Entrepreneurs article shows the same photo for sale at Shutterstock and other stock photo sites.

DomainTools says PeopleFinderFree was registered through Alibaba Cloud, Beijing. Attempts to purchase reports through PeopleFinderFree produce a notice saying the full report is only available via Spokeo.com.

Lynda Fairly is Entrepreneur #24, and she is quoted as co-founder of Numlooker[.]com, a domain registered in April 2021 through Alibaba in China. Searches for people on Numlooker forward visitors to Spokeo.

The photo next to Ms. Fairly’s quote in Entrepreneurs matches that of a LinkedIn profile for Lynda Fairly. But a search on that photo shows this same portrait has been used by many other identities and names, including a woman from the United Kingdom who’s a cancer survivor and mother of five; a licensed marriage and family therapist in Canada; a software security engineer at Quora; a journalist on Twitter/X; and a marketing expert in Canada.

Cocofinder[.]com is a people-search service that launched in Sept. 2019, through Alibaba in China. Cocofinder lists its market officer as Harriet Chan, but Ms. Chan’s LinkedIn profile is just as sparse on work history as the other people-search owners mentioned already. An image search online shows that outside of LinkedIn, the profile photo for Ms. Chan has only ever appeared in articles at pay-to-play media sites, like this one from outbackteambuilding.com.

Perhaps because Cocodoc and Cocosign both sell software services, they are actually tied to a physical presence in the real world — in Singapore (15 Scotts Rd. #03-12 15, Singapore). But it’s difficult to discern much from this address alone.

Who’s behind all this people-search chicanery? A January 2024 review of various people-search services at the website techjury.com states that Cocofinder is a wholly-owned subsidiary of a Chinese company called Shenzhen Duiyun Technology Co.

“Though it only finds results from the United States, users can choose between four main search methods,” Techjury explains. Those include people search, phone, address and email lookup. This claim is supported by a Reddit post from three years ago, wherein the Reddit user “ProtectionAdvanced” named the same Chinese company.

Is Shenzhen Duiyun Technology Co. responsible for all these phony profiles? How many more fake companies and profiles are connected to this scheme? KrebsOnSecurity found other examples that didn’t appear directly tied to other fake executives listed here, but which nevertheless are registered through Alibaba and seek to drive traffic to Spokeo and other data brokers. For example, there’s the winsome Daniela Sawyer, founder of FindPeopleFast[.]net, whose profile is flogged in paid stories at entrepreneur.org.

Google currently turns up nothing else for in a search for Shenzhen Duiyun Technology Co. Please feel free to sound off in the comments if you have any more information about this entity, such as how to contact it. Or reach out directly at krebsonsecurity @ gmail.com.

A mind map highlighting the key points of research in this story. Click to enlarge. Image: KrebsOnSecurity.com

ANALYSIS

It appears the purpose of this network is to conceal the location of people in China who are seeking to generate affiliate commissions when someone visits one of their sites and purchases a people-search report at Spokeo, for example. And it is clear that Spokeo and others have created incentives wherein anyone can effectively white-label their reports, and thereby make money brokering access to peoples’ personal information.

Spokeo’s Wikipedia page says the company was founded in 2006 by four graduates from Stanford University. Spokeo co-founder and current CEO Harrison Tang has not yet responded to requests for comment.

Intelius is owned by San Diego based PeopleConnect Inc., which also owns Classmates.com, USSearch, TruthFinder and Instant Checkmate. PeopleConnect Inc. in turn is owned by H.I.G. Capital, a $60 billion private equity firm. Requests for comment were sent to H.I.G. Capital. This story will be updated if they respond.

BeenVerified is owned by a New York City based holding company called The Lifetime Value Co., a marketing and advertising firm whose brands include PeopleLooker, NeighborWho, Ownerly, PeopleSmart, NumberGuru, and Bumper, a car history site.

Ross Cohen, chief operating officer at The Lifetime Value Co., said it’s likely the network of suspicious people-finder sites was set up by an affiliate. Cohen said Lifetime Value would investigate to determine if this particular affiliate was driving them any sign-ups.

All of the above people-search services operate similarly. When you find the person you’re looking for, you are put through a lengthy (often 10-20 minute) series of splash screens that require you to agree that these reports won’t be used for employment screening or in evaluating new tenant applications. Still more prompts ask if you are okay with seeing “potentially shocking” details about the subject of the report, including arrest histories and photos.

Only at the end of this process does the site disclose that viewing the report in question requires signing up for a monthly subscription, which is typically priced around $35. Exactly how and from where these major people-search websites are getting their consumer data — and customers — will be the subject of further reporting here.

The main reason these various people-search sites require you to affirm that you won’t use their reports for hiring or vetting potential tenants is that selling reports for those purposes would classify these firms as consumer reporting agencies (CRAs) and expose them to regulations under the Fair Credit Reporting Act (FCRA).

These data brokers do not want to be treated as CRAs, and for this reason their people search reports typically don’t include detailed credit histories, financial information, or full Social Security Numbers (Radaris reports include the first six digits of one’s SSN).

But in September 2023, the U.S. Federal Trade Commission found that TruthFinder and Instant Checkmate were trying to have it both ways. The FTC levied a $5.8 million penalty against the companies for allegedly acting as CRAs because they assembled and compiled information on consumers into background reports that were marketed and sold for employment and tenant screening purposes.

The FTC also found TruthFinder and Instant Checkmate deceived users about background report accuracy. The FTC alleges these companies made millions from their monthly subscriptions using push notifications and marketing emails that claimed that the subject of a background report had a criminal or arrest record, when the record was merely a traffic ticket.

The FTC said both companies deceived customers by providing “Remove” and “Flag as Inaccurate” buttons that did not work as advertised. Rather, the “Remove” button removed the disputed information only from the report as displayed to that customer; however, the same item of information remained visible to other customers who searched for the same person.

The FTC also said that when a customer flagged an item in the background report as inaccurate, the companies never took any steps to investigate those claims, to modify the reports, or to flag to other customers that the information had been disputed.

There are a growing number of online reputation management companies that offer to help customers remove their personal information from people-search sites and data broker databases. There are, no doubt, plenty of honest and well-meaning companies operating in this space, but it has been my experience that a great many people involved in that industry have a background in marketing or advertising — not privacy.

Also, some so-called data privacy companies may be wolves in sheep’s clothing. On March 14, KrebsOnSecurity published an abundance of evidence indicating that the CEO and founder of the data privacy company OneRep.com was responsible for launching dozens of people-search services over the years.

Finally, some of the more popular people-search websites are notorious for ignoring requests from consumers seeking to remove their information, regardless of which reputation or removal service you use. Some force you to create an account and provide more information before you can remove your data. Even then, the information you worked hard to remove may simply reappear a few months later.

This aptly describes countless complaints lodged against the data broker and people search giant Radaris. On March 8, KrebsOnSecurity profiled the co-founders of Radaris, two Russian brothers in Massachusetts who also operate multiple Russian-language dating services and affiliate programs.

The truth is that these people-search companies will continue to thrive unless and until Congress begins to realize it’s time for some consumer privacy and data protection laws that are relevant to life in the 21st century. Duke University adjunct professor Justin Sherman says virtually all state privacy laws exempt records that might be considered “public” or “government” documents, including voting registries, property filings, marriage certificates, motor vehicle records, criminal records, court documents, death records, professional licenses, bankruptcy filings, and more.

“Consumer privacy laws in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia all contain highly similar or completely identical carve-outs for ‘publicly available information’ or government records,” Sherman said.

❌
❌