Telly begins to ship out its free 55-inch 4K TVs

0
[ad_1]

Free Telly TVs are beginning to ship out to those who signed up for one, Variety reports. A little earlier this year, Telly announced it would be bringing a 4K TV to market that you wouldn’t have to spend a dime on. It waas basically free, but there was a catch. You had to sign up to receive one and there are only a limited amount of them. Which means not everyone was going to be a lucky recipient.

Getting the TV for free is also reliant on you agreeing to view and watch ads via the second dedicated display that sits below the main panel. Opting out of that agreement results in you having to pay up to $1,000 for the TV (the initial report in May says it could cost up to $500). Naturally, some were probably skeptical of opting into the situation. But even still it’s no doubt a tempting proposition as you get a free 4K TV with a 55-inch screen.

Telly has no confirmed that the TVs are just starting to head out of the warehouse and make their trip to those who were accepted to get one. So you’ll want to be on the lookout if you were one of those people. The company plans to ship around 500,000 of these TVs out, and says it received more than 250,000 signups. Which suggests there’s still more to go around.

Most free Telly TVs will ship out close to Black Friday

As mentioned only some of the TVs are starting to ship out. The first wave of TVs begins headed to consumers this week, while the majority of them will ship out around Black Friday.

The company doesn’t confirm a specific ship date for the larger portion of the TVs going out. But does mention that “there is no better Black Friday deal than free.” Suggesting this to be the timeframe when most can expect the TVs to show up. If you want to sign up for a free TV from Telly, it sounds like you may still be able to do so. But there’s a lot you have to agree to. So make sure to read all the fine print.


[ad_2]
Source link

YouTube announces quiz posts are coming to iOS and Android devices

0
[ad_1]

After spending several months in beta, the option to create quiz posts in the Community tab is finally rolling out to everyone on Android, iOS and the web. YouTube confirmed earlier today that quiz posts are launching to all devices where Community posts are supported.

This means that creators with access to the Community tab will now be able to create quizzes and viewers on Android and iOS devices can engage with them. Here is how you can add a quiz to your post:

  • Enter a question in the text field.
  • Enter answers in the “Answer” fields. Answers can be up to 80 characters each.
  • If you need more answer fields, tap Add answer. You can have up to 4 answers.
  • Select the correct answer. You can add an optional explanation for why this is the correct answer in the text field. Explanations can be 350 characters max.

It’s important to mention that you can only have one correct answer on these quizzes, which makes perfect sense if you want to use these as educational tools. The announcement comes days after YouTube confirmed that it has started testing AI-generated quizzes on mobile. A small number of YouTube users are now part of an experiment that shows AI-generated quizzes on their Home feed. Of course, there’s no telling when these AI-generated quizzes will be made available for everyone nor if YouTube plans to really go ahead with this controversial feature.

[ad_2]
Source link

Red Menshen APT Group Deploying BPFDoor in Linux Kernel

0
[ad_1]

APTs Red Menshen expands targets to Linux and cloud servers, as seen in ransomware attacks on VMware ESXi, Mirai botnet variations, and cloud-focused stealers and crypto miners.

APT groups extend focus beyond Windows, signified by Sandworm’s attacks on Linux-based routers. Unlike cybercrime malware with broad targets, APT malware prioritizes persistent stealth and routine maintenance.

Red Menshen, an APT group active in the Middle East and Asia, continuously enhances the BPFDoor backdoor, utilizing Berkeley Packet Filter (BPF) to evade Linux and Solaris OS firewalls. 

Cybersecurity researchers at Trend Micro identify the Linux and Solaris variants as Backdoor.Linux.BPFDOOR and Backdoor.Solaris.BPFDOOR.ZAJE, respectively, with added monitoring and detection patterns.

Red Menshen advances BPF filters, increasing instructions six-fold, indicating active development and successful deployment of BPFDoor.

Workflow of BPFDoor

The intriguing technical aspect of BPFDoor lies in its kernel-level loading of packet filters, commonly known as BPF or LSF in Linux, representing the same underlying technology.

BPFDoor’s BPF filters enable backdoor activation with a single network packet, bypassing firewalls by leveraging the kernel’s BPF engine, and this rootkit-like capability sets it apart from typical backdoors.

BPFDoor variants employ classic BPF filters, with Linux samples using SO_ATTACH_FILTER and Solaris samples utilizing libpcap functions for runtime filter loading.

When a packet with the magic number arrives, BPFDoor connects back to the source IP, establishing a distinct identifier-based communication.

A privileged reverse shell is established by BPFDoor, enabling remote command execution by the attacker through a pipe connection to the infected machine’s shell.

Activation of BPFDoor backdoor (Source – TrendMicro)

The samples of BPFDoor across 2018-2022 feature a uniform BPF program accepting unique magic numbers for the following protocols:-

BPF program instruction old (Source – TrendMicro)

The BPF program in these samples comprises 30 instructions, which measure the filter’s complexity, reads the report shared.

On the affected systems, there are three distinct packets that trigger the activation of the backdoor, and here below, we have mentioned them:-

  • UDP packet containing the magic number 0x7255 at the data field
  • ICMP ECHO (ping) packet containing the same 0x7255 magic number at the data field
  • TCP packet containing the magic number 0x5293 at the data field

Experts identified four telfhash-supported samples introducing a 4-byte magic number for TCP packets, resulting in a new BPF program with 39 instructions.

BPF program instruction New (Source – TrendMicro)

In 2023, three samples utilized an enhanced BPF program with 229 instructions, specifically validating ICMP packets as ICMP ECHO requests.

Targets of Red Menshen APT

Here below, we have mentioned the countries targeted using BPFDoor:-

Here below, we have mentioned the industries targeted using BPFDoor:-

  • Telecommunication services
  • Financial services
  • Other services

Incorporating BPF bytecode into malware poses a new complicated hurdle for security experts. So, the BPFDoor’s evolving filters indicate threat actors’ efforts to enhance stealth and evade detection.

Updating rules and diving into BPF filter analysis promptly is advised for network defenders and malware analysts.


[ad_2]
Source link

Threads’ user engagement has dropped off since launch

0
[ad_1]

Threads made waves when it first launched last week, amassing over 100 million users since then. It even prompted Twitter Elon Musk to speak out (and potentially sue Meta). While that’s the case, Threads’ user engagement has dropped off a bit since its launch.

The platform is very similar to Twitter; it brings the same mentality, at least. People are able to post their quick thoughts and augment them with images and videos, and GIFs. It doesn’t resemble Twitter; it resembles Twitter before Elon Musk took over. This is one reason why people flocked to the new platform.

But, Threads’ user engagement dropped off a fair bit

Several sources are looking into Threads’ numbers, and they’re reporting a post-honeymoon dip, according to CNBC. Sensor Tower, one of the sources reporting on Threads saw that on Tuesday and Wednesday this week, the number of daily active users was down about 20% from Saturday. Also, those who were on the platform spent about half as much time- 10 minutes spent on the app down from 20 minutes.

Another firm, Similarweb, also has analytics; however, these are only for the Android app. Statistics for the iOS app should come soon. Based on the company’s data, Threads had 36.6 million users on Monday.

Similarweb showed that it peaked on July 7th. Between that day and this Monday, Threads lost about 25% of its daily active users. Between July 6th and July 10th, time spent on the app dropped from 20 minutes to about 8 minutes. That’s a 60% drop.

Should Meta be worried?

Meta’s Threads broke records and became the fastest-growing social media platform ever. But now, we’re seeing a pretty notable dropoff. Should the company be worried?

No. It’s natural for a new platform to see a dropoff as time goes on. People spent more time getting used to it and seeing what it’s all about. After time passes, it moves into the back of people’s minds as they go on with their day. This happens to other apps.

We also can’t rule out the fact that some people just found the app is not their thing. There are people who prefer other platforms and uninstalled the app. At this point, there’s still a fair number of things that you can’t do on Threads.

So, this dropoff is just the initial excitement deflating. After a few weeks, we might get an idea of the average user engagement that Threads is going to see over the following years. As time goes on, Threads will see peaks and drops in its numbers as Meta adds more features.


[ad_2]
Source link

Anthropic launches Claude 2, the next-gen of ‘friendly’ AI chatbot

0
[ad_1]

Ever since ChatGPT kicked off the AI revolution, other tech companies have been hard at work trying to develop the next evolution of generative AI. Now, in a recent development, Anthropic, the company founded by former OpenAI research executives, has released the next generation of their conversational chatbot, Claude 2, following a $750 million investment.

While similar in concept to Google’s Bard or OpenAI’s ChatGPT, Claude sets itself apart with its conversational tone and added humor. Additionally, the new version also allows for longer and more detailed responses while improving its skills in math, coding, and reasoning. Moreover, the company also highlighted the fact that the new chatbot outperformed its predecessor, scoring 76.5% on the multiple-choice section of the bar exam compared to Claude 1.3’s score of 73%.

Furthermore, addressing recent concerns about chatbots generating harmful and manipulative content, Anthropic claims that Claude 2 is twice as effective at providing harmless responses, reducing the risk of generating harmful content during interactions.

“We really feel that this is the safest version of Claude that we’ve developed so far, and so we’ve been very excited to get it into the hands of a wider range of both businesses and individual consumers,” said Daniela Amodei, co-founder of Anthropic.

Not connected to the internet

Although Claude 2 shares similarities with the Bing AI chatbot, it is not connected to the internet and is trained on data up until December 2022. As a result, the chatbot does not have access to the latest information or developments. However, it’s worth mentioning that its dataset is more up-to-date than the free version of ChatGPT, which cuts off in 2021.

Analyzing books and papers

Another notable feature of Claude 2 is its contextual understanding, which can accommodate approximately 75,000 words. This not only allows users to upload lengthy documents, such as novels or research papers, for analysis by Claude but also helps them quickly obtain summaries of complex texts and documents.


[ad_2]
Source link

Beware of Weaponized TeamViewer Installer that Delivers njRAT

0
[ad_1]

Threat actors relying on legitimate, well-known software TeamViewer for exploitation has been a very common scenario.

There have been several cases where threat actors used well-known software to deliver malware to the victims.

Similarly, a recent report from Cyble Research & Intelligence Labs stated that the most popularly used remote desktop support software, “TeamViewer” has been exploited by threat actors to deliver njRAT malware.

Other software that was delivering njRAT malware include Wireshark, Process Hacker, etc.,

njRAT is a remote access trojan that can perform keylogging, password stealing, data exfiltration, accessing webcams, and microphones, downloading additional files, and many others.

It was first discovered in 2012 and was attacking organizations in Middle Eastern nations. 

Weaponized TeamViewer Installer

The Initial level of compromise for njRAT involves traditional methods like phishing campaigns, cracked software on file-sharing websites, and drive-by downloads. In addition to this, the malware is now being distributed via trojanized applications.

njRAT malware dropped on the Windows Folder (Source: Cyble)

Once the malware is executed, it drops two files on the C:\Windows folder in which, one of them is the njRAT malware.

The Installer then triggers the malware “TeamViewer Starting.exe” and eventually launches the legitimate “teamviewer.exe” application.

During the installation of TeamViewer, njRAT simultaneously starts the installation by copying itself to the \AppData\Local\Temp folder with the name “system.exe.”

It then executes the newly dropped file, and njRAT creates a mutex.

Post Exploitation and Persistence

njRAT modifies the “SEE_MASK_NOZONECHECKS” environment variable in Windows, which prevents security warning prompts or dialog boxes from being presented to the user, thereby operating without any hindrance.  

njRAT autorun entries in System Registry (Source: Cyble)

Furthermore, the malware also changes the Firewall regulation to allow communications with the C2 (Command and Control) server. 

The malware creates two autorun entries in the system registry to maintain persistence in the system. 

The malware then collects information about Keystrokes, Windows OS version, service pack, webcam information, the current date, username, system architecture, and specific registry keys.

It stores all of this information in the “%appdata%/temp” folder under the filename “System.exe.tmp”.

Indicators of Compromise

Indicators Description 
224ae485b6e4c1f925fff5d9de1684415670f133f3f8faa5f23914c78148fc31Trojanized Teamviewer
9b9539fec7d0227672717e126a9b46cda3315895
11aacb03c7e370d2b78b99efe9a131eb
9bcb093f911234d702a80a238cea14121c17f0b27d51bb023768e84c27f1262asystem.exe/ TeamViewer Starting.exe
b2f847dce91be5f5ea884d068f5d5a6d9140665c
8ccbb51dbee1d8866924610adb262990
hxxp://kkk[.]no-ip[.]biz                      C&C

[ad_2]
Source link

Worried about Android OS updates? Google has a solution

0
[ad_1]

Every year, a new version of Android comes out, but not all of us are quick to install it. Some people really want to know what they’re getting themselves into when they tap Install. Well, Google is working on an Android upgrade invite system that will better show you what features you’ll be getting.

Most people in the tech world hear about all of the rumored features and additions coming with a new Android version. However, that’s not the case for everyone. Some don’t know what’s coming with the new version, so it can be a bit of a shock when something changes that they don’t like.

This is where the Android upgrade invite program comes in

This program will make it easier for OEMs to show what features they’re bringing in the latest update. Currently, the user will see a changelog for the update. While that’s useful, some people would like a more visual representation.

When an update is pending, the OEM will be able to send a notification to the user’s phone. When they tap on this notification, they’ll get a visual representation of the new features rather than just text. Mishaal Rahman posted a screenshot of the user flow that this could involve.

When you tap on the notification, you’ll see an intro screen- most likely saying something like “See what exciting features are in Android…”. After that, you might get a succession of screenshots showing you the new features that are present in the new version. After that, you’ll get an outro screen. You might actually be able to install the update from the notification.

This program is part of Google Play Services, so it’s only available on devices with Google Mobile Services. That’s something to keep in mind.

Another thing to keep in mind is that, while Google is distributing this, it’s dependent on the OEM. So, depending on the OEM, you might not see this feature. Also, it will look or behave differently depending on the OEM.


[ad_2]
Source link

The iPhone 15 could be the most AI-oriented iPhone Apple has ever released

0
[ad_1]

While Apple will never come out and say “AI”, it has been using AI in its products and services for quite some time. In fact, it’s now using a LLM for autocorrect in iOS 17 (and it’s a huge upgrade!). Now, moving onto the iPhone 15 and the Health app in iOS 17, Apple could be using a whole lot of AI.

This comes from industry insider, Dan Ives, who claims that Apple is going to emphasize the role of artificial intelligence on the iPhone 15 a whole lot more. Though, don’t expect Apple to say that it is using artificial intelligence. Apple tends to not use names of things that other companies use. Like 120Hz, AI, Machine Learning, and even VR on the new headset it debuted at WWDC.

There’s hints that AI is coming to the Health app as well, and it could be a game-changer, says the insider. Basically, after enough time and number of interactions between the user and machine, AI would be able to give personalized recommendations about the person’s everyday life. For example, how you workout and even the ability to suggest a diet. And these plans would be based on collected information such as heart rate, sleep, and breathing data. Things that Apple Health already has.

iPhone 15 could use AI to get to know your moods

One thing that the iPhone 15 could do is, using AI to get to know what mood you’re in. This could be possible on the iPhone 15 due to the phone tracking a user’s speech and/or text messages. It’s still unclear how else this would work, or why it could be limited to the iPhone 15.

While the iPhone 15 is likely going to look the same on the outside, it looks like there’s going to be a lot of changes internally that could make this the year to upgrade to a new iPhone.


[ad_2]
Source link

BreachForums’ Pompompurin Pleads Guilty to Holding Child Abuse Content

0
[ad_1]

The court document described the disturbing content as “videos depicting prepubescent minors and minors who had not attained 12 years of age engaging in s**ually explicit conduct.”

Conor Brian Fitzpatrick, known by his online aliases Pompompurin and Pom, a 2021 graduate of Peekskill High School, was arrested in March 2023, for his involvement in operating the notorious hacker and cybercriminal platform called BreachForums. The arrest has also revealed a disturbing link to another illegal activity involving child abuse images.

Court documents (PDF) seen by Hackread.com shed light on the dark secrets hidden within Fitzpatrick’s digital possessions. It has been discovered that his devices contained over 600 explicit images of child abuse, leading him to plead guilty in court.

The court document described the disturbing content as “videos depicting prepubescent minors and minors who had not attained 12 years of age engaging in sexually explicit conduct.”

BreachForums Admin Pompompurin Pleads Guilty of Holding 600 Child Abuse Images

This new development was first reported by Dissent Doe of the Databreaches blog. It then went viral on Twitter when vx-underground, an online library for malware samples, tweeted about it.

BreachForums Admin Pompompurin Pleads Guilty of Holding 600 Child Abuse Images

The trial for Pompompurin, as he is known online, is scheduled to commence on November 17th. However, he is subject to strict restrictions, including no access to computers, no contact with minors, no browsing of websites focused on data leaks and no usage of virtual private networks (VPNs).

It is worth noting that the arrest of Fitzpatrick came in the wake of the apprehension of Diogo Santos Coelho, the owner and administrator of Raid Forums in the United Kingdom. BreachForums, which emerged as a reincarnation of Raid Forums, was seized by the FBI (Federal Bureau of Investigation) in their crackdown against cybercriminal activities.

Despite the intervention, a new version of BreachForums has recently resurfaced, now under the control of the infamous ShinyHunters group.

BreachForums and its predecessor, Raid Forums, have long been known as platforms where hackers and cybercriminals gather to exchange stolen data, hacking techniques, and illicit tools.

These forums have been a cause of concern for law enforcement agencies worldwide due to their role in facilitating various cybercrimes, including data breaches and identity theft.

The emergence of a new incarnation of BreachForums, led by the notorious ShinyHunters group, raises alarm bells for cybersecurity experts. The ShinyHunters group has been involved in high-profile cyberattacks, often targeting corporations, government entities, and financial institutions. Their expertise and influence within the hacking community make them a formidable force to reckon with.

As the trial of Conor Brian Fitzpatrick approaches, many await the legal proceedings with a sense of urgency. The case not only highlights the dangers posed by cybercriminal forums but also sheds light on the dark underbelly of illegal activities involving child abuse imagery.

Hackread.com will continue to closely follow this case and provide updates as more information becomes available.

Note: Hackread.com encourages readers to report any suspicious online activities related to child abuse imagery to the appropriate law enforcement authorities.

  1. 5 Ways to Ensure Your Child’s Online Safety
  2. Authorities seize world’s biggest dark web child abuse site
  3. Data Breach at New BreachForums: 4,000 members’ data leaked
  4. Gender Diversity in Cybercrime Forums: Women Users on the Rise
  5. Raidforums Database Leak: Data of 460,000 Users Dumped Online

[ad_2]
Source link

Here’s the new emoji coming to iPhone and Google Pixel in 2024

0
[ad_1]

There’s new emoji heading to a smartphone near you in 2024. The new Emoji 15.1 specification from the Unicode Consortium has just been announced and will be improved around September. That means that they will likely be part of iOS 17, and potentially a feature drop for Android phones later this year or next year – more likely, next year.

The emoji that’s listed by Emojipedia are currently proposed and under consideration, however it’s important to note that most emoji that make it to this stage, are eventually approved and make it into the official release. There are some sample designs of the proposed emoji, which is what you see in the picture above. So these are very likely not going to be the final versions.

108 new directional emoji are coming

As if we didn’t have enough emojis already, there are 108 new directional emojis on the way. Now most of these consist of people emoji with different skin tones. The emoji build on existing person walking, person running, person kneeling, person with white cane, person in manual wheelchair, and person in motorized wheelchair emoji. There’s also adding orientation directions like left and right.

Once the Emoji 15.1 characters are finalized in September of 2023, other smartphone manufacturers like Apple, Google, Samsung, etc, with adapt them through software updates. We’ve seen this before with both Google and Apple. Google will typically add them onto the Pixel through a Feature Drop. Other OEMs will need to add them, in their software updates. So not all Android devices will get them at the same time.

The last set of approved emojis came to the iPhone with iOS 16.4 in February 2023. And the last set landed on the Google Pixel in January with QPR3 Beta 2, and later was made available to all Pixel devices in March. When that feature drop was made available.


[ad_2]
Source link