The Irish DPC fined WhatsApp €5.5M for violating GDPR

The Irish Data Protection Commission (DPC) fined Meta’s WhatsApp €5.5 million for violating data protection laws. The popular messaging app WhatsApp has been fined €5.5m by the Irish Data Protection Commission (DPC) for violating the General Data Protection Regulation (GDPR). The DPC has given six months to the Meta-owned company to bring its data processing […]

The post The Irish DPC fined WhatsApp €5.5M for violating GDPR appeared first on Security Affairs.

January 21, 2023
Read More >>

2FA omitted on FB attack. Possibly session hijacking?

Hi everyone,

Basically the title. I had a Facebook account that had enabled 2FA, email notifications and a strong password.I am not aware for any of my devices to be compromised.

On the 7th of January, I received a notification from Facebook that my account has been suspended due to violating community guidelines.

I initially thought it was mistake, but I am currently looking at the logs and I can see two sessions being initiated on the night of 6th, one from New York, the other from China.

And I am baffled, unless my devices/PC has been compromised (which I scanned and they don’t seem to be), how in the world did someone created a session like this. Furthermore without triggering 2FA or even an email warning for suspicious activity.

Does anyone has any ideas, I am very curious on how that has been achieved?

submitted by /u/_yy96_
[link] [comments]

January 21, 2023
Read More >>