Iran’s MuddyWater APT targets Saudis and Israelis with BugSleep Backdoor

0
[ad_1]

New Backdoor ‘BugSleep’ Discovered in MuddyWater Phishing Attacks. Cybersecurity researchers uncover a custom-made backdoor used by the notorious MuddyWater hacking group to gain remote access to compromised systems. Learn about the new threat and how to protect yourself from phishing scams.

Iranian threat group ‘MuddyWater’, linked to the Ministry of Intelligence and Security, has intensified cyber warfare targeting the Middle East, particularly Israel, since the onset of the Israel-Hamas war in October 2023, reveals the latest report from Check Point Research.

For your information, MuddyWater (aka Mango Sandstorm and Static Kitten), is an infamous cyberespionage group known for using phishing emails to trick victims into clicking on malicious links or downloading infected attachments.

The group uses compromised email accounts to target various organizations in areas of interest, including Israeli municipalities, government entities, airlines, travel agencies, and journalists. MuddyWater is believed to be active since 2017.

BugSleep Backdoor – Saudi Arabia – Israel

Usually, MuddyWater’s campaigns involve the use of legitimate Remote Monitoring and Management (RMM)Tools like Atera Agent and Screen Connect, but this time they have deployed BugSleep, a custom monitoring tool with backdoor capabilities.

Initially, actors used a tailored lure in campaigns sent to dozens of targets in the same sector, such as municipalities, to download a new app. However, as per Check Point’s report, the group now use generic-themed phishing lures like webinars and online courses to reuse the same lure across different regions. 

The group also use English more frequently now. Two emails identified by CP researchers used the same lure, one sent to Saudi Arabia and the other to Israel, with the main differences being email addresses and the final payload.

In Saudi Arabia, the payload was an RMM, while in Israel, it was BugSleep. Moreover, files related to this campaign, uploaded on VirusTotal were from IP addresses in Azerbaijan and Jordan, with the Azerbaijani language in the PDF lure allowing a correlation with the target.

BugSleep operates by first utilizing the Windows Sleep API multiple times, a tactic employed to evade detection by automated security programs known as sandboxes. It then proceeds to load the necessary functionalities required for its operation. 

Iran's MuddyWater APT targets Saudis and Israelis with BugSleep Backdoor
Malicious emails sent by the MuddyWater APT group to Israel and Saudi Arabia (Credit: Check Point)

While the core functionality remains consistent across versions, Check Point highlights that BugSleep offers the attackers the ability to execute commands on the compromised machine and transfer files between the infected computer and a C&C server controlled by the attackers.

The malware is distributed through Egnyte, a secure file-sharing platform, and is triggered every 30 minutes daily. The updates, occurring within short intervals between samples, suggest a trial-and-error approach.

The discovery of custom-made malware demonstrates the evolving tactics of cybercriminals and MuddyWater’s commitment to bypassing traditional security measures. Therefore, it’s crucial to be cautious of unsolicited emails, verify the sender’s identity before opening them, regularly update your operating system and security software, use strong passwords, and enable multi-factor authentication whenever possible.

  1. Iran’s Mint Sandstorm APT Hits Unis with Hamas-Israel Phishing Scam
  2. Iran’s Scarred Manticore Targets Middle East with LIONTAIL Malware
  3. Iran’s Peach Sandstorm Deploy FalseFont Backdoor in Defense Sector
  4. Iranian Hackers Posed as Israelis in Targeted LinkedIn Phishing Attack
  5. Microsoft reports two Iranian hacking groups exploiting PaperCut flaw

[ad_2]
Source link

Samsung launches drone delivery for Galaxy Z Fold 6 and Flip 6

0
[ad_1]

Samsung is using drones to deliver the Galaxy Z Fold 6 and Galaxy Z Flip 6 in its home country South Korea. The company says it’s a pilot aimed at speeding up foldable deliveries to nearby areas. If the pilot is successful, it may launch a drone delivery service for other mobile products in the future.

Samsung is delivering the Galaxy Z Fold 6 and Flip 6 using drones

This drone delivery service for Samsung’s new foldables is the company’s collaborative project with the Korean Ministry of Land, Infrastructure, and Transport. The firm uses the government’s drone delivery infrastructure, including drones, take-off and landing zones, and control systems built under the Drone Demonstration City Construction Project.

According to Samsung, drones can reduce delivery times from about a week to just a day in some areas. This improves consumer experience as they won’t need to physically visit a store or wait long for delivery. The service is operational even during vulnerable times. It can be used to deliver critical goods urgently when other delivery methods are not available.

Samsung first tested its drone delivery service on Jeju Island with a loading weight of up to 10kg in June. After a successful test, the company is now expanding the pilot to more areas. It aims to eventually roll it out across the nation. The ultimate goal is to deliver mobile devices such as Galaxy smartphones, tablets, wireless earbuds and watches wherever possible.

Samsung drone delivery Galaxy Z Fold 6 Flip 6 2

“The drone delivery service is a new attempt to provide a faster and more convenient Galaxy experience to consumers in island areas,” a Samsung official said. “As a company that leads the AI era, we will continue to develop new technologies and services to improve the convenience and rights of consumers.” Samsung offers various other delivery services to consumers, including timed installation for large home appliances.

The service is limited to select areas

Samsung’s drone delivery service for the Galaxy Z Fold 6 and Flip 6 will begin on July 19. This first-of-its-kind delivery service for mobile products will be available for buyers of the new foldables in nearby island areas of Jeju Island, Tongyeong, and Yeosu. In Jeju, the drone will take off from dedicated centers such as Sangmori and Geumneung. It will deliver the product to three bases in Gapado, Marado, and Biyangdo.

In Yeosu and Tongyeong, Samsung offers drone delivery of the Galaxy Z Fold 6 and Flip 6 to more than ten bases, including Hahwa-do, Islands, Songdo, Bisan-do, Jwa-do, and Manji-do. As said earlier, the Korean conglomerate plans to expand this futuristic delivery service to more regions in its home country. Maybe we will also see Samsung deliver its products using drones in markets outside of South Korea someday.


[ad_2]
Source link

The OnePlus Open is an absolute STEAL at $1,299 during Prime Day

0
[ad_1]

The OnePlus Open was one of my favorite phones of 2023 and arguably one of the best foldables to land in the US last year. And now it’s on sale.

Currently, it is on sale for $1,299, which is $400 off. That is a pretty incredible deal. Because this is the 16GB/512GB variant – also the only variant of the Open, it’s far cheaper than the Galaxy Z Fold 6, which has a regular price of $2,019 for that RAM/Storage variant.

I’ve been using the OnePlus Open on and off since the device was announced last fall. It’s still my absolute favorite foldable available and perhaps my favorite phone available today. It’s just that good. OnePlus nailed the screen sizes and brightness here. It gives us an 18:9 aspect ratio on the front display, so you don’t need to open the phone every time you want to use it. That also means that you can use two apps side-by-side on the inner display at a regular app size. There’s also Open Canvas, which does a good job with multi-tasking and lets you use more screen real estate than you actually have.

The displays are also incredibly bright at 2,800 nits of peak brightness. So, the problem of not being able to see foldable displays in the sun is not a problem here.

On top of that, OnePlus included an incredible camera setup on this phone. It’s been the first time that I have routinely grabbed a phone that wasn’t a Pixel to take photos. That’s really saying a lot.

Finally, we can’t forget about the rest of the specs, which are pretty high-end for the end of 2023. This includes the Qualcomm Snapdragon 8 Gen 2 processor, 16GB of RAM, and 512GB of storage onboard, along with a 4,800mAh capacity battery, which is quite impressive for a foldable, especially one that is this light.

You can pick this up at Best Buy today, but this sale won’t last long, so you’d better be quick.

Buy at Amazon


[ad_2]
Source link

Samsung tests its fastest DRAM with MediaTek chip amid Galaxy S25 rumors

0
[ad_1]

In April, Samsung announced the launch of the industry’s fastest LPDDR5X DRAM. Optimized for AI applications, the new chip delivers a peak speed of 10.7Gbps and offers improved power efficiency. The company has now successfully tested it with MediaTek’s next-gen Dimensity 9400 chipset. This partnership is particularly interesting because Samsung is rumored to use the upcoming Dimensity flagship on its Galaxy S25 series.

Samsung and MediaTek successfully tested the new 10.7Gbps LPDDR5X DRAM

Built on a 12nm process node, Samsung’s new LPDDR5X (Low Power Double Data Rate 5X) DRAM (Dynamic Random Access Memory) is the smallest yet fastest among all existing LPDDRs. It topped the previous speed record of 8.5Gbps (gigabits per second) the company achieved in October 2022 by over 25%. Its specialized power-saving technologies and compact size also allowed for 25% higher power efficiency.

At launch, Samsung said these improvements make the new solution ideal for on-device AI applications. Since AI has become a norm on high-end smartphones, device makers would want to use this DRAM chip in their upcoming offerings. The company has also improved memory capacity by 30%, offering the chip in up to 32GB capacities. Generative AI tasks are resource-heavy, so this is another upgrade for AI applications.

Ahead of its expected mass production in late 2024, Samsung successfully tested its fastest LPDDR5X DRAM for use on MediaTek’s Dimensity 9400. Scheduled to arrive later this year, the new Dimensity became the world’s first chipset to be validated to deliver LPDDR5X speeds of up to 10.7Gbps. The Korean firm says it used a 16GB package for verification and completed the process within just three months.

Samsung is rumored to use the Dimensity 9400 on the Galaxy S25 series

Samsung explicitly named the unannounced MediaTek processor in its press release. While it didn’t specify, the company may also be testing the new LPDDR5X DRAM chip with Qualcomm’s next-gen Snapdragon 8 Gen 4. Rumors say it is considering using both chipsets on its Galaxy S25 series. The firm might even add its Exynos 2500 to the mix for a three-pronged chip strategy, a first for the flagship lineup.

These are unconfirmed rumors, so take the information with a grain of salt. The Galaxy S25 series is still several months away, so Samsung may still have to finalize its chip suppliers. Ideally, it would want to improve its Exynos 2500 yield rate so it doesn’t have to rely on multiple outside vendors. Or at least minimize the use of outside chips. Expect more leaks and rumors about the Galaxy S25 lineup in the coming months.


[ad_2]
Source link

Claude has an Android app! So, how is it?

0
[ad_1]

When talking about the best AI chatbots on the market, we typically mention ChatGPT and Gemini. However, we often forget about Anthropic AI’s flagship chatbot named Claude. This is also a powerful chatbot powered by a powerful model. Well, Google and Amazon-backed Anthropic just released the Claude app on Android. Here’s a rundown of what this app is all about and what it has to offer.

Download Claude for Android

The Claude app is now available for Android users!

Why should Gemini and ChatGPT users have all the fun? If you choose to use Claude, then using the app will be much more convenient. It’s available to download today from the Google Play Store. It’s free to download, and you can use it with any Anthropic plan, even if you’re a free user.

When you get the app, all you have to do is sign into your account. If you’re making a new account then and there, then you’ll need a valid phone number to sign up. Once you make your account, you’ll give Claude your name and agree to all of the terms of service.

Claude Android App Screenshot (2)

Using the Claude app

Once you’re in, you’ll see a very familiar sight. The Claude app has a layout similar to the ChatGPT and Gemini apps. At the very bottom of the screen, you’ll see the text field. The text field will show you which specific model you’re using. Free users will be using Claude 3.5 Sonnet by default. Above that, you’ll see a message letting you know that your free plan is limited.

Claude Android App Screenshot (3)

Up top, above the “Welcome” message, you’ll see the profile button. It will be the circle with the first letter of your name. Tapping on that will bring you to the Settings. Here, you’ll be able to upgrade your plan, view your email address, and change your name. That’s pretty straightforward.

Back to the home screen, the majority of the screen is empty space. As you have conversations with Claude, you’ll see this empty space fill up with a feed of your conversations. The app will generate a title for them that’s straightforward and related to the conversation.

If you don’t like what Claude called one of the conversations, or if you just want to make your own title, you can simply tap and hold on a conversation. You’ll see a little dropdown menu show up with the option to rename it or delete it.

What you can do with Claude

Using the Claude app is just like using the website. It’s hard to list exactly what you can ask Claude, as it’s designed to be an “Everything chatbot” just like ChatGPT and Gemini. You can ask it to summarize content, retrieve information for you, create written content, etc. You can use it for just about anything.

Another great feature of the app is the real-time translation. If you need to talk to a person who speaks another language you can use the app as an interpreter.

Different inputs

As you can tell, Claude takes text as an input, but that’s not all. Claude is multi-modal, which means that it can accept other forms of input like images and documents.

Look at the text field, and you’ll see the paperclip icon. Tapping on that will bring up a panel from the bottom. This will give you the option to take a photo with your camera, upload an image from your gallery, or upload a document.

Taking a picture is pretty straightforward. Just take the picture of the object that you want Claude to look at. If you want to upload an image, you’ll be taken to your system’s photo picker. When you add the picture, you’ll see a small preview of it in the text field. Next, ask the question about the image that you want.

The same thing goes for uploading documents. You’re able to upload DOC files, PDFs, and more.

You can also access the upload options by tapping on the text field and tapping on one of the icons that appear under the placeholder text.

When you’re in a conversation with an uploaded file, you’ll see that file at the very top of the interface. Tapping on the file won’t do anything. That’s a bit unfortunate, as it’d be nice to see an expanded view of the images you took to double-check what the app says about it. However, that’s not a bit deal.

Sidenote

The app doesn’t ask for permission to access your camera or files when you choose these options for the first time. There’s a chance that you grant the app permission when you agree to the terms of service at the beginning. That’s something to keep in mind. So, before you actually enter the app, you might have already given the app access to your files. If that’s not something that you want, you may need to reconsider getting the app.

Cross-platform

Anthropic Claude is a cross-platform chatbot. This means that all of your conversations will transfer no matter what platform you’re using. So, if you start a bunch of conversations on the Claude website, then you’ll be able to access them using the Android and the iOS app. So, you can log in on the website and pick up where you left off with the conversations that you started on the app.

You don’t need to take any extra steps or transfer your conversations. They’re readily available on the Claude app, whether it be for iOS or Android.

App performance

After using the app for a bit, there aren’t any bugs or hiccups evident throughout the app. Everything’s fast and responsive. Since it’s a new app, you can’t rule out the occasional bug here and there. However, in our experience, it was perfectly smooth.

Upgrading

If you’ve reached the limit of what you can do with the free plan, you might want to consider upgrading to Claude Pro. This is a $20/month plan that gives you access to 5x the usage, so you’ll be able to send 5x as many queries as with the free plan.

Along with that, you’ll be able to use the Claude 3 Opus and Haiku models. These are more powerful models than Sonnet, so you’ll have access to smarter AI.

Next, you’ll gain priority access during high-traffic times. During times in the day when more people are using Claude, free users might be put on a waiting list until the usage goes down. Well, Claude Pro users won’t need to wait.

Lastly, Pro users gain early access to new features. If you upgrade on the app, you’ll gain all of these features throughout every platform you use Claude on.

Claude Android App Screenshot (1)

All in all, the Claude app for Android is a great and convenient way to access one of the best chatbots on the planet.


[ad_2]
Source link

The iRobot Roomba Combo i3+ drops to its Lowest Price Ever

0
[ad_1]

Amazon’s Prime Day brings the iRobot Roomba Combo i3+ down to its lowest price ever. It’s now priced at just $329, which is going to save you $270 off of its regular price. Making this a really great time to grab a new robot vacuum.

The iRobot Roomba Combo i3+ is a robot vacuum and mop, all-in-one. Since this is the plus model, we also have the auto-empty dock included here. So it can clean your home by vacuuming and mopping all at the same time. Which is really convenient.

Since this is one of the cheaper Roomba Combo models, it means that you will need to swap out the dustbin and the dustbin with mopping pad. It’s not that big of an issue, but this is done so that it doesn’t get your carpets wet. iRobot has included some really good suction power on this robot vacuum, along with its rubber brushes which will keep hair from getting tangled around the brush. That’s pretty important as the bristle brushes can get tangled up very quickly.

This is a really impressive robot vacuum and mop that you can pick up during Prime Day for only $329.

Buy at Amazon


[ad_2]
Source link

Google’s Pixel Buds Pro drop to $119 for Prime Day

0
[ad_1]

Amazon has just marked down the Google Pixel Buds Pro, making them very affordable once again. They are now just $119.99. This brings the Pixel Buds Pro back down to an all-time low.

Pixel Buds Pro is the first “pro” pair of earbuds from Google, giving you better battery life and, more importantly, ANC. So, with this pair of earbuds, you can get up to 11 hours of continuous playback and up to 31 hours with the included carrying case. That carrying case isn’t super bulky, either. It’s about the same size as the older Pixel Buds, which is really more of an egg size.

Google made the Pixel Buds Pro to fit comfortably in your ears. They were designed for a comfortable, secure fit with sensors that help to reduce the plugged-ear feeling.

You can make and take calls on the Pixel Buds Pro. Thanks to the beamforming mics, you’re going to get crystal clear calls, even in noisy settings, as they are able to block out the background noise. Like with AirPods, the Pixel Buds Pro can easily switch between your devices. So, you can go from using them with your phone to using them on your tablet or your laptop. That’s thanks to Google’s Fast Pair feature.

Finally, the Pixel Buds Prom is also water resistant. So you can wear them in the rain or to the gym and not worry about them getting damaged at all. That’s a big deal if you’re looking for a pair of earbuds to wear at the gym to work with. Not to mention, they sound incredible when used at the gym or anywhere else.

You can pick up the Google Pixel Buds Pro from Amazon today at the link below.

Buy at Amazon


[ad_2]
Source link

AI device Rabbit r1 logged user interactions without an option to erase them before selling

0
[ad_1]

Rabbit, the manufacturer of the Artificial Intelligence (AI) assistant r1 has issued a security advisory telling users it’s found a potential security risk. If a user loses or sells their device, a person in possession of the r1 could potentially jailbreak the device and gain access to files that contain logging information, chats, and photos.

To tackle the potential problem with sensitive data being left behind on the r1, Rabbit has taken the following measures:

  • A factory reset option is now available in the settings menu that lets you erase all data from the r1 prior to transferring ownership.
  • Pairing data is no longer logged to the device.
  • The amount of log data that gets stored on the device has been reduced.
  • Pairing data can no longer be used to read from the user’s Rabbithole journal section. It can only trigger actions.

Rabbit also says it is performing a full review of device logging practices to check whether additional technical controls are needed.

If you have an r1, you don’t need to do anything as the fix will be downloaded and installed automatically. While most updates to the r1 do not require any action of the user, updates that require you to accept them, including new features and more supported apps, will happen via over-the-air updates. For these, follow the prompt on your r1, make sure you’re connected to WiFi and a power source, and wait for it to update.

For those not familiar with the concept, the Rabbit r1 is an AI-powered gadget that can manage the use of your apps for you. It’s a standalone gadget with a 2.88-inch touchscreen, a rotating camera for taking photos and videos, and a scroll wheel/button designed to navigate the menu or allow you to talk to the built-in AI.

The Rabbithole mentioned earlier is an all-in-one web portal to manage the relationship with rabbit OS, and the device that you pair the r1 to. The Rabbit r1 uses a Large Action Model (LAM) to translate the user’s voice into actions on the device it’s paired with, whether that’s a handheld device, like a phone, or a desktop computer.

It’s still pretty much a project under development. Right now, the Rabbit r1 can answer questions, call an Uber, order DoorDash, play music on Spotify, translate speech, generate images on Midjourney, identify nearby objects with its camera and record voice memos. Nothing your phone can’t do, but Rabbit promises more options on the horizon and claims that all these actions are easier to accomplish when you’re using the r1.

The journal section of the Rabbithole web portal shows any visual searches you’ve conducted using the r1’s camera and voice memos you’ve recorded.

Rabbit says there’s no indication that pairing data has been abused to retrieve Rabbithole journal data belonging to a former device owner. Yet the possibility exists, and it’s good that users now have the ability to erase all data before selling the device. However, this doesn’t solve the issue if the r1 is stolen or lost.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection.


Summer mega sale

Go into your vacation knowing you’re much more secure: This summer you can get a huge 50% off a Malwarebytes Standard subscription or Malwarebytes Identity bundle. Run, don’t walk!


[ad_2]
Source link

Another Pixel 9 Pro leak shows the camera’s zoom range

0
[ad_1]

Google’s been a big leaky faucet this year, as we’ve seen several leaks of the Pixel 9 Pro. Someone got their hands on working units and they’re literally taking them out and taking pictures with them. Thanks to another leak, we see just how far the Pixel 9 Pro can zoom.

It looks like, in its attempts to shove AI down our throats, Google has forgotten about safeguarding its phones. We’ve seen some pretty massive Pixel 9 Pro leaks over the past couple of weeks. People have been able to get their hands on several handsets and show them off in videos and social media posts.

For example, we just saw videos showing off several of the Pixel 9 models, comparing them to the Galaxy S24 Ultra, and comparing them to the iPhone 14 Pro Max. They all look legit, so there’s very little left to the imagination.

A new leak shows how far the Pixel 9 Pro can zoom

In recent years, the Pixel Pro phones have come with periscopic zoom cameras, and those helped boost their reach. The last few Pixel Pro phones could reach up to 30x with a combination of optical and software zoom.

Well, a TikTok user just posted a new video showing the Pixel 9 Pro in all its glory. In the video, we see that this phone could max out at 30x zoom just like the previous models. 30x zoom seems to be the sweet spot. It’s far enough to give you some decent reach but not too far as to create blurry and ugly results.

In the video, we see that the text is in Russian. Also, we see that the phone is running the old Pixel Camera UI. Late last year, Google started replacing the UI on its phones to make the interface a bit cleaner. It moved the saturation, brightness, and contrast sliders below the viewfinder with the update.

So, we’re not sure why it has the older design. It’s possible that the Pixel 9 was in testing before the update, and the user in the video, Pixo_unpacking, is using an early unit that was in testing before the camera app was updated.

In any case, we see that the zooming isn’t quite smooth. You can tell when the camera switches between sensors. We can see the quality and color temperature change. It’s not smooth at all, but let’s hope that the company can iron this out before the official launch.


[ad_2]
Source link

New case leak confirms Sony Xperia 5 VI is in the works

0
[ad_1]

Recent reports that Sony plans to discontinue the Xperia 5 series may not be true. A fresh leak suggests the Xperia 5 VI is very much in the company’s pipeline. A third-party accessory maker is already selling a rugged case for the unannounced Android phone, hinting at a nearing launch. The leaked case images reveal a few design details.

Sony is readying the Xperia 5 VI, new leak reveals

Sony’s smartphone lineup consists of three models. The Xperia 10 series is its entry-level or budget offering, while the Xperia 1 series is a flagship. The Xperia 5 slots in between the two, closer to the latter. It’s a mix of premium-ness and affordability. Last year, Sony launched the Xperia 10 V and Xperia 1 V in May and followed up with the Xperia 5 V in September. The Xperia 10 VI and Xperia 1 VI debuted in May too, and we were expecting the Xperia 5 VI around September.

However, a tipster last month claimed that Sony won’t launch an Xperia 5 series phone this year. The source even said that the Japanese company plans to entirely discontinue the lineup, keeping only two models. While the tipster didn’t have an excellent track record of leaks, it did seem to be a logical decision. People wanting a high-end Sony phone are more likely to buy the Xperia 1 model than the Xperia 5, which costs a little less and comes with some compromises.

It appears the information was inaccurate. A German retailer recently listed an alleged Spigen Rugged Armor case for the Xperia 5 VI in Matte Black. The accompanying images show a slight redesign of the camera housing, suggesting a new phone rather than a fake listing. Instead of a circular LED flash unit next to a microphone hole between the two rear cameras, the device has a rectangular dual-LED solution placed centrally with the microphone hole sitting slightly under it.

The device may lack a dedicated camera shutter button

This leak reveals a few more design details of the Xperia 5 VI. Well, we can see a 3.5mm headphone jack and a microphone hole at the top, but their positions are unchanged from the Xperia 5 V. The button placement is also the same, with the power button doubling up as a fingerprint scanner. The upcoming model seemingly lacks a dedicated camera shutter button. Or maybe this leaked case doesn’t accurately depict its design. If the Xperia 5 VI exists in Sony’s pipeline, expect more leaks in the coming weeks.

Sony Xperia 5 VI case leak 7


[ad_2]
Source link