Yahoo News gets smarter with AI-powered makeover

0
[ad_1]

Image credit — Yahoo

Yahoo News has recently unveiled a significant update to its news app, incorporating artificial intelligence (AI) to enhance the user experience. This revamp comes after Yahoo’s acquisition of Artifact, an AI-powered news app founded by Instagram’s co-founders. With this update, Yahoo aims to streamline news consumption for its massive user base of over 180 million monthly visitors in the US.The most notable feature of the updated app is its personalized news feed. Users can select topics and publishers of interest, allowing the AI algorithms to tailor the feed accordingly. Additionally, a “Key Takeaways” feature provides a concise summary of an article’s main points, saving users time by offering a quick overview. This is akin to Artifact’s “Summarize” feature, highlighting the integration of Artifact’s technology into Yahoo News.

The new Yahoo News app | Image credit — Yahoo

Customization options go beyond topic selection. Users can block specific keywords or publishers they wish to avoid, further refining their news consumption experience. A particularly intriguing feature is the app’s ability to identify clickbait headlines. The AI can rewrite misleading, sensationalized, or incomplete headlines to provide more accurate and informative summaries.Yahoo’s AI-powered enhancements extend beyond the app itself. The company is also revamping its homepage layout, emphasizing top news, personalized recommendations, and real-time trending topics. This updated interface is designed to evolve and adapt over time, promising an ever-improving user experience. Yahoo plans to introduce new AI-powered features gradually, allowing users to opt in and explore these changes as they become available.

The AI-powered update to the Yahoo News app represents a significant step in personalizing news consumption. By leveraging AI algorithms and user preferences, Yahoo aims to deliver a more relevant and engaging news experience. While currently available for mobile users in the US, the update is expected to roll out on desktop platforms soon, further expanding its reach.

It’s worth noting that this integration of AI into news delivery raises questions about the potential for algorithmic bias and the need for transparency in how news is selected and presented. As AI plays an increasingly prominent role in shaping our information landscape, these are important considerations for both news providers and consumers. You can download the new Yahoo News app from the App Store or the Google Play Store.


[ad_2]
Source link

The Pixel 8 has an extended display warranty

0
[ad_1]

We’ve heard about the display issue affecting Samsung and OnePlus displays, but Google shouldn’t be left out. Some Pixel 8 users have complained about an odd display issue affecting their units, and they’re not happy about it. As a response, Google is bringing an extended display warranty for Pixel 8 users.

To catch you up, some Pixel 8 users have been seeing some oddities with their displays. There’s a display issue resulting in a line running down the screen. The lines are pink just like with OnePlus phones. Another issue is a flickering problem. It’s an unfortunate issue to have, as the Pixel 8 is still a relatively new phone. While we’re following news about the Pixel 9, the Pixel 8 is still a great device.

Google is bringing an extended display warranty for Pixel 8 users

If you’re experiencing any of these issues, then you’re in luck. According to a new report, Google brought an extended warranty for people with these issues. Pixel 8 users are covered for three years. If your screen hasn’t experienced any issues in a full three years, then it’s safe to say that you have a good unit.

It’s important to note that there are a few requirements for this warranty. Firstly, and this is obvious, it needs to be experiencing one of the issues; vertical line or flickering. Secondly, your device needs some sort of identifier letting Google know that it qualifies for the repair program. An example is the IMEI number.

So, if your phone experiences these display problems, but it’s not covered by the new extended warranty for some reason, then it may still be covered by the limited warranty.

If you’re curious about picking up a Pixel 8, you should consider it. This is one of the best Android phones on the market right now. It comes with seven years of software updates, the latest Google Tensor chip, powerful AI with Gemini Nano, and many more features. Be sure to check out our Pixel 8 review.


[ad_2]
Source link

Apple and OpenAI deal is for ChatGPT exposure, not money

0
[ad_1]

One of the biggest announcements during the latest WWDC24 was the integration of ChatGPT in iOS 18. However, for this, it seems that Apple and OpenAI reached an agreement that does not involve revenue-sharing strategies. That said, the Cupertino giant would resort to that monetization method in the future.

Apple’s market share in the smartphone segment is gigantic. Every year, the brand sells tens of millions of iPhones around the world. Therefore, ensuring a place as a service integrated into that ecosystem is a very appealing idea for anyone. Apparently, both Apple and OpenAI think the same, which is why, according to Bloomberg, neither is currently charging the other.

Neither Apple nor OpenAI are paying in their current deal for ChatGPT integration

The report indicates that Apple considers being present in its millions of devices around the world as “of equal or greater value than monetary payments.” While ChatGPT is pretty well known today, there are still people who are hesitant to try the service for the first time. But having it right at your fingertips, built into an iPhone, can be an ideal jumpstart to start enjoying the power of AI.

The source adds that Apple is not seeking exclusivity of any kind with ChatGPT. In fact, the company is said to be in talks with Google to integrate Gemini. Also with Anthropic, a startup focused on AI. It is even said that they would negotiate with Baidu and Alibaba to offer AI integration in China. This is because services from companies such as OpenAI or Google are limited or prohibited in the Asian country.

Apple’s goal would be to turn iOS into an access hub for the most popular AI services. These services would coexist with Apple Intelligence, the company’s own AI platform. Third-party services would support tasks that Apple Intelligence cannot yet perform.

Apple would take a cut from OpenAI paid plans as future revenue share strategy

In the future, Apple would resort to a monetization model based on revenue share with OpenAI and other companies. The report indicates that the company would take a portion of the premium subscriptions made through its payment platform. Basically, it would implement a model similar to that of the App Store. Lastly, Apple would try to get people to replace traditional search engines with AI-powered services.


[ad_2]
Source link

Samsung could partner up with Meta, Amazon & Qualcomm on AI

0
[ad_1]

Samsung Chairman Lee Jae-yong concluded his two-week business trip to the US with meetings with the CEOs of major tech companies. Lee met Meta CEO Mark Zuckerberg, Amazon CEO Andy Jassy, and Qualcomm CEO Cristiano Amon to discuss cooperation in various industry trends. Artificial Intelligence (AI) was one of the hot topics alongside foundry, chips, cloud services, and networks.

Samsung seeking cooperation with Qualcomm, Amazon, and Meta on AI

Lee Jae-yong left for the US in early June to meet with industry leaders and discuss how their companies can improve collaboration. Over the past two weeks, he held meetings with several big names from the industry. On June 10, Lee invited Qualcomm President and CEO Cristiano Amon to Samsung’s Device Solutions Americas (DSA) office in San Jose, California. The duo discussed ways to expand cooperation in the emerging sectors of the semiconductor market.

As the industry ushers into a new era of AI, Samsung wants to be at the forefront of this revolution. The company has already set a trend with Galaxy AI. Lee’s meeting with Qualcomm’s CEO revolved around AI semiconductors and next-generation communication chips. The two companies already have a close partnership (Samsung often gets exclusive, overclocked versions of the latest Snapdragon chips) and this meeting might strengthen their bond.

On June 11, Meta CEO Mark Zuckerberg invited Lee to his home in Palo Alto, California. It was their second meeting in four months—Lee invited Mark to a Samsung guest house, during the latter’s Korea visit in February. During the most recent meeting, the two tech leaders discussed cooperation in the future ICT (Information and Communications Technology) industry. They also talked about AI, virtual reality, augmented reality, and other futuristic tech fields.

In a press release, Samsung said it expects to further expand its cooperation with Meta in the field of AI, though it didn’t specify anything. During his Korea visit earlier this month, Zuckerberg described Samsung as a foundry giant with an important position in the global economy. “This could be an important point in our cooperation with Samsung,” the Meta head said. It appears the two firms are cooking something big in the AI industry.

Samsung Chairman Lee Jae young Meta CEO Mark Zuckerberg

Amazon and Samsung are collaborating in TV, mobile, and content

Lee’s final major meeting in the US was with Amazon CEO Andy Jassy on June 12. The meeting in Amazon’s headquarters in Seattle was also attended by Samsung’s DS Division Head Jeon Young-hyun, Memory Business Division Head Lee Jung-bae, DSA Vice President Han Jin-man, and North America President Choi Kyung-sik. The executives discussed the future of various flagship businesses, including generative AI and cloud computing.

Lee and Jassy also shared their opinions on cooperation in these fields. Samsung and Amazon are already collaborating in TV, mobile, and content. This meeting may see the two firms extend their partnership to more areas. Samsung plans to hold a global strategy meeting of its key executives later this month. Lee may share his insights from the US visit with the executives during the meeting. The company is expected to develop a specific vision and business plan for the future.

Samsung Chairman Lee Jae young Qualcomm CEO


[ad_2]
Source link

The Pixel Recorder app gets smarter and faster with a new shortcut and other improvements

0
[ad_1]

Image credit — Google

Google’s Pixel Recorder app, known for its transcription capabilities, has received a significant boost in functionality with the June Feature Drop. Alongside enhancements to the Summarize feature, a new app shortcut has been added for even quicker access.

As spotted by 9to5Google, Pixel users can now create a shortcut on their home screens to instantly start a new recording. The shortcut appears as a red circle on a white background, similar to the floating action button (FAB) within the app. This update not only offers a more convenient way to start recordings but also brings it on par with the Quick Settings Tile functionality.

Image credit — 9to5Google

This June update isn’t just about convenience, though, as it also extends the Summarize feature to the Pixel 8 and Pixel 8a, which was previously exclusive to the Pixel 8 Pro. By enabling the Gemini Nano model in Developer options, users of these devices can now benefit from automatically generated summaries of their recordings. What’s more, these summaries are now capable of identifying and labeling speakers within the conversation, enhancing their accuracy and usefulness.The Summarize feature’s speaker identification works in conjunction with the manual Speaker Labels that users can set. This means you can either let the app automatically detect and label speakers, or take control and assign labels yourself for greater precision.

The updated Pixel Recorder app, version 4.2.20240502.639621645, is currently rolling out to Pixel users through the Play Store. This update is a noteworthy advancement as it comes ahead of Apple’s introduction of live audio transcription in Notes and Voice Memos with iOS 18.

In terms of features, the June Feature Drop for Pixel Recorder brings a host of improvements. Whether it’s the added convenience of a home screen shortcut, the expanded availability of the Summarize feature, or the enhanced speaker identification within summaries, Pixel users now have an even more powerful tool for recording and transcribing their conversations.


[ad_2]
Source link

Microsoft Window Ntqueryinformationtoken Flaw Escalate Privilege

0
[ad_1]

Microsoft has disclosed a critical vulnerability identified as CVE-2024-30088.

With a CVSS score of 8.8, this flaw affects Microsoft Windows and allows local attackers to escalate their privileges on affected installations.

The vulnerability resides in the implementation of the NtQueryInformationToken function within Microsoft Windows.

This function is responsible for querying information about a token, which is a critical component in the Windows security model.

The specific issue arises from the lack of proper locking mechanisms when performing operations on an object.

An attacker can exploit this oversight to escalate privileges and execute arbitrary code in the context of the SYSTEM account, which has the highest privileges on a Windows system.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot.

According to the Zero Day Initiative reports, to exploit this vulnerability, an attacker must first gain the ability to execute low-privileged code on the target system.

This could be achieved through various means, such as phishing attacks, exploiting other vulnerabilities, or leveraging social engineering techniques.

Once the attacker has a foothold on the system, they can exploit the NtQueryInformationToken flaw to elevate their privileges, potentially gaining full control over the affected system.

The impact of this vulnerability is significant, as it compromises the security of the entire system.

With SYSTEM-level privileges, an attacker can install malicious software, exfiltrate sensitive data, and disrupt system operations.

The high CVSS score of 8.8 reflects the severity of this vulnerability, highlighting the need for immediate attention and remediation.

Microsoft’s Response

Microsoft has responded promptly to this vulnerability by issuing a security update that addresses the flaw.

The update corrects the improper locking mechanism in the NtQueryInformationToken function, preventing attackers from exploiting the vulnerability to escalate privileges.

Users and administrators are strongly advised to apply this update as soon as possible to protect their systems from attacks.

The timeline for the disclosure of CVE-2024-30088 is as follows:

  • 2024-03-28: Vulnerability reported to Microsoft by Emma Kirkpatrick.
  • 2024-06-12: Coordinated public release of the advisory by Microsoft.

This timeline demonstrates a coordinated effort between the researcher and Microsoft to ensure that the vulnerability was addressed and communicated to the public promptly.

The discovery of CVE-2024-30088 underscores the importance of continuous security research and prompt response from software vendors.

This critical vulnerability in Microsoft Windows could have severe consequences if left unpatched.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

Beware WARMCOOKIE Backdoor Knocking Your Inbox

0
[ad_1]

WARMCOOKIE is a new Windows backdoor that is deployed by a phishing effort with a recruiting theme dubbed REF6127.

The WARMCOOKIE backdoor can be used to take screenshots of the target computer, deliver additional payloads, and fingerprint a system.

“This malware represents a formidable threat that provides the capability to access target environments and push additional types of malware down to victims”, Elastic Security Labs shared with Cyber Security News.

WARMCOOKIE Execution Flow

Researchers have been observing phishing efforts that use lures associated with recruitment firms since late April 2024.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot.

By addressing recipients by name and their present employer, these emails enticed them to look for new employment by clicking on a link that would take them to an internal system where they could read a job description.

Phishing email – Subject: “We’re Interested”

After clicking, users are taken to a landing page that appears to be an authentic website that was created only for them. 

There, they must complete a CAPTCHA test to download a document. The landing pages, which mention a new variation of URSNIF, are similar to earlier campaigns that Google Cloud’s security team has identified.

WARMCOOKIE attack flow

When the CAPTCHA is solved, an obfuscated JavaScript file is downloaded from the page. This obfuscated script launches PowerShell, initiating the initial task to load WARMCOOKIE.

The PowerShell script uses the Background Intelligent Transfer Service (BITS) to download WARMCOOKIE and launch the DLL. 

Researchers note that 45.9.74[.]135 is the IP address where the threat actor continuously and swiftly creates new landing pages.

The actor made an effort to target several hiring agencies while combining industry-related keywords.

Domains associated with 45.9.74[.]135

The backdoor gathers the following values before sending its first outgoing network request, and they are used to identify and fingerprint the target system.

  • Volume serial number
  • DNS domain of the victim machine
  • Computer name
  • Username

In particular, the malware that can take screenshots from victims’ computers offers a variety of harmful possibilities, like making use of private data that is visible on the screen or keeping a close eye on the victim’s computer. 

Screen capture

According to analysts, threat actors create new infrastructure and domains every week to support these campaigns.

“While there is room for improvement on the malware development side, we believe these minor issues will be addressed over time,” researchers conclude.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

Jabra is leaving the consumer headphone market

0
[ad_1]

Jabra is a pretty popular brand producing headphones, earbuds, and other audio equipment. It manufactures a wide range of products spanning different markets, and that makes it a brand for the average man. However, according to a new report, Jabra is leaving the consumer headphone market.

This decision wasn’t Jabra’s, as it came from its parent company GN. It was pretty surprising news because Jabra announced some new earbuds on the same day as the news that it was leaving the consumer market. The earbuds in question are the new Elite 10 (2nd-gen) and Elite 8 (2nd-gen). These are the next iterations of the earbuds released back in August 2023.

As you can guess, they bring improvements in audio quality, hardware, and usability. The new Elite 10 and Elite 8 cost $280 and $230, respectively.

Jabra is leaving the consumer headphone market

The consumer market is important for many businesses to thrive. It’s the bread and butter of several of our favorite companies. However, there are brands that can sustain with the income from a more premium market. This might be what Jabra is being steered toward.

The CEO of GN, Peter Karlstromer, issued a statement on why the company made this decision. He said that it’s “part of our commitment to focus on attractive markets where we can deliver profitable growth and strong returns.” Plain and simple, Jabra is being steered to a market that will bring better profits. We respect the lack of PR speak and sugar-coating in this straightforward statement.

So, with this shake-up, Jabra will be giving a few product series the boot. These are the Elite series and the Talk series. The Talk devices are the mono Bluetooth headsets that go in one ear. While Jabra is discontinuing these series of products, the company said that it will still support them for several years. So, you’ll still be able to get firmware updates for the products and probably additional features.

As the year goes on, the company is going to be getting rid of its stock of products, so you’ll see availability shrink. As its stock of affordable devices dwindles, you’ll see more of its premium devices hitting the shelves. Jabra will be in closer competition with companies like Apple, Bose, and Sony.a


[ad_2]
Source link

Spotify Jams could soon get a chat feature

0
[ad_1]

Image credit: Spotify

Spotify, the popular music streaming service, might be adding a new feature to its Jam sessions. A recent breakdown of the Spotify app code, known as an APK teardown, revealed a hidden “Chats” feature with the codename “campfire.” This discovery suggests that Spotify may be working on adding a chat function to Jam sessions, allowing friends to have conversations while listening to music together.Spotify Jam is a feature that allows premium subscribers to create a shared playlist with friends. Whether in person or virtually, friends can listen to and add songs to the queue together. However, it currently lacks an in-app chat function, forcing users to switch to other apps to communicate. This upcoming addition of a chat feature would address this issue and enhance the social aspect of Jam sessions.While the code for this chat feature appears to be a work in progress, its presence hints that Spotify is actively developing it. Based on the limited code found, it seems that this feature is specifically designed for group conversations within Jam sessions. Although not yet confirmed, it’s possible that Spotify is already internally testing the feature.
Video Thumbnail

The ability to chat directly within the Spotify app during Jam sessions would be a welcome addition for users, particularly during virtual sessions where face-to-face communication isn’t possible. It would eliminate the need to switch between apps to message friends and create a more seamless and integrated social experience.

It’s important to note that APK teardowns offer a glimpse into potential future features, but they don’t guarantee that these features will be officially released. However, this discovery does indicate that Spotify is exploring ways to enhance the social aspect of its platform and make Jam sessions more interactive and engaging for users.

As Spotify continues to refine and develop this chat feature, it will be interesting to see how it integrates with Jam sessions and what additional functionalities it might offer. We’ll definitely be keeping an eye out for further updates on this potential addition to Spotify’s features.

[ad_2]
Source link

0day Vulnerability In 10,000 Web Apps Exploited Using XSS Payloads

0
[ad_1]

A significant vulnerability, tracked as CVE-2024-37629, has been discovered in SummerNote 0.8.18. It allows Cross-Site Scripting (XSS) via the Code View Function.

Summernote is a JavaScript library that helps you create WYSIWYG editors online.

An attacker can insert harmful executable scripts into the code of a trustworthy application or website through a technique known as cross-site scripting (XSS).

An XSS attack is often initiated by an attacker tempting a user to click on a malicious link that they deliver to them.

According to security researcher Sergio Medeiros, 10,000 Web apps have a 0-day vulnerability that may be exploited with a simple XSS payload.

Finding XSS Vulnerability In The Editor

Given the prior vulnerabilities linked to other editors like CKEditor and TinyMCE, which are known to have comparable XSS concerns, the security researcher chose to investigate the WYSIWYG Editor itself.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot.

This led to the SummerNote website, allowing users to see their WYSIWYG editor’s features directly on the home page.

They also included a URL to the GitHub repository, which could be used to examine the codebase. 

Users can style their input with HTML components while testing the editor’s Code View function.

The researcher chose to provide the following XSS payload to observe how the WYSIWYG editor handled “malicious” input:

This image has an empty alt attribute; its file name is Capture%20(1).webp
Testing the Code View Function

“After I set my payload, I clicked on the </> button to disable the Code View functionality to see if the editor processed and executed my payload.

To my surprise, I received an alert box confirming that the XSS payload and vector were valid!” the researcher said.

This image has an empty alt attribute; its file name is Capture%20(2).webp
Alert box confirming the XSS payload

Because the Code View function isn’t sanitized, it was possible to inject malicious XSS payloads to execute malicious JavaScript code once they reached the DOM.

According to this analysis, over 10,000 web-based applications employ this WYSIWYG editor. 

Because the Summernote editor manages user input formatting, some users are constantly susceptible to systemic, persistent XSS issues within the web application.

Thus, this ought to inform aspiring hackers that sometimes it’s better to keep things simple regarding “payload creation and exploitation.”

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link