Update Chrome now! Google patches actively exploited zero-day

0
[ad_1]

Google has released a Chrome update for a zero-day for which an exploit is actively being used in the wild.

Google has released an update which includes two security fixes. One of these security fixes is for a zero-day about which Google says it’s aware that an exploit for this vulnerability exists in the wild.

How to protect yourself

If you’re a Chrome user on Windows, Mac, or Linux, you should update as soon as possible. Android users will also find an update waiting.

The easiest way to update Chrome is to allow it to update automatically, which basically uses the same method as outlined below but does not require your attention. But you can end up lagging behind if you never close the browser or if something goes wrong—such as an extension stopping you from updating the browser.

So, it doesn’t hurt to check now and then. And now would be a good time, given the severity of the vulnerabilities in this batch. My preferred method is to have Chrome open the page chrome://settings/help which you can also find by clicking Settings > About Chrome.

If there is an update available, Chrome will notify you and start downloading it. Then all you have to do is relaunch the browser in order for the update to complete.

screenshot of up to date ChromeChrome is up to date

After the update the version should be 114.0.5735.106 for Mac and Linux, and 114.0.5735.110 for Windows, or later.

Zero day

Google never gives out a lot of information about vulnerabilities, for obvious reasons. Access to bug details and links may be kept restricted until a majority of users are updated with a fix. However, from the update page we can learn a few things.

The vulnerability was reported by Clément Lecigne of Google’s Threat Analysis Group. This could indicate that Google found this vulnerability while researching an active attack, which matches the fact that an exploit for the vulnerability exists in the wild.

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The CVE for the zero-day is:

CVE-2023-3079: a type confusion in V8 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Type confusion vulnerabilities are programming flaws that happen when a piece of code doesn’t verify the type of object that is passed to it before using it. Type confusion can allow an attacker to feed function pointers or data into the wrong piece of code. In some cases, this can lead to code execution.

In other cases, type confusion vulnerability leads to an arbitrary heap write, or heap spray. Heap spraying is a method typically used in exploits that places large amounts of code in a memory location that the attacker expects to be read. Usually, these bits of code point to the start of the actual code that the exploit wants to run in order to compromise the system that is under attack.

At the heart of every modern web browser sits a JavaScript interpreter, a component that does much of the heavy lifting for interactive web apps. In Chrome, that interpreter is V8.

An attacker can exploit this vulnerability by using a specially crafted piece of HyperText Markup Language (HTML). It needs user interaction, which could be easier than it sounds. HTML is the standard markup language for documents designed to be displayed in a web browser and these documents (webpages) can contain JavaScript. Potentially this means that by opening the wrong website, which contains such a specially crafted JavaScript, the browser could be compromised.

Users of other Chromium based browsers, like Edge, should be on the lookout for updates as well, as this one is likely to affect all Chromium based browsers.


We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using Malwarebytes Vulnerability and Patch Management.


[ad_2]
Source link

Sony Xperia Pro-I II may include two 1-inch camera sensors

0
[ad_1]

It has been about a year and a half since the Sony Xperia Pro-I handset arrived. It’s about time for the second-gen model to show itself. Well, the first rumors regarding the device just surfaced. According to this info, the Sony Xperia Pro-I II could include two 1-inch camera sensors.

The Sony Xperia Pro-I II may end up including two 1-inch camera sensors

So, what’s going on? Well, a sketch of the Sony Xperia Pro I II surfaced, along with some concept renders based on that sketch. We cannot confirm this sketch is valid, though, so take this info with a grain of salt.

Sony Xperia Pro I II sketch 1

As you can see in the sketch, there are two large camera sensors on the back. The original Sony Xperia Pro-I did have a 1-inch camera on the back, but that camera was not made for smartphones.

Today, we have the Sony IMX989 1-inch camera sensor, specifically made for smartphones. The rumors claim that the Sony Xperia Pro-I II will include two 1-inch camera sensors. This is just a wild rumor at this point.

Will Sony use two IMX989 sensors, or…?

Sony could opt to include two IMX989 units here, or something else entirely. The company actually created a brand new camera sensor for the Xperia 1 V, so we wouldn’t be surprised if something else ends up being used in the Xperia Pro-I II.

Now, the rumors also claim that the phone will be equipped with a “double-layer transistor stacked pixel sensor”. Sony could actually utilize the largest sensor(s) to date in this phone. We’ll have to wait and see.

You can check out the renders based on the sketch above in the gallery that follows. These are not leaked renders or anything of the sort, so keep that in mind.

We still don’t know when will this phone launch. If Sony intends to stay in line with the Xperia Pro-I launch timeframe, however, you can expect it to arrive in October. The first-gen model launched on October 26, 2021.


[ad_2]
Source link

Apple makes Skiff the default encrypted email service for iOS

0
[ad_1]

In this day and age, where hackers are constantly finding new ways to infiltrate your device and gain unauthorized access, finding secure communication channels has become a top priority. And although there are many encrypted messaging apps and VPNs available on the internet, none of them come close to providing that default experience. Now, in an effort to solve this issue, Apple is making Skiff, an encrypted email service, one of the default emailing options on all iOS devices.

What is Skiff?

Founded by Andrew Milich (CEO) and Jason Ginsberg (CTO) in 2020, Skiff aims to make privacy protection accessible to all users without requiring the technical expertise of setting up a secure firewall or VPN. The company operates on a zero-trust privacy approach, ensuring that it neither stores nor collects any sensitive user information, including location data. Moreover, all communications on the platform are end-to-end encrypted and open-sourced, enabling independent audits and ensuring transparency.

“We firmly believe that protecting your privacy online should be effortless rather than a privilege limited to the tech-savvy or cryptography experts,” said CEO Andrew Milich.

How did Skiff become the default mail app for Apple?

While it may seem like becoming the default email app for Apple was straightforward considering Skiff’s features, the real journey involved over a year of continuous product improvements, including enhanced offline support, secure sign-in options, and seamless compatibility with all email links on iOS. These efforts ultimately caught the attention of Apple, and its inclusion will be a significant step forward in making secure email services more accessible to the general public.

“We are thrilled that Apple has made privacy a key priority and has worked with us to seamlessly integrate end-to-end encrypted email with iOS,” said Milich.

Finally, for those users who want to make Skiff their default email app, the process is quite simple. Just go to the App Store, download the Skiff Mail app on your iOS device, and navigate to Settings > Skiff Mail to set it as the default choice.


[ad_2]
Source link

Victims’ faces placed on explicit images in sextortion scam

0
[ad_1]

We take a look at some new developments in sextortion cases via a warning issued by the FBI.

The FBI has issued a warning about criminals digitally manipulating people’s faces on to pornographic images—known as deepfaking—and then using those images to harass or extort money out of their victim in a practice known as sextortion.

The FBI said the victims include children. From the release:

The FBI continues to receive reports from victims, including minor children and non-consenting adults, whose photos or videos were altered into explicit content. The photos or videos are then publicly circulated on social media or pornographic websites, for the purpose of harassing victims or sextortion schemes.

To hear that children are now being inserted into deepfake creations is horrifying, though perhaps unsurprising. The way these attacks work is that potential victims are contacted through a variety of methods, most commonly by instant messaging apps. Here’s how the FBI describes sextortion:

Sextortion, which may violate several federal criminal statutes, involves coercing victims into providing sexually explicit photos or videos of themselves, then threatening to share them publicly or with the victim’s family and friends. The key motivators for this are a desire for more illicit content, financial gain, or to bully and harass others. Malicious actors have used manipulated photos or videos with the purpose of extorting victims for ransom or to gain compliance for other demands (e.g., sending nude photos).

There’s a few different ways sextortion attacks can play out. One of the most basic forms is sending emails to people whose login details have been exposed in a password breach. The email claims to have nude photographs of the recipient, and threaten to release the photos unless the recipient pays up. There are no images, it’s all a lie. 

The more traditional form of sextortion is where a fraudster convinces the person they’re speaking to that they’re interested in romance, obtains revealing images of the victim, and then uses those images for blackmail. The victim is asked to pay money, often wired or through digital currency, or else the images will be sent to the victim’s friends and family. As it’s usually easy to build up a picture of someone’s network on social media like Facebook and Twitter, the pressure may well be too much for the person on the receiving end of such a scam.

That’s how it usually works. With deepfakes on the scene, a lot of the pre-scam work can simply be discarded. Now fraudsters go and grab some photos of their target, and feed those images into their faking tool of choice. All of that social engineering, the possibility of the victim not falling for it and sending revealing images is completely done away with. Why bother, when you can just swipe a photograph and press a few buttons?

The end result is the same. In fact, it’s arguably much worse as the pornographic movie creations thrown together by these tools are almost always a lot more graphic than anything a target would probably come up with. The pressure to pay up is going to be immense, and realistically non-internet savvy relatives or friends may not have even heard the word “deepfake” before. What are the chances of them knowing a file landing in their mailbox is fraudulent?

There are several general pieces of advice we can give when talking about the different sextortion tactics which exist:

  • Don’t engage: report. If you’re shown evidence of stolen images, report to your local authorities and the FBI as soon as you can. Never engage with the sextortionist.
  • Be cautious about what you say to someone online. When asked certain questions, be vague and never give specifics.
  • Remember that online, people can pretend to be someone they’re not, and can even look and sound like a different person with today’s technology.
  • Personalize your security and privacy settings. Lock down your accounts as much as you can, and keep as much hidden from public view as possible.
  • Data is typically forever. Remember that once you send something to someone—whether they’re a stranger, a romantic partner, relative, or friend—you have no control over where it goes next.

Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Here’s a first look at Meta’s Twitter competitor app

0
[ad_1]

Back in March, a report surfaced stating that Meta is working on an Instagram-branded Twitter competitor. Well, Meta held an employee preview of that Twitter alternative app, and screenshots surfaced, giving us a first look at the app itself.

Take a first look at Meta’s Twitter competitor app

The internal name for this app is ‘Project 92’, while the official name could be ‘Threads’. Now, the screenshots that surfaced are included below this paragraph, in case you’d like to take a peek.

Meta Twitter competitor app screenshots

If it looks familiar, there’s a good reason for it. It basically looks like Instagram’s UI, but without images. So, what’s this app all about? Well, it seems like Meta noticed an opportunity when Elon Musk took over Twitter, and it’ll try to compete directly with the service.

According to Chris Cox, who is Meta’s Chief Product Officer (CPO), this app will utilize the ActivityPub social networking protocol. In other words, it’ll allow users to migrate their Instagram accounts and followers to the new platform.

If you decide to use this app, your Instagram account info will be there for you

Mr. Cox also flat out said that this app will be “our [Meta’s] response to Twitter”. If you switch, your Instagram account info will be there, waiting for you.

Based on reports, Meta is currently in talks with a number of celebrities to start using the platform. Those people include Oprah Winfrey, Dalai Lama, DJ Lime, and so on.

Meta started developing this app back in January, and it’s expected to launch it in the near future. Meta, of course, wants to do it as soon as possible, but it also wants to offer a compelling product.

Twitter has been criticized left and right since Elon Musk took over, for its actions. It has also been praised in some ways, but one thing is for sure, it has been at the center of attention. It will be interesting to see if Meta can actually launch a compelling Twitter alternative and lure users.


[ad_2]
Source link

Apple Vision Pro Zeiss lens inserts might be $300

0
[ad_1]

When Apple announced the Vision Pro headset during WWDC23, it also announced a pair of Zeiss vision correction inserts that could slot into each eye of the headset over the displays.

These magnetically attach to the inside of the headset and can easily be taken out when not needed. Say for example, when someone else who doesn’t need vision correction wants to use the headset. As the lenses are made by Zeiss and they’re for an Apple product, they probably won’t be anywhere near inexpensive. Apple didn’t officially announce pricing but that doesn’t mean there isn’t a potential range.

A tweet from Bloomberg’s Mark Gurman suggests that Apple could charge anywhere from $300 to $600 per pair for the Zeiss vision correction inserts. Turning an already expensive product into a setup that could end up costing more than some high-end gaming PCs. And that’s before you factor in the price of any other potential accessories, as well as taxes and fees.

Apple Vision Pro Zeiss inserts will be necessary for some users

Chances are if you’re willing to spend $3,499 on an AR/VR headset, you’re probably willing to spend the extra $300-$600 you might need for these Zeiss inserts. But that won’t necessarily apply to every user. Surely there will be some that either can’t or would prefer not to spend that extra money.

But for people where vision correction lenses would be necessary, the only option would be to not buy the headset. At least if they couldn’t spend the extra money on the lens inserts. More to the point, if these prices are accurate it really puts into perspective how much this setup will cost.

At minimum you’re looking at $3,799. And at most you’re looking $3,999. Assuming you aren’t counting the tax or any extra money for additional add-ons. All that being said, eventually, these prices are likely to go down. Even if it might be a while.


[ad_2]
Source link

Key role targeted cyber attacks are on the rise

0
[ad_1]

Research by Ponemon Institute and cyber security company BlackCloak has found that hackers have been directly targeting C-suite executives and their family members with cyber attacks via their personal email addresses. 

In Understanding the serious risks to executives’ personal cybersecurity and digital lives, which was released on June 5, researchers found that 42 percent of organizations said that an executive or an executive’s family member had been the direct target of a cyber attack. This targeted threat vector is also referred to as key employee/role targeting

Cyber Security Hub research has found that more than one in four (26 percent) cyber security professionals believe that key employee/role targeting will have the biggest impact on cyber security in 2023.

The Ponemon Institute and BlackCloak institution found that executives and their families are targeted with a number of threat vectors including social engineering-, malware and network infiltration-based attacks.

Chris Pierson, founder and CEO of BlackCloak, explained to cyber security news site Cybersecurity Dive that “cybercriminals have realized that most executives are almost completely unprotected outside of their corporate accounts and devices”, meaning that they are particularly vulnerable to these attacks. 

The research also found that this issue represents a significant part of cyber security employee’s roles. On a scale from one to ten, where ten represents something intensely time-consuming, 35 percent of respondents rated the amount of time they spent on key role targeting as a nine or ten. 

Read more about social engineering attacks in Cyber Security Hub’s guide to this manipulate threat vector. 


[ad_2]
Source link

Xiaomi 13 Ultra global launch date is now officially official

0
[ad_1]

The Xiaomi 13 Ultra launched in China back in April. Back then, Xiaomi confirmed that the phone is coming to more markets, but it did not say when. Xiaomi France (possibly) slipped up recently, announcing that the Xiaomi 13 Ultra global launch date is set for June 12, and the company’s CEO just confirmed the news.

The Xiaomi 13 Ultra global launch date is now officially confirmed by CEO

Lei Jun went to Twitter to say that the Xiaomi 13 Ultra’s global sale will kick off on June 12. He did say, however, that this is a Western Europe launch, but that more markets will join soon after that.

So, the floodgates open on June 12, it would seem. It’s worth noting that the phone launched in Hong Kong recently, two days ago. It is coming to plenty more markets, that’s for sure.

The Xiaomi 13 and 13 Pro launched globally earlier this year. The Xiaomi 13 Ultra is the most powerful smartphone the company ever announced. It comes with an even more powerful camera setup than the Xiaomi 13 Pro.

We reviewed the device not long ago, the Chinese variant. The global model will include the same specs and design, but different software. A global version of MIUI will come pre-installed on it.

The phone includes plenty of RAM, fast wired & wireless charging, four 50MP cameras & more

As a reminder, the Xiaomi 13 Ultra is fueled by the Snapdragon 8 Gen 2 processor. The phone packs in up to 16GB of LPDDR5X RAM in China, and up to 1TB of UFS 4.0 flash storage. We’re not sure what the global model will offer in this regard.

A 5,000mAh battery is also included in the package, and the same goes for 90W wired charging. 50W wireless charging is also supported, while the device does include a charger in the box.

Four 50-megapixel cameras sit on the back, with Leica lenses. The main one utilizes a 1-inch camera sensor from Sony, and a 2-stop variable aperture. The camera hardware overall is immensely powerful.

A 6.7-inch QHD+ display with a 120Hz refresh rate is also a part of the package. The same goes for stereo speakers, and much more.


[ad_2]
Source link

Microsoft used AI to refrain people from downloading Chrome

0
[ad_1]

It comes as no surprise that ever since the success of ChatGPT and its subsequent integration into the Edge browser as the Bing AI chatbot, Microsoft has gone from being the underdog in the search engine market to now seeing themselves fighting for market share with Google. However, the company has always been aggressive in discouraging people from downloading Chrome, and its recent actions have raised some eyebrows as Microsoft shamelessly tampered with its Bing AI chatbot, effectively ignoring searches for Google Chrome and promoting Bing features instead.

As reported by The Verge, Microsoft presented users searching for Chrome or related terms with a Bing AI “widget” that did not provide the expected search results but instead displayed a list of Bing features. This essentially served as a full-scale advertisement for the service, disrupting the user’s search experience and favoring Microsoft’s products over unbiased search results.

Furthermore, to make matters worse, the result that Microsoft displayed to people searching for Chrome-related terms wasn’t even a Bing AI-generated message. It was a calculated move by the company, as the message remained the same for all searches, and the AI is designed to never generate the same message twice.

However, this is not the first time Microsoft has engaged in such practices. Earlier this year, the Edge browser showed an ad for Bing next to the Google Bard URL in the search bar, and although the ad disappeared after a while, it left a Bing icon in place that opened the Bing AI chatbot in split view.

Microsoft’s response

In response to the controversy, Microsoft released a statement acknowledging their experimentation with new features and behaviors to enhance customer experiences. While Microsoft’s efforts in the AI field are commendable, and it is common for companies to conduct tests to improve their products, the situation is quite severe as by disregarding searches for a leading competitor’s product and substituting them with self-promotion, Microsoft not only undermines fair competition but also erodes user trust.

“We often experiment with new features, UX, and behaviors to test, learn, and improve experiences for our customers. These tests are often brief and do not necessarily represent what is ultimately or broadly provided to customers,” said Microsoft.


[ad_2]
Source link

A new icon arrives for the Google Play Books app

0
[ad_1]
According to 9to5Google, a new icon for the Google Play Books app is rolling out now starting with version 2023.5.30.0.1 of the Android app. The previous version of the icon had a book with a light blue cover sticking out from the triangular background. That book has been removed in the new icon. With that book gone, the purple color of the triangle can now be seen. The bookmark that hangs from inside the book still appears as though it is hanging out of the triangle. And the three corners of the triangle are now more rounded.
You can find the revised icon on the app’s listing in the Google Play Store. And the icon wasn’t the only change that Google made to the Play Books app. On tablets, the bottom bar is replaced with a “navigation rail” on the left side of the screen. The rail includes icons for Home, Library, Wishlist, and Shop. No other changes were made to the tablet version of the Google Play Books app.
If you don’t have the Google Play Books app on your mobile device, you can install it from the Play Store by tapping on this link. If you’re using iOS, the Play Books app can be installed from the App Store via this link.

As we mentioned in the first paragraph, the new Google Play Books icon can be seen starting with version 2023.5.30.0.1. You can check out which version of the app you have on Android by going to Settings > Apps > See all xxx apps and scroll until you see Google Play Books. Tap on the listing and scroll down to the bottom of the page where the version number is listed. Currently, my Pixel 6 Pro is running 2023.5.15.0.0 which means the new icon has yet to hit my phone.

From the Google Play Books app, you can preview ebooks and read the ones that you purchase. Google also includes a cool Android widget for the app that shows as many as the last six titles you’ve sampled or purchased. To add the widget, you must have the Play Books app installed on your Android device. If you do, find an empty piece of home screen real estate and long-press on it. You’ll see a pop-up with three options. Tap on Widgets. Scroll down to Google Play Store, long-press on the 3×2 widget, and slide it to the opening on the page you are taken to.


[ad_2]
Source link