VMware patches critical vulnerabilities in Aria Operations for Networks

0
[ad_1]

VMware has released security updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution

VMware has released security updates to fix three vulnerabilities in Aria Operations for Networks which could result in information disclosure and remote code execution.

The vulnerabilities were found in Aria Operations for Networks which was formerly known as vRealize Network Insight. Users of versions VMware Aria Operations for Networks 6.x are under advise to applying the patches listed in the VMware KB article about these vulnerabilities.

Before you download and apply the security patch for your Aria Operations for Network deployment, it is advised to perform clean up using steps mentioned in VMware KB 88977 to avoid issues with patch upgrade failing with “Insufficient disk space toast message.”

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The CVEs patched in these updates are:

CVE-2023-20887 (CVSS score: 9.8 out of 10): Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution (RCE).

CVE-2023-20888 (CVSS score: 9.1 out of 10): Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid ‘member’ role credentials may be able to perform a deserialization attack resulting in remote code execution (RCE).

CVE-2023-20889 (CVSS score: 8.8 out of 10): Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.

Command injection is an attack method that aims to execute arbitrary commands on a system. Typically, the threat actor injects the commands by exploiting an application vulnerability, such as insufficient input validation.

Deserialization is the process of extracting data from files, networks or streams and rebuilding the data as objects. Deserialization of user input is considered a security misconfiguration, and can have serious consequences.

VMware Aria Operations for Networks helps IT teams to monitor, discover, and analyze networks and applications to build an optimized, highly available and secure network infrastructure across clouds.

Virtualization technology has taken the scalability of IT systems to the next level. Cybercriminals are very much aware of that and have a vested interest in hypervisor software and network mapping tools, because they make it easier to control a host of virtual machines. Which is much more effective than attacking individual systems.

So, vulnerabilities in such software are guaranteed to be researched by malicious actors.


We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using Malwarebytes Vulnerability and Patch Management.


[ad_2]
Source link

Ever wanted to ride a raptor in Fortnite? Well, now you can!

0
[ad_1]

If you’re excited about what Fortnite has in store for its next season, the wait is over. Chapter 4 season 3 just released its latest cinematic trailer, and it shows that, among other things, you may be able to ride raptors. Fortnite Wilds is set to launch today and it ties into an upcoming movie.

It’s not hard to see which movie when you watch the end of the trailer. Optimus Prime makes an appearance. This new season revolves around the upcoming Transformers: Rise of The Beasts. So, if you’re excited about the movie, then you will enjoy this season.

Fortnite Wilds gets its official cinematic trailer

One thing you can say about Fortnite is that it is really good at hyping up its fans. The cinematic trailer begins with four characters standing on a cliff as they watch the entire middle section of the island collapse into a gigantic jungle. Soon after coming down the cliff, they see the Raptors for which they ride to the center. In the center, there’s a large temple where they meet Optimus Prime.

Optimus Prime’s model is no bigger than the other characters, which means that you’ll most likely be able to play as him. Not only that, but we were introduced to a new weapon as well. It appears to be a giant blaster with explosive capabilities.

Fortnite Wilds is set to launch today, so you should most likely see it when you log on. If not, then you will have to just wait until it reaches your region.

Excited about the Movie?

If you’re looking forward to watching Transformers: Rise of The Beasts, the movie is now out in theaters. It’s rated PG-13, and it’s just over 2 hours long. The movie stars notable actors such as Pete Davidson, Peter Cullen, and Ron Perlman. Why not watch the movie, and then relax with a little bit of Fortnite?


[ad_2]
Source link

Qbot malware adapts against Microsoft’s latest defence tactic

0
[ad_1]

Although over the past few years, Microsoft has done a commendable job in taking steps to combat malware and prevent its havoc, including the recent ban on macros from running in Office files downloaded from the internet, it looks like threat actors always find a way as the notorious Qbot malware has now evolved to remain effective against Microsoft’s latest tactic.

According to research conducted by Black Lotus Labs, the Qbot malware, which initially started as a banking trojan over a decade ago, has quickly adapted its distribution network, deployment methods, and command and control (C2) server in response to Microsoft’s changes. Additionally, threat actors have also introduced new techniques for initial access in phishing campaigns, such as using malicious OneNote files, Mark of the Web evasion, and HTML smuggling.

“Qakbot has shown resilience by employing a resourceful approach in building and developing its architecture..it demonstrates technical expertise by employing various initial access methods and maintaining a robust yet evasive residential C2 architecture,” reads the report.

Greater adaptability

Besides the new deployment methods, the Qbot operators have modified how they manage their C2 servers, as instead of relying on hosted virtual private servers (VPS), threat actors now hide the C2 servers within compromised web servers and hosts in residential IP spaces. Although this approach results in a shorter lifespan for servers, hackers can quickly obtain new ones. Approximately 90 new C2 servers are brought up every week during a spam cycle.

Furthermore, converting bots into C2 servers is crucial to Qbot’s operations. This is because over 25% of these servers are active for a day, and half do not survive beyond a week. Therefore, converted bots play a vital role in replenishing the C2 server supply.

To make matters worse, the report states that the malware will persist as a significant threat for the foreseeable future. “There are currently no signs of Qakbot slowing down.”


[ad_2]
Source link

Update your Cisco System Secure Client now to fix this AnyConnect bug

0
[ad_1]

We take a look at a recent update for Cisco Secure System Client and why you should apply the update as soon as possible.

Cisco Secure Client is the fresh recipient of a fix to address a high-severity vulnerability related to improper permissions. The flaw allows attackers to potentially escalate privileges to the SYSTEM account.

From the vulnerability advisory:

A vulnerability in the client update feature of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM.

This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the upgrade process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.

As Bleeping Computer notes, Secure Client allows for remote work thanks to a secure Virtual Private Network and also gives admins telemetry and endpoint management functionality. The attacks themselves do not need user interaction to get the exploitation ball rolling. Bleeping Computer also mentions that there is no current evidence to suggest active exploitation in the wild. With this in mind, there’s never been a better time to start patching. 

As with so many other vulnerabilities out there, there is no workaround for this issue. What this means is that if you’re delayed applying an update for whatever reason, there’s no way to put a band-aid over the wound until you’re ready to hit the update button. Your setup will simply remain at risk until you do it.

The vulnerable products are as follows:

Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows.

Note: For releases earlier than Release 5.0, Cisco Secure Client for Windows is known as Cisco AnyConnect Secure Mobility Client for Windows.

There’s a number of products not at risk from this issue, which are listed below. You’ll note that none of them are Windows.

  • Cisco AnyConnect Secure Mobility Client for Linux
  • Cisco AnyConnect Secure Mobility Client for MacOS
  • Cisco Secure Client-AnyConnect for Android
  • Cisco Secure Client AnyConnect VPN for iOS
  • Cisco Secure Client for Linux
  • Cisco Secure Client for MacOS

This issue has been resolved with the release of Cisco Secure Client for Windows 5.0MR2, and AnyCOnnect Secure Mobility Client for Windows 4.10MR7. If you haven’t already done so, it’s time to check out the Cisco downloads page and make your network a little bit safer.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Google News got 2 new widgets that use Material You

0
[ad_1]

Google is busy applying the Material You paint job to every corner of Android. It started this process back in 2021, and most of the software has the updated aesthetic. However, the company’s job is not done. The Google News app just got two new widgets, and these all have the Material You design, according to Android Police.

If you’re looking for a reliable source to aggregate the latest news headlines, then you might want to use Google News. As you can tell, it’s a news platform that will curate news stories based on the hottest headlines.

Also, since it’s tied to your Google account, you’ll get personalized seeds of headlines based on your search history and activity. Your Android phone may come with it already installed. If not, you can get it from the Play Store.

Google News is getting too new Material You widgets.

Before, there was only one Google News widget. Now, the company boosted it to two. The first widget is a smaller 2×2 widget, and it shows you one headline at a time. It will show you the latest top news headline. You will get the title of the article, the publication at the bottom, and the age. This will provide you with a quick at a glance look at what’s happening.

The next widget is a bit larger. This one is 4×3, and the size can be adjusted. The larger widget will show you two headlines, and they’ll all have the same information.

Being a Material You widget, all the corners are very rounded. Also, they have the classic Material You two-toned colors. The colors will comply with your system’s color palette. The background of the second widget will be a lighter shade while the actual articles will be a darker shade. That may change if you switch to dark mode.

Right now, this is not available to the general public. The widgets are in version 5.82, and the latest version on the Play Store is version 5.81. However, if you absolutely need to have these new widgets today, you can download the APK file here.


[ad_2]
Source link

Google Bard gains advanced logic & reasoning skills

0
[ad_1]

Google is pushing a new update to its generative AI tool Bard, improving its logic and reasoning skills. This update makes the service better at mathematical tasks, coding questions, and string manipulation. Bard is also getting support for exporting tables to Google Sheets.

Google developed a new technique to improve Bard’s logic skills

In March, Google incorporated PaLM (Pathways Language Model) into Bard for improved math and logic capabilities. The company said that it would continue to develop advanced logic skills for the AI tool in the coming months. As promised, it has now updated the service with capabilities for solving complex mathematical tasks and coding questions.

According to Google, a new technique called “implicit code execution” helps Bard detect computational prompts. In response, it runs code in the background to solve the question and give you accurate answers (it may get things wrong occasionally). With this update, Bard can detect and solve computational and logical prompts like:

  • The angle of elevation of the top of a building from the foot of the tower is 30 degrees and the angle of elevation of the top of the tower from the foot of the building is 60 degrees. If the tower is 50m high, find the height of the building.
  • A is older than B. C is older than B but younger than A. D is younger than E and B. B is older than E. If they sit in the increasing order of their age, who is in the middle?

Google says Bard’s improved logic and reasoning skills rely on a combination of large language models (LLMs) and traditional code. The method has improved the accuracy of Bard’s responses to computation-based word and math problems by about 30 percent. The AI tool may not always get it right, but it is getting better at such problems.

Bard now lets you export tables to Google Sheets

This update for Bard comes just a few days after Google added precise location support to the service. That addition followed a host of updates in May, including the ability to export content to Google Docs and Gmail complete with formatting. It’s now gaining support for Google Sheets export as well. If you prompted Bard to generate a table for some data, or it automatically responded with a table for your question, you can export that table to Google Sheets.

Google will likely push several more updates to Bard in the coming weeks. It is working on a host of new features for the AI tool, including chat history, refining responses according to specific tones, file uploading support, and text-to-speech. We will let you know when the company rolls out these features to Bard.


[ad_2]
Source link

Ransomware review: June 2023

0
[ad_1]

May saw a record number of 556 reported ransomware victims, the unusual emergence of Italy and Russia as major targets, and a significant rise in attacks on the education sector.

This article is based on research by Marcelo Rivero, Malwarebytes’ ransomware specialist, who monitors information published by ransomware gangs on their Dark Web sites. In this report, “known attacks” are those where the victim didn’t pay a ransom. This provides the best overall picture of ransomware activity, but the true number of attacks is far higher.

In May, Lockbit, usually the reigning king of ransomware, found a fierce competitor in MalasLocker. Last month also witnessed a record number of 556 reported ransomware victims, the unusual emergence of Italy and Russia as major targets, and a significant rise in attacks on the education sector.

Let’s jump right in with MalasLocker, who burst onto the scene last month with 171 total victims—beating out LockBit (76) by almost 100 known attacks.

Known ransomware attacks by gang, May 2023
Known ransomware attacks by gang, May 2023

This isn’t the first time this year a gang has overhauled LockBit and climbed to the top spot on our monthly charts. In April Cl0p rose to the number one spot by compromising over 100 victims with a zero-day vulnerability in the widely-used managed file transfer software GoAnywhere MFT.

This month, MalasLocker’s meteoric rise to the top can be explained along similar lines.

MalasLocker attacked vulnerabilities in Zimbra servers, including CVE-2022-24682, to enable remote code execution (RCE). Zimbra Collaboration, formerly known as the Zimbra Collaboration Suite (ZCS) is a collaborative software suite that includes an email server and a web client.

What sets MalasLocker most apart, however, is its unique ‘charitable’ twist. Rather than demanding ransoms, it asked victims to donate to its approved charities.

MalasLocker: The Robin Hood of ransomware?

Needless to say, it is highly unusual for a ransomware gang to purport to attack organizations on altruistic grounds. We haven’t seen it once since keeping track of gangs in early 2022. 

“Unlike traditional ransomware groups, we’re not asking you to send us money. We just dislike corporations and economic inequality,” reads the MalasLocker ransom note README.txt.

One might assume that a ransomware gang principally opposed to corporations and economic inequality might disproportionately target larger and more wealthy organizations, but this isn’t necessarily the case. The gang’s blog suggests it’s open to targeting businesses of all sizes, so long as they aren’t located in “Latin America, Africa, or other colonized countries.”

We are completely unmoved by MalasLocker’s supposed altruism. Ransomware gangs (and cybercriminals in general) have a long and storied history of writing long and tedious tracts justifying their criminal activity with grandiose claims.

MalasLocker is no different. We read its manifesto so you don’t have to, and the only line you need to pay any attention to is the one that reads “so we will become just another ransomware group.”

So far, we have no confirmation that MalasLocker is keeping its word for a decryptor when a victim donates money to a charity.

Known ransomware attacks by country, May 2023
Known ransomware attacks by country, May 2023
Known ransomware attacks by industry sector, May 2023
Known ransomware attacks by industry sector, May 2023

Italy and Russia emerge as targets

The upswing in ransomware activity in Italy and Russia in May is striking. Both countries were propelled into the top three most targeted nations in May, a list typically dominated by the USA and the UK.

Italy saw more than a six-fold increase from the month before, and Russia went from zero reported attacks to 50 in a single month. For comparison, Italy had only eight reported ransomware incidents in April, while Russia wasn’t even listed. Similarly, in March, Russia had no reported incidents, and Italy had just eight.

The surge in attacks on these two countries is entirely due to MalasLocker, which hit more targets in Russia and Italy than anywhere else. We assume that this is not a matter of deliberate targeting but simply a matter of where there were vulnerable targets.

Known MalasLocker attacks by country, May 2023

Known MalasLocker attacks by country, May 2023

Traditionally, most ransomware gangs have avoided targeting Russia and the Commonwealth of Independent States (CIS) to prevent attracting the attention of local authorities who otherwise turn a blind eye to them.

Either MalasLocker isn’t based in the CIS and therefore doesn’t fear the Federal Security Service (FSB), or they are going to have a very short stay in the ransomware charts.

Increased ransomware attacks on Education

The increase in ransomware attacks on the education sector in May is particularly concerning. May saw 30 known attacks—the highest we’ve seen in a single month since we started keeping records in early 2022, and the continuation of a trend that has seen a sustained increase over the past twelve months.

Known ransomware attacks against education, June 2022-May 2023

Between June 2022 and May 2023, Vice Society attacked more education targets than any other gang—a specialization that should alarm schools, colleges, and universities everywhere.

A new norm?

Ransomware gangs seem to be adopting a new modus operandi: Exploiting known vulnerabilities for multi-target attacks. This year we have seen Cl0p and MalasLocker attack multiple targets simultaneously with (presumably automated) targeting of specific system weaknesses, expanding the scale and impact of their ransomware operations.

Cl0p, for example, has a history of exploiting platforms like Accellion FTA and GoAnywhere MFT. In April, it shifted its focus to a vulnerability in another popular platform, PaperCut.

In June, as we prepared this report, it emerged that Cl0p was been exploiting yet another vulnerability, this time in the widely used file transfer software MOVEit Transfer. The gang started exploiting the vulnerability on May 27th, during the US Memorial Day holiday.

A security bulletin released on May 31, 2023 by Progress Software states:

“A SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an un-authenticated attacker to gain unauthorized access to MOVEit Transfer’s database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.“

This approach is unusual and should concern us all because it has the potential to make ransomware attacks more scalable.

New players

BlackSuit

BlackSuit is a new ransomware that is strikingly similar to Royal, sharing 98% of its code. Last month, BlackSuit targeted both Windows and Linux hosts. 

BalckSuit could be a new variant developed by Royal’s authors, a mimicry attempt using similar code, an affiliate of the Royal ransomware gang running its own modifications, or even a breakaway group from the Royal ransomware gang. 


Rancoz

Rancoz is a new ransomware variant which shares similarities with Vice Society. Its sophistication lies in its ability to modify existing code from leaked source codes to target specific industries, organizations, or geographic regions, increasing its attack efficacy and ability to evade detection.


8BASE

8Base is a newly discovered ransomware gang which, despite only recently gaining attention, has been in operation since April 2022. In May, it had a total of 67 victims.

Predominantly targeting small and medium-sized businesses (SMBs), 8Base has attacked mainly companies within the Professional/Scientific/Technical sector, comprising 36% of known attacks, followed by Manufacturing at 17%. Geographical analysis of the victims suggests a concentration in America and Europe, with the United States and Brazil being the most targeted countries.


RA Group

RA Group is a new ransomware primarily focusing its attacks on pharmaceutical, insurance, wealth management, and manufacturing firms located in the United States and South Korea. 

The RA Group employs an encryptor derived from the leaked source code of Babuk ransomware, an operation that ceased in 2021. The encryptor employs intermittent encryption, which alternates between encrypting and not encrypting sections of a file to expedite the encryption process, but leaves some data partially recoverable. 

How to avoid ransomware

  • Block common forms of entry. Create a plan for patching vulnerabilities in internet-facing systems quickly; disable or harden remote access like RDP and VPNs; use endpoint security software that can detect exploits and malware used to deliver ransomware.
  • Detect intrusions. Make it harder for intruders to operate inside your organization by segmenting networks and assigning access rights prudently. Use EDR or MDR to detect unusual activity before an attack occurs.
  • Stop malicious encryption. Deploy Endpoint Detection and Response software like Malwarebytes EDR that uses multiple different detection techniques to identify ransomware, and ransomware rollback to restore damaged system files.
  • Create offsite, offline backups. Keep backups offsite and offline, beyond the reach of attackers. Test them regularly to make sure you can restore essential business functions swiftly.
  • Don’t get attacked twice. Once you’ve isolated the outbreak and stopped the first attack, you must remove every trace of the attackers, their malware, their tools, and their methods of entry, to avoid being attacked again.

Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Best Buy discounts Google Pixel Buds for Father’s Day

0
[ad_1]

For Father’s Day, Best Buy is discounting both versions of the Google Pixel Buds – Pixel Buds a-series and Pixel Buds Pro. Currently, the Pixel Buds a-series are discounted to $79, while the Pixel Buds Pro are now $159.99. That’s going to save you $20 and $40 respectively.

This also makes these some of the cheapest, but good, truly wireless earbuds. So definitely a good time to pick them up.

The Google Pixel Buds A-Series and Pixel Buds Pro are two of the best wireless earbuds on the market. They offer great sound quality, comfortable fit, and a variety of features that make them a great choice for anyone looking for a new pair of earbuds.

The Pixel Buds A-Series are the more affordable option, but they still offer a lot of value. They have a snug and secure fit, thanks to their flush-to-ear design and three included eartip sizes. They also have touch controls that let you answer calls, play, pause, and skip between tracks easily. And thanks to their IPX4 water resistance rating, you don’t have to worry about them getting wet in the rain or from sweat.

The Pixel Buds Pro offer a more premium experience, with features like active noise cancellation, transparency mode, and spatial audio. Active noise cancellation uses microphones to detect and cancel out ambient noise, so you can focus on your music or podcast without being interrupted. Transparency mode lets you hear what’s going on around you without taking your earbuds out. And spatial audio creates a surround sound experience that makes you feel like you’re right in the middle of the action.

Both the Pixel Buds A-Series and Pixel Buds Pro are great choices for anyone looking for a new pair of wireless earbuds. The Pixel Buds A-Series are a great option for budget-minded buyers, while the Pixel Buds Pro offer a more premium experience.

Here is a table that summarizes the key features of the two models:


[ad_2]
Source link

A new tool can tell if your paper was written by AI

0
[ad_1]

Generative AI is the engine that’s going to power the future, and there’s a lot of potential for it to do great things. However, the people who’ll be developing the technology in the future are using it to generate their college essays today. Fortunately, The University of Kansas has a tool that can tell if your report was generated using AI.

With the rise of AI-generated essays, there has been a rise in tools designed to detect them. The thing about generative AI is that the results are meant to sound as human as possible. So, to the untrained ear, an AI-generated essay can sound just like a human wrote it. This means that, ironically, people need to use AI to detect if someone used AI to write their essays.

The University of Kansas developed a tool to detect essays generated by AI

A tool like this is one that comes in handy when grading reports. It doesn’t have a name at the time. However, what’s important is that it’s really accurate. The researchers stated that this tool can detect AI-generated content with 99% accuracy. That’s insane seeing how close chatbots can get to the real thing.

The researchers took 64 perspective articles and used them to generate 128 articles using ChatGPT. This is what they used to train the tool with. With these articles, the tool was able to correctly identify AI-written content with 100% accuracy. Also, it was able to identify specific paragraphs in the articles with 92% accuracy.

Tools like these are crucial

Anyone could see this situation from a mile away. Since AI now gives us the power to pretty much create anything by typing in just a few words, there’s a high chance that half of what you read on the internet was typed up by a language model. Sure, there are people who use it as a springboard and inspiration, but there are also people who will use it to gain an unfair advantage over true creators.

Tools like these are crucial to detect when people are using AI excessively. Not only are people using it to generate college essays, but people are using it to win competitions, author books, make money, and even scam people.

The fire has already been lit; the bad side of generative AI has already been revealed. All we can do now is rely on tools like these to help as much as they can.


[ad_2]
Source link

Chinese Communist Party had “God mode” entry to US data

0
[ad_1]

A former executive at TikTok’s parent company ByteDance has claimed in court documents that the Chinese Community Party (CCP) had access to TikTok data, despite the data being stored in the US.

A former executive at TikTok’s parent company ByteDance has claimed in court documents that the Chinese Communist Party (CCP) had access to TikTok data, despite the data being stored in the US. The allegations were made in a wrongful dismissal lawsuit which was filed in May in the San Francisco Superior Court.

The former executive is Yintao “Roger” Yu, who worked as head of engineering for ByteDance. Yu worked for ByteDance between 2017 and 2018. According to his claims, the CCP had its own office inside ByteDance’s headquarters.

In the lawsuit he also accuses ByteDance of pushing nationalistic content that served to both increase engagement on ByteDance’s websites and to promote support of the CCP, and that the Communist Party could access American user data through what he called a backdoor channel in the code.

That statement was supported by recent events. The Australian Financial Review has been shown a sample of code to secretly suppress or elevate content that supports Communist Party narratives or sows division within democracies. This is exactly the reason why General Paul Nakasone, Director of the National Security Agency (NSA) called TikTok a loaded gun. Speaking at a US Senate hearing, the general said “one third of Americans get their news from TikTok,” adding “one sixth of American youth say they’re constantly on TikTok.”

Even more shocking is the claim that the CCP not only could access US user data via a backdoor channel in the code but also that some members of the ruling Communist Party used data held by the company to identify and locate protesters in Hong Kong.

Hong Kong is a semi-autonomous region in China with its own government. TikTok is no longer available there. Anyone who tries to open TikTok from within Hong Kong will see a message that reads “We regret to inform you that we have discontinued operating TikTok in Hong Kong.”

He also accused ByteDance of scraping data from competitors, mainly Instagram and Snapchat, without users’ permission.

After being banned from devices of employees of several—mostly government—organizations, TikTok is battling to convince politicians that it operates independently of ByteDance, which has deep ties to the CCP. Yu’s suit alleges that ByteDance was aware that if the Chinese government’s backdoor was removed from the US version of the app, the Chinese government would likely ban the company’s valuable Chinese-version apps.

Responding to Yu’s allegations, ByteDance said it will “vigorously oppose what we believe are baseless claims and allegations in this complaint.” It is “committed to respecting the intellectual property of other companies” and obtains data “in accordance with industry practices and our global policy.”


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link