X gets with the program and lets free users make voice and video calls

0
[ad_1]

When Elon Musk’s X gained the ability to make voice and video calls, we were all pretty bummed by the fact that it was only available for X Premium users. This is a feature that’s freely available on platforms like WhatsApp, Instagram, Facebook Messenger, Snapchat, and so on. However, it appears that X got with the program and now allows free users to make video and voice calls.

Late last year, X introduced the ability to make voice and video calls, and it finally made it to the public. However, one thing about this feature that people appreciated was the fact that a person can only call you if they’ve been in contact with you at some point before. So, if you’ve sent a person the message in the past, only then will they be able to call you. There are other settings you could set to control who can call you, as well.

X now lets free users make video and voice calls

X Employee @enriquebrgn made a post stating “we’re slowly rolling out audio and video calling to non premium users, try it out!” In the post, we see a screenshot of the voice and video call settings. These settings allow you to choose who is able to call you.

You can choose to have only people in your address book call you, only people you follow, only verified users, and everyone. The ability to allow everyone to call you is a new addition. So, if you’re feeling brave, you can enable that feature. However, notable figures and accounts with a lot of enemies may want to steer clear of it. Enabling voice and video calls from everyone basically gives any sort of person free rein to call you out of the blue.

Since this is still rolling out, there’s a chance that you won’t be able to make calls just yet. You’re going to have to wait for the functionality to reach you via the latest update. To check for an update, go to the Google Play Store or Apple App Store and search for X. If you’re on Android, you can simply hold your finger down on the X app icon on your home screen and tap the App info button. This will take you straight to the X Google Play Store page.

If you see the option to update the app, update it. If you don’t see it, then you’ll just want to wait a few days.


[ad_2]
Source link

US goes even further to prevent a 5nm successor to Huawei’s Kirin 9000s

0
[ad_1]

Reuters reported that the Biden administration has intensified restrictions on China’s top sanctioned chipmaker, SMIC, following revelations that its most advanced factory, SMIC South, produced a sophisticated chip for Huawei’s Mate 60 series devices.

China manages to fabricate chips despite several trade restrictions intended to prevent the same

The trade sanctions aim to curb the flow of U.S. technology to SMIC and undermine its ability to manufacture advanced chips for Huawei or any other Chinese manufacturer. The Huawei Mate 60 series, powered by the 7nm Kirin 9000 series chip, symbolized China’s technological resurgence despite ongoing efforts by the U.S. to impede its semiconductor capabilities.

There are also reports that Huawei is working on a 5nm chip amidst all the sanctions. As PhoneArena noted, this new Kirin chip could result in a significant leap for Huawei phones in 2024. It reportedly gets closer to Apple’s 3nm A17 Pro. Although, there’s no concrete evidence of the development at this point. Nonetheless, US officials are definitely feeling the need to impose even stricter restrictions on the US suppliers of chip-building equipment in order to prevent a successor to China’s Kirin 9000 chips.

A response to Huawei’s development of Kirin chips

Late last year, the US Department of Commerce sent letters to US suppliers to SMIC, preventing them from supplying chip manufacturing equipment to SMIC’s most advanced plant, SMIC South. Notably, it was reported that SMIC South is the only chip manufacturing plant in China capable of fabricating cutting-edge chips that can meet the requirements of Huawei’s flagship devices. The said letters to US suppliers effectively cut off millions of dollars worth of shipments of chipmaking materials to the said plant, reported Reuters.

The trajectory of restrictions on SMIC and Huawei has been gradual but consequential. Both companies were added to trade restrictions lists in 2019 and 2020, respectively, over alleged violations and ties to China’s military complex. However, the Trump administration allowed shipments to them under certain conditions. In October 2022, the Biden administration implemented new rules banning U.S. suppliers from sending semiconductor tools and materials to advanced Chinese-run chipmaking factories, including SMIC South.

While Entegris, a Massachusetts-based company maintains it complied with valid export licenses, it ceased shipments after receiving letters from the Commerce Department. The Biden administration’s actions signify a concerted effort to restrict SMIC’s access to advanced U.S. technology, a move criticized by the Chinese embassy in Washington as “economic bullying.”

The impact of these restrictions extends beyond SMIC’s operations, affecting its supply chain and potentially disrupting production for several months. As Lita Shon-Roy, CEO of market research firm Techcet said, “It would take time to find and conduct rigorous testing of new suppliers unless SMIC South had done so in advance.”


[ad_2]
Source link

A Red Team Tool For Generative AI Systems

0
[ad_1]

In a significant move to bolster the security of generative AI systems, Microsoft has announced the release of an open automation framework named PyRIT (Python Risk Identification Toolkit).

This innovative toolkit enables security professionals and machine learning engineers to proactively identify and mitigate risks in generative AI systems.

Collaborative Effort in AI Security

Microsoft emphasizes the importance of collaborative efforts in security practices and the responsibilities associated with generative AI. The company is dedicated to providing tools and resources that support organizations worldwide in responsibly innovating with the latest AI technologies.

PyRIT, along with Microsoft’s ongoing investments in AI red teaming since 2019, underscores the company’s commitment to democratizing AI security for customers, partners, and the broader community.

The Evolution of AI Red Teaming

AI red teaming is a complex, multistep process that requires an interdisciplinary approach. Microsoft’s AI Red Team consists of experts in security, adversarial machine learning, and responsible AI, drawing on resources from across the Microsoft ecosystem.

This includes contributions from the Fairness Center in Microsoft Research, AETHER (AI Ethics and Effects in Engineering and Research), and the Office of Responsible AI.

Over the past year, Microsoft has proactively red-teamed several high-value generative AI systems and models before their release to customers.

This experience has revealed that red teaming generative AI systems distinctly differ from traditional software or classical AI systems. It involves probing security and responsible AI risks simultaneously, dealing with the probabilistic nature of generative AI, and navigating the varied architectures of these systems.

Document
Analyse Shopisticated Malware with ANY.RUN

More than 300,000 analysts use ANY.RUN is a malware analysis sandbox worldwide. Join the community to conduct in-depth investigations into the top threats and collect detailed reports on their behavior..

Introducing PyRIT

PyRIT was initially developed as a set of scripts used by the Microsoft AI Red Team as they began red teaming generative AI systems in 2022. The toolkit has evolved to include features that address various risks identified during these exercises.

PyRIT is now a reliable tool that increases the efficiency of red teaming operations, allowing for the rapid generation and evaluation of malicious prompts and responses.

The toolkit is designed with abstraction and extensibility in mind, supporting a variety of generative AI target formulations and modalities. PyRIT integrates with models from Microsoft Azure OpenAI Service, Hugging Face, and Azure Machine Learning Managed Online Endpoint.

It also includes a scoring engine that can use classical machine learning classifiers or leverage an LLM endpoint for self-evaluation. It also supports single and multi-turn attack strategies.

Moving Forward with PyRIT Components

Microsoft encourages industry peers to explore PyRIT and consider how it can be adapted for red teaming their own generative AI applications. To facilitate this, Microsoft has provided demos and is hosting a webinar in partnership with the Cloud Security Alliance to demonstrate PyRIT’s capabilities.

PyRIT components
PyRIT may be used as a web service or incorporated in apps to formulate generative AI targets. Text inputs are originally supported, but more modalities can be added. Microsoft Azure OpenAI Service, Hugging Face, and Azure Machine Learning Managed Online Endpoint models work smoothly with the toolkit. This integration makes PyRIT a versatile AI red team bot that can interact in single and multi-turn scenarios.
The datasets component of PyRIT lets security experts choose a static collection of malicious questions or a dynamic prompt template to test the system. These templates enable encoding many damage categories, including security and responsible AI failures, and automated harm investigation across all categories. PyRIT’s initial version contains prompts with popular jailbreaks to assist people get started.
PyRIT’s scoring engine evaluates target AI system outputs using a standard machine learning classifier or an LLM endpoint for self-evaluation. Additionally, Azure AI Content filters may be used via API.
Two attack techniques are supported by the toolkit. Sending jailbreak and harmful suggestions to the AI system and rating its reaction is the single-turn strategy. The multi-turn approach responds to the AI system depending on the starting score, creating more intricate and realistic adversarial behavior.
To analyze intermediate input and output interactions later, PyRIT stores them in memory. This feature allows for more multi-turn talks and the sharing of explored topics.
Microsoft invites industry colleagues to use PyRIT to red team generative AI solutions. Microsoft and Cloud Security Alliance are holding a webinar to highlight PyRIT’s capabilities. Microsoft’s plan to map, measure, and manage AI risks promotes a safer, more responsible AI environment.

This release represents a significant step in Microsoft’s strategy to map, measure, and mitigate AI risks, contributing to a safer and more responsible AI ecosystem.

For more information on Microsoft’s AI Red Team and resources for securing AI, interested parties can watch Microsoft Secure online and learn about product innovations that enable the safe, responsible, and secure use of AI.


[ad_2]
Source link

Russian Ministry Software Backdoored with North Korean KONNI Malware

0
[ad_1]

Discover the latest cybersecurity revelation: KONNI malware, linked to North Korean cyber operations, targets the Russian Ministry of Foreign Affairs. Learn about the sophisticated tactics and geopolitical implications

German cybersecurity firm DCSO has discovered a malware sample uploaded to VirusTotal in January 2024, believed to be part of North Korea-linked activity targeting the Russian Ministry of Foreign Affairs (MID). The malware is believed to be KONNI, a North Korean nexus tool used since 2014.

KONNI, first discovered in 2014, is associated with the Democratic People’s Republic of Korea (DPRK)-nexus actors like Konni Group and TA406. The malware has unique stealer functionality and remote administration capability. It’s installed in an MSI file, with C2 servers encrypted with AES-CTR, and a CustomAction for detection and payload selection.

In the latest discovery, researchers noted that KONNI’s command set remains unchanged, allowing operators to execute commands, upload/download files, specify sleep intervals, communicate via HTTP, and compress file extensions into .CAB archives.

Interestingly, the sample DCSO analyzed was delivered via a backdoored Russian language software installer, similar to a previously observed KONNI delivery technique. The sample was for a tool called “Statistika KZU”, which is believed to be intended for internal use within the Russian MID. The software is used for relaying annual report files from overseas consular posts to the MID’s Consular Department via a secure channel.

Additionally, two user manuals were found in the backdoored installer, detailing the installation and usage of the “Statistika KZU” program. The first manual explains installing the program on an administrative account, providing minimum software requirements and screenshots.

The second 22-pager manual, “StatRKZU_Pyкoвoдcтвo,” outlines how to use the software for generating annual report files on KZU consular activities, including templates for calculating registered and detained citizens.

The MID’s software, identified as “GosNIIAS” (a Russian federal research institute primarily involved in aerospace research), was tested offline and found legitimate. Despite no direct correlations between GosNIIAS and Statistika KZU, references to contracts were found, including a procurement order for automated system maintenance and data protection software.

This discovery comes amid increasing geopolitical proximity between Russia and the DPRK, following Russia’s renewed invasion of Ukraine in 2022.

Russia and North Korea’s Cyber Standoff

This is not the first time Russia and North Korea have made collective headlines over cybersecurity threats. In August 2023, the world witnessed another significant incident when “elite North Korean hackers” affiliated with OpenCarrot and the Lazarus group breached NPO Mashinostroyeniya, a key Russian missile developer. This breach, lasting for at least five months, revealed the alarming capabilities and determination of the attackers.

Previous Use of KONNI Backdoor

KONNI has been used in many cyberespionage campaigns targeting Russian agencies. FortiGuard Labs discovered a KONNI malware campaign in November 2023, targeting Windows systems through Word documents with malicious macros. Malwarebytes researchers discovered a campaign in mid-2021 using Russian language lures concerning Russian-Korean trade and economic issues and a meeting of a Russian-Mongolian intergovernmental commission.

An unknown hacking group targeted North Korean organizations using KONNI Malware in 2017. Three campaigns were identified back then- two by Talos Intelligence, a Cisco-owned cybersecurity firm, and the third reported by Cylance security firm.

For insights into this, we reached out to John Bambenek, President at Bambenek Consulting, who emphasised that “It is not uncommon for intelligence agencies to spy even on their putative allies, if for nothing else, for insights to either strengthen the relationship or to identify and mitigate threats.”

Mr. Bambenek highlighted that “The use of a backdoor in software used almost exclusively by the Russian Foreign Ministry stands out and shows that the DPRK did their research here for a particular hook into their victims and is, ironically, a more targeted and precise adaptation of the approach Russian intelligence used with NotPetya.”

“Espionage has a couple of nuances where sometimes you want more sophisticated tools and for some attacks, you want narrow and simpler tools. For espionage, you want long-term persistent infection and sophisticated and interactive tools provide defenders more opportunities for detection. It’s not uncommon to see tools used for espionage that lack some of the obfuscation commonly observed in cybercrime tools,” he added.

  1. Gone: Russian Central Bank hacked; $31 million stolen
  2. 2 Russian Industrial Firms Hacked, 112GB of Data Leaked
  3. Anonymous Leaks 128 GB of Data from Russian ISP Convex
  4. Elite North Korean Hackers Breach Russian Missile Developer
  5. Anonymous Hacks Central Bank of Russia; Leaks 28GB of Data

[ad_2]
Source link

Intel aims to surpass TSMC in advanced chip-manufacturing

0
[ad_1]

Intel has revealed its strategy to surpass its biggest rival TSMC in advanced chip manufacturing, aiming to regain its position as the maker of the world’s fastest and most sophisticated chips. At the IFS Direct Connect 2024 event in San Jose, California, the company disclosed its roadmap, including the use of Intel 18A and Intel 14A manufacturing technologies, with Microsoft set to utilize its 18A technology for a custom computing chip.

Intel’s ambitious plans mark a significant effort to reclaim its dominance in chip manufacturing. The company aims to outpace TSMC later this year with its Intel 18A technology, followed by extending this lead into 2026 with the introduction of Intel 14A. With Microsoft on board as a customer for its 18A technology, Intel expects to see an increase in foundry orders, now projecting $15 billion compared to the previously estimated $10 billion.

TSMC remains tight-lipped about the competitiveness of its advanced technologies

Meanwhile, TSMC is keeping quiet about the competitiveness of its advanced technologies, despite Intel’s push to regain market leadership. TSMC’s stock performance reflects its current dominance in producing advanced chips for AI applications, with its Taipei-listed stock surging nearly 17% this year.

The unveiling of Intel’s 14A technology marks the company’s first detailed roadmap beyond 2025, a deadline set by Intel CEO Pat Gelsinger to regain chipmaking supremacy. Intel’s focus on attracting outside customers and securing government subsidies underscores its commitment to revitalizing its chip manufacturing operations. The company hopes to leverage its geographic diversity and partnerships with institutions like ARM and universities to strengthen its position in the market.

Intel’s effort to entice outside customers, including potential collaborations with industry leaders like Nvidia, is seen as crucial for its turnaround strategy. While Nvidia has not announced a deal with Intel yet, analysts believe Intel’s special technology for AI chips could be appealing to companies in the AI chip market.

Overall, Intel’s roadmap signals a determined effort to regain its competitive edge in chip manufacturing, with the success of its strategy dependent on attracting key customers and executing its plans effectively over the coming years.

Intel Core Ultra Specs Benchmarks Features (1)


[ad_2]
Source link

Outlook Users Beware 0-Day Exploit Released on Hacking Forums

0
[ad_1]

Outlook has identified a security flaw that affects how it handles certain hyperlinks. 

Malware actors actively exploit the vulnerability in real-world attacks.

The assigned CVE number for this vulnerability is CVE-2024-21413, with a severity rating of 9.8 (Critical).

Microsoft has successfully resolved the vulnerability in question and implemented the fix in their February 2024 Patch Tuesday release.

In case of successful exploitation of the vulnerability, a malicious actor can bypass the protected view of Office and open a file in editing mode instead of the protected mode.

Outlook 0-Day RCE Flaw

According to the Checkpoint report, if the hyperlink starts with http:// or https://, Outlook uses Windows’s default browser to open the URL.

If there are additional protocols, such as the “Skype” URL protocol, clicking on the hyperlink will trigger a security warning.

In other cases, like the “file://” protocol, Outlook did not display a warning dialog box.

A slight modification in the “file://” protocol link bypasses the previously shown security restriction and proceeds to access the resource.

According to experts, utilizing this particular resource involves utilizing the SMB protocol.

However, this protocol has a flaw where it inadvertently reveals the local NTLM credentials during the access process.

Exploit on Hacking Forums

The Daily Dark Web recently reported that specific hacking forums have been discussing an exploit for CVE-2024-21413.

This exploit allows attackers to access NTLM information and execute remote code.

The vulnerability can exploit the Office Protected View and use it as a means of attack to target other Office applications.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Resilience to Acquire BreachQuest for an undisclosed price

0
[ad_1]

In a strategic move to enhance its cyber risk management capabilities, Resilience has announced the acquisition of BreachQuest, an innovative incident response technology firm.

This acquisition marks a significant step in Resilience’s efforts to combat the escalating threat of Business Email Compromise (BEC) attacks and other cyber threats.

Document
Live Account Takeover Attack Simulation

Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks.

Strengthening Defenses Against Cyber Threats

BreachQuest is renowned for its cutting-edge platform that integrates seamlessly into cloud office systems, providing invaluable insights for incident forensics and expediting response efforts.

Integrating BreachQuest’s technology into Resilience’s cyber risk management software is expected to significantly enhance incident response mechanisms, particularly against BEC attacks, which have become a significant concern in the digital landscape.

BEC attacks have increased, with the U.S. Government’s Internet Crime Complaint Center (IC3) reporting losses exceeding $2.7 billion in 2022.

In 2023, these incidents ranked as the second leading cause of financial loss for Resilience clients, highlighting the urgent need for advanced risk management strategies.

Shaun Gordon, co-founder and CEO of BreachQuest, expressed pride in his team’s work and enthusiasm for scaling their mission through integration with Resilience’s software.

“Resilience shares our mission in helping improve a client’s cyber resilience and lowering the impact of costly cyber incidents,” Gordon stated, emphasizing the synergy between the two companies’ approaches to incident management.

Vishaal “V8” Hariprasad, co-founder and CEO of Resilience, highlighted the growing sophistication of cybercriminals, particularly with the advent of generative AI technologies.

“Cybercriminals are becoming smarter and faster in executing business email compromise, and with the addition of tools like generative AI, the threat is only growing,” Hariprasad said.

He expressed excitement about welcoming BreachQuest to Resilience, noting that their team and technology have been proven to reduce the financial impact of their clients’ cyber risks.

Enhancing Incident Preparedness

The acquisition of BreachQuest is part of Resilience’s broader strategy to adapt to evolving cyber threats and enhance incident preparedness.

This move follows a period of significant expansion for Resilience, underscoring the company’s commitment to leveraging data and technology to stay ahead of cyber adversaries.

Tim Riley, SVP of Business Development at Resilience, highlighted client benefits, emphasizing the synergy between BreachQuest’s platform and Resilience’s proactive incident management approach.

This collaboration is expected to reduce the financial impact of cyber threats for clients, further enhancing their security posture in the face of evolving digital risks.

In conclusion, acquiring BreachQuest by Resilience significantly advances the fight against cyber threats.

By integrating BreachQuest’s innovative technology into its cyber risk management software, Resilience aims to provide its clients with enhanced protection against the growing menace of BEC attacks and other cyber risks.

This strategic move demonstrates both companies’ shared commitment to improving cyber resilience and lowering the impact of costly cyber incidents.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Patent shows that Google wants a dual-view feature for Maps

0
[ad_1]

Even though navigating via Google Maps is very convenient, it can still be a bit of a hassle when trying to navigate certain roads. The thing is, having a map view of your location isn’t always the most convenient. However, a new patent shows that Google may want to incorporate a dual-view mode for Google Maps.

We’re all familiar with Google Street View. This gives you a more personal View of the streets you’re trying to navigate. You’re able to navigate streets and parking lots as though you’re actually there. Well, based on this patent, Google might have some plans for Street View.

A new patent shows that Google May develop a dual-view mode for Google Maps

As stated, this is just a patent; it’s only Google reserving the technology mentioned in the case it wants to pursue an actual feature like that. It’s not an indication that Google is actively working on this feature. So, don’t hold your breath. In any case, this kind of feature seems well within the realm of possibility for Google.

A new patent shows an example of Google Maps running with two separate views one on top of the other. The top view shows a typical map view that you would see when navigating. However, the bottom half of the screen will show the Street View. This means that you will simultaneously be able to view your location via the map and Street View.

Google maps dual view

This feature could be very useful. There are times when using Google Maps that we stumble upon a pretty complicated set of roads that need to be navigated a certain way. Well, this is the kind of information that you just don’t get with the map view. This results in us passing our destinations and having to backtrack.

However, simultaneously showing the Street View can be a major benefit. You’ll be able to see what types of streets or buildings are around your location, so you’ll be able to go off of that information rather than trust the map view. Since this is just a patent, there’s no telling when/ if Google is going to actually make this a feature. We will just have to wait and see.


[ad_2]
Source link

Elon Musk hints at Xmail, an alternative to Google’s Gmail

0
[ad_1]

As Google goes full damage control following Gemini’s “woke” critiques, Elon Musk has just hinted at a Gmail alternative; Xmail. X, formerly Twitter, has been promising alternatives to many mainstream services as of late. The point of these alternatives, according to Musk, is to provide the user with an unbiased tool that’s not pre-fed prejudiced data. An example of this is the Grok AI; an alternative to OpenAI’s ChatGPT. Now, it appears Musk might be looking to make moves in the email service industry as well.

“It’s coming” says Elon Musk about Xmail

The whole ordeal gained popularity quickly when Nathan McGrady, Senior Security Engineer at X, asked when they were going to make Xmail. Nathan tweeted “When we making Xmail?”. The tweet might have seemed like a throwaway joke, had Elon himself not responded to it saying “It’s coming” right after.

The comments, predictably, exploded with people praising the potential alternative to Google’s Gmail. Memes and personal gripes with Gmail were found galore under Musk’s tweet. One user said, “Awesome! I will switch over from Gmail when it is ready. I look forward to this.”

Others began to come up with more ideas for alternative tools named after X. Search engines, smartphones, and alternatives to services like Google Docs were top of the list. Some users said they couldn’t wait to ditch Google for its “woke” tendencies, a point of contention recently in the spotlight after Google’s Gemini AI was criticized for its forced racial diversity in historically inaccurate settings.

What Xmail could mean for Google going forward

It’s not actually confirmed if Xmail will be a thing, though it definitely seems very likely now. If such a service does come out, there will most definitely be a mass exodus from Gmail. Since his acquisition of X, Elon Musk has become a sort of “champion of the people” among a subset of online users. His popularity and elite position certainly help sell his critiques of modern society.

When Grok AI was released, quite a large number of users subscribed to use it to escape ChatGPT’s “nagging” and politically correct humor. An X search engine would be a definite blow to Google. The company has been facing accusations of biased search results from even before Musk bought Twitter. And if an X smartphone does come out, it’s sure to gain an immediate cult following. Even if it doesn’t reach the popularity of Samsung or Apple.


[ad_2]
Source link