Microsoft points to Google’s dominance in the AI market

0
[ad_1]

Currently, the EU is investigating top tech brands to see if they are in violation of anti-competitive practices pertaining to AI. Obviously, brands under the EU’s eye consist of Microsoft, Google, and other large companies. Well, it appears that Microsoft wanted to tattle, and pointed to Google’s dominance in the AI market.

Right now, we are still learning about the potential impacts of big brands on AI. This is still uncharted territory, but we’ve seen some scary things happen so far. For example, a new report states that publishers could stand to lose up to $2 billion in ad revenue thanks to Google’s Search Generative Experience. This is the AI tool that generates text-based responses to Google searches. It allows searchers to forego clicking on links and get their answers immediately.

Microsoft points to Google’s dominance in the AI market

Right now, it seems that Microsoft wants to take some of the heat off of itself and throw some on to other companies. This should come as no surprise, as the EU has been extremely strict and proactive about regulating competition and mitigating the risks of AI technology. So, if the EU is not happy with the way a company is operating, it will take action.

Microsoft submitted a report to EU antitrust regulators and talked about how Google’s access and business structure gives it an unfair advantage in the AI market compared to Microsoft. “Today, only one company – Google – is vertically integrated in a manner that provides it with strength and independence at every AI layer from chips to a thriving mobile app store. Everyone else must rely on partnerships to innovate and compete,” the company said in the report.

This argument definitely holds weight, as Google has access to a metric ton of data from users. It is an ad company that is not shy about scooping up consumer data. Also, it owns the rights to YouTube which is another massive source of data. This, and other factors, means that Google is well-positioned to be the top AI brand.

Microsoft also takes shots at Apple

It appears that Google isn’t the only company under Microsoft’s crosshairs. In the report, Microsoft also pointed to Apple. Apple has not made any palpable moves in the generative AI space as of yet. However, it appears that Microsoft wants to think ahead. In talking about Google, Microsoft referred to the fact that both it and Apple have voice assistants Google Assistant and Siri.

However, Microsoft did have a voice assistant back in the day called Cortana (it’s just that no one cared about it). So it’s a little bit weird on Microsoft’s part to point out its competitor’s voice assistants when it wanted to have the same thing.

Defending its partnership with OpenAI

Right now, the EU is locked on Microsoft, as the company has invested roughly $13 billion into OpenAI. That could possibly be seen as an anti-competitive move on the company. This is because not many other companies have the funds to invest such a substantial amount of money into a large AI startup. So, this could be seen as Microsoft throwing its weight around.

However, Microsoft defended its stance on partnerships such as these. In defending itself, Microsoft referred to Google’s and Amazon’s investment into Anthropic. This is a leading AI company, having just released Claude 3. Also, it referred to Canada’s Cohere (which received funding from Salesforce and Nvidia) and Mixtral (which received €15 million from Microsoft).

“All of these start-ups relied on different forms of investments and partnerships that enabled them to enter and expand in the space,” Microsoft said in the statement.

The company is saying that Microsoft’s investment into OpenAI is not anti-competitive, as startups like these basically depend on investments in order to thrive. Microsoft definitely has a point there, as developing AI technology is not a cheap endeavor whatsoever. Training tons of AI data to create AGI (artificial general intelligence) absolutely burns through money.

Microsoft helps that this will take some of the heat off of it, as competition  in the AI market is set to heat up in the coming years


[ad_2]
Source link

RA World Ransomware Exploits Group Policy infrastructure

0
[ad_1]

The RA World ransomware, previously known as the RA Group, has been a significant threat to organizations worldwide since its emergence in April 2023.

Focusing on the healthcare and financial sectors, ransomware has predominantly targeted entities in the United States while also affecting organizations in Germany, India, and Taiwan.

Industries affected by RA World ransomware based on the group’s leak site
Industries affected by RA World ransomware based on the group’s leak site (source: Trend Micro)
Countries affected by RA World ransomware based on the group’s leak site
Countries affected by RA World ransomware based on the group’s leak site (source: Trend Micro)
Document

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

Initial Access: The Entry Point

RA World operators commence their attack by compromising domain controllers and deploying their malicious components into the SYSVOL share path for a machine Group Policy Object (GPO), setting the stage for a widespread attack within the organization’s network.

The RA World attack chain
The RA World attack chain (source: Trend Micro)

The attackers leverage a PowerShell script to execute Stage1.exe, indicating a modification in Group Policy settings to allow such actions.

This strategic placement within the Group Policy infrastructure suggests deliberate tampering to include the malicious payload, enabling its execution across multiple machines during Group Policy processing.

Lateral Movement: Spreading Across the Network

Stage1.exe plays a crucial role in identifying and validating domain controllers, setting conditions for further actions based on the presence of specific files, and proceeding to deploy Stage2.exe across the network.

Stage1.exe checks if the conditions are met before proceeding
Stage1.exe checks if the conditions are met before proceeding (source: Trend Micro)

This step signifies a targeted attack strategy, emphasizing the use of Group Policies for spreading the ransomware.

A recent analysis by the Trend Micro threat hunting team has unveiled a sophisticated multistage attack targeting healthcare organizations in Latin America. The attack showcases the group’s methodical approach to maximizing the impact of its operations.

The global attack of RA World Ransomware Cyber Alert has increased, as reported by Ensar Seke – a cyber researcher, in a recent tweet.

Persistence and Defense Evasion Techniques

The attackers ensure their presence within the compromised system by creating a new service and manipulating the Boot Configuration Data (BCD) to enable Safe Mode with Networking.

These actions and registry modifications highlight the ransomware’s ability to persist and evade detection.

Upon successful deployment, Stage3.exe encrypts data and drops a ransom note, employing extortion tactics by listing recent victims unable to pay the ransom.

This stage underscores the ransomware’s ultimate goal: To coerce payment from its victims.

Anti-AV Measures and System Manipulation

RA World operators deploy scripts to disable antivirus measures and manipulate system settings, including wiping specific directories and removing Safe Mode options. This culminates in a forced system reboot.

These actions demonstrate the ransomware’s comprehensive approach to evading detection and ensuring its payload’s effectiveness.

The RA World ransom note
The RA World ransom note (source: Trend Micro)

The leakage of Babuk ransomware’s source code has facilitated the emergence of new threat actors, including RA World.

This incident highlights the ongoing challenges in the cybersecurity landscape, where source code leaks enable less technically skilled criminals to launch sophisticated ransomware attacks.

Recommendations and Solutions for Organizations

To mitigate the risk of ransomware attacks, organizations are advised to employ best practices such as limiting administrative rights, updating security products, conducting regular backups, and educating users on potential threats.

A multi-layered security approach, including solutions like Trend Vision One™ and Trend Micro Apex One™, can significantly enhance an organization’s defense against such threats. 

This article synthesizes the provided information into a structured news piece.

For actual images and references, one would typically include links to reputable sources or embed pictures directly related to the content, such as screenshots of the ransomware’s notes or graphical representations of its attack chain.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

AI-Powered Scams, Human Trafficking Fuel Global Cybercrime Surge: INTERPOL

0
[ad_1]
AI-Powered Scams, Human Trafficking Fuel Global Cybercrime Surge: INTERPOL

AI tech fuels surge in financial fraud and cybercrime, warns INTERPOL. Sophisticated scams and human trafficking rings exploit cryptocurrency and social engineering to steal billions. Urgent global action is needed to combat this growing threat.

In its latest assessment of global cybercrime and financial fraud, INTERPOL has rung the alarm on the rapidly increasing threat posed by growing sophisticated criminal operations leveraging technology.

The report reveals a difficult-to-face reality: the emergence of Artificial Intelligence (AI), large language models, cryptocurrencies, and service-based fraud models like phishing and ransomware are empowering a surge in fraudulent activities worldwide.

Advanced technologies have enabled organized crime groups to carry out professional and complex fraud campaigns with minimal technical expertise and cost previously required. The emergence of malicious AI-powered chatbots like WormGPT and FraudGPT are a few such examples.

Notably, the report highlights the expansion of human trafficking networks involved in call center operations, particularly in executing hybrid scams such as ‘pig-butchering‘ schemes, which blend elements of romance and investment frauds while exploiting cryptocurrencies.

Secretary General of INTERPOL, Jürgen Stock, expressed serious concern over the epidemic of financial fraud, emphasizing the devastating impact on individuals, businesses, and even governments. He emphasised the urgent need for coordinated action to close existing loopholes, enhance information-sharing mechanisms, and encourage a global response to combat this threat.

Key findings from the report highlight the pervasive nature of financial fraud, with prevalent trends including investment fraud, advance payment fraud, romance fraud, and business email compromise. Furthermore, financial fraud typically involves networks of co-offenders, varying from highly organized to loosely affiliated groups.

To address the growing menace of financial fraud, the report advocates for the establishment of multi-stakeholder Public-Private Partnerships to trace and recover lost funds.

Notably, since the launch of INTERPOL’s Global Rapid Intervention of Payments (I-GRIP) mechanism in 2022, over USD 500 million in criminal proceeds have been intercepted, primarily originating from cyber-enabled fraud.

Regional trends outlined in the report shed light on the evolving nature of financial fraud across continents:

Africa: Business Email Compromise (BEC) remains prevalent, with emerging trends in ‘pig butchering’ fraud. West African criminal syndicates are expanding transnationally, exhibiting expertise in various forms of online financial fraud.

Americas: Fraud types include impersonation, romance, tech support, advance payment, and telecom fraud. Human trafficking-driven fraud is on the rise, with syndicates exploiting victims coerced into committing financial crimes.

Asia:Pig butchering‘ fraud schemes have proliferated, alongside telecommunication frauds where perpetrators impersonate officials to deceive victims. Criminal organizations in Asia are adopting business-like structures to facilitate fraudulent activities.

Europe: Online investment frauds and phishing schemes are escalating, targeting selected individuals and exploiting mobile phone apps. Criminal networks involved exhibit sophisticated modi operandi, often combining multiple fraud types.

In response to the news, we reached out to Oliver Spence, CEO of Cybaverse who emphasised the importance of employee training, of not ignoring the threats and tackling them before it is too late.

“This news from Interpol should not be taken lightly by organisations and clearly, financially motivated cybercrime is on the rise, and generative AI tools are heightening the problem while lowering the technical barrier of entry into cybercrime.

“To counter the threat, employees need to be trained about AI-generated phishing scams and taught to question emails, even when they seem realistic. Organisations must bolster this with email security solutions that can detect malicious code embedded into emails, so they can be stopped before reaching user inboxes, he advised.

As financial fraud continues to evolve and increase globally, the INTERPOL report goes on to highlight the urgent need for collaborative efforts to stem this growing epidemic and protect vulnerable individuals and entities from exploitation.

  1. INTERPOL Dismantles ’16shop’ Phishing-as-a-Service Platform
  2. Interpol Nets $300M, Arrests 3,500 in Major Cyber Crime Bust
  3. US government seizes classified advertising website Backpage
  4. Utilizing Programmatic Advertising to Locate Abducted Children
  5. Operation Narsil – INTERPOL Busts Decade-Old Child Abuse Network

[ad_2]
Source link

Beeper’s redesigned messaging app for Android is here

0
[ad_1]

You might have heard of the Beeper Mini app, which had added support for iMessage in Android. However, the time wasn’t in its favor and Apple officially banned it later. They have launched a new messaging app for Android with a complete redesign and many new features. The new Beeper messaging app will be entirely different from the previous app they had, it’s redesigned.

Beeper opens beta testing for its new, redesigned messaging app

The new Beeper for Android is finally here and all the eligible beta testers have already started getting access to the app. As mentioned earlier, this new application completely differs from their previous messaging app, and hence, users need to freshly download the app. If you use the older application, then you must uninstall it before installing the newer app.

Android users can download the new Beeper app straight from the Google Play Store. Although it shares the same foundation as the Beeper Mini, the entire user interface has been redesigned to make it appear more in line with the Android OS. If you start using the app, you will notice a lot of changes; from its design to speed and the overall functionality.

Local caching of chats has reduced the overall load time. Not only this, the user can now directly link the app from the desktop version of the application using the Android’s QR scanner. The app now has the support for Android’s renowned chat bubbles feature. The Beeper Mini didn’t have the support for RCS services, but it’s unclear whether they will add it in the new app or not.

Beeper has also optimized it for the bigger screen devices as it now has dual panel support for foldable, tablets and ChromeOS devices. The native search is now universal, which means you can directly search across all the connected services. Also, the brand has said that the app will become paid in the future and they are all set to introduce subscription-based plans as well.

There’s no iMessage support this time

Beeper Mini was famous for having native support for iMessage. But with the newer application, Beeper has eliminated the support of iMessage in the app. Even though the app is still in beta and the brand claims that they are going to add more features in the coming weeks, it is kind of confirmed that they are not going to bring the iMessage support this time. That makes some sense, as they don’t want to find themselves in a difficult circumstance once more.


[ad_2]
Source link

Samsung to get $6 billion chip grant from the US, TSMC $5 billion

0
[ad_1]

Samsung may get a massive grant from the US government to expand its semiconductor facilities in the country. The Joe Biden administration plans to award more than $6 billion to the Korean firm to fund its expansion projects. The company already has a chip factory in Austin, Texas, and is building another in Taylor, Texas. TSMC, which is also constructing its second chip plant in the US, will get a $5 billion grant.

US government to give Samsung $6 billion for chip plants

Samsung is one of the world’s largest semiconductor companies and the second-biggest foundry after TSMC. Along with designing, developing, and manufacturing chips in-house, it also manufactures chips designed by other fabless firms such as Qualcomm. The company operates three manufacturing facilities in its homeland, South Korea, and one in the US (Austin). The Taylor plant may be operational in 2025.

In recent years, the US government has been encouraging semiconductor firms to expand production in the country. As part of the CHIPS and Science Act, it is offering $52.7 billion to companies for American semiconductor research, development, manufacturing, and workforce development, including $39 billion in direct grants. Samsung, TSMC, and other industry players have all applied for grants under this act.

Bloomberg recently reported that Samsung will get more than $6 billion while TSMC will receive over $5 billion. According to the publication, which cites anonymous people familiar with the matter, this is a preliminary agreement. The final decision is yet to be made, so the amount may vary. Both firms should still get a huge sum of money from the US government. An official announcement may follow soon.

Intel may get a bigger grant

Samsung and TSMC’s American rival, Intel, may get a bigger sum of money from the US government. The firm is reportedly set to receive over $10 billion in grants and loans. It may also take home an additional $3.5 billion in grants for the production of military chips. Intel had opposed the idea of providing grants to foreign companies from the US taxpayers’ money.

These grants will certainly help boost the US semiconductor supply chain in the future. Samsung’s upcoming plant in Taylor was originally estimated to cost $17 billion but may end up costing $25 billion. A help of $6 billion from the US government would be huge. TSMC, which has a chip plant in Washington, is investing $40 billion in its upcoming factory in Phoenix, Arizona. Originally slated to be operational in 2026, it has been delayed to 2027 or 2028.


[ad_2]
Source link

RedLine Malware Tops Charts by Hijacking 170M+ Passwords

0
[ad_1]

The cybersecurity landscape has been shaken by the discovery that a single piece of malware, known as RedLine, has stolen over 170 million passwords in the past six months.

This alarming statistic has placed RedLine at the forefront of cyber threats, accounting for nearly half of all stolen credentials analyzed during this period.

Darren James, the Senior Product Manager at Specops, commented on the research outcomes, stating:

“It’s quite remarkable that a single strain of malware has been implicated in the theft of almost 50% of the passwords we’ve examined.

Document

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

Our analysis reveals that Redline malware has emerged as the preferred tool among hackers for password theft, amassing an astonishing 170 million compromised credentials within six months.”

Specopssoft has released a report outlining the most commonly used malware techniques hackers employ to steal user passwords.

most popular credential thieves
most popular credential thieves

Top three password-stealing malware:

Redline: The Premier Password Pilferer

Overview and Discovery
Redline, identified in March 2020, has quickly become a highly favored tool among cybercriminals for its proficiency in extracting personal information.

Its primary objective is to siphon off credentials, cryptocurrency wallets, and financial data and subsequently upload this stolen information to the malware’s command-and-control (C2) infrastructure.

Redline often comes bundled with a cryptocurrency miner, targeting gamers with high-performance GPUs for deployment.

According to a recent tweet by ImmuniWeb, Redline malware has been identified as the primary credential stealer over the past six months.

Distribution Techniques

The malware employs diverse distribution methods, with phishing campaigns taking the lead.

Cybercriminals have adeptly utilized global events, such as the COVID-19 pandemic, as bait to entice unsuspecting individuals into downloading Redline.

From mid-2021, an innovative approach involving YouTube has been observed:

  • Initially, a Google/YouTube account is compromised by the threat actor.
  • The attacker creates various channels or uses existing ones to post videos.
  • These videos, often promoting gaming cheats and cracks, include malicious links in their descriptions, cleverly tied to the video’s theme.
  • Unsuspecting users clicking these links inadvertently download Redline, leading to the theft of their passwords and other sensitive information.

Vidar: The Evolving Threat

Genesis and Operation
Vidar, a sophisticated evolution of the Arkei Stealer, scrutinizes the language settings of infected machines to selectively target or exclude specific countries.

It initializes necessary strings and generates a Mutex for its operation.

Vidar is available in two versions: the original, Vidar Pro, and a cracked version known as Anti-Vidar, distributed through underground forums.

Distribution Channels

In early 2022, Vidar was detected in phishing campaigns disguised as Microsoft Compiled HTML Help (CHM) files.

It has also been distributed via various malware services and loaders, including PrivateLoader, the Fallout Exploit Kit, and the Colibri loader.

By late 2023, the GHOSTPULSE malware loader was observed as a new distribution method for Vidar.

Raccoon Stealer: Malware-as-a-Service

Introduction and Sales Model

Raccoon Stealer, first seen on the cybercriminal market in April 2019, operates on a malware-as-a-service model.

This allows cybercriminals to rent the stealer every month.

It debuted on the prominent Russian-language forum Exploit, boasting the slogan “We steal, You deal!”

Market Presence

The malware has been primarily marketed on Russian-language underground forums, including Exploit and WWH-Club.

In October 2019, it expanded its reach to the English-speaking segment of the cybercriminal underworld via Hack Forums.

The promoters of Raccoon Stealer occasionally offer “test weeks,” suggesting that potential customers can try the product before making a purchase.

The research underscores the risks associated with password reuse, a familiar yet dangerous practice.

Even with robust password policies, reused passwords can be compromised on insecure sites and devices, posing a significant threat to organizational security.

Studies by Bitwarden and LastPass have highlighted the prevalence of password reuse despite widespread awareness of its risks.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Massive Data Breach Exposes Info of 43 Million French Workers

0
[ad_1]
Massive Data Breach Exposes Info of 43 Million French Workers

A massive data breach at a French employment agency is affecting over 43 million users – representing more than half of France’s total population.

A large-scale data breach has compromised the personal information of a staggering 43 million French workers, raising concerns about identity theft and fraud. The attack is believed to have impacted around two-thirds of France’s population. The unclaimed cyberattack targeted two French employment agencies France Travail and Cap Emploi.

On March 13, 2024, French employment agency France Travail, previously called Pole Emploi, announced becoming the victim of a data breach that exposed the personal data of their registered users. This includes names, social security numbers, dates of birth, email, postal addresses, phone numbers, and user IDs.

France Travail named another company Cap Emploi, a government employment service supporting people with disabilities, as the victim of this breach. France Travail confirmed that login credentials, passwords, and bank details are not at risk. 

On March 8, the agency notified the Commission Nationale de l’Informatique et des Libertés (CNIL), the national data protection agency, and filed a police complaint after which a formal investigation was launched.

Initial probing by the Paris Public Prosecutor’s Office and the Cybercrime Brigade of the Paris Judicial Police Department revealed that a malicious actor gained unauthorized access to Cap Emploi’s systems on February 6, impersonating a Cap Emploi civil service officer. France Travail began noticing suspicious activity within its IT systems between 6 February and 5 March 2024. 

According to CNIL, a cyberattack on France Travail (francetravail.fr) could have potentially exposed data of those currently registered on the job seekers list, those registered over the last 20 years, and those with a candidate space on the platform. The company will notify impacted users individually.

The French cybersecurity community has criticised France Travail’s security shortcomings, with some professionals surprised that the agency took around a month to notify authorities and 20 years of users’ data being accessible online.

While it is legally required to keep users’ data for a certain period, storing the oldest part in a secure backup repository is generally recommended. The CNIL has now initiated an investigation to assess the company’s compliance with data security measures with the EU’s General Data Protection Regulation (GDPR).

Interestingly, ethical hacker Olivier Laurelli (aka Bluetouff) attempted to publicly notify France Travail of security flaws in the agency’s new web application in February without receiving a response. The French government has warned of potential cyber threats, including phishing, scams, and identity theft, following the data breach.

CNIL is urging French workers to remain vigilant and be cautious of any suspicious communication. They recommend monitoring bank statements closely for unusual activity and considering placing a fraud alert on credit reports. 

This massive data breach comes as a significant blow to France’s reputation for data security, highlighting the need for stricter regulations and improved cybersecurity practices within French companies, particularly those handling sensitive employee data.

Expert Comments

For insights into the data breach, we reached out to Nick Tausek, Lead Security Automation Architect at Swimlane who added, “The scale of this latest breach surpasses previous incidents, highlighting the ongoing challenges faced by governmental agencies entrusted with safeguarding the personal data of millions.”

“To mitigate against these threats, organizations need to adopt a proactive cybersecurity approach. Investing in security platforms that centralize investigation and detection through the use of automation will allow security teams to respond to threats in real time and gain visibility across the SOC,” Nick advised.

  1. Air France website hacked by ‘Algerian Mujahideen’ Hackers
  2. France Weather Forecast Website Hacked By Anti-War Hacker
  3. Franch newspaper exposed 8TB of data with 7.4 billion records
  4. France Believes Russia Hacked TV5Monde Posing as ISIS Hackers
  5. Death linked to prank – France seeks extradition of hacker from Israel

[ad_2]
Source link

Motorola Edge 50 Fusion is also coming, here are its specs

0
[ad_1]

In addition to the Motorola Edge 50 Pro, the Motorola Edge 50 Fusion is also coming, and its specs have just been shared. The specifications of this handset have been shared by Evan Blass, a well-known tipster.

We’ve exclusively shared renders of the Motorola Edge 50 Pro not long ago. On the screen, April 4 was highlighted as the date, which suggested that the phone will launch on April 4. Yesterday, Motorola started sending out invites for the April 3 event in India.

The Motorola Edge 50 Fusion is coming, and its specs have also surfaced

As we’ve mentioned in that article, it’s possible that the Motorola Edge 50 Pro will launch under a different name, and then arrive to global markets a day later. The Motorola Edge 50 Fusion could launch alongside it, or instead of it, though.

The Motorola Edge 50 Fusion is codenamed ‘Cusco’, says Evan Blass. The device will feature a 6.7-inch POLED display, and it will be fueled by the Snapdragon 6 Gen 1 SoC. This handset will be a lot more affordable than the Motorola Edge 50 Pro, that’s for sure.

The phone is also said to include a 5,000mAh battery and supports 68W wired charging. The tipster also says that it will include 256GB of internal storage and a 50-megapixel main camera on the back. A 32-megapixel selfie camera was also tipped.

It’s coming in three color variants, and two backplate options

This phone’s display will be protected by the Gorilla Glass 5, and the phone will also come with an IP68 certification for water and dust resistance. The Motorola Edge 50 Fusion is coming in Ballad Blue, Peacock Pink, and Tidal Teal colors.

The Ballad Blue color variant will feature a vegan leather backplate. The two other color models will presumably come with a glass backplate.

It seems like we’ll be seeing at least two Motorola smartphones launch during the event. We’re just not sure if the ‘Fusion’ model will be limited to India or not.


[ad_2]
Source link

Apple finds another way to block Spotify’s app in the EU

0
[ad_1]

Although the Digital Markets Act came into force on November 1, 2022, some gatekeepers designated by the European Commission had until March 2024 to comply with the new regulations.

Apple, Alphabet, Meta, Microsoft, Amazon, and ByteDance are the six important companies that had extra time to make all the necessary changes to their business models to comply with the new set of rules and obligations.

Unfortunately, even after being fined some of these companies are trying to delay the inevitable. Apple was recently hit with a $2 billion fine in the EU over complaints from Spotify about its App Store rules.

But that didn’t seem to convince Apple that the EU is serious about the DMA, so the Cupertino giant decided to find another way to prevent Spotify from informing customers about the prices of its services, nor to allow customers to purchase subscriptions directly from the provider of the services.

In an email to the European Commission obtained by The Verge, Spotify complains that Apple has “neither acknowledged nor responded to Spotify’s submission,” thus preventing the streaming company from updating the app for its users.

The Spotify app update that was submitted to Apple on March 5, but hasn’t been approved nor rejected by the latter.

According to Spotify, Apple claims that they turn around reviews and app submissions within 24 hours, so the fact that the update that was submitted nearly 10 days ago basically means that Apple is trying to circumvent the European Commission’s decision.

This is not the first time that Apple defies the Digital Markets Act. The company revoked Epic Games’ developer license after a tweet posted by CEO Tim Sweeney criticizing Apple.

Thankfully, Epic Games got back its developer license only a few days later after the European Commission reviewed the case.


[ad_2]
Source link

Google Chrome to Roll Out Real-time Phishing Protection

0
[ad_1]

Google has announced an upgrade to its Safe Browsing technology to provide Chrome users with real-time protection against phishing, malware, and other malicious sites.

This enhancement is set to revolutionize how users navigate the web, ensuring safety without compromising privacy.

For over 15 years, Google Safe Browsing has been a bulwark against online threats, safeguarding users across more than 5 billion devices worldwide.

However, the rapid evolution of online threats necessitates a more dynamic approach to protection.

Google’s latest update to Safe Browsing introduces real-time URL checks in Chrome’s Standard protection mode, a feature designed to adapt as swiftly as the threats it aims to counter.

Document

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

The Current Threat Landscape

Traditionally, Chrome has protected users by comparing visited sites against a locally stored list of known unsafe sites, updated every 30 to 60 minutes.

Hash-based check overview
Hash-based check overview

However, this method struggles against the fleeting nature of modern malicious sites, which may exist for less than 10 minutes.

The introduction of real-time, privacy-preserving URL protection aims to close this window of vulnerability.

How Real-time Protection Works

The new system enhances security by checking URLs against a constantly updated list on the Safe Browsing server, capturing malicious sites as soon as they’re identified.

This process involves several privacy-preserving steps:

  1. URL Obfuscation: Chrome converts the URL into truncated, encrypted hash prefixes.
  2. Privacy-Preserving Checks: These encrypted hashes are sent to a privacy server, which anonymizes the data before forwarding it to the Safe Browsing server.
  3. Real-time Response: The Safe Browsing server matches these hashes against its database, alerting Chrome to any threats.
Real-time check overview
Real-time check overview

This method ensures that Google does not see the user’s IP address, and the privacy server, operated by Fastly, cannot decrypt the URL hashes, maintaining user privacy throughout the process.

Staying Speedy and Reliable

Despite the additional step of real-time checks, Google has implemented several measures to maintain a smooth browsing experience.

These include caching known-safe URLs and employing a fallback mechanism for slow or unsuccessful requests, ensuring that browsing remains fast and reliable.

For Chrome Users

With the latest Chrome update, users will automatically benefit from real-time phishing protection in Standard protection mode without needing to share their browsing history with Google.

Enhanced protection mode for Safe Browsing
Enhanced protection mode for Safe Browsing

The real-time protection feature is enabled by default for Chrome users, including enterprise environments.

For the feature to function correctly, enterprises may need to configure their networks to allow traffic to the Fastly privacy server.

Additionally, Google plans to extend these protections to developers through the Safe Browsing API for non-commercial use, further expanding the ecosystem of secure web browsing.

Google’s introduction of real-time phishing protection in Chrome significantly advances online security.

By leveraging privacy-preserving technology, Google ensures users enjoy a safer browsing experience without sacrificing speed or privacy.

As the digital threat landscape continues to evolve, these enhancements to Safe Browsing demonstrate Google’s commitment to staying ahead of malicious actors and safeguarding the web for everyone.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link