• 79 Posts
  • 114 Comments
Joined 1 year ago
cake
Cake day: June 3rd, 2023

help-circle






  • I am definitely not trying to defend the manufacturers here, only point out that there are solutions for those like myself who want to continue using their wired headphones with newer phones.

    Understood.

    I agree with you with the SD card too. That one probably annoys me more. It made everything so much more difficult. Transferring files, backups, swapping out music, seeing pictures from a camera or drone… Made the device less like a computer in everyway.


  • Yes that is true but speaking on clinging on to an older phone, a headphone jack had a superior physical hold. My phone got saved a few times because my phone was connected to my wired headphones.

    These dongles that came with phones were also usually very thin. It also sticks out and made of plastic. It just adds another weak point. They somehow added a weak point to a great piece of technology… On top of that phones no longer comes with the dongles.

    Also dongles aren’t sexy. It looks like a hack to make something work. Phone companies made headphones unsexy while making wireless earbuds really sexy.

    Some people said that a headphone jack made dustproofing and waterproofing more difficult. Maybe but it had be done before. They also said it brings down the price of the phone to get rid of them. Weird considering the Google A series and Samsung mid range phones had it but their flagship phones didn’t.

    You made a lot of great points. Thank you for those.

    I actually have bluetooth earbuds either came bundled, or I was gifted them. They have come a long way. Easier to connect. Better latency and better sound quality compared to the older version of bluetooth.

    I like them, I am not a complete hater but I really am annoyed that this stuff will just turn to ewaste while my headphones have lasted me decades.

    I’m just an old head yelling at the clouds.





  • The security advisory is for version 13.x until 13.6 on the popular virtualization software for macOS. The bug — CVE-2024-38811 — has a CVSSv3 base score of 8.8 and is caused by an insecure environment variable. Mykola Grymalyuk of RIPEDA Consulting reported the vulnerability and VMWare has issued a patched version of the software.

    The vulnerability allows a user with standard privileges to execute code within the Fusion application.

























  • New Tickler malware used to backdoor US govt, defense orgs

    By Sergiu Gatlan August 28, 2024 02:36 PM

    The APT33 Iranian hacking group has used new Tickler malware to backdoor the networks of organizations in the government, defense, satellite, oil and gas sectors in the United States and the United Arab Emirates.

    As Microsoft security researchers observed, the threat group (also tracked as Peach Sandstorm and Refined Kitten), which operates on behalf of the Iranian Islamic Revolutionary Guard Corps (IRGC), used this new malware as part of an intelligence collection campaign between April and July 2024.

    Throughout these attacks, the threat actors leveraged Microsoft Azure infrastructure for command-and-control (C2), using fraudulent, attacker-controlled Azure subscriptions that the company has since disrupted.

    APT33 breached targeted organizations in the defense, space, education, and government sectors following successful password spray attacks between April and May 2024. In these attacks, they attempted to gain access to many accounts using a small number of commonly used passwords to avoid triggering account lockouts.

    “While the password spray activity appeared consistently across sectors, Microsoft observed Peach Sandstorm exclusively leveraging compromised user accounts in the education sector to procure operational infrastructure. In these cases, the threat actor accessed existing Azure subscriptions or created one using the compromised account to host their infrastructure,” Microsoft said.

    The Azure infrastructure they gained control of was used in subsequent operations targeting the government, defense, and space sectors.

    “In the past year, Peach Sandstorm has successfully compromised several organizations, primarily in the aforementioned sectors, using bespoke tooling,” Microsoft added.

    The Iranian threat group also used this tactic in November 2023 to compromise the networks of defense contractors worldwide and deploy FalseFont backdoor malware.

    In September, Microsoft warned of another APT33 campaign that had targeted thousands of organizations worldwide in extensive password spray attacks since February 2023, leading to breaches in the defense, satellite, and pharmaceutical sectors.

    Microsoft has announced that starting October 15, multi-factor authentication (MFA) will be mandatory for all Azure sign-in attempts to protect Azure accounts against phishing and hijacking attempts.

    The company has previously found that MFA allows 99.99% of MFA-enabled accounts to resist hacking attempts and reduces the risk of compromise by 98.56%, even when attackers attempt to breach accounts using previously compromised credentials.