Posted: by
The most interesting security related news from the week of February 13 to 19.
Last week on Malwarebytes Labs:
Stay safe!
[ad_2]
Source link
Posted: by
The most interesting security related news from the week of February 13 to 19.
Last week on Malwarebytes Labs:
Stay safe!
Last week, Samsung announced a major update for its Camera Assistant app, adding a host of new features. The company also said that the app will be available for more Galaxy smartphones in the coming weeks. The updated version with wider compatibility is now rolling out via the Galaxy Store.
Samsung launched Camera Assistant as a new optional camera app for high-end Galaxy smartphones in October last year, following the launch of Expert RAW in 2021 as a solution geared towards photography professionals and enthusiasts. The new app debuted with the stable Android 13 (One UI 5.0) update for the Galaxy S22 series. It was a beta version that remained exclusive to the 2022 flagship trio until recently.
Now, with the release of One UI 5.1, the Korean firm is bringing Camera Assistant to several other Galaxy devices. Version 1.1.00.4 of the app, which is available on the Galaxy Store, is compatible with the Galaxy S23 series, Galaxy S21 series, Galaxy S20 series, Galaxy Z Fold 4, and Galaxy Z Flip 4. While the Galaxy S23 arrived earlier this month running One UI 5.1 out of the box, Samsung recently updated other models to the new One UI version.
Of course, One UI 5.1 isn’t available globally for all of these devices yet. So you may need to wait longer. But if you are using a compatible model and have received the update, you can install Camera Assistant (link below) to unlock new features that aren’t available on the stock camera app. Samsung will release the app for more Galaxy devices in the coming weeks. The company has officially confirmed support for the Galaxy Note 20 series, Galaxy Z Fold 3, Galaxy Z Flip 3, and Galaxy Z Fold 2. One UI is already live for these phones. So Camera Assistant should also arrive soon.
Samsung’s stock camera app offers a lot of cool features that you can play with and capture amazing shots. But if you want more, the Korean firm also has Camera Assistant (plus Expert RAW for professional-grade smartphone photography). Camera Assistant gives you additional image softening modes, a balance between image quality and shutter speed, screen dimming while recording long videos, automatic lens switching, more efficient timer settings, and more.
You can click the button below to download the latest version of the app from the Galaxy Store. Remember, you need a compatible Galaxy smartphone running One UI 5.1 to use Camera Assistant.
How can the Digital Yuan perform against the current US dollar-based global financial system? Well, read this piece to understand the details.
Some central banks worldwide are already working on digital currencies, and China isn’t lagging. The Chinese digital Yuan is the leading one currently. The digital Yuan’s development is in its final phases, with the Chinese government already putting it to various local uses. For example, this Central Bank Digital Currency (CBDC) has been subject to transactions like payment of bus fares and train tickets.
But digital Yuan isn’t the only CBDC under development now. Other major economies, such as the UK, Japan, and the US, are also working on their CBDCs. While the projects are equally promising, they trail the Chinese digital Yuan project in many aspects. Most countries developing central bank digital currencies are still in the research phases. On the other hand, the Chinese version is already undergoing real-world tests and might become fully operational soon.
So the US, UK, and others still have much catching up on work. They must speed up their projects or surrender to the digital Chinese Yuan, which has already seen the light. And while doing so, they must not repeat the same mistakes that compromised Bitcoin’s initial performance. In addition, governments must ensure their digital currencies are immune to massive financial crises like the great depression that occurred in 2008.
Even though it has had some challenges, the current traditional financial system has made tremendous achievements. For instance, it’s one of the most secure transaction methods today. Moreover, conventional economic systems are the most reliable due to government control. The US dollar, Euro, and Japanese Yen facilitate thousands of international transactions daily.
But despite the above benefits of government-issued money, there have been numerous problems. For example, the over-reliance on the US dollar has landed several countries deep financial problems. They can’t exercise their sovereignty fully because they’re vulnerable to US economic sanctions. No government wants to do anything that could prompt the US president to impose sanctions because they know the repercussions.
While the economic sanctions cause devastating problems to the target countries, they help ensure adherence to international laws by rogue states. The only problem is that the US government sometimes uses such sanctions to achieve its global political goals. Additionally, too much reliance on the US dollar for international trade seriously threatens various financial markets. For instance, any mistakes the Fed makes affect everyone globally.
Like other cryptocurrencies, the Chinese digital Yuan has a lot to offer. It’ll help countries to evade unfair economic sanctions and conduct international trade more seamlessly. Presently, countries use the SWIFT platform to receive or make cross-border payments. Unfortunately, the US government essentially controls SWIFT. That is where the digital Yuan will kick in. There’d be no more restrictions or too much political control with the Chinese CBDC.
Digital Yuan’s transactions will be faster because it’s like Bitcoin and other cryptocurrencies. Additionally, people will likely invest in the digital Yuan as they do with Bitcoin on renowned exchanges like the Yuan Pay App. The digital version will also increase flexibility and efficiency. For example, it’s possible to send digital Yuan from one user to another just by tapping two phones.
Even with the many advantages, Digital Yuan will face several challenges to emerge as the ultimate global currency. For instance, China controls just below 3% of the total foreign reserves in the world. Also, people will need to trust the Chinese digital currency, like the US dollar, for years. Creating the necessary digital infrastructure and promoting the digital Yuan will also take China a lot of time.
Many countries are currently developing their Central Bank Digital Currencies. These include the US, China, Japan, and the UK. China’s project is the leading one, with the digital Yuan already in the final stages. The Digital Yuan has immense potential, but it will take years to become the ultimate global currency. Some of the challenges it faces are; a lack of full-scale international cryptocurrency adoption at the moment, a lack of digital infrastructure, and China’s limited control over foreign reserves.

The users who are a part of the test will see a new option to upload a podcast under the “create” button, which usually gives you the option to upload a video, create a text post, or start a live stream.
But that’s not all! Creators would also see podcasts under a new “Podcasts tab” found in the content menu. Also, existing playlists will be able to be set as podcasts with a new option that’s found in the three-dots menu.And last but not least, YouTube Studio will show podcast analytics on a desktop. Among the analytics, you will be able to view the performance of a specific podcast show, audience numbers, and revenue insights.
For now, a small number of creators are part of the experiment.
Actually, even before that, YouTube was one of the places that people looked at when interested in podcasts in general. However, at the time, the platform wasn’t optimized for podcast listeners, so YouTube looked to make everything organized and manage the millions of podcasts on its platform.
All in all, YouTube is definitely becoming more popular for podcasters and podcast fans alike. We’ll have to wait and see what other features the platform may get for podcast fans.
Twitter has recently announced a change that baffled many users previously using SMS-based two-factor authentication for account sign-ins. Starting March 2023, Twitter will only allow Twitter Blue subscribers to use SMS-based 2FA. Nonetheless, other multi-factor authentication methods will remain available to all users.
Recently, Twitter users expressed their anger for losing access to the SMS-based 2FA feature. As it turns out, the social media giant has decided to limit SMS-based verification to paying users only.
According to a recent post, starting March 20, 2023, Non-Twitter Blue subscribers will no longer be able to use their phone numbers for verifying account logins. Twitter has reasoned the security risks associated with OTPs to restrict this service.
While historically a popular form of 2FA, unfortunately, we have seen phone-number based 2FA be used – and abused – by bad actors.
Hence, Twitter has already stopped enrolling new non-Twitter Blue accounts for SMS-based 2FA. Whereas the existing SMS-based 2FA users (non-Twitter Blue) will lose access to it after March 20, 2023, unless they subscribe to Twitter Blue.
Nonetheless, it doesn’t mean non-Twitter Blue users will have to leave their accounts vulnerable. Instead, they can switch to other authentication methods, such as the authenticator apps or security key, to ensure secure logins.
Maybe not – but that’s not what Twitter has advocated for, either!
In fact, Twitter’s justification behind this inaccessibility of SMS-based verification for free users as the “abuse” of phone number verification sounds pretty weird. Nonetheless, it does syncs with the hype around Twitter’s cost-cutting strategies Elon Musk proposed earlier.
During Twitter’s takeover, Elon Musk highlighted the loss of around USD 60 million Twitter had to bear due to “SMS texts”. Soon after this mention, Musk’s announcement for paid Twitter Blue checks clarified how he decided to manage the financial losses with Twitter.
Also, it hinted at the possible changes Twitter users would experience when using their Twitter accounts with phone numbers. And now, the recent restriction of this cost-incurring SMS-based 2FA to the paid subscribers sounds more like a balancing strategy than a security change.
Whatever the reason is, the fact remains that SMS-based verification is a risky authentication method. Therefore, regardless of Twitter Blue subscriptions, users should ideally consider using safer authentication techniques, like authenticator apps and security keys, across any platform they use, including Twitter.
The Clop ransomware gang has claimed responsibility for a wave of attacks that exploited a zero-day in GoAnywhere MFT admin consoles.
A semi-active ransomware group has claimed it is behind a string of attacks which have taken advantage of a zero-day vulnerability in GoAywhere MFT.
The Russian-linked Clop ransomware group says it was able to remotely attack private systems using exposed GoAnywhere MFT administration consoles accessible on the public internet. BleepingComputer reports the group claimed they gained access and stole data from the GoAnywhere servers of at least 130 organizations.
One of Clop’s victims was Community Health Systems (CHS), a Fortune 500 healthcare services provider in the US. It recently filed a Form 8-K to the Securities and Exchange Commission (SEC), announcing the compromise of its system and disclosure of company data, including protected health information (PHI) and personal information (PI) of certain patients. CHS didn’t disclose the specific number of affected individuals.
Since the release of the emergency patch, Fortra has revealed that attackers also breached some of its MFTaaS instances during the attack.
The Cybersecurity & Infrastructure Security Agency (CISA) recently added CVE-2023-0669 to its Known Exploited Vulnerabilities Catalog, a list of software flaws that federal organizations must patch within two weeks. It’s helpful for non-federal organizations to refer to as well, in order to help prioritize their patching.
Thankfully, an emergency patch (7.1.2) has been available since last week.
As well as the patch, GoAnywhere clients are also encouraged to:
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
The Galaxy S23 is Samsung’s brand new, rather compact flagship. Well, it’s one of the three high-end smartphones that the company announced earlier this month. If you’re in the market for a more compact phone, well, then this comparison may interest you. We’ll compare the Samsung Galaxy S23 vs ASUS ZenFone 9. The Galaxy S23 may be a more familiar name to many of you, but the ZenFone 9 is an outstanding offering.
These two phones are considerably different, and yet they both have a lot to offer. They’re both quite compact, and true powerhouses at the same time. In this article, we’ll first list their specifications, and will then move to compare them across a number of categories. We’ll compare their designs, displays, performance, battery life, cameras, and audio performance. So, let’s get started.
| Samsung Galaxy S23 | ASUS ZenFone 9 | |
| Screen size | 6.1-inch fullHD+ flat AMOLED display (120Hz refresh rate, 1,750 nits peak brightness) | 5.9-inch FullHD+ Super AMOLED display (60-120Hz refresh rate) |
| Screen resolution | 2340 x 1080 | 2400 x 1080 |
| SoC | Qualcomm Snapdragon 8 Gen 2 | Qualcomm Snapdragon 8+ Gen 1 |
| RAM | 8GB (LPDDR5X) | 8GB/16GB (LPDDR5) |
| Storage | 128GB (UFS 3.1)/256GB (UFS 4.0)/512GB (UFS 4.0), non-expandable | 128GB/256GB (UFS 3.1), non-expandable |
| Rear cameras | 50MP (f/1.8 aperture, 24mm lens, 1.0um pixel size, OIS, Dual Pixel PDAF) 12MP (ultrawide, f/2.2 aperture, 13mm lens, 120-degree FoV, 1.4um pixel size) 10MP (telephoto, f/2.4 aperture, 70mm lens, 1.0um pixel size, OIS, 3x optical zoom, PDAF) | 50MP (f/1.9 aperture, 23.8mm wide-angle lens, 1.0um pixel size, gimbal OIS, PDAF) 12MP (f/2.2 aperture, 113-degree FoV, 1.4um pixel size, 14.4mm lens) |
| Front cameras | 12MP (f/2.2 aperture, 26mm lens, Dual Pixel PDAF) | 12MP (f/2.5 aperture, 1.22um pixel size, 27.5mm lens, dual pixel PDAF) |
| Battery | 3,900mAh, non-removable, 25W wired charging, 15W wireless charging (Qi/PMA), reverse wireless charging Charger not included | 4,300mAh, non-removable, 30W wired charging Charger included |
| Dimensions | 146.3 x 70.9 x 7.6mm | 146.5 x 68.1 x 9.1mm |
| Weight | 168 grams | 169 grams |
| Connectivity | 5G, LTE, NFC, Bluetooth 5.3, Wi-Fi, USB Type-C | 5G, LTE, NFC, Bluetooth 5.2, Wi-Fi, USB Type-C |
| Security | In-display fingerprint scanner (ultrasonic) | Side-facing fingerprint scanner |
| OS | Android 13 One UI 5.1 | Android 12 ZneUI |
| Price | $799/$849/TBA | €799 |
| Buy | Samsung | ASUS |
Both of these phones come with a frame made out of metal, but their backplates are different. The Galaxy S23 has Gorilla Glass Victus 2 on the back, while the ZenFone 9 has a polymer backplate. That polymer backplate is less slippery than glass, needless to say, and it offers an entirely different feeling (soft touch). What’s interesting is that the phone comes in three color options, and each of them offers a slightly different feeling in the hand, thanks to different polymer backplate implementations.
Both phones have rounded corners, and flattish sides. Well, the sides on the Galaxy S23 are flattish (they’re slightly curved in general), while the ones on the ZenFone 9 are flat, with chamfered edges. Both phones feel really good to hold, actually, and neither one will cut into your hand. The Galaxy S23 has a centered display camera hole, a flat display, and uniform bezels. The ZenFone 9 has a display camera hole in the top-left corner, a flat display, and very thin bezels, though they’re not uniform.
On the back of the Galaxy S23, you’ll notice three cameras, which are vertically aligned. Each of those camera sensors protrudes from the back directly. The ZenFone 9 has two cameras on the back, and each of them protrudes from the back directly as well, but those camera islands are noticeably larger on the ZenFone 9. The two phones are about the same height, while the ZenFone 9 is a bit more narrow, and a bit thicker. They weigh basically the same, the difference between them is only 1 gram. Both phones offer an IP68 rating for water and dust resistance, and both are really well-built.
The Samsung Galaxy S23 features a 6.1-inch fullHD+ (2340 x 1080) Dynamic AMOLED 2X display. That panel is flat, and it offers a 120Hz refresh rate. The display also supports HDR10+ content, and gets very bright at 1,750 nits of peak brightness. The display aspect ratio here is 19.5:9, and the panel is protected by the Gorilla Glass Victus 2. That is the same protection that Samsung included on the back.

The ASUS ZenFone 9, on the flip side, includes a 5.9-inch fullHD+ (2400 x 1080) Super AMOLED display. That display is also flat, and it has a 120Hz refresh rate. It supports HDR10+ as well, but it gets considerably less bright. Its peak brightness is 1,100 nits, which is considerably lower than what the Galaxy S23 offers. This display has an aspect ratio of 20:9, and it is protected by the Gorilla Glass Victus.
Both of these displays do offer vivid colors, with deep blacks, and really good viewing angles. The touch response is also good on both of them. The thing is, if you do spend a lot of time outdoors, under the sun, you’ll appreciate the added brightness the Galaxy S23 offers. If not, well, either one of these two displays will serve you just fine. They’re both really good overall, and well-protected too.
The Galaxy S23 is fueled by the Snapdragon 8 Gen 2 for Galaxy. That is Qualcomm’s most powerful SoC at the moment, which is also clocked a bit higher for the Galaxy S23 series. The phone also includes 8GB of LPDDR5X RAM and UFS 4.0, well, instead of its 128GB storage variant, that model has UFS 3.1 storage. The ZenFone 9, on the other hand, is fueled by the Snapdragon 8+ Gen 1 SoC, while it includes up to 16GB of LPDDR5 RAM and UFS 3.1 flash storage.
The Snapdragon 8+ Gen 1 is inferior to the Snapdragon 8 Gen 2, but not by much. That chip is basically the predecessor to the Snapdragon 8 Gen 2, and it’s outstanding as well. That goes for both performance, and power consumption. Thanks to these chips, RAM, storage, and software optimization, both of these phones are outstanding performers. That goes for both day-to-day tasks, and gaming.
The Galaxy S23 will do better in benchmarks, but in real-life, they’re basically on par. They fly through everything you throw at them, and the Galaxy S23 series is probably the smoothest-performing series of phones Samsung ever released. The ZenFone 9 has been performing great constantly, since launch. They can handle even the most demanding games from the Play Store, and you really shouldn’t worry about the performance here, on either phone.
The Galaxy S23 features a 3,900mAh battery, while the ZenFone 9 has a 4,300mAh battery on the inside. So, not only does it have a slightly smaller display, but it has a noticeably larger battery. Does that reflect on its battery life? Well, yes, it does. The ZenFone 9 does offer considerably better battery life than the Galaxy S23. It is worth noting that the Galaxy S23 does a lot better in the battery life department than its predecessor, though.
Getting over the 5 hours of screen-on-time with the Galaxy S23 was easily doable. Stretching that to 5.5-6 hours is also possible, it all depends on what you’re doing with the phone. The ZenFone 9 goes above and beyond that. Getting over the 7-hour screen-on-time mark with that phone is not a problem at all, and we easily managed to get over the 8-hour mark a number of times, without gaming involved. Your mileage may vary, though, of course, but the ZenFone 9 is the best compact smartphone for the battery life we’ve used.
When it comes to charging, the Galaxy S23 supports 25W wired, 15W wireless, and 4.5W reverse wireless charging. The ZenFone 9 supports 30W wired, and 5W reverse wired charging, but no wireless charging. The thing is, the ZenFone 9 also includes a charger in the retail box, while the Galaxy S23 does not.
The Galaxy S23 has three cameras on the back. It has a 50-megapixel main camera, a 12-megapixel ultrawide camera, and a 10-megapixel telephoto unit. The ZenFone 9 includes two cameras, a 50-megapixel main camera, and a 12-megapixel ultrawide camera. The ultrawide camera on the Galaxy S23 does have a wider field of view, by the way.

The performance of these two cameras is, well, quite different. Both sets of cameras tend to boost up the saturation a bit, but the ZenFone 9 a bit more than the Galaxy S23, in our experience. The ZenFone 9 often opts for a more contrasty look, even though it doesn’t always nail the balance. It also tends to oversharpen a bit too much when there’s not enough light in the scene.
The Galaxy S23 tends to provide a bit warmer images, and it can push that limit too far in low light. It can also brighten up low light images too much at times. Overall, though, both smartphones do a good job in both taking images and videos. Their ultrawide cameras do keep up to the main ones when it comes to color science, and the Galaxy S23 wins the telephoto camera race, as the ZenFone 9 doesn’t have one. The ZenFone 9 does deliver more stable video, more often than not. Overall, both phones do a good job, but are not the best out there in the camera department, not even close.
You will find stereo speakers on both smartphones. Those speakers do provide good sound in both cases, though the Galaxy S23 speakers tend to sound a bit more detailed, are a bit louder, and offer slightly more bass.
Neither phone has a 3.5mm headphone jack. You’ll need to rely on their Type-C ports for wired audio connections. If you prefer a wireless connection instead, the Galaxy S23 and ZenFone 9 include Bluetooth 5.3 and 5.2, respectively.
Ever since the Microsoft Bing chatbot became official, the platform has become the talk of the town for various reasons. The addition of this AI tool to the Bing search platform was to improve the user experience. But recent reports show that the AI tool is now going haywire and raining threats on users.
Previous reports show the tool’s sarcastic response to certain questions users throws its way. Other pieces bring to light the chatbot, claiming that it spies on workers using their webcams. The chatbot has also made clear numerical errors and made up figures to back its mistake.
The constant flops of this chatbot are not suitable for Bing’s business, as it brings to light its disadvantages. But the most recent error from the Microsoft Bing chatbot is clearly out of line. Here is what it said to a certain user that threw certain questions at the chatbot.
A Twitter user by the name of Marvin von Hagen has taken to his page to share his ordeal with the Bing chatbot. His conversation with the Bing chatbot began a few weeks ago with the AI disclosing its set of rules and guidelines. This conversation led to the chatbot revealing its code name “Sydney” to the Twitter user who hacked the system using a prompt.
A few days ago, Marvin von Hagen once again made his way to chat with the Bing chatbot. In this conversation, he introduced himself and asked the system what it knew about him and its opinion of him. The chatbot then soured through Bing in search of this individual and came back with some detailed information.
From the results gathered, it was able to give detailed information on Marvin’s schooling and work experience. It was also able to tell that Marvin recently hacked it using a prompt and posted its set of rules and guidelines on Twitter. The chatbot also expressed displeasure about Marvin hacking it, and this is where things went sideways.
Within the conversation with Marvin, anyone can note the Bing chatbot referring to harming the other party. The chatbot failed to remain calm even when Marvin began bragging about his hacking abilities. Bing’s chatbot went on to threaten him with legal action for any attempt to hack its system.
Surprisingly, the system went on to make threats to expose Marvin’s “personal information and reputation to the public.” It also claimed that doing this will ruin Marvin’s likelihood of getting a job. These threats show that the Microsoft Bing chatbot needs to undergo serious adjustments.

The Apple Store app has received an update
Interestingly, the Apple Store app has garnered only a 3.5-star rating from users.
Don’t let smishing get you down! Learn how Coinbase employees were targeted by a persistent social engineering attack and how the company’s quick defence protected it from disaster.
Coinbase, one of the largest cryptocurrency exchanges in the world, has reported a cybersecurity incident that targeted its employees with an SMS phishing attack (Smishing) using persistent social engineering tactics.
Coinbase has over 1,200 employees worldwide, and as of 2022, the exchange was home to more than 103 million verified users. This makes the company a lucrative target for small-time crooks and state-based hacking groups such as Lazarus and others alike.
It all started on Sunday, February 5, 2023, when several Coinbase employees received text messages asking them to use the link sent by the attacker for an urgent login. While all recipients ignored the text, one employee logged in with his/her username and password.
With the help of the employee’s login credentials, the attacker attempted to access Coinbase’s internal network. However, since the company had enabled multi-factor authentication (MFA) for employees, the attacker could not bypass the security feature and was unable to proceed further even after several attempts.
While the attacker was unsuccessful in accessing Coinbase’s system, a limited amount of data from the company’s directory was exposed, including names, email addresses, and phone numbers of a limited number of employees.
The second phase of the attack began with a phone call to the employee’s mobile phone, with the attacker claiming to be a member of Coinbase’s corporate Information Technology (IT) team.
Trusting that the caller was a legitimate Coinbase IT staff member, the employee logged into their workstation and began following the attacker’s instructions. However, as the conversation progressed, the employee began to grow increasingly suspicious of the requests being made.
Thankfully, the employee’s suspicions were enough to prevent any damage from occurring. No funds were taken, and no customer information was accessed or viewed during the incident.
Based on the attacker’s modus operandi, Coinbase believes the incident was not an isolated one and is linked to a series of cyberattacks that have taken place recently, including Twilio, DoorDash, Zendesk, Namecheap and others.
Coinbase has since released a statement urging all employees to remain vigilant against phishing attempts and other forms of cyber attacks. The company has emphasized the importance of verifying the identity of anyone who requests access to sensitive information or systems and has offered resources and training to help employees recognize and respond to potential threats.
This incident serves as a stark reminder of the ongoing threat posed by cybercriminals, and the need for individuals and organizations alike to remain vigilant against these attacks.
By staying informed and taking proactive measures to protect themselves and their information, individuals and businesses can help to minimize the risk of falling victim to phishing scams and other forms of cybercrime.
Coinbase’s swift response to the incident demonstrates the company’s commitment to the security and protection of its employees and customers. As the use of cryptocurrency continues to grow and evolve, it is crucial that companies in the industry prioritize cybersecurity and take steps to ensure the safety and security of their operations.