How Log Monitoring Prevents Web Attacks?

0
[ad_1]
Log Monitoring

Security logging and monitoring failures feature in the OWASP Top 10 list, moving up to #9 from #10 in the 2017 list. Why so?

Because logging and monitoring failures hinder your effective threat detection.

If the website risks are not logged properly, flaws will go unnoticed and unaddressed. And the longer it takes to identify and stop threats, the higher the damage and costs.

Given the importance, website log monitoring is critical to detect and respond to web attacks

An Introduction to Website Logs

Website logs are text files that contain time-stamped immutable records of events. All websites, applications, network devices, operating systems, servers, etc., automatically write and maintain log files.

Web logs contain events such as

  • Hits to the website
  • Views of HTML documents, images, and other objects
  • Who is visiting the site?
  • Where are they visiting from?
  • Visitors’ activities on the site

Types of Website Logs 

There are different kinds of website logs based on the source of logs and their nature. Here are some examples:  

Web Server Logs

They record all activities related to a specific web server over a defined time period. They offer an unfiltered look at the website traffic and all requests to the server. Stored as text documents in the database, they are created automatically.

It constantly collects server data to provide organizations insights on when, how, and by whom the server is used. These website server logs contain raw data and can be customized to produce other reports. 

The types of server logs that can be produced are: 

  • Error Logs 
  • Access Logs
  • Referrer Logs

Activity Logs 

They are user-friendly and readable logs. They inform the organization about all the activities taken by every user on the website. 

Why is Website Logging So Important? 

Prevent Website Attacks 

Improved website security logs and monitoring would also play a role in prevention. It aids in the detection and response of breaches.

Some logging and monitoring flaws include the following issues:

  • Insufficient, unclear, or no logging of auditable events
  • Website logs not being examined for malicious activities
  • Improper storage of logs
  • Inadequate/ unclear error messages
  • Not using real-time log monitoring and alerting systems

The best logging and monitoring tools offer real-time alerts and insights on website changes, errors, and gaps. Thereby enabling you to prevent a wide range of attacks and data breaches. 

Detecting Anomalous/ Suspicious Behaviour

Website and web server logs offer a complete record of all events and activities happening on the website. Hence, you can seamlessly track user journeys and behavior on the site. It includes:

  • Time spent by users
  • Pages on which users spent time
  • Actions performed
  • Uploads/ downloads
  • Navigational patterns
  • Failed processes

By analyzing the logs, you can identify anomalies and suspicious behaviors of users. You can stop various attacks, including injections, bot attacks, and DDoS.  For instance, many failed login attempts often indicate a bot attack.

Gaining Visibility into Website Changes 

With a good log management and monitoring solution, website logs enable you to monitor any website changes closely. Some of the activities that logs offer visibility into are: 

  • Changes to core website files
  • Privilege escalation
  • Changes in user roles and permissions 
  • Addition, deletion, and updates to blog posts
  • File uploads 
  • Activation, deactivation, and modification of plugins and themes

Regulatory Compliance 

Most regulatory frameworks, including GDPR, HIPAA, PCI-DSS, etc., require organizations to maintain and monitor website logs.  

Debugging the Application 

Logs also provide details about the path of your code. This way, you can unearth errors and bugs in your application.

They enable you to discover errors that occur in runtime and fix them. So, website logs are useful in debugging the application. 

Monitor Website Health

With key metrics and insights, logs enable you to continuously monitor the health of your website. For instance, by using error rate insights, you can quickly identify and fix problems. 

Website logs also tell you what is happening behind the scenes and when it happened. Suppose something goes wrong with the systems/ applications or networks. In that case, you will have detailed records of all actions before the anomaly.

You can also perform forensic analysis and identify the root cause of issues. If the systems behave normally, you can find how applications react and perform. Enabling you to finetune and improve performance. 

Conclusion 

Website logs are imperative for threat detection and prevention.  They help to strengthen your website’s security, availability, and performance. 


[ad_2]
Source link

Two Supreme Court cases could change the Internet as we know it

0
[ad_1]

The Supreme Court’s reconsideration of Section 230, a law that’s been the foundation for the way in which we have used the Internet for decades, could trigger major changes.

The Supreme Court is about to reconsider Section 230, a law that’s been the foundation of the way we have used the Internet for decades.

The court will be handling a few cases that at first glance are about online platforms’ liability for hosting accounts from foreign terrorists. But at a deeper level these cases could determine whether or not algorithmic recommendations should receive the full legal protections of Section 230.

The implications of removing that protection could be huge. Section 230 has frequently been referred to as a key law, which has allowed the Internet to develop to what it is now. Whether we like it or not.

The are two cases waiting to be heard by the Supreme Court are Gonzalez v. Google and Twitter v. Taamneh. Both seek to draw big tech into the war on terror. The plaintiffs in both suits rely on a federal law that allows any USA national who is injured by an act of international terrorism to sue anyone who knowingly provided substantial assistance to whoever carried it out. The reasoning is that the platforms, Google and Twitter, provided assistance to terrorists by giving them the ability to recruit new members.

Section 230 is the provision that has, until now, protected those platforms from the negative consequences of user-generated content.

Section 230

Section 230 is a section of Title 47 of the United States Code that was enacted as part of the Communications Decency Act (CDA) of 1996, which is Title V of the Telecommunications Act of 1996, and generally provides immunity to websites from the negative effects of third-party content.

What’s in question is whether providers should be treated as publishers or, alternatively, as distributors of content created by its users.

Before the Internet, a liability line was drawn between publishers of content and distributors of content. A publisher would be expected to have awareness of the material they published and could be held liable for it, while a distributor would likely not be aware and as such would be immune.

No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.

Section 230 protections have never been limitless though, and require providers to remove material illegal on a federal level, such as in copyright infringement cases.

It all became a bit more complicated when online platforms—and social media in particular—started using algorithms that are designed to keep us occupied. These algorithms make sure that we are presented with content we have shown an interest in. The goal is to make us spend as much time on that platform as possible while the platform earns advertising dollars. While the content was not created by the platform, the algorith definitely does the bidding of the platform.

In the early days (cases that played out before the turn of the century) moderation was seen as an editorial action which shifted a platform from a distributor role into a publisher role, which didn’t exactly help to get some form of moderation started.

In modern times, now that moderation has become the norm on social platforms, the scale of content moderation decisions that need to be taken is immense. Reportedly, within a 30-minute timeframe, Facebook takes down over 615,000 pieces of content, YouTube removes more than 271,000 videos, channels and comments, and TikTok takes down nearly 19,000 videos.

Possible implications

Section 230, from an Internet perspective is an ancient law, written at a time when the Internet looked very different than it does today. Which brings us back to the algorithms that have people scrolling social media all day. One of the consequences of these algorithms noticing a preference for a particular subject is that they will serve you increasingly extreme content in that category.

Making platforms liable for the content provided by their users is likely to make everything a lot slower. Imagine what will happen if every frame of every video has to be analyzed and approved before it gets posted. We would soon see rogue social media platforms where you can’t sue anyone because the operators are hiding behind avatars on the Dark Web or in countries beyond the reach of US extradition treaties.

It could even have a chilling effect on freedom of speech, as social media platforms seek to avoid the risk of getting sued over the back and forth in a heated argument.

And what about the recent popularity surge we have seen in chatbots? Who will be seen as the publisher when ChatGPT and Bing Chat (or DAN and Sydney as their friends like to call them) uses online content to formulate a new answer without pointing out where they found the original content?

Let’s not forget sites that have an immense userbase, like Reddit, which largely depend on human volunteer moderators and a bit of automation to keep things civilized. Will those volunteers stick around when they can be blamed for million dollar lawsuits against the site?

Even easily overlooked services like Spotify could be facing lawsuits if their algorithm suggested a podcast that contains content considered harmful or controversial.

The Halting Problem

Stopping bad things from happening on platforms like Google and Twitter is an admirable ambition, but it is probably impossbile. Even if they were able to fully automate moderation, they would quickly run into the halting problem associated with decision problems.

A decision problem is a computational problem that can be posed as a yes–no question of the input values. So, is this content allowed or not? That sounds like a simple question, but is it? Turing proved no algorithm exists that always correctly decides whether, for a given arbitrary program and input, the program halts when run with that input. This is called the halting problem.

A direct derivative of the halting problem is that no algorithm will always make the correct decision in a decision problem as complicated as content moderation.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

T-Mobile hands out free MLS season pass to customers via Apple TV

0
[ad_1]

T-Mobile subscribers, that also happen to be soccer fans, are getting a big treat from their carrier by way of a free season pass for MLS. You’ll of course need to be a T-Mobile customer but this promotion should be good for new and existing customers. The offer follows on the heels of T-Mobile previous promotion where it gave out Apple TV+ subscriptions for free.

And just like that promotion, there are some caveats to pay attention to. In addition to being a T-Mobile customer, you’re limited to where you can watch these games. For starters, you can access the MLS season pass on your T-Mobile device using the Apple TV app, as long as it’s an Apple iPhone or iPad. Android devices aren’t entirely left out here though. T-Mobile says you can still watch the games through the Apple TV website using a browser. You do have to have an Apple TV+ subscription though.

You can also watch through other devices like streaming boxes. Game consoles such as the PS5 and Xbox Series X|S, and smart TVs are compatible as well.

T-Mobile MLS season pass holders can watch every regular game with no blackouts

T Mobile MLS Season Pass

If there’s one thing that feels like a miss when it comes to watching your favorite sports, it’s that there tend to be blackout dates. Times where you simply can’t watch the game as part of the package you’re on. Well, that isn’t the case with the MLS season pass. You’ll actually be able to watch every single regular season match, all MLS Cup playoff matches, and the Leagues Cup. With absolutely no blackouts.

A pretty good deal if you’re a fan of the MLS. And the even better news is that this is available to all T-Mobile customers and Metro by T-Mobile customers. You will need to have a qualifying plan though and you can’t claim the offer until February 21. Once that date comes around, you’ll find the offer in the T-Mobile Tuesdays app.


[ad_2]
Source link

How to Watch WWE Elimination Chamber 2023

0
[ad_1]

The road to Wrestlemania continues, with Elimination Chamber taking place this weekend from Montreal, Quebec, Canada. This is the second year in a row that Elimination Chamber is taking place outside of the US. With last year being held in Saudi Arabia. It’s taking place on Saturday, February 18, 2023.

There’s a lot of anticipation going into the 2023 Elimination Chamber premium live event this year. With the whole thing between Sami Zayn and Roman Reigns, Brock Lesnar being obsessed with Bobby Lashley, and there’s also two Elimination Chamber matches. And for the first time, the Elimination Chamber will play host to a mid-card championship – the US Title.

WWE Elimination Chamber Main Event Preview

Despite this being the Elimination Chamber, and there being two matches based on that gimmick, the main event is definitely Sami Zayn and Roman Reigns. This is a match that has been a long time coming, since Reigns brought Zayn into the Bloodline last year. It took Zayn a while to get all members of the Bloodline to accept him. Having to prove himself again and again. His real-life best friend and fellow Canadian, Kevin Owens, told Zayn that he needed to betray the Bloodline before they did it to him. This made sense, since Zayn was a baby face, and the Bloodline are heels.

So at the Royal Rumble, after Reigns defeated Owens, the Bloodline came out and started to beat him up some more. Zayn stepped in the way of Reigns so he was unable to hit him with the chair. And instead, told Zayn to do it. After some coercion, he did use the chair. But not on Owens. Instead, he betrayed Roman Reigns and the Bloodline, by hitting Reigns with the chair. And it looked eerily similar to when Seth Rollins did it Reigns many years earlier.

That all set up this match for the WWE Universal Championship at the Elimination Chamber. But the problem is, does the WWE see Sami Zayn as “the guy” in the company? Is he the right one to dethrone Reigns from his 900+ day reign? WWE was planning for Cody Rhodes to do this. Having him win the Royal Rumble in January, and headline Wrestlemania against Roman Reigns. But what if Zayn beats Reigns and it’s Rhodes vs Zayn at Wrestlemania?

Not to mention the fact that Elimination Chamber is in Sami’s hometown of Montreal, and the USO’s won’t be there. As they are not allowed to travel to Canada due to their DUI’s they’ve gotten while in Canada before. So the only backup Reigns will have is, Solo Sikoa.

This whole thing has wrestling fans sitting on the edge of their seats. And it’s not hard to see why.

Edge and Beth Phoenix vs Rhea Ripley and Finn Balor

Another match that is perhaps flying under the radar, is a mixed tag team match between the Judgement day, and Edge who created the Judgement Day and his real-life wife, Beth Phoenix. Rhea Ripley from the Judgement Day has been wanting a match with Beth Phoenix for a while, and the WWE has been teasing it for almost a year at this point. And we’re finally getting it, or something close to it.

We kind of already know that this will be a one-off for these four, as Rhea Ripley won the Women’s Royal Rumble match last month, and will face Charlotte Flair for the Smackdown Women’s title at Wrestlemania. But will Edge finally destroy his own creation? Like he has been promising to do for months now? We’ll find out on Saturday.

wwe elimination chamber

How to watch WWE Elimination Chamber 2023 on Peacock

First up, make sure to login to your Peacock account. Or sign up if you haven’t already.

Then click on the “WWE” tab at the top of the page. It’ll be to the right of “Sports”.

This year, Elimination Chamber is back to its regular time. With the pre-show taking place at 7PM EDT and the regular show starting at 8PM EDT. The post-show press conference is set to start at 11:30PM EDT, which will be broadcast on Peacock as well as other social channels, including YouTube.

What time does WWE Elimination Chamber 2023 start?

As mentioned, the Elimination Chamber is back in North America this year, so the starting times are back to normal, compared to Elimination Chamber in 2022.

The pre-show will kick off on Peacock and other social channels starting at 7PM EDT. This is where the experts will break down every match, as well as seeing some exclusive interviews ahead of the big premium live event.

The main show will start at 8PM EDT. Typically, these run until around 11PM EDT, and there is the press conference set for 11:30PM EDT, right after the show. So it should only be about three to three-and-a-half hours long this time.

Who’s on the card?

The card for WWE Elimination Chamber 2023 is actually fairly short. There’s only six matches on the card this time around, however there are two Elimination Chamber matches, which can take up quite a bit of time.

As of February 17, 2023, this is the card for Elimination Chamber.

  • Undisputed WWE Universal Championship: Sami Zayn vs. Roman Reigns (c)
  • United States Title Elimination Chamber Match featuring Montez Ford, Johnny Gargano, Bronson Reed, Seth “Freakin” Rollins, Damian Priest and Austin Theory (c)
  • Elimination Chamber Match to determine challenger to the Raw Women’s Title at WrestleMania featuring Carmella, Nikki Cross, Raquel González, Asuka, Liv Morgan and Natalya
  • Edge & Beth Phoenix vs. Finn Bálor & Rhea Ripley
  • Bobby Lashley vs. Brock Lesnar

As always, the card is subject to change due to injuries, time slots, etc. And where this is being written before the final Smackdown before the event, there could be changes to the card, including an additional match or two being added. We’ll be sure to update this post accordingly so you have the most up-to-date information.


[ad_2]
Source link

Android and iOS users need to uninstall these 203 apps before their bank accounts are drained

0
[ad_1]

If you worry about installing malware-laden apps on your phone that can get into your bank account and steal your money, this story might cost you some sleep but hopefully nothing more. Thailand’s Ministry of Digital Economy and Society (DES) and National Cyber Security Agency (NCSA) discovered 203 dangerous Android and iOS apps. The Bangkok Post (via LaptopMag). The ministry asked Google and Apple to remove the malicious apps from the Play Store and App Store respectively.

These malware-infected apps can be used to drain your bank account

DES Minister Chaiwut Thanakamanusorn said that both Android and iOS users should make sure that their devices don’t contain any of the infected-apps and suggested that they update their phones to make sure that they are running the most up-to-date software with the latest security patches. “The public is being asked to look out for malicious apps. If they are downloaded, hackers can steal your personal data or take control of your phones,” said the minister.

He also warned those using any type of connected device to be on the lookout for emails and texts that appear to be legitimate messages, but are not legitimate. These fake messages come from the attackers who are tricking you by asking you to tap a link that could activate the malware loaded inside a malicious app. This is called “phishing,” and the messages will often appear to come from your bank, your wireless carrier, and even companies you have dealt with in the past.

Not only are these fake texts and emails trying to get you to tap on a link, but they might also ask you for the credit card you used to make a purchase hoping to steal all of the pertinent information from you. Or they might ask for the password you use on certain apps. Never tap a link on an email or text unless you are 100% certain about the identity of the sender. If you’re not sure about the legitimacy of an email or text, call the company on the phone. Do not use any phone number or email address that comes from the suspect message.
Bank of Thailand’s (BoT) assistant governor Chayawadee Chai-Anant said that for safety reasons, mobile banking apps and e-wallets should be used on only one device. She said that the country’s central bank has instructed commercial banks to improve the security of their mobile apps.

Even if all 203 apps have been removed from the Play Store and the App Store, if they have been installed on your phone they can still cause problems for you and your bank account unless you uninstall them now. These apps have been known to steal money from bank accounts, obtain personal data stored on affected mobile devices, and can even give attackers complete control over victims’ phones and tablets.

Follow these guidelines to protect yourself from installing a malicious app in the future

We’ve included the list of all 203 apps that were used by the attackers. Again, make sure that you do not have them downloaded on your iOS, iPadOS, and Android devices. If you want to lessen your risk of installing one of these apps, check the comment section for all apps you install developed by someone or some company that you never heard of before. Look for red flags in the comments. After all, these comments come from people who have installed the app and are warning you to stay away.

If you’ve already installed an app and start experiencing things like rapid battery drain or notice that your device has slowed down noticeably, delete that app immediately. Sure, not all malware is designed to steal your money. Other infected apps are made to use your device like an ATM by running ads in the background some of which you might never see.

When it comes to your mobile devices, be smart when it comes to the apps you download.

[ad_2]
Source link

Hackers Exploit ProxyShell Flaws to Deploy ProxyShellMiner

0
[ad_1]
Hackers Exploit ProxyShell Flaws

ProxyShellMiner is being distributed to Windows endpoints by a very elusive malware operation, according to Morphisec.

To generate income for the attackers, “ProxyShellMiner” deploys cryptocurrency miners throughout a Windows domain using the Microsoft Exchange ProxyShell vulnerabilities.

ProxyShellMiner exploits a company’s Windows Exchange servers using the ProxyShell vulnerabilities CVE-2021-34473 and CVE-2021-34523 to get initial access and distribute crypto miners.

“After successfully breaching an Exchange server and obtaining control, the attackers use the domain controller’s NETLOGON folder to ensure the miner executes throughout the domain, similar to how software is delivered through GPO”, Morphisec reports.

Researchers noticed that the attackers were utilizing four C2 servers. The legitimate, infected mail servers are all where the malware-dependent files are stored.

“Mining cryptocurrency on an organization’s network can lead to system performance degradation, increased power consumption, equipment overheating, and can stop services”, according to Morphisec.

Technical Analysis of the ProxyShellMiner Malware

The malware needs a command line parameter that acts as a password for the XMRig miner component in order to activate.

“This parameter is later used as a key for the XMRig miner configuration, and as an anti-runtime analysis tactic”, Morphisec

The parameter serves as anti-analysis technique, and as a password for the XMrig miner
The parameter serves as an anti-analysis technique and as a password for the XMrig miner

The XOR decryption algorithm, an XOR key, and an embedded dictionary are all used by ProxyShellMiner. The subsequent embedded code modules are then executed using the C# compiler CSC.exe with “InMemory” compile parameters.

The malware then downloads a file with the name “DC DLL” and uses .NET reflection to get the task scheduler, XML, and XMRig key arguments. The decryption of additional files is done using the DLL file.

By setting up a scheduled activity to start when the user logs in, a second downloader achieves persistence on the compromised system. The report says four other files and the second loader are downloaded from a remote resource.

The deobfuscated scheduled task 
The deobfuscated scheduled task

Using a technique called “process hollowing,” that file determines which of the installed browsers on the hacked system would be used to inject the miner into its memory space. The mining process then starts after selecting a random mining pool from a hardcoded list.

Picking a mining pool
Picking a mining pool

Setting a firewall rule that blocks all outgoing traffic and is applicable to all Windows Firewall profiles is the last stage in the attack chain. This is done to reduce the likelihood that defenders may find infection signs or get notifications about a possible compromise from the compromised system.

“The malware waits at least 30 seconds while the target machine blocks any outbound connection. It does this to tamper with the process runtime behavior analysis of common security solutions”, researchers.

Adding a firewall rule to block all outgoing traffic
Adding a firewall rule to block all outgoing traffic

Final Thoughts

ProxyShellMiner doesn’t just disrupt business networks, drive up power bills, overheat equipment, and stop services from operating. It gives threat actors access to further evil purposes.

“Once attackers have a foothold in a network, they have deployed web shells, backdoors, and used tunneling utilities to further compromise victim organizations”, Morphisec

Hence, Morphisec encourages all administrators to install all available security updates and employ thorough and all-encompassing threat detection and defense measures to reduce the danger of ProxyShellMiner attacks.

Network Security Checklist – Download Free E-Book


[ad_2]
Source link

What it is, and how to remove it

0
[ad_1]

Is your iPhone claiming that you’ve been hacked, your phone isn’t protected, or that viruses have damaged it? It could be calendar spam.

If you open up your iPhone and see a variety of messages claiming that you’ve been hacked, your phone is not protected, that viruses have damaged your phone, or, my personal favourite, “Click to get rid of annoying ads”, fear not. It’s quite possible you’ve accidentally wandered into a common form of scam: Calendar spam.

Calendar spam is a way for scammers to insert nonsensical claims, offers, and warnings with potentially harmful links into your calendar, which triggers notifications on your device.

How you get it

The most common techniques for spreading calendar spam are bogus adverts, popups, and other forms of coding used on websites which may be of a questionable nature. They can be found on pornography sites, but also file sharing sites, unofficial streaming platforms, gaming sites, random blogs, pretty much anywhere at all.

Calendar applications like iCal make it easy to add public calendars, which are just URLs, and the scammers exploit that ease of use. The aim of the scammers’ game is to get unsuspecting users to accept a calendar subscription. Often, they will obscure the subscription with a distraction. For example, a user may be asked to confirm that they’re a human via CAPTCHA. The user clicks through, and before they realise it, they’ve also clicked “OK” to a follow-up message containing a calendar subscription.

Should you accept one of these subscriptions, the spam calendar and all related events will be added to your calendar app. The events in the calendar contain alerts, which generate notifications, which could leave your screen looking a little something like this. Should you venture into your calendar, a tangled mess of calendar entries awaits.

The links in the calendar entries lead to the usual range of spam, surveys, bogus apps, fake security tools, and more besides. They have nothing you want or need to be wasting your time on. With this in mind, what can you do about it?

How to remove it

This is such a problem point for Apple that a dedicated page exists for just this problem. There are two ways to remove calendar spam, and it’s dependent on which iOS version you use. From the help pages:

iOS 14.6 or later

  • Open the Calendars app.
  • Tap the unwanted Calendar event.
  • Tap Unsubscribe from this Calendar at the bottom of the screen.
  • To confirm, tap Unsubscribe.

Earlier versions of iOS

  • Open the Calendar app.
  • At the bottom of the screen, tap Calendars.
  • Look for a calendar that you don’t recognize. Tap the More Info button next to that calendar, then scroll down and tap Delete Calendar.

If this doesn’t fix the issue, delete the calendar subscription in Settings:

  • Open the Settings app.
  • Tap Calendar > Accounts. Or if you use iOS 13, tap Passwords & Accounts > Accounts instead.
  • Tap Subscribed Calendars.
  • Look for a calendar that you don’t recognize. Tap it, then tap Delete Account.

Not just iPhone

Spammers will try and abuse all sorts of devices, apps, and systems in order to besiege you with calendar spam (or even calendar-style spam) notification alerts. In 2019, Google Calendar users were hit with a wave of spam notifications, and Calendly users were impacted by phishers abusing the service in 2022. In that same year, new safety features appeared for Google Docs users in order to give users a little more confidence that notifications were not bogus.

No matter the device or service, anything with notification ability could be a target. In many ways, phone calendar spam is a perfect fit for phones where everyday misclicks are very common. It only takes one spam calendar prompt hidden behind something else and a split second lapse in attention for the scammers to stake a claim on your phone.

The good news is that once you understand how the scam works, it’s very easy to remove the notifications and keep your phone free from endless spam notifications.

Keeping your calendars spam free

  • Be careful where you click. Scammers have to fool you into subscribing to a calendar for this to work, so read before you click! If you do add a calendar prompt, don’t panic. Follow the removal instructions above.
  • Use Malwarebytes for iOS. It can block rogue websites and adverts, the two primary causes of unwanted calendar prompts.

Stay safe out there!


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

One UI 5.1 update is live for Galaxy S22 series in the US

0
[ad_1]

Samsung‘s One UI 5.1 update is available for the Galaxy S22 series in the US. Both carrier-locked and unlocked variants are getting the new One UI version stateside. The rollout began a few days back in Europe.

One UI 5.1 is the latest iteration of Samsung’s Android-based custom software. Built on top of Android 13, the new version debuted with the Galaxy S23 series, which launched on February 1. The Korean firm started rolling it out to older Galaxy models earlier this week. As expected, the Galaxy S22 series was the first to get it. Following the initial rollout in Europe, the update is now available in the US too.

The latest update for the Galaxy S22, Galaxy S22+, and Galaxy S22 Ultra in the US comes with the firmware build numbers S901USQU2CWAI (carrier-locked) and S901U1UEU2CWAI (unlocked). Along with One UI 5.1 goodies, the phones are also getting the February 2023 Android security patch. The new security release contains more than 50 vulnerability fixes, including a few critical ones.

But we are still more interested in One UI 5.1. The new One UI version brings a host of new features and improvements. Samsung has added new options to the stock camera app and also introduced new editing features. The update also adds English support for Bixby Text Call, Samsung Notes collaboration, improved widgets, improved multitasking, more Modes and Routines, smart suggestions, and more. You can refer to Samsung’s official changelog for all One UI 5.1 features.

One UI 5.1 will reach more Galaxy devices in the US

The Galaxy S22 series may have picked up the One UI 5.1 update first, but Samsung also seeded the new One UI version to the Galaxy S21, Galaxy S20, Galaxy Z Fold 4, Galaxy Z Flip 4, Galaxy Z Fold 3, Galaxy Z flip 3, and a few more Galaxy devices in a span of just a few hours. The rollout for all of these devices began in Europe. The company is now bringing the update to more markets. Users of these devices in the US should get One UI 5.1 soon.

As usual, you will get a notification once the OTA (over the air) release becomes available for your phone. Alternatively, you can open the Settings app on your phone, go to the Software update menu, and tap on Download and install to check for updates manually. Repeat the steps a few days later if you don’t see many updates today. We will let you know when Samsung releases the One UI 5.1 update for other Galaxy devices in the US.


[ad_2]
Source link

Elon Musk gave $1.95 billion of Tesla stock to charity last year

0
[ad_1]

According to the BBC, Elon Musk donated $1.95 billion of Tesla stock to charity between August and December last year. This charitable act is revealed in a regulatory filing and described as “a bona fide gift.” Yet, the recipient or recipients of these billions need to be clarified, and the filing didn’t reveal the names.

Of course, this is not the first time that Musk is donating billions of dollars of Tesla shares to charities. Back in 2021, he gave up $5.74 billion of shares. Additionally, he promised to donate $20 million to Cameron County schools and $10 million to the city of Brownsville in Texas for the so-called “downtown revitalization.”

Musk has recently lost his position as the wealthiest man on the planet and was replaced by Bernard Arnault, co-founder, chair, and CEO of LVMH. The reports also claim Musk lost $200 billion of his wealth in over a year.

Elon Musk donates almost $2 billion of Tesla stock to charity while the company’s stock is plummeting

Elon Musk is probably one of the most controversial people in the world due to his Twitter takeover and the radical changes he made to the social media company. Of course, Musk’s occupation as Twitter CEO didn’t go well with Tesla shareholders. They complained Musk is devoting much of his focus and time to Twitter, and the EV maker is running on a wing and prayer.

Despite growth in pre-orders and EV delivery, Tesla stock is plummeting. The company stock has fallen 45% over two months, and it’s not showing any sign of recovery (via ABC News). That’s why Elon Musk is now more serious about leaving his executive role at Twitter and returning to Tesla.

The billionaire recently said the end of this year might be a good time for him to find another CEO for Twitter. “I think I need to stabilize the organization and just make sure it’s in a financially healthy place and that the product roadmap is clearly laid out,” Musk added.


[ad_2]
Source link

Facebook drains users’ cellphone batteries intentionally says ex-employee

0
[ad_1]
A long-standing rumor suggests that the Facebook and Facebook Messenger apps drain the battery on cellphones that have the apps installed. If you believe former Facebook employee George Hayward, a data scientist, Facebook can secretly drain the battery on its users’ cellphones on purpose. As reported by The New York Post, there is actually a name for what it is that Facebook is doing, It is called “negative testing” and it allows tech companies to secretly run down the batteries on someone’s phone in order to test features on an app or to see how an image might load.
Hayward was fired by Facebook parent Meta for refusing to participate in negative testing. “I said to the manager, ‘This can harm somebody,’ and she said by harming a few we can help the greater masses. Any data scientist worth his or her salt will know, Don’t hurt people,” he told the Post.

Hayward was axed by Meta in November and originally filed a lawsuit against the company in Manhattan Federal Court. The 33-year-old worked for Meta’s Facebook Messenger app which delivers text, phone calls, and video calls between users. In the suit, Hayward’s attorney, Dan Kaiser, pointed out that draining users’ smartphone batteries puts people at risk especially “in circumstances where they need to communicate with others, including but not limited to police or other rescue workers.”

The suit had to be withdrawn because Meta’s terms of employment forced Hayward to argue his case in arbitration. Kaiser says that most people have no idea that Facebook and other social media companies can drain your battery intentionally. Commenting on the practice of negative testing, the lawyer added, “It’s clearly illegal. It’s enraging that my phone, that the battery can be manipulated by anyone.”

Originally hired in 2019, Hayward was receiving a six-figure annual paycheck from Meta. But when it came to the company’s request to perform the negative testing, Hayward said, “I refused to do this test. It turns out if you tell your boss, ‘No, that’s illegal,’ it doesn’t go over very well.”

At one point during his employment at Meta, the company handed Hayward an internal training document titled “How to run thoughtful negative tests.” The document included examples of how to run such tests. After reading the document, Hayward said that it appeared to him that Facebook had used negative testing before. He added, “I have never seen a more horrible document in my career.”


[ad_2]
Source link