PetSmart warns of Active Password Cracking Attacks

0
[ad_1]

PetSmart, Inc. is a renowned retail chain operating in the United States, Canada, and Puerto Rico.

It offers a comprehensive range of pet products and services such as pet supplies, grooming, training, and in-store adoptions.

PetSmart prides itself on being a trusted partner to pet parents and a dedicated advocate for pets’ well-being.

PetSmart has issued a warning regarding an uptick in password-guessing attempts on their website.

The pet retail giant reassures that there has been no breach of their systems, but the increased activity has prompted them to take precautionary measures.

Security Measures in Place

PetSmart’s vigilant security tools detected the unusual activity, which led to the company’s decision to deactivate the passwords of potentially affected accounts.

Document
Integrate ANY.RUN in your company for Effective Malware Analysis

Malware analysis can be fast and simple. Just let us show you the way to:

  • Interact with malware safely
  • Set up virtual machine in Linux and all Windows OS versions
  • Work in a team
  • Get detailed reports with maximum data
  • If you want to test all these features now with completely free access to the sandbox: ..

Customers will need to reset their passwords the next time they attempt to log in to petsmart.com.

The company has provided straightforward instructions for password reset:

users can click the “forgot password” link on the login page or directly navigate to www.petsmart.com/account/ to initiate the process.

A Call for Stronger Password Hygiene

The PetSmart Data Security Team emphasizes the importance of robust password practices in the face of persistent threats from online fraudsters.

These malicious actors are known to obtain usernames and passwords and test them across various platforms, including those like PetSmart’s.

According to a recent tweet by Dark Web Informer, PetSmart has notified its customers about a security breach in its system via email.

To combat this, the retailer advises customers to create strong, unique passwords for their accounts and to update them several times a year.

The use of different passwords for separate important accounts is also strongly recommended.

Understanding the inconvenience this may cause to their patrons, PetSmart extends its customer service support for any questions or concerns arising from this issue.

Customers can reach out via email at [email protected].

Maintaining Vigilance

PetSmart’s prompt response to the detected password-cracking attempts is part of its ongoing commitment to customer data security.

The company’s efforts to communicate with its customers about the potential risks and the steps being taken to mitigate them reflect an industry-wide push towards greater transparency and proactive security measures in the digital age.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are incredibly harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Samsung cuts off updates for Galaxy Note 10 Lite, S10 Lite & more

0
[ad_1]

Samsung has ended update support for four Galaxy devices. The Galaxy Note 10 Lite, Galaxy S10 Lite, Galaxy A71, and Galaxy A02 will not receive updates anymore. Not just feature updates but security updates either. If you are using any of these devices, it’s high time you switch to a newer model.

Galaxy Note 10 Lite and S10 Lite will no longer get updates

During the Galaxy S24 launch in January, Samsung announced that its flagship phones will receive seven Android OS updates and seven years of security updates. It is a massive jump from the previous policy of four Android updates and five years of security patches. Before that, the company promised a maximum update support for three to four years depending on the model.

The Galaxy Note 10 Lite, Galaxy S10 Lite, Galaxy A71, and Galaxy A02 were all covered under that policy (Samsung didn’t extend its updated policies to these devices). The former three models debuted in January or February 2020 and turned four earlier this year. The latter arrived in January 2021 and completed three years this January. The promised support period has elapsed.

Expectedly, Samsung has removed these devices from its official support website. They are no longer guaranteed an update. The company could still push one if there is a critical security flaw it must patch. It has done so for a few devices in the past. But the firm is no longer obliged to roll out new security patches to Galaxy Note 10 Lite, Galaxy S10 Lite, Galaxy A71, and Galaxy A02 every few months.

If you are rocking one of these Samsung phones, you should consider upgrading to something newer. The company has already discontinued the Note lineup, so you won’t find a successor to the Galaxy Note 10 Lite. The Galaxy S10 Lite also never got an outright successor, though the Fan Edition (FE) lineup falls in this category—the Galaxy S23 FE is the latest model in the lineup.

The Galaxy A71 5G and A02s are still supported

Samsung also released a 5G version of the Galaxy A71. It debuted in June 2020 and should receive updates until at least June 2024. The Galaxy A02s is also still supported, though that’s a little weird. It launched a few weeks before the Galaxy A02. Since it packs better specs, the company likely doesn’t consider the Galaxy A02s an entry-level product and plans to offer four years of support. In that case, it will get updates till January 2025.


[ad_2]
Source link

NSA Details Seven Pillars Of Zero Trust

0
[ad_1]

The National Security Agency (NSA) issued a Cybersecurity Information Sheet (CSI) that discusses limiting adversary lateral movement within an organization’s network to access sensitive data and vital systems.

This offers instructions on how to use Zero Trust principles to strengthen internal network control and restrict network intrusions to a segmented section of the network.

“This guidance is intended to arm network owners and operators with the processes they need to vigilantly resist, detect, and respond to threats that exploit weaknesses or gaps in their enterprise architecture”, NSA Cybersecurity Director Rob Joyce.

The NSA CSI defines zero trust (ZT) in Embracing a Zero Trust Security Model as a security strategy based on two key principles: acknowledgment of the ubiquity of cyber threats and removal of implicit confidence in favor of ongoing verification of all elements of the operating environment.

ZT implementation initiatives aim to improve cybersecurity defenses, responses, and operations gradually.

Document
Integrate ANY.RUN in your company for Effective Malware Analysis

Malware analysis can be fast and simple. Just let us show you the way to:

  • Interact with malware safely
  • Set up virtual machine in Linux and all Windows OS versions
  • Work in a team
  • Get detailed reports with maximum data
  • If you want to test all these features now with completely free access to the sandbox: ..

Seven Pillars Of Zero Trust

The seven pillars that comprise the Zero Trust framework are:

  • User
  • Device
  • Network & Environment
  • Data
  • Application & Workload
  • Automation & Orchestration
  • Visibility & Analytics
Seven pillars of Zero Trust

Using many essential features of each of the four networking and environment pillar capabilities, the ZT maturity model provides extensive network security such as Data flow mapping, Macro segmentation, Micro segmentation, and Software Defined Networking.

ZT architecture uses a secure network segmentation mechanism in addition to
securing network traffic with robust encryption and ongoing verification
of all users, devices, and data.

Defined procedures and security guidelines are essential for automation and orchestration, as are adaptable network features that allow for the dynamic isolation or modification of network segmentation as needed. 

Reports say sophisticated analytics keep an eye out for suspicious behavior on the network and in other events and activities.

All of these features support the ZT architecture and have the potential to significantly increase network security when used properly.

The network and environment pillar protects vital resources from unwanted access by defining network access, managing data flows, dividing workloads and apps, and utilizing end-to-end encryption.

This is achieved by combining software-defined networking (SDN) with appropriate macro- and micro-level network segmentation to provide centralized control and automation.

“Advancing Zero Trust Maturity throughout the User Pillar” is an extensive set of guidelines that the NSA released in April 2023 to help users in the zero-trust framework acquire certain levels of maturity.

Recommendation

The NSA strongly advises network owners and operators to enhance their network and environment by acquiring capabilities that correlate with the advanced maturity models outlined in this CSI.

“Network and environment security begins with an accurate inventory of all current data flows.

This ensures that access to these flows is properly protected, vetted, and appropriate”, the NSA said.

An organization should implement the following to improve its network and environment capabilities:

  • Map data flows based on usage patterns and operational business requirements.
  • Segment the network appropriately on both a macro and micro scale.
  • Employ SDN for automated tasking and centralized control.
  • Automate security policies to gain operational efficiency and agility.
  • Define access rules using risk-based approaches. These rules should contain precautions against allowing unauthorized or malicious traffic to flow across the perimeter, macro, and micro borders and onto network resources.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

0
[ad_1]

Paris, France, March 7th, 2024, Cyberwire

Company Open Sources FHE Libraries to Build Privacy-Preserving Blockchain and AI Applications for the First Time.

Investment secured to bring Fully Homomorphic Encryption (FHE) to the fore, giving developers the ability to address data privacy challenges across blockchain and AI use cases.

Zama, an open source cryptography company building state-of-the-art FHE solutions to protect privacy in blockchain and AI, today announced a $73M Series A round led by Multicoin Capital and Protocol Labs, with participation from Metaplanet, Blockchange Ventures, VSquared, and Stake Capital, as well as blockchain pioneers Juan Benet (founder of Filecoin), Anatoly Yakovenko (co-founder of Solana), and Gavin Wood (co-founder of Ethereum and co-creator of Polkadot). The funds will be used to hire talented engineers, software developers, and researchers in cryptography to maintain its open source libraries, and collaborate with strategic partners to develop a new class of Fully Homomorphic Encryption (FHE) applications. 

As demand for robust data protection grows internationally, businesses and organizations need a way to protect consumer data without compromising its utility. FHE provides a novel encryption technique that makes it possible to compute over encrypted data for the first time, revolutionizing what’s possible with data privacy for organizations, governments and consumers alike. Over the course of four years, Zama has built a suite of open source cryptographic libraries and solutions that make FHE readily available to developers to build privacy-preserving applications. 

“We envision a world where data privacy isn’t an afterthought, but rather guaranteed by design. With the support of our investors, our talented team, and over 3,000 developers in our community, we can make FHE and privacy synonymous and ubiquitous,” said Rand Hindi, CEO of Zama. “This funding gives us the resources to add to the best and brightest cryptography minds we already have on the team, while also continuing to advance the state of the art of what’s possible in data privacy. Our investors, Multicoin and Protocol Labs in particular, lend valuable experience as we bring FHE to market in the blockchain sector.”

Zama has been at the vanguard of FHE innovation since its inception in 2020. To date, the company has secured multi-million dollar deals in the blockchain and AI space, and has successfully released four cutting-edge FHE solutions. The company’s most recent solution, fhEVM, is the first confidential smart contract protocol for EVM blockchains. Using FHE, the fhEVM enables on-chain state and transaction data to remain end-to-end encrypted during processing, addressing the core data privacy challenge in blockchain. 

“FHE is the most important foundational cryptographic primitive for the next decade of computing. Zama’s technology is the key to build multiplayer, privacy-preserving applications,” said Kyle Samani, Managing Partner of Multicoin Capital. “Zama’s groundbreaking work on open source FHE tooling is only the beginning. We are proud to help them build the next generation of crypto-enabled, privacy-first applications.”

In addition to addressing data privacy challenges in the blockchain industry, Zama is also building bespoke solutions in the artificial intelligence, healthcare, financial services, and governmental security industries. 

“The potential for FHE in both blockchain confidentiality and AI privacy is massive,” says Pascal Paillier, CTO of Zama. “Being able to share our tools with people who are passionate about the same mission is an incredible privilege, something that has only been possible thanks to continuous support, resources and knowledge provided by our investors and community.”

Zama’s team is made up of over 75 individuals from 22 different nationalities, drawn from the fields of cryptography, machine learning, and blockchain technology. Half of the team hold PhDs in their respective fields and are passionate about ensuring data privacy. 

To learn more about Zama, please visit https://www.zama.ai/. 

-ENDS- 

About Zama https://www.zama.ai/

Zama is an open source cryptography company building state-of-the-art FHE solutions to protect privacy in blockchain and AI. Their technology enables a broad range of use cases, from confidential smart contracts to encrypted machine learning and privacy-preserving cloud applications. Zama was founded by Dr Pascal Paillier and Dr Rand Hindi, and has the largest research team in homomorphic encryption.To learn more about Zama, please visit https://www.zama.ai/. 

About Multicoin Capital 

Multicoin Capital is a thesis-driven investment firm that invests in cryptocurrencies, tokens, and blockchain companies. Crypto networks and companies will create trillions of dollars of value over the next decade. But investing in tokens is fundamentally different than investing in companies. New tools, heuristics, and security measures are needed to responsibly invest in this ecosystem. We leverage our deep understanding of blockchain technology and crypto markets to deliver exceptional returns. For more information, visit: https://multicoin.capital.  

About Protocol Labs

Protocol Labs is an open-source research, development, and deployment laboratory. Our projects include IPFS, Filecoin, libp2p, and many more. We aim to make human existence orders of magnitude better through technology. We were founded in 2014 by Juan Benet as a fully distributed company. Our team of more than 100 members works remotely and in the open to improve the internet — humanity’s most important technology — as we explore new advances in computing and related fields. To learn more about Protocol Labs, please visit https://protocol.ai/. 

Contact

PR Consultant
Kirsty Jarvis
Luminous PR
[email protected]
+44 7966 291216


[ad_2]
Source link

Someone posted a Galaxy A55 review before launch

0
[ad_1]

Samsung can’t seem to be able to plug Galaxy A55 leaks. Just as it announced a January 11 launch of the advice alongside the Galaxy A35, a couple of European retailers prematurely listed the duo on their websites complete with images and specs. Now, we have come across a review video of the unreleased device, detailing its performance.

Galaxy A55 review pops up online before Samsung launches the device

This Galaxy A55 review is in Russian and is currently live on the Chinese video streaming platform Bilibili. It is a 15-minute-long video that offers a detailed insight into the upcoming Samsung smartphone. According to the reviewer, the device’s Exynos 1480 processor performs similarly to Qualcomm’s Snapdragon 778G from 2021. While it may not sound very promising, wait for the bigger picture.

The reviewer ran multiple benchmark tests on the Galaxy A55 and it consistently performed substantially better than its predecessor. Geekbench and AnTuTu scores were up by over 20 percent, which is great news. A 15-minute CPU speed limit test also didn’t raise the device’s temperature to an uncomfortable level, nor there was a steep decline in performance due to thermal throttling. This bodes well for Samsung’s Exynos chipsets.

The Exynos 1480’s Xclipse 530 GPU, which is a custom solution co-developed by Samsung and AMD with the latter’s RDNA 2 graphics architecture, also lived up to expectations. It delivered a 31.4 percent performance boost over the Galaxy A54’s Mali-G68 GPU on Geekbench. You can expect smooth gaming here. The new chip also reportedly brings a whopping 167 percent increase in the NPU performance.

The Galaxy A55 brings improvements in other areas too. Firstly, the 6.6-inch Super AMOLED display is said to boast a peak brightness of 1,650 nits. The device will feature Gorilla Glass Victus+ protection along with a metallic (aluminum) frame. While the camera setup will probably remain unchanged, there are hints about a new 12GB RAM variant that recently appeared on Geekbench. Overall, it appears to be a notable upgrade from the Galaxy A54.

The phone launches next Monday

As mentioned at the beginning, Samsung has already announced a March 11 launch of the Galaxy A55. It will debut alongside the Galaxy A35. Sales may begin about a week later, though the US release may take longer. Both phones will arrive with Android 14 and receive four Android OS updates, i.e., up to Android 18. You can expect more leaks about the dup in the build-up to launch next Monday. We will keep you posted accordingly.


[ad_2]
Source link

Hackers Use Number of Legitimate Tools in Ransomware Attacks

0
[ad_1]

Ransomware attacks remain a formidable challenge for organizations worldwide.

These attacks not only encrypt critical data, rendering it inaccessible to the rightful owners but increasingly involve the exfiltration of sensitive information. 

This dual-threat approach amplifies the potential damage, as attackers not only demand ransom for the decryption key but also threaten to release the stolen data unless additional payment is made.

A critical aspect of these attacks that often goes unnoticed is the use of legitimate tools by hackers to carry out their nefarious activities.

Symantec researcher’s report delves into the phenomenon, highlighting the tools commonly repurposed by cybercriminals.

Data exfiltration refers to the unauthorized transfer of data from a computer or server.

In the context of ransomware attacks, it serves a dual purpose.

Initially, it adds an extra layer of coercion, as the attackers threaten to publish the stolen data if their demands are not met.

Secondly, it provides an additional revenue stream, as this data can be sold on the dark web or used in further targeted attacks.

The sophistication of these operations has increased, with attackers leveraging legitimate administrative and security tools to avoid detection and facilitate their malicious activities.

Document
Integrate ANY.RUN in your company for Effective Malware Analysis

Malware analysis can be fast and simple. Just let us show you the way to:

  • Interact with malware safely
  • Set up virtual machine in Linux and all Windows OS versions
  • Work in a team
  • Get detailed reports with maximum data
  • If you want to test all these features now with completely free access to the sandbox: ..

The use of legitimate tools by hackers complicates the detection and prevention of ransomware attacks.

These tools, designed for system administration, network management, and security assessments, are repurposed to conduct reconnaissance, gain persistence, escalate privileges, and exfiltrate data, reads Symantec report.

PowerShell: A powerful scripting language and command-line shell, PowerShell is often used by attackers for its ability to execute scripts and commands across the network, automate tasks, and manage configurations.

Its widespread availability on Windows systems makes it a favored tool for initiating attacks and moving laterally across networks.

PsExec: Part of the Sysinternals Suite, PsExec allows administrators to execute processes on other systems remotely.

Hackers use it to spread malware across networked computers, execute ransomware payloads, and maintain persistence within the compromised environment.

Mimikatz: This open-source utility is designed to extract plaintext passwords, hash, PIN codes, and Kerberos tickets from memory.

Attackers commonly use Mimikatz to escalate privileges and gain access to high-value targets within the network.

Cobalt Strike: Although intended as a security tool for penetration testers, Cobalt Strike has been adopted by cybercriminals for its robust set of features for network reconnaissance, exploitation, and the deployment of payloads.

Its beacon component is particularly useful for maintaining communication with compromised systems.

Rclone: Rclone is a command-line program to manage files on cloud storage. It has been repurposed by attackers for data exfiltration, leveraging its capabilities to efficiently transfer large volumes of data to cloud services under their control.

7-Zip: A file archiver with a high compression ratio, 7-Zip is used by attackers to compress stolen data before exfiltration.

This reduces the bandwidth required for the transfer and helps evade detection by minimizing the number of outbound connections.

WinRAR: Similar to 7-Zip, WinRAR is another compression tool used to package data before exfiltration.

Its widespread use and support for various compression formats make it a versatile tool for attackers.

Advanced IP Scanner: This network scanner allows for quick identification of all devices on a network.

Attackers use it to map out the network, identify potential targets, and plan their attack vectors.

The use of legitimate tools in ransomware attacks presents a unique challenge for cybersecurity professionals.

These tools are often whitelisted within organizations, making malicious activities harder to detect. 

It underscores the importance of robust network monitoring, the principle of least privilege, and continuous education on the evolving tactics of cyber adversaries.

By understanding the tools and methods used by attackers, organizations can better prepare their defenses against the multifaceted threat of ransomware.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

The March update brings some new features, but it takes one away

0
[ad_1]

The latest March update just launched for Pixel devices, and people are digging into the new features that it provides. However, while the update brings a slew of features, it looks like it also took away a very important one. According to reports, the March update saw the battery Information page on Pixel devices disappear.

If you own a Pixel device, then you should be getting the latest Android update and feature drop. With it, you’re getting the typical slew of security and stability patches. Also, you’re getting some new features. One feature adds more functionality to the Google call screen function. For example, if the line goes quiet, you can tap a button to have an artificial voice say “Hello” to catch the other person’s attention. More people are cracking into this update, so more features will be discovered.

The March update took away the Battery Information screen for some people

It wouldn’t be a new Android release without some sort of bug. People are reporting that, after updating to the March update, the useful Battery Information page has disappeared. The Battery Information page shows you useful Information about your phone’s battery. This includes how many recharge cycles it’s gone through. That’s extremely useful to get a good idea of how far along your battery is. It doesn’t give you a 0% – 100% rating on your battery health like iOS does. However, it’s still very useful.

It’s highly unlikely that Google is getting rid of this page. It seems more likely that this is just a bug that Google will have to fix. In any case, the latest Google update is not available for everyone just yet. For starters, Pixel 5a users haven’t seen it yet. Also, if you live in the US, you will have to wait until March 11th to receive the update. Hopefully, by then, Google would have figured out the battery page issue and fixed it.


[ad_2]
Source link

Protecting your online privacy in a digital world

0
[ad_1]

An Android system is often a top choice for many people looking for a smartphone or tablet, as it is more flexible, customizable, and easier to use than iOS. Despite offering superb features, there is no debating they aren’t designed with online privacy in mind.

In today’s digital world, which is rife with cybercriminals, government snooping, and geo-restrictions, you must ensure every device you use is safe and secure each day. For this reason, you must consider installing a VPN for Android device to protect your online privacy. Continue reading to find out more.

Surf the Internet Anonymously

Most internet users will want to hide their IP address for various reasons. For instance, you might want to keep your sensitive data private, prevent companies from tracking your browsing history, conceal online activities, or access censored content in your country. Stay safe online with a VPN free download, as it will hide your IP address and provide a secure, encrypted internet connection to protect your online privacy. Once connected to a VPN, you can trust all network traffic will be forwarded to a VPN server, ensuring third parties will only have access to the VPN server’s IP address and never yours, helping you surf the internet anonymously.

Defend Against Surveillance Threats

As a VPN will conceal your IP address and encrypt your internet data, it can prevent your online activities from being monitored by cybercriminals, governments, and internet service providers (ISPs). As a result, you are less likely to fall victim to a cyber-attack, and you can avoid the exposure of your sensitive data and online behaviors. It is the best way to defend against various surveillance threats, allowing you to visit websites, stream content, or access financial accounts with confidence.

Browse with Confidence on Public Wi-Fi

Most people choose to connect to unsecured public Wi-Fi from time to time. For example, you might want to work in a coffee shop, upload photos onto social media when in a restaurant, or browse the internet when killing time at an airport. Unfortunately, using public Wi-Fi can increase the risk of hacking, as you could expose your private data and photos to cybercriminals lurking on the network. However, after you have installed a reliable VPN, you can use public Wi-Fi or an unsecured network safely and securely, as your identity, data, and location will be invisible to potential hackers.

Access Locked Geo-Restricted Content without Worry

Have you noticed you are unable to access various online content? Geo-blocking places restrictions on the sites and services you can receive at your location. For instance, a UK Android user cannot access US streaming services, and vice versa. If you are eager to access the likes of US Netflix or the UK’s BBC iPlayer on an Android device, a VPN will provide access to the content, and you don’t need to worry about others monitoring your online activities. It works by a VPN redirecting your web traffic to one of its servers in another region, as it can match your desired location. For instance, you can watch a US Disney+ show when a VPN connects to a US server. It’s a quick, hassle-free way to gain access to a TV series.

Conclusion

It doesn’t matter if you use an Android smartphone or tablet to send private messages, browse the internet, watch movies and videos, pay bills, or all the above; it is an intelligent idea to install a dependable VPN. As it will mask your IP and encrypt online activities, you can feel confident your data and behavior are safe and secure from prying eyes, such as hackers, governments, and internet service providers.

Also, you don’t need to worry about logging into your bank or signing into a website when using public Wi-Fi or an unsecured network, as you will remain invisible each time you connect. If the above isn’t enough, you can overcome geo-restrictions, as you can mask your location to access content unavailable in your country, such as location-based streaming services, national news sources, and prohibited social media sites.

Keep the above information in mind when picking a VPN provider and perform in-depth research to ensure they live up to their promises each day. For example, read the company’s testimonials and reviews to make an informed decision.


[ad_2]
Source link

Hackers Exploiting iOS 0-Day To Attack iPhones

0
[ad_1]

Apple releases emergency fixes to address two new zero-day vulnerabilities in iOS that impact iPhones.

The two zero-day vulnerabilities were discovered in RTKit, tracked as CVE-2024-23296, and the iOS Kernel, tracked as CVE-2024-23225.

If exploited by an attacker with kernel read and write privileges, this zero-day might also be used to bypass kernel memory protections.

“Apple is aware of a report that this issue may have been exploited,” Apple said in its advisory.

Details Of The Two-Zero Days Exploited Vulnerabilities

Kernel CVE-2024-23225

An issue with memory corruption has been fixed by improved validation.

“An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections,” the company said.

Impacted Devices:

iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later.

RTKit -CVE-2024-23296

Enhanced validation fixed an issue with memory corruption. However, if an attacker has arbitrary kernel read and write access, it might be possible to bypass kernel memory protections.

Apple has not stated if the two zero-days were found internally or who reported them.

Impacted Devices:

iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later.

Fixes Available

Apple fixed the security vulnerabilities for iPad 16.7.6, iOS 17.4, iPadOS 17.4, iOS 16.76, and iOS 17.4.

Other Security Flaws Addressed

Apple fixed a privacy vulnerability in the Accessibility feature (CVE-2024-23243) that would have let apps access sensitive location data.

Also, when Locked Private Browsing is enabled, a Safari Private Browsing flaw tracked as CVE-2024-23256 exposes users’ locked tabs while they move tab groups.

The business stated that more patches that have not yet been described will be published to the advisory later along with CVEs detailing additional issues. 

Because hackers are already using these two flaws in their attacks, ensure that you apply the relevant security upgrades as soon as possible if you own a vulnerable iPhone, iPad, or Mac.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Apple’s development of SmartRing hints at a meticulously designed housing

0
[ad_1]

Amidst Samsung’s recent announcement of Galaxy Ring at MWC 2024, reports have surfaced regarding Apple‘s venture into the product category. The Cupertino-based giant captured people’s attention to the virtual reality space with its spatial computing device, the Apple Vision Pro. Apple is now reportedly working on its SmartRing.

Initial hints emerged last year from patent filings related to finger-worn wearables. Although not much was known about the product at that point. However, thanks to recent revelations by yeux1122 via tipster Revegnus on X, now we have some information about Apple’s development of the SmartRing.

The Apple SmartRing is rumored to boast a meticulously designed housing

Apple reportedly wants the housing material to be thinner than the competitors. It will also help the embedded form of the sensors and the housing to look and feel more intricately designed. This product is currently in the prototype stage and reportedly includes various sensors that include sensors for motion, temperature, ambient light, health, compass, gyroscope, and inertial measurement devices.

This attention to detail underscores Apple’s aim to come up with a wearable ring that not only offers health tracking and other smart features but also looks and feels good with its elegant design.

Possible functionalities of Apple’s new wearable

Central to the Apple SmartRing’s functionality is its motion sensor, configured as an accelerometer, and proximity communication circuit equipped with a reader. These components enable a range of capabilities, from detecting user input through gestures like tapping and shaking to facilitating data synchronization with Apple devices. Moreover, the integration with Apple Watch opens avenues for seamless interaction between multiple wearables, enhancing the user experience across the Apple ecosystem.

The inclusion of a microphone in the ring enables user audio input alongside gesture-based commands. This multifaceted approach not only empowers users to interact with their devices in new ways but also sets the stage for the implementation of AI features and integration with the company’s visionOS platform.

Samsung’s offering in this product category also offers a range of health tracking and other features. The Samsung Galaxy Ring will reportedly support ECG functionality, blood flow measurement, device control via Samsung SmartThings, and wireless payments via Samsung Pay. Additionally, it brings the ‘My Vitality Score,’ an intelligent metric reflecting users’ physical and mental readiness based on sleep, activity, and heart-rate data.

Nonetheless, keeping Apple’s development of the spatial computing platform in mind, the foray into the realm of smart rings seems to hold the promise of yet another groundbreaking addition to its ecosystem and to the realm of wearable products as well.


[ad_2]
Source link