Apache Log4j2 Vulnerability Remains A Threat For Global Finance

0
[ad_1]

Despite a working patch that has been around for years, the Apache Log4j2 vulnerability still poses a threat to the global finance sector. A security researcher warned users about the threat.

Apache Log4j2 Vulnerability Remains A Threat – Warns Researcher

Security researcher Anis Haboubi directed the cybersecurity and financial sector’s attention to a critical security issue. As highlighted through his recent X post, the well-known yet notorious Apache Log4j2 vulnerability wreaked havoc a few years ago.

To reiterate, log4j2 is a variant of the first detected vulnerability Log4Shell, which allowed remote code execution in apps running the vulnerable Java logging library. It took the firm several attempts to patch the flaw before releasing the Log4j version 2.17.1, addressing the vulnerability CVE-2021-44832. This vulnerability, tagged as a moderate-severity issue, allowed RCE to an attacker with write access to the logging configuration.

Elaborating further on this matter in his X post, Haboubi wrote,

“A critical vulnerability (CVE-2021-44832) allows attackers with write access to the logging config to exploit a JDBC Appender with a JNDI URI, enabling remote code execution. This could compromise your system by executing malicious code remotely.
Once compromised, attackers can pivot using SSH tunnels to access private network databases.”

The researcher also cited Sisense’s guide on SSH tunnel connections to a private network, explaining that an adversary exploiting the Log4j2 vulnerability could further exploit SSH tunnels for lateral movement on the network.

Haboubi also explained Sisense’s latest move to integrate PEM key-based authentication in the setup script to prevent unauthorized access. While this step alleviates the severity of Log4j2, Haboubi also urged the relevant organizations to update logging configurations and implement SSH security measures to prevent potential threats.

These findings arrive following the recent security breaches at Sisense and Snowflake, which occured due to the exploitation of security flaws in their infrastructure, exposing sensitive financial data to hackers.

Let us know your thoughts in the comments.


[ad_2]
Source link

Here’s a leaked image of the HMD Atlas

0
[ad_1]

HMD has disconnected itself from Nokia and unveiled some very typical-looking mid-range phones. while we’ve already seen several HMD-branded phones, there are still a few surprise devices popping up. We now have a leaked image of the HMD Atlas. This is going to be a mid-ranger with a pretty nice display based on the information.

As you may know, HMD took over the license to build Nokia phones several years back. Since then, it’s been struggling to polish the company’s tarnished golden image. The company has been popping out some affordable devices over the past few years at a slowing pace. So, HMD struck out on its own and got to work on its own phones. While that’s the case, HMD has released some Nokia-branded phones recently.

We got a leaked image of the HMD Atlas

At this point, we shouldn’t expect any radical new designs or premium flagships from HMD just yet. Right now, the Finnish company is still focusing on padding out the sub-$300 market. As such, this newly leaked phone won’t have you drooling over the specs.

Starting off with the display, the HMD Atlas looks like it’s going to have a 6.64-inch LCD display with a 1080p+ resolution and 120Hz refresh rate. That’s not jaw-dropping, but it’s still an improvement over the 720p+ resolution on the other phones.

Powering the device, we have a Snapdragon 4 Gen 2. So, we’re not looking at a lot of power, but it still grants it 5G connectivity. Backing that up, there’s 8GB of RAM and 128GB of onboard storage.

In the battery department, we’re seeing some impressive numbers. This phone has a 5,500mAh battery. That’s a 10% boost from the standard 5,000mAh battery capacity we see with most phones.

Moving over to the cameras, this phone could have a 48MP main camera with an f/1.8 aperture. We expect that to be accompanied by a 5MO ultrawide camera and a depth sensor. Up front, we’re looking at a 16MP selfie camera.

Lastly, this phone could have a 3.5mm headphone jack, Micro SD card expansion, and Bluetooth 5.1 connectivity. The Atlas could cost $239.99 when it launches.


[ad_2]
Source link

Max (formerly HBO Max) follows industry trends as ad-free plans get pricier

0
[ad_1]
In what seems to be the latest trend in the streaming world, Max (formerly known as HBO Max) has announced that it will be increasing the price of its ad-free plans. This news follows a report last month that hinted at the possibility of a price change.

As of today, new subscribers will be paying $16.99 per month for the standard ad-free plan, a dollar more than the previous price. For those who prefer the 4K ad-free plan, the monthly cost is now $20.99, also a dollar more than before. Existing Max subscribers won’t see the change immediately, but they can expect the price increase to take effect starting with their next billing cycle on or after July 4th.

If you’re a fan of the ad-free experience and prefer to pay annually, you’ll also see an increase. The standard ad-free yearly plan will now cost $169.99 (up from $149.99), and the 4K ad-free yearly plan will be $209.99 (up from $199.99). However, for those who don’t mind watching a few ads, there’s a silver lining: the price for the ad-supported subscription will remain unchanged at $9.99 per month or $99.99 per year.

Current Max plans and pricing | Credit: Max

This isn’t the first time that Warner Bros. Discovery, the parent company of Max, has raised prices. Last year, they also bumped up the cost of their streaming service. And it appears they’re not alone in this trend. NBCUniversal is planning to increase the price of Peacock by $2 in July, and Disney is set to start charging customers who share passwords this month. The moves to raise prices by all these companies are becoming more increasingly tough to keep up with.The move to raise subscription prices comes at a time when streaming services are investing heavily in content and technology. While these price increases might not be popular with consumers, they’re likely necessary for the companies to continue providing high-quality content and remain competitive in the ever-growing streaming market, however detrimental they may become to the viewer’s wallets.

[ad_2]
Source link

Criminal IP Unveils Innovative Fraud Detection Data Products

0
[ad_1]

AI SPERA, a leader in Cyber Threat Intelligence (CTI) solutions, announced that it has started selling its paid threat detection data from its CTI search engine ‘Criminal IP‘ on the Snowflake Marketplace. Criminal IP is committed to offering advanced cybersecurity solutions through Snowflake, the leading cloud-based data warehousing platform.

 

<Image caption: Criminal IP’s Intelligence Listings on Snowflake Marketplace >

Criminal IP’s Intelligence for Fraud Detection and Privacy Protection is meticulously crafted to address the growing concerns surrounding fraudulent activities and privacy breaches. By aggregating data on known malicious and masked IP addresses, including those with historical abuse records such as IDS, malware, phishing, ransomware, and blocked IPs, this dataset equips organizations with actionable insights to identify and mitigate fraudulent activities in real time. Additionally, the product boasts advanced capabilities to detect servers infected by botnet and C2 software, as well as IP addresses leveraging masking services like VPNs, proxies, and hosting. This product is tailored to support fraud detection (FDS) and malicious IP plans, enabling organizations to bolster their security posture and streamline incident response protocols.

Criminal IP’s Intelligence for Threat Detection & Incident Response is designed to empower organizations to combat cyber threats effectively. This comprehensive cyber threat intelligence dataset provides invaluable insights into malicious IP addresses, leveraging data sourced from Criminal IP’s Cyber Threat Intelligence Database (CTIDB).

These new datasets on the Snowflake Marketplace offer granular, real-time threat intelligence, enabling organizations to safeguard digital assets, mitigate risks, and respond swiftly to security incidents. Snowflake’s global customers can access a complimentary trial of up to 1,000 data items, with subscription options for daily updates.

About AI Spera

AI SPERA, a leader in Cyber Threat Intelligence (CTI) solutions, significantly expanded its reach by launching its flagship solution, Criminal IP, in 2023.

Since then, the company has formed technical and business collaborations with over 40 renowned global security firms, including VirusTotal, Cisco, Tenable, Sumo Logic, and Quad9.

Besides the CTI search engine, the company offers Criminal IP ASM, a SaaS-based Attack Surface Management Solution on AWS and Azure Marketplace, and Criminal IP FDS, an AI-based Anomaly Detection Solution used for credential stuffing prevention and fraud detection.

Available in five languages (English, French, Arabic, Korean, and Japanese), the search engine provides a powerful service for users worldwide.


[ad_2]
Source link

Nokia shows off immersive phone call technology with 3D audio

0
[ad_1]

A Nokia executive has made the first “immersive” phone call as a demonstration. This is a new technology that the company is working on. It promises to offer an improved calling experience thanks to 3D spatial audio technology.

Pekka Lundmark, CEO of Nokia, revealed more details about the technology. He was also the one who held the call with Stefan Lindström, Finland’s Ambassador of Digitalization and New Technologies. According to Lundmark, immersive phone calls are designed to offer a closer communication experience. It will help make interactions between all parties more lifelike. The goal is similar to Google’s Project Starline, but with much fewer requirements.

The new Nokia’s 3D audio-based immersive phone call technology

Currently, voice calls use monophonic audio. This means that all sound is compressed to output through a single channel, which significantly reduces quality. It also completely eliminates the feeling of separation between all the sound elements present during a call. On the other hand, Nokia’s immersive calls solve this by implementing 3D audio technology.

One of the advantages of the technology is that it does not require special devices. The first immersive call was made using a normal 5G-supported phone. The only hardware requirements are support for 5G networks and at least two microphones. Today, millions of devices meet these requirements.

The technology is compatible with both calls between two people and meetings between multiple people. In the latter, it could be used even better, since the three-dimensional sound will separate the voices of all the participants. This will allow you to distinguish the voices of each participant according to their spatial position.

Nokia’s immersive phone call technology will be one of the advantages of 5G Advanced. 5G Advanced is the next evolutionary leap in mobile networks before the arrival of 6G. The company will have to reach licensing agreements for its implementation. So, you’ll probably have to wait some years before it’s available to everyone.


[ad_2]
Source link

Google Home’s “Favorites” widget rolls out for Android

0
[ad_1]

Google has begun the wide rollout of its Google Home 3.18 update, bringing a highly anticipated feature to Android users: the “Favorites” widget. First announced last week, this update is now available via the Play Store, although you may need to restart your device before it shows up. If you’re enrolled in the Preview Program, you’ll get a first look at this new tool for managing your smart home.The Favorites widget offers two customization options: syncing with your favorites from the Home app or choosing specific controls unique to the widget. Syncing with the app mirrors the grid layout of the Favorites tab, while the custom option allows for arranging devices in your preferred order. You can further tweak the widget using the edit icon, and even switch between different homes. For now, you can select Actions (Assistant, Broadcast, Call Home) and Devices, with support for automations promised in the near future.

Google Home Favorites widget installation | Credit: PhoneArena

For devices like lights, plugs, and blinds, a simple tap on the widget will toggle them on or off. Google notes that some devices may take a moment to respond, but the widget will keep you updated on the progress. Devices like cameras, Wi-Fi, thermostats, and commands will open the corresponding control page in the app when tapped.

Security remains a priority, with sensitive actions like opening smart locks or garage doors requiring extra authentication. This added layer of protection ensures that your home stays secure.

The widget refreshes its status every 30 minutes and offers flexibility in sizing. You can have it fill your entire homescreen, shrink it down to a single tile, or choose a different configuration. You can even have multiple widgets on your homescreen. Tapping on any empty space within the widget will launch the full Google Home app.

Google Home Favorites widget resizing | Credit: PhoneArena

This new feature joins the growing list of updates Google has been rolling out to its smart home ecosystem this year. With the Favorites widget, the company is clearly aiming to streamline the control of smart devices for Android users, prioritizing both convenience and security. However, only time will tell how well this new feature is received by the broader user base.

[ad_2]
Source link

Docker Hub Services No More Available In Russia

0
[ad_1]

Shortly after multiple users complained online about the unavailability of Docker Hub services, it’s now official that Docker Hub services have been suspended in Russia. The platform cites US export laws as a reason to pull out their services post-Russia-Ukraine war.

Docker Hub Ends Operations In Russia Sans Prior Notifications

Reportedly, the developer platform Docker has blocked Russian users from accessing it due to US laws. This development came as a shock to many Russian developers who relied on Docker Hub.

Specifically, Docker Hub is the main public registry for the developer platform-as-a-service giant Docker, facilitating the developer community globally. The platform employs a freemium model and has become beneficial for most users as a seamless cloud platform for sharing, storing, and managing container images.

The matter gained traction in the media following multiple complaints from users regarding the inaccessibility of Docker Hub services in Russia. Besides highlighting the matter on social media sites like Reddit, users also shared their concerns on the official Docker forums.

Eventually, Russian media confirmed that Docker blocked its services for Russian users, citing compliance with US export control laws as the reason. Moreover, besides banning Russian users, Docker also restricted users from five other countries: Iran, Cuba, North Korea, Syria, and Sudan.

Users trying to access Docker and facing the restriction witness the following message from the platform.

Since Docker is a US company, we must comply with US export control regulations. In an effort to comply with these, we now block all IP addresses that are located in Cuba, Iran, North Korea, Republic of Crimea, Sudan, and Syria. If you are not in one of these cities, countries, or regions and are blocked, please reach out to https://hub.docker.com/support/contact/

Since Docker mentioned blocking IP addresses from these regions, users may still be able to access the platform using a VPN. In fact, VPNs are often used for accessing blocked sites and services globally. Nonetheless, this isn’t a fool-proof strategy due to potential IP/DNS leak issues that may trigger the ban if the platform knows the real IP addresses or if Docker implements measures to detect and block VPN users.

Let us know your thoughts in the comments.


[ad_2]
Source link

Last year’s top social media platform might surprise you

0
[ad_1]
Do you consider YouTube to be a social media platform? Lifesight.io, a marketing research company, puts YouTube in that category and calls it the top social media platform based on the number of visits. Last year, the streaming video provider hosted 1.35 trillion visits, up 80.49% from the 263.3 billion that came to the platform in 2019. At 67%, the majority of YouTube visitors are male and nearly 70% are viewing YouTube videos on their mobile devices.
One of the now iconic ads that Apple released for the original iPhone in 2007 was all about the YouTube app that was pre-installed on iOS until iOS 6. Apple even took a moment in the advertisement to point out how unusual it was for a phone to have a YouTube app. As the commercial showed a skateboarding bulldog, the voice-over announcer said, “Maybe the biggest surprise is finding YouTube on your phone.”

While YouTube attracted the largest number of visitors to a social media platform in 2023, one of the biggest growth rates in the genre over the five years from 2019-2023 belonged to TikTok. With a growth rate during the five years reaching a stunning 6015%, the controversial social media player saw the number of visits rise from .7 billion in 2019 to 41.8 billion last year. TikTok is a “mobile-centric” site that is just as popular with men as women.

Overall social media visits rose 70.56% worldwide during the five years from 2019 to 2023 as the number of visits rose to 1.98 billion from 582.9 billion. The top three countries to host visitors to social media platforms last year were the U.S. (436.1 billion visitors), India (171.8 billion), and Brazil (123 billion). At 68.65%, most visitors to social media sites were male (leaving 31.35% for females). 59.10% preferred to visit these sites using their mobile devices.

The top ten social media platforms of 2023 include:

YouTube-streaming video site hosted a leading 1.35 trillion visitors in 2023.

Facebook-with 216.4 billion visitors last year, Facebook had a very modest five year growth rate of 15.33% and lost its spot at number one.

X (formerly Twitter)-male-dominated platform had 112.9 billion visits last year, up from 41.6 billion in 2019. Over 77% of visitors view X on their mobile devices.

Instagram-another mobile-centric platform with a majority of male users, Instagram counted 87.3 billion visits in 2023, a 62.40% increase from 2019.

Reddit-yet another male-dominated mobile-centric platform that features community-driven content.

TikTok-controversial platform saw the number of visits rise over 60 times between 2019 and 2023.

What’sApp-Large number of desktop users as What’sApp is used for cross-platform communications.

LinkedIn-professional networking platform had 20.5 billion visits last year.

Twitch-live streaming gaming platform counted 20 billion visitors in 2023, predominantly male and mobile.

Quora-19 billion visits last year as the platform shares knowledge and passes along information.

How many of the top-ten social media sites do you frequently visit?


[ad_2]
Source link

Free Android VPNs Suffering Encryption Failures, New Report

0
[ad_1]

VPN apps for Android increase privacy and security over the internet since connection data is encrypted, consequently making it impossible for hackers or other parties to access communication data. 

They also help unblock region-restricted content through IP address hiding, support anonymity on the Internet, and protect secure information more so when using insecure Wi-Fi.

Cybersecurity researcher Simon Migliano at Top10VPN recently discovered that free Android VPNs are suffering encryption failures.

Free VPNs Encryption Failures

Encouraged by the growing trends of government-imposed internet restrictions worldwide and subsequent appeal for virtual private networks (VPNs), this study examines the privacy and security issues about free VPN applications.

With ANYRUN You can Analyze any URL, Files & Email for Malicious Activity : Start your Analysis

Since 2018, the total installations of the 100 most popular free Android VPNs have skyrocketed from 260 million to over 2.5 billion.

This in-depth research evaluated the privacy and security risks associated with the top 100 free Android VPN apps, which have garnered over 2.5 billion total installations due to increasing global demand.

By testing each app on separate devices, using various tools within an isolated environment, the study identified shocking flaws in encryption, data leakage, and privacy-infringing functions in the codes of these apps.

Most importantly, it was discovered that most of them openly shared personal user information directly with firms such as “Yandex” and “Bytedance,” consequently showing a contradiction between serving people without charging them and safeguarding a VPN’s real confidentiality goal.

For those who cannot afford to pay for VPNs, it is possible to find good, free ones by doing extensive research. However, affordable paid options are more reliable.

The tests revealed worrying encryption flaws and data leakage among all 100 free VPN applications.

11 experienced full-scale breakdowns in the encryption process, slightly over a third deployed an inadequate form of encryption, and few used the best hashing algorithms or TLS 1.3.

This resulted from 88 leaking information, including 83 that disclosed DNS requests and 79 that did not tunnel all traffic. Over half of these applications suffered from connection instability.

A comprehensive study on user privacy and security vulnerabilities, conducted through Wireshark traffic analysis within a unique test environment, unraveled such extensive vulnerabilities.

Here below, we have mentioned the names of those 11 VPNs:-

  • HTTP Injector
  • Phone Guardian VPN
  • VPN Private
  • iTop VPN
  • PotatoVPN
  • Swift VPN
  • Tenta Private VPN Browser
  • Maple VPN
  • GoFly VPN
  • AVG Secure Browser
  • VPN Satoshi

11 apps were found to have no encryption at all, consequently exposing the browsing activities.

Many of these data leaks were widely spread, 83 of them leaked DNS requests and only 79 could tunnel all traffic.

In addition, many of the investigated apps (96) contained code with potential privacy impacts but some had first-party location tracking together with permissions.

More worrying were those with 12 apps, including third-party precise location tracking code and permissions; some even track in the background.

The main contributors to major privacy concerns included SDKs such as ByteDance, Yandex, and Facebook embedded in popular apps.

In total, during this test period, 71 applications shared personal information while their VPN was still running.

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo 


[ad_2]
Source link

Detour ahead: latest Google Maps beta disrupts Android Auto navigation

0
[ad_1]
The latest beta update to Google Maps is causing some Android Auto users to experience issues with the navigation app. These things are always possible, that’s why it’s a beta version, but this issue seems to be making the entire app crash instead of just glitching.

Several forum reports indicate about Google Maps crashing in Android Auto. Luckily, the rest of the Android Auto experience works. Launching Google Maps is what seems to be an issue right now. However, the app on phones is fully functional.

It seems that Google Maps for Android beta version 11.132.0100 is the culprit. This version was released on June 3. The issue impacts Pixel, Samsung Galaxy, and other Android phones, and we expect Google to issue a patch to fix it shorty.
Some users on the stable version of Google Maps have also reported issues, but the majority of reports come from people on the beta. If you want to leave the beta, you can do so through the Play Store. After that, find App Info, then go to the overflow menu and tap on “Uninstall updates”. Then, return to Google Play and update to the latest stable version.

This bug seems annoying but at the same time, beta versions are still versions in development and I find it understandable that they might not work as expected. After all, that’s a risk all users on beta should be well aware of. Getting to see cool features before they’re officially launched comes with this trade-off, usually.

[ad_2]
Source link