Here’s what the canceled Pixel Fold prototype looked like

0
[ad_1]

Google boarded the foldable smartphone bandwagon by launching the Pixel Fold at the I/O event 2023. By then, major brands like Samsung had already released multiple generations of their foldable smartphones. Although Google was late to the party, it already had a foldable phone in the pipeline since 2019.

The first-gen Google foldable smartphone was allegedly in active development under the codename “Passport” in 2020 and “Pipit” in 2022. Unfortunately, the first Google foldable prototype never saw the light of the day. However, nearly a year after the Pixel Fold’s launch, alleged photos of the canceled Google Pixel Fold prototype have appeared online.

The canceled Google Pixel Fold prototype had a familiar design

The photos of the alleged first-generation Google Pixel Fold prototype first appeared in an XDA forum thread last month. The original images have since been deleted. However, Android Authority managed to get copies of the images. Furthermore, the source claims that these images are indeed of the canceled Google Pixel Fold prototype. These photos are of the prototype, which was in development under the codename “Pipit” (Passport earlier).

The leaked images show that the first-generation Google Pixel Fold smartphone’s prototype had a familiar design. It appears to be eerily similar to the final Pixel Fold. The major difference between their design is a Pixel 6-like seamless glass bar running through the entire width of the prototype offering. The final product sports a smaller camera module made of polished metal, just like the Pixel 7 Pro.

Apart from the aforementioned differences, the Pipit prototype is almost similar to the final product. It has a similar aspect ratio, frame, and hinge design. Although it’s not visible in the images, the prototype model even had a matte back glass like the final phone. There appears to be a skin applied to the back of the prototype version.

Notably, the source claims that the Pipit foldable prototype even had support for a stylus. If launched, it would’ve arrived with the first-gen Tensor chipset, two 12MP primary Sony cameras, and an 8MP selfie snapper. Furthermore, the report suggests that the Pipit prototype had a smaller display at 66 x 128mm as compared to 67 x 130mm on the final Pixel Fold.

The Pixel Fold 2 is likely launching on August 13 alongside the Pixel 9 series

Google is now all set to host its annual “Made by Google” event on August 13. At the event, the company is expected to introduce a couple of new Pixel 9 series flagships. In addition, the Mountain View-based tech giant could also unveil the Pixel Fold 2 at the same event. Some reports suggest that the second-gen foldable offering from Google could be called the Pixel 9 Pro Fold instead.

Recently, a few leaked case render images suggested that the Pixel Fold 2 will be taller and narrower than the first-gen model when folded. The device will sport a much different primary camera island at the rear. It will be placed in the top-left corner of the handset’s backside as compared to the middle on the Pixel Fold.

The rumor mill indicates that the Pixel Fold 2 or Pixel 9 Pro Fold will be powered by the Tensor G4 chipset. It could be offered with up to 16GB of RAM and the upgraded UFS 4.0 faster storage solution. The new foldable is also expected to flaunt some AI-powered camera enhancements and more. We can expect official details about the phone in a matter of weeks, so stay tuned.


[ad_2]
Source link

Hackers Using Google Ads To Deliver ‘Poseidon’ Mac Stealer

0
[ad_1]

Hackers abuse Mac Stealer to covertly extract sensitive information such as passwords, financial data, and personal files from macOS devices.

Besides this, macOS users or Mac users are considered valuer targets.

On June 24th, Malwarebytes researchers identified another Mac-specific stealer campaign named Poseidon. This campaign used Google malicious ads for the Arc browser.

This is the second instance of Arc being used as a lure by OSX in recent times. RodStealer is distributing malware.

Created by Rodrigo4, a threat actor who competed with Atomic Stealer, this tool is more developed and can steal VPN configurations.

Hackers Using Google Ads

The ad for this malware was found on the XSS underground forum and it offers similar functionalities to Atomic Stealer such as file grabbing, extraction of crypto wallets, and theft of password managers.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

What this campaign shows is that attackers responsible for Mac-related malware have started using new strategies while always exploiting popular software.

A Google ad campaign for the Arc browser that maliciously redirects people to a fraudulent site (arc-download[.]com) that offers a Mac-only version is connected to “Coles & Co” and arcthost[.]org.

Malicious ad for Arc browser via Google search (Source – Malwarebytes)

The downloaded DMG file uses a right-click bypass for security to make it seem like a genuine Mac application installation process.

This recent malware called “Poseidon,” which builds on previous ones, has incomplete code for stealing VPN configurations from Fortinet and OpenVPN.

Malware exfiltrates data to a specific IP address leading to a Poseidon-branded control panel, implying a sophisticated and evolving risk to MacOS users.

An active Mac malware development scene focuses on stealers like Poseidon. Threat actors advertise feature-rich products with low antivirus detection to potential customers. 

The observed campaign confirms the active targeting of new victims. Protection requires vigilance when installing new apps. 

Malwarebytes continues detecting this threat as OSX.RodStealer and has informed Google about the malicious ad. 

Users are advised to employ web protection tools like Malwarebytes Browser Guard to block ads and malicious websites as a primary defense against such evolving Mac-targeted threats.

IoCs

IoCs (Source – Malwarebytes)

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files


[ad_2]
Source link

HONOR Magic V3 camera, battery & more details appear

0
[ad_1]

New HONOR Magic V3 details have just appeared, following the phone’s teaser that surfaced not long ago. This information comes from Teme, who shared some camera, battery, hinge, and other details.

Some HONOR Magic V3 details have just appeared

We still do not have exact specs for the device, but let’s see what the tipster said. He says that the phone will be fueled by the Snapdragon 8 Gen 3. That makes sense, the Magic V2 was fueled by the Snapdragon 8 Gen 2.

The tipster also says that the phone will support satellite connectivity, but only in China. It will also support 5.5G connectivity. It was already revealed that it will be 9.Xmm thick when folded, so possibly thinner than its predecessor (9.9mm).

The HONOR Magic V2 will weigh 22X grams. So somewhere between 220 and 229 grams.  Its predecessor’s weight was 231 or 237 grams, depending on which model we’re talking about.

In regards to battery, the tipster says it will be 5xx0mAh, in other words, at least 5,000mAh. That was the battery capacity of the HONOR Magic V2, and that phone offered really good battery life.

The phone will feature a 50-megapixel camera & 66W charging

The device will also support 66W wired charging. Wireless charging likely won’t be a part of the package yet again. A 50-megapixel ‘Eagle Eye’ camera will also be a part of the package.

The phone will also include an ultra-thin Type-C connector and an upgraded hinge. That hinge will include some sort of water resistance, last year’s did not.

That is pretty much everything that the tipster shared. The HONOR Magic V2 launched on July 12, so we’re expecting its successor to arrive in the near future too. HONOR still didn’t reveal its launch date, however.

Let’s just hope that the global model will arrive sooner this time around. It took HONOR around 6 months to deliver the Magic V2 global model following the China launch.


[ad_2]
Source link

Samsung Health may be getting two helpful medication-related features in a future update

0
[ad_1]
Samsung Health might be getting some notable improvements in the near future. Code discovered by the folks at Android Authority suggests that the app will be getting medicine scanning and drug-allergy interaction in a future update.

Samsung Health is Samsung’s platform for health and fitness monitoring, which powers the health-tracking features of Galaxy Watches and soon, the Galaxy Ring. The new features were discovered hidden in the code for the app, which means they’re currently in development and not officially available yet.

The first one will allow you to scan your medication and add its information automatically. Probably, data like the name of the medication, the mg dose (strength), and whether it’s a tablet or a capsule will be able to be added automatically.

In 2023, Samsung announced medication tracking for Health. Basically, it helps you track your medications and provides tips about them, as well as general descriptions and possible side effects from the medication added.

The second feature that’s currently in the works is drug-allergy interactions. You will be able to select from some common allergies or add your own and Samsung Health may be informing you whether a drug can cause you an allergic reaction.


The way this warning will work is similar to how drug-to-drug interactions show up.

[ad_2]
Source link

Microsoft Alerts More Users in Update to Midnight Blizzard Hack

0
[ad_1]

Microsoft has issued a new alert to its users, updating them on the continued threat posed by Midnight Blizzard, a Russian state-sponsored hacking group also known as NOBELIUM.

The alert follows the initial detection of the attack by Microsoft’s Security Team on January 12, 2024.

The attack, which targeted Microsoft’s corporate email systems, prompted an immediate response from the company.

Subsequent investigations have revealed that Midnight Blizzard has been using information exfiltrated from these systems to attempt unauthorized access to other areas, including some of Microsoft’s source code repositories and internal systems.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

Increased Attack Volume and Sophistication

In recent weeks, Microsoft has observed a significant increase in the volume and sophistication of Midnight Blizzard’s attacks.

The group has ramped up its efforts, with password spray attacks increasing tenfold in February compared to January 2024.

This escalation underscores the group’s sustained commitment and coordination, reflecting a broader trend of sophisticated nation-state cyber threats.

Despite these efforts, Microsoft has found no evidence of compromised customer-facing systems.

“Midnight Blizzard increased the volume of some aspects of the attack, such as password sprays, by as much as tenfold in February compared to the already large volume we saw in January 2024, Microsoft said

However, the company remains vigilant and proactive in its defense strategies.

In response to the ongoing threat, Microsoft has bolstered its security investments and cross-enterprise coordination.

The company has implemented enhanced security controls, detections, and monitoring to protect its environment against this advanced persistent threat.

Microsoft is also actively contacting customers whose information may have been compromised to assist them in taking mitigating measures.

The Midnight Blizzard attack highlights the evolving and increasingly complex global threat landscape.

Microsoft remains committed to transparency and will continue to share updates as its investigations progress.

The company’s ongoing efforts to secure its systems and protect its users reflect a broader industry need for heightened vigilance and robust cybersecurity measures in the face of sophisticated nation-state attacks.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files


[ad_2]
Source link

Juniper Releases Out-Of-Cycle Critical Update for Smart Routers

0
[ad_1]

Juniper Networks has released an out-of-cycle critical update to address a severe vulnerability affecting its Session Smart Router, Session Smart Conductor, and WAN Assurance Router products.

The security flaw, identified as CVE-2024-2973, allows network-based attackers to bypass authentication and gain full control of the affected devices.

This vulnerability is particularly concerning due to its high severity, with a CVSS score of 10.0 under both CVSS 3.1 and CVSS 4.0 metrics, indicating the maximum level of risk.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

Products Affected

The vulnerability impacts the following products:

  • Session Smart Router: All versions before 5.6.15, versions from 6.0 before 6.1.9-lts, and versions from 6.2 before 6.2.5-sts.
  • Session Smart Conductor: All versions before 5.6.15, versions from 6.0 before 6.1.9-lts, and versions from 6.2 before 6.2.5-sts.
  • WAN Assurance Router: Versions 6.0 before 6.1.9-lts and versions 6.2 before 6.2.5-sts.

The vulnerability is classified as critical because it could allow attackers to bypass authentication and take complete control of the device.

This issue specifically affects routers and conductors operating in high-availability redundant configurations, which are commonly used in mission-critical network infrastructures such as large enterprises, data centers, telecommunications, and government services.

Juniper Networks has released updates to mitigate this vulnerability. The fixed versions are:

  • Session Smart Router: SSR-5.6.15, SSR-6.1.9-lts, SSR-6.2.5-sts, and subsequent releases.
  • Session Smart Conductor: Same versions as the Session Smart Router.
  • WAN Assurance Router: Automatically patched when connected to the Mist Cloud.

Administrators are advised to upgrade to these versions to secure their systems. In Conductor-managed deployments, upgrading the Conductor nodes will automatically apply the fix to all connected routers.

However, upgrading the routers to the fixed versions is still recommended to ensure complete protection.

Juniper’s Security Incident Response Team (SIRT) has not observed any malicious exploitation of this vulnerability. The issue was discovered during internal security testing and research.

There are no known workarounds for this issue. The only recommended action is to apply the available updates.

The fix’s application is designed to be non-disruptive to production traffic, with only a brief downtime (less than 30 seconds) for web-based management and APIs.

Juniper Networks’ prompt response to this critical vulnerability underscores the importance of maintaining updated security measures in network infrastructure.

Administrators should prioritize applying these updates to protect their systems from potential exploitation.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files


[ad_2]
Source link

A week in security (June 24 – June 30)

0
[ad_1]

June 28, 2024 – The Arkansas Attorney General filed a lawsuit against webshop Temu for allegedly being dangerous malware which is after personal data.

June 27, 2024 – Researchers have found an online repository leaking sensitive data, including driving licenses and other identity documents.

June 27, 2024 – A competitor of the infamous Atomic Stealer targeting Mac users, has just launched a new campaign to lure in more victims.

June 26, 2024 – LockBit claimed to have breached Federal Reserve but in fact the data came from Evolve Bank & Trust

June 26, 2024 – Malwarebytes Premium blocked 100% of malware during the most recent testing by the AV Lab Cybersecurity Foundation.


[ad_2]
Source link

Sony Enters Crypto Exchange Arena with Acquisition of Amber

0
[ad_1]

Sony Group, the Japanese conglomerate renowned for its gaming, music, and camera prowess, has officially entered the crypto exchange market.

According to crypto reporter Wu Blockchain, Sony has acquired Amber Japan, a regulated digital asset trading service provider.

Amber Japan, previously known as DeCurret, is the Japanese subsidiary of the global Amber Group.

This acquisition marks Sony’s significant step into the burgeoning world of cryptocurrency.

Amber Group’s Journey and Challenges

Amber Group, a global digital asset company, expanded its operations into Japan by acquiring and rebranding the Japanese crypto exchange DeCurret to Amber Japan in 2022.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

However, the company faced substantial financial challenges due to its trading capital exposure to the now-defunct crypto exchange FTX.

According to Crypto Briefing reports, The collapse of FTX prompted Amber Group to pivot its fundraising strategy, leading to a successful $300 million Series C round in December 2022.

Fenbushi Capital led this round, which also saw participation from notable investors such as Temasek, Sequoia China, Pantera, Tiger, and Coinbase.

The funds were aimed at protecting customers who lost money due to the FTX debacle.

Sony’s Blockchain and NFT Ambitions

Sony’s acquisition of Amber Japan is part of its broader strategy to diversify its portfolio, which already boasts a market value exceeding $100 billion.

For several years, the company has been exploring the potential of non-fungible tokens (NFTs) and blockchain technology in gaming.

In March 2023, Sony filed a patent for an “NFT Framework for Transferring and Using Digital Assets Between Games Platforms.”

This patent outlines a system for using NFTs across different platforms, including features like NFT-locked gameplay, limited-use in-game tasks, and rewarding players with NFTs.

This move into the crypto exchange market aligns with Sony’s vision of integrating blockchain technology into its diverse range of products and services.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files


[ad_2]
Source link

Tantrum in Jersey, YouTube’s lullaby, and the EU’s no to broccoli bundles

0
[ad_1]

Buckle up, news hounds! It’s time again for another episode of “News You Probably Missed and Shouldn’t Have!” We’ve got a whirlwind of headlines that went under the radar this past week packaged together to make you go, “Wait, what? When did this happen?” From illegal roadblocks for wireless giants to who-knows-what, this roundup is sure to keep you informed and maybe even a little surprised. So, grab a cup of coffee (or tea, we don’t judge), and let’s dive in!

New Jersey town blocks T-Mobile from building a tower

A town in New Jersey is throwing a tantrum like a toddler refusing broccoli because it’s “icky.” They are not letting T-Mobile build a cellphone tower in the area because it is allegedly unsafe, an illegal claim. That’s despite the carrier meeting all the requirements mandated by the law for creating a telecom facility, including the radio frequency emission limit. T-Mobile is trying to improve your wireless network connectivity, townfolks. It certainly won’t be using the tower to communicate with aliens.

YouTube prepares a sleep timer to let you sleep

Insomniacs rejoice! YouTube might finally stop keeping you company all night with a built-in sleep timer. The Music version of YouTube already has the feature, so it’s nice to see the video counterpart copying it. The new feature doesn’t yet have an ETA but imagine falling asleep to cat videos without the worry of waking up to polka music at 3 am. That’s what it can do. It’s like putting your phone on bedtime with a teddy bear. Sweet dreams!

The EU wants Microsoft to keep Teams and Office separate

Microsoft seems to be in hot water with the EU again! This time, it’s over its bundling of Teams with Office products. Imagine getting broccoli shoved in your lunchbox every day, even if you only wanted the pizza. That’s kind of the situation the EU sees with Teams being forced down users’ throats alongside Office. The EU is worried this gives Teams an unfair advantage and limits competition. So, Microsoft might be facing a hefty fine if it doesn’t clean up its act fast. A “broccoli pizza” for lunch might not work.

Google Search rolls back to Goooooooooogle days

Google Search is going back to the drawing board! Remember that endless scroll that lets you see results for days? Yeah, it’s getting the boot. From now on, you’ll be back to clicking through pages like a digital explorer in the olden days. Google says this change will make searches load faster, but some folks might miss the convenience of that never-ending scroll. Think of it as a forced break from the rabbit hole of search results – maybe you’ll actually find what you’re looking for faster after all!

Google Search continuous scrolling update next page

Your Google reviews are going public under one profile

Big brother Google is watching… your reviews! Get ready to be internet famous (or infamous) because Google just launched a new feature: public profiles for your reviews. Everyone can see if you think the latest Nicolas Cage flick is a masterpiece or a disaster. Bragging rights for that 5-star “Casablanca” review? You got it! Shame of admitting you secretly love reality TV? Uh oh. There is an option to make your profile private, but just like that time you accidentally posted a selfie you meant to delete… the internet never forgets.

You can now “Hype” up your favorite YouTube creator

Attention, YouTube devotee! Tired of just liking and sharing videos? Want to feel like a true patron of the arts (well, the art of cat videos)? YouTube is testing a new feature called “Hype”. It makes you a digital hype machine, boosting your favorite creators’ latest content. Think of it as showering them with virtual confetti (that grants them more views). It’s a win-win: creators get discovered, and you feel important. Now, someone just needs to invent a way to throw virtual tomatoes at bad content…

Apple aims to replace humans with robots in its iPhone factories

Ah, Apple and automation: a match made in…well, not exactly heaven for some folks. The company is looking to turn its iPhone factories into Terminator 2: Judgement Day. Instead of friendly humans, a bunch of robots will build your iPhone. It aims to replace at least half of human workers with machines. The good news: consistent quality control, maybe even lower prices. The bad news: saying goodbye to some human jobs, and the slight possibility of a robot uprising. Let’s just hope Siri doesn’t get any ideas…

Rimac is making a Level 4 robotaxi

Move over Bugattis, and make way for robotaxis! Rimac, the Croatian company known for its sleek and insanely fast electric supercars, is taking a sharp turn. Imagine ditching million-dollar rides for self-driving pod things. That’s basically Rimac’s new game plan. Their latest project is a Level 4 robotaxi called the Verne, and it’s aiming to hit the streets in 2026. So, ditch the dream of owning a Rimac supercar (unless you’ve got a Scrooge McDuck money vault), the future might involve being chauffeured around by one.

Verizon fined over $1 million for 911 outage

Verizon, the cell phone company that definitely isn’t run by pigeons in trench coats, blocked 911 calls in six whole US states for almost two hours! Instead of reaching paramedics or firefighters, all subscribers got was the soothing sounds of dead air. This happened sometime back, but the carrier couldn’t escape without repercussions. It had to cough up a cool $1 million for the blunder. Maybe invest in some signal flares for your next network upgrade, Verizon?

Korean internet provider installed malware on customer PCs

In a move that would make even a pirate raise an eyebrow, Korean internet service provider KT (aka Korea Telecom) is in hot water for allegedly installing malware on hundreds of thousands of customer computers (over 600,000). Why? To mess with their torrents, of course! Talk about a bad connection. This ISP decided to take a shady route to block a shady practice. Can’t wait to see how this plays out in court! Download justice may be slow, but it might hit KT hard.

Samsung to increase memory prices, blames AI for it

Samsung’s memory chips are suddenly in high demand, thanks to the booming world of AI. The company is using this as an excuse to bump up prices, which is about as subtle as a robot breakdancing. Imagine AI walking into a store, demanding memory chips in a robotic voice, and then accidentally tripping the inflation alarm. That’s basically what’s happening here. Looks like Samsung’s AI overlords are teaching it more about profit margins than processing power!

WhatsApp prepares a shortcut for video message replies

WhatsApp seems tired of seeing users fumbling around to reply to video messages (hey, WhatsApp claims it cannot see your messages). Its latest test update is saying “ditch the text, just react with a video!” Imagine a world where your grandma responds to your vacation clip with a thumbs-up video message – the future is here, folks! (Although, maybe hold off on sending that skydiving video to your parents just yet…)

WhatsApp video message replies test


[ad_2]
Source link

Apple is not promoting this Apple Music feature coming in iOS 18

0
[ad_1]
Last month we discussed a cool feature reportedly heading to Apple Music with the iOS 18 update. This feature is called Smart Crossfade and is supposed to make transitioning between songs seamless without hearing gaps of silence between tunes. While the song currently playing fades out, the next song starts to fade in. When I was in radio back in the day, this would be used when two songs were played back-to-back without any ads or DJ patter between songs.
Apple added Crossfade for Apple Music in iOS 17 but plans on making it smarter in iOS 18. Smart Crossfade is more seamless and not every transition between songs will allow for a fade out and a fade in; some will start immediately after the last word is sung on the tune currently playing. 

Apple is also making sure that the feature doesn’t change how an album sounds when the feature is enabled. A good example of this is the suite or medley (whichever you want to call it) of songs on  side 2 of the The Beatles’  Abbey Road album. This brilliant piece of musicianship, songwriting, and performing starts with “You Never Give Me Your Money” and continues through the end of the album with the 23-second “Her Majesty.” With the Smart Crossfade feature, the songs will segue right into each other as they do on the album.

Smart Crossfade turns on once you enable Crossfire in the Apple Music app’s settings (more on that later). With Crossfade, users can set the length of the crossfade from one second to 12 seconds. If you’re an Apple Music subscriber running the iOS 18 beta, you can try Smart Crossfade. Go to Settings > Music and toggle on Crossfade. Play around with the settings until you find which Crossfade length (again, you can choose between one second and 12 seconds) you prefer. You can still do this to activate Crossfade in iOS 17 although you won’t get the new Smart Crossfade features until iOS 18 is installed.


[ad_2]
Source link