Pixel Watch is finally getting overnight SpO2 tracking

0
[ad_1]

Although Google unveiled its Pixel Watch late last year, there is one critical feature that the watch has lacked and fans have been eagerly waiting for, i.e. SpO2 measurement. However, according to reports, Google could finally be bringing blood oxygen saturation (SpO2) tracking to all users.

A Reddit user named triforce28 first discovered the feature when they stumbled upon an “Oxygen saturation” card in the Fitbit Today app. The card appeared below the Sleep score and provided users with a percentage representing their “Last sleep session,” and when tapped, the app redirected them to a detailed fullscreen stats page dedicated to SpO2, along with a comprehensive explanation.

“The Fitbit app on the watch shows oxygen saturation from sleeping last night. I’ve never seen it before. Is that new, or have I just not paid attention in the past?” said the Reddit user.

Big step ahead

The new addition of the SpO2 tracking is a significant step forward, as previously, the Pixel Watch only provided estimated oxygen variation (EOV) data under the ‘Restoration’ section. And even after the Heart Metrics dashboard became freely accessible in March, following the removal of the Fitbit Premium requirement, the metrics for SpO2 or skin temperature stated “no recent data,” along with a message indicating that these features were not available on the current device.

Although the exact rollout details of SpO2 tracking on the Pixel Watch remain uncertain, as many users have not reported seeing the new feature in the June update, the addition of SpO2 tracking could finally make the Pixel Watch a strong contender in the Android smartwatch space, which in recent years has been dominated by the likes on Samsung. Furthermore, it would provide users with valuable insights into their blood oxygen saturation, especially during activities like exercise or sleep, contributing to a more holistic understanding of their well-being.


[ad_2]
Source link

Spotify is testing a new feature for simplifying offline music downloads

0
[ad_1]

Streaming music online brings a lot of benefits like getting access to millions of songs, freeing up valuable space on your phone, and creating and sharing playlists with your friends. However, a downside to streaming is that as soon as you lose your internet connection, your music disappears as well. Spotify, one of the most popular music streaming platforms, is now testing a new feature that will simplify the process of downloading music for offline listening. According to a tweet spotted by Android Central, Daniel Ek, Spotify’s CEO, says the company is testing a feature called “Your Offline Mix.” While there aren’t many details available yet, such as a release date or specific workings, one thing is clear: it is “designed for those times when you might not be online.”

The concept behind this new feature is to allow you to enjoy your recently played music even when you’re unexpectedly offline. The app will automatically download a mix of the songs you’ve recently listened to, so if you find yourself in airplane mode, in the middle of nowhere, or in a long, long tunnel, for instance, you’ll still have something to listen to.

Based on an image shared on Twitter, we can assume the Offline Mix could be over three hours long, which provides plenty of listening time. However, it needs to be clarified how often these playlists will be downloaded or if they will be automatically deleted after a certain period. Otherwise, the app could become quite large. Just to give an idea, a playlist with 100 high-quality songs can use up to around 1GB of storage.

Right now, Spotify offers the option to download music for offline listening. While downloading an entire playlist is simple with just one button, downloading a single song can be a bit tricky and frustrating. You have to add the song to a playlist first and then download the entire playlist or add it to an already downloaded playlist.

With this new feature, Spotify aims to simplify things: a much-needed step to enhance user experience. Its competitor, YouTube Music, has been offering this feature to its premium subscribers for quite some time now. To remain a major player in the game Spotify needs to keep up with these updates.

Spotify boasts around half a billion users, and adding new features is a smart move, especially considering that only around 40% of Spotify users are premium subscribers. This new feature will likely only be available to premium users, which may help Spotify attract new paid subscriptions.

[ad_2]
Source link

AT&T pledges RCS support on all Android devices

0
[ad_1]

AT&T has pledged whole-hearted support for Google’s RCS (Rich Communicate Services) on Android devices. With this partnership, Google Messages will be the default messaging app on all AT&T Android phones in the US. This follows a similar commitment from T-Mobile in March, making messaging a more consistent experience for Android users. Verizon is yet to get on board, though.

AT&T finally embraces RCS wholeheartedly

RCS is a modern messaging standard and a massive upgrade to age-old SMS and MMS technologies. It brings features like read receipts, typing inductor, support for larger files, better group chats, end-to-end encryption, and many more to your phone’s messaging app. As you may have guessed, RCS requires an internet connection to work. But even if you’re offline, your messages will still go through as SMS or MMS. So your communication won’t be cut when there’s no internet, something that instant messaging apps like WhatsApp and Telegram don’t offer.

Google has been long trying to make RCS the default messaging system on Android devices. But despite its best efforts, US wireless carriers never committed to this system wholeheartedly. In October 2019, AT&T, Verizon, T-Mobile, and Sprint (which merged with T-Mobile in 2020) formed a consortium and launched a joint venture called the Cross-Carrier Messaging Initiative (CCMI) to improve the messaging experience for mobile users. However, years later, nothing has materialized out of it.

Meanwhile, Google took matters into its own hands and integrated RCS into its Messages app, which comes pre-installed on most Android devices around the world. It then started calling on carriers for full-fledged RCS support through Messages, which is finally coming. Shortly after T-Mobile committed to it, AT&T joined the bandwagon too. Verizon is sticking to its own RCS solution with a separate app, but we hope it would also adopt the more universal standard and help make messaging on Android more consistent.

RCS is still missing on iPhones

Unfortunately, carrier support will only improve the messaging experience in the Android space. Cross-platform messaging between Android devices and iPhones is still a mess. That’s because Apple doesn’t support RCS on iPhones. Messages sent from an Android device to an iPhone go through as SMS and are notably distinguished in the iMessage app using “green bubbles”. Messages sent from other iPhones appear in “blue bubbles”. Despite Google repeatedly taking digs at the company publicly, Apple has shown no signs of fixing this mess. It recently debuted iOS 17 without RCS support.


[ad_2]
Source link

Google introduces new AI photo editing tool called ‘Imagen Editor’

0
[ad_1]

It comes as no surprise that the last few years have been nothing short of a revolution when it comes to artificial intelligence, with text-to-image AIs like DALL-E and Stable Diffusion changing the landscape of photography and image production as we know it. Now, in line with these efforts, Google has recently unveiled a new AI tool called Imagen Editor, which allows users to make specific modifications to images based on textual prompts without altering the rest of the picture.

A new way of editing

One of the major features of the new tool is its simplicity, as users only need to upload their image, select the region they wish to edit, and describe the desired changes for that particular area. For example, when a user highlights a dog’s body in an image and requests a “red spacesuit with a white star,” the tool accurately incorporates the spacesuit into the selected area. In another instance, the tool added a “rocket made out of cardboard” and “blue gaming headphones” to the image of the dog.

Similar to Google’s object eraser, users can erase unwanted elements in the background of a photo, thus highlighting the main subject and removing distractions. Additionally, the Imagen Editor tool also offers the ability to alter the colour of the sky in a photo. For instance, if you have a picture of a sunset and want to enhance its visual impact, the tool can transform the sky into a more vibrant and captivating shade of blue, adding depth and beauty to the image.

No release date yet

Although the features of the Imagen Editor have the potential to transform the world of photo editing and photography, Google has decided not to release the tool to the public due to concerns related to responsible AI and bad actors potentially misusing it to manipulate images. Therefore, if Google ever intends to release the tool to the public, the company must implement stringent measures, such as proper image labelling and marking, when processing images through the tool.


[ad_2]
Source link

r/iPhone is the first victim of this latest strike against Reddit

0
[ad_1]
A huge part of having one of the best phones on the market in your pocket, is that you get to stay connected with your favorite online communities. Naturally, with the internet being the internet and you being on it, Reddit is a prime suspect when it comes to making the aforementioned happen.

Half social media platform, half new-age forum, Reddit has it all. Typically, if you aren’t too deep into the platform’s culture, you are rarely going to see scandals surrounding the webspace. But back in April, the company shared some planned changes regarding its API pricing strategy.

As in, Reddit was planning to start charging third-party Reddit clients for doing their thing. And if you aren’t a hardcore redditor just yet, then you should know that most redditors prefer third-party solutions by default. They typically offer more customization and features, which is always welcomed, but most of them are also unable to afford the API anymore. 

So, context! What better way to showcase how big of an issue this is than with an example? Christian Selig — founder of the Apollo App, a fan-favorite third-party Reddit client for iOS — was asked for $20 million per year by Reddit corporate in order to keep the app running. And yes, that is insane. So he made the tough call to shut down the service. 

But let’s get back to the “going private” thing for the iPhone subreddit. What does that mean? Well, basically that only approved members can visit and post on there. The shocking twist is that as part of the strike, the mods of the subreddit won’t be approving anyone new, so this basically means that r/iPhone is closed off for the time being.

While the strike itself looks to become quite huge, Reddit has made it clear in the past that they will do “what must be done” in order to keep its services active. As such, they may opt to place new moderators on all participating subreddits in an attempt to mitigate the strike. But that sounds like a recipe for a disaster, so we hope to not see it happen. 

But beyond that? No further comments have been made as of now. The Reddit community expects Reddit to fix this, but only time will tell if the company is willing to go back on their decision. We do hope that everything gets sorted out in the end, though, because as things are now: Reddit fans are the ones suffering these consequences.

[ad_2]
Source link

HSE latest victim of MOVEit cyber attack

0
[ad_1]

Health Service Ireland (HSE) has become the latest victim of a supply chain cyber attack launched against document transfer service MOVEit. The attack was launched by ransomware gang, Clop.

Clop were able to infiltrate MOVEit by exploiting a zero-day vulnerability that allowed the malicious group to break into company networks and steal data. Professional services partnership EY was also impacted by the cyber attack, leading to the breach.

HSE was working with EY to automate its recruitment process using software provided by MOVEit. On June 8, HSE was alerted to the fact that EY had been impacted by the cyber attack on MOVEit. Following this, HSE investigated the impact of the cyber attack on HSE and its data.

Following an investigation and analysis of the attack, HSE has determined that “no more than 20 individuals involved in the recruitment process” were affected by the data breach. The data potentially accessed by the hackers includes the names, addresses, mobile numbers and position of those on the recruitment panel, as well as more general information about the job roles to be filled. No other personally identifying or financial information was accessed during the cyber attack.

HSE is working with the relevant authorities including the Irish Data Protection Commission (DPC) regarding the cyber attack and data breach. The organization is in the process of contacting those affected by the breach.

Other companies affected by the breach include those who use the payroll services provider, Zellis. The network infiltration of Zellis led to the breach of more than 100,000 employees’ data from companies including the British Broadcasting Company (BBC), health and beauty retailer Boots and flag carrier of Ireland Aer Lingus. 

The ransomware gang later took to the dark web in an ettempt to extort victims of the data breach. Clop issued an ultimatum to the data breach victims, saying that comapnies affected by the attack need to contact them by June 14, or their personal data would be leaked online.

Clop claimed that all those who worked for local or national government or the police services were exempt from this threat. The ransomware gang addressed them directly, saying they should “not worry”. They continued, saying “we erased your data you do not need to contact us. We have no interest to expose [sic] such information”, although the legitimacy of this statement has been called into question.


[ad_2]
Source link

New Banking AitM Phishing and BEC Attacks

0
[ad_1]
Banking AitM Phishing

In a recent revelation, Microsoft disclosed that banking and financial service institutions had become the active target of a fresh attack known as adversary-in-the-middle (AitM) phishing and BEC.

As the number of reported cases surpasses 21,000 and the losses skyrocket by $2.7 billion, the Federal Bureau of Investigation (FBI) unveils a drastic surge in business email fraud.

Federal law enforcement agencies have taken notice of an unknown strategy employed by threat actors, which enables them to bypass “impossible travel” alerts, commonly used to detect and prevent abnormal login attempts and other doubtful account actions, thereby facilitating the monetization of Cybercrime-as-a-Service (CaaS).

In this case, Companies like Trustifi Stop Advanced Email Threats That Target Your Business Email with AI-Powered Email Security.

Banking AitM Phishing

The pace of cybercriminal activity concerning business email compromise is speeding up rapidly. 

In adopting platforms like BulletProftLink, attackers have made a dramatic shift as it’s a favored choice for directing malicious email campaigns on an industrial scale.

Experience the full suite of services at BulletProftLink, where you can access templates, hosting, and automated tools to enhance your BEC operations.

With this Crime-as-a-Service (CaaS), adversaries access victim credentials and their corresponding IP addresses.

After executing the BEC scheme, threat actors engage residential IP services to obtain the IP addresses corresponding to the location of the victim. 

Through the creation of residential IP proxies, they can hide their true origin, providing cybercriminals with enhanced anonymity.

Microsoft has most frequently observed the deployment of this tactic in Asia and an Eastern European nation where threat actors have been actively involved.

When identifying potential compromise of a user account, the detection of “impossible travel” is utilized as an indicator.

The scale of these attacks is heightened as threat actors leverage IP/proxy services that are also utilized by marketers and other research-oriented individuals.

Threat actors facilitate phishing campaigns and the acquisition of compromised credentials through the utilization of phishing-as-a-service platforms such as:-

  • Evil Proxy
  • Naked Pages
  • Caffeine

Annually, organizations suffer financial losses of hundreds of millions of dollars due to the success of BEC attacks.

Top Targets for BEC

Here below, we have mentioned the top targets for BEC:-

  • Executives
  • Senior leaders
  • Finance managers
  • Human resources staff

BEC attacks in almost all their forms are experiencing a notable surge, and the top trends contain:-

  • Lure
  • Payroll
  • Invoice
  • Gift card
  • Business Information
Top Targets for BEC

Within the cybercrime ecosystem, BEC attacks stand out for their specialized use of social engineering tactics and the ability of deceptive practices.

Recommendations

Here below we have mentioned all the recommendations offered by the researchers at Microsoft:-

  • Take all the essential security measures to maximize the security settings that protect your inbox.
  • Establish a robust authentication system for enhanced security.
  • Provide comprehensive training to employees to effectively identify warning signs.
  • Secure your environment by implementing a proper and robust security system.
  • Enhance your email security by utilizing a secure and well-established email solution.
  • Strengthen identity authentication to restrict unauthorized lateral movement within the infrastructure.
  • Implement a trustworthy and protected payment platform for secure transactions.
  • Take a short pause and use a phone call as a reliable method to verify financial transactions.

Stop Advanced Email Threats That Target Your Business Email – Try AI-Powered Email Security


[ad_2]
Source link

Super Smash Flash 2 Unblocked

0
[ad_1]

Super Smash Flash 2 Unblocked is the next fun version of the impressive game series which is titled Super Smash Bros.

Super Smash Flash 2 was designed by McLeodGaming operator. The release of the game was as brilliant as its first version. The second edition was improved a lot.

It is an entirely new version and has nothing to compare to the original. All the improvements, updates, and attractive features make Super Smash Flash 2 Unblocked 6969 very popular.

It helps players play in full-screen mode. Also, you can fight against online opponents simply by using the proprietary network system of McLeodGaming.

There are a lot of decent Flash games available online, but it is rated as one of the best. This game has a strong appeal to the fans.

Now you understand why just a short time after the release, the game has reached 400,000 plays per day. Even now it is at the peak of its popularity.

super smash unblocked

Super Smash Flash 2 Unblocked

Super Smash Flash 2 Unblocked or Super Smash Flash Hacked offers a big variety of playing characters.

You will be delighted to play your favorite character roles such as Mario, Link, Pikachu, Sonic, Zelda, Ichigo Naruto, Goku, and many others. There are two playing modes in this game.

The Super Smash game was based on the Super Smash Bros series and the game includes single-player & multiplayer modes.

There is a mode for a single player where you will be given a chance to join campaigns and defeat an impressive series of rivals controlled by PC.

You can choose between the classic and adventure modes which are also programmed inside this game.

Once you have completed all the roster modes, you will be getting the All-star mode enabled.

Before starting the play for the first time, training is necessary, yes it includes training mode also to enhance the skills.

There is another multiplayer game mode, where you have a chance to affiliate with several players on the same device.

This mode is fun because you can defeat the rivals controlled by PC with a reasonably tricky level.

Now, let’s have a look at the primary game objective. The mission of the game is similar to Super Smash Bros.

Super Smash Flash where you will have to use a lot of special abilities and skills in order to knock all your game opponents off the PC screen.

Super Smash Flash 2 Hacked 88 has a difference of much more diverse experience with the main game characters: Marth, Zero Suit Samus, and Chibi-Robo.

While playing you will have to achieve the fastest speed. You can play on your personal computer.

It is effortless to capture the game rules and control the keyboard as quickly as possible.

It includes 44 characters, the game includes a series of super smash games and the game is available as an app file.

By having Nintendo 3ds Emulator you can play your lovable classic games such as Super Mario, Top Gun, and Base Wars.

Conclusion

Although the game has some incomplete points, it is obviously a great flash game. Many fans have already left positive feedback.

The game Super Smash Flash 2 deserves your attention and a bit of free time! Download Here.

However, if you’re interested in playing Super Smash Flash 2, you can search for reputable websites that offer the game legally and play it directly from there.

Many websites provide access to the game without any restrictions or the need to unblock it.

Please ensure that you are obtaining the game from a legitimate source and not engaging in any activities that may infringe upon copyright laws or violate any terms of service.


[ad_2]
Source link

Two U.S. Senators accuse TikTok of lying to Congress and demand answers

0
[ad_1]
Back in March, TikTok CEO Shou Zi Chew spoke to members of the House Energy and Commerce Committee about the alleged storage of U.S TikTok. users’ personal data by the app’s parent company ByteDance. Last week, a letter written to the CEO by Senators Richard Blumenthal, Democrat of Connecticut, and Marsha Blackburn, Republican of Tennessee, accused TikTok officials of giving misleading and inaccurate answers to Congress and demanded the answers to a dozen questions before the end of this coming week.
In the letter dated June 6th, the lawmakers cite published material from The New York Times that claims that user data from American TikTok users, including driver’s licenses and child sexual abuse materials, was shared at TikTok and its parent company ByteDance through an internal messaging platform named Lark.

The Senators accuse TikTok employees of giving them “misleading or inaccurate responses”

The Senators say in their letter, “We are disturbed by TikTok’s pattern of misleading or inaccurate responses regarding serious matters related to users’ safety and national security, and request that TikTok correct and explain its previous, incorrect claims.” The Times report says, “[the] profusion of user data on Lark alarmed some TikTok employees, especially since
ByteDance workers in China and elsewhere could easily see the material.” The report also noted that data from the Lark platform was kept on China-based servers.

A story in Forbes published last month was mentioned in the letter written by the two Senators. That article accuses TikTok of storing the financial information of U.S. TikTok creators, including tax information and social security numbers, in China.

Senators Blumenthal and Blackburn point out that they have been told numerous times by TikTok employees and by its CEO that TikTok stores U.S. user data in Virginia and Singapore. Talking to CEO Chew, the pair write, “Nowhere in your response did you mention that TikTok stores user data in China, or that information about U.S. users— including sensitive information like photos and driver’s licenses or reports containing illegal materials like child sexual abuse materials — would be shared on Lark, and therefore accessible to ByteDance employees.”

The Senators demand responses to these questions by June 16th

The letter includes 14 questions that the Senators want TikTok to answer by next Friday, June 16th:

Under what conditions does TikTok currently store information or personal data about American users on servers located in China, or allow employees that are based in China or associated with ByteDance to access that data?At the time that Mr. Beckerman testified in October 2021 that “U.S. user data is stored in the United States,” what American data was stored by, or accessible to, China or ByteDance?Is there anything from Mr. Beckerman’s testimony in October 2021 or your testimony in March 2023 that TikTok believes merits correction?
Why did you and Mr. Beckerman previously testify that TikTok does not store user data in China when Forbes and New York Times reports have clearly found otherwise?

Did TikTok notify CFIUS that it continued to store U.S. user data on servers in China, and if so, when?

For how long has the user data related to the TikTok Creator Fund referenced in the Forbes report been stored in China and why did TikTok store that data in China?

Detail the scope of the U.S. user information stored on servers in China related to the TikTok Creator Fund or any other programs. The Forbes report references “sensitive financial information, including social security numbers and tax IDs.”

According to the New York Times report, U.S. TikTok user data shared on Lark was stored on servers in China as recently as late 2022. For how long was that user data being stored in China and is any Lark data from U.S. users still stored or retained on servers in China?

China’s National Intelligence Law requires organizations and citizens to “support, assist and cooperate with the state intelligence work.” Can ByteDance or TikTok be compelled to share U.S. user data stored in China to Beijing?

Has TikTok taken any steps to investigate whether data related to the TikTok Creator Fund or any other U.S. user data stored in China or accessible to ByteDance employees was shared with officials of the Chinese Communist Party or the Chinese government?

Has TikTok and/or ByteDance deleted the U.S. user data referenced in the New York Times and Forbes reports from its servers in China? Do you intend to maintain those as backup to the cloud infrastructure, as well?

Are TikTok employees still using Lark for internal messaging and management functions? Is ByteDance still involved in the development and maintenance of this data sharing tool?

The New York Times report mentioned the sharing between employees on Lark of sexually explicitly images of children as young as 3 years old. We previously wrote to TikTok to ask a series of questions about how the company handles the moderation of such content. What protocols do you use to ensure the appropriate handling and reporting of these unlawful materials?

What oversight, involvement, or role does TikTok have with other products offered by ByteDance to users in the United States, such as Lemon8 or CapCut?


[ad_2]
Source link

New Phishing Scam Spoofs German Media, Broadband Conference Anga

0
[ad_1]

The Anga Com Conference is Europe’s leading business platform for Broadband, Television, and Online, based in Germany. However, in the latest phishing scam, crooks are exploiting the platform to steal personal data.

In a cunning display of cyber deception, hackers have devised an intricate phishing attack by leveraging the reputation of Germany’s renowned Anga Com conference. By sending spoofed emails and creating deceptive web pages, these hackers are deceiving unsuspecting users into divulging their login credentials.

Security researchers at Avanan, a subsidiary of Check Point Software, have uncovered the details of this sophisticated attack, shedding light on the techniques employed by crooks. Anga Com is a widely attended conference in the broadband and media distribution industry, drawing more than 22,000 participants from 470 companies globally.

Typically, conferences serve as a platform for companies to generate interest and revenue by sharing lead lists. However, hackers have exploited this process by inserting themselves into the lead delivery system. In this case, they have created fraudulent web pages on legitimate developer sites, making it challenging for victims to detect the scam.

The attack begins with an email that appears to originate from Anga Com, informing recipients that visitors expressed interest in their exhibition during the conference. The email entices users with the prospect of generating new business and urges them to click on a provided link to engage with potential clients. Upon inspection, the email address of the sender is found to be an Outlook address not associated with Anga Com.

Clicking on the link redirects users to a deceptive login page skillfully designed to mimic the legitimate Anga Com platform. Unbeknownst to victims, the URL of this page is angacom-de.surge.sh, whereas the genuine URL is angacom.de. The hackers have utilized Surge.sh, a legitimate web development service, to create a convincing replica of the Anga Com website. When users enter their email and password on this fraudulent page, their credentials are promptly stolen.

This attack combines several techniques, including impersonation, social engineering, and credential harvesting. The initial email preys upon the trust and interest associated with the Anga Com conference. Hackers capitalize on the conference’s popularity and the promise of new business opportunities to manipulate users into clicking malicious links.

Moreover, the creation of the look-alike webpage requires some level of expertise, although the availability of tools like Surge.sh facilitates this process for cyber criminals.

German Broadband and Media Conference Anga Spoofed to Steal Data
Phishing email and its content (Image credit: Avanan)

According to the company’s blog post, Avanan researchers promptly notified Surge.sh and Anga Com of the situation upon discovering this attack. By replacing the links in email bodies and attachments, security services can enhance their ability to detect and prevent attacks that hide malicious links.

To defend against such attacks, security professionals are advised to implement security measures that thoroughly examine all URLs and emulate the webpages behind them.

Furthermore, leveraging URL protection systems that recognize phishing techniques, such as those employed in this attack, can serve as valuable indicators of malicious activity. Educating users and employees to hover over URLs and exercise caution when clicking on links can also help mitigate the risk posed by sophisticated phishing campaigns.

  1. How to detect phishing images in emails
  2. Scammers Pose as ChatGPT in New Phishing Scam
  3. Geo Targetly URL Shortener Abused in Phishing Scam
  4. YouTube phishing scam using authentic email address
  5. Coinbase Employees Targeted by SMS Phishing Attack

[ad_2]
Source link