Newly Surfaced ThirdEye Infostealer Targeting Windows Devices

0
[ad_1]

While the ThirdEye infostealer is now in town, researchers have already identified several of its variants, all aiming at victims’ data.

FortiGuard Labs uncovered a not-so-sophisticated but highly malicious infostealer while analyzing suspicious files during a cursory review. They named this ThirdEye Infostealer. According to the report authored by Fred Gutierrez, James Slaughter, and Shunichi Imano, researchers became suspicious after spotting an archive file in Russian titled “Табель учета рабочего времени.zip“, which means “time sheet” in the English language.

This file contained two additional files, both with double extensions, including a .exe extension and another document-related extension. One of these files is titled “CMK Правила оформления больничных листов.pdf.exe.”

The title means “QMS Rules for issuing sick leave” in the English language. Further investigation revealed traits that researchers had previously seen in ThirdEye infostealer samples they had been detecting since early April 2023.

Various Versions of ThirdEye ThirdEye Infostealer Discovered

The earliest sample of ThirdEye infostealer was discovered on 3 April 2023 at 12:36:37 GMT. This sample collected client_hash,  OS_type, host_name and user_name and sent it to C2 server “(glovatickets(.)ru/ch3ckState)” with a custom web request header: Cookie: 3rd_eye=. It was submitted to a file scanning service on 4 April 2023.

A few weeks later, researchers found a variant which had a compile timestamp of 26 April 09:56:55 GMT. This variant collected additional data, including the BIOS vendor and release date, RAM size, CPU core number, user’s desktop files list, list of registered users on the device, and network interface data. However, this version crashes in some virtual machines.

One day later, they found a new variant with just one change: it used a PDF icon. This variant used “(ohmycars(.)ru/ch3ckState)” as C2 communications.

Later, another variant was found which gathered additional data such as total and free disk space on the C drive, domain name, network ports list, list of programs and version numbers, systemUptime, CD-ROM, drive letters volume information, currently running processes list, and programs installed in the Program Files directory.

Another file in the archive WAS titled “Табель учета рабочего времени.xls.exe,” which is a ThirdEye infostealer variant capable of performing the same activities.

Newly Surfaced ThirdEye Infostealer Targeting Windows Devices
Credit: FortiGuard Labs

Functionalities of ThirdEye Infostealer

in their blog post, FortiGuard Labs’ researchers revealed that ThirdEye Infostealer can steal system data from infected devices, including BIOS and hardware information. In addition, it can enumerate folder files, running processes, and network data.

Upon execution, the infostealer quickly gathers the data and transmits it to a C2 server hosted at “shlalala(.)ru/ch3ckState.” Apart from this, ThirdEye Infostealer does not perform any other function.

While researching, an interesting feature was noted – a string named 3rd eye, from which they derived the name of this malware family. The malware decrypts this string and uses it with another hash value to identify the C2 server. ThirdEye infostealer isn’t too sophisticated; however, it is evolving fast. Some recently collected samples stole more system data than the previously discovered versions.

Moreover, researchers noted that the infostealer targets Windows-based systems with a medium severity level. There is currently no evidence that ThirdEye Infostealer has been used in attacks.

However, since it is designed to collect data from compromised devices and systems, it can come in handy for cybercriminals in launching attacks. Researchers believe that all previous and latest variants of ThirdEye Infostealer are named in Russian, so the attacker is probably eyeing Russian-speaking organizations to deploy malware.

  1. Legion: SMS Hijacking Malware Sold on Telegram
  2. New Jupyter infostealer dropped through MSI installer
  3. Malicious ChatGPT Installers Distribute RedLine Stealer
  4. Infostealer Adrozek malware hits Firefox, Chrome browser
  5. New MacStealer Malware Targeting macOS Catalina Devices

[ad_2]
Source link

This flip phone concept has an E Ink cover display

0
[ad_1]

We’ve been seeing all kinds of concept smartphones in the last couple of years, but nothing like the one we’re here to talk about. This flip phone concept has an E Ink cover display… on the bottom.

This flip phone concept has an E Ink cover display, and it looks quite unique

Yes, you read that right. It not only has an E Ink display, but it has it in the bottom portion of the phone’s body. The designer seemingly placed it there so that it can take full advantage of that portion of the phone, without having to think about the rear cameras.

The device also has flat sides all around. Even though its corners are rounded, it has a boxy feel to it. A display camera hole is included on the main display, and it’s centered. The bezels are quite thin, around the main display.

This concept device is called ‘0/1 Phone’, and it has been designed by Andrea Mangone. He says that this phone, if real, would “help people disconnect from digital distractions and regain control of their lives”.

Using this phone would surely feel different to any other foldable

The designer says that this phone is supposed to cater to both regular users, and minimalists who want to use their phones to the very minimum. When the phone is closed, the layout for minimalists emerges thanks to the E Ink display, when you open it, you get access to a regular UI.

This phone also has two cameras on the back, which are included in a round camera island. You’ll also notice an orange tag on the left side, which complements this white-colored device nicely. That tag comes in other colors too, and it’s actually there not only for design purposes, that’s also where the SIM tray lies. All you have to do is pull on it, no SIM removal tool needed.

The designer also envisioned vegan leather on the upper portion of the phone’s back, around the rear cameras.

This phone will not become a reality, of course, but it’s still nice to see. In fact, it would be interesting to see something similar to it reach the market at some point. It would surely have something different to offer.


[ad_2]
Source link

Samsung TVs, monitors get improved color vision accessibility

0
[ad_1]

Samsung has added a new accessibility feature to its 2023 TVs and monitors. The big-screen devices are getting the company’s SeeColors mode, which allows viewers with color vision deficiency (CVD) to recalibrate the display colors of their devices for the best viewing experience. It offers various color settings based on degrees and types of CVD to ensure that everyone can easily distinguish colors on the screen.

Launched in January 2017, Samsung’s SeeColors mode originally debuted as a standalone app for smartphones. The company has since expanded it to TVs and monitors, integrating the service with the accessibility menus on these devices. This helps make the service readily accessible. While its newest TVs and monitors lacked this accessibility feature out of the box, a new software update will bring it soon.

The Neo QLED, QLED, OLED, Smart Monitor, and the G95SC gaming monitor lineups will get this update. To check for updates over the internet, press the Home button on your TV’s remote control and go to Settings. Now, navigate to All Settings and select Support. Finally, click on Software Update, followed by Update Now. If Software Update is greyed out, exit and change your TV source to Live TV and repeat the steps.

SeeColors mode offers nine picture presets. Users can browse through those presets and select the one that is most suitable for them. Depending on the selected picture preset, the feature adjusts the red, green, and blue levels of the screen. This enables viewers to distinguish colors easily regardless of the type or degree of their color vision deficiency. Samsung says the SeeColors mode is a commitment to accessibility under the vision of “Screens Everywhere, Screens for All.”

Samsung SeeColors mode has obtained “Color Vision Accessibility” certification

According to Samsung, its SeeColors mode received the “Color Vision Accessibility” certification from Cologne, Germany-based globally renowned testing organization TÜV Rheinland earlier this month. The certification acknowledges that the feature can “help those with CVD better enjoy content on Samsung screens.” The feature isn’t intended for use in the diagnosis or prevention of color vision deficiency, though.

“We are thrilled to introduce additional accessibility features, including SeeColors and Relumino mode, in our 2023 TV and monitor lineup to assist individuals with color blindness and low vision,” said Seokwoo Jason Yong, Executive Vice President of Visual Display Business at Samsung. “Under the vision of ‘Screens Everywhere, Screens for All,’ we will continue to innovate and bring inclusive technologies closer to our consumers.”

Samsung SeeColors mode TVs monitors 2


[ad_2]
Source link

Twitter introduces 25,000-character tweets for its Twitter Blue users

0
[ad_1]

Tweeting, or the art of sharing snippets of your thoughts, passions, and moments in real-time in just 280 characters, is not an easy job to master. However, Twitter Blue users can now breathe easily, as their tweets can be much longer, stretching up to 25,000 characters.

According to a tweet by Twitter employee Prachi Poddar (via Android Headlines), Twitter Blue users now have the freedom to compose posts up to 25,000 characters in length. Previously, paid subscribers were limited to 10,000 characters, which can still be a very long tweet. Since Elon Musk took over the company, numerous changes have been implemented, and tweet length is just one of them.

This update, which allows Twitter Blue users to express themselves in up to 25,000 characters, is likely to appeal to writers, journalists, bloggers, and anyone eager to share more detailed news, research, or articles. It’s important to note, however, that this change might diminish one of Twitter’s unique features, as its shorter posts have set it apart from other social media platforms.


Since Musk became the owner of Twitter, he has been actively seeking ways to make the company more profitable. One of his decisions was the introduction of a paid subscription known as Twitter Blue, which was launched globally in March. To attract an increasing number of paid users, Twitter continuously updates its service by adding new features, such as tweet editing.


Currently, Twitter boasts over 80 million users in the United States alone and a global user base of approximately 353 million. Interestingly, this represents a slight decline compared to the previous year. Thus, it comes as no surprise that the company is striving to update its platform and introduce new features to attract potential paid users. Hopefully, free users will also benefit from exciting updates in the near future.


[ad_2]
Source link

IBM QRadar SIEM Flaw Leads to XSS Attack

0
[ad_1]

IBM QRadar is a popular SIEM (Security Incident and Event Management) tool organizations use to detect and monitor threats.

The IBM QRadar SIEM can be used in the form of a physical appliance, a software-only solution, or a virtual appliance.

As of 2023, It is being used by over 1130 companies worldwide as part of their SIEM.

IBM discovered three new vulnerabilities in the IBM SIEM and CVEs, and necessary fixes were also released.

These vulnerabilities were related to Cryptography, XSS, and information disclosure which was discovered by IBM’s Security Ethical Hacking team.

IBM QRadar SIEM Flaw

CVE-2023-26276: Weak Cryptographic Algorithm

This vulnerability exists due to the use of a weaker or expected cryptographic algorithm in the QRadar tool, which could allow a threat actor to decrypt highly sensitive information.

This vulnerability was given a CVSS Score of 5.9 (medium)

CVE-2023-26274: Cross-Site Scripting (XSS)

An attacker can exploit this vulnerability to embed arbitrary JS code in the Web UI that can alter the functionality that can lead to credentials disclosure through XSS on a trusted session.

This vulnerability was given a CVSS Score of 4.6 (medium).

CVE-2022-34352: Information Disclosure

This vulnerability allows a delegated Admin tenant with a specific domain security profile to see other domain data.

This vulnerability was given a CVSS Score of 6.5 (medium).

Affected Products

ProductVersionRemediation/First Fix
IBM QRadar SIEM7.5.0 7.5.0 UP6

There are no workarounds or mitigations available. IBM recommended all its users patch their IBM QRadar SIEM by upgrading it to the latest version.

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.


[ad_2]
Source link

Software company accused of illegally profiling millions of mobile phone users

0
[ad_1]

A digital rights and privacy organization has filed a complaint against software company TeleSign for gathering and selling information on millions of mobile phone users.

A digital rights and privacy organization has filed a complaint against software company TeleSign for gathering and selling information on millions of mobile phone users.

The organization that filed the complaint is nyob. nyob is an Austrian based digital right organization that focusses on commercial privacy issues on a European level. After the General Data Protection Regulation (GDPR) came into force on May 25, 2018, commercial privacy violations can now be enforced on a European level, which allows for much more effective procedures and strategic litigation.

The complaint targets BICS, TeleSign, and Proximus. BICS is a Belgium-based communications service that enables phone calls, roaming, and data flows between different communications networks and services all over the world (500 mobile operators in more than 200 countries). Instead of having direct agreements with each other, hundreds of mobile phone providers can connect their networks through the interconnection service of BICS.

TeleSign is a US-based company that provides Application Programming Interfaces (APIs) that deliver user verification, digital identity, and omnichannel communications, to help other brands with secure onboarding, maintain account integrity, prevent fraud, and streamline omnichannel engagement. Among its customers are Ubisoft, ByteDance (TikTok), Skype, and Salesforce. 

Proximus is the Belgium based parent company of both BICS and TeleSign.

The problem

When processing phone customer data, BICS gets detailed information like the regularity of completed calls, call duration, long-term inactivity, range activity, and successful incoming traffic. And it receives these data for about half of the worldwide mobile phone users.

In 2022, Belgian newspaper Le Soir published an article about BICS sharing these data with TeleSign. Based on these data, TeleSign gave every mobile phone user a “trust score” between 0 and 300 points. This trust score helps their customers decide whether to allow users to sign up to a platform or, for example, require an SMS verification first.

According to Telesign’s website, it verifies over five billion unique phone numbers a month, representing half of the world’s mobile users, and provides critical insight into the remaining billions.

The data BICS shares includes information such as the type of technology used to make calls or texts, the frequency of activity, and the duration of calls.

nyob co-founder Max Schrems said:

“Your phone provider likely forwards data to BICS who then forwards it to TeleSign. TeleSign generates a ‘trust score’ about you and sells phone data to third parties like Microsoft, Salesforce or TikTok  – without anyone being informed or giving consent.”

While GDPR allows for sharing data for the purposes of taking appropriate, proportionate, preventive and curative measure and in order to detect fraud and malicious use of networks and services, nyob feels that this is not the case here.

From Max Schrems:

“The responses received by BICS and TeleSign suggest that this business model is not complying with EU privacy laws. We have therefore filed a complaint with the Belgian Data Protection Authority, who is competent for Proximus,  BICS and TeleSign.”

The lawsuit could end up to be very costly. The Belgian Data Protection Authority (DPA) can issue a fine up to 4% of the global turnover of Proximus, which is roughly $250 million.

EU citizens that want to know whether TeleSign has data on them, and has assigned them a score like the complainants, nyob has developed a template that you can use to send an access request to TeleSign. Companies holding data about you have the obligation under GDPR to tell you not just whether they process information about you, but also where they received the data, for which purpose they use it, and with whom they shared it.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Main Pixel Fold display & camera performance praised by DXOMARK

0
[ad_1]

DXOMARK has finished testing Google’s very first foldable phone, the Pixel Fold. As per usual, the company tested the display, camera, and audio performance of the device, and the Pixel Fold did really well.

The Pixel Fold display, camera, and audio performance got tested by DXOMARK

Let’s talk about the display first, shall we. In this category, the Pixel Fold shone the brightest. It actually managed to earn 151 points, which means it now takes up a joint top position in DXOMARK’s display rankings.

DXOMARK says that the display has “good, adapted brightness and contrast for HDR10 video content”. It also praised “good color management”, as colors seem to remain faithful for both still and dynamic content. Do note that the company is talking about the main display.

The company also said that the display offered “smooth interactions” in most use cases. You may notice stutters when browsing the web, with a slight jello effect. Things are not nearly as bad as on some other foldables, though.

The phone has the brightest display of any foldable DXOMARK tested

DXOMARK says that the Pixel Fold has the brightest display out of the foldables the company tested. The company tested max brightness of around 1,430 nits, making it rather easy to use in most environments. The crease is easily visible outdoors, though. Direct sunlight can also make things a bit difficult to read.

There was no mention of the cover display, though.

The phone’s camera performance was also good

The Pixel Fold cameras scored 133 points in DXOMARK’s test, which puts it in the 28th position. That doesn’t sound great, but do note that there are a lot of great camera smartphones out there that DXOMARK tested.

In the main category, the photo category, the phone did really well. The bokeh and zoom portions didn’t really shine all that much, but overall, the Pixel Fold has good camera performance.

DXOMARK notes that the phone’s cameras shine in the autofocus, exposure, and dynamic range departments, as expected. The company did not appreciate the noise that crept in low light environments, or the phone’s bokeh performance.

The company also noted that the phone did show some “instabilities in exposure and white balance” when it comes to video performance. The autofocus and video stabilization worked great.

The audio performance is also nothing to scoff at

DXOMARK also tested the audio aspect of the device. With a score of 133, the Pixel Fold ended up being placed in the 38th position. It is claimed that the Pixel Fold has the best audio performance of any foldable device DXOMARK tested.

The Pixel Fold offers a “pleasant sound signature” with its speakers. It seemingly performed best when music playback is concerned. It also did well with movie content and games, though.

DXOMARK says that the phone offers an “overall nice tonal balance”, which ends up resulting in good clarity. That goes for most musical content that DXOMARK tried. Dynamic performance is also good, notes the company. The speakers are also loud enough, but strong compression and significant distortion can be noticed at the highest volumes.

The best recording audio performance can be reached when using a selfie camera in the device’s folded state. The sound has an “accurate envelope, a sharp attack, and excellent signal-to-noise ratio”.

If you’d like to check out the full report by DXOMARK, click here.


[ad_2]
Source link

Things to consider before buying a smartphone in 2023

0
[ad_1]

The 21st century has witnessed a tremendous evolution in mobile phone development. Each year, big brands like Samsung, Apple, Xiaomi, and Oppo release flagship phones. The competition is fierce and each brand tries to outperform the other with every new release.

Smartphones have become so interactive that they play a significant role in everyday life. Therefore, in deciding which one to buy, many individual factors must be considered. Many stick to a specific brand for their excellent camera, while others consider features like performance, battery life, processor, durability, and, more importantly, cost.

In this current dispensation where mobile phones have become more than just call devices, we take you on a journey of the fantastic features that define the best brands.

Connectivity

Regarding connectivity, many things come to mind. 5G connectivity, Bluetooth, and Wi-Fi are the major connection features in modern phones. Particularly 5G connectivity is crucial as the world has moved past the era of Edge, 3G, and 4G networks. On average, 5G connections are theoretically 20 times faster than 4G LTE. With this speed, users can connect seamlessly and share data at unprecedented rates.

Many gamers can stream their favorite esports games like Call of Duty, GTA, and Need for Speed without issues. Likewise, if you fancy live dealer games like the ones on AustraliaOnlineCasinoSites, you need a stable 5G network to stream events from live studios worldwide. Hence, if you deal with a lot of media for uploads, you need a phone with 5G connectivity.

Screen and Display

The size of a screen is not a reflection of its quality. Instead, many people make their choices based on personal preference. However, the quality of that screen is what counts, and this is undoubtedly something to consider. There used to be IPS and LCD monitors, which are standard on mid-range and low-price phones. Biggest brands like Samsung and Apple now use AMOLED, OLED, and Super AMOLED panels.

Lately, some smartphones use a 2K display with high pixel resolution for a more realistic, balanced contrast and accurate color display. Thus, if you like watching videos on YouTube or Netflix.com or playing video games, you must get a smartphone with an exemplary screen display.

Cameras

Unless you are a professional photographer, the world has evolved past people going about with big cameras and a tripod to take pictures or film short videos. Mobile phones have become sophisticated in that they come with high-megapixel sensors that are comparable with professional cameras. For example, the Samsung Galaxy S22 launched with a 108 MP primary camera, and that was only just the beginning.

The most recent S23 has a massive 200 MP primary sensor with additional dedicated cameras that take excellent shots. Likewise, the iPhone is another smartphone with one of the best cameras. Unlike Samsung and other smartphones, they do not use high sensors but rely heavily on their software for processing excellent images and videos.

Therefore, if you take many photos for business or fun, you want a smartphone with an excellent camera setup.

RAM and Processor

Get all the good screen resolution, best camera sensors, and fast connectivity, if the processor and RAM aren’t up to the task, then it’s all for nothing. One of the many things that position the iPhone as the best camera is not the high sensors they use. Until the iPhone 14 Pro had the highest 45 MP sensor, previous versions only had a 13 MP triple camera setup. Even the Google Pixel maintained a single camera and still took some of the best shots on a smartphone, and it all comes down to the processor.

As for the RAM, it is what makes the entire phone operation seamless. Your ability to multitask, take great photos, transfer files, and enjoy fast uploads and downloads using the 5G connectivity depends on it.

Internal Storage

One of the popular trends with recent smartphones is that they do not allow for additional storage space. Before now, users could use SSD cards to boost the default internal storage. But, we can all agree that was the good old days when the internal storage was relatively small. Most high-end smartphones have internal storage of up to 1 TB, which is more than enough to handle any work.

With the quality of cameras and phone screen resolutions, a typical photo takes up to 10 MB. An average one-minute 4K video takes over 1 GB of storage, and some devices now support 8K. The best part is that these devices are available in different storage sizes, so you can choose one that suits your needs.

Battery

Before now, most phones could barely last a few hours of heavy usage. However, each phone manufacturer strives to improve battery performance with every new launch. From boosting the battery size to software optimization, most flagship smartphones can last several days which is excellent.

The best part is that they also consider the charging speed of these devices. Imagine charging your device from 0% to 100 in less than 30 minutes. Therefore, as you think about getting a phone with high screen resolution, good connectivity, an excellent camera, and all the other stuff, remember that you need the device running to enjoy these features.

Conclusion

Before buying a smartphone, first, you must have a budget. These high-end phones with massive specs do not come cheap. Based on your preference, you can make a list in order of your priority. Moreover, you can get more tips from androidheadlines.com for the latest trend in mobile technology.


[ad_2]
Source link

Cisco AsyncOS Flaw Let Remote Hackers Launch XSS Attack

0
[ad_1]

Cisco AsyncOS Software, used by Cisco Secure Email and Web Manager, Cisco Secure Email Gateway (previously Cisco Email Security Appliance; ESA), and Cisco Secure Web Appliance (WSA), has multiple flaws in its web-based management interface.

The vulnerabilities could allow a remote attacker to launch cross-site scripting (XSS) attack against a user of the interface.

What is XSS Attack?

Cross-site scripting (XSS) is an attack that lets hackers inject malicious javascript into the application or the website code.

When user input is not properly sanitized before being used in the generated output, a web page or web app becomes vulnerable to cross-site scripting attacks.

Cisco AsyncOS Software Flaw

Cisco said that “the vulnerabilities are independent of one another, exploiting one of the vulnerabilities is unnecessary before attempting to exploit another. “

Also, “a software release that is vulnerable to one of the vulnerabilities may not be vulnerable to the others,” Cisco added.

Products Affected

CVE-2023-20119: Cisco Secure Email and Web Manager – Reflected XSS

CVE-2023-20120: Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance – Stored XSS.

CVE-2023-20028: Cisco Secure Email and Web Manager and Cisco Secure Web Appliance – Stored XSS.

CVE-2023-20119: Cisco Secure Email and Web Manager

An unauthenticated, remote attacker could execute an XSS attack against a user of the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager due to a vulnerability.

Insufficient user input validation is the cause of this vulnerability. A user of a vulnerable interface could be tricked into clicking a forged link by an attacker.

 A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVE-2023-20120: Cisco Secure Email, Web Manager & Web Appliance

This vulnerability could allow an authenticated remote attacker to conduct an XSS attack against a user of the interface.

It is also an insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link.

If the exploit is effective, the attacker may be able to access private browser-based data or run arbitrary script code in the context of the exploited interface.

CVE-2023-20028: Cisco Secure Email, Web Manager, & Web Appliance

This vulnerability could also be able to allow an authenticated remote attacker to conduct an XSS attack against a user of the interface due to insufficient user input validation.

A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Updates & Workarounds

Cisco said there are no workarounds available to address these vulnerabilities, and users are recommended to consider software updates. According to PSIRT, there is no active exploitation of the vulnerability recorded.

Patches Released

Cisco released patches to fix the vulnerability;

Secure Email and Web Manager

Secure Email Gateway

Secure Web Appliance

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.


[ad_2]
Source link