According to Samsung, these days more consumers prefer to read the news from their mobile devices. As a result, Samsung today announced that it has launched the Samsung News app that delivers “everyday news experience in one convenient place.” The company says that the app will include “trusted news sources” and users will be able to access briefings in the morning and evening. It also will give Galaxy device users the ability to see their trusted news sources via a single swipe.
The Samsung News app is coming to U.S. Galaxy phones first
Available first to U.S.-based Galaxy users as an update to the Samsung Free app that contains free premium content and services for Samsung device owners. If you already have the Samsung Free app on your Galaxy phone, starting today you will see the icon change to reflect the Samsung News name. Or, the Samsung News app can be downloaded from the Galaxy Store. Samsung will first roll out this new feature on select phones and it will be made available to all other eligible U.S. devices over the coming weeks.
You’ll certainly recognize the list of news sources that will be available from the Samsung News app. Right now, this list includes:
Bloomberg Media
CNN
Fortune
Fox News
Glamour
GQ
HuffPost
Money,
Newsweek
New York Post
Parade
POLITICO
Refinery29
Reuters
Salon
Slate
Sports Illustrated
The Daily Beast
TheStreet
USA TODAY
Vice
No matter which side of the political spectrum you’re on, or whether you want hard-hitting news or just want to learn about your favorite sports teams, the Samsung News app will give you access to the news sources that you favor. Samsung says that over time it will add additional news sources.
Get the Samsung News app on your brand-new Galaxy S23 Ultra. Buy it now!
There are three ways to access the news from the app. Daily Briefings are delivered twice a day, in the morning and the evening. These briefings give users the top headlines of the day in one location. Users can also view news feeds from Samsung’s partners, organized for quick and easy access. With the “Following” tab, users can update the preferences they select to customize the news that they want to see. And the Samsung News app also gives users a location to access all of their favorite podcasts or discover new ones.
Avner Ronen, VP of Product Development at Samsung Electronics, sums up the new app by saying, “We created Samsung News to deliver breaking and premium news to Galaxy users in an easy-to-access format. Our goal is to support users by letting them curate their ideal news experience.”
Every day tens of thousands of Spear phishing emails are sent to millions of victims around the world.
Cyber-attacks have different pathways now; they can strike you from inside or outside, with equal damages across your network.
Targeted takedowns could be critical if analyzed and executed with absolute precision.
In this guide. We’ll look at Spear Phishing Attacks, techniques, examples, mitigation procedures, and a few best practices.
What is Spear Phishing?
Spear Phishing is a malicious practice that executes via Email campaigns that hackers research their target audience, understand their likes and dislikes, study their day to day operations, and customize the mail to steal sensitive data and install malware. This type of targeted email campaign deployment to infiltrate their target audience group is called Spear Phishing Attack.
Any anonymous email that drops into your inbox from an unknown sender can be assumed to be phishing Attack. Blasting millions of emails to the database of email id’s with malicious intent is called phishing.
It could be for the deployment of malware, remote code executions and more, however, this phishing may not be rewarding for hackers.
How does Spear Phishing Attack Work?
Spear Phishing is executed in four stages,
Target identification
Studying the target’s behavior
Customizing the message
Blasting emails
Target identification:
The hackers initially identify their target victims by narrowing down their audience based on their motive of the campaign, this could be targeted at corporate in a particular vertical or patients of a healthcare company.
The identification procedure is divided into two stages, the primary and secondary target, primary target will be executives working for an MNC, who will be receiving the blasted emails and the secondary target will be the key ones who will have access to business sensitive information.
These primary targets that have become victims to the spear phishing attack will be manipulated to exploit the secondary targets.
Studying the target’s behavior:
Gathering information about the targeted audience by digging deep into their social media profiles, job sites, portfolios, comments, likes and groups they belong to, and communities they belong to. One way or another the hackers will gain their personal information like email, phone numbers, first name, surname, history of experience, schooling, college, area of expertise and more which they will use to influence their potential targets.
Customizing the message
Hackers will customize their emails and message based on the information collected from these external resources for better open rates and reduced bounce rates. Once a successfully established message is obtained they will proceed for the email blasting procedure.
Blasting emails
After all the research hackers will prepare their attack vector and strategy to ensure the mail gets delivered to the target audience inbox and not into the spam folder.
They will disguise the sender details to be a legitimate one, to ensure the proper delivery of the mail is made and the end user opens it as expected.
After opening the email, the user will click a link or download an attachment-based on the content as it is made accurate.
With all research, the CTR will definitely be high. Thanks to the reliability of the mail crafting procedures the hackers have implemented.
What are 3 types of Spear-phishing emails?
Usually, hackers prefer one of three techniques below to manipulate their target audience.
Impersonation
Personalization
Emotional Response
Impersonation
As the name defines, hackers pretend to be someone else or a legal entity to establish trust and elude with data. This technique is very commonly used by disguising a genuine person or entity in the sender section with an indistinguishable subject line.
Personalization
This technique has an
excellent success rate, as the message is very much customized for the
recipient so he believes that this email will be of use to him or for his
profession in general.
Emotional Response
This technique creates a fear, happiness, shock or surprise to make the end user open the mail and click/download the malicious content as planned.
What is an example of spear phishing?
Examples of Spear Phishing Attacks are very much targeted and often have disastrous outcomes for enterprises, below are few examples for successful spear phishing attacks.
Ubiquite Networks Inc
This Company paid more than USD $40 million in 2015, as a result of spearphishing attack because of a CEO fraud. The emails were impersonated as if they were from senior executives to transfer funds to a third party entity in Hong Kong, which was then found to be some anonymous entity and not a genuine third party.
RSA
RSA is a leading security firm but unfortunately, even they themselves become victim to a targeted spear phishing attack in 2011.
Mails with subject line ‘2011 Recruitment Plan’ were blasted, though most of it was marked as spam one user opened it, leading to the deployment of malware into the infected system and eventually gave remote access to the hackers to infiltrate the computer and network.
Amazon
Amazon is another leader among the fortune 500 companies, targeting this firm will definitely improve your success rates for spear phishing.
In 2015, a mass spear phishing attack was unleashed targeting Amazon customers with a subject line ‘Your Amazon.com order has been dispatched’, followed by a code.
However, unlike the normal emails from Amazon, where you could see the dispatch status directly in the mail or via your Amazon account, in this case, it was mentioned to be available in the attachment.
Few employees become prey to this maneuver and a Locky ransomware was downloaded and installed in the infected systems to encrypt data and demand ransom.
How can you protect yourself from phishing?
Spear phishing prevention is a process that depends on different factors like awareness, tools, education, emotional response and more. Below are the best practices that both organizations and individuals should practice to protect yourself from phishing,
Increasing cyber awareness
Employing cyber tools
Identifying fake emails
Avoiding clicks and attachments
Avoid mails that force urgency
According to a report from Intel 97% of people were unable to identify a phishing mail. The best suggestion to apply spear phishing prevention by creating cyber awareness and improving cyber education. Spear phishing prevention is a process that will depend on a number of factors and their amount of precision.
Increasing cyber awareness:
Organizations and individuals should improve their cyber awareness either themselves or through cyber guidelines. Understanding the attack vectors, their mechanisms, procedures and possible procedures can help the end users and individuals prepare themselves any potential phishing scams and ensure they avoid them all times.
Employing cyber tools
As already mentioned in earlier sections, no tools are good against phishing attacks but properly configured browser policies, email filters, and endpoint configurations can reduce the chances of becoming a victim to phishing scams. GPO policies for stronger passwords and firewall configurations could also help organizations secure their users against phishing mails.
Identifing fake emails
Users can also
distinguish between a genuine and fake mail by looking at the subject line, the
sender and the relativity. Based on the content of the email this can be
re-confirmed. Any unknown senders or purpose of the mail could be a potential
phishing scam.
Avoiding clicks and attachments
Not all phishing scams do work when the mail is opened, most is switched ON only when the link in the mail is being clicked or an attachment is being opened. So the users need to ensure they are aware of the links and attachments, perhaps by hovering over the link or looking at the attachment file.
Avoid mails the force urgency
Users should avoid emails that create an urgency; emotional response is what will become prey to these sort of phishing emails. Any emotional mail that create a fear, surprise, shock, or personalized emotional response based on your tax, and health metrics should be avoided.
Spear Phishing Infographic
Organizations need to have few policies and configurations in place to keep phishing mails away from the enterprise network, however when users expose themselves to public networks only a self-analysis and cyber practices can keep them safe against spear phishing attack.
If you guys have ever experienced a phishing email, or do have an example to share, please free to comment below your experiences and message so we will see some real-time information on this threat.
Spear phishing attacks are hard to detect and mitigate, so keep your browsers and firewalls active and updated.
Google has released an updated version of Chrome to address a zero-day flaw that is being exploited in the wild.
In a recent security advisory, Google says it patched a high-severity zero-day security flaw in its Chrome browser—the first in 2023—currently being exploited in the wild by threat actors. The company urges all its Windows, Mac, and Linux users to update to version 112.0.5615.121 immediately, as this flaw is present in Chrome versions before this one. Updating your browser can be done manually or automatically.
If you use other Chromium-based browsers, you may need to update them as well.
The vulnerability, tracked as CVE-2023-2033, is exploitable when a user visits a malicious webpage using an unpatched Chrome browser. The page could run arbitrary code in the browser, potentially leading to your computing device being hijacked. Google knows an exploit code for this flaw already exists and is circulating in the wild.
CVE-2023-2033 is a type-confusion bug in V8, Google’s open-source JavaScript and WebAssembly engine. As with zero-day patch announcements, the company supplied little to no details on how attackers could exploit this flaw. However, we know that attacks on V8, although uncommon, are considered one of the most dangerous. Exploiting a weakness in V8 typically leads to a browser crashing.
“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” says Google in the advisory. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”
Google is giving all its Chrome users enough time to update to the latest version until technical details are released.
How to manually update Chrome
Google Chrome typically updates automatically. However, it’s worth double checking. To check if your browser is up to date:
Click the three vertical dots at the upper right-hand side of the URL bar.
Select Help > About Google Chrome.
Simply doing this should trigger Chrome to update. Once done, the browser will ask you to relaunch. Click the button to confirm and complete the update process.
Google would never let users manually download and install a separate file to update Chrome. Scammers and threat actors have used this tactic many times in the past, and, for a time, it worked. Now and then, this tactic is adopted in a malicious campaign, to catch those who aren’t familiar with how Chrome works or how Google updates its products.
Stay safe!
Malwarebytes removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.
Gaming headsets are a must-have accessory for your gaming sessions for a number of different reasons and there are lots to choose from, but if you want the best ones as options, then you need to wade through the ones that aren’t worth your effort.
We’ve put together a list that has ten different options for you so you can save some of that precious game time. Which means you can spend more time on gaming with a headset you’ll love and less time trying to find something that works. Regardless of whether you’re playing on PS4, PS5, PC, Xbox One, Xbox Series X, Nintendo Switch, or other options like mobile or Stadia.
This is a rolling post so we’ll be updating the list every month. The options on the list may not always change completely, but there will always be something that works for every user.
Best Gaming Headsets Summary
Below you’ll find a short summary table of all the best gaming headsets we’ve selected.
If you’re short on time, you can scan the table below and see every option we picked, along with how much they cost and buy links to jump right to where you can get them for yourself.
Should you have a little more time, you’ll find short descriptions of each headset below the summary table along with the same information as well as videos and buy links to snag the headset of your choice.
Xbox Series X|S has the Beoplay Portal headset, and now PS5 has its own luxury gaming headset in the Master & Dynamic MG20. While pricey at $449, you’re paying a premium for a super high-quality gaming headset that comes with just the right features. And trust us, you’re getting every single damn thing you pay for here.
For starters, Master & Dynamic is using materials like magnesium earcups, lambskin leather earpads, and an Alcantara and canvas-coated headband. Additionally, it comes with a detachable boom mic which comes with a pop filter, and it has a second built-in mic for voice calls or chat in a more casual setting.
It also comes with a low-latency adaptor, a premium carry pouch, and it uses USB-C for charging. There’s 7.1 surround sound onboard as well, and it comes with up to 22 hours of battery life. I could go on. As there are many more features that make this headset worth it. Sure, it’s $50 less than the Disc Edition of the PS5 console itself. But, you’ll be glad you picked it up if you want a more premium experience in your games as this is one of the best gaming headsets out there.
EPOS | Sennheiser GSP 670
When it comes to PC gaming, Sennheiser’s GSP 670 is the cream of the crop. It’s expensive, but Sennheiser knows audio and it’s excellent on this headset.
Perhaps the best part is the mic. The swivel motion that lets you flip it up to mute the mic is the easiest way to mute yourself in chat. Period. The headset is also extremely comfortable and can be worn for all-day gaming sessions without getting uncomfortable.
Speaking of comfort, it features adjustable fit on both sides of the headset as well as on the top of the band for more or less tension. The mic is also noise cancelling. So even if you’re using Discord which has a decent software-based noise filter, this just ensures that you’re voice is coming through crystal clear.
And, you have separate volume dials for regular game audio and chat audio. Letting you adjust things perfectly.
It works for PC, PS4, and mobile devices too, and it offers extremely low-latency gaming audio. It works ok with PS4 and mobile, but it doesn’t have the benefits of the PC software that really make the audio shine. For PC this is one of the best gaming headsets you’ll find.
These two closed-back headsets from Beyerdynamic are some of the best you can get for around their price point. Which is $150 for the MMX 150 and $99.99 for the MMX 100. Fitting, we know.
Both come with detachable META Voice cardioid condenser microphones for vocal clarity, as well as an impedance of 32 ohms, dedicated volume dials for precise audio adjustment and more. And if you go with the MMX 150 you get the benefit of the augmented mode. Turning this on enables sounds from outside the headset to filter in some. So you can hear both the game audio and what’s around you.
Both headsets are wired so you’ll not have the freedom of a wireless headset here. But the comfort and sound quality are awesome and they’re both relatively affordable.
Logitech G Pro X Lightspeed Wireless
Next to the Sennheiser (or EPOS depending on which version you have) GSP 670, the Logitech G Pro X Wireless Lightspeed gaming headset is one of the best headsets we’ve ever had the pleasure to put on our heads. The large, soft ear cushions wrap your ears in a pillowy goodness that makes these extremely comfortable to wear for many hours on end. Heck, wear them all day if you want. We have, and it still felt great even in the second half of the day.
What’s even better is that Logitech G gives you two pairs of ear cushions. One made from a plush leatherette, and another set made from a soft microfiber that should help to cut down on perspiration. The latter pair is great if you live in a warmer climate. Or if your ears just get really hot when wearing headsets for extended periods of time.
Beyond the comfort factor, the Lightspeed wireless technology is bar none the best wireless tech for any peripherals. It’s hard to interfere with so you should have little to no issues with audio breaking up. And it has a decent range. So you can easily get up from the chair or couch and grab something from the kitchen if you need to.
There’s also easy to use on-ear controls, and a detachable boom mic. Which is always a huge plus. Overall, these sounded nearly as good as the GSP670s, and they were on average more than $100 less.
Razer Kraken V3 Pro
The Razer Kraken V3 Pro is one of Razer’s newest headsets coming with much of the same high-quality audio features you know and love, but with some advanced new features too. Like the HyperSense stereoscopic haptics. This lets you essentially feel parts of what you’re hearing so you get new levels of immersion you’ve never experienced before in your games.
In addition to the HyperSense, the headset is also wireless and works for PC, PlayStation 4 and PlayStation 5, and it should work with Xbox one and Xbox Series X|S as well. All thanks to the 2.4GHz wireless adapter. THX spatial audio with 7.1 surround sound and Razer Chroma RGB are also familiar features that make a return. And one of the best features, at least we think so, is the detachable mic so you can remove it when you aren’t using voice chat.
SteelSeries Arctis Nova 1
The reason we love this headset is because it’s affordable for one, and because it comes with a lot of the design updates that started with the Arctis Nova Pro. Like the redesigned headband system and the extendable ears so it can more easily fit people with all different head sizes. It also features a retractable noise cancelling mic, comes in two colors (Black and White), and it supports the Sonar software when being used on PC for enhanced audio features.
But you don’t have to use it on PC. It will work with any platform that’s compatible with a 3.5mm audio jack. Lastly it only weighs 236g and uses a breathable AirWeave memory foam for comfort during long gaming sessions.
Sony Pulse 3D
Sony’s Pulse 3D wireless headset for the PS5 is probably going to be the most popular option for PS5 owners. Quite simply because it is pretty decent and it’s available at a good price point. $100 is a good price for something that offers 3D audio support, stereo sound, and a lossless 2.4GHz connection to keep you immersed.
The Pulse 3D wireless headset also has a built-in mic that doesn’t protrude outward like some other options. So if you prefer that more seamless look this is a good trait. It also makes it easy to ensure you aren’t bumping the mic if you’re ever lifting your hands up towards your mouth to take a drink or snack on something during games. There’s on-ear controls as well.
You also get pretty decent battery life of up to 12 hours of play time, and quick charge time. If you need to conserve some of that battery life, you can even plug the headset into the DualSense controller via a 3.mm audio jack. Which you may need to do from time to time. Comfort wise there may be some better options out there. But you’ll likely spend more.
So for the price, you get a very comfortable headset that carries the same design as the PS5 console, great audio quality, and because it’s coming directly from Sony you should have pretty good support if anything ever goes wrong.
Razer Black Shark V2 Pro
Razer is rooted in Esports. So it shouldn’t be a surprise that our pick for the best Esports headset is Razer’s Black Shark V2 Pro.
This is a wireless headset so you’re unencumbered by long, annoying cords that do nothing but get in your way and brush up against your arm when you’re in the heat of the moment, causing the immersion to break.
It also has a detachable mic for when you don’t need team voice chat, and it supports THX 7.1 surround sound audio. The best thing about the headset though is the comfort. Whether you’re playing competitively or you’re playing on your own during your own time, you can wear these all day and not get fatigued.
The giant oval-shaped cushions help you stay comfortable during longer gaming sessions. And the infused cooling gel inside of them helps keep your ears cool and prevent sweat. Or at least excessive amounts of it.
SteelSeries Arctis Nova Pro Wireless
Of course we had to make sure one of the clear contenders for the best overall headset was added to this list. The SteelSeries Arctis Nova Pro Wireless. As the successor to the Arctis Pro Wireless, the Nova Pro Wireless has a lot to live up to. But it seems that it manages to surpass the older model with some pretty great upgrades.
For starters, it now comes with Active Noise Cancellation and a transparency mode. So you can either choose to block out anything but your game or let a little bit more sound in. The retractable mic also now sits flush with the headset earcup.
SteelSeries also got rid of the ski goggle headband and has made the headset extendable. It even comes with a slightly smaller gaming DAC than the last model. Which still lets you connect to two devices at once. So you can plug it into your PC and your console. Best of all, it comes with two hot-swappable batteries so you can always keep one charged and never have to worry about the headset battery dying on you in the middle of a game.
All that said, the headset is certainly pricey. But you get what you pay for. And you’re paying for quality here. If you want one headset for basically everything, this should do the trick. You can also pick up the wired model for Xbox and save $100. Whether you go with wireless or wired, this is one of the best gaming headsets out there.
HyperX Cloud Alpha
HyperX has been around making gaming headsets for quite some time and the Cloud Alpha is one of its best.
This is a wired gaming headset and like many of the models HyperX makes, it features an aluminum frame so it’s pretty durable and still very comfortable.
It also works with just about every platform, comes with dual chamber drivers, and large comfy earpads so you can wear these for long gaming sessions.
It’s no secret that coral reefs are one of nature’s most magnificent wonders, but climate change, overfishing, and pollution have severely damaged these ecosystems. Now, in an effort to save our coral reefs, Google is teaming up with marine biologist Steve Simpson and marine ecologist Mary Shodipo to launch a new citizen science project called “Calling in Our Corals.”
The project aims to monitor the health of coral reefs by planting underwater hydrophones, which will record the sounds 24/7. Participants can listen to these recordings on an online platform and identify sounds made by fish, shrimp, and other marine creatures. And if enough people contribute to the program, Google would then use this data to train its AI and automate the process.
“In some locations, our research involves placing sound recorders inside marine protected areas (where there is no fishing) and in nearby fished areas for comparison to listen in on the benefits of protection. In other locations, we are comparing sites that have declined due to overfishing and poor water quality with those where we are actively restoring coral reefs by replanting corals and rebuilding habitats,” said Simpson.
How will this project protect coral reefs?
With climate change not slowing down, increased carbon dioxide levels in the atmosphere have caused ocean acidification, which has led to mass coral bleaching. Therefore, with these soundscapes, scientists can identify how climate change has impacted every reef by analyzing the creatures that live there. By doing this, they can make calls on how to rebuild those populations and restore the biodiversity of the reef.
Moreover, to help people educate on what different marine animals sound like, each recording on the platform will also be paired with a spectrogram, which will show the spectrum of frequencies of the recorded sound waves. As a result, volunteers will also be able to learn the difference between creatures with higher and lower-frequency sounds.
Expect more IRS tax-related shenanigans from fraudsters, who are now going for corporate accounts, after some states received deadline extensions.
Last week, the IRS reminded taxpayers that Tax Day, April 18, is Tuesday this week. However, in some states like Alabama, California, and New York, the federal office extended the filing deadlines due to natural disasters. This is an excellent reason for scammers to keep launching tax scam campaigns even when tax is due tomorrow for most Americans.
Just a few weeks ago, we wrote about a fake IRS tax email carrying a malware payload: Emotet. Now, our Senior Director of Threat Intelligence, Jerome Segura, has found an email with the title “IRS Notice of intent to seize (Levy) Your Property or rights to property”, which was purportedly sent by “Tax IRS 152”.
The email, with an HTML file attachment, contains a short message:
Please note: [redacted]
<=> For information please continue to check here or use our free mobile=app. Updates status are made no more than once a day.
Opening the attached HTML file reveals a Microsoft email phishing page. According to Segura, stolen data is sent to a Telegram channel via a bot. So, avoid giving away your credentials, especially if your Microsoft email is tied to a business, if you don’t want scammers hijacking your account and using it for more nefarious purposes.
Avoiding tax scams
Here are some ways you can outsmart tax fraudsters and keep one step ahead of the phishing, malware, and social engineering attacks that come around every year during tax season.
File early. One of the quickest ways to stumble into a trap is to leave filing your tax return until the last minute. That added pressure can mean responding to fake emails you otherwise would have ignored.
Be careful around suspicious refunds. Tax agencies have a proper process for issuing refunds, as found on their websites. Some, like HMRC, are very clear that refunds are never issued by email. If in doubt, phone the tax office directly and ask if what you have is the real deal or a fake.
Beware of fake bank portals. Some tax scams will ask you who you bank with, and then open up a phishing page for that bank. Always navigate directly to your banking website, click throughs and redirects typically spell danger.
Avoid the pressure pitch. Tax scammers like to hurry you along to data theft and malware installs. Claims of only having 24 or 48 hours to file for a refund should be treated with skepticism. As with most solutions for these forms of social engineering, contact the tax entity directly.
Malwarebytes removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.
Samsung has released a new update for its Expert RAW app for the Galaxy S23 series. The company is pushing some quality improvements and a bug fix to the app. The new version is only compatible with the latest April 2023 firmware build for the Galaxy S23 trio.
The latest update for the Expert RAW app comes with version number 2.0.08.5. The official changelog supplied by Samsung mentions image quality improvements and a fix for the loading error of Astrophoto to Lightroom with High-efficiency RAW (via @daniel_scuteri). Overall, it’s a relatively minor update but could help improve the user experience a lot. If you’re using a Galaxy S23, Galaxy S23+, or Galaxy S23 Ultra running the April security patch, you should be able to download the new update for Expert RAW from the Galaxy Store (link below).
This Expert RAW update doesn’t seem to fix the Galaxy S23’s “halo effect” issue
It appears this update for the Expert RAW doesn’t fix the abnormal halo effect that Galaxy S23 phones produce around subjects in photos. Subjects have a light outline across the borders, which is particularly visible in low-light photos, though regular daylight photos also often exhibit similar unnatural effects. The issue has been there since day one and Samsung hasn’t fixed it yet. We recently learned that the company is finally readying a fix.
By the looks of it, the said resolution will roll out with an update for the phones rather than the Expert RAW app. In that case, we will likely have to wait for the May security update. Samsung released the April patch for the Galaxy S23 phones in the last week of March. It remains to be seen if the May patch arrives before we enter the new month. We will keep you posted. In the meantime, you can click the button at the end of this article to download the latest version of the Expert RAW app from the Galaxy Store.
As for users of other Galaxy flagships, like the Galaxy S22, Samsung recently announced that it plans to bring more camera features from the Galaxy S23 series to them. It has already pushed Image Clipper with the April update. There are a few more in line, including a focus priority option. Make sure to keep your Galaxy flagship updated so you don’t miss out on the latest features. Go to Settings > Software update > Download and install to check for updates manually.
In the US, iMessage is a status symbol. Many iPhone users won’t even talk to people that have a green bubble – aka an Android device. Because the green bubble looks terrible. Though, it’s likely more because iMessage has so many more features than just regular SMS does.
And new with iOS 16, Apple has also added a few more features to iMessage. This includes the ability to edit as well as undo send messages in iMessage. It’s a pretty simple thing to do, and something that users have wanted for years. So today, we’re going to show you exactly how you can do this.
How to edit an iMessage
To edit a message that you’ve sent on iMessage, you’ll need to first long-press on the message you wish to edit.
From there, a menu will pop up. Select the “Edit” option.
Now, you’ll be able to edit your message and hit send again.
You can edit a message as many as five times, but only within 15 minutes of sending it. So you can’t edit a message the next day or even an hour after you’ve sent it, unfortunately.
There are a couple of caveats here. For example, this only works with iMessage. So if you’re messaging someone with a green bubble, you will not be able to edit the message. Nor can you unsend it. Additionally, this only works on iPhones and iPads using iOS 16 and later. As well as Macs using macOS Ventura and later.
How to unsend an iMessage
Much like editing an iMessage, you can unsend it by long-pressing on the message you want to unsend.
Now in this menu, you’ll see an option for “Undo Send”. Just tap on that, and you’ll see the message vanish.
The user will still see that a message was sent, and then unsent. So do keep that in mind. And they might also still see the notification for the message, depending on how quickly you unsent it.
And that’s it. That is how you can edit and/or unsend a message in iMessage.
NCR, a major player in the US payments industry, admitted it was a target of a ransomware attack for which the BlackCat/Alphv group claimed responsibility.
On April 12, NCR revealed that it was looking into an “issue” with its Aloha restaurant point-of-sale (PoS) system.
The business announced an outage at a single data center had affected just a few of its hospitality customers’ ancillary Aloha applications on April 15.
“On April 13, we confirmed that the outage was the result of a ransomware incident. Immediately upon discovering this development we began contacting customers, engaged third-party cybersecurity experts and launched an investigation. Law enforcement has also been notified,” NCR said.
NCR is a software and technology consulting firm in the United States that offers restaurants, enterprises, and retailers digital banking, POS systems, and payment processing solutions.
Since Wednesday, one of its products, the Aloha POS platform used in the hospitality industry, has been down, making it impossible for customers to use.
Ransomware Attack That Led to the Outages
After going silent for many days, NCR finally revealed today that the Aloha POS platform’s data centers were the target of a ransomware attack that triggered the outage.
“As a valued customer of NCR Corporation, we are reaching out with additional information about a single data center outage that is impacting a limited number of ancillary Aloha applications for a subset of our hospitality customers,” reads an email sent to Aloha POS customers.
According to a statement NCR provided to BleepingComputer, just a subset of their Aloha POS hospitality customers are affected by this outage, along with a “limited number of ancillary Aloha applications.”
However, Aloha POS customers have reported on Reddit that the downtime significantly hindered their ability to conduct business.
“Restaurant manager here, small franchise stuck in the Stone Age with around 100 employees. We’re doing the old pen and paper right now and sending to head office. The whole situation is a huge migraine,” a user wrote on the AlohaPOS Reddit.
Other users are anxious about making payroll on time for their employees, with many customers urging that data be extracted manually from the data files until the outage is resolved.
“We have a clear path to recovery and we are executing against it. We are working around the clock to restore full service for our customers,” NCR informed BleepingComputer.
“In addition, we are providing our customers with dedicated assistance and workarounds to support their operations as we work toward full restoration.”
On the data leak site used by the BlackCat/ALPHV ransomware gang, cybersecurity researcher Dominic Olivieri saw a short-lived post where the threat actors took ownership.
A section of the negotiation dialogue between the ransomware gang and an alleged NCR official was also included in this post.
In his discussion, the ransomware group allegedly informed NCR that they had not stolen any server-stored data during the attack.
Threat actors stated that they had stolen login information for NCR’s customers and threatened to publish it if a ransom was not paid.
“We take a lot of credentials to your clients networks used to connect for Insight, Pulse, etc. We will give you this list after payment,” the threat actors told NCR.
BlackCat has since removed the NCR post from their data breach website, hoping the firm will agree to discuss a ransom.
With a highly advanced encryptor that allowed for extensive attack customization, the BlackCat ransomware gang began operating in November 2021 and had ransom demands ranging from $35,000 to over $10 million.
Internally, the threat actors use ALPHV when discussing their activities in negotiations and hacker forums.
ChatGPT, a machine learning (ML)-powered chatbot, is rapidly growing across all sectors. The app’s developer, OpenAI, reported that it gained one million users in just five days. The app has now been visited over two billion times, according to research by Similarweb. This being said, concerns have been raised about the use of the intelligent chatbot, with Italy’s data privacy agency even going so far as to temporarily ban the use of the app in the country over concerns that it violates GDPR law.
Due to the app’s impact on the sector, Cyber Security Hub’s Advisory Board members discussed ChatGPT’s impact on the industry in its March meeting.
Cyber Security Hub’s Advisory Board is a group of experts in IT security and technology that meets every two months to discuss the most important issues and developments in cyber security.
When discussing whether they use AI in their cyber security strategy, however, one member was quick to point out that common misconceptions about what AI is can muddy the waters when discussing its use.
“AI is a huge buzzword at the moment but what people are talking about is not true AI as such,” they explained, “We use a lot of ML as we need to understand all user behavior analytics from ingress points through to instruction. AI is instruction-based and ML is behavior-based.”
Another member agreed that they do not use as much AI as the technology is still in its infancy, however they do use machine learning as it can use data to make predictions in a fraction of the time it would take a human to. They also noted, however, that true AI may open up more risks to a company’s network. This potential risk has led to the member “follow[ing] trends more on the conservative side, leveraging people and using technology as a blend to get the best results”.
The future of artificial intelligence and machine learning
When considering how and when AI and ML will be integrated into most if not all cyber security solutions, a member said this will happen once those in the cyber security industry realize that they cannot change human behavior.
“You can positively or negatively reinforce behaviors. It is great to automate and great to use AI but it also needs the human, we should not forget that we cannot have a tool for everything,” they shared.
Another member agreed, saying that AI and ML will continue to progress in the workforce as cyber security itself has a lack of people who wish to get involved and gain experience, choosing to rely on technology instead.
“You can positively or negatively reinforce behaviors. It is great to automate and great to use AI but it also needs the human, we should not forget that we cannot have a tool for everything.”
“Innovation is becoming so critical in all areas that we need to keep pushing the needle forward. It is exciting but scary, because you can have the machine do things that usually need multiple people with the click of a mouse. What you can get from ChatGPT used to take hours or days, but people always have to be part of the process as long as there are people to do it. I don’t know if there are enough people coming in [to the cyber security space].”
Based on this, members agreed that behavioral scientists will be involved in the expansion of machine learning especially, as they will be able to drive machine learning algorithms and allow them to anticipate decision trees to quickly make decisions or provide several avenues for the decision.
With this being said, one member clarified that AI and machine learning will never truly overtake humans, even if it does manage to catch up with the speed of human thought: “AI and ML will supersede but as soon as processing power catches up to brain power it will take over. It still needs the human, however. Social media and cyber warfare will drive the AI and ML evolution forward”.
Why cyber security professionals are concerned about ChatGPT
When discussing this concern at the meeting, one Advisory Board member described that they had already noticed ChatGPT being used to make cyber attacks more sophisticated within their company.
They explained that they see about 37,000 phishing campaigns weekly and have recently noticed that malicious actors have gone from using broken or misspelled English to “prim and proper” language. The member suspected that they have started using ChatGPT to craft a style that helps them with their English.
The member also noted that ChatGPT is also helping malicious actors to understand the psychology of the recipient and better put them under duress to increase the effectiveness of their phishing attempts. To combat this, people have been developing anti-GPT solutions, including one that can tell whether content has been typed by a human or systematic programming.
“AI and ML will supersede but as soon as processing power catches up to brain power it will take over. It still needs the human, however. Social media and cyber warfare will drive the AI and ML evolution forward”.
Another member dubbed ChatGPT as “cool but scary” because of its potential to be used by bad actors.
“Phishing is the number one attack surface and [malicious actors] will use it to make scams more realistic. It will be the voice of spear phishing and targeted spear phishing will be enhanced due to ChatGPT. It is just another way to increase their success with their attacks.
“When you talk about malware or ransomware, bad actors [may use] third parties as ransomware, [but] now we may see them using ChatGPT and eliminating the third party. There is lots of good but there is always something bad to do with it,” they explained.
Later on in the discussion, a member noted that ChatGPT may also cause an issue within cyber security teams, as if their development team is using ChatGPT to generate code and then using this within their platform, the code may be unsafe and open their network up to a number of threats. They said that this problem may be exacerbated if companies are constantly hiring new developers, as they may feel reliant on ChatGPT to complete their work quickly.
The member explained that employees may take code from ChatGPT without reviewing it first as it is human nature to trust sources, even if these sources come via the internet. They noted that those in cyber security must move quickly to stay on top of technological changes, like the development of AI, as well as to mitigate the aspects of human behavior and psychology that are a threat to cyber security.