Charon Android Botnet Made a Comeback With New Weapons

0
[ad_1]

The notorious Charon Android Botnet has resurfaced with enhanced capabilities, according to a threat actor’s announcement on a popular cybercrime forum.

The botnet, an edited version of the infamous Ermac, has undergone significant improvements, making it a formidable threat in the cybersecurity landscape.

A recent tweet from ThreatMon shared that the announcement of Charon Android Botnet was detected.

Enhanced Capabilities and Fixes

The Charon Android Botnet has been revamped with many new features and fixes.

Analyze any MaliciousURL, Files & Emails & Configuration With ANY RUN : Start your Analysis

The APK source code has been rewritten from scratch, addressing the chronic issues that plagued its predecessor, Ermac.

One of the significant improvements includes resolving the bot death issue, which previously caused the botnet to lose control over infected devices.

Additionally, new injects have been added, and existing ones have been updated to enhance the botnet’s functionality.

The communication speed between the bots has also been significantly increased, making the botnet more efficient and more challenging to detect.

New Theme and User Interface

In addition to the technical upgrades, the Charon Android Botnet now boasts a new theme and user interface.

This aesthetic overhaul is not just for show; it also improves the usability of cybercriminals who operate the botnet.

The new theme is designed to be more intuitive, allowing operators to deploy and manage malicious activities more efficiently.

This user-friendly interface will likely attract more threat actors to adopt Charon for their nefarious purposes.

Implications for Cybersecurity

The resurgence of the Charon Android Botnet with these new enhancements poses a significant cybersecurity threat.

The faster communication and improved injects mean the botnet can spread rapidly and execute more sophisticated attacks.

Cybersecurity experts urge organizations and individuals to be vigilant and update their security measures to protect against this evolving threat.

The announcement on the forum and the subsequent updates highlight the continuous arms race between cybercriminals and cybersecurity professionals.

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo


[ad_2]
Source link

Galaxy Z Flip 5 gets June patch amid a wave of second May update

0
[ad_1]

Samsung‘s Galaxy Z Flip 5 has started getting the June security patch. The 2023 clamshell foldable is picking up the update in select Central American countries. A global rollout may follow soon, covering the US and other markets. This comes amid a wave of a second May update for several Galaxy devices.

Galaxy Z Flip 5 grabs Samsung’s June security update

The June SMR (Security Maintenance Release) is currently available for the Galaxy Z Flip 5 in Guatemala and Panama. The update comes with the firmware build number F731BXXS2CXEA. It appears to be a simple security release with no additional changes. The build number doesn’t hint at any new features or functional improvements. The next major feature update should be One UI 6.1.1, which may arrive in late July or early August.

Samsung usually releases new security patches to its Fold and Flip foldables from the same year around the same time, so the Galaxy Z Fold 5 should join the party soon. The company has already pushed this update to the Galaxy S24 series, Galaxy S23 series, and a few other devices in some markets. The latest SMR contains fixes for 37 Android OS vulnerabilities and 22 Galaxy vulnerabilities, including at least one critical security flaw.

If you are using a Galaxy device, you can check for updates manually from the Settings app. Well, every smartphone maker offers this ability, though the steps may vary. On a Galaxy, open the Settings app and go to the Software update menu. Now tap Download and install to check if you have an OTA (over the air) update pending download. If not, check again later. You may also get a notification when a new update is available for your phone.

A second May update is rolling out in Europe

As Galaxy Z Flip 5 users in Central America download the June security patch, European users are getting a new update with an old patch. Samsung is rolling out a second May update in the region. It seemingly addresses some camera and battery issues that cropped up following the One UI 6.1 update. This bug-fixing firmware release is also available for the Galaxy S24, Galaxy S23, Galaxy Z Fold 5, and a few other models.

Samsung may soon follow up with the June update for these devices in Europe. The company is also preparing One UI 6.1.1 for several Galaxy devices, including foldables. Based on Android 14, the new One UI version will debut with the Galaxy Z Fold 6 and Galaxy Z Flip 6 next month before expanding to compatible older models. Rumors say it will bring new AI features and various other improvements to the Galaxy family, so stay tuned.


[ad_2]
Source link

Samsung hires ex-Apple Siri AI chief to lead new AI research center

0
[ad_1]

After mocking Apple’s AI features, Samsung has hired an Apple Siri veteran to lead its AI development. The Korean firm has reportedly roped in Murat Akbacak, the former head of Siri’s contextual and conversational AI. Akbacak will lead Samsung’s newly formed AI research center. The North America AI Center is a centralized group combining its existing AI teams in Toronto and Mountain View, California.

Samsung hires Apple Siri head to lead its AI development

Apple announced a plethora of AI features at WWDC 2024, and Samsung rushed to mock it for arriving lack to the AI party. However, deep down, the Korean tech biggie knows that the AI battle is getting real and it must amp up its Galaxy AI game to stay on top. With Apple Intelligence, Siri has become more personalized. It can understand the context of requests and assist iPhone users in various everyday tasks.

Samsung‘s Bixby, on the other hand, is hardly relevant today. The digital assistant doesn’t benefit much from Galaxy AI. It is unclear if Bixby still has a future in the AI era, though the latest development suggests the company has plans to rejuvenate it. Citing an internal memo Bloomberg reports that Samsung has combined two of its AI research teams in North America “to improve operations and increase efficiency.”

The memo didn’t specify if the teams would be housed in a single location or if they would continue working from the existing sites in Toronto and Mountain View. However, it revealed that Murat Akbacak will be leading the combined unit. At Apple, Akbacak was “responsible for defining and executing the strategy for Siri… focusing on personalization, contextualization, and advancements in conversational and multimodal AI,” according to the memo.

Before joining Apple in 2015, Akbacak was a senior scientist and AI researcher at Microsoft. He worked on the Windows maker’s voice assistant services for over two years. Samsung would be hoping to benefit from his vast experience in the field of digital assistant and AI. We’ll have to wait and see whether Akbacak can revive Bixby. Perhaps time will tell if Samsung hired him to work on Bixby or Galaxy AI in general.

Samsung will unveil new AI features next month

Samsung launched Galaxy AI with the Galaxy S24 series in January and gradually expanded it to older models. The company is now gearing up to add more features to the suite, including an AI tool that can create images from rough sketches and text prompts. The new features will debut with the Galaxy Z Fold 6 and Galaxy Z Flip 6 next month. The foldable duo may go official on July 10 alongside the Galaxy Ring, new watches, and earbuds.


[ad_2]
Source link

Facebook, Meta, Apple, Amazon Most Impersonated in Phishing Scams

0
[ad_1]

Phishing scams are a constant threat, but have you ever wondered which brands scammers impersonate the most? New research by Mailsuite sheds light on this phenomenon, revealing the brands and industries most susceptible to imitation.

Mailsuite analyzed over 1.14 million reported phishing scams from January 2020 to March 2024, uncovering the impersonation trends. About 256 major brand names were analyzed for reported and verified phishing scams on PhishTank, excluding unreliable ones and matching each name to its headquarters country.

Here are the findings of their research.

Facebook/Meta is the top spoofed brand, used in around 10,457 verified phishing scams over four years. Apple and Microsoft follow closely behind, used in 9,110 and 4,518 scams, respectively. Amazon and eBay also make the top ten, with 8,919 and 2,080 verified phishing reports whereas Steam is among the top ten brands with 4,833 scams since 2020. 

Japanese telecom firm au by KDDI is the most impersonated international brand, with 18,964 scams since January 2020, while Japanese payment brand JCB is the most impersonated banking/finance brand, with 14,907 instances. Train company JR East also had over 10,000 verified scams to its name. 

British online role-playing game RuneScape is UK’s most impersonated brand whereas it was the second most impersonated brand globally in 2020. Three Polish brands are also part of the list.

The study revealed that over 27.93% of brand impersonation phishing scams involve IT & Technology brands followed by Banking & Financial Services (24.57%). Moreover, tech giants and the IRS have been the most common targets of phishing scams since 2020 and in 2022, Japanese brands experienced a surge in phishing scams, attributed to the Russian invasion of Ukraine and North Korean cyberattack group ‘Lazarus’ particular focus on this region.

Facebook, Meta, Apple, Amazon Most Impersonated in Phishing Scams
Credit: Mailsuite

Phishing emails rely on a single, crucial element: trust. Scammers leverage the reputation of well-known brands to trick victims into clicking malicious links or divulging personal information.

To stay phis-free, be sceptical of all emails, verify the information before clicking, and use unique and complex passwords for all online accounts. Stay informed and practice caution to reduce vulnerability to digital deceptions.

  1. Pop Culture Passwords Most Likely to Get You Hacked
  2. Check Point: Microsoft the Most Phished Brand in Q2 2023
  3. SSH Remains Most Targeted Service in Cado’s Cloud Report
  4. Google, Microsoft and Oracle generated most vulnerabilities
  5. Top 10 Android Educational Apps That Collect Most User Data
  6. Microsoft, PayPal, Facebook most targeted brands in phishing
  7. Signal, AI Gen Art Least, Amazon, Facebook Most Invasive Apps

[ad_2]
Source link

Cleveland City Closes Offices Following Attack on IT Systems

0
[ad_1]

Cleveland City Hall and Erieview offices will remain closed for a second consecutive day, June 11, as officials continue investigating a significant “cyber event” that has disrupted city operations.

A recent tweet from the City of Cleveland shared that the City Hall and Erieview are closed today June 10, except for essential staff, as we investigate a cyber incident.

Mayor’s Briefing on the Incident

During a media briefing, Mayor Justin Bibb provided an update on the situation.

Analyze any MaliciousURL, Files & Emails & Configuration With ANY RUN : Start your Analysis

He announced that city phone services have been restored, and efforts are underway to bring other critical IT systems back online.

“Though we continue to investigate the nature and scope of the incident, we do know that certain city data is currently unaffected,” Mayor Bibb stated.

“Those include taxpayer information held by the Central Collection Agency Division of Taxation and customer information held by public utilities.”

Despite the cyber event, basic city services, including public safety, public works, public utilities, and airport operations, remain functional, albeit with limited computer capabilities.

The incident did not impact emergency services such as police, fire, and EMS.

Investigation and Response

The FOX 8 I-Team reported that the city of Cleveland was actively investigating the incident.

The city’s information technology commissioner Kim Roy Wilson revealed that officials had identified “abnormalities” in its IT environment.

While Mayor Bibb referred to the incident as a “breach” in his opening remarks, Wilson preferred the term “cyber event,” emphasizing the need to withhold specific details to avoid compromising the ongoing investigation.

“You’re seeing this happen all across the country from city governments to large Fortune 500 companies, to large health care companies as well,” Mayor Bibb noted.

“We wanted to make sure that we contain, manage, and get back to business as quickly as possible.”

Office Closures and Public Impact

Cleveland City Hall and the Erieview offices were closed on June 10 and will remain closed on June 11.

As the city works to recover from the cyber event, residents requiring critical documents or services supported by city networks must wait until the issue is resolved and the offices reopen.

City officials are working diligently to restore full functionality to all IT systems and ensure the security of city data.

The incident is a stark reminder of the growing threat of cyber attacks on public institutions and the importance of robust cybersecurity measures.

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo


[ad_2]
Source link

Light Phone 3 is a minimalist marvel with modern upgrades

0
[ad_1]

Light, the maker of minimalist phones of the same name, is here with its newest offering. The company launched the Light Phone III (Light Phone 3) with some improvements over the second-gen model that arrived in 2019. Most notably, it has added cameras and upgraded from an E Ink screen to an OLED panel. The device is currently available for pre-order.

Light Phone 3 arrives with a camera and OLED display

In May 2017, Light launched a credit card-sized minimalist phone that could only make calls. It had a keypad to dial the phone number and that’s about it. No keyboard, T9 texting, or even a contact list—you could save up to ten phone numbers on speed dial. Two years later, the Light Phone 2 arrived with more features while keeping the same core concept. It could save phone numbers, text, play music, give directions, and more.

Now, we have the Light Phone 3 with more features that, according to Light’s co-founder Kaiwei Tang, “most users just can’t live without.” Tang says people found it difficult to adapt to an E Ink display, so the company upgraded to an OLED panel. The new model, which has the same width as a regular smartphone but is substantially shorter, features a 3.92-inch black-and-white OLED display of 1080 x 1240 pixels resolution.

Light Phone 3 1

The phone has a new control wheel on the left side to adjust the screen brightness. The wheel clicks to turn on the flashlight, The Verge noted. The Light Phone 3 features a 50MP rear camera and an 8MP selfie camera. Light has added a dedicated shutter button to the device. Unsurprisingly, the phone lacks editing and sharing features—it doesn’t have access to social media. The cameras are for snapping memorable moments.

The package also contains several other features that might be enough to leave your smartphone at home for good. For one, the Light Phone 3 has an NFC chip for enabling contactless payments in the future. Powered by Qualcomm’s SM 4450 processor, the phone boasts 6GB of RAM and 128GB of storage. There’s also a fingerprint, a user-removable battery, and a USB Type-C port. The phone has aluminum buttons on the side.

Light Phone 3 2

Price & availability

Light’s minimalist phones are ideal for people trying to take a break from social media and the internet, like when going for a holiday or spending a peaceful weekend away from all the hustles. The Light Phone 3 cuts off it all while ensuring you remain in contact with your families so they can reach out in case of an emergency. It supports 5G cellular connectivity. This phone is also a great alternative to feature phones and will appeal to privacy-minded people.

Despite the lack of modern technology, the Light Phone 3 doesn’t come cheap. It has a price tag of $799, a massive jump from the Light Phone 2’s $299. Light believes the functional upgrade and sustainability improvements justify this price for its latest offering. That said, you can pre-order it now for half the price, i.e., $399. It’s an early bird offer from the company. Light will use the money to fund mass production of the phone. Pre-orders can be canceled anytime for a full refund.

Speaking of mass production, it is still months away, so your Light Phone 3 won’t arrive anytime soon. The company expects to begin shipping the device in January 2025. It will deliver pre-orders chronologically, so the shipping date will vary depending on when you place your order. Light says it will reach out to you to confirm your address before shipping the device. The firm also plans to lower the final price if it gets enough pre-orders for the phone.


[ad_2]
Source link

YouTube Music working on a feature that lets you upvote playlists

0
[ad_1]

YouTube Music seems to be working on a nice little addition to its feature set. The app will reportedly be getting an option that allows users to upvote their favorite playlists. Right now, YouTube Music displays the total number of plays on a playlist, but it doesn’t indicate in any way of its reception by other people. The folks over at Android Authority have dug into YouTube Music’s code and have found references of this feature. Of course, this feature is in development and it may or may not make it as an official release.

The discovered code refers to what seems like a setting for allowing for voting on a playlist. The setting appears to have the option for you to allow everyone to vote, or collaborators only, or to disable voting.

YouTube Music’s rival, Spotify, offers a similar feature, displaying a “save” count on playlists (used to be a “like” count until recently). However, YouTube Music’s feature seems to give you more control.

The feature isn’t out yet and we don’t know when it will be publicly available. However, the code appears to be in place, so it might get activated sooner or later. It’s not clear if these upvotes will reflect search rankings for these playlists, but it’s likely that it will influence them.


[ad_2]
Source link

Pure Storage Data Breach Following Snowflake Hack

0
[ad_1]

Pure Storage has confirmed that a third party temporarily gained unauthorized access to a Snowflake data analytics workspace.

This workspace contained telemetry information used by Pure Storage to provide proactive customer support services.

The exposed data includes company names, LDAP usernames, email addresses, and the Purity software release version number.

Incident Details

Following a thorough investigation, Pure Storage revealed that the compromised workspace did not contain sensitive information such as passwords for array access or any data stored on customer systems.

The company emphasized that such information is never communicated outside of the array and is not part of telemetry data.

Consequently, the telemetry information cannot be used to gain unauthorized access to customer systems.

Pure Storage swiftly blocked any further unauthorized access to the compromised workspace.

The company has also reported no evidence of unusual activity on other elements of its infrastructure.

Analyze any MaliciousURL, Files & Emails & Configuration With ANY RUN : Start your Analysis

Pure Storage is actively monitoring its customers’ systems and has not detected any unusual activity targeting their Pure systems.

Customer Communication and Assurance

Pure Storage is in contact with affected customers, who have reported no unusual activity targeting their systems.

The company has engaged a leading cybersecurity firm to conduct a preliminary investigation, which has validated Pure Storage’s conclusions regarding the information in the compromised workspace.

Pure Storage remains committed to providing timely and transparent updates to its customers.

The company will continue to monitor the situation closely and, as necessary, use its communication channels to provide important updates.

While the breach has raised concerns, Pure Storage’s prompt response and ongoing monitoring efforts have helped mitigate potential risks.

The company reassures its customers of its dedication to maintaining the security and integrity of its systems.

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo


[ad_2]
Source link

HTC U24 Pro is official, and it’s not a high-end phone, as expected

0
[ad_1]

The HTC U24 Pro has been announced by the company. Not many people expected it to be a high-end phone, as its processor surfaced not long ago, and that turned out to be true. This is a mid-range smartphone.

The HTC U24 Pro is official with mid-range specs

Having said that, it does seem like a really good mid-range offering, at least on paper. Before we get down to specs, let’s take a look at its design. The phone has a curved display with thin bezels and a centered display camera hole.

Its back side is proportionally curved to the front, while there’s glass on the back. Three cameras sit in the top-left corner of the phone’s back. The thing is, two are separated under one camera island, while the third one sits below them.

The HTC U24 Pro has a matte texture so that it’s less prone to fingerprints. HTC also once again used the so-called ‘double-sided corner design’, which make the phone easier to grip and use.

The Snapdragon 7 Gen 3 processor fuels this handset

The Snapdragon 7 Gen 3 processor fuels this handset. That is Qualcomm’s mid-range 4nm chip, so a rather modern chip. A 6.8-inch fullHD+ (2436 x 1080) OLED display is included here. It supports a 120Hz refresh rate and the Gorilla Glass Victus protection.

HTC included 12GB of LPDDR5 RAM inside of this phone. Users can choose between 256GB and 512GB of UFS 3.1 flash storage here, while the storage is expandable via a microSD card.

Android 14 comes pre-installed, while there are two SIM card slots here. An audio jack is also included, a fingerprint scanner sits under the display. The phone is also IP67 certified for water and dust resistance.

A 4,600mAh battery is included, while 60W charging is supported

A 4,600mAh battery is included here too. The phone supports 60W wired charging, along with 15W wireless charging. Reverse wireless charging is also on offer here, 5W charging. The phone does support 5G, while Bluetooth 5.3 is also on offer.

There is a 50-megapixel main camera (f/1.88 aperture, OIS, EIS) is backed by an 8-megapixel ultrawide unit (f/2.2 aperture). A 50-megapixel telephoto camera (2x optical zoom, f/2.2 aperture) also sits on the back. A 50-megapixel selfie camera (f/2.45 aperture) is also a part of the package.

The HTC U24 Pro could stay exclusive to HTC’s homeland

The HTC U24 Pro measures 167.1 x 74.9 x 8.98mm, while it weighs 198.7 grams. The phone comes in Space Blue and Twilight White color options. It is priced at 18,990 Taiwan dollars, which translates to $586, for the 256GB storage option. The 512GB storage model is a bit more expensive. Chances are this phone will remain exclusive to Taiwan, but we’ll see.


[ad_2]
Source link

Google Meet add-ons are coming to Android devices

0
[ad_1]
After making them available on desktop devices, Google announced that Meet add-ons are finally coming to Android phones and tablets. This means that Android users can now install and use third and first-party apps directly from within the Meet app.

Android users can find Meet add-ons in the Activities panel, along with features like polls and Q&A. Keep in mind that desktop add-ons that aren’t available on mobile will be categorized as “Unavailable.”

Google announced that visibility of all add-ons is controlled by a dedicated setting, which has separate toggles for the visibility of Google add-ons and featured third-party add-ons. Admins can review their configuration by heading to Apps / Google Workspace / Settings for Google Meet / Meet video settings.

It’s also important to mention that the setting handles add-on availability for both the desktop and Android app, which means that how the setting is configured will determine what types of add-ons users will see.

If you’re an end user, you don’t have to do anything. Your admin must configure your experience, which means you may or may not be able to access add-ons in Google Meet with your Android device.

According to Google, this feature is rolling out right now and it will take up to two weeks to reach everyone. However, “Scheduled Release domains” won’t get it until June 24-27. The search giant confirmed add-ons should be available to all Google Workspace customers.

[ad_2]
Source link