YouTube has solidified its position as the leading streaming service in America. According to Nielsen, the global powerhouse in audience measurement, YouTube has held the #1 spot in watch time for a full year. This translates to 12 months of users regularly turning to the platform for content from YouTubers, artists, and other media sources.YouTube shared the news today on its blog, and attributes this honor to the platform’s unique strengths that keep viewers continuously engaged and returning. Now that traditional boundaries between professional and user-generated content are blurring, audiences are more driven than ever to the platform. In a recent letter to the community, YouTube CEO Neal Mohan stated: “When I started at YouTube, people thought about content from major studios and content from creators as entirely different. But today that stark divide is gone.”
Furthermore, YouTube also gave credit to the power of its creators and immersive experiences. It recognized that viewers appreciate the authenticity and connection they experience with the broad and diverse spectrum of creators currently on the platform. The definition and perception of what a content creator represents is always evolving, and right now the fact that the creators on the platform are not exactly as polished as Hollywood celebrities, but rather have that personal and real quality, is what resonates with the audiences.
YouTube’s rise in television viewership also signals a shift in viewing habits. According to Nielsen, the platform boasts a remarkable average of over 1 billion hours of daily TV content consumption. The number of creators receiving the bulk of their views on TVs has also seen a dramatic 400% increase, and the popularity of YouTube Shorts on connected TVs has surged by over 100% between January and September 2023.
YouTube’s recent updates to its content experience on mobile, desktop, and the living room, show a commitment by the platform to remain in the number one spot. It remains to be seen if YouTube will continue to hang on to the crown and if more changes are on the way to make this a longer reign.
The privacy breach, as per Wyze, occurred when it was restoring cameras, causing customers to see mysterious images/video footage in their Events tab.
On Friday, Wyze cameras reportedly allowed a whopping 13,000 customers to access unauthorized images and video from cameras installed in other homes. Reports began surfacing among Wyze Discord users as early as 4 AM ET, spreading rapidly by 6 AM ET. By 1 PM ET, some Wyze owners reported their devices were back online.
The privacy breach, as per Wyze, occurred when it was restoring cameras, causing customers to see mysterious images/video footage in their Events tab. The company disabled access to this tab and initiated an investigation.
According to co-founder David Crosby, the issue initially impacted 14 customers and escalated to 13,000 customers. Wyze blamed the outage on a technical glitch due to an Amazon Web Service partner issue but has not provided details. The company sent an email titled “An Important Security Message from Wyze” to customers to apologize and share details.
“The outage originated from our partner AWS and took down Wyze devices for several hours early Friday morning. If you tried to view live cameras or Events during that time, you likely weren’t able to. We’re very sorry for the frustration and confusion this caused,” Wyze’s email read.
Wyze claims the incident involved a third-party caching client library, which was impacted by high load conditions and devices’ simultaneous online activity. The library mixed up device ID and user ID mapping, connecting data to incorrect accounts. Wyze blocked the Events tab and added a verification layer for the app’s Event Video section. Despite that Wyze noted that 99.75 percent of accounts remained unaffected, however, users have reported seeing thumbnails and Event Videos from other cameras.
It is worth noting that this is the second incident involving Wyze customers seeing feeds from un-owned cameras through its online viewer. In September, 2,300 people were able to see 10 strangers’ feeds for 40 minutes.
Wyze blamed a “web caching issue” for the issue and implemented technical measures to prevent recurrence. Bitdefender also disclosed security vulnerabilities with Wyze cameras in 2022, which allowed hackers to access feeds from un-owned cameras and strangers’ SD cards.
However, Wyze isn’t the only company experiencing data leaks or breaches. Security cameras frequently become targets of hacking and are prone to vulnerabilities leading to private data exposure. In September 2023, a Vietnam-based group was discovered selling private footage from hacked cameras, advertised as “dark corners” and “hot scenes.” The breach was attributed to poor password hygiene.
To protect your security camera, ensure regularly updating firmware, using strong and unique passwords, securing your home network with Wi-Fi passwords and WPA3 encryption, and avoiding using a device with default credentials.
Reddit, the popular social media platform known as the “front page of the internet,” has reportedly signed a significant content licensing agreement with an undisclosed AI company.
This $60 million deal is poised to impact AI research substantially, Reddit’s impending initial public offering (IPO), and the AI company involved.
DocumentLive Account Takeover Attack Simulation
Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks.
Impact on AI Research
The licensing agreement allows the AI company to use Reddit’s vast repository of user-generated content to train its AI models.
This could significantly advance the development of more sophisticated AI algorithms. Reddit’s content is diverse and extensive, with a built-in user engagement system through upvotes and downvotes.
The deal underscores the growing importance of high-quality, human-moderated data in the evolution of AI technologies.
As Reddit prepares for a $5 billion IPO debut in March, this deal could be a strategic move to demonstrate to investors the platform’s untapped potential for revenue generation, reads the Bloomberg report.
By capitalizing on the current AI boom, Reddit is a valuable partner for tech companies seeking to enhance their AI capabilities. This partnership may also serve as a model for future contracts, potentially opening new revenue streams for Reddit.
While the AI company remains unnamed, the partnership indicates the tech industry’s increasing reliance on legitimate data sources to train AI models.
The deal could set a precedent for how social media platforms and AI companies collaborate, ensuring that AI development is fueled by legally obtained and ethically sourced data.
User Reaction and Ethical Considerations
The decision to license user content has sparked debate over the ethics of using public data to train AI.
Reddit’s community has previously expressed concerns about the platform’s business decisions, and this latest move could generate further discussion about user privacy and the ownership of digital content.
Reddit’s content licensing deal marks a pivotal moment in the intersection of social media and AI technology. It highlights the platform’s strategic initiatives ahead of its IPO and underscores the importance of ethical considerations in AI development.
As the AI landscape evolves, partnerships like this could become increasingly common, shaping the future of AI research and social media companies’ business models.
Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.
There’s a pretty well-defined line between Apple products and other products. iOS, iPadOS, and macOS exist only on Apple’s devices, but that’s not stopping some companies from blurring the line. According to a new leak, it appears that the Vivo X Fold 3 will be able to clone and remote control macOS.
This honestly sounds more like a clever engineer experimenting with adding absurd software to phones rather than a legitimate feature. We’ve seen this many times before with people loading full Windows 11 until a Pixel 6 or porting Wordle into a Game Boy. However, this is not the case this time.
Vivo X Fold 3 users might be able to remote control their macOS devices
This information comes to us from a leak, so you’ll definitely want to take it with a grain of salt. We’re talking about information that has not been officially confirmed by the company. At any point, something could change before the official launch.
Ice Universe made a post on the Chinese social media site Weibo, and it shows us some interesting pictures. We see an image of a foldable phone, which is the Vivo X Fold 3. However, looking at the interface, we see something pretty odd. On it, we actually see it running a full macOS interface.
Now, this isn’t a case of a person hacking or modding the phone and loading macOS onto it. The phone is merely mirroring the macOS from a Mac computer. Also, the phone is actually able to remote control it. So, technically, the phone isn’t running macOS. However, it may as well be.
According to reports, this is all because of a few features within the Vivo X Fold 3’s software. We are unaware of what these features are, but they facilitate this functionality.
Right now, we’re still following leaks and rumors surrounding this upcoming phone, and we’re really excited about it. It appears that this phone will be an absolute beast when it launches. It’s a phone, just like the OnePlus Open (Review), that will really give Samsung a run for its money. We expect Vivo to launch this phone around the end of the first quarter of 2024, so there’s not much more time to wait
In an attempt to prevent water damage, a lot of iPhone users resort to the time-tested method of placing their damp phone inside a bag of rice. Apple is now cautioning against this common do-it-yourself technique, claiming it can cause more harm than benefit.
The risks of drying your wet iPhone in rice
Many people’s first response when their iPhone gets wet is to go for a bag of rice, whether from dumping it in the sink or getting caught in a downpour. Using rice to absorb moisture from the phone and aid in its drying out is the theory behind this approach. Rice fragments may easily become lodged in the ports of the device and cause more harm, thus Apple has released a statement warning against this behavior.
Grains of rice have the potential to damage your iPhone’s internal components as well as obstruct the charging port and headphone socket. This might eventually cause your iPhone to become irreparably damaged due to rust and more water damage.
What you should do instead?
So what should you do if your iPhone gets wet? Apple recommends following these steps:
Disconnect the iPhone’s cable and the other end of the cable from the accessory or power adapter. Make sure, until both your iPhone and the cord are entirely dry, avoid plugging them in again.
First, if there is more liquid on your iPhone, gently press it on your palm with the connector side down. Your iPhone should be left somewhere dry and open to the air. Second, try attaching an accessory or using a Lightning or USB-C connection to charge after at least thirty minutes.
Third, liquid may still be present in the connection or beneath the cable’s pins if you notice the warning once more. For up to a day, keep your iPhone somewhere dry and open to air circulation. For the duration of this time, you can attempt charging or connecting an item once again. The entire drying process might take up to 24 hours. Finally, connect the adapter and cable back together once they have dried out if your phone is still not charging. If this isn’t feasible, disconnect the adapter from the wall as well as the cord.
What you should prevent
Apple also asks users to avoid using pressurized air or an external heat source to dry their iPhones. Moreover, avoid sticking an unfamiliar object, such as a paper towel or cotton swab, into the connection. In conclusion, even while placing your damp iPhone in a bag of rice can seem like a quick repair, it’s advisable to heed Apple’s advice to prevent further harm to the device.
While the patches have been released, Ivanti users must rush to update their systems with the latest versions to avoid trouble. That’s because Ivanti addressed another serious vulnerability in Connect Secure VPN while the previously fixed issues went under attack.
Ivanti Vulnerability Fiasco Continues
Recently, Ivanti addressed another serious vulnerability affecting its Connect Secure, Policy Secure, and ZTA gateways.
According to its advisory, the firm detected the vulnerability while performing internal code testing, though, it seemingly caught the attention of another researcher with the alias “watchTowr” as well, who responsibly disclosed the flaw to Ivanti. Specifically, this vulnerability, CVE-2024-22024 (CVSS 8.3), affected the XML external entity (XXE) in the SAML component, allowing the attacker to access restricted resources without authentication.
Ivanti patched this vulnerability with the following product versions, assuring no active exploitation detections for the flaw.
Ivanti Connect Secure versions 9.1R14.5, 9.1R17.3, 9.1R18.4, 22.4R2.3, 22.5R1.2, 22.5R2.3 and 22.6R2.2). The patch is also available for versions 9.1R15.3, 9.1R16.3, 22.1R6.1, 22.2R4.1, 22.3R1.1, and 22.4R1.1.
Ivanti Policy Secure versions 9.1R17.3, 9.1R18.4 and 22.5R1.2, as well as 9.1R16.3, 22.4R1.1 and 22.6R1.1.
ZTA gateways versions 22.5R1.6, 22.6R1.5 and 22.6R1.7.
Shortly after this vulnerability fix, researchers detected active exploitation of another vulnerability Ivanti patched recently. According to the post from Orange Cyberdefense, they found the vulnerability CVE-2024-21893 under attack soon after the PoC release.
They observed the attacks (with limited targets) going on to deploy a new backdoor. Identified as ‘DSLog’ backdoor, the malware is inserted into the Perl file called ‘DSLog.pm,’ maliciously modifying the logging module. This allows the malware to evade detection while ensuring persistent access for the attacker. Details about this malicious campaign are available in the researchers’ post.
The researchers initially detected 670+ compromised assets in early scans, observing a slight drop in this number in the following days. Given that the threat continues to exist, the researchers urge all users to ensure updating their devices with the latest firmware releases. Moreover, they also advise users to factory reset their devices before applying the fix.
A Ukrainian national, Mark Sokolovsky, has been indicted for crimes related to fraud, money laundering and aggravated identity theft and extradited to the United States from the Netherlands, the US Attorney’s Office of the Western District of Texas has announced.
In March 2022, around the same time of Sokolovsky’s arrest by Dutch authorities, the FBI and law enforcement partners in Italy and the Netherlands dismantled the digital infrastructure supporting the Raccoon Infostealer, taking its then existing version offline.
On September 13, 2022, the Amsterdam District Court ordered Sokolovsky’s extradition to Texas, where many of his victims were located. After the Sokolovsky’s appeal was dismissed in June of 2023, the extradition could take place.
Sokolovsky is suspected of operating the Raccoon Infostealer as a malware-as-a-service (MaaS). This means criminals intent on stealing information could “hire” the malware and the infrastructure to steal data from victim computers.
For this reason Sokolovsky is charged with one count of conspiracy to commit fraud and related activity in connection with computers; one count of conspiracy to commit wire fraud; one count of conspiracy to commit money laundering; and one count of aggravated identity theft. He made his initial court appearance February 9, and is being held in custody pending trial. If convicted, he will be sentenced to a maximum of 20 years for wire fraud and money laundering, five years for computer fraud charges, and a mandatory two-year term for identity theft offenses.
The Raccoon Infostealer operation is a tightly-run ship, to the extent that customers have digital signatures tied to their executables. If files end up on malware scanning services, the malware authors know exactly where the leak originated.
Raccoon’s two most popular delivery methods are phishing campaigns (the tried and tested malicious Word document/Macro combination) and exploit kits. Once data is located on the target system, it is eventually placed into a .zip file and sent to the malware Command and Control (C&C) server.
The main targets of the stealer are credit card data, autofill entries, browser passwords, and cryptocurrency wallets.
The FBI identified at least 50 million unique credentials stolen by Raccoon Infostealer from victims worldwide. Because of this, the agency has created a dedicated website, raccoon.ic3.gov, where potential victims can check if their data has been stolen. All they need to do is to enter their email address. Note, however, that the website only contains data for US-based victims.
The FBI also encourages potential victims to fill out a detailed complaint and share the harm the malware caused them at the FBI’s Crime Complaint Center (IC3).
If you want to find out how much of your own data is exposed online, you can try our free Digital Footprint scan. Fill in the email address you’re curious about (it’s best to submit the one you most frequently use) and we’ll send you a report.
We don’t just report on threats – we help safeguard your entire digital identity
Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using Malwarebytes Identity Theft Protection.
With Android 15, the Pixel Fold could finally allow you to continue using apps on the cover screen after folding the device. Google is readying a new setting to let you choose when to transition apps from the inner display to the cover screen. It is borrowing the swipe-up gesture for app continuity from the OnePlus Open. We already have early visuals of the new tool thanks to Android expert Mishaal Rahman.
Pixel Fold will let you swipe up on the cover screen to continue apps
Currently, the Pixel Fold doesn’t support app continuity for all apps. It works automatically when you are watching full-screen videos on the inner display or using Google Maps for navigation. The video or navigation continues on the cover screen. However, most other apps don’t transition similarly. The cover screen simply goes off when you fold the device. You have to manually turn it on and re-open the app, which can be a hassle.
Thankfully, Google is working on a fix. Spotted in the first Developer Preview (DP1) of Android 15, the company is testing an app continuity tool called “swipe up to continue”. After you fold the device, you can swipe up on the cover screen to continue using the app you were using on the inner display. If you don’t want to continue the app, leave the cover screen untouched and it will be locked in a few seconds.
As said earlier, a similar feature already exists on the OnePlus Open—the screen is locked three seconds after folding the device if left untouched. This is in addition to having app continuity always enabled or disabled, though neither option may be always ideal. The swipe-up gesture gives you control over when to transition apps to the cover screen. Rahman recently shared a screenshot showing the in-development setting for the Pixel Fold.
Google is currently testing this feature
Google has been working on app continuity for the Pixel Fold for a long time. The company first introduced the feature with Android 14 QPR1 Beta 1 in September 2023. It added a setting called “Continue using apps on fold” to let you have app continuity always enabled/disabled or only turn it on for apps that prevent the screen from going idle, like games and videos.
However, much to the disappointment of Pixel Fold users, Google removed the feature from subsequent beta builds. The updated version—with the swipe-up gesture instead of limiting auto transition to games and videos—was spotted in the code for Android 14 QPR3 Beta 1, released earlier this month. It exists on Android 15 DP1 too. Google might roll it out publicly with the stable Android 15 update for the Pixel Fold.
Right now, major companies are acquiring GPUs to train their AI models. Because of this, Nvidia is one of the most valuable companies in the world. Well, there’s a company named Groq that’s just burst on the scene, and this company is bringing a special kind of chip that might make other companies reconsider what they’re doing. Groq introduced the LPU and, based on an early example, it’s pretty fast.
To clear things up, many people on social media and across the web are referring to Groq as an AI model. However, Groq isn’t actually an AI model. A more accurate description of it would be an “AI chip system.” Any examples you see of Groq generating text is through a chatbot called GroqChat. The company employs open-source models like Llama 2 and Mixtral to showcase examples of how quickly AI models can run on the Groq AI chip interface. So, the text being generated isn’t being made by Groq. Think of Groq as the conveyor belt moving the text along.
Groq, with its LPU technology, might shake the AI chip market
The company became an overnight success once videos of it producing text surfaced. However, the company was actually founded back in 2016, the same year that OpenAI was founded. So, it’s not really a newcomer.
If you’re curious about what an LPU is, so is most of the world. The LPU stands for Language Processing Unit, and it was designed by Groq Inc. itself. It’s a chip specially designed for the tasks it’s performing.
side by side Groq vs. GPT-3.5, completely different user experience, a game changer for products that require low latency pic.twitter.com/sADBrMKXqm
We’ve seen examples of GroqChat versus ChatGPT, and they’re pretty wild. One example shows Groq generating a large wall of text in about 3 seconds. It took ChatGPT around 20 seconds to do the same thing. In fact, the company states that Groq is able to process up to 500 tokens per second. This is massive compared to GPT 3.5’s 40 tokens per second.
Why is Groq so fast? Well, why are Apple products so fast?
What Groq has going on is seriously impressive, and it could usher a massive paradigm shift for AI chips going forward. Groq Inc. posted a video on X explaining a few aspects of the company, and one quote stuck out. “We’re faster because we designed our chip & systems”.
This points to the fact that these chips are highly optimized from the ground up to work with Groq’s own systems. When it comes to other AI companies, they purchase their GPUs from companies such as Nvidia.
If this sort of dynamic sounds familiar, then you know about Apple versus well, the rest of the world! Apple designs its chips and builds its hardware and software from the ground up to work seamlessly with one another. This is why its devices are so insanely fast and reliable. Well, this is probably what we’re seeing now with Groq.
The company is building its chips and the interface running on top of them, which is Groq. So, this sort of optimization definitely lends to the speed and performance we’re seeing in the videos.
We’re not certain if other companies are going to emulate this model. However, if Groq proves to be as much of a disruptor as it looks, then other companies are sure to follow suit
In a significant blow to one of the most prolific ransomware operations, authorities from the U.S. and U.K., in collaboration with international law enforcement, have disrupted the LockBit ransomware variant.
The coordinated effort led to the arrest of two operators in Poland and Ukraine and the release of a free decryptor tool that will aid hundreds of victims worldwide restore their encrypted systems.
DocumentLive Account Takeover Attack Simulation
Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks.
The LockBit Ransomware Variant
The National Crime Agency (NCA), alongside the FBI and other international partners, developed decryption capabilities to counteract the LockBit ransomware.
Victims are encouraged to contact the FBI through a dedicated portal to determine if their systems can be decrypted.
The operation, known as Operation Cronos, was a months-long effort that compromised LockBit’s primary platform and critical infrastructure, including the seizure of 34 servers across multiple countries and the freezing of over 200 cryptocurrency wallets.
LockBit, which first appeared in January 2020, had become one of the most active ransomware groups, targeting many organizations, including high-profile victims like Boeing and the UK Royal Mail.
The U.S. Department of Justice has unsealed indictments against two Russian nationals for their involvement in LockBit attacks, adding to previous charges against other members of the group.
International Law Enforcement Operation
The takedown of LockBit’s servers and the release of the free decryptor tool, available via the ‘No More Ransom‘ portal, represent a significant victory in the ongoing battle against cybercrime.
The NCA reveals details of an international disruption campaign targeting the world’s most harmful cyber crime group, Lockbit.
Watch our video and read on to learn more about Lockbit and why this is a huge step in our collective fight against cyber crime. pic.twitter.com/m00VFWkR9Z
The international crackdown, coordinated by Operation Cronos, has compromised LockBit’s primary platform and other critical infrastructure, including the takedown of 34 servers in the Netherlands, Germany, Finland, France, Switzerland, Australia, the United States, and the United Kingdom.
This infrastructure is now under law enforcement control, and more than 14,000 rogue accounts responsible for exfiltration or infrastructure have been identified and referred for further action.
The free decryptor tool, developed with Europol’s support, is a significant resource for LockBit 3.0 Black Ransomware victims, enabling them to recover their encrypted files without ransom.
The operation also retrieved over 1,000 decryption keys from the seized LockBit servers, which will be instrumental in ongoing operations targeting the group’s leaders.
With the release of the free decryptor and the seizure of the ransomware group’s infrastructure, there is renewed hope for organizations affected by LockBit’s malicious activities.
Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.