Apple reportedly faces billions in fines for failing to comply with Europe’s Digital Markets Act

0
[ad_1]
Apple made a number of changes to the iPhone in Europe to adhere to the EU’s Digital Markets Act (DMA). The DMA has forced Apple to allow iPhone users to sideload apps from third-party app stores, and use third-party browsers that run on non-WebKit engines. The DMA also allows developers to give consumers in-app options for making payments that bypass Apple’s in-app payment platform.
According to the Financial Times, the European Commission is not happy with Apple’s Core Technology Fee and plans to charge the company for failing to be in compliance with the DMA. If Apple is found not to have complied with the DMA, it will face a fine of up to 10% of its average annual worldwide revenue. In fiscal 2023, Apple took in $383 billion which means that it could be on the hook for a hefty $38.3 billion fine. Companies that repeatedly infringe on the DMA face penalties of up to 20% of their global annual revenue.
The tech giant imposes the Core Technology Fee fee on developers who decide to be governed by Apple’s new App Store rules in the 27 EU countries. These new rules allow the developers to use  alternative payment processors for their App Store apps in the EU listed throughout Apple’s various operating systems. The Core Technology Fee charges developers €0.50 (valued at approximately 54 U.S. cents) for each annual install over one million. Apple does have some rules to protect smaller developers.

Developers in the EU can avoid the Core Technology Fee as long as they continue to follow the old rules and have in-app payments directed to Apple’s in-app payment processing platform. Apple did reduce the so-called “Apple Tax” charged to developers who use its platform for in-app payments from a range of 15%-30% to a lower 10%-17% range.

Back in March, long-time App Store critics like Spotify and Epic Games, along with 32 other firms, wrote a letter to the EC accusing Apple of “making a mockery of the DMA and the considerable efforts by the European Commission and EU institutions to make digital markets competitive.” The letter adds, “The new fee structure in the proposed new terms seems designed to maintain and even amplify Apple’s exploitation of its dominance over app developers.”

While today’s report notes that the European Commission could formally announce charges against Apple during “the coming weeks,” these findings are preliminary and Apple might still have some time to make the necessary changes to iOS that would keep the European Commission off of its back.


[ad_2]
Source link

Google rolls out Pixel VPN update, No Android 14 QPR3 needed

0
[ad_1]
Image credit — Google
Google is rolling out a fresh update for its Pixel VPN app through the Play Store. Interestingly, users of the Pixel 7, 7 Pro, 7a, and Fold won’t need the Android 14 QPR3 update to install it. This is significant news for Pixel 7 users as it brings the replacement for the subscription-based Google One VPN service, which is set to be discontinued on June 20.The updated Pixel VPN made its debut with the Pixel 8 series in October of last year. It boasts a smoother integration compared to its predecessor, eliminating the persistent notification icon that previously occupied the status bar. Now, according to this report, users will only see a discreet key icon on the right side of the status bar when the VPN is active.

This update also includes a rebranding effort, changing the name of the app and service from “VPN by Google One” to simply “VPN by Google” across various areas within the app and system settings. Accompanying this change is a new blue shield icon with a “G” at its center, which will appear in specific locations like the Network & internet settings and the Recent apps screen.

New “VPN by Google” vs old “VPN by Google One” branding | Image credit — 9to5Google

The version number of this updated Pixel VPN app is 1.0.635841321, and it’s currently being rolled out to Pixel 8, 8 Pro, and 8a devices through the Play Store. If you have a Pixel 7 device running Android 14 QPR2 and haven’t received the June Feature Drop yet, you can still install the new VPN by visiting the Google Play listing directly. According to reports, it functions flawlessly even without the latest Android update.After installation, users can set up the VPN by opening it from the app listing and enabling notifications and mobile network usage. It’s important to note that adding the new Quick Settings tile and removing the old one must be done manually.

As a side note, while the Pixel VPN offers enhanced privacy and security for Google Pixel users, it does not allow users to select specific server locations, which may limit its ability to unblock geo-restricted content. It also lacks advanced features like a kill switch, split tunneling, or support for torrenting.

This latest update is a welcome addition for Pixel users, especially those on the Pixel 7 series who will continue to have access to a VPN service even after the Google One VPN is discontinued.

[ad_2]
Source link

Truist bank confirms data breach

0
[ad_1]

On Wednesday June 12, 2024, a well-known dark web data broker and cybercriminal acting under the name “Sp1d3r” offered a significant amount of data allegedly stolen from Truist Bank for sale.

Truist is a US bank holding company and operates 2,781 branches in 15 states and Washington DC. By assets, it is in the top 10 of US banks. In 2020, Truist provided financial services to about 12 million consumer households.

The online handle of the seller immediately raised the suspicion that this was yet another Snowflake related data breach.

Sp1d3r offering Truist bank data for sale
Post by Sp1d3r on breach forum

The post also mentions Suntrust bank because Truist Bank arose after SunTrust Banks and BB&T (Branch Banking and Trust Company) merged in December 2019.

For the price of $1,000,000, other cybercriminals can allegedly get their hands on:

  • Employee Records: 65,000 records containing detailed personal and professional information.
  • Bank Transactions: Data including customer names, account numbers, and balances.
  • IVR Source Code: Source code for the bank’s Interactive Voice Response (IVR) funds transfer system.

IVR is a technology that allows telephone users to interact with a computer-operated telephone system through the use of voice and Dual-tone multi-frequency signaling (DTMF aka Touch-Tone) tones input with a keypad. Access to the source code may enable criminals to find security vulnerabilities they can abuse.

Given the source and the location where the data were offered, we decided at the time to keep an eye on things but not actively report on it. But now a spokesperson for Truist Bank told BleepingComputer:

“In October 2023, we experienced a cybersecurity incident that was quickly contained.”

Further, the spokesperson stated that after an investigation, the bank notified a small number of clients and denied any connection with Snowflake.

“That incident is not linked to Snowflake. To be clear, we have found no evidence of a Snowflake incident at our company.”

But the bank disclosed that based on new information that came up during the investigation, it has started another round of informing affected customers.

Protecting yourself after a data breach

There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.

  • Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened and follow any specific advice they offer.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop or phone as your second factor. Some forms of two-factor authentication (2FA) can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for fake vendors. The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify the identity of anyone who contacts you using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online, and helps you recover after.

Check your exposure

While matters are still unclear how much information was involved, it’s likely you’ve had other personal information exposed online in previous data breaches. You can check what personal information of yours has been exposed with our Digital Footprint portal. Just enter your email address (it’s best to submit the one you most frequently use) to our free Digital Footprint scan and we’ll give you a report.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection.


[ad_2]
Source link

Here’s when the next Galaxy Unpacked will happen

0
[ad_1]

We’ve all been wondering just when Samsung’s going to launch its latest and most exciting phones. Well, wonder no more, as the date for the next Galaxy Unpacked event has just been leaked.

Samsung typically holds two main Unpacked events during the year. We already saw the first one where it introduced us to the Galaxy S24 phones and Galaxy AI. Now, with several major tech events behind us like Google I/O and WWDC, we’re looking forward to the next one.

The date for the next Galaxy Unpacked event just leaked

Evan Blass, the noted leaker, just gave us a nifty sneak peek at when Samsung’s going to host its next event. In the GIF, we see that it’s going to happen on July 10th. Also, there’s this large countdown counting down the days, hours, minutes, and seconds. It’s 25 days from today.

Galaxy Unpacked 2024 leak

This confirms the theory that Samsung is pushing its Galaxy Unpacked events earlier in the year. Last year, Samsung’s second Unpacked event took place on July 26th. That’s more than two weeks later than this year. Also, the Unpacked event in 2020 took place on August 6th. So, Samsung is moving its launches earlier in the year. That might be a good move once Apple eventually launches its foldable devices. It’d be better for the company to create as much space between it and Apple’s launch event as possible.

What we’re expecting

Right now, we know that Samsung is going to announce its latest slew of flagship foldable phones; the Galaxy Z Fold 6 and Galaxy Z Flip 6. We’re in the dark about what models to expect. We’ve been following rumors about Samsung announcing a more affordable Galaxy Fold under the FE series and a more premium model with the Ultra moniker. Also, we’ve been following rumors that the company will launch a more affordable Z Flip phone, but that one might have been squashed.

In fact, we got word that Samsung is raising the price of its Flip phones. The 256GB Galaxy Z Flip 6 could cost $1,099 and the 512GB model could cost $1,229.

Along with its foldable phones, we’re also going to hear about the company’s latest smartwatches. Samsung is most likely going to announce the Galaxy Watch 7 and Galaxy Watch 7 Ultra. It just recently announced the Galaxy Watch FE, which is a rebadged Galaxy Watch 4.

Let’s not forget about AI. Of course, Samsung is going to be talking about what’s new with Galaxy AI and how it’s going to impact the Galaxy experience. So, if you’re excited about what Samsung has in store, mark your calendar!


[ad_2]
Source link

Galaxy Z Fold 6 dummy poses next to Galaxy Z Fold 5

0
[ad_1]

The Samsung Galaxy Z Fold 6 and Flip 6 are right around the corner. As we’re waiting for the launch event, more and more information keeps dropping. Well, in the latest turn of events, the Galaxy Z Fold 6 dummy popped up, and it’s posing next to the Galaxy Z Fold 5.

The Galaxy Z Fold 6 dummy has been shared by a well-known tipster, and compared to Fold 5

If you check out the image below, you’ll see the two phones side by side. This was shared by Ice Universe, a well-known tipster, so the design of this dummy is probably very accurate.

Galaxy Z Fold 6 dummy image 11

You’ll immediately notice that the cover screen on the Galaxy Z Fold 6 is wider. That is something we knew would happen for a long time. That will also make the device wider when opened too.

You’ll also notice that the Galaxy Z Fold 6 has sharper corners compared to the Fold 5. Samsung is doing that to bring it closer to the Galaxy S24 Ultra design language, it seems.

Three additional images have been shared, showing off the design of the upcoming foldable

In addition to that one image we shared above, three additional ones were shared. You can check them out in the gallery below. They’re showing off the Galaxy Z Fold 6 dummy from several angles.

You can clearly see that the phone will have three cameras on the back, with pretty much unchanged placement. The frame around the device will be flat.

The Samsung Galaxy Z Fold 6 and Galaxy Z Flip 6 are rumored to arrive on July 10. The event will allegedly take place in Paris, though Samsung still hasn’t confirmed anything. The Galaxy Ring is also expected to arrive. That device will become the company’s very first smart ring.

The Galaxy Watch 7 series is also expected to launch during the same event, and the same goes for a new pair of Samsung earbuds.


[ad_2]
Source link

Threat Actor Claiming Leak Of 5 Million Ecuador’s Citizen Database

0
[ad_1]

A threat actor has claimed responsibility for leaking the personal data of 5 million Ecuadorian citizens.

The announcement was made via a post on social media tweets from the DarkWebInformer account.

The breach has raised significant concerns about data security and privacy in the country.

Details of the Breach

The threat actor, whose identity remains unknown, posted a message on a tweet stating that they had successfully infiltrated a government database and extracted sensitive information.

The leaked data reportedly includes names, addresses, phone numbers, and national identification numbers.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot

According to cybersecurity experts, the data appears to be authentic, and the scale of the breach is unprecedented in Ecuador.

“This is one of the largest data breaches we have seen in recent years,” said Carlos Mendoza, a cybersecurity analyst.

“The implications for the affected individuals are severe, as this information can be used for identity theft and other malicious activities.”

In response to the breach, the Ecuadorian government has launched an investigation to determine the source and extent of the leak.

The Ministry of Telecommunications and Information Society issued a statement urging citizens to remain vigilant and monitor their accounts for suspicious activity.

“We are taking this matter very seriously and are working with international cybersecurity experts to mitigate the impact of this breach,” the statement read.

The government has also set up a hotline and a dedicated website for citizens to check if their data has been compromised and to receive guidance on protecting themselves.

Public Outcry and Concerns

The news of the data breach has sparked outrage among Ecuadorian citizens, many of whom are demanding greater government accountability and transparency.

Social media platforms are flooded with comments from concerned individuals expressing their frustration and fear over potentially misusing their personal information.

“This is a wake-up call for all of us,” said Quito resident Maria Fernandez. “We need stronger data protection laws and better security measures to prevent such incidents in the future.

“As the investigation continues, the focus remains on identifying the perpetrators and ensuring that the affected citizens receive the necessary support and protection.

The incident is a stark reminder of the growing threat of cyberattacks and the importance of robust cybersecurity measures in safeguarding personal information.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

OnePlus Nord CE4 Lite launch date announced, live photo leaked

0
[ad_1]

The OnePlus Nord CE4 Lite 5G (yeah, that’s a mouthful) is officially set for a June 18 launch. The company’s announcement didn’t explicitly name the device but an Amazon page gave it away. The handset has also leaked in a live photo ahead of its debut next week.

OnePlus announces a launch date for the OnePlus Nord CE4 Lite

There have been some contrasting rumors about the OnePlus Nord CE4 Lite’s launch date. Some said the device will go official in June, while others hinted at an early July unveiling. The company has now settled all the debate. OnePlus India took to X to announce that “your all-day entertainment companion” is arriving on June 18 at 7 PM local time. The post didn’t reveal the device’s name, while the accompanying image only showed its corner.

However, Amazon India didn’t hold back. A “Notify Me” microsite published by the retailer features a similar image with “OnePlus Nord CE4 Lite” in the file name. The page title also names the product and reveals that it will be a 5G handset with 8GB RAM and 128GB storage. There may be more configurations, of course. One of the color variants will be called Mega Blue. This is all we can take away from these official teasers.

OnePlus Nord CE4 Lite 5G official teaser launch date

Meanwhile, a live photo of the OnePlus Nord CE4 Lite has leaked to show its rear design. Posted on X by @gadget_bits—which incorrectly predicted a July launch for the phone—the image confirms a dual camera setup on the back, along with dual LED flash. We can also see “50MP ASPH” imprinted below the cameras, confirming a 50MP primary camera with an aspherical (ASPH) lens, a lens that doesn’t have a spherical surface shape.

The leaked design supports rumors that the OnePlus Nord CE4 Lite is a rebranded OPPO K12x launched in March. A Geekbench listing for the phone confirms the Snapdragon 695 chipset with 8GB RAM and Android 14. If these rebrand rumors are accurate, then we are looking at a 6.67-inch OLED display, an under-display fingerprint scanner, a 16MP selfie camera, stereo speakers, and a 5,500mAh battery with 80W fast charging.

OnePlus Nord CE4 Lite 5G leaked live photo

Another Nord 4 series device is on the way

The OnePlus Nord CE4 Lite will reportedly be available for pre-order immediately after its unveiling on June 18. General sales may begin on June 24. It’s the second model in the series, following the OnePlus Nord CE4 that launched in April. The company has another model in the pipeline. It is readying the standard OnePlus Nord 4 with no CE (Core Edition) or Lite branding. The device is rumored to go official in July.


[ad_2]
Source link

Smishing Triad Hackers Attacks Banking, E-Commerce Platform

0
[ad_1]

Hackers often attack online banking platforms, e-commerce portals, and payment systems for illicit purposes.

Resecurity researchers have recently revealed that the Smishing Triad group has launched a fresh smishing campaign targeting Pakistani mobile users.

The gang members send harmful messages pretending to be Pakistan Post via iMessage and SMS in an attempt to steal personal and financial information.

These continue their previous operations in the:–

Following recent data breaches, the crew is estimated to be sending 50,000-100,000 automated daily smishing messages, using stolen dark web databases containing the phone numbers of Pakistani citizens.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot

Technical Analysis

This huge operation points out that telecom firms should improve their capabilities for identifying fraud and taking a proactive approach by stopping this malicious activity from occurring continuously against clients.

Smishing message (Source – Resecurity)

The Smishing Triad has spread its smishing operations into Pakistan, sending malicious messages claiming to be from Pakistan Post to steal mobile users’ personal and financial information.

Using stolen local phone number databases, the actors send a maximum of 100,000 smishing texts daily, using URL shorteners and QR codes to avoid detection.

Some serve as validation tactics for targeted attacks on active users.

Fake message from Pakistan Post (Source – Resecurity)

The actors exploit these recent data breaches that have exposed Pakistani citizens’ data to pose as legitimate local firms asking for payment details.

This resulted in PKCERT releasing a security advisory on March 27th, 2020, regarding this widespread campaign targeting major Pakistani carriers.

In addition to Pakistan Post, the group also impersonates courier services with fake delivery scams, which shows how their smishing tactics continue evolving across different countries.

Fake Pakistan Post Payment Page (Source – Resecurity)

Besides this, the Smishing Triad group is still attacking victims from all over the world.

They have various hosts and domain names mapped to the same IP address 23.231.48.129 for their smishing kits.

The actors, in addition to impersonating Pakistan’s postal services, recently targeted Correos, Spain’s state-owned postal provider, confirming their previous activities in July 2023.

This shows that the gang keeps operating all the time on a large scale and changing ways of conducting smishing attacks against postal and delivery services across regions like Pakistan and EU.

Mitigations

Here below we have mentioned all the provided mitigations:-

  • Be Skeptical
  • Don’t Respond
  • Verify the Source
  • Don’t Click on Links
  • Use Security Software
  • Report Suspicious Messages
  • Educate Yourself

IOCs

Domain Names:-

  • ep-gov-ppk[.]cyou
  • pk-post-goi[.]xyz
  • pak-post[.]com/id
  • pakpotech[.]top/id

URLs:-

  • l[.]ead[.]me/bf6fB8
  • is[.]gd/bpEPk3
  • l[.]ead[.]me/BjsT
  • is[.]gd/8vcwYW
  • 2h[.]ae/nwxP
  • 2h[.]ae/cNRd
  • ytfrt[.]top/id
  • linkr[.]it/4bStpB
  • qrco[.]de/bf56c0

Phone Numbers:-

  • +923361021455
  • +923301956704
  • +923315640313
  • +601128430746
  • +923301956704
  • +923328862313
  • +923121461238

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

Samsung Galaxy S25 battery capacity has been revealed

0
[ad_1]

The Samsung Galaxy S25 battery capacity has just been revealed. The information comes from GalaxyClub.nl, as the source claims that the battery capacity will remain unchanged. The Galaxy S25 will have a 4,000mAh battery.

The Galaxy S25 battery capacity has seemingly been revealed

As a reminder, both the Galaxy S20 and Galaxy S21 had a 4,000mAh battery. Then Samsung decided to decrease it with the Galaxy S22 (3,700mAh) and Galaxy S23 (3,900). With the Galaxy S24, the company brought back a 4,000mAh unit.

The Galaxy S24 did not have the best battery life, that’s for sure. However, it was notably better than what the Galaxy S22 and Galaxy S23 offered. It was not great, but not exactly bad either. Chances are we’ll get something similar with the Galaxy S25.

Do note that the Galaxy S25 will be the smallest smartphone in the series. The Galaxy S25+ and Galaxy S25 Ultra will be notably bigger, and will thus require bigger battery packs, to power their larger displays.

All three phones are expected to arrive in Q1 2025

The entire Galaxy S25 series is expected to drop in the first quarter of next year. If we had to guess, we’d say that they’re coming in January, as the Galaxy S24 series arrived in January this month.

All three phones are a bit of a mystery at this point. Their designs did not leak out just yet, even though Samsung is not expected to make major changes, but we’ll see. It’s about time for a change so… we’ll see.

The Snapdragon 8 Gen 4 is expected to fuel all three smartphones. The inclusion of Exynos variants remains to be a possibility, though, we’ve seen some conflicting reports on that.

What’s interesting is that the Galaxy S25 is rumored to have a larger display than its predecessor. It will allegedly include a 6.36-inch panel instead of a 6.2-inch one. The Galaxy S25+ and Galaxy S25 Ultra are tipped to retain display sizes.


[ad_2]
Source link

Amazon is trailing behind with its new Alexa

0
[ad_1]

Amazon, Google, and Apple crafted the three best voice assistants on the market. Alexa, Amazon’s assistant was slated to receive a huge generative AI make-over. However, according to a new report, Amazon is falling behind with the new Alexa.

Right now, it’s hard to say what is the best voice assistant on the market. Google Assistant was at the top of the pecking order for a while, but Google has been trimming it down in preparation for Gemini to take over. However, that process has been less than smooth.

In Apple’s camp, Siri is set to get a ton of generative AI goodness through Apple Intelligence. That’s going to make it the best voice assistant on the market, hands down. However, it’s not currently available, so it can’t wear the championship belt just yet. So, the competition is between a handicapped Google Assistant, a half-baked Gemini, the concept of a better Siri, and Alexa.

Amazon is falling behind with its new Alexa

Last Fall, Amazon held an event that was 90% about AI. During the event, the company announced a revamped Alexa that will be powered by generative AI. This technology would make it more conversational and give it the ability to generate content. Rather than being text-based, it would just be vocal. You could, for example, ask it to generate a bedtime story and read it for you.

This was exciting for many people, as it would make Alexa more useful. Also, the new Alexa would be available on a ton of Alexa devices both old and new.

Organization (or a lack thereof)

This is all good news, but when will we actually see it? The event happened about seven months ago, and we haven’t heard anything about the new feature. According to a new report, Amazon is really falling behind with its implementation of the new Alexa. As noted by Fortune, “none of the sources… believe Alexa is close to accomplishing Amazon’s mission of being ‘the world’s best personal assistant,’”

The publication interviewed several former employees, and they told Fortune some of the reasons why the e-commerce giant is trailing behind the competition. One major reason is the organization of the teams. There are thousands of people working on Alexa, but they’re all spread out among several teams. So, there’s friction and an overall lack of unity between the teams. For a company as large as Amazon, that’s not something you want to hear.

Alexa vs. Alexa

Another hurdle mentioned by former workers is something that Google is also dealing with, and that is, well, Alexa. More specifically, the current workers need to cut ties with the current Alexa before it can move on. The current Alexa was built up over nearly a decade, so there are probably millions of lines of code that the company needs to comb through. It might be much harder to implement AI into an existing product than it is to start a new one from scratch. One former employee told Fortune that they needed to “basically burn the bridge with the old Alexa AI model and pivot to only working on the new one.”

Amazon is having trouble getting the new Alexa to make the appropriate API calls and understand natural language. These are extremely important if the company wants to construct a proper Gemini/Siri competitor.

Amazon responded

While Amazon is in the middle of fumbling its game-winning product, the company still appears to be optimistic about it. Kristy Schmidt told The Verge that, “Our vision for Alexa remains the same,” she continued to say, “We have already integrated generative AI into different components of Alexa, and are working hard on implementation at scale — in the over half a billion ambient, Alexa-enabled devices already in homes around the world.”

That isn’t quite the most convincing, but it shows that the company is still working on its ambitious plans.


[ad_2]
Source link