Connect with us

Technology

Vulnerability in MediaTek chips allows ‘zero-click’ remote takeover

Published

on

Vulnerability in MediaTek chips allows ‘zero-click’ remote takeover

A vulnerability discovered inside the MediaTek chipsets can allow attackers to take over a victim’s device. The “zero-click” bug opens the door to Remote Code Execution (RCE) without user interaction.

Vulnerability in MediaTek Wi-Fi chipsets can compromise devices

Some of the most dangerous attacks on electronic devices need no action from the victims. These attacks can compromise the security of a device and take over control without the user needing to click or tap on anything. Such a vulnerability exists in MediaTek chipsets, particularly those that handle wireless communication. Several device makers embed MediaTek chipsets, which makes multiple electronics vulnerable.

SonicWall Capture Labs researchers who discovered the issue have alerted MediaTek. The chipmaker has tagged the vulnerability as CVE-2024-20017. The vulnerability’s severity rating is CVSS 9.8. Simply put, this bug is reportedly a nearly max-critical zero-click vulnerability.

Security researchers have indicated the vulnerability is an out-of-bounds write issue that resides in “wappd”. In simple words, a “network daemon”, which is an always-active service, can be targeted and compromised. Wappd is responsible for configuring and managing wireless interfaces and access points, indicated the researchers.

Advertisement

“The architecture of wappd is complex, comprising the network service itself, a set of local services that interact with the device’s wireless interfaces, and communication channels between components via Unix domain sockets.”

How to stay protected from the latest MediaTek security exploit?

The vulnerability impacts MediaTek SDK versions 7.4.0.1, and earlier. Attackers can also target devices that run older versions of OpenWrt, a custom router firmware, and even couple it with other recently discovered vulnerabilities.

End-users with MediaTek Wi-Fi chipsets can tweak their Wi-Fi settings to mitigate the risks. Smartphone users should avoid public Wi-Fi hotpots as the backend networking hardware could be vulnerable.

Attackers could also target smartphones with the latest MediaTek chipsets as a public proof-of-concept exploit (PoC) recently became available. Hence, it is wise to stay connected to reliable Wi-Fi routers. When outside, switch to “Airplane” mode when in public places or use mobile data. Additionally, users must keep their devices updated.

Advertisement

Source link

Continue Reading
Advertisement
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Technology

What can governments do about online disinformation from abroad?

Published

on

What can governments do about online disinformation from abroad?

Riots took place in Sunderland and elsewhere in the UK after online disinformation inflamed tensions over immigration

Drik/Getty Images

Last week, police in Pakistan charged a man with cyberterrorism in connection with a misleading news article blamed for inciting riots in the UK. The article falsely claimed that the killing of three girls in Southport, UK, was carried out by an asylum seeker and the misinformation spread rapidly on social media, fuelling anger over immigration.

The threat of online disinformation stirring up real-world trouble is a major worry for governments around the world, and it can be especially hard to…

Advertisement

Source link

Continue Reading

Technology

How to enable RCS messaging in Apple iOS 18

Published

on

How to enable RCS messaging in Apple iOS 18
how to enable rcs messaging in apple ios 18 on hero

Bryan M. Wolfe / Digital Trends

Support for Rich Communication Services (RCS) is one of the lesser-known features in iOS 18, which is now available for everyone. RCS is an enhanced version of SMS for text messaging, and its implementation will enable Apple users to communicate with Android users in a similar way to how they do with other Apple users.

In doing so, you will be able to use read receipts with your friends and family on Android. You can also send high-quality images and videos, view typing indicators, and enjoy enhanced group messaging capabilities.

Getting started with RCS as an iPhone user is a pain-free process. Let’s take a look.

How to enable RCS messaging in iOS 18

Luckily, RCS should be activated on your iPhone with iOS 18 installed automatically. To be sure, follow these directions.

Step 1: Open the Settings app on your phone.

Advertisement

Step 2: Scroll down and choose Apps.

Step 3: Select Messages.

Screenshots showing how to access Messages settings on iOS 18.

Bryan M. Wolfe / Digital Trends

Step 4: Scroll down, under Text messaging and select RCS messaging.

Step 5: Toggle RCS messaging to the on position if it is not already enabled. You can also disable RCS messaging by toggling off the feature.

Screenshots showing how to find RCS settings on iOS 18.

Bryan M. Wolfe / Digital Trends

How to tell you are using RCS

There are a few ways you can tell that you are sending a message in iMessage via RCS.

Step 1: First, even without sending a message, you’ll see “RCS” at the top of the message box as soon as you type in the number of someone not using an Apple device.

Advertisement
Screenshots confirming an Android and iPhone users are texting via RCS.

Bryan M. Wolfe / Digital Trends

Step 2: You can also recognize the use of RCS when someone sends you something beyond regular text. For example, there’s congratulations confetti, as seen in the example below. That wouldn’t be possible in iOS 17 or older.

Screenshot showing what happens when an Android user sends something other than regular texts to an iPhone user with RCS.

Bryan M. Wolfe / Digital Trends

What to do if RCS isn’t working on your iPhone

If you’ve checked the steps above and still can’t get RCS working on your iPhone, there is a reason why — your carrier.

For the major carriers in the U.S., which include AT&T, Verizon, and T-Mobile, RCS should already be enabled. There are also a few regional providers (Europe, Asia-Pacific, Africa, Latin America, the Middle East, and India) and several mobile virtual network operators (MVNOs) that also support it. In short, if you’re on a major carrier, then you should have RCS support, but if you’re on a smaller network, then it might not be supported yet.

So again, if you don’t see the RCS messaging option after completing the steps above on your iPhone with iOS 18 installed, then it’s because the carrier needs to get on board with supporting it. The fix for that is unfortunately just waiting it out. You can check Apple’s wireless carrier support page to check if your carrier supports RCS.



Advertisement




Source link

Continue Reading

Technology

iPhone 17 & iPhone 17 Air tipped to flaunt 120Hz displays

Published

on

iPhone 17 & iPhone 17 Air tipped to flaunt 120Hz displays

It’s only been a few days since Apple unveiled the iPhone 16 series. The company just began shipping the units to the early buyers yesterday. However, it hasn’t stopped the rumors around the iPhone 17 series from pouring in. Ross Young of Display Supply Chain Consultants has already shared some details regarding the displays of 2017 iPhones. Young predicts the iPhone 17 and the slimmer model, presumably called iPhone 17 Slim or iPhone 17 Pro, will have 120Hz displays.

It’s worth mentioning that most of the information about the iPhones from Young before launch has been true in the past. Notably, he was the first to reveal that the iPhone 16 Pro and 16 Pro Max would offer 6.3-inch and 6.9-inch screens, respectively.

iPhone 17 and iPhone 17 Air (or iPhone 17 Slim) will finally get a 120Hz refresh rate

In a post on X, Young said that the iPhone 17 and iPhone 17 Air, or whatever Apple ends up calling will finally get a 120Hz refresh rate. Both iPhones will flaunt the ProMotion technology, which will allow them to deliver a 120Hz screen refresh rate. The newly launched standard iPhone 16 and 16 Plus can still only offer up to a 60Hz screen refresh rate.

Thanks to the higher refresh rate, the iPhone 17 and iPhone 17 Air will be able to provide smoother scrolling and videos. They will also be able to switch to a more power-efficient refresh rate, thanks to the ProMotion tech. This will allow for the always-on display functionality. It will allow the next year’s iPhones to provide various Lock Screen elements, even when they are locked.

Advertisement

The iPhone 13 Pro can ramp down to 10Hz, while the iPhone 14 Pro through 16 Pro can reduce to 1Hz. But, it’s not clear if it would ramp down to 10Hz or 1Hz on the iPhone 17 series.

iPhone 17 Pro will not offer under-display Face ID tech

In the now-deleted X post, Young was also replying to some queries regarding the iPhone 17 series via comments. He also responded to questions regarding the presence of the under-display Face ID tech on the regular iPhone 17 Pro models. Some misinterpreted the information and reported that the standard iPhone 17 Pro would also have under-display Face ID. However, in a comment later, Young clarified that this tech is not expected on the iPhone 17 Pro.

Source link

Advertisement
Continue Reading

Technology

Elgato’s Stream Deck+ drops to a record low of $170 in this early Prime Day deal

Published

on

Elgato’s Stream Deck+ drops to a record low of $170 in this early Prime Day deal

You can save big today on the Elgato Stream Deck+ with $30 off the control panel on Amazon. Great for streamers or anyone who wants tactile shortcuts and dials for their workflow, the Stream Deck+ drops from its usual $200 to $170 with a discount and a clickable coupon.

Although the Stream Deck+ sacrifices some buttons compared to the cheaper Stream Deck MK.2, this model makes up for it with four dials and a touch strip. Each dial is customizable and clickable, allowing you to layer different dial shortcuts with each press inward. You can twist them to adjust things like volume, smart lights and in-game settings.

Elgato

Advertisement

Save $30 on Elgato’s Stream Deck model that adds dials and a touch strip.

Save $30 with clickable coupon

$170 at Amazon

Its eight buttons are backlit and fully customizable. Streamers can use the Stream Deck desktop app to assign functions for things like muting mics, activating effects or triggering transitions. But you don’t need to be a YouTuber or Twitch streamer for it to be helpful. For example, I’m neither and use a Stream Deck daily to toggle preset macOS window arrangements through the third-party app Moom. It’s also handy for text expansion shortcuts or emojis.

Advertisement

The 4.2 x 0.5-inch touch strip displays labels and levels for each knob, giving you a clear visual cue about what you’re controlling with each twist. The touch-sensitive bar also supports custom long presses and page swipes.

Amazon’s sale covers both the black and white Stream Deck+ models. Make sure you click on the $10 coupon box on the product page to bring it down to $170.

Follow @EngadgetDeals on Twitter for the latest tech deals and buying advice in the lead up to October Prime Day 2024.

Advertisement

Source link

Continue Reading

Technology

Why prompt engineering is one of the most valuable skills today

Published

on

Why prompt engineering is one of the most valuable skills today

Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More


In a world that is rapidly embracing large language models (LLMs), prompt engineering has emerged as a new skill to unlocking their full potential. Think of it as the language to speak with these intelligent AI systems, enabling us to tap into their vast capabilities and reshape how we create, work, solve problems and do much more. It can allow anyone — including your grandma — to program a complex multi-billion parameter AI system in the cloud.

LLMs are fundamentally built on deep learning algorithms and architectures. They are trained on massive datasets of text. Like a human who has devoured countless books, LLMs learn patterns, grammar, relationships and reasoning abilities from data. Internal settings can be tuned to change how the model processes information and adjusted to improve accuracy. When given a prompt at the inferencing stage, the LLMs use their learned knowledge and parameters to generate the most probable and contextually relevant output. It is because of these prompts that the LLMs can generate human-quality text, hold conversations, translate languages, write different kinds of creative content and answer questions in an informative way.

Many free (open source) LLMs and paid (closed source) hosted LLM services are available today. LLMs are transforming every industry as well as every aspect of our lives. Here’s how:

Advertisement
  • Customer service: Powerful AI chatbots provide instant support and answer customer queries.
  • Education: Personalized learning experiences and AI tutors are available.
  • Healthcare: LLMs are being used to analyze medical issues, accelerate drug discovery and personalize treatment plans.
  • Marketing and content creation: LLMs can generate engaging marketing copy, website content and scripts for videos.
  • Software development: LLMs are assisting developers with code generation, debugging and documentation.

Important prompt types and techniques

Prompts act as a guiding light for LLMs. A well-crafted prompt can significantly impact the quality and relevance of the output of LLMs. Imagine asking a personal assistant to “make a reservation for dinner.” Depending on how much information you provide, such as preferred cuisine or time, you will get a more accurate result. Prompt engineering is the art and science of crafting prompts to elicit desired outputs from AI systems. It involves designing and refining prompts to generate accurate, relevant and creative outputs that align with the user’s intent.

Let us delve deeper by looking at prompt engineering techniques that can help a user guide LLMs toward desired outcomes.

From practice, prompts could be broadly classified as falling into one of the following categories:

  • Direct prompts: These are small direct instructions, such as “Translate ‘hello’ into Spanish.”
  • Contextual prompts: A bit more context is added to small direct instructions. Such as, “I am writing a blog post about the benefits of AI. Write a catchy title.”
  • Instruction-based prompts: These are elaborate instructions with specific details of what to do and what not to do. For instance, “Write a short story about a talking cat. The cat should be grumpy and sarcastic.”
  • Examples-based prompts: Prompters might say, “Here’s an example of a haiku: An old silent pond / A frog jumps into the pond— / Splash! Silence again. Now, write your own haiku.”

The following are important techniques that have been proven to be very effective in prompt engineering:

  • Iterative refinement: This involves continuously refining prompts based on the AI’s responses. It can lead to better results. Example: You might start with “Write a poem about a sunset.” After seeing the output, refine it to “Write a melancholic poem about a sunset at the beach.”
  • Chain of thought prompting: Encouraging step-by-step reasoning can help solve complex problems. Example: Instead of just a complex prompt like “A farmer has 14 tractors, eight cows and 10 chickens. If he sells half his birds and buys 3 more cows, how many animals would give him milk?”, adding “Think step by step” or “Explain your reasoning” is likely to give much better results and even clearly point out any intermediate errors that the model could have made.
  • Role-playing: This means assigning a role or persona to the AI before handing it the task. Example: “You are a museum guide. Explain the painting Vista from a Grotto by David Teniers the Younger.”
  • Multi-turn prompting: This involves breaking down a complex task into a series of prompts. This technique involves using a series of prompts to guide the AI to the required answer. Example: “Create a detailed outline,” followed by “Use the outline to expand each point into a paragraph,” followed by “The 2nd paragraph is missing X. Rewrite it to focus on…” and then finally completing the piece.

Challenges and opportunities in prompt engineering

There are some challenges and opportunities in prompt engineering. Although they have improved exponentially, LLMs may still struggle with abstract concepts, humor, complex reasoning and other tasks, which often requires carefully crafted prompts. AI models also can reflect biases present in their training data.

Prompt engineers need to understand this and address and mitigate potential biases in their final solutions. Additionally, different models may naturally interpret and respond to prompts in different ways, which poses challenges for generalization across models. Most LLM creators usually have good documentation along with prompt templates and other guidelines that work well for that model. It is always useful to familiarize yourself to efficiently use models. Finally, although inferencing speeds are continuously improving, effective prompting also presents an opportunity to program LLMs precisely at inference time to save compute and energy resources.

As AI becomes increasingly intertwined with our lives, prompt engineering is playing a crucial role in shaping how we interact with and benefit from its power. When done right, it holds immense potential to unleash possibilities that we have not imagined yet.

Advertisement

Deven Panchal is with AT&T Labs.  

DataDecisionMakers

Welcome to the VentureBeat community!

DataDecisionMakers is where experts, including the technical people doing data work, can share data-related insights and innovation.

Advertisement

If you want to read about cutting-edge ideas and up-to-date information, best practices, and the future of data and data tech, join us at DataDecisionMakers.

You might even consider contributing an article of your own!

Read More From DataDecisionMakers


Source link
Advertisement
Continue Reading

Technology

Lenovo ThinkPad T14s Gen 6 AMD launches with a 14-inch touch display, Zen 5 core and robust security

Published

on

Lenovo ThinkPad T14s Gen 6 AMD launches with a 14-inch touch display, Zen 5 core and robust security

Lenovo has released the ThinkPad T14s Gen 6, a new notebook that comes equipped with Zen 5 core and RDNA 3.5 chips.

This thin and lightweight device measures just 16.9mm in thickness and weighs only 1.3kg, making it an excellent choice for business users on the move.

Source link

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.