HONOR Magic V Flip announced as the company’s first clamshell foldable

0
[ad_1]

The HONOR Magic V Flip is now official after months of rumors and leaks. The device was announced in China, and this is the company’s very first clamshell foldable. HONOR has great foldable under its belt already, but they did not have a flip phone… until now.

The HONOR Magic V Flip is the company’s first flip phone

As you can see in the provided images, the HONOR Magic V Flip has a large cover screen. In fact, HONOR says that it has the largest cover screen around. It is larger than the one on the Galaxy Z Flip 5 and Motorola Razr 40 Ultra.

The phone’s main cameras are placed inside that display, basically, while the main (foldable) display has a display camera hole in it. Speaking of which, the cover display measures 4 inches (1092 x 1200) in diagonal, while the main display measures 6.8 inches (2520 x 1080).

It has two OLED panels, and the Snapdragon 8+ Gen 1 SoC

The main display on the HONOR Magic V Flip is actually quite great. It’s an LTPO 8T+ display, and it offers an adaptive refresh rate from 0.1Hz to 120Hz, as needed. This display also has a 405 PPI, and a 2,160Hz PWM to go easy on your eyes. It also has a peak brightness of 3,000 nits. Both are OLED panels, by the way.

The Snapdragon 8+ Gen 1 fuels the HONOR Magic V Flip. That is quite a surprise, as we’ve expected at least the Snapdragon 8 Gen 2 to be included. The Snapdragon 8+ Gen 1 is still a powerful chip, and it’s capable of running phones without a hitch, though so… there you go. It also allowed HONOR to keep the price tag down.

The phone offers 12GB of RAM and comes in three storage options. Users in China can choose between 256GB, 512GB, and 1TB storage variants of this phone. A 4,800mAh battery is also a part of the package, and it supports 66W charging. Android 14 comes pre-installed, with MagicOS 8.0 on top of it. There are also two SIM card slots inside the device. Bluetooth 5.3 is supported. The fingerprint scanner sits inside the power/lock button on the right side.

Two main cameras are included, while the phone comes in three colors and a ‘Special Edition’

A 50-megapixel main camera (f/1.9 aperture, OIS, EIS) is included on the back, along with a 12-megapixel ultrawide unit (f/2.2 aperture). There is also a camera on the main display, a 50–megapixel unit (Sony’s IMX816 sensor, f/2.0 aperture).

HONOR announced the phone in three color options, Camilla White, Champagne Pink, and Iris Black. The HONOR Magic V Flip measures 1673. x 75.6 x 7.15mm when unfolded. When folded, it measures 86.5 x 75.6 x 14.89mm. The device weighs 193 grams.

The pricing in China starts at CNY4,999 ($689), while it goes up to CNY5,999 ($827) for the ‘normal’ version. The ‘Special Edition’ will set you back CNY6,999 ($965), and it comes with 16GB of RAM and 1TB of storage. What’s the difference between them? Well, the ‘Special Edition’ was actually made in collaboration with Jimmy Choo, a fashion icon. It has a different design, basically. You can see both variants below.

HONOR Magic V Flip Special Edition Jimmy Choo official image 1


[ad_2]
Source link

Should you upgrade to iPhone 15 Pro and later just for Apple Intelligence? Maybe not for now

0
[ad_1]

iPhone 15 Pro | Image credit – PhoneArena

Just a few days back, Apple officially joined the AI club and announced its so-called Apple Intelligence, a suite of AI features set to debut on select devices with the official release of iOS 18 later this fall.

However, the tech giant clarified that Apple Intelligence will only be available on the latest iPhone 15 Pro models and newer, as well as iPads and MacBooks powered by the M1 chip or later. This got me thinking: Would I upgrade to the current Pro models or the upcoming iPhone 16 series just for Apple Intelligence? My answer is no, and here is why.

Not giving up my iPhone 13 mini yet


So, here is the thing. As intrigued as I am by Apple’s latest AI features, they just don’t justify spending $1000+ on a new Pro model for me. My current iPhone 13 mini, while it may be considered older now, still gets the job done. Plus, its compact form factor is something I find irreplaceable, especially in a market where smaller phones are increasingly rare.

But setting aside size, Apple Intelligence just doesn’t impress me all that much, at least not yet. While the features Apple unveiled are useful in certain scenarios, I personally prefer taking matters into my own hands rather than relying on AI, especially when it involves private conversations and a big part of the new AI features are related to new writing tools in basically anywhere where there is a cursor, such as Mail and the Messages app.I mean, where is the fun in chatting with your girlfriend if AI is suggesting responses to her witty questions? And what about AI summarizing lengthy messages, making it easier to catch up on conversations? How would I then know what John joked about and why our group trip is going south?

Plus, statistics indicate that 52% of consumers have doubts about AI’s ability to protect private information, so features like that might not be widely adopted. There are simply aspects of life where AI has no place despite its rapid development. As the wise girls from the Spice Girls once said:

Apple also unveiled a new AI-powered feature that allows users to remove unwanted objects from their images. It is cool, although not groundbreaking since Google and Samsung already have similar tools like Magic Eraser and Object Eraser. But is this feature alone worth an upgrade?

Apple’s new Clean Up tool | Image credit – Apple

There are plenty of online platforms offering the same solution, and if you really need to remove someone or something from a photo, you can still do it — just with a few extra clicks, but the job gets done.

The one thing that can make me consider an upgrade at the moment is Siri


The updated Siri sounds significantly improved compared to the current version. Apple has revamped Siri using large language models to make it smarter and more responsive to user queries. The new Siri can now perform actions within Apple’s own apps, greatly enhancing its capabilities.Imagine telling Siri to open a document, move a file, delete an email, edit a photo, or provide a quick summary of your notifications and articles. That is the level of convenience Apple is introducing with the updated Siri.

However, as impressive as these updates are, they are not compelling enough for me to upgrade sooner than planned. Plus, in my case, I will have the opportunity to experience Apple Intelligence on my MacBook, so upgrading just doesn’t make sense for me, and probably for many of you too — especially if you already own an iPhone 13,  iPhone 14 series, or the basic models of the iPhone 15 series.

Why only the Pro models?


To be honest, it feels like a bit of a jerk move from Apple to release Apple Intelligence exclusively for its latest Pro models. The iPhone 15 series launched less than a year ago, and I am sure many customers who purchased the basic models were caught off guard.

Rumors suggest that DRAM (dynamic random-access memory) is the reason why AI will be available on the iPhone 15 Pro models and beyond. The iPhone 15 and iPhone 15 Plus have 6GB of DRAM, which is less than the 8GB found on the A17 Pro powering the iPhone 15 Pro and iPhone 15 Pro Max. Allegedly, Apple Intelligence’s on-device AI LLM (large language model) requires about 2GB or less of DRAM.

And you might wonder why Apple didn’t give the basic models 8GB of RAM, as well. I mean, flagship Android phones are slowly moving towards 12GB of RAM as the standard. I wonder about that, too, but I will save that topic for another time.

Right now, Apple says most Apple Intelligence features work directly on your iPhone, keeping your data secure because it stays local. But for more complex tasks or those that go beyond what your iPhone can handle, Apple uses larger server-based models on its own servers built with Apple silicon, called Private Cloud Compute.

Another way to handle complex tasks is through ChatGPT. Apple teamed up with OpenAI, so your iPhone might suggest using the chatbot for tasks ChatGPT is good at. You can say no if you want. Apple’s big on privacy for ChatGPT users: their IP addresses stay hidden, and OpenAI doesn’t store their requests.

Your iPhone will ask you whether you want to use ChatGPT or not | Image credit – Apple

When Apple eventually reveals more details about its AI, likely in September during the iPhone 16 series unveiling, I hope the company will also expand compatibility for its Apple Intelligence, even if not on-device.

This could be a great solution for iPhone owners who still want to try the AI features but aren’t ready or able to upgrade yet or don’t mind their data going to a cloud. You know, offering someone a sneak peek is one of the best ways to convince them to buy it later on.


[ad_2]
Source link

Hackers Exploiting MS Office Editor Vulnerability Deploy Keylogger

0
[ad_1]

Researchers have identified a sophisticated cyberattack orchestrated by the notorious Kimsuky threat group.

The group has been exploiting a known vulnerability (CVE-2017-11882) in the Microsoft Office equation editor (EQNEDT32.EXE) to distribute a keylogger, posing significant user risks worldwide.

The vulnerability in question, CVE-2017-11882, resides in the equation editor component of Microsoft Office.

This flaw allows attackers to execute arbitrary code by exploiting the equation editor, often embedded in Office documents.

According to the AhnLab Security Intelligence Center (ASEC) reports, despite being an old vulnerability, it remains a potent tool for cybercriminals due to its high success rate in executing malicious scripts.

The Kimsuky group has been leveraging this vulnerability to run a page with an embedded malicious script using the mshta process.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot.

The attack begins when a user opens a compromised Office document, triggering the equation editor to execute mshta.exe.

mshta.exe executed via the equation editor program (EQNEDT32.exe)
mshta.exe executed via the equation editor program (EQNEDT32.exe)

The Malicious Script

The mshta process connects to a page named error.php, which deceptively displays a “Not Found” message to the user, masking the execution of the malicious script.

The C2 server screen (mshta.exe)
The C2 server screen (mshta.exe)

The content of error.php, reveals the script’s major behaviors, including downloading additional malware via a PowerShell command, creating a file named desktop.ini.bak under the Users\Public\Pictures path, and attempting to register this file in the Run key under HKLM with the name “Clear Web History.”

However, due to an error in the script, this registration fails initially.

Content of the malicious script (error.php)
Content of the malicious script (error.php)

The Keylogger Deployment

Upon correcting the script for replication purposes, the desktop.ini.bak file is successfully created and registered.

This file is crucial for the keylogger’s operation.

Registration to the autorun registry
Registration to the autorun registry

The first downloaded malware, a PowerShell script, collects system and IP information and sends it to the C2 server.

It also can download and execute a keylogger from the C2.

The keylogger script creates the desktop.ini.bak file in the Users\Public\Music path to record users’ keystrokes and clipboard data.

It uses a mutex value “Global\AlreadyRunning19122345” to prevent duplicate instances.

The collected data is periodically sent to the C2 server, deleted, and recreated, ensuring continuous data exfiltration.

The Kimsuky group’s persistent exploitation of CVE-2017-11882 underscores the importance of patching vulnerabilities promptly.

Users must ensure their software is updated to the latest versions and avoid using software that has reached the end of service (EOS).

It is also crucial to refrain from opening suspicious document files and keep security solutions, such as V3, updated to prevent malware infections.

Implementing endpoint security products and sandbox-based APT solutions like MDS can significantly mitigate the risks of such cyberattacks.

IOC

MD5s

  • 279c86f3796d14d2a4d89049c2b3fa2d
  • 5bfeef520eb1e62ea2ef313bb979aeae
  • d404ab9c8722fc97cceb95f258a2e70d

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

Update now! Google Pixel vulnerability is under active exploitation

0
[ad_1]

Google has notified Pixel users about an actively exploited vulnerability in their phones’ firmware.

Firmware is the code or program which is embedded into hardware devices. Simply put, it is the software layer between the hardware and the applications on the device.

About the vulnerability, Google said there are indications it may be:

“under limited, targeted exploitation.”

This could mean that the discovered attacks were very targeted, for example by state-sponsored actors or industry-grade spyware. However, it’s still a good idea to get these patches as soon as you can. And whether you have a Pixel or not, all Android users should make sure they’re using the latest version available, because the June 2024 security update addresses a total of 50 security vulnerabilities.

Updates to address this issue are available for supported Pixel devices, such as Pixel 5a with 5G, Pixel 6a, Pixel 6, Pixel 6 Pro, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel 8, Pixel 8 Pro, Pixel 8a, and Pixel Fold.

For these Google devices, security patch levels of 2024-06-05 or later address this issue. You can find your device’s Android version number, security update level, and Google Play system level in your Settings app.

You should get notifications when updates are available for you, but it’s not a bad idea to manually check for updates. For most phones it works like this: Under About phone or About device you can tap on Software updates to check if there are new updates available for your device, although there may be slight differences based on the brand, type, and Android version of your device.

Technical details

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The CVE for this vulnerability is:

CVE-2024-32896: an elevation of privilege (EoP) issue in Pixel firmware.

An elevation of privilege vulnerability occurs when an application gains permissions or privileges that should not be available to them. This can be a key element in an attack chain when a cybercriminal wants to move forward from initial access to a device to a full compromise.


We don’t just report on phone security—we provide it

Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by downloading Malwarebytes for iOS, and Malwarebytes for Android today.


[ad_2]
Source link

Galaxy S24 FE gets Exynos 2400, Tab S10+ has a MediaTek chip

0
[ad_1]

A couple of upcoming Samsung devices popped up on Geekbench today. The Galaxy S24 FE and Galaxy Tab S10+ were benchmarked, revealing interesting pieces of information. The next-gen flagship tablet, in particular, caught us by surprise. It appeared with a MediaTek chipset, a first for the series. The Fan Edition phone is, expectedly, getting the Exynos 2400.

Galaxy Tab S10+ may run a MediaTek chipset

Samsung’s Galaxy S series flagship Android tablets have always used either its in-house Exynos chips or Qualcomm’s Snapdragon solutions. However, the next-gen models may no longer maintain this record. The newly spotted Geekbench listing for the Galaxy Tab S10+ shows it running a MediaTek processor, namely the Dimensity 9300+.

Spotted by MySmartPrice, the listing is for the US version of the tablet (model number SM-X828U). We exclusively reported in May that this model number belongs to the Galaxy Tab S10+, along with SM-X826B and SM-X826N. The latter two are the global and Korean versions, respectively. The Geekbench entry showed the device with Android 14 and 12GB of RAM.

But more importantly, it doesn’t have an Exynos or Snapdragon chip. Instead, it’s running MediaTek’s Dimensity 9300+, a flagship chipset featuring a peak CPU speed of 3.4GHz. Produced on TSMC’s 4nm process node, the chip is as powerful as Qualcomm’s latest, the Snapdragon 8 Gen 3. However, this comes as a surprise because of Samsung’s history.

Samsung Galaxy Tab S10 Plus MediaTek chipset geekbench

Unless this Geekbench entry is fake (it’s easy to fabricate these benchmarks), Samsung is all set to launch its first flagship tablet with a MediaTek chipset. Well, the Galaxy Tab S10+ may not launch at Unpacked next month, but you get the gist. It remains to be seen if the vanilla and Ultra models also switch to Dimensity chips. The new tablets may arrive later this year.

Galaxy S24 FE will ship with the Exynos 2400

Samsung’s flagship smartphones aren’t switching to MediaTek just yet. The company is readying the Galaxy S24 FE with the Exynos 2400, the same chipset that powers the Galaxy S24 and Galaxy S24+ in some global markets. Well, at least the global version (SM-S721B) will get the Exynos ship, Geekbench reveals. We don’t yet have a confirmation about the US version.

The Geekbench listing also confirms Android 14 and 8GB of RAM for the Galaxy S24 FE. It is unclear if Samsung also plans to release the phone in a 12GB RAM variant. The new Fan Edition device should go official in a few months. Recent developments suggest the Galaxy Tab S10 series will arrive around the same time. We will let you know when we have more information.

Samsung Galaxy S24 FE Exynos 2400 chipset geekbench


[ad_2]
Source link

Samsung preparing to launch AI-focused 2nm chips in 2025

0
[ad_1]

Samsung‘s semiconductor foundry is on track to mass-produce 2nm chips in 2025 and 1.4nm chips in 2027. At the ongoing Samsung Foundry Forum (SFF) event in San Jose, California, the company revealed that its process technology development is progressing smoothly as planned. The Korean firm also announced two new process nodes and AI solutions for the next generation of electronics.

Samsung is preparing to introduce 2nm mobile chips next year

Samsung has long aimed to start 2nm mass production in 2025. Shortly after introducing its first 3nm chip in 2022 produced on its 3GAE process node, the company unveiled its semiconductor roadmap for the next five years. It planned to launch the second-gen 3nm process node (3GAP) in 2024. The Exynos 2500, which should power the Galaxy S25 series early next year, will probably be made on the 3GAP 3nm process.

The roadmap further revealed that Samsung will introduce 2nm chips in 2025, followed by a second-gen 2nm process node in 2026. Finally, in 2027, the company would enter the sub-2nm era, bringing a 1.4nm chip to the market. All this while, the Korean firm would be continuously increasing its production capacity for advanced chips. The total capacity is projected to grow over 3x between 2022 and 2027.

Samsung Foundry 2nm chips 2025 2

Samsung says its semiconductor technology is developing along these lines. At SFF, the company introduced an improved 2nm process node called SF2Z. Slated to enter mass production in 2027, it reduces voltage drop compared to the first-gen 2nm node (SF2), “enhancing the performance of HPC designs.” It also enhances power, performance, and area (PPA) thanks to backside power delivery network (BSPDN) technology.

The Korean tech titan also launched a high-value 4nm variant at SFF. Dubbed SF4U, the new 4nm process node “offers PPA improvements by incorporating optical shrink.” Samsung aims to start mass production on this node alongside its first-gen 2nm node in 2025. The company says it is also “actively shaping future process technologies below 1.4nm through material and structural innovations.”

Samsung Foundry 2nm chips 2025 1

The GAA transistor architecture has become imperative in the AI era

Samsung uses the gate-all-around (GAA) transistor architecture in its 3nm chips. The new architecture brings PPA improvements over FinFET, the older architecture used up to 4nm chips (TSMC still uses FinFET and plans to upgrade to GAA with its 2nm chips next year). The Korean firm aims to benefit from an early adoption of advanced transistor technology.

According to Samsung, “structural advancements like gate-all-around (GAA) have become imperative to meet power and performance demands” of the AI era. The company says its GAA process has matured significantly over the past two years, both in yield and performance. Its GAA production will substantially expand in the coming years as it moves to 2nm and 1.4nm semiconductor process technologies.

Samsung’s ongoing foundry event in the US also brought Samsung AI Solutions, a turnkey AI platform integrating the strengths of the company’s Foundry, Memory, and AVP (Advanced Package) businesses. Customers get high-performance, low-power, and high-bandwidth solutions that can be tailored to suit their AI requirements. The Korean firm plans to introduce an all-in-one, CPO-integrated one-stop AI solution in 2027.

Samsung Foundry 2nm chips 2025 3


[ad_2]
Source link

Indian Ex-Employee Jailed for Wiping 180 Virtual Servers in Singapore

0
[ad_1]

A Singapore court has sentenced a 39-year-old Indian national, Kandula Nagaraju, to two years and six months imprisonment for hacking into his former employer’s computer system and deleting critical data.

Nagaraju was part of a 20-member team at National Computer Systems (NCS) between November 2021 and October 2022, responsible for managing a quality assurance computer system containing 180 virtual servers and testing new software and programs before launch. Court documents reveal that Nagaraju felt “confused” and “upset” after getting fired in October 2022 over poor performance, believing that he had performed well.

Indian Ex-Employee Jailed for Wiping 180 Virtual Servers in Singapore
A snippet of Kandula Nagaraju’s experience letter was obtained by Hackread.com

Upset with the termination, Nagaraju returned to India and launched a series of cyberattacks against NCS between January and March 2023.  Operating remotely, he gained unauthorized access to the company’s systems multiple times.

The attacks unfolded in stages. First, Nagaraju accessed the system six times between January 6th and 17th, likely familiarizing himself with the architecture and exploring vulnerabilities. He then wrote computer scripts, essentially malicious programs, to test their effectiveness in deleting servers.

In February 2023, after finding a new job in Singapore, Nagaraju returned, rented a room with a former NCS colleague and used his Wi-Fi network to access NCS’ system once more. This act demonstrates a calculated and persistent effort to target his former employer.

As per the Singaporean news site CNA, the most damaging phase occurred in March 2023. Nagaraju accessed the NCS Quality Assurance (QA) system 13 times. Finally, on March 18th and 19th, he executed his pre-written script, resulting in the deletion of a staggering 180 virtual servers, one at a time. This act caused significant financial losses to NCS, estimated to be around SGD 918,000 (approximately USD 678,000).

Indian Ex-Employee Jailed for Wiping 180 Virtual Servers in Singapore
Kandula Nagaraju (Image credit: Boon Keong Ooi – TODAY)

The NCS team discovered the system was inaccessible the following day and the servers had been deleted. A police report was made on April 11, 2023, and several IP addresses were handed over. Nagaraju’s laptop was seized, and the script used to delete the servers was found. Investigations revealed that Nagaraju had searched for scripts to delete virtual servers on Google, which he used to code the script.

Disgruntled Employees – Threat Within!

The case highlights the dangers of disgruntled employees on a company’s cybersecurity, emphasizing the need for robust access control measures. Companies must also consider exit strategies for terminated employees, including timely removal of access privileges.

Nevertheless, this is not the first time that a disgruntled employee damaged the hands that fed them. In April 2017, an ex-Marriott employee hacked into the hotel reservation system from his apartment in New York City and reduced rates on more than 3,000 rooms from $159 – $499 per night … to $12 – $59.

In May 2018, Coca-Cola announced a data breach after one of its ex-employees managed to steal a hard drive containing the personal information of over 8,000 workers. In June 2018, Tesla sued an ex-employee for hacking and sharing gigabytes of data with 3rd parties. The stolen data included dozens of photos and a video of Tesla’s manufacturing systems.

In July 2018, Israeli authorities arrested a 38-year-old man for stealing secrets from the NSO Group, a Herzliya-based firm specializing in developing spyware, including the notorious Pegasus spyware, which helps governments spy on unsuspecting individuals and journalists worldwide. According to authorities, the stolen data was being sold on the dark web for a whopping $50 million.

In August 2020, an ex-employee and Indian citizen on an H1-B visa hacked Cisco’s Amazon Web Services (AWS) infrastructure and erased virtual machines. Sudhish Kasaba Ramesh pleaded guilty to “damaging Cisco’s network.“

  1. Preventing Insider Attacks on Your HR System
  2. Managing Insider Threats with Internal Monitoring
  3. Ransom Your Employer Email Scam Suspect Arrested 
  4. Data Security Threats – Strategies to Strengthen Your Defense
  5. Insider Threat Awareness: Protecting Your Business from Within

[ad_2]
Source link

Ivanti EPM SQL Injection Flaw Let Attackers Execute Remote Code

0
[ad_1]

In May 24, 2024, Zero-Day Initiative released a security advisory for Ivanti EPM which was associated with SQL injection Remote code execution vulnerability.

This vulnerability was assigned with CVE-2024-29824 and the severity was given as 9.6 (Critical).

Though ZDI did not mention any additional information regarding this critical vulnerability, they specified a function name that affected Ivanti EPM which was “RecordGoodApp”.

However, a proof-of-concept for this vulnerability has been published by Horizon3 researchers.

Technical Analysis – Proof Of Concept

According to the reports shared with Cyber Security News, this RecordGoodApp function existed in the PatchBiz.dll file present in the installation folder.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot.

Further, this DLL was dissected using Jetbrains dotPeek tool for further review. This Patchbiz.dll wa a C# binary.

RecordGoodApp Disassembly (Source: Horizon3)

On investigating the SQL statements in this binary, the first SQL statement was found to be vulnerable to SQL injection as it used string.Format for inserting the value of goodApp.md5 into the SQL query.

Additionally, the RecordGoodApp function was first called from the AppMonitorAction.RecordPatchIssue is present inside an IF ELSE statement.

AppMonitorAction.RecordPatchIssue (Source: Horizon3)

Further, the AppMonitorAction.RecordPatchIssue was called by Patch.UpdateActionHistory which was called from three different locations such as LANDesk.ManagementSuite.PatchBiz, LANDesk.ManagementSuite.WSVulnerabilityCore and StatusEvents.

Patch.UpdateActionHistory Usage (Source: Horizon3)

Among these locations, the StatusEvents.EventHandler.UpdateStatusEvents was the most interesting, as it had annotations with [WebMethod] inside the EventHandler class.

This EventHandler class inherits from the System.Web.Services.WebService declares that it can be used to hit UpdateStatusEvents over HTTP.

Triggering The Exploit

As a means of analysing the location of this EventHandler class, an IIS manager was used which provided the exact location of EventHandler.cs that was located in /WSStatusEvents endpoint. Visiting this endpoint provided a list of sample requests and responses.

IIS Manager WSStatusEvents (Source: Horizon3)

Further analysis revealed that this endpoint was sent with requests, finally showing one particular request that used the xp_cmdshell.

This xp_cmdshell can execute commands on the system, which can now be used to achieve Remote Code Execution on vulnerable Ivanti EPM.

Successfully exploiting using Burp (Source: Horizon3)

Horizon3 has released an exploit code to trigger this vulnerability, which is now available on GitHub.

Users can use the MS SQL logs to examine the usage of xp_cmdshell for any malicious purposes.

It is recommended that Ivanti EPM users upgrade their products to the latest version to prevent threat actors from exploiting this vulnerability.

MS SQL Logs as Indicators of Compromise of using xp_cmdshell (Source: Horizon3)

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

Galaxy Z Fold 6 Ultra won’t be limited to one market

0
[ad_1]

Samsung is undeniably a strong competitor in the smartphone market, especially with its powerful foldable devices. However, Chinese OEMs are rapidly catching up. To maintain its lead, Samsung needs to introduce a highly competitive foldable. Samsung actually seems to be working on an “Ultra” foldable phone. This is the first time an ‘Ultra’ model visiting the Galaxy Fold series. Previously, we shared with you that we discovered two devices in the Fold 6 series. Galaxy Z Fold 6 and Fold 6 Ultra. We know that Samsung is working on two distinct foldable devices, internally codenamed “Q6” and “Q6A.” Initially, we thought that Galaxy Fold 6 Ultra will be exclusive to Korea, but it appears Samsung plans to launch the Galaxy Z Fold 6 Ultra in the Chinese market as well.

Galaxy Z Fold 6 Ultra won’t be limited to Samsung’s home market

We spotted a new device in our database with the internal codename “Q6A” and the model number “SM-W9025“. We already know that Samsung codenamed Galaxy Z Fold 6 Ultra as “Q6A”. Additionally, we previously reported the device will be available in Korea and Samsung will introduce Galaxy Z Fold 6 Ultra with the model number SM-F958N. It appears that the model number of Samsung’s upcoming foldable in China is quite different from the Korean variant, even though they bear the same internal codename. And there is a reason behind this.

Samsung introduces some of its devices in China under a completely different marketing name than in the global market. The previously announced Galaxy Z Fold 5 and Galaxy Z Flip 5 were released in China with a different market branding. Specifically, Samsung launched them as Galaxy W24 and Galaxy W24 Flip in China. We expect this device to be released in China as the “Galaxy W25 Ultra”. Note that the Chinese variant will have the same specifications as the Korean variant that we previously spotted. Therefore, we can easily say that the Galaxy W25 Ultra will be a Chinese clone of the Galaxy Z Fold 6 Ultra.

The New ‘Fold’ will be wider than its predecessor

The previous leaks also revealed Galaxy Z Fold 6 will come with a slightly refreshed design. While renders of the Galaxy Z Fold 6 series have surfaced online, and Samsung Kazakhstan even released official images of the Z Fold 6 and Z Flip 6. The “Galaxy Z Fold 6 Ultra” was interestingly absent on Samsung’s promotional images. This actually might reveal that only the regular Galaxy Z Fold 6 will be available globally, or that ‘Ultra’ is coming at a later date. We anticipate the Ultra variant’s introduction in 2025. Initially, we thought Galaxy Z Fold 6 Ultra would be a Korea-exclusive device, but it turned out to be available in China as well.


[ad_2]
Source link

CISA Warns of Scammers Impersonating as CISA Employees

0
[ad_1]

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a surge in impersonation scams.

These scams often involve fraudsters pretending to be government employees, using their names and titles to deceive unsuspecting victims.

Recently, CISA has become aware of scammers claiming to represent the agency, attempting to exploit individuals and businesses.

Scammers’ Tactics

According to CISA, these impersonation scammers may contact potential victims through phone calls, emails, or other communication methods.

They often request money transfers via wire, cash, cryptocurrency, or gift cards.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot.

Additionally, they may instruct victims to keep the discussion confidential, adding a layer of urgency and secrecy to their fraudulent activities.

CISA emphasizes that its employees will never make such requests or ask for sensitive financial informa

CISA advises the public to remain vigilant and take specific steps if they suspect an impersonation scammer is targeting them.

Firstly, do not pay the caller or provide personal or financial information.

Secondly, take note of the phone number from which the call originated.

Thirdly, hang up immediately to avoid further interaction. Finally, validate the contact by calling CISA (844) SAY-CISA (844-729-2472) or report the incident to law enforcement.

By following these guidelines, individuals can protect themselves from falling victim to these scams.

CISA continues to work diligently to safeguard the public and raise awareness about the tactics used by scammers.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link