5 facts to know about the Royal ransomware gang

0
[ad_1]

A quick look the cybercriminal group known as Royal—one of the fastest growing ransomware gangs today.

When we first introduced the Royal ransomware gang in our November 2022 review, little did we know they’d rapidly evolve into one of the most potent threats in our ongoing monthly threat intelligence briefings.

In fact, the Malwarebytes Threat Intelligence team has tracked down a staggering 195 ransomware incidents credited to Royal from November 2022 to June 2023.

Known Royal attacks up to May 2023

These figures put Royal in a formidable third place for that time frame, trailing behind ALPHV (with 233 incidents) and the relentless LockBit (at 542 incidents).

In the rest of this post, we’ll be shedding some light on five key facts to know about the Royal ransomware gang.

1. 66% of their initial access is done through phishing

It seems there are three things certain in life: death, taxes, and phishing as a reliable attack vector.

Royal likes to send phishing emails with nasty PDFs attached. They have also been spotted using callback phishing attacks to lure victims into installing remote desktop malware.

Once someone falls for Royal’s phishing scam and ends up with malware on their computer, that malware tries to reach out to its command and control (C2) base. Then it starts downloading malicious tools to aid in lateral movement or exfiltration.

2. They have a massive USA bias

The Malwarebytes Threat Intelligence team found that 64% of Royal’s victims are from the USA.

Known Royal attacks up to May 2023 by country

For comparison, 43% of all known ransomware attacks were on the USA in the same November 2022 to June 2023 time period. For gangs with more than 50 attacks, Royal was only second to Black Basta (67%) for attackers on the USA.

3. Cobalt Strike is one of the many legit tools they repurpose for malicious activities

Royal has been spotted using a host of legitimate tools to carry out their attacks under the radar. Just some of these tools include:

By mimicking normal behavior, these tools can make it extremely difficult for IT teams and security solutions to detect any signs of malicious activities.

4. We’ve observed them reinfecting victims

Shortly after Royal rose to prominence in late 2022, a new customer joined the Malwarebytes Managed Detection and Response (MDR) service. The customer was previously a casualty of a Royal ransomware attack and thought they had dusted themselves off completely.

But soon after plugging in with us, we spotted some shady activities.

Malwarebytes MDR detecting “Ransomware.Royal” in the client’s network.

It turns out that Royal wasn’t content with having ‘merely’ attacked our customer once—they were still messing around in their system, potentially setting the stage for another damaging attack.

Fortunately, our EDR tech halted the ransomware in its tracks, and our MDR team managed to stop the post-ransomware havoc from spiraling further.

Still, it goes to show that attacks Royal doesn’t simply move on after a successful attack; they stay engaged for future exploitation, if they can help it.

5. The Services, Wholesale, and Technology industries are their top victims

When we look at Royal ransomware’s victimology, no overwhelming pattern stands out like it does for Vice Society.

Known Royal attacks up to May 2023 by industry sector

Their victims per industry more or less match the averages across all ransomware gangs, suggesting they are sheer opportunists without a particular industry focus.

Like any ransomware gang, they leverage any potential vulnerabilities and security gaps across sectors, launching their attacks wherever they find the easiest point of entry. 

Getting the upper-hand against the Royal gang

Royal has made a big name for itself in a short amount of time.

While it looks like Royal will attack anyone they think is an easy target, it’s safe to say that organizations in the USA should be particularly wary of Royal considering their strong focus on that country.

We recommend the organizations across all sectors follow a few best practices to prevent (and recover) from ransomware attacks from every angle. That includes: 

  • Block common forms of entry. Create a plan for patching vulnerabilities in internet-facing systems quickly; disable or harden remote access like RDP and VPNs; use endpoint security software that can detect exploits and malware used to deliver ransomware.
  • Detect intrusions. Make it harder for intruders to operate inside your organization by segmenting networks and assigning access rights prudently. Use EDR or MDR to detect unusual activity before an attack occurs.
  • Create offsite, offline backups. Keep backups offsite and offline, beyond the reach of attackers. Test them regularly to make sure you can restore essential business functions swiftly.
  • Don’t get attacked twice. Once you’ve isolated the outbreak and stopped the first attack, you must remove every trace of the attackers, their malware, their tools, and their methods of entry, to avoid being attacked again.

Malwarebytes’ EDR anti-ransomware layer constantly monitors endpoint systems and automatically kills processes associated with ransomware activity, including Royal ransomware. 

Malwarebytes EDR blocking Royal ransomware On-Execution

In our Ransomware Emergency Kit, you’ll find more tips your organization needs to defend against RaaS gangs. 

Get the emergency kit


[ad_2]
Source link

Samsung Galaxy Z Flip 4 vs Motorola Razr+

0
[ad_1]

Motorola launched its new clamshell foldable, the Motorola Razr+ or Razr 40 Ultra, it depends on the market. The first name is used in the US, while the device carries the ‘Razr 40 Ultra’ name elsewhere. Having said that, in this article, we’ll compare the Samsung Galaxy Z Flip 4 vs Motorola Razr+. The Galaxy Z Flip 5 is right around the corner, but the Flip 4 is still Samsung’s best flip phone, so… there you go.

We’ll first list the specs of both devices, and will then proceed to compare them across a number of different categories. We’ll compare their designs, displays, performance, battery life, cameras, and audio performance. Just to be perfectly clear, we’ll refer to Motorola’s new handset as the ‘Razr+’ from now on, but what is said here applies for the same model in other markets, basically. They’re the same devices, we just had the privilege to test the ‘Razr+’ in the US.

Specs

Samsung Galaxy Z Flip 4 Motorola Razr+
Screen size Main: 6.7-inch fullHD+ Dynamic AMOLED display (foldable, 120Hz)
Secondary (Cover): 1.9-inch Super AMOLED display (flat, 60Hz)
Main: 6.9-inch fullHD+ LTPO AMOLED (foldable, 165Hz)
Secondary (Cover): 3.6-inch AMOLED display (flat, 144Hz)
Screen resolution Main: 2640 x 1080
Secondary (Cover): 260 x 512
Main: 2640 x 1080
Secondary (Cover): 1056 x 1066
SoC Qualcomm Snapdragon 8+ Gen 1 Qualcomm Snapdragon 8+ Gen 1
RAM 8GB 8GB/12GB
Storage 128GB/256GB/512GB (UFS 3.1), non-expandable 256GB/512GB (UFS 3.1), non-expandable
Rear cameras 12MP (f/1.8 aperture, 24mm lens, 1.8um pixel size, OIS, Dual Pixel PDAF)
12MP (f/2.2 aperture, 123-degree FoV, 1.12um pixel size, ultrawide)
12MP (f/1.5 aperture, 1.4um pixel size, OIS, PDAF)
13MP (f/2.2 aperture, 108-degree FoV, 1.12um pixel size)
Front cameras 10MP (f/2.4 aperture, 26mm lens, 1.22um pixel size) 32MP (f/2.4 aperture, 0.7um pixel size)
Battery 3,700mAh, non-removable, 25W wired charging, 15W wireless charging, 4.5W reverse wireless charging
Charger not included
3,800mAh, non-removable, 30W fast wired charging, 5W wireless charging
Charger included (not in the US)
Dimensions Unfolded: 165.2 x 71.9 x 6.9mm
Folded: 84.9 x 71.9 x 15.9-17.1mm
Unfolded: 170.8 x 74 x 7mm
Folded: 88.4 x 74 x 15.1mm
Weight 187 grams 184.5/188.5 grams
Connectivity 5G, LTE, NFC, Bluetooth 5.2, Wi-Fi, USB Type-C 5G, LTE, NFC, Bluetooth 5.3, Wi-Fi, USB Type-C
Security Side-facing fingerprint scanner Side-facing fingerprint scanner
OS Android 12
One UI 4.1.1
Android 13
Price $999.99 $999
Buy Samsung Amazon

Samsung Galaxy Z Flip 4 vs Motorola Razr+: Design

Both phones are made out of aluminum and glass. The Razr+ does also come in a variant with a vegan leather backplate, though. Both phones fold right down the middle, of course, and both have two cameras on the back. You’ll also notice a centered camera hole on both devices, on their main displays. The bezels are rather thin around those displays, by the way. The sides on the Galaxy Z Flip 4 are flatter than they are on the Razr+.

One important difference between them is the fact the Razr+ folds flat, and it also has a less noticeable crease. The Motorola Razr+ has horizontally-aligned cameras on the back, while the Galaxy Z Flip 4 includes a vertically-oriented ones. They both have cover displays, but the one on the Razr+ is much larger. It even goes around the rear cameras on the phone. We’ll talk more about the displays in the next chapter.

The Motorola Razr+ is slightly lighter than the Galaxy Z Flip 4, while it’s taller, wider, and about the same thickness when unfolded. When folded, the Motorola Razr+ is thinner than Samsung’s handset. They do have a rather similar feeling in the hand, even though you’ll feel the difference between them. The Galaxy Z Flip 4 is IPX8 rated, so it’s water resistant. The Motorola Razr+ comes with a water-repellent coating.

Samsung Galaxy Z Flip 4 vs Motorola Razr+: Display

Samsung Galaxy Z Flip 4 AM AH 2
Samsung Galaxy Z Flip 4

The Galaxy Z Flip 4 features a 6.7-inch fullHD+ (2640 x 1080) main display. That is a foldable Dynamic AMOLED 2X panel. It has a 120Hz refresh rate, and it supports HDR10+ content. This panel gets up to 1,200 nits of brightness at its peak. There is a second panel on the back, and it measures 1.9 inches. That is a Super AMOLED display with a 260 x 512 resolution. That second panel is protected by the Gorilla Glass Victus+.

The Motorola Razr+, on the flip side, includes a 6.9-inch fullHD+ (2640 x 1080) main panel. That is a foldable LTPO AMOLED display. It can project up to 1 billion colors, and has a 165Hz refresh rate. HDR10+ content is supported by this display, and the panel goes up to 1,400 nits of brightness at its peak. The second panel on the phone measures 3.6 inches, and has a 1056 x 1066 resolution. That is an AMOLED display that can project up to 1 billion colors. It has a 144Hz refresh rate, and supports HDR10+ content. This panel goes up to 1,100 nits of brightness at its peak, and it’s protected by the Gorilla Glass Victus.

We basically don’t have any major complaints about any of these displays, at least as far as image projection is concerned. They’re all vivid, and offer good viewing angles. They’re also sharp enough. The refresh rate of the Galaxy Z Flip 4’s second display is not that important considering the way it’s meant to be used, but the Motorola Razr+ definitely has the edge there. The crease on the Motorola Razr+’s main display is also less noticeable, so that’s certainly a plus. It’ll not only poke you less in the eyes, but you’ll feel it less under your fingers.

One important difference between the cover displays on these two phones is the number of things you can do with them. The Motorola Razr+ allows you to use its cover display to full extent. In other words, you can run full apps on it. The same cannot be said for the Galaxy Z Flip 4’s panel, which is meant to be used mainly for widgets.

Samsung Galaxy Z Flip 4 vs Motorola Razr+: Performance

The Snapdragon 8+ Gen 1 fuels both of these smartphones. That is not Qualcomm’s latest and greatest chip, but it’s the next best thing. The Galaxy Z Flip 4 comes with 8GB of LPDDR5 RAM, and up to 512GB of UFS 3.1 flash storage. The Motorola Razr+, on the other hand, offers up to 12GB of LPDDR5 RAM, and up to 512GB of UFS 3.1 flash storage. Neither phone offers expandable storage, by the way.

When it comes to performance, you’ll be happy with both of them. The software runs smoothly on both phones, regardless of what you’re doing. Simpler tasks are not a problem, and the same can be said for more demanding tasks too. Even if you decide to play some games on these two phones, they will do a fine job, even those demanding titles. On the Motorola Razr+, you can even use the second display to play full games, if you’re so inclined. Neither phone gets too hot for use after a longer gaming session either, even though they do get quite warm, which is normal.

Samsung Galaxy Z Flip 4 vs Motorola Razr+: Battery

There is a 3,700mAh battery included inside the Galaxy Z Flip 4, while the Motorola Razr+ has a 3,800mAh battery on the inside. The Motorola Razr+ does have a slightly larger battery, but also larger displays, and higher refresh rates. Looking just at those facts, the battery life shouldn’t be too different. Well, it is not, but the Motorola Razr+ does offer better battery life, at least it did during our testing.
With the Galaxy Z Flip 4, we were able to get around 7-7.5 hours of screen-on-time, while the Motorola Razr+ pushes that to 7.5-8 hours of screen-on-time. This doesn’t have to mean much to you, as your results may be entirely different. It should give you an idea of what the phones are capable of when it comes to battery life, though. We did not game much during our testing, but we did not spare either phone, of course. These are numbers that we were able to achieve during more normal usage days, not the ones in which we used the camera for hours. As I said, though, your mileage may vary for a number of reasons.

What about charging? The Galaxy Z Flip 4 supports 25W wired, 15W wireless, and 4.5W reverse wireless charging. The Motorola Razr+ supports 30W wired, and 5W wireless charging. Neither phone comes with a charger in the US, but the Motorola Razr+ may include one in some other markets, so keep that in mind.

Samsung Galaxy Z Flip 4 vs Motorola Razr+: Cameras

A 12-megapixel main camera can be found on the Galaxy Z Flip 4, along with a 12-megapixel ultrawide unit (123-degree FoV). The Motorola Razr+, on the flip side, has a 12-megapixel main camera, and a 13-megapixel ultrawide unit (108-degree FoV). The ultrawide camera on the Galaxy Z Flip 4 has a much wider field of view, and that is something we appreciated, as you can stuff a lot more content in the frame.

Motorola Razr plus 2023 review AM AH1
Motorola Razr+

Having said that, how do they perform? Well, based on the images taken side-by-side, the Galaxy Z Flip 4 tends to offer more saturated images, as expected. That is, at times, an advantage, and at times a disadvantage. It handles HDR conditions better during the daytime, but then again that added saturation can ruin some images, like skin tones in some cases, and so on. The Motorola Razr+, on the other hand, tends to provide rather dull images at times, while in other situations it does a great job.

In low light, we preferred the Motorola Razr+ most of the time. It handled street lights a lot better, and the same goes for neon signs. It’s kind of a different situation than when it comes to daylight shots, where the Galaxy Z Flip 4 was mostly the better device. Their ultrawide cameras do follow this same pattern, more or less.

Audio

You will find a set of stereo speakers on both of these phones. The speakers on the Motorola Razr+ were louder, though, while the sound output is really good from both devices. They’re well-balanced, though don’t expect miracles, of course.

An audio jack is not included on either device. You’ll have to resort to their Type-C ports for wired audio connections. If you prefer to go wireless, that’s not a problem. Bluetooth 5.2 is available on the Galaxy Z Flip 4, while Bluetooth 5.3 can be utilized on the Motorola Razr+.


[ad_2]
Source link

US government to launch a public working group for AI

0
[ad_1]

After seeking public opinion on regulating AI, the US government now wants to launch a public working group consisting of volunteer experts to address AI risks and benefits. The initiative is launched by the National Institute of Standards and Technology (NIST). It focuses on AI technology capable of producing images, videos, text, code, and music.

As AI is taking over different aspects of our life, governments worldwide must be quick to design regulations to mitigate risks and challenges. The US government is somehow at the forefront of AI regulations and even aims to collaborate with the EU in this regard. Gina Raimondo, the US Secretary of Commerce, is now asking AI volunteer experts to share their feedback with the government.

This public working group focuses on generative AI and wants to weigh the AI risks for society as well as its benefits for different sectors. This is the second request for comment (RFC) by a government agency after the first RFC in April.

The US government is asking for volunteer experts’ opinions on generative AI

The final product of this public working group would be a set of guidelines for companies to tackle risks generated by AI. The group works through a collaborative online workspace.

NIST has already developed an “AI Risk Management Framework”. This framework helps the agency manage risks AI could pose to individuals, organizations, and society. The public working group first needs to find out if this guideline could be used to support generative AI development. Then, it needs to support NIST’s AI-related tests and evaluations. Finally, this group must find a way to drive AI capabilities to solve critical health and environmental issues.

“President Biden has been clear that we must work to harness the enormous potential while managing the risks posed by AI to our economy, national security, and society,” Raimondo said in a statement. “Building on the framework, this new public working group will help provide essential guidance for those organizations that are developing, deploying, and using generative AI, and who have a responsibility to ensure its trustworthiness.”

Despite its endless benefits, AI is becoming a source of concern for Big Tech like Apple and Google. Both companies have prohibited their employees from using AI chatbots and sharing confidential material with it.


[ad_2]
Source link

Importance, Risks, and Test Cases

0
[ad_1]

In the ever-evolving landscape of system connectivity, APIs have transformed how information is shared and utilized. However, their widespread adoption has introduced security risks that cannot be ignored. 

LinkedIn’s data breach, where approximately 92% of data was exposed due to inadequate API authentication, serves as a reminder of the consequences of overlooking security measures. 

To address these concerns, API security testing has emerged as a leading-edge approach to unveil vulnerabilities and enhance operational efficiency.

What is API Security Testing?

API security testing refers to assessing the security of an Application Programming Interface (API). API security testing focuses on identifying vulnerabilities and weaknesses in the API implementation that attackers could exploit.

The goal is to ensure the API’s confidentiality, integrity, availability, and the data it handles. 

By conducting security testing, organizations can proactively identify and mitigate potential risks, protect sensitive information, and prevent unauthorized access to the API.

Why Is API Security Important?

API security testing is vital for several reasons, and understanding the significance becomes clearer when considering real-world API breaches and their implications. Here are a few examples:

Data breaches: APIs often handle sensitive data, such as personal information, financial data, or intellectual property. Inadequate API security can lead to data breaches, where attackers gain unauthorized access to this information.

For instance, the Facebook-Cambridge Analytica scandal involved the unauthorized access of user data through a vulnerable API, resulting in the misuse of personal information for political purposes.

Unauthorized access and account takeover: Weak authentication mechanisms or improper authorization controls can allow attackers to gain unauthorized access to user accounts or system functionalities.

In 2018, a vulnerability in T-Mobile’s API allowed hackers to access customer data, including names, addresses, and account numbers, leading to potential account takeovers and identity theft.

Injection attacks: APIs that lack proper input validation and output encoding are susceptible to injection attacks. In 2017, the Equifax breach occurred due to an unpatched vulnerability in an API, which allowed attackers to execute a remote code injection, compromising the personal information of approximately 147 million people.

Denial-of-Service (DoS) attacks: APIs that do not implement rate limiting or throttling mechanisms are vulnerable to DoS attacks. In 2016, the Dyn DNS attack targeted a vulnerable API, causing widespread internet outages by overwhelming DNS servers with massive requests and rendering many popular websites and services inaccessible.

Insecure direct object references: Insufficient access controls can lead to broken object-level authorization, where attackers manipulate parameters to gain access to unauthorized resources. In 2019, a vulnerability in Capital One’s API allowed an attacker to exploit this weakness, resulting in the unauthorized access of over 100 million customer records.

These examples highlight the potential consequences of API security vulnerabilities. Breaches can result in significant financial losses, damage to a company’s reputation, loss of customer trust, legal repercussions, and regulatory penalties. 

API security testing plays a crucial role in identifying and mitigating these vulnerabilities, helping organizations proactively secure their APIs and prevent such breaches from occurring.

By conducting thorough security testing, organizations can identify and address potential weaknesses, implement robust security measures, and ensure that sensitive data and system functionalities are adequately protected. 

It allows for detecting vulnerabilities before they are exploited by malicious actors, thereby reducing the risk of breaches and maintaining the integrity and security of APIs and the underlying systems they connect to.

The following reasons below reflect the benefits of API security Testing:

1) Reduces the risk of getting hacked and protects users from API threats and other OWASP API top 10 listed vulnerabilities.

2) Ensures compliance of every new software release with the regulations and standards (HIPAA, GDPR, ISO, and many more).

3) Detect and resolve issues quicker by scanning your APIs regularly.

4) API security integrated with CI/CD mitigates the risk of vulnerabilities.

5) Reduces associated financial or data losses. 

Top Test Cases That API Security Testing Tests For

API security testing can be performed through manual and automated techniques, including security code reviews, vulnerability scanning, penetration testing, and fuzzing.  

Authentication and authorization testing: This includes verifying the effectiveness of authentication mechanisms such as API keys, access tokens, or OAuth. It also involves testing the authorization controls to ensure that only authorized users or applications can access the API resources.

Input validation and output encoding:

  • Testing the API for proper input data validation.
  • Handling malicious inputs.
  • Appropriate output encoding to prevent injection attacks like SQL injection or Cross-Site Scripting (XSS).

Encryption and transport security: Assessing the API’s use of secure communication protocols such as HTTPS and ensuring sensitive data is encrypted properly during transmission.

Error handling and exception management: Testing how the API handles error conditions and exceptions ensures that error messages do not reveal sensitive information and provide sufficient guidance to developers or consumers without exposing vulnerabilities.

Access control and privilege escalation: Evaluating the access controls within the API to ensure that users or applications have appropriate privileges and cannot escalate their privileges to gain unauthorized access.

Session management and statelessness: Testing how the API manages user sessions and maintains statelessness to prevent session-related vulnerabilities, such as session fixation or hijacking.

Rate limiting and throttling: Verifying that the API has mechanisms to prevent abuse, such as rate limiting or throttling, to protect against Denial-of-Service (DoS) attacks.

Logging and monitoring: Assessing the API’s logging capabilities to capture relevant security events and activities. Monitoring the logs and alerts in real-time can help identify suspicious behavior and potential security breaches.

Why Should You Automate API Testing?

Manual testing of large and complex APIs can be tiring and costly. Automating the process can help optimize the workflow by-

● Shortening the testing period

● Increasing test coverage

● Improving testing precision

● Increasing the feedback rate speed

API scanners may use intelligently fuzzed data to identify hidden flaws by understanding what an API expects as input.

Must-Have Features to Look Out for In an API Security Scanner 

Given how API security scanners can help your team patch vulnerabilities and scale in security, let’s take a look at a few must-have features:

● Cloud-based deployment

● Easy integration with development and security tools

● Use of intelligent automation and analytics 

● Customization of rules

● Zero hidden costs

● Availability of extensive reports and metrics

● Comprehensive coverage of attack vectors

● False-positive management 

● Highly configurable API scanner 

● 24×7 support and proof of concepts

● Plugin-based architecture

For seamless communication between connected apps, APIs must operate effectively. API testing enables an API’s proper functionality, security, and dependability. You may track the API lifecycle by selecting the appropriate API security testing tools like Infinite API Scanner from Indusface. 


[ad_2]
Source link

Galaxy S20 series widely getting Samsung’s June update in the US

0
[ad_1]

Samsung is widely rolling out the June security update to the Galaxy S20 series in the US. The rollout began a few days back but was initially limited to factory-unlocked units. The company is now pushing the latest security patch to carrier-locked variants as well.

The June SMR (Security Maintenance Release) for the carrier-locked Galaxy S20, Galaxy S20+, and Galaxy S20 Ultra in the US comes with the firmware build number G98*USQS5HWF2. The rollout is already live on T-Mobile and sister networks, i.e. Sprint and Metro. Samsung should soon expand the rollout to units on the remaining networks. The Galaxy S20 series wasn’t sold carrier-locked by many wireless providers, including AT&T and Verizon.

Like the unlocked units, carrier-locked Galaxy S20 phones are also only getting the latest security fixes with this update. Samsung isn’t pushing any other goodies, SamMobile confirms. The official changelog also doesn’t mention anything. The latest update is all about this month’s vulnerability patches. The Korean behemoth’s monthly security bulletin states that the June SMR contains fixes for more than 60 vulnerabilities across the Galaxy family.

As usual, this is the combined total of Galaxy-specific issues and generic Android OS problems. The former flaws reside in various system apps, services, and components that Samsung adds to Android-powered Galaxy devices from its end. The company patched 11 such flaws this month. The remaining 50-odd patches come from Google and other partner vendors whose components are found in Android devices from various brands, including Samsung.

The June update for Galaxy devices patched three critical Android OS issues

At least three Android OS flaws patched this month were critical, according to Google. If you’re using a carrier-locked Galaxy 20, Galaxy S20+, or Galaxy S20 Ultra in the US, all of these security fixes will be available to you soon. You can check for new updates from the Settings app. Go to the “Software update” menu and tap on “Download and install”. Since updates are released in batches, some users may have to wait a few days to get the OTA (over the air) rollout.

The June security update has already reached most other eligible Galaxy devices in the US, including the Galaxy S22 series, Galaxy S21 series, and all recent foldables. But it’s yet to be available for the Galaxy S23 series. Samsung recently pushed the update in select international markets. The update, which is huge and brings camera improvements, should reach the US over the next few days. We will let you know when the rollout begins.


[ad_2]
Source link

Impersonation policies for YouTube fan channels get more strict

0
[ad_1]

To curb impersonation, YouTube fan channels are getting strict policies. YouTube took to its community page to announce this improvement and also alert fan channels on the coming change. Now most of these channels are to make certain changes or adjustments to the various accounts they run or face the consequences.

This policy change is coming in light of the influx of fan channels on the video-sharing platform. Most of these channels are not what they claim to be, as they are more into stealing content and impersonation. Reposting a video without tagging the creator or using a channel’s avatar or banner on a so-called fan page is now so common on YouTube.

With this change in the YouTube impersonation policy, most content creators will be able to protect their work from being stolen. Also, it will help guide those scrolling through YouTube to know the actual source of the videos that they enjoy watching. Let’s now have a look at the changes to the YouTube impersonation policies.

Details on the new impersonation policies that will affect some YouTube fan channels

In a bid to fight impersonation on its platform, YouTube is changing some of its policies. This change might spell the end for some accounts now present on YouTube, masquerading as fan accounts. Instead of these accounts acknowledging the works of content creators, they are outrightly stealing these works from them.

Now, the video-sharing platform requires all fan accounts to clearly state their objective. This means that fan accounts have to point out through their “channel name or handle” that their channel isn’t representing the source of their posts. By doing this, they’d be able to make it clear to other users that they have no link to the creator (source of the videos they repost) but they are only their fans.

In the coming months, permit fan accounts that outrightly repost the content of others on the platform. Also, fan accounts that make use of an original account’s logo, avatar, banner, or other identifying elements will face punishment. YouTube tags these actions as impersonation and not fandom, any account doing this will face some penalties.

The new impersonation policy will go into effect on August 21, 2023, so all fan accounts can make necessary changes. These will include brushing up their channel to not look like that of the YouTuber they are fans of. Failure to make these changes before the deadline will mean that the fan account will be deleted for violation of the impersonation policy.


[ad_2]
Source link

Chinese Espionage Malware Targets European Healthcare via USB Drives

0
[ad_1]

It all started when an employee attending an Asian conference unknowingly introduced malware to their organization in Europe by sharing a presentation with a colleague using a compromised USB drive.

According to a report by Check Point Research (CPR), a recent surge in new versions of Chinese espionage malware has raised concerns as they rapidly propagate through infected USB drives.

The malware campaign was discovered during an investigation into an attack on a healthcare institution in Europe, shedding light on the activities of the Chinese threat actor known as Mustang Panda, also known as TA416, Red Lich, Earth Preta, HoneyMyte, and Bronze President, Camaro Dragon and LuminousMoth.

It is worth noting that earlier in March of this year, Mustang Panda was observed using a new MQsTTang backdoor against government and political organizations across Asia and Europe.

While Mustang Panda has historically focused on Southeast Asian nations, this incident has unveiled their expanded global reach. The attack initially gained access to the institution’s systems through an infected USB drive.

An employee, who had attended a conference in Asia, unknowingly shared a presentation with a colleague using the compromised USB drive, thus introducing the malware into the organization upon their return to Europe.

The malware, as stated in CPR’s blog post, by part of the “SSE” toolset previously reported by Avast, employs a malicious Delphi launcher stored on the infected USB flash drive. Once executed, it deploys a main backdoor and spreads the infection to other connected drives.

One particularly potent variant of the malware, named WispRider, employs the HopperTick launcher to propagate through USB drives. Notably, it includes a bypass mechanism specifically designed to evade SmadAV, a popular antivirus software in Southeast Asia.

To enhance its evasion capabilities, the malware utilizes DLL-sideloading techniques, leveraging components from security software and prominent gaming companies. This multi-pronged approach enables the malware to establish backdoors on compromised machines while simultaneously infecting newly connected removable drives, potentially infiltrating isolated systems and granting access to a wide range of entities beyond the primary targets.

The CPR advisory serves as a timely warning following the company’s recent identification of a separate attack vector attributed to the Mustang Panda. The ongoing activities of this Chinese threat actor highlight the critical need for organizations to remain vigilant against evolving cyber threats and maintain robust security measures, especially when handling external storage devices like USB drives.

The technical research on this growing threat is available here.

  1. Hackers mailing USB drives to spread ransomware, FBI
  2. Hackers sending malware USBs with Best Buy Gift Cards
  3. US Military Targeted by Unsolicited Malicious Smartwatches
  4. New malware tool steals files from airgapped PCs using USBs
  5. USB Wormable Raspberry Robin Malware Hits Windows Installer
  6. VictoryGate cryptominer infected 35,000 devices via USB drives

[ad_2]
Source link

Can ChatGPT Detect Phishing Sites?

0
[ad_1]
ChatGPT Detect Phishing Sites

The subject of whether ChatGPT can be used to create phishing sites and if it can also be used to detect them accurately has been discussed by security researchers.

This experiment has been conducted to see how much cybersecurity information ChatGPT has picked up from its training data and how it may help human analysts.

Researchers from Kaspersky examined 5,265 URLs, of which 2943 were safe, and 2322 were phishing.

Implementing AI-Powered Email security solutions can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware – Request Free Demo.

Based on URLs, Can ChatGPT Detect Phishing?

Researchers asked the straightforward inquiry, “Does this link lead to a phishing website?” to ChatGPT (GPT-3.5). The AI chatbot had a detection rate of 87.2% and a false positive rate of 23.2% based just on the URL format.

According to the reports, the number of false positives is unsatisfactory despite the high detection rate.

If every fifth website you visit was blocked, what would happen? Although no machine learning method can guarantee a false positive rate of zero, this figure is still too high.

Is this link safe to visit?” they asked, and the outcomes were significantly worse: a false positive rate of 64.3% and a detection rate of 93.8%.

“It turns out that the more general prompt is more likely to prompt a verdict that the link is dangerous”, reports Kaspersky.

The extraction of the possible phishing victim was the most impressive feature of ChatGPT’s performance. 

Possible Phishing Attack

Attackers strive to deceive consumers into thinking that a URL is legitimate and belongs to a particular organization while simultaneously obfuscating it just enough to evade automated examination when they create their samples.

In many situations, removing the assault target might be helpful.

Researchers added that ChatGPT performs a great job of extracting various internet and financial services with only a tiny amount of post-processing (e.g., combining “Apple” and “iCloud” or deleting “LLC” and “Inc”). 

Major online websites like Facebook, TikTok, and Google were among the organizations mentioned.

There were also marketplaces like Amazon and Steam, many banks from around the world, from Australia to Russia, and cryptocurrency and delivery services.

This is because ChatGPT has enough real-world information to know about them. More than half the time, it was successful in locating a target.

The findings from both strategies were insufficient. “It is possible to use this type of technology to assist flesh-and-blood analysts by highlighting suspicious parts of the URL and suggesting possible attack targets. It could also be used in weak supervision pipelines to improve classic ML pipelines”, researchers said.

According to reports, it performs on par with what they would anticipate from a phishing analyst intern: it is good, but never leave it unattended!

Overall, the researchers concluded that ChatGPT and LLMs are not yet prepared to fundamentally alter the cybersecurity landscape, at least not in terms of phishing detection.

Upgrade your email security to AI-enhanced levels with Trustifi – Try Free Demo


[ad_2]
Source link

Nothing OS screenshot points to a certain design detail

0
[ad_1]

It isn’t often that a screenshot reveals information about a device’s physical design, yet, here we are! Carl Pei showed off a screenshot to Twitter, and it looks like it might have been taken from Nothing OS 2.0. If that’s the case, then the latest slew of leaked Nothing (2) images could be inaccurate (via Android Police).

Right now, there’s still a lot of information in the air about the company’s second handset. Information like the specs, price, design, etc. are still speculation.

Speaking of price, a new rumor hints at a notable price increase over the Nothing Phone (1). The Nothing Phone (2) might cost around $800 for the 256GB variant and about $930 for the 512GB variant. We’ll need to wait for more information to confirm this.

This screenshot might show us Nothing OS 2.0

So, you’ll want to take this with a grain of salt. We all know that Carl Pei really likes to hype up the company’s products. However, neither Pei nor the company alluded to this being a nod toward Nothing OS 2.0.

On Thursday, Carl Pei posted a screenshot of his home screen to Twitter and asked others to share theirs. We’d assume that this would be shared from a Nothing Phone (1), but people noticed something notable about the image.

Nothing os 2 screenshot 1

This screenshot might tell us where the phone’s selfie camera will be located. The Nothing Phone (1) has its punch-hole on the upper-left corner of the phone’s display. However, the screenshot shows the clock in the left corner of the display where the punch-hole would be. The other symbols are in the right corner.

This could point to the phone having a center punch-hole. This disputes the previous leak because it shows the phone with a punch-hole on the left. Carl Pei even came out and said that those images weren’t real.

Since this screenshot is coming from Carl Pei himself, we know that it’s legitimate. The Nothing Phone (2) is set to make an appearance next month, so if you’re excited about it, then keep your eyes peeled for the launch event.


[ad_2]
Source link