TikTok talks cyber-security and answers three burning questions

0
[ad_1]
Oh, boy, the social media platform TikTok just can’t get any rest. The never ending drama ride that highlights legal dispute after ban attempt is truly challenging. Not only because the security concerns on hand are extremely relatable and natural, but also because at the end of the day TikTok is not only a business, but a business opportunity for numerous influencers that use it to earn a living. That being said, TikTok has made strides to prove its innocence through transparency and a very clever tactic: not running away from a challenge. The company outright opened its doors for state officials to explore public data to their leisure.

To continue that trend, a TikTok spokeswoman took the time to talk with the BBC regarding three of the reoccurring cyber-security concerns. Namely: the collection of “excessive” amounts of user data, the involvement of the Chinese communist party and the allegations that the app is effectively a brainwashing construct.

While concerns over user data initially blew up in 2022 when an Australian cyber company published a report, which claimed that TikTok collects huge amounts of sensitive and specific data, things might not have been quite objective. Ever since that statement, other teams have stepped in — like Citizen Labs or the Georgia Institute of Technology — and conducted comparative analysis. Well, it turns out that TikTok collects pretty much the same quantity and type of data that most social platforms do. No shock there, considering the competition.

But the point is that said data may end up with China, right? Well, TikTok continues to stand firmly on the position that it is an independent company, which has not and would not supply China with user info. In all reality, even if the risk is totally understandable and fair to be concerned about, it is entirely theoretical, as no evidence of such a data transfer ever surfaced.

Hold on though — TikTok doesn’t need China in order to brainwash you. Its app is already on your phone! Right? Well, the BBC report highlights only one side of the conversation, and it is related to political misinformation. Citizen Labs compared the Chinese and worldwide versions of TikTok and concluded that political-oriented content is not being moderated outside of China. While that is ultimately a good thing, there’s tons more to be discussed on the topic of addictive habit forming and the impact on dopamine that TikTok in particular has.

Overall, while we wouldn’t call TikTok’s slate clean, we absolutely commend the company for its bravery and handling of the entire situation. This is a bumpy ride that has been going on for years and despite that, the company isn’t showing any signs of burnout. That being said, when the political side of things concludes, we’re eager to see what TikTok will do for the mental health of its astoundingly large user base.


[ad_2]
Source link

U.S. Marshals Service Hacked – Sensitive Information Leaked

0
[ad_1]
U.S. Marshals Service Hacked

The theft of critical law enforcement data is currently under investigation by the U.S. Marshals Service (USMS), triggered by a ransomware attack that targeted a stand-alone USMS system. 

The USMS has confirmed that the compromised information is of a sensitive nature and is working to identify the culprits behind the attack.

The United States Marshals Service (USMS) is a crucial bureau operating under the Department of Justice, catering to every facet of the federal justice system. 

Their functions span from executing federal court orders and seizing assets that have been acquired illegally, to safeguarding the well-being of government witnesses and their kin. Additionally, USMS provides a range of other services that are essential to the efficient functioning of the federal justice system.

As per a report by NBC, the federal law enforcement agency has confirmed that the recently stolen data contains personally identifiable information of its employees. The agency is taking immediate measures to contain the damage and has urged its employees to be extra vigilant with their personal information.

Here’s what the USMS spokesperson, Drew Wade stated:-

“On February 17th, a stand-alone USMS system was hit by a ransomware attack that resulted in a data exfiltration event.” 

However, the Marshals Service immediately took notice of the situation and launched an investigation to identify the attackers behind this incident. Even they also disconnected the affected system from the network to stop the further spread.

Sensitive Information Leaked

There is sensitive information contained within the affected system that is relevant to law enforcement, including:-

  • Returns from legal process
  • Administrative information
  • PII related to USMS investigations
  • PII related to third parties
  • PII related to USMS employees

USMS’ Witness Security Files Information System was not accessed by the attackers, as they were unable to establish any access to the system. While this security breach has not led to any danger to anyone in the witness protection program.

The recent incident involving the USMS system is a matter of significant concern, as it involves the theft of sensitive information related to ongoing investigations by the Marshals Service. 

The compromised data is of high importance to law enforcement agencies and could potentially jeopardize the safety and security of the subjects of these investigations. 

The USMS is treating this matter with utmost seriousness and taking all necessary measures to contain the damage caused by the breach.

Despite the recent ransomware attack and data exfiltration event, the USMS has managed to develop a temporary solution to ensure that their operations are not affected. 

The agency is working diligently to track down fugitives and suspects, even as it investigates the extent of the damage caused by the attack. While the situation remains precarious, the USMS is confident that their measures will allow them to continue their efforts until a permanent solution can be found.

Network Security Checklist – Download Free E-Book


[ad_2]
Source link

A week in security (February 20

0
[ad_1]

The most interesting security related news from the week of February 20 to 26.

Last week on Malwarebytes Labs:

Stay safe!


Have a burning question or want to learn more about our cyberprotection? Get a free business trial below.

GET STARTED


[ad_2]
Source link

OnePlus Fold will have a similar form factor to OPPO Find N2

0
[ad_1]

OnePlus has confirmed recently that it will launch its first-ever foldable smartphone in the second half of this year. Many people assumed that it will be identical to the OPPO Find N2, but we’ve received conflicting reports regarding that. According to some fresh info from a trusted source, however, the OnePlus Fold will have a similar form factor to the OPPO Find N2, but it won’t be identical.

The OnePlus Fold will offer a similar form factor to the OPPO Find N2

This information comes from Max Jambor, who is almost never wrong about OnePlus tips. Do note that the phone may not be called the OnePlus Fold, that’s just a guess and a placeholder name.

What does he mean by “similar form factor”? Well, it means that it will lean towards the landscape orientation when unfolded, not vertical like the Galaxy Z Fold 4. That means you won’t have to rotate it when watching video on the main display, for example, to take full advantage of screen real estate.

We’re just not sure how different will it be. There is limited width that OnePlus can use, as the phone cannot be too wide when folded. It may be wider than the OPPO Find N2, though, and thus have a larger form factor, and a larger cover display as a result.

OnePlus’ first foldable will also be a flagship-grade device

We’ll have to wait and see what exactly is OnePlus planning. It’s nice to see a different approach, though, as OPPO is the only one who decided to try out such a form factor. Also, do note that the OnePlus Fold will be a “flagship phone”, as OnePlus said.

Do note that the Google Pixel Fold is also rumored to utilize this form factor. Google’s first foldable is rumored to be considerably larger than the OPPO Find N2, though, so it will likely be quite a bit wider when unfolded.


[ad_2]
Source link

President Biden launches $39 billion CHIPS for America Funding Program

0
[ad_1]

In an effort to reduce its reliance on Taiwan and outcompete China in chip manufacturing, the Biden administration has launched the CHIPS for America funding program worth $39 billion. The program’s objective is to establish the US as the primary choice for leading chip manufacturers, with numerous cutting-edge logic fabrications and DRAM manufacturing facilities set up by the decade’s end.

Authorized under the CHIPS and Science act, the Biden administration has divided the program into several rounds of funding opportunities. The first opportunity, which opens for applications on March 31, 2023, will focus on constructing, expanding, or modernizing commercial facilities for the production of current-generation, leading-edge, and mature-node semiconductors.

Strict guardrails in place

To ensure that the companies use the funding efficiently and for the right purposes, the government has put guardrails in place. Firstly, companies cannot use the funding for stock buybacks or to pay out dividends. Secondly, payments will be tied to meeting specific milestones to ensure that funding is used in a way that aligns with the program’s vision for success. Finally, companies requesting more than $150 million in funding will need to provide childcare for their construction and factory workers and share part of their profits with the government if they make more than projected.

While the first round funding opportunity focuses on commercial facility construction, the program will introduce additional funding rounds in the spring and fall to increase investment in chip-making materials and research facilities. With Samsung and TSMC already onboard to establish factories across the US, the CHIPS for America funding opportunity is a vital step in boosting the US semiconductor industry and contributing to economic recovery and national security.

“Today’s Notice of Funding Opportunity is a crucial step to unleashing the promise of the CHIPS and Science Act to create good-paying jobs right here at home and end our dangerous dependence on semiconductors manufactured abroad,” said Rep. Frank Pallone Jr. (D-NJ).


[ad_2]
Source link

Top Cyber Security Trends: Securing Software Development in a Digital World – GBHackers – Latest Cyber Security News

0
[ad_1]

In today’s digital age, software development is constantly evolving to meet the demands of an increasingly interconnected world. However, this progress also means that cyber threats are becoming more sophisticated and frequent. As a result, cyber security has become a top priority for software developers across all industries. In this article, we will discuss the top cybersecurity trends in software development.

  1. Shift Left Security

Traditionally, security has been an afterthought in software development. However, the shift left security approach aims to change this by integrating security practices and tools earlier in the software development process. This helps to identify and address security vulnerabilities before they become costly problems. Shift left security involves implementing security testing, analysis, and feedback loops throughout the development process.

  1. SecDevOps

SecDevOps is an extension of the DevOps methodology, which emphasizes collaboration, automation, and continuous delivery. SecDevOps integrates security into the DevOps process to create a more secure software development pipeline. This approach involves involving security teams earlier in the development process, automating security testing and validation, and promoting a culture of shared responsibility for security among all stakeholders.

  1. Zero Trust Architecture

Zero Trust is a security model that assumes that no device, user, or network is trustworthy by default, and that all access requests must be verified and authenticated before being granted. Zero Trust architecture aims to provide better protection against cyber threats by enforcing strict access controls, continuously monitoring activity, and requiring multi-factor authentication.

  1. Container Security

Containers are becoming increasingly popular for deploying and scaling applications, but they also introduce new security challenges. Container security involves securing the container images, orchestrator, and runtime environment. This includes implementing container-level access controls, using secure image registries, and ensuring that containerized applications are properly configured and updated.

  1. Cloud Security

As more organizations move their applications and data to the cloud, cloud security becomes more important. Cloud security involves securing cloud infrastructure, applications, and data. This includes implementing access controls, using encryption to protect data at rest and in transit, and continuously monitoring cloud environments for suspicious activity.

  1. Artificial Intelligence (AI) and Machine Learning (ML) in Security

AI and ML are becoming increasingly popular in cyber security due to their ability to quickly analyze large amounts of data and identify patterns. These technologies can be used to detect and respond to cyber threats, as well as to identify potential vulnerabilities in software code. AI and ML can also be used to improve security awareness training by identifying and targeting employees who are most susceptible to phishing attacks.

In conclusion, cyber security is a top concern for software developers in all industries. The top cyber security trends in software development include shift left security, SecDevOps, zero trust architecture, container security, cloud security, and AI and ML in security. By staying up to date with these trends and implementing appropriate security measures, software developers can help to protect their organizations from cyber threats.


[ad_2]
Source link

TikTok probed over child privacy practices

0
[ad_1]

Canadian privacy protection authorities have announced they will start an investigation into TikTok’s privacy practices, especially in relation to its younger users.

The privacy protection authorities for Canada, Québec, British Columbia, and Alberta have announced they will start an investigation into TikTok’s privacy practices, especially in relation to its younger users.

The investigation will include whether the company obtained valid and meaningful consent from its users for the collection, use, and disclosure of their personal information.

The investigation was initiated in the wake of now settled, class action lawsuits in the United States and Canada, as well as numerous media reports related to TikTok’s collection, use, and disclosure of personal information.

TikTok

TikTok claims to have 1 billion users, and when you look at the age distribution it’s no surprise to see that younger people take up the largest share of users.

Source: App Ape

So, it is understandable that the Canadian regulators put extra emphasis on protecting the privacy of younger users.

Since it is near impossible to determine with whom information is shared, the focus of the Canadian investigation will be to determine if the company is meeting its transparency obligations, particularly when collecting personal information from its users. It will also assess whether the organization’s practices are in compliance with Canadian privacy legislation.

Bans

The Chinese-owned platform is under growing Western scrutiny. The FCC has called the app a “unacceptable security risk” and asked it to be removed from app stores.

Because of the suspected ties to the Chinese government, TikTok has been banned from the devices of state employees in several US states. The US Congress passed a ban on downloading TikTok for most government devices, which President Joe Biden signed in late December, and momentum is building among lawmakers to broaden it even further.

Recently, public authorities in the Netherlands were told to steer clear of TikTok. Staff working at the European Commission have been ordered to remove the TikTok app from their phones and corporate devices. In the UK, there is a call for the UK government to follow the European Commission, the EU executive, and the EU Council, and order staff to delete the app.

Last year the state of Indiana filed a lawsuit against TikTok because it found that TikTok’s 12+ rating on the Apple App Store and the “T” for “Teen” rating in the Google Play Store and the Microsoft Store are misleading, since minors are repeatedly exposed to inappropriate content generated by the app’s algorithm.

There have also been concerns that TikTok does not limit its tracking to users of the app.

Defense

TikTok said privacy is a top priority. TikTok’s main defense consists of the fact that most of its senior staff are outside of China. In defense of the earliest accusations, TikTok clarified on its blog where its data are stored, saying the data are not subject to Chinese law.

“TikTok is led by an American CEO, with hundreds of employees and key leaders across safety, security, product, and public policy here in the US. We have never provided user data to the Chinese government, nor would we do so if asked.”

A representative for TikTok stated as a response to the announced Canadian investigation that it has tried to set the record straight regarding how the company protects Canadians’ privacy.

We’ll keep you posted on how this develops.


Have a burning question or want to learn more about our cyberprotection? Get a free business trial below.

GET STARTED


[ad_2]
Source link

Nothing Phone (2) will use a Snapdragon 8 series SoC

0
[ad_1]

It’s official, the Nothing Phone (2) will use a Snapdragon 8 series SoC. The company has confirmed that during the Mobile World Congress (MWC) in Barcelona.

The Nothing Phone (2) will utilize a Snapdragon 8 series processor

The company did it in an interesting way. Its CEO, Carl Pei, posed for a picture with Qualcomm’s CEO, Cristiano R. Amon. They posed with a jersey that had the name of the phone on it, and the number 8 under it.

Carl Pei and Cristiano Amon Nothing Phone 2 SoC image

 

Nothing’s official Twitter account retweeted that, and flat-out confirmed that the Snapdragon 8 series will be used. That basically means the Nothing Phone (2) will use either the Snapdragon 8+ Gen 1 or the Snapdragon 8 Gen 2 chip.

Your guess is as good as ours, but let’s try to guess. The Snapdragon 8+ Gen 1 is still an immensely powerful chip with excellent power consumption. It could enable Nothing to keep the price lower. The Snapdragon 8 Gen 2 would cost considerably more.

It remains to be seen if it will be the Snapdragon 8+ Gen 1 or the Gen 2

On the flip side, Nothing may be going for the “flagship killer”-esque phone with the Nothing Phone (2), and stuff the Snapdragon 8 Gen 2 on the inside. We do wonder what its price will be in that case.

The Nothing Phone (1) features the Snapdragon 778G+ SoC, so the Snapdragon 8 series chip will be a considerable improvement. The phone is quite affordable at the moment, at €469, but we do expect its successor to cost significantly more

If we had to guess, we’d say that Nothing will go for the Snapdragon 8+ Gen 1 for pricing reasons. There’s also a good chance it may have different plans, so we’ll see.

The Nothing Phone (2)’s design is still a mystery, but Nothing will likely keep to its style. LED lights on the back are expected once again, along with a see-through glass backplate.


[ad_2]
Source link

Bing AI is making its way to your Windows 11 taskbar

0
[ad_1]

AI is the new frontier in tech, as so many companies are investing heavily in the technology. Microsoft was quick to pounce on ChatGPT and implement it into Bing. This is to help it gain an edge over Google. Now, Microsoft is adding Bing AI to the Windows 11 taskbar, according to Engadget.

Microsoft isn’t the only company planning to use ChatGPT for its own AI venture. Snapchat is soon to launch a chatbot of its own powered by ChatGPT. It’s called My AI, and it’s a chatbot that’s supposed to play the role of a human being that you message. You can use it to summon answers to your questions or just chat with you if you need to talk.

Bing AI is coming to Windows 11

With all of the time, money, and effort Microsoft is putting into ChatGPT, it’s no shocker that the company is making it a part of its PC operating system. Windows 11 is the latest version of Windows, and the company has been sending out a torrent of updates to the software as it matures.

An update that users can expect soon is the eventual addition of Bing AI. The chatbot will be integrated into the taskbar. Looking at the screenshot, you’ll see it in the search bar right between the start menu and your pinned apps.

This means that you won’t have to go through Edge in order to access the chatbot. Just click on the search bar and you’ll be able to type in your query. This will streamline the experience a lot.

Windows is currently rolling out this feature in an update today. If you’re a part of the Bing AI preview, then you should be able to access the features. If not, then you’ll want to sign up. You can click here to sign up. You’ll be put on the waitlist to gain access to Bing AI. Microsoft says that, if you want to move higher up the waitlist, then you can use the Bing engine for general searches.


[ad_2]
Source link

Alarming Rise in Mobile Banking Malware

0
[ad_1]
Rise in Mobile Banking Malware

In 2022, the number of new mobile banking Trojan installers found by Kaspersky Lab’s cybersecurity researchers surged to 196,476, which is more than twice the number reported in 2021. 

This alarming statistic underscores the increasing sophistication and frequency of cyberattacks on mobile devices. The proliferation of mobile banking Trojans has reached an unprecedented level, marking the highest surge observed in the past six years. 

The fact that cybercriminals are actively targeting mobile users and prioritizing the theft of financial data is becoming increasingly apparent. This trend is further reinforced by the significant investments being made in the creation of new malware designed to exploit vulnerabilities in mobile devices. 

The growing sophistication of these attacks poses a major threat to the financial well-being of their targets, with the potential for significant financial losses.

Newly Discovered Banking Malware

In 2022, cybersecurity experts uncovered the presence of multiple mobile Trojan subscribers on the Google Play Store. A number of banking Trojan families are still available on Google Play that is disguised as utilities, including:-

Cybersecurity researchers have identified a new mobile Trojan family, known as Harly, that has been active since 2020. This new threat has been added to the list of known mobile Trojan families, which includes Jocker and MobOk.

In 2022, a staggering 2.6 million downloads of Harly malware programs were recorded from Google Play, the official app store for Android devices. In the previous year, cybercriminals took advantage of the Google Play Store to disseminate a range of fraudulent apps that promised enticing incentives, such as:- 

  • Welfare payments 
  • Lucrative energy investments

The Sharkbot Trojan has been found to be actively distributing downloaders that imitate file manager apps. These downloaders are designed to request permission to install additional packages required for the Trojan to function effectively on the user’s device. 

However, granting such permissions could expose the user’s device to potential security breaches, thereby putting their sensitive information at risk.

Trends Going Surge

According to a recent analysis, mobile attacks experienced a gradual decline in the latter half of 2021 and throughout 2022 plateaued at approximately the same level.

In 2022, a significant decline of 1,803,013 malware or unwanted software installers was detected by experts, as compared to the previous year. A total of 1,661,743 malware or unwanted software installers were identified by experts in the past year.

In 2022, the rankings for potentially unwanted software witnessed a shift, with RiskTool-type software taking the lead with 27.39% prevalence. Adware, which was the previous leader, has been replaced and now accounts for 24.05% of the total unwanted software detected.

In comparison to 2021, there has been a significant decrease in the share of RiskTool and adware software in 2022. RiskTool witnessed a decline of 7.89 percentage points, while adware witnessed a more significant decrease of 18.38 percentage points.

Trojan-type malware secured the third position in the rankings, accounting for 15.56% of the total malware detected in 2022. This is a notable increase of 6.7 percentage points from the previous year.

Cybercriminal activity in 2022 did not witness any significant changes, as the attack numbers remained steady after a decrease in the previous year. This indicates that the cybersecurity measures put in place by individuals and organizations are becoming more effective in preventing attacks.

Recommendations

Here below we have mentioned the recommendations offered by the security analysts at Kaspersky:-

  • Only download apps from official app stores if you want to ensure the safety of your device.
  • Before granting permission to an application, review the permissions of the app you are using.
  • In order to detect malicious software and adware, it is important that you use a reliable security solution.
  • If you believe that apps should not have access to photos, contacts, or GPS features, Apple provides some privacy controls to block them.
  • Ensure that your operating system as well as essential apps are always up-to-date.

Network Security Checklist – Download Free E-Book


[ad_2]
Source link