10 Best Practices to Enhance Office 365 Security

0
[ad_1]

Cloud service providers fundamentally changed the way we do business in 2023. Office 365 is one of the most popular cloud-based services catering to online businesses.

The suite’s advanced collaboration and productivity features make it a go-to service for businesses that want to transition digitally. But digital transformation is anything but smooth sailing.

Despite more businesses adopting these technologies, the increased adoption paints a target on their back. Namely, hackers and threat actors understand the value of Office 365 and similar services.

Considering these solutions can hold insurmountable amounts of data, it becomes a priority to enhance Office 365 protection.

But is Microsoft capable of protecting sensitive data, and what can we do to make our environments more secure? This article will discuss the ten experts’ best practices to enhance Office 365 security and promote a safe and secure environment. Let’s begin.

Enable MFA (Multi-Factor Authentication)

Office 365 Security

One of the most effective ways to strengthen Office 365 security is by enabling Multi-Factor Authentication. MFA improves the suite’s security by requesting additional verification from users.

The verification methods can be a one-time passcode from an authentication app, a fingerprint scan, or an email code.

So in case a threat actor has managed to compromise employees’ credentials, they would still require additional verification for full access to Office 365.

As a result, MFA is one of the more reliable security features in Office 365, capable of preventing unauthorized access to the suite and improving your organization’s security posture.

Enable Data Loss Prevention (DLP) Policies

Office 365 Security

DLP is another potent security feature found in the Security and Compliance Center. With DLP, we can create policies to allow organizations to identify and protect sensitive information within Office 365.

The way DLP works is through rules and conditions. Administrators can define rules and conditions to detect and prevent the unauthorized sharing or leakage of confidential data, such as financial records, personally identifiable information (PII), or intellectual property.

By implementing data loss prevention policies, businesses ensure compliance with data protection regulations and minimize the risk of data breaches. For example, suppose an employee is sending financial records through email.

In that case, a DLP policy can alert them of potentially sending confidential data and, in many cases, prevent them from doing so in the first place.

Utilize Advanced Threat Protection (ATP)

Office 365 Security

ATP is a standout security feature capable of protecting the suite against all kinds of malware and threats sent primarily through email. Advanced threat protection is part of Microsoft Defender for Office 365.

The feature aims to strengthen email accounts, defend against emerging phishing attacks and advanced threats, and utilize artificial intelligence and machine learning to stop email-based security threats. In addition, ATP is capable of stopping zero-day exploits.

With ATP, businesses use industry-leading AI that scans attachments, documents, and links to identify threats.

Enabling ATP can significantly enhance your defense against sophisticated cyber attacks, safeguarding your organization’s sensitive information.

Regularly Update and Patch Office 365

Office 365 Security

When it comes to utilizing the best practices and measures for Office 365 protection, we cannot forget the importance of updating the suite with the latest security patches.

Microsoft regularly releases updates that address vulnerabilities and strengthen the platform’s overall security.

Security updates are essential for a number of reasons, including anti-phishing protection, preventing security exploits from one of the many applications, and enhancing advanced protection.

As a general rule, tenant accounts should have auto-updating enabled. However, it is not enabled by default.

Admin accounts can go into each tenant and enable auto-updating to maintain a secure environment free of potential security exploits.

Educate Users on Security Awareness

Despite the numerous features available to you in Office 365, cyber threats can bypass your security measures and compromise your organization’s sensitive data.

Moreover, no matter how much we try, hackers find all kinds of ways to gain access to the suite and wreak havoc. In most cases, this is down to human error.

Human error remains a significant factor in security breaches. Without them even knowing, your employees are active targets for hackers and threat actors.

Therefore, educating them about security best practices and raising awareness about potential threats becomes essential.

You can conduct regular training sessions that cover topics such as recognizing phishing attempts and stopping phishing attacks, creating strong passwords, and exercising caution while sharing sensitive information.

Empowering your users with knowledge will help create a security-conscious culture within your organization.

Monitor and Analyze User Activities

Office 365 security allows you to implement robust monitoring and auditing capabilities. With the Unified Audit log feature, you can track user activities, identify suspicious behavior, and detect potential security breaches.

The monitoring features allow you to identify unauthorized login attempts, file access, and other user actions to respond to any anomalies and mitigate security risks effectively.

Employ Data Encryption

Encryption is yet another data protection and security feature and a critical aspect of the Office 365 suite. Encryption allows you to protect sensitive data by encrypting it both at rest and in transit.

Office 365 provides two encryption options that can be enabled to protect your data from unauthorized access.

Lastly, encryption works on emails, documents, and other files, adding an extra layer of security, even if they fall into the wrong hands.

Regularly Back up Office 365 Data

While Office 365 comes with built-in data redundancy features, it is still essential to have a comprehensive backup strategy in place.

Accidental deletion, retention policy gaps, malicious actions, and outages can result in costly data loss events.

Therefore, implementing a backup solution that periodically backs up your Office 365 data to an external location will prevent critical data loss and ensure you have access to the latest version.

Restrict External Sharing and Access

Review and configure external sharing settings in Office 365 to ensure that sensitive data is not inadvertently exposed to unauthorized users.

Utilize features like Azure Active Directory (Azure AD) Conditional Access and go into your Exchange Online configuration settings to control access to Office 365 services based on specific criteria, such as user location, device compliance, or IP address.

With these features, you create rules and external access policies to protect your Microsoft Office environment and ensure people only the access they need to perform their tasks.

Conduct Regular Security Assessments

Lastly, you can never be sure your Microsoft environment is fully safe if you don’t perform regular security assessments.

Through security assessments and penetration testing, we can identify vulnerabilities and weaknesses in Office 365 and take the appropriate actions to address them.

Conclusion

Enhancing Office 365 security is crucial for organizations to mitigate the ever-evolving cyber threats that target cloud environments. Fortunately, the Office 365 suite comes with advanced and robust security features.

But it requires an understanding of these features to ensure they’re implemented accordingly. These ten experts’ best practices and tips will help you do just that.


[ad_2]
Source link

Amid Galaxy S23 FE rumors, Samsung to re-launch Galaxy S21 FE

0
[ad_1]

As the Galaxy S23 FE starts to take shape, Samsung appears to be preparing to re-launch the Galaxy S21 FE, at least in one market. The device will reportedly hit the Indian market with a different chipset next month. Not an entirely new processor, though. The company will seemingly bring the existing Snapdragon variant of the phone to India.

Like many other Samsung flagships launched in recent years, the Galaxy S21 FE also comes in two processor variants. Some markets got Qualcomm’s Snapdragon 888 SoC, while the phone shipped with the Korean firm’s in-house chipset Exynos 2100 in some others. As you might have guessed, buyers in India got the latter variant.

But a year and a half after the original launch in January 2022, Samsung is reportedly gearing up to re-launch the Galaxy S21 FE in India. This time, it will sell the Snapdragon variant in the South Asian country. The information comes courtesy of Twitter user @tarunvats33, who claims to have verified it with Samsung’s retail channels.

According to the source, Samsung plans to price the Snapdragon 888-powered Galaxy S21 FE at around ₹40,000 (roughly $490) in India, with sales beginning in July. As of this writing, the Exynos 2100 variant starts at ₹32,999 (roughly $400), though it was selling for even lower a few months back (during Samsung’s sales period).

The Snapdragon-powered Galaxy S21 FE would compete against the Galaxy A54 5G

At its rumored price, the “new” Galaxy S21 FE would cost as much as the Galaxy A54 5G in India. While it may be a no-brainer to pick the former, the latter benefits from being a newer device. It ships with Android 13 out of the box and will get updates until Android 17.

Since Samsung is essentially bringing an existing phone to India, it may not treat the Snapdragon-powered Galaxy S21 FE as a new device in the market. Hence, it is unlikely to arrive with Android 13 or any other changes. It’ll already be a year and a half old the day it hits store shelves in the country.

However, if Samsung goes the extra mile and re-launches the Galaxy S21 FE as a new phone powered by a new processor, it will easily cannibalize the sales of the Galaxy A54 5G. But, we have little hope. The company may be trying to clear the inventory from markets where it sold the phone with the Snapdragon chip. If the rumored timeline for the Galaxy S21 FE’s re-launch in India is accurate, we may hear more soon.


[ad_2]
Source link

Reddit issues final warning to moderators of private subreddits

0
[ad_1]

Reddit may have just issued a final warning to moderators of subreddits that are still private. The company has reportedly given those moderators a deadline to confirm if they plan to reopen the communities. The deadline ends later today. The firm hasn’t revealed the next course of action for moderators who keep their Reddit communities closed beyond the deadline. But it has previously threatened to remove those who don’t comply with guidelines defined by the Moderator Code of Conduct.

“Per Rule 4 of the Moderator Code of Conduct, moderators are required to be active and engaged within their communities. Given this, we encourage you to reopen. Please let us know within the next 48 hours if you plan on re-opening,” part of the message moderators received from a Reddit admin reads. “This community remaining closed to its members cannot continue,” the admin added in a separate note to one of the biggest Reddit communities that is still private, The Verge reports.

“Wanting to take time to consider future moderation plans is fine, but that must be done in at least a ‘restricted’ setting. This community will not remain private beyond the timeframe we’ve allowed for confirmation of plans here,” the Reddit admin warned. Another moderator was told that continued violation of the rule “will result in further action.” It sure looks like a final warning. Today’s deadline is notable because several subreddits recently wrote an open letter to the company for a response to their demands and concerns by June 29, i.e., today.

The Reddit community wants third-party apps back

The said open letter asks Reddit to “commit to exploring ways by which third-party applications can make an affordable return,” among other things (via). Several popular Reddit apps are shutting down at the end of this month due to the company’s API updates that require them to pay a hefty fee (about $20 million a year for some) to continue their operations. The firm has so far shown little regard for public disappointment. CEO Steve Huffman has been critical of third-party developers as well as moderators protesting the changes.

More than 8,000 subreddits went dark or private in a mass protest that began on June 12. Most have since re-opened or at least switched from private to restricted. But some moderators are still fighting. Reddit has been pushing them to reopen, threatening to replace moderators who don’t comply. Some have given in under pressure, but the company wants all subreddits back to normal as if nothing happened. It remains to be seen what’s to come next. Reddit’s proposed API updates will go into effect on July 1, 2023.


[ad_2]
Source link

Snapchat convinced more than 4 million people to pay for its subscription service

0
[ad_1]

Back in August, Snapchat announced that 1 million users have decided to pay for its subscription service. Fast forward almost one year and the social company revealed Snapchat+ has more than 4 million subscribers.

It’s an interesting evolution considering that Snapchat+ gained 1 million subscribers only two months after launch. At just $3.99 per month, Snapchat+ offers exclusive features that aren’t available in free version of the social app.

To make things even more appealing for its users and justify the monthly fee, Snapchat promised to bring new features to its premium service quite often. In the last year, Snapchat+ subscribers received access to more than 20 features, including custom app themes, unique app icons, as well as the ability to pin their #1 BFF.

Today’s announcement regarding the number of Snapchat+ subscribers also includes details about what’s coming for those who pay for the subscription service. Apparently, Snapchat plans to add “expressive chat messages” to Snapchat+ in the not-so-distant future. These are messages that allow users to express themselves using big reactions or small notes. Basically, Snapchat+ subscribers will be able to change the font size of their messages.

In addition, custom chat colors will be coming to Snapchat+ too, allowing users to pick the hue want to use when they message their friends. These two upcoming features are teased on Snap’s official website, so check them out if you’re paying for Snapchat+ or plan to become a subscriber.

[ad_2]
Source link

Top 25 Most Dangerous Software Weaknesses

0
[ad_1]

The top 25 most dangerous software weaknesses impacting software for the previous two calendar years have been published by MITRE as part of the 2023 Common Weaknesses Enumeration (CWE).

Attackers can utilize these flaws to seize control of a vulnerable system, steal data, or disrupt the functioning of certain programs. Because of these flaws, software becomes seriously vulnerable.

“These weaknesses lead to serious vulnerabilities in software. An attacker can often exploit these vulnerabilities to take control of an affected system, steal data, or prevent applications from working,” CISA advised.

Software defects cover a wide variety of problems, such as holes, bugs, weaknesses, and mistakes in the architecture, implementation, code, or design of software solutions.

With a focus on the CVE records added to CISA’s Known Exploited Vulnerabilities (KEV) database, MITRE evaluated 43,996 CVE entries from NIST’s National Vulnerability Database (NVD) for vulnerabilities discovered and reported across 2021 and 2022 to compile this list.

Each weakness was then given a score based on its severity and prevalence.

Following the gathering, scoping, and remapping stages, a scoring formula was used to determine the weaknesses in order of severity. 

This formula takes into account both the frequency (the frequency with which a CWE is the primary cause of a vulnerability) and the average severity of each vulnerability when it is exploited (as determined by the CVSS score), according to MITRE.

Both frequency and severity are normalized concerning the maximum and minimum values recorded in the data set.

Top 25 Software Weaknesses

RankIDNameScoreCVEs in KEVRank Change
1CWE-787Out-of-bounds Write63.72700
2CWE-79Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)45.5440
3CWE-89Improper Neutralization of Special Elements Used in an SQL Command (‘SQL Injection’)34.2760
4CWE-416Use After Free16.7144+3
5CWE-78Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)15.6523+1
6CWE-20Improper Input Validation15.5035-2
7CWE-125Out-of-bounds Read14.602-2
8CWE-22Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)14.11160
9CWE-352Cross-Site Request Forgery (CSRF)11.7300
10CWE-434Unrestricted Upload of File with Dangerous Type10.4150
11CWE-862Missing Authorization6.900+5
12CWE-476NULL Pointer Dereference6.590-1
13CWE-287Improper Authentication6.3910+1
14CWE-190Integer Overflow or Wraparound5.894-1
15CWE-502Deserialization of Untrusted Data5.5614-3
16CWE-77Improper Neutralization of Special Elements Used in a Command (‘Command Injection’)4.954+1
17CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer4.757+2
18CWE-798Use of Hard-coded Credentials4.572-3
19CWE-918Server-Side Request Forgery (SSRF)4.5616+2
20CWE-306Missing Authentication for Critical Function3.788-2
21CWE-362Concurrent Execution using Shared Resources with Improper Synchronization (‘Race Condition’)3.538+1
22CWE-269Improper Privilege Management3.315+7
23CWE-94Improper Control of Generation of Code (‘Code Injection’)3.306+2
24CWE-863Incorrect Authorization3.160+4
25CWE-276Incorrect Default Permissions3.160-5
Top 25 Most Dangerous Software Weaknesses

The list highlights the most prevalent and significant software flaws at the moment. These can result in exploitable vulnerabilities that enable adversaries to take over a system entirely, steal data, or stop apps from running.

They are frequently simple to detect and exploit. Successful exploitation can provide attackers access to sensitive data, exfiltrate the data, or cause a denial-of-service (DoS) on the targeted computers.

CISA urges developers and product security response teams to analyze the CWE Top 25 and assess suggested mitigations to choose the ones that are most appropriate for adoption.

“CISA encourages developers and product security response teams to review the CWE Top 25 and evaluate recommended mitigations to determine those most suitable to adopt”, CISA said.

“Over the coming weeks, the CWE program will be publishing a series of further articles on the CWE Top 25 methodology, vulnerability mapping trends, and other useful information that help illustrate how vulnerability management plays an important role in Shifting the Balance of Cybersecurity Risk”.

Additionally, CISA, the FBI, the Australian Cyber Security Centre (ACSC), and the UK’s National Cyber Security Centre (NCSC) all released a list of often exploited issues for 2020.

A list of the top 10 most often exploited security issues from 2016 to 2019 has also been provided by CISA and the FBI.

The most hazardous programming, design, and architectural security issues that affect hardware systems are also listed by MITRE in a list.

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.


[ad_2]
Source link

How to enter Full Screen Mode on Motorola Razr+ (2023) External Display

0
[ad_1]

One of the more unique features about the new Motorola Razr+ is the fact that you can run entire apps on the outer display. Unlike other flip-style foldables, the Razr+ is almost all screen on the outside, and even has cutouts for the cameras. Allowing you to run apps on a 3.6-inch 1:1 aspect ratio display.

Now, yes, it’s pretty cramped there. Especially since Motorola does have a status bar on the bottom that lines up with the cameras. However, you can enter full screen mode, and get a bit more display space on that external display. And in this tutorial, we’re going to show you how exactly you can do that.

How to enter Full Screen Mode on Motorola Razr+

There are two ways that you can use Full Screen mode on the Motorola Razr+. One way is pretty easy, while the other is a bit tough. We’re going to go over both ways, however.

Firstly, you can long-press on the status bar at the bottom, and in the right spot, it’ll enter full screen mode. In my experience, this is almost impossible to do. As you do need to do it in the correct spot, for it to work.

The second way to do this is, swipe up from the bottom to enter the Recents screen, like you would on the full screen. Below the app, you’ll see an option for “Full Screen”. Just tap on that, and you’ll be put into full screen mode. Giving you just a bit more space to get things done on that external display.

Screenshot 20230629 102837 Medium

If you want to jump out of full screen mode, you can do this in two ways. The easiest way is going to be to lock your device, and then unlock it. Or you can again swipe up to get into Recents, and tap on “Default View”.

Screenshot 20230629 102845 Medium

The Razr+ will automatically default to the “Default View” each time you unlock it. Unfortunately, there’s no way to set the Razr to automatically open apps in full screen on the external display. The thought process here is likely that, you won’t want to always do this. But in a pinch, you can make it happen.


[ad_2]
Source link

Top 5 web development languages 2023

0
[ad_1]

Web application development is the hottest employment market ever, according to the press. With demand for outsourced web development services rising 14% yearly, it’s little surprise so many tech businesses are spending hard on making sure their technology is competitive.

Job seekers who wish to take advantage of digital transformation’s ability to boost creativity and efficiency must know programming languages. This article discusses the advantages of learning various programming languages and lists our top web development options for 2023.

2023’s Best Web Development Languages

Website construction has progressed. HTML, CSS, ASP, and Adobe ColdFusion used to build websites. Today, organisations construct websites utilising JavaScript, PHP, Python, CSS3, and HTML5. This article discusses 2023’s top web development languages.

Web programming languages

Programming languages let you write computer and web programmes. Java, Python, PHP, and JavaScript are the most popular programming languages. Programming languages vary by development kind. The general-purpose programming languages vary in design, testing, and debugging.

Web programmers fall into two categories. Front-end development creates the interface. The layout and browser-based interface code are designed, developed, and deployed. Server-based back-end development comprises data architecture, development, and deployment.

1. Front-end Development

Front-end development software produces the UI for most web development applications. HTML and CSS codes may design material and add graphics, clickable sections, links, and other helpful features to sites. This front-end development paradigm creates the user interface while preserving the backend code.

2. Backend Development

The back-end development paradigm creates content. This time, you must learn JavaScript, Python, and maybe server-side programming. You’ll also need to understand AI and machine learning methods as much of the material will be developed utilising them. Server work dominates.

3. Full-stack Development

Full-stack developers know front-end and back-end programming. User interface development and server-side programming will be understood. They will organise code utilising many technologies. Full-stack developers have the most growth potential.

Top 5 web development languages

Today, organisations construct websites utilising JavaScript, PHP, Python, CSS3, and HTML5. This article discusses 2023’s top web development languages.

1. HTML & CSS

Creating a website requires coding. Thus, HTML and CSS knowledge is needed. Shortcodes can format most materials. Files in your server’s /www/ directory include these codes. Ask your server administrator where these files are.

HTML and CSS are the most used markup languages worldwide. They make Webmastering easy for developers. JavaScript requires a deeper grasp of HTML and CSS. Few people can develop code with these tools. Fortunately, many additional languages function well with HTML and CSS.

Websites began with HTML. Websites developed with language. CSS and HTML together form a webpage. HTML websites utilise CSS to format information, style navigation, headers, footers, and more. CSS styles pictures, links, and tables. HTML merely styles text.

2. JavaScript

You’ve reviewed the greatest programming languages for web development in 2023, but you haven’t covered the one most websites use. You’ll examine JavaScript’s changes and why.

JavaScript & ES6 Basics for Beginners with Problem Solving and Projects

Modern web app development uses JavaScript. It is an easy-to-learn scripting language for beginners and experts. This language lets anybody build webpages. JavaScript lets you build anything from a portfolio to an application. With proper coding, JavaScript can accomplish almost anything.

JavaScript is a popular programming language. It’s simple and flexible, making it ideal for web development. JavaScript lets you build complex websites and apps like those on your desktop or laptop. JavaScript is quick, making it ideal for web applications and online transactions. JavaScript is ideal for building quick, appealing websites.

3. Python

Python has unequalled flexibility. It is a high-level, general-purpose programming language. It creates websites, web apps, and mobile apps. It has a strong developer community and several successes. It is simple to learn and contains many libraries and tools to help programmers. It handles dynamic material well, making it a popular website backend programming language. The CLDC standard is widely used. Its ease of use makes it a great learning tool.

Python’s syntax and object-orientation make it ideal for website development. Object-oriented programming is best for beginners. It will improve your programming understanding. Python supports current web frameworks and technologies well. It has several useful libraries and utilities. Its syntax is clear and straightforward to understand and write. User-friendly testing and debugging procedures are included in.

Python’s online learning is a plus. There are several online Programming courses in qatar

and programmes. Developers may speak and exchange code in many groups and social media networks.

Python runs on everything, another fantastic feature you may not know about. It operates on smartphones and supercomputers! Python runs on any device. Its adaptability allows for various uses. Your website may talk live. Mobile apps may become decentralised web browsers. Voice-activated purchasing is possible with your web app. This great programming language can do anything.

4. PHP

PHP is popular for web development. It may be used to create basic webpages or sophisticated apps and is straightforward to learn. PHP can do many jobs well. Its popularity stems from its suitability for web development.

PHP includes several programming choices. It can construct practically any website. It manages, develops, and analyses. Its syntax is straightforward and adaptable. It may be used to make apps for scheduling sports teams and managing budgets. A huge community provides help and resources for novice developers.

PHP’s simplicity makes it great. There are several online training programmes that teach PHP concepts and development. This popular programming language has many functionalities, so you’ll never be bored.

5. On Rails

Web application frameworks are not new. Its invention predates 15 years. No one ever considered integrating web and application frameworks into one. Web application frameworks are just that. It helps construct web apps. Language is undoubtedly the most renowned instrument. Ruby on Rails is a general-purpose language for experienced web developers. Simple but effective syntax.

Ruby on Rails simplifies web app development. It’s simple to learn and uses Python syntax. It’s fantastic for web development since you don’t have to learn a new language for each website. Ruby on Rails can also build complicated websites. A functioning website requires a lot of code and can handle vast quantities of data. Ruby on Rails is easy if you know Python.

Web development career reasons

Web development is booming. Web developers are in demand as websites, companies, and apps grow. Web development interest has grown 50% in the previous five years. Web development is adaptable and complex and may be applied in many sectors. It builds websites, apps, and mobile apps.

Web developers require programming abilities, web design and development expertise, and web standards knowledge. Web development is considered the ideal job for web designers and developers. Successful web developers have the proper abilities and expertise.

Web development future

Web development is promising. With new technology and business models, web developers will become more important. As online payment options improve, web development companies will include them. E-commerce companies will need the newest technology to satisfy clients as online buying grows.

Customers nowadays prioritise site speed while shopping. Time is money, and customers are pleased when purchases are processed quickly. Thus, new web programming technologies will emerge daily, requiring expertise to apply it. Thus, web programmers will be in demand.

Web development provides options in business, marketing, and technology. Web development careers are plentiful for anyone with the necessary abilities and education.

As the world gets more connected, web developers need to learn and improve. Web developers help make the world more online-friendly.

Web developer salary

Web developers earn $75,000–$100,000. Web development is a competitive profession. Understanding pay expectations is crucial for web developers. In this instance, you must work to discover your strengths.

Web developer salaries depend on several things. Project size is crucial. Web developers that can accomplish small, medium, and big projects receive comparable salaries. Developers’ hours also depend on project size.

Conclusion

The coming decade will see a huge need for web developers. Because consumers demand more from websites. Technology allows individuals to purchase, socialise, and accomplish other daily duties online. Websites are needed more as the internet grows. A user-friendly, engaging website may be built with the correct tools. Web developer wages will rise with demand.


[ad_2]
Source link

Samsung brings its AI image editor app to more premium Galaxy phones

0
[ad_1]

Initially launched on the Galaxy S22 series last year, and the Galaxy S23 series in 2023, the Galaxy Enhance-X app is now available for a bunch of additional Galaxy premium smartphones, Samsung announced. Along with the announcement, Samsung confirmed its powerful AI image editor app is now out of beta.Officially launched on June 20, the Galaxy Enhance-X app is available for a range of premium Galaxy smartphones, including the Galaxy S23 series, S22 series, S21 series, Note20 series, Z Fold4, Z Flip4, Z Flip3, Z Fold2, Z Flip 5G and Z Flip LTE devices powered by One UI 5.1 or above.

In addition to these premium smartphones, Samsung announced that support for Galaxy Enhance-X on Galaxy A series, Galaxy M series and Galaxy tablets will be available at a later date. However, the company didn’t say if all the features that owners of Galaxy premium users benefit from will also be available to those who own non-premium phones.

If you haven’t used Samsung’s Galaxy Enhance-X app, it’s worth noting that this app promises to automatically refine any visual noise, blur and low details, thus improving the image quality. What makes the app extremely easy to use is that all this is done with a single tap.

That’s not to say that the AI image editor app doesn’t have a wide range of tools that allows users to customize their images. If you want, you can use different levels of HDR intensity, take advantage of the Upscale tool to boost the resolution of images under 1MP by up to four times, as well as remove shadows from certain areas in a picture.

The Galaxy Enhance-X editing functions include a bunch of other features such as Brighten, Fix Blur, Sharpen, Remove Reflection and Fix Lens Distortion. The app is available for download for free via the Galaxy Store.


[ad_2]
Source link

Brave New Privacy Feature Limit Access to Local Resources

0
[ad_1]
Brave New Privacy Feature

Brave version of 1.54 for desktop and Android will include more powerful features for controlling which sites can access local network resources and for how long.

Malicious requests from websites to access local host resources act as a fingerprinting technique which concerns users’ privacy and security at risk.

The conventional desktop version of web browsers like Chrome, safari, firefox, Mozilla, etc., allows secure and nonsecure public sites to access your local host resources.

Local host resources are nothing but images and web pages that are hosted by other software on your local machine.

Reason to Access Local Host Resources:

Browsers allow websites to access localhost resources for various reasons, but the main two reasons are historical legacy and backward compatibility.

Brave New Privacy Feature
Access Local Resource. Image Credits brave

Generally, browsers did not strictly enforce the distinctions between first-party resources (those hosted by the website you’re visiting), third-party resources (those hosted on other public websites), and local-host resources due to a decreased concern for user privacy.

Due to this vulnerability, a significant amount of software has been created to be freely accessible via websites that are invisible to users.

And many of these uses are acceptable. Examples include specific cryptocurrency wallets, security software offered by banks or security firms, and gear whose configuration uses specific Web interfaces.

Unfortunately, a large variety of harmful, user-harming software on the Internet makes use of access to local-host resources for illicit purposes. 

To re-identify you, for instance, fingerprinting scripts look for specific patterns in the other software you have operating on your device. 

Other scripts look for weak or susceptible software on the system and attempt to attack.

About Brave:

Unlike other browsers, Brave puts you in control of your data. The secure browser automatically blocks trackers and unwanted ads while also providing anti-phishing and anti-malware protection.

Brave is the only popular browser to ship multiple protections against sites maliciously accessing localhost resources. Brave currently uses filter list rules to:

  • Block scripts are known to maliciously scan localhost resources
  • Block requests from public sites to localhost resources

Brave has developed a new approach for protecting users against sites abusing local network resources. This new system will have the following parts:

  • Requests to localhost resources from a localhost context are allowed automatically; Brave does not block a locally hosted page from accessing other locally hosted resources.
  • Brave will continue to use filter list rules to block scripts and sites known to abuse localhost resources.
  • Brave will include a new permission called the “localhost” permission. Only sites with this permission will be able to make sub-resource requests to local-host resources. By default, no sites have this permission, and, importantly, most sites have no way to prompt users for this permission. However, advanced users can use the existing site settings interface to grant sites this permission. 
  • Brave will also include a list of trusted sites, or sites known to access localhost resources for user-benefiting reasons. The first time a site on this list initiates a sub-request to a localhost resource, it will trigger a permission prompt of the previously mentioned localhost permission. This list is publicly available and will be maintained by Brave.

Furthermore, Brave enhances its protections deeper in the network stack, so that Brave can protect users against additional, less common methods of sites making localhost requests (including DNS records that refer to localhost).

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.


[ad_2]
Source link

Galaxy A32, A32 5G, A31 & A41 get Samsung’s June update

0
[ad_1]

A bunch of mid-range Galaxy A series phones are getting Samsung‘s June update. The company is pushing the latest security patch to the Galaxy A32, Galaxy A32 5G, Galaxy A31, and Galaxy A41. It has previously updated dozens of other models to the June SMR (Security Maintenance Release), which patches more than 60 vulnerabilities.

The June update for the Galaxy A32 is rolling out widely in Europe, Asia, Africa, and Latin America. Users in the former three markets are getting the new SMR with the firmware build number A325FXXU5DWE3. The build number in Latin America is A325MUBU5DWF1. The changelog remains the same everywhere, though. Samsung says the device is getting some system stability and reliability improvements along with this month’s security fixes.

Unlike its 4G sibling, the Galaxy A32 5G isn’t getting the June update widely yet. The latest SMR for this phone is available in a handful of Latin American countries, including Brazil, Chile, Colombia, and the Dominican Republic. For users in Chile, the new firmware build number is A326BXXS6CWF3, but that for users in the remaining countries is A326BXXS6CWF2. This phone isn’t picking up additional goodies anywhere.

The rollout for the Galaxy A31 and Galaxy A41 is even more limited. As of this writing, Samsung has released the June SMR for the two 2020 mid-range phones only in Kazakhstan. The update comes with build numbers A315FXXS3DWF1 and A415FXXS4DWF1 (via SamMobile). Neither model is getting anything else apart from the latest security fixes. A wider rollout of the June update for these phones should follow in the coming days.

Samsung’s June update for Galaxy devices fixes over 60 security issues

The June SMR for Galaxy devices is a pretty big one. This month’s security release contains fixes for more than 60 vulnerabilities. The vast majority of those (50) are Android OS issues, at least three of which were classified as critical flaws by Google. The remaining issues are Galax-specific flaws patched by Samsung.

As usual, not every Galaxy device is affected by all 60 of these security flaws. But every model is vulnerable to a few of those. You should update your phone to the latest security patch as soon as possible to stay clear of these vulnerabilities. If you’re using a Samsung smartphone, you can navigate to Settings > Software update > Download and install on your phone to check for updates manually. You may also get a notification once the latest update reaches your Galaxy device.


[ad_2]
Source link