Innovative tools for binary options strategies

0
[ad_1]

In the fast-paced world of financial trading, binary options offer a unique opportunity for traders to capitalize on market movements with a clear risk-reward proposition. However, navigating the binary options market requires more than just intuition; it requires a solid strategy, precision timing, and the use of innovative tools to enhance decision-making and maximize profits. In this comprehensive guide, we’ll delve into the world of binary options strategies and explore the cutting-edge tools that can give traders an edge.

image1 (1)

Understanding Binary Options

Before diving into strategies and the best tools available for Binary Options Trading, it’s crucial to understand what binary options are. Binary options are financial instruments that allow traders to speculate on the price movement of an underlying asset, such as stocks, commodities, indices, or currencies. The outcome is binary; either the trade finishes in the money (profit) or out of the money (loss), based on whether the asset’s price is above or below a certain point at the expiry time.

Developing a Solid Strategy

A successful binary options trader doesn’t rely on luck; they have a well-thought-out strategy that takes into account market analysis, risk management, and timing. Strategies can range from technical analysis, which involves chart patterns and indicators, to fundamental analysis, focusing on economic indicators and news events. The key is to find a strategy that suits your trading style and stick to it with discipline.

The Role of Innovative Tools

In the digital age, traders have access to a variety of tools that can significantly enhance their trading efficiency and effectiveness. Here are some of the most innovative tools for binary options strategies:

1. Technical Analysis Software

Technical analysis software provides traders with advanced charting capabilities, real-time data, and a plethora of technical indicators. These tools allow traders to analyze historical price action and predict future movements more accurately. Popular software includes MetaTrader 4/5, TradingView, and Thinkorswim.

2. Economic Calendar

An economic calendar is an indispensable tool for traders who employ fundamental analysis. It lists upcoming economic events, such as GDP announcements, interest rate decisions, and employment data, which can have significant impacts on the markets. By staying informed about these events, traders can make more educated predictions about market movements.

3. Binary Options Signals

Signals are essentially recommendations or tips on binary options trades, usually based on technical or fundamental analysis performed by experienced traders or algorithms. While signals can be incredibly useful, it’s important for traders to vet the source of their signals to avoid scams.

4. Risk Management Tools

Effective risk management is crucial in binary options trading. Tools that help manage risk include position sizing calculators, which help traders determine the optimal amount to invest based on their risk tolerance and account size, and stop-loss orders, which automatically close out a trade at a predetermined loss threshold.

5. Automated Trading Bots

For those looking to automate their trading strategy, there are numerous trading bots available that can execute trades based on predefined criteria. While automated trading can save time and help maintain discipline, it’s important to monitor these bots closely, as market conditions can change rapidly.

6. Social Trading Platforms

Social trading platforms allow traders to follow the trades of more experienced or successful traders. This can be a great way for beginners to learn and for experienced traders to gain insights from their peers.

7. Mobile Trading Apps

In today’s world, being able to trade on the go is crucial. Mobile trading apps ensure that traders can execute trades, monitor markets, and manage their accounts from anywhere, at any time. Most reputable brokers offer mobile apps that are robust and user-friendly.

image3

Combining Tools and Strategies for Success

The most successful traders don’t rely on a single tool or strategy; they use a combination to adapt to changing market conditions and enhance their decision-making process. For instance, a trader might use technical analysis software to identify potential trades, an economic calendar to avoid trading during volatile news events, and a position sizing calculator to ensure they’re not overexposed on any single trade.

Expanding Your Trading Toolkit: Beyond the Basics

While the tools mentioned are essential for every binary options trader, expanding your toolkit can significantly enhance your trading capabilities. Advanced charting tools, volatility trackers, and market sentiment indicators can provide deeper insights into market movements and trader behavior.

– Advanced Charting Tools: Beyond basic technical analysis software, there are platforms that offer more sophisticated charting capabilities, including customizable indicators and the ability to backtest strategies against historical data.

– Volatility Trackers: Tools that monitor and report on the volatility of assets can help traders anticipate significant market movements.

– Market Sentiment Indicators: Understanding the general sentiment among traders can provide clues about future price movements. Tools that aggregate sentiment from various sources can be particularly useful.

Comparison of Advanced Charting Platforms

Screenshot 2024 06 17 15 13 08

The Importance of Community and Education in Binary Options Trading

Engaging with a community of traders and prioritizing education are critical steps for success in binary options trading. Through forums, webinars, and online courses, traders can gain insights, learn new strategies, and stay updated on market trends.

– Forums and Discussion Boards: Places where traders can share experiences, strategies, and advice.

– Webinars and Online Courses: Educational resources that cover various aspects of binary options trading, from beginner to advanced levels.

Key Benefits of Engaging with Trading Communities

– Access to a wealth of trading knowledge and experience

– The opportunity to learn from successful traders

– Support during challenging trading periods

Backtesting Strategies: The Key to Confidence and Improvement

Backtesting your trading strategies against historical data is crucial for refining your approach and building confidence. This process allows traders to assess the viability of a strategy before risking real money.

– Importance of Historical Data: Understanding past market conditions and how they affect your strategies.

– Tools for Backtesting: Software that allows traders to simulate strategies against historical market data.

Essential Components for Effective Backtesting

– A comprehensive dataset of historical price movements

– A clear set of trading strategy rules for entry, exit, and money management

– The ability to simulate trades under various market conditions

image2

Navigating Regulatory Considerations and Ensuring Compliance

Binary options trading is subject to regulatory oversight, which varies by jurisdiction. Staying informed about these regulations and ensuring compliance is vital for traders to avoid legal issues and penalties.

Regulatory Bodies and Key Regulations in Major Markets

Screenshot 2024 06 17 15 16 26

By incorporating these additional sections into the guide, traders can gain a more holistic view of binary options trading. Not only do they learn about the tools and strategies needed for success, but they also understand the importance of community, education, backtesting, and regulatory compliance in shaping a successful trading career.

Mastering the Psychological Game in Trading

The psychological component of trading is as critical as the strategic and analytical elements. Achieving success in binary options trading demands not just a mastery of market analysis but also a deep understanding of one’s own emotions and behaviors. Emotional control is paramount, requiring traders to manage fear and greed effectively.

Developing a resilient trading mindset involves fostering qualities such as patience, discipline, and a commitment to ongoing learning. Additionally, incorporating stress management techniques like meditation, regular physical activity, and ensuring sufficient rest can help maintain mental clarity and emotional stability.

Traders must be wary of psychological pitfalls such as overconfidence following a series of wins, the urge for revenge trading after losses, and the confirmation bias, where one might only seek information that confirms pre-existing beliefs or predictions, potentially leading to missed signals or flawed decisions.

Staying Ahead: The Evolution of Binary Options Trading Tools

The landscape of binary options trading is continually transformed by technological advancements, making it essential for traders to stay informed about the latest tools and trends. The integration of artificial intelligence (AI) and machine learning into trading algorithms is providing unprecedented accuracy in market predictions and the automation of complex strategies.

Meanwhile, blockchain technology is being increasingly utilized in trading platforms, offering enhanced levels of transparency, security, and trust. Innovations in mobile trading are also significant, with ongoing enhancements to apps enabling traders to execute decisions swiftly and stay updated with market movements instantaneously. Looking towards the future, emerging technologies such as quantum computing and augmented reality (AR)/virtual reality (VR) promise to further revolutionize the trading experience.

Quantum computing holds the potential for processing massive datasets at incredible speeds, offering a significant advantage in market analysis. AR and VR technologies could transform how traders interact with market data, providing immersive and intuitive ways to analyze trends and execute trades.

Incorporating an understanding of the psychological challenges of trading and staying abreast of technological advancements are crucial steps towards becoming a more proficient and successful binary options trader. These elements underscore the importance of a holistic approach to trading, combining effective strategy, psychological resilience, and technological savvy.

Conclusion

Binary options trading offers a unique opportunity for profit in the financial markets, but it comes with its own risks. By developing a solid strategy and leveraging innovative tools, traders can significantly increase their chances of success. Remember, the key to success in trading is not just in the tools you use but in the discipline, research, and continuous learning you apply to your trading practice. As the binary options market continues to evolve, so too should your strategies and tools, ensuring you remain at the cutting edge of trading technology.


[ad_2]
Source link

Microsoft Recommends Always-On VPN; Deprecates DirectAccess

0
[ad_1]

Microsoft alerts organizations, particularly those using remote access features on their networks, to migrate to the ‘Always-On VPN’ feature as the tech giant deprecates the Windows DirectAccess solution.

Microsoft Deprecates Windows DirectAccess, Confirming Feature Removal In the Future

According to a recent announcement, Microsoft plans for Windows DirectAccess removal in future releases as it deprecates the feature starting this month.

Windows DirectAccess has long been a remote access solution widely used in organizations for securing remote access to the company networks. It facilitated direct secure connections, ditching the conventional procedure of connecting and disconnecting VPNs. Hence, a remote client could connect to the organization’s network without requiring a VPN, simultaneously allowing easy access to the IT admins to their systems.

However, Microsoft observed some limitations with DirectAccess, which modern VPN connections address better.

As highlighted, the ‘Always-On VPN’ functionality allows more secure connections without requiring recurrent connections/disconnections with Windows VPNs. Moreover, it offers better support for contemporary VPN protocols and empowers IT admins to choose which apps use the VPN connection. Besides, Always-On VPN works equally well for domain-joined and non-domain-joined users, unlike DirectAccess, which only works with the former.

Considering these strengths of the DirectAccess successor, Microsoft now recommends all users migrate to the Always-on VPN while the tech giant deprecates DirectAccess. The firm urges organizations to complete this migration at the earliest to avoid possible downtimes and connection issues in the future.

Though Always-On VPN isn’t a new feature, it remained in use in tandem with the widely used DirectAccess. Therefore, Microsoft has decided on a gradual phase-out of this feature, sharing a detailed guideline for migration to Always-On VPN as the firm goes ahead with DirectAccess depreciation.

In future releases, Microsoft plans to completely remove this feature, leaving the Always-On VPN as the prime technology for securing remote network connections.

Let us know your thoughts in the comments.


[ad_2]
Source link

Ulefone kicks off Summer Sale, up to 69% off

0
[ad_1]

Ulefone has launched its Summer Sale event and is offering discounts of up to 69%. The company’s latest handsets, the Ulefone Armor 25T Pro and Armor 26 Ultra are discounted too. As per usual, the sale is conducted via AliExpress. Ulefone has its store there.

The sale kicked off today and will last until June 23, in case you’re wondering. Various different devices are available. We’ll highlight some of them in this article, while you’ll be able to access the rest via the link below the article.

The Ulefone Summer Sale 2024 is ongoing, and the Armor 25T Pro is one of the discounted devices

The main phone worth highlighting is the Ulefone Armor 25T Pro. This is the company’s flagship which not only comes with thermal imaging and night vision capabilities, but it’s also a rugged phone with a large battery.

Ulefone Armor 25T Pro (1)

This smartphone also delivers 5G connectivity, and it’s usually priced at $499.99. Thanks to this sale, you’ll be able to save up $210. The phone is priced at $289.99 at the moment.

Buy the Ulefone Armor 25T Pro (AliExpress)

The Ulefone Armor 26 Ultra is 40% off

The Ulefone Armor 26 Ultra is also discounted, both its standard and Walkie-Talkie versions. This phone comes with a truly powerful speaker on its back, a speaker that provides 121dB of loudness.

Ulefone Armor 26 Ultra (2)

A gigantic 15,600mAh battery is also included, and the same goes for 120W charging. There is a 200MP camera placed on the back as well. This handset is also referred to as a ‘flagship’ by the company.

The standard model of this phone is priced at $359.99 (40% off), while the Walkie-Talkie model costs $419.99 (40% off).

Buy the Ulefone Armor 26 Ultra (AliExpress)

Buy the Ulefone Armor 26 Ultra Walkie-Talkie (AliExpress)

The company’s best tablet is discounted, and a number of other devices

Armor Pad 3 Pro

If you’re in need of a tablet, the Ulefone Armor Pad 3 Pro can be yours for $279.99. It’s 50% off. The Ulefone Note 18 Ultra is also discounted, as it’s now available for $149.99 (50% off). Check out those phones and all the others via the links below.

Buy the Ulefone Armor Pad 3 Pro (AliExpress)

Buy the Ulefone Note 18 Pro (AliExpress)

Ulefone’s Summer Sale 2024 (AliExpress)


[ad_2]
Source link

Google will push AI features despite slip-ups

0
[ad_1]

Google is one of the biggest AI companies in the world, but that doesn’t mean that its AI is all that good. As powerful as the Gemini-powered products are, they certainly make a bunch of mistakes. Well, the newly-appointed Google Search head said that Google will continue to push AI features despite slip-ups.

No AI tool is without its mishaps, but Google seems to be the company making the most blunders with its tools. Bard’s first hallucination happened when it was unveiled, Gemini’s image generator was making racially inaccurate pictures, and we can’t forget about the whole glue-on-pizza debacle.

Google will launch AI features despite slip-ups

You’d think that, with all of the mess-ups that Google’s AI tools have gone through, the company would slow things down and really make sure that its tools are functional before launching them. Well, you’d think wrong!

The newly-appointed head of Google Search, Liv Reid, spoke to Google’s employees in a company-wide meeting. CNBC was able to obtain audio from the meeting, and it revealed Google’s problematic approach to AI. “It is important that we don’t hold back features just because there might be occasional problems, but more as we find the problems, we address them,” she said. “When we find new problems, we should do the extensive testing but we won’t always find everything and that just means that we respond.”

So, it sounds like she’s suggesting that the company roll out new features and address the problems after they arise. That seems like the company’s plan ever since it launched Bard, so what’s new? Of course, other models have had issues in the past, but when was the last time that a large ChatGPT slip-up made the news? What was the last time DALL-E had to be rolled back due to a massive error?

Google is a large and powerful company, but it’s rushing. How much longer will this go on until people start losing faith in its products? Sure, if users start to lose faith, that’ll be bad, but once investors start to lose faith, that’s when the company might need to panic.


[ad_2]
Source link

Hunt3r Kill3rs Group claims Infiltrated Schneider Electric Systems

0
[ad_1]

The notorious cybercriminal group Hunt3r Kill3rs has claimed responsibility for infiltrating Schneider Electric’s systems in Germany.

The announcement was made via a post on the social media platform Twitter by the account MonThreat, which is known for tracking cyber threats and activities.

Details of the Breach

The Hunt3r Kill3rs group breached Schneider Electric’s systems, potentially compromising sensitive data and critical infrastructure.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot

Schneider Electric, a global leader in energy management and automation, has a significant presence in Germany, making this breach particularly concerning for the company and its clients.

The exact nature of the data compromised has not been disclosed, but experts suggest that the breach could have far-reaching implications, given Schneider Electric’s role in managing critical infrastructure.

The company has yet to release an official statement regarding the breach, but sources indicate that an internal investigation is underway.

Cybersecurity experts have expressed alarm over the breach, highlighting the increasing sophistication of cybercriminal groups like Hunt3r Kill3rs.

“This incident underscores the urgent need for robust cybersecurity measures, especially for companies involved in critical infrastructure,” said Dr. Laura Stein, a cybersecurity analyst at the Berlin Institute of Technology.

“The potential fallout from such breaches can be catastrophic, affecting not just the company but also the broader economy and public safety.”

Government Response

In response to the breach, German authorities have initiated a comprehensive review of cybersecurity protocols for companies involved in critical infrastructure.

The Federal Office for Information Security (BSI) has been alerted and is collaborating with Schneider Electric to assess the extent of the breach and mitigate any potential damage.

This incident is a stark reminder of the ever-present threat cybercriminals pose and the need for continuous vigilance and investment in cybersecurity.

As the investigation continues, both Schneider Electric and German authorities are expected to provide further updates

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

Microsoft Recall delayed after privacy and security concerns

0
[ad_1]

Microsoft has announced it will postpone the broadly available preview of the heavily discussed Recall feature for Copilot+ PCs. Copilot+ PCs are personal computers that come equipped with several artificial intelligence (AI) features.

The Recall feature tracks anything from web browsing to voice chats. The idea is that Recall can assist users to reconstruct past activity by taking regular screenshots of a user’s activity and storing them locally. The user would then be able to search the database for anything they’ve seen on their PC.

However, Recall received heavy criticism by security researchers and privacy advocates since it was announced last month. The ensuing discussion saw a lot of contradictory statements. For example, Microsoft claimed that Recall would be disabled by default, while the original documentation said otherwise.

Researchers demonstrated how easy it was to extract and search through Recall snapshots on a compromised system. While some may remark that the compromised system is the problem in that equation—and they are not wrong—Recall would potentially provide an attacker with a lot of information that normally would not be accessible. Basically, it would be a goldmine that spyware and information stealers could easily access and search.

In Microsoft’s own words:

“Recall does not perform content moderation. It will not hide information such as passwords or financial account numbers. That data may be in snapshots that are stored on your device, especially when sites do not follow standard internet protocols like cloaking password entry.”

Microsoft didn’t see the problem, with its vice chair and president, Brad Smith even using Recall as an example to demonstrate how Microsoft is secure during the Committee Hearing: A Cascade of Security Failures: Assessing Microsoft Corporation’s Cybersecurity Shortfalls and the Implications for Homeland Security.

But now things have changed, and Recall will now only be available for participants in the Windows Insider Program (WIP) in the coming weeks, instead of being rolled out to all Copilot+ PC users on June 18 as originally planned.

Another security measure taken only as an afterthought was that users will now have to log into Windows Hello in order to activate Recall and to view your screenshot timeline.

In its blog, Microsoft indicates it will act on the feedback it expects to receive from WIP users.

“This decision is rooted in our commitment to providing a trusted, secure and robust experience for all customers and to seek additional feedback prior to making the feature available to all Copilot+ PC users.”

Our hope is that the WIP community will convince Microsoft to abandon the whole Recall idea. If not, we will make sure to let you know how you can disable it or use it more securely if you wish to do so.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

The Zenfone 11 Ultra shows up in a new beautiful color

0
[ad_1]

The ASUS Zenfone series of phones isn’t quite a trailblazer in the smartphone industry, but it’s still a great series of devices. The latest line in the series, the Zenfone 11, launched three months ago, but ASUS isn’t done with new releases. ASUS just launched the Zenfone 11 Ultra (Review) in a beautiful green color.

Feast your eyes on the new green Zenfone 11 Ultra

The official name of this color is called Verdure Green. The word “Verdure” means the greenness of growing vegetation. It has roots (no pun intended) in Anglo-French, and it’s been used since at least the 14th century. While the word’s roots stretch back hundreds of years, the colorway was inspired by something that exists in modern times.

According to the report, this green color was inspired by Central Park, New York City. “Inspired by NYC’s Central Park, this stylish shade blending nature and technology is now part of the Zenfone 11 family.” That’s a quote from the post on the ASUS Twitter account.

Zenfone 11 Ultra Green 2

One notable thing about this color is the fact that the entire back of the phone is clad in this lush green color; this includes the camera bump. The other colors of the phone (Eternal Black, Misty Gray, Skyline Blue, and Desert Sand) have a black camera bump. The Verdure Green colorway stands out by being a complete wash of green.

Zenfone 11 Ultra specs

While ASUS gave this phone a new paint job, everything under the hood is the same. If you pick up this phone, you’re still getting the powerful Snapdragon 8 Gen 3 backed up by 12GB of RAM and 256GB of storage.

The Zenfone 11 Ultra has a 6.78-inch AMOLED display with a 1080p+ resolution. As for the refresh rate, this is a 120Hz display. It’s an LTPO panel, which means that it can drop its refresh rate down to as low as 1Hz.

Moving onto the camera, this phone has a 50MP main camera, and that’s accompanied by a 13MP ultrawide camera and a 32MP telephoto camera. Rounding out the specs, there’s a large 5,500mAh battery with 65W charging (15W wireless charging).

Pick up the Zenfone 11 Ultra – $899


[ad_2]
Source link

ARM’s ‘TIKTAG’ attack affects Google Chrome and Linux systems

0
[ad_1]

Recently, a team of Korean researchers from Samsung, Seoul National University, and Georgia Institute of Technology have tested a new speculative execution attack called TIKTAG. Quite surprisingly, this specially designed attack targets ARM’s Memory Tagging Extension allowing data leakage with a success rate higher than 95%. The practical implications of this discovery are significant as it enables hackers to bypass key protection mechanisms against memory corruption.

Understanding ARM’s memory tagging extension

Integrated as a base option with the ARM v8. Specifically, 5-A architecture, MTE is an enhancement in dealing with the memory corruption problem, which is one of the biggest categories of security issues. Lower overhead tagging is used in MTE with tags in the size of four bits allocated to 16-byte memory blocks. This mechanism helps in ascertaining that the pointer attached to a tag asserts to the tag of the memory region being accessed hence reducing cases of unauthorized memory access and abuse.

MTE, as indicated earlier, exists in three categories namely; synchronous, asynchronous as well as asymmetric and each comes with balanced type of security and performance. Still, the TIKTAG attack highlights system vulnerabilities, showing even top-level protection can be defeated.

ARM's 'TIKTAG' attack affects Google Chrome and Linux systems
Image credit: arxiv.org

The researchers observed two main programs with high efficiency and speed, including TIKTAG-v1 and TIKTAG-v2, which targeted speculation execution to leak MTE memory tags.

TIKTAG-v1: branch prediction and data prefetching

The features used in TIKTAG-v1 include the speculation shrinkage in branch prediction and the data prefetching of the CPU. This gadget has been resistive to the Linux kernel especially in the functions that involve memory speculations. Malicious code alters kernel pointers and uses cache side channels through system call function calls; they then access and measure the states of a cache to obtain memory tags.

tiktag 1
Image credit: arxiv.org

TIKTAG-v2: store-to-load forwarding

TIKTAG-v2 focuses on the store-to-load forwarding in timing speculation of the processor. The first step is storing the value to a memory address and loading it from the same address simultaneously. The value is passed to the next tag, successfully loading and changing the shared cache state. On the other hand, a mismatch prevents the forwarding, the cache state remains in the same state. If attackers examine cache state after speculative execution, they can deduce tag check outcome.

TIKTAG-v2 was proved to be effective against the target vulnerable process – the Google Chrome browser, with an emphasis on the parts including the V8 JavaScript engine: the exploitation of memory corruption vulnerabilities in the renderer process has been shown here in this paper as well.

tiktag 2
Image credit: arxiv.org

Implications and industry response

The leakage of MTE tags is not tied to the leakage of passwords, encryption keys, etc. However, it effectively weakens the security that MTE claims to offer. Therefore, enabling memory corruption attacks that are surreptitious in nature. The field research ended in November and December 2023, with the team submitting findings to the entities. While the general reception has been quite positive, there were no quick Band-Aids immediately applied.

In a technical paper deposited on a repository known as arxiv.org, the researchers suggested several mitigations to counter TIKTAG attacks. First, do not allow speculation to modify cache states after the tag check is done. Second, enclosing speculation barriers (‘sb’ or ‘isb’ instructions) helps prevent executing sensitive memory procedures. Third, pad for additional time between branch instructions and memory accesses with padding instructions.  Finally, enhance the sandboxing strategies to limit the constructiveness proactively of AMAs in sensible memory spaces as securely as possible.

mte bypass
Image credit: arxiv.org

ARM and Chrome’s responses

ARM understood that the TIKTAG attack was very strong and then pointed out that it is still safe to disclose the tags for allocation at the architecture level using speculative methods. Their bulletin stressed that allocation tags are not covert in the address space.

On the other hand, Google Chrome’s security team pointed out these issues but chose not to fix them and noted that the V8 sandbox does not keep memory data and MTE tags secret. Also, as of now, Chrome does not have MTE-based defenses enabled, so fixing the bugs is not urgent.

Although the Pixel 8 device MTE oracles mechanism was later disclosed to the Google Android security team in April 2024 and confirmed as a hardware issue that qualified for a bounty. The attacks could not have been possible without exploitation of the Pixel 8 device’s boot and recovery images.


[ad_2]
Source link

Chrome on Android gains a new “Listen to this page” feature with playback controls

0
[ad_1]

Last year, Google experimented with a read-aloud feature for Chrome on desktop, but it hasn’t been publicly released yet. Now, a similar feature is making its way to Chrome users for Android.

Chrome on Android now includes a feature that allows it to read webpages out loud right from within the app


Google is adding a new feature called “Listen to this page” to the Chrome browser for Android. This feature lets you hear a webpage read aloud, and it includes playback controls similar to those in music or podcast apps. You can pause, change the reading speed, skip forward or backward by 10 seconds, and scrub through the content.

After you choose the “Listen to this page” option, a player will pop up, featuring a progress bar and controls for play/pause, as well as options to skip forward and rewind. At the bottom corners of the player, there are two functions.


On the left side, you can adjust the playback speed from 0.8x to 4x. Meanwhile, the bottom-right corner of the player includes a triple-dot menu where you can access additional settings like Highlight Text & Auto Scroll and Voice.


Yes, you can also tweak the voice and switch up the language. Google’s help page mentions that this feature supports a variety of languages, like English, French, German, Arabic, Hindi, Spanish, Japanese, and more.


To check if you have it, navigate to a text-heavy page, then tap the three-dot menu and look for “Listen to this page,” positioned just below the Translate option.


You can also have Google Assistant read webpages aloud and translate them into other languages at the same time. However, when you choose this option, it switches you from Chrome to the Google app, whereas the new feature lets you stay within your browser.


This feature is particularly handy when you want to catch up on, let’s say, the news while multitasking. Safari for iPhone also offers a similar feature called “Listen to Page,” which reads webpages using Siri’s voice and includes similar controls to Google’s.

 
Google appears to be rolling out this feature gradually with Chrome version 125, so it may take some time before you notice it. If you haven’t received it yet, hang tight — it is on its way.


[ad_2]
Source link

Operation Celestial Force Employing Android & Windows Malware

0
[ad_1]

A Pakistani threat actor group, Cosmic Leopard, has been conducting a multi-year cyber espionage campaign named Operation Celestial Force, targeting Indian entities.

Since 2018, they have used GravityRAT malware, initially for Windows and later for Android, which has been deployed through malicious documents and social engineering

In 2019, they expanded their toolkit with HeavyLift, a malware loader distributed via fake installers, where each campaign within the operation is managed by custom “GravityAdmin” panels, highlighting the need for user education on cyber hygiene and implementing defense-in-depth security models. 

 Malicious drop site delivering HeavyLift. 

Operation Celestial Force, a cyberespionage campaign targeting Indian entities, uses two main infection vectors: spearphishing emails with malicious documents and social engineering on social media to trick targets into downloading malware.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot

The malware suite includes GravityRAT, a remote-access Trojan for Windows and Android, and HeavyLift, a Windows malware loader.

The operators manage these tools with a multi-paneled administrative interface called GravityAdmin. 

Operation Celestial Force’s infection chains

GravityAdmin is a malware framework used to manage various malicious campaigns. The panel binary authenticates users with a server and retrieves a token to communicate with campaign-specific C2 servers. 

Different campaigns target different platforms (Windows and Android) and deploy different malware families (GravityRAT and HeavyLift).

There are infrastructure overlaps between campaigns, such as sharing malicious domains to host payloads or maintaining infected machine lists. 

 Login screen for GravityAdmin titled “Bits Before Bullets.” 

GravityRAT, a multi-platform remote access trojan, first targeted Windows machines but has since expanded to Android devices, which are likely used by Pakistani actors against Indian targets and spread through fake app websites and social media. 

New variants steal user data (SMS, call logs, files), device information (IMEI, location), and even associated email addresses.

The malware communicates with hidden command-and-control servers and can wipe data on infected devices. 

 The group uses Cloudflare service to hide the true location of their C2 servers. 

HeavyLift, an Electron-based malware loader, is disguised as an installer and deployed through social engineering, which communicates with C2 servers to steal system information (including username, MAC address, and OS version) and download malicious payloads. 

These payloads are executed persistently on the compromised system using crontab for macOS and scheduled tasks for Windows. The malware also implements anti-analysis techniques to evade detection in virtual environments.  

The provided Indicators of Compromise (IOCs) by Cisco Talos are hashes of malicious files, domains, and URLs that are associated with Android malware, including HeavyLift, GravityRAT Android, and GravityAdmin. 

The URLs contain suspicious parameters and may be used to exploit vulnerabilities on Android devices, and by checking these IOCs against files, network traffic, and URLs, security researchers can identify potential infections.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link