// platform security

All signals tagged with this topic

Gizmodo breach exposes readers to ClickFix malware distribution

Gizmodo's account compromise became an active malware distribution vector. Major media properties now function as delivery infrastructure for threats. The differential targeting—Windows users receiving trojans, Mac users spared—suggests attackers are optimizing payloads by operating system. Compromised high-traffic sites are now valued not just for credential theft but as efficient infection channels with built-in audience trust. This alters how publishers should approach account security. A breach no longer just exposes user data; it weaponizes their editorial platform.

Signal's Backup Security Becomes Target in Phishing Campaign

Attackers are exploiting the friction between Signal's encrypted messaging and its cloud backup feature. Users must manually manage a recovery key to access backed-up messages, creating an ideal social engineering vector. The gap is stark: security-conscious consumers choose Signal to avoid surveillance, yet the operational complexity forces them to manage secrets outside the app's protection, leaving them vulnerable to credential theft at the moment they're trying to protect their data.

Discord enables end-to-end encryption for all voice and video calls

Discord's move to encrypt all calls by default removes a significant revenue and content-moderation lever—the company can no longer access call data even when requested by law enforcement or for safety investigations. This shifts the liability and operational burden onto users and third parties while positioning Discord as a privacy-first platform in direct competition with Signal and other E2EE services. It also complicates Discord's ability to moderate harassment, CSAM, and other harms that often occur within calls rather than in text channels.