Data Leak Exposes Business Leaders and Top Celebrity Data

0
[ad_1]

A data leak incident involving Clarity.fm left the personal data of business leaders and celebrities exposed to public access. Learn the details of the leak, the potential consequences, and how to protect yourself from the aftermath of a data leak.

A recent data leak involving the San Francisco-based firm Clarity.fm, a platform connecting entrepreneurs with industry experts, left sensitive and personal information about business leaders and celebrities exposed to public access without any security authentication.

Founded in 2012, Clarity.fm prides itself on facilitating on-demand consultations between entrepreneurs and established professionals, boasting over 3,000 experts and having Mark Cuban, Brad Feld, and Eric Ries as clients. 

However, cybersecurity researcher Jeremiah Fowler discovered a non-password-protected database containing an estimated 155,531 records and 121,000 member accounts of entrepreneurs, top celebrities and business leaders. The records included a trove of information including the following:

  • Full names
  • Phone numbers
  • Email addresses
  • Consultation content
  • Hourly consultation rates
  • Payment records related to previous consulting sessions

and more…

Data Leak at Clarity.fm Exposes Business Leaders and Top Celebrity Data
The leaked data (Screenshot provided by Jeremiah Fowler – Website Planet

“The profiles showed personal and professional email addresses, hourly rates, past consulting sessions’ payments, and their internal rating or score (based on user feedback). The records were marked as production data, and indicated if the person was a member, leader, or mentor,” Fowler wrote in his blog post on WebsitePlanet. 

Business leaders and celebrities entrusted Clarity.fm with sensitive details. These individuals may have sought guidance on critical matters related to their businesses or careers.

Therefore, this leak raises serious concerns about data security and the potential consequences for its high-profile clients as with the data exposed, they face an elevated risk of being targeted by cybercriminals. 

This information could be a goldmine for malicious actors seeking to launch targeted scams, phishing attacks, and blackmail attempts. They may also target cloud storage infrastructure, exploit vulnerabilities, or use social engineering techniques for credential theft.

The use of artificial intelligence in phishing campaigns has made it easier to deceive recipients into providing personal or business information. Voice-cloning AI can also be used to gain trust and obtain unauthorized access to sensitive accounts.

Fowler promptly sent a responsible disclosure notice and secured the database, but it’s unclear how long it was exposed or if anyone else gained access. An internal forensic audit could identify the information.

It’s also unclear if the database was owned by Clarity.fm or a third-party contractor. Still, Fowler believes Clarity.fm, its partners and affiliates were not directly responsible for the leak.

Platforms handling sensitive user information must ensure proper cybersecurity measures, including regular data encryption, secure storage practices, and user authentication protocols. Businesses and individuals should be mindful of the data they share online, sharing only the minimum amount to mitigate risks.

  1. Z2U Market Leak Exposes Access to Illicit Services
  2. Major UK Security Provider Leaks Trove of Guard, Suspect Data
  3. Watch out: Fake celebrity endorsements advertising Bitcoin scam
  4. Data Leak Exposes 500GB of Indian Police, Military Biometric Data
  5. Mastermind of 2020’s top celebrity Twitter hack sentenced to 3 years

[ad_2]
Source link

800 arrests, 40 tons of drugs, and one backdoor, or what a phone startup gave the FBI, with Joseph Cox: Lock and Code S05E12

0
[ad_1]

This week on the Lock and Code podcast…

This is a story about how the FBI got everything it wanted.

For decades, law enforcement and intelligence agencies across the world have lamented the availability of modern technology that allows suspected criminals to hide their communications from legal scrutiny. This long-standing debate has sometimes spilled into the public view, as it did in 2016, when the FBI demanded that Apple unlock an iPhone used during a terrorist attack in the California city of San Bernardino. Apple pushed back on the FBI’s request, arguing that the company could only retrieve data from the iPhone in question by writing new software with global consequences for security and privacy.

“The only way to get information—at least currently, the only way we know,” said Apple CEO Tim Cook, “would be to write a piece of software that we view as sort of the equivalent of cancer.”

The standoff held the public’s attention for months, until the FBI relied on a third party to crack into the device.

But just a couple of years later, the FBI had obtained an even bigger backdoor into the communication channels of underground crime networks around the world, and they did it almost entirely off the radar.

It all happened with the help of Anom, a budding company behind an allegedly “secure” phone that promised users a bevvy of secretive technological features, like end-to-end encrypted messaging, remote data wiping, secure storage vaults, and even voice scrambling. But, unbeknownst to Anom’s users, the entire company was a front for law enforcement. On Anom phones, every message, every photo, every piece of incriminating evidence, and every order to kill someone, was collected and delivered, in full view, to the FBI.

Today, on the Lock and Code podcast with host David Ruiz, we speak with 404 Media cofounder and investigative reporter Joseph Cox about the wild, true story of Anom. How did it work, was it “legal,” where did the FBI learn to run a tech startup, and why, amidst decades of debate, are some people ignoring the one real-life example of global forces successfully installing a backdoor into a company?

The public…and law enforcement, as well, [have] had to speculate about what a backdoor in a tech product would actually look like. Well, here’s the answer. This is literally what happens when there is a backdoor, and I find it crazy that not more people are paying attention to it.

Joseph Cox, author, Dark Wire, and 404 Media cofounder

Tune in today to listen to the full conversation.

Cox’s investigation into Anom, presented in his book titled Dark Wire, publishes June 4.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.


[ad_2]
Source link

Xiaomi MIX Fold 4 & HONOR Magic V3 coming with flagship specs

0
[ad_1]

The Xiaomi MIX Fold 4 and HONOR Magic V3 are both expected to arrive in the near future, and both will offer flagship specs. Some of those specs were shared by one of the best-known tipsters around.

The Xiaomi MIX Fold 4 & HONOR Magic V3 are coming with flagship specs

The information comes from Digital Chat Station, who shared the details via Weibo. Both of those smartphones will be fueled by the Snapdragon 8 Gen 3. That’s what was expected, and the tipster basically just confirmed it.

In addition to that, he mentioned that both phones will include a 5,000mAh battery on the inside. That means a slight bump for Xiaomi’s phone, as the Xiaomi MIX Fold 3 features a 4,800mAh battery pack.

In the case of the HONOR Magic V3, well, it only means that it will keep the case battery capacity as its predecessor. At the moment, the Vivo X Fold 3 Pro is leading the battery size race, as that foldable includes a 5,700mAh battery.

Their predecessors launched in Q3 last year

The Xiaomi MIX Fold 3 launched back in August last year. The HONOR Magic V2 arrived in July 2023. In other words, both smartphones are right around the corner, and both phones are rumored to launch a bit earlier than last year. It remains to be seen how accurate that is, however.

What’s also worth noting is that both of these phones will soon launch their first clamshell smartphones. The Xiaomi MIX Flip is coming, and the same goes for the HONOR Magic V Flip. In fact, we already know that the HONOR Magic V Flip is coming on June 13. It will launch in China first. We’re not sure if it’s coming to global markets.

The Xiaomi MIX Flip is expected to launch in markets outside of China, though. That could suggest that the Xiaomi MIX Fold 4 will also launch globally. That would be great, as not a single one of its predecessors left China.


[ad_2]
Source link

TSMC dismisses Huawei as non-threat to its chip supremacy

0
[ad_1]

TSMC, the world’s largest semiconductor foundry, doesn’t see Huawei‘s resurgence as a threat. The company believes its chip technology is too advanced for Huawei, China, or any other emerging competitors to catch up to it. The Taiwanese giant’s confidence and optimism aren’t unfounded as even established players have failed to eat its market.

TSMC says Huawei and China are no trouble for it

A handful of companies dominate the global semiconductor foundry market. TSMC is the largest contract chip manufacturer by a huge margin. In Q1 2024, it captured 62% of the market by revenue. Samsung followed it distantly with a 13% share. It has been like this for many years. These are the only two firms currently manufacturing 3nm chips, the most advanced solutions yet.

Intel has also stepped into the 3nm era but it doesn’t manufacture chips for other firms. The American firm plans to expand into contract manufacturing but hasn’t started yet. Samsung also mostly produces its in-house Exynos chipsets. It is open to producing chips for others but doesn’t get as many orders as TSMC. This is primarily because the latter’s tech has always proved superior.

As such, TSMC holds a lion’s share in this market. Unsurprisingly, the company doesn’t see anyone challenging it anytime soon, not even Huawei, which has been rapidly advancing its chip technology in recent years. In its annual shareholder meeting earlier this week, TSMC’s Chairman Mark Liu said that Huawei and other emerging semiconductor firms are no threat to it.

Liu noted how the company has stood long and tall despite many competitors trying to topple it. The Taiwanese firm has thwarted all the competition. TSMC’s President Wei Zhejia echoed his colleague’s sentiments. He said it’s “impossible” for anyone to come close to the company in chip fabrication technology. Its years of experience are invaluable and can’t be replicated in a jiffy.

Huawei is working towards self-sufficiency

The US strand restrictions have severely impacted Huawei’s business. It is now mostly limited to China and doesn’t have access to the latest smartphone technologies. Chinese semiconductor firm SMIC supplies chips to the company. It uses the older DUV equipment instead of EUV, so its chips aren’t as competitive as Qualcomm’s Snapdragon, MediaTek, Dimensity, and Samsung’s Exynos.

However, backed by the state fund, Huawei is working towards self-sufficiency with a robust domestic smartphone supply chain. The road ahead is still too long—Huawei is struggling to achieve healthy nm yields while TSMC and Samsung aim to start 2nm production next year—but the Chinese firm believes that “a semiconductor breakthrough is inevitable.” Surely, competition is good for the market. But can anyone challenge TSMC, only time will tell.


[ad_2]
Source link

Here’s how AI-created “smart replies” will make iOS Mail and Siri more useful

0
[ad_1]
The days are few between now and Monday which is when Apple will preview the AI features that it is adding to iOS 18 this year in what has been tipped as the largest update in iOS history. According to AppleInsider, one of the apps that will get an AI makeover this year is the iOS Mail app. I remember when this was the app you needed to send and receive email on the original iPhone. But once the App Store opened for business and Google released the Gmail app, the iOS Mail app lost much of its usefulness.

Don’t you love hearing the “swoosh” from Apple’s native Mail app?

To be honest with you, I like to use the iOS Mail app to send emails because there is nothing more satisfying than pressing the send button and hearing that “swoosh” signifying that the mail has been sent. Today’s report indicates that “Project BlackPearl” will be used to give iOS Mail a massive AI makeover in iOS 18. Search results in the AI-powered iOS Mail app will allow users to send “Smart Replies” to emails created by Apple’s on-device Ajax LLM (Large Language Module).

Such a feature is a huge time saver and is perfect for companies that need to respond to huge amounts of customer emails. Using the “Smart Reply” feature, an answer is quickly generated on-device by AI and the user can even request that a response be created by AI using a more professional style. Besides Mail, “Smart Reply” is expected to be available to Siri and Messages users.

Using “Smart Reply” will allow an iPhone user to adjust the tone of responses using other options besides making them sound more professional. These emails could be re-written by AI to sound more friendly, or written to be more easily understood by the targeted recipient.

Project BlackPearl will also allow emails to be placed in categories based on the content of the email. Time-sensitive emails will also be identified. According to those familiar with Apple’s plans, email will be classified and placed into a pre-defined category such as:


  • Commerce
  • News
  • Other
  • Promotions
  • Social
  • Transaction

These categories could be used by Siri to help the virtual assistant identify different types of email. One new feature that I’m looking forward to will allow Siri to summarize emails, email threads, and certain types of text.

AppleInsider says that it has learned from those familiar with the matter that in iOS 18 and macOS 15, the following kinds of text-based content can be summarized:

  • Emails and email threads
  • Messages
  • Notifications and notification stacks
  • Notes
  • Posts
  • User-provided texts and news articles

The new AI initiative will allow the iOS apps that provide summaries to create different types such as:

  • Topic-level summaries – with just three topic words, this summary will provide the key concepts of a text.
  • 10 or 20-word summaries that use clauses instead of full sentences.
  • Paragraph-level summaries – brief and to the point, a three-sentence paragraph, containing no more than 60 words, reveals the major point of a text.

While Apple’s Ajax LLM could handle these summaries, Apple might rely on its AI partnership with OpenAI to handle more advanced summarization.

Siri will look completely different once iOS 18 is released

Apple’s plan to make its AI summaries useful is to have AI act as an expert with the main goal of helping users of Apple’s operating system understand text. This would seem to mean that virtual digital assistant Siri will certainly look completely different when iOS 18 is released thanks to the addition of LLM capabilities.

The Photos app will work with Siri to enhance images, find certain photos, and display them. With the Notes app, Siri will be able to open and analyze certain documents, analyze them, and share them via the Messages app.

And with AI, Apple’s software will be able to create and edit images. Such images will include:

  • Animation
  • Emoji
  • Illustration
  • Line Art
  • Sketch

Recently we told you that AI will allow devices running iOS 18 to create Emoji on the fly based on contextual clues.

All the fun will begin this Monday, June 10th, starting with the WWDC 2024 Keynote which begins at 10 am PDT/1 pm EDT. Check out PhoneArena throughout the day for the latest news and analysis about Apple’s WWDC announcements.


[ad_2]
Source link

Breach Forums Plans Dark Web Return This Week Despite FBI Crackdown

0
[ad_1]

Infamous cybercrime forum Breach Forums is making a comeback! The dark web resurrection is confirmed with a new Onion domain, while the clearnet site might relaunch sometime in the coming weeks.

Important – Editor’s Note:

The following claims originated from a Telegram account previously associated with ShinyHunters, before the seizure of Breach Forums. However, Hackread.com cannot verify whether the account is still used by the original ShinyHunters hacker.

Therefore, Hackread.com strongly advises readers against engaging in any cybercrime activities. If considering registration on a cybercrime forum, proceed at your own risk.

Breach Forums, the infamous cybercrime and hacker forum, is set to return to the dark web with a new Onion domain, Hackread.com can confirm. While the exact timeline for the revival of its clearnet domain remains uncertain, administrators are working towards its relaunch any time this week.

ShinyHunters, both a hacker and administrator of Breach Forums, confirmed these developments to Hackread.com. According to the hacker, the new Onion domain for Breach Forums stands prepared for a comeback, set to take place sometime in the following week.

“The onion is ready, it’s not public yet, but it will be launched probably this week.” When questioned about the status of the clearnet domain, the hacker simply mentioned that “the clearnet will come back,” offering no specific timeframe.

Notably, Breach Forums V2 fell under FBI seizure on May 15th, 2024, reportedly following the apprehension of two administrators, one known by the alias Baphomet. ShinyHunters disclosed to Hackread.com their suspicion that Baphomet may have surrendered backend credentials to the FBI, leading to the complete seizure of the forum’s Escrow, both dark web and clearnet domains.

However, recent developments have taken an interesting turn, as ShinyHunters announced the retrieval of access to the seized clearnet domain for Breach Forums last week from the FBI, utilizing a method whose specifics remain undisclosed.

Interestingly, neither the FBI nor the DoJ has issued press releases regarding the seizure or any of the related events. While the FBI has acknowledged the seizure and urged victims of data breaches on Breach Forums to step forward and complete a form to facilitate further investigation, official statements from the authorities are still pending.

With ShinyHunters’ announcement of regaining access to the seized clearnet domain, the plot thickens, leaving many questions unanswered about the forum’s future and the role of law enforcement agencies.

Nevertheless, is it obvious that Breach Forums is undergoing a significant transformation. From its seizure by the FBI to the potential revival with a new Onion domain, the story goes on to show the tricky and strange world of cybercrime.

  1. Owner of Breach Forums V1 Pompompurin Arrested in New York
  2. Data Breach at New BreachForums: 4,000 members’ data leaked
  3. Original BreachForums Breached, PII Data of 210K Users Sold Online
  4. BreachForums Admin Pompompurin Gets 20-Year Supervised Sentence
  5. FBI Seizes RaidForums and Arrests Alleged Founder Diogo Santos Coelho

[ad_2]
Source link

The Same Phone You Love, Now With More AI

0
[ad_1]

When Google announced the Pixel 3a (and 3a XL) back in May of 2019, the whole tech world was taken aback by how great a sub $350 phone could be. It sported basically all of the same specs and features as its more expensive counterpart (at the time, Pixel 3 and 3 XL), but for about half the price.

Now, fast forward five years, and a few price increases later, we have the Pixel 8a. On paper, it looks incredible for $499. We’re talking a 6.1-inch 120Hz 2000nit display, Tensor G3 processor, 8GB of RAM, 128GB or 256GB of storage, and, of course, the renowned Pixel camera. But what makes this an interesting phone is, the fact that the Pixel 8 exists. It is only $200 more (though it is often times on sale for only $50 more) and brings you all of these features, with a glass back, a better display, better cameras and slightly larger battery life. Which begs the question, which phone is stealing buyers from which?

In this review, we’re going to try and answer why both of these phones exist in 2024, and who each one is for. Also, why should you buy or shouldn’t you buy the Pixel 8a?

Google Pixel 8a Review: Hardware & Design

The design of the Google Pixel 8a is exactly what you would expect from Google. You can see from across the room that this is a Pixel phone. Complete with the camera bar on the back and slightly more rounded corners this time around, compared to the Pixel 7a. The Pixel 8a isn’t as boxy as the Pixel 7a and is even more curved than the Pixel 8 and Pixel 8 Pro, which is rather interesting.

This time around, Google is offering it in two funky colors: Aloe and Bay. The Aloe color is what we have here, which is a bright green color, and honestly, it’s growing on me. Seeing all of the leaks and renders from Google, I wasn’t too sure about this color. But having it in hand, with the matching Google silicon case, it looks incredible. And it’s definitely fun to take photos of. The other color is the Bay blue color that debuted on the Pixel 8 Pro last year. I really like this color, and while I haven’t seen it in person yet, it does look to be a tad darker than the Bay on Pixel 8 Pro. This is likely due to the materials used in each phone.

The sides of the phone are somewhat color-matched, aluminum, and the buttons match, too. It’s a small thing, but I really like the look of that. Far more than the shiny rails of the Pixel 8 Pro. You might think the Pixel 8a is using plastic rails that are disguised to look like aluminum, but these have antenna lines, which makes these aluminum rails. Pretty nice to see on a $499 phone.

Perhaps my favorite part about the design of the Pixel 8a is the camera bar. I love this camera bar, but on the a-series, it’s even thinner. It’s not entirely flat, but much closer to being flat than the Pixel 8 and Pixel 8 Pro’s camera bars. Now the front has my least favorite design choice, and that’s the display. Google introduced some nice updates to the display this year, but it also introduced some very large bezels. Normally, the bezels don’t bother me, but on the Pixel 8a, they really bother me. On top of that, they aren’t symmetrical either, with the bottom bezel being thicker than the other three sides.

Google Pixel 8a Review: Display

As Google typically does, some of the upgrades from the Pixel 8 and Pixel 8 Pro have made their way down to the Pixel 8a this year. New this year is a 120Hz refresh rate and the Actua display. That means you’re looking at a 2000 nit peak brightness or 1600 nit high brightness mode here. That’s really incredible to have on a phone at this price point. Especially when you take into account that the iPhone 15 costs $799 and is still using a 60Hz panel.

Google Pixel 8a Review AM AH 22

What this means is, outside in the bright Summer Sun, I’ve been able to use this phone with absolutely no issues. There is some glare on the display, as you can see in the pictures throughout this review, but as far as actually being able to see the display, not a single problem. That’s not always the case with phones. But having this brighter display makes it worthwhile.

Google Pixel 8a Review AM AH 1

The colors on this display are exactly what you’d expect from Google, stunning with a tiny bit of saturation. Not so much that the display looks inaccurate, but enough to really make the colors pop. I’ve used this phone to watch a ton of content over the past week on YouTube, Netflix, and elsewhere and have not had a single problem with it. This display is not quite as good as the Pixel 8 Pro, colors still seem to pop a bit more on that display. But Google does need to give you a reason to jump up to the Pixel 8 Pro after all.

Google Pixel 8a Review: Performance

Google is once again using the same processor in its Pixel 8a, as it used in the Pixel 8 and Pixel 8 Pro. So, the performance is basically the same across all three models. The major difference here is that the Pixel 8 Pro uses 12GB of RAM while the other two have 8GB of RAM. Now Google did say that there are some differences in the Tensor G3 inside the Pixel 8a, compared to the Pixel 8 and 8 Pro, but they are pretty small.

In our usage, we noticed that the performance was largely the same. It performed well enough for a $499 smartphone, but Tensor is still somewhat slow compared to other chipsets in smartphones this year. However, at this price, you can kind of forgive it. We also did not notice it overheating much. So maybe that issue is fixed now as almost every other Tensor-powered Pixel was overheating.

The Benchmarks

Unfortunately, since we are using the Pixel 8a ahead of its official release, some of the benchmark apps that we normally use are not available to download on the Pixel 8a. But we will be updating this review later on with that data once we are able to run those benchmarks. This includes Geekbench and 3D Mark.

However, some of the other benchmarks and thermals that we typically run on phones are available. The first one is with Capcut. With this test, we load in the same 60-second video into Capcut and then export it at 1080p and 30 fps. We then time how long it takes to export, most phones are under 20 seconds, including the Pixel 8a, which was able to do the export in 16.57 seconds. That was, surprisingly, far faster than the Pixel 8 Pro did the same test last fall, which was around 40 seconds. So maybe Google was right in saying that there are some changes made to the chipset here. Not to mention, Google has also had more time with the chipset to optimize hardware now.

The Thermals

An important part of any phone is definitely the thermals. And in our testing, the Pixel 8a actually performed quite well. There are four tests that we run for thermals, and obviously the 3D Mark test we can’t run yet since we can’t download the app. But that will come later on.

The tests we were able to do included playing Genshin Impact for an hour, at the highest settings and max brightness. After an hour, we tested the temperature, and it was 93.4 degrees Fahrenheit. That’s actually about five degrees cooler than the Pixel 8 Pro.

The next test is actually a two-part test. Essentially we are using the camera to record video at 4K60 for 10 minutes, checking the temperature at 5 minutes and again at 10 minutes. Typically recording at 4K60 can really heat up the phone, so this is a good test to check out the thermals. The Pixel 8a was at 87.9 degrees Fahrenheit at 5 minutes, and 92.1 degrees Fahrenheit at 10 minutes. Those are some pretty good readings actually.

Google Pixel 8a Review AM AH 2

These results really make me think that the plastic backside of the Pixel 8a mixed with some optimization of the Tensor G3 since its launch last fall, has really helped with thermals on the Pixel 8a. Considering the Pixel 8 and Pixel 8 Pro both use glass backs, which does make it tougher for heat to dissipate. Overall, a pretty good showing for the Pixel 8a here.

Google Pixel 8a Review: Battery Life & Charging

For the last couple of years, really since Google switched to Tensor chipsets, the battery life on Pixel phones hasn’t been that great. Before Tensor, Pixel had pretty good battery life. But, when Google switched to Tensor, other chip makers like Qualcomm moved over to TSMC which provided some incredible battery gains. Whereas the Pixel has continued to have essentially the same battery life.

That said, the Pixel 8a should be able to get you through a day. During the review process, I would unplug the Pixel 8a around 7AM, and by the time I go to bed around 11PM, it was still around 25-30%. That was with around 6 hours of screen on time. It’s decent, but not the best.

As far as charging goes, that’s where things really look bleak. Google is gatekeeping the charging speed on the Pixel 8a, since it is rated at 18W wired and 7.5W wireless. That’s pretty slow, even compared to the Pixel 8 and Pixel 8 Pro, which use the same processor and can do 30W and 15W. That makes the battery life of the Pixel 8a even slower since it is going to take close to two hours to fully charge the phone.

Benchmarks

As we do with the performance of each phone, we also have benchmarks for battery life and charging. These are quite simple. For battery life, we charge to 100% overnight, to make sure it is fully charged completely. Then play the same 24-hour YouTube video as we do on every phone. We keep the phone at 100% brightness, and run it down to about 1%, so we can track how long it lasted. Our testing showed that the battery lasted 14 hours and 30 minutes. That’s quite low actually, and one of the lowest times we’ve had since doing this test over the past year.

For charging, we start a timer after we plug it into an appropriate charger after the video test mentioned above. And record how long it took. We also use a USB-C cable that shows us the charging speed, to make sure it is charging properly. If there is a charger in the box, we’ll use that for this test. But as you probably know, the Pixel 8a does not come with a charger in the box. So just a regular 30W charger will do the trick. In our testing it was able to fully charge in just under two hours.

Google Pixel 8a Review: Software

With the Pixel 8a, you’re getting Android 14 out of the box. As expected, you will get Android 15 on the Pixel 8a by the end of the year. And as a Pixel, it will be among the first to get Android 15. Similar to the Pixel 8 and Pixel 8 Pro, the Pixel 8a is going to get 7 years of updates, security updates and feature drops. That’s pretty incredible for a phone at this price point. Since so many others are lucky to get a single update, never mind updates for seven years.

The software on the Pixel 8a is basically what you’d expect from Google. Including a slew of great AI features, like the Generative AI wallpapers. Now, this is not available on the phone out of the box. However, you should have an update waiting for you, which does bring in this feature. It works just like it does on the Pixel 8, Pixel 8 Pro and Galaxy S24 series, where you give it a few options and it will generate a couple of wallpapers that you can use.

Google Pixel 8a Review AM AH 16

Some of Google’s popular AI Camera features are also available on the Pixel 8a, including Magic Editor. But we’ll talk more about that a bit later.

The software on this phone is pretty good. The Pixel Experience is still one of my favorite software experiences on Android right now, and it works so well on the Pixel 8a’s hardware.

Google Pixel 8a Review: Camera

Last year, Google upgraded the cameras pretty hugely on the Pixel 7a. So this year, we were not expecting large camera upgrades, at least on the hardware. And that’s true. Google stuck with the 64-megapixel primary camera, and a 13-megapixel ultrawide camera. Now that primary camera does sound like it might be better than the Pixel 8 and Pixel 8 Pro, since those sport a 50-megapixel primary camera, but that’s not entirely accurate. On the Pixel 7a and Pixel 8a, the 64-megapixel camera is actually a smaller camera, than what the Pixel 8 and Pixel 8 Pro has. So the Pixel 8 and Pixel 8 Pro is able to get more details in each image, versus the Pixel 8a.

Google Pixel 8a Review AM AH 20

However, if you put pictures taken with the Pixel 8 Pro and Pixel 8a side-by-side, you likely wouldn’t notice the difference. Why is that? It’s simple, Google’s computational photography. That is how Google has been able to produce such great pictures without the latest and greatest camera sensors like what Samsung, Vivo and OPPO might be using.

Now, let’s talk about the camera quality on this phone. I’ve taken this phone out to take photos over the past week that I’ve been working on reviewing it, and it takes great Pixel pictures. There’s not much to be disappointed with here other than the lack of Zoom. Below, you’ll see a number of pictures that were taken with the Pixel 8a. Portraits look great, as you’d expect from a Pixel, and so do normal pictures as well as close-ups. There’s no macro mode here, but you can get sort of macro-style pictures from this phone.

Now let’s talk about some of the other software on the Pixel 8a, including Magic Editor. This is a feature that Google debuted with the Pixel 8 and Pixel 8 Pro last year. Basically, it’s using generative AI to change the way your picture looks. It can change the sky, add or remove clouds, it can also make your portrait look more like a portrait with more bokeh in the background. Among many other things.

Best Take, which also debuted on the Pixel 8 series last fall, has come to the Pixel 8a. Basically, what this does is it takes burst shots of a group of people, and lets you change the faces of people after the picture is taken. So if someone is always blinking or not smiling when the picture is taken, you can fix that pretty easily here.

Finally, my last favorite feature for the camera is Audio Magic Eraser. If you’ve ever been in a busy city and wanted to take a video, you’ve likely heard plenty of road noise and other noises you might not want in your video. With Audio Magic Eraser, the Pixel 8a can remove that for you. That includes car noise, wind, and construction noises. You can also remove voices, or enhance voices too.

The camera experience on the Pixel 8a is actually really good, and I’d say it’s probably the best of any phone in this price range.

Should you buy the Google Pixel 8a?

Normally, if I’m looking at just the Pixel 8a and phones in its price range, it should be a no-brainer that the Pixel 8a is a must-buy. But where the Pixel 8 exists, and is constantly on sale, that makes the recommendation to buy the Pixel 8a a bit tougher. Typically, the Pixel 8 can be found for around $549 (MSRP is $699 though). And for that $50 more, you’re getting a glass build, better cameras, a better display, and slightly better battery life.

Google Pixel 8a Review AM AH 30

You should buy the Google Pixel 8a if:

  • You want a good phone that doesn’t cost a lot
  • You want a Pixel phone that’s under $500
  • You want a small phone that doesn’t suck.

You should not buy the Google Pixel 8a if:

  • You have a Pixel 7a or later Pixel phone.
  • You need incredible battery life
  • You need a camera with decent zoom capabilities

[ad_2]
Source link

Muhstik Malware Attacking Apache RocketMQ Platform To Execute Remote Code

0
[ad_1]

Apache RocketMQ platform is a widely used messaging system that handles high volumes of data and critical operations, often attracting hackers. 

Exploiting the vulnerabilities in RocketMQ allows attackers to disrupt communications, access sensitive information, and potentially gain control over the data flow.

Cybersecurity researchers at Aqua Nautilus recently discovered that Muhstik malware has been actively attacking the Apache RocketMQ platform to execute remote code.

Muhstik Malware Attacking Apache RocketMQ

RocketMQ had a remote code execution vulnerability (CVE-2023-33246) in versions 5.1.0 and below, allowing attackers to execute commands by leveraging the insecure update configuration function.

With ANYRUN You can Analyze any URL, Files & Email for Malicious Activity : Start your Analysis

Experts detected attacks exploiting this to download Muhstik malware, part of the Kaiten family targeting Linux devices for cryptomining and DDoS attacks. 

The attack flow first exploits the RocketMQ flaw to upload and execute a malicious payload that fetches Muhstik, bearing resemblance to prior Mirai-based attacks following that malware’s source code leak.

Researchers exposed a honeypot with a vulnerable RocketMQ version. Attackers detected and exploited the flaw to update the broker configuration, enabling remote code execution. 

They delivered a malicious shell script fetching Muhstik malware binaries matching the system architecture. 

Attack Flow (Source – Aqua Sec)

Muhstik then copied itself across directories like /dev/shm and edited inittab for persistence, restarting its process on boot. 

It employed fileless techniques loading directly into memory from temporary locations to evade detection while using a pty3 filename masquerading as a legitimate process.

The Muhstik malware gathered system details via uname, checked for network monitoring tools like strace and tcpdump, scanned for SSH services, and communicated with a C2 server over IRC. 

It connected to p.de-zahlung[.]eu, an identified malicious domain, joining channel #ex86 with password 8974.

An encrypted command was sent instructing cleanup of malicious processes like cnrig and kinsing by killall. 

The malware persisted by PING and PONG exchanges to confirm the active IRC connection for receiving further commands from the C2 server.

To make money from compromised systems, Muhstik removes malicious processes and DDoS floods them as well as cryptomines on infected computers.

The vulnerability to CVE-2023-33246 made 5200 RocketMQ instances globally vulnerable, according to Shodan scans conducted by researchers.

This highlights the risks of unpatched systems.

This implies that security will remain a top priority for companies with cloud-native applications since some new vulnerabilities and misconfigurations could expose their systems to attackers like Muhstik.

RocketMQ is a good example of a messaging infrastructure that can be used during development to help developers build more resilient applications.

Recommendations

Here below we have mentioned all the recommendations:-

  • Secure your environment
  • Scan your environment
  • Educate your employees

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo 


[ad_2]
Source link

Debt collection agency FBCS leaks information of 3 million US citizens

0
[ad_1]

The US debt collection agency Financial Business and Consumer Solutions (FBCS) has filed a data breach notification, listing the the total number of people affected as 3,226,631.

FBCS is a nationally licensed, third-party collection agency that collects commercial and consumer debts, with most of its activity involving the recovery of consumer debts on behalf of creditors. According to the official statement provided by FBCS, the exposed data includes:

  • Full names
  • Social security numbers
  • Birth dates
  • Account information
  • Drivers license or other state ID numbers

In some cases, it also includes medical claims information, provider information, and clinical information (including diagnosis/conditions, medications, and other treatment information), and/or health insurance information.

FBCS has sent data breach notifications to those affected, detailing what data was compromised and offering 12 months of free credit monitoring.

Protecting yourself after a data breach

There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.

  • Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened, and follow any specific advice they offer.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop or phone as your second factor. Some forms of two-factor authentication (2FA) can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for fake vendors. The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify the identity of anyone who contacts you using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online, and helps you recover after.

Scan for your exposed personal data

You can check what personal information of yours has been exposed online with our Digital Footprint portal. Just enter your email address (it’s best to submit the one you most frequently use) to our free Digital Footprint scan and we’ll give you a report.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection.


[ad_2]
Source link

Another company is working on 300W charging for smartphones

0
[ad_1]

Yet another company seems to be working on 300W charging for smartphones. The company in question is Realme, as the company’s Head of Marketing for Realme Global, Francis Wong, confirmed.

Yet another company is working on 300W charging for Smartphones, Realme

This was confirmed during TheTechChap’s interview with Francis Wong. He confirmed that the company is testing 300W charging already. That is not surprising, as Realme is usually at the very front when it comes to charging tech.

By presenting 300W charging tech, Realme will join the likes of Xiaomi‘s Redmi, who already demoed its 300W charging. Redmi’s 300W charging managed to fully charge a phone in under five minutes.

Having said that, Realme already offers 240W charging, which is immensely fast on its own. The Realme GT Neo 5 supports 240W charging, and it can charge fully in under 10 minutes. Needless to say, that’s truly impressive.

Realme doesn’t seem to think that’s enough, though, although many would disagree. The company wants to push the ante even further up. We’re expecting to see similar results to what Redmi demoed.

Redmi did demo 300W charging already, but it still doesn’t offer a phone that supports it

Do note that Redmi still doesn’t have a phone that charges at 300W, though. It did not release it. So, there’s still time for Realme to do it first. It remains to be seen what will happen.

What is unfortunate is that Francis Wong didn’t go into specifics during the interview. It would be great to know a bit more about heating during such charging, the company’s plan to prevent that, and also to safeguard battery life in the long term.

Chances are Realme will demo its 300W charging tech in the near future, though. There’s a reason Francis Wong mentioned it during this interview. It could debut inside the Realme GT Neo 6. The Realme GT Neo 5 arrived back in February, so we’re still over half a year away from its successor if Realme ends up sticking to its release cycle.


[ad_2]
Source link