[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5D7-73e-DOBeczqVIFmXF9GqJLjhKRK6vgyQyUx-eaE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":16,"created_at":17,"published_at":18,"article":19,"tags":23,"podcasts":36},"70a54529-4368-4252-8155-787dc1e53546","push-notification-cache-exposes-encrypted-messages-to-law-enforcement","79dff190-ab0e-407e-9b6a-2e9b4441e449","Push Notification Cache Exposes Encrypted Messages to Law Enforcement","The FBI successfully extracted encrypted Signal messages from an iPhone's push notification cache, even after the app was deleted, revealing a critical data exposure vulnerability. Push notifications store message content in device memory to enable quick preview displays, creating an unencrypted copy that bypasses the app's end-to-end encryption. This affects all messaging apps using push notifications and demonstrates how system-level caching can undermine application security. The incident highlights that users must actively configure notification settings to prevent sensitive data exposure, as default settings often prioritize convenience over privacy.","**Immediate actions:**\n- Configure messaging apps to hide message content and sender information in push notifications\n- Review and disable detailed notifications for all sensitive applications\n- Enable full device encryption with strong passcodes on all mobile devices\n\n**Long-term improvements:**\n- Establish organizational policies prohibiting sensitive communications via standard push notifications\n- Implement mobile device management (MDM) solutions to enforce secure notification configurations\n- Educate users about the privacy implications of push notification settings\n\n**Technical safeguards:**\n- Deploy endpoint detection tools that monitor for unauthorized data extraction attempts\n- Implement data loss prevention (DLP) solutions to identify sensitive data in transit\n- Regular security assessments of mobile device configurations and cached data exposure",[12,13,14,15],"NIST SP 800-124 (Mobile Security)","CIS Control 13 (Data Protection)","NIST Privacy Framework PR.DS-1","ISO 27001 A.13.2.1","published","2026-04-11T12:07:36.258089+00:00","2026-04-11T12:07:36.124+00:00",{"id":7,"url":20,"slug":21,"title":22},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fsecurity-news-this-week-your-push-notifications-arent-safe-from-the-fbi\u002F","your-push-notifications-aren-t-safe-from-the-fbi-b6427c","Your Push Notifications Aren’t Safe From the FBI",[24,30],{"id":25,"name":26,"slug":27,"description":28,"color":29},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":31,"name":32,"slug":33,"description":34,"color":35},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[37],{"id":38,"date":39,"edition":40,"title":41,"audio_url":42},"167ed0ba-dad4-49b6-bca2-4b6eec766cd8","2026-04-11","afternoon","ThreatNoir Weekend Brief — April 11","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-11\u002Fthreatnoir-afternoon-brief-2026-04-11.mp3"]