Update your PaperCut application servers now: exploits in the wild

0
[ad_1]

We take a look at urgent updates needed for users of PaperCut, after two exploits were found in the wild.

PaperCut, maker of print management solutions, has urged product users to update as soon as possible. A security vulnerability which exploits unpatched servers has been seen in the wild, with serious ramifications for any organisation impacted.

Two specific vulnerabilities are at the heart of this alert, and are ranked with severity scores of 9.8 (critical) and 8.2 (high) respectively. Full information about the individual security flaws has not been revealed, in order to reduce the likelihood of more attackers making use of them.

Mitigation

At time of writing, both security issues have been addressed with patches. If you update your PaperCut application servers, you are no longer at risk. A recent check in security tool Shodan’s search functionality highlights roughly 1,700 software instances currently exposed to the internet. These flaws are quite severe, so it’s absolutely worth your time to get things updated as soon as possible.

From the Updating FAQ:

  • Please follow your usual upgrade procedure. Additional links on the ‘Check for updates’ page (accessed through the Admin interface > About > Version info > Check for updates) will allow customers to download fixes for previous major versions which are still supported (e.g. 20.1.7 and 21.2.11) as well as the current version available.
  • If you are using PaperCut MF, we highly recommend following your regular upgrade process. Your PaperCut partner or reseller information can also be found on the ‘About’ tab in the PaperCut admin interface.

If you’re unable to upgrade

PaperCut advises those who are unable to apply the patches to follow the below steps:

  • Block all inbound traffic from external IPs to the web management port (port 9191 and 9192 by default)
  • Block all traffic inbound to the web management portal on the firewall to the server. Note: this will prevent lateral movement from internal hosts but management of the PaperCut service can only be performed on that asset.
  • Apply “Allow list” restrictions under Options > Advanced > Security > Allowed site server IP addresses. Set this to only allow the IP addresses of verified Site Servers on your network. Note this only addresses ZDI-CAN-19226 / PO-1219.

Exploits

The two exploits in question are:

CVE-2023-27350: This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability.

CVE-2023-27351: This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system.

In both cases, compromised systems could be used to perform additional exploitation after the initial attack. Arbitrary code can be deployed, or even ransomware if that’s part of the attacker’s toolkit. The relative ease with which these exploits can be launched is just one reason for the high threat severity score. Indeed, researchers quickly discovered two types of (legitimate) remote management software being used in these attacks. These management tools are used to grant a potential form of persistent remote access to the target network. From here, they can burrow in ever deeper without the affected organisation noticing.

It will probably be a while before all possible patchable installations are running the necessary updates. If you’re potentially affected, do your part and head over to the updates page immediately.


Malwarebytes removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Twitter drops ‘government-funded’ label on media accounts

0
[ad_1]

Twitter removed the “government-funded” label from the major media accounts. The platform has come under fire for labeling news organizations and associating them with the government.

Since Elon Musk’s takeover, Twitter had multiple controversies that made the company a target for public criticism. In one of the latest cases, Musk decided to add a “government-funded” label to major news accounts like CBC, BBC, and PBS. In an interview with BBC, Musk promised to remove the label while saying he knows “BBC is generally not thrilled about being labeled state media.”

Some news organizations also stopped using Twitter to being labeled as government-affiliated media. However, the labels and “state-affiliated” descriptions are now removed from the media accounts, and plaintiff accounts can resume their activities.

Twitter removes government-affiliated label from media accounts, but there is a catch here

While some Western media may not be directly controlled by the government, there is ample evidence that Russian and Chinese media are directly affiliated with the governments. News networks like China’s Xinhua, Russia’s RT, and Sputnik, as well as Qatar’s Al Jazeera, are state-owned. So the problem with Musk’s recent move is these state-owned networks also lost the government-funded label.

Occasional changes and controversies have made media and advertisers rethink continuing to use Twitter. According to a recent report by Insider Intelligence, Twitter’s revenue in 2023 might drop 27.9% due to the reluctance of advertisers and the low number of Blue users.

Twitter is obviously striving to change its business model and switch from advertising-based to subscription-based revenues. The platform has recently removed checkmarks from legacy accounts and announced only Blue subscribers could get the badge. This move was met with many objections from previously verified accounts, and many of them said they would never pay $8 for the badge.

Businesses on Twitter can also receive a golden badge, while a gray badge is given to government and multilateral organizations. Likewise, advertisers with minimum spending of $1000 will get the blue checkmark automatically.


[ad_2]
Source link

ChatGPT will let you disable your chat history

0
[ad_1]

If you use ChatGPT, then you know that the powerful chatbot saves a log of your previous conversations. However, if you don’t like that, then this announcement from OpenAI might be up your alley. The company will disable this feature so that ChatGPT will not save your chat history.

ChatGPT is really good about saving your conversations, as most chatbots are. You’re able to go back and look at the previous conversations that you had in the past in case you want to continue from where you left off or take note of them. However, there may be people out there who don’t like the thought of that.

We also can’t rule out people who don’t want their conversations to train the OpenAI’s language model. Most users just don’t care, but OpenAI wants ChatGPT to appeal to the masses.

ChatGPT will allow you to disable your chat history

The company announced this in a short and sweet blog post. It says that this is a way for users to better manage their data. If you disable your chat history, you will no longer see your past conversations pop up on the left panel.

However, OpenAI will retain those conversations on its servers for 30 days. This is only so that it can scan those conversations for abuse. After that, the company will delete them from its service permanently.

As for conversations you had before disabling your history, those will not be deleted. Also, OpenAI will still continue to use those conversations to train the model. The setting only applies to conversations you saved after disabling the history.

How to disable your chat history

Disabling your chat history is pretty simple. First, log in to ChatGPT and go to the left panel. There, go to the bottom and click on the three-dot menu next to your profile picture and name. In the menu that pops up, click on the Settings button.

You’ll see a little popup window appear. At the bottom of the window, you’ll see Data Controls. Click on the Show button, and it will expand to show you the toggle to disable your chat history. Turn the toggle off, and ChatGPT will not save your chats.


[ad_2]
Source link

Bluesky is “Skyrocketing” while Twitter’s a falling bird

0
[ad_1]

Elon Musk has been the owner of Twitter for some time now, and things have been hectic, to say the least. However, Jack Dorsey, the creator of Twitter has come out with his own social media app called Bluesky. According to a new report, Bluesky has been gaining followers as Twitter has been struggling.

A lot of the current drama surrounding Twitter has to do with the verification checkmark and Twitter Blue. The verification checkmark is a pretty important part of the Twitter experience, but Elon Musk has felt the need to fix what ain’t broken.

Because of this drama, people are leaving Twitter in droves and walking toward other platforms such as Mastodon and Hive Social. Jack Dorsey introducing Bluesky only adds fuel to the fire.

Jack Dorsey’s Bluesky is gaining users

Bluesky has been pretty underground since it was created, but the platform did see an uptick in followers since Elon Musk took over Twitter. According to Bloomberg, the fledgling social media platform has amassed over 245,000 downloads on the iOS app store. More than half of those downloads came within the last month.

This means that people are vigorously looking for an alternative to Twitter. A few months ago, Mastodon gathered a bunch of users, and now, it’s time for Bluesky to have its moment in the Sun.

While Bluesky is just now gaining popularity, the app itself began development back in 2019. It’s a long time coming, as Bluesky is currently on an invite system. People who joined the waitlist back in last October are now being let into the app. If you are excited about joining Bluesky, just know that it will be a bit of a wait.

As for the app itself, it’s pretty simple in its execution. Just like with Twitter, you’re allowed to make text-based posts and add photos or videos to them as well. Text-based posts can be up to 300 characters long and you’re able to reply to them and repost them.

Bluesky is meant to be a more open platform than Twitter, so if you happen to use it, you will definitely see some differences between the apps. There’s also an Android app out, so if you want to download the app and wait for your invite, you can do so now.

Download Bluesky on the Play Store


[ad_2]
Source link

Microsoft Teams will no longer be bundled with Office

0
[ad_1]

In an effort to prevent another antitrust investigation by the European Union (EU), Microsoft has reportedly agreed to stop bundling its Teams remote collaboration software with its Office productivity suite. This move comes after the rival platform, Slack, filed a complaint accusing the company’s practice of bundling the two services together as anti-competitive.

According to sources familiar with the matter, Microsoft will eventually start offering users the choice to purchase Office with or without Teams installed. However, the mechanism for doing so is still unclear, and negotiations are ongoing.

“We are mindful of our responsibilities in the EU as a major technology company. We continue to engage cooperatively with the commission in its investigation and are open to pragmatic solutions that address its concerns and serve customers well,” says Microsoft.

Nonetheless, it also remains uncertain whether Microsoft’s offer to stop bundling Teams will satisfy the commission, given that Slack has requested officials to require Microsoft to sell Teams separately from its Office suite.

Microsoft’s History of antitrust allegations

This is not the first regulatory issue for the company. Back in 2009, Microsoft settled with the European Commission to start offering users the choice of browsers after being accused of using its dominant position to promote its Internet Explorer browser by bundling it with Windows. However, in 2013, the commission fined Microsoft €561 million for not adhering to its promise.

In recent times, Microsoft’s push towards acquiring Activision Blizzard for $69 billion has come under a lot of scrutiny from regulatory bodies, which fear that it would give Microsoft a dominant position in the gaming industry. However, the company’s ten-year deal to provide Call of Duty games on Nintendo consoles attempted to alleviate some of these concerns. An attempt which ultimately failed with the CMA’s report on April 26 that it’s blocking the deal.


[ad_2]
Source link

Samsung brings Image Clipper to its Galaxy A series devices

0
[ad_1]

Samsung‘s newly-introduced Gallery feature Image Clipper is now rolling out to its mid-range smartphones. The April security update for the Galaxy A53 5G brings the feature. The company has already pushed it to several flagship models, including the Galaxy S22 series and the latest foldables.

For the uninitiated, Image Clipper is a new tool in Samsung’s Gallery app for its Galaxy smartphones. Debuting with the Galaxy S23 series earlier this year, it lets you quickly crop out subjects from images.

When viewing photos in Gallery, you can press and hold on a subject to instantly crop it out. The cropped image can be saved as a separate file or copied to paste into other apps. You can also instantly share it on social media.

Shortly after the Galaxy S23 release, Samsung started pushing Image Clipper to its older devices. Unsurprisingly, the Galaxy S22 series received it first. The likes of the Galaxy Z Fold 4, Galaxy Z Flip 4, and other flagship models followed soon.

The company also seeded the new feature to low-cost flagships such as the Galaxy S20 FE. It has now shifted focus to mid-range models, with the Galaxy A53 5G being the first in the segment to pick up Image Clipper.

The April update for the Galaxy A53 5G brings Samsung’s Image Clipper feature

As said earlier, the new feature arrives with the April security update for the 2022 premium mid-range smartphone. The update is rolling out with the firmware build number A536BXXU5CWD1 in Europe. Samsung should soon expand the release to other markets.

It’s worth noting that the April SMR (Security Maintenance Release) has already reached some Galaxy A53 5G users in the US. But it didn’t bring Image Clipper. Those users may get this new feature with the May update. Or maybe Samsung will push a second April update in the region.

Either way, if you’re using a Galaxy A53 5G, Image Clipper is headed your way. All eligible units around the world will receive this feature over the next few weeks. Of course, this update isn’t just about the new feature. The April SMR also contains dozens of vulnerability fixes.

We are talking about more than 70 security patches here, at least five of which were identified as critical issues by Samsung and Google. The remaining flaws were also mostly of high severity. You can check for updates by navigating to Settings > Software update and tapping on Download and install.


[ad_2]
Source link

TSMC is struggling to make 3nm chips for iPhone 15

0
[ad_1]

Apple uses TSMC to make all of its chipsets, across all of its products. And starting with the iPhone 15 Pro, Apple is moving to 3nm chipsets, which TSMC is now struggling to produce.

This is according to EE Times, which states that the company is having issues with tools and yield. This is impacting the ramp up to volume production of the new chip technology.

TSMC is manufacturing the A17 Bionic chipsets that will be found in the iPhone 15 Pro models. Which are set to be 3nm chipsets. They are also working on the M3 chips for Mac, which are also 3nm. Right now, analysts are estimating that the yield for A17 and M3 processors are around 55%. That sounds about right, for where TSMC is at, in development.

Could this affect iPhone 15 Pro sales?

It could affect sales, or more importantly, stock of the iPhone 15 Pro. Making it tougher to buy one, at launch. While yes, we are many months away from the iPhone 15 Pro even being announced, and TSMC could catch up by then, it could still affect the stock at launch in September.

We’ve seen, in the past, Apple delay certain models of the iPhone for a month or so, due to supply issues. Like the iPhone 12 launch, the iPhone 12 Pro Max and Mini were both delayed for a month. And that was after the iPhone 12 was initially delayed and launched in October. So those phones didn’t come out until November. And we could see that again this year from Apple.

This would also explain why the MacBook Air 15 that is set to be announced at WWDC in June is likely coming with an M2 chipset over the new M3. Though we also haven’t gotten the M2 Max nor the M2 Ultra yet, so M3 is likely still quite a ways away.


[ad_2]
Source link

Decoy Dog Malware Tool Kit Spotted Via Malicious DNS Queries

0
[ad_1]

A new malware tool kit, “Decoy Dog,” has been actively targeting enterprise networks for a year. The researchers identified Decoy Dog after analyzing billions of DNS queries.

Decoy Dog Malware Actively Targeting Enterprises

Sharing the details in a recent blog post, the cybersecurity firm Infoblox has unveiled a new malware tool kit, “Decoy Dog,” running active campaigns in the wild.

As elaborated, the researchers became curious about the matter upon detecting billions of malicious DNS queries. They scanned at least 70 billion DNS queries to find a similar DNS pattern from 0.0000027% of all active domains globally. What alarmed them about the DNS queries was their peculiarity – they returned unresolvable IP addresses, something quintessential of US Dept. of Defense or malicious phishing campaigns.

Analyzing the matter further made the researchers detect these queries generated from enterprise networks. Then, the C2 communications linked back to Russian hosts.

Eventually, the researchers could find PupyRAT related to this activity. The Decoy Dog malware tool kit supposedly deployed PupyRAT on target enterprise networks.

While most domains associated with this campaign linked to the tool kit, some domains did not, hinting that they may be left for domain aging.

The researcher first detected Decoy Dog in the wild in April 2023. However, analyzing the domains made them deduce that the tool kit became active in April 2022.

It remains unclear if all Decoy Dog activity originates from the same threat actor. Alternatively, the creators might have set up Decoy Dog for commercial use, letting numerous threat actors use the tool kit for different malware.

Besides, the researchers found Decoy Dog typically focused on enterprise networks only, sparing consumer devices. Nonetheless, their target enterprise networks may include small and large businesses alike.

To mitigate such attacks, Infoblox advises enterprises to deploy blocklists on their networks to prevent malicious DNS queries. They have also shared the IOCs for the tool kit, which organizations may use to configure the filters.

Let us know your thoughts in the comments.


[ad_2]
Source link

What is Free Ad-Supported TV (FAST)? Everything you need to know

0
[ad_1]

Lately, FAST Channels, or Free Ad-Supported TV Channels, have been taking over the streaming industry. But what exactly are they? It’s pretty straight-forward, they are streaming channels that are free and have ads. But in this article, we’re going to go over everything you need to know.

What is FAST?

In its simplest form, FAST is Free Ad-Supported TV. Typically used as a TV channel, similar to what Cable was, but of course, free. The content on these channels are solely funded by advertisements and commercials.

FAST channels generally have both linear channels and video that is available on demand. A good example of this is Sling’s FreeStream service. Which has over 300 channels, that are completely free and have ads.

FAST Channels have become pretty popular as of late, with streaming companies continuing to raise prices on their paid plans. A lot of people are looking for areas where they can get free content. And that’s where FAST has started to take off. Especially with the explosion of users that Pluto TV, Tubi, Xumo and others have seen in the past few years.

What kind of content is available on FAST?

Content that you’ll find on FAST channels are typically not originals. Studios will license content out to these FAST channels, and typically it’s older content. Content that they likely can’t get a ton of money out of licensing. So instead what these studios do is, they get a portion of the advertising revenue from the ads shown alongside their movies and TV shows.

So, many times, you’ll see older content, or even content that has hundreds of episodes. Like some of Gordon Ramsey’s shows like Hell’s Kitchen. As well as others like Pawn Stars, and such. Some of the bigger shows will get their own channels on these platforms for streaming 24/7.

With FAST, companies can make themed channels, as well as live cable television channels, and even niche channels about sports and news shows. Peacock, while not entirely a FAST service, does offer some channels in this way. Like there’s a channel specifically for NBC news.

PP 20220923 Cadent iStock 1376203813 3X2

What are some examples of FAST services?

So what are some examples of services that utilize FAST channels? Well there’s quite a few, but below, we’ve rounded up some of the more popular models.

Pluto TV

Pluto TV was one of the first to move in on FAST. It launched back in 2013, and released a beta version of its website in 2015. Pluto TV offers around 250 virtual streaming channels. These are channels that go across a variety of categories, including entertainment, news, comedy, sports, and classic TV.

It also has some themed channels like “Cats 24/7” and “Totally Turtles” which has episodes of Teenage Mutant Ninja Turtles on repeat.

Xumo

Another example is Xumo, which first launched in 2011, and was then acquired by Comcast. It’s one of the largest FAST services out there, and is exclusively available in the US. It does, surprisingly, offer OTT streams of traditional broadcast channels, including NBC, CBS and ABC. It also has some content and channels from digital-first video content publishers like Fail Army, as well as free movie channels and much more.

Sling Freestream

Sling Freestream is one of the newer FAST services out there, having launched in 2023. But it has over 300 channels that are available for free. You just need to login or create a free account.

Sling is a subsidiary of Dish Network and has offered a paid streaming service for nearly a decade now. It offers an a la carte option for those cutting the cord. But now it also offers up free content as well. This is actually something it started during the pandemic, and then decided to keep it and expand it.

Sling has continued to add more and more content to these channels, and will likely continue to do so.

The Roku Channel

Roku, yes the company that makes streaming hardware, has it’s own FAST service, which is built into the Roku platform. But you don’t need to have a Roku device to use it. It’s available on most platforms. The Roku Channel has a ton of free to access channels, and even bought the tech and content from Quibi when it went out of business in 2020.

Peacock

Peacock is a bit different from the others here. That’s because it offers a free version of its service, though that’s going away soon. And it offers FAST channels, but that’s included in your monthly subscription. Peacock does have a number of FAST channels available, mostly themed channels, like Today all day, as well as channels for MSNBC and CNBC and much more. It’s not quite a FAST service, but it offers a similar option.

Should I be using a FAST streaming service?

There’s no streaming service that you have to use. That’s all entirely up to you. But the fact that you can sign up for all of these services, without spending a penny, is pretty nice.

FAST channels are really good for background noise. You know, turning on the TV and having it playing while you do chores like cooking or cleaning around the house. That’s what a lot of these paid streaming services like Netflix are really missing right now. And FAST makes that possible, without spending any money.


[ad_2]
Source link