Super Mario game used to spread malware

0
[ad_1]

A Trojanized installer for the popular Nintendo fan game Super Mario Forever has been used to spread malware.

This discovery was made cyber security company Cyble. Cyble’s researchers found that malicious actors were spreading a Monero (XMR) miner, a SupremeBot mining client and an open-source Umbral stealer all bundled with a legitimate installer for Super Mario Forever. 

Once successfully installed on a device and the game is launched, the malware then secretly executes malware files on the infected device. The XMR miner uses the infected device to mine for the cryptocurrency Monero. The miner operates discreetly in the background processes of the device, meaning the unauthorized mining is hidden from the victim.  
 
The XMR miner also harvests data from the victim’s computer, including the computer name, username, graphics processing unit and central processing unit and transfers it to a command and control center.

The SupremeBot mining client executes processes on the infected device to retrieve and execute malicious data-stealing software from a command and control center to the device. This then unloads the Umbral stealer onto the device’s process memory. The Umbral stealer then rapidly collects data off the device and sends it to the malicious actor who uploaded the Trojanized software via instant messaging platform Discord using webhooks.

Cyble noted that the Umbral stealer can execute the following processes:

  • Capturing screenshots  
  • Retrieving browser passwords and cookies  
  • Capturing webcam images  
  • Obtaining telegram session files and discord tokens  
  • Acquiring Roblox cookies and Minecraft session files  
  • Collecting files associated with cryptocurrency wallets.

Together, this malicious payload bundle can significantly impact victims, both monetarily via stolen cryptocurrency or fraudulent bank transfers and materially, through the impact crypto mining will have on their device. This is because crypto mining massively disrupts a system’s processes as well as depleting its resources.

Learn more about Trojanized malware with Cyber Security Hub’s ultimate guide to malware. 



[ad_2]
Source link

OnePlus 13 to get a camera boost, include three 50MP cameras

0
[ad_1]

The OnePlus 13 will include three 50MP cameras based on a new rumor that surfaced online. This information comes from a well-known tipster, Digital Chat Station. He’s usually spot on, so we have no reason to doubt this info.

The OnePlus 13 will get a camera boost, and include three 50MP cameras on the back

The tipster said that the phone will feature an improved periscope telephoto camera. It will have a 50-megapixel unit, and 3x optical zoom. That camera will also come with Hasselblad boost.

As a reminder, the OnePlus 12 includes a 64-megapixel periscope telephoto camera with 3x optical zoom. That’s not the only camera that will see a change, however. The ultrawide unit will also be a 50-megapixel unit, instead of a 48-megapixel camera.

We’re still not sure what sensors will OnePlus use, as that’s a rather important detail. The main camera will stay a 50-megapixel unit, but OnePlus could end up using a different sensor. That detail is still under wraps.

OnePlus could end up using the Sony LYT-900 camera sensor

The OnePlus 12 uses Sony’s LYT-808 sensor for the main camera. That sensor is compelling, but it’s not as good as the Sony LYT-900 used by the OPPO Find X7 Ultra. Will the OnePlus 13 get a boost in that regard and use the LYT-900? It’s a possibility.

The device will be fueled by the Snapdragon 8 Gen 4. That’s a given. It will actually become one of the first smartphones to use that chip. The OnePlus 13 is expected to become official in November, at least in China.

The phone is also rumored to include a redesign, with a different camera island on the back. A 6,000mAh battery will allegedly also be included. The phone could lose wireless charging, though, unfortunately. It remains to be seen, but that’s what’s rumored at the moment.


[ad_2]
Source link

Acer SpatialLabs Eyes 3D Stereo Camera

0
[ad_1]

Acer’s new SpatialLabs Eyes camera brings 3D excitement to your photography

Acer brought some fun new products to Computex 2024 in Taiwan this week, one of which was its new SpatialLabs Eyes, a 3D stereo camera that’s designed for 3D photography, but is also perfect for content creation.

Whether you’re new to 3D photography or experienced with it, Acer says the SpatialLabs Eyes is an easy-to-use camera that will help bring your photos and videos to life. It features 8MP per eye and a built-in selfie mirror to help you get those perfect selfie shots. Acer plans to launch this camera in Q3 for $549. While we haven’t had the chance to use the camera, it caught our attention thanks to its compact nature and exciting 3D features, which is why it earned a Best of Computex 2024 award from Android Headlines.

Point-and-shoot photography becomes more fun with the SpatialLabs Eyes camera

Point-and-shoot photography has been around for ages with what feels like little movement forward when it comes to fun new features or experiences. Acer’s new SpatialLabs Eyes stereo camera changes all that. For starters, this is a compact camera. It’s small enough to fit in your pocket. Yet it’s not so small that you would find it annoying to use. On top of this, Acer designed it to be weatherproof. Which means you should be able to use it even in light rain.

Although you can use the camera out of the box without fiddling with settings, it does have a manual mode. Should you want more control over your image output, you can adjust quite a few things. ISO, white balance, and shutter speed settings are all available to tweak to your liking.

What’s more, is that you can use it for capturing 3D video in addition to photos. It’ll also have support for video conferencing apps like Zoom, Google Meet, and Microsoft Teams in Q3 alongside the camera. Acer says the camera’s “carefully calibrated lens alignment and advanced optical system allows for photographing subjects in greater 3D depth and detail.” You’ll need a SpatialLabs laptop or monitor to make the most of this camera. If you didn’t want one before, you’ll probably want one now.

Remember how we said this was easy to use? Well, it gets easier than just point-and-shoot. There’s a decent-sized touch screen on the back for menu and settings interaction. It supports microSD cards for storage and only weighs about 220g too. Acer has been pushing the envelope with cool new products and the SpatialLabs Eyes 3D stereo camera is the latest example of that. This is why we awarded it the Best of Computex 2024 award.


[ad_2]
Source link

Google Lens to simplify adding context to searches

0
[ad_1]
Google Lens is a cool tool that lets you use your phone’s camera to search the world around you. Just point your camera at something, and Google Lens will try to identify it using image recognition technology.

Once it recognizes the object, it gives you relevant info about it. But sometimes, an image search could use a little extra context. That’s why Google might improve Google Lens to accept more context.

Google Lens might soon make it easier to add context to your searches


A recent teardown of the Google app revealed some upcoming changes. It looks like Google is working on making it easier to start a search and add extra context. Now, you can press the shutter button to start a search, but soon, you will be able to tap and hold (i.e., long press) the shutter button to add context with your voice at the same time.Currently, when you use Google Lens for an image search, you press the shutter button to start the search. After the image search is done, you can add context by tapping on the voice search icon. This extra context can be in the form of voice or text.

So, with this upcoming update, adding context to your image search will be quicker and easier. Plus, it seems Google is also working on a feature that lets you search using video, not just still images.

If Google decides to roll out this handy feature, users will be able to record a video and add extra search context through voice at the same time.

However, none of these features are live in Google Lens yet, which you can access through Google Search. They might roll out in the future, but there’s no guarantee. Fingers crossed, though!

I mean, having more search options is always a plus, don’t you think? Especially when you’re in a rush or trying to find info about something you can’t quite put into words – and we all know those situations happen.

[ad_2]
Source link

WhatsApp Chats Vulnerable To Government Monitoring – Report

0
[ad_1]

WhatsApp engineers share their fears about the app being vulnerable to government monitoring via n internal report. While the WhatsApp structure doesn’t exhibit any vulnerability, the existing network monitoring techniques may help governments bypass the app’s encryption to monitor users’ app usage pattern.

Government May Bypass WhatsApp Encryption For Monitoring

According to an internal Meta report, WhatsApp engineers have noticed a severe security issue making WhatsApp users vulnerable to government monitoring. First disclosed by The Intercept, the report reveals WhatsApp employees’ fears for the privacy and security of their users.

As reported, the problem—or security lapse—isn’t because of any technical vulnerability. Meta spokesperson Christina LoNigro assured that no backdoors or vulnerabilities exist in WhatsApp’s workings. However, the problem exists because of the current network monitoring techniques governments employ, or may employ, to monitor their citizens’ digital activities.

Using network monitoring and traffic analysis, authorities can identify WhatsApp users—senders and receivers alike—and their locations (via the IP addresses), deducing whether a respective user is part of a WhatsApp group. While the exact chat contents remain veiled due to the underlying WhatsApp encryption, the metadata gathered via traffic analysis suffices for the authorities to profile target users.

Regarding the practical exploitation of this scenario, Meta officials mention Israel as a state targeting Palestinian WhatsApp users.

This security issue doesn’t typically risk WhatsApp only. Almost every service encrypting users’ communications can be surveilled in this manner. However, given WhatsApp’s huge user base (roughly 2 billion) and the typical pattern of WhatsApp traffic flowing through Meta servers, the risk is far greater for WhatsApp users.

Though the engineers have internally reported the matter to Meta management, there seem no specific plans from the management to address this issue anytime soon.

Is There A Fix?

While the report sounds terrifying, average WhatsApp users need not worry much about such monitoring since not all governments apply such intensive network monitoring. (Though, they may do it at any time as needed.)

Nonetheless, considering that the threat persists—particularly for citizens in authoritarian regimes—using means such as VPN may significantly help them avoid WhatsApp surveillance. While the VPN’s encryption would still be detectable, it will at least save users from the specific exposure of WhatsApp usage, encrypting all internet activities alike.

Besides, users must remain wary of WhatsApp spam messages, unsolicited calls, and group invites. Even with trusted contacts, users must avoid sharing sensitive details or information they don’t want snoopers to know. Instead, users may switch to other securer means of communication for sharing sensitive stuff.

Let us know your thoughts in the comments.


[ad_2]
Source link

Xiaomi MIX Flip to launch globally; Xiaomi MIX Fold 4 coming early

0
[ad_1]

This time around we have some exciting news regarding Xiaomi’s upcoming fodlable smartphones. The Xiaomi MIX Flip is expected to launch globally, while the Xiaomi MIX Fold 4 could arrive sooner than expected.

The Xiaomi MIX Fold is expected to launch globally

Let’s start with the Xiaomi MIX Flip, the company’s very first clamshell foldable. Why do we believe it will reach markets outside of China? Well, because it appeared in the GSMA’s IMEI database with the model number 2405CPX3DG. That’s important because the ‘G’ at the end stands for ‘global’. Models with that letter usually launch in markets outside of China.

The same phone also got certified in China but with a different model number. That model has the 2405CPX3DC model number. As you can see, it has the letter ‘C’ at the end, which stands for ‘China’.

As a reminder, that phone is expected to be fueled by the Snapdragon 8 Gen 3 processor. It will have a 50-megapixel main camera, a 12-megapixel ultrawide unit, and a 60-megapixel telephoto snapper… if the rumors are accurate. It’s expected to arrive at some point between July and September.

The Xiaomi MIX Fold 4 could arrive sooner than you think

What about the Xiaomi MIX Fold 4? Well, that phone could arrive sooner than expected. The Xiaomi MIX Fold 3 arrived in August last year, and this model could launch in July.

That info comes from ‘Smart Pikachu’, a Chinese tipster. In fact, the two foldables could launch during the same event, that would make sense for Xiaomi, that’s for sure. Both will likely launch in China first.

Do note that the Xiaomi MIX Fold series does not have a global variant yet. So, if the Xiaomi MIX Flip will launch globally, who knows, perhaps Xiaomi has huge plans for the Xiaomi MIX Fold 4 as well. Let’s hope that will be the case. That phone will be fueled by the Snapdragon 8 Gen 3 too, and it will have high-end specs in general.


[ad_2]
Source link

TECNO MEGABOOK T16 PRO and PRO Ultra

0
[ad_1]

Tecno has produced some stellar phones, but it also has a computer to match

Tecno is the tech brand that wants to take on the world, as it’s been making some serious steps in that direction. Those who know the company know it as the brand that’s made some impressive phones. However, it showed off the MEGABOOK T16 Pro 2024 Ultra at Computex 2024, and it’s got some serious power.

Tecno makes computers as well as phones, and it also showed off its MEGABOOK K16S at the event. This is a 16-inch laptop with a lot of great features. The MEGABOOK T16 Pro 2024 Ultra, on the other hand, is a more advanced model, and it’s for people who want the most power from their computer.

This is a computer that’s designed for power users who need to get some serious work done. The computer has a sturdy metal body that lends to the overall great feeling in the hand. It will also keep it protected in the event of a fall.

As for the screen, you’re looking at a 16-inch screen with a 2.5K resolution. With that resolution, you can expect some pretty good visuals. It covers 100% of the sRGB color gamut and it has a peak brightness of 400 nits. Along with that, the screen also reduces glare.

This computer uses the Intel Core Ultra processor. It’s backed up by 16GB/32GB of RAM and 512GB/1TB of storage. As for the battery, this computer has a 99.99Wh battery, and it supports 100W charging.

Tecno touted this computer’s AI capabilities. It will have Copilot integrated, you should expect some great on-device AI processing from this computer. This is the device to get if you’re looking for a computer to handle your work life. This is why it received our award for Best of Computex 2024.


[ad_2]
Source link

Sonos app gets another big update that brings back some basic features

0
[ad_1]

After Sonos’ redesign app fiasco, the audio company vouched to listen to the feedback and bring back all the features that were removed when the refreshed version of the app was rolled out not long ago.

This will take time because in an attempt to make its app as streamlined as possible, Sonos removed a lot of the features that users were using very often. Basic features like “Play Next,” “Play Last,” “Shuffle All,” and the ability to search for songs in local/offline music library were no longer available when the new app was released.

Despite its attempts to defend the app’s new design, Sonos admitted that it now has a major issue as many users threaten to stop using and/or buying the company’s products.

New features added


The first update meant to fix some of the app’s problems was released last month, and Sonos promised to roll out a new one in June. Well, it looks like Sonos has kept its promise and a new update is now available for download. Here is what’s included and what Sonos plans to add to the app in the coming weeks:
  • Added support for the all new Sonos Ace headphones
  • Added sleep timer settings
  • Added “play next” and “add to end of queue”
  • Improved Home Feed scrolling
  • Improved setup reliability
  • Added WiFi configuration for products with BLE
  • Improved battery consumption for Bluetooth discovery
  • Improved ability to update older firmware systems
  • Further improved navigation for visually-impaired customers
  • Added VoiceOver support to read toast message automatically on iOS
  • Introduced mute button on iOS
  • Improved local library connectivity
  • Improved Trueplay setup on iOS
  • Added distance settings for surrounds
  • Added line-out settings for Sonos Port

New features incoming

Besides the pretty beefy changelog, Sonos also revealed some of the features that fans should expect to see in a future update. Keep in mind that most of these upcoming features have ETAs, but not all of them.
  • Continued improvements to navigation for visually impaired customers: mid-June
  • Playback controls including mute and volume numbers: June
  • Local music library search and playback: mid-June
  • Improved playback settings including Play Now: July
  • Create and edit local music library: July
  • Improved Autoplay settings: July
  • Improved Sub audio settings with Amp: July
  • Snooze alarms: TBD

Based on the roadmap above, the next update for the Sonos app should arrive in mid-June, but there’s also another one scheduled for July. If you’re using Sonos’ app to control your audio products, there are a lot of good things coming your way, so stay tuned.

[ad_2]
Source link

Tenable Acquires Eureka Security To Provide Data Security

0
[ad_1]

Tenable® Holdings, Inc., a leading Exposure Management company, has announced a definitive agreement to acquire Eureka Security, Inc., a prominent provider of data security posture management (DSPM) for cloud environments.

This strategic acquisition aims to bolster Tenable’s cloud security capabilities, providing comprehensive data security across cloud infrastructures.

Tenable’s acquisition of Eureka Security is set to close this month, marking a significant step in enhancing its cloud-native application protection platform (CNAPP).

Eureka Security’s DSPM technology offers security teams a holistic view of an organization’s cloud data security footprint, addressing policy drift and misconfigurations that pose risks to data.

By integrating these capabilities, Tenable aims to help customers identify critical evidence of cloud data risks, including the location of sensitive data, access permissions, and the severity of potential data compromises.

In the 2024 Tenable Cloud Security Outlook study, 95% of organizations reported experiencing cloud-related breaches in the past 18 months, with 92% of those breaches involving the exposure of sensitive data.

Analyze any MaliciousURL, Files & Emails & Configuration With ANY RUN Start your Analysis

This acquisition underscores Tenable’s commitment to providing robust cloud security solutions that can mitigate such risks and improve overall security posture over time.

Enhancing Visibility and Control

Shai Morag, Senior Vice President and General Manager of Cloud Security at Tenable, emphasized the importance of this acquisition in advancing cloud security innovation.

“Eureka Security’s technology will enable Tenable to provide even better prioritization of cloud risks and identify toxic combinations beyond vulnerabilities, misconfigurations, and over-privileged access to include data at risk as well,” Morag stated.

This integration will offer security teams the context and prioritization guidance to make efficient and accurate remediation decisions.

Liat Hayun, Co-founder and CEO of Eureka Security, expressed enthusiasm about joining forces with Tenable.

“Eureka Security’s data-centric approach provides the visibility, control, and automation needed to navigate the dynamic cloud landscape while ensuring the highest level of security and compliance,” Hayun said.

“Integrating our capabilities into Tenable’s CNAPP offering creates a compelling capability for customers.

Tenable also brings an expansive customer base and solid go-to-market capabilities.

We couldn’t have found a better match to help us expand our global mission to reduce cloud data risk.”

Comprehensive Cloud Security Solution

Integrating Eureka Security’s DSPM capabilities will complement Tenable’s existing cloud security solutions, including unified CNAPP, cloud security posture management (CSPM), cloud workload protection, and cloud infrastructure entitlement management (CIEM).

This comprehensive suite of tools will provide security teams with the necessary context and prioritization to address cloud security challenges effectively.

Tenable’s acquisition of Eureka Security is not expected to have a material impact on revenue this year.

However, the long-term benefits of enhanced cloud security capabilities are anticipated to strengthen Tenable’s market position and provide significant value to its customers.

About Tenable

Tenable® is a leading Exposure Management company trusted by approximately 44,000 organizations worldwide to understand and reduce cyber risk.

As the creator of Nessus®, Tenable has extended its expertise in vulnerabilities to deliver the world’s first platform capable of securing any digital asset on any computing platform.

Tenable’s customers include approximately 65% of the Fortune 500, 50% of the Global 2000, and numerous large government agencies.

This press release contains forward-looking statements about Tenable’s acquisition of Eureka Security, Inc.

These statements involve substantial risks, uncertainties, and assumptions that could cause results to differ materially from those expressed or implied.

Forward-looking statements are based on Tenable’s current plans, objectives, estimates, expectations, and intentions and inherently involve significant risks and uncertainties, many of which are beyond Tenable’s control.

This acquisition represents a pivotal moment for Tenable as it continues to push the envelope in cloud security innovation, providing customers with best-in-class capabilities to effectively manage and mitigate cloud data risks.

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo 


[ad_2]
Source link

Google’s June 2024 update patches 37 vulnerabilities, Samsung adds 22 more

0
[ad_1]

Google has published the monthly Android Security Bulletin (ASB) for June 2024. This month’s security release for Android devices fixes 37 vulnerabilities, including three critical issues. Android OEMs will roll out these patches to their devices in the coming weeks. Some firms may bundle additional patches for issues exclusive to their products. Samsung, for example, is addressing 22 Galaxy-specific vulnerabilities with the June update.

June security update patches 37 vulnerabilities in Android devices

As usual, Google released the June 2024 ASB in two parts. The first part arrives with the 2024-06-01 security patch level and contains fixes for 19 high-severity vulnerabilities. The most severe vulnerability in this group could lead to “local escalation of privilege with no additional execution privileges needed.” Most of those exist on Android 12 through to Android 14, though a few don’t affect devices running the latest Android version.

In the second group, Google bundled 18 high-severity vulnerability patches marked under the security patch level 2024-06-05. These include issues across various partner components, including those from MediaTek, Imagination Technologies, ARM, and Qualcomm. This group also includes a kernel vulnerability that could “lead to local escalation of privilege in the kernel with no additional execution privileges needed.”

All of these patches will roll out to Pixel smartphones and tablets in the coming weeks. Google has yet to begin the rollout, though the wait may not be much longer now. Other Android manufacturers like Samsung, OnePlus, Oppo, Vivo, Xiaomi, and Tecno will also push these patches to their devices as the June security update. There is no evidence of any of these vulnerabilities being exploited in the wild. You should still update your device as soon as you can.

Galaxy devices get 22 additional security patches

Along with the 37 patches part of Google’s latest ASB, Samsung’s June update for Galaxy devices addresses another 22 vulnerabilities that don’t exist on Android devices from other brands. Called Samsung Vulnerabilities and Exposures (SVE) items, these issues affect various system apps, services, and components that make up the core of Galaxy products or Samsung’s custom Android skin, i.e., One UI.

This month’s release fixes a critical vulnerability in “chnactiv TA” that allowed local privileged attackers to lead to potential arbitrary code execution. The Korean firm also patched several high-severity issues, including a buffer overflow vulnerability in the bootloader that enabled physical attackers to overwrite memory. These patches will soon roll out to eligible Galaxy devices, including the Galaxy S24 series. We will let you know when the rollout begins.


[ad_2]
Source link