WhatsApp is adding a new way (kind of) to communicate with your friends

0
[ad_1]
We have more ways than ever to communicate with each other nowadays: you can simply text someone, send them a voice message, or compose an email if it is a more formal conversation. What is that? You can also call people on the phone you say? Sure, if you are weird.

Do you know what’s not so weird (ironically), though? Sending short, spontaneous, raw video clips. Snapchat was the first to make this communication medium popular back when Snapchat was yet to be robbed and swallowed up by Meta’s apps.

While we are on the topic of Meta’s apps stealing prominent Snapchat features, WhatsApp is apparently looking of implementing its own jab at video messaging, as spotted by WABetaInfo in a beta update. The new feature was discovered in both the Android and iOS versions of the app, and it is already accessible to some beta testers.

Of course, WhatsApp users already had the ability to send recorded videos in chat, either by selecting one from their gallery or by recording one on the spot and clicking the send button. The video messaging feature, on the other hand, will work more like voice messages.

In other words, you tap and hold the button while recording, and it will automatically send itself once you remove your finger. Presumably, you would also be able to swipe up to lock the recording in, so you don’t have to keep pressing. You should also be able to swipe left to delete.

The new video messaging button will be where the voice messaging one is, and users have to tap once to switch between the two modes.

Safety-wise, these video messages will be end-to-end encrypted, meaning the only people with access to them would be the sender and recipient. Additionally, the one receiving the video message won’t be able to forward it to others. The video message will stay in the chat after being sent, however, unless it is manually deleted.

The feature is still in beta, but it is safe to assume something as fundamental as this will eventually come to the stable version of the app sometime in the near future.


[ad_2]
Source link

Chinese Hackers Exploit VMware ESXi Zero-Day

0
[ad_1]
VMware ESXi Zero-Day

The Chinese cyberespionage gang, identified as UNC3886, has been spotted employing a VMware ESXi zero-day vulnerability to get escalated privileges on guest virtual machines.

UNC3886 has been using malicious vSphere Installation Bundles (VIBs), typically used to maintain systems and deploy updates, to install backdoors on ESXi hypervisors, and gain access to command execution, file manipulation, and reverse shell capabilities. This activity was first reported in September 2022.

The group’s malicious activities would affect Windows virtual machines (VM), vCenter servers, and VMware ESXi hosts.

UNC3886 VMware Zero-Day Attack

The gang has also used a zero-day vulnerability in VMware Tools to bypass authentication and run privileged commands on Windows, Linux, and PhotonOS (vCenter) guest VMs.

The vulnerability, CVE-2023-20867, has been given a “low severity” rating since it can only be exploited by an attacker with root access to the ESXi server.

“A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine,” VMware said in its security advisory.

Mandiant claims that UNC3886 was seen employing scripts to enumerate all ESXi hosts and their guest VMs, change lists of allowed IPs across all connected ESXi hosts, and collect credentials from compromised vCenter servers using the associated vPostgreSQL database.

Expanded UNC3886 attack path
Expanded UNC3886 attack path

“Additionally, the use of CVE-2023-20867 does not generate an authentication log event on the guest VM when commands are executed from the ESXi host,” researchers said.

The cybersecurity company also saw the group installing two backdoors (VirtualPita and VirtualGate) that used VMCI sockets for persistence and lateral movement.

In addition to enabling network segmentation bypass and the evasion of security inspections for open listening ports, the malware gives the attackers a new degree of persistence (access to the infected ESXi host is recovered by accessing a VM).

“The attack is highly targeted, with some hints of preferred governmental or government-related targets,” Fortinet said.

“The exploit requires a deep understanding of FortiOS and the underlying hardware. Custom implants show that the actor has advanced capabilities, including reverse-engineering various parts of FortiOS.”

Fortimanager attack flow
Fortimanager attack flow

According to Mandiant, UNC3886’s usage of a wide variety of new malware families and harmful tools designed specifically for the platforms they are targeting implies significant research capabilities and an out-of-the-ordinary capacity to comprehend the sophisticated technology the use of the targeted appliance.

In assaults against organizations involved in defense, technology, and telecommunications in the US and the Asia-Pacific area, UNC3886 is renowned for using zero-day vulnerabilities in firewall and virtualization solutions.

Stop Advanced Email Threats That Target Your Business Email – Try AI-Powered Email Security


[ad_2]
Source link

Don’t Miss Out on This Deal on the MSI Creator Z16

0
[ad_1]

Amazon has a great deal on the MSI Creator Z16 Professional Laptop right now, where you can pick it up for just $1,499. That’s going to save you about $1,000 on this laptop. Making it a really great deal right now.

MSI Creator Z16 – Amazon

Why you should buy the MSI Creator Z16

The MSI Creator Z16 is a powerful and versatile laptop that is perfect for creative professionals. It features a 16-inch QHD+ (2560×1600) display with a 120Hz refresh rate, which is ideal for video editing, graphic design, and gaming. The laptop is also powered by an 11th Gen Intel Core i9 processor and an NVIDIA GeForce RTX 3060 graphics card, which provides plenty of power for demanding tasks.

In addition to its powerful performance, the MSI Creator Z16 also features a number of other features that make it ideal for creative professionals. These include a backlit keyboard, a fingerprint sensor, a Thunderbolt 4 port, and a Wi-Fi 6E connection. The laptop also comes with a number of pre-installed creative software applications, such as Adobe Photoshop, Illustrator, and Premiere Pro.

The MSI Creator Z16 is a great value for creative professionals who are looking for a powerful and versatile laptop. It is currently on sale for just $1,499, which is a great deal for a laptop with this level of performance and features.

Here are some of the reasons why you should buy the MSI Creator Z16:

  • Powerful performance: The 11th Gen Intel Core i9 processor and NVIDIA GeForce RTX 3060 graphics card provide plenty of power for demanding tasks such as video editing, graphic design, and gaming.
  • Stunning display: The 16-inch QHD+ (2560×1600) display with a 120Hz refresh rate is ideal for video editing, graphic design, and gaming.
  • Versatile features: The laptop also features a backlit keyboard, a fingerprint sensor, a Thunderbolt 4 port, and a Wi-Fi 6E connection.
  • Great value: The MSI Creator Z16 is currently on sale for just $1,499, which is a great deal for a laptop with this level of performance and features.

If you are a creative professional who is looking for a powerful and versatile laptop, the MSI Creator Z16 is a great option. It is currently on sale for just $1,499, which is a great deal.

MSI Creator Z16 – Amazon


[ad_2]
Source link

Spotify fined $5.4 million for allegedly mishandling user data

0
[ad_1]

Over the past few years, the European Union has been the top watchdog when it comes to safeguarding its people’s data. Now, in line with these efforts, the Swedish Authority for Privacy Protection (IMY) has fined Spotify of SEK 58 million ($5.4 million) for allegedly mishandling user data, thereby breaching the General Data Protection Regulation (GDPR).

The complaint, lodged in 2019 by privacy advocacy group Noyb, led by campaigner Max Schrems, stated that Spotify not only failed to provide customer data upon request but also neglected to disclose the purpose of processing such data. Additionally, upon further investigation, the IMY also found that Spotify couldn’t adequately explain how they were using this data, raising some serious concerns.

As a result, the IMY has now ordered Spotify to provide the complete set of requested data and emphasized the need for the company to be transparent about how they handle personal data and the purposes for which they process it.

Stefano Rossetti, a privacy lawyer at Noyb, expressed his satisfaction with IMY finally taking action and stated that it is a basic right for every user to have full information about their processed data. However, he also highlighted the prolonged duration of the case and the need for the Swedish authority to expedite its procedures.

Spotify’s response

While Spotify’s inadequate measures to protect customer data raised some concerns, the IMY considered the violations to be of “low level of seriousness” and recognized that Spotify had taken steps to address the issues. Moreover, the authority also mentioned that they fined Spotify based on its revenue and user count.

In response to the fine, a Spotify spokesperson stated, “Spotify offers all users comprehensive information about how personal data is processed. During their investigation, the Swedish DPA found only minor areas of our process they believe need improvement. However, we don’t agree with the decision and plan to file an appeal.”


[ad_2]
Source link

Save $200 on the Dolby Atmos-powered Sony HT-A3000 Soundbar

0
[ad_1]

Today, Amazon has a great deal on a pretty good soundbar from Sony. It’s the Sony HT-A3000 which is a Dolby Atmos soundbar, and now it’s just $498. That’s going to save you $200 off of its regular price. Making this a really great deal.

Sony HT-A3000 Soundbar – Amazon

Why you should buy the Sony HT-A3000 soundbar

The Sony HT-A3000 is a great soundbar for anyone looking to upgrade their home theater experience. It offers immersive surround sound, thanks to its support for Dolby Atmos and DTS:X. The soundbar also has a sleek and compact design that will look great in any room.

Here are some of the reasons why you should buy the Sony HT-A3000:

  • Immersive surround sound: The Sony HT-A3000 supports Dolby Atmos and DTS:X surround sound, which creates a more immersive audio experience. This is ideal for watching movies or TV shows, as it will make you feel like you are right in the middle of the action.
  • Sleek and compact design: The Sony HT-A3000 has a sleek and compact design that will look great in any room. It is also relatively lightweight, making it easy to move around if needed.
  • Powerful bass: The Sony HT-A3000 is powered by two 100W subwoofers that deliver powerful bass and clear sound. This is ideal for watching action movies or listening to music.
  • Built-in features: The Sony HT-A3000 has a number of built-in features, such as Bluetooth, Wi-Fi, and Google Assistant compatibility. This makes it easy to connect to your devices and control the soundbar with your voice.

If you are looking for a great soundbar that offers immersive surround sound, a sleek and compact design, powerful bass, and built-in features, the Sony HT-A3000 is a great option. It is currently on sale for just $498, which is a great deal for a soundbar with this level of performance and features.

Sony HT-A3000 Soundbar – Amazon


[ad_2]
Source link

Popular Reddit app might adopt a subscription based model

0
[ad_1]

Reddit’s recent decision to start charging for API access has caused widespread outrage among Redditors, as it would essentially be the end of many popular third-party clients unless they are willing to pay exorbitant fees each month. However, it looks like Relay for Android, the popular Reddit client, might have found a way to survive the API changes by implementing a new strategy.

In a recent blog post, developer Dave shared his insights on the future of the app and stated that the current free version of Relay would no longer be financially sustainable. Instead, the app will adopt a subscription-based model, which will also come with the added benefits of no ads or recommended content.

However, Dave also acknowledged the challenges associated with transitioning to a subscription-based model and explained that the success of this new approach would depend on users’ willingness to stick with Relay and embrace the subscription system. Additionally, he also expressed concerns about the tight timeline to implement the necessary changes, as Reddit’s new API pricing goes into effect on July 1st.

“The entire model is ultimately subject to how many, and what type of, users choose to stay with Relay as a subscription-based app. I want to stress that my estimates are only relevant to call data collected by Relay for Relay. Other apps have different layouts and feature sets,” said Dave.

Pricing structure

Under this new proposed model, users might need to pay a base subscription fee of $2 per month along with an additional $1 fee for the message notifications to accounts. However, it is important to note that the current pricing model is based on the latest release of Relay for Reddit, which included bug fixes and other changes aimed at reducing API calls.

Although the prospect of Relay surviving this API change is exciting and showcases developers’ determination to navigate evolving platform policies while providing users with a positive experience, it’s crucial to recognize that these projections are purely speculative at this point, and the future of the app remains uncertain.


[ad_2]
Source link

Ticket scammers target Taylor Swift tour

0
[ad_1]

We take a look at multiple reports of ticket reseller fraud aimed at fans of Taylor Swift’s Era tour.

Taylor Swift fans are being warned to be cautious when buying tickets for her current “Eras” tour, with scammers waiting in the wings to trick would-be gig goers. The Better Business Bureau says it has received somewhere in the region of 200 complaints from residents of Michigan, and there’s bound to be more from other locations.

The issue is so bad that Michigan’s Attorney General advised the local “Swifties” about fraud in relation to last weekend’s Michigan leg of the tour. His warning reads as follows:

“Michigan residents who are defrauded by online ticket scammers should not just shake it off,” said Nessel. “We know these scams all too well. If you believe you were taken advantage of, filing a complaint with my office is better than revenge.”

Reports of scammers taking advantage of Swift’s fans, called Swifties, indicate some have lost as much as $2,500 paying for tickets that don’t exist or that never arrive. The Better Business Bureau has reportedly received almost 200 complaints nationally related to the Swift tour. The complaints range from refund struggles to outright scams.

Other locations for the tour are trying to get ahead of the scam curve, issuing their own warnings ahead of events where possible. For example, Cincinnati has highlighted tales of woe related to fake ticket sales on Facebook. Detroit flagged fake ticket sales on Instagram. CBC covered multiple fake sale attempts cheating folks in Canada out of significant chunks of money. Elsewhere, teens have lost out on $1,200 thanks to Craigslist scammers.

With something like 19 dates left in the US alone stretching from Minneapolis and Pittsburgh to Los Angeles and Seattle, there’s still plenty of opportunity for scammers to crawl out of the woodwork. These are undoubtedly the hottest music tickets around at the moment, so you’ll want to follow some common sense rules before trying to get your hands on some. This is especially the case given that the only ticket source left may be resellers.

How to avoid ticket scams

  • Research the ticket seller. Anybody can set up a fake ticket website, and sponsored ads showing at the top of search engines can be rife with bogus sellers. You may also run into issues buying tickets from sites like ebay. Should you decide to use sites other than well known entities like Ticketmaster, check for feedback on the BBB website.
  • Use a credit card if possible. You’ll almost certainly have more protection than if you pay using your debit card, or cash. We definitely recommend that you avoid using cash. If someone decides to rip you off, that money is gone forever.
  • A “secure” website isn’t all it seems. While sites that use HTTPS (the padlock) ensure your communication is secure, this does not guarantee the site is legitimate. Anyone can set up a HTTPs website, including scammers.
  • It’s ticket inspector time. One of the best ways to know for sure that your ticket is genuine is to actually look at it. Is the date and time correct? The city, the location? Are the seat numbers what you were expecting to see? It may well be worth calling the event organisers or the event location and confirming that all is as it should be. Some events will give examples of what a genuine ticket should look like on the official website.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

Google Messages gets a home screen makeover

0
[ad_1]

Most apps are destined to get redesigns over time, and that goes especially for apps owned by major companies. Google Messages, the main SMS/RCS messaging app from Google, is getting a small redesign that brings a bit of attention to Google’s branding.

Google Messages comes with several useful features that really make it a nice messaging app. If you are an Android user, and you want to try out some of these features, you can always download Google Messages from the Google Play Store. You’ll just have to assign it as the default messaging app when you open it on your device.

Download Google Messages

Google Messages gets a redesign

This comes to us from 9To5Google. The redesign mostly affects the home screen. So, everything else throughout the rest of the app looks the same. The main change with this redesign is the lack of a navigation drawer. The navigation drawer was usually on the top left corner of the UI inside of the search bar. Both it and the search bar are now gone.

After the redesign, you’ll see the four-color Google logo on the top left corner of the UI, and it’s followed by the word messages. On the right side, you’ll see your profile picture as usual, but you’ll also see a magnifying glass icon. This will bring on the search function.

So, where’s the navigation drawer going? You might be wondering how to access the items that once lived within it. Well, when you tap on your profile picture, you will see those items moved to that menu. If you want to change your theme, you have to do so in the settings.

There’s another notable change, and that has to do with the search feature. Before the redesign, you would tap on the search bar and be presented with a carousel of different items like categories and such. Now, when you tap on the magnifying glass icon, you will see a grid of your categories. They’re all laid out so you can see everything on one screen as opposed to the older method.

This is a nice upgrade to make the interface a bit more unified and more consistent across the ecosystem of Google apps. If you don’t see this, make sure that your app is fully updated.


[ad_2]
Source link

Samsung’s impressive update policy may have just got better

0
[ad_1]

Samsung has the best update policy in the Android space today. While a few other companies match its policy of four major Android OS updates and five years of security updates, they only cover their flagship models. The Korean firm, on the other hand, offers the same update support to some mid-range models as well. And if that wasn’t already enough for Samsung to be called the undisputed king of Android updates, it may have just upped its game.

Samsung seems to have upgraded its already impressive update policy

Samsung maintains a list of devices that are eligible for new security updates. It divides all eligible models into three update categories: monthly, quarterly, and bi-annual, with the latter meaning two updates in a year. Flagships and premium mid-range models start at monthly patches before dropping to the less-frequent categories over time. All other devices start at quarterly patches and drop to the bi-annual category after a few years.

Usually, flagship models get monthly updates for up to three years from their launch before dropping to quarterly updates. However, as you can see in the official list here, the Galaxy S20 series is still getting monthly updates. The 2020 flagships completed three years on the market in March 2023. Almost three months into the fourth year, Samsung hasn’t dropped them to the less-frequent security update category.

This suggests that Samsung has further upgraded its already impressive update policy. It appears to be offering monthly security patches to flagship models for four years. The devices may be dropped to quarter updates in the fifth year. We will have to wait one more year to find out, though. That’s because flagship Samsung phones launched before the Galaxy S20 series aren’t eligible for five years of security updates. The company has already stopped pushing new updates to the Galaxy S10 series.

On that note, when Samsung announced five years of security patches for Galaxy devices, it didn’t reveal the frequency of the updates across those five years. The company may have always intended to offer monthly updates for the first four years and quarterly updates in the final year, at least for flagship models.

We are finding it now because the Galaxy S20 series is the oldest flagship to get extended update support. When Samsung offered security updates for a total of four years, it was a 3+1 system. We will let you know if the company releases an official statement on the matter or if it demotes the Galaxy s20 series to quarterly patches in the coming months.


[ad_2]
Source link

Update Chrome now! Google fixes critical vulnerability in Autofill payments

0
[ad_1]

Google has released an update which includes five security fixes including a critical vulnerability in Autofill payments.

Google has released a Chrome update which includes five security fixes. One of these security fixes is for a critical vulnerability in Autofill payments.

Google labels vulnerabilities as critical if they allow an attacker to run arbitrary code on the underlying platform with the user’s privileges in the normal course of browsing.

How to protect yourself

If you’re a Chrome user on Windows, Mac, or Linux, you should update as soon as possible. 114.0.5735.130/.131 for Android will become available on Google Play over the next few days.

The easiest way to update Chrome is to allow it to update automatically, which basically uses the same method as outlined below but does not require your attention. But you can end up lagging behind if you never close the browser or if something goes wrong—such as an extension stopping you from updating the browser.

So, it doesn’t hurt to check now and then. And now would be a good time, given the severity of the vulnerabilities in this batch. My preferred method is to have Chrome open the page chrome://settings/help which you can also find by clicking Settings > About Chrome.

If there is an update available, Chrome will notify you and start downloading it. Then all you have to do is relaunch the browser in order for the update to complete.

Chrome displays the Relaunch button to complete the updateChrome needs a relaunch to apply the update

After the update, your version should be 114.0.5735.133 for Mac and Linux, and 114.0.5735.133/134 for Windows, or later.

The critical vulnerability

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The critical CVE patched in these updates is listed as CVE-2023-3214:  Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Google is always very careful about providing information about vulnerabilities, for obvious reasons. Access to bug details and links may be kept restricted until a majority of users are updated with a fix. However, from the vulnerability description we can learn a few things.

The Autofill payments function is to automatically enter payment details in online forms.

Use after free (UAF) is a type of vulnerability that is the result of the incorrect use of dynamic memory during a program’s operation. If, after freeing a memory location, a program does not clear the pointer to that memory, an attacker can use the error to manipulate the program.

Heap corruption occurs when a program modifies the contents of a memory location outside of the memory allocated to the program. The outcome can be relatively benign and cause a memory leak, or it may be fatal and cause a memory fault, usually in the program that causes the corruption.

A remote attack means that this vulnerability could potentially be exploited by tricking the user into visiting a specially crafted website.

Whether all this actually means that vulnerable Chrome versions will spill payments details on such a website remains to be seen, but it’s not the unlikeliest of scenarios.


We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using Malwarebytes Vulnerability and Patch Management.


[ad_2]
Source link