Saturday, July 31, 2021

Galaxy Z Flip 3, Fold 3, Watch 4, more: what we expect from Samsung's August event

With the next Samsung Unpacked event of 2021 scheduled for August 11, we're just around the corner from learning all about the new tech Samsung is hiding up its sleeves.

We're expecting loads of new devices, with four gadgets likely according to leaks, rumors and also teases from Samsung itself. There are also a few new things some fans are hoping for, but that likely won't show up - we've listed them below as well.

One thing we're certain isn't showing up is the Samsung Galaxy Note 21, which the company has already confirmed has been canceled.

Visit TechRadar on August 11 for coverage of all the new gadgets that do show up, as well as analysis and commentary on this suite of devices.

Samsung Galaxy Z Fold 3

Samsung has confirmed there will be foldable phones at its August 11 event, and the Galaxy Z Fold 3 is one we're expecting to see. This is Samsung's third-generation book-style folding device, which might also act as a Galaxy Note replacement.

We're expecting a handset with three rear cameras, a 7.5-inch 120Hz main screen (for when the device is opened up), a smaller battery than the Galaxy Z Fold 2, and compatibility with Samsung's S Pen stylus - with one possibly coming bundled with the smartphone.

The odds on this phone coming are pretty high, since the Z Fold 2 debuted at Samsung's similarly timed event in 2020, and loads of leaks are pointing to the device being on the way.

Reserve your new handset at Samsung.com
If you're in the US and you want to be the first to get your hands on the new Galaxy phone, reservations are already open. It's not an obligation to buy it, but it gives you the option if you wanted to be first in line and offers trade-in credit and other extras too.

- Head to Samsung.com to reserve your phone

Samsung Galaxy Z Flip

Samsung Galaxy Z Flip (Image credit: Future)

Samsung Galaxy Z Flip 3

Another foldable phone that could come alongside, or instead of, the Z Fold 3 is the Samsung Galaxy Z Flip 3 - there wasn't actually a Z Flip 2, not unless you count the Z Flip 5G (and we don't). This is set to be a small-body 'clamshell' style foldable phone, similar to the original Galaxy Z Flip.

According to leaks, the Galaxy Z Flip 3 could have a 6.7-inch screen when unfolded, with a smaller information panel on the front of the device when it's folded up, a bigger battery than the original Flip, and perhaps up to three rear cameras, though this sounds unlikely.

There have been a good few Galaxy Z Flip 3 leaks, but we're still struggling to get a clear picture of the folding device, so our eyes will be peeled during the event to get a better picture as to how it could look and function.

Samsung Galaxy Watch 4

Samsung's smartwatch game may be a little confusing - we were expecting the Galaxy Watch 4 and Watch Active 4, but leaks suggest there will actually be the Watch 4 and Watch 4 Classic, with the 'Classic' replacing the standard watch and the 'Active' name being dropped from the sporty version.

In any case, we're expecting two different smartwatches, both running Google's brand-new Wear OS 3 software. Leaks suggest different sizes for both, ranging between 40mm and 46mm, with perhaps three side buttons and a brand-new Exynos chipset.

It's hard to know for sure though, both with the naming confusion, and the myriad contradictory leaks we've seen. More so than the other devices on this list, we'd recommend watching the Samsung stream with an open mind and no expectations.

Samsung Galaxy buds

Samsung Galaxy buds (Image credit: TechRadar)

Samsung Galaxy Buds 2

We're expecting the newest version of Samsung's true wireless earbuds at the event, apparently called the Galaxy Buds 2 (though they're actually the third new hearables since the original Galaxy Buds, with the Buds Pro and Buds Live coming out more recently).

According to rumors, the Buds 2 could have a similar design to the original Galaxy Buds, but with more color options; they're said to tout improved sound quality from their predecessor but perhaps the same noise cancelation tech.

Leaks suggest the Buds 2 will launch at the August event, though Samsung hasn't teased them as it has its foldable phones. However the Buds Live launched at Unpacked in mid-2020 so the timing lines up.

Not expected: Galaxy S21 FE

Like the Note 21, it seems the Samsung Galaxy S21 FE has possibly been canceled, and even if not it's very likely to be delayed. We say this because, though there are quite a few leaks about the phone, recent leaks suggest it won't appear in August.

The S21 FE will apparently have similar specs to the Galaxy S21, including the Snapdragon 888 chipset, three rear cameras and a similar amount of RAM. We're also expecting a 6.4-inch screen, a 4,500mAh battery and 45W wired charging.

While the Galaxy S21 FE might not show up at Unpacked, it might come in the following months, with an October launch date rumored. It probably won't get a dedicated launch event though, as the Samsung Galaxy S20 FE didn't.

Not expected: Galaxy Tab S8

While the Samsung Galaxy Tab S7 was launched at the late 2020 Samsung Unpacked event, the Galaxy Tab S8 is said to be delayed, something the relatively-recent launch of the Tab S7 FE backs up.

We're expecting a Galaxy Tab S8 Plus and Ultra as well as the standard device, with screens of 11, 12.4 and 14.6 inches, which would make the Ultra pretty huge. The super-spec Ultra has been leaked most and is said to have a 12,000mAh battery, Snapdragon 888 chipset, multiple rear cameras and a 120Hz screen refresh rate.

Most recent leaks suggest the Tab S8 line will launch alongside the Galaxy S22 range in early 2022, and with all the tech already slated to appear at Unpacked on August 11, we seriously wouldn't expect three tablets to be in attendance too.



from TechRadar - All the latest technology news https://ift.tt/3rI2RQJ

Five common misperceptions about business cyberattacks

Most decision makers in IT management are having to spin so many plates, all at the same time, that there’s always a danger one of them will eventually fall to the floor and smash.

About the author

Peter Mackenzie, incident response manager, Sophos.

The problem is, just because you’ve attended to a cyber security issue, or decided that it’s not relevant for your business, that doesn’t mean you can forget all about it. With the increasing sophistication and determination of attackers, and the type of threats evolving all the time, you can’t afford to drop your guard with any aspect of security, even for a moment.

While maintaining IT security is an increasingly challenging task, a good place to start is to avoid a number of common misperceptions, all of which were encountered within a wide range of organizations when investigating and neutralizing attacks over the past year.

Misperception 1: We are too small to be a target and don’t really have anything worth stealing

It's easy to think attackers might be targeting bigger fish than your organization. Or that you’re in a low-interest sector and simply don’t have any assets likely to attract the attention of a passing cybercriminal. But our experience tells us otherwise. If you have processing power and a digital presence, you are a potential target.

It’s worth remembering that even though hackers from North Korea and Russia make the headlines, most attacks are not carried out by nation states but opportunists looking for easy prey. So, whatever size your business, if you have any weaknesses in your defenses, such as security gaps, errors or misconfigurations, then you could easily be next.

Misperception 2: We don’t need advanced security technologies installed everywhere

Some IT teams still believe that endpoint security software is enough to thwart all threats, and that they subsequently don’t need security for their servers. Big mistake. Unlike in the past, any errors in configuration, patching or protection make servers a primary target.

The list of attack techniques designed to bypass or disable endpoint software include those operated by humans which exploit social engineering, malicious code injected directly into memory, ‘fileless’ malware attacks such as reflective DLL (Dynamic Link Library), and attacks using legitimate remote access agents like Cobalt Strike, alongside everyday IT admin tools. Unfortunately, basic anti-virus technologies will struggle to detect and block such threats.

Even the assumption that protected endpoints can prevent intruders from making their way to unprotected servers is misguided. Recent experience tells us servers are now a prime target and attackers can easily find their way in using stolen access credentials.

Most contemporary cyber criminals have a strong understanding of Linux machines. In fact, attackers can hack into and install back doors in Linux machines to hide and maintain access to your network. If your organization only relies on basic security, intruders won’t find it too difficult to bypass your defenses in this way.

Misperception 3: We already have robust security policies in place

Yes, having security policies for applications and users is critical. But once you’ve got them in place, that’s not the end of the matter. These policies need to be checked and updated constantly as new features and functionality are added to devices connected to the network, and the strategies of cyber attackers become increasingly more sophisticated.

Your organization needs to test its cyber security policies regularly, using techniques such as penetration testing, tabletop exercises and trial runs of your disaster recovery plans to ensure your defenses are as robust as you would like to believe.

Misperception 4: Our employees understand security

According to Sophos’ State of Ransomware 2021, 22 per cent of organizations believe they’ll be hit by ransomware in the next 12 months as it’s hard to stop their end users from compromising security. Training helps but messages learned can soon be forgotten.

Besides, social engineering tactics like phishing emails are becoming increasingly hard to spot. Messages are often hand-crafted, accurately written, persuasive, and carefully targeted.

Cyber criminals are constantly finding new ways to catch end users unaware. As they step up their efforts, you need to increase yours too. Educate your employees on ways to spot suspicious messages and what to do when they receive one. Make sure they have the contact details of the right person in your team to notify, and that they do it immediately so other employees can be alerted.

Misperception 5: Incident response teams can recover my data after a ransomware attack

Unfortunately, your confidence in the response team’s powers of recovery is misguided. Attackers today are more ‘professional’ than ever. They make fewer mistakes and the encryption process has improved, so you can no longer rely on your responders to find a way to undo the damage.

Automatic backups like Windows Volume Shadow Copies are also deleted by most modern ransomware. As well as overwriting the original data stored on disk, this makes recovery impossible if you aren’t prepared to pay the ransom. And, even then, only 8 per cent of organizations that pay the ransom successfully retrieve all their data.

As you will have gathered by now, IT decision makers and complacency do not go well together. Too many organizations who believed it could never happen to them are now counting the cost after it has happened.

Instead of sitting back and assuming everything’s going to be OK, you need to take full control of your business affairs before somebody else does.



from TechRadar - All the latest technology news https://ift.tt/3j6eVYb

Friday, July 30, 2021

Samsung Cloud deadline: Migrate your files now

The deadline for many Samsung customers to migrate their files away from the company's own-brand cloud storage service is fast approaching.

Previously, Samsung Cloud allowed users to store a range of data off-device, freeing up local storage for apps. But the company is now cutting back the service, withdrawing the ability to store anything but lightweight items, such as contacts, calendar items and notes.

The phased termination process has been divided into two streams, based on users' geographical location. Members of Group 1, which covers the UK, US, Australia and much of Europe, have until the end of the day to make use of an automated OneDrive migration tool that will do much of the heavy lifting.

Samsung Cloud shutdown

Originally, Samsung had set a deadline of March 31 for members of Group 1 to shift their data away from Samsung Cloud, but decided to offer users an extra three months to make the necessary arrangements. However, there is no indication the company will offer another extension.

Members of Group 1 should already have received a notification prompting them to activate the automated OneDrive migration process. Doing so will not only transfer all Samsung Cloud files into OneDrive, but also expand the capacity of their account from 5GB to 20GB.

However, the expanded OneDrive storage offer will expire after one year. After that, users will either have to pay to increase their cloud storage capacity or transfer their data to an external hard drive, portable SSD or another cloud backup service.

If tonight's deadline is missed, Group 1 will have until September 30 to download their Samsung Cloud data to their device or computer manually and will not be able to claim additional OneDrive capacity. After this date has passed, all photos and files held in Samsung Cloud will be deleted outright and will no longer be recoverable.

Samsung customers that fall into Group 2, which covers much of Asia, Africa and the Middle East, have been given a little more time to play with. These users have until September 30 to shift their date to OneDrive and until November 29 to perform a manual download.



from TechRadar - All the latest technology news https://ift.tt/2V7NMvR

Motorola Edge 20

The long-rumored Motorola Edge 20 and its siblings are Motorola’s newest flagships, with improved specs and cameras over its predecessors. Most surprising of all, they're already available to buy in some parts of the world after Motorola quietly launched them with little fanfare.

The standard Motorola Edge 20 launches with two other models: the premium Motorola Edge 20 Pro and the more affordable Motorola Edge 20 Lite. The Motorola Edge 20 range follows up on 2020’s Motorola Edge, Motorola Edge Plus, and (more or less) the Motorola One 5G, respectively.

All three phones have similar flagship appearances as their predecessors, with some notable changes – gone are the curved-edge displays, for instance, which gave the Edge phones their name. But all pack improved cameras and faster specs, with a large 6.7-inch Full HD OLED display and big batteries.

While we haven’t gotten our hands on the new phones yet, the specs list, availability, and prices have been announced – read on for what you can expect from Motorola’s next flagships. 

Cut to the chase

  • What is it? The next generation of Motorola Edge phones
  • When will it be out? August 2021 in some regions
  • How much will it cost? Multiple devices at various prices

Motorola Edge 20 price and availability

The Motorola Edge 20 release date varies between countries: the phone and its siblings were announced in July 2021 with planned availability sometime in August in select markets in Europe, Latin America, Middle East and Asia. Some or all of the phones will also be released in North America this fall (Q3 2021). 

The Motorola Edge 20 Lite is the most affordable model, and starts at €349 (around $415 / £299 / AU$565), with price increasing for higher-spec configurations. The Motorola Edge 20 comes in a single configuration and costs €499 / £429 (around $590 / AU$805). The Motorola Edge 20 Pro is the premium device in the range, and starts at €699 / £649 (around $829 / AU$1,129), with price increasing for higher-spec configurations.

Motorola Edge 20

The Motorola Edge 20 on a yellow background showing the front and rear of the phone

(Image credit: Motorola)

The standard Motorola Edge 20 follows the Motorola Edge with a mid-range Snapdragon 778G processor, which isn't as powerful as the best phones on the market though it fits the price. It only comes in a single configuration, with 8GB of RAM and 256GB of storage, and comes in gray, white or green colors.

The OLED 6.7-inch display has a 144Hz refresh rate, and notably it doesn't curve at the edges, unlike its predecessor. But all three models have the same screen, more or less.

The Motorola Edge 20, along with the rest of the range, inherits the 108MP main camera from last year’s Motorola Edge Plus, which is a boon for the non-premium models. The Edge 20 shares its  ultra-wide camera with its Pro sibling, but the third snapper is a telephoto for 3x optical and 30x digital zoom, not the periscope of the Pro. 

We're dubious about the 4,000mAh battery, as that sounds a little on the small side, but the 30W charging is about standard for a device at this price.

Motorola Edge 20 Lite

The Motorola Edge 20 Lite on a yellow background in two different shades

(Image credit: Motorola)

This Motorola Edge 20 Lite phone has a price that positions it more like a Moto G phone than an Edge one, which could make it a serious value phone. 

The Edge 20 Lite uses an unspecified MediaTek chipset with 8GB of RAM and it's 5G-enabled – another bonus for affordable phones. The battery is 5,000mAh, which is nice and big, and the 30W charging from its siblings is here too.

The Edge 20 Lite has the same 6.7-inch OLED screen as its siblings, and it also has the same 108MP camera main, which is pretty surprising at this price. There's also an ultra-wide camera but it's not clear if there are other lenses.

Motorola Edge 20 Pro

The Motorola Edge 20 Pro in its blue shade showing the front and back of the phone

(Image credit: Motorola)

The Motorola Edge 20 Pro is the premium phone of the line and has the best specs of its range, though not quite the top of the line – but they fit its affordable flagship price. The Pro packs the Snapdragon 870 chipset - notably not the top Snapdragon 888, though it's not that much weaker - as well as 12GB of RAM and 256GB of storage.

The Edge 20 Pro has a 6.7-inch OLED screen that supports HDR10+ and has a 144Hz refresh rate, which is rare for non-gaming phones (most max out at 120Hz). 

The Edge 20 Pro has a 108MP main camera as well as an ultra-wide and periscope camera, the latter of which has a 5x optical and up to 50x digital zoom. The handset also records 8K video.

The phone charges up to 30W, though we don't know the actual battery capacity - Motorola says it'll last 30 hours between charges but that doesn't tell us much.

The Edge 20 Pro comes in blue or white hues, though there's also third option that's a blue color coated in faux leather.



from TechRadar - All the latest technology news https://ift.tt/2UZ5NfZ

Patch this WordPress plugin bug, thousands of site owners warned

The Wordfence Threat Intelligence team has discovered two separate vulnerabilities in a popular WordPress plugin used to change how download pages are displayed.

The plugin in question is called WordPress Download Manager and it has been installed on over 100,000 sites according to WordPress.org.

The first vulnerability can be exploited to achieve authenticated directory traversal according to Wordfence. While WordPress Download Manager had some protections in place to protect against directory traversal, they were far from sufficient. As a result, it was possible for a user such as a contributor with lower privileges to retrieve the contents of a site's wp-config.php file by adding a new download and performing a directory traversal attack.

From here, upon previewing the download, the contents of the wp-config.php file would be visible in the page's source code. However, since the contents of the file were echoed out onto the page source, a user with author-level permissions could also upload a file with an image extension containing malicious JavaScript and set the contents of file[page_template] to the path of the uploaded file which could result in Stored Cross-Site Scripting.

Double extension attack

Before Wordfence discovered these two vulnerabilities, the team behind the WordPress Download Manager patched a vulnerability that allowed users to upload files with php4 extensions as well as other potentially executable files.

Although this patch protected many configurations, it only checked the very last file extension which made it possible for an attacker to carry out a “double extension” attack by uploading a file with multiple extensions like info.php.png.

The Wordfence Threat Intelligence Team responsibly disclosed its findings to the WordPress Download Manager team at the beginning of May and the plugin's developer released a patched version of the plugin the following day.

Still if you're a WordPress site owner that uses the plugin, it is highly recommended that you update to the latest version immediately to avoid falling victim to any attacks exploiting these two now patched vulnerabilities.



from TechRadar - All the latest technology news https://ift.tt/3BZwwcR

Should I buy Raycon earbuds? A look at the YouTube famous true wireless earbuds brand

You’ve probably heard of Raycon earbuds from YouTube, as many of the streaming site’s biggest names have at one time or another endorsed them for their great sound and even better prices. 

While that’s obviously paid sponsorship on behalf of Raycon, you can’t help but wonder what they’re really like and, more importantly, if they’re worth buying over other tried and true wireless earbuds from Sony, Samsung, LG, Amazon and Apple. 

To put them to the test, we reached out to Raycon to get a pair – their high-end active noise canceling The Work Earbuds. At $149.99 (around £100, AU$200), these cost as much as a pair of Apple AirPods or Sony WF-SP800N but come with a few extra features that might, on paper, make them feel like the better deal.

Let’s dive into the drawbacks and advantages of the earbuds – of which there are many – and then we’ll get into their pricing and specs, and close out with an overview of the company and how it got so popular. 

Should I buy a pair of Raycon earbuds? 

The reason you were likely drawn to the earbuds in the first place was because they seem like a great cheap alternative to the Apple AirPods or Google Pixel Buds – and if you’re only referring to the Everyday or Performance earbuds, you’d absolutely be right.

At just $79.99 (around £60, AU$100), the Raycon Everyday has great specs and an 8-hour battery life on-board. It also includes a wireless charging case that provides another 24 hours of use. They’re IPX6 water and splash-resistant, which makes them good for workouts, and users are typically wowed by their sound quality – which is pretty impressive for the price.

Moving a step up to the Raycon Performance earbuds, you get a slightly better fit thanks to the built-in wing that hooks into your outer ear and a better overall battery life with the case. They’re a bit more expensive than the Raycon Everyday earbuds at $110 (around £80, AU$150) but they seem like a better option if you’ve had problems with earbuds falling out during a workout.

Raycon earbuds

Pictured: A woman wearing Raycon earbuds on a blue background. (Image credit: Raycon)

Last up is the highest-end Raycon The Work earbuds. They are certainly the most expensive of Raycon’s earbud lineup, and therefore they really have to offer the most for their sticker price. To help justify the cost, these are the only earbuds to feature active noise cancellation and stems to really give you that AirPods-style look. They come with memory foam eartips – a nice bonus – and use six microphones to offer good call quality (hence the reference to work in their name). 

The problem with the earbuds is that users sometimes report issues with connectivity – an issue we also had with our pair – and getting the fit just right. Having tested hundreds of earbuds over the years, Raycon’s The Work are some of the most finicky, even when you use the included foam tips that should conform nicely to your ear canal. Audio performance is good, however it requires a great fit to get that beefy bass response, something that’s tough to achieve when the buds don’t fit correctly. 

We’d recommend starting with the Performance earbuds and only stepping up to The Work if you absolutely need the active noise cancellation for your commute. Otherwise a good passive seal with the Performance buds will get you just as good of sound quality and we think you'll like them more than the Google Pixel Buds.

Raycon earbuds

Raycon The Everyday Headphones (center) next to Raycon The Everyday Earbuds (left) and Raycon The Performance Earbuds (right). (Image credit: Raycon)

How are the Raycon Everyday Headphones? 

We didn’t lump them in with the earbuds because, well, they’re headphones, but we also got our hands on The Everyday Headphones to test out as well. 

What the headphones promise is active noise cancellation in a pair of over-ear headphones with the same sound signature as the earbuds. Raycon says they’ll last about 22 hours with ANC turned off but less when you’ve got it turned on. They’re also relatively cheap for over-ear noise-canceling headphones at only $99 (around £70, AU$135). 

So what’s not to like? Mostly they deliver on good sound, with surprisingly good stereo separation, but the sound spectrum definitely caters more to bass than anything else. The noise cancellation itself isn’t all that powerful, especially when stacked against the leaders in the space like Bose or Sony, and it doesn’t support any of the better audio codecs – you’re stuck with SBC and AAC. 

At their price, they’re seated nicely in the middle of the pack, but we wouldn’t recommend them over any of the best noise-canceling headphones from our guide.

Raycon earbuds

Pictured: Ray J, American rapper turned entrepreneur and co-founder of Raycon.  (Image credit: Raycon)

What is Raycon? Is it a good company? 

Raycon is co-founded by Ray J, the American rapper turned reality TV star, alongside the other Ray, Ray Lee. The pair joined forces to create a wireless headphone company that aims to undercut the major players in the tech industry with more affordable options – though it currently only sells them in the US.

Raycon as an entity has been around since 2017, and rose in popularity thanks to its mix of celebrity endorsements and YouTube affiliates. That, coupled with its already low prices and even further discounts have really paved the way for its success amongst the bigger players. 

On its website, users give Raycon’s earbuds glowing reviews en masse and we found that largely to hold true with our testing, though many don’t mention the downsides of the earbuds. Overall, Raycon is trustable company that makes decent products – but, like every company, those products aren’t quite as perfect as they’re made out to be.



from TechRadar - All the latest technology news https://ift.tt/3icOUqE

Samsung Galaxy Z Fold 3-compatible S Pen Pro could launch with Bluetooth

Details have finally leaked about a new, more advanced Samsung stylus, the S Pen Pro, which could be compatible with the display on the Samsung Galaxy Z Fold 3, expected to launch at Samsung Unpacked on August 11. 

The S Pen Pro isn’t a secret – Samsung itself revealed the stylus, suggesting it would launch with the Samsung Galaxy S21 Ultra. While that premium phone didn’t launch with the S Pen Pro, we hadn’t heard anything about it until earlier in July when a rumor linked it with the Z Fold 3. 

But the new information, tweeted out by leaker Chun (@chunvn8888), includes some crucial info that’s big if true: unlike the ‘dumb’ analog S Pen that launched with the S21 Ultra, the S Pen Pro could pack Bluetooth functionality like that in the S Pens that come with the Samsung Galaxy Note 20 and Samsung Galaxy Tab S7 Plus. Presumably, that means gesture controls and remote functionality. 

See more

Per Chun’s tweet, the S Pen Pro will have the same 0.7mm tip and 4,096 pressure points as the S21 Ultra’s S Pen stylus, but it will also be usable on the Z Fold 3’s foldable display, manually charge via USB-C, and attach magnetically to the back of certain phone cases. Presumably, that won’t also mean wireless charging akin to the way the S Pen charges when clipped to the Tab S7 tablet, but we can hope. 

It’ll also be priced at “around 70 bucks in the UK,” which could mean either $70 (around £50) or £70 ( around $97). Either way, it’ll cost more than the standard S Pen’s $39.99 / £34 (roughly AU$50) price tag.

Samsung Galaxy Note 20 Ultra

(Image credit: Aakash Jhaveri)

Analysis: Could the S Pen Pro make up for the Note 21’s cancellation? 

While we’d heard that the Samsung Galaxy Z Fold 3 would launch with S Pen stylus support, suggesting Samsung was positioning the foldable as a replacement of sorts for the Samsung Galaxy Note 21, a company executive recently confirmed the Z Fold 3 had officially replaced the stylus-packing phone, at least for the 2021 lineup. 

That may not have comforted Note fans, who probably aren’t looking forward to paying potentially twice the launch price of a Note 20 Plus to get stylus functionality in a foldable Z Fold 3 – not for a device that likely won’t have an S Pen slot, and especially to have a ‘dumb’ stylus like the one that came with the S21 Ultra.

But an S Pen Pro could sweeten that deal somewhat. When Samsung introduced it earlier this year, the Pro stylus looked larger and easier to handle, with what could be multiple buttons on it. Combined with the leaked perks, like Bluetooth and magnetic attachment to phone cases, the S Pen Pro might make the Z Fold 3 a bit more palatable to the productivity-minded Note fans – and maybe getting to use the foldable’s extensive screen as an S Pen canvas might make it more enticing, too.  



from TechRadar - All the latest technology news https://ift.tt/3x96Wys

Discord once again found to be hosting malware payloads

Cybersecurity researchers have once again witnessed Discord being used to host malicious payloads during an investigation into the increasing use of HTML smuggling.

A previous report from Sophos researchers showed the popular gaming-centric messaging platform has unwittingly emerged as the cybercriminals' ally as a means to host and distribute malware.

Now, researchers at Menlo Security deconstructing a new attack have also found threat actors using Discord for hosting malicious payloads.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Named ISOMorph, the campaign uses HTML smuggling to drop the first stage malware through the web browser.

Attack the browser

The researchers explain that HTML smuggling helps deliver malware by effectively bypassing various network security solutions including sandboxes, legacy proxies, and firewalls

“We believe attackers are using HTML Smuggling to deliver the payload to the endpoint because the browser is one of the weakest links without network solutions blocking it,” notes Menlo Security in a blog post analyzing the ISOMorph campaign.

HTML Smuggling was also used in the most recent spear-phishing campaign by the Nobelium group, the threat actor which perpetrated the SolarWinds supply-chain attack.

Popular with web developers as a means to optimize file downloads, threat actors use HTML smuggling to bypass standard perimeter security, explains Menlo Security.

Once it’s in place, the dropper fetches the malicious payload and installs remote access trojans (RATs) that allow the attacker to use the infected machine for their illegitimate purposes.



from TechRadar - All the latest technology news https://ift.tt/3ig4hyw

Google's plan to make advertising less invasive hits another roadblock

Replacing third-party cookies in Chrome to prevent users from being tracked online is proving more difficult than initially thought for Google as the company continues work on its Privacy Sandbox.

As reported by The Register, the search giant's Privacy Sandbox is a set of technologies designed to deliver personalized ads while making it much more difficult to track users online. 

All of the web technology proposals included in Google's Privacy Sandbox have bird-themed names and although we've heard a lot about FLoC (Federated Learning of Cohorts) senior software engineer at Microsoft, John Mooring recently created a conceptual attack that could be used to target FLEDGE which stands for First Locally-Executed Decision over Groups Experiment.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

While FLoC tracks users across the web by putting them into groups as opposed to doing so individually, FLEDGE is a remarketing proposal that will be used to reach users on other sites after they've previously visited a company's website.

FLEDGE

In a recently opened issue in the GitHub repository for Turtledove which is now known as FLEDGE, Mooring described a conceptual attack that would allow an attacker to create code on webpages to use Google's technology proposal to track users across different sites.

This is particularly concerning as Google has designed FLEDGE to enable remarketing without tracking site visitors using personal identifiers. Google Mathematician Michael Kleber responded to Mooring's issue by acknowledging that his sample code could be abused to create an identifier in situations where there's no ad competition, saying: 

"This is indeed the natural fingerprinting concern associated with the one-bit leak, which FLEDGE will need to protect against in some way. We certainly need some approach to this problem before the removal of third-party cookies in Chrome." 

Before Google goes through with its plan to phase out support for third-party cookies in 2023, this one-bit leak issue will certainly need to be fixed to ensure the success of its Privacy Sandbox initiative.

Via The Register



from TechRadar - All the latest technology news https://ift.tt/3lsyzjZ

PS5 restock date: Best Buy PS5 stock remains elusive after big Target drop

Trust and credibility

PS5 restock Twitter tracker Matt Swider

(Image credit: Matt Swider / Instagram)

PS5 restock tracker Matt Swider has helped 61,100 people in the US buy a next-gen console in 2021 with his tireless 24/7 tracking, in-stock Twitter alerts and exclusive restock reporting.

The Best Buy PS5 restock date will be sent to you by our 24/7 PS5 restock tracker Matt Swider – if you follow Matt's Twitter account and turn on notifications – but it might not be today, July 30. Matt is closely monitoring a dozen stores in the US, including Best Buy, and he tweeted about the big Target PS5 restock this morning, when the Sony console was in stock for just 13 minutes nationwide. When will Best Buy PS5 restock? Well, the electronics store had both the $499 PS5 Disc and $399 PS5 Digital for sale Friday of last week, and the restock time was 11:38am EDT for both PS5 consoles. We're now well past that time and the latest time it's ever done a restock is 5:05pm EDT, with 3:30pm EDT being its most popular choice. That's why we have to do 24/7 tracking at all of the stores in the US, even if Best Buy stocks PlayStation 5 early next week. 

When? Where? Follow our PS5 restock Twitter tracker Matt Swider and turn on notifications for Best Buy PS5 restock alerts. It's the fastest way to get restock updates.

Warning: don't buy from other Twitter users. They're all scams. Only buy from the US stores Matt alerts you about. No one will sell a PS5 for just $550.

Why trust TechRadar? We don't point you to a bunch of US retailer links, which are always dead ends. Others do that – not us. Matt Swider will send you a push notification when there's actual PS5 stock through his 24/7 tracking efforts.

Directions: Click on this image of an example of a Best Buy PS5 restock alert from Matt Swider and turn on notifications (that little bell icon) for instant alerts.

PS5 restock Best Buy Twitter alert with advice and two PS5 consoles

(Image credit: Matt Swider / Twitter)

Best Buy PS5 restock date and time

  • Next Best Buy PS5 restock date: Restocks every nine days (recently) on average
  • Last Best Buy PS5 restock date: July 23, 2021 at 11:38am EDT  
  • How to buy PS5 from Target: Follow our PS5 restock tracker account

The Best Buy PS5 restock isn't guaranteed to be today, though some people are very adamant about the restock date simply because the US retailer had the PS5 Disc and PS5 Digital in stock on Friday of last week.

However, looking at the history of Best Buy restock dates, there's recently been a nine-day gap in between, so we could see PS5 in stock online next week. Yes, nine days would fall on a Sunday, but we rarely see a PS5 restock on weekends. 

While the Best Buy restock date is easier to predict, the actual time that add-to-cart button goes live is much, much harder to figure out. Best Buy had opened up PS5 sales anywhere from 9:05am to 6:05pm, so during daylight hours, we have to be ready with a Best Buy restock Twitter alert. 

PS5 restock at Target Twitter alert by Matt Swider

(Image credit: Matt Swider / Twitter)

Best Buy PS5 drop: it's the hardest to buy online

Truth be told, while over one hundred Matt Swider followers are usually able to buy the PS5 from Best Buy, it's not the easiest retailer to check out with in the US. Thousands are left frustrated by the Best Buy website and app.

While everyday customers have to wait through a mini virtual queue with Best Buy asking for you to hang on the page for 'one more step' (which it doesn't explain just means waiting until the greyed-out add-to-cart button loads back up in yellow), bots are able to open up multiple windows and determine which page will load that button up the quickest. We've seen hundreds of PS5 consoles secured by bots, leaving customers without a PlayStation 5 to claim within 250 miles of their location.

Best Buy does require people to pick up the PS5 in person at their local store – the actual video game system is held at a warehouse when orders are placed and then shipped to individual stores. It takes 3-5 days for the console to arrive at your local Best Buy. It goes without saying, the actual restock purchase remains online and you should travel to your Best Buy to try to buy the PS5. It hasn't been for sale in stores at Best Buy for all of 2021.

Best Buy PS5 tracker alerts – get it faster

The Best buy bot situation is why getting our PS5 Twitter tracker alerts have become an essential tool in securing the Sony console. While Sony sold 10 million PS5 consoles wordwide, millions more in the US alone are still looking to buy it.

There's an entire add-to-cart process when it comes to checking out: tap the yellow button, wait whole it's grayed out and turn yellow again, tap it again to truly add it to your cart and try to check out. Often this is where people get stuck, and it requires waiting until the Best Buy PS5 restock second wave happens – when it does, try to complete the purchase or chose a different store to pick it up from.

Because of these 'waves' where Best Buy constantly makes consoles available to purchase, often for over 30 minutes, persistence remains key. Speed on clicking on our restock Twitter alerts is also important, but only so far as to get more chances to add it to your cart and complete the convoluted checkout process.

PS5 restock

(Image credit: Twitter / Matt Swider)

Best Buy PS5 restock history: when has it been in stock?

Best Buy is all over the place with its PS5 restock history, according to an alaysis of the Twitter alerts by Matt Swider. His 24/7 tracking of US stores like Best Buy offers insight into when the Sony console could be available next.



from TechRadar - All the latest technology news https://ift.tt/3xd4lDB

Chipotle email marketing hacked to send phishing emails

Cybercriminals have begun sending out phishing emails after they were able to gain access to one of the email marketing accounts used by the US-based Mexican food chain Chipotle.

According to a new blog post from the email security company Inky, those behind the campaign sent out at least 120 malicious emails in just three days from a hacked Mailgun account that the food chain uses for email marketing.

Cybercriminals often try to obtain legitimate email addresses from businesses as they increase the chances of their phishing emails being delivered since they'll be able to bypass authentication methods including DomainKeys Identified Mail (DKIM) and Sender Policy Framework.

While the majority of the phishing emails sent from Chipotle's hacked Mailgun account led users to credential-harvesting sites, a small number also had attachments which contained malware.

Compromised Mailgun account

Many of the emails sent out from the hacked Mailgun account led users to a fake Microsoft login page with the aim of harvesting their credentials. According to Inky, 105 of the 120 malicious emails it detected tired to harvest users Microsoft account credentials.

The emails themselves appeared as if they came from the “Microsoft 365 Message center” and the body of these emails informed recipients that their messages could not be delivered as a result of low email storage in the cloud. When a user then clicked on a button labeled “release messages to inbox”, they would be redirected to a fake login page used to collect their credentials.

In addition to Chipotle, the cybercriminals behind this recent campaign also impersonated the United Services Automobile Association (USAA) and tricked users to visiting a phishing site that appeared to be legitimate at a first glance. The remaining fake emails posed as voicemail notifications that also contained malware attachments.

To prevent falling victim to this and similar phishing scams, Inky recommends that users pay close attention to any discrepancies between a sender's display name (Microsoft, USAA, VM Caller ID” and the message's actual email address.

Via BleepingComputer



from TechRadar - All the latest technology news https://ift.tt/3idx9Ye