Hackers Can Control Your PC With This 17 Year Old Microsoft Word Bug

With the growing size of software every year, it’s entirely possible that some unattended vulnerability can allow hackers to take advantage of the software and compromise computers.
The case of MS Office is no different. A recently patched 17-year-old remote code execution bug (CVE-2017-11882) is known to have acted as the Nitrous boost for the Cobalt malware which uses the famous tool Cobalt Strike used for penetration testing.

The bug exists in MS Office when the software fails to properly handle the objects in memory. If a user has admin rights, the scope of the attack worsens as an attacker can issue commands and take control of the machine. The list of affected Microsoft products include:

Office 2016 (32-bit & 64-bit)
Office 2013 SP1 (32-bit & 64-bit)
Office 2010 SP2 (32-bit & 64-bit)
Office 2007 2007 SP3
The security patch was made available to the users earlier this month. According to Fortinet, the actors were quick to take advantage of the vulnerability and tried to fulfill their deeds.

//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js(adsbygoogle = window.adsbygoogle || []).push({}); Fortinet has reported the Cobalt malware campaign that targeted Russian speakers with a spam mail, including an RTF document containing the malicious code, notifying about some policy changes in Visa payWave service.

Cobalt malware ms office 1
Fake notification mail
The RTF document was password protected (credentials provided in the mail) to prevent it from being detected. An archive file containing the body of the email was also present in the email.

cobalt malware ms office 2
Attached document
One thing that looks odd and can be used to spot something fishy is when the document is opened, it runs a PowerShell script and downloads Cobalt Strike tool to gain control of the system.

The security firm notes that the attackers used “trusted Microsoft Windows tools to run client-side scripts, which can be overlooked by traditional AV products.” They were able to load the Cobalt module with writing it as a physical file.

Users are recommended to install the security update to reduce the risk of such attack vectors.
Link : hackers-can-control-pc-microsoft-bug-cobalt-malware

10 Reasons Why Your Computer Hates You More Than Ever | Fix Slow Computer

Do you use a computer nowadays? The answer could be yes because that might be the machine you’re using to read this post. So, without doing any useless talk, let’s come to the point. What is the reason you think our computers or any other hardware run into problems? It could be one or many.
Other than the obvious and inevitable ones like aging, unexpected power surge, hardware failure, people not taking good care of their computer can be a topic of utmost concern. It can reduce the life expectancy of your machine and make it slower by the day.

Tech, computer

Why your computer hates you? Why is it so slow?
//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js (adsbygoogle = window.adsbygoogle || []).push({}); So, if you’re among the careless ones and do one or many things mentioned below, your slow computer would most likely hate you if it were a person.

1. You deprive your PC of software updates and security patches

If you want to know the answer to the question “Why is my computer so slow?”, Chances are high you may find it on the software update screen. You might realize that tons of software updates and bug fixes are pending.

Software updates are important; your vendor might have done changes and updates to improve the machine’s overall performance.

So, not letting your computer update regularly would deprive it of new features, as well as, security patches for the latest bugs discovered now and then. And you should also keep the virus definitions of your antivirus software up to date.

The same goes for other software you’re using on your computer. Problems related to a particular app can affect the overall performance of your system.

2. You don’t care if there is dust and filth are all over your computer

dust inside computer

I can recall days in college, my roommate’s computer had layers of dust deposit, and he didn’t even take the pain to wipe it once in months.

If you want to prevent your computer from dying a premature death, keep in mind, dust and electronics don’t go along, ever. It shouldn’t be a thing that you have to wash your hands after using your computer.

Dust deposit also occurs inside a computer around the cooling fan, thus, trapping the outbound heat from the components within the body itself. Eventually, the internal hardware wears out faster than it should, and it is a reason for a slow computer over time. So, you need to keep your computer neat and tidy if you want it to last for a few years. Don’t forget to read our article on how to prevent your computer from overheating.

3. You don’t think before downloading stuff

System Update Malware Main

Don’t be that person who just fills their computer with things he doesn’t even know what they do or if they’re needed. It’s also the case that people don’t pay attention while downloading or installing software and end up getting adware and other freebies.
//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js (adsbygoogle = window.adsbygoogle || []).push({}); These free tools can be bad for your computer and might open gates for malware invasion. That’s how ransomware sneaks into people’s computer. Becuase they click any random link and the rest happens in the background. Consider using some anti ransomware tools if you think some ransomware might land on your computer.

4. You’ve stored digital garbage on your hard drive

garbage in computer hard drive

Now, filling your hard drive with data won’t cost anything to you nor me. It’s your hard drive, and you can do whatever you want. But doing the same on a regular basis might upset your computer, especially, if most of the data is absolute garbage. Like, the photos of your childhood crush that are still lying in that hidden folder, or the videos in the study folder you have already watched.

In the case of Windows, features like System Restore and Hibernate require some space on your hard drive to store related data. Moreover, keeping unnecessary things on your hard drive increases work for the antivirus software and the defragger, as they have to handle more files while scanning.

Filling the hard drive up to the brim can have its disadvantages. Your PC needs some space vacant to work efficiently. The recommended amount of free space you should leave is between 10 to 15%, if you can manage more, it would be better.

Here is how you can free up around 20GB of hard drive space in Windows 10. To get more space, you should regularly clean the recycle bin and temporary files.

5. You load tons of programs during startup

Another answer to “Why is my computer so slow?” is that you allow too many applications to load on startup. Not to mention, most of them are installed by the OEM. Your PC will definitely hate you if you’re lazy enough to disable the unnecessary ones.

Slow computer fix: disable startup programs

disable startup programs windows 10

In Microsoft Windows 10, you can disable startup program by visiting Task Manager > Startup. Click the desired application in the list and click Disable. Similarly, you can prevent apps from loading at startup on your other operating systems like MacOS, and Linux distros. Similarly, you can read various other tips and tricks to make your Windows PC faster and improve performance.

6. You never shutdown or restart your computer

shutdown computer

Many people are often confused if they should keep their PC running forever, properly Shutdown after every use, or at least, Restart it once in a while. You can clear your confusion by reading our detailed post on whether you should restart your PC or not.

A system restart clears your computer’s RAM and shuts down all the processes. It helps the system get a fresh start after incidents of freezing or software crash, and solve problems like RAM leakage, or broken installations. So, use this slow computer fix and reduce your worries.

Read our complete guide explaining the difference between Fast Startup, Hybrid Sleep, Hibernate, Sleep, Shutdown

7. You never fix issues on your computer

Now, some apps or malware has been messing around with your system for a while, and you don’t seem to care much because all you believe is Netflix and chill, and Facebook. As a response, your angry computer slows down to the level that one day you can’t use it. Then you’ll be left with two choices: fix what’s broken or get a new machine.

Software related problems can be easily fixed. Like you can repair your hard drive using various tools mentioned in this post. For Windows, various common issues include the 100% disk usage, high RAM and CPU usage due to the ntoskrnl.exe process, etc.

You shouldn’t forget the hardware part. A faulty RAM chip or a hard drive going rogue can cause problems for your computer. It would make the computer lag and crash more often. So, consider replacing malfunctioning hardware as soon as possible.

8. You connect to unknown WiFi networks

free wifi public places

Everything that’s labeled “free” isn’t always good. Things are similar in case of WiFi. If you find open WiFi networks at public cafes, airports, parks, don’t immediately rush to connect to the network and soak some internet out of it. And here I am not talking about the WiFi networks other than ones authorities have deployed as a part of customer service.

The free WiFi network could be bait set up by some attacker trying to get access to people’s computer using different WiFi hacking apps to steal information and install malicious stuff including ransomware.

Moreover, you should turn off the Bluetooth radio on your computer. It’s also equally vulnerable as tons of attack vectors take advantage of Bluetooth.

9. Your computer’s security isn’t tight enough

computer security

Do you use the most famous password, 123456? Then you’re very well putting your innocent PC which thinks it’s password-protected at risk.

For various password cracking tools, guessing your so-called strong password is like a child’s play. Here are some tips sourced from experts that can help you create hard to crack passwords. If you are running Microsoft Windows, you can try these alternative sign-in options instead of typing a password.

10. You’re running your daddy’s operating system

OLD COMPUTER

Even though I still have a soft corner for Windows XP, I won’t prefer the deceased veteran over Windows 10. Apart from the feature updates offered by the new versions, new operating system versions also enhance the security by fixing bugs discovered in the past. And since the new OS versions are the part of their developers’ mainstream support, new bugs are fixed first for them.
//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js (adsbygoogle = window.adsbygoogle || []).push({}); The story is similar in the case of other operating systems, be it the macOS or some Linux distribution. Even your beloved old OS would want you to be a part of the evolution and switch to a newer version.

So, these were some reason I think might slow down your computer, and your digital friend might stop loving you if you don’t change your habits. If you have something to add, you can drop your suggestion in the comments.

Link : https://fossbytes.com/reasons-why-my-computer-slow-fix/

75% Android Apps Track Users With 3rd Party Tools, Says Study

A combined study conducted by a French research organization Exodus Privacy and the Privacy Lab, Yale University concludes that around 3 out of every 4 Android apps track users in some way, using third-party trackers.
While, what one might initially assume, the tracking may not be evil but for advertising, behavior analytics, location tracking, etc.

Exodus Privacy checked more than 300 Google Play apps for the signatures of the 25 trackers currently known to them; 75% of the apps had one or more.

The list of Android apps includes popular names like Uber, Tinder, Spotify, and OKCupid which have a Google-made tracker called Crashlytics. It helps the developers gather details about app crashes, but the tracker can also know about user activity among other features.

Another tracker found is called Fidzup, which is capable of tracking phones and their users through the use of sound inaudible to humans. However, the French company behind the tracker claims that the technology is not used anymore. The tracker profiles created during the study have been uploaded to GitHub (find it here).
//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js (adsbygoogle = window.adsbygoogle || []).push({});
“There is an entire industry based on these trackers, and apps identified as “clean” today may contain trackers that have not yet been identified.” Privacy Lab said in a press release that developer may add app trackers in future versions of their apps.

Everyday users are unknown to most of the trackers used by the apps. Also, the lack of transparency regarding the data collection, transmission, and processing raises privacy and security concerns. Privacy Lab says that network traffic associated with such apps generally hops over multiple countries and legal jurisdictions.

Apps made for iOS weren’t a part of the study, but according to Privacy Lab, the story might not be much different for Apple’s App Store. Many app developers distribute apps for both Android and iOS.

“Android users, and users of all app stores, deserve a trusted chain of software development, distribution, and installation that does not include unknown or masked third-party code.”

The Lab has called app developers and Google itself to introduce more transparency in security and privacy with respect to the app trackers.

The tool used by Exodus Privacy to verify tracker signatures has also been open sourced and uploaded to their GitHub repo.

Link : https://fossbytes.com/android-apps-tracker-google-play/

PHP 7.2 And Kotlin 1.2 Programming Languages Released

Kotlin 1.2

Moving to Kotlin–the latest programming language to get official Android support. JetBrains announced Kotlin 1.2 and called it a major release which will let the devs reuse code between JVM and JS. The release announcement states that now one can write the business logic of an app once and reuse for the backend, browser frontend, and Android mobile app. So, this release supports multiplatform projects.

One should also note that IntelliJ IDEA 2017.3 (it’s being released this week) already comes bundled with Kotlin 1.2. In case you’re using Android Studio or older version of IntelliJ IDEA, you can get the update.
//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js (adsbygoogle = window.adsbygoogle || []).push({});
JetBrains says that they’ve been able to deliver about 25% performance improvement over Kotlin 1.1. In further 1.2.x updates, performance will be further improved.

CompilationSpeed kotlin 1.2
Image: JetBrains
The company has also worked to bring a number of minor improvements to language and standard library, for ex., now there’s a more concise syntax for passing multiple arguments to an annotation.

PHP 7.2

As the second feature update to the PHP 7 series, the PHP development team has shipped the PHP 7.2.0 release. As expected, this releases comes with many improvements and features. You can find the source downloads of PHP 7.2.0 on the downloads page.

As per the release notes, the major improvements and new features include the ability to convert numeric keys in object/array casts, object typehint, counting of non-countable objects, and HasContext as Object.

That’s not all. PHP 7.2 also improves TLS constants to sane values. The Mycrypt extension has been removed and new sodium extension has been added.

“The migration guide is available in the PHP Manual. Please consult it for the detailed list of new features and backward incompatible changes,” PHP 7.2 release announcement adds.

Link : https://fossbytes.com/php-7-2-kotlin-1-2-programming-languages-releas/

Qualcomm Is Looking To Get Apple’s iPhone X And iPhone 8 Banned

The ongoing legal battle between Apple and Qualcomm continues to get messier. The new suit filing (PDF) from Qualcomm aims to ban iPhone X and iPhone 8 models in the US. The company has accused Cupertino of violating a total of 16 patents.
Prior to this development, on November 29th, Apple sued Qualcomm over Snapdragon 800 and 820 processors. As per the claims, the company is violating eight or more patents related to power management.

Coming back to the latest lawsuit, Qualcomm’s claims that Apple violates patents related to memory design, power management, RF transceivers, etc. Some of them are also related to multi-touch displays and how WebOS operated on the Palm Pre.
//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js (adsbygoogle = window.adsbygoogle || []).push({});
“Rather than pay Qualcomm for the technology Apple uses, Apple has taken extraordinary measures to avoid paying Qualcomm for the fair value of Qualcomm’s patents,” the complaint states. It also states that Apple’s founder had boasted in the past that Apple “steals” great ideas of others.

That’s not all. The patent also claims that Apple is infringing copyright while using the technology being used to create the iPhone’s new Portrait Mode effect as well as the well-known tap-to-focus feature of the camera.

Apart from demanding an unspecified amount of payment from Apple and stopping the use of technologies, Qualcomm has also asked in a claim with US International Trade Commission to ban the imports of iPhone X, according to San Diego Tribune.

The company had already filed similar series of claims in July, asking for payments and seeking a ban. This new lawsuit has updated those claims and included the new iPhone models which weren’t released back then.

Link : https://fossbytes.com/qualcomm-iphone-x-iphone-8-sales-banned/