As we get closer to Google’s launch event on August 13, we’re starting to see more and more leaks coming out. Including a set of promo images that Onleaks and 91Mobiles have just put out, for the entire Pixel 9 lineup.
These promo images confirm that there will be a Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL and a Pixel 9 Pro Fold – two of which, Google themselves have already confirmed. The Pixel 9 will sport a 6.3-inch display, with the Pro models coming in 6.3 and 6.9-inch sizes, and of course the Pixel 9 Pro Fold will have a 6.3-inch and a 8-inch display. These were all confirmed yesterday, in other leaks.
The entire lineup will also sport the Tensor G4 chipset, with 16GB of RAM across the board – with the exception of Pixel 9, which will be 12GB. The Pixel 9 Pro models are getting a whopping 42-megapixel front-facing camera, while the Pixel 9 gets a 10.5-megapixel and the Pixel 9 Pro Fold is sporting a 10-megapixel front-facing camera. The Pixel 9 Pro will also stick with the same cameras as the Pixel 8 Pro, which includes a 50MP primary, 48MP ultrawide, and a 48MP telephoto camera. Meanwhile, the Pixel 9 has a 50MP primary and a 48MP ultrawide. Finally, the Pixel 9 Pro Fold has a 48MP main camera, a 10.5MP ultrawide, and a 10.8MP telephoto.
Google Pixel 9 is “designed for AI”
In Google’s marketing material it is also claiming that the Google Pixel 9 is designed for AI, which should come as no surprise since this Google. And it’s also 2024 so everything is designed for AI. Google is providing Pixel 9 users with Gemini Advanced included at no extra cost, for 12 months. There’s also a new feature called “Pixel Screenshots,” which will help “you save info that you want to remember later – like events, places, and more.” It’s sort of like Microsoft’s controversial Recall feature, but more watered down.
As expected, the Pixel 9 series will also be receiving seven years of updates, similar to the Pixel 8, Galaxy S24, Galaxy Z Fold 6 and Galaxy Z Flip 6. Finally, the new Pixels also get EMergency SOS, which will send you crisis alerts about nearby fires or floods. Google also claims that this can thrwart malware and phishing scams.
This is shaping up to be a pretty big launch by Google, if not the biggest launch that the Pixel brand has ever seen.
In June, Chargeasap launched the Zeus 280W USB-C GaN Charger as a minor upgrade over its 270W GaN (gallium nitride) charger. It is the world’s first and smallest 280W charger yet. The upgraded power brick features four output ports — three USB-C and one USB-A — and a built-in OLED display that shows real-time charging speeds for each port separately. You get up to 140W of charging from one port. The firm supplies the charger with four different plugs (with interchangeable converters), ensuring a perfect fit in the wall socket everywhere. In this review, we look deeper into the Chargeasap 280W Charger’s everyday performance, portability, build quality, and other features.
Table of contents
Chargeasap 280W Charger Review: Hardware & Design
Chargeasap’s Zeus 280W USB-C GaN Charger is a massive power brick. It has a dimension of 89 x 59 x 44mm/3.5 x 2.32 x 1.73 inches and weighs 380 grams/0.83 pounds. While it feels relatively compact for what it offers, its weight doesn’t go unnoticed. It’s the first thing you’ll notice after taking the charger out of its box. The power brick is a bit too heavy to carry around in your handbag or backpack. Well, it’s certainly a better option than carrying multiple chargers. But if you travel frequently, this is something you’d want to be wary about.
Overall, this Chargeasap 280W charger has a well-built design with a smooth finish that feels premium. There is a “Chargeasap” logo on the left and right faces, while the front face has a display on the top with four output ports below it. The tiny rectangular display is a colored OLED panel that separately shows the real-time charging volts, amps, and wattage for each port. The ports are labeled C1, C2, C3, and A1, both on the display and the charger. The former three are USB-C ports while the latter is the lone USB-A port.
The USB-A port sits on the top left and has a maximum output power of 65W. The C1 port is next to it and offers up to 140W of charging speed, enough to charge your powerful new Windows laptop or Macbook. The C2 port sits directly below it and has the same output power. Finally, the C3 port is on the bottom left with a maximum charging speed of 100W. The ports are spaced well enough for easy connecting and disconnecting of charging cables. You can simultaneously plug in four cables without making the setup look overcrowded.
Some of the plug converters are built a little poorly
On the opposite face, the Chargeasap Zeus 280W USB-C GaN Charger has a convertible plug to draw power from the wall socket. The charger ships with the US version installed permanently, with additional plugs supplied in the box to convert it into the plug type used in your region. You get three interchangeable prongs, which should be enough to make the charger universal. The built-in prong folds into the charger’s body when connecting a converter, helping keep a compact shape. You can also fold it when carrying the charger in your bag.
While it’s a well-thought-out design from Chargeasap, pulling out the prong requires that extra bit of force and effort. You have to pull it out with your nails. If your nails are short and tidy, the prong might hurt your fingertip. If only the firm added a button or something to pull the prong out of its folded state. I also found some of the plug converters poor in build quality. If you are plugging the charger into a wall socket horizontally, the plug cannot hold it straight because of its sheer weight. I had the charger fall off the socket a couple of times. This might also damage the plug or the socket over time.
I would have also liked Chargeasap to provide users with instructions on connecting and disconnecting the plug converters. While it’s not rocket science—most users should figure it out pretty quickly—it should have printed the instructions on the box or the paperwork supplied inside the box. Maybe also add arrows showing the direction you should pull the converter when disconnecting it. Some people might end up pulling it in the wrong direction and potentially damaging the prong. These little things help enhance the user experience.
No USB cable in the box
This 280W charger from Chargeasap is designed carefully to not obstruct switches and sockets around it. Some multi-port chargers block things around them, negating their benefit of charging multiple devices simultaneously. Chargeasap deserves praise for taking care of that. However, the firm should have supplied at least one USB-C to USB-C cable in the box. The brick comes with no cable. You have to purchase them separately. Alongside the charger and plug converters, the box includes a pouch and some paperwork. Nothing more.
The pouch in question is nothing special. It’s a basic pouch with a drawstring to keep your charger, cables (that you purchased separately), plug converters (you should carry them when traveling abroad), and other accessories tucked away from your other belongings. A thoughtful addition from Chargeasap, but buyers would be happier to see a cable than a pouch. Maybe the firm thought device makers already supply a cable in the box, so we don’t need to include one. It’s no excuse, though. If I am buying a charger, I want a cable with it.
Chargeasap 280W Charger Review: Performance
The Chargeasap Zeus 280W USB-C GaN Charger delivers a maximum output power of 280W. As mentioned above, it has two USB-C ports (C1 and C2) with a 140W power output, one with 100W (C3), and a USB-A port with 65W (A1). However, you don’t always get the maximum speed for each port. The official specifications say C1 and C2 can simultaneously deliver 140W of power for a total of 280W. A C1/C2 + C3 combination gives you the expected maximum of 240W (140W+100W). Likewise, a C1/C2 + A1 combinations delivers 205W of power (140W+65W).
However, combining C1, C2, and C3 ports drops the power output of the latter two to 65W (C1 still at 140). You get the same power output when combining C1, C2, and A1 ports. The charging speed drops drastically when you bring the A1 port into the mix. A C3+A1 combination, for example, drops the power to just 15W. So, it’s better to use a USB-C to USB-C cable than a USB-A to USB-C. Chargeasap has equipped the charger with a laptop-first power distribution system. It ensures 140W of power output from the C1 port regardless of which other port you use.
This is great for charging your laptop at full speed. Other ports might suffer a speed drop but the C1 will constantly deliver 140W charging speed. Well, the speed depends on the power and charging settings of your device, as well as other factors such as system temperature and maximum supported charging speed, but you get the gist. If you are only charging one device, try to use the C1 port. It supports all kinds of fast charging technologies, including PPS, PD, QC, AFC, FCP, SCP, PE, and SFCP. The last one isn’t used widely but Chargeasap still supports it.
The charger appears to lack over-charging protection
While I didn’t have a device that charged at 140W, I tested Chargeasap’s new 280W charger with various devices that supported charging speeds ranging from 5W to 100W, and it performed as expected. I got a reliable speed, comparable to the in-box chargers that came with some of the tested devices. However, the charger appears to lack over-charging protection. The display, if it shows accurate information (more on this later), indicated a 1W power supply even after the device was fully charged. There was no indicator showing a full charge.
Interestingly, Chargeasap claims protection against over-current, over-voltage, over-temperature, and short circuits. It would have been nice if the charger cut off the power supply completely as soon as the device was fully charged. Or maybe it does but the display is incorrectly showing a power draw. There was definitely no overheating issue. The charger or the wall socket never got excessively warm even when all four ports were in use. Overall, this Chargeasap power brick performed in the expected lines. No major issues to worry about.
Chargeasap 280W Charger Review: Display
The Chargeasap Zeus 280W USB-C GaN Charger’s display is no gimmick. The tiny screen on its front side tells you how much power your device is drawing. It lets you track whether the device is charging at its full speed or not. The screen shows the real-time volts, amps, and wattage for each port separately. The information is marked clearly so anyone can understand what is going on. The display lights up when a device is connected and goes off automatically after you disconnect the device or cut off the main power source. It’s a handy addition to this powerhouse of a charger.
The display isn’t the brightest or sharpest out there but does its job effectively. It shows four rows of information. The top row is for the C1 (140W) port, the second for the C2 (140W), the third for the C3 (100W), and the last row for the A1 (65W) port. Chargeasap has color-coded the rows to make it easy to distinguish between them. Next to the legends denoting the port are readings showing the real-time volts, amps, and wattage, in that order. The readings are spaced widely so you can easily see them when your device is charging.
According to Chargeasap, this power brick has the Navitas GaNFast NV6127 Power IC technology. The firm has equipped the charger with four of these industry-leading chips. This enabled it to offer faster charging speeds and superior efficiency in a more compact form factor. It could throw in a display alongside four US ports and yet offer up to 280W of power output, all in a package with a volume of 231 cubic centimeters or 14.1 cubic inches. Most competing solutions are bigger and heavier than this Chargeasap charger.
Chargeasap 280W Charger Review: Should you buy it?
At $219, the Chargeasap Zeus 280W USB-C GaN Charger isn’t cheap. It’s quite expensive for a charger that doesn’t give you a cable. However, the power brick still offers great value for your money. It has a solid build and a compact size with four output ports and a display. If you are constantly on the move with multiple electronic devices that need to be charged every often, this might be the perfect solution for you. Yes, it is heavy. But not if you are already packing multiple power bricks every time you are on the go.
You should buy the Chargeasap 280W charger if you:
…are looking for a compact multi-port charger with fast charging support …want a charger that offers USB-C and USB-A output ports …need a charger with a built-in display for monitoring the real-time charging speed …frequently travel abroad and need plug converters for your charger
You shouldn’t buy the Chargeasap 280W charger if you:
…want a cable in the box …prefer a lightweight design over four ports
Gemini, Google’s AI chatbot, is receiving a major upgrade with the rollout of Gemini 1.5 Flash for its free version. This update promises faster response times, improved reasoning and image understanding, and a quadrupled context window, all accessible for free. These enhancements are designed to make Gemini a more efficient and helpful tool for users in their daily tasks, from writing emails to debugging code.
Previously only available for the Gemini Advanced tier, the expanded 32K token context window allows for longer conversations and more complex questions. To make the most of this, Gemini will soon support file uploads via Google Drive or directly from your device. Having this capability will enable Gemini to create practice questions from study guides, analyze data files, and visualize insights through charts and graphics.Another notable addition is the “related content” feature, which displays links to relevant websites or emails within Gemini’s responses. This aims to reduce hallucinations (instances where AI generates incorrect information) and encourage users to explore topics further. Additionally, Gemini’s double-check feature uses Google Search to verify responses, highlighting corroborated or contradicted statements on the web.
Gemini in more places and languages
Gemini is also expanding its reach, with availability in over 230 countries and territories and support for 40 languages. It is also being integrated into Google Messages on select Android devices in the European Economic Area (EEA), UK, and Switzerland, with support for new languages like French, Polish, and Spanish. The Gemini mobile app is also rolling out to more countries, enabling more people to access Gemini on the go.
Additionally, teenagers globally will soon have access to Gemini in over 40 languages. This is aimed at helping them with school subjects, university preparation, and creative projects. However, to ensure safe and responsible usage, Google has implemented additional policies and safeguards, including a teen-specific onboarding process and an AI literacy guide.
Throughout Gemini’s development, Google has focused on being responsible and keeping users safe, and thus they’ve now published more information on how they design Gemini and how it’s meant to respond. This includes details on their policy guidelines for handling complex and sensitive topics, which are based on Google’s AI Principles on using the technology in a responsible and open way.
Google plans to share more Gemini news at its Made by Google event next month alongside the launch of their newest devices. In the meantime, you can try out all these new features in Gemini for free today.
Google Chrome has introduced a revamped download experience with comprehensive warnings about potentially malicious files.
This update is part of Chrome’s ongoing effort to keep users secure while interacting with downloaded content.
Last year, Google Chrome unveiled a redesigned downloads interface on desktops, designed to make it easier for users to manage their recent downloads. This new interface offers a more flexible and spacious UI and provides a platform for enhanced security features.
The redesign allows Chrome to deliver more detailed and nuanced warning messages, helping users make informed decisions about their downloads.
Adding Context and Consistency to Download Warnings
According to the Google blog reports, With the additional space in the new downloads UI, Chrome has replaced its previous warning messages with more detailed ones.
These messages now offer better context about the nature of the threat, enabling users to understand the risks more clearly.
Our legacy, space-constrained warning vs. our redesigned one. The warnings are part of a two-tier system based on AI-powered malware verdicts from Google Safe Browsing:
Suspicious Files: These carry a lower confidence verdict and an unknown risk of user harm.
Dangerous Files: These have a high confidence verdict and a high risk of user harm.
The two types of warnings are differentiated by iconography, color, and text, making it easier for users to quickly assess the threat level and decide on the appropriate action.
Differentiation between suspicious and dangerous warnings
Protecting More Downloads with Automatic Deep Scans
For users who have opted into the Enhanced Protection mode of Safe Browsing in Chrome, there is an additional layer of security.
These users are prompted to send the contents of suspicious files to Safe Browsing for deep scanning before opening the file.
This process has proven highly effective, catching new malware and dangerous files that Safe Browsing has not previously encountered. Files sent for deep scanning are over 50 times more likely to be flagged as malware than the average download.
An automatic deep scan resulting in a warning
To streamline this process and reduce user friction, Chrome performs automatic deep scans for Enhanced Protection users rather than prompting each time.
Staying Ahead of Attackers Who Hide in Encrypted Archives
A current trend among attackers is distributing malware in encrypted archives, such as .zip, .7z, or .rar files, which are protected by passwords. This method hides the file contents from Safe Browsing and other antivirus detection scans.
Enter a file password to send an encrypted file for a malware scan
To counter this, Chrome has introduced two protection mechanisms based on the user’s Safe Browsing mode:
Enhanced Protection Mode: Users are prompted to enter the file’s password and send it along with the file to Safe Browsing for a deep scan. The uploaded files and passwords are deleted shortly after scanning.
Standard Protection Mode: Users are still prompted to enter the file’s password, but in this case, both the file and the password remain on the local device. Safe Browsing checks only the metadata of the archive contents.
Collaborating for Better Security
The Chrome Security team collaborates closely with Google Safe Browsing, Google’s Threat Analysis Group, and security researchers worldwide.
This collaboration helps Chrome stay ahead of attackers by continuously adapting its product strategy based on the latest insights into attack techniques.
Google Chrome’s new download warnings and enhanced security measures represent a significant step in protecting users from malicious files.
By providing more detailed warnings and leveraging AI-powered malware detection, Chrome is helping users make safer choices and stay protected online.
As attackers continue to evolve their methods, Chrome remains committed to enhancing its security features and keeping users safe. By incorporating these advanced security measures, Google Chrome sets a new standard for user safety in the digital age.
Stay tuned for more updates as Chrome continues to innovate and improve its security protocols.
Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo
It’s been over two years since Google debuted the Pixel Buds Pro, so it’s time for an upgrade. Next month, Google will introduce the Pixel Buds Pro 2, and we can now show you them in every single color.
Google’s Pixel Buds Pro 2 will be available in four colors. These include the usual Charcoal and Porcelain, an Aloe color to match the Pixel 8a, and a Hot Pink color to go along with the new Pink Pixel 9 and Pixel 9 Pro models.
As we’ve seen in more recent leaks of the Google Pixel Buds Pro 2, the case is going to be a little bit more bulky versus the original model. Otherwise, the case looks the same. Complete with the LED light in the center on the front. And the good news here, is Google is remaining stemless, unlike the new Samsung Galaxy Buds 3 Pro.
There are a few more changes here versus the original Pixel Buds Pro, including a more prominent grill on each earbud. This is likely going to be used for ANC and Transparency modes. What you will also notice on these earbuds is that the wing is back, sort of. It doesn’t stick out quite as much as the original Pixel Buds wing did, which many said were uncomfortable to wear for a long period of time.
Google is giving Pixel Buds Pro a much needed upgrade
Seeing as the Pixel Buds Pro were first announced in May 2022 and released in July 2022, it’s been quite some time since Google released a new pair of earbuds. And honestly, it’s about time. Starting off with four colors is pretty nice to see. Currently, the Pixel Buds Pro comes in six colors, with Google adding a new color with each fall release.
It’s still unclear how the audio has been upgraded here, but we should expect some pretty nice upgrades on that front. Additionally, with the more bulky case, I’d also expect battery life to be better. On the current-gen Pixel Buds Pro, Google claims 31 hours with the battery case and ANC off or 20 hours with the battery case and ANC on. We’ll learn more in a few weeks when Google unveils all of the new Pixel products.
Google is a company that stays in the headlines consistently for one reason or another. They could either be good reasons or bad reasons. The company made waves by entering a deal with Reddit to use its data to train its AI. Well, it seems that, conveniently, Reddit is only showing search results for Google and no other search engine. This could be a developing story, so more details may come out as time goes on.
Right now, major media companies and publications are entering deals that will fork over their data to AI companies. For example, companies like Axel Springer (owns Business Insider), Vox Media (owns The Verge), and News Corp (owns more than a dozen publications) have entered multi-million-dollar partnerships that will allow OpenAI to legally train on their data.
Well, before many of these deals took place, Google entered a partnership with Reddit that lets the search giant access its content and data. That’s unfortunate, as we found out about this right after we found out that OpenAI was scraping tons of data from social media sites. So, these major companies were making deals that would give AI our data without our knowing.
Reddit seems to be blocking search engines, but not Google
Google isn’t the only search engine this side of the Mississippi. Other search engines have been serving up results for years like Bing (Google’s biggest competitor), DuckDuckGo, Mojeek, and Qwant. There are hundreds out there, but we mostly only know about a handful.
Well, it appears that Reddit only knows one, and that’s Google. According to a new report from 404 Media, when searching for content using “site:reddit.com” you won’t see any recent results if you’re not using Google. It appears that you won’t see any results from the past week or so. This only goes for search engines that don’t rely on Google’s indexing. If a search engine uses Google’s crawlers, then it will surface results.
Users surmise that this is because of the deal that the two companies cut a few months back. It’s just so convenient that Reddit and Google cut a content deal and suddenly, all non-Gooogle search engines can’t access Reddit’s recent content. However, that hasn’t been confirmed just yet.
Crawlers
While there’s no proof that Reddit is blocking other search engines because of the deal, it would make sense. A bit part of AI tech has to do with what are called “crawlers.” Crawlers “crawl” throughout websites and extract important information from them. If you have a website, it has crawlers from different companies on it at all times. It’s important, as this is how search engines index your site. It’s how they surface your site in search results. So, in order to see your website in Google’s search results, your site needs to be crawled by Googlebot, Google’s crawler.
Well, crawlers are also notorious because AI companies use them to extract data to train their models. Well, there’s a way to combat crawlers. Site developers can use “Robots.txt.” This is a file that tells them not to index that site’s data. However, these files can also make exceptions for certain crawlers, allowing them to crawl the site and not others.
Well, since Reddit allows Google to use its data, there’s a chance that it only allows Google to crawl it, so only it can access its data to train Gemini. However, since other companies aren’t able to crawl it to train their models, they’re also not able to index Reddit and surface search results. That’s only speculation.
Mojeek’s CEO’s situation
According to 404 Media, Mojeek’s CEO, Colin Hayhurst, recounted his experience with this issue. The company realized that Reddit was blocking Mojeek’s crawler from indexing the website.
What makes things worse is the fact that Reddit hasn’t responded to his emails. It’s been nearly two months since he emailed the social media site. He told 404 Media in a call that Reddit is “killing everything for search but Google.”
“It’s never happened to us before,” he continued. “Because this happens to us, we get blocked, usually because of ignorance or stupidity or whatever, and when we contact the site you certainly can get that resolved, but we’ve never had no reply from anybody before.”
That’s probably the most frustrating part of this ordeal. Hayhurst has been trying to resolve the issue for over a month with no progress. We’re not sure if other search engines are also experiencing the same issues that he’s experiencing.
Reddit claims no foul play
Reddit has been radio silent to Hayhurst, but not to everyone else. A company spokesperson responded to the accusations.
“This is not at all related to our recent partnership with Google. It is not accurate to say recent Reddit results are not coming up in non-Google search engines because of our recent deal with Google,” said spokesperson Tim Rathschmidt to 404 Media. According to Rathschmidt, Reddit has been shooting down crawlers that want to use data to train AI models.
Rathschmidt continues to say that Reddit has been “in discussions with multiple search engines. We have been unable to reach agreements with all of them, since some are unable or unwilling to make enforceable promises regarding their use of Reddit content, including their use for AI.”
If true, then that would be good on Reddit. However, we can’t overlook the fact that only Google search engines seem to be getting through to Reddit, and that’s the only company that signed a $60 million deal with it. With that information, it seems that Reddit is only interested in letting sites crawl in if they pay up. That’ll be corroborated if we see news of Microsoft making a deal with Reddit, and suddenly, Bing results start showing recent Reddit posts in its results.
Reddit is already in bad faith with its users. Last year, there was the whole controversy of the company charging an exorbitant amount of money to access its API. After that, signing over its users’ data to Google for use in AI. If Reddit is really selling access to its site for search engines, it could really sour its vision in the public eye.
Developing story
As stated, this is still a developing story, so it will be updated should any more information reach the surface. We’re still waiting for some sort of response from Google on the whole situation.
The notorious Chinese Smishing Triad gang, known for its SMS phishing attacks against Pakistan, the US, and European nations, has now set its sights on iPhone users in India. The group is exploiting iMessage and the government-owned India Post in a sophisticated phishing scam.
FortiGuard Labs has revealed a sophisticated Smishing (SMS Phishing) campaign targeting users of India Post, the country’s government-operated postal system. The scam, attributed to a China-based threat actor known as the Smishing Triad, involves sending deceptive iMessages to iPhone users, claiming that a package is waiting for them at an India Post warehouse.
The fraudulent messages often contain a short URL leading to a fake website designed to mimic the official India Post site. Victims are then prompted to provide sensitive personal information, such as their name, residential address, email ID, and phone number. In some cases, the scammers even request credit card details under the guise of a small redelivery fee.
FortiGuard Labs’ investigation revealed that between January and July 2024, over 470 domain names were registered to impersonate India Post’s official domain. Notably, 296 of these domains were registered through a Chinese registrar, Beijing Lanhai Jiye Technology Co., Ltd., raising concerns about the intentions behind the campaign.
The Smishing Triad has previously targeted other regions, including the US, UK, EU, UAE, KSA, and Pakistan. Their modus operandi involves using third-party email addresses, such as Hotmail, Gmail, or Yahoo, to create Apple IDs and send phishing messages via iMessage. This tactic allows the scammers to bypass traditional email security measures and reach users directly on their iPhones.
Malicious text messages received by users – One of the fake India Post domains used in the scam (Credit: FortiGuard Labs)
According to Fortinet Labs’ report shared with Hackread.com ahead of its publication on Thursday, the phishing campaign is quite sophisticated and well planned. The investment in registering the malicious domain names alone exceeds USD 1500.
Jason Soroko, Senior Vice President of Product at Sectigo, commented on the issue, stating, “The use of third-party email addresses on iMessage facilitates these attacks, highlighting a need for increased awareness and robust security measures among users to mitigate potential financial losses and data breaches.”
Stephen Kowski, Field CTO at SlashNext Email Security+, emphasized the need for comprehensive mobile web threat protection, stating, “As smishing attacks become increasingly sophisticated, organizations must prioritize educating their users on how to identify and report suspicious messages, while also implementing robust security measures that can inspect and mitigate threats in real-time, regardless of the communication channel used.”
To protect themselves from such scams, users are advised to be cautious of unexpected emails or messages, verify URLs before clicking on them, and avoid sharing personal information via email or messaging apps. Enabling multi-factor authentication and keeping software up to date can also help strengthen account security.
A hacktivist entity known as USDoD has asserted that it has leaked CrowdStrike’s “entire threat actor list” and claims to possess the company’s “entire IOC [indicators of compromise] list,” which purportedly contains over 250 million data points.
Details of the Alleged Leak
On July 24, 2024, the USDoD group announced an English-language cybercrime forum, stating that they had obtained and leaked CrowdStrike’s comprehensive threat actor database.
The group provided a link to download the alleged list and shared sample data fields to substantiate their claims.
The leaked information reportedly includes:
Adversary aliases
Adversary status
The last active dates for each adversary
Region/Country of Adversary Origin
Number of targeted industries and countries
Actor type and motivation
Claim of the breach
The sample data contained “LastActive” dates up to June 2024, while the Falcon portal’s last active dates for some actors extend to July 2024, suggesting the potential timeframe of the data acquisition.
Cyber Press researchers stated that they were able to view some of the documents leaked.
Background on USDoD
USDoD has a history of exaggerating claims, likely to enhance its reputation within hacktivist and eCrime communities.
For example, they previously claimed to have conducted a hack-and-leak operation targeting a professional networking platform, which was later debunked by industry sources as mere web scraping.
Since 2020, USDoD has engaged in both hacktivism and financially motivated breaches, primarily using social engineering tactics.
In recent years, they have focused on high-profile targeted intrusion campaigns and have sought to expand their activities into administering eCrime forums.
USDoD also claimed to possess “two big databases from an oil company and a pharmacy industry (not from the USA).” However, the connection between these claims and the alleged CrowdStrike data acquisition remains unclear.
The potential leak of CrowdStrike’s threat actor database could have significant implications for cybersecurity:
Compromise of ongoing investigations
Exposure of tracking methods for malicious actors
Potential advantage for cybercriminals in evading detection
This story unfolds following a CrowdStrike update that caused Windows machines to experience the Blue Screen of Death (BSOD) error.
CrowdStrike’s Response
CrowdStrike, a leading cybersecurity firm known for its threat intelligence and incident response services, has responded to the claims. The company stated:
“The threat intel data noted in this report is available to tens of thousands of customers, partners, and prospects – and hundreds of thousands of users. Adversaries exploit current events for attention and gain. We remain committed to sharing data with the community.”
While USDoD has been involved in legitimate breaches, its credibility in this specific case is questionable.
Their history of exaggeration, the inconsistencies in the leaked data, and CrowdStrike’s response all cast doubt on the authenticity and severity of the claimed leak.
Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo
While the Samsung Galaxy Watch Ultra is the company’s first “Ultra” smartwatch, and it really doesn’t disappoint. In my review, I called it the “Best Wear OS smartwatch available” and that will likely be true for a good amount of time. As we’re only expecting the Pixel Watch 3 to launch this year with Wear OS now. It’s a huge 47mm smartwatch that is made for those that are more outdoorsy. We’re talking hikers, cyclists and runners. As this is a much more durable smartwatch, with the MIL-STD-810H certification.
The Galaxy Watch Ultra comes in Titanium White, Titanium Silver and Titanium Black, with different bands for each one. Samsung has created a new band mechanism for attaching to the watch, so unfortunately your old bands won’t work on this one. But there are Marine, Trail and Peakform bands available.
In this article, we’ll be showing you the best deals you can get on the Galaxy Watch Ultra and we’ll be keeping it updated too.
Researchers have uncovered a vulnerability in Microsoft’s Windows Hello for Business (WHfB) that allows attackers to bypass its robust authentication mechanism.
This flaw, which downgrades the authentication process to a less secure method, has raised concerns about the security of enterprise environments relying on WHfB for phishing-resistant authentication.
What is Windows Hello for Business?
According to the Medium blog report, Windows Hello for Business is a sophisticated authentication mechanism that enhances security using a cryptographic key pair stored on the user’s device.
It leverages the Trusted Platform Module (TPM) to store the private key securely while the public key is sent to the authentication server. The process involves two main phases:
Registration: Users register for WHfB, creating a cryptographic key pair. The private key is stored in the TPM, and the public key is sent to the server.
Authentication: When users authenticate, they use their Windows Hello PIN or fingerprint, which triggers the encryption of a nonce (unique challenge) issued by Microsoft. This encrypted nonce, along with the origin field, is sent back to the server for validation.
Windows Hello for Business prompt
The Flaw: Bypassing WHfB Authentication
The vulnerability in WHfB allows attackers to intercept and alter the authentication requests, coercing users into using a less secure, phishable authentication method.
This can be achieved by manipulating the POST request values, specifically the isFidoSupported parameter and the User-Agent header.
Regular sign-in using WHfB
Exploitation Process
Intercepting Requests: Attackers use tools like Burp Suite to intercept the outgoing authentication request.
Modifying Parameters: They change the isFidoSupported parameter to false or alter the User-Agent header to an unsupported value.
Downgrading Authentication: This manipulation downgrades the authentication method from WHfB to a standard, less secure method, which can be easily phished using frameworks like EvilGinx.
A proof of concept (PoC) video demonstrates how this attack can be executed.
The authentication method is downgraded by intercepting the POST request to /common/GetCredentialType and changing the isFidoSupported parameter, allowing attackers to bypass WHfB.
Automated Exploitation with EvilGinx
Researchers have modified the EvilGinx framework to automate this attack. EvilGinx is a tool used for phishing attacks, and the customizations include:
Modifying the core/http_proxy.go file: This allows manipulation of POST requests with JSON bodies.
Creating a Phishlet: A phishlet is a customizable template for creating phishing pages.
The phishlet for this attack alters the POST request to /common/GetCredentialType to set isFidoSupported to false and hides the “Sign-in options” button.
Snippet from BurpSuite’s intercept proxy (/common/GetCredentialType) showing the value “isFidoSupported”
/ set the value of the specified key in the JSON body
func SetJSONVariable(body []byte, key string, value interface{}) ([]byte, error) {
var data map[string]interface{}
if err := json.Unmarshal(body, &data); err != nil {
return nil, err
}
data[key] = value
newBody, err := json.Marshal(data)
if err != nil {
return nil, err
}
return newBody, nil
}
lp() function
Firstly, find the document element by class (table), which belongs to the box containing the various sign-in methods — such as Fido/WHfB authentication:
Identifying the class name `table`
Recommendations for Mitigation
Microsoft recommends creating conditional access policies using authentication strength to mitigate this attack vector.
This involves:
Implementing Strong Authentication for Cloud Apps: Enforce phishing-resistant authentication methods across all cloud applications.
Creating Custom Authentication Strengths: Define custom authentication strengths that include phishing-resistant methods like Temporary Access Pass (TAP).
Secondary Policy for Registering Phishing-Resistant Methods: Implement a secondary Conditional Access (CA) policy for users registering new methods via compliant devices.
The discovery of this vulnerability in Windows Hello for Business highlights the need for continuous vigilance and robust security practices.
By implementing strong authentication policies and staying informed about potential threats, organizations can better protect their sensitive data and maintain the integrity of their authentication processes.
Windows Hello for BusinessCaption: Windows Hello for Business aims to provide a secure and phishing-resistant authentication mechanism.
Organizations must adopt advanced security measures as cyber threats evolve and stay ahead of potential vulnerabilities.
The flaw in Windows Hello for Business serves as a reminder of the importance of layered security and proactive risk management.
This comprehensive news article provides an in-depth look at the vulnerability in Microsoft’s Windows Hello for Business, detailing the exploitation process, proof of concept, and recommendations for mitigation.
By understanding the mechanics of this flaw and implementing the suggested security measures, organizations can enhance their defense against sophisticated phishing attacks.
Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo