Google ads are being used to spread malware

0
[ad_1]

Malicious actors are using Google advertisements and SEO tactics to entice victims into clicking on links poisoned with malware.

According to cyber security company Secureworks, malicious actors have been using poisoned ad installers as Trojans, specifically to spread Bumblebee malware. These ad installers are associated with a number of well-known companies including Zoom, Citrix Workspace, Cisco AnyConnect and OpenAI’s ChatGPT. For example, Secureworks researchers found that a malicious actor had not only created a poisoned ad installer for Cisco AnyConnect, but a fake download page for the malware as well. They were able to do this by exploiting a compromised WordPress site.

Once Bumblebee malware is downloaded, malicious actors most often use it to launch ransomware within the infected device. In one case, Secureworks researchers found that the malicious actor moved laterally across the device, downloading and launching a number of applications and software programs including legitimate remote access tools AnyDesk and Dameware as well as penetration testing malware Colbalt Strike.

By using paid Google ads as well as SEO tactics in their fake download pages, malicious actors are able to ensure that their Trojanized and poisoned uploads are at the top of the Google search results page, meaning victims are more likely to click on them.

An example of this was seen on January 15, 2023, when a cryptocurrency and NFT influencer known as NFT God said that their “entire digital livelihood was violated” after hackers gained access to and stole “a life changing amount of [their] net worth” in funds and NFTs from their digital wallet. The hackers were able to gain access to their funds through a poisoned ad installer masquerading as a legitimate video streaming software, OBS. 

After downloading and attempting to run the software, NFT God noticed that it had not properly installed, but dismissed this as a technical difficulty. In actuality, they had introduced malware to their device which allowed malicious users access to their social media accounts and digital wallet.

According to NFT God, the hackers stole “at least 19 ETH, worth almost US?$27,000 at the time, a Mutant Ape Yacht Club (MAYC) NFT with a current floor price of 16 ETH ($25,000), and several other NFTs”.

To prevent falling prey to poisoned ads, only download software and updates from trusted sites and go to the sites directly to avoid clicking on a Trojanized link. 



[ad_2]
Source link

US federal agencies hit with MOVEit cyber attack

0
[ad_1]

A Russian-speaking hacking group successfully gained access to the email addresses of approximately 632,000 US federal employees within the US Departments of Defense and Justice during an extensive hack, according to a report obtained through a Freedom of Information Act.

The report, released by the US Office of Personnel Management (OPM), sheds light on the cyber attack’s specifics, with the hackers exploiting vulnerabilities within the file-transfer tool MOVEit. However, little information was provided in the report about the attack’s scale or the affected agencies.

Government email addresses breached

Reporting to a congressional committee, the OPM revealed that an unauthorized actor had breached government email addresses, links to government employee surveys administered by the OPM, and internal OPM tracking codes.

The impacted employees were reportedly spread across the Department of Justice and various sectors of the Defense Department, including the Air Force, Army, US Army Corps of Engineers, and the Office of the Secretary of Defense among others.

The eight-page report by the OPM, originally presented to the House Science, Space, and Technology Committee in July, disclosed that the attack occurred on May 28-29, with hackers exploiting a vulnerability within the MOVEit file transfer program used by Westat Inc., a vendor that the OPM engages for federal employee viewpoint surveys. However, there was “no indication” that any unauthorized user had accessed the survey links.

Despite characterizing the hack as a “major incident,” the OPM clarified that it did not perceive it as posing a significant risk, and the compromised data was “generally of low sensitivity” and unclassified.

The OPM’s disclosure was reported on 30 October by Bloomberg and Forbes, but the Department of Justice and the Department of Defense did not immediately respond to requests for comment.

MOVEit users targeted in cyber attack

According to reports, other US agencies such as the Department of Health and Human Services, the Department of Agriculture, and the General Services Administration, had previously confirmed their exposure to the MOVEit hack. Additionally, the Energy Department was said to have received ransom requests from the hackers after two of its entities had been victimized by the breach.

Progress Software Corp., the parent company of MOVEit, gave assurances that they have taken measures to mitigate the cyber attack’s impact. The company said it empathized with the affected users and pledged to play a collaborative role in the industry-wide effort to combat cyber criminals.

According to reports, Westat responded to the attack by conducting a comprehensive investigation and collaborating with third-party specialists to enhance system security and reduce the likelihood of similar incidents occurring in the future.

Who is Clop?

The attack has been attributed to a Russian hacking group known as Clop, or ClOp. The group has been active since February 2019 and has a website located on the dark web where it routinely posts warnings or uploads data dumps from the organizations it has breached.

In June 2023, Clop posted a notice on the dark web warning firms it had exploited MOVEit to obtain data, giving the affected organizations a deadline to email them before the stolen data would be published. More than 100,000 staff at the BBC, British Airways and Boots were subsequently told that payroll data may have been taken. However, the BBC later reported that Clop, speaking over email, claimed ”we don’t have that data” – raising the possibility that either another unknown hacking group had the stolen data or that Clop was lying.

Clop has reportedly survived multiple attempts to break its activities, including server raids by Ukrainian police in June 2021, which included arrests of multiple alleged hackers working for the group.

According to estimates, Clop has successfully attacked more than 230 organizations to date.



[ad_2]
Source link

Study finds Galaxy S23 Ultra as most popular phone for gaming

0
[ad_1]

A recent study conducted by wireless carrier comparison service ‘USwitch‘ looked at the most popular phones for mobile gaming, and has found that Samsung’s Galaxy S23 Ultra tops the list. USwitch says it came to this conclusion by finding the most popular phones in the UK using a service called CompareDial. It then looked at each device’s specs like screen size, battery capacity, and RAM amount, then gave each of those a score out of 10. Finally it took those scores and gave each phone an average to determine the rankings.

Surprisingly, there’s not a single actual gaming phone in the ranking list. And when we talk about gaming phones this refers to devices like the ROG Phone 7 Ultimate, or those from brands like RedMagic. Phones that are developed with unique gaming features and designed with mobile gamers in mind first and foremost. Instead, the ranking list is populated with mostly Samsung devices. Which might not be that hard to believe given how popular Samsung is as a brand.

In fact, when it comes to the most popular phones for mobile gaming, the top 5 are all from Samsung. This includes the Galaxy S22 Ultra 5G, Galaxy Z Fold 5, Galaxy Z Fold 4, and Galaxy A23 5G in the number 2, 3, 4, and 5 spots respectively.

the iPhone 15 Pro Max is one of the most popular phones for gaming

While the list is dominated by Samsung phones, Apple secured a spot too. The interesting part is that this is the only Apple device. And it happens to be Apple’s most recent phone. The iPhone 15 Pro Max. Given that Apple has a flourishing mobile gaming ecosystem, it makes sense. Apple also announced that it would bring some of Capcom’s biggest recent console and PC games to mobile. Not as mobile ports but the full versions of those games.

With that said, Apple takes the 6th spot. The remaining devices include the Galaxy S23 Plus, the Galaxy Z Flip 5, the Galaxy Z Flip 4, and then the Galaxy S20 FE 2022.

Most Popular Phones For Mobile Gaming USwitch Study

Is this study accurate?

Here’s the thing. Most of these devices have decent enough specs for gaming. But there is one thing worth noting. While these might be the most popular phones in the UK based on purchases, that doesn’t mean they’re being used for gaming. It also only takes into account purchases in the UK. The study doesn’t factor in any devices being purchased in regions where mobile gaming is the biggest. Based on Sensor Tower’s report called ‘The State of Mobile Gaming 2023’ the biggest regions for mobile gaming are the US, Japan, China, South Korea, then Taiwan. With all other regions lumped into the “other” category.

The Sensor Tower report doesn’t mention any about device specifics. But it feels like it should be important to include the largest mobile gaming regions for this kind of study.

Screenshot 2023 11 09 154951


[ad_2]
Source link

Meta’s new policy to counter deepfake ads during the 2024 election

0
[ad_1]

The year of deepfakes is quickly approaching as some of the world’s largest democracies prepare for elections. The US, UK, and India are among the countries that will hold general elections in the upcoming year. Meta has taken a proactive approach, foreseeing the role of AI and deepfakes in spreading misinformation. In a recent statement, Meta announced that all advertisers must now “disclose when they digitally create or alter a political or social issue ad in certain cases.” This new policy is aimed at helping users “understand when a social issue, election, or political advertisement on Facebook or Instagram has been digitally created or altered.”

Deepfakes are a type of sophisticated digital manipulation. These AI-generated hyper-realistic videos or audio recordings can substitute a person’s likeness with another. In the context of political advertising, deepfakes present a significant threat. They have the power to undermine political discourse by fabricating images, persuasive speeches, or statements that spread misinformation and deceive the public.

Misinformation has been a significant issue on social media for a long time. We’ve all fallen victim to it at least once. The evolution of deepfakes, including video alterations and AI-generated images, has reached a point where distinguishing authenticity without proper context becomes quite challenging. Meta’s move anticipates and tackles the likelihood of misleading content or deepfake videos going viral in the run-up to the upcoming elections.

Effective from January, Meta’s new global policy mandates advertisers running ads with digitally altered media to transparently disclose the alterations

The policy includes scenarios such as portraying a real person speaking words they never spoke, featuring a lifelike individual who doesn’t exist, or depicting a realistic event that never occurred. To be in breach of the policy, a digital alteration must significantly contribute to the overall message. For example, simple cropping of a small image would not violate the new guidelines.

Meta has outlined its commitment to adding information to ads when digital alterations or deepfakes are disclosed, although specifics are not provided. Advertisers failing to disclose altered media will result in “penalties against the advertiser.” Meta reserves the right to remove content violating these policies. Meta’s prior policies addressed deepfakes and digital alterations. These new changes represent a significant stride in their commitment to combat deceptive content.

Interestingly, Google has taken a similar stance in addressing AI in advertisements. Moreover, X (Twitter) has implemented a Community Notes feature to combat misinformation and altered media. TikTok opts for a safer route by outright banning all forms of political advertising. This collective industry response reflects a growing threat of misinformation during an election year.


[ad_2]
Source link

Epic rejected nine-figure deal to launch Fortnite on Google Play

0
[ad_1]

Epic reportedly rejected a massive deal to bring Fortnite to the Google Play Store that would have earned it a solid nine-figure payday. The company behind one of the world’s largest online games and Unreal Engine could have netted well over a hundred million if it accepted Google’s deal.

That’s according to Google via testimony from VP of Play Partnerships Purnima Kochikar. Testimony was heard during the company’s ongoing trial with Epic over Play Store fees. Kochikar notes that the deal was presented to Epic following its decision to forego Google’s storefront. And that it would have seen the company earn a total of $147 million over a three-year period.

Epic has been highly critical of Google and its 30% cut of Play Store revenue earned from in-app purchases. So much so that it chose to launch Fortnite for Android outside of the Play Store. Instead offering the game’s download file directly on its own website. This apparently prompted Google to offer Epic the $147 million deal. As Epic puts it, the money was offered because Google went into a panic and was afraid Epic’s choice to launch outside of Play could have a snowball effect. And that other developers might follow.

The Fortnite Google Play deal was meant to prevent a large developer exodus

Google reportedly feared that Epic leaving would cause other big developers and publishers to do the same. Which it says could have cost the company billions in revenue. Details about these fears (as noted by The Verge) were referred to as “contagion documents” and mention that Google could have potentially lost up to $3.6 billion. That is of course if other publishers left the Play Store in a mass exodus. This obviously didn’t happen. But at the time Google was apparently afraid that it would.

Former Google Play Games head Lawrence Koh also testified at the trial this week noting that Google felt the investment was “worth all the dollars.” Continuing that the company was just trying to get games on the Google Play service.


[ad_2]
Source link

Google Wallet will soon allow users to digitize their workplace IDs

0
[ad_1]
Back in June, Google announced a series of new features that would slowly make their way to the Google Wallet app in order to make it a more comprehensive digital wallet solution. Most of these features have already launched, and one in particular was quietly added in a recent Google Play Services update.
We are referring to the ability to add your workplace ID cards to the app, effectively eliminating the need to carry a physical ID or lanyard. This means that, unless your workplace insists that physical identification needs to be shown at all times, you may finally be able to leave your ID at hoe and use your phone to access your workplace facilities.
This new capability is part of the Google Play Services app update to version 23.44 that began to rollout yesterday, as detailed in the app’s changelog. However, it doesn’t seem to have reached all users yet, not even those using the beta version of the app, which is now at version 23.44.14. Once rolled out, the feature will show up alongside the current options for adding a digital ID, such as a state driver’s license.
In its June announcement, Google never did specify a rollout timeline for the workplace ID card support, except for “later this year.” Hopefully, this means that it should hopefully start reaching users soon, making it easier for them to set up digital IDs for reliable use in the future.

[ad_2]
Source link

Galaxy Z Fold 5 & Flip 5 close in on stable Android 14 update

0
[ad_1]

Samsung‘s Android 14-based One UI 6.0 update may soon be available for Galaxy Z Fold 5 and Galaxy Z Flip 5 globally. The company is currently running beta programs in select markets and it just pushed the fifth beta update to the two foldables. The latest beta build comes with a minimal changelog, hinting at an imminent stable release.

Galaxy Z Fold 5 and Flip 5 get new Android 14 beta updates

Samsung has been testing Android 14 and One UI 6.0 among Galaxy users publicly since August. The company opened beta programs for dozens of models across all price segments in seven countries—China, Germany, India, Poland, South Korea, the UK, and the US. Over the past three months, it has released several beta builds for all eligible devices.

Last week, Samsung started rolling out the big update to the Galaxy S23 series globally, pushing the stable One UI 6.0 version to the phones. It is expected to update more models to Android 14 this month. The Galaxy Z Fold 5 and Galaxy Z Flip 5 should be at the top of the company’s priority list. While the firm hasn’t announced the stable update for the foldable duo yet, the latest beta release suggests we aren’t too far off it now.

Spotted by SamMobile, the fifth One UI 6.0 beta update for the new foldables comes with the firmware build number ZWK5 (last four characters). A screenshot shared by the publication shows that the update improves system stability and fixes some bugs. The changelog doesn’t mention anything else, suggesting that Samsung has already fixed all major issues with the previous beta builds.

It is unclear whether the Galaxy Z Fold 5 and Galaxy Z Flip 5 will get any more beta updates or if it is the last. The Korean firm released nine beta builds for the Galaxy S23 series before pushing the stable update. However, new foldables may get the big update sooner rather than later. We will keep a close eye on the developments and let you know as soon as we have more information about Samsung’s One UI 6.0 update plans.

This update brings the November security patch

Samsung’s recent One UI 6.0 beta updates have bundled the November security patch and it’s no different this time. Galaxy Z Fold 5 and Galaxy Z Flip 5 users who have enrolled in the beta program are getting the latest security patch with the fifth beta build. The Korean firm has already started pushing the new SMR (Security Maintenance Release) to devices running Android 13. It patches 65 vulnerabilities, at least five of which are critical.


[ad_2]
Source link

Snap lets go of more staff, laying off 20 product managers

0
[ad_1]

In a move to hasten the company’s decision-making process, Snap has laid off 20 product managers. This sad move is also part of the reorganization process that the company is currently going through. Over the past few months, Snap has been cutting jobs within its ranks and reshuffling positions among its leadership.

The major aim of this process is to cut down costs incurred during the process of running the business. However, according to the company, the layoff of over 20 of its product managers will help to hasten its decision-making process. Currently, certain aspects of Snap’s business are suffering and need attention.

Well, things are not all bad, as the company has begun to see some growth after two quarters of decline. Snap’s third-quarter earnings have seen a significant 5% rise, while the brand’s ad business suffers. These new layoffs might not only cut costs down for the brand but also hasten the decision-making process across various departments.

Snap hopes that its recent layoff affecting 20 product managers will drive growth

You might be wondering how laying off 20 project managers can help hasten Snap’s decision-making process. Well if you have a look at the job description of a project manager you might see things from Snap’s perspective. However, the layoff of these workers is concerning and its possibility of driving growth is still questionable.

This isn’t the first lay-off process that Snap has undergone in recent months. Sometime last year, the social media service provider laid off 1300 of its staff. Just like with this new layoff the company stated the layoff from last year was a cost-cutting move and its effects were felt by users.

As a result of this layoff, a lot of features that were available to Snap users were put on maintenance. Users weren’t able to access these features for a while, as well as shows that got cancelled. After this layoff, the company was able to get back its balance and finally is seeing some growth in its business.

While this new layoff is smaller than the previous, it’s a major blow to the leadership chain in the company. Now, the gap between employees and managers is narrow, hence allowing each to work closely together. Decision-making will now be a bit faster as there are fewer project managers to go through before making a decision.

Snap is now struggling to grow its business earnings and boost its ad business. However, the ads business might be down for a while considering the recent events. Most advertisers have cut down on their ads considering the influx of misinformation due to the current conflict in the Middle East.


[ad_2]
Source link

Hunters won’t launch until next year

0
[ad_1]

Launch delays suck, but they happen. They’re especially annoying if the item has been delayed for years, much anticipated, or based on a treasured franchise. Well, according to a new report, a game that meets all three of those categories just got delayed yet again. Star Wars: Hunters was just delayed again, and it’s not set to come out until next year.

What is this game?

If you look at the gameplay trailer, you’ll be impressed by the fact that someone actually made Overwatch even nerdier. Taking place on Vespaara, Star Wars: Hunters has you teaming up with other sci-fi characters like robots and alien creatures and combatting enemies in an almost battle royale style.

Different characters will have their own attacks and personalities. According to the report, there will be game modes like Payload and Control. These will give you certain objectives that you have to complete while battling foes.

This game is slated to come out on the Switch, Android, and iOS. So, if you have a decently powerful phone, you shouldn’t have any trouble playing this game.

Star Wars: Hunters has been delayed… again

If you have been waiting for this game since it was first introduced, then this will be a smack to the face. Zynga, the company behind the game, made a post on X. “To ensure we meet the highest quality, we have made the difficult decision to delay the worldwide launch of Star Wars: Hunters to 2024.”

That’s a huge bummer because this game was originally supposed to launch back in 2021. However, it faced numerous delays over the years. Now, the game isn’t coming out until next year.

This shows how uncertain the development of the game is because we didn’t get any specific quarter or half of the year to expect. We just know that it will come out between January 1st and December 31st, 2024. Hopefully, we get a more exact launch window as time goes on.


[ad_2]
Source link

Pixel exclusive Google Home app’s “Home Panel” feature coming to other devices with Android 14

0
[ad_1]
The once Google Pixel-exclusive “home panel” feature of the Google Home app will be making its way to other devices running Android 14 soon. This feature gives you quick access to your Spaces and Favorites directly from your lock screen or Quick Settings panel.
This was confirmed by Google via the Nest Community Blog earlier this week, where the company announced new Home and Nest updates and improvements that have recently taken place and some that are upcoming. For example, the launch of expanded controls for smart home devices from different brands, such as fans and sensors.
However, in between the Nest thermostat and generative AI announcements for home automation, was another tidbit that will benefit users of the Google Home app in devices other than the Google Pixel. The Home Panel, a section of the Home app that gives you quick access to all your favorite smart home devices directly from your home screen, will soon be coming to other Android devices with Android 14.

Source – Google

The Home Panel can be accessed by simply tapping on the Device Controls shortcut on your device’s lock screen or in the Quick Settings panel. Once the feature rolls out to the rest of the Android 14 family, you will then be able to see a list of all of your Spaces and Favorites, where you can then tap on any device to control it.
As explained by Mishaal Rahman, this is now possible thanks to the Home Panel taking advantage of a new API that lets apps embed a custom activity in the Device Controls interface. This API was not publicly available in the past and could only be used by the Google Home app on Pixels, but now with the API going public, third party apps will also be able to take advantage of it.

The home panel is a great way to quickly control your smart home devices without having to open the Home app. It will be interesting to see how third-party apps will leverage this to give their users quick access to their controls.


[ad_2]
Source link