Rite Aid says 2.2 million people affected in data breach

0
[ad_1]

The US’ third-largest pharmacy chain Rite Aid has filed a data breach notification in which it reports that the data stolen during a June ransomware attack compromised the data of some 2.2 million people.

Ransomware group RansomHub claimed responsibility for the attack that took place on June 6, 2024. Ransomware groups are always looking for ways to increase their leverage over their victims, and threatening to leak stolen customer data is one of their most common methods.

The site where RansomHub’s leaks stolen data features a ransom demand next to a typical countdown timer, demanding payment before the timer expires on July 26, after which the group has threatened to release the stolen data.

Rite Aid listing on RansomHub leak site
Rite Aid listing on RansomHub leak site

After the discovery of the breach on June 20, Rite Aid started an investigation. The restoration of the compromised systems has now reached completion, according to Rite Aid.  

Reportedly, the stolen data appears to be limited to purchases made between June 6, 2017, and July 30, 2018. Rite Aid says names, addresses, dates of birth, and the numbers associated with driver’s licenses or other ID documents were stolen.

RansomHub claims that:

​”While having access to the Riteaid network we obtained over 10 GB of customer information equating to around 45 million lines of people’s personal information. This information includes name, address, dl_id number, dob, riteaid rewards number.”

Rite Aid is offering affected customers a standard 12 months of credit monitoring from Kroll. Details on how to claim that offer can be found in the letter it’s sending customers.

Protecting yourself after a data breach

There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.

  • Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened, and follow any specific advice they offer.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop or phone as your second factor. Some forms of two-factor authentication (2FA) can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for fake vendors. The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify the identity of anyone who contacts you using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online, and helps you recover after.

Malwarebytes has a free tool for you to check how much of your personal data has been exposed online. Submit your email address (it’s best to give the one you most frequently use) to our free Digital Footprint scan and we’ll give you a report and recommendations.


Summer mega sale

Go into your vacation knowing you’re much more secure: This summer you can get a huge 50% off a Malwarebytes Standard subscription or Malwarebytes Identity bundle. Run, don’t walk!


[ad_2]
Source link

Grab Anker Soundcore Liberty 4 at just $69 in Prime Day Sale

0
[ad_1]

Anker’s Soundcore Liberty 4 wireless earbuds are one of the best low-cost noise-canceling earphones in the market for Android users. Normally priced at $99.99, the pair is more affordable than ever right now. Amazon is selling it for just $69.99 with its Prime Day deal. All five color variants are available at this unbelievable price.

Prime Day slashes Anker Soundcore Liberty 4’s price, available at $69

Made by Anker’s sub-brand Soundcore, the Liberty 4 wireless earbuds feature a high-sensitivity in-ear sound sensor and an innovative noise isolation chamber that cancels up to 98.5% of noise. Its Adaptive ANC technology intelligently adjusts noise cancellation for maximum comfort and quiet. This ensures an immersive listening experience enhanced by Hi-Res wireless audio and LDAC technology.

The earbuds support a fully adjustable equalizer to fine-tune the audio output according to your music taste. So download the Soudcore app on your phone and do the tuning yourself. You can remix, optimize, and personalize the Soundcore Liberty 4’s audio quality to perfection. If you don’t want the hustle, you can choose from 22 audio presets. The buds’ IPX4 build allows you to wear them in the rain or accidentally spill some water onto them.

The Soundcore Liberty 4 earbuds are also great for calls. The six beamforming mics and an AI algorithm amplify your voice and reduce background noise so the other party hears you clearly. As far as the battery life is concerned, these wireless buds run for up to ten hours on a single charge. With the charging case, the runtime goes up to 50 hours. These excellent pair of earphones from Anker can be yours at just $69.99 if you grab this Amazon Prime Day deal. They are available in white, light blue, navy blue, pink, and black colors.

buy at amazon


[ad_2]
Source link

Prime Day brings Samsung Galaxy Watch 4 down to just $129

0
[ad_1]

Samsung’s Galaxy Watch 4 may be aging but is still a very capable Wear OS smartwatch. It offers almost everything you get on newer Galaxy watches, with an upcoming update expected to bring more new features from the recently launched Galaxy Watch 7 and Galaxy Watch Ultra. This watch is available for just $129.99 during Amazon’s ongoing Prime Day sale. At this price, it’s a steal—it usually costs $199.99.

Galaxy Watch 4 drops to $129 for Prime Day, a steal deal

Launched in 2021, the Galaxy Watch 4 has already seen three succeeding models. However, Samsung still updates it regularly with new features and security enhancements. The updates should come for at least another year if not longer. As said earlier, the watch is scheduled to get another major feature update soon. It will get the Wear OS 5-based One UI 6 Watch from the Galaxy Watch 7 series.

These feature additions have ensured that the Galaxy Watch 4 doesn’t feel outdated. It boasts a wide range of health features like heart rate monitoring, sleep monitoring, stress monitoring, ECG, blood pressure, body composition, and blood oxygen. It can also automatically detect various physical activities like walking, cycling, running, and more, and track workouts to determine your calorie burns and other health stats.

Additionally, the Galaxy Watch 4 supports all Wear OS apps, can show notifications from your phone with quick reply options, can make and receive calls, control your smartphone camera, control your wireless earbuds, and do a lot more. Newer Samsung watches offer a few extra features, but this 2021 model is still a great pick at just $129.99. Amazon Prime Day is underway and won’t last forever, so hurry up and grab the deal.

buy at amazon


[ad_2]
Source link

Samsung’s Live Translate will be expanding to WhatsApp, Instagram, and even Signal

0
[ad_1]

Generative AI is getting better and better with each passing second, and its main aim is to make our lives easier. One such feature powered by AI is Samsung’s Live Translate feature, which basically acts as an interpreter during phone calls. And now, the feature will get a very nice update with the upcoming One UI 6.1.1. update: it will be able to work with voice calls from popular messaging apps. Live Translate was first introduced with Samsung’s flagship line, the Galaxy S24 series, and came with One UI 6.1 to supporting phones. It acts as a real-time interpreter during phone calls. You can activate it during a phone call by pulling down the Quick Settings panel and tapping on the Live Translate button.

Last week, during Samsung Unpacked, Samsung confirmed that Live Translate will be getting updated to work with a variety of third-party messaging apps, which is, quite frankly, a great thing, especially for people with loads of international friends (me being one of them).


According to Samsung’s post on its Korean blog, the feature will be available with the following messaging apps: KakaoTalk, Line, WeChat, WhatsApp, Telegram, Facebook, Messenger, Instagram DM, Signal, and Google Meet. Pretty much all the mainstream ones. By the end of the month, Live Translate should work with 16 languages. In the beginning, there was support for 13 languages: Chinese (Mandarin), English (India, UK, US), French, German, Hindi, Italian, Japanese, Korean, Polish, Portuguese, Spanish (Mexico, Spain, US), Thai, and Vietnamese, and in April, Samsung added Arabic, Indonesian, and Russian to the mix. It also speaks dialects, like Australian English, Cantonese, and Canadian French.

Later this year, support for Romanian, Turkish, Dutch, Swedish, traditional Chinese, and European Portuguese will be coming to Live Translate.

I personally find this feature extra cool. As I said, I have friends from all over the world and although we communicate in English, sometimes for some of us it could be a challenge to express exactly what we want. Live Translate could serve as a door towards a creative way to overcome being stuck at a word you don’t remember. So, kudos to Samsung for bringing it to more apps!


[ad_2]
Source link

Beware of New Phishing tactics impersonating HR & Attacking Employees

0
[ad_1]

Phishing attacks are becoming increasingly sophisticated, and the latest strategy targeting employees highlights this evolution.

This new phishing attempt impersonates a company’s Human Resources (HR) department, presenting a significant threat to corporate security.

In this article, we’ll dissect the recent phishing tactic and provide detailed insights to help you recognize and avoid falling victim to such scams.

The Deceptive Email: A Closer Look

According to the Cofense reports, a phishing email is meticulously designed to look like official communication from a company’s HR department.

It arrives in employees’ inboxes with a subject line that immediately grabs attention: “Modified Employee Handbook For All Employees – Kindly Acknowledge.”

This subject line creates a sense of urgency, prompting recipients to open the email and engage with its contents without hesitation.

The email’s layout and language further enhance its perceived legitimacy.

It opens with a formal greeting and presents a message in a structured format typical of corporate communications.

The language used is professional, clear, and direct, mimicking the tone and style that employees would expect from an HR department.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files

The body of the email includes formal language and directives typical for corporate communications.

It begins with a polite greeting and swiftly transitions into a directive to review a revised employee handbook.

The email stresses the importance of compliance by a specific deadline, typically by the end of the day, fostering a sense of urgency and importance among recipients.

The Phishing Page: A Deceptive Trap

The primary goal of this phishing email is to lure recipients into clicking on the embedded hyperlink and trick them into entering their credentials on a fake login page.

By appearing to originate from a trusted source (HR department), the email leverages authority and urgency to persuade recipients to take immediate action without questioning the authenticity of the request.

Phishing Page

The email contains a hyperlink with the heading, “HR COMPLIANCE SECTION FOR REVISED EMPLOYEE HANDBOOK.”

Clicking on this link takes you to a page that mimics a legitimate document hosting site. Here, you are presented with a “PROCEED” button to continue.

Upon clicking the “PROCEED” button, you are redirected to a page that appears to be branded by Microsoft.

This is where the phishing attack becomes more sophisticated.

The page asks for your Microsoft username and looks very convincing.

The threat actor’s strategy is to gain your trust by presenting a legitimate-looking website where you are prompted to log in with your company’s Microsoft credentials.

Here’s a detailed breakdown of what happens next:

  1. Capture of Credentials: When you enter your company email address and press next, you are redirected to what looks like your company’s Microsoft Office 365 login page.
  2. Error Message: After entering your username and potentially your password, you receive an error message stating, “There was an unexpected internal error. Please try again.” This message is a ruse.
  3. Redirection to Legitimate Login Page: You are then redirected to your actual company’s SSO/Okta login page, and the victim will likely not even realize the URL changed. In the meantime, the threat actor has captured your username and password from the login attempt.

To protect yourself and your organization from such sophisticated phishing attacks, it is crucial to stay vigilant and follow these preventive measures:

  • Verify the Source: Always verify the sender’s email address and look for any inconsistencies.
  • Hover Over Links: Before clicking on any link, hover over it to see the actual URL.
  • Report Suspicious Emails: Immediately report any suspicious emails to your IT department.
  • Regular Training: Participate in regular cybersecurity training sessions to stay updated on the latest phishing tactics.

By staying informed and vigilant, employees can play a crucial role in safeguarding their organization against these evolving phishing threats.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo


[ad_2]
Source link

Save big on these WiiM devices for Prime Day!

0
[ad_1]

Amazon Prime Day is happening now, and we’re seeing some killer deals. If you’re looking for some top-of-the-line audio equipment at a discount, look no further. The WiiM Amp and WiiM Pro Plus are discounted for Prime Day. These discounts knock the prices down to $239 (20% off) and $175.20 (20% off), respectively.

Before we start, if you want to try out Amazon Prime for free, new members can try a 30-day free trial.

Starting off with the WiiM Amp, this is an incredible amplifier that’s designed for your multi-room setup. This is a small device, but it packs some serious power. It can deliver 60W of power per channel at 8 ohms and 120W of power per channel at 4 ohms. This is great for all sorts of speakers on the market.

It can also integrate with several streaming services like Spotify and Tidal right from the amp. You’ll use the WiiM Home App to manage your services along with managing the volume on a per-room basis, syncing speakers, setting alarms, etc.

This is an all-in-one hub to control your multi-room audio setup, and it can also integrate with different voice assistants like Alexa, Google Assistant, and Siri. You’ll enjoy high-resolution playback at up to 24-bit/192kHz. That’s professional-quality, and it will make your lossless files from Tidal, QOBUZ, and Amazon Music Ultra HD sound amazing.

WiiM Pro Plus

If you’re a person who wants to stream music to your stereo setup, this is the device for you. The WiiM Pro Plus will let you stream music from your favorite streaming service and run it through your stereo setup.

You can stream music from all sorts of streaming services including Tidal, Spotify, Pandora, YouTube Music, Apple Music, Deezer, Tune In, Sirius XM, Amazon Music, Audible, QOBUZ, and many more.

Audio quality isn’t a problem either. You can stream lossless audio at up to 24-bit/192kHz. You can expect gapless playback through the AKM 4493S DAC.

It doesn’t matter if you’re a part of the Apple ecosystem or if you use Android/ChromeOS devices. This device is compatible with both Apple AirPlay and Chromecast. As if that’s not enough, you can use Google Assistant, Amazon Alexa, or Siri with this device for voice commands.

These are two extraordinary devices that are made better by their amazing discounts.


[ad_2]
Source link

Get over $100 off the HIFIMAN Arya Stealth for Prime Day!

0
[ad_1]

It’s Prime Day, and that means some serious savings are going around. If you’re looking to hop on the audiophile train, then you’ll want to take a look at this sweet deal from HIFIMAN. If you’re a Prime member, you can pick up the HIFIMAN Arya Stealth for more than $100 off for Prime Day. This brings the price down to $649 from $759.

Not a Prime member? You can try Prime out for FREE using a 30-day trial.

Being an audiophile is not cheap, so you’ll need to save money however you can! It’s okay to jump on a deal if you’re looking for the best on the market, and these are some of the best on the market.

Talk about high-quality headphones! The HIFIMAN Arya Stealth have a set of meticulously tuned drivers that are designed to give you some of the most detailed sound any headphones can give you. The company was able to achieve this with its revolutionary nanometer-thick diaphragm. This is something that only HIFIMAN can do.

Along with the ultra-thin diaphragm, the drivers actually come with a set of acoustically transparent magnets. These magnets will reduce the refraction of the sound waves traveling around them. This will lead to an overall cleaner sound.

The HIFIMAN Arya Stealth have an open design which makes them ideal for professional mixing and mastering along with listening to music. You’ll enjoy a more realistic and open sound. The earbuds have a window shade design that will help protect the diaphragm from all sorts of dirt or dust that can get in. A nanometer-thick diaphragm isn’t quite resilient. So, this will ensure that your headphones are well-protected.

If you’re a professional or a hobbyist, then you’ll love the HIFIMAN Arya Stealth. They’re top-tier headphones, and this deal makes them so much better.


[ad_2]
Source link

Apple’s Airpods Pro 2 with USB-C plummet to their lowest price ever for Prime Day

0
[ad_1]

Amazon has just discounted the newish USB-C AirPods Pro second-generation to their lowest price ever, just $168. The last time we wrote about a deal for these particular AirPods, they were priced at $199, which was the previous all-time low. So if you’ve been looking to pick up a pair, now is the time to do so.

These new AirPods Pro 2 don’t bring a lot of changes over the original second-generation model. The biggest change is Lightning to USB-C to match the iPhone 15. It also brings lossless audio, which is really impressive, but you’ll really only be able to use it on the Vision Pro.

When it comes to battery life here, Apple is claiming about six hours of listening time. That’s on a single charge; with the case, they are touting about 30 hours. So these should be able to get you through a good solid listening session. And even for a flight from New York to San Francisco. There’s also an LED on the front of the case to indicate charging and pairing. As well as a speaker there for Find My.

You can pick up the new USB-C AirPods Pro 2 from Amazon at the link below.

Buy at Amazon


[ad_2]
Source link

X investigated from the EU for possibly violating the Digital Services Act

0
[ad_1]

The European Union is regularly investigating big tech companies, and the latest company currently under scrutiny is X. The European Commission now claims X has violated the Digital Services Act (DSA), at least judging by the Commission’s preliminary findings.

It seems that the platform’s approach to paid verification is what is bothering the EU. Regulators say the practice “deceives users” and does not correspond to industry practice. The issue seems to be that since anyone can get a blue check-mark, it’s difficult to determine the authenticity of accounts. Also, there is, reportedly, evidence of bad actors using check-marks to trick people.

Paid check-marks seem to lead to an increase in scams and spam.

On top of that, the EU believes that X has a lack of advertising transparency. The EU claims that the tech giant doesn’t have a reliable, searchable ad repository. The EU says that X violates the DSA by failing to give researchers sufficient access to public data. According to the Commission, researchers are dissuaded from carrying out projects or forced to pay high fees to do their research.

-Thierry Breton, EU’s internal market commissioner


If the Commission finds that X is guilty, it can be fined up to six percent of its global annual revenue, which should be a pretty big sum. Also, the EU could direct X to ensure compliance with the DSA and impose further fines if the company fails to do so.

[ad_2]
Source link

My Favorite Bluetooth Speaker, the Sony BRAVIA U gets its first discount for Prime Day

0
[ad_1]

The Sony BRAVIA U was announced earlier this year, and has a regular price of $298. So it’s fairly surprising to see them on sale for $148 right now at Amazon, for Prime Day. Ever since Sony sent over a pair of the BRAVIA U, I’ve been unable to put them down. I wear them just about everyday while I’m working, and playing video games, because it’s just that good.

This is a wearable speaker that fits rather comfortably around your neck. It uses Bluetooth, so it can connect to virtually anything that uses Bluetooth. That includes Android phones, iPhones, TVs, laptops and much more. The sound coming out of this speaker is really good, with some deep bass, and crystal clear mids and highs.

Now, one of the advantages to a wearable speaker like this is that you can hear it, while others can’t. Or at least they can’t as much. If you have it turned up pretty loud, then others around you can hear it, as this is a speaker after all. But it does point the speakers up towards your ears. Additionally, Sony says that you’ll get 12 hours of battery life out of these, and they are rated at IPX4, so they can take a little bit of rain, but not the tornadoes we’ve seen in the midwest as of late.

Buy at Amazon


[ad_2]
Source link