The #1 cyberthreat to schools, colleges, and universities

0
[ad_1]

In the last 12 months, the Vice Society ransomware gang has conducted more known attacks against education targets globally, and in the USA and the UK individually, than any other ransomware group.

This article is based on research by Marcelo Rivero, Malwarebytes’ ransomware specialist, who monitors information published by ransomware gangs on their Dark Web sites. In this report, “known attacks” are those where the victim didn’t pay a ransom. This provides the best overall picture of ransomware activity, but the true number of attacks is far higher.

According to a recent Malwarebytes Threat Brief, in the last 12 months, the Vice Society ransomware gang has conducted more known attacks against education targets globally, and in the USA and the UK individually, than any other ransomware group.

Known ransomware attacks against education by gang, May 2022-April 2023
Known ransomware attacks against education by gang, May 2022-April 2023

Although attacks on education have been a staple of the ransomware ecosystem for years, Vice Society appears to have specialised in delivering misery to schools, colleges, and universities in a highly unusual way.

Education accounts for a huge proportion of known Vice Society attacks. Between April 2022 and March 2023, 39% of the gang’s attacks hit education, compared to an average of just 4% across all the other ransomware groups tracked by Malwarebytes.

Vice Society’s targeting of education is undoubtedly deliberate and has likely allowed the gang to develop domain-specific techniques and expertise.

The result is that Vice Society is the most prolific attacker of education institutions in the two most attacked countries in the world: the USA and the UK. In the USA, Vice Society is the most active among a group of gangs. In the UK, Vice Society accounts for a staggering proportion of known ransomware attacks on education—almost 70%.

The stakes for education could not be higher. In a modern ransomware attack the target is an entire organisation, not just one or two computers. The attackers’ aim is to put the organisation in an unbearable position by stopping it from functioning, and then demanding a ransom that can stretch to millions of dollars.

It is a challenge for any organisation to fight off a determined ransomware gang like Vice Society, but schools face the added pressure of doing so in a notoriously tight budgetary environment.

According to the Education Data Initiative, “Public education spending in the United States falls short of global benchmarks and lags behind economic growth.” In the UK, education has suffered a significant drop in funding in the last decade, according to the non-partisan Education Policy Institute. School budgets are tight and institutions are understandably keen to direct their budgets at things that directly benefit pupils.

Schools, colleges, and universities must somehow reconcile tight budgets with the need to deploy a sophisticated enough detection and response capability to find and evict stealthy adversaries like Vice Society.

To learn more about Vice Society attacks on education and how to protect against them, download the Malwarebytes Threat Intelligence Threat Brief: Vice Society.


[ad_2]
Source link

Apple introduces its first ever 15-inch MacBook Air

0
[ad_1]

Apple just announced the world’s thinnest 15-inch laptop. With the 15-inch MacBook Air coming in at just 15mm thick. That’s almost as thick as some smartphones. This MacBook Air does have the same display as the 13-inch model, but now larger. That includes the notch that everyone loves and hates.

It’s powered by the M2 chipset. So that does confirm that the M3 is not coming anytime soon, as that would come first in an Air. This does allow the MacBook Air 15 to get astonishing battery life – around 18 hours of battery life.

A lot like the 13-inch model, this does not have a fan inside. Which, if you’ve used any other M1 or M2-powered Mac, that should come as no surprise. As those chipsets are so powerful, that the fan really never comes on. Screenshot 2023 06 05 at 1 08 55 PM

This MacBook Air will start at $1299

The MacBook Air goes up for pre-order today and will be available next week. Surprisingly, the 15-inch model will come starting at $1,299. That is a pretty incredible price, and much cheaper than most of us expected. On top of that, the 13-inch model is getting a price drop to $1,099. So a $200 difference between the two sizes.

Additionally, the MacBook Air will come with up to 24GB of unified memory, up to 2TB of storage, and a 15.3-inch liquid retina display. Which, Apple says has twice the resolution and is 25% brighter than competing PCs. Though, Apple didn’t mention what PCs it was comparing it to, as usual.

It comes in four fun colors, as the MacBook Air normally does come in. And this is a pretty impressive laptop from Apple, at an even more impressive price.

That’s not all for Mac announcements today, as Apple is also announcing the M2 Ultra to the Mac Studio. But more on that a bit later.


[ad_2]
Source link

Apple tvOS 17 released with a few tweaks and notable redesigns

0
[ad_1]

At the WWDC23 event that took place this morning, the Apple tvOS 17 took the spotlight for some time. This version of the Apple TV software comes with a redesign which makes it look a bit fresher. Asides from this redesign, Apple fans around the world will also be able to use FaceTime from their TV screen.

If you are an Apple fan, you might already be jumping for joy after hearing of this update. Your joy might be a result of the thought that you no longer need your phone during FaceTime calls. Well, if so, you might need to think again, as you’d still need your phone to make or join FaceTime calls from your Apple TV.

Yet another amazing feature that you can expect with the new Apple tvOS 17 version is the ability to find your remote with your phone. This is yet another incredible feature and will bring a few Apple TV users a bit of rest while streaming their favorite movies and TV shows. Here is all the information users will need concerning this feature and how it will reimagine how they’ll interact with it on the Apple TV box.

Reimagine how you use your TV with the new Apple tvOS 17 update

One very important aspect of the Apple tvOS 17 software is that it looks different from its predecessor. It features a redesign that makes things look a bit more refined and makes the update worthwhile. There is a new Control Center and it now makes accessing most details (settings and information) quicker and easier.

Moving on, another feature that most Apple TV users look forward to with this update is the FaceTime app. Yes, users can now join or make calls with family and friends via their TV since the FaceTime app will be available with this update. But to enable videos, the users will have to rely on their smartphones with Continuity Camera support.

This connects the user’s phone camera to the TV wireless, letting the phone record a video while the user is on a call. The video will be visible to other members of the call and the user as well. What a game-changing update this is not only for Apple tvOS but also FaceTime lovers.

With Apple tvOS 17, users will no longer have to worry about the location of their remote. By using the Find My Device feature on their iPhone, they’d be able to track the remote location. Users can also look forward to the screen saver enhancement feature to help them customize their TV with a picture(s).

Other features to arrive with the Apple tvOS 17 update include Dolby Vision 8.1 support, Apple Fitness+ enhancement and a host of others. These are just a few features to make it to the Apple TV software with the new update. This update will become available to users globally towards the end of the year.


[ad_2]
Source link

iOS 17 will come to iPhones released in 2018!

0
[ad_1]

Today, Apple announced iOS 17, which is the latest version of iOS and it’ll launch this fall. With the betas beginning today. One of the big questions was whether iOS would drop support for some older iPhones. And it indeed has. It no longer supports the iPhone 8, 8 Plus and X.

According to Apple’s website, the iPhone Xs, and Xr and later will be supported. That means iPhones released in 2018 and later. Which is really good to see. That means five year old phones are still getting the latest version of iOS. Something that Android can’t and probably will never do.

Screenshot 2023 06 05 at 3 33 29 PM

This is why people don’t upgrade every year

The biggest reason why many don’t upgrade their phone every year, is due to Apple’s long software support. The fact that you could buy an iPhone Xs Max back in 2018, and still get iOS 17 on it in 2023, is pretty incredible. And it might even get iOS 18 next year.

Compared to the Android side of things, where we are excited that companies are promising three Android upgrades. And that’s after it’s already behind, launching on Android 12 after Android 13 comes out, etc. Android OEMs have a long way to go to compete with Apple.

Now keep in mind, Apple controls every part of iOS. From the software down to the hardware, so it is able to keep updating its phones for a whole lot longer versus say Samsung or Motorola. Who only make the hardware, and have to use components from partners like Qualcomm and MediaTek.

For those that have the iPhone 8, iPhone 8 Plus or the iPhone X, you might want to look at getting a new phone. Now if it’s still in good working order, you can keep it. As Apple will continue to push out security updates to it, for a few more years. But if it’s on its last leg, now is a good time to upgrade.


[ad_2]
Source link

Samsung, Intel earn a 17X return on their ASML investment

0
[ad_1]

Semiconductor firms Samsung and Intel are reaping the fruits of their investment in Dutch chip equipment supplier ASML. Their investment values have reportedly grown 17-fold over the past few months, buoyed by a sooner-than-expected chip industry recovery. TSMC also brought ASML shares alongside Samsung and Intel back in 2012, but the Taiwanese firm sold off its entire stake in the company in 2015.

Samsung and Intel held onto their ASML investment

ASML (originally standing for Advanced Semiconductor Materials Lithography) is one of the biggest names in the semiconductor industry. It doesn’t make chips but supplies the equipment required for manufacturing chips. Based in Veldhoven, Netherlands, the company is one of the best and biggest in the business. In fact, it is the world’s only supplier of extreme ultraviolet lithography (EUV) machines used to manufacture the most advanced chips.

However, ASML hasn’t always been at the top of its game. Just over a decade back, it required investment from its customers to keep its business operations and R&D projects going. Samsung, Intel, and TSMC offered help. They bought a three percent, fifteen percent, and five percent stake in ASML, respectively, between August and September 2012. This equity sale provided the Dutch company with enough funds to run its business.

In January 2015, TSMC announced that it is selling all of its ASML shares. Samsung followed by selling a 1.4 percent stake in the company in September 2016, keeping the remaining 1.6 percent stake. Intel also cut its stake in ASML to 4.9 percent in late 2017, followed by another cut in 2018 to reduce its stake to under three percent. There haven’t been any reports of further share cuts from Samsung and Intel.

It proved to be a great move from the two semiconductor companies. ASML’s monopoly over EUV machines means it’s now one of the hottest prospects of the industry as we move towards sub-3nm chips. Despite an economic slowdown, ASML’s share prices on the New York-based stock exchange have risen 15.9% to $724.65 over the past three months (via). The company’s shares hit a one-year high of $735.93 on May 26.

With stocks flying high, ASML investors are reaping great profits. Early investors like Samsung and Intel are getting a 17-fold return on their investment at current prices. Samsung’s investment value in the Dutch firm has risen to $4.56 billion. Of course, these are unrealized gains unless the companies sell off their stock, which they are unlikely to. But it shows the value ASML has in the semiconductor market today.


[ad_2]
Source link

After rollout across personal accounts, Google enables Passkeys for Workspace accounts

0
[ad_1]
Touted as “The beginning of the end of the password,” Passkeys allow users to authenticate themselves across multiple devices seamlessly. Instead of relying on traditional methods like passwords or PINs, Passkeys utilize cryptographic keys stored on a user’s device to verify their identity. This approach eliminates the need to remember complex passwords and provides a more secure authentication mechanism.
As it stands, Passkeys for personal accounts are available as a sign-in option that has to be first enabled, and do not currently replace existing sign-in options. For Workspace accounts, though, the process has to go through an administrator first, who can then decide whether to enable the feature for the organization. The setting is off by default, but once enabled users will be able to create and use passkeys as a 2-step verification (2SV) method.
https://storage.googleapis.com/gweb-cloudblog-publish/original_images/passkey-creation_no-bg_workspace_cymbal_2x.gif

Signing in to a personal or work Google Account with a passkey – (Source: Google)

The use of Passkeys is not a new thing. In fact, last year Google, Apple, Microsoft and the FIDO Alliance announced that they would begin the work to bring passkeys support to all platforms. Now that it is here, it’s good to see that companies and their employees will get a chance to leverage the convenience of using passkeys as a more secure alternative to passwords.

The feature’s roll out will begin today, but will take a few weeks before it reaches all Google Workspace Administrators. Once implemented, Passkey support should be available to all Workspace users across various platforms, including Android, iOS, and desktop devices. This ensures that users can benefit from the convenience and security of Passkey authentication regardless of their preferred device or operating system.


[ad_2]
Source link

SAP Security: Creating a Comprehensive Security Framework – GBHackers – Latest Cyber Security News

0
[ad_1]

SAP (Systems, Applications, and Products) is a leading enterprise resource planning (ERP) software suite that helps businesses manage critical operations such as finance, logistics, and supply chain management.

With the increasing reliance on SAP systems for mission-critical business operations, it’s more important than ever for businesses to ensure the security of their SAP security systems. This article will discuss critical steps for creating a comprehensive security framework for SAP.

Understanding the risks

We must have a solid understanding of the dangers linked with SAP systems before we dig into the relevant procedures. Due to the sensitive and secret information housed in SAP systems, these systems are a primary target for hackers. Hackers can take data, change financial records, and disrupt corporate operations by exploiting weaknesses in SAP systems. As a result, it is essential to have a solid security structure in place to safeguard SAP security systems from these dangers.

Key steps for creating a comprehensive Security Framework

Identify and assess vulnerabilities

Locating and evaluating any security flaws in SAP is the initial stage of developing a complete security framework for SAP. To do this, you will need to conduct an exhaustive risk assessment to determine the components of the SAP system most susceptible to being compromised by malicious software. This evaluation must be carried out consistently to keep one step ahead of ever-evolving security risks.

Implement access controls

Access restrictions are vital to stop unauthorized users from accessing SAP systems. By installing access controls, businesses may guarantee that only authorized individuals can access sensitive data and carry out essential activities. This protects the data from unauthorized access. Multiple-factor authentication, role-based access controls, and access granted with the least power are all examples of access controls.

Apply patches and updates

Because SAP systems are so complex, vulnerabilities can appear for various reasons, including out-of-date software versions or missing patches. Because of this, it is vital to install patches and upgrades to the SAP system consistently. Patches for vulnerabilities, bug fixes, and service packs are all examples of these updates. Regularly applying patches and updates can effectively ward off cyberattacks that exploit previously discovered flaws.

Implement security monitoring

It is necessary to monitor security to identify and respond to security events in real time. Businesses can swiftly identify possible cyberattacks and take action required to reduce the damage they cause by monitoring SAP systems for behavior that is deemed suspicious. Network monitoring, log analysis, and threat intelligence feeds are all examples of what may be included in security monitoring.

Conduct regular security audits

Regular security audits can assist businesses in locating weak points in the security of their SAP systems and in putting in place the necessary controls to address these risks. Penetration testing, vulnerability assessments, and compliance audits are all examples of what might be included in a security audit. Regular inspections should be carried out to keep one step ahead of ever-evolving security risks.

Educate employees

Errors caused by humans are one of the most common reasons for breaches in security. As a result, providing staff with education on the best practices for SAP security is very necessary. This instruction can include training on securing passwords, spotting and reporting unusual behavior, and avoiding falling victim to phishing schemes.

Implement disaster recovery and business continuity plans

Disaster recovery and business continuity plans are essential to guarantee that operations will continue normally during a terrorist attack or natural disaster. These strategies must be examined and evaluated regularly to ensure that they continue to effectively lower risks and reduce downtime.

SAP systems are an essential component of the success of modern enterprises, yet, hackers frequently focus their attention on these systems as potential points of vulnerability. Businesses can defend their SAP systems from ever-evolving security risks and ensure the continuation of their operations if a security incident occurs if they put in place a comprehensive security framework and use it. Implementing access controls, applying patches and updates, implementing security monitoring, conducting regular security audits, educating employees, and implementing disaster recovery and business continuity plans into action are the key steps in creating a comprehensive security framework for SAP. Other necessary steps include identifying and assessing vulnerabilities, implementing security monitoring, applying patches and updates, and implementing security monitoring. Businesses can build a solid security architecture that safeguards their SAP systems and guarantees the continuity of their operations if they follow the essential measures outlined below.


[ad_2]
Source link

WatchOS refocuses on widgets in massive WatchOS 10 update

0
[ad_1]

Today Apple announced the WatchOS 10 update, which brings in loads of new changes and features for users.

Apple says the new version of the software is delivering “redesigned apps, a new smart lock” and “additional watch faces” among a bunch of other changes. Not the least of which is widgets. Widgets were first introduced with the original version of WatchOS via the ‘Glances’ features. But since then Apple has placed its focus on building up the app ecosystem for the smartwatch.

WatchOS 10 will refocus on widgets to a certain degree and give them a little more attention and time in the spotlight moving forward. As always the new version of the OS will introduce improvements to health features, customization, and more. So there’s plenty to excite most or all users of the platform.

The WatchOS 10 update introduces a new design language

Apple is sort of going back to the drawing board with this new software update. It’s not reinventing the wheel or anything or bringing in drastically sweeping changes to the user interface design. But it is placing emphasis on the fact that WatchOS 10 is introducing a new design language.

This centers a lot around newly designed apps providing more glanceable information. More information in general, and more of it that you can glance at to find what you need quickly.

Apple says a whole host of apps will now use more of the display so you can quickly glance down at it. Letting you get your information more efficiently. Widgets will now also adapt to user context, so things feel more personalized, and you can adjust visibility of this with the watch dial.

New watch faces and new health oriented features

Apple is introducing a couple new watch faces to the platform with this update. Pallette and Snoopy. Pallette shifts colors as the time changes throughout the day. While Snoopy gives your watch an animated view of the Peanuts comic strip via two iconic characters. Snoopy and Woodstock.

There’s also new health features aimed at cyclists and hikers, as well as new health features in general. Including some that focus on mental health and wellness. For instance, Apple Watches on WatchOS 10 will automatically connect to Bluetooth-enabled cycling accessories.

As for the mental health features, the new Mindfulness app in WatchOS 10 lets users log their current emotions to reflect on their current state of mind. WatchOS 10 will arrive for users as a free update this Fall, although a public beta will be available in July.


[ad_2]
Source link

Your hands will be your Apple Vision Pro controller

0
[ad_1]

Apple just unveiled its wildly expensive, yet still intriguing Vision Pro augmented reality (and virtual reality) headset this morning, but you might notice that the physical controls were missing.

That’s because the Vision Pro doesn’t come with what you would expect for a traditional controller or set of controllers. Now, the headset isn’t supposed to release until early next year, and Apple doesn’t appear to have let anyone have hands-on use time with it. So you won’t be seeing anyone actually interacting with the interface for quite some time. However, Apple CEO Tim Cook does explain how you’ll control the headset and engage with content.

You’ll use “the most natural and intuitive tools” you have at your disposal. Your hands, eyes, and voice.

Apple’s Vision Pro controls will rely on the user’s own hands

Your hands won’t be the only tool for navigation. But it wouldn’t be surprising if this is what feels most natural to the majority of people who may pick one of these up.

You can flick your wrist to scroll through content and tapping your fingers will allow to select something. Say you’re scrolling through Apple TV+ for something to watch. Like the season 3 finale of Ted Lasso for instance. With Vision Pro, you can scroll through Apple TV+ content either by looking at it or by flicking your wrist in a similar way you might scroll through your feeds on your smartphone or tablet.

Then once you find what you want to watch, you make sure it’s highlighted and then tap your fingers together to select it and hit play. Of course not everyone is going to want to interact with the user interface this way. And that’s fine as you’ll be able to use your voice to dictate navigation too.

Apple doesn’t give too much information on the specifics. But it does show off the technique during the event. Now granted, this probably isn’t going to be the way you play those more than 100 Apple Arcade games coming to the headset at launch. But there will doubt be some developers who take advantage of this new input system eventually.


[ad_2]
Source link

Atomic Wallet Hit by $35M Theft in Recent Crypto Breach

0
[ad_1]

Reports from affected users indicate that some lost their crypto assets after a recent software update, while others suffered losses despite not having updated to the latest version.

In a recent incident that has sent shockwaves through the crypto community, Atomic Wallet has fallen victim to a substantial theft of various tokens amounting to nearly $35 million. 

The attack, which began on June 2nd 2023, affected less than 1% of Atomic Wallet’s monthly active users, according to the company’s Twitter statement on Monday. The firm, currently conducting investigations, has requested victims to submit relevant information via a Google Docs form to aid in the inquiry.

Reports from affected users indicate that some lost their crypto assets after a recent software update, while others suffered losses despite not having updated to the latest version.

The stolen tokens include popular cryptocurrencies such as Bitcoin (BTC), ether (ETH), tether (USDT), dogecoin (DOGE), Litecoin (LTC), BNB coin (BNB), and polygon (MATIC). 

ZachXBT, an independent investigator known for tracking stolen crypto funds, revealed that the largest victim had lost a staggering $7.95 million in Tether (USDT). Based on their findings, ZachXBT expressed concern that the total amount stolen could potentially surpass $50 million. These revelations have left the Atomic Wallet user base on edge, with many fearing for the security of their own assets. 

Atomic Wallet, a noncustodial-decentralized wallet, emphasizes in its Terms of Service that users bear sole responsibility for the assets stored in the application. The terms explicitly state that Atomic Wallet will not be liable for damages exceeding $50, a clause that may complicate matters for affected users seeking restitution.

The investigation into the security breach remains ongoing, with Atomic Wallet collaborating with leading security companies to identify possible attack vectors. The support team has reached out to major exchanges and blockchain analytics firms in an attempt to trace and block the stolen funds. However, the company has been criticized for the limited information shared with users, leaving many in a state of uncertainty and frustration.

On the other hand, it appears that ZachXBT decided to take matters into their own hands to aid the breach victims. On Twitter he wrote:

“A huge shoutout goes to @buffalu__  @brian_smith_0 for helping us successfully rescue $1m from the Atomic Wallet hacker for one of the victims.”

While their efforts are commendable, the responsibility for timely recovery of the funds ultimately falls on Atomic Wallet. 

It should be noted that last week Jimbos Protocol experienced a loss of $7.5 million after hackers exploited a vulnerability resulting from the lack of slippage control on liquidity conversions. Attacks such as these highlight the vulnerabilities which continue to persist in the crypto ecosystem. 

  1. 6 of the Best Crypto Bug Bounty Programs
  2. Crypto ATM Manufacturer Suffers $1.5m Bitcoin Theft
  3. Crypto Discord Communities Hit by Malicious Bookmarks
  4. Crypto exchange Fiatusdt leaked trove of users KYC data
  5. Google Ads Malware Wipes NFT Influencer’s Crypto Wallet

[ad_2]
Source link