Chinese hackers breach Indian, US internet firms via startup, says Lumen

Chinese hackers breach Indian, US internet firms via startup, says Lumen



The state-sponsored Chinese hacking campaign known as Volt Typhoon is exploiting a bug in a California-based startup to hack American and Indian internet companies, according to security researchers. 


Volt Typhoon has breached four US firms, including internet service providers, and another in India through a vulnerability in a Versa Networks server product, according to Lumen Technologies Inc.’s unit Black Lotus Labs. Their assessment, much of which was published in a blog post on Tuesday, found with “moderate confidence” that Volt Typhoon was behind the breaches of unpatched Versa systems and said exploitation was likely ongoing. 


Versa, which makes software that manages network configurations and has attracted investment from Blackrock Inc. and Sequoia Capital, announced the bug last week and offered a patch and other mitigations. 


The revelation will add to concerns over the susceptibility of US critical infrastructure to cyberattacks. The US this year accused Volt Typhoon of infiltrating networks that operate critical US services, including some of the country’s water facilities, power grid and communications sectors, in order to cause disruptions during a future crisis, such as an invasion of Taiwan. 


Lumen shared its findings with Versa in late June, according to Lumen and supporting documentation shared with Bloomberg.


Versa, which is based in Santa Clara, California, said it issued an emergency patch for the bug at the end of June, but only began flagging the issue widely to customers in July once it was notified by one that claimed to have been breached. Versa said that customer, which it didn’t identify, didn’t follow previously published guidelines on how to protect its systems via firewall rules and other measures.

Dan Maier, Versa’s chief marketing officer, said in an email Monday that those 2015 guidelines include advising customers to close off internet access to a specific port, which the customer had failed to follow. Since last year, he said, Versa has now taken measures of its own to make the system “secure by default,” meaning customers will no longer be exposed to that risk even if they haven’t followed company guidelines.


The bug carries a “high” severity rating, according to the National Vulnerability Database. On Friday, the Cybersecurity and Infrastructure Security Agency, known as CISA, ordered federal agencies to patch Versa products or stop using them by Sept. 13.


The vulnerability has been exploited in at least one known instance by a sophisticated hacking group, Versa said in a blog post on Monday. The company didn’t identify the group, and on Friday, Versa told Bloomberg it didn’t know the identity.


Microsoft Corp. named and unveiled the Volt Typhoon campaign in May 2023. Since its discovery, US officials have urged companies and utilities to improve their logging to help search for and eradicate the hackers, who use vulnerabilities to get into systems and then can remain undetected for long stretches of time. 


The Chinese government has dismissed US accusations, saying the hacking attacks attributed to Volt Typhoon are the work of cyber criminals. 


CISA Director Jen Easterly told Congress in January about the malicious cyber activity, warning the US has discovered only the tip of the iceberg when it comes to victims and that China’s aim is to be able to plunge the US into “societal panic.”


US agencies, including CISA, the National Security Agency and the FBI, said in February that Volt Typhoon activity dates back at least five years and has targeted communications, energy, transportation systems, water and wastewater systems. 


Lumen first identified the malicious code in June, according to Lumen researcher Michael Horka. A malware sample uploaded from Singapore on June 7 bore the hallmarks of Volt Typhoon, he said in an interview. 


Horka, a former FBI cyber investigator who joined Lumen in 2023 after working on Volt Typhoon cases for the federal government, said the code was a web shell that allowed hackers to gain access to a customer’s network via legitimate credentials and then behave as if they were bona fide users.

First Published: Aug 27 2024 | 11:21 PM IST



Source link

Hindenburg takes aim at AI server maker Super Micro with short position

Hindenburg takes aim at AI server maker Super Micro with short position



Hindenburg Research on Tuesday disclosed a short position in Super Micro Computer and alleged “accounting manipulation” at the AI server maker, the latest by the short seller whose reports have rocked several high-profile companies.


The report pits the short seller, which has tussled with billionaire-investor Carl Icahn and India’s Gautam Adani, against the server marker that has been one of the biggest winners of the generative artificial intelligence boom.


Shares of Super Micro were down 3.5% in morning trade. The stock has nearly doubled in 2024, after more than tripling last year.


Hindenburg said it found evidence of undisclosed related party transactions, failure to abide by export controls, among other issues, citing an investigation that included interviews with former senior employees and litigation records.


“It (Super Micro) benefited as an early mover but still faces significant accounting, governance and compliance issues and offers an inferior product and service now being eroded away by more credible competition,” Hindenburg said in its report.


Super Micro did not immediately respond to a request for comment. Reuters could not independently verify the claims in the Hindenburg report.


Close ties with chip giant Nvidia have allowed Super Micro, known for its liquid cooling technology for high-power semiconductors, to capitalise on the surge in demand for AI servers.


Though revenue has surged, margins have taken a hit recently due to the rising costs of server production and pricing pressure from rivals including Dell.


Analysts have flagged the company’s hefty spending on supporting new generation of AI chips, including those sold by Nvidia.

The company’s shares have also come under pressure in recent months on rising worries that Big Tech could scale back AI spending due to slow payoffs from the billions of dollars they are investing in the technology.

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

First Published: Aug 27 2024 | 8:55 PM IST



Source link

Tech wrap Aug 27: Apple event on Sep 9, YouTube Premium, Xiaomi TVs, more

Tech wrap Aug 27: Apple event on Sep 9, YouTube Premium, Xiaomi TVs, more



Apple has announced that it will hold an event, named “It’s Glowtime,” on September 9. Invitations have been sent out for the in-person event at Apple Park in California, USA. The event is scheduled to start at 10 AM PT (10:30 PM IST) and will be streamed live on Apple’s website for viewers around the world.


Taiwanese electronics brand ASUS has unveiled a new range of laptops in India, covering both gaming and consumer categories. Under its Republic of Gamers (ROG) line, it introduced the ROG Zephyrus G16 and ROG TUF Gaming A14. For the consumer segment, ASUS launched the Vivobook S 14 OLED, Zenbook S 16 OLED, and ProArt PX13. These latest models are equipped with AMD’s Ryzen AI 300 series processors, which feature a neural processing unit (NPU) capable of performing 50 trillion operations per second (TOPS) to handle artificial intelligence tasks.


Xiaomi has introduced the X Pro QLED TV series and the X Series 2024 Edition TVs in India. The X Pro QLED Series TVs, available in sizes up to 65 inches, come with a 4K QLED display that Xiaomi asserts delivers an authentic viewing experience. The 2024 Edition of the X Series TVs also features notable enhancements.


WhatsApp is exploring an option an Android app that will let the users mark all chats as read at once. Available on iOS for some time, the instant messaging platform has begun testing it now on the Android app. The latest beta version for Android, 2.24.18.11, available on the Google Play Store, includes this new feature, discovered WhatsApp update tracker WABetainfo.


Vivo has introduced the T3 Pro 5G smartphone in India. As the newest model in the T-series, the Vivo T3 Pro is equipped with the Qualcomm Snapdragon 7 Gen 3 processor and boasts a 5,500mAh battery. Vivo has described the device as the “brightest, slimmest, and fastest curved phone” in its category. Furthermore, the phone’s display is safeguarded by Schott Xensation Glass and features Wet Touch Technology, which enables touch functionality even when hands are wet.


Airtel has revealed a partnership with Apple to provide exclusive Apple TV+ and Apple Music benefits to its customers in India. Beginning later this year, Airtel Xstream users will receive access to Apple TV+ content through Airtel’s premium Wi-Fi and postpaid plans.


Google has reportedly announced that the stable version of Android 15 will be available for eligible smartphones in October. According to 9To5Google, Google has issued a system update enabling Android 15 beta testers to revert to Android 14 if they decide to leave the Android Beta Program. The update’s description notes, “If you are anticipating the Android 15 stable update, please disregard this OTA until Android 15 is released in October.”


YouTube has updated the pricing for its premium plans in India, with increases applied to all tiers, including Individual, Family, and Student subscriptions. The new rates are now in effect, and new subscribers will need to pay according to the updated pricing for their selected plan.


Snapchat has started rolling out an update for Apple devices that brings native support to iPads. This new update ensures that the multimedia messaging app is now fully optimized for iPads. Although Snapchat has been available on iOS devices since 2011, it initially only offered a version designed for iPhones, which resulted in thick black borders on iPads due to its vertical layout. With this update, Snapchat now fully supports iPads, launching in full-screen mode without any black borders.


After its launch in the US, Amazon is now bringing its AI-driven shopping assistant, Rufus, to its mobile app in India. The company revealed that Rufus, which has been trained using Amazon’s product catalog and a wide range of web data, will help users with shopping inquiries, recommendations, and product comparisons.


Longtime Apple Inc. Chief Financial Officer Luca Maestri will resign from his position at the end of the year, with the role being passed to his top deputy, Kevan Parekh, after more than a decade in the role.

First Published: Aug 27 2024 | 8:03 PM IST



Source link

Telegram under scanner for extortion, gambling; messaging app may face ban

Telegram under scanner for extortion, gambling; messaging app may face ban


| Image: Wikimedia Commons


Days after Telegram founder and CEO Pavel Durov was arrested in Paris over his app’s moderation policies, the Indian government has launched an investigation into extortion and gambling allegations against the company.


The future of Telegram, which has over five million registered users in India, will depend on the findings of the investigation, according to a MoneyControl report. The messaging app may face a ban if the investigation identifies grounds for such action.


The investigation is being conducted by the Indian Cybercrime Coordination Centre (I4C) under the Ministry of Home Affairs (MHA) and the Ministry of Electronics and Information Technology (MeitY). The ministries are examining the app’s peer-to-peer (P2P) communications.


So far, Telegram has not issued a statement regarding the investigation in India. Notably, Telegram complies with India’s Information Technology (IT) Rules, which require platforms to appoint a nodal officer and a chief compliance officer, as well as publish monthly compliance reports.


Tryst with controversies

 


The popular messaging app Telegram was launched in 2013 by brothers Pavel and Nikolai Durov. The app has grown significantly, boasting over 950 million users worldwide as of 2024.


In recent months, several exams, including UGC-NET, MPPSC, UP Police Constable Recruitment, and NEET-UG, have been tainted by paper leak scandals, with Telegram frequently being at the centre of these controversies. The app has also been implicated as a major source of leaked and false information during the Class 10 and 12 board exams.


Telegram’s security features allow users to maintain anonymity, keeping their identities – such as name, number, and photo – confidential based on their settings. This makes it easier for individuals to commit crimes, such as leaking exam papers, without being caught.


Pavel Durov’s arrest

 


French authorities arrested Pavel Durov, co-founder and CEO of the secure messaging app Telegram, at Le Bourget airport near Paris on Saturday (August 24).


Durov – who holds French citizenship in addition to Emirati, Saint Kitts and Nevis, and Russian (the country of his birth) citizenship – was arrested as he disembarked from his private jet after returning from Baku, the capital of Azerbaijan.


French investigators had issued a warrant for Durov’s arrest as part of an inquiry into allegations of fraud, drug trafficking, organised crime, the promotion of terrorism, and cyberbullying.


Following the arrest, Telegram issued a statement saying, “Telegram CEO Pavel Durov has nothing to hide and travels frequently within Europe. Almost a billion users globally use Telegram as a means of communication and a source of vital information. We are awaiting a prompt resolution to this situation.”

First Published: Aug 27 2024 | 5:48 PM IST



Source link

Xiaomi launches X Pro QLED TVs, Redmi Watch 5 Active, more: Check details

Xiaomi launches X Pro QLED TVs, Redmi Watch 5 Active, more: Check details



China’s Xiaomi has launched the X Pro QLED TV series alongside the X Series 2024 Edition TVs in India. The Xiaomi X Pro QLED Series TVs, available in up to 65 inches, feature a 4K QLED display that Xiaomi claims provides a true-to-life viewing experience. The 2024 Edition of the X Series TVs also includes significant upgrades. Here are the details:


Xiaomi X Pro QLED: Price, availability, and offers


  • 43-inch: Rs 34,999

  • 55-inch: Rs 49,999

  • 65-inch: Rs 69,999


The Xiaomi X Pro QLED TVs will be available for purchase from August 30 on Mi online store, e-commerce platforms Amazon and Flipkart, and at select retail outlets.


Introductory Offers: An instant discount of Rs 5,000 is available on the 43-inch and 55-inch models, while the 65-inch model is offered with an instant discount of Rs 7,000. Additionally, customers can avail a bank discount of Rs 7,000 on credit cards and equated monthly transaction from ICICI bank.


Xiaomi Smart TV X Series (2024 Edition): Price, availability, and offers


  • 43-inch: Rs 28,999

  • 50-inch: Rs 35,999

  • 55-inch: Rs 39,999


The Xiaomi X Series 2024 Edition TVs will be available from August 30 on Mi online store, e-commerce platforms Amazon and Flipkart, and at select retail outlets.


As for the introductory offers, an instant discount of Rs 4,000 is available on all models. Customers can also benefit from a bank discount of Rs 7,000 on select credit cards.


Xiaomi X Pro QLED: Details


The Xiaomi X Pro QLED TVs, available in 43-inch, 55-inch, and 65-inch sizes, feature a 4K QLED panel with what Xiaomi describes as a “billion colour display”. The TVs are powered by the Vivid Picture Engine 2 technology for vibrant visuals and support Dolby Vision HDR for enhanced content viewing. They come with 30W built-in speakers supporting Dolby Audio, DTS-HD, and DTS: Virtual X technology. Additionally, the TVs have 32GB of built-in storage.


Xiaomi Smart TV X Series (2024 Edition): Details


The 2024 Edition of the X Series TVs features a 4K HDR display that supports Dolby Vision and HDR10 technologies. They sport a metallic bezel-less design and include 30W built-in speakers with Dolby Audio support.


Ecosystem products


In addition to the new TVs, Xiaomi has launched the 10,000mAh Xiaomi Pocket Power Bank Pro and the 20,000mAh Xiaomi Power Bank 4i, priced at Rs 1,799 and Rs 2,199, respectively.


The company has also introduced the Redmi Watch 5 Active, which includes Bluetooth calling functionality with a three-microphone setup. Priced at Rs 2,799, the Redmi Watch 5 Active features a 2-inch display and is rated IPX8 for water resistance.

First Published: Aug 27 2024 | 4:15 PM IST



Source link

WhatsApp explores 'mark all chats as read' option on Android app: Details

WhatsApp explores 'mark all chats as read' option on Android app: Details



WhatsApp is testing a new feature on an Android app that will allow the users to mark all chats as read in one go. Although this feature has been available on iOS for some time, the instant messaging platform from Meta is now testing it on the Android app. WhatsApp update tracker WABetainfo has discovered that the latest beta version for Android, 2.24.18.11, available on the Google Play Store, includes this new feature.


Based on screenshots shared by WABetainfo, the option to mark all chats as read will appear in the overflow menu within the chats list, enabling users to clear all unread messages with a single action. This feature is expected to become widely available in the coming days.


This update may help users manage app clutter by allowing them to clear all unread messages at once, eliminating the need to open or select each chat individually.


Previously, WABetainfo reported that WhatsApp was developing a feature to clear unread message counts. This feature would provide users with the convenience of automatically resetting unread message notifications each time the app is opened in the future.


Additionally, WhatsApp has recently introduced an in-chat voice note transcription feature for Android. This new feature eliminates the need for third-party transcription apps, allowing users to transcribe voice notes in five languages: English, Hindi, Spanish, Portuguese, and Russian.


WhatsApp is also working on incorporating augmented reality (AR) capabilities for video calls. According to WABetainfo, AR features for call effects and filters have been detected in the iOS 24.17.10.74 update, which is available on TestFlight.

First Published: Aug 27 2024 | 3:32 PM IST



Source link

YouTube
Instagram
WhatsApp