HONOR Magic6 Ultimate Edition design officially revealed

0
[ad_1]

Both the HONOR Magic6 Ultimate Edition and Porsche Design HONOR Magic6 RSR are coming on the same day, March 18. That being said, the design of the HONOR Magic6 Ultimate Edition has just been revealed.

HONOR just revealed the design of the HONOR Magic6 Ultimate Edition handset

HONOR itself revealed its design. We got to take a look at its camera shape recently, and now we get to see the vast majority of its backplate. If you check out the three images below, you’ll get to see the phone.

As you can see, black and purple color variants are teased here. Those are likely the only color options that we’ll be able to get. You can clearly see that the back side of the phone is vastly different than what the Magic6 Pro delivers.

The camera island has a different shape, and curved glass on top

The camera island on the back has a completely different shape, though the camera layout is still the same. The top-right and bottom-left corners of the camera island are more rounded than the other two corners.

The glass on top of the cameras is also curved towards the sides. HONOR will seemingly use vegan leather on the back of the HONOR Magic6 Ultimate Edition. That goes for both color variants of the phone.

HONOR will add plenty of character to the backplate

You will also notice that HONOR is also using vertical protrusions on the back. A small one above the camera island, and a larger one below it. That will likely be useful for grip purposes, at least based on where it’s located. This phone should be quite grippy in general, though, due to the use of vegan leather.

The phone will be fueled by the Snapdragon 8 Gen 3 SoC. A 6.8-inch 2800 x 1280 LTPO AMOLED display will be used, with up to 120Hz refresh rate. The phone will likely offer up to 16GB of RAM, perhaps even up to 24GB.

A 5,600mAh battery will be used, while 80W wired and 66W wireless charging will be supported. The camera setup will be the same as on the HONOR Magic6 Pro, most likely. You can read our Magic6 Pro review if you’d like to know more about it.


[ad_2]
Source link

X plans to remove likes & reposts from your feed

0
[ad_1]

Twitter, now X, has undergone several changes since its acquisition by business leader Elon Musk. One of the most controversial changes remains its rebranding to X.com, offering verification badges for a price. But if that’s not enough, Musk might’ve other plans. In a series of posts shared by Elon Musk, he may have announced the future overhaul of X. This time, it’s not a minor but a substantial overhaul.

Elon Musk now wants to remove likes and reposts from X’s feed in favor of total views

As indigestible as it may seem, never doubt Elon, especially when he wants something specific. He wants to remove the likes and reposts from the X’s feed in favor of the total “view count” because according to him, that’s “very clean”. Of course, he adds that he’s “been dying to do this for a year”.

This first came to light after DogeDesigner posted that X may be considering removing the likes and reposts from the feed. However, the catch of the account pinned is you can see them once you tap on the post. Musk replied to the post, confirming “That is definitely happening.”

In the tipped layout, the count of views on posts, which tells you how many people are interested, will be shifted to the top right near the posting time. To engage with the post in this updated format, you’ll swipe right to reply and swipe left to favorite it. Musk mentioned that once you tap on the post, you’ll see the number of likes, reposts, and favorites it has, but it’s still being determined if their display will change.

This is how the UI will look like

Another reliable tipster Abhishek Yadav has shared a screenshot of how the platform would look, once this feature comes to life.

If you know Elon Musk, you’d know he has a thing for aesthetics. Notably, he put his platform through some changes earlier, including the removal of URL cards. But he brought it back after a short hiatus.


[ad_2]
Source link

Elon Musk: “OpenAI is a lie”, xAI will open-source Grok. Carl Pei: “Based”

0
[ad_1]

Elon Musk announced that his AI company – xAI, will open-source the Grok chatbot, OpenAI’s ChatGPT rival (via Reuters).

To “open-source” means to share a program’s code with everyone for free, so anyone can use, change, and share it again. It’s like sharing a recipe publicly, so people can tweak it, improve it, or make something new with it. This helps make the program better and more secure because lots of eyes are looking at it and helping fix any problems.

Carl Pei is impressed, and comments:Here’s the original Elon Musk tweet itself:Then, another X user says that “OpenAI should do the same. If they are “open” that is”, to which Elon Musk has this to say: “OpenAI is a lie”. Here’s that post:Earlier this month, Elon Musk filed a lawsuit against OpenAI, the company behind ChatGPT, and its CEO Sam Altman. Musk accused them of straying from the company’s founding goal of developing artificial intelligence to benefit humanity, rather than for profit.This is quite the twist, given that the day after OpenAI’s launch in December 2015, when co-founder Sam Altman emphasized his trust in co-chair Elon Musk and their shared vision for safely distributing AI.

Nearly ten years later, Musk and Altman are disputing the future of AI, as Musk has sued OpenAI in California, accusing Altman and others of deviating from the company’s original altruistic mission by seeking commercial gain.

During a podcast with computer scientist Lex Fridman in November, Musk expressed his appreciation for the idea of AI that is open-source. That same month, his startup released its AI model to a select group of users.

Following this, in December, Musk’s company introduced Grok, a rival to ChatGPT, exclusively for Premium+ subscribers of the social media platform X. Musk’s vision for Grok is to create an AI that is devoted to seeking the truth to the utmost degree.


[ad_2]
Source link

WordPress Sites Exploited To Brute-Force Passwords Via Browsers

0
[ad_1]

According to a recent post from Sucuri, their website scanner detected an active distributed brute-force attack exploiting WordPress sites to steal other sites’ passwords. The attackers inject malicious scripts into the target websites, which execute whenever a visitor reaches those sites. Then, the scripts lure users into performing the action as directed, convincing them to hand over their data.

As explained, the researchers found this tactic in use for some time, attracting Sucuri’s attention for injecting crypto wallet drainers. The researcher followed the initial malware campaigns, observing two iterations. Even since February 2024, they found over 1200 websites infected with malware injected via cachingjs/turboturbo.js script.

Following this campaign, the researchers observed a shift in the attackers’ target, switching from injecting crypto drainers to brute-force scripts. So, when a visitor reaches the compromised website, the script hijacks the visitor’s browser and brute force passwords for other websites.

For this, the scripts are loaded to the browsers via https://dynamic-linx[.]com/chx.js. Once the victim browser connects to the attacker’s server, it receives brute-force tasks from the server https://dynamic-linx[.]com/getTask.php. This task arrives as a JSON file that includes all bruteforce parameters, such as the target site’s URL and a list of passwords to try. Upon successful brute-force of credentials, the browser sends the task completion intimation to the attackers’ server, asking for the next task.

The researchers have shared a detailed technical analysis of this campaign in their post. Since the attack happens sneakily, it gets difficult for the victim users to protect their passwords. Nonetheless, as the researchers suggested, users can still prevent the threat by setting up strong passwords for their accounts. Likewise, WordPress admins may restrict their sites’ login interface to trusted IPs only.

Let us know your thoughts in the comments.


[ad_2]
Source link

Porsche Design HONOR Magic6 RSR will launch on March 18

0
[ad_1]

Last month, HONOR confirmed that the Porsche Design HONOR Magic6 RSR is coming. In a separate announcement, the company also said it’s coming in March. Well, now we know its launch date. The Porsche Design HONOR Magic6 RSR will launch on March 18.

The Porsche Design HONOR Magic6 RSR launch date has been revealed

This confirmation comes from HONOR China, via Weibo (China’s social media network). So, it’s safe to say that the launch will occur in China. That phone is expected to become available globally too, however.

Porsche Design HONOR Magic6 RSR launch date

This device will become the second Porsche Design device that was announced this year. It’s also the second device that Porsche Design and HONOR delivered in general. The Porsche Design HONOR Magic V2 RSR arrived not long ago.

The device will have a different back side than the HONOR Magic6 Pro

The Porsche Design HONOR Magic6 RSR is expected to have a different backplate than the HONOR Magic6 Pro (including the camera island design). Other than that, the two phones will probably be the same.

We are expecting the same specifications under the hood. Well, the Porsche Design model could end up offering more RAM, or something of the sort, but all the rest of its specs are expected to remain the same.

The ‘Ultimate’ version could have the same design

We are expecting the design to be the same or at least similar to what the HONOR Magic6 Ultimate will deliver. That phone is coming on the same date, by the way, March 18. It will also launch during the same event, so… there you go. You can check out the expected camera design and backplate finish below.

HONOR Magic6 Ultimate Edition teaser featured

The Porsche Design HONOR Magic6 RSR will be fueled by the Snapdragon 8 Gen 3 processor. A 6.8-inch 2800 x 1280 LTPO OLED display will be in use, and that will be a 120Hz panel. Android 14 will come pre-installed along with MagicOS 8.0. Advanced facial scanning will also be a part of the package, along with 80W wired, and 66W wireless charging. You can read our HONOR Magic6 Pro review for more information.


[ad_2]
Source link

Russian hackers stole Microsoft’s source code repositories

0
[ad_1]

Microsoft is grappling with the aftermath of a nation-state attack, revealed earlier this year, perpetrated by the group known as Midnight Blizzard or Nobelium. Initially targeting the company’s corporate email systems, the attack has now extended to compromising source code repositories and internal systems, Microsoft disclosed in a recent blog post. This breach poses significant concerns as hackers exploit exfiltrated data from Microsoft’s corporate email systems to gain or attempt to gain unauthorized access. Reportedly, this includes access to some of the company’s source code repositories and internal systems.

Midnight Blizzard attempted to leverage shared secrets between Microsoft and its customers

The attack, attributed to Midnight Blizzard, has evidence that suggests attempts to leverage stolen information. It includes shared secrets between Microsoft and its customers. Microsoft emphasizes that while there is no evidence of compromise to customer-facing systems, the breach underscores the importance of proactive security measures from the company.

Password spray attacks have seen a 10-fold increase in volume since the attack in January. As HYPR notes, this is a type of brute force attack. Threat actors utilize a large dictionary of potential passwords for this purpose. They attempt a single password on many accounts. Then they move on to the next one and repeat the process.  In the context of the Windows maker, it indicates a sustained and coordinated effort to infiltrate the company’s infrastructure.

Despite ongoing investigations into Midnight Blizzard’s activities, the threat landscape remains challenging. Microsoft acknowledges the unprecedented scale of the global threat landscape. The company notes, “It [Midnight Blizzard] may be using the information it has obtained to accumulate a picture of areas to attack and enhance its ability to do so.”

Microsoft says they are taking measures to improve their security infrastructure

Microsoft’s response to the ongoing attack includes bolstering security controls, detection mechanisms, and monitoring capabilities across its infrastructure. “Across Microsoft, we have increased our security investments, cross-enterprise coordination, and mobilization, and have enhanced our ability to defend ourselves and secure and harden our environment against this advanced persistent threat,” notes Microsoft in a recent blog post. “We have and will continue to put in place additional enhanced security controls, detections, and monitoring.”

The company also remains committed to sharing insights from its investigations to enhance industry-wide resilience against cyber threats.

While details of the compromised source code and internal systems remain undisclosed, the breach highlights the need for organizations to prioritize cybersecurity readiness. Microsoft’s experience serves as a stark reminder of the ever-present threat posed by determined adversaries. It necessitates a proactive approach to safeguarding sensitive data and critical infrastructure.


[ad_2]
Source link

Is your WhatsApp chat secure? New feature will tell you

0
[ad_1]
WhatsApp, as one of the world’s most popular messaging apps, is constantly striving to enhance user experience with regular updates and new features. Now, a modest yet handy feature is in the pipeline.

As per WABetaInfo, the reliable source for WhatsApp updates, the Meta-owned app is introducing a feature to indicate end-to-end encrypted conversations. This new feature was discovered in the latest WhatsApp beta for Android 2.24.6.11 update, currently accessible on the Google Play Store.

The purpose of this feature is to make it simple for you to identify which chats are end-to-end encrypted, assuring you that your conversations are secure.

In the screenshot, you can notice a new label under the contact or group name in chats, highlighting the end-to-end encryption status. This feature ensures you always know when your chats are securely encrypted using the Signal protocol. It’s a visual cue that your messages and calls are safe from prying eyes and ears.

Keep in mind that this caption is temporary. According to WABetaInfo, it will only be visible for a short time before being replaced by the last-seen indicator.

This feature, signaling end-to-end encryption in chats, is currently available to beta testers who install the latest updates of WhatsApp beta for Android from the Google Play Store. The rollout is expected to extend to more users over the next few weeks.

Encryption plays a crucial role in modern messaging apps, ensuring that conversations remain protected and secure. End-to-end encryption (E2EE) is a security method that scrambles data between two communicating devices, such as smartphones. The data is only unreadable gibberish (ciphertext) to anyone who doesn’t have the special key to unscramble it (decrypt) into its original form (plaintext).


[ad_2]
Source link

Matanbuchus Malware Weaponizing XLS files to Hijack Windows

0
[ad_1]

The Matanbuchus malware has been reported to initiate a new campaign, exploiting XLS files to compromise Windows machines.

This sophisticated threat, known for its loader-as-a-service model, has been active for several years and poses a risk to users worldwide.

Matanbuchus, a name that has become increasingly familiar among cybersecurity experts, has found a new method to infiltrate systems.

By leveraging malicious XLS files, the malware fetches a JavaScript (JS) file, which subsequently downloads a malicious Dynamic Link Library (DLL), marking the beginning of a potential cascade of infections.

This technique underscores the evolving nature of cyber threats and the continuous need for vigilance.

A Closer Look at Matanbuchus

Originally surfacing in 2021, Matanbuchus has not only persisted but evolved, showcasing the adaptability and persistence of cybercriminals.

Document
Integrate ANY.RUN in your company for Effective Malware Analysis

Malware analysis can be fast and simple. Just let us show you the way to:

  • Interact with malware safely
  • Set up virtual machine in Linux and all Windows OS versions
  • Work in a team
  • Get detailed reports with maximum data
  • If you want to test all these features now with completely free access to the sandbox:

As a loader, its primary function is to facilitate the download and execution of other malicious payloads, effectively acting as a gateway for further exploitation.

Its capabilities are notably sophisticated, allowing for direct memory execution of .exe or .dll files, task schedule modifications, custom PowerShell command execution, and standalone executables to load additional malicious DLLs.One of the more alarming aspects of Matanbuchus is its association with Cobalt Strike beacons.

While a legitimate penetration testing tool, Cobalt Strike has been co-opted by threat actors for malicious purposes.

The malware’s ability to drop these beacons on compromised machines significantly enhances the threat actors’ control over the infected system, enabling a wide range of malicious activities.

Broadcom has recently disclosed the Matanbuchus campaign, which involves the use of a malicious XLS file.

This campaign is designed to exploit vulnerabilities in Microsoft Excel and potentially allow threat actors to execute malicious code on target systems.

Specific identifiers such as ACM.Ps-Rd32!g1, Scr.Malcode!gen, Trojan.Gen.MBT, and Trojan. Mdropper, among others, has been deployed to recognize and neutralize threats posed by Matanbuchus.

The Importance of Vigilance

The resurgence and evolution of Matanbuchus underscore the dynamic and persistent nature of cyber threats.

Users and organizations are urged to stay informed about the latest cybersecurity developments and to adopt robust security measures to protect against such sophisticated threats.

Regular updates, cautious email handling, and the use of reputable security solutions are fundamental to maintaining a strong defense against the ever-changing tactics of cybercriminals.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are incredibly harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

A week in security (March 4 – March 10)

0
[ad_1]

March 8, 2024 – The flaws could allow an attacker with privileged access to a guest VM to access the hypervisor on the host.

March 8, 2024 – Users of JetBrains TeamCity on-prmises server need to deal with two serious vulnerabilities.

March 7, 2024 – Pet retail company PetSmart has emailed customers to alert them to a recent attack that used reused passwords.

March 7, 2024 – The US Treasury Department has sanctioned Predator spyware vendor Intellexa Consortium, and banned the company from doing business in the US.

March 6, 2024 – The ALPHV gang’s attempt to cover up an exit scam isn’t going well.


[ad_2]
Source link

WhatsApp is ready to interoperate with third-party messengers

0
[ad_1]

In a recent blog post, Meta has explained how third-party messengers will interlink with Messenger and WhatsApp. The company’s initiation into this venture follows the release of the Digital Markets Act (DMA) by the European Union, a regulation that takes effect this week. Meta says it will use its existing client/server architecture to achieve interoperability.

Meta explains how third-party messengers will safely integrate with WhatsApp

The firm claimed that this method not only meets the DMA’s requirements but also offers user security and privacy for other providers integrating with Meta. The interoperability framework has been in the works in collaboration with the European Commission for over two years.

Engadget notes that Meta will initially keep the system limited to text-based messaging, sharing images, voice notes, videos, and other document files. Group chats, calling features, and third-party app interoperability may come later.

Third-party developers looking to connect with Messenger and WhatsApp will likely have to use the Signal protocol for now. Meta currently uses Signal for end-to-end encryption (E2EE) in both apps as it is considered an industry standard. Developers may use compatible protocols if they can show they offer equivalent security guarantees to Signal.

Meta recommends caution and explains when messages remain within either the WhatsApp or Messenger ecosystems, the company controls both sending and receiving clients. This way, Meta ensures content is visible only to intended recipients. However, when messages go through third-party apps from other endpoints outside these ecosystems, Meta does not control them and cannot guarantee security.

Developers will face these limitations before crossing with WhatsApp

To integrate their apps with Messenger and WhatsApp, developers must host media files they send on their servers; WhatsApp or Messenger will then download these files via a Meta proxy service. The makers of a third-party messaging app must sign an agreement with Meta to enable interoperability.

The company commits that once it has received an onboarding request from a developer, it will try to activate interoperability with that service within three months. However, the functionality could take longer before going official publicly. Meta plans on enabling a seamless connection between its messaging apps and those from other developers while prioritizing user privacy and security. By including interoperability within its ecosystem, developers and users will have more opportunities at their disposal.


[ad_2]
Source link