Bing just beat Google in the race to have its AI chatbot as your smartphone home screen widget

0
[ad_1]

Although no timeframe was given on when the Bard Android widget would be available, we knew that this was an important next step considering Google’s recent laser focus on AI, as evident in every single Google I/O presentation this year. It was also rumored that this widget would come first to Pixel phones before it makes its way to other Android devices.

Now, Microsoft is once again beating Google to the punch when it comes to rolling out its contextual AI chatbot on as many platforms as possible. Bing AI will now be part of the Bing app on both Android and iOS with a Bing Chat widget available to be added on the home screen.

This isn’t Microsoft’s first attempt at bringing Bing’s AI chatbot to mobile, though. Earlier last month, Microsoft incorporated Bing Chat into the SwiftKey app for Android, a feature that has been expanded upon starting today by adding an AI compose feature that will help you draft a message based on your preferred tone, format, and length.

To round things off as far as AI is concerned, Microsoft is also making contextual chat improvements in the Edge mobile app, adding the capability to ask it questions about the page in the mobile browser you are currently viewing, including asking it to summarize it. It’s evident that Microsoft is taking its investment in OpenAI very seriously and does not intend to sit on its laurels, specially not following Google’s very recent AI-heavy Google I/O event.


[ad_2]
Source link

Qilin’s RaaS Program Advertised on Dark Web

0
[ad_1]
Qilin’s RaaS Program

In March 2023, Group-IB’s Threat Intelligence team accessed the Qilin ransomware (Agenda ransomware) group and discovered that it is a Ransomware-as-a-Service affiliate program using Rust-based ransomware to target victims.

Qilin ransomware employs personalized attack strategies, including modifying file extensions and terminating targeted processes, to optimize the impact of their attacks on individual victims.

The Rust variant of Qilin ransomware is particularly powerful due to its evasive nature, strong encryption capabilities, and flexibility to customize malware for various operating systems, including:-

Observations from Group-IB Threat Intelligence experts reveal that Qilin ransomware is promoted on the dark web, featuring a proprietary DLS with distinct company IDs and leaked account information.

Qilin Ransomware Operator

Qilin ransomware operators employ a double extortion method, encrypting and exfiltrating sensitive data, demanding payment for decryption, and promising non-disclosure of stolen information while retaining control over different encryption modes.

Qilin ransomware employs phishing emails with malicious links to initiate network infiltration, exfiltrate sensitive data, and subsequently explore the victim’s infrastructure for critical information to encrypt.

The threat actors implant a ransom note within every compromised system directory during the encryption procedure. The ransom note implanted by the threat actors contains the complete guide for purchasing the decryption key for the victims.  

Qilin ransomware may further complicate data recovery by attempting to reboot systems in normal mode, stop server-specific processes, and, if encryption is successful, use a double extortion technique to demand payment and prevent the release of stolen data.

Group-IB researchers found that Qilin ransomware not only targets victims but also posts their data on the group’s DLS, with data from 12 companies across multiple countries identified in May 2023:-

  • Australia
  • Brazil
  • Canada 
  • Colombia
  • France
  • Netherlands
  • Serbia
  • United Kingdom
  • Japan
  • The United States

Qilin’s Admin Panel

Group-IB discovered that Qilin ransomware operates as a Ransomware-as-a-Service (RaaS) and offers its affiliates an administrative panel to manage attacks, with further analysis of the program’s inner workings and admin panel made possible after Group-IB’s infiltration in March 2023.

In total there are six sections under which the affiliates’ panel of the Qilin ransomware group is divided, and here they are mentioned below:-

Section 1: Targets

While this section in Qilin’s administrative panel provides details on targeted companies and ransom amounts and enables affiliates to generate customized samples of Qilin ransomware with different configurations.

Here below, we have mentioned all the details that could be configured:-

  • name of the company
  • ransom amount
  • waiting period for a ransom payment
  • the timezone of the company
  • information about the company’s revenue from the Zoominfo website
  • announcement
  • description of the attacked company
  • content of the ransom note
  • the directories that will be skipped
  • the files that will be skipped
  • the extensions that will be skipped
  • the processes that will be killed
  • the services that will be stopped
  • login credentials of accounts
  • safe mode excluded hosts
  • mode of encrypting
  • extensions that will be encrypted
  • list of virtual machines (VMs) that will not be killed/shut down

Section 2: Blogs

Within this designated section, associates can generate and modify blog posts featuring details regarding targeted organizations that have failed to fulfill the demanded ransom.

Section 3: Stuffers

Qilin’s “Stuffers” section allows attackers to perform the following tasks:-

  • Create accounts for their team members
  • Control their level of access
  • Enable them to witness all attacks
  • Build ransomware samples
  • View victim chats

Section 4: News

As of April 2023, no updates or published posts were found in the News section of Qilin ransomware, where operators typically share information regarding their ransomware partnership.

Section 5: Payments

Qilin ransomware affiliates can withdraw ransom money from the Payments block, which includes details about the balance of their wallets, transactions, and fees to the ransomware group.

Section 6: FAQs

It is also possible for affiliates to access support and documentation in the FAQ section, as it provides detailed information about a variety of things, such as:-

  • The type of infections
  • How to use the malware
  • Additional information about the targets

Recommendations

Here below we have mentioned all the recommendations offered by the cybersecurity analysts:-

  • Increase the level of security by adding more layers.
  • Make sure that you have a “backup” plan in place.
  • Make sure to use a reputable business email protection service.
  • Implement a solution that is capable of detonating advanced malware.
  • Make sure to patch your connected devices with the latest available patch. 
  • It is important to train your employees.
  • Identify and control vulnerabilities in the system.
  • Whenever you receive a ransom note, do not pay it.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link

Here’s how the Google Weather app will look on the Pixel Fold

0
[ad_1]

Google officially unveiled the long-awaited Pixel Fold at Google I/O, and fans seem to like it so far. Now, we’re going to be seeing how Google will format its first party apps for the foldable form factor. Thanks to 9To5Google, we now have a glimpse of the Google Weather app on the Pixel Fold.

If you want to know more about this device, Android Headlines has a lot of coverage on it. You can also check out coverage on the Pixel 7a and the Pixel Tablet. All three of these devices were announced at Google I/O, and they add to the Google Pixel ecosystem.

This is how the Google Weather app will look on the Pixel Fold

Now, this is going to be the first foldable phone with true to-form-stock Android. This is software coming straight from Google, so we expect its first party apps to work flawlessly with the device. Now, we can’t rule out a couple of growing pains while Google is getting used to developing for a foldable.

In the case of the Google Weather app, it looks like Google will effectively utilize the extra real estate. Looking at the picture below, we see that each side of this display shows one part of the app. On the left side, we see the search bar for the location and the 10-day forecast.

Pixel fold weather app

On the right side, we get the more detailed information about the current day. This includes the high and low temperatures for the day, the hourly forecast, and other information like the humidity and the max wind.

As you can imagine, the interface has the classic material you aesthetic. All of the rectangular elements are rounded as are the squares. We see a consistent color scheme with the app, and that might be the color of the system’s color scheme.

You can pre-order your Pixel full today, and the phone is going to start shipping next month. It starts at a hefty $1,799, so you’ll definitely want to either save up or trade in an older device.


[ad_2]
Source link

Kyocera is making a notable shift in the Japanese market

0
[ad_1]

Kyocera might not be one of the top brands in the smartphone market, but it’s been around for a while. The Japanese company has been able to survive several phases in the history of the smartphone, and right now, the company’s looking to make some changes to its business. According to Japanese publication Nikkie (via Android Authority), Kyocera will be shifting its focus in the Japanese Market.

You don’t see many Kyocera phones out in public. In the US market, Kyocera made a shift away from consumer phones and toward Enterprise devices a few years ago. You’re more likely to see an office worker sporting a Kyocera device than your next door neighbor.

The consumer smartphone market in America is very much tied up in Apple, Samsung, and Motorola. At this point, it’d be really tough to make a splash in the US market against the competition.

Kyocera makes a shift in the Japanese Market

This strategy seems to be working for Kyocera, as the company will soon do the same for the Japanese market. At the behest of its parent company Kyocera Corporation, the company will be shifting away from the consumer market in its home country Japan.

The head of the company, Hideo Tanimoto, announced this during a conference call to discuss the fiscal year for Kyocera. We’re not sure about the company’s numbers, but there is word that about half of the company’s business last year came from corporate users.

Kyocera never really held a strong place in the smartphone market, and it hasn’t really been able to stand out. But, taking a more conservative route and distributing phones amongst Enterprise users might be a good call for the business. That’s a sector that is typically overlooked.

Hopefully this change in strategy will mean good fortune for the Japanese company. We’ll have to wait and see.


[ad_2]
Source link

Sonos discontinues important feature for Android devices

0
[ad_1]

Sonos is an increasingly popular brand in the audio streaming market, which makes the company’s latest announcement quite disappointing for those who love its products. Starting next week, Sonos will no longer support streaming of local audio files from Android devices.Android was the last mobile platform to support the feature since iOS devices have been removed from the list of supported devices about three years ago. On the bright side, Sonos offers quite a few audio streaming options, including Bluetooth, AirPlay, and NAS (network-attached storage).

Not to mention that services like Apple Music, YouTube Music, Deezer and Plex allow you to upload and stream music online. Of course, you still have to pay for a premium subscription if the streaming service requires it. Once you’ve uploaded the music to one of these services, the tunes will be accessible via Sonos as soon as the service using the Sonos app is added.

That being said, if you have an Android device, you will no longer be able to play audio files directly to Sonos starting May 23. Instead, you can play the audio files downloaded to your Android devices on the Sonos system using the Sonos app via Bluetooth.

As far as the reasoning behind the change, Sonos said that “as newer versions of mobile operating systems are released, it can sometimes change the way information is shared between devices, and this feature will no longer be compatible with newer version of the Android operating system.”


[ad_2]
Source link

Ducktail Operation – Hackers May Steal Your Credentials

0
[ad_1]
Ducktail Operation

WithSecure Labs, researchers uncovered a cyber operation named Ducktail in July 2022, where threat actors employed information-stealing malware to specifically target marketing and HR professionals with spear-phishing campaigns through LinkedIn direct messages, focusing on individuals and employees with potential access to Facebook business accounts.

The Ducktail campaign can compromise Facebook business accounts and misuse the ad feature for malicious advertising. While along with Facebook, LinkedIn is also now actively targeted by threat actors for cybercriminal activities. 

Trend Micro’s Managed XDR team in March 2023 found a file that collects user data and connects to Facebook and Telegram domains during their investigation of Ducktail-related incidents.

Operation Ducktail

How the Attackers Trick Victim

The sample file’s name, referencing a marketing director job opening, appears specifically tailored to attract marketing professionals by hinting at a higher leadership position.

Although the exact delivery method of these links to the target is uncertain, the historical use of LinkedIn messages by Ducktail suggests it as a potential means.

Experts determined the contents and source of the archive by examining the file name, and upon investigating the domain, they discovered that the malicious file was hosted on Apple’s iCloud service, although the URL is currently inactive.

Upon analyzing the created processes, security researchers identified three, including separate processes for Microsoft Edge and Google Chrome, which collect the victims’ IP addresses and geolocation data.

Here below, we have mentioned the arguments that are used in these processes:-

  • –headless
  • –disable-gpu
  • –disable-logging
  • –dump-dom

The last process is used to open a PDF file, and the complete details about the fake job are embedded inside this PDF. 

The malware operates by extracting browser credentials and acquiring Facebook-related information. At the same time, victims read the spawned PDF file, storing it in a temporary text file before exfiltrating it using Telegram every 10 minutes.

Due to the frequent use of social engineering lures by contemporary threat actors, both individuals and organizations need to exercise caution when opening links or downloading files from unknown sources, regardless of whether they are delivered through renowned social media platforms or means like:-

Security Recommendations

Here below, we have mentioned all the best security practices that could help users mitigate spear-phishing attacks:-

  • Beware of unexpected emails; exercise caution.
  • Always verify the sender’s identity before opening attachments from unknown sources.
  • Avoid suspicious links, especially from unknown or suspicious sources.
  • Educate employees on spear phishing to recognize and avoid it.
  • Enable multi-factor authentication for added security.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link

A week in security (May 8-14)

0
[ad_1]

The most interesting security related news of the week from May 8 till 14.

Last week on Malwarebytes Labs:

Stay safe!


Malwarebytes removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Spotify app is now available in 11 new languages

0
[ad_1]

Spotify is now available in more regional languages. The company announced on Monday that it has added support for 11 new languages to its app. These include Arabic (Egypt), Arabic (Morocco), Arabic (Saudi Arabia), Basque, Bosnian, English (UK), Galician, Macedonian, Spanish (Argentina), Spanish (Mexico), and Traditional Chinese (Hong Kong). The latest additions take the total number of supported languages to 74.

Spotify is one of the most popular music streaming platforms around the world. In fact, it is the largest music streaming service globally by market share. The company offers a vast library of music and is rapidly expanding its podcast collection. But the music library may not be the only factor driving its popularity. Spotify’s wide availability and support for regional languages is something that not many others match currently.

The app was available in 27 languages at launch. In March 2021, the company added support for 36 new languages, including a host of languages spoken in various parts of India. This expansion came around the same time Spotify announced plans to launch the app in more than 80 new markets across Asia, Africa, the Caribbean, Europe, and Latin America. As Spotify arrives in more markets, the company is now also adding support for more regional languages.

“This expansion will unlock an even more personal experience for our users, giving them the ability to access Spotify in their native or local tongue,” the company said in a press release announcing the rollout of new languages. “And the more people who can use Spotify, the more connections we can foster between creators and their audiences”. You can find the full list of Spotify’s supported languages here.

Spotify is testing a new UI on the web

Coinciding with the latest language expansion, Spotify is testing a new UI on the web. It is replacing the plain sidebar with a richer and expandable sidebar that lets you quickly access your playlists, podcasts, and more. The main section also gets a redesign with cards featuring rounded corners (via).

As of this writing, Spotify hasn’t officially announced this redesign of its web client. The new UI also appears limited to select users. The company is probably testing this update among a small group of users and may roll it out to everyone in the coming weeks. Meanwhile, if you want to use the Spotify app in one of the newly-added regional languages, check for an update for the app. You can click the button below to download the latest version of Spotify from the Google Play Store.

DOWNLOAD SPOTIFY


[ad_2]
Source link

Snapdragon 8 Gen 3 to be an “excellent SoC”, details shared

0
[ad_1]

The Snapdragon 8 Gen 3 is expected to arrive later this year, and it will allegedly be an “excellent SoC”. This information comes from Ice Universe, one of the most prominent tipsters out there.

The Snapdragon 8 Gen 3 will be an “excellent SoC”, as details surface

He went to Twitter to say that, and also share some details about the processor itself. The Snapdragon 8 Gen 3 will allegedly use a 1+5+2 setup, so it will be an octa-core CPU. The Adreno 750 GPU will be in charge of graphics processing.

The tipster also says that the performance “has been greatly improved”. In other words, it will be a better performer than its predecessor. Ice Universe also mentioned that you’ll get 10MB of L3 cache here.

To wrap things up, the tipster said the following: “This generation will maintain the overall energy efficiency of 8Gen2”. That is great, as the Snapdragon 8 Gen 2 is a very efficient processor.

The Snapdragon 8+ Gen 1 and Snapdragon 8 Gen 2 turned out to be outstanding. If what Ice Universe says is true, the Snapdragon 8 Gen 3 will be as well. It’s nice to see that Qualcomm found its footing, following the not-so-great Snapdragon 8 Gen 1.

Many smartphone OEMs will utilize the Snapdragon 8 Gen 3 next year

This processor, needless to say, will be utilized by a ton of companies. The Snapdragon 8 Gen 2 is included in the vast majority of proper streamlined flagship smartphones this year. The same will likely be the case with the Snapdragon 8 Gen 3, but next year.

The Snapdragon 8 Gen 3 could actually arrive sooner than expected. The Snapdragon 8 Gen 2 launched on November 16, while the Snapdragon 8 Gen 3 is tipped to arrive in late October. That would be rather early considering what happened in previous years, but there you go.

Qualcomm is also rumored to skip the Snapdragon 8+ Gen 2 entirely. The company usually launches two flagship processors a year, but the Snapdragon 8 Gen 2 is so great that the Snapdragon 8+ Gen 2 is completely unnecessary, it would seem.


[ad_2]
Source link

Now you Can Lock & Hide Chats

0
[ad_1]
WhatsApp Chat Lock

Meta is introducing a new “Chat Lock” feature for WhatsApp to assist customers in securing their conversations.

“We’re excited to bring to you a new feature we’re calling Chat Lock, which lets you protect your most intimate conversations behind one more layer of security,” WhatsApp stated in a blog post.

Over two billion people around the world now use the WhatsApp video calling and instant messaging network, according to Meta.

Increasing the Privacy of Your Most Private Conversation

When someone writes you when a chat is locked, the sender’s name and the message’s content will also be concealed. The new functionality lets you password-protect your most private conversations and keep them in a separate folder.

“Locking a chat takes that thread out of your inbox and puts it behind its own folder that can only be accessed with your device’s password or biometric, like a fingerprint. It also automatically hides the contents of that chat in notifications, too”, the company said.

Features to note:

  • Password-protect your most private conversations.
  • Automatically hides contents in notifications.
  • Store them in separate folders.

By tapping the name of a one-on-one or group conversation and selecting the lock option, you can lock it. Pull down your inbox gently and input your password or biometric to reveal these chats.

“We believe this feature will be great for people who share their phones from time to time with a family member or in moments where someone else is holding your phone at the exact moment an extra-special chat arrives,” the company added.

The Meta-owned firm wants to expand Chat Lock’s capabilities, including locks for companion devices and the ability to create a customized password for your chats, allowing you to use a password distinct from the one you use for your phone.

Although WhatsApp provides end-to-end encryption, it is ineffective when someone has unlocked your phone and can read your messages. In these cases, the new functionality adds an extra degree of security.

The new feature arrived just a few weeks after WhatsApp made a few changes to its platform regarding polls and sharing.

As part of these upgrades, you can now build single-vote polls, which means you can run a poll where users can only vote once. You can directly forward media with captions when sharing.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link