Everything you need to know

0
[ad_1]

Many of you have probably heard of Google Docs at this point, even if you’re not using Google. Google Docs service has been around for a long time as part of Google’s suite of productivity tools. Many people know it as a direct replacement for Microsoft Word, actually. In this article we’ll talk more about Google Docs in order to get you more familiar with the tool, starting with what exactly is it. If you’ve been wondering, or you’re simply looking to step away from Microsoft Word, this could be a great option for you. It also has some benefits, of course, especially if you’re a Google user. So, let’s get to it.

What are Google Docs?

Google Docs is an online word processor. That’s the best explanation of the tool. It’s a part of Google’s web-based suite of productivity tools. That suite also includes Google Sheets, Google Slides, Google Drawings, Google Forms, Google Sites, and Google Keep. Considering that this suite is often looked at as a direct replacement for Microsoft Office, you’ll likely hear Google Docs, Google Sheets, and Google Slides mentioned most frequently.

AH Google Docs 2024 image 2

Google Docs have been around for a long time, actually. Google launched it back in March 2006, so we’re 18 years in at the time of writing this article. The service is available in 100 languages at this point in time, and has come a long way since its inception. It also comes with direct integration with Google apps, and most importantly Google Drive. Google Drive is the company’s cloud storage which is connected to your Google account. You can launch Google Docs from there directly if you want, though it’s available as a separate app too.

What platforms are Google Docs available on?

Google Docs tool comes in both app and web formats. So you can basically access it from any web browser, as long as you log into Google Drive, where the service is docked. It really doesn’t matter what platform you’re using at that point, whether be it Windows, macOS, or some sort of a Linux-based OS. Alternatively, you can also access Google Docs in an app format. Google Docs app is available on Android, iOS, and ChromeOS. Needless to say, Android and iOS are the world’s largest mobile OS’ which hold almost the entire market, so… you’re well-covered in that regard.

Are Google Docs free to use?

Google Docs are free to use, yes, as long as you have free storage on Google Drive. As mentioned earlier, Google Docs comes with your Google account, and it’s a web-based service. Anything you do in Google Docs gets saved to the cloud pretty much immediately so that you don’t lose any of your work. That does take free online space from your Google account. When you open your Google account, you do get 15GB of free storage space. Every Google service that you use will take chunks of that space, including Google Docs, Sheets, Keep, Photos, Gmail, and so on. So, the bottom line is, yes, it’s free… but you need to have free space on Google Drive.

What are Google Docs’ competitors/alternatives?

The best-known Google Docs alternative is Microsoft Word. Those are arguably the two most popular word-processing tools out there. They even open the same types of files, .doc and .docx, amongst others. Microsoft Word is not the only competitor to Google Docs, though. There are a number of other word-processing suites out there, but let’s stick with direct competitors that open the same types of files. Many of you have probably heard of LibreOffice and WPS Office.

LibreOffice is an open-source office software suite that came to life in 2010. It’s very popular for Linux users, actually. WPS office is way older, as it came to life way back in 1988. It’s cross-platform, and it actually has a wider availability than Microsoft Word and Google Docs. WPS Office is not only available on Android and iOS but also on Fire OS and HarmonyOS, as far as mobile platforms are concerned. You can also access it from desktop operating systems, though.

Another competitor that comes to mind is the Zoho Writer. It’s a part of Zoho’s rich suite, and you can link it to your Google and Yahoo accounts. It is also web-based and saves documents for you automatically. It’s feature-rich, and a solid alternative to Google Docs.

Can I use Google Docs if I’m not connected to the Internet?

Is it possible to use Google Docs if you’re not connected to the Internet? Well, yes, it is. You can do that for Google Docs, Sheets, and Slides, actually. Do note that it’s not available outright, though. You’ll need to turn on offline access for specific files you have created via Google Docs, well, unless the document we’re talking about is already saved on your phone or something. Let’s assume it’s not, though. You’ll need to have an Internet connection and navigate to the document you’d like to use offline. Once you find it, either via desktop PC or your smartphone, you’ll need to make it available offline or download it.

AH Google Docs make available offline

On desktop PCs, you’ll need to locate the file, right-click on it, and you’ll see the ‘Make available offline’ option. Once you enable that, you’ll be able to edit it while you’re not connected to the Internet. The moment you get an Internet connection, however, your changes will be saved. You can also download the document for offline use, though that’s something else entirely, as you’ll basically disconnect that file from Google Drive. Do note that you’ll need to long-press on a specific file from your smartphone in order to get the same options menu as the right-click delivers on desktop PCs.

Do Google Docs require any type of configuration before you start using it?

You’ll be glad to know that you don’t really have to configure Google Docs before you start using it. Just make sure you have a Google account, and you’re ready to go. You can always go in the Google Docs app and set your preferred theme, though, or something like that, but that’s completely optional. The app will work as intended without any configuration whatsoever. The same goes for the web client too.

What are the best features of Google Docs?

Google Docs is a very capable text-processing tool. If you’ve ever used Microsoft Word, Google Docs basically delivers that functionality in a different packaging… plus some added ones. The feature lists are not the same, but they do share a lot of the same functionality. That being said, we won’t really talk about all the tools available in the app and stuff like that, as that would take up an eternity. We will, however, highlight some of the most interesting Google Docs features, and the ones we use the most.

AH Google Docs 2024 image 4

Continuous auto-saving

This was one of my personal favorite features when I started using Google Docs. Your words will get saved as you write them, so even if you lose power or something, pretty much everything will be saved. You never have to manually click the ‘save’ or ‘save as’ options, or anything like that. This feature always worked seamlessly for me, and it’s probably still my favorite thing about Google Docs.

Pageless view

By default, Google Docs does separate your documents into pages. However, you can change that. You can activate the pageless view if you’d like to just write on an endless piece of paper, basically. You won’t see any page breaks or anything of the sort. This is likely not ideal if you’re writing a book, or collaborating with someone on something like that. However, it is convenient in many other situations, especially if you’ll be using images, tables, and so on. You can do that by going to ‘File’, and then ‘Page Setup’. There you’ll see the ‘Pageless’ tab and need to confirm your choice. If you opt for the ‘Set to default’ option, you’ll get a pageless view of all your future documents.

Google Docs pageless format

Sending emails straight from Google Docs

This is more of an interesting and cool feature than something I’m using regularly, but still, it’s worth noting. You can actually send emails directly from Google Docs if you want. This enables you to place tables, dropdowns, and more in your emails. Simply click the ‘Insert’ menu, and hover over the ‘Building blocks option’. There, you’ll need to select ‘Email draft’, and set everything the way you like it. Once you’re done, click the ‘Gmail’ icon in order to export it. You’ll get a preview of your email before you send it.

Version History

The ‘Version History’ feature is also one of my favorites. You can access it from the ‘File’ menu. It’s great to have in general, especially if you’re collaborating with someone. Thanks to this feature, you’ll get access to a detailed log of all document versions. You’ll also see the changes made, the person who made them, and when they were made. That way, you’ll know exactly what’s what, without surprises.

Google Docs version history

Sharing documents

As is the case with files in Google Drive in general, you can easily share your Google Docs files with other people. You have the option to send them a link to be able to read a document or allow someone to co-edit a file with you. It all depends on what your plans are for that specific file, of course. Furthermore, you can create a link for the document that anyone with the link can access, or you can add Google users directly to the sharing menu, it’s all up to you. Google does provide you with options.

Google Docs sharing

Suggesting edits

If you’re collaborating with someone on a specific document, you can suggest edits for said document. You can easily select any portion of the text you want, and then you’ll see a pill-shaped pop-up menu on the right. The third and last option there is ‘Suggest edits’. Once you do that, the other side will see that a specific portion of the text is highlighted, and they’ll see what you said about it. This is a great way to proofread something for someone, or generally collaborate on a project.

Google Docs suggest edits

Voice typing

Some of you are likely using voice typing wherever you can. Well, you’ll be glad to know that it’s built straight into Google Docs. That tool is located in the ‘Tools’ menu. You’ll see the ‘Voice Typing’ option there. Needless to say, this tool is very accurate, as we’ve come to expect from Google. If you’re unwilling to manually type, you can always use this option and dictate your text. You can, of course, proofread and change what needs changing later on.

Google Docs voice typing

Custom keyboard shortcuts

Another extremely useful feature to have in Google Docs is custom shortcuts. This is not something many people will use, but if you have the time to set it up, it can be really useful. It can increase your workflow quite a bit. Google Docs does support your standard shortcuts, such as CTRL+C for copying and CTRL+V for pasting, for example. Thanks to the custom shortcuts option, however, you can make a ton of other options. The possibilities are endless. Simply open the ‘Tools’ menu, and click on ‘Preferences’. You’ll figure it out from there.


[ad_2]
Source link

The Galaxy S25 could use Gemini Nano version 2

0
[ad_1]

It should be common knowledge by now that Samsung’s Galaxy AI is powered by Google’s Gemini Nano AI model. While some of the tools do use Gemini Pro via an online connection, many of the computations are done on-device. Well, according to a new report, Google’s Gemini Nano 2 will power the Galaxy S25’s AI.

Galaxy AI was a major selling point for the Galaxy S24 series. In fact, this series broke the record held by the Galaxy S23 phones. These tools involve on-device AI, and many of them include text generation and language translation. If you are excited about picking up a Galaxy S24, the base model starts at $799 with the Galaxy S24 Ultra (Review) coming in at $1,299.

Gemini Nano 2 could power the Galaxy S25’s AI

This news comes to us from Nguyen Phi Hung on X. This is a reputable source, but you will still want to take this news with a grain of salt. Since this has not been officially announced by the companies, there’s always the chance that anything could change between now and the official launch.

According to the report, Google and Samsung are set to collaborate again for the next batch of Galaxy S phones. Releasing early next year, Samsung plans to bring further improvements to Galaxy AI with the introduction of the Galaxy S25 phones. Now, there’s not too much information regarding these devices. We can expect the usual slew of performance and camera improvements with a similar form factor to what we’ve gotten over the past couple of years.

However, since Samsung really hit gold with Galaxy AI, we should also expect the company to shift a ton of effort and improvements over to the new platform.

However, one thing we didn’t expect was a new version of Gemini Nano. Gemini Nano was introduced only a few months ago, so we have no idea about Google’s release plan. However, if Gemini Nano version 2 is released early next year with the Galaxy S25, then we should probably expect yearly iterations of its AI models.

Right now, information about both the Galaxy S25 and Gemini Nano 2 is scarce. Luckily, information about the latest Galaxy S phones starts popping up relatively early in the year. Couple that with the fact that Google is terrible at stopping leaks, then we should rightfully expect information about both of these products to start coming forth relatively soon.


[ad_2]
Source link

T-Mobile probes mysterious texts bribing employees for SIM swaps

0
[ad_1]

T-Mobile faces fresh scrutiny after reports of mysterious texts offering employees cash in exchange for performing unauthorized SIM swaps recently started doing rounds on social media. The messages target current and former employees across the country and offer up to $300 per SIM swap. This brazen attempt to exploit T-Mobile’s staff raises serious concerns about the carrier’s security practices and highlights the ever-present threat of SIM-swapping attacks.

What is SIM swapping, and where did employee data come from?

SIM swapping is a fraudulent act in which a bad actor tricks a cellular carrier into transferring your phone number to a new SIM card. It gives the attacker control of your phone, allowing them to intercept calls, texts, and, most importantly, two-factor authentication codes. This can lead to, among other things, financial loss, as attackers can hijack bank accounts, cryptocurrency wallets, and other sensitive online services accessible through your phone.

The big mystery is how the perpetrators got their hands on T-Mobile employee phone numbers. The company denies a recent systems breach. However, the inclusion of former employees suggests the data might be linked to previous breaches. This may also represent a new, yet undisclosed, breach—a truly troubling prospect for T-Mobile given its recent history with data breaches.

T-Mobile’s response is not entirely reassuring

While acknowledging the investigation, T-Mobile’s statement does little to calm customer nerves. According to The Mobile Report, T-Mobile has denied any possibility of another data breach. T-Mobile also claims this issue isn’t limited to the Un-carrier. “We did not have a systems breach,” part of the statement reads. However, they’ll “continue to investigate these messages that are being sent to solicit illegal activity.” They also note that “other wireless providers have reported similar messages.” Still, the ongoing nature of these texts hints at a possible attack. Or worse yet, the presence of willing accomplices within T-Mobile’s ranks.

T Mobile mysterious texts on SIM swaps

Customer concerns and the erosion of trust

This incident adds to a growing list of security scandals that have plagued T-Mobile in recent years. The company’s once-stellar reputation is rapidly eroding, and customers are rightfully questioning whether their information is safe. SIM swap attacks are a serious problem for the entire industry, but this incident suggests that T-Mobile seems especially vulnerable.

There’s no guaranteed fix for this. However, for better security, you can avoid SMS-based two-factor authentication and switch to app-based authenticators like Google Authenticator or Authy. Always scrutinize links and phone numbers. Also, be wary of mysterious texts or calls claiming to be from T-Mobile support. Lastly, enable the SIM protection function that T-Mobile offers, and be sure to activate it on your account.

Even as the investigation continues, T-Mobile needs to be more transparent about the source of these latest SIM swapping attempts (assuming it’s not a new data breach). The company must also reassure customers that their information is truly secure and that it is taking decisive steps to prevent similar incidences in the future.


[ad_2]
Source link

Google’s laying off more people, shifts roles to other countries

0
[ad_1]

While the year 2024 has been great for Google’s AI technology, it has not been great for Google’s workers (or, shall we say, “former workers”). The company has been shedding employees like crazy, and the layoffs don’t seem to be slowing down. According to a new report, Google is laying off even more people, and it shifted some roles to other countries.

Major tech companies have been laying off workers left and right over the past couple of years due to a turbulent economic climate. Recently, Tesla just laid off about 10% of its workers and Apple let go of about 700 workers. Google is one of the main companies getting rid of its employees, as the company had to lay off several thousand workers at a time.

Google is laying off more employees and shifted roles to other countries

Right now, this news is still pretty new. You should expect more information to come out about it soon. Google officially confirmed to Business Insider that the company will cut jobs this week. However, the spokesperson did not say just how many people will be let go. No other sources gave any sort of ballpark as to the number either. However, some employees confirm that affected workers include those working in finance and in real estate.

Since Google has laid off pretty massive numbers of employees in the past, there is reason to believe that this layoff will see a significant number of workers leaving. However, we’ll have to wait for more information to confirm that.

While many workers will likely get the ax, other workers in different countries have new opportunities. Google confirmed that it is moving roles to cities in other countries including Bangalore, Mexico City, and Dublin. Not all of the roles are being moved outside of the United States. The company will move some roles to its office in Atlanta, Georgia.

When following this story, you should expect a thick layer of PR speak from Google as the company responds to questions. However, it’s likely that the company is doing this for cost-saving reasons.

Hopefully, the number of layoffs isn’t substantial, and those affected will be able to find new positions. In fact, a bit of a silver lining is the fact that several workers have been offered different positions within the company. More information about this situation will be revealed as time goes on.


[ad_2]
Source link

Google Photos working on an option to hide your downloaded memes and other UI tweaks

0
[ad_1]
Google Photos might soon become a little easier to manage with two potentially significant features recently found within the app’s code. These are designed to tidy up the sometimes overwhelming experience of managing our ever-growing photo libraries.
We all probably store a lot more in Google Photos than just our cherished memories. Screenshots, memes, and GIFs, while sometimes useful or entertaining, can seriously clutter up the main photos tab. Thankfully, as spotted by Android code expert AssembleDebug (via PiunikaWeb), Google seems to understand this and is giving us a new “Hide clutter” setting within the app.

Having this option should help put some order into the chaos that is the Google Photos library, but won’t completely disappear distracting items like screenshots or memes. What it does, is that it tucks them away in their designated albums where you can find them if needed. The primary difference is that they won’t invade your main photo grid while you’re trying to reminisce. These changes were found hidden in Google Photos version 6.79.0.624777117 with the below strings:

<string name=”photos_allphotos_gridcontrols_hide_clutter_base_filter_setting_title”>Hide clutter</string>

<string name=”photos_allphotos_gridcontrols_hide_clutter_base_filter_setting_subtitle”>Backed-up photos like screenshots, GIFs, and memes are hidden</string>

Memories are getting a makeover too

The Google Photos’ Memories tab is also getting a fresh coat of paint. The current collage-like presentation will make way for a more streamlined interface. Individual memories will now be shown as rounded rectangles, each with a single representative photo. Whether you love or hate the change, it’s definitely a shift in Google’s approach to presenting those nostalgic moments.

Google Photos’ Memories before and after | Source: PiunikaWeb

A bit more personalization

Google is also sneaking in a small but welcome tweak to its AI feature suggestions. Sometimes, the AI-generated Memory titles offered by Google Photos can be less than ideal. A new toggle in the app settings will let users disable these suggestions if they wish, allowing for more control over how their memories are labeled.

Source: PiunikaWeb

It’s important to remember that these features are still under development, so they may change at any time or may not even roll out at all. Still, it’s encouraging to see Google Photos continuing to evolve and offer users more control over their digital photo libraries.


[ad_2]
Source link

Hackers Exploiting Palo Alto Networks Zero-Day

0
[ad_1]

The Palo Alto Networks PAN-OS software has a critical command injection vulnerability that allows an unauthorized attacker to run arbitrary code on the firewall with root access. 

The vulnerability is identified as CVE-2024-3400, with a CVSS score of 10.0. Operation MidnightEclipse has been coined to describe its exploit.

Palo Alto Networks confirmed targeted attacks using this vulnerability last Friday in an alert, crediting a threat actor for known exploitation and noting the possibility of further exploitation by threat actors.

Only PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls are configured with device telemetry enabled, and either the GlobalProtect gateway or GlobalProtect portal (or both) are affected by this issue. 

Prisma Access, Panorama appliances, and cloud firewalls (Cloud NGFW) are unaffected by this flaw. 

How Attackers Exploited The Flaw?

Using the vulnerability, the attackers set up a cron job that retrieves commands hosted on an external server once every minute.

The bash shell is then used to carry out these commands. Palo Alto said the URL is believed to be a delivery system for a firewall backdoor running on Python.

The embedded backdoor component that carries out the threat actor’s directives is decoded and operated by another Python script that is written and launched by the Python file.

Document
Stop Advanced Phishing Attack With AI

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Stopping 99% of phishing attacks missed by other email security solutions. .

The threat actor was observed to be remotely exploiting the firewall to download more tooling, establish a reverse shell, change course into internal networks, and eventually steal data.

Palo Alto Networks released a hotfix to address command injection vulnerability in its custom operating system.

The attack was probably the result of a state-sponsored threat actor’s campaign, which security experts discovered began in March.

According to the threat intelligence firm that discovered it, Volexity tracks a threat actor named UTA0218 that started taking advantage of the zero-day vulnerability on March 26. 

Based on the resources needed to find and exploit the zero-day, the type of victims targeted, and the complexity of a Python-coded backdoor the threat actors placed to gain additional access to victim networks, Volexity attributes the attack to a government.

According to Volexity, zero-day exploitation appears to be targeted and restricted. However, as of this writing, “evidence of potential reconnaissance activity involving more widespread exploitation aimed at identifying vulnerable systems does appear to have occurred at the time of writing.”

Volexity discovered proof that after the intrusions, the attackers switched to internal networks.

The Active Directory database, as well as browser data from Microsoft Edge and Google Chrome, were among the critical Windows files that the threat actors targeted.

Hotfixes Released

The issue is fixed in hotfix releases of PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and all later PAN-OS versions. 

Additionally, the company said that the hotfixes for commonly deployed maintenance releases will be made available.

Palo Alto Networks advises users to watch for unusual behavior on their networks and investigate any sudden activity.

Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP.


[ad_2]
Source link

Logitech introduces its Logi AI Prompt Builder

0
[ad_1]

Just about every major tech company is making a hard pivot toward implementing AI in some way. This is not only for software companies. Logitech, the popular keyboard and mouse company, is making it easier to access ChatGPT by using its Logi AI prompt Builder.

Most of us within the Logitech ecosystem should know about the Logi Options+ app. This is a very useful app that you can use to fully customize your experience by letting you change the mouse settings, map buttons to certain functions and applications, etc. It’s available to download on Windows and Mac computers. So, if you have a supported keyboard or mouse, this may boost your experience.

Logitech announced the Logi AI prompt Builder to help you access ChatGPT faster

So, Logitech isn’t exactly going out and developing its own LLM. However, with how furiously companies are adopting AI, it wouldn’t have been surprising if the company did. In any case, Logitech just announced something a bit less ambitious. The Logi AI prompt Builder is a new addition added to the Logi Options+ app that will make it easier to access ChatGPT on the fly.

You can map a shortcut button to quickly access the Prompt Builder. The Prompt Builder will show up as a pop-up on the screen. You will see two main halves of the pop-up. The left half will show you the different Recipes that you can use. A Recipe is a certain function that you want the AI to perform. The current functions are rephrase, summarize, reply, and email.

On the right side, you’ll see several components. In the middle of the screen, you will see a large text field. This is where you will either paste or type the text that you want to be affected. Under that field, you will see certain options that will affect the outcome. These functions will vary depending on the recipe.

When you are finished, all you have to do is click on the Submit button at the bottom right of the screen. You will then receive your response to copy and paste.

This is a functionality that will make it quicker to access powerful generative AI capabilities. So, no matter if you are trying to type up an email for a client, write a report, digest a long bit of text, etc., you’ll have easy access to ChatGPT.


[ad_2]
Source link

Spectrum TV Stream launched with 90+ channels

0
[ad_1]

US Cable TV giant Charter Communications has launched Spectrum TV Stream, a new bundle of internet-based channels from multiple broadcasters. The $39.99 per month subscription offers a bouquet of more than 90 channels from some of the biggest entertainment content producers.

Charter bundling 90 channels in one Streaming TV package

Charter Communications has reportedly launched Spectrum TV Stream, a new streaming TV bundle, primarily targeted at its Spectrum broadband customers. Incidentally, the company has launched two streaming bundles.

There’s the Spectrum Stream Latino, which offers 45 Spanish-language channels. The Spectrum TV Stream is aimed at an English-speaking audience. It has over 90 live channels.

This is a significant detour or diversification for Charter. It is now venturing into a new area where multiple streaming giants such as Netflix, Hulu, and others are competing. Sharon Peters, Executive Vice President, and Chief Marketing Officer for Charter claimed Charter has deliberately positioned the service as a lower-cost TV package for broadband-only customers.

“We are focused on creating more flexible, lower-cost video options for our customers that include a bundle of channels they want to watch. With Spectrum TV Stream and Stream Latino, our customers now have the option to choose high-value, internet-delivered streaming TV packages that include the most popular news and entertainment networks and Spanish-language programming.”

This new service offers 90+ live-streaming TV channels from Walt Disney Company, Warner Bros. Discovery, Fox, A&E, AMC, BBC America, CNN, National Geographic, and more.

The Spanish package with 45 Spanish channels costs $24.99 per month. It includes channels from Univision, Telemundo, beIN Sports en Español, and Discovery en Español. Interestingly, Charter already offers Mi Plan Latino, which is a Spanish-language TV package.

Sports Channels missing from Spectrum bundle

The Spectrum TV Stream subscription includes channels that offer entertainment and news. It is available to Spectrum Internet customers.

The entire package is reportedly available through the Spectrum TV App. Charter offers the Spectrum app for nearly every imaginable hardware, including iOS and Android smartphones and tablets, Apple TV, Roku, Xbox One, Amazon Kindle Fire, Samsung Smart TVs, Xumo Stream Box, and more. The same service is also available via the SpectrumTV.com website.

Notably missing from the English language Spectrum TV Stream bundle are sports channels. Even the ESPN+ stream, which Disney usually bundles in cable deals, is missing. The ESPN+ stream is available with the Spectrum TV Select Plus package. This might be a deal-breaker for many, especially considering how fierce the competition is.


[ad_2]
Source link

Cisco Warns Of Massive Brute-Force Attacks : VPNs & SSH Services

0
[ad_1]

Hackers use brute-force attacks since it is an uncomplicated technique to break passwords or get into systems without permission. 

By systematically trying various combinations of usernames and passwords, attackers can exploit weak credentials.

Brute-force attacks are automated and scalable, enabling hackers to compromise multiple accounts or systems in a relatively short time.

Cybersecurity researchers at Cisco recently warned of massive brute-force attacks targeting VPNs and SSH services.

Cisco: Massive Brute-Force Attacks

Cisco Talos appreciates the contributions of Brandon White, Phillip Schafer, Mike Moran, and Becca Lynch for identifying a worldwide increase in brute force attacks on VPNs, web authentication portals, and SSH services since at least March 18th, 2024.

Free Live Webinarfor DIFR/SOC Teams: Securing the Top 3 SME Cyber Attack Vectors - Register Here

All these attacks originate behind TOR exit nodes and other anonymizing proxies and tunnels.

However, due to this reason, Cisco Talos is currently observing this widespread campaign.

These brute force attacks, which depend on the targeted environment, may result in unauthorized network access, account lockouts, and denial-of-service conditions. 

Traffic volumes associated with this campaign have steadily increased since March, and this trend will probably continue.

This campaign affects other services as well; however, certain services have been identified as being affected.

Here below, we have mentioned all the services that are affected:-

  • Cisco Secure Firewall VPN 
  • Checkpoint VPN  
  • Fortinet VPN  
  • SonicWall VPN  
  • RD Web Services 
  • Miktrotik 
  • Draytek 
  • Ubiquiti 

Besides this, brute-force attempts leveraged both generic and organization-specific valid usernames. 

The targeting appears indiscriminate and does not focus on any particular region or industry.

The traffic sources are commonly proxy services, including but not limited to those listed below:-

  • TOR   
  • VPN Gate  
  • IPIDEA Proxy  
  • BigMama Proxy  
  • Space Proxies  
  • Nexus Proxy  
  • Proxy Rack

The given proxy services are employed as non-exclusive sources of traffic, whereas the attackers may use other ones. 

Talos has blacklisted known associated IP addresses due to an enormous traffic surge, although source IPs will probably be changed. 

Mitigation steps vary depending on the affected VPN solution, as these brute-force attacks aim at different types of VPN, web authentication portals, and SSH services.

Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP.


[ad_2]
Source link

Unfazed by Yet Another Critical Firewall Vulnerability (CVE-2024-3400)

0
[ad_1]

Las Vegas, United States, April 17th, 2024, CyberNewsWire

Zero Knowledge Networking vendor shrugs off firewall flaw

In the wake of the recent disclosure of a critical vulnerability (CVE-2024-3400) affecting a leading firewall solution, Xiid Corporation reminds organizations that Xiid SealedTunnel customers remain secure. This latest vulnerability, currently unpatched and rated 10/10 on the CVSS (Common Vulnerability Scoring System), highlights the limitations of traditional security approaches.

Xiid SealedTunnel, the world’s first and only Zero Knowledge Networking (ZKN) solution, goes beyond Zero Trust architecture. Unlike today’s firewalls susceptible to zero-day exploits because of their break-and-inspect approach and the inevitable use of “smart” detection techniques that can and do fail, SealedTunnel is inherently resilient by design.

“This is a great example of why complex firewalls become their own security risk. Keep your firewalls simple, and just have them block all inbound access,” said Josh Herr, Head of Deployment and Integration at Xiid Corp. “Xiid SealedTunnel takes a fundamentally different approach. Our ZKN architecture ensures that data remains completely private and never exposed, even in the face of unknown threats.”

Xiid’s ZKN technology leverages the power of Zero Knowledge Proofs, allowing users to verify access rights without ever revealing sensitive information. This eliminates attack surfaces and renders data unreadable to unauthorized parties, even if a network breach occurs.

About Xiid Corporation

Xiid Corporation is a leading cybersecurity provider specializing in Zero Knowledge Networking solutions. Xiid’s flagship product, SealedTunnel, empowers organizations to achieve unparalleled security and privacy through a revolutionary approach that goes beyond traditional firewalls and zero-trust models. www.xiid.com

Contact

CEO
Steve Visconti
Xiid Corporation
[email protected]
7753382174


[ad_2]
Source link