
By Brian X. Chen
The dream of carrying one power cable for all your devices is becoming a reality. But things aren’t as simple as they sound.
Published: September 11, 2023 at 06:00PM
from NYT Technology https://ift.tt/x0DEVup
via IFTTT

By Brian X. Chen
The dream of carrying one power cable for all your devices is becoming a reality. But things aren’t as simple as they sound.
Published: September 11, 2023 at 06:00PM
from NYT Technology https://ift.tt/x0DEVup
via IFTTT

By Tripp Mickle
European regulators passed a rule requiring USB-C charging across electronic devices, forcing the change in Apple’s newest iPhones.
Published: September 11, 2023 at 06:00PM
from NYT Technology https://ift.tt/dprejA3
via IFTTT
The most remarkable thing about these new in-ear high-end headphones is how overpriced they are.
from Gear Latest https://ift.tt/MAvgEjp
via IFTTT
Microsoft today issued software updates to fix at least five dozen security holes in Windows and supported software, including patches for two zero-day vulnerabilities that are already being exploited. Also, Adobe, Google Chrome and Apple iOS users may have their own zero-day patching to do.

On Sept. 7, researchers at Citizen Lab warned they were seeing active exploitation of a “zero-click,” zero-day flaw to install spyware on iOS devices without any interaction from the victim.
“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” the researchers wrote.
According to Citizen Lab, the exploit uses malicious images sent via iMessage, an embedded component of Apple’s iOS that has been the source of previous zero-click flaws in iPhones and iPads.
Apple says the iOS flaw (CVE-2023-41064) does not seem to work against devices that have its ultra-paranoid “Lockdown Mode” enabled. This feature restricts non-essential iOS features to reduce the device’s overall attack surface, and it was designed for users concerned that they may be subject to targeted attacks. Citizen Lab says the bug it discovered was being exploited to install spyware made by the Israeli cyber surveillance company NSO Group.
This vulnerability is fixed in iOS 16.6.1 and iPadOS 16.6.1. To turn on Lockdown Mode in iOS 16, go to Settings, then Privacy and Security, then Lockdown Mode.
Not to be left out of the zero-day fun, Google acknowledged on Sept. 11 that an exploit for a heap overflow bug in Chrome is being exploited in the wild. Google says it is releasing updates to fix the flaw, and that restarting Chrome is the way to apply any pending updates. Interestingly, Google says this bug was reported by Apple and Citizen Lab.
On the Microsoft front, a zero-day in Microsoft Word is among the more concerning bugs fixed today. Tracked as CVE-2023-36761, it is flagged as an “information disclosure” vulnerability. But that description hardly grasps at the sensitivity of the information potentially exposed here.
Tom Bowyer, manager of product security at Automox, said exploiting this vulnerability could lead to the disclosure of Net-NTLMv2 hashes, which are used for authentication in Windows environments.
“If a malicious actor gains access to these hashes, they can potentially impersonate the user, gaining unauthorized access to sensitive data and systems,” Bowyer said, noting that CVE-2023-36761 can be exploited just by viewing a malicious document in the Windows preview pane. “They could also conduct pass-the-hash attacks, where the attacker uses the hashed version of a password to authenticate themselves without needing to decrypt it.”
The other Windows zero-day fixed this month is CVE-2023-36802. This is an “elevation of privilege” flaw in the “Microsoft Streaming Service Proxy,” which is built into Windows 10, 11 and Windows Server versions. Microsoft says an attacker who successfully exploits the bug can gain SYSTEM level privileges on a Windows computer.
Five of the flaws Microsoft fixed this month earned its “critical” rating, which the software giant reserves for vulnerabilities that can be exploited by malware or malcontents with little or no interaction by Windows users.
According to the SANS Internet Storm Center, the most serious critical bug in September’s Patch Tuesday is CVE-2023-38148, which is a weakness in the Internet Connection Sharing service on Windows. Microsoft says an unauthenticated attacker could leverage the flaw to install malware just sending a specially crafted data packet to a vulnerable Windows system.
Finally, Adobe has released critical security updates for its Adobe Reader and Acrobat software that also fixes a zero-day vulnerability (CVE-2023-26369). More details are at Adobe’s advisory.
For a more granular breakdown of the Windows updates pushed out today, check out Microsoft Patch Tuesday by Morphus Labs. In the meantime, consider backing up your data before updating Windows, and keep an eye on AskWoody.com for reports of any widespread problems with any of the updates released as part of September’s Patch Tuesday.
from Krebs on Security https://ift.tt/jdeImx8
via IFTTT
New iPhones, sure. But the company’s compelling new service lures you even deeper into its ecosystem.
from Gear Latest https://ift.tt/ntuw3b9
via IFTTT

By David McCabe and Cecilia Kang
In opening statements for the government’s first monopoly trial of the modern internet era, Google defended itself and said people had many choices for online search.
Published: September 12, 2023 at 04:01PM
from NYT Technology https://ift.tt/jrNQuk7
via IFTTT

By Tripp Mickle
European regulators passed a rule requiring USB-C charging across electronic devices, forcing the change in Apple’s newest iPhones.
Published: September 12, 2023 at 12:53PM
from NYT Technology https://ift.tt/dprejA3
via IFTTT
The company debuted the iPhone 15, two new Apple Watches, new AirPods Pro, and some enhanced services.
from Gear Latest https://ift.tt/EwGStYu
via IFTTT

By Brian X. Chen
The dream of carrying one power cable for all your devices is becoming a reality. But things aren’t as simple as they sound.
Published: September 12, 2023 at 01:04PM
from NYT Technology https://ift.tt/x0DEVup
via IFTTT
Say goodbye to the mute switch and the Lightning port. The new iPhone 15 lineup packs USB-C, but it’s the Pro models that have the spotlight.
from Gear Latest https://ift.tt/5avEqky
via IFTTT