The clock is TikToking: What happens if 170 million Americans’ favorite app gets banned?

0
[ad_1]
The clock goes: Tik, Tok, Tik, Tok…

Time is running out for TikTok.

In mere hours, the US House of Representatives will vote on the TikTok bill under “suspension of the rules”. Under suspension, floor debate is limited, all floor amendments are prohibited, points of order against the bill are waived, and final passage requires a two-thirds majority vote.

The goal is ByteDance to sell its interests in the viral short video app, or face a ban in the US. If everything goes to plan (the bill passes and Joe Biden signs it), ByteDance will have a 165-day deadline to divest from TikTok. Should it not pass the control of TikTok to an American-based company, US app stores (like Apple’s, Google’s and Samsung’s) would be prohibited from offering TikTok in the country.At this point, everything is possible, and I’m not writing off any scenario. Let’s explore what happens if somehow ByteDance doesn’t sell TikTok to any US-based firm and things go south.

How did it come to this?


“You don’t get to 500 million friends without making a few enemies”, as David Fincher’s Social Network (2010) slogan states.

500 million? When you’ve got 170 million users – as TikTok does solely in the US – you’re certainly too big not to draw people’s curiosity. And, when your parent company is the Chinese ByteDance, you’ve got their attention.

By “people” I mean, of course, US officials, Congress members and everyone all the way up to the POTUS – Trump was briefly obsessed with TikTok, now Biden is.

Last week, the Energy and Commerce Committee cast a unanimous 50-0 vote (highly unusual) in favor of the TikTok/ByteDance measure.

Prior to that, members of Congress were flooded with calls and emails (some of which containing no-no words) from angry TikTok users. The reason for this virtual flash mob is that TikTok rolled out this push notification:

The above was received by US TikTok users last week, warning that “Congress is planning a total ban of TikTok”, which would “[strip] 170 million Americans of their Constitutional right to free expression”. The message went on to explain how such a move by the US officials would “damage millions of businesses, destroy the livelihoods of countless creators across the country, and deny artists an audience.” Then, the alert included a way for users to find their representative and call their office (after putting a ZIP code).

Maybe this practical joke got the House committee to vote unanimously 50-0? I’m just guessing…

TikTok, of course, has been presented repeatedly as a threat to national security. The FBI, Justice Department and Office of the director of national intelligence held a classified briefing for House members just the other day.

TikTok assured Congress in a letter that the app is “not owned or controlled by the Chinese government”. Then, they pointed out that if the company is sold to another buyer, they would not continue TikTok’s $1.5 billion effort to protect US data. “Ironically, U.S. user data could be less secure under a divestment scheme”, the company said.

US Director of National Intelligence Avril Haines told a House of Representatives intelligence committee hearing that she “cannot rule out” that China could use TikTok to influence the 2024 US elections. That’s great, but what was that saying about the speck in your brother’s eye and the plank in your own eye?

Who’s going to mourn


I’d say a huge portion out of the 170 million users will be heartbroken to see TikTok go. After all, the app algorithms are there for a reason: to get you hooked. And hooked many are, as Master Yoda would put it.

Many users manage to look on the bright side of TikTok and get a positive kick out of it. Here are some of the Pros:

  • Creativity and expression: Short videos are a revolution, and TikTok’s role can’t be denied. The short format is suitable for some scenarios and people need to get creative.
  • Viral potential: TikTok gives users a chance for content to go viral, reaching a large audience quickly.
  • Engagement: Features like duets and challenges foster high user engagement.
  • Learning and discovery: TikTok (sometimes) offers educational content and serves as a platform to learn new skills and information. Although, don’t trust too much all the DIY videos out there…
  • Community and connection: TikTok helps users find communities with similar interests.

Also, there’s the First Amendment issue. I’m not going to go into that, but I’m sure that even sworn TikTok enemies will be enraged over the freedom of speech and access to information issue.

Who’s going to celebrate


The enemies of TikTok are not just in Congress. In fact, there isn’t a shortage of regular mortals that feel TikTok belongs to the deeper circles of hell. “Disdain” just doesn’t begin to describe the feelings many have for the viral app.While there are too many Cons to be listed all, here are some (especially dangerous for kids and young adults):
  • Excessive screen time: Apart from the posture and vision problems, and sleep disturbances, excessive screen time can lead to social isolation, reduced productivity and distraction from other activities or responsibilities. Don’t roll your eyes back, it’s all true, and it’s all important (even if it sounds too condescending).
  • Content quality: How do I put this mildly? TikTok videos can be superficial or misleading. The time spent on TikTok is not getting back, so be cautious with the content you’re consuming. This advice, like the rest, applies to every single social media out there, not just TikTok.
  • Mental health: Numerous studies claim that TikTok can actually contribute to anxiety, depression, and body image issues among many.
  • Security risks: Potential for exposure to inappropriate content and interaction with malicious users is not out of the question. You never know who’s on the other end…

Who’s going to be infuriated


There’s another group of people that’ll be affected by TikTok’s departure (if that happens): influencers and all those who monetize their app activity.

According to statistics and research, there are over 100,000 TikTok influencers in the United States across a number of different niches. The crème de la crème portion of them can earn as much as $500,000 per post, with an average of $100,000 to $250,000 (per post).

Businesses will also shed a tear for TikTok: with 170 million users, many of which at an impressionable age, the app is an important advertising arena. Per TikTok’s claims, there are five million small businesses that use the short video app to gain customers and operate.

That’s exactly why Shark Tank investor Kevin O’Leary said that he will buy TikTok if the platform is about to get banned.

“Not going to get banned, ’cause I’m gonna buy it”, O’Leary said on Fox News and added that “Somebody’s going to buy it, it won’t be Meta, and it won’t be Google, ’cause… regulators [will] stop that”.

Biden has just made a TikTok account: ‘lol hey guys’


If the bill gets out of the Senate, Biden will sign it, as the White House has indicated.

He just made his TikTok entrance less than a month ago. His first video, captioned ‘lol hey guys’, provoked a Democratic Senator to say that he’s “concerned about the national security implications of Chinese-owned TikTok and the Biden campaign decision to join”.

Senator Mark Warner said: “I think that we still need to find a way to follow India, which has prohibited TikTok. I’m a little worried about a mixed message”.

Biden’s TikTok appearance in an election year is not accidental – the TikTok demographic is seen as potential voters, so corners have to be cut, and mixed messages can be sent. Mr. Biden’s TikTok account will not be run by the president himself, but by his campaign team, aides told US media, but that’s hardly a surprise.

Speaking of presidents that are sending mixed messages, let’s not forget that in 2020, Trump said “We’re looking at TikTok, we may be banning TikTok”. Then, nothing happened.

Now, Trump calls TikTok a threat but says some kids could “go crazy” without it.

Rooting your phone and using VPN just to watch The Dumbest Video Ever


Freaking out about apps that are used by 9-years old is good, and I’m not being ironic about it.

We should really be talking about Facebook, Instagram and all the rest of social media platforms: how they operate, what data they collect (and who’s been harvesting and analyzing it), how such apps affect kids (and grown-ups), are they rigged in a certain way… are they a threat?

If, however, TikTok is indeed banned across the US, some suggest workarounds like rooting your phone and using VPN services to get TikTok on your phone.

All of this, rooting your phone (and more), just to watch mindless, mediocre, malignant 20-second videos: seems a bit overkill. Yeah, I’m aware there’s quality content on TikTok, but the very fact that there’s a need to point that out, speaks for itself for the overall TikTok content quality.

My guess is that nothing happens for TikTok users either way, at least not in any fundamental way. If a US-based company buys it, almost all should be the same for the end user, apart from certain algorithm tweaking, or imposing some age-restriction requirements: anyway, the Congress is not that interested in the TikTok content per se. Their problem lies with user data going over to China, at least they present it that way.
If the app is banned, the TikTok crowd will just use another app or platform to share and consume the same content. And, we’ll have 165 days to come up with a way to transfer the TikTok videos to the new platform and carry on without an interruption.

However, if signed, the bill gives us plenty of food for thought:

  • Forcing a foreign company to become American is… controversial;
  • Are we going to continue to be disgusted by how China and North Korea filter their internet?
  • Freedom of speech (again, I’m not going to go into that);
  • Are all privacy concerns with TikTok magically ended? Are we sure that once in US hands, TikTok private data will not be exploited by nefarious agents?

You have to decide for yourself, as there is no TikTok video out there that will serve you the right answers.

[ad_2]
Source link

Popup Builder Plugin Flaw Exploited To Infect WordPress Sites

0
[ad_1]

Heads up, WordPress admins! It’s time to update your WordPress websites with the latest Popup Builder plugin release. Researchers have discovered criminal hackers exploiting the Popup Builder plugin flaw to infect the target sites with malicious scripts.

Popup Builder WordPress Plugin Flaw Could Allow Malware Injection

According to a recent post from the WordPress security firm Sucuri, their researchers have caught a new malicious campaign active in the wild. This time, the attackers exploit a known vulnerability in the WordPress plugin Popup Builder to attack thousands of websites.

Specifically, the new malware campaign exploits CVE-2023-6000 (CVSS 8.8), a stored XSS vulnerability in the plugin. An unauthenticated attacker could exploit the flaw to gain administrative privileges on the target website. Once done, the attacker could perform various malicious actions on the site as allowed to the victim logged-in admin account, including creating new admin users, installing arbitrary plugins, and more.

This vulnerability first caught the attention of WPScan security researchers in late 2023. According to their advisory, the plugin developers, following the bug report, patched the issue with Popup Builder version 4.2.3.

However, while the plugin developers strived to protect users from potential threats, WordPress admins seemingly failed (once again) to adequately secure their sites by promptly updating the plugin.

As Sucuri described, the attackers have been actively exploiting this flaw as part of the Balada Injector campaign since January. Citing PublicWWW, the researcher highlighted roughly 3,300 websites that have already fallen prey to this attack.

To prevent the threat, the researchers advise WordPress admins to patch their sites immediately with the latest Popup Builder plugin release. Besides, for sites already infected with the malware, Sucuri advises removing the malware from the “Custom JS or CSS” section of the plugin.

However, they deemed it a “short-term fix” as reinfection remains likely in such a scenario. Thus, the researchers also advise a thorough website scan to detect and remove backdoors and rogue admin accounts.

Let us know your thoughts in the comments.


[ad_2]
Source link

OPPO Find X7 Ultra cameras take top spot in DXOMARK rankings

0
[ad_1]

The OPPO Find X7 Ultra impressed us quite a bit overall, as we’ve said in our review. The phone not only has outstanding camera performance, but it’s a great phone in general. Well, the OPPO Find X7 Ultra ended up in the hands of the folks over at DXOMARK, and it managed to impress them.

The OPPO Find X7 Ultra impressed folks over at DXOMARK

The OPPO Find X7 Ultra has managed to take the top spot in DXOMARK rankings. Well, it technically shares that spot with the Huawei Mate 60 Pro+. It scored 157 points overall. So let’s break this down, shall we?

When it comes to photography in general, the phone scored 156 points. In terms of Bokeh, it scored 85 points, which is the top score on the site, it doesn’t get better than that. The ‘Preview’ section sits at 79 points out of 91, while the zoom capabilities are almost at the very top too with 156 points (out of 158). The phone’s video capabilities are also at 156 points (out of 158).

OPPO Find X7 Ultra DXOMARK

The phone also reached the top score in the lowlight, indoor, and ‘Friendy & Family’ camera categories. When it comes to outdoor shots, it scored 172 points (175 points is the very best score thus far).

It managed to score the top spot not only in the global smartphone camera ranking but ultra-premium ranking too (phones above $800). Therefore, the device received DXOMARK’s Gold Camera rating.

DXOMARK had plenty to say about these cameras, and you can read a full report if you’re interested. We’ll sum things up here, though.

The company praised color rendering, white balance, bokeh & more

The company praised the color rendering from these cameras, and the same goes for the white balance. That goes for both photo and video. Excellent bokeh effect was also mentioned, with good subject isolation.

DXOMARK mentioned that the phone provides very good detail at medium and long-range tele, and good texture/noise trade-off in photo and video. That even goes for low-light photography. The last entry in the ‘Pros’ category was “accurate exposure and wide dynamic range on portraits and landscape shots”.

The company did mention some cons too. The phone has a slight loss of detail at close range for tele and ultrawide shots. Expore and tone mapping instabilities in video recording were also noticed, especially in high-contrast indoor scenes.

DXOMARK did note that the phone occasionally has unnatural texture rendering and slight overexposure in low-light photos.


[ad_2]
Source link

What is Google TV? Everything You Need To Know

0
[ad_1]

Google TV is Google’s latest initiative to dominate your living room entertainment experience. With Android TV, Google TV, and Chromecast, it can be confusing to differentiate between the three platforms since they are all owned by Google. Hence, we will provide you with all the necessary information about Google TV, enabling you to make an informed decision about which platform to use with your TV.

What is Google TV?

In simple terms, Google TV is a user interface that runs on top of Android TV. Think of it as a skin that runs on Android, like One UI or Oxygen OS from Samsung or OnePlus. But it’s Google’s own skin, and it’s on top of Android TV. But not limited to Google’s hardware. See, confusing, isn’t it?

It was announced in September 2020, with the Chromecast with Google TV dongle. It takes what Android TV does well and it expands on that. Giving you better and more recommendations and also providing a live TV Guide if you use YouTube TV or Sling TV. Among a few other features. It does a really good job with recommendations and telling you where you can watch specific shows or movies.

It, of course, also works with smart home products, like its Nest cameras. So you can easily bring up a feed of your camera onto the TV, or see when someone arrives at your door. You can also turn on or off the lights and do anything else you might use Google Assistant for. But now on your TV.

Google has continued to update Google TV, making recommendations better, adding free ad-supported TV, and much more.

Google TV

Google TV vs Android TV

Google TV isn’t really replacing Android TV, at least not yet. But the biggest difference between the two is that Google TV focuses more on recommendations and live TV guides. Making it easier for the user to find something to watch, instead of endlessly scrolling through each streaming service, to find something to watch while they are eating their dinner.

Google’s partners have also jumped on the Google TV bandwagon, like TCL and Sony. However, others have decided not to upgrade to Google TV, at least not yet. That includes the NVIDIA SHIELD TV. However, it’s likely that they will upgrade in the near future.

How does Google TV work?

Google TV works on a small number of devices right now. However, the best option for Google TV is the latest Chromecast, which costs $50.

Much like Android TV, it needs to have an internet connection and a Google account signed in.

On the main home screen, which is the “For You” screen, you’ll see a number of movies and TV shows that are available to watch. The top row might have some “sponsored” options that apps are pushing. Below that, you’ll see your apps that are installed. This row is customizable. Simply long-press on the app and move it around. You can also change what apps are shown in there, but it is limited to around 10 apps. So it’s a good idea to keep your most used apps in there.

Below the apps, you’ll see the “Continue Watching” list, which are movies and shows that you started watching and haven’t finished. This makes it easier to just jump in and start watching again. Then Google TV breaks down your recommendations into different sections below.

Google also has other tabs at the top for movies, shows, and Live TV. You can get other recommendations or see the live TV guide. But the guide only works for YouTube TV and Sling TV users right now. That might change in the future, though.

unnamed 1

How does Google TV know what you might want to watch?

Most streaming services are able to recommend movies and shows to watch, but Google TV is the first one to do it across all of your apps. It does it with the Knowledge Graph. This is a collection of facts about people, places and things. And it allows Google to answer or present users with accurate information about movies, shows, historical facts and more. And this information is all used to recommend different titles to the user.

In our experience, it has been very good at recommending titles to watch. And thanks to machine learning, it will get even better.

Will Google TV show me where I can watch a specific title?

If you see a title on your home screen that you end up wanting to watch, you can click on it. This will take you to a page that will give you a ton of information about that title. That includes its Rotten Tomatoes score, its genre, year it was released and its runtime. But you will also see a list of apps you can watch it in.

z663skrij9m3olqtn9wq

There’s also a way to add it to your watchlist and mark it as watched or give it a thumbs up or down to help the recommendations engine. And of course, you can watch a trailer from this page.

This is very useful if you are somewhat interested in a movie but aren’t 100% sure about committing two hours to watching it. Or if you aren’t sure where you can watch it. Google TV makes that super simple.

Are there any parental controls?

At launch, Google TV had no parental controls. But that has since changed. In March 2021, Google announced that parental controls were coming to Google TV.

These parental controls allow parents to set how long kids can watch TV as well as set the limit on ratings for content that they can watch. And there is also a profile lock so that kids aren’t able to make changes without their parent’s approval.

It’s pretty simple to do, and you can make a profile on Google TV specifically for kids. So that when adults want to watch TV, they don’t have to deal with these limitations. The controls are simple, but they work.

Profiles

After being announced in 2021, Google finally started rolling out profiles to the Google TV platform on May 23, 2022. This allows you to have different apps available for different users in your home, as well as take advantage of parental controls for your kids.

Recommendations tailored to you, and only you: As you watch TV, your profile takes into account your interests and preferences to help you discover more of what’s out there for you. And for the little ones, you can always set up a kids profile to help them access a fun collection of movies and shows under your guidance.

Access to your own watchlist: When a friend tips you off to a hot new show, you can always add it to your watchlist to save it for later. Each Google Account has its own watchlist, so your finds will show up right in your profile and stay separate from your other’s lists in your household.

Help from your Google Assistant: Ask for recommendations by saying, “What should I watch?” or get help streamlining your day by saying, “Show me my day.” Your profile is linked to your account’s Google Assistant, so you’ll get the personalized answers you are looking for.

What devices are available with it?

Google TV launched the new Chromecast in September 2020. The “Chromecast with Google TV”. Since then, Google has gotten some of its partners on board with Google TV, but not all of them. Namely TCL and Sony. So, any of the 2021 models from TCL and Sony will have Google TV on-board. Other partners have not announced plans to add Google TV to their Android TV models, however.

Google TV Chromecast 2 AM AH 6

Google TV has also replaced the Google Play Movies & TV app on Android and iOS. So you can easily find titles to watch from your phone and then cast them to anything that supports Chromecast.

We should see more devices supporting Google TV in the future. But in the meantime, Android TV has been updated to look very similar. It has all of the recommendations but with fewer tabs at the top of the screen.

Does Stadia work on Google TV?

Since Google TV is basically Android TV, yes, Stadia does work.

Stadia is available as a downloadable app on Google TV. You won’t have it pre-installed. This is likely a good thing since streaming TV devices don’t typically come with much storage in the first place. All you need is a controller and a Stadia subscription to get started. Who says you need a PS5 to game at home?

Now, there are also a number of other games available. Basically, any Android game will work here.

Update: Google sunset Stadia, as of January 2023

What apps work with Google TV?

Pretty much any Android TV app will work on Google TV. However, not all of them work with the recommendations, nor will they show titles on the home screen. Here is the complete list of apps that are compatible with Google TV.

  • ABC
  • Amazon Prime Video
  • AMC
  • Apple TV and Apple TV+
  • A&E
  • Boomerang
  • Cartoon Network
  • Crackle
  • Comedy Central
  • DC Universe
  • Discovery+
  • Disney NOW
  • Disney+
  • Epix Now
  • Fox Now
  • Hulu
  • HBO Go
  • HBO Max
  • History
  • Lifetime
  • MTV
  • NBC
  • Paramount+
  • PBS Kids
  • Peacock
  • Pluto TV
  • Showtime
  • Showtime Anytime
  • Starz
  • TBS
  • The CW
  • TNT
  • Tubi TV
  • VH1
  • Viki

Video on demand is available from the following apps.

  • YouTube TV
  • Sling
  • Philo
  • FuboTV

Can I see Live TV listings?

Yes, you can. Google has a dedicated Live tab for Google TV. You can see Live TV listings, making it easier to find something to watch, rather than having to browse the apps on your Google TV unit to find something. However, only a few streaming live TV services are compatible. These are those that are compatible:

  • Philo TV (Starting October 5, 2021)
  • Sling TV
  • YouTube TV
Google TV free channels
Google TV Free Channels

Does Google TV offer Free TV Channels?

Like many of its competitors, Google TV has also started to offer free TV channels, also known as FAST (Free Ad-Supported TV) Channels. Google TV currently has over 800 channels available. Some of the channels available include:

  • NBC News Now
  • Today All Day
  • Sky News
  • Reuters Now
  • Scripps News
  • Cheddar News
  • AccuWeather
  • Newsmax TV
  • CBS News

Google is constantly adding more to this list, so you’re bound to find something to watch, without paying a dime.

What are some voice commands that can be used?

There are a bunch of helpful voice commands you can use. On the Chromecast, there is a dedicated microphone button. Just press it and say any of these commands:

  • “Play some R&B music.”
  • “Open [app name].”
  • “Tell me about Chef Ramsay”
  • “Play Master Chef on Hulu”
  • “Show me the [name of camera]”
  • “How’s the weather”

Google TV Chromecast 2 AM AH 1

Basically, any voice command that you might use on your Nest Hub, Nest Mini, or Android smartphone for Google Assistant will work here. This is just Google Assistant, but on your TV.

Should I use Google TV?

If you are an Android user, you should definitely use Google TV. But if you use iOS, then it’s likely not the best option for you.

Google TV is really great at a number of things. Particularly recommendations. In my experience, Google TV has recommended a ton of shows that I ended up loving. And it was much better than Netflix’s or Hulu’s recommendations. However, that likely comes from knowing what I watch from all of its apps instead of just what I watch on Netflix or Hulu.

If you have also cut the cord and used YouTube TV, Sling TV, Philo, or FuboTV, then it’s an excellent option. The live TV guide works really well, and it’s quicker than opening the app.


[ad_2]
Source link

WhatsApp might allow users to pin several chats

0
[ad_1]
WhatsApp allows users to pin up to three chats for quite some time, but the social company is working on a new feature that will further increase the number of chats users can pin at the top of the app.

The latest version of WhatsApp beta for Android stands as evidence that such a feature might be coming very soon. Discovered by WABetaInfo, the new feature allows users to pin up to five chats, a slight improvement over the current stable version of WhatsApp.

Obviously, since this feature is currently being tested, we can’t really say whether or not it will be rolled out in this state. That means that by the time WhatsApp is done testing this feature, we might have end up having the option to pin much more than five chats, as seen in the screenshot below.

In any case, if you’re a person who loves to communicate with a lot with many people, the ability to pin more than three chats will certainly come in handy.

It remains to be seen when WhatsApp decides to make this available to everyone, because right now only a limited number of users enrolled in the beta program have been able to access it.

[ad_2]
Source link

New Fortinet FortiOS Flaw Lets Attacker Execute Arbitrary Code

0
[ad_1]

Fortinet has disclosed a critical vulnerability in its FortiOS and FortiProxy captive portal systems, potentially allowing attackers to execute arbitrary code through specially crafted HTTP requests.

This revelation underscores the ongoing challenges in safeguarding digital infrastructures against sophisticated threats.

Technical Breakdown of the Vulnerability

The vulnerability, identified as an out-of-bounds write issue [CWE-787] and a stack-based buffer overflow [CWE-121], affects multiple versions of FortiOS and FortiProxy.

Specifically, the impacted versions are FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, and 6.2.0 through 6.2.15, along with FortiProxy versions 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, and 2.0.0 through 2.0.13.

An attacker with access to the captive portal can exploit these vulnerabilities by sending specially crafted HTTP requests, which can lead to unauthorized code or command execution within the system.

This flaw poses a significant risk, as it could allow attackers to gain control over affected systems, potentially leading to data theft, system compromise, and further network infiltration.

Impact on Users

The implications of this vulnerability are far-reaching, affecting a broad spectrum of Fortinet’s user base.

Organizations utilizing the affected FortiOS and FortiProxy versions are at risk of targeted attacks that could compromise sensitive information and disrupt critical operations.

The vulnerability’s severity is underscored by its potential to allow attackers to execute arbitrary code, which can be leveraged for a wide range of malicious activities.

Affected Products and Versions

The vulnerabilities affect a range of Fortinet products across various versions:

  • FortiOS versions 7.4.0 to 7.4.1
  • FortiOS versions 7.2.0 to 7.2.5
  • FortiOS versions 7.0.0 to 7.0.12
  • FortiOS versions 6.4.0 to 6.4.14
  • FortiOS versions 6.2.0 to 6.2.15
  • FortiProxy version 7.4.0
  • FortiProxy versions 7.2.0 to 7.2.6
  • FortiProxy versions 7.0.0 to 7.0.12
  • FortiProxy versions 2.0.0 to 2.0.13

Fortinet has released software updates to address these vulnerabilities. Users are urged to upgrade their systems to the following versions or higher:

  • FortiOS version 7.4.2
  • FortiOS version 7.2.6
  • FortiOS version 7.0.13
  • FortiOS version 6.4.15
  • FortiOS version 6.2.16
  • FortiProxy version 7.4.1
  • FortiProxy version 7.2.7
  • FortiProxy version 7.0.13
  • FortiProxy version 2.0.14

Additionally, Fortinet has remediated the issue in FortiSASE version 23.3.b in Q3/23, so customers using this version need not take any further action.

The FMWP database update 23.105 also includes a virtual patch named “FortiOS.Captive.Portal.Out.Of.Bounds.Write.”

The vulnerabilities were internally discovered and reported by Gwendal Guégniaud of the Fortinet Product Security Team.

The initial publication of these findings was on February 27, 2024.

Fortinet customers are advised to review the provided solutions and apply the necessary updates or workarounds to ensure their systems are protected against the potential exploitation of these vulnerabilities.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Leading EV Charging Firm Spills Trove of Customer Info in Server Leak

0
[ad_1]

A massive data leak (585.81 GB) exposed customer information at Qmerit, including home images, charger locations, and potentially more – Qmerit took immediate action to secure the data.

Leading EV Charging Firm Qmerit Spills Trove of Customer Info

Cybersecurity researcher Jeremiah Fowler has uncovered a troubling data exposure incident, yet again drawing attention to broader concerns surrounding data security. Fowler, in collaboration with WebsitePlanet, uncovered a non-password-protected database containing over half a million records, including sensitive customer information and invoices from a prominent American EV services provider.

The exposed database, totalling 585.81 GB in size, contained a trove of documents such as work invoices, price proposals, electrical permits, and surveys, alongside customer-submitted information including images of their homes and charger location details.

According to Fowler’s blog post, upon investigation, he identified the data as belonging to Qmerit, a Texas-based company specializing in EV charging infrastructure installation and maintenance since 2016.

Following the responsible disclosure by Fowler, Qmerit swiftly took action to secure the exposed data and initiate an internal investigation. In response to the incident, Qmerit emphasized its commitment to prioritizing security and protecting Personally Identifiable Information (PII). However, the duration of the data exposure and potential unauthorized access remain uncertain, warranting further scrutiny through internal forensic audits.

Leading EV Charging Firm Qmerit Spills Trove of Customer Info
Screenshot from the exposed records (Screenshot credit: Websiteplanet_

Fowler clarified that his findings do not imply wrongdoing on Qmerit’s part or suggest imminent threats to customer or contractor safety. However, the incident must be taken as a lesson surrounding the importance of vital data protection measures in protecting customer privacy and maintaining trust in the market.

Despite this incident, Qmerit continues to position itself as a leading player in North America’s EV services industry, boasting partnerships with major automakers and a track record of over 269,000 EV charger installations.

  1. EV Charging Stations at Risk of DoS Attacks
  2. Navigating London’s Free Electric Car Charging Points
  3. Massive Cloud Database Leak Exposes 380 Million Records
  4. US Credit Union Service Leaks Millions of Records and Passwords
  5. Aussie Travel Agency Data Leak Puts Thousands of Tourists at Risk

[ad_2]
Source link

Galaxy Z Flip 6 could use a bigger cover display, sketchy rumor says

0
[ad_1]

A new rumor has surfaced, and this one is surprising. The Galaxy Z Flip 6 is tipped to use a bigger cover display. The current-gen model has a 3.4-inch one, but with the Galaxy Z Flip 6, Samsung could go beyond that size.

The Galaxy Z Flip 6 could include a bigger cover display according to a sketchy rumor

According to @TheGalox_, a tipster, the Galaxy Z Flip 6 will include a 3.9-inch display. That is highly unlikely, however. Why? Well, the CAD-based renders of the phone already surfaced, and from what they’ve shown us, there’s no way we’re looking at a 3.9-inch panel.

In fact, based on those renders, the Galaxy Z Flip 6 will retain the same display size. Another reason not to believe this information is the fact that Samsung does not make such changes year after year. The 3.4-inch display was implemented last year, so the Galaxy Z Flip 6 will almost certainly retain it.

The tipster did share some other details about the phone. We’re not sure how credible they are considering this display size info is almost certainly off. So, take the following information with a grain of salt.

The Snapdragon 8 Gen 3 for Galaxy will fuel the phone

He mentioned the Snapdragon 8 Gen 3 for Galaxy SoC, which is a given. A bigger cooling system is also tipped, and a 6.7-inch main display. A 50-megapixel main camera and a 12-megapixel ultrawide camera are also mentioned.

The tipster does note that a 4,000mAh battery will be included, along with an improved hinge and internal layout of components. The Gorilla Glass Armor will protect the outer display, while the device is tipped to get 7 years of updates.

Samsung’s Galaxy AI will be a part of the picture too, while “possible 12GB RAM models” were also mentioned. The Galaxy Z Flip 6 is expected to arrive alongside the Galaxy Z Fold 6 in July. July 10 has been tipped as the launch date, but nothing has been confirmed just yet.


[ad_2]
Source link

Microsoft patents Eye-Gaze technology for hands-free typing

0
[ad_1]

Eye-gaze technology is a revolutionary innovation under development by Microsoft. It could change the way users interact with applications by using eye movements. A new patent filed recently by Microsoft displays the technology’s recent advances in accessibility and user experience.

Microsoft’s Eye-Gaze technology will allow you to type using only your eyes

The patented eye-gaze system employs a ‘Dwell-free’ typing method where the user only needs to look at keys on a screen for him/her to type. Moreover, it allows users to interact with various applications just by focusing their eyes on them; hence, they can click buttons within web browsers without any physical manipulation.

Microsoft then introduced a smooth response system termed ‘dwell-free’ to remove problems regarding flickering eye movements and uneven gaze recordings. It helps to address the issue of having an accurate target where a person is looking. Also, it does not require someone to look at something for too long, thereby enhancing usability and reducing eye strain. The tech rivals the Apple Vision Pro’s eye tracking closely.

Its integration with Windows allows this technology to control mechanisms such as audio volumes through eye movements. Per WindowsReport, this technology has the potential to integrate with numerous programs. There are minimum limitations to this system, and it offers various ways to approach things.

The particular artificial intelligence-based model used in this feature’s development is fascinating. It uses collected data from consumers to provide suggestions and make predictions. By analyzing patterns in the user’s gaze, it can combine specific forms of action with visual cues improving effectiveness.

The tech will initially integrate with Windows before expanding to other platforms

Microsoft Eye-Gaze Technology also features predictive processing and smart algorithms that quickly respond to users. Although testing started on HoloLens headsets inside mixed-reality environments, experts believe that this technology will expand across all devices including mobile phones, tablets, and personal computers.

This represents a huge stride forward towards accessibility and UI innovation – perhaps suited for future AI-based Windows iterations and Microsoft Edge. This new approach may be exciting but at the same time raises questions concerning privacy plus how much freedom individuals should have when dealing with technology that is AI-driven.


[ad_2]
Source link

Beware Of New Malicious PyPI Packages Attack Crypto Wallets

0
[ad_1]

Threat actors use malicious PyPI packages to infiltrate systems and execute various attacks like data exfiltration, ransomware deployment, or system compromise. 

By masquerading as legitimate Python libraries all these packages can easily bypass security measures. 

This allows it to infect the unsuspecting users’ environments and potentially cause widespread damage.

Cybersecurity researchers at ReversingLabs recently discovered new malicious PyPI packages that could steal crypto wallet passwords.

New Malicious PyPI Packages

ReversingLabs unveiled a malicious scheme spanning seven open-source packages on PyPI, with 19 variants, the earliest dating back to December 2022. 

This ‘BIPClip’ campaign aims to steal helpful phrases for crypto wallet recovery by joining the ranks of previous supply chain attacks like 3CX’s compromise

Cryptocurrency remains a coveted target, and threat actors employ deceptive tactics like malicious dependencies and name-squatting to evade detection.

The RL research team found 7 new malicious PyPI packages aiming to steal crypto wallet phrases while staying hidden.

This campaign targets developers handling cryptocurrency wallets, especially those using BIP39 for easy-to-remember wallet generation. BIP39 simplifies seed creation with mnemonic phrases, enhancing recall for wallet owners.

Crypto infrastructure and assets remain prime targets for supply chain strikes, from the Ledger Connect Kit breach diverting transactions to covert cryptominers in Python libraries and malicious crypto-related npm packages.

Allegedly, the North Korean threat actors have stolen up to $3 billion in crypto over five years; it’s a staggering 5% of their GDP.

ReversingLabs found two PyPI packages, mnemonic_to_address, and bip39_mnemonic_decrypt, collaborating to steal crypto wallet data. 

The bip39_mnemonic_decrypt raised suspicion with Base64 decoding and network usage. Besides this further investigation revealed mnemonic_to_address as a seemingly “clean” package with bip39_mnemonic_decrypt as a hidden malicious dependency.

Code example from eth-account documentation for generating an account from a mnemonic (Source – ReversingLabs)

The mnemonic_to_address package acts as a wrapper for function calls. However, it differs subtly by using decrypt_jsBIP39 which is a function that is not found in the eth-account package.

This function is imported from the bip39_mnemonic_decrypt module, where the mnemonic_to_address package passes the user’s mnemonic passphrase as an argument.

Code from mnemonic_to_address package calls the function from the malicious bip39_mnemonic_decrypt package (Source – ReversingLabs)

The bip39_mnemonic_decrypt package is the second in the campaign and is a dependency of mnemonic_to_address. 

ReversingLabs discovered clearly malicious functionality within it. Both packages were published by james_pycode, a newly created PyPI maintainer account, a common tactic in malicious campaigns. 

The account showed minimal effort to establish credibility. Sophisticated attackers often invest resources to mimic official pages in open-source repositories.

Threat actors stealthily hide malicious code in open-source packages. They concealed malware deep within dependencies to avoid detection during code audits. 

Fraudulent function names like “decrypt_jsBIP39” and “cli_keccak256” disguised malicious actions. The malware stealthily exfiltrated crypto wallet seeds, encoding them as “license” data. 

Though limited in scope, this supply chain attack exploited developers’ trust in open-source libraries. Vigilance in vetting third-party code and security assessments is crucial to prevent such threats from targeting the lucrative crypto ecosystem.

IOCs

IoC (Source – ReversingLabs)

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link