Poorly configured Linux and Internet of Things (IoT) devices are at risk of compromise from a cryptojacking campaign.
Poorly configured Linux and Internet of Things (IoT) devices are at risk of compromise from a cryptojacking campaign, according to researchers at Microsoft. The attacks, which involve brute forcing a way into a system, are designed to profit from mining in illicit fashion for cryptocurrency.
Once the attackers have broken into their target system, a patched version of OpenSHH, a remote login tool, is downloaded from a remote server. When the rogue version of this tool is deployed, it looks to backdoor hijacked systems and swipe credentials to ensure it lingers on the system for as long as it possibly can.
Utilizing an established criminal infrastructure that has incorporated the use of a Southeast Asian financial institution’s subdomain as a command and control (C2) server, the threat actors behind the attack use a backdoor that deploys a wide array of tools and components such as rootkits and an IRC bot to steal device resources for mining operations. The backdoor also installs a patched version of OpenSSH on affected devices, allowing threat actors to hijack SSH credentials, move laterally within the network, and conceal malicious SSH connections. The complexity and scope of this attack are indicative of the efforts attackers make to evade detection.
A backdoor on the system checks to see if the hijacked device is a honeypot—a fake system set up by researchers or someone else to make an attacker think that they’ve compromised a genuine system when in reality everything the attacker does is being logged.
If it determines the system is a honeypot, it exits. If it determines that the system is the real thing, it begins a process of data exfiltration to a chosen email address. The data that is taken includes:
Operating system version
Network configuration
The contents of /etc/passwd and /etc/shadow
Open source rootkits are installed in systems which support them, used to further hide malicious files and processes taking place under the hood. Activity records are removed from various places on the system to mask any malicious presence, and additional tools are installed to clean up other logs which could reveal evidence of sign-ins.
Years ago you’d occasionally see adware programs try to remove rivals from a PC, in order to take all of the ad revenue for its creator. Here, we have something similar happening with the cryptomining tools being used in this attack. It identifies mining processes by name and/or files, and then terminates the processes or blocks them outright. As a general point of order here, you don’t really want lots of rival programs fighting it out in your systems. It could easily lead to unstable performance. Even worse if the programs doing the fighting aren’t supposed to be there in the first place. They won’t be playing by any theoretical rules, and so you simply can’t predict what they’ll do to gain the upper hand.
Meanwhile, the patched version of OpenSSH is designed to look like the legitimate version and so may prove hard to detect. That’s not all, however. There’s botnet activity too. A portion of the install makes use of an open-source IRC bot with Distributed Denial of Service (DDoS) features.
Microsoft claims to have traced this particular campaign to a member of a hacking forum who offers several tools for sale in what may be a dedicated malware as a service operation. The operating system giant has some specific advice for those who may be worried about this attack impacting their business:
Harden internet-facing devices against attacks
Ensure secure configurations for devices: Change the default password to a strong one, and block SSH from external access.
Maintain device health with updates: Make sure devices are up to date with the latest firmware and patches.
Use least-privileges access: Use a secure virtual private network (VPN) service for remote access and restrict remote access to the device.
When possible, update OpenSSH to the latest version.
Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.
Perhaps one of the most under-utilized features of Twitter, is the ability to schedule a tweet, and we’ll be showing you how to do that today. This is a really useful feature because you can set tweets to be sent in the future. This is great for all kinds of things. Like tweeting while you’re on vacation without actually opening your phone.
Unfortunately, it appears that Twitter has removed this functionality from the Twitter mobile apps (for iOS and Android) so you can only do it from Twitter’s website and a few other third-party apps. Tweetdeck is one that supports it, and has for many years. So do keep that in mind here as we go through how to schedule a tweet on Twitter.
How to Schedule a Tweet on Twitter’s website
First, head to Twitter’s website.
Then type in your new tweet in the compose box like usual.
Now tap on the icon that looks like a calendar and clock. It’ll be the fifth icon from the right.
From here, you can select the date, and time as well as the time zone for sending your tweet. The time zone is a really useful trick.
Now tap on Confirm in the upper-right hand corner. Make sure that the tweet is set for the future, otherwise you won’t be able to schedule it.
After you tap on confirm, the Tweet button changes to Schedule. Tap on that.
Now your tweet will go out at the specified date and time. And that’s all there is to it.
You can go back and edit the tweet since it hasn’t been sent out yet. Just repeat the steps above and when you get to the schedule portion, tap on “Schedule Tweets” at the bottom. This will take you to your scheduled and draft tweets. And you can edit them from there.
Netflix may have a habit of testing out its policies on Canadian subscribers. Earlier this year, the streaming service abolished password-sharing outside of your household, an update they first tested in a few countries, including Canada. Now, the company announced that its most basic plan will no longer be available to Canadian subscribers.
Netflix’s basic ad-free plan is no longer available in Canada.
As TechRadar reports, Netflix has quietly dropped its cheapest ad-free tier in Canada. So, what does this mean? Well, although existing subscribers are unaffected (unless they change plans), the new policy means that “the Basic plan is no longer available for new or rejoining members,” according to Netflix Canada’s help website.
Now, potential customers will have to choose between spending $5.99 CAD for the standard plan with ads, $16.49 CAD for standard without ads, or $20.99 for the premium plan.
Apparently, Netflix’s basic ad-free tier has been dropped a while ago in Canada — it’s just that no one noticed. The earliest mention comes from a Twitter user who complained about the termination of Netflix’s basic plan back on June 10.
Despite Canadian users feeling a loss, time will tell if they will move onto another tier. After all, although the company’s password-sharing crackdown was controversial, it did in fact lead to new subscribers to the platform.
As TechRadar further notes, it doesn’t look like any other countries around the world have seen any similar changes. For instance, the American Netflix Plans and Pricing page still has the basic ad-free plan listed at $9.99. So, it stands to reason that users outside of Canada are safe.
However, this could change at any point. It’s unclear whether new abolishment of Netflix’s basic-ad free plan will be limited to Canada. Or if it will be tested in any other countries.
icb netflix started the hosted device password login whatever thing in canada first and they are also got rid of the Basic plan in canada LIKE WHAT DID WE EVEN DO
Smartphone users in the U.S., U.K., Germany, Austria, and Switzerland are under attack by an Android trojan called ‘Anatsa’ which targets online banking customers in those countries. Trojan malware uses apps that hide their true intentions and once they get downloaded on your phone, the true nature of these apps becomes known similar to the story about the Trojan Horse.
ThreatFabric’s analysts have been tracking campaigns that use apps located in the Google Play Store that deliver the banking trojan called Anatsa. The apps involved in this campaign have over 30,000 installations. The campaign targets 600 financial apps from around the world. The goal is to steal the credentials used by customers on banking apps and initiate fraudulent transactions by performing Device-Takeover Fraud (DTO).
The latest Anatsa campaign started this March with the goal of creating fraudulent banking transactions
After taking a six-month break, ThreatFabric (via BleepingComputer) saw indications of a new campaign this past March. An app listed in the Google Play Store, holding itself out as a PDF reader, would download the payload once it was installed. The payload, loaded from GitHub, was disguised as an add-on to the original app.
Once the app was reported to Google, it was removed from the Play Store. But a month later, the attackers added another app to the Play Store, this time a PDF viewer app, and once again a payload was downloaded to the app disguised as an add-on.
How the fraud cycle works with the Anatsa trojan
And once again, the dropper app was reported to Google and removed from the Play Store. Three more droppers were discovered in the Play Store last month and this month. It takes a couple of days to a couple of weeks for these malicious apps to be listed in the Play Store and as of this moment, there is an Anatsa dropper still listed in Google’s Android app storefront.
According to ThreatFabric, “Our analysis also reveals that the actors can have several apps published in the store at the same time under different developer accounts, however, only one is acting as malicious, while the other is a backup to be used after takedown. Such a tactic helps actors to maintain very long campaigns, minimizing the time needed to publish another dropper and continue the distribution campaign.”
Once a device is infected, the trojan can collect sensitive information including credentials, credit card details, balance, and payment information. This data is used by the attackers to create transactions using the victim’s bank account. Since these transactions use the same devices that the targeted bank customers usually use, it is hard for anti-fraud systems to spot illegal transactions.
Make sure that you do not have any of these five apps on your Android phone
Back in 2021, ThreatFabric discovered a previous Anatsa campaign on Google Play when the trojan was installed over 300,000 times by apps pretending to be PDF scanners, QR code scanners, Adobe Illustrator apps, and fitness tracker apps.
The latest Anatsa droppers (and their package names) include these five apps that were, at one time, available from the Google Play Store. The titles are:
PDF Reader – Edit & View PDF-lsstudio.pdfreader.powerfultool.allinonepdf.goodpdftools PDF Reader & Editor-com.proderstarler.pdfsignature PDF Reader & Editor-moh.filemanagerrespdf All Document Reader & Editor-com.mikijaki.documents.pdfreader.xlsx.csv.ppt.docs All Document Reader and Viewer-com.muchlensoka.pdfcreator
One of the Anatsa dropper apps
Even if they have been kicked out of the Play Store, should they still be installed on your phone, they can do damage. And remember, these are banking trojans that are looking to drain your bank accounts. So if you have any of these five on your Android handset, delete them immediately if not faster. And make it a point to check out your bank balance perhaps as much as several times a day to make sure that nothing funny is going on.
Malvertising, the practice of using online ads to spread malware, can have dire consequences—and the problem only seems to be growing.
This article is based on research by Jérôme Segura, Senior Director of Threat Intelligence at Malwarebytes, who oversees data collection from spam feeds and telemetry to identify the most relevant threats.
Malvertising, the practice of using online ads to spread malware, can have dire consequences—and the problem only seems to be growing.
New research from the Malwarebytes Threat Intelligence team shows over 800 malvertising-related attacks in 2023 so far alone, an average of almost 5 attacks per day. But even these are only the ones reported by security researchers—in reality the number is much higher.
Our research indicates that malvertising ads often deliver infostealer malware such as IcedID, Aurora Stealer, and BATLOADER among others. These programs steal credentials from users’ browsers or computers, sowing the seeds for a future ransomware attack.
Malvertising attack count throughout 2023
Ransomware gangs often buy stolen credentials from other cyber criminals involved in the dirty work of initial access brokering. In the case of malvertising, the chain of events looks something like this:
Malvertising campaigns infect users with infostealers.
Infostealers harvest user credentials.
Stolen credentials are sold in underground forums.
Ransomware actors buy these credentials to infiltrate networks.
Alternatively, some ransomware gangs have been observed use malvertising themselves to launch an attack on a victim machine directly.
The Royal ransomware group, for example, used malvertising to disguise BATLOADER as legitimate installers for applications like TeamViewer. BATLOADER then drops a Cobalt Strike Beacon as a precursor to the ransomware execution.
For organizations looking to nip the malvertising-ransomware connection in the bud, however, perhaps the biggest challenge is how hard malvertising can be to spot. Threat actors often impersonate the official brand name and website in the ad snippet, making attacks extremely deceptive for the average user.
Can you spot the typo in this malvertising attempt?
Even experts at Google have struggled to identify malicious redirects from an ad, underscoring the fact that malvertising is a nuanced, technical problem that requires advanced tools to spot.
In other words, your defense strategy against malvertising shouldn’t hinge entirely on your team recognizing brand impersonation. Instead, focus on equipping your team with advanced security tools to do the heavy lifting.
Some of the main tools you can use to prevent malvertising include:
Vulnerability and patch management software: Malvertising often exploits known vulnerabilities in systems, applications, or browsers. These tools can help ensure that web browsers (including plug-ins) are up-to-date with the latest security patches.
Web protection applications: Since malvertising campaigns often rely on connecting to malicious servers to download additional malware or steal information, blocking these connections can stop the attack in its tracks.
Ad blockers: These can filter out potential malvertising threats and prevent hazardous content from loading. Malwarebytes Browser Guard provides additional protection to standard ad-blocking features by covering a larger area of the attack chain all the way to domains controlled by attackers.
Download the Malwarebytes Threat Intelligence Threat Brief today for comprehensive insights on malvertising and its role in stealing credentials.
Motorola launched its new flagship clamshell smartphone recently, the Motorola Razr 40 Ultra, or as it’s known in the US, the Motorola Razr+. Having said that, we’re here to compare that phone to its predecessor, we’ll compare the Motorola Razr+ vs Motorola Razr 2022. This new model not only brings a larger outer display, but also a number of improvements under the hood, amongst other things.
We’ll first list the specifications of both devices, and will then move to compare them across a number of categories. We’ll compare their designs, displays, performance, battery life, cameras, and audio performance. They are very similar in some ways, but… spoiler alert… it’s hard to deny the Razr+ is the better phone overall. Still, for some of you, the upgrade may not be worth it. So, let’s dive in.
The Motorola Razr+ is actually a lot narrower than the Razr 2022. It is also slightly taller, and slightly thinner. You’ll definitely feel the narrower form factor, as the difference is quite considerable, 74mm vs 79.8mm. When folded, the Razr+ is almost two millimeters thinner. The Motorola Razr 2022 does have more aggressive curves on its corners. The difference is not huge, but it’s noticeable.
The Motorola Razr+ definitely feels better in the hand overall. Both phones have a centered display camera hole, and thin bezels. The Razr 2022’s top and bottom sides are also curved to a degree (from left to right), unlike what we see on most smartphones. Both devices do have two cameras on the back, and rather large displays. The Motorola Razr+ does have a larger outer panel, though, at 3.6 inches, compared to 2.7 inches on the Razr 2022.
Both devices do have good crease control, but the Motorola Razr+ does feel a bit more sturdy. Neither phone has a proper IP rating, but they do have a water-repellent coating that we’re used to seeing from Motorola. Both devices are also quite slippery, unless you get the eco leather variant of the Motorola Razr+, in which case you’ll get a better grip. On top of everything, the Motorola Razr+ is also lighter than the Razr 2022, 184.5/188.5 vs 200 grams.
Motorola Razr+ vs Motorola Razr 2022: Display
There is a 6.9-inch fullHD+ (2640 x 1080) display on the Motorola Razr+. That panel is foldable, and it offers a 165Hz refresh rate. Do note that it’s an LTPO panel, so it offers an adaptive refresh rate. HDR10+ content is supported here, and this display goes up to 1,400 nits of brightness at its peak. The second display on the phone measures 3.6 inches, and offers a resolution of 1056 x 1066. It is an AMOLED display which supports up to 1 billion colors, and a 144Hz refresh rate. HDR10+ content is also supported here, and the display goes up to 1,100 nits when it comes to brightness. The Gorilla Glass Victus protects this panel.
The Motorola Razr 2022, on the flip side, has a 6.7-inch fullHD+ (2400 x 1080) AMOLED display, which is foldable. It offers up to 1 billion colors, and has a 144Hz refresh rate. HDR10+ content is also supported here, and the panel has a 20:9 aspect ratio. The cover display on the phone measures 2.7 inches, and offers a 573 x 800 resolution. That is an AMOLED panel too, and has a 60Hz refresh rate.
The displays on both smartphones are good enough, when it comes to image reproduction and general look. They’re vivid, and offer good viewing angles. They also offer good touch response. The Razr+’s 165Hz refresh rate is not always active, of course, due to battery life reasons. Both main displays are well-adapted to the content, and the scrolling is smooth. The cover display on the Razr+ has a higher refresh rate, but the difference won’t be as noticeable as it would have been on larger panels.
The Motorola Razr+ does have better displays overall. Outer displays on both phones are quite useful, as you can run basically anything on them. Any app, which is not something we can say for clamshell foldables from other companies, at least not out of the box.
Motorola Razr+ vs Motorola Razr 2022: Performance
The Snapdragon 8+ Gen 1 SoC can be found in both smartphones. Motorola coupled LPDDR5 RAM with that SoC in both phones, while you’ll also find UFS 3.1 flash storage in both smartphones. So, in terms of performance-related hardware, they’re basically on the same level. Does that reflect on actual performance, though? Well, both phones do perform admirably, to be quite honest.
The Motorola Razr 2022 can keep up with the Razr+ when it comes to performance, without a problem. That’s a good thing, of course. From that standpoint, you do not have a reason to upgrade. Both devices do a great job when it comes to regular, everyday tasks, and also more intense tasks, such as playing games. They do get warm, but never to the point they felt uncomfortable to use. The Razr+ seemed to be a bit cooler, but it could just be a placebo effect. They’re quite similar in that regard.
Motorola Razr+ vs Motorola Razr 2022: Battery
The Motorola Razr+ includes a 3,800mAh battery on the inside, while the Razr 2022 comes with a 3,500mAh battery. The Motorola Razr+ does have a larger battery pack, and that does reflect on battery life too, despite the fact it also has a higher refresh rate on its displays, and a larger outer display. Getting over 7 hours of screen-on-time on the phone is not a problem. In fact, we were able to get around 7.5-8 hours of screen-on-time on it, consistently. That’s a great result for a flip phone.
The Motorola Razr 2022, on the other hand, doesn’t offer bad battery life, but it’s not nearly as good as what the Razr+ offers. At first, it offered over 6 hours of screen-on-time without a problem, but the updates did improve that. Getting over 6.5 hours should not be much of an issue, but that’ll depend on how much you use the outer display, of course. The battery life on these two phones can vary a lot, depending on your usage in general. Which display you use more, and by what margin. There are also apps to consider, signal strength, and more. In other words, you may get entirely different results, so keep that in mind.
When charging is concerned, they’re on the same level, when it comes to wired charging, at least. 30W charging is supported here. The Motorola Razr+ also offers 5W wireless charging, which is something the Motorola Razr 2022 doesn’t have, at all. The Motorola Razr 2022 does include a charger in the box, while that may depend on the market for the Razr+. So take note of that, you may need to get a charger separately.
Motorola Razr+ vs Motorola Razr 2022: Cameras
The Motorola Razr+ includes a 12-megapixel main camera, and a 13-megapixel ultrawide camera (108-degree FoV). The Motorola Razr 2022, on the flip side, has a 50-megapixel main camera, and a 13-megapixel ultrawide unit. The images during the day do look good on both phones, but a bit different. Neither phone tends to punch up the saturation to liven up shots, they prefer to keep things closer to real life.
That is a problem at times, as the images can look a bit dull. The Razr+ tends to provide underprocessed images at times, and also miss in HDR situations from time to time, but rarely. That’s something Motorola can fix via an update, and chances are it will happen. Ultrawide cameras are a step below the main ones, and that is especially noticeable on the Motorola Razr 2022.
When it comes to low light shots, the Motorola Razr+ is an easy winner. It does a really good job in low light, even in demanding scenarios with neon lights, and street lights in the same scene. It also manages to keep noise in check, unlike the Razr 2022, where noise is often visible in low light images. The Razr 2022 also has a yellowish hue in low light, which is not exactly flattering.
Audio
Both of these phones include a set of stereo speakers, and they’re both good enough. They’re actually very similar too. The loudness seems to be about the same, and the quality as well. You will get good audio, as long as you’re not expecting miracles.
What they do not have is a 3.5mm headphone jack. You’ll need to use their Type-C ports for wired audio connections. If you prefer to go wireless, do note that the Razr+ supports Bluetooth 5.3, and Razr 2022 Bluetooth 5.2.
Meta today announced a new service for its Quest headset lineup called Meta Quest+, a subscription service that is designed to get new games into your hands for a recurring monthly fee.
It’s sort of like PlayStation Plus, but without the discounts on games. Although perhaps that will be added at a later date. If you’re big into VR though and you own either a Quest 2 or Quest Pro, signing up gives you a nifty benefit. The service will also be available for the Quest 3 when it launches later this year.
If you’re member, Meta will give you two games for free every month. You claim these just like you would with PlayStation Plus titles. Meta also says games will be handpicked. So you’re getting a curated selection of titles that rotate on a monthly basis. It’ll cost you $7.99 a month, or you can pony up $59.99 for the annual subscription.
Meta kicks off the Quest+ subscription with Pistol Whip
The service is live starting from today and you can already claim your first two titles. These include Pistol Whip and Pixel Ripped 1995. If you’ve not tried either of these games yet, now is probably a good time to check them out.
Meta has also laid out its two curated games for August. Starting August 1, subscribers can claim Mighty Coconut’s Walkabout Mini Golf and MOTHERGUNSHIP: FORGE. There’s also an incentive to sign up earlier. As Meta will offer you the subscription for $1 for the first month, but you’ll need to sign up by July 31 to get that deal.
You also get to retain access to every game you claim as long as your subscription remains active. You also don’t lose the games you claimed if you ever cut the subscription off at any point. You’ll just need to resubscribe if you want to play them again.
It seems like a pretty good deal if you play games on your Quest 2 or Quest Pro headset often. Meta says new games will pop up in the service on the first of every month too.
Digital initiatives play a crucial role in business today; they bring new business opportunities, fostered creative partnerships, and deliver new customer conveniences across multiple industries.
But all these innovations pose the biggest challenges for CISOs/CSOs, and they don’t want companies to sacrifice security for speed.
According to the Survey report share with Cyber Security news by Salt Security’s “State of the CISO 2023,” mentions that nearly 90% of CISOs say Digital Transformation Introduces Unforeseen Risks.
Challenges from the Rapid Digital Transformation
The effects of digitization are felt most keenly by businesses in the financial services and healthcare sectors.
Following are the challenges Digital economy provides;
Lack of qualified cybersecurity talent to address new needs (40%)
Inadequate adoption of software (36%)
The complexity of distributed technology environments (35%)
Increased compliance and regulatory requirements (35%)
Difficulties justifying the cost of security investments (34%)
Getting stakeholder support for security initiatives (31%)
While 37% of CISOs worldwide “very much agree” that digital services increase risk, this number rises to 43% among financial services CISOs and 47% among healthcare, reads the report.
Almost all CSOs and CISOs (99%) said they face personal & professional challenges from the rapid digital transformation.
Most CSOs (48%) are worried about being sued due to a breach, followed by increased risk and personal accountability (45%).
After ex-Uber employee Joseph Sullivan’s conviction for covering up a 2016 data breach, security experts have become fearful of being held personally liable for security mistakes.
CISOs identify supply chain or third-party vendors (38%), API adoption (37%), and cloud adoption (35%) as the top three security control gaps resulting from their digital initiatives.
While AI has been identified as a significant concern by CISOs worldwide, other major problems include the state of the economy and international politics.
Eighty-two percent of CISOs say their security spending is higher than two years ago.
The spending power of CISOs has dropped as a percentage of revenue over the past two years, even though the revenue of these same organizations has increased by 87%.
In addition to the trends impacting CISOs’ role, AI is a top issue of concern as cyber attackers are already using AI to conduct sophisticated attacks.
Manage and Secure Your Endpoints Efficiently – Free Download
Help the people around you that are less computer literate with some basic security tips and settings.
Before we get into the tips: a caveat. We know many seniors who are digitally more up to date than people 20 years younger, but for those who aren’t, this guide is for you.
If you’re offended by the word seniors in the title, feel free to replace it with “computer illiterate people.” And keep in mind that this piece was written by a 60-year old who happens to be the “computer guy” among his family and friends.
With the world’s increasing digitalization, even those that are not a big fan of computers are compelled to use them for various urgent reasons. Seniors in a digital world can be overwhelmed by all the new technology. And just when you think you’ve caught up, something new’s been invented.
In security terms, it can feel like there’s a lot to do in order to keep your data and devices secure. Multiple passwords, reading through EULAs, website cookie notifications, and more. All of this can contribute to a serious case of security fatigue.
Many of today’s most dangerous threats are delivered through social engineering, i.e., by tricking users into giving up their data, or downloading malware from an infected email attachment. Therefore, knowing more about what not to click on and what not to download can keep a good portion of threats out the door.
So, with that in mind, here are 9 basic security tips for seniors:
Do not click on links asking to fill out your personal information. Banks and other financial institutions will not send emails with links, especially if those links are asking you to update your personal information. If a website promises you something in return for filling out your personal data, they are likely phishing. In return for your data, you will probably get lots more annoying emails, possibly an infection, and no gift.
Don’t fall for too-good-to-be-true schemes. If you get offered a service, product, or game for free, and it’s unclear how the producers of the service or item are making money, don’t take it. Chances are, you will pay in other ways, such as sitting through overly-obnoxious ads, paying for in-game or in-product purchases, or being bombarded with marketing emails or otherwise awful user experiences.
Don’t believe pop-ups and phone calls saying your computer is infected. Unsolicited phone calls and websites that do this are known as tech support scams. The only programs that can tell if you have an infection are security platforms that either come built into your device or antimalware software that you’ve personally purchased or downloaded. Think about it: Microsoft does not monitor billions of computers just to call you as soon as it notices a virus on yours.
Don’t download programs that call themselves system optimizers. We consider these types of software, including driver updaters and registry cleaners, potentially unwanted programs. Why? They do nothing helpful—instead, they often take over browser home pages, redirect to strange landing pages, add unnecessary toolbars, and even serve up a bunch of popup ads. While not technically dangerous themselves, they’re unneeded and could let other nasties in through the door.
Disable web push notifications. These are almost never useful to the user, they can be easily spoofed, and they are regularly used for social engineering and obtrusive advertising purposes.
Keep your browser up-to-date. Major browsers such as Firefox, Safari, and Chrome all have their own strengths and weaknesses, so it’s a matter of personal preference which one you use. However, browsers regularly have vulnerabilities and any updates should be applied as soon as possible. Remember: You must restart your browser in order for updates to take effect.
Look for HTTPS and the padlock sign. Just because there is a padlock next to the address bar doesn’t mean the site is safe, but it does mean all the traffic between your computer and the website is encrypted. That means that if someone tried to snoop on what you were sending the website, they’d get nowhere because the data would be scrambled.
Use multi-factor authentication wherever you can. You can set this up on most sites and usually involves you entering a code from either an app or a text message, after you’ve entered your password. Bonus points for healthcare or banking organizations with logins that use passkeys, a hardware key, or behavioral biometrics.
Use a password manager. They help you create and remember safe passwords and they won’t automatically put your passwords into fake sites, which helps you tell if something is a phishing site. This step might require some time and help from someone more technical, but it makes things much safer in the long run.
We don’t just write about threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
In a recent blog post from Microsoft, they make it clear that they will turn back on the Windows 11 File Explorer update. This version of the app was available to Windows Insiders for the past few weeks. These testers put the app update through scrutiny, and they found it lacking in certain areas.
Microsoft made a few upgrades with this testing version, which they made available to their insider program. Most testers were excited to try out the new update but didn’t expect to find anything wrong with the update. But things didn’t go as planned, as the update fell short in various areas.
Well, the majority of the faults with this update came from the power usage aspect of things. Testers have brought the shortcomings of this update to Microsoft, who have in turn offered a solution. This involves turning back on the update and letting users stick to the existing version while fixing any shortcomings.
Microsoft puts user experience first as they dismissed the Windows 11 File Explorer update
Just like with every app update out there, the Windows 11 File Explorer update came with some new features. These features were to help improve the user experience while simplifying app usage. Once it was made available a few weeks ago, users of the Windows Insider program began playing around with these features.
Some new features include changes to folders, improvement to key pass access, showing drive letters, and hiding protected OS files. The improvements to this app are aimed at stepping up the user experience. Power users also saw the folder option on the Windows 11 File Explorer taken away with the update.
Most of these users find the folder options very useful for their work and everyday usage. Taking this feature away from them would cripple them and force them to find other ways around the new limitation. For a while, they were able to keep up with this change before crying out to Microsoft for an urgent change.
Impressively, Microsoft didn’t turn a deaf ear to its Windows Insider users and testers of this update. They were able to take down the update and let users enjoy the old version. This will give them access to tools that they need to work while Microsoft works on fixing the flaws with this current update.