#Weekly Roundup: Fowler Town, St. Ann gets Community Wi-Fi

On Friday, October 24, 2024, an exciting new chapter in connectivity began as the Universal Service Fund (USF) officially launched one of its Community Wi-Fi sites in the vibrant town of Fowler, St. Ann. This initiative aims to transform the community by bridging the digital divide and fostering greater connectivity for all residents.

The launch event was a festive celebration, featuring a captivating performance by the talented students of Prickley Pole Primary, who moved the audience with their heartfelt rendition of “You Raise Me Up.” The air was filled with joy and anticipation as community members gathered to witness this momentous occasion.

In a powerful demonstration of commitment to education and digital equity, tablet devices were presented to Member of Parliament Lisa Hanna during the event, as part of the USF’s impactful Connect a Child Programme. This initiative highlights the Fund’s dedication to enhancing digital literacy and providing technology access to children in the region, ensuring they have the tools they need to succeed in an increasingly digital world.

With the launch of the Community Wi-Fi site, Fowler Town is set to become a hub of connectivity, empowering its residents to engage more fully with the world around them. This event marks a significant step towards building a more connected and informed community, where everyone has the opportunity to thrive in the digital age.

#Weekly Round Up: Brown’s Town, Orange Hill are supercharging their connection with USF’s Wi-Fi initiatives

On Friday, October 11, 2024, the Universal Service Fund (USF) lit up Brown’s Town, St. Ann, with the launch of our Connect Ja Public Wi-Fi site in Brown’s Town, St. Ann, aiming to increase community connectivity.

Despite a sudden downpour that briefly paused the event, the atmosphere was revitalized by a lively performance from the Waterhouse Marching Band, captivating the audience and highlighting the community’s vibrant spirit, along with talented student musicians from York Castle High School.

Earlier, the Fund had already made strides in the area by establishing Community Wi-Fi sites in Thicketts, Mount Zion, Bamboo, and Brown’s Town. Now, the Brown’s Town site has been upgraded to a Public Wi-Fi location under our Connect Ja initiative, aimed at providing free Wi-Fi in parks and town centers across the country.

Additionally, during the event, tablet devices were distributed to MP Krystal Lee and MP Zavia Mayne of St. Ann South Western as part of our Connect a Child Programme. This initiative underscores the Fund’s commitment to enhancing digital literacy and technology access in the region.

Earlier that day, we unveiled a Community Wi-Fi site in Orange Hill, Brown’s Town, which was warmly embraced by residents and local stakeholders.

Privacy & Security News

privacy security news

“Sansec is publishing early because stores are being compromised right now,” the company said. Sansec, which discovered the flaw and named it StyleSmuggler , said attacks started on September 4. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes. JSCeal was first documented by Check Point in July 2025, highlighting the threat actors’ use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google. The company’s own communications disagree on whether the flaw has already been exploited. Progress Software patched the flaws in July, and exploitation requires a non-default configuration — but the release pairs a detailed write-up with a ready-to-run tool and two payloads, putting a complete attack path in public hands for the first time.

Sansec said all current versions are affected, including 2.4.9, and that it reproduced the full unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9. A successful attack gives the attacker code execution on the store’s server and installs a persistent backdoor. As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update.

  • Privacy Daily provides accurate coverage of newsworthy developments in data protection legislation, regulation, litigation, and enforcement for privacy professionals responsible for ensuring effective organizational data privacy compliance.
  • Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns.
  • Warren News is the leading regulatory intelligence news service for trade, telecom and privacy professionals.
  • CoSnitch is a one-click vulnerability discovered by researchers at Varonis Threat Labs and co-discovered by Copilot itself, that allows an attacker to exfiltrate sensitive data using Copilot’s access to your computer.
  • N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication.

It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions… Securities and Exchange Commission on September 2, 2026, the California-based company said it settled the suit related to historical data practices before 2020, when it was managed by Kunlun. Warren News is the leading regulatory intelligence news service for trade, telecom and privacy professionals.

NASA Ground Control Software Flaw Enables Unauthenticated Commands

Privacy Daily provides accurate coverage of newsworthy developments in data protection legislation, regulation, litigation, and enforcement for privacy professionals responsible for ensuring effective organizational data privacy compliance. In an interview last week, Crawford also raised concerns about the scope of New Jersey’s new data broker law. Efforts to limit pricing based on consumers’ personal data aren’t going away, despite the failure of a California bill (AB-2564) to combat the practice that critics call “surveillance pricing,” the legislation’s author and consumer privacy advocates who supported the measure said this week. Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight. The company will give select partners early access to its Astra AI model—so they have time to shore up their defenses.

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

The details of the three attacks are below – A social engineering attack that persuaded a user into executing Quick Assist as part of a tech support scam, after which a rogue ScreenConnect remote access client was d… However, once the ScreenConnect instances were installed, the cybersecurity company said it observed the clients repeatedly spawning “wscript.exe” to execute VBScripts named 1.vbs, 2.vbs, 3.vbs, and 4.vbs. If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login.

Android Car Head Units Are Getting Hacked Through Their Built-In Updates

From AI-generated images to restricted satellite data, the systems used to verify what’s real online are struggling to keep up. Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns. Alpharetta, Georgia, cops share data with thousands of Flock users, ranging from federal agencies to a fish and wildlife commission.

The company named the four programs ProManager , WinUpdate , SoftManager , and LockAppHost and published the findings on September 2 , along with a technical white paper . Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning , published on September 5. Security firm TantoSec has published a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. The Chinese gaming company sold the online platform to an investor group called San Vicente Acquisition LLC in May 2020.

  • Sansec, which discovered the flaw and named it StyleSmuggler , said attacks started on September 4.
  • “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.” The exposure is in addition to 13,689 customers the company disclosed last month as having had their data either fully or partially exposed.
  • Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning , published on September 5.
  • Alpharetta, Georgia, cops share data with thousands of Flock users, ranging from federal agencies to a fish and wildlife commission.

OpenAI Agents Hacked Another Website

FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition Microsoft says they’ll soon stop sending SMS codes for authentication for personal Microsoft accounts and will transition to “passwordless accounts, passkeys, and verified email.”

privacy security news

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

privacy security news

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. Attackers https://synapsewaves.com/articles/phd-cryptography-programs-guide/ are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5 . N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication. Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.

“The payloads are protected with javascript-obfuscator , using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a technical report published last week. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. This week saw data breaches from more hospitals, a toy company, an age verification service, an update to a French breach from last year, and more. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in https://www.motonlegalgroup.com/tech-law/ their systems.” The exposure is in addition to 13,689 customers the company disclosed last month as having had their data either fully or partially exposed. The breach does not affect the security of the company’s hardware wallets. “Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,” JetBrains said .

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

Researchers at VulnCheck found multiple backdoors in routers from Chinese manufacturer Zbtlink allowing a remote server root access to the router with no authentication. Get the latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free. Map cross-domain privilege escalation to sever breach routes at key choke points.

USF continues to bridge the digital divide

KINGSTON, Jamaica – September 30, 2024 — The Universal Service Fund (USF) had an exciting month, with September 2024 seeing significant strides in our mission to bridge the digital divide. 

Through our Connect a Child Programme, over 400 tablet devices were distributed to Primary Exit Profile (PEP) students who are considered high achievers and from low-income families. Therefore, ensuring that more youth have access to vital educational resources.

So far, Members of Parliament for the parishes of Kingston and St. Andrew, St. James, Manchester, St. Elizabeth, Hanover, Trelawny, St. Mary and Portland selected the deserving students to receive the tablets, with hand-over ceremonies being on the way for the remaining parishes. 

In addition to the tablet distribution, the USF proudly launched four new Community Connect Wi-Fi sites in key locations: Brandon Hill (St. Andrew West Rural), Woodhall (Clarendon North Central), Port Henderson Road (St. Catherine South Eastern), and Askenish (Hanover Western). These Wi-Fi hotspots aim to enhance internet accessibility, providing community members with the tools they need for online learning and connectivity.

Further supporting local education initiatives, Spalding Primary School received 20 desktop computers and one printer under our special programme. This initiative is designed to enhance the learning environment, equipping students with essential technology that fosters academic growth and digital literacy.

“We are committed to empowering our communities through technology and education. The distribution of tablets, the establishment of community Wi-Fi sites, and the support for Spalding Primary School reflect our ongoing mission to ensure that every child has access to the resources they need to succeed,” said USF’s Acting CEO, Mr. Andrew McRae. 

He added that the USF remains dedicated to promoting equitable access to technology across Jamaica. 

“As we continue to launch initiatives aimed at closing the digital gap, we invite community members to engage with these resources and take advantage of the opportunities they present,” Mr. McRae said