ConciseSignal

Federal judge halts Utah's VPN age-check law

A federal judge has temporarily stopped enforcement of Utah's new law requiring adult websites to verify users' physical locations, even if they're using VPNs. The ruling came after Aylo, Pornhub's parent company, challenged the law, arguing it was unconstitutional. The court found it likely violates the U.S. Constitution, particularly the dormant Commerce Clause. The law would have forced sites to bypass VPN encryption and verify all users' locations, a technical impossibility according to the judge.

Why it mattersThe pause signals legal limits on state-level restrictions targeting VPN use. The outcome could influence other states considering similar laws and shape online privacy standards.

Sources covering this

TechRadarFederal judge strikes down Utah's controversial VPN age verification rules3:08 PM →GizmodoFederal Judge Blocks Utah’s VPN Crackdown9:38 PM →
Concise Signal DailyEverything that mattered, every weekday at 7am.

More in Cybersecurity

10 sources · 1h ago

Critical zero-days in Citrix NetScaler exploited, patches released

Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited. Both flaws allow remote code execution, and security agencies in the US, UK, and elsewhere have issued urgent patch directives. Citrix released fixes after reports of active exploitation circulated for two days. Over 50,000 instances may be at risk, according to Unit 42. Cybersecurity authorities warn that forensic review and prompt updates are essential.

1 sources · 13m ago

GitHub AI tool finds 24 vulnerabilities in Android apps

GitHub's Security Lab developed an open source AI agent that identified 24 vulnerabilities in Android applications using automated taskflows. These taskflows help security researchers audit code by guiding AI models through common entry points and potential flaws unique to mobile apps. Researchers can run these workflows themselves, but need a GitHub Copilot license since the process uses advanced AI prompts and may require significant resources.

2 sources · 1h ago

Apple fixes CoreGraphics flaw after targeted attacks

Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly sophisticated attacks targeting specific users of older software versions. The flaw allowed attackers to run code by sending a maliciously crafted file. Apple says improved bounds checking now addresses the issue but hasn't disclosed how many people were targeted or if attacks succeeded.

1 sources · 12m ago

Over 16,000 Supabase databases expose sensitive user data

Security researchers found over 16,000 Supabase databases with misconfigurations exposing user data including personally identifiable information, passwords, and authentication tokens. Some of the leaked records also include credit card data. The exposures span businesses globally and affect services ranging from a U.S. valet service to an African government consulate. Researchers attribute the leaks to poor security configurations, often linked to AI-assisted app development.