Apple has recently released new Rapid Security Response (RSR) patches to fix a zero-day vulnerability. This vulnerability has been exploited in attacks and affects iPhones, Macs, and iPads that have been fully patched.
The zero-day vulnerability has been tracked as CVE-2023-37450, and this vulnerability was identified by an anonymous cybersecurity researcher.
The new Rapid Security Response (RSR) program if Apple rolls out a second patch, fixing a critical zero-day flaw across various Apple products like:-
iOS for iPhone
iPadOS for iPad
macOS Ventura for Mac
Safari for macOS Big Sur and Monterey
Apple WebKit Zero-DayFlaws
Apple’s silence leaves the reason undisclosed, but Safari glitches emerged after user-agent detection failure for Zoom, Facebook, and Instagram, impacting website rendering.
Rapid Security Response updates swiftly deliver zero-day fixes for iPhones and Macs, prioritizing critical patches over regular OS updates for user protection.
RSR updates alter user agents on iOS devices, appending the “(a)” string to the new updates as follows:-
iOS 16.5.1 (a)
iPadOS 16.5.1 (a)
macOS Ventura 13.4.1 (a)
Soon after Apple’s patch release for CVE-2023-37450, users encountered access errors on several websites post-installation, prompting complaints.
Apple acknowledges Rapid Security Responses impacting website display, so they will soon fix it with the upcoming updates:-
iOS 16.5.1 (b)
iPadOS 16.5.1 (b)
macOS 13.4.1 (b)
Remove Buggy Security Update
While the users who have already installed the buggy security updates on their Apple devices and while browsing the web face any issues, make sure to remove the updates from your device.
To do so, you have to follow the simple steps that we have mentioned below:-
Open the Settings app on your iPhone or iPad.
Scroll down and tap on “About.”
Look for the “iOS Version” option and tap on it.
On the iOS Version page, locate and tap on “Remove Security Response.”
A confirmation prompt will appear. Tap on “Remove” to confirm the action.
That’s it; now you are done.
The below-mentioned steps are for Mac:-
First of all, you have to click on the Apple logo or menu located in the top left corner of the screen.
From the dropdown menu, select “About This Mac.”
In the “About This Mac” window, click on “More Information.”
Next to the macOS version number, you will see an Info (i) button. Click on it.
A new window will appear with additional details about the macOS version.
In the new window, look for the “Remove” option and click on it.
A confirmation dialog box will appear. Click on “Remove” to confirm the action.
Once the removal process is complete, now you will be prompted to restart your Mac.
Click on “Restart” to restart your Mac.
That’s it now, you are done.
Apple’s WebKit browser engine carries this zero-day flaw (CVE-2023-37450), enabling arbitrary code execution through targeted web pages with manipulated content.
In total, there are ten zero-day vulnerabilities that were fixed by Apple this year for its following product line:-
Zero-days Fixed this Year by Apple
Here below, we have mentioned all the Zero-days fixed this year by Apple this year:-
Apple’s flawed Rapid Security Responses risk user resistance if issues persist, damaging the intended purpose of swift patch deployment.
After some time of waiting, we’re finally able to try out Threads, Meta’s answer to Twitter. People are cracking into the app, and they’re finding out all of the stuff that they can do. On the opposite side of that coin, they’re also finding out what they can’t do in Threads. Here’s a rundown of those things.
This isn’t meant to turn you away from the app. By all means, try it out and see what “Zuck” has up his sleeves. One thing to note, however, is that you should expect the app to add functionality over time. There are things you can’t do now, but that might not be the case a couple of months or even weeks from now. Just keep that in mind.
Before we get started, what is Threads?
In case you’re not familiar with this app, this is Meta’s version of Twitter. It’s a social media app that’s tied to Instagram, according to the company. However, there’s not much tying it to Instagram outside of the fact that you can log in with your Instagram credentials.
It follows the Twitter formula closely. You can make text-based posts, and they’ll be presented on an ever-scrolling feed. Along with text, you’re also able to post photos and videos.
What you can’t do in Meta’s Threads
So, you just downloaded Threads and you’re one of the over 100 million people threading along. That’s all fine and dandy. However, in this early stage of the platform, you’re going to quickly realize that there are some things that you won’t be able to do.
No DMs: Sorry, no sliding today
One core aspect of social media is being able to quickly and easily send a message to another person or group. This is why all major social media platforms have a DM (Direct Messaging) function. However, Threads doesn’t let you message other people as of yet.
That’s weird seeing as Instagram has a DM function, and Threads and Instagram are conjoined twins. It’d be nice if Meta could give us a messaging function for Threads.
However, since Threads and Instagram are so closely related, it’d be neat if the company could give us a unified messaging experience. If your Threads messages and Instagram messages could exist in the same inbox on both apps.
When you open your inbox on either app you’ll have a tab that will show just your Instagram messages and a tab that just shows your Threads message. There could also be a tab that shows both. We’ll have to wait to see what Meta plans to do.
Post GIFs from your keyboard: You have to work for it…
We all know that GIFs are like a second language to most of us. We’re able to post them on Twitter as an illustrated response to someone’s hot take. Recently, people gained the ability to post them on Instagram. When it comes to Threads, you can post them, but there’s a catch.
You’re not able to post them straight from your keyboard. Digital keyboards like Gboard have a GIFs tab that provides GIFs for you to insert with a single tap. If you try to do so, you’ll be met with disappointment.
How to insert GIFs
You can insert GIFs into your Threads and replies, but it just involves a few extra steps. You will need to download the GIF from the internet and insert the GIF as an attachment. You’ll want to search for the GIF using the search engine of your choice. Save the GIF to your device. Just make sure you’re downloading the actual .gif file and not a jpeg or png.
After you download the file, go to the Threads app and start your post or reply. Tap on the little paperclip icon under the text field. The app will then bring up the media picker UI. After you insert the GIF, you should be able to see it moving before you actually post it.
If you’re using Gboard, then this process will be a bit easier. Search for the GIF you want in the GIF tab on the Gboard. Tap on it. You’ll get the error message, yes, but you’ll see the “Go to link” icon appear over the GIF you tapped- the box with a little arrow pointing outward. Tapping on it will bring you to the actual URL of the GIF. Hold your finger on the GIF and save it. The rest of the process will remain the same.
See a timeline of just those you follow: We get it, celebrities exist!
Sorry to break this to you, but just like with other social media sites, you’re fighting the algorithm with Threads. It’s tough for the little guy to get noticed on social media. Most people post photos and videos to a handful of views while others wrack up millions. One unfortunate thing about this is that celebrities, influencers, and famous content creators are a shoo-in to gain millions of followers, views, likes, and comments.
In the case of Threads, it’s much the same. When you sign into Threads, you’ll be greeted by a feed of mostly super famous people. You’ll see celebrities and influencers who you didn’t even follow. You’ll see their follower count skyrocket by the second while yours doesn’t as fast.
However, Instagram fixed its feed issue by offering a Followed feed. This is something that people want to see from Threads. The super famous individuals already have millions of followers across the internet. Threads is a new platform, a chance for a new start, and probably a new community of people. It’s a bit of a smack to the face having the same thing happen as with other platforms.
Trim videos: You have to use other apps… darn
Threads gives you the ability to post pictures and videos. You can post videos up to several minutes in length, but if you exceed the maximum length for a video, you won’t be able to quickly trim the fat to make it fit.
After you select the video from your media library, you’ll just get a preview of the video, and that’s it. If you tap on the video, you’ll be brought back to the media picker UI. Also, if the video is too long, it seems that the app will attempt to upload it and give you a “Failed to upload” message. Hopefully, the app will allow you to trim your videos.
Edit photos: Zuckerberg, are you sure this is an Instagram app?
Threads is an Instagram app, and it’s heavily riding its parent app’s coattails. However, if you’re planning on uploading an image, then you’ll be met with a bare-bones experience. You’re not able to crop your photos before posting them. Also, you’re not able to add filters or make any adjustments.
AH Instagram Logo 1 newAH
You’re given a rudimentary photo editing experience on Instagram. You’re able to crop your photo, adjust the colors and brightness, apply effects, and more. Hopefully, Threads will inherit some of Instagram’s photo editing prowess.
Delete your account without deleting your Instagram account: Ride together, die together
Everyone experiences buyer’s remorse (or the equivalent of signing up for an account only to find out that you hate it), and we’ve found ourselves searching for the “Delete account” button from time to time.
In the case of Threads, if you decide that you don’t want to keep your account around, the only way that you can get rid of your Threads account is to delete your Instagram account in the process. That’s a bummer.
It feels like Meta built Threads off of Instagram just to rush it to the market and capitalize on Elon Musk going down with the ship. Thus, Threads might be so tied to Instagram that they’re basically conjoined. If that’s the case, then Meta dropped the ball.
The company stated that it’s looking for a way for users to delete accounts separate from one another. It seems odd that the company is trying to figure this out for its own app. In any case, you can expect this feature eventually.
The Pixel Fold is a great looking foldable, perhaps one of the best looking ones on the market these days. But, you’re going to want to protect it, or at least make it your own. And that’s where dbrand leather comes into play. It’s a great way to make the Pixel Fold your own, without making it more bulky. It’s a foldable, so it’s already fairly heavy.
dbrand isn’t new to making skins, it’s been around for many, many years now. And it has a ton of options available for the Pixel Fold. But I really like their leather skins. This particular one is the real brown leather skin (I also have it on my MacBook Air). It also comes in real Tan and real Black colors. It costs $34.95. Which is about what you’d pay for a case.
The cool thing with dbrand is the Grip Case. So if you wanted to get a case instead, you can do that. With the Grip Case, you get to choose any skin you want, to go on that case. So you could really make that case your own. It also comes with a kickstand along the hinge of the case, making it really nice. But let’s get back into the leather skin.
dbrand’s leather will patina over time
What’s great about this skin is that it’s going to patina over time. It will take a few months to really see a big difference in how it looks, but it will look great. dbrand does offer Leather Balm to help hurry up the patina process though.
With the Pixel Fold, dbrand does give you two pieces of leather. One for the back of the phone and another for the camera bar. Honestly, I’ll probably remove the camera bar skin, as I think it looks cleaner with just the back in leather. But overall, it does look really nice.
You can pick your own leather skin for the Pixel Fold (and many other devices) by clicking the link below.
The race among tech giants in the Artificial intelligence domain is reaching new heights, and Google is turning up the heat with its project, Bard. The company is taking Bard to the next level by expanding its availability to the European Union (EU) and introducing a range of new features.
Previously, Google Bard was only available in the US and the UK. Privacy concerns prevented it from being available in the EU. Still, now that Google has changed its rules to say that it can use information that is already available to the public to help teach its computer programs how to do things, Bard is entering the EU market as well.
Google Bard can now talk
In addition to its EU expansion, Bard is also evolving its linguistic capabilities and speech recognition. Google shares that users can now experience spoken responses by entering a prompt and selecting the sound icon. This feature supports over 40 languages and is already live.
Google Bard introduces image integration
Google is also unveiling an exciting new feature that allows users to enhance their interactions by incorporating images into prompts. Users can now ask the chatbot to provide explanations, funny captions, or relevant quotes that complement the image. Although this feature is currently only available in English, Google plans to extend it to other languages soon.
Bard adds pinning, renaming, and sharing features
Google is also introducing a few other new features, including the ability to pin and rename conversations, which means you can now pick up where you left off with your past Bard conversation. ChatGPT has had this option since the begging so it was about time for Bard to catch up. Now you can also share responses with others, and change the tone and style of the answers you get back from Bard.Bard is still in its early stages, but it’s clearly growing and getting smarter. And yes, I know it is not human, I mean come on, in just a few months, it’s learned to speak 40 languages and has a bunch of new features. This proves one thing, in the battle between OpenAI’s ChatGPT and Google Bard, you have to be fast if you don’t want to drop out of the game.
While Amazon’s Prime Day did technically end on July 12th a 11:59PM PT, there are still quite a few discounts on products after Prime Day. So in this post, we’ll be rounding up the best Prime Day deals that are still available. And the best part, most of these do not require you being a Prime member.
So what kinds of deals are still available? Tons of them. That includes some great deals on Samsung monitors, on Nest products, Samsung storage and so much more.
Best Prime Day deals available after Prime Day
A few of the deals that caught our attention was the iRobot Roomba robot vacuums that are on sale. These include the Roomba i3+ which is now $399, down from $549. There’s also the Braava Jet m6 on sale for $349. And if you’re a pet owner, the iRobot Roomba j7+ is also on sale for $649, saving you a cool $150 here.
The Pixel lineup is also still on sale at incredibly low prices. This includes the Google Pixel 7a going for $449, and the Pixel 7 at $499. Unfortunately, the Pixel 7 Pro and Pixel Buds are no longer on sale. But these are still some really good deals on the Pixel 7a and Pixel 7.
Those that are looking for a new TV, Sony has you covered here. It’s A80L OLED TVs are on sale starting at $1,,698. Which is not bad for a high-end OLED TV, to be quite honest. Sony’s Mini LED TVs are also discounted to $1,998. If you’re looking for something a bit cheaper, there’s the X80K series which is now down to just $778. That’s a pretty good price for a high-end 55-inch TV.
These are just some of the very many Amazon Prime Day deals available still today, and you can check out more here. If you need an Amazon Prime free trial, you can grab that here (students get 6-months free, here).
SonicWall has recently published a security notice in which 15 vulnerabilities were fixed.
CVEs for these vulnerabilities have been published, and patches for 4 Critical, 4 High, and 7 Medium severity vulnerabilities have been patched as per the notice.
These Vulnerabilities let attackers inject SQL queries and bypass authentication.
This vulnerability exists in the application database due to improper neutralization of SQL injection commands that allow an attacker to exfiltrate sensitive information. This vulnerability has a CVSS Score of 9.8 (Critical).
This vulnerability exists in the SonicWall GSM and Analytics Web Services, which had insufficient checks that led to authentication bypass. The CVSS Score for this vulnerability is given as 9.4 (Critical)
This vulnerability exists as SonicWall GSM and Analytics Web Services uses static values for authentication without proper checks which leads to authentication bypass. The CVSS Score for this vulnerability is given as 9.4 (Critical).
This vulnerability exists in the SonicWall GSM and Analytics Web Services due to improper neutralization of special elements for commands used in OS command injection, allowing an attacker to execute arbitrary code with root privileges. The CVSS Score for this vulnerability is given as 8.8 (High).
This vulnerability exists due to the Use of Hard-coded Cryptographic keys in the SonicWal GSM and Analytics Web Services. The CVSS Score for this vulnerability is given as 7.5 (High).
This vulnerability allows an authenticated attacker to upload files to the filesystem of SonicWall GSM and Analytics Web Services with root privileges. The CVSS Score for this vulnerability is given as 7.1 (High).
CVE-2023-34129: Post-Authenticated Arbitrary File Write via Web Service (Zip Slip)
This vulnerability allows an authenticated attacker to traverse to a restricted directory and extract arbitrary files to any location on the filesystem with root privileges using the Zip Slip method. The CVSS Score for this vulnerability 7.1 (High).
Google has just announced a big update to the Google Play Store policy, specifically for Android apps. This update allows app developers to include digital assets, like Non-Fungible Tokens (NFTs), in their apps.
If you wonder what NFTs are, well they are like certificates that prove you own something unique in the digital world, such as art, music, or virtual items. NFTs work using a technology called blockchain, which keeps track of who owns what. NFTs allow, for example, artists and creators to sell their digital creations directly to fans, and collectors can own and trade these one-of-a-kind digital items.
In a recent blog post, Google (via Android Authority) emphasized the importance of being transparent with users about these tokenized digital assets. It wants developers to clearly inform users if their apps contain these digital assets.
Google is serious about preventing any promotion or glorification of potential earnings from playing or trading activities. The company wants to protect users from sketchy practices and prevent the spread of questionable NFT apps in the Play Store.
The updated guidelines are to make sure that apps follow the existing policies for Real-Money Gambling, Games, and Contests. Apps must meet certain requirements and should not involve money transactions that allow users to win assets of unknown real-world monetary value, including NFTs. Google discourages the use of random blockchain-based items, like the controversial “loot boxes,” which have raised concerns about fairness and transparency.
While these new policies set important rules, they also encourage innovation in the app development community. Google’s Group Product Manager, Joseph Mills, mentioned the exciting possibilities this update brings. Developers now have the freedom to create unique gaming experiences by incorporating user-owned content and rewarding users with special NFTs to increase their loyalty.
Google will introduce the changes gradually to make the transition smooth and gather valuable feedback. Initially, a selected group of developers will be given the chance to offer apps and games containing blockchain-based digital content in Play Store. Ongoing partnerships will be established to test how users interact with these digital assets and improve the user experience.
The July 2023 Patch Tuesday update bundle patched at least six different actively-exploited vulnerabilities across different Microsoft products. In all, the update bundle addressed 132 different vulnerabilities.
Six Zero-Day Flaws Addressed With July Updates
While keeping the systems updated with the latest security fixes is always critical, the July updates are crucial for Microsoft users. That’s because Microsoft released patches for six zero-day vulnerabilities addressing different components.
Microsoft kept one of the six CVEs down for the public (until the time of writing this story). But it disclosed the details about the five other vulnerabilities under attack. All of these vulnerabilities bear important severity rating.
These include two privilege escalation flaws, each with CVSS 7.8, in Windows MSHTML Platform (CVE-2023-32046) and Windows Error Reporting Service (CVE-2023-36874), two security feature bypass (SFB) vulnerabilities, each with CVSS 8.8, affecting Windows SmartScreen (CVE-2023-32049) and Microsoft Outlook (CVE-2023-35311), and a single remote code execution vulnerability (CVSS 8.3) in Office and Windows HTML (CVE-2023-36884). Microsoft has even admitted public disclosure of this vulnerability before a fix could arrive.
Other Microsoft Patch Tuesday Updates For July 2023
Alongside the zero-days, Microsoft addressed over 100 other vulnerabilities with July Patch Tuesday. These include 9 critical severity issues and 116 important severity vulnerabilities.
Among these, the most notable security fix addressed a remote code execution vulnerability in Microsoft Message Queuing (CVE-2023-32057). An attacker may exploit this flaw by sending maliciously crafted MSMQ packets to an MSMQ server.
Besides releasing the patch, Microsoft has also shared a workaround to mitigate this issue, which involves blocking TCP port 1801. According to Microsoft’s advisory, users may review the Control Panel settings, look for “Message Queuing” among running services, and check whether the TCP port 1801 is listening.
The July update bundle includes no security fix for any low-severity vulnerabilities. The extent of security fixes and the high severity of all flaws indicate the importance of this update bundle. Hence, while the updates would reach all eligible devices automatically, users should still check for any updates manually to receive all security fixes in time.
The OWASP Zed Attack Proxy is a widely used tool for conducting web application penetration testing. It is free and open-source.
ZAP functions as a proxy between the tester’s browser and the web application, intercepting and scrutinizing messages.
ZAP is a tool that serves various professionals, from developers to security testing specialists, as well as those who are new to security testing.
ZAP 2.13.0
The new release of ZAP 2.13.0 adds support for HTTP/2, improved authentication handling, and Mac Silicon.
Starting from ZAP version 2.13.0, HTTP/2 is supported by default; no configuration changes are required.
The new version also enhances authentication handling, which helps auto-authenticate many web apps by just supplying the login page URL along with the credentials.
The latest update now allows support for Mac Silicon in the installer and docker images. You can obtain the docker images from the GitHub Container Registry.
New Scalable Options
“All of the “attack” tools which use threading, including both spiders and active scanner, have been changed to use 2x the number of processors as the default number of threads,” reads Zap release notes.
The network Rate Limiting feature enables pentesters to limit the request rate of HTTP/HTTPS and avoid overloading.
New scan rules have been added with ZAP that allow pentesters to scan for popular vulnerabilities such as;
New Add-Ons
Selenium add-on has been updated to use the Selenium v4 library.
Along with Selenium Authentication Helper released, which helps testers to identify and set up authentication with ZAP.
A complete list of enhancements and fixes can be found here.
During the initial half of 2023, a notable surge occurred in attacks exploiting infected USB drives for secret theft.
While the USB-based operation campaigns caused most incidents, impacting both public and private sectors worldwide.
Cybersecurity analysts at Mandiant Managed Defense recently observed two cyber espionage campaigns that are based on USB flash drives.
Security researchers dubbed the two campaigns as:-
SOGU Malware Infection
SNOWYDRIVE Malware Infection
We have provided comprehensive information about two USB-based attacks that hackers are currently using to target both public and private organizations.
SOGU Malware Infection
This USB-based cyber espionage attack is highly widespread, targeting public and private sectors globally, making it one of the most aggressive campaigns across industries.
SOGU malware loaded via USB flash drives that steal sensitive information linked to China’s TEMP.Hex actor, likely driven by national security and economic motives, reads the report.
In Europe, Asia, and the United States, there are various industries face risks from these operations, and here they are mentioned below:-
Construction
Engineering
Business services
Government
Health
Transportation
Retail
Entertainment
Manufacturing
Education
Finance
Logistic
Non-Proit
Media
Communications
IT
Energy
Pharmaceutical
Geographic distribution (Source – Mandiant)
The infected USB flash drive acts as the initial infection vector, housing multiple malicious software triggering DLL hijacking to load a malicious payload into memory.
SOGU Malware Infection Chain (Source – Mandiant)
There are three files that the complete infection chain contains and here they are mentioned below:-
A legitimate executable
A malicious DLL loader
An encrypted payload
Upon running the legitimate executable, it side-loads the KORPLUG DLL, initiating the execution of decrypted shellcode (.dat file) associated with the SOGU backdoor, identified by Mandiant.
After dropping a batch file on the RECYCLE.BIN path, the infection proceeds with host reconnaissance, storing the results in a file named “sys.info” (decoded from Base64 as c3lzLmluZm8).
The malware disguises itself as a genuine program by creating a hidden directory to ensure its continued presence on the system.
To communicate with its command and control server, during the final attack stage, the malware exfiltrates staged data via the following custom binary protocols over TCP/UDP, ICMP:-
SNOWYDRIVE Malware Infection
Using USB flash drives, this campaign deploys SNOWYDRIVE malware, establishing a host backdoor for remote command execution, while also infecting other flash drives and spreading across the network.
UNC4698, an oil-focused cyber threat, was identified as a campaign source by Mandiant. This campaign was detected for the first time during the Windows Explorer process execution hunt, revealing suspicious folder path (e.g., “F:”) often linked to USB drive malware execution.
As the initial infection vector, the infected USB flash drive is used, and the victim is enticed to click on the malicious file disguised as a legit executable, triggering the malicious executions for the attacker’s objectives.
The infection chain begins with an executable dropper that writes and launches malicious files. The extracted executables and DLLs from the encrypted files are written to the specified directory:-
C:\Users\Public\SymantecsThorvices\Bin
There are four components that comprise these files, which are loaded through DLL search order hijacking, with each containing a legitimate executable and a malicious DLL.
Execution chain (Source – Mandiant)
SNOWYDRIVE backdoor generates a unique ID from system info for C2 communication, with a hard-coded domain in shellcode. While the persistence is achieved through the “KCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ushsguaei1hgba” registry value storing the “Silverlight.Configuration.exe” path.
Malware duplicates onto plugged-in removable drives, forming “<drive_root>\Kaspersky\Usb Drive\3.0” folder and storing encrypted malicious files. Extracted executable “aweu23jj46jm7dc” writes to <drive_root><volume_name>.exe, handling decryption and execution of file contents.
Organizations are strongly urged to prioritize access restrictions on external devices, like USB drives, or conduct thorough scans for malicious files prior to the network connection.