By continuing to use the site or forum, you agree to the use of cookies, find out more by reading our GDPR policy

Attention readers, if you are using Chrome on your Windows, Mac, and Linux computers, you need to update your web browsing software immediately to the latest version Google released earlier today. With the release of Chrome 78.0.3904.87, Google is warning billions of users to install an urgent software update immediately to patch two high severity vulnerabilities, one of which attackers are actively exploiting in the wild to hijack computers. Without revealing technical details of the vulnerability, the Chrome security team only says that both issues are use-after-free vulnerabilities, one affecting Chrome’s audio component (CVE-2019-13720) while the other resides in the PDFium (CVE-2019-13721) library. The use-after-free vulnerability is a class of memory corruption issues that allows corruption or modification of data in the memory, enabling an unprivileged user to escalate privileges on an affected system or software. Thus, both flaws could enable remote attackers to gain privileges on the Chrome web browser just by convincing targeted users into visiting a malicious website, allowing them to escape sandbox protections and run arbitrary malicious code on the targeted systems. Discovered and reported by Kaspersky researchers Anton Ivanov and Alexey Kulaev, the audio component issue in the Chrome application has been found exploited in the wild, though it remains unclear at the time which specific group of hackers. For more and to update your browser visit OUR FORUM.

Google Android users have been put at risk again after it emerged a keyboard app called ai.type previously available on the Play Store has been making millions of unauthorized purchases of premium digital content. The Android app has been downloaded more than 40 million times, according to researchers at Upstream. Hiding in plain sight by masking its activity to spoof apps such as Soundcloud, the rogue Google Android app delivers millions of invisible ads and fake clicks, passing on user data about real views, clicks, and purchases to ad networks. Ai.type is a customizable on-screen keyboard app developed by Israeli firm ai.type LTD, which describes the app as a “free emoji keyboard.” But in the background, without your knowledge, the Android app turns your device into “one of the many bots of the network controlled by fraudsters to commit ad fraud,” says Guy Krief, CEO of Upstream. The app was deleted from the Google Play Store in June, but it remains on millions of Android devices and is still available from other third-party marketplaces. There was a spike in its suspicious activity once removed, the Upstream researchers say. Specifically, Upstream says its Secure-D platform has detected and blocked more than 14 million suspicious transaction requests from 110,000 unique devices that downloaded the ai.type keyboard. It’s one of many rogue Android apps reported in recent weeks. Only last week, researchers at ESET discovered a year-long campaign that saw 8 million installs of adware delivered through 42 apps. It came after ESET researcher Lukas Stefanko published his report detailing the 300 million malicious Android app reports during the month of September. Other recent rogue apps plaguing Android users include spyware and adware. Follow this thread by navigating to OUR FORUM.

Fifty years ago, two letters were transmitted online, forever altering the way that knowledge, information, and communication would be exchanged. On Oct. 29, 1969, Leonard Kleinrock, a professor of computer science at UCLA, and his graduate student Charley Kline wanted to send a transmission from UCLA's computer to another computer at Stanford Research Institute through ARPANET, the precursor to what we now know as the internet. ARPANET connected universities working for the Department of Defense under its ARPA (now DARPA) program for new military technologies. In 1969, only four universities had computers — which, Kline told OZY, were "room-sized ... with under-floor air conditioning" — connected to the network: UCLA, Stanford, University of California, Santa Barbara (UCSB) and the University of Utah. The message sent by Kleinrock and Kline was intended to be "login." Their system crashed, however, as soon as they typed the second letter. It took an hour to send the whole word, but by then, "lo" cemented its place in the internet's history. For Kleinrock, the message took on a completely different meaning, anyhow. “‘L’ and ‘O’ is ‘hello,’ and a more succinct, more powerful, more prophetic message we couldn’t have wished for," he told OZY. Two years later, in 1971, the first email was sent by MIT researcher Ray Tomlinson — which was also the first time the "@" sign was used to designate a specific recipient of a message. The World Wide Web, as we know it now, didn't get invented until 1989, when British computer scientist Tim Berners-Lee invented the web and the technologies to access, create and share web pages. He published the first web page in 1991. Browse over to OUR FORUM for more on this milestone.