OnePlus unveils Ace 3V, coming to global markets under a different name

0
[ad_1]

The OnePlus Ace 3V has been announced in its homeland, China. This smartphone is expected to arrive to global markets under a different name, with a ‘Nord’ branding. OnePlus will most likely use the OnePlus Nord 4 naming. There’s a chance the ‘Nord 4’ will be skipped, though, in favor of ‘Nord 5’, as the number 4 is considered to be unlucky in China.

The OnePlus Ace 3V is now official and will launch globally under the ‘Nord’ brand

With that being said, let’s take a closer look at the OnePlus Ace 3V. It has flat sides, with chamfered edges. All of its physical buttons sit on the right-hand side. There is an alert slider on the left, though.

A flat display sits on the front, with thin bezels, which are not uniform. A centered display camera hole is also located on the front. There are two cameras included on the back, and they’re vertically aligned.

Those cameras sit inside the same camera island. It is located in the top-left corner, and it does protrude on the back a bit. OnePlus’ logo is centered on the back side of the phone.

It’s fueled by the all-new Snapdragon 7+ Gen 3 processor

The OnePlus Ace 3V is fueled by the Snapdragon 7+ Gen 3 processor. That chip actually got announced today, in case you were wondering. It’s Qualcomm’s new mid-range processor with a focus on AI.

OnePlus included a 6.74-inch 1.5K AMOLED display here. It supports a 120Hz refresh rate, and its refresh rate goes up to 1,100 nits. This panel is flat.

This smartphone also comes in several variants. It’s available with 12GB and 16GB storage options. The 12GB RAM model includes either 256GB or 512GB of storage, while the 16GB RAM variant is available in a 512GB storage flavor. OnePlus used LPDDR5X RAM and UFS 4.0 flash storage.

A 5,500mAh battery powers this phone, while the OnePlus Ace 3V supports 100W wired charging. The charger is included in the retail box, and will be with the global variant too.

It has two cameras on the back, and Android 14 comes out of the box

A 50-megapixel main camera (Sony’s IMX882 sensor) is backed by an 8-megapixel ultrawide unit (Sony’s IMX355 sensor). A 16-megapixel selfie camera (Samsung’s S5K3P9 sensor) is also a part of the package.

Android 14 comes pre-installed here, with OnePlus’ software on top of it. The device is also IP65-certified for water and dust resistance. OnePlus promises 3 major updates and 4 years of software support for the device. You’ll find a set of stereo speakers here too.

The OnePlus Ace 3V’s pricing starts at CNY1,999 ($278) in China, and goes up to CNY2,599 ($361). The phone comes in black and silver color variants, as you can see below. We’re not sure when will the global variant launch. The OnePlus Nord 3 launched in July last year, so we may have to wait until July 2024.


[ad_2]
Source link

DOJ wants ByteDance to sell TikTok rather than ban it in the US

0
[ad_1]

TikTok, the popular social media app that has been criticized for its ties to China, is at risk of being banned outright in the United States. The U.S. House of Representatives already voted in favor of a bill that would require TikTok to be divested to a U.S. company or be banned, and TikTok’s fate now rests with the Senate. But, Department of Justice officials are having secretive meetings this week to help avoid a TikTok ban, according to The Business Times. The DOJ has a clear preference to forcing ByteDance to sell TikTok, rather than banning it altogether.

ByteDance is based in China, and there are concerns that the country’s government could use TikTok to harm the U.S. This could be through collecting data from American users, or by influencing Americans with content shown on TikTok’s “For You” page. Either way, these fears have created tremendous pressure from the U.S. government. Part of the reason that the DOJ wants ByteDance to sell TikTok is due to the app’s data. Chinese laws can force companies to hand over data to the government, and ByteDance could have to comply with a request for data, if asked.

Lisa Monaco, the deputy attorney general, is leading the effort. Additionally, the report notes that lobbying is taking place now. In a shocking twist, there is bipartisan support for action against TikTok. But Monaco believes ByteDance can sell TikTok to avoid a ban. “What we have seen is the asset that is being sought by our adversaries is not the brick-and-mortar institution,” Monaco said, as reported by The Business Times. “The asset is the data itself.”

Will ByteDance sell TikTok after DOJ pressure?

Though the DOJ is lobbying for TikTok to be sold, it’s unlikely. There aren’t major benefits to selling TikTok for ByteDance. The app is used globally, which means U.S. users only make up a small portion of TikTok’s global user base. As such, ByteDance might rather TikTok be banned than be sold. There has been no indication that ByteDance intends to sell TikTok, even after DOJ pressure.

Additionally, leaders at ByteDance and TikTok have maintained that they plan to fight U.S. legal action. If the Senate passes legislation, TikTok and its owner will “exhaust all legal challenges,” according to Bloomberg. Similarly, TikTok has categorically denied the allegations posed by some U.S. lawmakers. The app’s algorithm is not directed by any government, it says. We’ll have to wait and see how the Senate proceeds, but a resolution could be months away.


[ad_2]
Source link

Samsung brings cloud gaming to Galaxy phones with Gaming Hub

0
[ad_1]

Gaming is a big deal on mobile devices, so for tech companies, it is crucial to make the experience as smooth and enjoyable as possible. Some of the best gaming phones come from Samsung’s flagship Galaxy series. Now, the Korean tech giant has announced that its Gaming Hub, formerly known as the Game Launcher app, is getting some new features.Samsung revealed that its Gaming Hub for mobile is expanding its reach to a broader gaming community by offering instant access to games through the cloud gaming-enabled Instant Plays feature, which is currently in beta in the US and Canada.

Samsung is expanding gaming access and fostering growth within its Galaxy ecosystem:


  • The Gaming Hub for mobile now includes Instant Plays, allowing users to instantly access games without installation, enhancing game discoverability.
 
  • Samsung’s cloud platform supports Android APKs, offers a cloud-based attribution solution with major mobile measurement partners, and maintains support for existing in-game monetization models, ensuring seamless integration with game publishers’ operations.

At the yearly Game Developers Conference, Samsung’s Corporate Vice President Jikhan Jung delved deeper into the company’s ongoing advancements in game streaming for both players and partners:

In 2022, Samsung unveiled the Gaming Hub, an integrated game streaming and discovery platform. Evolving from the Game Launcher feature on Galaxy devices, the Gaming Hub for mobile aligns with Samsung Gaming’s goal to provide users with diverse options for discovering and enjoying their favorite games.


[ad_2]
Source link

Application-Layer Loop DoS Attack – 300,000 Online Systems At Risk

0
[ad_1]

Denial-of-service (DoS) attacks are usually exploited by hackers to interrupt regular network and website functioning, with motives of making money or for political reasons or simply to create a mess. 

The websites or networks can be made unavailable through the Denial of Service (DoS) attack method which sends numerous requests for resources and traffic to the system.

Researchers at CISPA Helmholtz-Center for Information Security discovered a new Denial-of-Service attack vector called “Application-layer Loop DoS Attacks.” 

It targets UDP-based application protocols by pairing their servers to communicate indefinitely, affecting both legacy protocols like QOTD, Chargen, and Echo and contemporary ones like DNS, NTP, and TFTP. 

This vulnerability puts an estimated 300,000 Internet hosts and networks at risk of denial-of-service conditions.

Loop DoS Attack

Loop DoS Attack

The newly discovered self-perpetuating DoS loop attack targets application-layer messages by pairing two network services that keep responding indefinitely, creating large traffic volumes resulting in denial of service. 

Once triggered, even attackers cannot stop it. Previously, loop attacks occurred on routing layers with finite iterations. 

This attack by CISPA researchers concerns 300,000 Internet hosts, confirming vulnerabilities in TFTP, DNS, NTP, and six legacy protocols providing basic Internet functionalities like time synchronization, name-to-IP mapping, and unauthenticated file transfer.

Application-layer loop DoS attacks employ IP spoofing, enabling initiation from a single spoofing-capable host. 

For example, attackers could trigger a perpetual loop between two vulnerable TFTP servers by injecting one spoofed error message, causing them to exchange error messages and stress networks between them endlessly. 

These attacks differ from known network-layer loops, bypassing existing packet lifetime checks at that level and representing a novel vector unaddressed by current mitigations.

This novel attack vector is yet to be exploited in the wild, however, Rossow warns that if left unaddressed it could readily be used by malefactors. 

Rossow and Pan reported their discoveries concerning December 2023 to the relevant vendors and a consortium of trusted operators. 

Moreover, CISPA researchers coordinated with The Shadowserver Foundation for an advisory publication and notification campaign on application-layer loop DoS threat.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Why Browser Security Matters More Than You Think

0
[ad_1]
Why Browser Security Matters More Than You Think

In today’s interconnected world, where our lives revolve around the internet, it’s imperative to understand the importance of browser security. Whether it’s for personal use or professional purposes, web browsers function as our primary gateway to the online world.

Consequently, they also serve as a potential entry point for cyber threats and attacks. In this article, we’ll highlight why browser security matters more than you might think and discuss some essential steps to enhance your online safety.

The Growing Cybersecurity Threat:

It’s no secret that cyber threats have become increasingly sophisticated over the years. Cybercriminals are constantly finding new ways to exploit vulnerabilities in browsers, leaving users vulnerable to privacy breaches, data thefts, and financial frauds.

According to cybersecurity experts, one of the most common tactics used by hackers is cross-site scripting (XSS) attacks. These malicious scripts injected into web pages can compromise users’ sensitive information.

Major Web Browsers Remain At Risk:

While modern web browsers work diligently to enhance their security features, they are not completely immune from threats. Some developers argue that certain browsers are more secure than others due to their built-in security mechanisms. However, critics believe that no browser is entirely invincible. Over time, vulnerabilities may emerge for even the most popular browsers for Windows as hackers adapt and discover new methods of attack.

The Need for Vigilance and Proactive Measures:

Considering the persistent threat surrounding web browsers, users like us must remain proactive with our online safety measures:

1. Keep Your Browser Up-to-Date:

Vendors frequently release security patches and updates for their web browsers as vulnerabilities are discovered and fixed. By regularly updating your browser software, you stay protected against known threats.

2. Enable Automatic Updates:

Enabling automatic updates ensures that you receive critical security updates immediately upon release without any manual intervention.

3. Utilize Browser Extensions with Caution:

Browser extensions can add extra functionality and enhance your browsing experience. However, they may also act as potential gateways for hackers. It’s important to research and use trustworthy extensions from reputable sources.

4. Enable Two-Factor Authentication (2FA):

Activating 2FA adds a layer of security to your user account by requiring you to provide a second form of verification, such as a unique code sent to your mobile device or email.

5. Implement Strong and Unique Passwords:

We’ve heard it countless times, but it bears repeating: strong, complex, and unique passwords are essential. Avoid using easily guessable passwords like consecutive numbers or common phrases. Consider utilizing a password manager to store and generate unique passwords securely.

6. Regularly Clear Browser Cache and Cookies:

Clearing your browser cache and cookies can help protect your privacy and prevent unauthorized access to your online activities.

7. Use Privacy-Focused Browsing Modes:

Most popular web browsers offer private browsing modes that do not retain any browsing history or save cookies upon session closure. Utilize these specialized modes when accessing sensitive information or using public networks.

8. Be Cautious with Downloads:

Exercise caution when downloading files from the internet, particularly those sent by unknown sources. Malware can be disguised within seemingly harmless files, leading to potential security breaches.

Common Mistakes to Avoid:

Despite the importance of browser security, many users make common mistakes that can leave them vulnerable to cyber threats. By avoiding these pitfalls, you can significantly enhance your online safety.

1. Ignoring Updates:

One of the most common mistakes people make is neglecting to update their web browsers. Developers continuously release updates to patch security vulnerabilities and improve overall performance. If you ignore these updates, your browser remains susceptible to attacks targeting known vulnerabilities.

Clicking on suspicious links in emails or on unfamiliar websites can lead to malware infection or phishing attempts. Always be cautious and verify the authenticity of links before clicking on them.

3. Using Weak Passwords Across Multiple Websites:

Using weak passwords that are easy to guess or reusing passwords across multiple websites places all your accounts at risk if one becomes compromised. Implement strong and unique passwords for each online service you use, and consider using a password manager to manage them securely.

Conclusion:

Your browser is more than just a tool for internet navigation; it serves as the gateway between you and the digital world around you – a world teeming with cyber threats desperately seeking gaps in security measures to infiltrate unknowing users’ devices.

By prioritizing browser security, remaining vigilant against emerging threats, and implementing the tips mentioned above, we can significantly reduce our vulnerability to cyber-attacks.

Remember: taking proactive steps towards enhancing browser security today means safeguarding yourself against tomorrow’s evolving risks—a small price for maintaining online safety in an ever-connected world.

  1. Apple Safari Safest, Google Chrome Riskiest Browser
  2. Mullvad VPN and Tor Project Release Mullvad Browser
  3. Brave Browser enters dark web with its own Tor Onion service
  4. Google Incognito Mode: New Disclaimer Reveals Data Tracking
  5. DuckDuckGo Allows Microsoft Trackers Despite No Tracking Policy

[ad_2]
Source link

Galaxy Tab Active 5 Enterprise Edition will get 8 Android updates

0
[ad_1]

The enterprise edition of Samsung’s Galaxy Tab Active 5 will get updates for eight years, a company executive revealed on LinkedIn. Not only security patches, but the device will also receive eight major Android OS updates during this time. The standard version of the newly launched rugged tablet is eligible for four major OS updates and five years of security patches.

Samsung promises eight years of updates for the Galaxy Tab Active 5

Samsung‘s enterprise edition Galaxy devices are aimed at business customers. These products come with additional software solutions and dedicated support channels so businesses can get more out of them. The company has always offered better update support to these devices. They get regular OS and security updates, often more frequently and longer than standard versions.

However, until recently, the longest guaranteed support for any Galaxy smartphone or tablet was five years. Most Samsung products launched since 2021 get four major Android OS updates and five years of security patches, including enterprise editions. Starting with the Galaxy S24 series, the company extended support to seven years for flagship models.

The new flagships debuted with Android 14 and will get OS updates up to Android 21 and security patches till 2031. No other Galaxy device was covered under the updated policy. That’s changing on the enterprise side of things. While the enterprise edition of the Galaxy S24 is still limited to seven years of updates, the Galaxy Tab Active 5 will get updates for eight years.

This means the new tablet will remain secure till 2032 and receive new features until Android 22. The enterprise edition of the Galaxy Xcover 7, a rugged smartphone launched alongside the Galaxy Tab Active 5 in January, will get seven years of OS and security updates. Like the tablet, its standard version is eligible for only four OS updates and five years of security patches.

The tablet can run without a battery

Samsung’s Active series tablets feature a ruggedized build, S Pen support, and a removable battery. With the Galaxy Tab Active 5, the company introduced a No Battery Mode that allows it to run without a battery. It directly sends the power to the device, bypassing the battery. This enables businesses to use the tablet in kiosks with an uninterrupted power supply.

With fewer charge and discharge cycles, the battery’s health will be preserved in the long run. After all, Samsung has promised eight years of updates for the Galaxy Tab Active 5 Enterprise Edition. The company may introduce enterprise editions of more Galaxy devices in the coming months. If history is any indication, the Galaxy A55 should get one. All previous models in the lineup have enterprise versions.


[ad_2]
Source link

Discount: Meta could lower the monthly subscription fee by almost 50% to €5.99

0
[ad_1]

Facebook and Instagram parent company – Meta – has proposed to reduce its subscription fee for ad-free versions of the social media apps in Europe by almost 50%, (going to €5.99/month from €9.99/month).

The decision comes amid criticisms of forcing Meta users to pay for privacy through its no-ads service, introduced to comply with the Digital Markets Act (DMA) and EU privacy laws last Fall.

In 2023, Meta unveiled a subscription service for Facebook and Instagram in the EU, EEA, and Switzerland, offering users an ad-free experience to align with EU regulations. This service prevents user data from being utilized for advertising purposes.

Reuters reports what Meta lawyer Tim Lamb told a European Commission hearing:

Austrian privacy activist Max Schrems said the issue is not about the fee: “We know from all research that even a fee of just 1.99 euros or less leads to a shift in consent from 3-10% that genuinely want advertisements to 99.9% that still click yes. The GDPR requires that consent must be ‘freely’ given,” he said.

“In reality, it is not about the amount of money – it is about the ‘pay or okay’ approach as a whole. The entire purpose of ‘pay or okay’ is to get users to click on okay, even if this is not their free and genuine choice. We do not think the mere change of the amount makes this approach legal.”

Companies risk fines of as much as 10% of their annual global turnover for DMA breaches.


[ad_2]
Source link

Microsoft Warns of New Tax Returns Phishing Scams Targeting You

0
[ad_1]
Beware Tax Phishing This Season: Microsoft Reveals New Scams Targeting You

New and sophisticated tax phishing scams are targeting taxpayers, warns Microsoft. These scams impersonate trusted sources and use urgency tactics to steal personal and financial data.

Taxpayers beware! Phishing scams are on the rise again as tax season heats up. Microsoft Threat Intelligence has issued warnings about new and innovative tactics cybercriminals are using to steal your personal information and financial data.

These scams don’t discriminate, but they do target specific groups more heavily. New taxpayers, recent immigrants with green cards, small business owners who file themselves, and older adults are all prime targets because they might be less familiar with tax procedures.

It is also worth noting that these threat actors are getting more sophisticated too. They’re impersonating trusted sources like employers, tax agencies, and even payment processors. They might send emails with blurry or incomplete tax documents to create a sense of urgency and trick you into clicking on a malicious attachment.

These attachments, as per Microsoft Threat Intelligence’s blog post, contain malware that steals your login credentials, or they might redirect you to a fake website that looks like a legitimate tax platform designed to capture your information.

One example scam identified in January involved emails that appeared to be from employers sending tax documents. Clicking on the attached HTML file led to a fake landing page designed to steal the user’s login credentials.

Beware Tax Phishing This Season: Microsoft Reveals New Scams Targeting You
Screenshot via Microsoft Threat Intelligence

Tycoon and NakedPages – PhaaS

In addition to their blog post, Microsoft Threat Intelligence has also sent out a series of tweets addressing the increasing prevalence of phishing campaigns during the tax season in the United States.

These campaigns, including those associated with notorious phishing-as-a-service (PhaaS) platforms like Tycoon and NakedPages, are leveraging tax-related themes for social engineering tactics, putting individuals and organizations at risk of financial fraud and data theft.

One notable campaign tied to the Tycoon PhaaS platform involved deceptive emails posing as official tax forms such as W-2 and W-9 notifications, alongside other payroll tax documents.

These emails featured HTML attachments that initiated a Cloudflare captcha check, ultimately leading victims to a phishing page designed to harvest sensitive information. When recipients opened these attachments, JavaScript scripts were executed, facilitating the installation of info-stealing malware.

Additionally, Microsoft observed phishing efforts linked to the AiTM phishing kit NakedPages, where fraudulent emails disguised as DocuSign-shared documents about tax adjustments were circulated. Clicking on embedded images within these emails triggered redirections culminating in phishing pages, demonstrating the sophisticated nature of these attacks.

This malicious software is designed to harvest sensitive data, including cryptocurrency wallet information, login credentials for PuTTY and WinSCP, as well as credentials stored in web browsers and email clients. Such comprehensive data theft poses significant risks to individuals and organizations, potentially resulting in financial losses and compromised digital identities.

Screenshot via Microsoft Threat Intelligence

Both Tycoon and NakedPages are recognized for their automation capabilities in executing phishing activities, as well as their ability to bypass multi-factor authentication (MFA) through adversary-in-the-middle (AiTM) techniques, strengthening the threat posed by these campaigns.

Microsoft recommends staying alert throughout tax season. Don’t click on suspicious links or attachments in emails, even if they seem to come from a familiar source. If you’re unsure about the legitimacy of an email, contact the sender directly through a verified phone number or website.

You can find more resources and tips for staying safe from tax season scams by searching for the “Microsoft Threat Intelligence tax season report.”

  1. IRS tax forms W-9 email scam drops Emotet malware
  2. New Ransomware Email Scam Using FBI and IRS as Bait
  3. Security Breach Rattles IRS, 334,000 Tax Payers Data Stolen
  4. US Citizens Hit by Ransomware via Fake IRS Tax Return Emails
  5. Thanks IRS for poor security: Data On 100,000 Taxpayers Stolen

[ad_2]
Source link

North Korea’s Kimsuky Group Equipped to Exploit Windows

0
[ad_1]

Cybersecurity experts have uncovered a sophisticated cyber espionage campaign orchestrated by the North Korean threat actor group Kimsuky, Black Banshee, or Thallium.

This group, notorious for its intelligence-gathering missions, has been active since at least 2012.

It has primarily targeted South Korean government entities, individuals involved in the Korean peninsula’s unification process, and global experts in fields of interest to the North Korean regime.

Their latest tactics involve exploiting Windows help files, indicating an alarming evolution in their methods to bypass modern security measures.

Evolving Tactics of Cyber Espionage

Rapid7 Labs’ continuous monitoring of threat groups has led to the discovery of Kimsuky’s updated playbook, which showcases their relentless efforts to refine their tactics, techniques, and procedures (TTPs).

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

This cat-and-mouse game between cybercriminals and defenders is a testament to the dynamic nature of cyber threats.

The group’s recent shift from weaponized Office documents and ISO files to the abuse of shortcut files (LNK files) has further evolved to the exploitation of Compiled HTML Help (CHM) files.

Initially designed for structured help documentation, these files can execute JavaScript when opened, making them a potential vehicle for malware distribution.

Anatomy of the Attack

The attack begins with identifying a target, followed by a reconnaissance phase to gain undetected access.

Kimsuky’s latest findings involve CHM files delivered through various containers, such as ISO, VHD, ZIP, or RAR files, which can bypass initial defenses and execute the CHM file.

Rapid7 Labs first identified a suspicious CHM file containing several HTML documents with Korean filenames, which, when translated, revealed topics related to North Korea’s nuclear strategy.

The first scenario in our analysis can be visualized
The first scenario in our analysis can be visualized

The CHM file, created on a Korean language Windows operating system, contained a ‘home.html’ file with a code snippet capable of executing arbitrary commands on a Windows machine using HTML and ActiveX.

CHM file contains the above files and structure
CHM file contains the above files and structure

Base64 Encoded VBScript Execution

The attack involves a multi-step process that includes echoing a Base64-encoded VBScript into a .dat file, decoding it back into a .vbs file using the certutil utility, and modifying the Windows Registry to ensure persistence.

The decoded Base64 value
The decoded Base64 value

The VBScript collects system information, running processes, recent Word files, and contents of specific folders, which are then encoded and exfiltrated to a remote server.

New Campaign Discovered

This C2 server is still active and while we have seen activity since September 2023, we also observed activity in 2024.
This C2 server is still active and while we have seen activity since September 2023, we also observed activity in 2024.

Further investigation led to more CHM files and VBS scripts with similar information-gathering code but with different Command and Control (C2) servers.

This indicates that Kimsuky is actively refining its techniques to gather intelligence from victims.

Another Approach Discovered

HashValue
MD571db2ae9c36403cec1fd38864d64f239
SHA15c7b2705155023e6e438399d895d30bf924e0547
SHA256e8000ddfddbe120b5f2fb3677abbad901615d1abd01a0de204fade5d2dd5ad0d
————-——————-

Using Yara rules based on the characteristics of previously discovered CHM files, Rapid7 Labs identified additional CHM files containing .bat files and VBS scripts with hidden code.

These files, once executed, create persistence scheduled tasks, gather system information, and send it to a C2 server after encoding and zipping the data.

In this particular case, multiple .bat files and VBS scripts are present
In this particular case, multiple .bat files and VBS scripts are present

Attack Prevalence

Rapid7 Labs has confirmed targeted attacks against entities based in South Korea and attributes this campaign with moderate confidence to the Kimsuky group.

The overall flow of this attack can be simplified in this visualization
The overall flow of this attack can be simplified in this visualization

The term “moderate confidence” indicates significant evidence of similarity to past observed activities of the group, with the caveat that there is always a possibility of mimicry.

The Kimsuky group’s ability to adapt and exploit Windows help files is a stark reminder of the evolving landscape of cyber threats.

Organizations must remain vigilant and proactive in cybersecurity to protect against such sophisticated attacks. 

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

19 million plaintext passwords exposed by incorrectly configured Firebase instances

0
[ad_1]

Three researchers scanned the internet for vulnerable Firebase instances, looking for personally identifiable information (PII).

Firebase is a platform for hosting databases, cloud computing, and app development. It’s owned by Google and was set up to help developers build and ship apps.

What the researchers discovered was scary. They found 916 websites from organizations that set their Firebase instances up incorrectly, some with no security rules enabled at all.

One of the researchers told BleepingComputer that most of the sites also had write enabled (meaning anyone can change it) which is bad, and one of them was a bank.

During a sweep of the internet that took two weeks, the researchers scanned over five million domains connected to Google’s Firebase platform.

The total amount of exposed data is huge:

  • Names: 84,221,169
  • Emails: 106,266,766
  • Phone Numbers: 33,559,863
  • Passwords: 20,185,831
  • Billing Info (Bank details, invoices, etc): 27,487,924

And as if that isn’t bad enough, 19,867,627 of those passwords were stored in plaintext. Which is a shame given that Firebase has a built-in end-to-end identity solution called Firebase Authentication that is specifically designed for secure sign-in processes and does not expose user passwords in the records.

So, an administrator of a Firebase database would have to go out of their way and create an extra database field in order to store the passwords in plaintext.

The researchers have warned all the affected companies, sending 842 emails in total. Only 1% of the site owners replied, but about a quarter of them did fix the misconfiguration.

In this case we can consider it a blessing that these researchers managed to get a lot of those instances correctly configured. On the other hand it’s frightening that the rest lives on in a state of insecurity.

If you want to find out how much of your data has been exposed online, you can try our free Digital Footprint scan. Fill in the email address you’re curious about (it’s best to submit the one you most frequently use) and we’ll send you a free report.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection.


[ad_2]
Source link