Microsoft tells some employees to replace their Android phones with iPhones in the office

0
[ad_1]
An internal memo reviewed by Bloomberg revealed that starting in September, Microsoft employees in China will need to use an iPhone for authentication when they sign into company systems. Android phones will not be allowed as multi-factor authentication devices. When signing into Microsoft systems, employees need to use a smartphone and two Microsoft apps to log in. 

When the new rules take effect in less than two months, iPhone handsets will be required to run the two Microsoft apps, the Microsoft Authenticator password manager and Identity Pass app. The software company requires multi-factor authentication to guard against hackers. The new rules will impact hundreds of Microsoft employees who work in Mainland China.

Microsoft’s memo notes that it blocked Android phones from being used for multi-factor authentication because Android phones are not allowed to run Google services in China. That prevents the Microsoft employees from accessing the Google Play Store leaving Apple’s App Store as the only place where these employees can download the required security apps. Android app storefronts are fragmented in China with the ban on Google services forcing phone manufacturers in the country to offer their own app stores. Such manufacturers include Huawei and Xiaomi.
Any members of the Microsoft staff in China owning an Android phone will be forced to purchase an iPhone 15 for a one-time payment. Microsoft will make iPhones available at hubs across China and even in Hong Kong where Google services are allowed. Microsoft employees in China will still be allowed to use Android handsets as their personal phones.

The company has been the target of multiple state-sponsored attacks by hackers. Back in January, an attack linked to Russia affected many U.S. government agencies including the State Department. With U.S. lawmakers putting pressure on Microsoft, the company started the Secure Future Initiative (SFI) company-wide last November. SFI will use AI to help it address vulnerabilities in the cloud faster, make it more difficult for hackers to obtain credentials, and automatically require multi-factor authentication for employees.

And that brings us right back to the internal memo alerting Microsoft workers on the Mainland that they must use an iPhone at work.


[ad_2]
Source link

Ticketmaster Hackers Leak 30K Ticket Barcodes, Share Counterfeit Tutorial

0
[ad_1]

Ticketmaster hackers leak 30,000 ticket barcodes for top upcoming events, including music concerts. They also share a DIY counterfeit tutorial on making physical tickets from the leaked barcodes and other ticketing data.

Ticketmaster hackers have leaked 30,000 additional ticket barcodes for some of the top upcoming events and concerts featuring popular artists and music bands.

It is also worth noting that on July 4 and 5, 2024, as exclusively reported by Hackread.com, ShinyHunters and Sp1d3rHunters, who are two different individuals but are affiliated with the group behind the Ticketmaster data breach, leaked 44,000 and 170,000 ticket barcodes related to Taylor Swift’s The Eras Tour. With these leaks, the total number of leaked ticketing data goes up to 640,000.

The latest 30,000 data leak includes ticketing and barcodes related to the following events and artists:

  • Pearl Jam
  • Sammy Hagar
  • Stevie Nicks
  • Steve Miller Band
  • Cirque du Soleil
  • USHER: Past Present Future
  • Chris Brown – The 11:11 Tour
  • P!NK: Summer Carnival 2024 (Multiple cities)
  • Aerosmith: PEACE OUT The Farewell Tour – (10+ cities)
  • Neil Young – Crazy Horse – Love Earth Tour July 08
  • Alanis Morissette – The Triple Moon Tour – July 13
  • Red Hot Chili Peppers: Unlimited Love Tour – July 17
  • Bruce Springsteen and The E Street Band 2024 Tour
Ticketmaster dataset (Screenshot credit: Hackread.com)
Screenshot from Ticketmaster dataset (Screenshot credit: Hackread.com)

What Exactly is in This Data Leak?

The ticket industry is a complicated one. Although Hackread.com has over a decade of experience in data breach analysis, things can be tricky sometimes. Therefore, we used ChatGPT-4o to analyze a small sample from the leak. Here’s what it found:

The leak of Ticketmaster ticketing data, including barcodes, is indeed bad news for Ticketmaster and its customers. Here's an analysis:

What is in the Leak

The provided data includes:

1: Ticket Barcodes: Unique ticket barcode values.
2: Event Details: Start time, event key, event ID, event name, venue details, etc.
3: Sales Order Information: Sales order ID, transaction ID, ticket type codes.
4: Seating Information: Section name, row number, seat number.
5: Venue Info: Venue ID, venue name, address, city, state, country, postal code.
6: User and Session Information: Browser ID, web session cookie values.

Potential Risks and Implications

Ticket Forgery and Resale:

Barcode Duplication: The leaked barcodes can be duplicated to create counterfeit tickets. Fraudsters could print fake tickets using these barcodes and sell them to unsuspecting buyers.

Loss of Revenue: Counterfeit tickets can lead to revenue loss for both Ticketmaster and event organizers.

Overcrowding and Security Risks: Events could face overcrowding if counterfeit tickets are used, leading to security and safety issues.

Verification Challenges: Ensuring the authenticity of tickets at event entry points will become more challenging, potentially causing delays and operational disruptions.

Increased Costs: Implementing measures to mitigate the impact of the leak, such as reissuing tickets or enhancing verification processes, will incur additional costs.

This leak is a significant issue for Ticketmaster, requiring immediate and comprehensive action to mitigate the risks and prevent future occurrences.

Can Anyone Use These Tickets?

Well, kind of. The online tickets could be impossible to use, but apparently, the physical copies of tickets can be used without any hurdles. Last week, Ticketmaster told Hackread.com that there is no way to use these tickets because the company uses a technology called “SafeTix,” which protects tickets by automatically refreshing with a new and unique barcode every few seconds, making it impossible to reuse.

However, the company did not mention anything about physical copies of tickets, which hackers have pointed out in their latest counterstatement, announcing that they have extracted physical tickets as well.

“Our Response to Ticketmaster’s claims is Ticketmaster lies to the public and says barcodes can not be used. The ticket database we have includes both online and physical ticket types.”

Hackers

What’s worse for Ticketmaster is that the hackers have also shared a four-step tutorial explaining how to make your own real tickets using the leaked information. This includes a YouTube video, Ticketmaster’s TicketFast artwork guidelines, and a link to the Ticketmaster site explaining printing guidelines for their tickets. Hackread.com will not share the complete tutorial due to security reasons.

Ticketmaster Hackers Leak 30K Ticket Barcodes, Share Counterfeit Tutorial
Sp1d3rHunters on Breach Forums with the latest Ticketmaster dataset (Screenshot credit: Hackread.com)

Who is Behind the Ticketmaster Data Breach?

The original Ticketmaster data breach saw claims from the ShinyHunters hacker group of stealing 560 million user records and a ransom demand of $1 million—an offer that Ticketmaster denies it ever facilitated or has any plans to accept.

Last week, the ransom demand increased to $8 million after ShinyHunters revealed (in a now-deleted post on Breach Forums) that the stolen data was larger than previously anticipated, making it more valuable than ever. This includes the following information:

  • 980 million sales orders
  • 680 million orders detail
  • 1.2 billion party lookup records
  • 440 million unique email addresses
  • 4 million uncased and deduped records
  • 560 million AVS (Address Verification System) detail records
  • 400 million encrypted credit card details with partial information

But who is the threat actor or group behind the Ticketmaster data breach? According to two known cybersecurity researchers who shared exclusive information on the basis of anonymity, ShinyHunters is not behind this data breach but is merely affiliated with a high-profile, financially motivated threat group that is the actual actor behind the breach.

The name of the threat group cannot be shared at this time due to security reasons and for reasons Hackread.com would rather not disclose until authorities do so on their own. On the other hand, sources also told Hackread.com that Sp1d3rHunters is also not involved in the breach; their main role is to post about the breach on different forums to attract as many potential buyers as possible.

Nevertheless, it’s another day with more bad news for Ticketmaster. If you are a Ticketmaster user, make sure to change your account password and keep an eye on any suspicious activity.

  1. BreachForums Returns Under ShinyHunters Hackers
  2. Alleged ShinyHunters Hacker Group Member Arrested
  3. TEG Ticket Vendor Breach: 30M User Records for Sale
  4. ShinyHunters Leak 33 Million Twilio Authy Phone Numbers
  5. AT&T breach ShinyHunters selling AT&T database with 70M SSN

[ad_2]
Source link

Google Play Protect may get a more powerful local APK scanning

0
[ad_1]

Google could boost Play Protect’s local app scanning capabilities soon. Now, the system would be more powerful and efficient thanks to the implementation of the YARA tool. The change would be a new step in the mixed malware-scanning approach implemented last year by the company.

Play Protect, Play Services, and Play Store are Google’s main tools to keep your Android device free of malware. Play Protect works both on apps you download from the Play Store and on APKs from external sources. Previously, the company used a cloud-based approach that required sending APKs from external sources to Google for analysis.

However, since last year, Google Play Protect can locally scan unknown APKs for malware. This way, the Mountain View giant adopted a mixed malware-scanning approach instead of a fully cloud-based one. Now, Play Protect’s local malware scanning could get more powerful thanks to the implementation of YARA.

YARA would enhance Google Play Protect’s local APK scanning

YARA is not exactly a new tool, and it has even been used in traditional antivirus for a long time. YARA is a tool capable of detecting malware by classifying it by “families.” It works by searching for code that is common among a “family” of malware. Families are set through “YARA rules” where files (apps in this case) meet certain common characteristics.

This approach prevents malware from bypassing traditional hash-based scanning. The latter works by searching for an exact hash match, but modern malware is capable of modifying itself to generate a new hash. So, basically, local malware scanning should become more efficient and effective soon, with greater detection capacity. YARA scanning references are available in the latest Play Store v41.7.16 update, as spotted by Android Authority.

It’s notable that local scanning is less powerful than cloud-based scanning. Mobile devices do not have the hardware resources necessary to run all the scanning tools that Google runs on its powerful servers. That’s why the company takes a mixed approach rather than local-only. However, the implementation of YARA will make Play Protect’s local malware analysis more capable, powerful, and autonomous.


[ad_2]
Source link

Microsoft’s staff in China forced to exclusively use iPhone devices

0
[ad_1]

Microsoft’s employees based in China will have to change their phones if they run Android. Microsoft is establishing a new policy where its employees will have to exclusively use iPhone devices. The main reason seems to be the ban on Google Play Services in the Asian country.

According to Bloomberg, as of September, employees affected by the decision will only be able to use Apple devices to access identity verification apps. The company wants to ensure that everyone has the Microsoft Authenticator and Identity Pass apps on their phones.

Microsoft employees forced to replace their Android devices with iPhones

The decision is part of an initiative to set stronger security measures that strengthen the company against potential attacks. For months now, Microsoft has been the target of constant attacks allegedly sponsored by the Russian government. The US government even confirmed that a related data breach also affected the State Department. The breach did not compromise the security of key confidential data. However, the situation caused US legislators to pressure the Redmond giant to implement stricter security systems.

According to the report, the company will provide iPhone 15 units as a “one-time purchase” to its staff in China. Interestingly, even employees based in Hong Kong will have to comply with the measure. It’s noteworthy that Google Play Services are available in Hong Kong. However, Microsoft is not making exceptions with its new policies.

New policies contradict the Chinese government’s position regarding foreign devices

Still, the Chinese government may not be too happy with Microsoft employees now exclusively using iPhone devices. Since 2023, they have been promoting the abandonment of devices of foreign origin at work. Like Microsoft, the Chinese government cites security concerns as the reason for the measure. However, now Microsoft employees in China will have to discard Android devices from local brands such as Xiaomi and Huawei in favor of iPhones.


[ad_2]
Source link

Play Store to change how it shows ratings by different form factors

0
[ad_1]

Google has introduced a lot of new updates to the Play Store in recent months. The search titan has already made it easier for you to discover new apps and games, which work best on your device. The Play Store also shows ratings for apps and games with dedicated icons for different form factors.

You can easily check the ratings of a particular app with dedicated rating options for phones, tablets, and even Chromebooks. Now, Google will reportedly introduce a new update for the Play Store, which will simplify viewing ratings for various devices.

Play Store will soon start displaying app ratings inside the icon for different form factors

Currently, the Play Store displays app ratings for apps with dedicated icons for different form factors. You can tap on any of the dedicated buttons to view the exact user ratings for various devices. However, in a new APK teardown, Android Authority and code sleuth AssembleDebug have found a small but important tweak to this functionality.

The sources have found a more convenient way of viewing ratings by form factor in version 41.7.16-31 of Play Store. In the latest change, the Play Store will start displaying ratings right inside the dedicated icons for different devices. So, you will no longer have to tap on the icon to view the app or game’s rating for a particular device. It appears to be a small but welcome change, saving you a couple of seconds of your time.

The new tweak to the Play Store ratings appeared in the latest beta version of the app. Moreover, the feature was only spotted after an APK teardown of the latest version. So, there’s no clarity on when Google will make this functionality available to everyone. There’s a possibility that Google may simply remove the new tweak and show the ratings as they are displayed right now.

Another update for Play Store will soon open installed applications automatically

Google will also be adding another feature to the Play Store in the near future. The upcoming feature will automatically open applications after they are installed. Called App Auto Open, it will be an optional feature, which users can easily switch on or off.

Soon, there will be an option to activate the auto-open functionality right below the Install button. It should be available to the public in the upcoming versions of the Play Store soon.

Play Store rating form factors


[ad_2]
Source link

Samsung starts testing Android 15 & One UI 7.0 for Galaxy S24

0
[ad_1]

Samsung may have begun testing the Android 15-based One UI 7.0 update for the Galaxy S24 series. The Plus model recently surfaced on Geekbench running the new Android version. The big update may not arrive anytime soon though. Rumors say the company will slightly delay One UI 7.0 to focus on One UI 6.1.1.

Galaxy S24+ spotted on Geekbench with Android 15

Debuting with Android 14, the Galaxy S24, Galaxy S24+, and Galaxy S24 Ultra will receive as many as seven major Android OS updates. You will get new features all the way up to Android 22 in 2031, and potentially a couple of notable One UI updates in 2032. That may be long away, but the journey begins later this year with Android 15 and One UI 7.0.

Samsung started working on the new One UI version for the Galaxy S24 series in May. Well, the work development may have begun earlier, but we got the first proof in May. It appears the company has achieved a significant milestone in the development milestone and started testing the big update internally. Hopefully, users will get a taste of it soon.

Samsung was expected to open One UI 7.0 beta programs for the Galaxy S24 trio in August, followed by the stable update in October. However, a reliable industry insider recently claimed that the update is delayed. They didn’t specify whether the delay would affect the beta update, stable update, or both but said Samsung is prioritizing One UI 6.1.1 over it.

Based on Android 14, the new One UI version will debut with the Galaxy Z Fold 6 and Galaxy Z Flip 6 foldables launching on July 10. It’s a substantial update thanks to new AI features and camera improvements. Samsung will push this update to several older foldables, tablets, and S series flagships (will arrive as One UI 6.1 on the Galaxy S24 and its predecessors).

The Korean firm likely doesn’t plan to begin the One UI 7.0 beta before completing the One UI 6.1.1 rollout. This means the first beta update is unlikely to arrive in early August. We may still get the stable update before the end of October, though. We will keep track of One UI 7.0 development and let you know when we have more information.

AI features, privacy improvements, and more are on the cards

Samsung will probably introduce more AI features to Galaxy devices with One UI 7.0. Perhaps those AI features may be one of the reasons why the update could be delayed. Additionally, rumors have hinted at a built-in app locker, a basic privacy tool that One UI lacked all this while. Stick around for more about One UI 6.1.1 and One UI 7.0 for Galaxy devices.

Samsung Galaxy S24 Android 15 One UI 7 testing Geekbench


[ad_2]
Source link

Apple’s new Siri should arrive next Spring

0
[ad_1]

Current and potential iPhone users are all awaiting the new features coming to Siri with iOS 18. The only question is when are they going to be able to get their hands on the features? Well, we just got word about when they should eventually land, and you’re not going to like it. According to a new report, we should expect the new Siri to officially hit the iPhone sometime next Spring.

Apple really shook the tech world when it announced Apple Intelligence back during WWDC. This technology brings a slew of additions to the software like tight integration with ChatGPT. Users will also gain generative AI tools like the ability to generate emojis.

Along with the announcements, we also got news about a new Siri coming to the platform. The new Siri will be much more integrated into the software, which is something that people have been pining for. You’ll be able to ask Siri to perform certain actions within apps without lifting a finger. The new Siri is one of the things that people are most excited about.

The new Siri should come next Spring

The new Siri is something that’s going to bring a ton of people over to iOS, and we’re sure that it’s going to be a driving force behind the iPhone 16’s sales. However, people buying that phone on day one will need to wait some time for their new features.

According to Mark Gurman, the new Siri features won’t hit iPhones until sometime next Spring. That’s a bit of a bummer, as we’re getting ready to enter 2024’s Summer season. So, this means that users might have to wait about a year for the new Siri.

That’s not to say that users will need to wait that long for all of the Apple Intelligence features. The visual redesign and ChatGPT integration are expected to land this Fall along with other AI features. So, if you’re an iPhone user waiting for the new AI features, you’re most likely going to have features trickle in over the coming year.


[ad_2]
Source link

Proton Docs Arrives As An Encrypted Document Sharing Platform – Latest Hacking News

0
[ad_1]

The security brand Proton has just launched another online product aimed at securing users’ privacy. Named Proton Docs, the cloud document editing and sharing platform strives to serve as a secure alternative to existing tools like Google Docs.

Proton Docs To Serve As Secure Online Document Management Alternative

As announced in a recent post, Proton Docs is now available for users as a secure document management solution.

Proton Docs is an end-to-end encrypted platform that provides detailed document editing and sharing features. Like Google Docs, it also works in collaboration with the secure alternative Proton Drive, which stores documents.

Using this tool, users can experience all major document sharing and collaborative features, including comment additions, real-time document editing, adding photos, and storing documents safely. While all of that sounds similar to most other document management tools, Proton Docs takes the lead by encrypting users’ keystrokes and cursor movements—a key step towards protecting users’ privacy.

Besides launching this product, the provider highlighted the privacy risks associated with most existing document-sharing platforms like Google Docs and Microsoft 365. These include data collection and sharing by the vendors (with or without users’ consent), which they may further use for various purposes, such as training AI models. Likewise, the lack of encryption makes users’ documents vulnerable to data breaches, government monitoring, third-party access, and other sorts of surveillance due to weak privacy laws.

Proton Doc’s end-to-end encryption protects users from all such threats. It secures users’ data to the level of keystrokes, ensuring no third-party access, not even from the provider itself. It gives users complete control over the documents they create and store and whom they share with.

Proton Docs – like other Proton products – comes with a freemium model. Its free plan provides users with a 5GB storage, whereas pro users can subscribe to the higher pricing plans, offering 200GB, 500GB, and 3TB of storage. The two subscription plans also offer users an access to the entire Proton ecosystem.

Let us know your thoughts in the comments.


[ad_2]
Source link

Android devices could get Fuchsia OS, but not as you expect

0
[ad_1]

Google could integrate Fuchsia OS into Android devices after all. However, probably not as you imagine, but in a more discreet way. Everything would revolve around the microfuchsia project.

Fuchsia OS, the least known among Google’s operating systems

In the OS segment, the Mountain View giant is well known for Android and Chrome OS. That said, the lesser-known Fuchsia OS has also been around for years. Android and Chrome OS were developed on the Linux kernel. Meanwhile, Fuchsia OS uses Zircon as its core, which has a microkernel-like architecture. For reference, HarmonyOS NEXT architecture is also microkernel-based.

A microkernel architecture means that the entire OS does not run directly in the kernel. Instead, only the most basic services (such as the items necessary to boot the system) do so. So, there is less of a highly privileged code, which translates into improved security and stability. There’s a drawback to this, since the performance is lower because there is more data continuously moving between different spaces (kernel and user space).

Perhaps the performance issue is what has delayed (or canceled) Google’s rumored intentions to replace Android with Fuchsia OS. However, it can still be implemented on a smaller scale, and that’s what Google could do on smartphones.

Fuchsia OS could be implemented on Android devices for improved security

According to Mishaal Rahman, Google has been working on “microfuchsia” since April 2024. This is a project to run Fuchsia OS on current devices through virtualization. With this, the company would aim to implement microfuchsia on Android to run certain types of processes in securely isolated environments. Currently, the Microdroid subsystem takes care of that on Android. So, Google could replace Microdroid with microfuchsia for greater security, and perhaps greater speed.

The source adds that AOSP just got preparatory patches for the implementation of microfuchsia. However, Google’s plans in this regard are still not entirely clear. Currently, the company has only implemented Fuchsia OS on smart home devices from the Nest family. Hopefully, more details about the microfuchsia project will emerge in the coming weeks or months.


[ad_2]
Source link

This foldable keyboard is a full-fledged PC, believe it or not

0
[ad_1]

Mini or portable PC tech has evolved over the years. Raspberry Pi and Intel NUCs are some of the biggest names in this segment. Now, a Chinese electronics company that goes by the name Linglong has created a foldable “keyboard PC”. This device stuffs the innards of a decent notebook inside a foldable keyboard. The mini PC is small enough to fold in half and fit into your back pocket.

It is both a foldable keyboard and a mini PC with an AMD Ryzen 7 8840U processor

Linglong has shared a live presentation of its “keyboard PC” on the video-sharing site bilibili. In the video, the presenter pulled out the actual mini PC from his back pocket, showing the device’s ultra-portability. The device is both a foldable keyboard and a mini PC with an AMD Ryzen 7 8840U processor. The portable offering even has a built-in battery and a trackpad, so all you need is a display to use it.

The Chinese company has presented the Linglong “keyboard PC” as the ultimate mobility device. The tiny dimensions of the device make it even smaller than the other products in the category. The machine appears to be a more affordable and portable version of the Spacetop G1. In the video, the company has shown the Linglong “keyboard PC” being attached to a TV, a tablet, and a phone. These devices can double as the display for it.

It has 32GB RAM, 1TB SSD, and delivers up to 10 hours of battery life

The Linglong foldable keyboard PC can be configured with either 16GB or 32GB of RAM. The SSD storage configurations include 512GB and 1TB. The company claims that the mini PC offers 10 hours of battery life for light office work. Or you can watch movies for up to six hours. It’s worth mentioning that, if you attach it to a display that consumes power from the keyboard PC unit, the battery life will go down significantly.

Besides the aforementioned features, the Linglong keyboard PC also has a USB 3.0 port, a USB 4 Type-C port, and a USB 3.2 Type-C port. The other connectivity options include Wi-Fi 6 and Bluetooth. There’s also a small fan inside the keyboard PC for active cooling. The whole package tips the scale at 800 grams.

The Linglong keyboard PC will retail at RMB 4,699 or $645 for the 16GB/ 512GB version. The 32GB/1TB storage variant will sell for RMB 5,699 or $780. According to Tom’s Hardware, Linglong is initially planning to sell around 200 units of the device to beta testers in China. There’s no word if and when the portable will be available to buy worldwide.


[ad_2]
Source link