First look at the two new Google News Android widgets

0
[ad_1]
A week ago we told you about some new features that Google is adding to the Android platform. Among these features are new widgets that Android users can use to track stock prices on their home screens, receive recommendations about which television shows and movies to stream on Google TV, and get the latest news from the Google News app. There are actually two Google News widgets coming which will replace the current solitaire Google News widget.
The two new Google News widgets are available with version 5.82 of the app. Considering that version 5.81 is still the build of the app being pushed out of the Play Store, getting the new widgets is a waiting game at this point. Nail Sadykov, editor of the Google News Telegram Channel, tweeted out a couple of images showing the two new widgets in use. One is a Quick View widget 2×2 in size that will give you limited information about one story.

The second widget weighs in at 4×3 and is called a List View. It shows you two headlines and small images for each story. That compares with the current 4×2 widget that shows limited information and a small picture for one story. So once you receive Google News version 5.82 for your Android phone, you can forget about the latter widget and choose one smaller one or a larger one to place on your home screen.

To see which version of Google News you have installed on your Android phone, go to Settings > Apps > See all xxx apps and scroll down until you see Google News. Tap on it and you’ll be taken to the Google News App info page. Scroll down to the very bottom of the page and you’ll see the version number of the app that you have installed. Unfortunately, the version of Google News running on my Pixel 6 Pro is 5.80.

[ad_2]
Source link

ChatGPT’s False Information Generation Enables Code Malware

0
[ad_1]

The issue allows attackers to exploit ChatGPT’s tendency to generate false information, particularly in the form of nonexistent code packages.

In a recent study, cybersecurity researchers have discovered a concerning vulnerability in ChatGPT, a popular generative artificial intelligence (AI) platform. The flaw/issue allows attackers to exploit ChatGPT’s tendency to generate false information, particularly in the form of nonexistent code packages.

By utilizing what the researchers term “AI package hallucinations,” threat actors can create and distribute malicious code packages that developers may inadvertently download and integrate into their legitimate applications and code repositories.

The researchers, from Vulcan Cyber’s Voyager18 research team, detailed their findings in a blog post published on June 6th, 2023. They highlighted the risks posed to the software supply chain, as malicious code and Trojans could easily slip into widely used applications and repositories such as npm, PyPI, GitHub, and others.

The root cause of the problem lies in ChatGPT’s reliance on outdated and potentially inaccurate training data. As a large language model (LLM), ChatGPT is capable of generating plausible but fictional information. This phenomenon, known as AI hallucination, occurs when the model extrapolates beyond its training data, leading to responses that seem plausible but may not be accurate.

The attack technique involves posing coding-related questions to ChatGPT, which then provides recommendations for code packages. Attackers exploit the platform’s tendency to suggest unpublished or nonexistent packages. They can then create their malicious versions of these packages, waiting for ChatGPT to recommend them to unsuspecting developers. Consequently, developers may unknowingly install these malicious packages, thereby introducing significant risks into their software supply chain.

To demonstrate the severity of the issue, the researchers conducted a proof-of-concept simulation using ChatGPT 3.5. They engaged in a conversation with the platform, asking for a package to solve a coding problem. ChatGPT responded with multiple package recommendations, some of which were nonexistent.

The researchers then proceeded to publish their malicious package, replacing the nonexistent recommendation. Subsequently, when another user posed a similar question, ChatGPT suggested the newly created malicious package, leading to its installation and potential harm.

Watch the demonstration video shared by Vulcan Cyber

The research team also provided recommendations on how developers can identify and mitigate these risks. They advised validating the packages they download by scrutinizing factors such as creation dates, download numbers, comments, stars, and any associated notes.

Developers are urged to exercise caution, especially when recommendations come from AI platforms rather than trusted sources within the community.

This discovery adds to a series of security risks associated with ChatGPT. As the platform gained widespread adoption, threat actors seized the opportunity to exploit its capabilities for various malicious activities. From malware attacks, phishing campaigns and credential theft; the rise of generative AI platforms like ChatGPT has attracted both legitimate users and malicious actors.

  1. ARMO integrates ChatGPT to secure Kubernetes
  2. OpenAI ChatGPT Bug Bounty – Earn $200 to $20k
  3. Fake ChatGPT Extension Hijacks Facebook Accounts
  4. DarkBERT AI: Bringing Cybersecurity to the Dark Web
  5. Polymorphic Blackmamba malware created with ChatGPT

[ad_2]
Source link

Galaxy Z Flip 4 & A53 grab Samsung’s June 2023 update in the US

0
[ad_1]

After the Galaxy Z Fold 4 and Galaxy Note 20 series, a couple more Samsung smartphones are receiving the June 2023 security update in the US. The Korean firm is pushing the latest security patch to the Galaxy Z Flip 4 and Galaxy A53 stateside. More eligible devices will join the party in the coming days.

Like the previous two devices, the June SMR (Security Maintenance Release) for the Galaxy Z Flip 4 is also initially rolling out to factory-unlocked units. Samsung is pushing the firmware build number F721U1UES2CWE1 to the 2022 clamshell foldable. The official changelog supplied by the company only mentions the latest security fixes, and that’s probably it. Don’t go deep looking for anything else. The update should soon reach carrier-locked units as well, while the Korean firm gradually expands the release to international markets.

The story for the Galaxy A53 5G, meanwhile, is the other way around. Samsung has begun with the carrier-locked variant here. The latest update for this premium mid-range phone comes with the build number A536USQS6CWE5. As of this writing, the rollout appears limited to units on the Dish Wireless network, according to SamMobile.  However, it may not be long before the Korean firm widely rolls out the June SMR for the Galaxy A53, covering unlocked units as well as international versions of the phone.

As said earlier, the Galaxy Z Flip 4 and Galaxy A53 are following the Galaxy Z Fold 4 and Galaxy Note 20 series in Samsung’s June 2023 update party. The latter two were the first Galaxy phones to get this month’s security patch. The company has also released this update for the Galaxy S22, Galaxy S20, Galaxy A52s 5G, Galaxy A52, Galaxy A23, Galaxy Tab Active 3, and Galaxy A12 Nacho in a handful of international markets. The rollout should reach the US in the coming weeks (for models launched in the US).

Samsung is pushing over 60 security fixes to Galaxy devices with the June 2023 update

This month’s security update for Galaxy devices patches more than 60 vulnerabilities. 11 of those are Galaxy-specific patches (these security issues don’t exist on Android products from other brands). The remaining patches concern generic Android OS issues, at least three of which were labeled critical flaws by Google. If you’re using any of the aforementioned Galaxy devices and haven’t received the June SMR yet, watch out for a new update in the coming days. As usual, you can check for updates manually from the Settings app.


[ad_2]
Source link

Meta investigates Instagram algorithm boosting CSAM content

0
[ad_1]

It’s no secret that the criticism surrounding Instagram’s algorithm recently prompted the company to shed some light on how it works. However, it looks like Instagram’s algorithm is once again under scrutiny as according to researchers from Stanford University and the University of Massachusetts Amherst, the algorithm is not only associated with a “vast pedophile network,” but it also promotes it by allowing users to search for explicit Instagram hashtags related to CSAM.

The researchers also discovered that these hashtags led users to accounts selling pedophilic materials, which included videos depicting children harming themselves or engaging in acts of bestiality. Shockingly, some accounts even provided options for buyers to “commission specific acts” or arrange in-person meetings.

“Instagram is an onramp to places on the internet where there’s more explicit child sexual abuse. The most important platform for these networks of buyers and sellers seems to be Instagram,” said Brian Levine, director of UMass Rescue Lab.

Instagram’s response

In response to this disturbing report, Meta, the parent company of Instagram, has set up an internal task force and launched an active investigation. Moreover, the company is also making efforts to block networks involved in child sexual abuse material (CSAM) and implement system changes. However, the fact that Instagram often ignored attempts made by users to report these CSAM accounts and even viewing an account associated with an underage seller triggered the algorithm to recommend new accounts raises some serious concerns.

“Child exploitation is a horrific crime. We are continuously exploring ways to actively combat this behavior,” said Meta.

Although Meta claimed that they actively seek and remove users involved in child exploitation, citing the takedown of 490,000 accounts violating child safety policies in January alone, this report comes at a time when social media platforms, including Meta’s Instagram, face increased scrutiny regarding their efforts to regulate and prevent the dissemination of abusive content. Moreover, Meta’s recent plans to expand end-to-end encryption have had law enforcement agencies like the FBI and Interpol worried, as it could hinder the detection of harmful content related to child sex abuse.


[ad_2]
Source link

Advanced Espionage Malware “Stealth Soldier” Hits Libyan Firms

0
[ad_1]

The Stealth Soldier campaign marks the possible reappearance of a threat actor known as “The Eye on the Nile” since its last operation in 2019.

Check Point Research has recently uncovered a series of highly-targeted espionage attacks in Libya, shedding light on a previously undisclosed backdoor called Stealth Soldier. This sophisticated malware operates as a custom modular backdoor with surveillance functionalities, including file exfiltration, screen and microphone recording, keystroke logging, and stealing browser information.

The campaign, which appears to be targeting Libyan organizations, marks the possible re-appearance of a threat actor known as “The Eye on the Nile” since its last operation in 2019.

Advanced Espionage Malware "Stealth Soldier" Hits Libyan Firms

Stealth Soldier, an implant used in limited and targeted attacks, has shown active maintenance with the latest version, Version 9, compiled in February 2023. Check Point Research’s investigation began with the discovery of multiple files submitted to VirusTotal between November 2022 and January 2023 from Libya.

These files, named in Arabic, such as “هام وعاجل.exe” (Important and Urgent.exe) and “برقية 401.exe” (Telegram 401.exe), turned out to be downloaders for different versions of the Stealth Soldier malware.

The execution flow of Stealth Soldier starts with the downloader, which triggers the infection chain. Although the delivery mechanism of the downloader remains unknown, social engineering is suspected.

The malware’s infection process involves downloading multiple files from the Command and Control (C&C) server, including the loader, watchdog, and payload. These components work together to establish persistence and execute the surveillance functionalities.

First, the loader downloads an internal module called PowerPlus to enable PowerShell commands and create persistence. Then, the watchdog periodically checks for updated versions of the loader and runs it accordingly. Finally, the payload collects data, receives commands from the C&C server, and executes various modules based on the attacker’s instructions.

The victim’s information collected by the Stealth Soldier’s payload includes the hostname, username, drive list, and files within specific directories. The malware supports various commands, including directory listing, file upload, screenshot capture, microphone recording, keylogging, browser credential extraction, and PowerShell command execution. 

Check Point Research identified three different versions of Stealth Soldier (Versions 6, 8, and 9), each with slight variations in functionality, filenames, and persistence mechanisms.

Additionally, the investigation uncovered a set of phishing domains linked to the campaign, with some masquerading as websites belonging to the Libyan Ministry of Foreign Affairs.  The phishing domains, hosted on IP addresses associated with previous malicious activities, indicated a likely intention to conduct phishing campaigns.

Check Point Research also discovered similarities between this recent operation and the “Eye on the Nile” campaign, previously linked to government-backed bodies by Amnesty International and Check Point Research. The overlapping infrastructure suggests a possible connection between the two campaigns, indicating the persistence and adaptability of the threat actor behind them.

The Stealth Soldier malware campaign targeting Libyan organizations highlights the increasing sophistication of cyber espionage operations. The use of custom backdoors and advanced surveillance capabilities poses significant threats to targeted entities’ data security and privacy.

Detecting and mitigating advanced threats like Stealth Soldier requires a combination of proactive threat intelligence, user awareness, and effective security solutions to ensure a resilient defence against evolving cyber threats.

  1. Facebook removes accounts over iOS, Android malware
  2. Worok Hackers Hit Orgs, Govts in Asia, Middle East, Africa
  3. Russia used Triton malware to sabotage Saudi petro plant

[ad_2]
Source link

ASUS confirms that the Zenfone 10 will launch this month

0
[ad_1]

We have a bunch of new and exciting devices coming out to kick off the Summer. After following rumors about the Asus Zenfone 10, the company confirmed when this phone is going to launch. It’s going to be coming out later this month.

Winter is the Galaxy S season and Fall is the iPhone/Galaxy foldable/Pixel phone season. Right in the middle, we have summer, which is the time of year when we should expect the latest phones from companies like Nothing, Asus, Etc. That’s the case with the upcoming Zenfone 10, the latest flagship from computer company Asus.

The Zenfone 10 will launch later this month

Asus launches its ROG phones which are meant to be top-tier phones for hardcore Gamers. However, if you’re looking for your basic core Android smartphone experience, then the Zenfone should be the one for you. The latest iteration is the Zenfone 10, and ASUS just confirmed that it’s coming out on June 29th.

As for this phone’s specs, we have a ton of information about it. However, these are merely rumors at this point. You’ll want to take them with a grain of salt until the company launches the device.

Starting off with the display, this phone is expected to have a relatively small 6.3-inch full HD+ AMOLED  display. What’s neat is that it’s expected to run at 120Hz.

Moving on to the internals, rumors point to this phone using the Octa-Core Snapdragon 8 Gen 2 SoC. This could be backed up by an impressive 16GB of LPDDR5X RAM and 256GB/512GB of UFS 4.0 storage. It may come with a 5,000mAh battery with 67-watt fast charging.

As for the camera package, this phone is expected to have a 200-megapixel main camera that can record 8K video. This will make another phone to hit the market with a 200-megapixel camera.

Other specs include Android 13 out of the box running on top of Zen UI 10, dual SIM support, IP68 water and dust resistance, a 3.5mm headphone jack, Wi-Fi 6, and Bluetooth 5.3. Overall, this is going to be a very feature-rich phone with a lot to love.

We don’t know the price just yet, but FoneArena speculates that the phone could start at around $749 for the 16GB/256GB variant. There are just a few more weeks to wait before this phone launches.


[ad_2]
Source link

Bally Sports will probably lose 4 more MLB Teams after refusing to pay them

0
[ad_1]

Bally Sports’ parent-company, Diamond Sports Group or DSG, is currently in bankruptcy court. It is trying to restructure its deals with different sports teams – which it inherited from Fox when Disney bought Fox and had to sell off the Fox Sports RSNs.

However, during this time, Bally Sports has also not been paying the teams that they broadcast. That included 9 teams: Angels, Braves, Cardinals, Diamondbacks, Guardians, Padres, Rangers, Reds and Twins. However, last week, a judge ordered that they pay what they owe, or they will forfeit the TV rights to those teams.

Now, the company is considering not paying for four of these MLB teams. That’s the Twins, Diamondbacks, Guardians and Rangers. So it’s likely that these teams will be put onto MLB.TV for the rest of the year. That’s if Bally Sports does go through with this and doesn’t pay them.

Bankruptcy is getting messy for DSG

For DSG, bankruptcy is getting pretty messy, and when all is said and done, they may not have many teams left to broadcast. RSNs have had a tough time lately, with AT&T SportsNet shutting down their RSNs, and Bally Sports now in bankruptcy. It’s getting harder and harder for sports fans to watch their local teams.

However, local sports is expensive, and with so many people cutting the cord, it leaves RSNs like Bally Sports with less revenue for the teams they do broadcast. And of course, teams don’t want to lose Bally Sports or any other RSN, because they pay the teams a pretty large sum every few months. Those payments are what help make the crazy, historic contracts that some players receive.

There are sharks in the water, as others are looking to grab these RSNs from DSG. Like Scripps. Scripps believes that all local sports should be on free TV, also known as OTA channels. That’s how it should be, as it will get more and more people on-board to watching the games. Since they won’t have to pay $20 per month for a single team – like Bally Sports+ currently does.


[ad_2]
Source link

A dedicated YouTube Music App may be coming to more devices soon

0
[ad_1]

As we already reported, Siri on HomePod will soon gain support for YouTube Music, which means you will be able to tell Siri to play songs directly from YouTube’s streaming music service. However, it appears that Apple‘s HomePod won’t be the only device gaining support for the service.

As 9to5Google first reported, YouTube Music will soon be available on more devices, according to an unnamed source familiar with the matter. For example, the source claims that Google is planning to release a new YouTube Music app specifically for Apple TV. At the moment, there is no information on whether Google plans to release a separate YouTube Music app on Android TV as well, but we have our hopes up that we will see such an app on Android TV too.

9to5Google’s source also claims that a dedicated YouTube Music app is also coming to Garmin smartwatches. At the moment, Garmin smartwatch users have access to Spotify, Deezer, and Amazon Music through the Connect IQ store, and it’s great news that YouTube Music subscribers will also be able to listen to their favorite songs directly from their favorite Garmin smartwatch.

The source also informed the publication that a dedicated YouTube Music app is coming to other wearables as well, but they did not specify which ones. There is also no information on when Google plans to release the YouTube Music app on Apple TV and Garmin smartwatches.

We are excited to see that Google is planning to make the YouTube Music app available to more and more devices. A lot of people are using the streaming service, and having a dedicated app always makes the user experience better.

[ad_2]
Source link

Nothing OS 2.0 might look wildly different from version 1.0

0
[ad_1]

From a hardware standpoint, the Nothing phone (1) really sticks out. From the software standpoint, by stark contrast, there’s nothing notable about it. However, XDA Developers was able to have a conversation with Mladen M. Hoyss, the software creative director at Nothing, and he has some interesting news to tell us about the software coming up. Nothing OS 2.0 is said to look very different from the first-generation software.

Hoyss spoke about why the software was so derivative of stock Android. The software and its overall aesthetic look very similar to Android 11, and that seems pretty odd. We were looking for a wild and completely different Android experience. The truth of the matter is that Nothing was working with a very limited team of people with Nothing for OS 1.0.

There were about five people on the team with additional third-party contractors. So, it seemed that the company needed to keep things relatively simple.

However, Nothing OS 2.0 might look very different

The Nothing Phone (1) was popular enough to warrant a second iteration, and that means more people to work on the software. Hoyss said that the team ballooned to over a hundred people, and the company is able to bring a refreshing change to the software. We’re expecting the software to look very different from the first iteration, and we’re all excited.

While we have no visual on Nothing OS 2.0, Hoyss described the driving mentality behind the software. The thing is, Hoyss believes that your phone’s home screen is underutilized in Android. It’s just a screen full of “company logos.” However, the home screen can be used in a much different manner.

It seems that the company wants to surface more core functionality on the home screen. So, you won’t have to leave your home screen to dig in and find certain functions that should be accessible readily. We’re not quite sure what he means by that, but it appears that the company wants to have functionality accessible on a more at-a-glance basis.

This might remind you of the At a Glance widget on pixel devices. However, Hoyss mentioned that the company is going to put its own spin on it. That’s great news to hear, as we are always looking forward to things that are new and refreshing in the tech world. Many Android OEMs tend to stick with a near-stock Android look, While others take Android in a wildly different Direction.

We’re all excited about Nothing OS 2.0 and the Nothing Phone (2). It’s set to launch sometime in July, so there’s not much more time to wait.


[ad_2]
Source link

How to check Air Quality (AQI) on Android and iPhone

0
[ad_1]

With the recent wildfires in Canada having pushed the smoke down into the US, there’s been a lot of news lately about just how bad the air quality has been along the east coast. From Chicago all the way to New York City, and it’s only starting to move further south. Recently, the AQI in New York City was well over 400. The scale only goes to 500, and once it hits 300, it’s dangerous to be outside. So that tells you just how bad it’s been lately.

So, how can you check the air quality around you? It’s actually quite easy, and today, we’re going to show you how to do this on both Android and iOS.

How to check Air Quality on Android

The easiest way to check the AQI on Android is by opening Google Maps.

Once you’ve opened Google Maps, tap on the Layers button.

Now at the bottom, you’ll see an option for “Air Quality”. This is a new feature for Google Maps, and couldn’t have come at a better time.

Screenshot 20230608 100025

Now, you’ll see the AQI for your area, and you can also zoom out to see what it looks like elsewhere.

How to check Air Quality on iPhone

Google Maps on iOS also allows you to check the Air Quality. So you can follow the same steps above to check on the iPhone. But you can also use the Weather App.

Typically, when the air is very unhealthy, it’ll show a card at the top with the AQI, and show that it might be “unhealthy for sensitive groups”.

IMG 0017

If you’re not in an area where the air quality is that bad, you might not see it at the top, but it will be shown towards the bottom of the screen as another card along with the sunrise/sunset, humidity and other factors.

That’s how you can check the Air Quality Index for your area on both Android and iPhone.


[ad_2]
Source link