The ability to see more sensor data from the Google Home app is rolling out

0
[ad_1]

Most netizens today rely on the Google Home app to control their smart home devices. However, some of these users lack full control of certain devices due to the limitations that the app poses. Now, recent reports point out that Google is now removing these limitations and letting users of this smart home integration app gain full control of sensors around their homes.

For some time now, Google has been working to bring more controls to users of the Home app on their smartphones. To do this, support for more devices and controls is coming to the app to help improve user experience. Additions of these controls have been coming to the app one after another over the past months.

Two days ago, the Google Home Reddit page announced more information from sensors coming to the app. Users of the app are already excited to get data from more sensors on various smart devices in their homes. With access to more data from sensors, users of the app will get better insight into their smart devices.

More information from sensors is coming to the Google Home app

If you use the Google Home app for your smart devices, then you are in for a treat. A user took to the Google Home community Reddit page to share a discovery on his Home app. While checking the reading on his Hue indoor motion sensor, the user also noticed that the app was giving two temperature readings.

While this was an error on the user’s part, the screenshot he provided gave off more sensor readings. The sensor readings available via the app were motion, light level, and temperature. With all these readings, users can better understand how their smart devices operate and the data they collect from their sensors.

Aside from the Hue indoor motion sensor, more devices are now reaching their full potential. This is to say that users can access more information from these devices’ sensors. Regardless of the device’s usage, the Google Home app will be able to read data from its sensors.

This change is coming to more users along with some other important improvements. An example of a new feature to look out for on your app is the ability to “control the rotation and speed of your compatible fans directly in the Home app.” These upgrades are currently rolling out and will become available to users in the coming weeks.


[ad_2]
Source link

Google Messages could be getting “Profiles” to share your information with other users

0
[ad_1]
Google has been reportedly working on a Profiles feature for its Messages application for several months. This feature appears to be a way for users to have their desired name, photo and other information attached to their contact card within the application.
The “Profiles” feature was spotted in an APK teardown by 9to5Google, which helped identify more details on what it could do. According to this teardown, code was found in the latest beta version of Google Messages (v20231106_01_RC00) which describes Profiles as a way for users to “Choose your profile name & picture so people can recognize you.”

The feature is still under development, but it appears that users will be able to create a profile with their name, photo, and other information. This profile could then be shared with other Messages users, so that they can easily identify each other in conversations.”Profiles” was originally spotted back in January as a preferences page in Android system settings, although the toggle was not functional when turned on. This suggested that Profiles could be a standalone feature that is managed by Google Messages, rather than being part of RCS.

If Profiles are implemented, it is likely that they would appear at the top of conversations in Google Messages. I would speculate that tapping on a profile name or photo could then open a profile page with more information about the user that other users could then save to the corresponding contact card.

Google has not yet announced a release date for the Profiles feature. However, given that it has been in development for several months and is now appearing in beta versions of the app, it is likely that it will be released in the near future.

Google Messages Profiles have the potential to be a significant new feature that would improve the messaging experience for users. It will be interesting to see how Google implements Profiles and how it integrates them with other Messages features, such as RCS and group chats.

[ad_2]
Source link

Judge rules it’s fine for car makers to intercept your text messages

0
[ad_1]

A federal judge has refused to bring back a class action lawsuit that alleged four car manufacturers had violated Washington state’s privacy laws by using vehicles’ on-board infotainment systems to record customers’ text messages and mobile phone call logs.

The judge ruled that the practice doesn’t meet the threshold for an illegal privacy violation under state law. The plaintiffs had appealed a prior judge’s dismissal.

Car manufacturers Honda, Toyota, Volkswagen, and General Motors were facing five related privacy class action suits. One of those cases, against Ford, had been dismissed on appeal previously.

Infotainment systems in the company’s vehicles began downloading and storing a copy of all text messages on smartphones when they were connected to the system. Once messages have been downloaded, the software makes it impossible for vehicle owners to access their communications and call logs but does provide law enforcement with access, the lawsuit said.

The Seattle-based appellate judge ruled that the interception and recording of mobile phone activity did not meet the Washington Privacy Act’s (WPA) standard that a plaintiff must prove that “his or her business, his or her person, or his or her reputation” has been threatened.

In a recent Lock and Code podcast, we heard from Mozilla researchers that the data points that car companies say they can collect on you include social security number, information about your religion, your marital status, genetic information, disability status, immigration status, and race. And they can sell that data to marketers.

This is alarming. Given the increasing number of sensors being placed in cars every year, this is becoming an increasingly grave problem.

In the same podcast, we also explored the booming revenue stream that car manufacturers are tapping into by not only collecting people’s data, but also packaging it together for targeted advertising.

According to the Mozilla research, popular global brands including BMW, Ford, Toyota, Tesla, Kia, and Subaru:

“Can collect deeply personal data such as sexual activity, immigration status, race, facial expressions, weight, health and genetic information, and where you drive. Researchers found data is being gathered by sensors, microphones, cameras, and the phones and devices drivers connect to their cars, as well as by car apps, company websites, dealerships, and vehicle telematics.”

In fact, the seasoned Mozilla team said “cars are the worst product category we have ever reviewed for privacy” after finding that all 25 car brands they researched earned the “Privacy Not Included” warning label.

Since that doesn’t give us much of a choice to go for a brand that respects our privacy, I suggest we turn of our phones before we start the car. It’s both safer and better for your privacy.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your and your family’s personal information by using Malwarebytes Identity Theft Protection.


[ad_2]
Source link

Google Messages might show people’s profiles in the future

0
[ad_1]

Google has been adding new features to Google Messages over the past several months, and we just got a glimpse of one that might be on the way. According to a new report, Google Messages might let you view people’s profiles when using it.

This news was discovered through an APK deep-dive. This means that you’ll want to take this information with a grain of salt. There’s code hidden within Android, and it points to this feature being in production. However, this was not officially announced by Google. This means that the company could make changes to the feature or pull it altogether. stay tuned for more updates on this story.

Google Messages might let you see users’ profiles

Google isn’t a social media company, but you still have a profile with it that shows a profile picture and some information about you. You see your profile when you’re using services like Gmail, Google Maps, Chrome, and other products.

You’re also able to see it when you’re using Google Messages. You just need to tap on your profile picture in the top right corner of the screen to access it.

However, if you tap on one of your contacts, it won’t show you their profile. Instead, it will take you to your Contacts app. Well, according to the code hidden within Android, it looks like Google Messages is looking to make the messaging experience more personal.

In the APK deep-dive, there were some strings found pointing to you being able to see other people’s profiles:

<string name=”profile_settings_title”>Profile</string>
<string name=”profile_sharing_title”>Profile sharing</string>
<string name=”profile_onboarding_banner_title”>Choose your profile name &amp; picture so people can recognize you</string>
<string name=”profile_onboarding_banner_snackbar_success_text”>Preferences saved</string>
<string name=”profile_onboarding_banner_snackbar_save_error_text”>Failed to save name &amp; picture. Please try again later.</string>

These strings point to the settings screen that will let you customize the profile settings. It looks like you’ll be able to customize how your profile will appear on Google Messages.

Right now, when you use Google Messages, other people appear as color circles with the first letter of their name. If you want to see a picture of the person, you’ll have to manually set it. However, if Google Messages enables profiles, then you should be able to see your contacts’ profile pictures show up automatically.


[ad_2]
Source link

Google’s Search Generative Experience is expanding to more countries

0
[ad_1]

Google has turned the AI dial up to 11, as it’s been implementing generative AI into many of its services. Many of its AI tools are tested and debuted in the US, but the company doesn’t want to be stingy with it. In a new blog post, Google announced that SGE (Search Generative Experience) is now expanding to more than 120 countries.

If you don’t know what SGE is, well it’s Google Search upgraded with AI. After joining the experiment, you’ll see AI-generated summaries of what you’re searching for.

If you type something in Google Search, say “best ways to remove nail polish”, you’d previously see the list of top pages that inform you how to do so. However, SGE will generate a direct answer to your question above the results. This eliminates the need to travel to different pages.

As you can imagine, this tool is not without its controversy. Since you’re not going to the actual websites, those sites aren’t getting your traffic. This greatly reduces the site’s ad revenue and their business.

Google SGE is expanding to 120 more countries

As with most of Google’s AI tools, SGE has gone through a lengthy testing phase before making its way to the public. It was in testing for several months.

Now, Google is expanding SGE to 120 more countries around the world including Mexico, Brazil, South Korea, Indonesia, Nigeria, Kenya, and South Africa. A drawback to this is that it’s arriving in only a handful of languages, but Google is working on expanding that. The languages available are Spanish, Portuguese, Korean and Indonesian.

Google is also bringing Search Labs to these countries. Search Labs is the greater testing platform where users can test out new AI features coming to Google. It lets you be some of the first people to try out new AI features coming to Google.

If you are looking forward to trying out these new features, you can sign up for Search Labs and start using them.


[ad_2]
Source link

Update now! SysAid vulnerability is actively being exploited by ransomware affiliate

0
[ad_1]

Users of SysAid on-premises should take action to deal with a vulnerability. SysAid is a widely used IT service management solution that allows IT teams to manage tasks.

Microsoft discovered an ongoing exploitation of a zero-day vulnerability in the SysAid IT support software in limited attacks by Lace Tempest. Lace Tempest is an initial access broker (IAB) usually associated with the Cl0p ransomware.

Once SysAid were notified by Microsoft on November 2, 2023, they started an investigation which confirmed that it was indeed a zero-day vulnerability. By definition, a zero-day vulnerability is any software vulnerability exploitable by hackers that doesn’t have a patch yet.

The investigation identified a previously unknown path traversal vulnerability leading to code execution within the SysAid on-prem software. Path traversal vulnerabilities allow attackers to read, and possibly write to, restricted files by inputting path traversal sequences like ../ into file or directory paths.

The attackers used the vulnerability to upload a web shell and other payloads into the web root of the SysAid Tomcat web service. Tomcat is an open-source web server and servlet developed by the Apache Software Foundation. A web shell is a malicious script used by an attacker with the intent to escalate and maintain persistent access on an already compromised web application.

The web shell provided the attacker with unauthorized access and control over the affected system. The attackers then used two PowerShell scripts to expand their hold. One to launch the Gracewire malware loader and the other to erase other evidence of the intrusion.

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The CVE assigned to this vulnerability is:

CVE-2023-47246: a path traversal vulnerability that affects all SysAid On-Premises installations running versions before 23.3.36. SysAid Cloud customers are not affected by this vulnerability.

If you are a SysAid customer using a SysAid On-Prem server, you are under advise you to ensure that your SysAid systems are updated to version 23.3.36 or later, which includes the patches for the identified vulnerability.

Organizations using SysAid should apply the patch as soon as possible and look for any signs of exploitation prior to patching (see Indicators of Compromise below). The Lace Tempest group exploited the vulnerability in the SysAid software to deliver a malware loader for the Gracewire malware. Once this foothold is established, it’s usually followed by human-operated activity, including lateral movement, data theft, and ransomware deployment.

You should also review any credentials or other information that would have been available to someone with full access to your SysAid server and check any relevant activity logs for suspicious behavior.

IOCs

File:

b5acf14cdac40be590318dee95425d0746e85b1b7b1cbd14da66f21f2522bf4d     Malicious loader

IPs:

81.19.138.52     GraceWire Loader C2

45.182.189.100 GraceWire Loader C2

179.60.150.34  Cobalt Strike C2

45.155.37.105  Meshagent remote admin tool C2

Malwarebytes blocks 179.60.150.34

Malwarebytes blocks the Cobalt Strike C2 179.60.150.34

File Paths:

C:\Program Files\SysAidServer\tomcat\webapps\usersfiles\user.exe

C:\Program Files\SysAidServer\tomcat\webapps\usersfiles.war  

C:\Program Files\SysAidServer\tomcat\webapps\leave  

How to avoid ransomware

  • Block common forms of entry. Create a plan for patching vulnerabilities in internet-facing systems quickly; and disable or harden remote access like RDP and VPNs.
  • Prevent intrusions. Stop threats early before they can even infiltrate or infect your endpoints. Use endpoint security software that can prevent exploits and malware used to deliver ransomware.
  • Detect intrusions. Make it harder for intruders to operate inside your organization by segmenting networks and assigning access rights prudently. Use EDR or MDR to detect unusual activity before an attack occurs.
  • Stop malicious encryption. Deploy Endpoint Detection and Response software like Malwarebytes EDR that uses multiple different detection techniques to identify ransomware, and ransomware rollback to restore damaged system files.
  • Create offsite, offline backups. Keep backups offsite and offline, beyond the reach of attackers. Test them regularly to make sure you can restore essential business functions swiftly.
  • Don’t get attacked twice. Once you’ve isolated the outbreak and stopped the first attack, you must remove every trace of the attackers, their malware, their tools, and their methods of entry, to avoid being attacked again.

Our business solutions remove all remnants of ransomware and prevent you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.


[ad_2]
Source link

Samsung’s 2023 and 2022 foldables get new update in the US

0
[ad_1]

Samsung is pushing a new update to its 2023 and 2022 foldable smartphones in the US. While Android 14 isn’t here just yet, the Galaxy Z Fold 5, Galaxy Z Flip 5, Galaxy Z Fold 4, and Galaxy Z Flip 4 are getting the latest security patch. All four foldables are picking up the November SMR (Security Maintenance Release) stateside ahead of other markets.

The November update is available for Samsung foldables in the US

Yesterday, Samsung released the November security patch for the carrier-locked variant of the Galaxy Z Flip 5 stateside. The update came with the firmware build number F731USQS1AWJ7 and didn’t bring anything more than the latest security fixes. That was expected as the company is gearing up to push the Android 14-based One UI 6.0 to the phone, adding tons of new features and improvements.

While we wait for the big update, Samsung has now released the November SMR for the unlocked Galaxy Z Flip 5 and expanded the coverage to all of its recent foldables. Users with an unlocked 2023 clamshell foldable are getting the new security patch with the build number F731U1UES1AWJ7. Once again, the changelog is bland with no additional goodies in tow.

For the Galaxy Z Fold 5, the update is available for both carrier-locked and unlocked units with firmware versions F946USQS1AWJ7 and F946U1UES1AWJ7, respectively. Likewise, the Galaxy Z Fold 4 is getting the latest security patch with build numbers F936USQS3DWJ4 and F936U1UES3DWJ1. The update for the carrier-locked Galaxy Z Flip 4 bears the build number F721USQS3DWJ4.

As of this writing, the unlocked variant of the 2022 Flip model doesn’t seem to have received Samsung’s November update. However, it should be just a matter of time before the company covers those units. A global rollout of the latest security patch for these devices should follow in the coming days. Don’t expect anything major here, though. One UI 6.0 will arrive soon with new features and improvements.

This month’s security update patches more than 60 vulnerabilities

Samsung’s November SMR for Galaxy devices contains patches for 65 security issues, including five critical and more than 40 high-severity Android OS vulnerabilities. The remaining issues are Galaxy-specific, meaning that they don’t exist on Android products from other brands. Every Galaxy phone and tablet is affected by at least one of these vulnerabilities.

If you’re using any of Samsung’s recent foldables in the US, you will soon receive an update that safeguards your phone from these security issues. The Korean firm has also released the November security patch for the Galaxy S21 series in international markets. A US rollout should be in the pipeline too. You can always check for new updates manually from the Settings app.


[ad_2]
Source link

A ton of details leaked about the Humane AI Pin, and it won’t cost $1,000

0
[ad_1]

Throughout the year, we’ve seen some bits of information about yet another device vying to put the smartphone out of business; AR glasses being the other. Called the AI Pin, this is Humane’s first device, and it’s quite an interesting device. The company is set to do an official announcement today; however, The Verge obtained a ton of details about the AI Pin. Good news, it’s not going to cost you a grand.

Details on the Humane AI Pin

We’re used to seeing devices like these, only, the people wearing them were usually fighting giant robots, speeding across space at light speed, or deflecting laser beams with their laser swords. Devices like the AI Pin have long been science fiction. However, Humane has been working on bringing this device into the real world for some time.

Earlier this year, Humane co-founder Imran Chaudhri showed off the device at a Ted Talk, and we got a glimpse of what this device could do. Since then, we’ve gotten reports stating that this device is going to cost $1,000. Well, thanks to the information obtained by the Verge, that’s not the case.

Price

The document states that the Humane AI Pin will cost a much more palatable $699. This makes the device just a bit more accessible to the common user. However, that’s not the only time you’ll have to take out your wallet for this device.

Reports about a subscription service were true, as you’ll be paying a $24/month fee to use the AI tools. Shockingly, this small device can’t contain an entire AI model, so it will need to connect to the chatbot through the internet. You’ll receive your internet service through T-Mobile, and it also grants you a phone number.

This subscription will also get you a certain amount of cloud storage and the ability to make unlimited queries.

Usage

So, how will you use this device? Well, the AI Pin has a camera, microphone, speaker, and tiny projector. It will use the camera to scan its environment, a functionality it showed off during the Ted Talk. You’ll use it to scan objects and ask it questions about what it scanned. You could probably scan a sea shell and ask it what type of shell it is.

Since it doesn’t have a screen, it will use an AI-generated voice to tell you through the speaker. That could be rather inconvenient in situations when you need to be quiet or when your environment is too loud. However, the company has two solutions for this. Firstly, there’s a little projector on the device that will show you information on a nearby surface (most likely, your hand). Secondly, the AI Pin can connect to Bluetooth headphones.

In order to use the device, you’ll need to activate it, but we don’t know how that works yet. This is good as many people would be concerned about the fact that it comes with several sensors onboard. People worried about their privacy would be happy to know that the device is not always listening. In fact, the device has a trust light that shines when the sensors are in use.

Interacting with the AI Pin

The Pin has a little projector, and we saw that it projected some buttons onto Imran Chaudhri’s hand. The incoming call screen and the active call screen all had buttons on them that make it look like you’re able to tap on the area on your hand with those buttons to interact with the device. That’s a neat functionality, but we don’t know if that’s how it will work.

Humane AI Pin 1

However, we know that the pin will have a capacitive touch screen that you can interact with. We’re not sure if the device will employ one or both.

Charging

The Pin will attach to your clothes through a magnetic clip. The clip will also act as a battery backup (called a “Battery Booster”)  to keep the device charged. So, if need be, you could swap out batteries on the fly.

The document makes it seem like you’re getting two batteries in the box with your purchase. Hopefully, the company will allow users to purchase battery packs in case people want more.

AI

Rumors pointed to the AI Pin using OpenAI’s GPT-4 language model, however, we’re not 100% sure about that. The Pin uses humane’s proprietary operating system called Cosmos, and it seems like it will be able to summon different AIs for different purposes. According to the report, this is reminiscent of GPT-4’s functionality. That’s something we’ll need to wait for the official announcement to know.

The AI Pin is something that might change the way we view AI. We’ll have to wait to see if it is truly the next stage in mobile technology.


[ad_2]
Source link

No ads in WhatsApp, at least not in the chats section (but possibly in other places)

0
[ad_1]

WhatsApp is once again reassuring users won’t see ads in the super popular messaging app, but this time, there’s a fine print.

In an interview for a Brazilian news media, WhatsApp boss Will Cathcart elaborated on the app’s future and how Meta, which acquired WhatsApp, makes money with the free WhatsApp (via 9to5Mac).

A word from the boss


When asked about displaying ads in the app, Cathcart emphasized that the company “will not place ads in the inbox or chats” – that’s not at all the same as “No ads in WhatsApp”.“We don’t think that’s the right model. People, when they open their inbox, don’t want to see advertising,” he said. However, the executive doesn’t rule out the idea of WhatsApp showing ads in other parts of the app.

Per Cathcart, one possibility is for advertisements to be shown in the Public Channels and Status sections. WhatsApp’s boss suggested other ways to monetize the app, such as charging people to join a channel – like Telegram does with its users.

The Meta executive also said in the interview that the countries where WhatsApp is most popular are India, Indonesia, and Brazil; with Brazil being a champion on the largest number of audio messages sent on WhatsApp, as well as the largest number of messages that disappear.

One of WhatsApp’s biggest sources of revenue is the WhatsApp Business API, offering special tools for the business. It’s a $10 billion-a-year business, according to Cathcart. WhatsApp could increase its revenue without relying on ads by offering other paid services and taking a commission.


[ad_2]
Source link

ChatGPT Down? OpenAI Blames Outages on DDoS Attacks

0
[ad_1]

Is your ChatGPT down? Are you experiencing issues with ChatGPT, such as connectivity problems or encountering a ‘Network error on long responses’? – ChatGPT has been under a series of DDoS attacks, apparently orchestrated by Anonymous Sudan.

OpenAI’s ChatGPT, a popular AI-powered chatbot, has been experiencing outages for the past 24 hours due to distributed denial-of-service (DDoS) attacks. The company confirmed the attacks in a statement on its status website, saying that it is working to mitigate the attacks and restore full service.

“We are dealing with periodic outages due to an abnormal traffic pattern reflective of a DDoS attack. We are continuing to work to mitigate this.

OpenAI on Nov 08, 2023 – 19:49 PST

According to OpenAI CEO Sam Altman, as of this week, ChatGPT now boasts 100 million weekly active users. While this places ChatGPT as the most popular platform on the internet, it also renders it a lucrative target for cybercriminals and hacktivists.

OpenAI has not yet said when it expects the ChatGPT outages to be fully resolved. However, the company has assured users that it is working to resolve the issue as quickly as possible.

ChatGPT Down? OpenAI Blames Outages on DDoS Attacks
ChatGPT’s status page as of Nov 09, 2023

The ChatGPT outages have had a significant impact on users of the service. Many users have been unable to access ChatGPT at all, while others have experienced intermittent outages.

DDoS attacks are a type of cyberattack in which an attacker sends a large number of requests to a website or server in order to overwhelm it and make it unavailable to legitimate users. In the case of ChatGPT, the attackers are flooding the service with more requests than it can handle, causing it to go down.

Anonymous Sudan Claims Responsibility

Hackread.com can confirm that the responsibility for the attacks on OpenAI’s infrastructure has been claimed by Anonymous Sudan. The group shared various screenshots on its Telegram channel, depicting examples where OpenAI’s website and ChatGPT’s dashboard experienced downtime or displayed various errors and connectivity issues.

The group further elaborated on their motives for targeting OpenAI and ChatGPT, highlighting the reasons behind their DDoS attacks on one of the most popular platforms globally. In a Telegram post, they stated that as they are specifically targeting American companies, OpenAI, being an American company, is naturally among their prime targets.

The group additionally cited another major reason for targeting OpenAI, pointing to its association with the state of Israel, its investment plans in Israel, and the recent meeting between OpenAI’s CEO, Sam Altman, and the Israeli Prime Minister, Benjamin Netanyahu. Emphasizing their support for the Palestinians, the group mentioned this as a significant rationale behind targeting OpenAI and ChatGPT.

For your information, Anonymous Sudan is a group of hacktivists who claim to be affiliated with the Anonymous collective. However, cybersecurity experts have cast doubt on these claims, suggesting that Anonymous Sudan may be a front for other Russian hacktivist groups.

Anonymous Sudan first emerged in January 2023, when they launched a series of DDoS attacks against Swedish and Danish organizations in response to the far-right activist Rasmus Paludan. In February 2023, Anonymous Sudan also DDoSed Swedish SAS Airlines.

The group has since claimed responsibility for a number of other DDoS attacks, including attacks against X (formerly Twitter), Microsoft, and other Western targets.

If you are a user of ChatGPT, there is not much you can do to prevent DDoS attacks. However, you can check the OpenAI status page for updates on the situation and to see if the service is available. You can also try accessing ChatGPT at different times of day, as the attacks may not be continuous.

  1. Hackers Target Israeli Rocket Alert App Users with Spyware
  2. 10 Top DDoS Attack Protection and Mitigation Companies in 2023
  3. Google, Cloudflare and AWS Disclose Largest DDoS Attack in History
  4. Hackers Send Fake Rocket Alerts to Israelis via Hacked Red Alert App
  5. Researchers Leverage ChatGPT to Expose Notorious macOS Malware
  6. WormGPT – Malicious ChatGPT Alternative Empowering Cybercriminals

[ad_2]
Source link