adplus-dvertising
Connect with us

Tech

Exclusive: Massive spying on users of Google's Chrome shows new security weakness – Reuters

Published

 on


SAN FRANCISCO (Reuters) – A newly discovered spyware effort attacked users through 32 million downloads of extensions to Google’s market-leading Chrome web browser, researchers at Awake Security told Reuters, highlighting the tech industry’s failure to protect browsers as they are used more for email, payroll and other sensitive functions.

FILE PHOTO: The logo of Google is seen in Davos, Switzerland Januar 20, 2020. Picture taken January 20, 2020. REUTERS/Arnd Wiegmann

Alphabet Inc’s (GOOGL.O) Google said it removed more than 70 of the malicious add-ons from its official Chrome Web Store after being alerted by the researchers last month.

300x250x1

“When we are alerted of extensions in the Web Store that violate our policies, we take action and use those incidents as training material to improve our automated and manual analyses,” Google spokesman Scott Westover told Reuters.

Most of the free extensions purported to warn users about questionable websites or convert files from one format to another. Instead, they siphoned off browsing history and data that provided credentials for access to internal business tools.

Based on the number of downloads, it was the most far-reaching malicious Chrome store campaign to date, according to Awake co-founder and chief scientist Gary Golomb.

Google declined to discuss how the latest spyware compared with prior campaigns, the breadth of the damage, or why it did not detect and remove the bad extensions on its own despite past promises to supervise offerings more closely.

It is unclear who was behind the effort to distribute the malware. Awake said the developers supplied fake contact information when they submitted the extensions to Google.

“Anything that gets you into somebody’s browser or email or other sensitive areas would be a target for national espionage as well as organized crime,” said former National Security Agency engineer Ben Johnson, who founded security companies Carbon Black and Obsidian Security.

The extensions were designed to avoid detection by antivirus companies or security software that evaluates the reputations of web domains, Golomb said.

If someone used the browser to surf the web on a home computer, it would connect to a series of websites and transmit information, the researchers found. Anyone using a corporate network, which would include security services, would not transmit the sensitive information or even reach the malicious versions of the websites.

“This shows how attackers can use extremely simple methods to hide, in this case, thousands of malicious domains,” Golomb said.

All of the domains in question, more than 15,000 linked to each other in total, were purchased from a small registrar in Israel, Galcomm, known formally as CommuniGal Communication Ltd.

Awake said Galcomm should have known what was happening.

In an email exchange, Galcomm owner Moshe Fogel told Reuters that his company had done nothing wrong.

“Galcomm is not involved, and not in complicity with any malicious activity whatsoever,” Fogel wrote. “You can say exactly the opposite, we cooperate with law enforcement and security bodies to prevent as much as we can.”

Fogel said there was no record of the inquiries Golomb said he made in April and again in May to the company’s email address for reporting abusive behavior, and he asked for a list of suspect domains. Reuters sent him that list three times without getting a substantive response.

The Internet Corp for Assigned Names and Numbers, which oversees registrars, said it had received few complaints about Galcomm over the years, and none about malware.

While deceptive extensions have been a problem for years, they are getting worse. They initially spewed unwanted advertisements, and now are more likely to install additional malicious programs or track where users are and what they are doing for government or commercial spies.

Malicious developers have been using Google’s Chrome Store as a conduit for a long time. After one in 10 submissions was deemed malicious, Google said in 2018 here it would improve security, in part by increasing human review.

But in February, independent researcher Jamila Kaya and Cisco Systems’ Duo Security uncovered here a similar Chrome campaign that stole data from about 1.7 million users. Google joined the investigation and found 500 fraudulent extensions.

“We do regular sweeps to find extensions using similar techniques, code and behaviors,” Google’s Westover said, in identical language to what Google gave out after Duo’s report.

Reporting by Joseph Menn; Editing by Greg Mitchell and Leslie Adler

Let’s block ads! (Why?)

728x90x4

Source link

Continue Reading

Tech

Aaron Sluchinski adds Kyle Doering to lineup for next season – The Grand Slam of Curling

Published

 on


Aaron Sluchinski’s team announced Wednesday on social media that Kyle Doering has joined the club for next season.

300x250x1

Sluchinski was searching for a new player after second Kerr Drummond stepped back from competitive curling late last month. The Airdrie, Alta., team also includes third Jeremy Harty and lead Dylan Webster.

Sluchinski had a breakout season, winning the Boston Pizza Cup to represent Alberta at the Montana’s Brier for the first time and also competed in three Grand Slam of Curling events. The team finished 16th in the world rankings and seventh among Canadian clubs.

Doering has spent the past two years playing with Edmonton’s Karsten Sturmay and was also on the lookout for a new squad after his skip announced his departure from competitive curling.

Winnipegger Doering earned a silver medal at the world men’s curling championship earlier this month as the alternate on Team Canada, skipped by Brad Gushue.

Doering captured the Canadian junior title and a world junior bronze medal in 2016 playing with skip Matt Dunstone.

The Canadian men’s curling landscape has seen several shifts in recent days. Brendan Bottcher’s teammates announced Tuesday they were looking for a new skip and Reid Carruthers’ team revealed Wednesday it has parted ways with skip Brad Jacobs.

Skip Glenn Howard also announced his retirement Tuesday.

Meanwhile, skip John Epping unveiled his new team last week, featuring third Tanner Horgan, second Jacob Horgan and lead Ian McMillan.

Adblock test (Why?)

728x90x4

Source link

Continue Reading

Tech

New EV features for Google Maps have arrived. Here’s how to use them. – The Washington Post

Published

 on


Google has announced new features in its Maps app designed to help electric car drivers find a charge.

The updates include a tool to help drivers find nearby chargers with real-time information about availability and charging speed, the ability to find charging stops on longer road trips and more detailed instructions about how to find chargers within parking lots and garages.

Google expects to start rolling out these features “in the coming months,” according to a blog post. Some will come first to people who drive a car that comes with “Google Built-in,” the company’s driver-assistance software. Google updated its other route-finding app, Waze, with information on EV chargers last month.

300x250x1

The update addresses one of Americans’ top concerns about owning an electric vehicle: finding a place to charge. Range anxiety remains a significant barrier for EV sales — especially for drivers who don’t own a house. Among people who don’t drive an EV, roughly half say they think finding a place to charge would be “extremely” or “very” difficult, according to a 2023 Washington Post-University of Maryland poll.

EVs make up roughly 7 percent of new U.S. car sales, which some experts believe is a tipping point at which electric cars will quickly become popular and take over the market. But lately, the EV market appears to be cooling off. Sales slowed in the first quarter of this year.

In addition to building more charging stations, companies can make driving an EV easier by building apps that help drivers find chargers, said Stephanie Valdez Streaty, director of Industry Insights at Cox Automotive. “That could be really helpful with mitigating some of those concerns about charging anxiety,” she said.

Find available EV charging stations

For electric-car drivers who need a last-minute charge, Google is developing a feature that can find nearby chargers with updated information about how many ports are available and their charging speed. The company says this feature will eventually be available to all drivers but will be available first for drivers with Google Built-in.

Plan a road trip with EV charging stops

The Maps update will allow EV owners with Google Built-in to plan where they can power up when taking long trips with multiple stops, such as a cross-country road trip. The feature will access information about your car’s battery life to suggest the best places to charge up.

The company also announced a search feature that allows travelers to look for hotels with electric car chargers.

Locate hard-to-find EV charging stations

Some EV chargers are tucked in hard-to-find corners of parking garages. The Maps update will crowdsource information from Google reviewers to generate more detailed instructions about how to get to a charger. According to the company’s blog post, the instructions might read something like, “Enter the underground parking lot and follow the signs toward the exit. Just before exiting, turn right.”

Adblock test (Why?)

728x90x4

Source link

Continue Reading

Tech

Cytiva Showcases Single-Use Mixing System at INTERPHEX 2024 – BioPharm International

Published

 on


The Xcellerex magnetic mixer, single-use mixing system was designed to address challenges in large-scale mAb, vaccine, and genomic medicine manufacturing processes.

Cytiva unveiled the Xcellerex single-use magnetic mixer at INTERPHEX 2024 in New York City on April 16, 2024. The single-use mixing system was designed to combat challenges in large-scale monoclonal antibody (mAb), vaccine, and genomic medicine manufacturing processes. The mixer is offered in 2000 L and 3000 L capacities and can be configured in several ways to accommodate diverse mixing processes. Its compact size benefits facilities with space constraints or complicated installation of large-scale consumables.

According to the company, minor leaks may cause significant delays and losses. “When dealing with a 3000 L batch of cell culture media, the estimated financial loss can cost between $60k to upwards of $100k” (1). The system helps prevent expensive leaks with a novel mixer biocontainer that incorporates user-centered design elements to improve durability and ease of use. The design provides enhanced safeguards and added protection from leaks that may occur during shipping, storage, and operation.

300x250x1

Time taken to mix batches can inhibit product development times, specifically the challenge of mixing floating powders such as cell culture media. Current systems have underpowered impellers with circular or cubical shapes that make producing large volumes challenging, according to Cytiva. This new single-use system “has a powerful impeller that when combined with the mixer’s hexagonal shape creates a vortex, enhancing the interaction at the liquid surface. This vortex effectively pulls down the floating powders into the main body of the liquid to allow for a more efficient and shorter mixing process,” the company stated in a press release.

“We’re tapping into our differentiated portfolio to solve a wide range of challenges for our customers. Our new magnetic mixing system is flexible and capable of meeting the many demands and constraints during buffer and cell culture media preparation,” said Amanda Halford, president, Bioprocess at Cytiva in the release. “By reimagining the design, we’ve tackled some of the biggest obstacles to downtime.”

Advertisement

Cytiva is also working to advance messenger RNA (mRNA) manufacturing. In an interview with Pharmaceutical Technology EuropeTM , Scott Ripley, general manager, Nucleic Acid Therapeutics and Precision Nanosystems at Cytiva, discussed technology that enables the “democratization” of mRNA manufacturing (2). Many mRNA therapies and other types of genetic medicines in clinical development are designed to be delivered with the help of lipid nanoparticles. One such platform is Cytiva’s Precision Nanosystems NanoAssemblr microfluidic-based nanoparticle manufacturing platform, which enables the development of genetic medicines with potentially increased stability, efficacy, yield, and quality of non-viral genetic medicines, according to Ripley.

Ripley was enthusiastic about this platform’s ability to “democratize” the good manufacturing practice (GMP) manufacturing aspects for advanced therapies, while managing to cope with the increased molecular diversity of the molecules being handled.

“For example,” Ripley says, “the mRNA platform is unique in that, on one end of the spectrum, it is vaccinating the planet, on the other end, it’s personalized cancer vaccines.”

Reference

1. Cytiva. Cytiva Unveils Latest Innovation for Large Scale Mab, Vaccine, and Advanced Therapy Manufacturing Processes–The Xcellerex Compact Single-Use Magnetic Mixing System. Press Release. April 16, 2024.
2. Spivey, C. Democratizing GMP Manufacturing for the New Therapeutic Pipeline. PharmTech.com. Nov. 21, 2023.

Adblock test (Why?)

728x90x4

Source link

Continue Reading

Trending