Meta had finally announced that WhatsApp for Wear OS is now rolling out to smartwatch users around the world in the coming days. After months of testing, the standalone smartwatch app is finally ready for primetime.
The Verge reports that the rollout is starting today, and that the new standalone app is compatible with all smartwatches powered by Google’s Wear OS 3. To avoid confusing users, WhatsApp’s smartwatch app is as simple as it gets.
The main features the app offers are the ability to send and receive text and voice messages, as well as emojis and quick replies. It might sound pretty basic, but this is more than enough considering that all of these features are available from your wrists.
As a slightly more advanced feature, users will be able to take VoIP calls when their smartwatch is not connected to their smartphones, as well as reply to messages and start new conversations.
Unsurprisingly, watchOS users haven’t been blessed with the same level of support, so their WhatsApp experience will be rather limited in comparison with Wear OS users. Apple Watch users can’t send messages or make calls through their smartwatch using WhatsApp, but they can reply to messages from their wrists. Not to mention that iPad users don’t even have an official app yet.
Usually, competition is good for consumers, but when it comes to WhatsApp, Meta seems to favor Wear OS over watchOS users. If you’re using a Wear OS 3 smartwatch, look for the standalone WhatsApp in the coming days.
NetScaler ADC and NetScaler Gateway (previously Citrix ADC and Citrix Gateway) contain multiple discovered vulnerabilities.
Citrix ADC is a powerful networking solution that ensures fast, secure, and reliable delivery of applications across networks.
While the NetScaler Gateway is a secure remote access solution that enables users to access their applications and data from anywhere securely.
Citrix recently issued a security bulletin, cautioning users about three new vulnerabilities impacting their above-mentioned product line.
Here below, we have mentioned those three vulnerabilities:-
Hackers Exploiting Zero-Day
While the cybersecurity analysts at Rapid7 marked the CVE-2023-3519 as the critical zero-day vulnerability among the three, enabling unauthenticated attackers to execute code on vulnerable Gateway systems remotely.
Since the CVE-2023-3519 is currently exploited in the wild, poses a significant risk. Due to the popularity of this product line among threat actors, Rapid7 advises immediate emergency updates instead of waiting for the regular patch cycle.
To exploit the security issue, hackers target vulnerable appliances configured as gateways (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or authentication virtual servers (AAA server).
Pre-requisites: Appliance must be configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
Affected Products
The vulnerabilities impact the following supported versions of NetScaler ADC and NetScaler Gateway:-
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.13
NetScaler ADC and NetScaler Gateway 13.0 before 13.0-91.13
NetScaler ADC 13.1-FIPS before 13.1-37.159
NetScaler ADC 12.1-FIPS before 12.1-65.36
NetScaler ADC 12.1-NDcPP before 12.65.36
Fixed Product Versions
Here below we have mentioned all the fixed product versions:-
NetScaler ADC and NetScaler Gateway 13.1-49.13 and later releases
NetScaler ADC and NetScaler Gateway 13.0-91.13 and later releases of 13.0
NetScaler ADC 13.1-FIPS 13.1-37.159 and later releases of 13.1-FIPS
NetScaler ADC 12.1-FIPS 12.1-65.36 and later releases of 12.1-FIPS
NetScaler ADC 12.1-NDcPP 12.1-65.36 and later releases of 12.1-NDcPP
Moreover, to mitigate these security flaws, make sure to apply patches in affected versions of NetScaler ADC and NetScaler Gateway on an immediate basis.
There are several folks who like to have their photos and videos backed up to Google’s servers. However, not everyone does. Well, Google Photos has a new banner prompting people to back up their photos, according to Android Police.
In case you don’t know what backing up your photos does, here’s a quick rundown. If you’re looking to back up your files, you’ll select which folder you want to back up. After that, every photo or video you add to that folder will be uploaded to Google’s servers.
When that happens, you’ll be able to access that photo or video from the Google Photos app on any device regardless if you took the picture on that device. You can even see it on the Google Photos website in your browser.
Just know that this is an automatic process that takes place in the background. You’ll want to be careful of what you take a picture of, as it will be uploaded.
Google Photos has a new banner telling you to back up your photos
If you don’t back up your photos on Google Photos, then you’ll see a persistent banner on the top of the UI prompting you to “Unlock the power of Google Photos”. When you tap on it, you’ll be taken to a page with a checklist on it.
The checklist will have three features to enable. The first one will back up your photos, the second will enable notifications, and the third will sign you into Google Photos. If you already have these enabled, then they’ll show up as checkmarks.
Of course, Google is marketing this as a way to get the most out of Google Photos. Most tech users know what they want and what they don’t want. If they don’t have notifications enabled, then they don’t want them enabled. That also goes for backups.
However, the less tech-savvy individuals might not be as rebellious. All they’re seeing is a way to make their experience more powerful. They’re more likely to sign on without giving it a second thought. So, this could be the audience that Google is targeting. In any case, if you’re not backing up your photos, get ready to be annoyed.
After initially snubbing Samsung, Tesla has reportedly returned to the Korean firm to manufacture its next-gen Full Self-Driving (FSD) chips, at least a portion of it. The Texas-based EV (electric vehicle) company had previously chosen TSMC as the sole manufacturer of the Hardware 5 (HW 5.0) auto chips.
According to The Korea Economic Daily, this change of wind came after Samsung chief Lee Jae-yong met Tesla CEO Elon Musk in May. The duo discussed ways to strengthen their tech alliance during the meeting at the Samsung research center in Silicon Valley, San Jose. Lee offered to co-develop chips for fully autonomous vehicles and reportedly pitched “favorable contract prices” for manufacturing Tesla’s chips. Musk seemingly could not refuse the offer.
This wouldn’t be the first time Samsung would be manufacturing chips for Tesla. The Korean firm supplied FSD chips for its Model 3, Model 5, Model X, and Model Y cars in the past. But in December last year, Tesla decided to snub its long-time partner and switched to TSMC to manufacture its next-gen FSD chips. Samsung’s poor 4nm yields were said to be the reason behind this decision from the EV company.
However, Samsung has significantly improved its yield rates in recent months. Its 4nm yields are now on par with that of TSMC, while its 3nm yields have surpassed the Taiwanese firm. As such, Tesla has changed its mind and returned to Samsung. It plans to use Samsung-made 4nm HW 5.0 chips in its Level 5 autonomous driving vehicles, which should enter mass production three to four years from now.
Tesla is reportedly considering splitting the manufacturing of the next-gen auto chips between Samsung and TSMC. But it hasn’t completely ruled out the possibility of completely switching from TSMC to Samsung. Splitting next-generation chip production between the two is more likely though,” said an industry official familiar with the matter. The chips are expected to enter production next year, so Tesla still has time to decide.
Samsung will also manufacture self-driving chips for other companies
Along with Tesla, Samsung will also manufacture self-driving chips for Ambarella and Mobileye Global. The former is a fabless semiconductor design company, whereas the latter is an autonomous driving tech affiliate of Intel. To fulfill these orders, the Korean firm has significantly increased its foundry capacity at its Pyeongtack plant in Korea. It will also begin operations at its upcoming chip factory in Taylor, Texas by the end of 2024. Samsung expects its global contract chip manufacturing capacity to triple between 2022 and 2027.
Hackers Use “chatgpt5 [.]zip” to Trick Users into Downloading Malware. Phishing remains a severe cybersecurity threat, deceiving employees with cleverly disguised malicious links and malware attachments, potentially causing company-wide troubles for over a decade.
The 2022 FortiGuard Labs report and the 2023 Global Ransomware Research both highlight phishing as the leading initial access method in network breaches, setting the stage for subsequent attack stages.
Threat actors employ creative names to disguise phishing attacks, with a new TLD ‘ .ZIP’ introducing a potential threat by chatgpt5 leading to malicious sites.
Reach Expansion
TLDs are vital components of domain names, like ‘.COM,’. ‘NET,. ‘ ‘.ORG,’ represents the highest level in the DNS hierarchy, shaping the structure of the web.
With internet evolution, countless gTLDs emerged for personalized web addresses, offering branding chances but also phishing opportunities that demand alertness.
The availability of public ‘.ZIP’ domains has created an unfortunate opportunity for the threat actors seeking new exploits and techniques.
The inclusion of ‘.ZIP’ as a gTLD adds complexity to phishing detection, particularly due to its association with compressed files, increasing confusion and providing phishers with a potent new tool for their attacks.
Exploiting ChatGPT
The cybersecurity researchers acknowledge the security risks of the ‘.ZIP’ TLD, but responsible individuals are actively working to mitigate the abuse of such domain names.
The hype around ChatGPT lead to the creation and registration of “chatgpt5 [.]zip ” on May 20th, supposedly for the next GPT iteration, but surprisingly, it holds a neutral text message instead of malware.
New .ZIP domain (Source – Fortinet)
Harmless text message (Source – Fortinet)
To trick the users by claiming to safeguard students from malware, “assignment[.]zip” was registered by the threat actors on May 15th, redirecting visitors to a download of a ZIP archive containing files that are completely safe.
Fake attack for students (Source – Fortinet)
Exploiting the widespread use of the .ZIP extension, malicious actors create campaigns and websites reminiscent of early domain squatting techniques.
Domains Observed
Here below, we have mentioned all the domains observed by the researchers:-
joomla[.]zip on May 15th
msnbc[.]zip on May 15th
nozominetworks[.]zip on May 19th
Threat actors leverage special IDN characters to craft carefully disguised links within fake emails, directing users to malicious .ZIP domains.
While the usage of IDN in .ZIP and .MOV TLDs is yet to be determined, unlike .COM and .ORG. The authority portion, [[email protected]:port number], includes optional fields like username and password.
But, some parts can be omitted based on protocols, and the basic authentication websites require user info, while others can ignore it.
Mitigations
Here below we have mentioned all the mitigations:-
Make sure to block .zip domains via firewall and web filtering services.
Enhance protection with browser security extensions and web filters.
Make sure to enhance security with advanced email filtering to prevent suspicious link-containing emails.
Ensure all software, including antivirus programs, web browsers, and operating systems, is up to date.
Promote user awareness and bridge knowledge gaps through regular phishing simulations and training exercises.
Threads, the latest social media platform in the town, got off to a flying start, surpassing 100 million users just a few days after its launch. But the craze quickly died down, with its daily active user count seeing a 50 percent drop in recent days. Much of this is due to the lack of key features found on other platforms. Meta has now released a major update for the app to add some of the features users have been asking for.
Announced by Threads and Instagran’s software engineer Cameron Roth on Threads, the new Meta app is picking up translation support with the latest update. It adds a translate button to the bottom of a post, alongside the existing buttons to like, comment, share, and send the post. The app will use the same AI-powered translations that Instagram uses, so it will be fairly robust from the get-go.
Threads is also gaining a Follows tab in the Activity feed, alongside the Replies, Mentions, and Verified tabs. A new Following tab on your profile page will let you check out who you follow on the platform. Next, the app is adding tappable reposter labels and now lets users subscribe to unfollowed users. Roth has also announced an “on Thread replies page” for the app. It’s getting a shortcut to open your Instagram followers list as well.
Additionally, the latest Threads update brings activity feed scrolling and loading improvements. It also fixes “a few small crash” issues and a handful of other bugs. Meta has cut the app’s binary size as well. The big Threads update with all of these changes will roll out to iOS users within the next few days. A similar update for Android users should follow soon, though there hasn’t been any official announcement from Meta or Roth yet. We will let you know when we have more information.
Meta is readying another big update for Threads
This is the first batch of several new features Meta has planned for Threads. A leaked internal document recently revealed that the company will soon add direct messaging support to the platform. The app will also gain a Twitter-like Trends & Topics feature. After all, Threads is Meta’s Twitter alternative. Finally, Meta is preparing to improve Threads’ search function. It’s barebones right now, only letting you look up account names. Stay tuned for more information about the upcoming Threads update.
In this day and age, where nearly every new appliance or electronic device is connected to the internet, and hackers are on the lookout to gain unauthorized access to your accounts and data, selecting a device with robust cybersecurity measures is paramount. Now, in a bid to bolster security for IoT devices, the Biden administration has launched a new initiative called the “U.S. Cyber Trust Mark,” which aims to help consumers choose the right smart appliances and fitness trackers that are relatively secure from cyberattacks.
Inspired by the Energy Star program, the U.S. Cyber Trust Mark will operate as a voluntary labeling system featuring a distinctive shield logo on products that meet stringent cybersecurity criteria. Additionally, several major players, including Amazon, Best Buy, Google, LG Electronics U.S.A., Logitech, and Samsung, have already pledged their support for the initiative.
How does the system work?
The Biden administration has tasked the National Institute of Standards and Technology (NIST) to develop the necessary cybersecurity standards, ensuring that certified IoT devices adhere to the highest security benchmarks. And although not finalized yet, the requirements could reportedly include strong default passwords, comprehensive data protection for stored and transmitted information, regular security updates, and the inclusion of incident detection capabilities.
Furthermore, approved devices will feature a QR code that provides up-to-date information on various cybersecurity aspects, such as software updating policies, data encryption standards, and vulnerability remediation. To further raise awareness, the Cybersecurity and Infrastructure Security Agency (CISA) will also educate consumers about the significance of the label and encourage retailers to prioritize labeled products.
However, it is important to note that the system will initially focus on developing cybersecurity standards for high-risk consumer-grade routers. This focus is due to malicious actors targeting these routers to launch Distributed Denial of Service (DDoS) attacks and gain unauthorized access.
Although the FCC is currently in the process of applying for a national trademark for the U.S. Cyber Trust Mark, the government plans to launch the official program in 2024.
As the world moves increasingly into a digital realm, the security of data stored in the cloud is an ever-growing concern for businesses and individuals alike.
Cloud computing enables access to our most sensitive and critical information from any device with an internet capability, making it extremely attractive to those looking for easy and efficient storage capabilities.
But this convenience also comes with risks – our data isn’t as secure as we might like or assume unless appropriately managed.
That’s why it’s essential to understand what measures can be taken to ensure that your data remains private, protected, and available only to authorized users on approved networks and systems.
In this blog post, we’ll explore the various ways you can securely use cloud services while maintaining total control over who has access to your business’s information – from encryption strategies to identity management solutions – so that you have peace of mind knowing that your company’s confidential electronic files remain secure in today’s uncertain online landscape.
What is Cloud Security and Data Privacy
The importance of cloud security best practices and data privacy continues to grow as cloud technology use surges upwards.
It is the measures they employ to defend against cyber intrusion and malicious attacks. Data privacy, on the other hand, pertains to maintaining the confidentiality of, if applicable, personal and sensitive information before, during, and after storage or processing distributes the same in a cloud environment.
This teaches proper consent for data collection and processing, ensuring proper disaster preparedness, and implementing secure data handling practices. Data encryption can also be used as a means to protect stored and transmitted data from unauthorized access, manipulation, or theft.
Benefits of using Cloud Security and Data Privacy
Data security and privacy are key concerns in today’s digital world, including the workings of businesses and even the everyday lives of individuals.
Cloud security best practices is taking root due to its advantages over traditional firewall measures for business entities.
Firstly, cloud security allows flexibility and scalability, enabling a business entity to alter its security needs based on evolving dynamics quickly.
Additionally, higher levels of automation provided by cloud security solutions mean less manual job costs and effort.
Identity and Access Management (IAM) solutions allow for comprehensive control over who can access sensitive data and applications while ensuring that these users remain compliant with policies.
Businesses can finally be confident that their sensitive information is protected since cloud security is reliable and cost-efficient. Moreover, data privacy is vital for any business or individual to retain trust and build a customer reputation.
By opting for the use of cloud security best practices, a business entity can be assured that its consumers’ sensitive information is stored and managed securely.
Challenges of using Cloud Security and Data Privacy
Business operators are moving their data and operations to the cloud with the continuous shift towards cloud computing. This move comes with its own challenges, especially in the guarantees for preserving privacy and safeguarding cloud security.
Today’s prime challenge businesses struggle with is securing important data in public clouds.
IAM solutions can assist in providing solutions to that dilemma and are primarily used as cybersecurity measures for regulating access to data in the cloud.
Security Compliance is another common challenge, as large companies have to meet specific regulations and industry standards. With the increased complexity of today’s cloud computing environment, business entities must ensure that all security measures are always up to date.
Also, businesses must adhere to several regulations and standards, such as GDPR or HIPAA, if they hoard sensitive data in the cloud. Non-compliance with these rules typically means skyrocketing costs, heavy fines, and legal problems.
How to ensure your data privacy with Cloud Security best practices
In recent years, more and more people are trusting cloud solutions for their businesses and personal uses. Although the convenience of the cloud is fantastic, the globe is concerned about dealing with data privacy issues.
Fortunately, there exist cloud security solutions that will help you ensure no one can easily access your data.
It should contain encryption functions, controls over who may access it, and monitoring mechanisms to detect irregular usage activity.
Besides that, choose a good provider that understands its clients’ privacy stance and has good experience in its lines.
Some factors to consider include choosing reliability and ensuring whatever solution you pick meets industry regulations and fields like GDPR or HIPAA standards. To learn more about cloud security best practices and find a reliable provider, you can explore N-ix for valuable insights and resources.
Best practices for maintaining data privacy in the cloud
Data privacy in the cloud is a serious concern as more and more companies rely on cloud-based services. However, businesses should follow several best practices to ensure their data’s privacy in the cloud.
One of the most important practices is choosing a cloud provider with strong security measures and a known entity that protects their customers’ data well.
Other good practices would include using robust authentication protocols, regularly monitoring activity logs, thoroughly checking up on software and security protocol updates until they cascade across all of the organization’s systems, and periodically refreshing knowledge bases on old threats, new attacks, and emerging trends/technologies so that organizations can stay one step ahead of potential threats.
Final Thoughts
Ultimately, it’s essential to maintain data privacy in the cloud for security and composure.
The solutions for securing the cloud and maintaining data privacy have many advantages: improved system reliability, protection from stolen services, secure communication services, and automated backup procedures, among others.
However, since reliance on the cloud entails a degree of uncertainty regarding storage or some service functions, ensuring sufficient data privacy has proved difficult.
Considering this aspect is vital as you evaluate various cloud security best practices before committing; that way, you can maximize their advantage while minimizing their disadvantage.
Over on Threads this week, Marques Brownlee (you’ve probably heard of him) asked for everyone’s “tech hot takes”. And Instagram and Threads’ boss Adam Mosseri chimed in saying that “Android’s now better than iOS”.
Now if you’ve been following him on Threads since it launched, you’ll know that he did recently switch to Android on his main device. And has talked about he prefers it over iOS these days.
One has to wonder if this is going to influence Instagram and Threads‘ product roadmap, with the head of the two apps preferring to use Android over iOS. However, some people believe it’s a bit deeper than just “preferring” one platform over another.
Could Mosseri dislike iOS because it forces apps to show what data they are collecting?
Some might think that Mosseri is preferring Android over iOS these days, due to the privacy of iOS. Don’t forget, that Apple did cost Facebook, Instagram’s parent-company, over $10 billion per year when it added the “Ask not to track” feature a couple of years ago. On top of that, Apple does force apps to show what data is collecting from its users. And it puts it front-and-center.
Now, Android does also show you on the Play Store listing what data is being collected for each app, but it’s not as front-and-center as Apple puts it on their App Store. So it’s pretty likely that he prefers Android over iOS because Android let’s them collect all of this data without their users really knowing.
Don’t forget, that Threads is not available in Europe because of how much data it is collecting. Which means that they would be scrutinized a ton in the EU, and violate some privacy laws as well. So this statement by Mosseri might sound like he’s stirring the pot, but it’s really just lobbying on Meta’s own platform.
OWASP Foundation has released the 0.9.0 version of Critical Vulnerabilities in LLMs (Large Language Models).
A groundbreaking initiative has emerged to address the pressing need for educating developers, designers, architects, and other professionals involved in AI models.
AI-based technologies are currently being developed across various industries with the goal of revolutionizing long-standing traditional methods that have been in use for over three decades.
The scope of these projects is not just to ease the work but also to learn the potential capabilities of these AI-based models.
Organizations working on AI-based projects must understand the potential risks they can create and work on preventing the loopholes in the near future.
Threat actors leverage every piece of information they collect to conduct cybercriminal activities.
OWASP Top-10 for LLMs
As per the recent publishing of the OWASP 0.9.0 version, the top 10 critical vulnerabilities are as follows,
LLM01: Prompt Injection
This vulnerability arises if an attacker manipulates an LLM’s operation through crafted inputs, resulting in the attacker’s intention to get executed.
There are two types of prompt injections as direct prompt injection and indirect prompt injection.
Direct Prompt Injection
Indirect Prompt Injection
Direct Prompt Injection which is otherwise called as “jailbreaking” arises if an attacker overwrites or reveals the underlying system prompt resulting in the attacker interacting with insecure functions and data stores that are accessible by the LLM.
Indirect Prompt Injection occurs if the LLM accepts external source inputs that are controlled by the attacker resulting in the conversation being hijacked by the attacker. This can give the attacker the ability to ask the LLM for sensitive information and can get severe like manipulating the decision-making process.
LLM02: Insecure Output Handling
This vulnerability arises if an application blindly accepts LLM output without sanitization, which can provide additional functionalities to the user if the user provides a complex prompt to the LLM.
LLM03: Training Data Poisoning
This vulnerability occurs if an attacker or unaware client poisons the training data, which can result in providing backdoors, and vulnerabilities or even compromise the LLM’s security, effectiveness or ethical behavior.
LLM04: Model Denial of Service
An attacker with potential skills or a method can interact with the LLM model to make it consume a high amount of resources resulting in exceptionally high resource costs. It can also result in the decline of quality of service of the LLM.
LLM05: Supply Chain Vulnerabilities
This vulnerability arises if the supply-chain vulnerabilities in LLM applications affects the entire application lifecycle including third-party libraries, docker containers, base images and service suppliers.
LLM06: Sensitive Information Disclosure
This vulnerability arises if the LLM reveals sensitive information, proprietary algorithms or other confidential details by accident, resulting in unauthorised access to Intellectual Property, piracy violations and other security breaches.
LLM07: Insecure Plugin Design
LLM plugins have less application control as they are called by the LLMs and are automatically invoked in-context and chained. Insecure plugin Design is characterised by insecure inputs and insufficient access control.
LLM08: Excessive Agency
This vulnerability arises when the LLMs are capable of performing damaging actions due to unexpected outputs from the LLMs. The root cause of this vulnerability is excessive permission, functionalities or autonomy.
LLM09: Overreliance
This vulnerability arises when the LLMs are relied on for decision-making or content generation without proper oversight. Though LLMs can be creative and informative, they are still under developmental phase and provide false or inaccurate information. If used without background check, this can result in reputational damage, legal issues or miscommunication.
LLM10: Model Theft
This refers to unauthorised access and exfiltration of LLMs when threat actors compromise, physically steal, or perform theft of intellectual property. This can result in economic losses, unauthorised usage of the model or unauthorised access to sensitive information.
OWASP has released a complete report about these vulnerabilities which must be given as high priority for organisations that are developing or using LLMs. It is recommended for all the organisations to take security as a consideration when building application development lifecycles.