X (Twitter) doubles down on video strategy and declares itself a video first platform

0
[ad_1]

Following its declaration in a blog post last month, X (formerly Twitter) is once again affirming its status as a video first platform. As proof of this, X CEO Linda Yaccarino shared yesterday some interesting stats on how the platform is growing in the video sharing space.


Four out of every five user sessions on X include video consumption, according to the stats originally provided by the official @XData account. Furthermore, the account reported that the average annual growth rate for video views on X is 35%, and the average amount of time spent on video has increased by 17%. These are numbers that the company considers very promising, declaring that “the future of video on X is bright!”

X’s transition to a video-first platform has greatly transformed the social media environment. X was once known for its short-form text updates, but it now prioritizes video content in a variety of formats. The platform’s emphasis on immersive, short-form videos matches the efforts of competitors such as TikTok, which adapt to shifting audience preferences. This transition is also driving the growth of long-form videos on the platform, as X strives to compete with established platforms such as YouTube.

As a consequence of this shift, many content creators on X are now focusing their efforts on video. X’s algorithmic prioritization of video content is promoting this pattern, influencing how information is consumed on the site. Furthermore, the recent addition of video-focused features has opened up additional possibilities for income, attracting creators eager to capitalize on this opportunity.

While the shift towards video content has shown promise in increasing engagement and revenue, X still has a long way to go in order to maintain a healthy and trustworthy platform for both creators and users. Implementing robust moderation tools and fact-checking mechanisms might become crucial in ensuring the long-term success of this new direction.


[ad_2]
Source link

Sharp Increase in Akira Ransomware Attack Following LockBit

0
[ad_1]

In the wake of the LockBit ransomware group’s takedown, a shift has occurred within the cybercriminal underworld, leading to a sharp rise in activities by the Akira ransomware collective.

This group, known for its sophisticated attacks, particularly against healthcare entities in the US, has seen an influx of talent from the remnants of the notorious Conti group, specifically from its post-Ryuk faction.

The Rise of Akira Post-LockBit

Following the dismantling of LockBit, a notable vacuum was left in the ransomware landscape. Akira, a group previously operating in the shadows, has quickly stepped in to fill this gap.

According to cybersecurity firm RedSense, which has been closely monitoring these developments since the Summer of 2023, Akira has established deep ties with former members of the Conti group, especially those involved with the Ryuk ransomware.

Conti-Akira R&D Collaboration

The collaboration between Akira and the post-Conti group, particularly the developers behind Ryuk, has been pivotal.

The original creator of the Ryuk locker, known for his affinity for anime (hence the name “Akira”), has played a crucial role in supplying Akira with research and development insights.

This partnership was first identified during Royal’s research competition for a new locker, ultimately leading to the BlackSuit locker’s development.

Despite releasing a decryptor to counter Akira’s ransomware, the group saw a significant increase in compromised entities and successful encryptions during the summer of 2023.

This surge is attributed to the direct involvement of the Ryuk developer in Akira’s operations.

Yelisey Bohuslavskiy, co-founder of Redsense and advIntel, recently posted on LinkedIn about the sharp increase in threats from the Akira ransomware.

Following the takedown of LockBit, the Akira ransomware group is now attracting highly skilled post-Conti pen-testers targeting healthcare organizations in the United States.

The Emergence of “Ghost Groups”

Akira’s relationship with the post-Conti ecosystem has also led to the formation of “ghost groups,” such as Zeon, which previously aligned with Conti1 and played a significant role in deploying Ryuk.

In December, intelligence indicated that Zeon had been acting as a group of elite pen testers for Akira and LockBit, focusing primarily on the latter until its takedown.

The LockBit takedown has forced Zeon to redirect its efforts toward supporting Akira, leading to an expected increase in the sophistication and frequency of Akira’s ransomware attacks.

Recommendations & Mitigations

RedSense recommends several mitigation strategies to combat the rising threat from Akira and its associated groups.

These include prioritizing Remote Monitoring and Management (RMM) deployments, updating hypervisors and cloud backup frameworks, and implementing network segmentation and segregation to complicate these groups’ infiltration efforts.

Furthermore, awareness of specific Common Vulnerabilities and Exposures (CVEs) exploited by Zeon pentesters, such as CVE-2024-22252, CVE-2024-22253, and CVE-2024-22254 CVE-2024-22255, is crucial for defending against these sophisticated attacks.

As the cyber threat landscape continues to evolve, the rise of Akira in the post-LockBit era serves as a stark reminder of cyber criminals’ persistent and adaptive nature.

Vigilance and proactive cybersecurity measures are more important than ever to protect against these emerging threats.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

How to update outdated software on Mac endpoints: Introducing ThreatDown VPM for Mac  

0
[ad_1]

ThreatDown is happy to announce that our Vulnerability Assessment and Patch Management (VPM) tool is now available for Mac endpoints. 

There are hundreds of third-party apps that Mac endpoint use on a daily basis—and with that large number of apps comes a dizzying amount of software updates to apply on a rolling basis. 

With VPM for Mac, Nebula and OneView users can now easily find missing updates and install them to take care of the large volume of software updates in third-party applications on Mac endpoints. Some key features include: 

  • Single, lightweight agent: Updates install in minutes, using the same agent and cloud-based console that powers all ThreatDown endpoint security technologies. 
  • Quick scans: Identifies software updates dates in modern and legacy applications in less than a minute. 
  • Install software updates easily: Create a schedule to install third-party software updates regularly. 

Let’s dive into how to set up software updates for Mac endpoints with ThreatDown VPM.

Configuring VPM for Mac 

To configure VPM for Mac in Nebula/OneView: 

  1. Go to Configure > Policies 
  1. Create a new policy or select an existing policy. 
  1. Click the Software management tab. 
  1. Check mark Allow scanning for known vulnerabilities in installed software Mac endpoints.  
  1. Click Save.  

In order to be able to apply software updates, users need to enable the policy setting Allow updating software inventory and applying Windows OS patches for endpoints for Mac.  

Viewing outdated software 

To view and update software: 

  1. Go to Monitor > Software Inventory page. 
  1. Filter Update available as Yes.
  1. Click Actions.
  1. Select Update Software.
  1. Click Update.

You can also view outdated software by endpoint by: 

  1. Click Manage > Endpoints  
  1. Select specific endpoint(s) under the Software tab.  
  1. Click Update Software.  
  1. Click Update.

Updating outdated software 

To update outdated software, you can go directly to the Patch Management page as well: 

  1. Manage > Patch Management 
  1. Under Software Updates tab, select specific version(s) .
  1. Click Actions
  1. Select Update Software.
  1. Click Update.

Try VPM for Mac today

3rd party software updates for Mac endpoints is available on both Nebula and OneView for our Patch Management users or users on an Advanced bundles and above.

Not a user but looking to learn more on how to protect your Mac endpoints? Reach out for a quote today.


[ad_2]
Source link

Spotify is adding music videos to its library in select countries

0
[ad_1]

Starting March 13th, Spotify is integrating music videos into its library in 11 countries including Brazil, Colombia, Germany, Indonesia, Italy, Kenya, Netherlands, Poland, Philippines, Sweden, and UK. Spotify has reportedly been working on this addition since July last year. Notably, the music videos are currently further limited to premium subscribers who are in beta. Spotify says that they have chosen the markets based on the market size and availability of local content support.

A “Switch to Video” button will appear on the “Now Playing” screen

If you happen to be from one of the countries and also meet the other criteria, you will see a “Switch to Video” button on the “Now Playing” screen for specific content. Clicking the button replaces the album image with the video, which starts playing from the beginning. You can rotate the phone to landscape and enjoy the video. The video is reportedly ad-free, unlike YouTube at least now in the testing phase. Just like how you switch to video, you also get an option to switch back to audio.

Notably, Spotify is hosting the music videos itself instead of working with any other service provider. Now you might have been thinking about royalties associated with the videos. Well, the music streaming giant was asked by TechCrunch about this matter, but as of the time of writing, it has not yet replied.

Music Videos are also available on TVs

Spotify says that music videos are also available on TVs where it might prove a lot more helpful. Likely, the initial collection of video content is limited on the platform. As The Verge notes, currently supported artists include Ed Sheeran, Doja Cat, Ice Spice, Aluna, and Asake. With the public rollout of this feature, you can expect Spotify to include content from a wider variety of artists.

“In our initial beta rollout, we’re starting with a limited subset of the full catalog, which includes thousands of music videos. Within this subset, we aimed to prioritize a wide range of genres and artists across our launch markets,“ said Sten Garmark, Spotify’s VP Global Head of Consumer Experience.

It’s good to see Spotify is catching up with other streaming services like YouTube Music and Apple Music, both of which have video content available at this point. For those unfamiliar with the platform, it has been offering video podcasts and Clips (short vertical videos). So, it previously had what it takes to host videos to a global audience as well.


[ad_2]
Source link

Your Pixel Watch will let you track of app downloads more easily

0
[ad_1]

Some Pixel Watch and Pixel Watch 2 owners have noticed a new handy feature that enables them to monitor the progress of app installation directly from the app drawer. Checking individual app downloads at the Google Play Store will become redundant with this feature, thus simplifying the process of handling downloads and updates.

App installs are now easier to track on a Pixel Watch making it more functional

Google’s commitment to enhancing the Pixel watch experience shines through with this feature. Among other things, adding an on-screen indicator for app installations means that Google’s Wear OS is one step closer to improved functionality.

The latest feature was first discovered by one user known as Dimitrios Vlachos, whose revelation was then seconded by Mishaal Rahman. The progress bar appears within the app drawer allowing Pixel Watch owners to oversee their workflow without interruption.

Pixel Watch downlaod Progress 2
From Mishaal Rahman on X

The progress bar feature on WearOS underscores the convenience of a Pixel Watch. Google further optimizes performance and functionality across the Pixel Watch lineup through regular updates and feature additions like those brought about by new Pixels’ Feature Drop releases.

The feature remains exclusive to Pixel Watch 1 and Pixel Watch 2

It indicates that Google has not stopped innovating or improving its smartwatch ecosystem. However, the added functionalities are only available for Pixel Watch and Pixel Watch 2 users. Nevertheless, it is important to note that other wearables using Wear OS like the OnePlus Watch 2 cannot execute this function yet.

Incorporating a feature showing the app download progress is a demonstration of Google’s desire to make Pixel watches much more integrated into the user’s ecosystem. Folks no longer have to check their app download status within the Play Store. The app drawer will let users know every time an installation progresses successfully or when there may be any issues that may need intervention while they are still working on something else on their watches.


[ad_2]
Source link

By a huge bipartisan margin, bill that could ban TikTok in the U.S. passes and moves on to the Senate

0
[ad_1]

NBC News reports that the U.S. House of Representatives has overwhelmingly voted in favor of a bill that would ban video app TikTok in the United States unless the app is divested by the owner of the app, China’s TikTok. The vote count of 352-65 (with one member voting “present”) shows how much lawmakers are concerned about the relationship between TikTok owner ByteDance and the Communist Chinese government.

The concern is that ByteDance collects a large amount of personal data from TikTok subscribers in the U.S. Per Statista, the app had 102 million users in the states last year and that total is expected to rise to nearly 108 million this year. House Speaker Mike Johnson (R-La) said, “Communist China is America’s largest geopolitical foe and is using technology to actively undermine America’s economy and security. Today’s bipartisan vote demonstrates Congress’ opposition to Communist China’s attempts to spy on and manipulate Americans, and signals our resolve to deter our enemies.”

50 Democrats and 15 Republicans voted against the bill including a surprising “no” vote from Rep. Marjorie Taylor Greene, R-Ga who pointed out that she had previously been banned from social media. Greene’s vote matched that of Rep. Jim Himes, D-Conn., the top Democrat on the Intelligence Committee. Rep. Himes voted against the bill noting that countries like China “shut down newspapers, broadcast stations, and social media platforms. We do not. We trust our citizens to be worthy of their democracy. We do not trust our government to decide what information they may or may not see.”

TikTok is trying to fight back by stating that the bill violates American’s First Amendment right to enjoy free speech. 

The next stop for the bill is the Senate where it might have a harder time getting through. If the Senate does advance the bill, the House and Senate versions will need to be reconciled and the final version of the bill will be sent to the president for his signature. President Biden has already said that if the bill is advanced to his desk, he will sign it.


[ad_2]
Source link

Code Injection & Other Vulnerabilities Patched

0
[ad_1]

Organizations using SAP products are urged to prioritize patching vulnerabilities outlined in the latest SAP Security Notes, which was released on 12th March 2024 on SAP Security Patch Day.

SAP Security Notes are official communications from SAP that detail newly identified vulnerabilities within their software products.

These notes provide critical information, including:

  • Severity of the vulnerability
  • Affected products
  • Patch availability

Here’s a summary of the most critical updates:

High Priority:

  • Code Injection: Patch available for vulnerabilities in SAP Build Apps (lower than 4.9.145) and SAP NetWeaver AS Java (Administrator Log Viewer plug-in) -version 7.50 (CVE-2019-10744, CVE-2024-22127).
  • Improper Authentication: Update SAP Commerce Cloud (HY_COM 2105, HY_COM 2205, COM_CLOUD 2211) to address CVE-2023-39439.
  • Denial-of-Service (DoS): Patches available for SAP HANA Database (2.0) and SAP HANA XS Advanced (1.0) to address CVE-2023-44487.
  • Path Traversal: Update SAP BusinessObjects Business Intelligence Platform (Central Management Console) (4.3) for CVE-2023-50164.
  • Security updates (to the issue that was released on April 2018 patch day) for the Google Chromium web browser engine that’s embedded within the SAP Business Client software.Product – SAP Business Client, Versions – 6.5, 7.0, 7.70

Medium Priority:

  • Cross-Site Scripting (XSS): Patch SAP NetWeaver AS ABAP applications based on SAPGUI for HTML (WebGUI) (7.89, 7.93) for CVE-2024-27902.
  • Information Disclosure: Updates available for SAP NetWeaver (WSRM) (7.50), SAP NetWeaver (Enterprise Portal) (7.50), and SAP NetWeaver Process Integration (Support Web Pages) (7.50) to address vulnerabilities (CVE-2024-25644, CVE-2024-25645, CVE-2024-28163).
  • Improper Access Control: Patch SAP Fiori Front End Server (605) for CVE-2024-22133.
  • Missing Authorization Check: Update SAP ABAP Platform (758, 795) for CVE-2024-27900.

For detailed information and download links, refer to the full SAP Security Notes.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Microsoft Patch Tuesday March 2024 includes critical Hyper-V flaws

0
[ad_1]

The March 2024 Patch Tuesday update includes patches for 61 Microsoft vulnerabilities. Only two of the vulnerabilities are rated critical and both of these are found in Windows Hyper-V.

Hyper-V is a hardware virtualization product that allows you to run multiple operating systems as virtual machines (VMs) on Windows. A virtual machine is a computer program that emulates a physical computer. A physical “host” computer can run multiple separate “guest” VMs that are isolated from each other, and from the host. The physical resources of the host are allocated to the VMs by a software layer called the hypervisor, which acts an intermediary between the host and guests.

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The Hyper-V CVEs patched in this round of updates are:

CVE-2024-21407 is a Windows Hyper-V Remote Code Execution (RCE) vulnerability with a CVSS score of 8.1 out of 10. Microsoft says exploitation is less likely since this vulnerability would require an authenticated attacker on a guest to send specially crafted file operation requests to hardware resources on the VM which could result in remote code execution on the host server.

This means the attacker would need a good deal of information about the specific environment, and to take additional actions prior to exploitation to prepare the target environment.

CVE-2024-21408 is a Windows Hyper-V Denial of Service (DOS) vulnerability with a CVSS score of 5.5 out of 10. This means an attacker could target a host machine from a guest and cause it to crash or stop functioning. However, Microsoft did not provide any additional details on how this DOS could occur.

The attention for Hyper-V is remarkable since only a week earlier, VMware released security updates to fix critical sandbox escape vulnerabilities in VMware ESXi, Workstation, Fusion, and Cloud Foundation. VMware ESXi and Hyper-V are both designed to handle large-scale virtualization deployments.

Another vulnerability worth mentioning is CVE-2024-21334, which has a CVSS score of 9.8 out of 10. It’s an Open Management Infrastructure (OMI) RCE vulnerability that affects System Center Operations Manager (SCOM). SCOM is a set of tools in Microsoft’s System Center for infrastructure monitoring and application performance management. A remote, unauthenticated attacker could exploit this vulnerability by accessing the OMI instance from the internet and sending specially crafted requests to trigger a use-after-free vulnerability.

OMI is an open source technology for environment management software products for Linux and Unix-based systems. The OMI project was set up to implement standards-based management so that every device in the world can be managed in a clear, consistent, and coherent way.

Use-after-free vulnerabilities are the result of the incorrect use of dynamic memory during a program’s operation. If, after freeing a memory location, a program does not clear the pointer to that memory, an attacker can exploit the error to manipulate the program. Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Microsoft states that if the Linux machines do not need network listening, OMI incoming ports can be disabled. In other cases, customers running affected versions of SCOM (System Center Operations Manager 2019 and 2022) should update to OMI version 1.8.1-0.

Other vendors

Other vendors have synchronized their periodic updates with Microsoft. Here are few major ones that you may find in your environment.

Adobe has released security updates to address vulnerabilities in several products:

The Android Security Bulletin for February contains details of security vulnerabilities for patch level 2024-03-05 or later.

Apple has released a security update for iOS and iPadOS to patch two zero-day vulnerabilities

SAP has released its March 2024 Patch Day updates.


We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using ThreatDown Vulnerability and Patch Management.


[ad_2]
Source link

Instagram explores file-sharing feature for Direct Messages

0
[ad_1]

Reportedly, Instagram is in the process of developing a new feature that will let users send files via direct messages (DMs). The add-on will enhance collaboration and communication among users. Although there are few details available about the new feature as of now, it seems to target business accounts, providing them with a relatively easy way to send documents and files like presentations to their customers or clients.

Instagram file-sharing feature in the works: Share more than photos with your DM

The leaked screenshot on X indicates that file sharing will be accessible through the “+” button in the chat bar. The option will appear near other toggles such as add sticker, saved replies, and others. The specifics about types of files and size limitations are yet unknown. However, Instagram would likely limit these aspects for a smooth user experience.

Instagram aims to enhance direct communication between businesses and their clientele directly on its platform by introducing file sharing in DMs. This step may reduce off-platform messaging. This way businesses would not have to rely on other messaging services for file sharing.

Instagram File Sharing button
Tipped by X user @alex193a

The proposed file-sharing feature could prove to be a game-changer for professionals who rely on Instagram for communication and networking. With this new functionality, users would be able to share important files and documents along with their messages, making it a more versatile and useful platform for work-related purposes.

Additional imminent features include ‘saved replies’ and ‘add yours’

Leaked screenshots also show that there are additional features incoming with the update such as “saved replies” and “add yours”. While it is possible that the function “saved replies” may enable keeping important messages for easier access, the meaning of “add yours” remains unknown.

The file-sharing feature has been long-awaited by many, and if it succeeds in being implemented, it could greatly enhance the overall user experience of Instagram. The hope is that eventually, all Instagram users will have access to this function, allowing them to seamlessly share and collaborate with others within the app.


[ad_2]
Source link

The EU sets the first strict rules regarding AI

0
[ad_1]

Ever since generative AI first hit the market in November of 2022, we’ve all been wondering just how governmental agencies were going to regulate this technology and force companies to keep from crossing very important lines. Well, it’s taking over a year, but the EU has just laid down its first set of strict rules regarding AI.

This marks a world first, leaving other countries playing catch-up. Other major countries developing regulations regarding AI technology include the US and China. However, these regulations all remain speculative. AI technology is developing quickly, so it’s no surprise that it’s taking a long time to develop proper laws. However, it seems that the EU has other countries beat. Hopefully, other countries will follow suit.

The EU outlines the first set of strict rules for AI

These rules all lie under the EU AI Act that was conceived back in 2021. While this act has been talked about since December, the MEP (Members of the European Parliament) officially endorsed it during the Parliament’s Wednesday session. While the act did receive a fair share of opposition in the form of 46 votes against it, they received a whopping 523 votes in favor.

What these rules will do is divide different types of AI systems based on their potential risk. For example, AI being used for something mundane like spam blocking counts as a low risk. However, AI technology targeted for governmental use will be counted as high risk. This means that it will have the strictest rules against it. Also, some uses of AI, like the use of AI for biometric surveillance, will be strictly prohibited.

A work in progress

Right now, the rules are still baking, so you shouldn’t expect any laws to be passed in the near future. For starters, these rules are still being finalized. When they are finalized, they are expected to be inducted into law by May or June this year.

Even then, it will still take a while for the government to start enforcing these laws. Countries will have deadlines to start enforcing these laws for AI systems being used within them. For example, if AI systems are prohibited, countries will have six months to ban them. These countries will also have a full year to enforce rules against general-purpose AI systems like chatbots. Lastly, countries will have 36 months to enforce laws governing high-risk AI systems.

So, some of these laws will not start taking effect until 2027. Hopefully, that’s not too late. Technology is rapidly evolving, so we have no idea what the AI landscape will look like in a year or in 36 months. In any case, it is good to see that there is some solid legislation being implemented towards AI.


[ad_2]
Source link