[New Episodes] Ken Goldin and his savvy team run the thrilling action in this series that goes inside a leading auction house specializing in rare collectibles.
from New On Netflix USA https://ift.tt/MC5UF7r
via IFTTT
[New Episodes] Ken Goldin and his savvy team run the thrilling action in this series that goes inside a leading auction house specializing in rare collectibles.
from New On Netflix USA https://ift.tt/MC5UF7r
via IFTTT
[New Episodes] Late-night TV legend David Letterman hosts an intimate talk show featuring insightful conversations and fun-filled excursions with notable figures.
from New On Netflix USA https://ift.tt/FK4NWy5
via IFTTT
Thousands of terracotta warriors guarded the first Chinese emperor’s tomb. This is their story, told through archeological evidence and reenactments.
from New On Netflix USA https://ift.tt/w9nCc1Z
via IFTTT
Seemingly in response to last month’s TAG Heuer-Kith mashup, Swatch looks closer to home for its next space-based Omega collaboration.
from Gear Latest https://ift.tt/2VpCwib
via IFTTT
“We have people stealing all over the world.” A digital sleuth named Bryan Hance has spent the past four years obsessively uncovering a bicycle-theft pipeline of astonishing scale, running from the US West Coast to Mexico.
from Gear Latest https://ift.tt/lD1Sbfi
via IFTTT
Microsoft today released updates to fix more than 50 security vulnerabilities in Windows and related software, a relatively light Patch Tuesday this month for Windows users. The software giant also responded to a torrent of negative feedback on a new feature of Redmond’s flagship operating system that constantly takes screenshots of whatever users are doing on their computers, saying the feature would no longer be enabled by default.

Last month, Microsoft debuted Copilot+ PCs, an AI-enabled version of Windows. Copilot+ ships with a feature nobody asked for that Redmond has aptly dubbed Recall, which constantly takes screenshots of what the user is doing on their PC. Security experts roundly trashed Recall as a fancy keylogger, noting that it would be a gold mine of information for attackers if the user’s PC was compromised with malware.
Microsoft countered that Recall snapshots never leave the user’s system, and that even if attackers managed to hack a Copilot+ PC they would not be able to exfiltrate on-device Recall data. But that claim rang hollow after former Microsoft threat analyst Kevin Beaumont detailed on his blog how any user on the system (even a non-administrator) can export Recall data, which is just stored in an SQLite database locally.
“I’m not being hyperbolic when I say this is the dumbest cybersecurity move in a decade,” Beaumont said on Mastodon.
In a recent Risky Business podcast, host Patrick Gray noted that the screenshots created and indexed by Recall would be a boon to any attacker who suddenly finds himself in an unfamiliar environment.
“The first thing you want to do when you get on a machine if you’re up to no good is to figure out how someone did their job,” Gray said. “We saw that in the case of the SWIFT attacks against central banks years ago. Attackers had to do screen recordings to figure out how transfers work. And this could speed up that sort of discovery process.”
Responding to the withering criticism of Recall, Microsoft said last week that it will no longer be enabled by default on Copilot+ PCs.
Only one of the patches released today — CVE-2004-30080 — earned Microsoft’s most urgent “critical” rating, meaning malware or malcontents could exploit the vulnerability to remotely seize control over a user’s system, without any user interaction.
CVE-2024-30080 is a flaw in the Microsoft Message Queuing (MSMQ) service that can allow attackers to execute code of their choosing. Microsoft says exploitation of this weakness is likely, enough to encourage users to disable the vulnerable component if updating isn’t possible in the short run. CVE-2024-30080 has been assigned a CVSS vulnerability score of 9.8 (10 is the worst).
Kevin Breen, senior director of threat research at Immersive Labs, said a saving grace is that MSMQ is not a default service on Windows.
“A Shodan search for MSMQ reveals there are a few thousand potentially internet-facing MSSQ servers that could be vulnerable to zero-day attacks if not patched quickly,” Breen said.
CVE-2024-30078 is a remote code execution weakness in the Windows WiFi Driver, which also has a CVSS score of 9.8. According to Microsoft, an unauthenticated attacker could exploit this bug by sending a malicious data packet to anyone else on the same network — meaning this flaw assumes the attacker has access to the local network.
Microsoft also fixed a number of serious security issues with its Office applications, including at least two remote-code execution flaws, said Adam Barnett, lead software engineer at Rapid7.
“CVE-2024-30101 is a vulnerability in Outlook; although the Preview Pane is a vector, the user must subsequently perform unspecified specific actions to trigger the vulnerability and the attacker must win a race condition,” Barnett said. “CVE-2024-30104 does not have the Preview Pane as a vector, but nevertheless ends up with a slightly higher CVSS base score of 7.8, since exploitation relies solely on the user opening a malicious file.”
Separately, Adobe released security updates for Acrobat, ColdFusion, and Photoshop, among others.
As usual, the SANS Internet Storm Center has the skinny on the individual patches released today, indexed by severity, exploitability and urgency. Windows admins should also keep an eye on AskWoody.com, which often publishes early reports of any Windows patches gone awry.
from Krebs on Security https://ift.tt/ziFDEl4
via IFTTT

By Cade Metz
The Tesla chief executive had claimed that the A.I. start-up put profits and commercial interests ahead of benefiting humanity.
Published: June 11, 2024 at 04:21PM
from NYT Technology https://ift.tt/FDzMSfe
via IFTTT
Apple has officially debuted macOS 15, which is named Sequoia. We break down all the new features to look forward to, and tell you whether your current Mac will support the new operating system.
from Gear Latest https://ift.tt/zSnIDl9
via IFTTT
What exactly is Apple Intelligence? We break down Apple’s AI onslaught plus all the features worth talking about in iOS 18 and iPadOS 18.
from Gear Latest https://ift.tt/RfHw9Ki
via IFTTT
Here’s a guide to all the models—plus case recommendations and hidden software tricks to try.
from Gear Latest https://ift.tt/Rwzv7Hq
via IFTTT