// Field Knowledge & Guides

Digital Security Guides & Tutorials

Practical guides for journalists and frontline activists on hardening phones, securing accounts, and countering hacking and inspection attempts.

Security Alerts ⏱️ 1 min read

Critical Vulnerability in WinRAR Software on Windows Systems

A severe security vulnerability has been exposed in WinRAR file compression software, on Windows operating systems, that allows hackers to perform “remote attacks” on victims’ machines. The vulnerability has been tracked and registered as CVE-2023-40477, and it requires users to interact by visiting malicious websites, or opening a booby-trapped zip file. We recommend users to update […]

Security Alerts ⏱️ 1 min read

Apple releases an emergency update for its OSs

Apple has issued an emergency security update to fill critical vulnerabilities that are already widespread and exploited by hackers. The vulnerability is of the “zero-day” type, which means that it is a vulnerability that is not known by the developers until the time it is corrected, and this vulnerability affects the operating systems IOS, iPadOS, […]

Security Alerts ⏱️ 1 min read

Firefox stops supporting discontinued OSs

Mozilla has announced the release of Firefox 115, and this update includes a set of new improvements and changes, but one of the most important things it focuses on is stopping support for discontinued versions of Windows and Mac Operating systems. According to the official announcement, Firefox 115 is the last version that supports Windows […]

Security Alerts ⏱️ 2 min read

Hackers Claim to Have Breached 30 Million Microsoft Customer Accounts

The hacking group “Anonymous Sudan” claimed to have breached Microsoft’s servers and leaked login credentials of 30 million customers. The group “Anonymous Sudan” has gained notoriety for carrying out distributed denial-of-service (DDoS) attacks against Western entities in recent months. Last month, Microsoft confirmed that the group “Anonymous Sudan” was responsible for the DDoS attacks it […]

Security Alerts ⏱️ 2 min read

Proton.me is blocked in Egypt

Egyptian “telecom companies” blocked proton.me domain, which belongs to the famous encrypted e-mail service. we recommend using a VPN to connect to their services. In this case, you can use the ProtonVPN service, making sure that the connection is activated via the Stealth protocol. As of June 4, we had received, via our helpline, complaints […]

Security Alerts ⏱️ 1 min read

Google fixes new Chrome zero-day vulnerability

Google issued an update to correct a security vulnerability in its #Chrome browser, which is a “zero-day” vulnerability, which means that it is a vulnerability unknown to browser developers until the time it was discovered and corrected, and it was registered as CVE-2023-3079, and this is the third time that Google has discovered a vulnerability […]

Security Alerts ⏱️ 2 min read

Difficulty accessing Proton services from inside Egypt

Users inside Egypt are having difficulty accessing Proton services, since yesterday evening, Sunday, June 4, 2023, through its websites and applications on smartphones. We have conducted several tests indicating that Proton services may be blocked inside Egypt, noting that the services work entirely outside Egypt and by connecting to VPN services from inside Egypt, and […]

News ⏱️ 2 min read

Kaspersky reveals the hacking of its employees’ phones

Kaspersky has accused hackers working for an unnamed “government” of carrying out attacks on its employees’ iPhones, through a security vulnerability in the iMessage program, which is a zero-click vulnerability, and this type of vulnerability allows the attacker to carry out the attack and hack devices without any interaction. From the user, that is, without […]

Security Alerts ⏱️ 2 min read

Microsoft finds macOS vulnerability

A security team from Microsoft revealed a security vulnerability in Apple’s MacOS operating systems, allowing attackers with root privileges to install “non-deletable” malware and access victim data by circumventing transparency, approval and control checks (TCC). And by bypassing the system (SIP). The gap was tracked under the heading CVE-2023-32369, and Apple fixed the vulnerability in […]

Security Alerts ⏱️ 1 min read

Apps with spyware on Play Store Installed Over 421 Million Times

Dr. Web, a cybersecurity company, has revealed over 100 applications on the Google Play Store for Android devices that utilize spyware called “SpinOk” to steal user data. According to the malware-fighting company, these applications disguise themselves as small games or task systems that offer rewards and bonuses to users. While appearing as innocent games, these […]