Pinoy Data Privacy
Pinoy Data Privacy stands as an advocacy of culture of data privacy awareness in the Philippines.
"Pinoy Data Privacy" stands as a robust advocacy initiative dedicated to fostering a culture of heightened data privacy awareness across the Philippines. Spearheaded by passionate individuals committed to safeguarding personal and sensitive information, this movement strives to empower Filipinos with the knowledge and tools necessary to protect their digital identities and privacy rights in an increasingly interconnected world. Through educational campaigns, workshops, and outreach programs, Pinoy Data Privacy seeks to demystify the complexities of data privacy laws and regulations, making them accessible and understandable to all. By promoting best practices in handling, sharing, and securing data, the initiative endeavors to equip individuals, businesses, and organizations with the skills needed to navigate the digital landscape responsibly and ethically. Moreover, Pinoy Data Privacy serves as a vocal advocate for legislative reforms and policy enhancements aimed at strengthening data protection frameworks within the Philippines. By collaborating with government agencies, industry stakeholders, and civil society groups, the initiative strives to shape a regulatory environment that prioritizes the privacy rights of Filipino citizens while fostering innovation and economic growth. At its core, Pinoy Data Privacy embodies a collective commitment to upholding the fundamental right to privacy and ensuring that every Filipino can confidently navigate the digital realm with a sense of security, dignity, and respect for their personal information.
11/09/2026
NEWS | Several Philippine government websites, including BIR's, were hacked on Sept. 8, 2026. Homepages were defaced, but the agencies and DICT restored them within hours. Taxpayer records and core systems reportedly weren't touched, though checks continue.
DICT's cybersecurity team, the Cybercrime Investigation and Coordinating Center, and the PNP Anti-Cybercrime Group are working to trace the breach and prevent repeats.
This isn't the first time gov't sites have been hacked, and "your data is safe" isn't the full picture. What's needed: regular security checkups, faster fixes, and clear public updates. Not a one-time patch.
Any cybersecurity experts here? What are your thoughts on how this could've been prevented? If you've got ideas or projects in this space, let's connect. Drop a comment or message us.
07/08/2026
๐ HTTP vs. HTTPS vs. VPN โ What's the Difference? ๐
Understanding these technologies is essential for protecting your privacy online. HTTP sends data without encryption, HTTPS encrypts your connection to websites, and a VPN creates a secure encrypted tunnel that helps protect your internet activity from your ISP and other third parties. Knowing when to use each option can significantly improve your online security and privacy.
๐ฌ Which do you rely on the most for secure browsingโHTTPS alone or HTTPS with a VPN? Share your thoughts in the comments!
07/08/2026
Nmap is a network scanning tool used by system administrators, IT professionals, and students for security auditing, troubleshooting, and learning.
Common Scans
nmap -sP โ Ping Scan: Checks which devices are active on a network.
nmap -sS โ TCP SYN Scan: Helps discover open services.
nmap -sU โ UDP Scan: Finds active UDP services.
nmap -sV โ Version Detection: Identifies service versions for maintenance.
nmap -O โ OS Detection: Detects operating system type (for compatibility testing).
nmap -A โ Aggressive Scan: Runs multiple checks for detailed results.
Timing & Input
nmap -T4 โ Timing Template: Controls scan speed.
nmap -iL โ Input from List: Reads targets from a file (useful for admins).
nmap -sn โ Host Discovery: Finds devices without scanning ports.
Advanced TCP Techniques
nmap -sX โ XMAS Scan: Uses a special test packet to check responses.
nmap -sF โ FIN Scan: Uses a different method for host analysis.
nmap -sT โ TCP Connect Scan: Connects directly to services.
nmap -sN โ Null Scan: Uses empty packets to analyze responses.
nmap -sA โ ACK Scan: Helps detect firewall filtering.
Scripting & Port Options
nmap -sC โ Default Script Scan: Runs safe built-in scripts.
nmap --script โ Run Specific Script: For detailed service checks.
nmap --top-ports โ Top Ports Scan: Scans the most used ports.
07/08/2026
๐ฑ A Few Minutes Updating Your Device Can Save Hours Of Frustration Later ๐
07/08/2026
โก๐ก๐ฒ๐๐น๐ ๐ฎ๐ฝ๐ฝ๐ผ๐ถ๐ป๐๐ฒ๐ฑ ๐ฎ๐ ๐ฎ ๐๐ฎ๐๐ฎ ๐ฃ๐ฟ๐ผ๐๐ฒ๐ฐ๐๐ถ๐ผ๐ป ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ๐ฟ? ๐ฆ๐๐ฎ๐ฟ๐ ๐๐๐ฟ๐ผ๐ป๐ด.
Equip yourself with the practical knowledge and skills to lead your organization's data privacy compliance. Join the ๐๐ฃ๐ข ๐๐๐ฆ๐ง-๐ง๐ฅ๐๐๐ ๐๐ฒ๐ฎ๐ฟ๐ป๐ถ๐ป๐ด ๐ฆ๐ฒ๐๐๐ถ๐ผ๐ป and learn how to implement the ๐๐ฎ๐๐ฎ ๐ฃ๐ฟ๐ถ๐๐ฎ๐ฐ๐ ๐๐ฐ๐ ๐ผ๐ณ 2012 (๐ฅ๐ 10173) with confidence and clarity.
Led by ๐๐๐๐. ๐ฅ๐ฎ๐ป๐ฑ๐ผ๐น๐ณ๐ผ ๐. ๐ฌ๐ฎ๐ป๐๐ฎ, this intensive webinar focuses on real-world compliance, practical applications, and the essential responsibilities of every DPO.
๐
August 22, 2026 (Saturday)
๐ 9:00 AM โ 4:30 PM
๐ป Zoom Webinar
๐ฐ Learning Investment: โฑ3,500
๐ฏ ๐๐๐๐๐จ๐ฉ๐๐ง ๐ฃ๐ค๐ฌ ๐๐ฃ๐ ๐๐๐จ๐ฉ-๐ฉ๐ง๐๐๐ ๐ฎ๐ค๐ช๐ง ๐ฟ๐๐ ๐๐ค๐ช๐ง๐ฃ๐๐ฎ.
๐ https://forms.gle/19YZB38mdPzBBgFf8
18/07/2026
๐จ Email Change Takeover Bug: When Changing Email Becomes Account Takeover
Email address is one of the most important parts of any online account.
It is used for login, password reset, security alerts, OTPs, invoices, notifications, and account recovery.
But if the email change process is weak, attackers may abuse it to take over user accounts.
This is called Email Change Takeover Bug.
๐ What Is Email Change Takeover?
Email change takeover happens when an attacker can change the email address linked to an account without strong verification.
If the system does not properly verify the old email, new email, password, session, or MFA, the attacker may replace the victimโs email with their own.
After that, they can reset the password, receive security alerts, and control the account.
โ ๏ธ Common Email Change Bugs:
๐น Email changed without password confirmation
๐น Email changed without verifying old email
๐น Email changed without verifying new email
๐น Verification link works multiple times
๐น Old session remains active after email change
๐น Password reset goes to attackerโs new email
๐น MFA not required for email change
๐น Email change allowed from hijacked session
๐น Weak CSRF protection on email update
๐น API accepts modified user ID or email field
๐น Email change token does not expire
๐น User not alerted after email update
๐ฏ Why This Is Dangerous:
๐น Full account takeover can happen
๐น Password reset can be redirected
๐น Security alerts go to attacker
๐น Victim may lose recovery access
๐น Business accounts can be compromised
๐น Sensitive data can be exposed
๐น Attacker can lock out the real user
๐น Trust and platform security can be damaged
๐ง Example Scenario:
An attacker gains access to a victimโs logged-in session.
They go to account settings and change the email address.
The platform only asks for the new email and does not require password, MFA, or old email confirmation.
Now the attacker controls the recovery email.
They can request a password reset and take full control of the account.
This is how weak email change logic can become account takeover.
๐ก๏ธ How Companies Can Stay Safe:
โ
Require password confirmation before email change
โ
Require MFA for sensitive account changes
โ
Verify the new email before activating it
โ
Send security alert to the old email
โ
Delay sensitive changes for high-risk accounts
โ
Invalidate old sessions after email change
โ
Prevent email change from suspicious sessions
โ
Use short-lived verification tokens
โ
Make verification tokens single-use
โ
Log every email change event
โ
Alert users about email update attempts
โ
Rate limit email change requests
โ
Validate ownership on backend APIs
โ
Test email change flow during security reviews
๐ฅ Why Ethical Hackers Should Care:
Email change takeover is a serious authentication and account security vulnerability.
It may look like a simple profile update feature, but the impact can be critical.
Modern ethical hacking should test email update flow, old email verification, new email verification, password confirmation, MFA enforcement, token expiry, session handling, and password reset behavior.
An email address is not just contact information.
It is the recovery key to the account. ๐งโ ๏ธ
If email change is weak, account takeover becomes easy.
18/07/2026
๐๐๐๐: Real reforms begin with institutions willing to lead. We are grateful to the ๐๐๐ฉ๐๐ซ๐ญ๐ฆ๐๐ง๐ญ ๐จ๐ ๐๐ฎ๐๐ ๐๐ญ ๐๐ง๐ ๐๐๐ง๐๐ ๐๐ฆ๐๐ง๐ญ (๐๐๐) and our government partners for demonstrating that leadership through their constructive engagement with ODPP, bringing the institutionalization of the Data Protection Officer profession closer to reality.
United by a common purpose, we will continue advancing the institutionalization of the ๐๐๐ญ๐ ๐๐ซ๐จ๐ญ๐๐๐ญ๐ข๐จ๐ง ๐๐๐๐ข๐๐๐ซ (๐๐๐) ๐๐ฌ ๐ ๐ซ๐๐๐จ๐ ๐ง๐ข๐ณ๐๐ ๐ฉ๐ซ๐จ๐๐๐ฌ๐ฌ๐ข๐จ๐ง to help build a more secure, privacy-respecting, and future-ready Philippines.
---
๐ง๐ผ ๐ฟ๐ฒ๐ฎ๐ฑ ๐๐ต๐ฒ ๐ณ๐๐น๐น ๐ฝ๐ผ๐๐ถ๐๐ถ๐ผ๐ป ๐น๐ฒ๐๐๐ฒ๐ฟ, ๐ฐ๐น๐ถ๐ฐ๐ธ ๐ต๐ฒ๐ฟ๐ฒ: https://www.facebook.com/odppi/posts/pfbid02vY5UZS3wJMxB1kUvwLFEwhe5ZTcJyNPsaaVNo4nQM6fNDqzUYuMtPAtkZnMCr5RMl
18/07/2026
๐๐ข๐ก๐๐ฅ๐๐ง๐จ๐๐๐ง๐๐ข๐ก๐ฆ to all our participants who successfully completed the seminar on ๐๐ฎ๐๐ฎ ๐ฃ๐ฟ๐ถ๐๐ฎ๐ฐ๐ ๐๐ฎ๐: ๐๐ฃ๐ข ๐๐๐ฆ๐ง-๐ง๐ฅ๐๐๐ ๐๐ฎ๐๐-๐๐ฒ๐ฎ๐ฟ๐ป๐ถ๐ป๐ด ๐ฆ๐ฒ๐๐๐ถ๐ผ๐ป.
We look forward to welcoming the next batch of participants in August!
Click here to claim your Sponsored Listing.
Website
Address
Manila