Thousands Of Internet-Exposed Ivanti VPN Appliances Vulnerable

0
[ad_1]

In a recent cybersecurity revelation, Ivanti, a leading provider of enterprise-grade secure access solutions, has been found to have significant vulnerabilities in its VPN appliances.

The most critical of these, identified as CVE-2024-21894, is a heap overflow vulnerability that could potentially allow remote code execution (RCE) by unauthenticated attackers.

This vulnerability, along with others, poses a severe risk to thousands of internet-exposed Ivanti Connect Secure and Ivanti Policy Secure Gateways.

The discovery was detailed in an advisory published on the Ivanti Community forums, which outlines the specifics of the vulnerabilities and the affected products.

Shadowserver said that approximately 16,500 instances of Ivanti Connect Secure appliances are likely vulnerable worldwide, with around 4,600 located within the United States.

This widespread exposure raises significant concerns for organizations relying on Ivanti’s VPN solutions for remote access and secure connectivity.

Remote Code Execution

CVE-2024-21894 is particularly alarming due to its potential for remote code execution, a type of attack that allows an attacker to run arbitrary code on the affected system.

This could enable unauthorized access to sensitive information, disruption of critical services, and further exploitation of network resources.

The advisory also mentions additional vulnerabilities, including CVE-2024-22052 (a null pointer dereference issue), CVE-2024-22053 (another heap overflow vulnerability), and CVE-2024-22023 (an XML entity expansion or XXE vulnerability), each contributing to the overall risk landscape.

Ivanti has acknowledged the severity of these vulnerabilities and is urging customers to apply the provided patches and mitigations immediately.

The company has released updates and detailed guidance on how to secure affected appliances against potential exploitation.

It is crucial for organizations using Ivanti’s VPN solutions to review their security posture and ensure that all necessary measures are in place to protect against these vulnerabilities.

The implications of these vulnerabilities are far-reaching, affecting not only the security of the organizations directly using Ivanti’s products but also the privacy and integrity of the data and systems they safeguard.

In an era where remote access solutions are more critical than ever, the discovery of such vulnerabilities underscores the importance of continuous vigilance and proactive security practices.

As the cybersecurity community continues to monitor and respond to these developments, the situation serves as a reminder of the ever-present challenges in securing complex IT environments.

Organizations are encouraged to stay informed about the latest security advisories and to prioritize the protection of their digital assets against emerging threats.

Secure your emails in a heartbeat! To find your ideal email security vendor, Take a Free 30-Second Assessment.


[ad_2]
Source link

Quick Share adopts new Material Design 3 animation

0
[ad_1]

Since its launch in 2014, Google has consistently updated its Material Design guidelines. With the introduction of Material Design 3, app developers are advised follow the new standard for UI elements. Although the adoption of these guidelines, even within Google’s own apps and Android system components, can be slow. Now, recent reports show that Quick Share (formerly known as Nearby Share) has started incorporating Material Design 3 progress bars, indicating a wider implementation of the new design philosophy.

Evolution of Material Design

Google introduced Material Design 3 in 2021 to enhance and streamline the design language for a seamless user experience. Since the launch, Google has been consistently enhancing design components to meet the Material Design 3 criteria. Recently, the focus has shifted to improving sliders and progress bars, crucial for user engagement and response.

Google’s approach to progress bars

The new progress bars in Material Design 3 have rounded corner segments and an endpoint indicator. While most Android app developers are slow to adopt these changes, Google’s own apps like Photos and the Play Store have already implemented the updated design elements.

Quick share new material design 3 animation
Image credit: Android Police

Quick Share embraces the Material Design 3

Quick Share is now using the Material Design 3, with progress bars clearly visible during file transfers. The UI now has an indeterminate circular progress bar for “Connecting” and a determinate progress bar for transfer completion status.

Material Design 3 is not limited to Android, it has the potential to expand to other platforms. With the recent release of a desktop client for Quick Share, users are looking forward to a unified design experience on all devices. Google is constantly improving its design language, so users can look forward to more enhancements and standardizations throughout its ecosystem.

Global rollout and implications

Surprisingly, the addition of the Material Design 3 progress bars in Quick Share seems to be enabled by a server-side switch, allowing for a smooth transition without the need for a recent app update. According to the source, the design change is being implemented globally, seen in countries like India and Germany. Although Google aims for improved user experience with Quick Share aligned to the Material Design 3 standards, no specific timeline given.


[ad_2]
Source link

Samsung to get $6 billion US subsidy for chip investment

0
[ad_1]

Samsung will reportedly receive more than $6 billion in subsidies and grants from the US government to expand chip production in the country. In return, the company will invest over $44 billion to construct two manufacturing plants, an advanced packaging facility, and a research and development center. One of the factories is already under construction and is expected to be operational by the end of this year.

US government to offer Samsung $6 billion in chip subsidies

The US government’s CHIPS and Science Act is proving a massive hit. As part of this act, the Biden administration has set aside a $52.7 billion fund to bolster the domestic semiconductor industry, including $39 billion in direct grants to companies for expanding their chip facilities. TSMC, which gets a $6.6 billion subsidy, has already agreed to increase its investment by $25 billion to $65 billion. It will add a third chip factory to its Arizona site by 2030.

Intel also intends to invest more than $100 billion in the American chip industry over the next five years, expanding production in its existing facilities in Arizona. The US government will award it with $8.5 billion in subsidies and $11 billion in loans. Samsung will get the third-biggest amount under the new act. According to a Reuters report, the Korean firm was also offered loans but it does not plan to take any loans.

Samsung already has a chip factory in Austin, Texas. In 2021, it announced plans to construct a new factory in Taylor, Texas. The project was initially estimated to cost $17 billion. However, various market conditions such as inflation have added to the cost. The company may end up spending well over $20 billion on the new factory, which it hopes to be operational later this year. The facility will be used to produce advanced semiconductor chips.

Samsung’s third chip factory in the US will also be located in Taylor. Early estimates have put its cost at around $20 billion. The packaging facility will cost the company $4 billion. Its new R&D center may span across the two factories. Samsung will also reportedly invest some amount in another undisclosed location, though it may not be significant. The total investment will reach $44 billion, more than double what it originally intended to invest.

An official announcement may come next week

Samsung will reportedly announce this expansion project next week, probably on Monday, April 15. Commerce Department Secretary Gina Raimondo will likely unveil the government’s subsidies and grants for the company on the same day, capping off a string of major grants over the past few weeks. Texas Governor Greg Abbott may attend the event.


[ad_2]
Source link

Android Auto now reads a message twice before sending it (bug?)

0
[ad_1]

Android Auto and other hands-free services make driving and interacting with your phone as safe as possible. And these apps often get updated with new features to make your drive even more convenient. Or at least, that’s usually the case. However, 9to5Google now reports Android Auto has gotten a… rather peculiar update (or bug?) recently.

Android Auto now reads a message twice before it sends it


Usually, if you want to send a message using voice with Android Auto, the process is quite simple. After you’ve summoned the Assistant, you say who the message is for and you dictate the message’s content. Google Assistant will then read out the message for you and after you confirm it, it is sent.

However, some users have posted on Reddit that this behavior has now changed. The change is – while Assistant says it’s sending the message, it reads it out loud once again. This second reading of the message doesn’t seem to really serve a purpose though.

So far, there’s no way to change this setting (if it is a setting at all). As for replies, the usual behavior remains so far: the Assistant reads the message, then you can choose if you want to send a message in reply. Then, you hear it out once before it’s sent to confirm.

For some users, Assistant is also disabling dictation too early, but it seems this issue isn’t as widespread as the aforementioned one.

It isn’t clear yet whether this is a bug or intended behavior. Whatever it is though, it doesn’t really add usability, just a couple more seconds to the process (which could be frustrating for some). When we know more, we’ll let you know!


[ad_2]
Source link

Attackers Gain Access to File Servers

0
[ad_1]

Targus International, LLC and its affiliates fell victim to a sophisticated cyberattack.

The company, an indirect subsidiary of B. Riley Financial, Inc., announced that an unauthorized entity breached its file systems, prompting an immediate and robust response to mitigate the damage.

Upon detecting the intrusion, Targus wasted no time mobilizing its incident response team.

With the aid of external cybersecurity experts, the company embarked on a thorough investigation to understand the scope and impact of the breach.

Efforts to contain the incident temporarily halted Targus’ business operations, highlighting the severity of the attack and the company’s commitment to security.

Document
Run Free ThreatScan on Your Mailbox

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

Recovery and Impact Assessment

Targus has since managed to contain the breach and is currently in the process of recovering its systems.

The company remains vigilant, with ongoing investigations to address all vulnerabilities.

Despite the temporary disruption, Targus and B. Riley Financial, Inc. are confident that the incident will not have a material impact on their financial health or operational results, as reported by the US Securities and Exchange Commission.

Regulatory Compliance and Law Enforcement Collaboration

Targus has notified the relevant regulatory authorities about the breach, which aligns with its commitment to transparency and legal compliance.

The company also cooperates with law enforcement agencies to trace the perpetrators and prevent future incidents.

This collaborative approach highlights Targus’ dedication to safeguarding its stakeholders’ interests.

Targus’ announcement includes forward-looking statements that caution stakeholders about risks and uncertainties.

These statements reflect the company’s current expectations based on the information available at the time.

However, they are subject to change, and the company commits to updating the public as new information becomes available.

The cyberattack on Targus is a stark reminder of the ever-present threats in the digital world.

While the breach has caused temporary disruptions, Targus’ swift response and comprehensive recovery plan demonstrate strength in adversity.

As the company continues to navigate this challenging time, its actions set a precedent for how businesses can effectively respond to and recover from cyber threats.

Secure your emails in a heartbeat! Take Trustifi's free 30-second assessment and get matched with your ideal email security vendor - Try Here


[ad_2]
Source link

35-year long identity theft leads to imprisonment for victim

0
[ad_1]

Sometimes the consequences of a stolen identity exceed anything you could have imagined.

Matthew David Keirans, a 58-year-old former hospital employee has pleaded guilty to assuming another man’s identity since 1988. He was convicted of one count of making a false statement to a National Credit Union Administration insured institution and one count of aggravated identity theft.

The man whose identity he assumed—William Donald Woods—and Keirans worked together in 1988 at a hot dog cart in Albuquerque.

Keirans was wanted for theft, so he used Woods’ identity “in every aspect of his life,” including obtaining employment, insurance and official documents, and even paying taxes under Wood’s name, according to a plea agreement signed by Keirans. He even fathered a child, whose last name is Woods.

In 1990, Keirans obtained a fraudulent Colorado identification card with Woods’ name and birthday. He used the ID to get a job at a fast-food restaurant and to get a Colorado bank account. He bought a car for $600 in 1991, using Wood’s name, with two $300 checks that bounced.

It wasn’t the first time Keirans had committed car theft. When he was 16, he stole a car after running away from his adoptive parents’ home in San Francisco.

In 2012, Keirans fraudulently acquired a copy of Woods’ birth certificate from the state of Kentucky using information he found about Woods’ family on Ancestry.com.

Under the assumed identity, Keirans also worked as a systems architect for the University of Iowa Hospital where he was fired for misconduct related to the identity theft investigation.

Meanwhile, the real William Woods was homeless and living in Los Angeles, when he discovered that someone was using his credit and had accumulated a lot of debt. Woods didn’t want to pay the debt and so went after the account numbers for any accounts he had open so he could close them. He handed a bank employee his real Social Security card and an authentic California Identification card, which matched the information the bank had on file. But because there was a large amount of money in the accounts, the bank employee asked Woods a series of security questions that he was unable to answer.

At that point, the bank employee called Keirans, whose phone number was associated with the accounts. He was able to answer the security questions correctly and stated that no one in California should have access to the accounts.

So, the bank employee called the police and after an investigation, the real Woods was arrested and charged with identity theft and false impersonation, under a misspelling of Keirans’ name: Matthew Kierans.

Because Woods refused to give up his own identity, a judge ruled in February 2020 that he was not mentally competent to stand trial and he was sent to a mental hospital in California, where he received psychotropic medication and other mental health treatment.

For legal reasons, Woods pleaded no contest to the identity theft charges—meaning he accepted the conviction but did not admit guilt—and was sentenced to two years imprisonment with credit for the two years he already served in the county jail and the hospital and was released.

But he didn’t give up his fight for his identity even though the judge ordered him to stop using the name William Woods. He attempted to regain his identity by filing customer disputes with financial organizations to clear his credit report.

It wasn’t until a police detective tested Woods’ biological father’s DNA against Woods’ DNA. Both men had the same birth certificate with the father’s name on it. The DNA test proved Woods was the man’s son. During a follow-up interview Keirans made a mistake and eventually confessed to the prolonged identity theft, according to court documents.

Keirans was indicted on five counts of making a false statement to a National Credit Union Administration insured institution and two counts of aggravated identity theft. He pleaded guilty to one count of each charge, and the other counts were dropped.

A sentence ruling has not yet been scheduled. Keirans is currently in the custody of the US Marshals Service, according to a news release about his plea.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection.


[ad_2]
Source link

HONOR starts rolling out Android 14 with MagicOS 8.0 to global devices

0
[ad_1]

HONOR has started rolling out Android 14 with MagicOS 8.0 to global devices. The rollout seems to have started with the HONOR Magic5 Pro, as it came pre-installed on the Magic6 Pro.

HONOR has started rolling out the global version of Android 14 with MagicOS 8.0

Multiple users from several regions reported that the update is rolling out. They said so via Reddit. The changelog is quite beefy, and you can check it out in its entirety by opening the gallery below.

As you can see, the changelog is split into 7 categories, and the update weighs 3 GB. We’ll talk about some of those changes here, of course. HONOR says that new “smooth animations” are rolling out as part of the update. They should offer a “more natural and comfortable experience”.

The ‘Magic Capsule’ is included in the HONOR Magic5 Pro update

The so-called ‘Magic Capsule’ is also included in the update. It’s basically HONOR equivalent to Apple’s Dynamic Island feature, as the HONOR Magic5 Pro also has a pill-shaped cutout. It’s not centered, but it’s there.

Folders are now more customizable, and a new design is rolling out. The new update also allows for stacking cards of the same size on the home screen. So you can basically stack some widgets on top of each other.

This update also brings ‘Magic Portal’ to the table. It allows you to touch and hold text or images and drag them left or right to trigger Magic Portal in some apps. That way you can share them to other apps.

You can now also double-press the Volume Down button in order to enable Ultra Snapshot or trigger the Flashlight. The Ultra Power Saving mode is also a part of this update, just in case.

‘Parallel Space’ can keep your photos, videos, and apps extra private

The ‘Parallel Space’ has been included too. That is a safe space where you can save your photos, videos, and apps. All that, and much more is included in this update.

Do note that the update is quite hefty, though. So, chances are you’ll want to use a Wi-Fi connection for this update. It all depends on your data plan, of course.


[ad_2]
Source link

WhatsApp for Android working on a feature to notify you if someone mentions you in a status

0
[ad_1]

WhatsApp is regularly working on new features and we get to catch glimpses of unreleased ones or in beta all thanks to WABetaInfo. Now, we’re hearing about a feature that will notify you if you’re mentioned in a WhatsApp status update that you haven’t seen yet.

WhatsApp testing notifications for status mentions


This feature is for the Android version of the popular chat app, and it’s still hidden in the code that WABetaInfo was able to dig out. The new feature isn’t even out to beta testers yet, so it may take a while for it to make it as an official feature. It’s been spotted in the code for version 2.24.8.13, which suggests it’s in the works.

It is not entirely clear how this feature might work. It may be activated if someone mentions your WhatsApp username in a status update you have yet to read. It could also be further developed to allow you to select from whom you’d like to get such notifications.

This will help you stay on top of things you might have otherwise missed in the app. Another similar feature that helps you limit the things you’ve missed on WhatsApp is a visual indicator about missing calls from contacts that the company introduced last year.

As with anything that’s still in development though, we can’t be sure when this feature will become official. Stay tuned!


[ad_2]
Source link

D-Link RCE Vulnerability (CVE-2024-3273) Exploited in Wild

0
[ad_1]

Cybercriminals have actively exploited a critical vulnerability in D-Link Network Attached Storage (NAS) devices globally.

Identified as CVE-2024-3273, this remote code execution (RCE) flaw poses a significant threat to as many as 92,000 devices worldwide.

The exploit allows attackers to execute arbitrary code on vulnerable devices, potentially leading to data theft, device hijacking, and the spread of malware.

The Discovery and Impact

A generic shell script pattern that botnet operators frequently use is involved in the exploit. This script attempts to execute malware across every possible CPU architecture, hoping that at least one attempt will succeed.

The malware, identified as “skid.x86,” is fetched from a remote server and has been analyzed and shared for further scrutiny on VirusTotal, a popular platform for malware analysis.

In response to the discovery, GreyNoise quickly released a tag for tracking attempts to exploit the CVE-2024-3273 vulnerability.

Document
Stop Advanced Phishing Attack With AI

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Stopping 99% of phishing attacks missed by other email security solutions. .

D-Link, the manufacturer of the affected NAS devices, has issued a support announcement regarding the vulnerability.

The company is actively working on addressing the issue and has urged users of the affected devices to stay informed about updates and patches.

D-Link’s commitment to resolving the vulnerability is a critical step in mitigating the exploit’s impact and safeguarding users’ data and devices.

Free Webinarfor DIFR/SOC Teams: Securing the Top 3 SME Cyber Attack Vectors - Register Here.

The Broader Implications

The exploitation of CVE-2024-3273 highlights the constant threat that cybercriminals pose and the significance of effective cybersecurity measures.

It highlights the need for continuous monitoring, timely updates, and the adoption of best practices in cybersecurity.

For users of D-Link NAS devices, it is imperative to follow the company’s guidance and apply any available patches to protect against potential attacks.

The vulnerability was first brought to light by GreyNoise, a cybersecurity firm renowned for its expertise in internet-wide scans and attack analysis.

The active exploitation of the CVE-2024-3273 vulnerability in D-Link NAS devices is a stark reminder of the vulnerabilities within our digital infrastructure.

GreyNoise and D-Link’s swift response exemplifies the importance of vigilance and collaboration in the fight against cyber threats.

As the situation evolves, staying informed and taking proactive measures will be key to ensuring the security of our devices and data.

In a world where cyber threats are constantly evolving, the discovery and mitigation of vulnerabilities like CVE-2024-3273 play a crucial role in maintaining the integrity and security of our digital ecosystem.

Secure your emails in a heartbeat! To find your ideal email security vendor, Take a Free 30-Second Assessment.


[ad_2]
Source link

Samsung to soon fix Galaxy S23’s fingerprint issues on One UI 6.1

0
[ad_1]

Samsung is preparing a fix for the Galaxy S23’s fingerprint issues that cropped up following the One UI 6.1 update. Responding to a user’s complaint on its community forum, a moderator said that the company is aware of the issues and plans to release a new update to fix those. We don’t yet have a timeframe for its release.

An upcoming update will fix the Galaxy S23’s fingerprint issues

Samsung started updating eligible Galaxy devices to One UI 6.1 at the end of March. The Galaxy S23 series picked up the update first, followed by the Galaxy Z Fold 5, Galaxy Z Flip 5, and Galaxy Tab S9 series. While the new One UI version brought plenty of new features and improvements, it introduced a few bugs to the Galaxy S23 trio.

Users reported issues with fingerprint recognition and the touchscreen. Samsung has already confirmed that the Google Discover feed causes the latter issue. The Google app has compatibility problems with One UI 6.1 on the Galaxy S23, Galaxy S23+, and Galaxy S23 Ultra. It is up to Google to fix it, the company said. In the meantime, you can try deleting app data and restarting the phone.

The fingerprint issues, on the other hand, are something Samsung will fix itself. The Korean firm hasn’t revealed the underlying cause of the problem but confirmed that a fix is on the way. It may arrive with the April security update, which has been already pushed to the latest foldables, flagship tablets, and a handful of mid-range devices. The Galaxy S23 series should also get it soon.

The fingerprint icon occasionally disappears after the One UI 6.1 update

The fingerprint issues on the Galaxy S23 series seem to be fairly widespread. Over the past few days, many users have reported problems with fingerprint recognition following the One UI 6.1 update. They reported the issues on Reddit, X, Samsung Community, and other online platforms. The Galaxy S23 FE, which has an optical scanner instead of an ultrasonic scanner, is also affected.

According to user reports, the fingerprint icon occasionally disappears. When that happens, the phone doesn’t recognize fingerprints. They have to lift their finger, wait for the icon to re-appear, and try again. This can be frustrating, to say the least. Thankfully, Samsung has quickly acknowledged it and is preparing a fix. We will let you know when the update arrives. You can also manually check for updates from the Settings app.


[ad_2]
Source link