Hackers Stole GoDaddy Source Code in a Multi-Year Data Breach

0
[ad_1]

In a filing with the Securities and Exchange Commission (SEC), GoDaddy revealed that three serious security breaches had impacted the company, boasting 21 million customers and almost $4 billion in revenue.

On Friday, GoDaddy, the world’s leading web hosting firm, confirmed that its network had been impacted by a data breach that started in 2020 and continued until 2022. As a result of this compromise, unidentified hackers stole the company’s source code.

Additionally, part of the stolen data included employees’ and customers’ login credentials. Moreover, the flaw allowed attackers to install malware, which would redirect customers’ websites to malicious domains.

This should not come as a surprise, since GoDaddy has a history of security-related incidents. For instance, in November 2021, hackers accessed 1.2 million GoDaddy customers’ accounts.

In November 2020, GoDaddy revealed that its employees had been tricked by hackers into modifying the DNS settings of at least two cryptocurrency websites. In April 2020, Escrow.com was defaced by hackers after they managed to hack one of GoDaddy’s employees.

As for the recent incident, in a filing with the Securities and Exchange Commission, GoDaddy revealed that three serious security breaches had impacted the company, boasting 21 million customers and almost $4 billion in revenue.

The incident started in 2020, and the latest was recorded in 2022. The company noted that a sophisticated hacker group was responsible for all the incidents. This means the same group has repeatedly invaded its networks and may or may not have left, despite the company’s extensive security measures.

The first incident occurred in March 2020, when the attackers obtained login credentials and accessed a limited number of employee accounts and hosting accounts belonging to approximately 28,000 customers. But they couldn’t access the main accounts of GoDaddy customers.

The most recent invasion was noticed in December of 2022. At that time, the attacker accessed the cPanel hosting servers. The company explained that it has responded to subpoenas about the incident that the Federal Trade Commission (FTC) issued in July 2020 and October 2021.

In November 2021, GoDaddy discovered another security breach in which the attacker obtained a password that provided access to GoDaddy’s Managed WordPress service source code.

The attackers gained access in September 2021 and obtained login credentials of WordPress admin accounts, email addresses, and FTP accounts of 1.2 million inactive currently Managed WordPress users. GoDaddy formally disclosed the breach in November 2021.

“We believe these incidents are part of a multi-year campaign by a sophisticated threat actor group that, among other things, installed malware on our systems and obtained pieces of code related to some services within GoDaddy.”

GoDaddy

GoDaddy has claimed that it has evidence, and law enforcement authorities have also confirmed that a security breach occurred, performed by an organized and sophisticated group.

Furthermore, the company added that the hackers’ primary targets are hosting services such as GoDaddy, infecting websites with malware, and launching phishing campaigns.

  1. GoDaddy customers targeted by clever phishing scam
  2. Sensitive data on 31,000 GoDaddy servers exposed online
  3. Ransomware attack hits SmarterASP.NET hosting’s network
  4. Dark web hosting firm quits after hackers delete its database

[ad_2]
Source link

New Update to Prevent Free Access to iOS 17 Developer Beta

0
[ad_1]

Developer Beta

An upcoming iOS update could prevent iPhone users from accessing the iOS 17 developer beta for free. 

Before now, users who want to enable iOS developer beta on their iPhone must install a configuration profile from the Apple Developer website. But that may no longer be the case. 

According to reports, the forthcoming iOS 16.4 now has a “Beta Updates” menu in the Settings app to allow users to enable iOS developer betas directly on their device. 

In other words, you no longer have to download configuration profiles to access the iOS beta. Furthermore, Apple intends to end profile downloads altogether, making a new menu the only way to enable developer betas on iPhones. 

The Beta Updates menu only appears on iPhones whose Apple IDs were enrolled in Apple’s Developer Program for $99 annually. That means iPhone users not part of the program can’t install the iOS 17 developer beta for free following its WWDC announcement in June. 

There’s more!

Cracking Down on Free iOS Developer Beta

Apple has been working to prevent free access to its developer betas on iPhones. 

Last year, the tech giant cracked down on websites like BetaProfiles.com that share developer beta profiles for free. Meanwhile, Apple’s legal team sent Twitter DMCA takedown notices for posts containing links to other sites such as IPSW.dev and BetaProfiles.dev. 

So how can iPhone users access beta profiles without paying the annual $99 fee?

You could try installing the iOS 17 developer beta using the IPSW file for free. However, it’s unclear whether this option is still available.

The good news is Apple’s public Beta Software Program is free. So users who want early access to the iOS 17 must wait for the public beta version, which will likely roll out in July. 

However, if you must access iOS 17 beta in June, paying the $99 to enroll in Apple’s Developer Program is best. 


[ad_2]
Source link

One UI 5.1 is here for Galaxy Z Fold 4 and Flip 4 in the US

0
[ad_1]

One UI 5.1 is here for Samsung‘s latest foldable in the US. Both carrier-locked and unlocked variants of the Galaxy Z Fold 4 and Galaxy Z Flip 4 are getting the new One UI version stateside. The company began the rollout in international markets last week.

The One UI 5.1 update for the carrier-locked Galaxy Z Fold 4 in the US comes with the firmware build number F936USQU1CWAC. That for the unlocked units is F936U1UEU1CWAC. As of this writing, the update is only available for users on AT&T, Comcast, Xfinity Mobile, Nextech, Bluegrass Cellular, US Cellular, and Cricket Wireless networks. But Samsung should soon cover devices on other networks too.

The story is similar for users of the Galaxy Z Flip 4 as well. Cellular South is the only additional carrier on which Samsung’s fourth-gen clamshell foldable is picking up the new update. But as said before, the Korean firm shouldn’t take long to bring One UI 5.1 to users on other networks. The updated firmware versions for this phone are F721USQU1CWAC (carrier-locked) and F721U1UEU1CWAC (unlocked).

One UI 5.1 reaches the latest Galaxy foldables in the US

The latest update for the Galaxy Z Fold 4 and Galaxy Z Flip 4 in the US brings the February security patch. This month’s SMR (Security Maintenance Release) from Samsung patches more than 50 vulnerabilities, including a handful of critical ones.

However, we are more interested in the content of One UI 5.1. While it may seem like a minor upgrade from One UI 5.0 that both foldable are currently running, the new release contains plenty of goodies.

For starters, Samsung has added a shortcut to Expert RAW in the stock camera app. You can now quickly switch to the professional-grade camera app (separate download) if the stock solution isn’t good enough for you.

One UI 5.1 also brings improvements to the multitasking experience on the foldable with new gestures and improved DeX. Samsung Notes, Bixby Text Call, AR Emoji, Samsung Keyboard, and other services get substantial functional improvements too. You can find Samsung’s full One UI 5.1 changelogs here (Galaxy Z Fold 4) and here (Galaxy Z Flip 4).

It’s pertinent to mention here that One UI 5.1 is causing battery drain for some users. Samsung hasn’t said anything about the issue, though. At least not yet. But you might still want to wait a few days and see if the company releases an official statement about this before installing the update. As usual, you can check for updates from the Settings app. Go to the Software update section and tap on Download and install.


[ad_2]
Source link

Microsoft is planning to integrate ads in Bing’s AI chatbot

0
[ad_1]

While it’s still early days for Bing’s AI chatbot, Microsoft is already exploring ways to monetize its investment. According to Reuters, the company is in discussions with advertising agencies to incorporate ads into the Bing AI chatbot. This move is not surprising, given the potential of AI chatbots to transform the way people search for information and the current advantage Microsoft has over industry giants like Google, which has already suffered a loss of $100 billion in market value over a botched Bard AI launch event.

How will Microsoft incorporate ads in the chatbot?

Reports suggest that the company plans to insert ads into the responses generated by the Bing chatbot, taking on traditional ads where brands pay to have their products or websites appear on search results for relevant keywords. Microsoft is already testing a version of these ads on Bing.

Secondly, Microsoft intends to introduce an advertising format customized for specific industries. For instance, when a user asks the chatbot for the most economical flights to Italy, booking website ads could appear. Additionally, Microsoft is also exploring the possibility of including ads in links that the chatbot uses for citations in its responses. This will enable advertisers to reach users in a more targeted and personalized way, benefiting both parties.

“They seem intent on starting off immediately with paid ads integrated,” said Michael Cohen, executive vice president of performance media at Horizon Media.

Integrating ads in Bing’s AI chatbot will be a game changer for Microsoft as they already have millions of people waiting to get access and every percent of the search industry market share that Microsoft gains would generate another $2 billion of ad revenue. However, there could be downsides to these ads, as users might see them as intrusive or annoying, which could detract from the user experience. Therefore, the company would need to determine the optimal balance between monetization and user experience.


[ad_2]
Source link

CEO Fraud Busted – Hacker Group Stole €38M in a Few Days

0
[ad_1]
CEO Fraud Busted

A Franco-Israeli criminal network engaged in extensive CEO fraud has been destroyed as a result of a combined investigation assisted by Europol.

The investigation was conducted jointly by Europol, the police forces of France, Croatia, Hungary, Portugal, and Spain.

In one case involving a single company, the thieves were able to steal €38,000,000 ($40.3M) in a few days, transferring the cash fast via Europe and China before withdrawing it in Israel.

Reports say five action days were the consequence of the operational efforts, and they happened in France and Israel between January 2022 and January 2023.

Results of the Five Action Days

  • 8 home searches in Israel and France
  • the key organizer’s arrest in Israel
  • 8 individuals were detained (6 in France and 2 in Israel)
  • Electronic equipment and vehicles are among the items seized, along with approximately 3 million euros from Portuguese bank accounts, 1.1 million euros from Hungarian bank accounts, 600 000 euros from Croatian bank accounts, 400 000 euros from Spanish bank accounts, and 350 000 euros in virtual currencies.
  • About 5.5 million euros is considered to be the entire worth of the seizures.

Fraudsters Impersonated CEOs 

Reports mention that employees in the target firms’ financial departments were approached by fraudsters posing as CEOs, and they tricked them into making payments to bank accounts controlled by the criminals.

BEC scams typically rely on hacking into the target company’s email accounts to covertly monitor communications and spot possibilities like an impending contractor payment.

When the time is right, the scammers send an email from the hacked user asking the accounting division to quickly modify the information for the receiving bank account. Alternatively, scammers may pose as a contractor and unexpectedly demand payment or as the CEO and direct the accountants to make a transfer urgently.

One of the suspects pretended to be the CEO of a metallurgy-focused company with headquarters in the Haute-Marne department of northeastern France around the beginning of December 2021. 

The scammer requested that the company’s accountant send a confidential and urgent transfer of 300 000 EUR to a bank in Hungary. A few days later, when the accountant attempted to transfer EUR 500 000 while claiming to be the CEO of the business, the scam was exposed.

A Paris-based real estate developer also fell prey to fraud with a similar method of operation in late December 2021. Yet in this instance, the damages were significantly greater. The suspects pretended to be lawyers working for a reputable French accounting firm in order to commit the fraud. 

The scammer demanded a sizable, urgent, and confidential transfer after winning the victim’s trust. They convinced the Chief Financial Officer (CFO) to send millions of euros abroad while posing as advisors. They stole over 38 million euros from the business overall in a sort of days.

“The analysis led to the identification of links between countries to enable the urgent seizure of criminal assets before the suspects could launder them”. 

“On the action days, Europol deployed experts to France, Hungary, and Israel to cross-check operational information against Europol’s databases in real-time and provide forensic support on the ground”, Europol.

In order to cross-check operational data against its databases in real-time and give forensic help on the ground, Europol sent experts to France, Hungary, and Israel.

Network Security Checklist – Download Free E-Book


[ad_2]
Source link

Original Galaxy Fold gets Samsung’s February 2023 update

0
[ad_1]

Samsung is rolling out a new software update to the Galaxy Fold, the world’s first globally available commercial foldable smartphone. The update is available for the 4G model in Latin America. It brings the February 2023 security patch to the device. The company should soon cover the foldable with the February SMR (Security Maintenance Release) in other markets too, including the US. The 5G model, which wasn’t sold stateside, should also get the new security patch in the coming weeks.

The latest update for the original Galaxy Fold 4G in Latin America comes with the firmware build number F900FXXS6HWA2. The rollout is live in Brazil, Colombia, Guatemala, Mexico, and Panama (via). Unsurprisingly, the new software release doesn’t bring anything notable for users. Samsung is only seeding the latest vulnerability fixes. The February SMR patches more than 50 vulnerabilities, including at least five critical issues. Seven vulnerabilities patched this month were Galaxy-specific. Samsung eliminated some major security issues with the Contacts and Phone apps, Secure Folder, and more.

All of these vulnerability fixes should reach the Galaxy Fold in other markets over the next few weeks. As usual, you can check for updates from the Software update menu in the Settings app. Simply tap on Download and install to see if you have any OTA (over the air) updates pending download. If available, you’ll be prompted to download it. If there’s no update waiting for you, wait a few days and check again. You may also get a notification once the OTA release hits your Galaxy Fold unit. Note that updates are released in batches and may not be available to everyone immediately.

Samsung’s first-ever Galaxy Fold will not get the One UI 5.1 update

This week, Samsung released the One UI 5.1 update for millions of Galaxy users around the world. Debuted with the Galaxy S23 series earlier this month, the new One UI version has reached the Galaxy S22, Galaxy S21, Galaxy S20, Galaxy Z Fold 4, Galaxy  ZFlip 4, Galaxy Z Fold 3, Galaxy Z Flip 3, and many other flagship models. The Korean firm is also expected to roll out the update to some premium models in the Galaxy A lineup.

However, the original Galaxy Fold will not get One UI 5.1. In fact, the aging foldable didn’t even receive One UI 5.0 or Android 13. The handset arrived running Android 9 Pie and will end its life on Android 12. It will now only get security updates. Those won’t come for much longer either. Samsung will likely offer official support for the device until September this year, which is when it will four years in the market. Meanwhile, the company is expected to launch its fifth-gen foldables in August. We will keep you posted.


[ad_2]
Source link

Samsung patent envisions a projector-equipped Galaxy Watch

0
[ad_1]

Samsung may have worked out a way to make the tiny screen on smartwatches more usable. It could attach a projector to the Galaxy Watch and use it to turn your hand or any adjacent surface into additional screen space. A newly-published patent filing from the Korean brand envisions this futuristic solution.

Spotted by Wareable, Samsung originally filed this patent application in Korea back in July 2021. The United States Patent and Trademark Office (USPTO) received the application in August last year. It was eventually published earlier this month. The patent concerns a “wearable electronic device including a projection display”. The USPTO documents describe the product as “a projection display disposed on a side portion of the housing and configured to display information on a display area adjacent to the housing.”

In simpler terms, it is a smartwatch with a built-in projector. Samsung explains that the wrist wearable can have the projector attached to the side. It can be used to project additional screen space on any adjacent surface. You could turn the back of your hand into a screen for your Galaxy Watch.

The virtual screen can mirror the watch’s screen or display something else. In that sense, you may be able to watch videos, play games, and do much more. Maybe include a camera too for capturing photos and making video calls.

Samsung’s patent application contains tons of sketches and drawings explaining how it plans to pull this off. The company says it could fit a bunch of lenses and LEDs onto the watch to project undistorted images on the adjacent surface. The lenses and LEDs could be arranged in multiple rows to ensure clear images even if the surface isn’t flat. You can find all the technical tidbits about this ambitious product here, complete with official schematics.

Samsung patented a projector-equipped Galaxy Watch in the past as well

This isn’t the first time we are seeing Samsung patent a projector-equipped smartwatch. The company also patented a similar concept in 2016. Needless to say, that product never saw the light of day. And we have little hope about this one too. It appears to be one of those patents that tech companies just file just to protect an idea. The Korean firm likely isn’t working on anything close to this. However, you can never rule out the possibility of Samsung making a projector-equipped Galaxy Watch in the future. We will keep an eye on it and let you know accordingly.

Samsung Galaxy Watch patent projector


[ad_2]
Source link

Zuckerberg copies Musk announcing Meta Verified for Facebook and Instagram

0
[ad_1]
It looks like Twitter isn’t the only company willing to put a little blue checkmark next to your name in return for a stream of monthly payments. As you probably know, Twitter is asking $8 per month or an annual payment of $84 in order to join Twitter Blue, which, among other features, will allow you to have your identity verified with a blue checkmark next to your name. Today, Meta co-founder, chairman, and CEO Mark Zuckerberg announced that Meta will test a new service called Meta Verified.
Meta calls Meta Verified a subscription bundle for Instagram and Facebook and includes a verified badge that shows that you are who you say you are and have verified your identity using a form of government ID. The bundle also helps protect subscribers from having their identities impersonated by using “proactive account monitoring.” Members of Meta Verified also will have access to a real person to handle common issues that an Instagram or Facebook user might have.

Meta Verified subscribers will have their content more prominently featured on Instagram and Facebook

Other features of the program will give Meta Verified users increased visibility and reach. This means that subscribers will have their posts prominently appear in certain areas of the Instagram and Facebook platforms such as “search, comments, and “recommendations.” Lastly, the subscription bundle offers users exclusive features that will allow them to express themselves “in unique ways.”

The Meta Verified subscription bundle will be available starting later this week in Australia and New Zealand as a direct purchase on Instagram and Facebook. Make the purchase on the web and it will cost the equivalent of $11.99 per month. If you subscribe via the Facebook or Instagram app on iOS or Android, the price is the equivalent of $14.99 per month. Hmm. Why should an in-app purchase from the App Store or Google Play Store be 25% more expensive (wink, wink)?

To be eligible to sign up for the program, accounts have to show that they were active in the past with a prior posting history, and the account owner must be at least 18 years of age. Those applying for a Meta Verified subscription must submit a government ID to Meta showing their name and photograph (like a Driver’s License, for example) which must match the name and photo used on their Facebook or Instagram account.

Meta Verified will soon be available globally

Meta says, “We’re also committed to continuous monitoring and review of reported violations, as well as taking swift action against those who try to evade our systems.” There will be no changes to accounts on Facebook and Instagram that are already verified based on previous requirements.

The company states, “Long term, we want to build a subscription offering that’s valuable to everyone, including creators, businesses, and our community at large. As part of this vision, we are evolving the meaning of the verified badge so we can expand access to verification and more people can trust the accounts they interact with are authentic.”

After being tested in Australia and New Zealand, Meta says that it hopes to bring Meta Verified to the rest of the world soon.

Back when the company was known as Facebook, it made what is arguably the best acquisition of all time in the tech industry by paying $1 billion for Instagram back in 2012. Some believe that Instagram is now worth in excess of $100 billion. Instagram has matured from a camera filter app to a broader, more well-rounded social media site.
In 2014, Facebook announced its purchase of messaging app WhatsApp for an initial price of $16 billion. By the time the deal closed a few months after it was first revealed, the final price tag of the transaction had ballooned to a range of $19 billion-$21 billion due to Facebook’s increasing stock valuation.

[ad_2]
Source link

GoDaddy Hacked – Attacked Installed Malware on its Servers

0
[ad_1]
GoDaddy Hacked

GoDaddy found malicious malware had been installed on servers in its cPanel shared hosting environment by an unauthorized third party. This results in the websites of its clients being intermittently rerouted.

“We investigated and found that the intermittent redirects were happening on seemingly random websites hosted on our cPanel shared hosting servers and were not easily reproducible by GoDaddy, even on the same website”, GoDaddy explains.

One of the biggest domain registrars, GoDaddy also offers to host services to more than 20 million users globally.

Even as the attackers had access to the company’s network for a number of years, GoDaddy only learned about the security breach after receiving customer complaints in early December 2022 that their sites were being exploited to reroute to random domains.

“We are working with multiple law enforcement agencies around the world, in addition to forensics experts, to investigate the issue further”. 

“We have evidence, and law enforcement has confirmed, that this incident was carried out by a sophisticated and organized group targeting hosting services like GoDaddy”, says GoDaddy.

GoDaddy added that evidence indicates that their apparent objective is to infect servers and websites with malware to carry out phishing operations, malware distribution, and other nefarious actions.

“Based on our investigation, we believe these incidents are part of a multi-year campaign by a sophisticated threat actor group that, among other things, installed malware on our systems and obtained pieces of code related to some services within GoDaddy,” GoDaddy said in an SEC filing.

This Multi-Year Operation Is Connected To Earlier Breaches

According to the company, this multi-year campaign is also connected to earlier breaches that were revealed in November 2021 and March 2020.

Following an attack on GoDaddy’s WordPress hosting environment using a stolen password in November 2021, 1.2 million Managed WordPress clients had their data compromised.

The affected customers’ email addresses, WordPress Admin passwords, sFTP and database login information, and SSL private keys for a subset of active clients were all compromised.

“Once we confirmed the intrusion, we remediated the situation and implemented security measures in an effort to prevent future infections”, GoDaddy

The company said it is actively gathering evidence and information about the attacker’s tactics and procedures to aid law enforcement as they continue to monitor their conduct and thwart attempts from this criminal organization.

Network Security Checklist – Download Free E-Book


[ad_2]
Source link

WhatsApp update makes sharing photos in bulk easier

0
[ad_1]

WhatsApp is adding a bunch of quality-of-life features to its Android app. The Meta-owned messaging service now lets you send more photos in bulk and caption documents before sharing. The company is also readying more such handy features which should arrive with a future update for the app.

WhatsApp improves user experience with the latest update

The latest additions to WhatsApp arrive with version 2.23.3.77 of the app for Android. The official changelog provided by the company on the Google Play Store mentions four major new features.

Firstly, you can now send up to 100 photos and videos at once. That’s a major jump from the previous limit of just 30. This change makes it more convenient to share photos in bulk. You don’t have to select batches of 30 files and repeat the process multiple times.

WhatsApp now also lets you add captions when sending documents. This feature allows you to give some context to the recipient about what you’re sending, without separately typing a message. It works for all types of documents supported by the messaging service.

The third new feature that WhatsApp added with the latest update is useful for group admins. The app now supports longer group subjects and descriptions, so you can describe your group better. The subject field supports 100 characters, while you can add descriptions longer than 2,000 characters. That should be enough to lay out the group rules and other important communication for members.

WhatsApp’s changelog on the Play Store also mentions the addition of personalized avatars. However, this feature was rolled out a couple of months back with version 2.22.24.73 of the app. Nonetheless, if you didn’t already know, you can go to Settings > Avatar on WhatsApp to create personalized avatars that can be sent as stickers or used as profile photos. WhatsApp lets you choose between various skin tones, hairstyles, hair colors, outfits, body types, eye colors, and various accessories to create an avatar unique to you.

WhatsApp is readying more new features

Apart from these, WhatsApp is also working on a host of other new features. It recently started beta-testing transcriptions for voice messages. The company is also developing a way to let you save selected messages in disappearing chats. We will let you know when these features roll out to the public. In the meantime, you can click the button below to download the latest version of WhatsApp for your Android devices from the Google Play Store.

DOWNLOAD WHATSAPP


[ad_2]
Source link