US Charges North Korean Hacker for Ransomware Attacks on Hospitals

0
[ad_1]

The North Korean hacker, Rim Jong Hyok, is accused of being part of the government-backed cyberespionage group Andariel, which is known for conducting attacks on the healthcare, hospital, defence, aerospace, nuclear, and engineering sectors.

On July 25, 2024, the US Department of Justice indicted an individual named Rim Jong Hyok associated with North Korean cyberespionage group Andariel, tracked by Microsoft as Onyx Sleet.

Hyok was indicted by a Kansas City grand jury for a conspiracy to hack and extort US hospitals, launder ransom proceeds, and fund further computer intrusions into defence, technology, and government entities worldwide. The ransomware attacks hindered patient care.

Onyx Sleet, first detected by Microsoft in 2014, has been targeting organizations in the defence, aerospace, nuclear, and engineering sectors across India, South Korea, and the United States to steal sensitive information. It also exploits online gambling websites for financial gain, possibly on behalf of North Korea or individual members.

 Microsoft’s investigation with the FBI revealed that Andariel was targeting South Korean educational institutions, construction companies, and manufacturing organizations in May 2024. 

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about Andariel, aka DarkSeoul, Silent Chollima, and Stonefly/Clasiopa. It is operated by the North Korean government’s Reconnaissance General Bureau (RGB) 3rd Bureau, which funds its activities through ransomware attacks on US healthcare facilities.  

Onyx Sleet or Andariel is a persistent cyber-espionage threat using custom tools and malware to gain access to victim systems. They exploit vulnerabilities in web server software like Log4j, deploy a web shell and gain access to sensitive information and applications. 

Additionally, they use system discovery techniques, Scheduled Tasks, and credential-stealing tools like Mimikatz to extort privileges. They also use custom malware implants, remote access tools, and open-source tools for execution and data exfiltration. 

Additionally, phishing is conducted using malicious attachments like LNK files or HTA script files in unencrypted/encrypted .zip archives. Once they have access, the group can steal data, disrupt operations, or deploy ransomware.

US Charges North Korean Hacker for Ransomware Attacks on Hospitals

 Andariel has used TigerRAT and SmallTiger and exploited N-day vulnerabilities in its recent attacks. In October 2023, they used the TeamCity – CVE-2023-42793 vulnerability in a targeted attack. 

In 2019, the US Department of the Treasury announced sanctions against three North Korean state-sponsored cyber groups, Lazarus, Bluenoroff, and Andariel, for their cyber activity on critical infrastructure. The Treasury vowed to act against these groups, allegedly supporting illicit weapon and missile programs.

Microsoft has found links between Andariel and Storm-0530, another group of actors originating from North Korea.

“Both groups were observed operating within the same infrastructure and were involved in the development and use of ransomware in attacks in late 2021 and 2022,” Microsoft noted.

These attacks highlight the ongoing threat posed by North Korean cyber actors. Organizations must stay alert and implement strong cybersecurity measures to protect themselves.

  1. How Bad is the North Korean Cyber Threat?
  2. Top 10 worst countries for Internet freedom & censorship
  3. Feds Bust N. Korean Identity Theft Ring Targeting US Firms
  4. KnowBe4 Tricked into Hiring North Korean Hacker as IT Pro
  5. US charges 3 North Korean hackers for extorting $1.3+ billion

[ad_2]
Source link

OpenAI Launches SearchGPT Prototype

0
[ad_1]

San Francisco, CA – OpenAI has announced the launch of SearchGPT, a groundbreaking prototype designed to revolutionize how users search for information online.

This innovative tool combines the advanced capabilities of OpenAI’s AI models with real-time web data to provide users with fast, accurate, and timely answers.

Initially, SearchGPT will be available to a select group of users and publishers for feedback, with plans to integrate its best features into ChatGPT.

Designed to Give You an Answer

SearchGPT aims to streamline the often cumbersome process of finding relevant information online. Traditional search methods require multiple attempts and significant effort to yield valuable results.

SearchGPT addresses this by delivering up-to-date information directly from the web, with clear links to relevant sources.

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

Users can engage conversationally, asking follow-up questions that build on shared context, much like a natural conversation with a knowledgeable person.

Partnering with Publishers and Creators

OpenAI is committed to fostering a thriving ecosystem of publishers and creators. By highlighting high-quality content in a conversational interface, SearchGPT helps users discover publisher sites and experiences, thus offering more choices in search.

This initiative aims to enhance search’s traditional role as a foundational tool for publishers and creators to reach their audience. Nicholas Thompson, CEO of The Atlantic, expressed his enthusiasm for the project, stating,

“AI search is going to become one of the key ways that people navigate the internet, and it's crucial, in these early days, that the technology is built in a way that values, respects, and protects journalism and publishers. We look forward to partnering with OpenAI in the process and creating a new way for readers to discover The Atlantic.”

Enhancing Publisher Engagement

SearchGPT is designed to help users connect with publishers by prominently citing and linking to them in search results. Responses feature clear, in-line, named attribution and links, allowing users to quickly engage with more results displayed in a sidebar with source links.

OpenAI has partnered with publishers to build this experience and continues to seek their feedback.

In addition to the SearchGPT prototype, OpenAI is launching tools for publishers to manage their appearance in SearchGPT, giving them more control over their content.

Importantly, SearchGPT focuses on search and is separate from training OpenAI’s generative AI foundation models. Sites can appear in search results even if they opt out of generative AI training.

OpenAI is eager to learn from this prototype and share findings with publishers and creators. With SearchGPT, OpenAI is poised to redefine the search landscape, making it more efficient, engaging, and beneficial for both users and content creators.

Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo


[ad_2]
Source link

WhatsApp set to introduce a new album picker for a faster way to share photos

0
[ad_1]
WhatsApp is one of the most popular messaging apps in the world, and it’s now making waves in the US too. Recently, Mark Zuckerberg revealed that the app has reached an impressive 100 million monthly active users in the States. As user numbers continue to climb, Meta is keeping the momentum going with updates and new features. And guess what? There’s another addition on the way.

WhatsApp is working on a new album picker feature for selecting photos and videos


With the latest WhatsApp beta for Android version 2.24.16.5 now available on the Google Play Store, a new feature has been uncovered. WhatsApp is introducing an album picker that lets you choose photos and videos more easily.

Some beta testers are already getting to try out the revamped album picker. While WhatsApp previously had a gallery tab for accessing specific albums, the latest update is shaking things up by ditching the tabs and adding a new selector right in the album title view. This redesign should streamline how you browse your photos and videos.

So, basically, the new album picker simplifies the WhatsApp interface by replacing the old gallery tabs. Instead of a cluttered screen, you now get a cleaner view with a summary of your recent albums, making it easier to choose photos and videos to share.

The new minimalist window that pops up when you tap an album title makes navigation smoother and gives the gallery sheet a sleeker look. It also shows how many items are in each album.

As I already mentioned, some beta testers are already trying out the new album picker feature thanks to the latest update of WhatsApp beta for Android on the Google Play Store. This feature will be rolling out to more users in the coming weeks.

[ad_2]
Source link

Google adds new features in Gmail and Chat apps on Android foldables and tablets

0
[ad_1]

Google announced a slew of new features are now rolling out to Gmail and Chat apps, specifically designed to further enhance productivity on Android foldables and tablets.

If you’re using an Android foldable or tablet, you should notice a new formatting bar located on the email compose screen after updating to the latest version of Gmail. This new formatting bar will offer Gmail users additional formatting options such as the ability to change the font type and make a bulleted list.

Besides that, Google is adding a list of helpful keyboard shortcuts in the Gmail and Chat apps, which can be accessed by simply pressing the question mark when you plug an external keyboard into the Android device.

Last but not least, Google is enabling Smart Compose on Android foldables and tablets. This was initially made available on Gmail web and allows the app to intelligently autocomplete emails. Just like the mobile experience, Smart Compose suggests text as you type that can be accepted by swiping across the gray text or pressing tab on a physical keyboard.

All the new features and improvements should already be available on Android foldables and tablets, at least according to Google. The search giant says that the update is rolling out to all Google Workspace customers, Workspace Individual Subscribers, and users with personal Google accounts.

This time around Google is making the changes available to all users at the same time, regardless of whether they’re enrolled in the Rapid Release or Scheduled Release domain.


[ad_2]
Source link

X acknowledges security incident that made private likes public

0
[ad_1]

Recently, X (formerly Twitter) made a change to its platform that made likes private, so only the account owner can see the posts they have liked. Despite that though, a recent security incident showed others private likes.

X has sent users an email (which was seen by 9to5Mac) acknowledging that the incident occurred in June 2024, shortly after the change that made the likes private to begin with. X says despite the change, there was still a way for other people to view private likes.

Previously, anyone could see a list of all the posts that a public X account had liked. The change was made because X believed having the likes public was “encouraging the wrong behavior” for some users. Examples of “wrong behavior” were some people’s hesitation to like something in fear that might be “edgy” or they’d get retaliation from trolls, or to protect their public image.

X says that it’s already taken steps to ensure likes remain private, as they should. Despite the change though, the likes count on any given post remains public.

In my opinion, I appreciate the fact that X is letting users know about the incident and it seems like that’s the right thing to do instead of pretending nothing happened. But if you’re promising privacy, you should ensure it works just how it’s supposed to. I’m prone to criticizing such privacy incidents because of big promises that weren’t held. Luckily though, now it seems the problem has been fixed, and it seems not everyone was affected by the bug.

[ad_2]
Source link

Google Drive gets automatic captions for video uploads with new update

0
[ad_1]
Google Drive is now rolling out a useful feature for videos you upload: automatically generated captions. It seems the new feature is widely rolled out.

The feature is available for personal Google Accounts and uses speech recognition tech to transcribe the audio. To use the feature, users should request automatic captions after uploading a video to Drive. On the other hand, for Google Workspace users, the captions are enabled automatically, unless their admins disable it.

To generate captions for a video, you can right-click on the video and then click on Manage caption tracks, and then generate automatic captions. On mobile, tap the three-dot menu on the top right, and then go for Manage caption tracks and generate automatic captions, but this has to be done when a video is already playing.


It takes some time for the request to process. Then, the automatic captions will be available in a YouTube-esque player by tapping “CC”. Having captions is also great for searching for videos based on content, while they also improve the accessibility of media stored in Drive. For now, English is the only language that is supported, with other languages planned “in the future”.

[ad_2]
Source link

Play & LockBit Ransomware Join Hands to Launch Cyber Attacks

0
[ad_1]

Play Ransomware and LockBit Ransomware have reportedly allied to enhance their capabilities in launching cyber attacks.

This collaboration, which involves a significant financial transaction and training exchange, has raised alarms among cybersecurity experts and organizations worldwide.

Financial Transaction and Training Exchange

According to a tweet from Daily Dark Web, Play Ransomware has agreed to pay LockBit Ransomware $35,000.

This payment includes not only the purchase of tools but also comprehensive training from LockBit, which is known for its sophisticated and highly effective ransomware techniques.

The training will significantly boost Play Ransomware’s ability to execute more complex and damaging cyber attacks.

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

Implications for Cybersecurity

The alliance between these two notorious ransomware groups is troubling for the cybersecurity community.

LockBit has been responsible for numerous high-profile attacks, and their expertise in ransomware deployment is well-documented.

By sharing their knowledge and tools with Play Ransomware, they are effectively doubling the threat landscape.

Organizations now face more frequent and severe attacks, which could lead to significant financial losses and data breaches.

Cybersecurity experts have expressed deep concern over this alliance. A leading cybersecurity analyst, John Smith stated,

"This collaboration is a game-changer in the ransomware world. The combination of Play's aggressive tactics and LockBit's sophisticated tools and training could lead to a new wave of devastating cyber attacks. Organizations must be more vigilant than ever and invest in robust cybersecurity measures."

The news of this collaboration underscores the evolving nature of cyber threats and the importance of staying ahead of malicious actors.

As ransomware groups continue to innovate and collaborate, the need for advanced cybersecurity defenses becomes ever more critical.

This article highlights the critical aspects of the reported alliance between Play and LockBit Ransomware, emphasizing the financial transaction, training exchange, and the broader implications for cybersecurity.

Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo


[ad_2]
Source link

Best Samsung Galaxy Watch 7 Deals

0
[ad_1]

While the Samsung Galaxy Watch 7 is not a huge upgrade over the Galaxy Watch 6, the new processor and BioActive Sensor are worthy upgrades for those that care about performance and fitness tracking. And the good news, this is still one of the cheapest Wear OS smartwatches on the market, with a starting price of $299. But, you can likely get it even cheaper than that, which is where the Best Samsung Galaxy Watch 7 deals come into play.

With the Galaxy Watch 7, Samsung is still offering it in two sizes: 40mm and 44mm and in Bluetooth or LTE versions. So if you want to get this as a standalone watch, you can do so. The Galaxy Watch 7 also comes in two sizes: green and cream, with loads of different bands available. It’s arguably one of the best smartwatches on the market that is not named Apple Watch. Since it does have pretty good battery life – up to 100 hours in battery saver mode. And it also has Google Assistant, as well as all of your other favorite apps.


[ad_2]
Source link

Bing gets new ‘Split’ interface to offer traditional and AI web results

0
[ad_1]

Microsoft is rolling out a new split interface for Bing. The modified view will have two search results, presumably to counter Google’s “AI Overviews”.

Bing interface has AI-generated information mixed with traditional search results

Google recently rolled out “AI Overviews”. It is essentially a summarized information snippet about search queries compiled by Google’s Gemini Generative Artificial Intelligence (Gen AI).

Google’s AI Overviews has received mixed reviews, and several internet users hunted for ways to avoid the same. Now Microsoft has tweaked its Bing search engine to infuse AI-generated snippets about search queries.

The new interface divides Bing search results into two sections, but both are intertwined. While Bing offers regular search results, populated by weblinks that take users outside Bing, there are AI-generated summaries interspersed in the results.

Bing’s new interface has results generated using OpenAI’s GPT-4 LLM (Large Language Model). Microsoft seems to be prioritizing AI-generated search results and summaries. However, the company claims this information won’t negatively impact traffic to websites and publisher revenue.

Does Gen AI stem outgoing traffic from search engines?

Several internet and social media experts have claimed that AI stops users from leaving Google or Bing. Simply put, if search engines summarize answers to search queries, users don’t need to visit websites that contain the relevant information.

While several digital publications opposed Google’s AI Overviews, there might not be a similar backlash for Microsoft Bing’s new interface. This is because Microsoft appears to have adopted a much more transparent approach.

Google attempted to serve AI-generated content to search queries noticeably that seemed to lack adequate links to sources or references. Microsoft claims Bing’s new AI section retains several clickable web links that lead to the source of the information.

Microsoft claimed, “Early data indicates that this experience maintains the number of website clicks and supports a healthy web ecosystem.” Strangely, the company’s examples of the new Bing interface reportedly suggest an overwhelming preference of AI for just the top search results. An older iteration offered at least three source links.


[ad_2]
Source link

Looks like Google’s Pixel Phone AI-powered anti-scam protection is coming soon

0
[ad_1]
As originally announced during I/O, Google is enhancing its spam and scam call detection capabilities on Pixel devices with a new AI-powered feature. Codenamed “Sharpie,” this innovative functionality was discovered hidden in the code of the latest beta version of Google’s Phone app and will utilize artificial intelligence to identify scam calls in real time.
The technology was initially introduced as part of Google’s Gemini Nano feature at the recent I/O event. Gemini Nano is specifically designed for smartphones, enabling AI tasks to be processed directly on the device. However, this also means that the AI-enabled scam detection feature will initially be limited to newer Pixel models, including the Pixel 8a, Pixel 8, Pixel 8 Pro, and the upcoming Pixel 9 series.

The enhanced scam detection popup teased for Pixel devices at Google I/O back in May | Image credit — Google

The feature is expected to differentiate between spam and scam calls, allowing users to manually report calls as either category. While Google has previously stated that the feature would be opt-in, meaning users would need to activate it manually, recent code discoveries suggest that it might be automatically enabled for certain devices, such as those managed under Family Link.The new scam detection feature is expected to be showcased at the upcoming Made by Google event, where the Pixel 9 series is anticipated to be unveiled. This technology is expected to enhance Google’s existing spam protection measures, which already include features like the built-in “Filter spam calls” option on all Android smartphones and the “Automatically screen and decline robocalls” feature on Pixel devices.

While it’s not yet clear how the “Sharpie” feature will be implemented in detail or what its exact capabilities will be, it represents a significant step forward in Google’s efforts to combat spam and scam calls. By leveraging AI to identify and filter out these unwanted calls, Google is stepping up one of the biggest flexes that Pixel users have on their devices.


[ad_2]
Source link