Google wants to make in-app ads less annoying

0
[ad_1]

By now, any person using an app nowadays knows exactly how annoying in-app ads are. If you haven’t paid for the ad-free version of a game, you’re most likely stuck looking at those annoying multistage apps in between levels. Well, as announced during Google’s Google for Gaming Developer Summit 2024, the company may have found a way of making ads less annoying.

This news comes along with the announcement that Google is getting ready to bring native PC games. So, rather than relying on a launcher, you will be able to install certain Android games directly on your computer. Google is currently working on a limited selection of games at the moment. However, we expect the number to grow as time goes on.

Google will make in-app ads less annoying

Right now, we are still in the early stages of this new change, so there’s no telling when we will actually see this. Currently, when you are shown an ad during gameplay, you will either see a banner somewhere on the screen or you will see a fullscreen ad that slows things down. These are the ads that really annoy people.

According to Google, the company has a plan to make these types of ads less painful. It will allow developers to place ads in less inconvenient spots. In fact, it will let developers place ads inside of custom containers within their apps. So, Those ads will not have to take up the entire screen.

What does this mean? Well, developers will be able to place the ads inside of actual game elements or UI components within your apps. Say, you make a side-scrolling game where a character runs across the city and passes a billboard. Ostensibly, you will have the ability to place the ad within that billboard so, the player will have the ability to tap on the ad there rather than having it fill the entire screen.

Another example is the screenshot below. We see that the app was placed on the loading screen in between levels. The square box being held up by the balloons is the container, in the ad is within that. So, rather than having an entire ad break between levels, developers can use an approach like this.

in app ad example

This may go against one dynamic of using ads

Hopefully, app developers will incorporate this en masse. One reason why this may not have the desired effect is that some ads are meant to be annoying. Sure, they generate ad revenue for app developers. However, one reason why some developers place so many incessant ads into their game is that they want to push the users to pay for subscription services or buy the ad-free version of the app. So, there is a chance that we will see little inspiration for developers to use this method if it means that playing the free version of the apps will be easier.


[ad_2]
Source link

Gemini will not answer questions about elections, which is a good thing

0
[ad_1]

Well, it’s that time again. Right now, several countries in the world are getting ready to host their elections, and this includes the United States. Since generative AI makes rapid misinformation a very real threat, Google announced that Gemini will not answer questions about global elections.

Misinformation has probably been an issue ever since mankind learned how to speak. However, it’s much more of an issue now with the advent of AI. While the technology is very smart, it is not immune to generating inaccurate results. Right now, many AI chatbots have the capacity to hallucinate and produce wrongful information. That can be devastating if potential voters are given inaccurate information.

Because of this, all eyes are on companies making these AI chatbots. Companies like Google, OpenAI, xAI, Anthropic, Meta, etc. are going to have to prepare for this.

Google will not let Gemini answer questions about global elections

While we are in the dark about what most of these companies are doing, Google gave us a clue as to what it plans on doing. The company announced that if anybody asks for information dealing with any of the numerous elections going on this year, Gemini will respond with a message saying “I’m still learning how to answer this question. In the meantime, try Google search.” So, if you try to ask it any questions about current US presidential candidates, you’re likely to get stonewalled.

This doesn’t only apply to the United States election going on. There are other elections in other countries coming on as well. Since Google’s information and Gemini pretty much span the globe, other countries are just as much at risk of AI hallucinations. So, this seems like a good step for Google.

Right now, the company is struggling with AI. For starters, the Gemini image generator was taken down due to the pictures of historical figures with inaccurate skin tones, ethnicities, and genders. This is only one example of Google’s rushed mentality toward AI technology. In fact, a former Google consultant spoke about this in a video.


[ad_2]
Source link

FakeUpdates Malware Campaign Targets WordPress

0
[ad_1]
FakeUpdates Malware Campaign Targets WordPress - Millions of Sites at Risk

WordPress websites are under attack! FakeUpdates malware exploits vulnerabilities and injects malicious code. LockBit3 dominates the world of ransomware. Web server flaws leave organizations exposed. Experts advocate strong security and zero tolerance for cyber threats.

As of March 2024, approximately 835 million websites are utilizing the WordPress Content Management System (CMS). This vast presence makes WordPress an extremely lucrative target for cybercriminals.

To highlight the ongoing threats to WordPress, according to the February 2024 Global Threat Index released by Check Point Software Technologies Ltd., this week, researchers have uncovered a fresh wave of cyber threats including malware attacks aimed at WordPress websites.

The campaign, identified as FakeUpdates or SocGholish, involved compromising WordPress sites through hacked admin accounts. The malware employed various tactics, including modified versions of legitimate WordPress plugins, to infiltrate websites and deceive users into downloading a Remote Access Trojan.

Despite efforts to combat it, FakeUpdates has persisted since at least 2017, posing a significant threat to website security. Some of the attack’s examples are previously identified incidents targeting products like Windows and Chrome browsers.

In the attack, the malware primarily targets websites with content management systems, aiming to trick users into downloading malicious software. Associated with the Russian cybercrime group Evil Corp, FakeUpdates is believed to generate revenue by selling access to infected systems.

As per the research shared with Hackread.com ahead of publication on Monday, Maya Horowitz, VP of Research at Check Point Software, emphasized the importance of protecting websites from cyber threats.

She highlighted the critical role websites play in modern society and the potential consequences of malware attacks on online presence and reputation. Horowitz stressed the need for proactive measures and a zero-tolerance approach to cybersecurity threats.

LockBit and Ransomware

Check Point’s Global Threat Index also revealed insights into ransomware activities, including data from approximately 200 ransomware “shame sites” operated by double-extortion ransomware groups.

Lockbit3, despite its shutdown, not only returned also but remained the most prevalent ransomware group in February, responsible for 20% of reported incidents. Play and 8base followed closely, with 8% and 7% of incidents, respectively. Play, which entered the top three for the first time, was responsible for a recent cyberattack on the city of Oakland.

Additionally, the report highlighted the most exploited vulnerabilities globally in February. The “Web Servers Malicious URL Directory Traversal” vulnerability affected 51% of organizations, followed by “Command Injection Over HTTP” and “Zyxel ZyWALL Command Injection,” each impacting 50% of organizations.

Protect Your WordPress Website

Here are 6 important tips to protect your WordPress website:

Strong Login Credentials:

  • Always use a strong and unique password for your WordPress admin account. Avoid using easily guessable information like your name, birthday, or pet’s name.
  • Consider using a password manager to generate and store strong passwords for all your online accounts.
  • Enable two-factor authentication (2FA) for an extra layer of security. This requires a second verification code, typically sent to your phone, in addition to your password when logging in.

Regular Updates:

  • Regularly update your WordPress core, themes, and plugins. Updates often contain security patches that address newly discovered vulnerabilities.
  • You can enable automatic updates in the WordPress dashboard to ensure your website stays up-to-date.

Security Plugins:

  • Consider installing a security plugin to add additional layers of protection to your website. These plugins can help monitor your website for malware, block suspicious activity, and protect against brute-force login attempts.

Backups:

  • Regularly back up your website files and database. This will allow you to restore your website to its previous state if it is compromised by a cyberattack.
  • There are several plugins available that can automate the backup process.

Limit User Access:

  • Only grant users the minimum level of access they need to perform their tasks. For example, if a user only needs to edit blog posts, there is no need to give them administrator privileges.

Secure Hosting Provider:

Choose a reputable web hosting provider that prioritizes security measures. While choosing a hosting service, always look for features like the following:

  • Regular security audits and vulnerability assessments.
  • Automatic malware scanning and removal.
  • Firewalls and intrusion detection systems.
  • Secure data centres with physical and digital access control.
    1. Fake Lockdown Mode Exposes iOS Users to Malware Attacks
    2. Fake Skype, Zoom, Google Meet Sites Infect Devices with RATs
    3. The Fake Fix: New Chae$ 4.1 Malware Hides in Driver Downloads
    4. Hackers on WordPress Websites Hacking Spree with Balada Malware
    5. Fake Resumes, Real Malware: TA4557 Exploits Recruiters for Backdoor

[ad_2]
Source link

Samsung treats US Galaxy S22 users with the March update

0
[ad_1]

Samsung has released its March update for the Galaxy S22 series in the US. The 2022 flagship lineup joins the Galaxy S24, Galaxy S23, and the past two generations of Galaxy foldables in this group. The company will update more devices in the coming weeks.

Galaxy S22 receives Samsung’s March update in the US

As of this writing, the March 2024 update is rolling out to carrier-locked variants of the Galaxy S22 trio in the US. More specifically, the update is available for users on Verizon’s network. Samsung should soon cover other carrier variants and expand the rollout to unlocked units. International versions of the phones should also pick up the update over the next few days.

The latest update for the carrier-locked Galaxy S22, Galaxy S22+, and Galaxy S22 Ultra in the US comes with the firmware build number S90*USQS4DXBG. The official changelog confirms that it is all about this month’s security fixes. “The current software update provides the most up-to-date Android security patches on your device,” Verizon says in its release notes. So, don’t go deep looking for anything else.

While there aren’t any new features or functional improvements to look forward to, Samsung’s March 2024 SMR (Security Maintenance Release) contains some critical security fixes for Android OS. So, you should install this update as soon as possible. The Korean firm has combined a total of 46 vulnerability patches in this release, including nine Galaxy-specific patches and 37 Android OS fixes from Google.

If you are using a carrier-locked Galaxy S22 on Verizon’s network in the US, you should receive this update anytime now if you haven’t already. Users on other networks or with an unlocked unit can also look forward to it. Like before, you can check for updates from the Settings app. Go to the Software update menu and tap on Download and Install. You may also get a notification once Samsung’s OTA (over-the-air) rollout hits your Galaxy device.

Galaxy S22 series will get One UI 6.1

Samsung launched the Galaxy S24 series with One UI 6.1 out of the box. The new One UI version brings AI features, UI improvements, smoother animations, and more. The company plans to push these changes to compatible older models starting this month. The Galaxy S23 series will get it first, followed by other models. Samsung’s recent foldables and older flagships may get this update in April. We will let you know when the rollout begins.


[ad_2]
Source link

See the Rabbit R1 in action in this demo video

0
[ad_1]

Not too long ago, we got information about an Innovative AI device called the Rabbit R1. This is a mobile device that will use AI to be your personal assistant. Rather than using software and applications to perform tasks, it will seamlessly contact AI models in the cloud to perform them. We just got a demo of the Rabbit R1, and it shows that this device will be rather Snappy.

The Rabbit R1 has been circulating a fair bit recently since its announcement. This is a personal assistant that you carry around with you.  If you want to perform tasks, you simply have to talk to it like you would a chatbot. It will then perform these tasks by contacting AI models in the cloud. If you want it to answer questions, book a flight to a different country, etc., it will be able to do it. So far, we don’t know too many of the capabilities of this device, but that remains to be seen.

A new Rabbit R1 demo just showed off the device’s note-taking capabilities

We just got our first glimpse of the Rabbit R1 in action, and it looks like it’s going to be a pretty useful pocket assistant. In the demo, Rabbit CEO Jesse Lyu gave us a sneak peek of what this little device can do. In a nearly 2-minute-long video, he showed us how easy it is to use the Rabbit R1 as a note-taking device. You simply have to activate the assistant and ask it to record a note. It will then begin recording. What was impressive was the speed at which the recorder started recording. It was lightning quick.

From there, we saw that the recording was saved and stored within a Cloud Server.  You’re quickly able to access the saved recording by going to the website. There, you can listen to the recording and download it.

That was only one small example of what this little device can do. We’re all excited to see what else it will be able to do in the near future.

If you’re excited about the Rabbit R1, you can place your pre-order today. This device is going to retail at $199 when it launches. The $199 price tag is a lot more reasonable than the $699 price tag of the AI Pin. Both of these devices strive to do the same thing, knock the smartphone out of your hand and replace it with an AI-powered assistant.

The future

That dream seems very far-fetched, as these devices are missing a key aspect of a mobile device, a user interface. Sure, you’ll be able to access all sorts of functionalities by using your voice, but not all situations are suitable for speaking to your device.

Another thing to know is being able to interact with files and media on your device is also a boon. You’re able to access the recording made by the Rabbit R1 on your Internet-connected computer. that’s great, but, that’s not as convenient as being able to save, rename, edit, and share the recording by using a simple app interface.

That’s the only one of the potential issues that devices like these will run into. Creating an appless world will be rather difficult, as there are hundreds of thousands if not millions of app developers out there. Getting rid of apps will get rid of millions of jobs from millions of companies and dev studios around the world.

In any case, we have no idea what the future holds for devices like these. For all we know, in a year’s time, the smartphone might look very different from what it looks like today, and it might be more rabbit-shaped.


[ad_2]
Source link

X (formerly Twitter) prepares passkeys support on Android

0
[ad_1]

X, the social media platform formerly known as Twitter, is reportedly working on bringing passkey support to its Android app, following the iOS rollout. The addition of this feature will provide a more convenient and secure way to log in to the app for Android users.

What are passkeys?

In case you are not familiar, passkeys are an alternative authentication method that eliminates the need to remember complex passwords. Instead, they rely on a combination of secure ways to authenticate, such as biometrics (fingerprint or facial recognition) or device-specific cryptographic keys. This makes your online accounts far less vulnerable to hacking or phishing attempts.

Support for passkeys has already been rolled out to the iOS version of the app, and according to findings by @AssembleDebug from The SP Android, it is soon coming to Android as well. During a code deep dive, references to the passkey feature were found in the X/Twitter beta app (version 10.32.0-beta). While forcing the feature to turn on by tweaking the code, @AssembleDebug was able to get a screenshot of the settings screen but not actually get the feature to work.

Passkeys settings found inside the X Android app | Image credit: TheSPAndroid/@Assembledebug

This suggests that the feature is actively in development, and, while not yet fully functional, is most likely close to its debut. Once launched, you’ll find the passkey settings within the X app under Settings and privacy > Security and account access > Security > Additional password protection.

A password-less future

Passkeys offer a superior level of security compared to traditional passwords. Passwords can be easily stolen, guessed, or exposed in data breaches. Passkeys, being tied to your device and often requiring biometric verification, are far more difficult to compromise.

X’s adoption of passkeys aligns with a growing industry trend toward passwordless authentication. This shift promises a more user-friendly and secure online experience for its users.


[ad_2]
Source link

Hackers Deliver MSIX Malware in The Lure of Freemium

0
[ad_1]

Cybercriminals usually use free apps to take advantage of the large number of people who use them freely. 

The broader user base serves as a larger attack surface that ensures the effective distribution of malware. 

In addition, this could happen if third-party plugins or features have been integrated into freemium apps, which the attackers can exploit to gain unauthorized access.

Cybersecurity researchers at ASEC recently discovered that hackers have been delivering MSIC malware in the lure of freemium productivity apps.

Hackers Deliver MSIX Malware

The Malicious MSIX file masquerades as a Notion installer, and the website mimics the official page.

Notion-x86.msix’ Windows app installer signed with a valid certificate is delivered. 

Fake website (Source - ASEC)
Fake website (Source – ASEC)

Besides this, the install prompts seemingly legitimate Notion deployment, but the system gets malware-infected.

The signature information of the malicious installer (Source - ASEC)
The signature information of the malicious installer (Source – ASEC)

The user clicks Install and gets malware-infected Notion. Installs create StartingScriptWrapper.ps1 and refresh.ps1 in the app path, ASEC said.

StartingScriptWrapper.ps1 has an MS signature that executes Powershell script from the argument and reads config.json during installation and script execution.

The refresh.ps1 is the malware that fetches and executes C2 commands.

However, it’s heavily obfuscated using blank characters integers added/multiplied to decode a 200-character command from an 8,663-character obfuscated script.

200-char command fetches and executes additional PowerShell from C2.

The initial analysis confirmed LummaC2 malware distribution. 

Logs show hxxps[:]//fleet-contents.com/1.dat downloaded, run in PowerShell.exe – likely C2 response to fetch/load 1. dat. 

1.dat is .NET EXE using process hollowing to inject LummaC2 into RegAsm.exe. While the malicious behavior process tree starts from the Windows Installer service host.

The process tree (Source - ASEC)
The process tree (Source – ASEC)

LummaC2 is an info stealer targeting browser data, crypto wallets, and files.

Users are advised to verify file sources match official domains and check signature authors despite legitimate certificate usage.

IoCs

Distribution Websites

  • hxxps://trynotion[.]org
  • hxxps://notion.rtpcuan138[.]com
  • hxxps://emobileo[.]com/Notion-x86.msix

File

  • d888a82701f47a2aa94dcddda392c07d (Dropper/APPX.LummaC2 2024.02.28.00) (Notion-x86.msix)
  • 3cdc99c2649d1d95fe7768ccfd4f1dd5 (Downloader/PowerShell.Obfus 2024.02.28.00) (refresh.ps1)
  • 8a3a10fcb3f67c01cd313a39ab360a80 (Trojan/Win.Generic.C5557471 2024.02.27.01) (dat1)

C2

  • hxxps://ads-tooth[.]top/check.php (refresh.ps1)
  • hxxps://fleetcontents[.]com/1.dat (check.php)
  • hxxps://problemregardybuiwo[.]fun/api (LummaC2)
  • hxxps://technologyenterdo[.]shop/api (LummaC2)
  • hxxps://lighterepisodeheighte[.]fun/api (LummaC2)
  • hxxps://detectordiscusser[.]shop/api (LummaC2)
  • hxxps://edurestunningcrackyow[.]fun/api (LummaC2)
  • hxxps://pooreveningfuseor[.]pw/api (LummaC2)
  • hxxps://turkeyunlikelyofw[.]shop/api (LummaC2)
  • hxxps://associationokeo[.]shop/api (LummaC2)

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are incredibly harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

WhatsApp thinks that pinning 3 chats is too little

0
[ad_1]

About seven years ago, WhatsApp gave people the ability to pin important chats to the top of their chat feed. This is something that greatly helps people put a spotlight on their most important chats. However, you’ve been able to pin only a few chats, and that’s rather limiting. Fear not, as WhatsApp is working on the ability to pin more chats to your feed.

As it stands,  you can only pin three conversations to the top of your feed. If you are a casual WhatsApp user, then that might not be a big issue. However, if you are a more seasoned user with plenty of contacts, then three might seem a little bit cramped. In order to pin your conversations, all you have to do is go to your conversation feed, hold your finger down on one of the conversations, and tap on the Pin icon at the top of the screen. It will then stick to the top of your feed no matter which other conversations flood in.

 WhatsApp will let you pin more conversations

We’re not entirely sure why WhatsApp only limited you to three pinned conversations. However, we can’t argue with progress. As spotted by the folks at WABetaInfo, in the latest WhatsApp beta for Android (version 2.24.6.13), it appears that WhatsApp is going to give you the ability to pin more chats to your chat feed. While you will be able to pin more, the increase is a bit underwhelming. According to the report, you will be able to pin up to five chats rather than three. So, you’ll be able to add two more chats to your feed.

It’s odd that WhatsApp is only adding two more chats, and it’s also odd that the company is beta-testing it. We would expect a feature as small as this to just be rolled out. Anyway, since this is such a small addition to the software, we don’t expect it to be in beta testing for too long. If you’ve been itching to pin just two more pinned conversations to your chat feed, then your chance will come soon enough.


[ad_2]
Source link

Gemini will make Google Slides much less frustrating

0
[ad_1]

At this point, Gemini has been implemented into many corners of Google, for better or Worse. Well, we just got the news that it made it into another Google product, and people will love this one. Gemini has been added to Google Slides, and it will allow users to remove the background from images.

Google Gemini is the company’s flagship AI model, and it’s accessible through several services. One example is the fact that Gemini Nano, the smallest version of Gemini, is available on a few smartphones. This includes a Google Pixel 8 Pro (Review). However, people wanting it to come down to the base Pixel 8 will be very disappointed. Google announced that Gemini Nano is not coming to the base Pixel 8 because of “hardware limitations.” This is a pretty big bummer and rather confusing. The Pixel 8 Pro and the Pixel 8 both use the same processor.

Google added Gemini to Google Slides, and it allows you to remove the background of images

We all like to add our own special flair to our presentations, and this may include using images with transparent backgrounds. However, that’s not always the case. People can search for PNG files online, however, there’s no guarantee that they’ll find the perfect picture.

So, if you need to have pictures for transparent backgrounds for your Slides presentation, Gemini might be able to help you. Using Google Slides, select the image that you want to remove the background from. Then, right-click the image or click on the Remove Background button on the toolbar. Then, using Gemini’s advanced computational capabilities, Slides will remove the background from the image. So, you’ll be able to freely move the image without the background.

Obviously, with any sort of background removal tool, the results will vary depending on the picture. You want to make sure that the subject is clearly in the foreground and that the background isn’t too convoluted or similar to the subject. It will be much easier to remove a black cat from a snowy-white background than to remove a green alligator from a grassy background. These are just things to keep in mind.

Availability

Unfortunately, not everyone will be able to use this feature. If you want to use this feature, you will need to have the Gemini Enterprise or Gemini Business add-on added to your workplace account. If you have a personal account, then you will need to have the Google One AI Premium plan. This will also give you access to Gemini Advanced.


[ad_2]
Source link

WordPress Plugin Flaw Exposes 2L+ Websites to XSS Attacks

0
[ad_1]

Over 200,000 websites have been left vulnerable to Cross-Site Scripting (XSS) attacks due to a flaw in the Ultimate Member plugin for WordPress.

This vulnerability, discovered by a researcher known as stealthcopter, underscores the ongoing risks in the digital ecosystem and highlights the critical role of cybersecurity firms like Wordfence in safeguarding the web.

Discovery and Disclosure

During the Wordfence Bug Bounty Extravaganza, stealthcopter submitted a report detailing an unauthenticated stored XSS vulnerability in the Ultimate Member plugin.

Document
Integrate ANY.RUN in your company for Effective Malware Analysis

Malware analysis can be fast and simple. Just let us show you the way to:

  • Interact with malware safely
  • Set up virtual machine in Linux and all Windows OS versions
  • Work in a team
  • Get detailed reports with maximum data
  • If you want to test all these features now with completely free access to the sandbox:

This plugin, designed for user profile, registration, and membership management on WordPress sites, boasts over 200,000 active installations, making the potential impact of this vulnerability substantial.

Wordfence, a leading security service for WordPress websites, awarded Stealthcopter a $563 bounty for this discovery.

The company’s swift action in validating and disclosing the vulnerability to the Ultimate Member team exemplifies its commitment to securing the web. By March 6, 2024, a patch was released, mitigating the risk for millions of web users.

Technical Breakdown

The vulnerability, CVE-2024-2123, allows attackers to inject malicious scripts into web pages via several parameters in Ultimate Member plugin versions up to and including 2.8.3.

This flaw arises from insufficient input sanitization and output escaping, particularly in the plugin’s member directory list functionality.

An examination of the plugin’s code revealed that user display names were displayed unescaped in template files, making it possible for attackers to provide a name containing a malicious script during registration as an unauthenticated user.

This could lead to a range of malicious activities, including adding administrative users, redirecting harmful sites, and injecting backdoors into theme and plugin files.

The revelation of this vulnerability has highlighted the importance of regular updates and vigilant security practices for website administrators.

Websites running outdated versions of the Ultimate Member plugin were at risk of being exploited by unauthenticated attackers, potentially leading to unauthorized administrative access and further compromise.

Wordfence has been at the forefront of addressing this vulnerability, providing immediate protection to its users through the Wordfence firewall’s built-in XSS protection.

This includes customers of Wordfence Premium, Wordfence Care, and Wordfence Response, as well as users of the free version of the plugin.

The swift identification, reporting, and patching of the XSS vulnerability in the Ultimate Member plugin testifies to the collaborative efforts between cybersecurity researchers and developers in protecting the digital landscape.

Wordfence’s role in this process not only highlights its commitment to web security but also reminds us of the importance of proactive security measures and regular software updates.

WordPress site owners are urged to update their installations to the latest patched version of Ultimate Member (2.8.4) to safeguard against potential exploits.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are incredibly harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link