Samsung’s Galaxy Ring faces competition from Circular Ring Slim

0
[ad_1]

Circular, the fitness and health tracking startup making smart rings, has launched a new model. The Ring Slim (2024) is an upgraded version of the same ring that debuted in November 2023. It boasts improved battery life, stronger build quality, and new health features. The wearable will take on Samsung‘s Galaxy Ring.

Circular launches Ring Slim (2024) just before Samsung’s Galaxy Ring

Smart rings are set to take over from smartwatches, offering all the health-tracking benefits in a much smaller package. You get a longer battery life and a free wrist for traditional timepieces and other accessories. Although you need a phone to check your health stats from the ring, let’s face it, most of us are on our phones more than enough anyway.

Oura is currently the biggest name in this industry, which is still in a nascent stage. Circular is another name that comes to mind when we mention smart rings. The firm has been around for several years now and just launched its most advanced offering. The new Ring Slim reportedly addresses all the issues users reported with last year’s original version.

Circular Ring Slim 2024 1

For starters, it features an IP68 rating for dust and water resistance, so you can wear the ring worry-free during workouts, swimming sessions, or your morning run under light rain. It can also withstand a dip in water for some time. Circular has also improved the scratch-resistant coating on its surface. It shouldn’t catch scuffs and scratches as easily as the original Ring Slim.

The upgraded version comes with a bundled compact USB-C charger that can charge the ring directly from your phone. It isn’t like you need to charge the wearable often, though. Despite being the world’s thinnest (2.2mm) and lightest smart ring (2 grams), Circular’s Ring Slim can last up to two days on a single charge. When used in Eco mode, the company claims a runtime of up to six days.

Circular Ring Slim 2024 2

The new Ring Slim features an upgraded sleep algorithm to accurately measure and monitor your heart rate, SpO2 levels, temperature, and breathing rate while sleeping. This gives you a deeper sleep analysis, with Circular claiming a 79% accuracy in recognizing sleep disorders. The firm has also added a new Sport algorithm for heart rate monitoring. It is tailored for sporting activities.

Samsung may launch its first-gen model next month

Circular’s new smart ring comes just weeks before the rumored launch of Samsung’s first-gen Galaxy Ring. Rumors suggest the Korean firm will price its ring at $300 and above. If true, Circular marginally undercuts it. The Slim Ring (2024) costs $281/€259/£226 and doesn’t require any additional subscription. Meaning that you get access to all health features with the ring. It’s unclear if Samsung will keep any Galaxy Ring feature behind a paywall.

Circular Ring Slim 2024 4


[ad_2]
Source link

TikTok facing fresh lawsuit in US over children’s privacy

0
[ad_1]

The Federal Trade Commission (FTC) has announced it’s referred a complaint against TikTok and parent company ByteDance to the Department of Justice.

The investigation originally focused on Musical.ly which was acquired by ByteDance on November 10, 2017, and merged it into TikTok.

The FTC started a compliance review of Musical.ly following a 2019 settlement with the company for violations of the Children’s Online Privacy Protection Act (COPPA). In the settlement, Musical.ly received a fine of $5.7m for collecting personal information from children without parental consent.

One of the main concerns was that Musical.ly did not ask the user’s age and later failed to go back and request age information for people who already had accounts.

COPPA requires sites and services like Musical.ly and TikTok – among other things – to get parental consent before collecting personal information from children under 13.

Musical.ly also failed to deal with complaints properly. The FTC found that—in just a two-week period in September 2016—the company received over 300 complaints from parents asking Musical.ly to delete their child’s account. However, under COPPA it’s not enough just to delete existing accounts, companies have to remove the kids’ videos and profiles from the company’s servers; Musical.ly failed to do this.

In 2022, TikTok itself faced a $28m fine for failing to protect children’s privacy after an investigation of a possible breach of the UK’s data protection laws.

In the US, TikTok agreed to pay $92 million in 2021 to settle dozens of lawsuits alleging that it harvested personal data from users, including information using facial recognition technology, without consent, and shared the data with third parties.

The FTC states that during the investigation it uncovered reasons to believe that “defendants are violating or are about to violate the law and that a proceeding is in the public interest.”

The FTC also said it usually doesn’t publicize the referral of complaints but feels it is in the public interest to do so now.

TikTok has been in the crosshairs of privacy and security professionals and politicians for years.

In June 2022,  the FCC (Federal Communications Commission), called on the CEOs of Apple and Google to remove TikTok from their app stores considering it an unacceptable national security risk because of its Chinese ownership.

In 2023, General Paul Nakasone, Director of the National Security Agency (NSA) referred to TikTok as a loaded gun in the hands of America’s TikTok-addicted youth.

Recently, we reported about the take-over of some high-profile TikTok accounts just by opening a Direct Message.

And the clock is ticking when it comes to TikTok’s presence in the US, after the US Senate has approved a bill that would effectively ban TikTok from the US unless Chinese owner ByteDance gives up its share of the still immensely popular app.

Somehow we don’t think we’ve heard the last of this.

Malwarebytes has a new free tool for you to check how much of your personal data has been exposed online. Submit your email address (it’s best to give the one you most frequently use) to our free Digital Footprint scan and we’ll give you a report and recommendations.


[ad_2]
Source link

Specifications, renders & a live image

0
[ad_1]

UPDATE: Initially, only one Motorola Moto G85 live image was shared, along with specifications and renders, but three more have been added shortly after publishing (from the same source). If you check out the gallery below, you’ll see some additional images provided by TENAA, giving us a great look at the phone itself.

ORIGINAL ARTICLE: A ton of Motorola Moto G85 information has surfaced online, including the phone’s specifications, renders, and even a live image. Let’s kick things off with the live image, as it’s a part of a certification.

The Motorola Moto G85 specifications, renders & live image appear

The phone was certified by TENAA in China. That is basically China’s equivalent to the FCC. That certification did not share a lot of info on its own, but it did share a live image of the phone. You can check it out below.

Motorola Moto G85 TENAA image 1

This image shows the front side of the phone, so it doesn’t show us all that much. We can see that a display camera hole will be centered up top, though. We also know that the display will be curved and that all of its physical buttons will sit on the right-hand side. The corners are slightly rounded.

Now, a tipster, Sudhanshu Ambhore, shared a ton of renders of the phone, in several images. You can check out all of those images in the gallery below. Those images should fill in the gaps in regard to the device’s design.

The device will have thin bezels, albeit not uniform

You can see that the bezels will be quite thin. The back side will be curved towards the sides, and likely proportional to the front side of the phone. Two cameras are located in the top-left corner and a part of the same camera island.

That camera island blends nicely with the phone’s backplate. It does protrude, though. Motorola’s logo sits in its usual place, in the middle of the phone’s backplate. Based on these renders, the Motorola Moto G85 is coming in purple, yellow and dark gray colors.

The tipster did share a ton of specs too. The device will be fueled by the Snapdragon 6s Gen 3 chip. It will include a 6.67-inch fullHD+ (2400 x 1080) OLED display with a 120Hz refresh rate.

Two rear cameras and a 5,000mAh battery will be a part of the package

A 50-megapixel main camera (Sony’s IMX882 sensor, f/1.79 aperture, 1.6um pixel size, OIS, PDAF) will be located on the back. The same goes for an 8-megapixel ultrawide camera (f/2.2 aperture, 118.6-degree FoV, 1.12um pixel size). On the front, you’ll find a 32-megapixel camera (f/2.45 aperture, 0.7um pixel size).

A 5,000mAh battery will power the device, while 30W wired charging will be supported. Motorola plans to offer both 8GB and 12GB RAM variants of the device. Both of those will come with 256GB of storage.

Android 14 will come pre-installed on the device. Stereo speakers will also be a part of the package, as will two microphones. The Moto G85 will measure 161.91 x 73.06 x 7.59mm, while it will weigh 171 grams.


[ad_2]
Source link

EU plans to scan your messages, including encrypted ones

0
[ad_1]

The European Union (EU) is seeking to scan your messages, including encrypted ones, to detect and stop child sex abuse material (CSAM). The proposed chat control legislation will undergo a vote in the EU Council later today. If the controversial new legislation passes this voting round, it will move forward in the Council’s law-making process.

EU wants to scan your encrypted messages for child safety

In this AI-powered digital world, child safety is one of the major concerns for lawmakers and parents alike. While internet platforms have placed various rules and regulations to make children safer online, these systems aren’t foolproof. The EU believes it can develop a more effective measure—scanning private messages to prevent the spread of CSAM.

Introduced in May 2022, this controversial regulation aims to implement an “upload moderation” system. Service providers must install a “vetted” monitoring technology that scans all your digital messages. It will check for potential child sex abuse material in images, videos, and links you share. Users will be asked to allow permission to scan their messages. You cannot share media files and links if you don’t allow permission.

Interestingly, the European lawmakers who drafted this regulation made arguments both in favor of and against end-to-end encryption (E2EE). The proposed law says E2EE “is a necessary means of protecting fundamental rights.” However, it also states that encrypting messages could inadvertently make messaging apps “secure zones where child sexual abuse material can be shared or disseminated.”

The regulation doesn’t ask service providers to lift E2EE in Europe. Instead, it wants a backdoor that allows scanning of the message before it is encrypted. This new moderation system leaves messages open for scanning without compromising the layer of privacy offered by end-to-end encryption. E2EE doesn’t allow anyone apart from the sender and receiver to read the message, not even the messaging platform and governments.

Industry players have opposed this regulation

Before the regulation goes into the voting round later today, several privacy advocates and industry players have expressed concerns over it. Organizations including the Electronic Frontier Foundation, the Center for Democracy & Technology, and Mozilla have signed a joint statement urging the EU to reject the law. Many European Parliament members have also opposed the proposed law.

Encrypted messaging platform Signal plans to exit Europe if this law is passed. “We will leave the EU market rather than undermine our privacy guarantees,” said Signal President Meredith Whittaker. “This proposal—if passed and enforced against us—would require us to make this choice. It’s surveillance wine in safety bottles.” It remains to be seen what the EU Council decides. It won’t be a long wait, so stay tuned.


[ad_2]
Source link

Threat Actor Claims Breach of Jollibee Fast-Food Gaint

0
[ad_1]

A threat actor has claimed responsibility for breaching the systems of Jollibee Foods Corporation, the Philippines’ largest fast-food chain.

Deepwebkonek, a company known for sharing information related to cyber threats and breaches, made the announcement via a post on the social media platform Twitter.

Details of the Breach

The post has since garnered significant attention and alleges that sensitive customer data, including personal information and payment details, has been compromised.

The threat actor claims to have accessed Jollibee’s internal systems and exfiltrated a substantial amount of data.

While the exact volume of the data breach remains unclear, the potential impact on millions of customers is a cause for concern.

Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan

Jollibee Foods Corporation has yet to release an official statement regarding the breach.

However, cybersecurity experts are urging customers to monitor their financial accounts for any unusual activity and to change their passwords as a precautionary measure.

The company is expected to conduct a thorough investigation to determine the extent of the breach and to implement measures to prevent future incidents.

Expert Opinions and Reactions

Cybersecurity analysts have weighed in on the situation, highlighting the growing threat of cyberattacks on major corporations.

“This incident underscores the importance of robust cybersecurity measures,” said Dr. Maria Santos, a cybersecurity expert at the University of the Philippines.

“Companies must invest in advanced security protocols and regular audits to safeguard their systems against increasingly sophisticated threat actors.”

Customers have expressed their concerns on social media, with many calling for greater transparency from Jollibee regarding the breach.

 “We deserve to know how this happened and what steps are being taken to protect our data,” tweeted one user.

As the investigation unfolds, Jollibee Foods Corporation must restore customer trust and ensure the security of its systems.

The breach is a stark reminder of the vulnerabilities that even the largest and most established companies face in the digital age.

Customers are advised to stay vigilant and to follow any guidance provided by Jollibee and cybersecurity professionals.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

HONOR Magic V3 info appeared and it looks promising

0
[ad_1]

The HONOR Magic V2 was a stunning phone. It was, and in some aspects still is, the thinnest and lightest book-style foldable on the market. HONOR is looking to improve things with its successor, though. The HONOR Magic V3 info surfaced, and it looks promising.

The HONOR Magic V3 looks promising based on the newly-surfaced info

The device was certified in China. To be more exact, it got certified by the 3C authority. In addition to that, a tipster shared some additional information about the device.

HONOR Magic V3 3C certification

So, what do we know thus far? The phone is said to be fueled by the Snapdragon 8 Gen 3 SoC, as expected. HONOR will use the most powerful Snapdragon chip available. In addition to that, the phone will support 66W wired charging. So, the same as the HONOR Magic V2. We’re not sure about wireless charging, but its predecessor did not offer it.

It was also revealed that the phone will support satellite connectivity. That could be limited to China only. It almost surely will, actually. The HONOR Magic V3 is, however, expected to reach global markets.

It will offer “thin and light” design

The tipster also said that the phone will offer “thin and light design”, which is a given considering its predecessor. It’s hard to imagine a thinner and lighter book-style foldable than the Magic V2, but HONOR will surely try to make it happen.

The source also said that “upgraded displays” are coming, without providing specific info. The Magic V2 had great displays, so it remains to be seen what he meant. Perhaps he meant display protection or something like that.

The HONOR Magic V2 arrived back in July last year. Towards the end of July, to be accurate. It launched in China first, and it took HONOR quite some time to bring it to global markets. Well, we’re expecting the Magic V3 to arrive around the same time this year.

We do hope that HONOR will bring it to global markets sooner this time around, however.


[ad_2]
Source link

Google reportedly canceling YouTube Premium subscriptions purchased using VPNs for lower pricing

0
[ad_1]

Image credit — PhoneArena

Users who have been enjoying YouTube Premium at a discounted rate through the use of VPNs are now facing cancellations, as Google is reportedly cracking down on this practice. A recent Reddit thread revealed that numerous subscribers, who had been using VPNs to access lower-priced subscriptions in countries like Ukraine, had their memberships abruptly terminated.This move by Google appears to be an effort to enforce regional pricing policies for YouTube Premium. The service offers varying rates for different markets based on local economic conditions and consumer expectations. By utilizing VPNs to mask their location, users were able to bypass these regional restrictions and subscribe at significantly lower prices.

According to this report, while some users have reported success in contacting customer service and reinstating their memberships, others have been informed that their cancellations are due to a change in location. Furthermore, they were advised that they need to re-subscribe using a local payment method and address to access the appropriate pricing for their region.
YouTube Premium cancellation email sent to Redditor Alopez1024 reportedly for using a VPN to subscribe
It’s worth noting that this crackdown is not just limited to Ukraine. Users from various countries who have been utilizing VPNs to access cheaper YouTube Premium subscriptions have also reported cancellations. This suggests a broader effort by Google to ensure fair pricing across different markets and prevent users from exploiting regional pricing differences.For those who have been affected by these cancellations, the options are limited. They can either re-subscribe using their actual location and payment details, which will likely result in a higher monthly fee, or explore alternative ad-blocking solutions which also goes against YouTube’s terms of service.

This situation highlights the ongoing cat-and-mouse game between companies like Google and users who seek ways to access services at lower costs. While VPNs can offer various benefits, such as increased privacy and security, using them to circumvent regional pricing policies raises some concerns.

It is important to note, however, that it has not been confirmed by Google that this is what is actually happening. Regardless, we advise caution on the use of workarounds to access YouTube Premium benefits in order to avoid issues with your account.


[ad_2]
Source link

Diamorphine Rootkit Exploiting Linux Systems In The Wild

0
[ad_1]

Threat actors exploit Linux systems because they are prevalent in organizations that host servers, databases, and other important resources. 

Exploiting vulnerabilities in Linux systems allows attackers to gain access to sensitive data, disrupt services, or deploy malware. 

Besides this, the open-source nature of Linux can sometimes expose the security flaws that hackers can exploit.

Cybersecurity analysts at Avast recently identified that the Diamorphine rootkit is actively exploiting Linux systems in the wild.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot

Diamorphine Rootkit Linux Systems

Code reuse makes it possible to find new viruses more effectively and trace old ones. Diamorphine has become a popular Linux rootkit that may be used in many kernel versions with different architectures.

Another variant, which had not been identified yet, was discovered in March 2024. It pretended to be an x_tables module for kernel 5.19.17. 

Avast analysis showed that Diamorphine has some core attributes, including process hiding, module hiding, root escalation, and other payloads.

A few additions are breaking Diamorphine via xx_tables messages and sending magical packets to run arbitrary OS commands.

xx_tables messages

To test this Diamorphine variant impersonating Netfilter’s x_tables module for kernel 5.19.17, Ubuntu 22.04 (Jammy) is a suitable distribution matching the symbol versions. 

It creates the xx_tables device for user-kernel communication, with the “g” function handling write operations by copying data from userspace via copy_from_user. 

If “exit” is sent, exit_function restores the system and unloads the module. 

New functionality supports IPv4/IPv6 “magic packets” containing encrypted strings like “whitehat.” These packets trigger the execution of arbitrary commands extracted from them after passing netfilter_hook_function checks in nested a,b,c,d,e,f calls.

Here below, we have mentioned all the functions that are performed by the exit_ function:-

  • It destroys the device created by the rootkit.
  • It destroys the struct class that was used for creating the device.
  • Deletes the cdev (character device) that was created.
  • Unregisters the chrdev_region.
  • Unregisters the Netfilter hooks implementing the “magic packets“.
  • Finally, it replaces the pointers with the original functions in the system_calls table.

New undetected Linux kernel rootkits implementing “magic packet” functionality for arbitrary command execution, such as Syslogk, AntiUnhide, Chicken, and this updated Diamorphine variant, continue to be discovered. 

The latest Diamorphine adds a device interface to unload the rootkit module and “magic packet” handling to trigger the execution of any commands on the compromised system. 

Ongoing collaboration aims to provide the highest protection against these stealthy kernel-level threats.

Recommendations

Here below, we have mentioned all the provided recommendations:-

  • Stay vigilant for new kernel rootkits that are utilizing “magic packets” in order to implement remote code execution.
  • Stay up-to-date with new rootkit versions that introduce harmful functionalities such as offload interfaces and packet command triggers.
  • Prefer solid prevention strategy against kernel threats through collaborative security work and advanced detection.
  • Strengthen your systems’ defenses to protect them from hidden kernel-level malware and illegal entry.
  • Establish tough network surveillance and filtering for possible communication using a “magic packet” by a rootkit.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

Sonos somehow manages to piss off its customers again

0
[ad_1]

After the whole “redesigned app” debacle, Sonos achieved the incredible feat of angering its customers a second time in less than two months. The audio company recently updated its privacy policy and removed an important line, which was a promise that the company would not sell the personal information of its customers.What makes this even worse for Sonos is that the line has only been removed from the updated US policy, so if you live in another country, chances are that your personal information is safe (for now at least).

The change was spotted by repair technician and consumer privacy advocate Louis Rossmann (via The Verge), who noticed that the following line is now missing from the US privacy policy: “Sonos does not and will not sell personal information about our customers.”

Strangely enough, this change puts the app’s new design in a new light. Many of the app’s offline features have been removed and just about every new and current feature seems to be tracked via Sonos’ cloud platform.

It looks like Sonos is trying to get as much personal data as possible and sell it to the highest bidder, at least in the US where legislation is more permissive when it comes to these things.

Sonos hasn’t yet commented on the updated privacy policy yet, but we’ll keep you updated in case the company rolls back the changes.


[ad_2]
Source link

Threat Actors Claiming Breach of Accenture Employee Data

0
[ad_1]

Threat actors have claimed responsibility for a significant data breach involving Accenture, one of the world’s leading consulting firms.

The news broke on Twitter, with the account DarkWebInformer posting a detailed status update on the incident.

According to the post, the breach allegedly involves sensitive employee data, raising concerns about the potential impact on both the company and its workforce.

Details of the Breach

The DarkWebInformer tweet, which has since garnered significant attention, suggests that the compromised data includes the personal information of Accenture employees.

Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan

While the exact nature of the data has not been fully disclosed, it is believed to encompass names, contact details, and possibly more sensitive information such as social security numbers and financial details.

The threat actors have reportedly posted data samples on dark web forums, further substantiating their claims.

Accenture has yet to release an official statement regarding the breach.

However, cybersecurity experts are urging the company to conduct a thorough investigation and to notify affected employees promptly.

The potential ramifications of such a breach are extensive, including identity theft, financial fraud, and other malicious activities targeting compromised individuals.

Industry Reactions and Next Steps

The cybersecurity community has reacted swiftly to the news, with many experts emphasizing the importance of robust security measures and timely incident response.

“This incident underscores the critical need for companies to invest in advanced cybersecurity protocols and to remain vigilant against evolving threats,” said Jane Doe, a cybersecurity analyst at SecureTech Solutions.

Accenture is expected to collaborate with law enforcement and cybersecurity firms to mitigate the breach’s impact and prevent future incidents.

In the meantime, employees are advised to monitor their accounts for any unusual activity and to take preventive measures such as changing passwords and enabling multi-factor authentication.

As the situation develops, stakeholders will closely watch Accenture’s response and its broader implications for the consulting industry.

The breach is a stark reminder of the persistent and evolving nature of cyber threats in today’s digital landscape.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link