Normal view

There are new articles available, click to refresh the page.
Yesterday — 17 May 2024Main stream

“Unprecedented” Google Cloud event wipes out customer account and its backups

17 May 2024 at 16:22
“Unprecedented” Google Cloud event wipes out customer account and its backups

Enlarge (credit: Bloomberg via Getty Images)

Buried under the news from Google I/O this week is one of Google Cloud's biggest blunders ever: Google's Amazon Web Services competitor accidentally deleted a giant customer account for no reason. UniSuper, an Australian pension fund that manages $135 billion worth of funds and has 647,000 members, had its entire account wiped out at Google Cloud, including all its backups that were stored on the service. UniSuper thankfully had some backups with a different provider and was able to recover its data, but according to UniSuper's incident log, downtime started May 2, and a full restoration of services didn't happen until May 15.

UniSuper's website is now full of must-read admin nightmare fuel about how this all happened. First is a wild page posted on May 8 titled "A joint statement from UniSuper CEO Peter Chun, and Google Cloud CEO, Thomas Kurian." This statement reads, "Google Cloud CEO, Thomas Kurian has confirmed that the disruption arose from an unprecedented sequence of events whereby an inadvertent misconfiguration during provisioning of UniSuper’s Private Cloud services ultimately resulted in the deletion of UniSuper’s Private Cloud subscription. This is an isolated, ‘one-of-a-kind occurrence’ that has never before occurred with any of Google Cloud’s clients globally. This should not have happened. Google Cloud has identified the events that led to this disruption and taken measures to ensure this does not happen again."

In the next section, titled "Why did the outage last so long?" the joint statement says, "UniSuper had duplication in two geographies as a protection against outages and loss. However, when the deletion of UniSuper’s Private Cloud subscription occurred, it caused deletion across both of these geographies." Every cloud service keeps full backups, which you would presume are meant for worst-case scenarios. Imagine some hacker takes over your server or the building your data is inside of collapses, or something like that. But no, the actual worst-case scenario is "Google deletes your account," which means all those backups are gone, too. Google Cloud is supposed to have safeguards that don't allow account deletion, but none of them worked apparently, and the only option was a restore from a separate cloud provider (shoutout to the hero at UniSuper who chose a multi-cloud solution).

Read 9 remaining paragraphs | Comments

Google fixes seventh actively exploited Chrome zero-day this year, the third in a week – Source: securityaffairs.com

google-fixes-seventh-actively-exploited-chrome-zero-day-this-year,-the-third-in-a-week-–-source:-securityaffairs.com

Source: securityaffairs.com – Author: Pierluigi Paganini Google fixes seventh actively exploited Chrome zero-day this year, the third in a week Google released security updates to address a new actively exploited Chrome zero-day vulnerability, the third in a week. Google has released a new emergency security update to address a new vulnerability, tracked as CVE-2024-4947, in […]

La entrada Google fixes seventh actively exploited Chrome zero-day this year, the third in a week – Source: securityaffairs.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Before yesterdayMain stream

Google Search adds a “web” filter, because it is no longer focused on web results

16 May 2024 at 15:18
Google continues to change what it means to be the "Google" search engine.

Enlarge / Google continues to change what it means to be the "Google" search engine. (credit: Aurich Lawson)

Google I/O has come and gone, and with it came an almost exclusive focus on AI. Part of the show was an announcement for Google Search that was so huge it was almost hard to believe: the AI-powered "Search Generative Experience (SGE)" that the company had been trialing for months is rolling out to everyone in the US. The feature, renamed "AI Overview," is here now, and it feels like the biggest change to Google Search ever. The top of many results (especially questions) are now dominated by an AI box that scrapes the web and gives you a sometimes-correct summary without needing to click on a single result.

AI Overview is a bit different from the SGE trials that were happening. First is that AI Overview is a lot faster than SGE. For some popular queries, it seems like Google is caching the AI answer, which should help with the high cost of running generative AI. For queries with cached overviews, you'll see the AI box load instantly, right along with the initial search results pop-in. SGE responses would come in word by word, like they are being typed by a person. When you aren't getting a cached result, you'll see a blank AI overview box that loads with the search page, which will say "searching" while it loads for a second or two. Other times, Google will try loading an AI Overview and fail, with the message "An AI overview is not available for this search." (As if anyone asked.)

When Google decides you have an AI-appropriate query, it now takes a lot of scrolling to see web results. Google scrolls infinitely, so there are no "pages" anymore, but let's consider a "page" to be a full browser viewport height: The first page is an AI overview that takes up half the screen and then another answer box extracted from some website. Page two is a "People also ask" box suggesting other queries, then one search result, then a box for videos. Page three is the bottom half of the video box, then a "Discussions and forums" section with Reddit and Quora posts. It's not until page four and miles of scrolling that we get the traditional 10 blue links. This list isn't even counting an ad block, which would appear first normally. I've yet to see an ad block and AI overview at the same time, but I'm sure that's coming. Despite pushing AI Overviews live into production for everyone on the most premium spot on the Google Search page, Google still notes that "Generative AI is experimental."

Read 4 remaining paragraphs | Comments

Revolutionary New Google Feature Hidden Under 'More' Tab Shows Links To Web Pages

By: msmash
16 May 2024 at 14:01
An anonymous reader shares a report: After launching a feature that adds more AI junk than ever to search results, Google is experimenting with a radical new feature that lets users see only the results they were looking for, in the form of normal text links. As in, what most people actually use Google for. "We've launched a new 'Web' filter that shows only text-based links, just like you might filter to show other types of results, such as images or videos," the official Google Search Liaison Twitter account, run by Danny Sullivan, posted on Tuesday. The option will appear at the top of search results, under the "More" option. "We've added this after hearing from some that there are times when they'd prefer to just see links to web pages in their search results, such as if they're looking for longer-form text documents, using a device with limited internet access, or those who just prefer text-based results shown separately from search features," Sullivan wrote. "If you're in that group, enjoy!" Searching Google has become a bloated, confusing experience for users in the last few years, as it's gradually started prioritizing advertisements and sponsored results, spammy affiliate content, and AI-generated web pages over authentic, human-created websites.

Read more of this story at Slashdot.

Google fixes third actively exploited Chrome zero-day in a week – Source: www.bleepingcomputer.com

google-fixes-third-actively-exploited-chrome-zero-day-in-a-week-–-source:-wwwbleepingcomputer.com

Source: www.bleepingcomputer.com – Author: Sergiu Gatlan ​Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. “Google is aware that an exploit for CVE-2024-4947 exists in the wild,” the search giant said in a security advisory published on Wednesday. The high-severity zero-day vulnerability (CVE-2024-4947) […]

La entrada Google fixes third actively exploited Chrome zero-day in a week – Source: www.bleepingcomputer.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Android to add new anti-theft and data protection features – Source: www.bleepingcomputer.com

android-to-add-new-anti-theft-and-data-protection-features-–-source:-wwwbleepingcomputer.com

Source: www.bleepingcomputer.com – Author: Sergiu Gatlan ​Google is introducing multiple anti-theft and data protection features later this year, some available only for Android 15+ devices, while others will roll out to billions of devices running Android 10 and later. To protect your personal and sensitive data if your device is stolen or lost, a new […]

La entrada Android to add new anti-theft and data protection features – Source: www.bleepingcomputer.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Android 15, Google Play Protect get new anti-malware and anti-fraud features – Source: www.bleepingcomputer.com

android-15,-google-play-protect-get-new-anti-malware-and-anti-fraud-features-–-source:-wwwbleepingcomputer.com

Source: www.bleepingcomputer.com – Author: Lawrence Abrams Today, Google announced new security features coming to Android 15 and Google Play Protect that will help block scams, fraud, and malware apps on users’ devices. Announced at Google I/O 2024, the new features are designed not only to help end users but also to warn developers when their apps have been tampered with. “Today, we’re announcing […]

La entrada Android 15, Google Play Protect get new anti-malware and anti-fraud features – Source: www.bleepingcomputer.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Google Patches Yet Another Actively Exploited Chrome Zero-Day Vulnerability – Source:thehackernews.com

google-patches-yet-another-actively-exploited-chrome-zero-day-vulnerability-–-source:thehackernews.com

Source: thehackernews.com – Author: . May 16, 2024NewsroomBrowser Security / Vulnerability Google has rolled out fixes to address a set of nine security issues in its Chrome browser, including a new zero-day that has been exploited in the wild. Assigned the CVE identifier CVE-2024-4947, the vulnerability relates to a type confusion bug in the V8 […]

La entrada Google Patches Yet Another Actively Exploited Chrome Zero-Day Vulnerability – Source:thehackernews.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Google Opens Up Its Smart Home To Everyone

By: BeauHD
15 May 2024 at 18:00
Google is opening up API access to its Google Home smart home platform, allowing app developers to access over 600 million connected devices and tap into the Google Home automation engine. In addition, Google announced that it'll be turning Google TVs into Google Home hubs and Matter controllers. The Verge reports: The Home APIs can access any Matter device or Works with Google Home device, and allows developers to build their own experiences using Google Home devices and automations into their apps on both iOS and Android. This is a significant move for Google in opening up its smart home platform, following shutting down its Works with Nest program back in 2019. [...] The Home APIs are already available to Google's early access partners, and Google is opening up a waitlist for any developer to sign up today. "We are opening up access on a rolling basis so they can begin building and testing within their apps," Anish Kattukaran, head of product at Google Home and Nest, told The Verge. "The first apps using the home APIs will be able to publish to the Play and App stores in the fall." The access is not just limited to smart home developers. In the blog post, Matt Van Der Staay, engineering director at Google Home, said the Home APIs could be used to connect smart home devices to fitness or delivery apps. "You can build a complex app to manage any aspect of a smart home, or simply integrate with a smart device to solve pain points -- like turning on the lights automatically before the food delivery driver arrives." The APIs allow access to most devices connected to Google Home and to the Google Home structure, letting apps control and manage devices such as Matter light bulbs or the Nest Learning Thermostat. They also leverage Google Home's automation signals, such as motion from sensors, an appliance's mode changing, or Google's Home and Away mode, which uses various signals to determine if a home is occupied. [...] What's also interesting here is that developers will be able to use the APIs to access and control any device that works with the new smart home standard Matter and even let people set up Matter devices directly in their app. This should make it easier for them to implement Matter into their apps, as it will add devices to the Google Home fabric, so they won't have to develop their own. In addition, Google announced that it's vastly expanding its Matter infrastructure by turning Google TVs into Google Home hubs and Matter controllers. Any app using the APIs would need a Google hub in a customer's home in order to control Matter devices locally. Later this year, Chromecast with Google TV, select panel TVs with Google TV running Android 14 or higher, and some LG TVs will be upgraded to become Google Home hubs. Additionally, Kattukaran said Google will upgrade all of its existing home hubs -- which include Nest Hub (second-gen), Nest Hub Max, and Google Wifi -- with a new ability called Home runtime. "With this update, all hubs for Google Home will be able to directly route commands from any app built with Home APIs (such as the Google Home app) to a customer's Matter device locally, when the phone is on the same Wi-Fi network as the hub," said Kattukaran. This means you should see "significant latency improvements using local control via a hub for Google Home," he added.

Read more of this story at Slashdot.

Google unveils Veo, a high-definition AI video generator that may rival Sora

15 May 2024 at 16:51
Still images taken from videos generated by Google Veo.

Enlarge / Still images taken from videos generated by Google Veo. (credit: Google / Benj Edwards)

On Tuesday at Google I/O 2024, Google announced Veo, a new AI video-synthesis model that can create HD videos from text, image, or video prompts, similar to OpenAI's Sora. It can generate 1080p videos lasting over a minute and edit videos from written instructions, but it has not yet been released for broad use.

Veo reportedly includes the ability to edit existing videos using text commands, maintain visual consistency across frames, and generate video sequences lasting up to and beyond 60 seconds from a single prompt or a series of prompts that form a narrative. The company says it can generate detailed scenes and apply cinematic effects such as time-lapses, aerial shots, and various visual styles

Since the launch of DALL-E 2 in April 2022, we've seen a parade of new image synthesis and video synthesis models that aim to allow anyone who can type a written description to create a detailed image or video. While neither technology has been fully refined, both AI image and video generators have been steadily growing more capable.

Read 9 remaining paragraphs | Comments

Google Expands Synthetic Content Watermarking Tool to AI-Generated Text – Source: www.infosecurity-magazine.com

google-expands-synthetic-content-watermarking-tool-to-ai-generated-text-–-source:-wwwinfosecurity-magazine.com

Source: www.infosecurity-magazine.com – Author: 1 Google has unveiled a new method to label text as AI-generated without altering it. This new feature, announced on May 14, has been integrated into Google DeepMind’s SynthID tool, which was already capable of identifying AI-generated images and audio clips. This method introduces additional information to the large language model […]

La entrada Google Expands Synthetic Content Watermarking Tool to AI-Generated Text – Source: www.infosecurity-magazine.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Android 15 gets “Private Space,” theft detection, and AV1 support

15 May 2024 at 13:00
The Android 15 logo. This is "Android V," if you can't tell from the logo.

Enlarge / The Android 15 logo. This is "Android V," if you can't tell from the logo. (credit: Google)

Google's I/O conference is still happening, and while the big keynote was yesterday, major Android beta releases have apparently been downgraded to Day 2 of the show. Google really seems to want to be primarily an AI company now. Android already had some AI news yesterday, but now that the code-red requirements have been met, we have actual OS news.

One of the big features in this release is "Private Space," which Google says is a place where users can "keep sensitive apps away from prying eyes, under an additional layer of authentication." First, there's a new hidden-by-default portion of the app drawer that can hold these sensitive apps, and revealing that part of the app drawer requires a second round of lock-screen authentication, which can be different from the main phone lock screen.

Just like "Work" apps, the apps in this section run on a separate profile. To the system, they are run by a separate "user" with separate data, which your non-private apps won't be able to see. Interestingly, Google says, "When private space is locked by the user, the profile is paused, i.e., the apps are no longer active," so apps in a locked Private Space won't be able to show notifications unless you go through the second lock screen.

Read 7 remaining paragraphs | Comments

Google now offers ‘web’ search — and an “AI” opt-out button

15 May 2024 at 08:24

This is not a joke: Google will now let you perform a “web” search. It’s rolling out “web” searches now, and in my early tests on desktop, it’s looking like it could be an incredibly popular change to Google’s search engine.

The optional setting filters out almost all the other blocks of content that Google crams into a search results page, leaving you with links and text — and Google confirms to The Verge that it will block the company’s new AI Overviews as well.

↫ Sean Hollister at The Verge

I hate what the web has become.

Dangerous Google Chrome Zero-Day Allows Sandbox Escape – Source: www.darkreading.com

dangerous-google-chrome-zero-day-allows-sandbox-escape-–-source:-wwwdarkreading.com

Source: www.darkreading.com – Author: Tara Seals, Managing Editor, News, Dark Reading Source: Kristoffer Tripplaar via Alamy Stock Photo Google has released an emergency security update for its Chrome browser, including a patch for a zero-day vulnerability that has exploit code released in the wild that could lead to data theft, lateral movement, malware implantation, and […]

La entrada Dangerous Google Chrome Zero-Day Allows Sandbox Escape – Source: www.darkreading.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Google Will Use Gemini To Detect Scams During Calls

By: BeauHD
15 May 2024 at 06:00
At Google I/O on Tuesday, Google previewed a feature that will alert users to potential scams during a phone call. TechCrunch reports: The feature, which will be built into a future version of Android, uses Gemini Nano, the smallest version of Google's generative AI offering, which can be run entirely on-device. The system effectively listens for "conversation patterns commonly associated with scams" in real time. Google gives the example of someone pretending to be a "bank representative." Common scammer tactics like password requests and gift cards will also trigger the system. These are all pretty well understood to be ways of extracting your money from you, but plenty of people in the world are still vulnerable to these sorts of scams. Once set off, it will pop up a notification that the user may be falling prey to unsavory characters. No specific release date has been set for the feature. Like many of these things, Google is previewing how much Gemini Nano will be able to do down the road sometime. We do know, however, that the feature will be opt-in.

Read more of this story at Slashdot.

Another Chrome Vulnerability – Source: www.schneier.com

another-chrome-vulnerability-–-source:-wwwschneier.com

Source: www.schneier.com – Author: Bruce Schneier Google has patched another Chrome zero-day: On Thursday, Google said an anonymous source notified it of the vulnerability. The vulnerability carries a severity rating of 8.8 out of 10. In response, Google said, it would be releasing versions 124.0.6367.201/.202 for macOS and Windows and 124.0.6367.201 for Linux in subsequent […]

La entrada Another Chrome Vulnerability – Source: www.schneier.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Downranking won’t stop Google’s deepfake porn problem, victims say

14 May 2024 at 18:00
Downranking won’t stop Google’s deepfake porn problem, victims say

Enlarge (credit: imaginima | E+)

After backlash over Google's search engine becoming the primary traffic source for deepfake porn websites, Google has started burying these links in search results, Bloomberg reported.

Over the past year, Google has been driving millions to controversial sites distributing AI-generated pornography depicting real people in fake sex videos that were created without their consent, Similarweb found. While anyone can be targeted—police already are bogged down with dealing with a flood of fake AI child sex images—female celebrities are the most common victims. And their fake non-consensual intimate imagery is more easily discoverable on Google by searching just about any famous name with the keyword "deepfake," Bloomberg noted.

Google refers to this content as "involuntary fake" or "synthetic pornography." The search engine provides a path for victims to report that content whenever it appears in search results. And when processing these requests, Google also removes duplicates of any flagged deepfakes.

Read 20 remaining paragraphs | Comments

Google, Apple gear to raise tracking tag stalker alarm – Source: go.theregister.com

google,-apple-gear-to-raise-tracking-tag-stalker-alarm-–-source:-gotheregister.com

Source: go.theregister.com – Author: Team Register Google and Apple are rolling out an anti-stalking feature for Android 6.0+ and iOS 17.5 that will issue an alert if some scumbag is using a gadget like an AirTag or similar to clandestinely track the user. Basically, if someone places a hidden tracking tag in your bag, car, […]

La entrada Google, Apple gear to raise tracking tag stalker alarm – Source: go.theregister.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Google Search Will Now Show AI-Generated Answers To Millions By Default

By: msmash
14 May 2024 at 14:10
Google is shaking up Search. On Tuesday, the company announced big new AI-powered changes to the world's dominant search engine at I/O, Google's annual conference for developers. From a report: With the new features, Google is positioning Search as more than a way to simply find websites. Instead, the company wants people to use its search engine to directly get answers and help them with planning events and brainstorming ideas. "[With] generative AI, Search can do more than you ever imagined," wrote Liz Reid, vice president and head of Google Search, in a blog post. "So you can ask whatever's on your mind or whatever you need to get done -- from researching to planning to brainstorming -- and Google will take care of the legwork." Google's changes to Search, the primary way that the company makes money, are a response to the explosion of generative AI ever since OpenAI's ChatGPT released at the end of 2022. [...] Starting today, Google will show complete AI-generated answers in response to most search queries at the top of the results page in the US. Google first unveiled the feature a year ago at Google I/O in 2023, but so far, anyone who wanted to use the feature had to sign up for it as part of the company's Search Labs platform that lets people try out upcoming features ahead of their general release. Google is now making AI Overviews available to hundreds of millions of Americans, and says that it expects it to be available in more countries to over a billion people by the end of the year.

Read more of this story at Slashdot.

Google strikes back at OpenAI with “Project Astra” AI agent prototype

14 May 2024 at 15:11
A video still of Project Astra demo at the Google I/O conference keynote in Mountain View on May 14, 2024.

Enlarge / A video still of Project Astra demo at the Google I/O conference keynote in Mountain View on May 14, 2024. (credit: Google)

Just one day after OpenAI revealed GPT-4o, which it bills as being able to understand what's taking place in a video feed and converse about it, Google announced Project Astra, a research prototype that features similar video comprehension capabilities. It was announced by Google DeepMind CEO Demis Hassabis on Tuesday at the Google I/O conference keynote in Mountain View, California.

Hassabis called Astra "a universal agent helpful in everyday life." During a demonstration, the research model showcased its capabilities by identifying sound-producing objects, providing creative alliterations, explaining code on a monitor, and locating misplaced items. The AI assistant also exhibited its potential in wearable devices, such as smart glasses, where it could analyze diagrams, suggest improvements, and generate witty responses to visual prompts.

Google says that Astra uses the camera and microphone on a user's device to provide assistance in everyday life. By continuously processing and encoding video frames and speech input, Astra creates a timeline of events and caches the information for quick recall. The company says that this enables the AI to identify objects, answer questions, and remember things it has seen that are no longer in the camera's frame.

Read 14 remaining paragraphs | Comments

Google is “reimagining” search in “the Gemini era” with AI Overviews

14 May 2024 at 14:33
Search for the best pilates studioes in Boston

Enlarge / "Google will do the Googling for you," says firm's search chief. (credit: Google)

Search is still important to Google, but soon it will change. At its all-in-one AI Google I/O event Tuesday, the company introduced a host of AI-enabled features coming to Google Search at various points in the near future, which will "do more for you than you ever imagined."

"Google will do the Googling for you," said Liz Reid, Google's head of Search.

It's not AI in every search, but it will seemingly be hard to avoid a lot of offers to help you find, plan, and brainstorm things. "AI Overviews," the successor to the Search Generative Experience, will provide summary answers to questions, along with links to sources. You can also soon submit a video as a search query, perhaps to identify objects or provide your own prompts by voice.

Read 5 remaining paragraphs | Comments

AI in Gmail will sift through emails, provide search summaries, send emails

14 May 2024 at 13:44
  • AI in Gmail summarizes recent emails. [credit: Google ]

Google's Gemini AI often just feels like a chatbot built into a text-input field, but you can really start to do special things when you give it access to a ton of data. Gemini in Gmail will soon be able to search through your entire backlog of emails and show a summary in a sidebar.

That's simple to describe but solves a huge problem with email: even searching brings up a list of email subjects, and you have to click-through to each one just to read it. Having an AI sift through a bunch of emails and provide a summary sounds like a huge time saver and something you can't do with any other interface.

Google's one-minute demo of this feature showed a big blue Gemini button at the top right of the Gmail web app. Tapping it opens the normal chatbot sidebar you can type in. Asking for a summary of emails from a certain contact will get you a bullet-point list of what has been happening, with a list of "sources" at the bottom that will jump you right to a certain email. In the last second of the demo, the user types, "Reply saying I want to volunteer for the parent's group event," hits "enter," and then the chatbot instantly sends an email. We thought it was interesting that the demo never showed a confirmation step, but a Google rep contacted us later to say the production version would show you the message before sending it.

Read 3 remaining paragraphs | Comments

Another Chrome Vulnerability

14 May 2024 at 07:01

Google has patched another Chrome zero-day:

On Thursday, Google said an anonymous source notified it of the vulnerability. The vulnerability carries a severity rating of 8.8 out of 10. In response, Google said, it would be releasing versions 124.0.6367.201/.202 for macOS and Windows and 124.0.6367.201 for Linux in subsequent days.

“Google is aware that an exploit for CVE-2024-4671 exists in the wild,” the company said.

Google didn’t provide any other details about the exploit, such as what platforms were targeted, who was behind the exploit, or what they were using it for.

Apple and Google Launch Cross-Platform Feature to Detect Unwanted Bluetooth Tracking Devices – Source:thehackernews.com

apple-and-google-launch-cross-platform-feature-to-detect-unwanted-bluetooth-tracking-devices-–-source:thehackernews.com

Source: thehackernews.com – Author: . May 14, 2024NewsroomLocation Tracking / Privacy Apple and Google on Monday officially announced the rollout of a new feature that notifies users across both iOS and Android if a Bluetooth tracking device is being used to stealthily keep tabs on them without their knowledge or consent. “This will help mitigate […]

La entrada Apple and Google Launch Cross-Platform Feature to Detect Unwanted Bluetooth Tracking Devices – Source:thehackernews.com se publicó primero en CISO2CISO.COM & CYBER SECURITY GROUP.

Apple and Google Introduce Alerts for Unwanted Bluetooth Tracking

By: msmash
13 May 2024 at 18:00
Apple and Google have launched a new industry standard called "Detecting Unwanted Location Trackers" to combat the misuse of Bluetooth trackers for stalking. Starting Monday, iPhone and Android users will receive alerts when an unknown Bluetooth device is detected moving with them. The move comes after numerous cases of trackers like Apple's AirTags being used for malicious purposes. Several Bluetooth tag companies have committed to making their future products compatible with the new standard. Apple and Google said they will continue collaborating with the Internet Engineering Task Force to further develop this technology and address the issue of unwanted tracking.

Read more of this story at Slashdot.

Pixel 8a review—The best deal in smartphones

13 May 2024 at 11:32
  • The Pixel 8a and its speedy 120 Hz display. [credit: Ron Amadeo ]

SPECS AT A GLANCE: Pixel 8a
SCREEN 6.1-inch, 120 Hz, 2400×1080 OLED
OS Android 14
CPU Google Tensor G3

One 3.0 GHz Cortex-X3 core
Four 2.45 GHz Cortex-A715 cores
Four 2.15 GHz Cortex-A510 Cores

GPU ARM Mali-G715
RAM 8GB
STORAGE 128GB, UFS 3.1
BATTERY 4492 mAh
NETWORKING Wi-Fi 6E, Bluetooth 5.3, GPS, NFC
PORTS USB Type-C 3.1 Gen 1 with 18 W USB-PD 3.0 charging
CAMERA 64MP main camera, 13 MP Ultrawide, 13 MP front camera
SIZE 152.1×72.7×8.9 mm
WEIGHT 188 g
STARTING PRICE $499.99
OTHER PERKS IP67 dust and water resistance, eSIM, in-screen fingerprint reader, 5 W wireless charging

Somehow, Google's midrange phone just keeps getting better. The Pixel 8a improves on many things over the Pixel 7a—it has a better display, a longer support cycle, and the usual yearly CPU upgrades, all at the same $499 price as last year. Who could complain? The Pixel A series was already the best bargain in smartphones, and there's now very little difference between it and a flagship-class device.

Year over year, the 6.1-inch, 2400×1080 display is being upgraded from 90 Hz to 120 Hz, giving you essentially the same experience you'd get on the "flagship" Pixels. The SoC is the same processor you'd get in the Pixel 9, a Google Tensor G3. That's a 4 nm chip with one Arm Cortex X3, four Cortex A715 cores, four Cortex A510 cores, and a Mali G715 GPU.

Previously, the 120 Hz display was the primary thing A-series owners were missing out on compared to the more expensive Pixels, so its addition is a huge deal. Any comparison between the "midrange" Pixel 8a and the "flagship" 6.2-inch Pixel 8 will now just be splitting hairs. The flagship gets an extra 0.1 inches of display, 2 percent more battery, and Wi-Fi 6E instead of Wi-Fi 7. The cameras are technically newer, but since they all run the same image-stacking software, the images look very similar. Are those things worth an extra $200? No, they are not.

Read 14 remaining paragraphs | Comments

Google Bringing Project Starline's 'Magic Window' Experience To Real Video Calls

By: msmash
13 May 2024 at 11:24
Google announced on Monday that it is preparing to bring its experimental Project Starline videoconferencing technology to the market. The company is collaborating with HP to integrate the system, which creates 3D projections of participants, into existing platforms like Google Meet and Zoom. The move aims to make the technology more accessible for offices and conference rooms, potentially transforming the way people communicate and collaborate remotely.

Read more of this story at Slashdot.

Google Employees Question Execs Over 'Decline in Morale' After Blowout Earnings

11 May 2024 at 21:34
"Google's business is growing at its fastest rate in two years," reports CNBC, "and a blowout earnings report in April sparked the biggest rally in Alphabet shares since 2015, pushing the company's market cap past $2 trillion. "But at an all-hands meeting last week with CEO Sundar Pichai and CFO Ruth Porat, employees were more focused on why that performance isn't translating into higher pay, and how long the company's cost-cutting measures are going to be in place." "We've noticed a significant decline in morale, increased distrust and a disconnect between leadership and the workforce," a comment posted on an internal forum ahead of the meeting read. "How does leadership plan to address these concerns and regain the trust, morale and cohesion that have been foundational to our company's success?" Google is using artificial intelligence to summarize employee comments and questions for the forum. Alphabet's top leadership has been on the defensive for the past few years, as vocal staffers have railed about post-pandemic return-to-office mandates, the company's cloud contracts with the military, fewer perks and an extended stretch of layoffs — totaling more than 12,000 last year — along with other cost cuts that began when the economy turned in 2022. Employees have also complained about a lack of trust and demands that they work on tighter deadlines with fewer resources and diminished opportunities for internal advancement. The internal strife continues despite Alphabet's better-than-expected first-quarter earnings report, in which the company also announced its first dividend as well as a $70 billion buyback. "Despite the company's stellar performance and record earnings, many Googlers have not received meaningful compensation increases" a top-rated employee question read. "When will employee compensation fairly reflect the company's success and is there a conscious decision to keep wages lower due to a cooling employment market?"

Read more of this story at Slashdot.

OpenAI revs up plans for web search, but denies report of an imminent launch

10 May 2024 at 13:57
OpenAI revs up plans for web search, but denies report of an imminent launch

Enlarge (credit: Aurich Lawson | Getty Images)

OpenAI is eventually coming for the most popular website on the Internet: Google Search. A Reuters report claimed that the company behind ChatGPT is planning to launch a search engine as early as this Monday, but OpenAI denied that Monday would be the day.

The company recently confirmed it's holding a livestream event on Monday, though, but an OpenAI rep told Ars that "Despite reports, we’re not launching a search product or GPT-5 on Monday." Either way, Monday is an interesting time for an OpenAI livestream. That's the day before Google's biggest show of the year, Google I/O, where Google will primarily want to show off its AI prowess and convince people that it is not being left in the dust by OpenAI. Google seeing its biggest search competition in years and suddenly having to face down "OpenAI's Google Killer" would have definitely cast a shadow over the show.

OpenAI has been inching toward a search engine for a while now. It has been working with Microsoft with a "Bing Chat" generative-AI search engine in Microsoft's search engine. Earlier this week, The Verge reported that "OpenAI has been aggressively trying to poach Google employees" for an upstart search team. "Search.chatgpt.com" is already being set up on OpenAI's server, so it's all falling into place.

Read 6 remaining paragraphs | Comments

Google patches its fifth zero-day vulnerability of the year in Chrome

10 May 2024 at 13:02
Extreme close-up photograph of finger above Chrome icon on smartphone.

Enlarge (credit: Getty Images)

Google has updated its Chrome browser to patch a high-severity zero-day vulnerability that allows attackers to execute malicious code on end user devices. The fix marks the fifth time this year the company has updated the browser to protect users from an existing malicious exploit.

The vulnerability, tracked as CVE-2024-4671, is a “use after free,” a class of bug that occurs in C-based programming languages. In these languages, developers must allocate memory space needed to run certain applications or operations. They do this by using “pointers” that store the memory addresses where the required data will reside. Because this space is finite, memory locations should be deallocated once the application or operation no longer needs it.

Use-after-free bugs occur when the app or process fails to clear the pointer after freeing the memory location. In some cases, the pointer to the freed memory is used again and points to a new memory location storing malicious shellcode planted by an attacker’s exploit, a condition that will result in the execution of this code.

Read 5 remaining paragraphs | Comments

Tech workers should shine a light on the industry’s secretive work with the military

10 May 2024 at 09:00

It’s a hell of a time to have a conscience if you work in tech. The ongoing Israeli assault on Gaza has brought the stakes of Silicon Valley’s military contracts into stark relief. Meanwhile, corporate leadership has embraced a no-politics-in-the-workplace policy enforced at the point of the knife.

Workers are caught in the middle. Do I take a stand and risk my job, my health insurance, my visa, my family’s home? Or do I ignore my suspicion that my work may be contributing to the murder of innocents on the other side of the world?  

No one can make that choice for you. But I can say with confidence born of experience that such choices can be more easily made if workers know what exactly the companies they work for are doing with militaries at home and abroad. And I also know this: those same companies themselves will never reveal this information unless they are forced to do so—or someone does it for them. 

For those who doubt that workers can make a difference in how trillion-dollar companies pursue their interests, I’m here to remind you that we’ve done it before. In 2017, I played a part in the successful #CancelMaven campaign that got Google to end its participation in Project Maven, a contract with the US Department of Defense to equip US military drones with artificial intelligence. I helped bring to light information that I saw as critically important and within the bounds of what anyone who worked for Google, or used its services, had a right to know. The information I released—about how Google had signed a contract with the DOD to put AI technology in drones and later tried to misrepresent the scope of that contract, which the company’s management had tried to keep from its staff and the general public—was a critical factor in pushing management to cancel the contract. As #CancelMaven became a rallying cry for the company’s staff and customers alike, it became impossible to ignore. 

Today a similar movement, organized under the banner of the coalition No Tech for Apartheid, is targeting Project Nimbus, a joint contract between Google and Amazon to provide cloud computing infrastructure and AI capabilities to the Israeli government and military. As of May 10, just over 97,000 people had signed its petition calling for an end to collaboration between Google, Amazon, and the Israeli military. I’m inspired by their efforts and dismayed by Google’s response. Earlier this month the company fired 50 workers it said had been involved in “disruptive activity” demanding transparency and accountability for Project Nimbus. Several were arrested. It was a decided overreach.  

Google is very different from the company it was seven years ago, and these firings are proof of that. Googlers today are facing off with a company that, in direct response to those earlier worker movements, has fortified itself against new demands. But every Death Star has its thermal exhaust port, and today Google has the same weakness it did back then: dozens if not hundreds of workers with access to information it wants to keep from becoming public. 

Not much is known about the Nimbus contract. It’s worth $1.2 billion and enlists Google and Amazon to provide wholesale cloud infrastructure and AI for the Israeli government and its ministry of defense. Some brave soul leaked a document to Time last month, providing evidence that Google and Israel negotiated an expansion of the contract as recently as March 27 of this year. We also know, from reporting by The Intercept, that Israeli weapons firms are required by government procurement guidelines to buy their cloud services from Google and Amazon. 

Leaks alone won’t bring an end to this contract. The #CancelMaven victory required a sustained focus over many months, with regular escalations, coordination with external academics and human rights organizations, and extensive internal organization and discipline. Having worked on the public policy and corporate comms teams at Google for a decade, I understood that its management does not care about one negative news cycle or even a few of them. Management buckled only after we were able to keep up the pressure and escalate our actions (leaking internal emails, reporting new info about the contract, etc.) for over six months. 

The No Tech for Apartheid campaign seems to have the necessary ingredients. If a strategically placed insider released information not otherwise known to the public about the Nimbus project, it could really increase the pressure on management to rethink its decision to get into bed with a military that’s currently overseeing mass killings of women and children.

My decision to leak was deeply personal and a long time in the making. It certainly wasn’t a spontaneous response to an op-ed, and I don’t presume to advise anyone currently at Google (or Amazon, Microsoft, Palantir, Anduril, or any of the growing list of companies peddling AI to militaries) to follow my example. 

However, if you’ve already decided to put your livelihood and freedom on the line, you should take steps to try to limit your risk. This whistleblower guide is helpful. You may even want to reach out to a lawyer before choosing to share information. 

In 2017, Google was nervous about how its military contracts might affect its public image. Back then, the company responded to our actions by defending the nature of the contract, insisting that its Project Maven work was strictly for reconnaissance and not for weapons targeting—conceding implicitly that helping to target drone strikes would be a bad thing. (An aside: Earlier this year the Pentagon confirmed that Project Maven, which is now a Palantir contract, had been used in targeting drone attacks in Yemen, Iraq, and Syria.) 

Today’s Google has wrapped its arms around the American flag, for good or ill. Yet despite this embrace of the US military, it doesn’t want to be seen as a company responsible for illegal killings. Today it maintains that the work it is doing as part of Project Nimbus “is not directed at highly sensitive, classified, or military workloads relevant to weapons or intelligence services.” At the same time, it asserts that there is no room for politics at the workplace and has fired those demanding transparency and accountability. This raises a question: If Google is doing nothing sensitive as part of the Nimbus contract, why is it firing workers who are insisting that the company reveal what work the contract actually entails?  

As you read this, AI is helping Israel annihilate Palestinians by expanding the list of possible targets beyond anything that could be compiled by a human intelligence effort, according to +972 Magazine. Some Israel Defense Forces insiders are even sounding the alarm, calling it a dangerous “mass assassination program.” The world has not yet grappled with the implications of the proliferation of AI weaponry, but that is the trajectory we are on. It’s clear that absent sufficient backlash, the tech industry will continue to push for military contracts. It’s equally clear that neither national governments nor the UN is currently willing to take a stand. 

It will take a movement. A document that clearly demonstrates Silicon Valley’s direct complicity in the assault on Gaza could be the spark. Until then, rest assured that tech companies will continue to make as much money as possible developing the deadliest weapons imaginable. 

William Fitzgerald is a founder and partner at the Worker Agency, an advocacy agency in California. Before setting the firm up in 2018, he spent a decade at Google working on its government relation and communications teams.

ChromeOS App Mall unifies app discovery for Chromebooks

9 May 2024 at 09:42

We’ve been on the lookout for the arrival of the ChromeOS App Mall for a few months now. First discovered back in March, the new App Mall is arriving to do one, simple task: put the apps users want in one place to be found a Chromebook.

While we have access to web apps, PWAs, Android apps and Linux apps on Chromebooks, it’s not always clear how to go about finding them. Should you install the web version or the Play Store version? Which Play Store apps install a PWA versus an Android app? Where should you go to find the right one for you?

↫ Robby Payne at Chrome Unboxed

ChromeOS definitely needs a more unified, single place to find applications, and this seems like exactly what’s happening here.

Google Will Exit Prominent San Francisco Waterfront Office Tower

By: BeauHD
8 May 2024 at 21:25
Google announced on Tuesday that it will be exiting One Market Plaza, a prominent office complex in San Francisco that it had been occupying since 2018. The company's lease for the 300,000-square-foot-office will expire next April. The San Francisco Chronicle reports: Many of Google's employees are already working outside of the giant waterfront office, in light of the company's flexible approach to office attendance. As one of the city's largest office properties and a prominent feature on its skyline, the 1.6-million-square-foot One Market Plaza complex features two high-rise towers and a 11-story office annex building known as the Landmark." Ryan Lamont, a spokesperson for Google, said the company will be moving out of One Market's Spear Tower, but will continue to occupy the smaller Landmark building. He declined to comment on how long Google plans to remain in the latter." As we've said before, we're focused on investing in real estate efficiently to meet the current and future needs of our hybrid workforce," Lamont said in an email to the Chronicle. "We remain committed to our long-term presence in San Francisco." Real estate market participants who spoke with the Chronicle indicated that Google plans to consolidate much of its operations from One Market to nearby 345 Spear St., where the company leases about 400,000 square feet. These individuals said that Google will likely renew its lease at that property once it expires next year.

Read more of this story at Slashdot.

DeepMind adds a diffusion engine to latest protein-folding software

8 May 2024 at 15:45
image of a complicated mix of lines and ribbons arranged in a complicated 3D structure.

Enlarge / Prediction of the structure of a coronavirus Spike protein from a virus that causes the common cold. (credit: Google DeepMind)

Most of the activities that go on inside cells—the activities that keep us living, breathing, thinking animals—are handled by proteins. They allow cells to communicate with each other, run a cell's basic metabolism, and help convert the information stored in DNA into even more proteins. And all of that depends on the ability of the protein's string of amino acids to fold up into a complicated yet specific three-dimensional shape that enables it to function.

Up until this decade, understanding that 3D shape meant purifying the protein and subjecting it to a time- and labor-intensive process to determine its structure. But that changed with the work of DeepMind, one of Google's AI divisions, which released Alpha Fold in 2021, and a similar academic effort shortly afterward. The software wasn't perfect; it struggled with larger proteins and didn't offer high-confidence solutions for every protein. But many of its predictions turned out to be remarkably accurate.

Even so, these structures only told half of the story. To function, almost every protein has to interact with something else—other proteins, DNA, chemicals, membranes, and more. And, while the initial version of AlphaFold could handle some protein-protein interactions, the rest remained black boxes. Today, DeepMind is announcing the availability of version 3 of AlphaFold, which has seen parts of its underlying engine either heavily modified or replaced entirely. Thanks to these changes, the software now handles various additional protein interactions and modifications.

Read 15 remaining paragraphs | Comments

The $499 Google Pixel 8a is official, with 120 Hz display, 7 years of updates

7 May 2024 at 12:00
  • The Pixel 8a. [credit: Google ]

Today is a big event day for Apple, but that doesn't mean Google is going to fade into the background: It's announcing the Pixel 8a today. The big news is that the Pixel a series is still $499 despite some upgrades.

What are those upgrades? How about a 120 Hz display on Google's mid-ranger for the first time? The 6.1-inch, 120 Hz, 2400×1080 display is closer to a flagship than ever, even if it is a smaller phone. You also get flagship-class support with Google's industry-leading seven years of OS updates, so the phone should be good until 2031, if you can hold out that long. Together, these two upgrades make the Pixel 8a an incredible value.

Major news with last year's launch of the Pixel 7a was the older Pixel 6a, which got a big price drop down to $349 when the 7a came out. When asked about a potential Pixel 7a price drop, Google says it "will continue to sell the Pixel 7a" but also that it has "no news to announce today on a pricing change." It did feel like the Pixel 6a's price drop stole some of the 7a's thunder last year, so maybe Google is giving that announcement some breathing room. For now, you'll have to think long and hard at checkout and decide between a $499 Pixel 8a and a $499 Pixel 7a. The base model Pixel 8, at $699 with nearly the same specs, is also a tough sell in the face of the Pixel 8a.

Read 4 remaining paragraphs | Comments

New Microsoft AI model may challenge GPT-4 and Google Gemini

6 May 2024 at 15:51
Mustafa Suleyman, co-founder and chief executive officer of Inflection AI UK Ltd., during a town hall on day two of the World Economic Forum (WEF) in Davos, Switzerland, on Wednesday, Jan. 17, 2024.

Enlarge / Mustafa Suleyman, co-founder and chief executive officer of Inflection AI UK Ltd., during a town hall on day two of the World Economic Forum (WEF) in Davos, Switzerland, on Wednesday, Jan. 17, 2024. Suleyman joined Microsoft in March. (credit: Getty Images)

Microsoft is working on a new large-scale AI language model called MAI-1, which could potentially rival state-of-the-art models from Google, Anthropic, and OpenAI, according to a report by The Information. This marks the first time Microsoft has developed an in-house AI model of this magnitude since investing over $10 billion in OpenAI for the rights to reuse the startup's AI models. OpenAI's GPT-4 powers not only ChatGPT but also Microsoft Copilot.

The development of MAI-1 is being led by Mustafa Suleyman, the former Google AI leader who recently served as CEO of the AI startup Inflection before Microsoft acquired the majority of the startup's staff and intellectual property for $650 million in March. Although MAI-1 may build on techniques brought over by former Inflection staff, it is reportedly an entirely new large language model (LLM), as confirmed by two Microsoft employees familiar with the project.

With approximately 500 billion parameters, MAI-1 will be significantly larger than Microsoft's previous open source models (such as Phi-3, which we covered last month), requiring more computing power and training data. This reportedly places MAI-1 in a similar league as OpenAI's GPT-4, which is rumored to have over 1 trillion parameters (in a mixture-of-experts configuration) and well above smaller models like Meta and Mistral's 70 billion parameter models.

Read 3 remaining paragraphs | Comments

Best printer 2024 for printing printers who love to print in 2024

By: Rhaomi
5 May 2024 at 14:45
It's weird because the correct answer to the query "what is the best printer" has not changed, but an entire ecosystem of content farms seems motivated to constantly update articles about printers in response to the incentive structure created by that robot's obvious preferences. Pointing out that incentive structure and the culture that's developed around it seems to make a lot of people mad, which is also interesting! Anyway, here's the best printer for 2024: a Brother laser printer. You can just pick any one you like; I have one with a sheet feeder and one without a sheet feeder. Both of them have reliably printed return labels and random forms and pictures for my kid to color for years now, and I have never purchased replacement toner for either one. Neither has fallen off the WiFi or insisted I sign up for an ink-related hostage situation or required me to consider the ongoing schemes of HP executives who seem determined to make people hate a legendary brand with straightforward cash grabs and weird DRM ideas.
Best printer 2024, best printer for home use, office use, printing labels, printer for school, homework printer you are a printer we are all printers / After a full year of not thinking about printers, the best printer is still whatever random Brother laser printer that's on sale. [Previously]

Judge mulls sanctions over Google’s “shocking” destruction of internal chats

3 May 2024 at 19:17
Kenneth Dintzer, litigator for the US Department of Justice, exits federal court in Washington, DC, on September 20, 2023, during the antitrust trial to determine if Alphabet Inc.'s Google maintains a monopoly in the online search business.

Enlarge / Kenneth Dintzer, litigator for the US Department of Justice, exits federal court in Washington, DC, on September 20, 2023, during the antitrust trial to determine if Alphabet Inc.'s Google maintains a monopoly in the online search business. (credit: Bloomberg / Contributor | Bloomberg)

Near the end of the second day of closing arguments in the Google monopoly trial, US district judge Amit Mehta weighed whether sanctions were warranted over what the US Department of Justice described as Google's "routine, regular, and normal destruction" of evidence.

Google was accused of enacting a policy instructing employees to turn chat history off by default when discussing sensitive topics, including Google's revenue-sharing and mobile application distribution agreements. These agreements, the DOJ and state attorneys general argued, work to maintain Google's monopoly over search.

According to the DOJ, Google destroyed potentially hundreds of thousands of chat sessions not just during their investigation but also during litigation. Google only stopped the practice after the DOJ discovered the policy. DOJ's attorney Kenneth Dintzer told Mehta Friday that the DOJ believed the court should "conclude that communicating with history off shows anti-competitive intent to hide information because they knew they were violating antitrust law."

Read 19 remaining paragraphs | Comments

AI in space: Karpathy suggests AI chatbots as interstellar messengers to alien civilizations

3 May 2024 at 15:04
Close shot of Cosmonaut astronaut dressed in a gold jumpsuit and helmet, illuminated by blue and red lights, holding a laptop, looking up.

Enlarge (credit: Getty Images)

On Thursday, renowned AI researcher Andrej Karpathy, formerly of OpenAI and Tesla, tweeted a lighthearted proposal that large language models (LLMs) like the one that runs ChatGPT could one day be modified to operate in or be transmitted to space, potentially to communicate with extraterrestrial life. He said the idea was "just for fun," but with his influential profile in the field, the idea may inspire others in the future.

Karpathy's bona fides in AI almost speak for themselves, receiving a PhD from Stanford under computer scientist Dr. Fei-Fei Li in 2015. He then became one of the founding members of OpenAI as a research scientist, then served as senior director of AI at Tesla between 2017 and 2022. In 2023, Karpathy rejoined OpenAI for a year, leaving this past February. He's posted several highly regarded tutorials covering AI concepts on YouTube, and whenever he talks about AI, people listen.

Most recently, Karpathy has been working on a project called "llm.c" that implements the training process for OpenAI's 2019 GPT-2 LLM in pure C, dramatically speeding up the process and demonstrating that working with LLMs doesn't necessarily require complex development environments. The project's streamlined approach and concise codebase sparked Karpathy's imagination.

Read 20 remaining paragraphs | Comments

Apple deal could have been “suicide” for Google, company lawyer says

2 May 2024 at 15:37
John Schmidtlein, partner at Williams & Connolly LLP and lead litigator for Alphabet Inc.'s Google, arrives to federal court in Washington, DC, US, on Monday, Oct. 2, 2023.

Enlarge / John Schmidtlein, partner at Williams & Connolly LLP and lead litigator for Alphabet Inc.'s Google, arrives to federal court in Washington, DC, US, on Monday, Oct. 2, 2023. (credit: Bloomberg / Contributor | Bloomberg)

Halfway through the first day of closing arguments in the Department of Justice's big antitrust trial against Google, US District Judge Amit Mehta posed the question that likely many Google users have pondered over years of DOJ claims that Google's market dominance has harmed users.

"What should Google have done to remain outside the crosshairs of the DOJ?" Mehta asked plaintiffs halfway through the first of two full days of closing arguments.

According to the DOJ and state attorneys general suing, Google has diminished search quality everywhere online, primarily by locking rivals out of default positions on devices and in browsers. By paying billions for default placements that the government has argued allowed Google to hoard traffic and profits, Google allegedly made it nearly impossible for rivals to secure enough traffic to compete, ultimately decreasing competition and innovation in search by limiting the number of viable search engines in the market.

Read 19 remaining paragraphs | Comments

Email Microsoft didn’t want seen reveals rushed decision to invest in OpenAI

1 May 2024 at 15:05
Email Microsoft didn’t want seen reveals rushed decision to invest in OpenAI

Enlarge (credit: HJBC | iStock Editorial / Getty Images Plus)

In mid-June 2019, Microsoft co-founder Bill Gates and CEO Satya Nadella received a rude awakening in an email warning that Google had officially gotten too far ahead on AI and that Microsoft may never catch up without investing in OpenAI.

With the subject line "Thoughts on OpenAI," the email came from Microsoft's chief technology officer, Kevin Scott, who is also the company’s executive vice president of AI. In it, Scott said that he was "very, very worried" that he had made "a mistake" by dismissing Google's initial AI efforts as a "game-playing stunt."

It turned out, Scott suggested, that instead of goofing around, Google had been building critical AI infrastructure that was already paying off, according to a competitive analysis of Google's products that Scott said showed that Google was competing even more effectively in search. Scott realized that while Google was already moving on to production for "larger scale, more interesting" AI models, it might take Microsoft "multiple years" before it could even attempt to compete with Google.

Read 17 remaining paragraphs | Comments

State Spies Exploited Cisco Zero-Days to Intrude Government Networks

25 April 2024 at 07:40

Cisco zero-days

Networking giant Cisco warned that a group of state-sponsored hackers exploited zero-days in its firewall appliances to spy on government networks over the last several months. Cisco in a Wednesday warning said that two zero-day vulnerabilities in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls were exploited by a state-backed hacking group since November 2023 to infiltrate government networks globally. Identified as UAT4356 by Cisco Talos and STORM-1849 by Microsoft, the hackers initiated their cyber-espionage campaign, dubbed “ArcaneDoor,” through targeting of vulnerable edge devices in early November 2023.
“This actor utilized bespoke tooling that demonstrated a clear focus on espionage and an in-depth knowledge of the devices that they targeted, hallmarks of a sophisticated state-sponsored actor,” Cisco Talos said.

Discovery and Details of the Two Cisco Zero-Days

Despite the absence of an identified initial attack vector, Cisco detected and rectified two security flaws - CVE-2024-20353, a denial-of-service bug and CVE-2024-20359, a persistent local code execution bug - which the threat actors used as zero-days. Cisco became aware of the ArcaneDoor campaign earlier this year but said the attackers had been testing and developing exploits for the two zero-days since at least July 2023. “The investigation that followed identified additional victims, all of which involved government networks globally,” Cisco Talos added. [caption id="attachment_64982" align="aligncenter" width="997"]Cisco zero-days, Cisco zero-days exploitation timeline Cisco Zero-Days Exploitation Timeline. Credit: Cisco Talos[/caption] The exploited vulnerabilities facilitated the deployment of previously unknown malware, allowing threat actors to establish persistence on compromised ASA and FTD devices. One such malware implant dubbed “Line Dancer,” acted as an in-memory shellcode loader, enabling the execution of arbitrary shellcode payloads to disable logging, provide remote access, and exfiltrate captured packets. The second implant, a persistent backdoor known as “Line Runner,” included various defense evasion mechanisms to evade detection and enable the execution of arbitrary Lua code on compromised systems. Perimeter network devices like the ASA and FTD firewall appliances “are the perfect intrusion point for espionage-focused campaigns,” Cisco said. “Gaining a foothold on these devices allows an actor to directly pivot into an organization, reroute or modify traffic and monitor network communications.” The networking and security giant said it had observed a “dramatic and sustained” increase in the targeting of these devices in the past two years, especially those deployed in the telecommunications and energy sectors as “critical infrastructure entities are likely strategic targets of interest for many foreign governments,” Cisco explained.

What Cybersecurity Agencies Said

A joint advisory published today by the UK's National Cyber Security Centre (NCSC), the Canadian Centre for Cyber Security (Cyber Centre), and the Australian Cyber Security Centre outlined additional activity undertaken by the threat actors: - They generated text versions of the device’s configuration file for exfiltration through web requests. - They controlled the enabling and disabling of the devices syslog service to obfuscate additional commands. - They modified the authentication, authorization, and accounting (AAA) configuration to provide access to specific actor-controlled devices within the impacted environment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the zero-day bugs to its Known Exploited Vulnerabilities Catalog and encouraged users to apply the necessary updates, hunt for malicious activity, and report any positive findings to the agency. Cisco released security updates on Wednesday to address the two zero-days and recommended all customers to upgrade their devices to the fixed software version to mitigate potential attacks. Cisco asked administrators to monitor system logs for signs of unscheduled reboots, unauthorized configuration changes, or suspicious credential activity. The company also provided instructions on verifying the integrity of ASA or FTD devices in the advisory.

Espionage Actors Increasingly Using Edge Device Zero-Days

Although no attribution was made for the ArcaneDoor campaign a recent trends report from Google security firm Mandiant fingered Chinese hackers for increasingly targeting edge devices like VPN appliances, firewalls, routers, and IoT tools in espionage attacks. Mandiant observed a more than 50% growth in zero-day usage compared to 2022, both by espionage groups as well as financially motivated hackers.
“China-nexus attackers have gained access to edge devices via exploitation of vulnerabilities, particularly zero-days, and subsequently deployed custom malware ecosystems,“ Mandiant said.
The security firm added that it is likely to see continued deployment of custom malware ecosystems from Chinese espionage groups that are tailored for the device and operation at hand. “This approach provides several advantages such as the increased ability to remain undetected, reduced complexity and increased reliability, and a reduced malware footprint.“ Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Google postpones phasing out third party cookies in Chrome once more

24 April 2024 at 19:30

While Firefox and Safari phased out third party cookies years ago, it’s taking Chrome a bit longer because, well, daddy Google got ads to sell. As such, Google has been developing a complicated new alternative to third party cookies that it calls “Privacy sandbox”, a name in the vain of “Greenland”. This process has not exactly been going well, because Google has had to postpone phasing out third party cookies several times now, and today, they had to postpone it again. This time, however, it’s because the UK competition authority, the CMA, still has some questions.

We recognize that there are ongoing challenges related to reconciling divergent feedback from the industry, regulators and developers, and will continue to engage closely with the entire ecosystem. It’s also critical that the CMA has sufficient time to review all evidence including results from industry tests, which the CMA has asked market participants to provide by the end of June. Given both of these significant considerations, we will not complete third-party cookie deprecation during the second half of Q4.

We remain committed to engaging closely with the CMA and ICO and we hope to conclude that process this year. Assuming we can reach an agreement, we envision proceeding with third-party cookie deprecation starting early next year.

↫ Google’s Greenland blog

Making a browser good enough to take over almost the entire browser market was an absolute master stroke by Google. Now can you all please switch over to Firefox or like Lynx or something?

The man who killed Google Search

23 April 2024 at 18:47

These emails — which I encourage you to look up — tell a dramatic story about how Google’s finance and advertising teams, led by Raghavan with the blessing of CEO Sundar Pichai, actively worked to make Google worse to make the company more money. This is what I mean when I talk about the Rot Economy — the illogical, product-destroying mindset that turns the products you love into torturous, frustrating quasi-tools that require you to fight the company’s intentions to get the service you want.

↫ Edward Zitron

Quite the read.

❌
❌