Home Top Ad

Responsive Ads Here

Movies with killer computers are nothing new. From Hal 9000 in 2001: A Space Odyssey to M3GAN , computers, dolls, and robots that become s...

Movies with killer computers are nothing new. From Hal 9000 in 2001: A Space Odyssey to M3GAN, computers, dolls, and robots that become sentient and turn sinister make for a bloody good time at the cinema. It's also the basis for many of the best sci-fi horror movies.

Nowadays, however, AI is everywhere, from inside the Mac I’m writing this article with to the smartphone you’re reading it on, it’s impossible to hide from it. And what happens when there’s a new buzzword or trend in town? Hollywood flocks to it and doubles down. Enter AfrAId, a movie about an AI that wants to kill you, and the horror film you probably shouldn't watch this Halloween Week.

AfrAId tells the story of a family whose lives are turned upside down after the father, Curtis, brings AIA, an Alexa-esque voice assistant, into their home. For AIA to work, “eyes” are installed throughout the house, small smart home cameras, tracking everything the family does and feeding the information back to the AI assistant. It’s a pretty unsettling vision of the smart assistant future, but it’s also incredibly corny. If, like me, you spend most of your time on the internet, then you’ll have been inundated with AI information over the last few years, and because of this, AfrAId feels like AI bingo, trying to fit as many buzzwords from pop culture in as possible in just 84 minutes.

AIA can do everything, from pay the family’s bills, teach the children, and even bribe them with points to use on rewards in exchange for doing house chores - It’s all a bit ludicrous, but then again did you expect deepfakes to be as realistic as they are now just a couple years ago?

Was this written by AI?

Horror films strive on the surreal, right? So criticizing AfrAId for being unrealistic would be unfair, but when bad writing, a silly plot, and poor acting combine with a tired premise, it makes the film a genuine chore to watch.

I got about 20 minutes into the movie before I couldn’t help but sigh at every reference thrown into the mediocre script. ChatGPT, Alexa, Minecraft, Cordyceps from The Last of Us, Atrial Fibrillation, and even The Emoji Movie makes an appearance. Honestly, AfrAId is exhausting, as if a group of writers (or an AI) decided to write a movie just to tick the boxes.

You know exactly how this film goes: AIA infiltrates the home, becomes sinister, bribes the kids, and causes mayhem - it’s a simple premise, and an incredibly tired one.

So why am I writing about AfrAId? I hear you ask. Well, considering there are AI horror films being churned out faster than the next AI image generator, I thought it was my duty to watch this one, so you don’t have to. My favorite quote from AfrAId comes in the form of a sales pitch from AIA’s creators, “We want to understand people then ask their permission to tell them stories they can believe in and feel a part of. That’s how you cut through the chatter of the internet and the millions of mouths whispering at you, the millions of eyes watching you. Because that is what people want, not a product, they want empathy, connection, community.”

This quote is incredibly ironic because the film completely misses the mark on giving people what they want. AfrAId is a quick cash grab without any of the thrills you want from a horror, and even if you’re interested in AI you should just avoid it completely.

You might also like



from TechRadar - All the latest technology news https://ift.tt/csrIpYl

ASRock Rack's TURIN2D48G-2L+ is a sizable new server motherboard designed to handle the most demanding needs of high-performance comput...

ASRock Rack's TURIN2D48G-2L+ is a sizable new server motherboard designed to handle the most demanding needs of high-performance computing.

Supporting dual AMD EPYC 9005/ 9004 series processors, including the top-tier 192-core EPYC 9965, this motherboard is engineered for maximum power and memory capacity.

With 48 DIMM slots - 24 per CPU socket - it can support up to 96GB per RDIMM and up to 512GB per RDIMM-3DS module (for a total of 24.6TB), offering substantial memory scalability. The board also supports DDR5 memory with frequencies of up to 5200MHz for single DIMMs per channel (1DPC), or 4400MHz when utilizing two DIMMs per channel (2DPC).

For the most demanding workloads

The TURIN2D48G’s layout has been designed specifically to accommodate these massive memory and processing requirements. Measuring 18" x 16.9", the board can support CPUs with a TDP of up to 500W, ensuring that even the most power-hungry processors are adequately managed. To fit the 48 DIMM slots the CPU sockets have been offset.

In addition to offering more memory capacity than many competing platforms, the motherboard offers impressive PCIe and storage capabilities. It supports 12 MCIO slots (PCIe 5.0/CXL 2.0 x8), along with up to 34 SATA 6Gb/s connections, and two M.2 slots also provide further storage options, each supporting either PCIe 3.0 x4 or SATA 6Gb/s drives.

Networking is handled by two RJ45 1GbE ports powered by Intel’s i350 controller, and remote management is available via integrated IPMI with a dedicated management LAN port.

The TURIN2D48G is designed to shine in environments where massive memory and high core counts are critical. Its support for CXL 2.0 and PCIe 5.0 promise fast communication between processors, memory, and peripherals, while the integrated cooling options, with support for high-powered CPUs, make it suitable for the most demanding workloads like AI training and large-scale data analysis.

ServeTheHome got a firsthand look at the motherboard during AMD's AI event following the launch of the EPYC 9005 Turin and noted, “Something neat about this motherboard is that beyond supporting a huge number of cores and DIMMs, it is also offers something Intel does not have. The Intel Xeon 6900P also has 12 channel memory, but can only support 1 DIMM per channel. As a result, the 12-channel 2DPC offering from AMD offers something beyond just the maximum raw core count for AMD EPYC Turin platforms over Intel Xeon platforms. It is also cool to see such a large motherboard!”

More from TechRadar Pro



from TechRadar - All the latest technology news https://ift.tt/WxNJFwO

Gemini 2.0 could be arriving in December Expect across-the-board performance improvements ChatGPT-5 may be launched at the same time ...


  • Gemini 2.0 could be arriving in December
  • Expect across-the-board performance improvements
  • ChatGPT-5 may be launched at the same time

It was only a few days ago we heard rumors around OpenAI launching a next-gen ChatGPT-5 model – rumors dismissed as "fake news" by OpenAI chief Sam Altman – and now we're hearing Google Gemini 2.0 could be made public in the next couple of months.

Like the ChatGPT rumor, this comes from The Verge (via 9to5Google). The last major Gemini upgrade came back in February, when Gemini 1.5 was pushed out. Google uses the Gemini name for both its AI bots, and the underlying models.

What we don't get in this report are any indications of what might be new and improved in Gemini 2.0. If previous releases are anything to go by, expect smarter answers, faster processing, support for longer inputs, and more reliable reasoning and coding.

As per the report, Gemini 2.0 doesn't offer the sort of performance increases its developers were originally hoping for – but the article also notes that this is a trend affecting all large language models (LLM) in general, not just those at Google.

Keeping up the pace

Google Gemini AI

Gemini (the app) runs on Gemini (the AI model) (Image credit: Google)

If Google (and perhaps OpenAI) did indeed launch AI model upgrades before the end of the year, it would be further evidence of the time and resources that companies are investing in artificial intelligence in order to stay ahead.

In recent weeks we've seen new video tools, improved image generation, and bespoke search features launched by AI companies. When next week rolls around, meanwhile, millions of iPhone owners will be able to try out Apple Intelligence for the first time..

That said, we're still waiting for Google to launch the next-gen Project Astra AI assistant we saw demoed at Google I/O 2024 back in May. Project Astra combines multiple inputs and outputs in a more advanced and natural way than ever.

While we have previously spent some hands-on time with Project Astra, it doesn't seem as though it's directly connected to Gemini 2.0 – though it may be powered by it. Of course as soon as anything is made official, we'll bring you the news here.

You might also like



from TechRadar - All the latest technology news https://ift.tt/IrRWvPY

I recently started using an iPhone 15 after five years away from Apple smartphones, and as my prior pieces on the iPhone’s lackluster 60Hz...

I recently started using an iPhone 15 after five years away from Apple smartphones, and as my prior pieces on the iPhone’s lackluster 60Hz screen and satisfyingly nostalgic form factor may have let on, coming back to iOS has been a bit of a rollercoaster.

There is one thing about the iPhone that I’m unreservedly happy about, though, a feature that I’m happy to call the best in its class.

It’s not the Dynamic Island with its useful notifications, nor the 48MP main camera with its excellent low-light performance, nor the USB-C port with all its interconnectivity – in fact, my favorite thing about the iPhone 15 is something that’s been part of the iPhone lineup since the very beginning.

I’m talking about the humble speaker, situated along the bottom edge of the iPhone 15 and paired with the speaker grille along the top of the screen for stereo sound. I have been continually amazed by how fantastic this tiny dual-channel system sounds, especially compared to the other handsets in my rotating smartphone loadout.

Sounding off

iPhone 15 review images

(Image credit: Future / Lance Ulanoff)

As a lover of both music tech and consumer tech, I’ve found myself genuinely confused at how Apple has managed to wring so much bass and presence out of such a physically small speaker, but at full volume I find I’m able to hear songs clearly from any room in the house.

I can clearly remember a time when phone speakers were something of an afterthought, a definitively sub-optimal way of listening to music on a phone. My first ever smartphone, an early HTC One, had a speaker grille about a centimeter wide that sounded predictably atrocious.

However, this didn’t stop me from listening to music on it – I’ve continued to use phone speakers in the years since, mostly just to put something on while I’m doing chores or getting ready to head out.

That said, the iPhone 15 is the first phone I’ve used that I feel offers a proper listening experience, rather than just a way to have something playing.

Lately, I’ve found myself eschewing the Amazon Echo smart speaker and Presonus Eris 3.5 monitors I’ve got dotted around the house for the convenience of the iPhone – it’s physically impossible to replicate the rich sound of a 3-inch speaker with a smartphone, but the iPhone 15 gets close enough that I rarely feel like I'm missing out for background listening.

It’s not that I don’t care about audio quality either – I quite regularly buy music online for the sake of getting the best quality sound and even produce my own music. The blend of simplicity and quality offered by the iPhone is just really tough to beat.

In fact, with the option of proper speakers already in place and portability solved by the iPhone, I find that I’m not tempted by even the best Bluetooth speakers – a necessity in my music listening arsenal in years past.

Overall, the iPhone 15 is a reminder of Apple’s engineering prowess and just how far the phone speaker has come. Audio is rarely the reason a phone makes it to our list of the best phones, but music lovers shouldn’t ignore this underrated aspect of the iPhone experience.

You might also like



from TechRadar - All the latest technology news https://ift.tt/BhUCPNG

In the past, OnePlus has revealed details of its handsets bit by bit as launch day approaches, and it's the same for the OnePlus 13 : t...

In the past, OnePlus has revealed details of its handsets bit by bit as launch day approaches, and it's the same for the OnePlus 13: the official unveiling is on Thursday, October 31, but we already know the camera specs for the upcoming flagship.

OnePlus confirmed the information in a post on Chinese social media platform Weibo (via Android Authority). There are three cameras on the back, which are a 50MP main camera, a 50MP periscope lens, and a 50MP ultrawide camera with a 120-degree field of view.

While the main camera matches the OnePlus 12, the other two have been given an upgrade. The periscope lens offers 3x optical zoom with an f/2.6 aperture, optical image stabilization, and a 1/1.95-inch sensor.

As our OnePlus 12 review will tell you, the existing flagship has a zoom camera with more megapixels but a smaller sensor size. In theory, those changes should mean better end results, especially when it comes to low light photos.

Picture samples

Image 1 of 2

OnePlus 13 camera sample

Camera samples for the OnePlus 13 (Image credit: OnePlus)
Image 2 of 2

OnePlus 13 camera sample

Camera samples for the OnePlus 13 (Image credit: OnePlus)

Other pieces of information that are now confirmed tell us the OnePlus 13 will support 4K and 60 frames per second video recording, with Dolby Vision, and higher quality Live Photos (images with a small amount of movement attached).

OnePlus has also taken to Weibo (via Android Headlines) to post some sample images from the OnePlus 13, so you can just for yourself how the quality stands up – particularly when it comes to the portrait and motion capture modes.

We now know a lot about this phone ahead of its full unveiling. OnePlus has previously shown off three colors for the handset, and we've also been told the device is going to feature the brand new Snapdragon 8 Elite processor from Qualcomm.

There have also been rumors swirling about a significant battery capacity upgrade, and an unboxing has already shown up online. It should be available in China on October 31, with a global release sometime early in 2025.

You might also like



from TechRadar - All the latest technology news https://ift.tt/UrCxMA3

The internet was flooded with iPad mini 7 reviews this week after Apple's quiet announcement of the mini tablet on October 15. Given i...

The internet was flooded with iPad mini 7 reviews this week after Apple's quiet announcement of the mini tablet on October 15. Given it's been three years since we last saw Apple launch an 8.3-inch iPad, surely it's a must-buy for tablet fans? According to those reviews, the answer is a little more complex than you might expect.

This is because the mini 7 is, most agree, something of a mixed bag. It now has an A17 Pro chip (for Apple Intelligence), supports the Pencil Pro, boosts its base storage to 128GB, and comes in fancy new colors. But its design and screen are also, among other things, the same as before. And that's disappointing to some who had lofty expectations for the tablet.

So, how did the iPad mini 7 perform in its various benchmarking tests and real-world scenarios? And what exactly can you use it for? We've gathered and summarized the biggest iPad mini 7 reviews so far in one handy place so you can decide if it's worth spending $499 / £499 / AU$799 – starting, of course, with TechRadar's own iPad mini 7 review.


TechRadar: 'A premium mini tablet experience that still captivates'

Our iPad mini A17 Pro (2024) review praised the performance of Apple's new mini tablet, despite its inclusion of an older A17 Pro chip. In our GeekBench 6 tests, the scores show a significant performance jump from the iPad mini 6, which also supports Apple Intelligence features.

On the downside, the iPad mini 7 is otherwise largely identical to its predecessor. As we noted, "Apple didn't bother to upgrade the design, the screen, the cameras, or the speakers."

Our battery life tests showed that it also provides just over ten hours of battery life, which is about par for an 8.3-inch tablet. Still, while it isn't an exciting upgrade, we enjoyed our time with the iPad enough to give it four-and-a-half stars and a 'recommended rating.'

The good

  • Perfectly portable
  • Excellent build
  • Lovely screen
  • A great Pencil Pro companion

The bad

  • Pricey for the size
  • Aging design
  • FaceTime camera still on the short side of the screen

The Verge: 'The new Mini isn't much of an upgrade at all'

The new iPad mini 7

(Image credit: Future)

The most critical take on Apple's new mini tablet so far has come from The Verge. It even says the mini 7 "represents a new low for the product," while also stating "if you want an iPad mini, buy this one."

Those two statements can coexist in the same review because The Verge has grand visions of what the iPad mini could be, which the new version falls short of. The mini 7 "feels like an iPad designed by a supply chain," its review notes, and is best for those who want a small screen combined with a great Apple Pencil experience.

Like our tests, The Verge's benchmarking showed some useful real-world performance boosts from the mini 6, noting that everything is "one beat faster than the last model." But the elephant in the room is Apple Intelligence.

We don't yet know how good that will be, and The Verge concludes that unless it's "game-changingly incredible, there are few good reasons to buy the new iPad Mini instead of the old one."

The good

  • Faster than the last one
  • A delightful size for a tablet
  • Supports the Pencil Pro

The bad

  • Jelly scrolling still present
  • Not as powerful as other iPads
  • Outdated Touch ID and camera placement

CNET: 'Not really taking amazing strides into new territory'

CNET's take on the iPad mini 7 is that while it is underwhelming in many ways, it's also good enough if you've been waiting a few years to buy one.

A couple of interesting points that haven't been widely raised include a lack of new accessories to suit the tablet's form factor. CNET notes that a small Pencil or a small keyboard case would have been nice complements to the mini 7, but neither has arrived.

More annoyingly, the review also notes that the Apple Pencil 2 doesn't work with the new tablet – you need either the Pencil Pro or the cheaper USB-C Pencil. Still, aside from those gripes, CNET concludes that if you've been waiting to get an iPad mini, "it's a great time to get one." Even if, for owners of the iPad mini (2021), "these upgrades may not be that meaningful to you."

The good

  • Compact size
  • Supports Pencil Pro
  • Apple Intelligence capable
  • Base model has 128GB storage

The bad

  • No big design changes
  • Needs smaller Pencil
  • No keyboard case

Engadget: 'Safe, boring and everything I want in a small tablet'

Apple iPad mini A17 Pro

(Image credit: Future/Jacob Krol)

Engadget's iPad mini 7 review is something of a 'glass half full' take on the tablet. While it acknowledges the same limitations as other reviews – the dated screen, old-school design, lack of Face ID and no M-series chip – it still thinks Apple has done enough to deliver "the full iPad experience in a compact package."

The review also discusses in depth what you might actually use the iPad mini for. On a broad level, Engadget says, "It’s an enjoyable secondary device that I mostly used after the workday was done, in place of my MacBook Pro or iPhone."

More specifically, it highlights reading, messaging, gaming, and watching videos as the main use cases – alongside digital art and sketching, if you're inclined that way.

The good

  • Supports the Apple Pencil Pro
  • A17 Pro chip is plenty powerful
  • Finally starts at 128GB of storage
  • Apple may have fixed the jelly-scrolling display issues

The bad

  • Display is limited to 60Hz
  • Bezels are looking a bit thick
  • No Face ID
  • No M-series chip

The verdict: Could be better, but good enough for most people

Apple iPad Mini A 17 Pro (2024) REVIEW

(Image credit: Future / Lance Ulanoff)

The iPad mini 7 has received a pretty lukewarm reception from reviewers (so far). The general consensus is that, while it's far from the best iPad mini that Apple could have made, it is the best small tablet you can buy. And that could be enough for you, depending on your needs.

All the reviews agree that it is a good time to buy an iPad mini for those who have been waiting patiently to do so. Where the conclusions differ slightly is on whether it represents a worthwhile upgrade for current Mini 6 owners.

The answer seems to largely depend on your expectations of the tablet. If you've been waiting for an iPad mini that delivers real-world boosts for gaming, apps, and photo or video editing, the benchmarking results show it delivers that. But if you were hoping for a Pro-level experience, you may still find it wanting.

The iPad mini 7 also supports Apple Intelligence, and while it isn't clear how future-proofed that A17 Pro chip will be down the line, it is another bonus if you're prepared to wait for Apple's AI features to flourish.

You might also like



from TechRadar - All the latest technology news https://ift.tt/b3KkATZ

If you’ve read my previous thoughts on iPhones here at TechRadar and its sibling site Tom's Guide , you’ll know I have fairly firm opi...

If you’ve read my previous thoughts on iPhones here at TechRadar and its sibling site Tom's Guide, you’ll know I have fairly firm opinions on Apple’s smartphones.

Since moving from Android to iPhone at the end of 2021, I’ve not gone back to the platform Google built, despite trying some of the best Android phones. The ease of iOS has taken in me; I love the titanium construction, I’ve found Ceramic Shield glass to be a minor game changer, I enjoy the Action button, and the cameras almost never let me down on iPhones.

But for once, I’m on the fence.

What’s got me pondering is the Camera Control ‘button.’ In some ways, it’s a cool new feature that uses haptics well. In other ways, it’s superfluous and not fully featured.

I’ve been trying out the iPhone 16 Pro Max for a couple of weeks now, and when it comes to capturing a photo, l try and use Camera Control as much as possible. As I’m 37 and a millennial, I still like snapping photos on my phone in landscape orientation, so having a physical button where my finger naturally sits is good for capturing a shot without messing up the framing by tapping on the screen or trying to hit the Action button – I have this mapped to trigger the ‘torch’ anyway, which is surprisingly helpful.

I also like flicking through zoom ranges with a swipe on the Camera Control without the need to tap on small icons. The exposure control is kind of cool, though swapping between the features Camera Control can control doesn’t quite feel intuitive to me yet, and often, my taps cause me to lose the precise design of a scene.

So yeah, Camera Control is interesting. But…

Did anyone really ask for it? It feels like a feature for the sake of Apple’s mobile execs to have something new to talk about at the September Apple event. It’s just about a ‘nice to have’ feature, but it’s hardly a phone photography game changer.

Not my tempo

Apple iPhone 16 Pro Max Hands on

(Image credit: Future / Lance Ulanoff)

However, maybe I’ll warm to it over time. Yet, the biggest issue is the lack of AI tools at launch for Camera Control. Apple actively touts the AI features for Camera Control that can be used to smartly identify things the cameras are pointed at and serve up all manner of information. That hasn’t happened yet, with a rollout arriving post-launch when Apple Intelligence fully arrives; there's a beta option, but I'm not willing to try that on my main phone.

I’ve yet to understand that. Sure, other phone makers have touted AI features that will come after their phones are released and may be limited to certain regions, to begin with, but at least they launch with some of the promised AI suites. The iPhone 16 range launched without any Apple Intelligence features.

This is not what I expected from Apple, a company that famously doesn’t adopt new tech until it’s refined and ready for polished prime time. So, for it to launch smartphones without next-generation smarts is baffling to me. But it’s also the primary reason why I feel torn about Camera Control; if it had Google Lens-like abilities at launch, baked into a hardware format, I can see myself being a lot more positive about Camera Control.

Of course, Apple's use of such a camera button will undoubtedly cause other phone makers to follow suit. I only hope they don’t skimp on features when their phones launch.

As for Camera Control in the here and now, I’ll keep an open mind and keep using it; I’ll just cross my fingers that it'll become seriously handy once it gets its prescribed dose of AI smarts.

You might also like



from TechRadar - All the latest technology news https://ift.tt/89qQ12R

Things are getting spooky round TechRadar way as we kicked off our Halloween Week event, but that hasn't scared off these major announ...

Things are getting spooky round TechRadar way as we kicked off our Halloween Week event, but that hasn't scared off these major announcements from the world of tech.

In fact far from it. After all, this was the week in which Apple teased its M4 Macs, the superb Severance returned to our screens (sort of) and Alien Romulus announced a VHS releases. Yes, really.

Read on for details of all of these stories and more as we recap the week's biggest news, and be sure to check back next week for details on those M4 Macs once they've been officially revealed.

And when you're done, why not read our guide to the seven new movies and TV shows to stream this weekend?

7. Alien Romulus got a release date for Blu Ray… and VHS

The Alien Romulus VHS box

(Image credit: 20th Century Studios / Disney)

Here’s a 2024 story you weren't expecting: Alien Romulus is coming to VHS.

This isn’t just some gimmick prop with a download code, either, with the Alien: Romulus tape being described as a “fully-functional VHS” which will launch in December with a 4:3 aspect ratio, and a vintage-style protective sleeve.

There are a few major questions to be answered – such as how much it’ll cost and how many will be made – but if you’ve been craving that vintage horror movie experience then it’s time to dust off your old VHS player (or buy one on eBay) and look out for Alien Romulus’ VHS tape when it releases.

6. Samsung released a new foldable

The Galaxy Z Fold Special Edition in Black Shadow

(Image credit: Samsung)

Samsung this week gave us the new Galaxy Z Fold Special Edition – well, those of us that live in South Korea. It comes with a handful of upgrades like a 200MP main camera, but will cost you: 2,789,600 won to be precise (or roughly $2,000 / £1,550 / AU$3,000).

The base model already comes in at the fairly steep $1,899.99 / £1,799 / AU$2,749, so fans were hoping Samsung might instead launch a cheaper Galaxy Z Fold Fan Edition (Or FE) to match the Samsung Galaxy S24 FE and its other more affordable phones.

This was shot down by Samsung itself, however, when it announced it has “no plans” to launch a cheap Galaxy Z Fold phone, even though it definitely should.

5. Garmin's all-new beta update arrived for Forerunners

Garmin Forerunner 965

(Image credit: Future)

Owners of recent Garmin Forerunner watches – specifically the Forerunner 965, Forerunner 265, Forerunner 165, Forerunner 955, and the Forerunner 255 – are getting new features as part of Garmin’s public beta program. The headline new abilities are around swimming (with "improvements to support pool swim workout with pace alerts and critical swim speed" and "improvements to the pool swim rest screen and alert tones") as well as an all-new meditation functionality.

Although you have to be signed up to the public beta in order to take advantage of it, Garmin rolling these features out as part of public beta means it’s coming to everyone else’s Forerunners in the near future. As well as top running watches, these changes make the Forerunners excellent swimming watches. Ideal for triathletes and all-rounders.

4. Things got spooky as TechRadar’s Halloween Week began

Michael Myers holding a knife in Halloween

(Image credit: Compass International Pictures )

TechRadar’s Halloween Week is running between now and October 31, and there’s plenty of great stuff to sink your teeth into. Whether you want the latest horror movie recommendations, soundbars for an immersive experience, or animated seasonal movies for the squeamish, it’s all here. Over the next few days you’ll be seeing articles from our Streaming, Gaming, Homes and AI channels, with our experts dishing out top tips to help you have the best Halloween yet.

Some of these recommendations were covered in our latest podcast episode too, so make sure you check that out for even more thoughts about the spookiest time of year.

3. Apple geared up for Apple Intelligence's launch

Apple Intelligence

(Image credit: Apple)

Apple Intelligence launches next week and we can’t wait to get our hands on Apple’s AI-powered features for iPhone, iPad, and Mac.

Expect iOS 18.1, iPadOS 18.1, and macOS Sequoia 15.1 to launch in just a few days alongside a huge AirPods Pro 2 hearing aid upgrade. The first wave of Apple Intelligence features will introduce the world to “AI for the rest of us” as Apple calls it, and will bring Writing Tools, photo editing via Clean Up, Notification summaries, and a Siri redesign.

We’ve been using the iOS 18.1 beta for a couple of months now and can’t wait to see what the public perception of Apple AI is when it officially arrives. If you’re waiting for image generation tools such as Genmoji and Image Playground, though, you’ll need to be patient – they won't be with us until iOS 18.2 later this year. Let’s hope iOS 18.1 has enough meat on its bones to keep you occupied until then.

2. Severance Season 2 got its first trailer

It’s been an agonizing wait, but we’ve finally been treated to the first official footage for Severance season 2. Just 24 hours after Apple invited us all to a big Severance-themed meeting, the tech giant revealed the inaugural teaser for Severance season 2. Suffice it to say, the Apple TV Plus sci-fi thriller series’ sophomore season looks like it’ll be just as weird, wacky, and wild as its predecessor was. Roll on January 17, 2025, we say, which is when the highly rated show will make its long-awaited return.

1. Apple told us to ‘Mac’ our calendars

Mac teaser viewed on an iPhone

(Image credit: Future)

We’ve been expecting Apple to launch M4 Macs this month, and right at the buzzer Apple is seemingly ready to do just that. In a teaser, Greg Joswiak – Apple’s SVP of Marketing – has all but confirmed that new Macs are incoming, with a social media post instructing us to “Mac your calendars!” as Apple has an “exciting week of announcements” to make starting on Monday.

We’re expecting this means new 14-inch and 16-inch MacBook Pros, a redesigned Mac mini, and an update to the iMac, all with M4 Apple silicon. The glowing apple image Joswiak shared reminds us of the look of Siri with Apple Intelligence, so we can seemingly also look forward to the long awaited iOS 18.1 update and mac OS Sequoia 15.1 with that feature to come next week, too.

Beyond this, new Magic accessories (the keyboard, and mouse) are likely to arrive, and perhaps we’ll get an update or two for some more Apple TV shows. Check back next week to see everything that was announced.



from TechRadar - All the latest technology news https://ift.tt/E8tl6dU

It’s easier to talk about the areas of life that AI won’t affect than where it will. Businesses are at the forefront of that adoption. But ...

It’s easier to talk about the areas of life that AI won’t affect than where it will. Businesses are at the forefront of that adoption. But where businesses go, bad actors often follow - sometimes, they’re even ahead.

Whilst Gen AI is being used positively amongst businesses, speeding up admin tasks and acting as an assistant to many, it has already gotten into the ‘wrong hands’. More and more Gen AI offerings are available on the dark web to assist wanna-be hackers and bad actors in their endeavours. The commodification of AI can help cybercriminals make phishing attacks seem more personable and realistic, which can increase the likelihood of successful intrusions that could lead to ransomware attacks. Ransomware is one of the biggest threats to businesses today, putting businesses, reputations and careers at risk, and it is here to stay.

In the face of these evolving threats, the onus is on businesses to engage all its stakeholders including C-Suite and prioritize cyber resilience to ensure business continuity. It is not a case of if an attack happens, but when. Data is every organization's most important asset and if your data is secure, your business is resilient.

Fuel to fire

Typically, we associate AI with large language models such as OpenAI’s ChatGPT and Google’s Bard AI, and not with the potential cybercrime threats that tools like Worm GPT and FraudGPT can bring.

However, in the cybercrime field, we are all too aware of cyber criminals focusing on the biggest return and reward for the lowest investment of time and effort, and Generative AI can represent a perfect synergy in this respect in the cybercrime underworld.

AI can be used by adversaries to optimize and expand the reach of their threat campaigns far more efficiently than ever before, resulting in attacks that narrow the window for defenders to respond and mitigate.

Emotional strain

As AI technology advances, the sophistication of scams is following suit. In the future, AI threats could include autonomous systems capable of making decisions on how to modify their attack strategies in real time, with the ability to analyze attack campaign effectiveness. It could enable the use of data sets to constantly evolve and improve automatically, building an adeptness at bypassing traditional security measures - something that we’ve not seen in the history of cybersecurity.

For stretched CISOs and IT teams, however, AI can appear to be an additional strain on their workloads. This is as in the UK, 92% of senior IT and security leaders in the UK reported changes to their emotional and/or psychological state as a direct result of a cyberattack, with 36% worrying over job security.

That doesn't have to be the case however. For example, Generative AI companions can help stretched teams in simplifying and automating cyber incident responses and therefore recovery.

AI for good

Despite the threats, it does pay to get ahead. Businesses need to be leveraging AI in controlled environments where they are confident of its benefits, which typically includes the automation of admin tasks, support with data compiling, and creative inspiration.

When used by CISOs and IT teams to support cyber resilience, AI can assist in the areas of analysis, investigation and threat modelling to understand potential attack vectors and enhance their anomaly detection capabilities. This not only takes away some of the strain on stretched teams, it reduces their admin time and allows them to focus on ‘bigger fish’ activity - and their cyber resilience strategies.

Investing in AI tools should include training employees on its use cases in controlled environments, shining a company-wide light on cyber resilience. However, IT teams and CISOs must continue to closely monitor its use, govern access to training data, and set guardrails.

It is imperative that the C-Suite is heavily involved in cyber resilience, as the ultimate responsibility to adopt and implement compliant AI functions will always lay with the executive leadership in an organization.

A new chapter

Simply relying on prevention is not enough. To help ensure uninterrupted business operations in the face of threats, IT teams and CISOs must build cyber recovery and resilience strategies that proactively safeguard data integrity, identify sensitive data and threats, and enable a clean, rapid recovery.

The newly proposed Cyber Security and Resilience Act introduces expanded reporting requirements for ransomware attacks, providing government agencies with valuable new information on the scale of attack and the ability to increase support to affected businesses.

The aim of the bill is that mandatory reporting requirements will provide policymakers and threat intelligence agencies with valuable data on the prevalence of cyberattacks, currently seen as a "known unknown." With all of this additional data to hand, it is critical that it is managed effectively, and with law enforcement and cybersecurity companies involved, to mitigate threats effectively.

When it comes to the impact on businesses, it is important to have a balanced approach - one that combines regulatory measures with practical support for affected organizations. Despite the threats when used positively by CISOs and IT teams, AI can help with analyzing, investigating and threat modelling to help build cyber resilience strategies, and better understand potential threats.

To meet these growing threats CISOs and IT teams must fight fire with fire or risk losing the AI cyber arms race.

We've reviewed and rated the best cloud antivirus.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from TechRadar - All the latest technology news https://ift.tt/4FwBYvh

Only 11% of IT budgets are being earmarked for cybersecurity needs despite half of UK organizations detecting and responding to cybersecuri...

Only 11% of IT budgets are being earmarked for cybersecurity needs despite half of UK organizations detecting and responding to cybersecurity threats at least once a week, new research has claimed.

A survey by Vanta found the majority (54%) of firms agreeing security risks for their business have never been higher, with phishing attacks (35%), AI-based malware (34%) and compliance violations (27%) all increasing over the past year.

Despite the clear need for greater investment in cybersecurity, the report reveals 17% of an IT department’s budget represents the sweet spot, indicating that companies don’t have far to go.

Cybersecurity deserves more

While artificial intelligence has impacted security globally, only two in five (43%) UK organizations conduct regular AI risk assessments, and fewer than half have implemented an AI policy to regulate its deployment and usage among employees.

The report also highlights the burden of compliance tasks. Around two in three (69%) noted that customers, investors and suppliers require more demonstration of compliance than before. UK businesses are now spending two extra weeks each year – a total of 12 weeks – working on manual security compliance tasks compared with last year.

Furthermore, IT decision-makers (ITDMs) are spending an average of seven hours, or around one day, each week assessing and reviewing vendor risk. This is because 44% of the British companies surveyed revealed that a vendor of theirs had experienced a data breach since they started working with them, highlighting that cybersecurity threats don’t always come from within.

Besides tackling threats head-on, increased IT budget allocation for cybersecurity also promises to drive customer trust and reduce financial risks.

“To uphold trust in an AI world, security leaders need to go beyond the standard way of doing things," noted Vanta CEO Christina Cacioppo, "they need to make trust continuous, collaborative and automated across their business.”

More from TechRadar Pro



from TechRadar - All the latest technology news https://ift.tt/UrRLevQ

Zero-trust access is a rigorous security model that is increasingly becoming the benchmark for companies and governments. It shifts away fr...

Zero-trust access is a rigorous security model that is increasingly becoming the benchmark for companies and governments. It shifts away from traditional perimeter-based security to continuously challenge and verify the identity and authorization of users and devices before granting access – even to the CEO, who has worked there for twenty years. Users are then granted only the minimum permissions necessary to perform their tasks, limiting the potential damage they can do while ensuring they can still do their jobs.

One area where zero-trust can be effective is with log file intelligence. This is because while incredibly valuable for infosecurity and threat detection, log files can also be a system vulnerability. As such, they need to be both protected at all times and accessible to those who need them.

This article explores the challenges of implementing zero-trust log file intelligence and how emerging technologies can address these challenges.

Log files: they reveal everything

Log files are digital records that reveal information about a system's activities. They are a crucial source of intelligence as, by analyzing them, organizations can gain valuable insights into network performance, identify vulnerabilities, and detect suspicious activity.

However, their value is also their threat. As if they reveal everything, then those with access to them know everything as well. For example, an attacker could use log files to track users' activities, identify privileged accounts, and steal sensitive information. Once they have used that information to access the system, they could use log files to manipulate, steal, or hold critical information to ransom.

It is, therefore, crucial to manage log file access throughout the workflow to ensure the absolute minimum access possible for analysts and cybersecurity staff and to protect them from exposure.

Step one: secure collection and storage

To protect the integrity and security of log files, collecting and storing them in real-time in a tamper-proof and isolated environment is crucial. One way to manage the collection of this large-scale log file data is with OpenTelemetry. Its standardized approach and ability to integrate with various backends, including postgres, makes it a go-to option.

Blockchain technology, meanwhile, offers an ideal solution for their storage. Its immutable nature ensures that logs cannot be altered, preserving their integrity and ensuring a compliant and transparent record. Additionally, the decentralized nature of blockchain reduces the risk of an attack with no single point of focus.

Step two: least privilege access control

Secure log management requires balancing security and productivity to ensure logs are never exposed while still enabling them to be analyzed. This is a challenge for traditional access controls like data classification, masking, and query-based access because while they can limit exposure, they can also hinder threat detection and analyst efficiency. They are also not entirely secure, with access still granted on a wide scale to the decrypted logs.

One way to achieve the least privileged access control without compromising productivity is homomorphic encryption, a cryptography solution enabling data to remain encrypted throughout its lifecycle. This is because, with homomorphic encryption, those who require access to logs for threat intelligence are able to analyze them in an encrypted state without actually being able to read them.

This encrypted access control can also be extended beyond the analysts to anyone involved in the log management. For example, admins will be able to manage the permissions and access to the logs and check access requests without ever being able to read the logs themselves with them remaining encrypted. This is true across the full breadth of zero-trust systems using homomorphic encryption with admins and any super users not having the ability to read the data under their care but still being able to manage it.

Step three: threat intelligence and response

It is crucial to limit the amount of data that is shared externally of the secure system in order to prevent potential exposure and the creation of vulnerable access points. A potential solution to this is to use native AI instead of third-party tools for the analysis.

For example a private Small Language Model (SLM) AI working within the database could provide specialized insights and machine learning on the encrypted data without that data ever being shared externally of the system. Furthermore, as it is an SLM, the results have the potential to be more accurate and free from AI hallucinations because the model is not trained on vast pools of data that may be inaccurate or biased and instead only works on the encrypted log file data and any relevant given resources.

As the logs remain encrypted at all times and access is only granted to analyze the encrypted logs on a least privilege basis, strict zero-trust security is maintained.

Final thoughts

This article has shown that zero-trust is viable regarding the complex issue of log file intelligence and management and optimal for security and privacy. After all, logs should never be exposed, and they should never be edited. What’s better for that than an immutable system of zero-trust access?

Even if you do not adopt a zero-trust approach to your log management and intelligence, however, it is still crucial to keep this essential data pool protected at all times - even while being used.

We've reviewed and rated the best identity management software.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from TechRadar - All the latest technology news https://ift.tt/QDF1j4H

In recent years, cyberattacks continue to grow nearly exponentially year over year. This intensity will only increase with sophisticated te...

In recent years, cyberattacks continue to grow nearly exponentially year over year. This intensity will only increase with sophisticated technologies such as generative AI in the hands of threat actors.

In 2023, security experts reported a staggering 75% increase in cyberattacks - 85% of which were caused by Generative AI. Relentlessly fast and precise, GenAI cyberthreats automatically determine optimal attack strategies, self-modify code to avoid detection, and launch automated attacks around the clock in a completely automated way.

For businesses to defend against these enhanced attacks, they must find a way to leverage AI themselves. But it’s not as simple as fighting fire with fire - AI cybersecurity tools are also vulnerable to attacks, with even the slightest interference with datasets or inputs risking system failures. Businesses cannot rely on a single solution to meet the rising level of AI cyberthreats, especially when the full extent of their capabilities is yet to be determined. The only way through this growing security emergency is with proactive security planning that provides multiple contingencies for preventing, detecting and eliminating cyberthreats across overlapping security tools and protocols. This comprehensive approach is known as defense in depth.

The list of vulnerabilities that cyberattacks can exploit is a long one. LLMs are particularly good at quickly identifying these weak spots, like zero-day vulnerabilities. These particular vulnerabilities can quickly become single points of failure that can be used to bypass existing security measures, opening the floodgates for threat actors to send cascading failures through cybersecurity infrastructure and gain extensive access to business systems.

Cybersecurity teams should be operating on the assumption that all software and hardware in use contains bugs that can be exploited to access business systems, whether in their own IT infrastructure or third-party services. For this reason, businesses cannot rely solely on any one security defense but employ more in-depth and layered security defenses.

The defense in depth philosophy

Defense in depth focuses on three key levels of security: prevention, detection and response. It prioritizes the ‘layering’ of multiple defenses across these levels to extensively protect all security controls, including both tools and best-practice procedures across staff teams.

Technical controls such as firewalls and VPNs, administrative and access controls such as data handling procedures, continuous security posture testing and monitoring, and security documentation, and even physical controls like biometric access, must all be accounted for. If one tool or approach proves to be inadequate, another will be there to back it up - that is why the philosophy is also known as defense in depth. It ensures that there are no single points of failure in a business system, guarding against complete disruption if a component malfunctions.

The key principle is that these three levels work together: if prevention fails, detection can identify the threat. If detection fails, a strong response can limit the damage.

It is a dynamic solution, not a static one. The goal for cybersecurity teams is to create a live, responsive ecosystem that can be easily assessed and adapted. Reporting measures and regular testing protocols are a must for any cybersecurity strategy, but especially for defense in depth, which entails a wide variety of tools and processes that are easy to lose track of. What works today may not work tomorrow, especially with the rapid developments of AI cyberthreats.

For a defense in depth approach to be successful, cybersecurity teams must choose their tools carefully and strategically.

The need for diverse tools

Diverse tools are key to establishing defense in depth. While AI is now a must-have for every cybersecurity strategy, it would be unwise to stack your defenses with only AI software, as they will all be vulnerable to similar types of attacks (such as adversarial attacks, which entails feeding AIs incorrect data to encourage incorrect behavior).

Diverse cybersecurity strategies prevent attackers from exploiting a single system vulnerability, slowing down even AI-enabled attacks so that they can be identified and eliminated before systems are compromised. For example, data protection practices should include not only encryption, but additional fortifications such as data loss prevention tools, as well as processes for data backup and recovery.

Businesses should also utilize as much of their own data as possible when forming their cybersecurity defense in order to create tailored AI tools that can more effectively determine unusual user behavior or network activity than an external AI tool could.

Naturally, tools should be chosen in accordance with a business’s system and operations - for example, businesses with critical online services may employ more defenses against DDoS attacks.

Invest in staff training

Educating system users on the importance of data protection and authentication is equally important. A network monitoring tool can detect a threat, but user education and processes will strengthen diligence around credential data protection, for example by preventing shared passwords and encouraging the use of single sign-ons or two-factor authentication, leading to fewer attackers gaining unauthorized access in the first place.

Cybersecurity teams need to plan for all possible scenarios, including new or optimized attacks that have been enhanced by AI or other emerging technologies. It is crucial that teams are given the resources to research potential unknown threats and stay up to date with industry developments and emerging risks.

The most important takeaway is that, while no single security measure can be entirely foolproof, defense in depth provides a level of redundancy and resiliency that makes it much harder for an attacker to breach the system, so businesses don’t have to be helpless. The more organizations that adopt the defense in depth philosophy, the more difficult it becomes for threat actors to exploit the data of businesses and their customers.

We've rated the best identity management software.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from TechRadar - All the latest technology news https://ift.tt/lIVr4FH

Voice is our primary means of communication, and telephony has enabled us to connect using our voices for over a century. The phone call as...

Voice is our primary means of communication, and telephony has enabled us to connect using our voices for over a century. The phone call as we know it has evolved from analogue to digital, from fixed to mobile, and from low speech quality to natural speech quality. One major advancement, however, was still lacking: how to enable a fully authentic, immersive sound to be transmitted, live.

The introduction of the IVAS (Immersive Voice and Audio Services) codec, standardized by 3GPP in Release 18 in June this year represents a major advancement in audio technology. Unlike traditional monophonic voice calls, IVAS enables the transmission of immersive, three-dimensional audio, offering a richer, more lifelike communication experience. This innovation is made possible using new audio formats optimized for conversational spatial audio experience. One such example is a new Metadata-Assisted Spatial Audio format, MASA, which uses only two audio channels and metadata for spatial audio descriptions. Spatial audio calls allow users to experience sound as though it were happening in real life, complete with features like head tracking.

Below we will explore the challenges of bringing 3D live calling to mobile phones, the requirements addressed in spatial communication and the new IVAS codec, and the game-changing impact live 3D audio will have for people, mobile operators, and business smartphones.

Bringing 3D calling to Mobile Phones

The last major innovation in voice calling was the EVS codec, introduced in 2014 and recognized by consumers as HD Voice+. While it significantly enhanced call quality, like all previous codecs, it only offered a monophonic listening experience.

With the introduction of 3D audio calling—the biggest leap in voice-calling audio technology in decades—comes the challenge of creating an authentic, immersive experience in everyday communication. While voice technology has evolved significantly – from analog to digital, fixed to mobile, and from low quality to natural speech quality – transmitting spatial audio, where sounds are perceived as naturally coming from all around, is far more complex to recreate in mobile environments. 

Achieving this level of immersive sound experience has been easier in controlled settings like movie theaters and video games, where sound design is a core element, but reproducing it in everyday mobile calls introduces a range of technical hurdles including real-time spatial sound processing, hardware constraints, and ensuring compatibility across devices.

The Immersive Voice and Audio Services (IVAS) voice codec is therefore the most significant step forward in voice-call audio technology for decades.

How to Tackle and Overcome Spatial Communication Challenges

There have been several challenges to overcome for Immersive Voice to become a robust spatial audio solution. A key issue is noise reduction, crucial for enhancing speech clarity in settings like concerts or nature. Traditional noise reduction methods often only filter out continuous sounds, such as air conditioning hums or traffic noise, but often leave other background noise. Wind interference also poses a challenge by introducing unwanted noise and causing fluctuations in audio levels. 

However, recent advancements in machine learning and intelligent noise reduction have addressed these issues. Immersive audio technology, for example, is designed to intelligently adjust how much background noise is reduced depending on the surrounding environment, as well as providing users control, allowing individuals to manually adjust the levels of noise reduction. This ensures that the essential sounds are transmitted while minimizing unwanted background noise.

Immersive audio setups with multiple microphones and loudspeakers also face a major obstacle – acoustic echo. This happens when microphones pick up sound from nearby speakers, causing unwanted feedback. The problem is even more challenging in setups with spatial audio, where the placement and number of loudspeakers affect sound quality and the device's ability to capture spatial audio. Traditional Acoustic Echo Cancellation (AEC) methods often do not work well in these complex environments. To solve this, a machine-learning-based spatial AEC solution was created, which removes the loudspeaker sound from the microphone input using a reference signal. This improves audio quality, especially for spatial audio in real-time voice applications.

Introducing the IVAS codec

To bring spatial audio to mobile phone calling, in addition to Over-the-Top (OTT) services, the 3rd Generation Partnership Project (3GPP) recently adopted a new voice codec standard. Developed through the collaboration of 13 companies, the IVAS codec standard was included in the 3GPP's Release 18, building on the widely used Enhanced Voice Services (EVS) codec. Importantly, the IVAS codec maintains full backwards compatibility, ensuring seamless interoperability with existing voice services.

One of the key innovations during IVAS standardization was the creation of a new parametric audio format, Metadata-Assisted Spatial Audio (MASA), designed specifically for devices with limited form factors, like smartphones. The IVAS codec integrates a built-in renderer that supports head-tracked binaural audio and multi-loudspeaker playback using the MASA format.

Additionally, an immersive voice client SDK can serve as the IVAS front-end, capturing spatial audio from device microphones and converting it into the standardized MASA format. This technology enables true 3D immersive audio experiences for various types of voice calls.

The Power of 3D Live Audio: What it Means for People, Operators, and Businesses

New immersive 3D audio revolutionizes the audio experience for consumers, enterprises, and industries. For consumers, it deepens engagement in interactions with friends and family by sharing local sounds, whether live-streamed or recorded, and offers full immersion in synchronized metaverse experiences. For enterprises, 3D audio voice calling unlocks new capabilities, from enhanced customer experience through directional audio to transforming team collaboration and decision-making. In industrial settings, audio analytics can drive automated processes like predictive maintenance, streamlining operations, and boosting efficiency.

In order to enable these experiences across diverse network conditions, service providers need scalable solutions that optimize performance regardless of bandwidth constraints. The 3GPP IVAS standard codec accommodates bitrates ranging from 13.2 to 512 kbit/s, ensuring immersive audio quality whether used in congested networks or high-quality streaming environments. This scalability empowers service providers to support more users while delivering rich audio experiences.

Looking to the future, it is expected that voice-based user behavior will continue to evolve. Beyond traditional calls, spatial audio communication will expand to include semi-synchronous messaging through popular apps, people sending voice clips to each other, and more extensive use of group calls. With the rise of extended reality devices and services across industries, the scope of voice communication is set to become even broader, with immersion as a defining feature. A key factor in this evolution will be standardization and the integration of the IVAS codec into the latest 5G advanced standard, which is essential to ensure the interoperability needed to bring 3D calling to every phone at the push of a button.

We've rated the best business phone systems.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from TechRadar - All the latest technology news https://ift.tt/1pRutAv

In the long history of computer crime, the players, goals and tactics have seen a lot of change. Early computers were fairly isolated syst...

In the long history of computer crime, the players, goals and tactics have seen a lot of change.

Early computers were fairly isolated systems reserved for niche applications, mainly in academic environments. The first instances of security "attacks" were examples of tinkering that went too far rather than malicious activity.

Today’s world is different. Computers power many aspects of our day-to-day lives. They are faster than ever and highly inter-connected. They are in our pockets, homes and offices, but also in our toothbrushes and refrigerators. They even power our critical infrastructure. This now widespread reliance on computers (and the data they process) attracts new kinds of malfeasants.

Over time, computer-based crime has become organized. What started as low-tech cons and scams, or clever technical feats by small groups has been gradually replaced by more professionalized, more damaging, and more hurtful collectives, such as state-sponsored groups. There is one sort of attack that illustrates this transition better than most: ransomware.

The simple effectiveness of ransomware

Ransomware is an extremely lucrative example of computer crime going "corporate": incentivized by the will of making more money by investing less effort.

Most ransomware attacks follow a simple pattern: 

1. They start by running a malicious tool, an encryptor, on the target system. True to its name, the encryptor will then encrypt the whole disk (or disks) and delete the key. If the perpetrators intend to make the data recoverable, they will keep a copy of the key on their files, away from the affected system. 

2. Then, they make their presence known, from red screens to timers. Ransomware campaigns go great lengths to communicate with their victims because they get their money only if the victims believe that paying is the best chance they have to recover their data. 

3. After payment, an "honorable" ransomware gang will provide the victim a decryptor tool with the secret key.

There are some instances of ransomware that do not encrypt the data. Instead, the attackers threaten the victims by disclosing data publicly, which could cause embarrassment or leak industrial secrets.

Challenging attackers

However, with ransomware attacks, there are two steps that are somewhat challenging for the attackers:

Challenge #1: Getting the encryptor into the target system. Unfortunately, attackers can (still) benefit from a very simple tactic: asking nicely. Phishing attacks are popular ways of distributing ransomware encryptors because many victims eagerly click links on emails without verifying the origin or giving it a thought. Technical entry points traditionally used to deliver malware remain a useful alternative: if there is an open file share, the attacker can deploy the file into the target system, then find another vulnerability to execute it. WannaCry, the attack considered by many as the most damaging ransomware campaign to date, is an example of this.

Challenge #2: Receiving the ransom payment without betraying the attacker's identity. Fifteen years ago, this challenge alone would have hindered the expansion of ransomware gangs. They would need to pay in cash, which is hard to scale and would be geographically restricted to the area of influence of the gang, or they would need to rely on digital payments and withdraw the money fast, creating a trail of evidence leading directly to the gang. However, the rise of cryptocurrency presented a solution to this challenge.

While authorities have succeeded in tracking down malicious businesses who took ransom in cryptocurrencies, the international availability of a means of payment that is not linked to an actual identity has made it much easier for criminals to receive their payments and much harder for law enforcement to follow the tracks.

Preventing disruption using backups

Many of the mechanisms that help to prevent ransomware attacks involve general practices that also help to prevent various types of cyber-attacks. Awareness training supports by warning employees about clicking random suspicious links, hardening at the network and operating system level, deploying updates quickly, malware scanning, etc.

There is also great importance in building a sturdy resilience plan, underpinned by a well-defined and tested backup strategy. Of course, backups are a usual control against accidental data loss and conventional disruptive hacking like, say, website defacement. You detect the incident, roll back your data or your environment to a certain previous point in time, and get back to business with (ideally) minimum data loss.

This backup model relies on a few assumptions. To put it simply, it expects backups to work (to contain enough information to allow for a clean rollback) and to be valid (the rollback would clean up any damage made by the attacker). Reality often challenges both assumptions.

Many companies have backup processes in place. Fewer have data recovery plans describing what to do with the backups to return to a working state. Only a small minority of companies test regularly those backups to ensure that they can, in fact, be relied upon. This makes the recovery process clunky and often unsuccessful.

Ransomware attacks also challenge the second assumption. For example: if the backups are hot (that is, constantly connected to the target system), the encryptor could also encrypt the backup drives, rendering the backup unusable. Or the encryptor could be installed at a certain point, stay idle for a few months, then encrypt the data. A backup taken after the initial compromise could recover the data of the system, but could restore an infected state, allowing a reinfection to occur.

To summarize: a robust backup strategy needs to rely on both hot and cold backup locations, sufficiently isolated from each other to keep an attack on the main system from spreading undeterred to the backups, both of which are regularly and rigorously tested. If the downtime requirements of a given system are particularly stringent, the ability to get back up with minimum data loss must be part of those tests.

Wrapping up

At a technical level, ransomware is not a terribly novel threat. The disruptive aspect of it lies in the economic incentives it introduces, leading to more organized criminal structures with the freedom to act more ruthlessly and at a larger scale, and to attack sensitive industries with the hope of maximizing their payment. It is a threat worth considering because it is increasingly prevalent and, for companies caught unprepared, could wreak havoc on their infrastructure. Just remember: do not pay the ransom.

Check out the best cloud antivirus.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



from TechRadar - All the latest technology news https://ift.tt/38zDqKS