Microsoft Addressed ~60 Vulnerabilities With March Patch Tuesday

0
[ad_1]

The Patch Tuesday update bundle for March 2024 carries some important security fixes for various Microsoft products. Nonetheless, no specific zero days were reported for this month’s fix.

Microsoft March 2024 Patch Tuesday Overview

With March updates, the Redmond giant addressed dozens of security vulnerabilities affecting different products. But interestingly, the updates do not include any zero-day fixes this time. So, while these updates do not demand an immediate rush from users, they are still important to secure eligible devices from potential threats.

The most noteworthy security fixes with the March 2024 Patch Tuesday bundle arrive for two critical vulnerabilities in Microsoft Hyper-V. These include,

  • CVE-2024-21407 (CVSS 8.1): A critical severity remote code execution vulnerability allowing attacks from an authenticated attacker. An adversary could exploit the flaw by sending maliciously crafted file operation requests to the guest VM that could allow code execution. Exploiting the flaw requires the attacker to first prepare the target environment by gathering specific information.
  • CVE-2024-21408 (CVSS 5.5): A denial-of-service vulnerability affecting Windows Hyper-V. While this vulnerability received a low CVSS score, it still achieved a critical severity rating given its impact.

Except for these two vulnerabilities, all other security issues received important severity ratings. These vulnerabilities affected different Microsoft products, including Windows Kernel, Print Spooler, Microsoft Edge, Windows Installer, and Microsoft Defender. From these, some noteworthy vulnerabilities include,

  • CVE-2024-26199 (CVSS 7.8): A privilege escalation vulnerability affecting Microsoft Office that could let an authenticated adversary gain SYSTEM privileges on the target system.
  • CVE-2024-26198 (CVSS 8.8): A remote code execution flaw in Microsoft Exchange Server. An unauthenticated attacker could exploit the flaw by placing a maliciously crafted file in an online directory or local network location, and tricking the victim user into opening the file which would load the malicious DLL.

While these updates would automatically reach all eligible systems, users must still check their devices manually for updates to ensure that they are promptly receiving the security fixes.

Let us know your thoughts in the comments.


[ad_2]
Source link

COTI Announces Upcoming V2 Airdrop Campaign Worth +10M USD

0
[ad_1]
COTI V2 is thrilled to announce a massive 40 million token Airdrop Campaign

Web3 infrastructure leader COTI is excited to announce a significant community rewards initiative, with the platform airdropping up to 40 million COTI V2 tokens, currently worth approximately $10 million, to its Native and ERC-20 $COTI holders. The need for COTI V2 as a confidentiality layer on Ethereum has resulted in a large, vocal community of supporters, and the platform is thrilled to reward that critical support.

The COTI V2 Airdrop Campaign will begin on Monday, March 25th, 2024. The planned distribution of the COTI V2 tokens will take place in Q4 2024, shortly after the COTI V2 TGE.  All Treasury participants will automatically be included in the airdrop of 40 million tokens, whether they are holding Native or ERC-20 $COTI.

Note, that this airdrop is in addition to all APY rewards for token holders. Users simply need to have a deposit in the Treasury to participate, but those who have made deposits before February 28th 2024 will receive an additional bonus as a show of the COTI team’s gratitude for their early support.

The Airdrop rewards will be determined for each member through a combination of each deposit’s current APY, the other deposit settings including multiplier and locking period, and the amount of time and activity spent in the Treasury itself.

COTI V2 Ecosystem and Treasury

COTI has quickly become a major Web3 infrastructure developer, building the lightest and fastest confidentiality layer for the Ethereum ecosystem. The key to this data protection breakthrough is a cryptographic protocol that is derived from Garbled Circuits, allowing for the privacy of on-chain data.  This layer is secured by Ethereum’s L1, which creates the most comprehensive data privacy solution that maintains full compliance. 

This breakthrough is nothing less than the key to unlocking brand new use cases for the Web3 economy, allowing confidentiality while utilizing all the data integrity and trustless benefits of blockchain.  Web3 companies will soon build applications for decentralized identification, DeFi, private auctions, data broker analysis (while protecting data privacy), and even Artificial Intelligence applications.

QUOTE ABOUT THE AIRDROP HERE

The COTI Treasury was launched in 2022 to provide a reward structure for those wishing to deposit $COTI and earn APY in the form of $COTI and $gCOTI.  As an indication of the COTI community’s overwhelming support, members have deposited over 500 million $COTI into the Treasury. 

In addition, to support, depositors have also been drawn to the Treasury by the strength of its rewards, allowing a member to customize their desired potential APY by setting the amount to deposit, a multiplier, a lock period, and an APY boost. The team plans to extend rewards even further by offering longer lock periods of 180, 270, and 360 days starting 25 March.

This campaign is also notable because, for the first time, the community’s $COTI ERC-20 token holders without VIPER wallets can also participate in Treasury rewards, both APY and the Airdrop Campaign. 

For those who don’t have a deposit in the Treasury yet, there is still time to visit Treasury.coti.io, connect a VIPER or Metamask Wallet, and set up a deposit by selecting the amount, multiplier, lock period, and APY boost (tutorial). Those with deposits already set up in the Treasury do not need to take further action, but do have the option to extend the locking period of their deposit to earn additional rewards.

The COTI V2 Airdrop Campaign is another successful step in COTI’s roadmap toward a thriving community of developers and users who are passionate about building an ever-improving Web3 ecosystem. 

With COTI’s compliant confidentiality layer, entire new industries within Web3 can be unlocked, which will continue COTI, Ethereum, and the rest of Web3 toward mass adoption across the globe. The airdrop is a very heartfelt thank you to the community that joins in COTI’s vision, rewarding both new and long-standing members for their continued support.

About COTI

COTI is the fastest and lightest confidentiality layer on Ethereum. Powered by the breakthrough cryptographic protocol Garbled Circuits and secured by Ethereum, COTI introduces the most advanced and compliant solution for data protection on the public blockchain.

Paving the way for the next wave of Web3 innovation and adoption, COTI unlocks a whole new world of use cases, including confidential transactions, Artificial Intelligence, DeFi, decentralized identification, and more.


[ad_2]
Source link

Porsche Design HONOR Magic6 RSR & Magic6 Ultimate are official

0
[ad_1]

HONOR has announced three new devices in China, two smartphones, and a laptop. The Porsche Design HONOR Magic6 RSR is official, as is the HONOR Magic6 Ultimate. The HONOR MagicBook Pro 16 was also announced by the company.

First and foremost, the Porsche Design HONOR Magic6 RSR and Magic6 Ultimate are not the same devices as everyone though they’d be. They have different backplates. The Porsche Design variant comes with a hexagonal camera on the back, while the ‘Ultimate’ variant has a square-ish camera island on the back.

The Porsche Design HONOR Magic6 RSR is coming to global markets

The Porsche Design HONOR Magic6 RSR will launch globally, while the ‘Ultimate’ model will be sold in China only. These two devices do share the vast majority of their internals with the regular HONOR Magic6 Pro.

Both phones have a very interesting design, different than the regular Magic6 Pro. On the HONOR Magic6 Ultimate, you’ll notice a centered camera island on the back, but with a rather different shape. Its top-right and bottom-left corners are more curved than the rest. The glass on top of the cameras is also curved towards the edges. The backplate HONOR opted for here is made out of vegan leather, and it also has some additional design elements. You’ll notice that vertical line that protrudes on the back, which will hopefully help with the grip too.

The Porsche Design model has a hexagonal camera island on the back, which is also centered. It has a different vertical line than the ‘Ultimate’ model, its is more centered. The backplate is also different, HONOR didn’t use vegan leather here, but glass instead.

There is a very interesting-looking camera island included on the back

If we flip the two phones around, you’ll notice that there’s a curved display included. A pill-shaped camera cutout sits at the top of the display, and it’s centered. The front side of the phone looks basically the same as the HONOR Magic6 Pro. The internals of the two phones are very, very similar, almost identical.

There is a 6.8-inch Dual-Layer OLED Tandem Display included on the front. That panel has an adaptive refresh rate of up to 120Hz and a resolution of 2800 x 1280 pixels. The maximum brightness it can reach, technically, is 5,000 nits. This display is also Dolby Vision certified. It also has a very high 4,320Hz PWM dimming.

These handsets are IP68 certified for water and dust resistance, and the display is protected by anti-scratch NanoCrystal Shield. The Snapdragon 8 Gen 3 SoC fuels these phones, while the devices has 24GB of RAM and 1TB of storage.

A silicon-carbon battery is in use here, while blazing fast wired & wireless charging is also on offer

A 5,600mAh silicon-carbon battery sits on the inside here, while the phones support 80W wired charging. 66W wireless charging is also supported thanks to HONOR SuperCharge tech.

A 50-megapixel Super Dynamic Falcon Camera H9800 (f/1.4-f/2.0 adjustable aperture, OIS, SMA Actuator, 1/1.3-inch sensor) sits on the back. It is backed by a 180-megapixel periscope telephoto camera (f/2.6 aperture, 2.5x optical zoom, 100x digital zoom), and a 50-megapixel ultrawide unit (f/2.0 aperture, 122-degree FoV).

On the front, you’ll find a 50-megapixel ultrawide camera and a 3D ToF sensor. The phones do have advanced facial scanning, which should work perfectly even in pitch-black conditions. It did work great on the HONOR Magic6 Pro, and this is basically the same thing in a different package. Well, different packages.

Android 14 comes out of the box, with HONOR’s custom UI

Android 14 comes pre-installed here, along with MagicOS 8.0. Bluetooth 5.3 is also supported, and the phones have a set of stereo speakers. There are also two nano SIM card slots included here.

The Porsche Design HONOR Magic6 RSR and Magic6 Ultimate devices measure 162.5 x 75.8 x 8.9mm, while the Porsche Design model weighs 237 grams. The ‘Ultimate’ may be a little bit heavier, we’re still not sure. The Porsche Design variant comes in Agate Gray and Frozen Berry colors. The HONOR Magic6 Ultimate, on the other hand, comes in Ink Rock Black and Sky Purple colors.

HONOR also announced a new laptop

In addition to these two phones, HONOR also announced the MagicBook Pro 16 laptop. This laptop comes with Windows pre-installed, and it’s an “AI-powered laptop”, says the company.

It comes with the NVIDIA GeForce RTX 4060 Laptop GPU. The Intel Core Ultra 7 processor (155H) is also a part of the package. The device also has six speakers, and supports spatial audio.

That’s basically all the information that we have about it thus far.

Pricing

The Porsche Design HONOR Magic6 RSR pricing starts at CNY9,999 ($1,389) in China. The HONOR Magic6 Ultimate can be purchased for CNY6,999 ($972), while the HONOR MagicBook Pro 16 costs CNY6,199 ($861). The Porsche Design model goes on sale today in China, while it will become available globally at some point in Q2 2024.

Porsche Design HONOR Magic6 RSR:

Porsche Design HONOR Magic6 Ultimate:


[ad_2]
Source link

Fitbit by Google has been renamed to Google Fitbit

0
[ad_1]

Fitbit by Google, the wearables division under Google since 2021, seems to now be called just Google Fitbit. 9To5Google noticed the change across Google’s branding, including on fitbit.com. The logo that came before ‘Fitbit by Google’ has also been removed. This change comes amidst a massive revamp of the Fitbit store. It indicates Google is taking a more direct approach to marketing its wearables.

The rebranding comes after other changes

Google acquired the fitness tracking company Fitbit in 2021, approximately three years after first planning to. This move was made to help the tech giant make its way into the fitness wearables market. The new division was called Fitbit by Google until this recent change. It’s new name, Google Fitbit, is much more on brand with how Google usually names its products and services. Popular examples include Google Assistant, Google Play, Google TV, Google Wallet, and Google Maps.

‘Fitbit by Google’ also had a logo made of dots of varying sizes. This logo came before the name, and has also been removed from the rebranded name. Concerns were raised after Google saw lots of restructuring within its hardware departments back in January. These changes were followed by the departure of James Park and Eric Friedman, the co-founders of Fitbit.

“We remain very committed to serving our Fitbit users well, innovating in the health space with personal AI, and building on the momentum with Pixel Watch, the redesigned Fitbit app, Fitbit Premium service, and the Fitbit tracker line. This work will continue to be a key part of our new org model,” said Courtenay Mencini of Google while addressing the concerns.

What is Google Fitbit?

Google Fitbit encompasses the offerings of Fitbit, in addition to products and services offered by Google. These products include smartwatches, smart scales, trackers, and related accessories. The trackers are the main focal point of Fitbit, and what most people gravitate towards when making a purchase.

These fitness trackers help people monitor heart rate, sleep, calories burnt, steps taken, and more. They’re the perfect lifestyle partner for people who are conscious of their health, or need 24/7 monitoring for medical reasons. The smartwatches go a step further. They combine the capabilities of the trackers with the convenience of a smartwatch. These products also help monitor stress, and can be used for guided meditation, breathing exercises, and similar activities.

The rebranding of Google Fitbit indicates the company isn’t content with just letting things be. There will probably be improvements to be seen across the entire Fitbit lineup pretty soon.


[ad_2]
Source link

Turkey cracks down on Meta: interim ban on Instagram and Threads data sharing

0
[ad_1]

Meta is not having a great start of the week. Turkey’s competition watchdog implemented a temporary restriction on Meta to block the exchange of data between Instagram and Threads.

The reason is that there’s an ongoing investigation into Meta’s potential abuse of its dominant position in the market (via Reuters).

This action follows the initiation of a probe in December by the watchdog into Meta, the parent company of Facebook, for potentially breaching competition laws by linking Instagram with its newer platform, Threads.

The watchdog stated that the interim measure will be in effect until a conclusive verdict is reached, since the data obtained and merged through these two apps could “violate competition law and cause irreparable damage” in the market.

On a side note, the Turkish authority fined Meta 4.8 million lira ($148,000) daily as part of a separate investigation over a notification message that the company sends users about the sharing of data.
The notification about data sharing between the company’s Facebook, Instagram, and WhatsApp services did not provide sufficient information and was not transparent enough, it said.

The authority also noted that the manner in which the notification prompts users to consent to data sharing does not adequately mitigate concerns regarding anticompetitive behavior.


[ad_2]
Source link

Acoustic Keyboard Side Channel Attack Let Attackers Steal Data

0
[ad_1]

In recent years, personal data security has surged in importance due to digital device usage. Side-channel attacks exploit system side effects to gather information. 

Electronic emissions are a known vulnerability to such attacks. Acoustic side-channel attacks are particularly threatening. In this attack, threat actors utilize the device’s sound emissions to extract sensitive data.

Cybersecurity researchers, Alireza Taheritajar and Reza Rahaeimehr from Augusta University recently discovered a new acoustic keyboard side-channel attack that lets hackers steal sensitive data.

Acoustic Keyboard Side Channel Attack

Keyboard acoustic side-channel attacks enable threat actors to remotely capture keystroke sounds through microphones and analyze waveforms to determine sensitive information like timing and intensity.

They exploit this data despite background noise challenges, utilizing techniques like statistical analysis, machine learning, signal processing, acoustic triangulation, and Time Difference of Arrival (TDoA).

This made some past studies to limit environmental conditions or ignore irregularities that could interfere with the results. 

However, noise from the surroundings and typing habits of a user are among those factors that are often not considered though they can change how people use keys leading to variations in recognition accuracy.

number of letters on the success rate

This is further complicated by interactions between models and other attributes of emissions that do not have uniform patterns, as well as their dependence on environmental circumstances. 

It also provides an opportunity for keyboard models themselves to spoil up algorithms when altered due to special sound features.

In recent times deep learning approaches bring further complexity to obtaining consistent outcomes. 

In this paper, researchers proposed another approach aimed at eliminating these drawbacks.

It consists of capturing keystroke audio, extracting timing data, training a statistical model for prediction, testing on unknown recordings, and enhancing results with an English dictionary. 

The interface of the data gathering software (Source – Arxiv)

The proposed method analyses typing patterns so as to be able to predict words even in real environments where there is noise and without limiting the keyboard models used.

Researchers’ method assumes identifying the victim, but ours isn’t limited to specific keyboard brands.

They expect victims to work in quiet rooms, allowing noise control through signal processing. 

They gather typing samples, text, and ambient noise to train statistical models.

Analysts assume an oracle can split audio into word files, which is realistic as users often generate distinct sounds by pressing the Enter or Space keys after typing.

A Windows app written in C# by experts to record keystroke sounds under three conditions:- 

  • Users just typing
  • Researchers typing sentences
  • Developers using normal words

Different sentences and words were chosen to represent various styles and trends of English typing.

Researchers conducted an IRB-approved study to collect typing patterns from 20 adult users, ensuring confidentiality and anonymity. 

Datasets included common English words to measure word length’s impact on prediction accuracy.

Visual representation in Figure 5 shows success rates increasing with word length up to six letters, then plateauing.

The researchers are trying to reduce reliance on environmental conditions in their approach, but accurately capturing the keyboard sounds is very important for precise keystroke identification. 

Acoustic detection methods rely on the production of sufficient sound by keyboards in order to overcome challenges with softer keys that may lower the accuracy. 

The technique supposes that users maintain consistent and recognizable typing patterns when constructing datasets. 

In this way, it is possible to deduce whether a certain key was pressed or not based on the variance between different key presses on the same computer.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

E-commerce & Aviation Industries Targeted

0
[ad_1]
Dark Web Tool Arms Ransomware Gangs: E-commerce & Aviation Industries Targeted

Cybersecurity researchers have published two concerning reports where the first report highlights the surge in cyber attacks against the aviation and aerospace industries – And the second report exposes a dark web tool called TMChecker fueling attacks against E-commerce platforms.

Recent cyber incidents targeting the aerospace and aviation sectors have raised concerns about the industry’s vulnerability to malicious attacks, according to a report by Resecurity. The report highlights the critical need for strong cybersecurity risk assessments to protect airports and aviation infrastructure.

The aerospace sector, including the design, manufacturing, and maintenance of aircraft and spacecraft, has become a prime target for cyberattacks due to its reliance on interconnected digital infrastructures and global supply chains.

The integration of Industrial Internet of Things (IIoT) technologies has further strengthened this threat, making aerospace organizations more vulnerable and susceptible to cyber attacks.

Credit: Resecurity

Ransomware Attacks & The Aviation Industry

Ransomware emerges as a top threat facing the aviation industry, with a 600% increase in occurrences reported by Boeing Chief Security Officer Richard Puckett at the 2023 Aviation Week MRO Americas Conference.

The European Organisation for the Safety of Air Navigation (Eurocontrol) also highlighted ransomware as the sector’s leading attack trend in 2022, accounting for 22% of all malicious incidents. Some of the examples highlighted in the report include the LockBit ransomware gang’s attack on Boeing in November 2023, which the aviation giant later confirmed.

Geopolitical tensions & The Aviation Industry

According to Resecurity’s blog post titled “The Aviation And Aerospace Sectors Face Skyrocketing Cyber Threats,” geopolitical tensions and the designation of aerospace and aviation as critical infrastructure by the U.S. government have fueled cyberattacks targeting the industry.

Threat actors, including hacktivist collectives, are increasingly targeting aviation organizations to advance political agendas or disrupt operations. One such example is the hacktivist group Anonymous Sudan which targeted FlyDubai, an Emirati government-owned airline in Dubai, United Arab Emirates in February 2024 citing the company’s alleged support to the Rapid Support Forces (RSF) in Sudan.

Other recent cyberattacks targeting the aerospace sector include Distributed Denial of Service (DDoS) attacks by groups such as Mysterious Team Bangladesh (MTB) against Saudi Arabian airports and ALTOUFAN TEAM against Gulf Air.

Additional incidents involve ransomware attacks on airlines like Air Albania and Continental Aerospace Technologies, compromising critical data and disrupting operations.

TMChecker – Dark Web Tool Targeting Remote Access and E-Commerce Platforms

In another report published on March 13, 2024, Resecurity detailed a new cybersecurity threat named TMChecker that has surfaced on the Dark Web, posing a notable risk to remote-access services and popular e-commerce applications.

Developed by an actor known as “M762” on the Russian language XSS cybercrime forum, TMChecker is a sophisticated tool that combines corporate access login (log) checking capabilities with a brute-force attack kit. Available for a monthly subscription fee of $200, TMChecker has garnered attention for its ability to target a wide range of VPN gateways, email servers, and e-commerce platforms.

Credit: Resecurity

TMChecker stands out from similar tools like ParanoidChecker due to its focus on corporate remote access gateways, which are often primary targets for ransomware attacks and other malicious activities. The tool supports 17 solutions, including Cisco VPN, Citrix VPN, Office 365, WordPress, Magento, and cPanel, among others, making it a versatile and powerful weapon.

Cybercriminals exploit TMChecker to identify compromised data containing valid credentials for corporate VPN and email accounts. In one observed incident, threat actors used TMChecker to target the email server of a government organization in Ecuador, demonstrating the tool’s real-world impact.

M762 operates a Telegram channel with over 3,270 subscribers, potentially indicating a sizable user base for TMChecker. The addition of such tools aligns with a concerning trend highlighted in recent Microsoft research, which noted a significant increase in human-operated ransomware attacks.

These attacks often involve the abuse of remote monitoring and management tools, leaving behind less evidence compared to automated attacks delivered through malicious documents.

As TMChecker and similar tools lower the barriers to obtaining remote access credentials, the risk of destructive ransomware attacks and other malicious campaigns amplifies. This threat is particularly acute in the context of mergers and acquisitions, where cybercriminals target vulnerable organizations to exploit for financial gain.

  1. Cl0p ransomware gang hits Aviation giant Bombardier
  2. Hackers Uncover Airbus EFB App Flaws, Risking Aircraft Data
  3. Israeli: Hackers Targeted EL AL Flights in Mid-Air Hijack Attempt
  4. Military Satellite Access Sold on Russian Hacker Forum for $15,000
  5. Hackers posing as LinkedIn recruiters to scam military, aerospace firms

[ad_2]
Source link

Price tag of Samsung’s budget foldable seemingly revealed

0
[ad_1]

Samsung is allegedly planning to launch a budget foldable later this year, and its price tag has seemingly been revealed. The device in question is the so-called Galaxy Z Fold 6 FE, which is expected to launch alongside the Galaxy Z Fold 6 in July.

The price tag of Samsung’s upcoming budget foldable has seemingly been revealed

Having said that, a report from Sisa Journal, a Korean publication, claims that the company’s smartphone will cost $800. That’s at least the price tag that Samsung is targeting.

It is also noted that the device will have inferior specifications than the flagship model. To be more specific, it will have an inferior SoC, display, battery, and some other components. The camera specs will be similar to the flagship model, it is noted.

Just to be perfectly clear, the Galaxy Z Fold 6 FE name has not been confirmed, not at all. Samsung’s budget book-style foldable was mentioned a number of times in the last couple of weeks, though.

The ‘Ultra’ model was also mentioned, but that’s not happening, it seems

First, we’ve heard about the Galaxy Z Fold 6 Ultra, but that phone will not be launching after all, it seems. The Galaxy Z Fold 6 and Galaxy Z Fold 6 FE are expected, in addition to the Galaxy Z Flip 6.

A budget clamshell model was not mentioned, this budget foldable is expected to be a book-style foldable. It will be interesting to see what corners will Samsung have to cut in order to reach such a price tag.

An $800 price tag for a book-style foldable would be a true feat for Samsung. That’s basically half the price of the Galaxy Z Fold 5 (at launch). Well, it’s even less than half, as the Galaxy Z Fold 5 was priced at $1,799 at launch.

That price tag even seems a bit unrealistic to us, unless the source was referring to a clamshell foldable, which is probably not the case. It remains to be seen.


[ad_2]
Source link

Former telecom manager pleaded guilty to running SIM swapping scheme

0
[ad_1]

A former telecommunications company manager in New Jersey confessed to involvement in a SIM-swapping scheme. This scheme granted hackers access to sensitive customer data, including emails and social media accounts.

Hackers employ a variety of tactics to breach a victim’s device, one of which is SIM swapping. In simple terms, SIM swapping is a process where an individual, often within the telecommunications company, replaces the targeted phone number with another physical SIM card or eSIM chip under the control of the malicious actor.

The former telecom manager enabled hackers to access the victim’s device through SIM swapping

Hackers might also target customer support agents to perform unauthorized SIM swapping. After a SIM swapping, hackers can read the victim’s SMS to access the one-time passwords sent by two-factor authentication systems.

In this case, Jonathan Katz, aka “Luna,” was the manager of a telecommunications company in Burlington County, New Jersey, who had unauthorized access to a protected computer. He allegedly could access several customers’ accounts via his managerial credentials between May 10 and 20, 2021.

So far, five of Katz’s victims have been detected in Wyoming, New Jersey, California, and Tennessee. He reportedly received $1,000 in Bitcoin per SIM swap and made around $5,000. The hackers could access the victims’ cryptocurrency accounts after SIM swapping, and Katz could have profited from that, too.

“In May 2021, Katz was employed as a manager at a telecommunications store and accessed several customer accounts by using managerial credentials.” the U.S. Department of Justice added. “Katz swapped the SIM numbers associated with the customers’ phone numbers into mobile devices controlled by another individual, enabling this other individual to control the customers’ phones and access the customers’ electronic accounts – including email, social media, and cryptocurrency accounts.”

According to the court order, Katz is sentenced to five years in jail. He should also pay a fine of up to $250,000 or twice the financial gain or loss from the crime.


[ad_2]
Source link

YouTube Music makes finding songs easier with a built-in song recognition feature

0
[ad_1]

YouTube has recently claimed the top spot as the leading streaming service in America. But that is not all, as YouTube Music and YouTube Premium surpassed 100 million subscribers worldwide not long ago. Despite its growing user base, YouTube Music faces tough competition from established platforms like Apple Music and Spotify. However, with each new feature, it aims to carve out a larger share of the market. According to 9to5Google, a new feature enabling song recognition is currently being rolled out to YouTube Music. To use it, you need to first tap the search icon in the top-right corner. Additionally, there is a dedicated button bearing the same icon design as the song search feature on YouTube, positioned next to the voice search option for quicker access.

On YouTube’s main app, the song search feature is available for a while now on Android. To use it, just start a search and tap the “Song” tab instead of “Voice.” Similar to “Hum to Search” in Google Search, you can play, sing, or hum the song you’re looking for. YouTube uses AI to match the sound to the original recording. 


The good news is, unlike YouTube, some YouTube Music users on iOS already have this capability, too, meaning it won’t be exclusive to Android.While both YouTube and YouTube Music come from Google, they have different functions. YouTube is a platform where you can find all sorts of videos, including music videos, movies, tutorials, vlogs, etc. Meanwhile, YouTube Music is solely for streaming music and podcasts.

With that said, it’s logical for the YouTube Music app to include this feature, especially if it aims to compete with others on the market. While Apple Music or Spotify, for instance, don’t offer a built-in feature to recognize songs by humming or listening to them, they both integrate with Shazam.

After all, since Apple owns the popular song identification app, it would be odd not to integrate it with its music streaming service. Once Shazam identifies a song, it offers the option to listen to it on Apple Music. This integration works similarly with Spotify as well.


[ad_2]
Source link