Spotify fined $5.4 million for allegedly mishandling user data

0
[ad_1]

Over the past few years, the European Union has been the top watchdog when it comes to safeguarding its people’s data. Now, in line with these efforts, the Swedish Authority for Privacy Protection (IMY) has fined Spotify of SEK 58 million ($5.4 million) for allegedly mishandling user data, thereby breaching the General Data Protection Regulation (GDPR).

The complaint, lodged in 2019 by privacy advocacy group Noyb, led by campaigner Max Schrems, stated that Spotify not only failed to provide customer data upon request but also neglected to disclose the purpose of processing such data. Additionally, upon further investigation, the IMY also found that Spotify couldn’t adequately explain how they were using this data, raising some serious concerns.

As a result, the IMY has now ordered Spotify to provide the complete set of requested data and emphasized the need for the company to be transparent about how they handle personal data and the purposes for which they process it.

Stefano Rossetti, a privacy lawyer at Noyb, expressed his satisfaction with IMY finally taking action and stated that it is a basic right for every user to have full information about their processed data. However, he also highlighted the prolonged duration of the case and the need for the Swedish authority to expedite its procedures.

Spotify’s response

While Spotify’s inadequate measures to protect customer data raised some concerns, the IMY considered the violations to be of “low level of seriousness” and recognized that Spotify had taken steps to address the issues. Moreover, the authority also mentioned that they fined Spotify based on its revenue and user count.

In response to the fine, a Spotify spokesperson stated, “Spotify offers all users comprehensive information about how personal data is processed. During their investigation, the Swedish DPA found only minor areas of our process they believe need improvement. However, we don’t agree with the decision and plan to file an appeal.”


[ad_2]
Source link

Save $200 on the Dolby Atmos-powered Sony HT-A3000 Soundbar

0
[ad_1]

Today, Amazon has a great deal on a pretty good soundbar from Sony. It’s the Sony HT-A3000 which is a Dolby Atmos soundbar, and now it’s just $498. That’s going to save you $200 off of its regular price. Making this a really great deal.

Sony HT-A3000 Soundbar – Amazon

Why you should buy the Sony HT-A3000 soundbar

The Sony HT-A3000 is a great soundbar for anyone looking to upgrade their home theater experience. It offers immersive surround sound, thanks to its support for Dolby Atmos and DTS:X. The soundbar also has a sleek and compact design that will look great in any room.

Here are some of the reasons why you should buy the Sony HT-A3000:

  • Immersive surround sound: The Sony HT-A3000 supports Dolby Atmos and DTS:X surround sound, which creates a more immersive audio experience. This is ideal for watching movies or TV shows, as it will make you feel like you are right in the middle of the action.
  • Sleek and compact design: The Sony HT-A3000 has a sleek and compact design that will look great in any room. It is also relatively lightweight, making it easy to move around if needed.
  • Powerful bass: The Sony HT-A3000 is powered by two 100W subwoofers that deliver powerful bass and clear sound. This is ideal for watching action movies or listening to music.
  • Built-in features: The Sony HT-A3000 has a number of built-in features, such as Bluetooth, Wi-Fi, and Google Assistant compatibility. This makes it easy to connect to your devices and control the soundbar with your voice.

If you are looking for a great soundbar that offers immersive surround sound, a sleek and compact design, powerful bass, and built-in features, the Sony HT-A3000 is a great option. It is currently on sale for just $498, which is a great deal for a soundbar with this level of performance and features.

Sony HT-A3000 Soundbar – Amazon


[ad_2]
Source link

Popular Reddit app might adopt a subscription based model

0
[ad_1]

Reddit’s recent decision to start charging for API access has caused widespread outrage among Redditors, as it would essentially be the end of many popular third-party clients unless they are willing to pay exorbitant fees each month. However, it looks like Relay for Android, the popular Reddit client, might have found a way to survive the API changes by implementing a new strategy.

In a recent blog post, developer Dave shared his insights on the future of the app and stated that the current free version of Relay would no longer be financially sustainable. Instead, the app will adopt a subscription-based model, which will also come with the added benefits of no ads or recommended content.

However, Dave also acknowledged the challenges associated with transitioning to a subscription-based model and explained that the success of this new approach would depend on users’ willingness to stick with Relay and embrace the subscription system. Additionally, he also expressed concerns about the tight timeline to implement the necessary changes, as Reddit’s new API pricing goes into effect on July 1st.

“The entire model is ultimately subject to how many, and what type of, users choose to stay with Relay as a subscription-based app. I want to stress that my estimates are only relevant to call data collected by Relay for Relay. Other apps have different layouts and feature sets,” said Dave.

Pricing structure

Under this new proposed model, users might need to pay a base subscription fee of $2 per month along with an additional $1 fee for the message notifications to accounts. However, it is important to note that the current pricing model is based on the latest release of Relay for Reddit, which included bug fixes and other changes aimed at reducing API calls.

Although the prospect of Relay surviving this API change is exciting and showcases developers’ determination to navigate evolving platform policies while providing users with a positive experience, it’s crucial to recognize that these projections are purely speculative at this point, and the future of the app remains uncertain.


[ad_2]
Source link

Ticket scammers target Taylor Swift tour

0
[ad_1]

We take a look at multiple reports of ticket reseller fraud aimed at fans of Taylor Swift’s Era tour.

Taylor Swift fans are being warned to be cautious when buying tickets for her current “Eras” tour, with scammers waiting in the wings to trick would-be gig goers. The Better Business Bureau says it has received somewhere in the region of 200 complaints from residents of Michigan, and there’s bound to be more from other locations.

The issue is so bad that Michigan’s Attorney General advised the local “Swifties” about fraud in relation to last weekend’s Michigan leg of the tour. His warning reads as follows:

“Michigan residents who are defrauded by online ticket scammers should not just shake it off,” said Nessel. “We know these scams all too well. If you believe you were taken advantage of, filing a complaint with my office is better than revenge.”

Reports of scammers taking advantage of Swift’s fans, called Swifties, indicate some have lost as much as $2,500 paying for tickets that don’t exist or that never arrive. The Better Business Bureau has reportedly received almost 200 complaints nationally related to the Swift tour. The complaints range from refund struggles to outright scams.

Other locations for the tour are trying to get ahead of the scam curve, issuing their own warnings ahead of events where possible. For example, Cincinnati has highlighted tales of woe related to fake ticket sales on Facebook. Detroit flagged fake ticket sales on Instagram. CBC covered multiple fake sale attempts cheating folks in Canada out of significant chunks of money. Elsewhere, teens have lost out on $1,200 thanks to Craigslist scammers.

With something like 19 dates left in the US alone stretching from Minneapolis and Pittsburgh to Los Angeles and Seattle, there’s still plenty of opportunity for scammers to crawl out of the woodwork. These are undoubtedly the hottest music tickets around at the moment, so you’ll want to follow some common sense rules before trying to get your hands on some. This is especially the case given that the only ticket source left may be resellers.

How to avoid ticket scams

  • Research the ticket seller. Anybody can set up a fake ticket website, and sponsored ads showing at the top of search engines can be rife with bogus sellers. You may also run into issues buying tickets from sites like ebay. Should you decide to use sites other than well known entities like Ticketmaster, check for feedback on the BBB website.
  • Use a credit card if possible. You’ll almost certainly have more protection than if you pay using your debit card, or cash. We definitely recommend that you avoid using cash. If someone decides to rip you off, that money is gone forever.
  • A “secure” website isn’t all it seems. While sites that use HTTPS (the padlock) ensure your communication is secure, this does not guarantee the site is legitimate. Anyone can set up a HTTPs website, including scammers.
  • It’s ticket inspector time. One of the best ways to know for sure that your ticket is genuine is to actually look at it. Is the date and time correct? The city, the location? Are the seat numbers what you were expecting to see? It may well be worth calling the event organisers or the event location and confirming that all is as it should be. Some events will give examples of what a genuine ticket should look like on the official website.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

Google Messages gets a home screen makeover

0
[ad_1]

Most apps are destined to get redesigns over time, and that goes especially for apps owned by major companies. Google Messages, the main SMS/RCS messaging app from Google, is getting a small redesign that brings a bit of attention to Google’s branding.

Google Messages comes with several useful features that really make it a nice messaging app. If you are an Android user, and you want to try out some of these features, you can always download Google Messages from the Google Play Store. You’ll just have to assign it as the default messaging app when you open it on your device.

Download Google Messages

Google Messages gets a redesign

This comes to us from 9To5Google. The redesign mostly affects the home screen. So, everything else throughout the rest of the app looks the same. The main change with this redesign is the lack of a navigation drawer. The navigation drawer was usually on the top left corner of the UI inside of the search bar. Both it and the search bar are now gone.

After the redesign, you’ll see the four-color Google logo on the top left corner of the UI, and it’s followed by the word messages. On the right side, you’ll see your profile picture as usual, but you’ll also see a magnifying glass icon. This will bring on the search function.

So, where’s the navigation drawer going? You might be wondering how to access the items that once lived within it. Well, when you tap on your profile picture, you will see those items moved to that menu. If you want to change your theme, you have to do so in the settings.

There’s another notable change, and that has to do with the search feature. Before the redesign, you would tap on the search bar and be presented with a carousel of different items like categories and such. Now, when you tap on the magnifying glass icon, you will see a grid of your categories. They’re all laid out so you can see everything on one screen as opposed to the older method.

This is a nice upgrade to make the interface a bit more unified and more consistent across the ecosystem of Google apps. If you don’t see this, make sure that your app is fully updated.


[ad_2]
Source link

Samsung’s impressive update policy may have just got better

0
[ad_1]

Samsung has the best update policy in the Android space today. While a few other companies match its policy of four major Android OS updates and five years of security updates, they only cover their flagship models. The Korean firm, on the other hand, offers the same update support to some mid-range models as well. And if that wasn’t already enough for Samsung to be called the undisputed king of Android updates, it may have just upped its game.

Samsung seems to have upgraded its already impressive update policy

Samsung maintains a list of devices that are eligible for new security updates. It divides all eligible models into three update categories: monthly, quarterly, and bi-annual, with the latter meaning two updates in a year. Flagships and premium mid-range models start at monthly patches before dropping to the less-frequent categories over time. All other devices start at quarterly patches and drop to the bi-annual category after a few years.

Usually, flagship models get monthly updates for up to three years from their launch before dropping to quarterly updates. However, as you can see in the official list here, the Galaxy S20 series is still getting monthly updates. The 2020 flagships completed three years on the market in March 2023. Almost three months into the fourth year, Samsung hasn’t dropped them to the less-frequent security update category.

This suggests that Samsung has further upgraded its already impressive update policy. It appears to be offering monthly security patches to flagship models for four years. The devices may be dropped to quarter updates in the fifth year. We will have to wait one more year to find out, though. That’s because flagship Samsung phones launched before the Galaxy S20 series aren’t eligible for five years of security updates. The company has already stopped pushing new updates to the Galaxy S10 series.

On that note, when Samsung announced five years of security patches for Galaxy devices, it didn’t reveal the frequency of the updates across those five years. The company may have always intended to offer monthly updates for the first four years and quarterly updates in the final year, at least for flagship models.

We are finding it now because the Galaxy S20 series is the oldest flagship to get extended update support. When Samsung offered security updates for a total of four years, it was a 3+1 system. We will let you know if the company releases an official statement on the matter or if it demotes the Galaxy s20 series to quarterly patches in the coming months.


[ad_2]
Source link

Update Chrome now! Google fixes critical vulnerability in Autofill payments

0
[ad_1]

Google has released an update which includes five security fixes including a critical vulnerability in Autofill payments.

Google has released a Chrome update which includes five security fixes. One of these security fixes is for a critical vulnerability in Autofill payments.

Google labels vulnerabilities as critical if they allow an attacker to run arbitrary code on the underlying platform with the user’s privileges in the normal course of browsing.

How to protect yourself

If you’re a Chrome user on Windows, Mac, or Linux, you should update as soon as possible. 114.0.5735.130/.131 for Android will become available on Google Play over the next few days.

The easiest way to update Chrome is to allow it to update automatically, which basically uses the same method as outlined below but does not require your attention. But you can end up lagging behind if you never close the browser or if something goes wrong—such as an extension stopping you from updating the browser.

So, it doesn’t hurt to check now and then. And now would be a good time, given the severity of the vulnerabilities in this batch. My preferred method is to have Chrome open the page chrome://settings/help which you can also find by clicking Settings > About Chrome.

If there is an update available, Chrome will notify you and start downloading it. Then all you have to do is relaunch the browser in order for the update to complete.

Chrome displays the Relaunch button to complete the updateChrome needs a relaunch to apply the update

After the update, your version should be 114.0.5735.133 for Mac and Linux, and 114.0.5735.133/134 for Windows, or later.

The critical vulnerability

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The critical CVE patched in these updates is listed as CVE-2023-3214:  Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Google is always very careful about providing information about vulnerabilities, for obvious reasons. Access to bug details and links may be kept restricted until a majority of users are updated with a fix. However, from the vulnerability description we can learn a few things.

The Autofill payments function is to automatically enter payment details in online forms.

Use after free (UAF) is a type of vulnerability that is the result of the incorrect use of dynamic memory during a program’s operation. If, after freeing a memory location, a program does not clear the pointer to that memory, an attacker can use the error to manipulate the program.

Heap corruption occurs when a program modifies the contents of a memory location outside of the memory allocated to the program. The outcome can be relatively benign and cause a memory leak, or it may be fatal and cause a memory fault, usually in the program that causes the corruption.

A remote attack means that this vulnerability could potentially be exploited by tricking the user into visiting a specially crafted website.

Whether all this actually means that vulnerable Chrome versions will spill payments details on such a website remains to be seen, but it’s not the unlikeliest of scenarios.


We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using Malwarebytes Vulnerability and Patch Management.


[ad_2]
Source link

Samsung Galaxy Z Fold 4 vs Huawei Mate X3

0
[ad_1]

Huawei introduced one of the best-looking and feeling book-style foldables earlier this year, the Huawei Mate X3. That phone launched in more markets not long ago, and it’s time to compare it to the best Samsung has to offer. In this article, we’ll compare the Samsung Galaxy Z Fold 4 vs Huawei Mate X3. Granted, the Fold 5 is right around the corner, as it’s coming next month, but until it does, the Fold 4 is the foldable we’re aiming at.

Both of these phones are book-style foldables, but they’re quite different, in a number of ways. Even their designs are quite different, despite the fact they have similar display sizes. There’s a lot to talk about here. We’ll first list their specs, and will then move to compare their designs, displays, performance, battery life, cameras, and audio performance. So, let’s get started.

Specs

Samsung Galaxy Z Fold 4 Huawei Mate X3
Screen size Main: 7.6-inch fullHD+ Dynamic AMOLED 2X display (foldable, 120Hz)
Secondary (Cover): 6.2-inch HD+ Dynamic AMOLED 2X display (flat, 120Hz)
Main: 7.85-inch QHD+ OLED (foldable, 120Hz)
Secondary (Cover): 6.4-inch fullHD+ OLED display (flat, 120Hz)
Screen resolution Main: 2176 x 1812
Secondary (Cover): 2316 x 904
Main: 2224 x 2496
Secondary (Cover): 2504 x 1080
SoC Qualcomm Snapdragon 8+ Gen 1 Qualcomm Snapdragon 8+ Gen 1
RAM 12GB (LPDDR5) 12GB
Storage 256GB/512GB/1TB (UFS 3.1), non-expandable 256GB/512GB/1TB, expandable
Rear cameras 50MP (f/1.8 aperture, 24mm lens, 1.0um pixel size, Dual Pixel PDAF, OIS)
10MP (telephoto, f/2.4 aperture, 67mm lens, 1.0um pixel size, PDAF, OIS, 3x optical zoom)
12MP (f/2.2 aperture, 123-degree FoV, 12mm lens, 1.12um pixel size)
50MP (f/1.8 aperture, 23mm lens, PDAF, OIS)
13MP (ultrawide, f/2.2 aperture, 13mm lens)
12MP (periscope telephoto, f/3.4 aperture, OIS, 5x optical zoom)
Front cameras Main: 4MP (f/1.8 aperture, 26mm lens, 2.0um pixel size, under-display)
Secondary: 10MP (f/2.2 aperture, 24mm lens, 1.22um pixel size)
Main: 8MP (wide, f/2.4 aperture)
Cover: 32MP (wide, f/2.4 aperture)
Battery 4,400mAh, non-removable, 25W wired charging, 15W wireless charging, 4.5W Wireless PowerShare
Charger not included
4,800mAh, non-removable, 66W fast wired charging, 50W wireless charging, 7.5W reverse wireless charging
Charger included
Dimensions Unfolded: 155.1 x 130.1 x 6.3mm
Folded: 155.1 x 67.1 x 15.8mm
Unfolded: 156.9 x 141.5 x 5.3mm
Folded: 156.9 x 72.4 x 11.8mm
Weight 263 grams 239/241 grams
Connectivity 5G, LTE, NFC, Bluetooth 5.2, Wi-Fi, USB Type-C 4G LTE, NFC, Bluetooth 5.2, Wi-Fi, USB Type-C
Security Side-facing fingerprint scanner Side-facing fingerprint scanner
OS Android 12 (upgradable)
One UI 4.1.1
Android
EMUI 13.1
Price $1,799 €2,199 ($2,376)
Buy Samsung Huawei

Samsung Galaxy Z Fold 4 vs Huawei Mate X3: Design

Both of these phones are made out of metal and glass (though the Mate X3 also comes in an eco leather variant), and both are book-style foldables. The thing is, the Huawei Mate X3 does fold flat, and it also has a much less noticeable crease. It even has the same water and dust resistance as the Galaxy Z Fold 4, so it’s not lacking in that regard either. As if all that wasn’t enough, its displays are larger, but the phone is considerably thinner and lighter.

The Huawei Mate X3 weighs 239 or 241 grams, depending on the model you get (eco leather or glass), compared to 263 grams of the Galaxy Z Fold 4. The Fold 4 is 6.3mm thick when unfolded, and 14.2-15.8mm when folded. The Huawei Mate X3, on the other hand, is only 5.3mm thick when folded, and 11.8mm when unfolded. Both phones have thin bezels, while the Huawei Mate X3’s outer display is wider than the Fold 4’s, and thus easier to type on.

The Galaxy Z Fold 4 has three cameras on the back, aligned vertically, in the same camera island. The Huawei Mate X3 has a camera oreo on the back, which is centered in the upper portion of the phone. Both phones do include thin bezels, and hinges that allow them to be placed in a number of different angles. Both phones are IPX8 certified for water resistance. The Huawei Mate X3 definitely feels more like a regular phone when folded, due to its thin form factor, weight, and wider display, most of all. It does seem like a more modern product due to a number of factors, but its thin profile, the fact it folds flat, and the fact its crease is much less noticeable, are the main ones.

Samsung Galaxy Z Fold 4 vs Huawei Mate X3: Display

The Galaxy Z Fold 4 includes a 7.6-inch 1812 x 2176 Foldable Dynamic AMOLED 2X display. That panel supports a 120Hz refresh rate, and HDR10+ content. It gets up to 1,200 nits of brightness at its peak. The cover display, on the other hand, measures 6.2 inches, and it has a 2316 x 904 resolution. That is also a Dynamic AMOLED 2X panel, but not a foldable one. It also offers a 120Hz refresh rate, and it’s protected by the Gorilla Glass Victus+.

Samsung Galaxy Z Fold 4 Review AM AH 02

The Huawei Mate X3, on the other hand, has a 7.85-inch 2224 x 2496 Foldable OLED main display. That panel offers a 120Hz refresh rate, and it can project up to 1 billion colors. The cover display measures 6.4 inches, and it’s an OLED panel with a 120Hz refresh rate. That display offers a resolution of 2504 x 1080, and it’s protected by the Huawei Kunlun Glass, which has proven to be great on the Mate 50 Pro.

Both phones have excellent displays. They’re vivid, more than sharp enough, and all of them offer a high refresh rate. The viewing angles are also great on all of them, and the blacks are deep. The crease on the Huawei Mate X3’s main display is less noticeable, and you’ll barely feel it under your finger, which is not something we can say for the Galaxy Z Fold 4’s crease. Either way, all of these displays are more than good enough, and offer good touch response.

Samsung Galaxy Z Fold 4 vs Huawei Mate X3: Performance

The Snapdragon 8+ Gen 1 SoC fuels both of these phones. The thing is, it’s limited to 4G connectivity inside the Huawei Mate X3, as a result of the US restrictions. The Galaxy Z Fold 4 supports 5G connectivity. That phone also has 12GB of LPDDR5 RAM and UFS 3.1 flash storage. The Mate X3 offers 12GB of RAM, and either UFS 3.1 or 4.0 flash storage. We’re also not sure if LPDDR5 or 5X RAM is used, Huawei did not disclose that info.

Having said that, both phones perform admirably. They’re very fluid, regardless of what you do on the phones. One could argue that the Mate X3 is even a bit more fluid in day-to-day tasks, with less stutters, but both perform great. The same goes for games, actually. One thing to note is that the Mate X3 does come without Google services, and thus without the Play Store. Huawei’s services and app store are pre-installed, though.

Both phones can handle even the most demanding Android games, without a problem. The Snapdragon 8+ Gen 1 is an outstanding processor, even though it’s no longer Qualcomm’s best offering at the moment. It is the company’s second-best chip, though, and there’s really not much to complain about here.

Samsung Galaxy Z Fold 4 vs Huawei Mate X3: Battery

The Samsung Galaxy Z Fold 4 includes a 4,400mAh battery, while the Mate X3 has a 4,800mAh battery on the inside. That’s not surprising considering that it has slightly larger displays. What’s the battery life like, though? Well, the battery life on the Fold 4 was not the best at first, in fact it was a bit disappointing. It did improve since launch, quite a bit. The Mate X3 still offers more in that regard, though.

It’s hard to give out exact battery life numbers for either device, as it all depends on your usage. With foldables, it’s even tougher to predict as there are two displays included in the equation. With mixed use, you should be able to have enough battery until the end of the day, on both devices, even with more intense use. Do note that gaming is not thrown into the mix, and it could force you to charge before the end of the day. Getting around 7 hours of screen-on-time with mixed usage is achievable on the Mate X3, while the Fold 4 will provide a bit less than that. As I said, your mileage may vary quite a bit, it all depends on your usage.

Now, when charging is concerned, the Galaxy Z Fold 4 is humbled by the Mate X3. The Huawei Mate X3 supports 66W wired, 50W wireless, and 7.5W reverse wireless charging. The Galaxy Z Fold 4, on the other hand, supports 25W wired, 15W wireless, and 4.5W reverse wireless charging. The Mate X3 also comes with a 66W charger in the box, while the Galaxy Z Fold 4 does not include a charger at all.

Samsung Galaxy Z Fold 4 vs Huawei Mate X3: Cameras

The Galaxy Z Fold 4 includes a 50-megapixel main camera, a 12-megapixel ultrawide unit (123-degree FoV), and a 10-megapixel telephoto camera (3x optical zoom). The Huawei Mate X3, on the other hand, has a 50-megapixel main unit, a 13-megapixel ultrawide camera, and a 12-megapixel periscope telephoto camera (5x optical zoom).

Samsung Galaxy Z Fold 4 Review AM AH 13

So, what’s the performance like? Well, during the day, the Huawei Mate X3 does take more natural-looking photos, but the dynamic range is a bit better on the Galaxy Z Fold 4 more often than not. The sharpening is aggressive on the Mate X3, but it never goes beyond what’s necessary. The Galaxy Z Fold 4 can go a bit too far with camera processing. Ultrawide units do a great job of keeping up with the color profile of the main cameras. The Mate X3 does have an advantage here, and the same goes for the telephoto camera.

Both phones do a good job in low light, but they’re not the best out there. The Mate X3 could use slightly better dynamic range in these shots as well. It does handle noise a bit better than the Galaxy Z Fold 4, though. Ultrawide cameras on both phones are a step below the main ones in low light, as expected. The Mate X3’s telephoto camera does a better job in low light, however.

Audio

There is a set of stereo speakers on both devices. Despite the fact the speakers inside the Mate X3 are rather thin, the sound output is really good. They are louder than the Galaxy Z Fold 4 speakers, while the sound quality is good on both. You won’t notice any notable distortion, even at the highest volume settings.

The audio jack is not present on either phone. You will need to use their Type-C ports for wired audio connections. If you prefer to go wireless, do note that Bluetooth 5.2 is supported by both devices.


[ad_2]
Source link

Google will now track employee badges for office attendance

0
[ad_1]

It’s no secret that Google’s new return-to-office policy hasn’t had the best adoption from its employees who have become accustomed to working from home. However, the company’s recent announcement that it will now track employee badges to monitor office attendance and consider in-person presence in performance evaluations has caused confusion and frustration among Google employees, leading to mixed messaging within the company.

According to CNBC, dissatisfied employees expressed their discontent on Google’s internal site, Memegen, with many stating that the company is treating them like schoolchildren. Furthermore, this move has also raised concerns among employees who have recently relocated to different cities and states after Google approved their requests to work remotely. This is because employees who previously had approval for full remote work may face a reevaluation of their status under the new policy.

In classic fashion, many employees also shared memes to express their frustrations, with one popular meme depicting the head of human resources, Fiona Cicconi, standing in front of a school chalkboard with the caption, “If you cannot attend the office today, your parents should submit an absence request.” Another highly-rated meme reads, “Check my work, not my badge.”

Google’s reasoning for returning to the office

Fiona Cicconi, Chief People Officer, emphasized the importance of physical proximity when announcing the new policy, stating that there is simply no substitute for in-person collaboration.

“Of course, not everyone believes in ‘magical hallway conversations,’ but there’s no question that working together in the same room makes a positive difference,” said Cicconi.

However, in response to the widespread backlash, a Google spokesperson explained that they would only track employee badges in an aggregated form for company reports, and it would not be shared at an individual level. But, Google did mention that it would inform group leaders about employees who have consistently been absent from the office, allowing them to provide support in either returning to the office or exploring alternative flexible work options.


[ad_2]
Source link

Microsoft fixes six critical vulnerabilities in June Patch Tuesday

0
[ad_1]

Patch Tuesday of June 2023 is relatively relaxed. No actively exploited zero-days and only six critical vulnerabilities.

It’s that time of the month again: We’re looking at June’s Patch Tuesday roundup. Microsoft has released its monthly update, and compared to previous months, it’s actually not so bad. No actively exploited zero-days and only six critical vulnerabilities.

So, we’ll have the luxury of going over those in some more detail.

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The critical CVEs patched in these updates are:

CVE-2023-29357 (CVSS score: 9.8 out of 10): a Microsoft SharePoint Server Elevation of Privilege  (EoP) vulnerability. Successful exploitation could provide an attacker with administrator privileges. For the exploitation, the attacker needs no privileges nor do they require user interaction.

The Microsoft advisory states:

“An attacker who has gained access to spoofed JWT authentication tokens can use them to execute a network attack which bypasses authentication and allows them to gain access to the privileges of an authenticated user.”

JWT is a token based stateless authentication mechanism. Basically, the identity provider generates a JWT that certifies the user identity and the resource server decodes and verifies the authenticity of the token by using secret salt or public key.

CVE-2023-29363 (CVSS score: 9.8 out of 10): a Windows Pragmatic General Multicast (PGM) Remote Code Execution (RCE) vulnerability.

PGM is a reliable and scalable multicast protocol that enables receivers to detect loss, request retransmission of lost data, or notify an application of unrecoverable loss. PGM is a receiver-reliable protocol, which means the receiver is responsible for ensuring all data is received, absolving the sender of reception responsibility. It is mainly used for delivering multicast data such as video streaming or online gaming.

CVE-2023-32014 (CVSS score: 9.8 out of 10): another PGM RCE vulnerability.

CVE-2023-32015 (CVSS score: 9.8 out of 10): another PGM RCE vulnerability.

For all the PGM vulnerabilities, Microsoft points out that: when Windows message queuing service is running in a PGM Server environment, an attacker could send a specially crafted file over the network to achieve remote code execution and attempt to trigger malicious code.

The Windows message queuing service, which is a Windows component, needs to be enabled for a system to be exploitable by this vulnerability. This feature can be added via the Control Panel. You can check to see if there is a service running named Message Queuing and TCP port 1801 is listening on the machine.

CVE-2023-32013 (CVSS score: 6.5 out of 10): a Windows Hyper-V Denial of Service (DoS) vulnerability. Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.

Hyper-V is Microsoft’s hardware virtualization product. It lets you create and run virtual machines, which are software emulations of a computer system.

CVE-2023-24897 (CVSS score: 7.8 out of 10): a .NET, .NET Framework, and Visual Studio Remote Code Execution (RCE) vulnerability. The word “Remote” refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE) because the attack itself is carried out locally.

I’d like to throw one important vulnerability in the mix because we expect to hear more about it, because it is, well, you know, Exchange.

CVE-2023-32031 (CVSS score: 8.8 out of 10): a Microsoft Exchange Server Remote Code Execution (RCE) vulnerability. An attacker could target the server accounts in an arbitrary or remote code execution. As an authenticated user, the attacker could attempt to trigger malicious code in the context of the server’s account through a network call.

This is typically a vulnerability that is used in a chained attack, because the attacker will need access to a vulnerable host in the network to gain the necessary authentication they need to successfully exploit this vulnerability.

Other vendors

Other vendors have synchronized their periodic updates with Microsoft. Here are few major ones that you may find in your environment.


We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using Malwarebytes Vulnerability and Patch Management.


[ad_2]
Source link