New Google Search filter might let you find short videos like Reels and YouTube Shorts easier

0
[ad_1]

Google Search is the go-to search engine for almost everything, with around 92% of all searches globally happening there. Whether you’re hunting for news, articles, images, places, or videos, you probably just Google it, right? And now, it seems like the tech giant is trying out another filter to add to the mix alongside Video, Images, News, Shopping, Books, and others.According to tipster and Android researcher AssembleDebug on X, Google is giving a shot at testing a new “Short videos” filter on mobile. It seems that this new filter might showcase short videos from platforms like YouTube Shorts, Instagram, TikTok, Snapchat, and more in the search results.
However, the filter is probably still in the early testing phase, so there’s no guarantee it’ll stick around as a permanent search filter. We’ll just have to wait and see if Google decides to roll with this experiment.The test was also recently spotted by SEO consultant Brodie Clark (via Android Police), who shared additional images of the new Short Videos search filter.

Once chosen, the Short Videos filter displays portrait-orientation content in a convenient two-column layout, such as Shorts from YouTube and videos from TikTok. The filter eliminates the need to add keywords like Reels, Shorts, or TikTok to your search query.

The short video format really took off thanks to apps like Snapchat and TikTok. Instagram Reels and YouTube’s Shorts jumped on the bandwagon soon after. And here’s a fun fact: stats reveal that a whopping 73% of consumers actually prefer short-form videos when looking for products or services. So, it’s not too shocking that Google decided to give this new filter a whirl.

These days, some creators specialize in crafting short-format content exclusively thanks to the format’s popularity, especially when it comes to informative content like tutorials and news snippets. Even LinkedIn is getting in on the action, experimenting with a new short video feed geared toward careers and professionalism.

[ad_2]
Source link

Multiple Cisco Small Business Routers Vulnerable to XSS Attacks

0
[ad_1]

Cisco has alerted its customers about a critical vulnerability affecting several Small Business RV Series Routers models.

This vulnerability, CVE-2024-20362, poses a significant risk, allowing unauthenticated, remote attackers to conduct cross-site scripting (XSS) attacks.

The affected models include the RV016, RV042, RV042G, RV082, RV320, and RV325 routers, widely used in small business environments for secure internet connectivity and VPN access.

The vulnerability stems from insufficient input validation in the web-based management interface of the affected routers.

Attackers can exploit this flaw by convincing users to click on a specially crafted link. This can lead to executing arbitrary script code in the context of the affected interface or the potential leakage of sensitive, browser-based information.

Document
Run Free ThreatScan on Your Mailbox

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

The Common Vulnerabilities and Exposures (CVE) system has assigned this vulnerability the identifier CVE-2024-20362, with a base score of 6.1 on the Common Vulnerability Scoring System (CVSS).

This score reflects a moderate severity level, emphasizing the need for affected users to take immediate action to mitigate the risk.

Affected Products and Mitigation Strategies

The advisory specifies that all software releases for the RV016, RV042, RV042G, RV082, RV320, and RV325 routers are vulnerable.

In contrast, this vulnerability does not affect other models in the Cisco RV Series, such as the RV160, RV260, and RV340 series routers.

Given the absence of software updates to address CVE-2024-20362, Cisco has outlined specific mitigation strategies for affected customers.

Disabling remote management is recommended for the RV320 and RV325 models.

For the RV016, RV042, RV042G, and RV082 models, Cisco advises disabling remote management and blocking access to ports 443 and 60443, which can be achieved through the router’s web-based management interface.

Fixed Software

Cisco has announced that it will not release software updates to address this vulnerability, as the affected routers have entered the end-of-life process.

Customers are encouraged to consult these products’ end-of-sale and end-of-life announcements and consider migrating to newer models that continue receiving security updates and support.

This situation underscores the importance of regular security assessments and the prompt application of mitigations or upgrades to protect against evolving cybersecurity threats.

Customers are advised to regularly review Cisco’s security advisories and consult with the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers to ensure their network infrastructure remains secure and resilient.

Secure your emails in a heartbeat! Take Trustifi free 30-second assessment and get matched with your ideal email security vendor - Try Here


[ad_2]
Source link

Samsung to invest $24 billion in new chip factory in the US

0
[ad_1]

Samsung plans to construct one more semiconductor manufacturing factory in the US, its third in the country. The new facility is planned in Taylor, Texas, where the company is currently building its second facility, The Wall Street Journal has learned. The Korean firm already operates a chip plant in Austin, Texas.

Samsung may double its chip investment in the US

In 2021, Samsung announced a $17 billion investment to construct a chip factory in Taylor. The factory is expected to be operational later this year. The latest estimates suggest the final cost of the facility will be more than $20 billion, potentially reaching $25 billion. The US government will reportedly support the Korean tech giant with federal funding of about $6 billion under the CHIPS and Science Act.

It appears that Samsung plans to use the grants and subsidies to increase its chip manufacturing capacity in the US. According to the WSJ, the planned second round of investment would bring the total to $44 billion, double what it would invest in the under-construction chip plant in Taylor. As we have seen with the current facility, depending on the market conditions, the total amount could increase as the construction proceeds.

Along with a semiconductor manufacturing facility, Samsung plans to construct a facility for advanced packaging and R&D (research and development). The new report says the initial estimated cost of the manufacturing site is $20 billion, while the packaging facility may cost $4 billion. The company will reportedly hold an event in Taylor next Monday, April 15, to announce its broadened investment plans.

It is a huge win for the US government

If Samsung’s plan materializes, it would massively boost the US semiconductor market. The Biden administration has been encouraging foreign chip companies to invest more in the country to expand their production capacity. That is the very purpose of the CHIPS and Science Act, to lure companies with grand, loans, and funding. The Act offers federal funding of $52.7 billion to chip firms, including $39 billion in direct grants.

TSMC, the world’s largest semiconductor foundry, is also building a new factory stateside. It will reportedly get funding of over $5 billion. American chip giant Intel may receive the biggest chunk of this pool, with rumors of over $10 billion in grants and loans and an additional $3.5 billion in grants for the production of military chips. It is unclear if Samsung will get another round of federal funding for its second chip factory in Taylor.


[ad_2]
Source link

TikTok’s US fate still uncertain, but EU politicians love the app

0
[ad_1]

TikTok’s popularity among European politicians rises despite security fears, reads a recent report by Reuters.

And can you blame them? After all, politicians care about votes: and if you want votes, you need young people. If you need young people – you know where this is going, don’t you – you need TikTok, end of story.

The report outlines Simon Harris’ TikTok usage. When he became Ireland’s prime minister-in-waiting in March, he turned to a favored platform of his: TikTok. Ireland’ youngest taoiseach (a local word for “Irish prime minister”) made a “Thank you” video for his 95,000 followers.

Harris is just one of the many European politicians who are embracing TikTok. That’s a trend – European politicians are turning to TikTok, believing that the importance of connecting with younger voters surpasses the alleged security worries.

Germany’s security agencies, for example, have warned against using the app over concerns it could share data with China’s government or be used to influence users.

Similar fears have haunted US lawmakers for years – that’s why less than a month ago, the US House of Representatives voted in favor of a bill that could ban TikTok in the United States.

The goal is ByteDance to sell its interests in the viral short video app, or face a ban in the US. If everything goes to plan (the bill passes and Joe Biden signs it), ByteDance will have a 165-day deadline to divest from TikTok. Should it not pass the control of TikTok to an American-based company, US app stores (like Apple’s, Google’s and Samsung’s) would be prohibited from offering TikTok in the country.

Overseas, the EU’s turn to TikTok isn’t without a cause – European elections draw near and younger votes are needed. Apart from early adopter Harris, who operates a TikTok account since 2021, another notable example is French President Emmanuel Macron, who boasts 4 million followers since joining TikTok in 2020.In Germany, the embrace of TikTok by senior politicians is a newer trend, with Health Minister Karl Lauterbach becoming the country’s first minister to open an account in March. “Revolution at TikTok: it starts today,” he said. Chancellor Olaf Scholz in February also suggested his government open a TikTok account.

The TikTok generation is extremely important for Germany, as 16-year-olds over there can vote in the June European elections.

Also, TikTok is seen as a major news source for younger people.


[ad_2]
Source link

Vedalia APT Group Exploits Oversized LNK Files to Malware

0
[ad_1]

The Vedalia Advanced Persistent Threat (APT) group, also known by its alias Konni, has been distributing malware using an innovative technique involving oversized LNK files.

This method marks an evolution in the group’s operational tactics, aiming to bypass conventional security measures and compromise targeted systems.

Broadcom recently published a blog post stating that the Vedalia APT group has utilized huge LNK files in their latest malware campaign.

Document
Run Free ThreatScan on Your Mailbox

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

Key Highlights of the Campaign

  • Innovative Delivery Mechanism: The Vedalia APT group has ingeniously utilized LNK files with double extensions, effectively masking the malicious .lnk extension.
  • This tactic deceives users into believing the files are harmless, increasing the likelihood of execution.
  • Obscuration through Whitespace: A notable characteristic of these LNK files is the excessive use of whitespace.
  • This technique is designed to hide the malicious command lines embedded within, making detection by security software and analysts more challenging.
  • Bypassing Security Defenses: The embedded command line script within the LNK files is crafted to search for and execute PowerShell commands.
  • This approach is specifically chosen to evade detection mechanisms. It leverages PowerShell’s legitimate system functions to locate and deploy the embedded malicious files and payload.

File-based

  • CL.Downloader!gen20
  • Scr.Mallnk!gen13
  • Trojan.Gen.NPE
  • WS.Malware.1

Implications and Recommendations

The Vedalia APT group’s adoption of oversized LNK files for malware delivery underscores the evolving landscape of cyber threats.

Organizations and individuals are advised to remain vigilant, update their security solutions, and educate users about the risks of opening files from unknown sources.

This campaign by the Vedalia APT group serves as a reminder of the continuous innovation among cyber adversaries.

By staying informed and proactive, organizations can better defend against these sophisticated threats, safeguarding their digital assets and the integrity of their systems.

Secure your emails in a heartbeat! Take Trustifi free 30-second assessment and get matched with your ideal email security vendor - Try Here


[ad_2]
Source link

Next Galaxy S24 Ultra update to fix ‘many camera problems’

0
[ad_1]

A new update is coming to the Galaxy S24 Ultra, and it is expected to fix many camera problems, it seems. This information comes from Ice Universe, one of the best-known tipsters around.

Next Galaxy S24 Ultra update is expected to fix quite a few camera problems

As per usual, he is heavily invested in the works of Samsung, and its devices. He went to X (formerly known as Twitter) to share the news with his followers. He promised this update will fix many camera problems, or at least it’s expected to.

The tipster did delve deeper into it, a bit deeper. He said that the update will bring improved telephoto image quality. On top of that, it will fix inaccurate white balance and “abnormal red color”.

What he doesn’t know is when exactly the update will land. He was not provided with that information. The tipster is hoping that the update will land in April, though. It remains to be seen.

Samsung has plenty of competition this time around

Even with some of the problems it has, the Galaxy S24 Ultra is still one of the best smartphone cameras around. Still, it has plenty of competition, though. Various Chinese smartphone OEMs released camera-centric smartphones which are really difficult to compete with.

The OPPO Find X7 Ultra, Xiaomi 14 Ultra, and Vivo X100 Pro come to mind first, that’s for sure. Those are the phones that will get mentioned in camera debates these days. If you throw the Pixel 8 Pro into the mix, and also the iPhone 15 Pro Max and the OnePlus 12, things become even more interesting.

It is worth noting that Huawei is expected to announce its new flagships in the near future too. The Huawei P70 series is coming, and based on what we’ve heard about the upcoming camera setups, Huawei will also compete, very much so.

All of that makes it hard for Samsung to truly stand out, The company needs to do everything in their power to properly optimize the Galaxy S24 Ultra’s camera output. It seems like that’s exactly what Samsung is trying to do.


[ad_2]
Source link

Multiple CData Flaws Let Attackers Bypass Security Restrictions

0
[ad_1]

A path traversal vulnerability was discovered in the Java versions of multiple CData products when using the embedded Jetty server, allowing remote attackers to potentially access sensitive information and perform limited actions on the system. 

The vulnerability arises from the interplay between how the embedded Jetty server and CData servlets handle incoming requests, creating a path traversal issue where an attacker can manipulate the path to access unintended directories on the system.

An attacker can exploit a path traversal vulnerability in CData Sync versions before 23.4.8843, which stems from unintended Jetty behavior when processing servlet mappings and security constraints in the web.xml file.

CData Vulnerabilities Bypass Security Restrictions

Jetty’s handling of backslashes (\) in URIs differs from other servers, allowing attackers to bypass restrictions, while the lack of proper session checks on certain endpoints makes it possible to perform unauthorized actions after exploiting the path traversal.

Document
Stop Advanced Phishing Attack With AI

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Stopping 99% of phishing attacks missed by other email security solutions. .

CData API Server versions prior to 23.4.8844 for Java with the embedded Jetty server are vulnerable to a path traversal attack (CVE-2024-31848), which allows unauthenticated remote attackers to exploit improper path validation to access arbitrary files on the system.  

It could potentially grant complete administrative control of the application, as the Common Vulnerability Scoring System (CVSS) assigns a score of 9.8, reflecting the critical severity of this exploit. 

CData Connect, a Java application running on the embedded Jetty server prior to version 23.4.8846, is vulnerable to a critical path traversal attack (CVE-2024-31849). 

The weakness allows unauthenticated, remote attackers to exploit the application’s directory traversal functionality to gain complete administrative access.

With a CVSS base score of 9.8, vulnerability poses a serious risk and immediate patching is recommended. 

Regular Request

When using the embedded Jetty server, CData Arc, a Java application with versions prior to 23.4.8839, is vulnerable to a path traversal attack that a remote, unauthenticated attacker can use to access sensitive data and potentially carry out limited actions on the system.  

According to Tenable, the attacker can manipulate the path to access files outside the intended directory structure, expose sensitive data, or allow unauthorized modifications. Z

With Path Traversal

CData Sync, a data integration software, is vulnerable to a path traversal attack (CVE-2024-31851) when using the embedded Jetty server in its Java version prior to 23.4.8843. 

A remote, unauthenticated attacker could take advantage of this flaw to access sensitive data and potentially carry out limited actions on the system.

The Common Vulnerability Scoring System (CVSS) assigns a base score of 8.6 to this vulnerability, reflecting its high severity. 

The security vulnerability was found in CData products, where accessing “/src/getSettings.rsb” could expose sensitive data, which was disclosed to CData on March 4th, 2024, and acknowledged two days later, while CData released updates to address this vulnerability on March 25th, 2024, and a public advisory was published on April 5th, 2024.

Secure your emails in a heartbeat! Take Trustifi free 30-second assessment and get matched with your ideal email security vendor - Try Here

[ad_2]
Source link

Snapdragon X Plus leak hints at an affordable Windows processor

0
[ad_1]

Qualcomm is readying a new processor for Windows laptops, a fresh leak has revealed. Called Snapdragon X Plus, it will be a more affordable version of the Snapdragon X Elite launched in October 2023. The company is testing two variants of the new chip likely with plans to release it later this year.

Qualcomm is testing the Snapdragon X Plus with an integrated 5G modem

Six months into its launch, the Snapdragon X Elite has yet to power any Windows machine. However, it may not be long before we see devices with the powerful ARM-based CPU from Qualcomm. The company has positioned it at the top tier of the Windows world—the same level as Apple’s M series chips for MacBooks. Early impressions are that it beats Apple’s latest M3 chips and Intel’s Core Ultra CPUs in power and performance.

As we wait for Windows PCs powered by the Snapdragon X Elite, Qualcomm appears to be working on a slightly less powerful version of the chip for more affordable devices. A few weeks ago, the German publication WinFuture discovered “concrete evidence” of four variants of the Snapdragon X Plus in Qualcomm’s pipeline. It has just learned that the company has been internally testing two of those for several months.

The two chips have internal identification numbers X1P44100 and X1P46100. The prefix “X1P” strongly indicates the “Snapdragon X Plus” branding (the Elite version is X1E). Qualcomm has been testing the chips with an integrated Snapdragon X65 5G modem for cellular connectivity. Unfortunately, no other information is available. Not even anything confirming that the chip is inferior to the Elite version. It’s an assumption based on the name.

That said, the publication speculates that the base of the Snapdragon X Plus may be the same chip as the Elite, which also has the same integrated 5G modem. Qualcomm could make it a deca-core (10 CPU cores) setup instead of 12 cores, though. It also planned an octa-core (8 cores) version but appears to have dropped the idea. The X series uses custom Oryon CPU cores developed by Nuvia, which Qualcomm acquired in 2021.

The new chip may debut later this year

Qualcomm’s Snapdragon X Plus chipset for Windows laptops may debut later this year. The company may unveil it at its next Snapdragon Summit in October (the Elite debuted at the same event last year). The event will also bring its next-gen smartphone processor, the Snapdragon 8 Gen 4. It will be Qualcomm’s first 3nm chip and will power the next generation of Android flagships, including Samsung’s Galaxy S25 Ultra.


[ad_2]
Source link

PhoneArena’s best iPhone and Android apps of the week

0
[ad_1]

Duolingo is like having a language-learning buddy right in your pocket. This app lets you dive into learning a new language at your own pace, whenever and wherever you want. Imagine having a fun and interactive way to pick up Spanish, French, or any other language you’ve been itching to learn.Instead of boring textbooks or stuffy classrooms, Duolingo spices things up with games and challenges. You’ll tackle bite-sized lessons that feel more like playing than studying. It’s all about matching words, completing sentences, and even speaking out loud to practice your pronunciation.

You can choose from a bunch of different languages, from the super popular ones to the more niche ones, such as Japanese, Hebrew, and Arabic, which you might not find elsewhere. Plus, you can track your progress, earn rewards, and even compete with friends to keep things interesting. The basic version is free, but if you want to dig deep, there’s a subscription called Super Duolingo that offers an ad-free experience with the option to review your mistakes.

Memrise

Platform: iOS, Android
Price: Free with in-app purchases
Get Memrise for iOS here
Get Memrise for Android here

Memrise is another language-learning app that’s gained popularity for its unique approach to teaching languages. Similar to Duolingo, Memrise offers courses in various languages, but it stands out with its focus on vocabulary acquisition through mnemonic techniques.The app utilizes spaced repetition and mnemonic devices to help users remember words and phrases more effectively. Mnemonics are memory aids, like visual imagery or associations with familiar words, that make it easier to recall new vocabulary. Memrise incorporates these techniques into its lessons, making language learning more engaging and memorable.

Memrise also offers features like interactive games, listening exercises, and pronunciation practice to enhance the learning process. Like Duolingo, it’s designed to be convenient and accessible, allowing users to learn at their own pace, anytime and anywhere.

LingoDeer


LingoDeer is yet another language-learning app that offers interactive lessons in various languages, but primarily focusing on Asian languages such as Japanese, Korean, Chinese, and Vietnamese.

What sets LingoDeer apart is its structured approach to language learning, which is tailored specifically to the grammar and vocabulary of each language it teaches. The app provides step-by-step lessons that cover essential language skills, including reading, writing, listening, and speaking.

One of the key features of LingoDeer is its clear explanations of grammar points and language concepts, which are presented in a way that’s easy to understand and remember. The app also incorporates a variety of interactive exercises and quizzes to reinforce learning and help users practice what they’ve learned.

The basic version is free, but you can buy different tiers of premium access, starting from a monthly subscription for $14.99 and going all the way up to a lifetime membership for $299 (often slashed down to $159.99).

Babbel


Babbel is one of the oldest language-learning tools on the internet, and it takes its name from the Babbel fish in the popular science-fiction book “The Hitchhiker’s Guide to the Galaxy.” The app does what other similar apps do but focuses more on the practical side of things, teaching you language skills that you can use in real-life situations.

That’s not to say that Babbel doesn’t offer a complete set of language learning tools, such as vocabulary, grammar, pronunciation, and cultural insights. It’s just that if you need to learn a couple of useful phrases for an upcoming short trip abroad, Babbel might be the right one for you.

Babbel also utilizes speech recognition technology to help you practice your pronunciation and ensure you’re speaking accurately, so you don’t make locals laugh on that upcoming trip. Plus, the app’s personalized review feature helps reinforce what you’ve learned, so it sticks with you for the long term.

Just like the other apps on that list, Babbel is free with some in-app purchases and subscriptions, starting at $8.99/mo.

Beelinguapp


Tired of the same repetitive language learning apps that use gamification and other similar techniques to make you come back and do your lessons? Prepare for something completely different! Beelinguapp is a unique language-learning app that offers an innovative approach to learning languages through reading. Imagine Beelinguapp as your cozy reading nook, where you can dive into captivating stories and articles while effortlessly picking up a new language.

Here’s the magic: Beelinguapp lets you choose from a library of texts in different languages, so you can find something that piques your interest, whether it’s a thrilling story or a fascinating article. You get to read these texts side by side, with the original language on one side and a translation in your native language on the other.

Additionally, Beelinguapp offers audio recordings of the texts, allowing users to listen to native speakers read the text aloud. This feature helps improve pronunciation and listening comprehension skills. It’s one of the more organic ways of learning a language, and for some people, it might work better than puzzles, games, and achievements.

Bonus: Brilliant


Learning a language is fun and all, but what about learning something different? How about delving into the deep and complex world of quantum physics or mathematics if you feel up for the challenge? There’s no need to go back to Uni and start a major in astronomy. There’s an app for that, and it’s called Brilliant.

Actually, Brilliant is a whole learning platform with a strong focus on math, science, and computer science, but before you click away, this platform is designed to explain complex subjects as intuitively as possible. It also provides learning at different levels, starting with beginner and going all the way up to expert, and it also features a range of interactive puzzles, quizzes, and challenges that encourage users to think creatively and apply their knowledge to real-world scenarios.

The downside is that the app requires a subscription. There’s a trial version that offers a glimpse at what you might achieve with the Problems of the Week feature, but if you want to get access to all the courses at a deeper level, you need to get Brilliant Premium.

[ad_2]
Source link

A week in security (April 1 – April 7)

0
[ad_1]

A list of topics we covered in the week of April 1 to April 7 of 2024

Last week on Malwarebytes Labs:

Stay safe!


Our business solutions remove all remnants of ransomware and prevent you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.


[ad_2]
Source link