PrivacySignal
Breach

Cellebrite said it cut off Russia, but Russia used its tools anyway

TechCrunch — Privacy · · International · Data Breaches

Security researchers found evidence that Russian authorities used a Cellebrite phone-unlocking device to access a political opponent's iPhone, despite Cellebrite's stated policy of cutting off sales to Russia following its invasion of Ukraine. The findings suggest the tools reached Russian law enforcement through channels the company either did not control or did not stop.

Why this matters: Cellebrite sells powerful tools that can crack into locked phones. When it announced it was cutting off Russia, that was supposed to mean something. It apparently did not. Whether the device was resold, stockpiled, or routed through a third party, the result is the same: a tool marketed to democracies ended up targeting a political dissident in an authoritarian state. This is the core problem with selling surveillance technology. Once it leaves your hands, you do not control it. Cellebrite now needs to explain not just what its policy says, but how it actually enforces one.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
HIPAA Journal · · US Federal

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners have issued a joint advisory warning healthcare organizations about Gunra, a ransomware-as-a-service operation actively targeting the sector.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
BleepingComputer · · International

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla has replaced the GPG key used to cryptographically sign Firefox and Thunderbird releases after the key was accidentally exposed in a public GitHub repository. The update is intended to ensure users can continue to verify that software releases are authentic and untampered.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach Critical
BleepingComputer · · International

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

US and South Korea warn of Gunra ransomware targeting govt agencies

U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →