0 Σχόλια
0 Μοιράστηκε
Κατάλογος
Κατάλογος
-
Παρακαλούμε συνδέσου στην Κοινότητά μας για να δηλώσεις τι σου αρέσει, να σχολιάσεις και να μοιραστείς με τους φίλους σου!
-
WWW.DENOFGEEK.COMAvengers: Doomsday Feels Like the Real Ending for the Fox X-MenTo me! My folding chairs?!Marvel raised a lot of questions yesterday when they chose to announce the cast of its much-anticipated Avengers: Doomsday via a five and a half hour video posted to social media, in which the camera moves every 12 minutes or so to reveal a new chair with a stars name on the back.But the biggest questions might be around names such as Patrick Stewart, Ian McKellen, Alan Cumming, and James Marsden. These names all belong to stars of the Fox X-Men movies from the 2000s, films made outside of Disneys influence and before the MCU ever existed. It isnt the first time that characters from the Fox X-Men movies have showed up in MCU movies before, of course. Last year nostalgia for their era powered Deadpool & Wolverine well north of $1 billion. But giving the name Doomsday and its role as a lead-up to Secret Wars, this return feels like the real final swan song for this version of the X-Men.Revealing the Secret WarsMarvel has published four major storylines called Secret Wars, all but one of which deal with the same basic idea. Secret Wars and Secret Wars II, written by one-time Marvel Editor-in-Chief Jim Shooter, both involve an all-powerful being called the Beyonder who intercedes in the heroes lives. In Secret Wars II, the Beyonder learns about humanity by taking the form of Michael Jackson but as a white man (yes, really). He thus requires Spider-Man to teach him how to pee (also really), and kills and resurrects the teens in the New Mutants just because he can.But the first Secret Wars is more straightforward story, in which the Beyond transports a bunch of heroes and villains to a Battleworld so they all can all fight one another. The 2015 Secret Wars and its multi-year round up by Jonathan Hickman reimagines that plot, with the various alternate realities all colliding and destroying one another. To save their own Earths, the heroes and villains of the various realities sometimes decide to destroy the other reality first, thereby avoiding the collision.Its this latter storyline that Marvel has been hinting most often. The Illuminati of Earth-838 in Doctor Strange and the Multiverse of Madness talks about their awareness of the dangers posed by other realities. At the end of that movie, Clea arrives to recruit Stranges help in stopping incursions, using the word that Hickman uses to describe the collisions in his Secret Wars opus. Simiarly, n the post-credit scene of Captain America: Brave New World, the Leader (Tim Blake Nelson) warns Cap (Anthony Mackie) that heroes from other realities will do anything to protect their Earths, even threatening our own.Thus its not hard to imagine that Avengers: Doomsday is about exactly that: the heroes and villains of various realities fighting to save their Earths. And it might end exactly like the stories leading up to Secret Wars ends, with Doctor Doom doing the unthinkable to save his reality, challenging and defeating the Beyonders, and using their power to recreate reality in which he is the God Emperor.In other words, Avengers: Doomsday and Avengers: Secret Wars might follow the same thematic path as the Russo Brothers last pair of Avengers films. Avengers: Infinity War is about Thanos trying to save the galaxy by gathering the Infinity Stones and snapping half of all life out of existence, dealing the Avengers a loss. In Avengers: Endgame, the defeated heroes spend some time in their new normal before gathering strength to set things right. Doomsday could be about Doctor Doom and his own heroes destroying other realities to save his Earth, defeating the Avengers and creating his own reality, a reality that will be undone through Secret Wars.If Doomsday and Secret Wars do follow that model, its very bad news for the Fox X-Men.Superhero Death Must StingAsgard is not a place, the Chris Hemsworths God of Thunder remembers his father telling him at the end of Thor: Ragnarok. Asgard is a place where our people stand. Those words brought comfort to Thor as he watched the destruction of the place he grew up calling Asgard. This concept let Ragarok end happily, as most superhero movies must.But when we see Thor and his people again at the start of Infinity War, theyre being decimated by Thanos. Thanos kills Loki and Heimdall, and only Hulk escapes, making his way back to Earth to warn Doctor Strange about the coming of the Mad Tyrant.Join our mailing listGet the best of Den of Geek delivered right to your inbox!Like Ragnarok, Deadpool & Wolverine has a happy ending for its displaced people, the Fox X-Men. After battling across realities to keep the TVA from pruning their Earth, Wade and Logan share a dinner with all their friends, seemingly safe in their own reality.But now they have to die. Not that we necessarily want bad things to happen to the Fox X-Men (well, not entirely that, anyway). Its just that Marvel needs to actually give some stakes to these characters, especially if theyre bringing back guys like Patrick Stewart as Professor X. Weve already seen Stewarts Charles Xavier die three times on screen, once in 2006s X-Men: The Last Stand, once in 2017s Logan, and most recently in 2022s Doctor Strange in the Multiverse of Madness.Sure, Xavier and the X-Men have died time and again in the comics. But its becoming especially meaningless in the movies, especially since Marvel keeps wanting us to act surprised when the X-Men come back, and then again when they get killed. The trick isnt working anymore, and if Marvel wants Doomsday to have any weight, it cant even pretend to pull this trick again. This version of the X-Men need to meet their doom for good.The death of the X-Men fits the model set by Infinity War. Its easy to imagine Doomsday opening in the reality of the Fox X-Men, fighting for the survival of their reality. When they faileither because of an incursion or because of Doctor Doom and his teamMonica Rambeau (Teyonah Parris), who has been stranded in this reality since the ending of The Marvels, escapes to warn the Avengers of Earth-616, just like the Hulk did before her.The Fall of the MutantsAll this talk of final deaths might sound silly in relationship to Avengers: Doomsday, a movie that boasts about bringing back Robert Downey Jr. and the Russo Brothers, people from the height of Marvels success returning to the fold.Yet its impossible to believe that all of these references to the past will keep working. If Marvel actually wants to become relevant again, it cannot keep pointing out that it isnt as good as it was five or more years ago. It needs to close the book on the past and move forward, starting by letting Doomsday actually doom some beloved heroes.Avengers: Doomsday arrives May 1, 2026.0 Σχόλια 0 Μοιράστηκε
-
NEWS.XBOX.COMTunguska Is Here on Xbox: How to Survive in the Zone as a Ghoul HunterSummaryChoose your preferred tactics for each battle.Great variety of items and weapons.Live a fulfilling life in the Zone with crafting, farming, cooking, and tons of quests and stories.Attention, fellow Ghoul Hunters! Welcome to the Zone. Or shall I say: welcome to your final demise? Because according to my studies, only one in a hundred Ghoul Hunters will survive in the Zone! Deadly Distortions, dangerous mutants, heavily-armed bandits, and yes, the cursed Visitations! They are here to claim your life and your soul.But fear not: the Cossacks are here to help! Well provide you with the best gears and training (for a small fee, of course), and well always have your back. Now, if you can spare me a few minutes, Im sure a few tips and tricks can get you started.Dont Get into Fights Unless You Have toYou may trust your grandpas Makarov and sawed-off double-barrel, but what are you up against? AKs, sub-machine guns, AS-Val, SVD, oh and even RPD and PKM bad guys armed to the teeth who dont even bother to loot rookies like you!So heres my advice: stick to the shadows, sneak past your foes, and learn to take them down quietly with a garrote. But when you get a hold of those big toys, work on improving your skill level with each kind, and find weapon attachments to unleash their true power.Take Good Care of Your GearsLife in the Zone is not your dream vacation. Your armors will degrade. Your devices will run out of battery. Your guns will jam.Remember, your life depends on your gears working flawlessly, so use a repair kit to maintain them after every battle! You can bring any worn-out weapon and armor to our workbench for repair free of charge, as long as you know how to fix them.Always Keep Your Eyes Peeled for More LootThere are always supplies in every nook and cranny for you to find. Food, ammo, medicine, serums, ingredients, they are all crucial to your survival in the Zone. Especially iodide pills for radiation, and Vodka for Tunguska Syndrome if you need more, come see our trader and well cut you a good deal.Dont forget: you can craft almost everything you need in the Zone. Cooking, farming, loading bullets, brewing serum, and even distilling alcohol for the serum lab (and of course, for escaping from your troubles and sorrow!), you can essentially live a life here.Finally, Bring All Your Spoils to The CossacksAfter all, you are here to be Ghoul Hunters, right? Remember: bullets dont do you any good theyll just rip up all those mutated body parts that youll need to make money with. On the other hand, melee weapons give you the best chance to harvest high quality serum ingredients. Just bring them to us and well make you rich, because the Cossacks make the best serums!So join us now, and well fight together, hunt together, and prosper together, only in Tunguska: The Visitation today on Xbox!Tunguska: The Visitation Complete EditionRotorist WorkshopGet it nowSeek fortune as a Ghoul Hunter in an abandoned Soviet Exclusion Zone. Use your grit and ingenuity to survive deadly radiation, mysterious anomalies, and poisonous mutants. Go in guns-blazing, or stay in the shadows your choice. Uncover the dark secrets of Tunguska from the Soviet era. Venture across desolate villages, abandoned facilities, toxic swamps, and ominous tunnels in this top-down adventure RPG, in a realm cursed by the mysterious Tunguska Event in 1908.Inspired by the novel Roadside Picnic, Tunguska is one man's vision and creation of a new post-Visitation zone: a place not just full of horror and danger, but also the freedom and opportunities sought after by many near the fall of the USSR.SURVIVALTunguska: The Visitation is 3D top-down action shooter, infused with moderate survival elements such as food, medicine, body energy, character stat buff, hazardous environments, and inventory management. The slow-paced, methodical gameplay inspires critical thinking and strategic planning.A perk-based skill system lets you decide on how to build expertise be it combat-heavy, stealthy, crafty, or just an all around survivor of the Zone.COMBATPut your grit to the test with real time melee brawls and gunfights. With a large arsenal of weapons, you can be creative and come up with the best approach for each combat scenario. Stick to the shadows and use distractions, if being stealthy is up your alley.CRAFTINGThe Zone is not a barren place. Collect wild herbs, grow crops, and hunt for wild animals to collect ingredients for cooking and brewing. Use the workbench to craft ammunition and repair your gears.COMPLETE EDITIONIncludes: main game, Ravenwood Stories, Shadowmaster, New Game+, and Slaughterhouse.0 Σχόλια 0 Μοιράστηκε
-
NEWS.XBOX.COMDrive Out the Darkness with Sea of Thieves Destiny-Inspired Lightbearer CosmeticsCalling all Guardians! Today brings the latest content update to Sea of Thieves, and with it, some radiant new additions to the Pirate Emporium Lightbearer items, inspired by the world and characters of Destiny, have arrived!Whether your pirate is as silent as a Hunter, mighty as a Titan or wise as a Warlock, theyll find a ship set to suit their style, complete with Collectors cosmetics and a Ships Crest. An array of matching weapons and a costume set to round out the range ensures youll be ready to take on whatever otherworldly foes may stand in your way.At first glance, venturing across the solar system may seem like a far call from securing swag in a tropical pirate paradise so how did this celestial collaboration come to be? Adam Park, Director of Brand & Licencing at Rare, sheds light on the partnership:As weve seen with our other cosmetic crossovers and our Tall Tales, our teams are always looking for opportunities to bring other worlds into Sea of Thieves and put a unique spin on them, no matter where the inspiration comes from. Even though it might not seem like an obvious choice, Destinys classes and co-operative play presented a crew-like bond that we thought was a great fit, along with some striking iconography, vivid art style and a sense of being mythical in tone and scope.Handily, there were already plenty of accomplished Guardians at Rare with a deep understanding of the Destiny universe, though the team completed more than their fair share of Quests while gathering ideas. If you want a sense of how much the team at Rare wanted to make this happen, just know that theyve been working with Bungie on this idea since 2023!Once plans were agreed, the next step in making the Lightbearer collection a reality was to create concept pieces for ship sets, weapons and clothing. Andria Warren, Director of Creative Operations at Rare, oversaw their development.Working with Bungie to bring Destiny 2 into Sea of Thieves was a creatively rich and deeply collaborative process. From the earliest concept sketches to finalising designs that honoured both universes, every step challenged us to think differently. We explored how iconic Destiny elements could be reimagined through a Sea of Thieves lens, translating tone, visual language, and character into something that felt fresh but unmistakably faithful. It pushed our teams creatively in the best possible way, and the result is something were truly proud of!Working alongside the Destiny team to iterate and refine the various Lightbearer items culminated in one of Sea of Thieves most comprehensive collections. Partnerships like this can take a lot longer than people realise to make happen, Park muses, But when you see the results it really does showcase the talent and hard work of everyone involved. Were sure the Lightbearer items will be a big hit with Destiny fans old and new, and cant wait to see people making creative use of them as they go about their adventures. Good luck, Guardians!You can check out the trailer below to see the full Lightbearer assortment, and then visit the Pirate Emporium to gear up and get ready for battle the seas are counting on you!0 Σχόλια 0 Μοιράστηκε
-
9TO5MAC.COMFinal Cut apps updated with Apple Intelligence and more new featuresToday Apple has released a trio of noteworthy updates for its suite of Final Cut apps. Final Cut Pro for both Mac and iPad have been upgraded with a variety of powerful new features, and Final Cut Camera gets some nice changes too.Full release notes for Apples Final Cut updatesApples latest array of Final Cut updates includes a wide variety of features. Apple Intelligence makes its first appearance with the new Image Playground support. But there are also a bunch of other big and small changes designed to speed up workflows, offer new capabilities, and expand versatility.Here are Apples full release notes for each of the updates.Final Cut Pro 11.1 includes the following enhancements and bug fixes:Add color corrections and effects to an adjustment clip above the timeline to apply them to a range of clips at once.Get inspired with Image Playground and use Apple Intelligence to quickly create stylized images based on a description, suggested concepts, or people from your Photos library. (Requires macOS 15.2 or later on Mac models with M1 or later.)Speed up your Magnetic Mask workflows with important bug fixes, performance improvements, and a new keyboard shortcut to show or hide the Magnetic Mask Editor.Use the Quantec QRS (Quantec Room Simulator) effect to create natural and transparent audio reverbs that simulate real acoustic spaces.Stay organized by renaming audio effects in the inspector.Reveal the source of a multicam angle or synced clip in the browser.Move markers in the timeline by dragging them in a clip, or remove markers by dragging them out of a clip.On the iPad side, new keyboard shortcuts and portrait orientation seem like highlights.Final Cut Pro for iPad 2.2 includes the following features and enhancements:Expand your editing workflows with support for portrait orientation on your iPad.Speed up your editing with keyboard shortcuts to nudge a selection, replace with gap, and lift or overwrite to the primary storylineGet inspired with Image Playground and use Apple Intelligence to quickly create stylized images based on a description, suggested concepts, or people from your Photos library. (Requires iPad with A17 Pro or M1 and later and iPadOS 18.2 or later.)Capture in 50 fps for additional editing flexibility and delivery options.Final Cut Camera 1.2 includes the following features and enhancements:Quickly switch to the 48 mm telephoto lens to capture the perfect shot. (Requires iPhone 14 Pro or later.)Play back your Log videos in SDR or HDR with the vibrancy of the original scene by applying the Apple Log LUT. (Requires iPhone 15 Pro or later.)Record videos in Spatial Audio for even more realistic and immersive sound. (Requires iPhone 16.)Capture in 50 fps for additional editing flexibility and delivery options.Which of these new Final Cut features are you most excited about, and what Apple Intelligence upgrades do you hope to see in the future? Let us know in the comments.Best Mac and iPad accessoriesAdd 9to5Mac to your Google News feed. FTC: We use income earning auto affiliate links. More.Youre reading 9to5Mac experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Dont know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel0 Σχόλια 0 Μοιράστηκε
-
9TO5MAC.COMOG Facebook is back with big change to Facebooks iPhone appEarlier this year, Meta CEO Mark Zuckerberg said one of his biggest priorities for the year was to get back to some OG Facebook. Starting today, were seeing the fruits of that thanks to a new Friends tab rolling out inside the Facebook app.New Friends tab works the way Facebook used to, before it went downhillMike Isaac writes for The New York Times:The company said the Facebook app would now include a separate news feed for users that featured posts shared exclusively by peoples friends and family. The feature, called the Friends Tab, will replace a tab in the app that showed new friend requests or suggested friends. Friends Tab will instead show a scrolling feed of posts, such as photos, video stories, text, birthday notifications and friend requests. For now, it will be available to Facebook users only in the United States and Canada.This idea of having a central place of whats going on with your friends, that was like the magic of the early days of social media, said Mr. Alison, who is head of the Facebook app. Were making sure that theres still a place for this stuff on Facebook. It is something that shouldnt get lost in the modern social media mix.Changing one tab in the Facebook app may not seem like a big deal. But the new Friends tab delivers a key feature Facebook has long been missing.The original (OG) way Facebook worked was centered entirely on your friends and family.You friended various people, and updates they wrote and shared would appear in your feed.Over time, Facebooks main feed became packed with a variety of other content too. Suggested posts, content from brands, and a bunch of other clutter squeezed out what first made Facebook great.Now, this new Friends tab sounds like it will be what Facebooks main feed used to be, before it went downhill.Per the article, this change is rolling out today. I had to force quit the app before it showed up for me, but if youre not seeing it yet, and youre in the US or Canada, you should soon.What do you think of Facebooks new Friends tab? Let us know in the comments.Best iPhone accessoriesAdd 9to5Mac to your Google News feed. FTC: We use income earning auto affiliate links. More.Youre reading 9to5Mac experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Dont know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel0 Σχόλια 0 Μοιράστηκε
-
FUTURISM.COMJack Dorsey's Flailing Crypto Business Is Laying Off More Than 900 EmployeesIn recent years, the financial technology sector has been making bank. Between 2018 and 2023, the rapidly growing "fintech" industry rose to over $39 billion in revenue, with projections to hit over $1.5 trillion by 2030.Fintech is a sweeping industry that offers money tech to financial institutions or individual users and increasingly crypto services, itself amulti-billion dollartrade.But with crypto comes risk. Alot of risk. Despite some fintech tycoons'promises that crypto will enable "infinite growth," companies are brushing up against the limits of blockchain hype faster than they anticipated.The latest among them is Block, the financial service conglomerate owned by Twitter cofounder Jack Dorsey. Block encompasses massive fintech platforms like Cash App and Square, as well as more boutique crypto outfits like Bitkey, a digital crypto wallet started in 2023.Now the company is seeing brutal cuts. In an email titled "smaller block," according to TechCrunch, the company's billionaire CEO announced the layoffs of 931 Block employees, or about 8 percent of the company's total staff."hi all," the hip all-lowercase message opens, dripping in authenticity the way only a CEO's email can. "today well be making some org changes, including eliminating roles and beginning the consultation process in countries where required."Dorsey proceeds to announce immediate layoffs and an overhaul to Block's managerial strategies, including 80 manager layoffs and 193 demotions from manager to "individual contributor roles." It also includes the immediate closure of some 748 open jobs that Block had been hiring for."thank you to all those leaving us," the CEO concludes. "we will continue to honor [your work] by increasing our value to our customers, and therefore to all of our shareholders, including you."Though Dorsey cryptically insists that the layoffs are meant to flatten the "org so we can move faster and with less abstraction," the moves come as Block's ambitions dramatically shift from crypto makework to buy-now-pay-later schemes, a growing trend in the fintech sector. In that sense, the layoffs are probably a sign that the blockchain hype train which Dorsey eagerly jumped aboard back in 2021 was too good to be true.In November of 2024, for example, Dorsey announced he was "winding down" Block's crypto-arm, known TBD, which is now in a permanent state of "wound down," according to its website. It was a telling moment, as Dorsey once hailed TBD as the frontier of decentralized digital currency, drawing investment cash from around the world.Luckily for the remaining Block employees, predatory loans are Dorsey's bread and butter. In 2023, a scathing report by Hindenburg Research claimed that Block had dramatically overhyped its user counts, facilitated fraud, and preyed on low-income users. Though Cash App marketing hailed the platform's "instant deposit" feature as "magic," the report claims it was really a form of predatory payday loan that fueled upwards of 31 percent of the app's revenue."The 'magic' behind Blocks business has not been disruptive innovation," the report reads, "but rather the companys willingness to facilitate fraud against consumers and the government, avoid regulation, dress up predatory loans and fees as revolutionary technology, and mislead investors with inflated metrics."That in mind, maybe the best way to look at Block's layoffs isn't an end to the crypto boom, but a return to a time-tested fintech model.The CEO should be set either way, as the report summarized at the time: "in the meantime, Dorsey and top executives already sold over $1 billion in equity near the top, ensuring they will be fine regardless of the outcome for everyone else.More on FinTech: Elon Searching for Investors Gullible Enough to Pour More Money Into TwitterShare This Article0 Σχόλια 0 Μοιράστηκε
-
FUTURISM.COMWhile You're Churning Out Studio Ghibli Selfies With OpenAI, Remember That Hayao Miyazaki Called AI Art "Disgusting" and an "Insult to Life Itself"The internet has been flooded with pictures modified by OpenAI's new image tool to evoke the style of animation legend Hayao Miyazaki's work at Studio Ghibli.Despite going mega-viral to the point where OpenAI took down the free version of its in-app image generator the trend flies directly in the face of the animator's personal views on the tech. In a 2016 documentary, the filmmaker was shown a demo of an AI-animated 3D model."I am utterly disgusted," he said at the time, arguing that the demo reminded him of a friend with a disability. "If you really want to make creepy stuff, you can go ahead and do it. I would never wish to incorporate this technology into my work at all.""I strongly feel that this is an insult to life itself," he fulminated.The latest trend spawned countless images that went viral, from Ghibli renditions of the JFK assassinationto the photo that showed Donald Trump hanging out with Jeffrey Epstein and, of course, 9/11.While it's far from the first time a generative AI-inspired trend has gone viral on the social media platform, the extent to which the Ghibli meme has taken off is notable.Even OpenAI CEO Sam Altman wasn't spared, complaining in a Wednesday tweet that "no one" cared about his career until you "wake up one day to hundreds of messages: 'look i made you into a twink ghibli style haha.'""My timeline is AGI," Stability AI founder Emad Mostaque quipped with a joke about artificial general intelligence. "All. Ghibli. Images."Even famous retired boxer Mike Tyson uploaded a Ghibli-fied rendition of his own likeness while holding a white pigeon.Besides directly opposing the views and wishes of its creator, the trend also highlights the continued debate surrounding copyright and the overall rights of human artists and publishers.As 404 Media found, it's also trivially easy to generate pictures of far more graphic images in the style of Studio Ghibli movies, demonstrating OpenAI's woefully inadequate implementation of guardrails.It's an unfortunate new reality, greatly denigrating the iconic, hard work of human animators."Imagine being Miyazaki, pouring decades of heart and soul into making this transcendent beautiful tender style of anime, and then seeing it get sloppified by linear algebra," one user tweeted.Other users also pointed out generative AI's infamous strain on the environment ironic, given many of Studio Ghibli's films are about humanity's disregard for the planet and ecosystem."Irony is dead and all but its pretty depressing to see Ghibli AI slop on the timeline not only because Miyazaki famously thinks AI art is disgusting but because hes spent the last 50 years making art about environmental waste for petty human uses," another user tweeted.Share This Article0 Σχόλια 0 Μοιράστηκε
-
THEHACKERNEWS.COMNew Morphing Meerkat Phishing Kit Mimics 114 Brands Using Victims DNS Email RecordsMar 27, 2025Ravie LakshmananEmail Security / MalwareCybersecurity researchers have shed light on a new phishing-as-a-service (PhaaS) platform that leverages the Domain Name System (DNS) mail exchange (MX) records to serve fake login pages that impersonate about 114 brands.DNS intelligence firm Infoblox is tracking the actor behind the PhaaS, the phishing kit, and the related activity under the moniker Morphing Meerkat."The threat actor behind the campaigns often exploits open redirects on adtech infrastructure, compromises domains for phishing distribution, and distributes stolen credentials through several mechanisms, including Telegram," the company said in a report shared with The Hacker News.One such campaign leveraging the PhaaS toolkit was documented by Forcepoint in July 2024, where phishing emails contained links to a purported shared document that, when clicked, directed the recipient to a fake login page hosted on Cloudflare R2 with the end goal of collecting and exfiltrating the credentials via Telegram.Morphing Meerkat is estimated to have delivered thousands of spam emails, with the phishing messages using compromised WordPress websites and open redirect vulnerabilities on advertising platforms like Google-owned DoubleClick to bypass security filters.It's also capable of translating phishing content text dynamically into over a dozen different languages, including English, Korean, Spanish, Russian, German, Chinese, and Japanese, to target users across the world.In addition to complicating code readability via obfuscation and inflation, the phishing landing pages incorporate anti-analysis measures that prohibit the use of mouse right-click as well as keyboard hotkey combinations Ctrl + S (save the web page as HTML), Ctrl + U (open the web page source code).But what makes the threat actor truly stand out is its use of DNS MX records obtained from Cloudflare or Google to identify the victim's email service provider (e.g., Gmail, Microsoft Outlook, or Yahoo!) and dynamically serve fake login pages. In the event, that the phishing kit is unable to recognize the MX record, it defaults to a Roundcube login page."This attack method is advantageous to bad actors because it enables them to carry out targeted attacks on victims by displaying web content strongly related to their email service provider," Infoblox said. ""The overall phishing experience feels natural because the design of the landing page is consistent with the spam email's message. This technique helps the actor trick the victim into submitting their email credentials via the phishing web form."Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.SHARE0 Σχόλια 0 Μοιράστηκε
-
WWW.INFORMATIONWEEK.COMWhat FedRAMP Automation Means for CIOs at Government ContractorsCarrie Pallardy, Contributing ReporterMarch 27, 20255 Min ReadMichael Ventura via Alamy Stock PhotoThe US General Services Administration (GSA) announced plans for an overhaul of the Federal Risk and Authorization Management Program (FedRAMP). The new approach, dubbed FedRAMP 20x, will lean into automation to make authorization simpler, easier, and cheaper while continuously improving security, according to the GSA press release.InformationWeek spoke to four leaders in the private sector about the anticipated changes to FedRAMP, the potential impact, and how CIOs at government contractors can prepare.The ChangesFedRAMP was first established in 2011, about midway through Jonathan Alboums 11-year government career. He held multiple senior IT positions within the government, including CIO of the United States Department of Agriculture (USDA) before making the switch to the private sector in 2018, giving him exposure to FedRAMP as both buyer and service provider.Since the inception of the program, GSA has been trying to continue to make it better.I really see these changes as a continuation of those overarching efforts, Alboum, currently the Federal CTO at ServiceNow, tells InformationWeek. ServiceNow provides an AI platform, and it has 100 authority to operate (ATO) letters on file with FedRAMP.FedRAMP 20x has five main goals. The first focuses on automating the validation of FedRAMP security requirements. Under this new framework, more than 80% of requirements could transition to automated validation.Related:The second goal aims to reduce documentation requirements if companies pursuing FedRAMP authorization can demonstrate their existing best practices and security policies.Continuous monitoring is also one of the primary objectives of FedRAMP 20x. The updated model is promising a simple, hands-off approach that that leverages secure by design principles and automated enforcement.Through FedRAMP, GSA has played a role between contractors and government agencies. FedRAMP 20xs fourth goal emphasizes more direct relationships.A major objective is to reduce third-party involvement of the FedRAMP team in favor of more direct agency-provider interactions, Shrav Mehta, CEO of Secureframe, an automated compliance platform, explains in an email interview. Secureframe intends to pursue authorization under the new FedRAMP model.The final goal centers on innovation. Under FedRAMP 20x, companies will undergo automated checks and be able to make changes without additional oversight, granted they follow an approved process for doing so.As is often the case, more automation comes with the possibility of fewer staff. Federal News Network reports that FedRAMPs program management will be staffed by a few federal employees.Related:The Potential ImpactWhile the FedRAMP authorization process could look quite different with more automation, the underlying intent remains the same.You're always going to have a set of guardrails, a set of compliance rules that everybody's going to have to play by, says Kevin Orr, federal president for RSA, an identity security solutions company.RSA ID Plus for Government is FedRAMP authorized, and Orr has coached a number of companies through the process. He has seen firsthand how long it can take. It's anywhere from 18 to 24 months, he shares. I've been through this four times.Increased automation that cuts down on the amount of paperwork, time, and labor involved in achieving FedRAMP authorization could result in a less expensive endeavor.Today, there are nearly 400 FedRAMP authorized services, according to the FedRAMP marketplace. If the process becomes more efficient, and less expensive, more companies might be interested in pursuing authorization.The byproduct of that could be greater competition. [It] could be greater availability of capabilities that just don't exist today in the government sphere, says Alboum.Related:Continuous monitoring could offer advantages over a manual audit-based approach. We develop software and capabilities in a continuous manner. We're constantly improving them. So, a continuous authorization management approach is really much more appropriate, says Alboum.The hope is that continuous monitoring will lead to a more robust cybersecurity posture across the cloud-based tools in use within government agencies.There is optimism among companies that have achieved FedRAMP certification in the past. Sumo Logic, a cloud-native, machine data analytics platform, achieved FedRAMP Ready designation in 2019 and FedRAMP Moderate authorization in 2021.We need to maintain rigor in how we're evaluating technology to ensure that it's a secure solution for government agencies. But ultimately we're very welcoming of efficiencies gained throughout the process, Seth Williams, the companys field CTO, tells InformationWeek.What Comes Next?The promise of a less burdensome FedRAMP authorization process is exciting for government contractors, but there are still unknowns.We're a little bit in the wait and see [mode] because the devils in the details Exactly how are we going to do continuous monitoring? Orr asks. I don't think anybody really wants the government inside your network telling you what you do. But at the same time, we all stand up and sign up for a security pledge to make the nation a [safer] place. So, somewhere in between is probably the truth, and we'll see what comes out of it.It also remains to be seen how automation is applied and how it works in practice. What will the impact of reduced FedRAMP staffing be? What will more direct relationships between government agencies and contractors look like?The future of FedRAMP is likely going to be shaped with input from industry stakeholders. FedRAMP working groups will gather input from industry, ensure equal access to information, encourage pilot programs, and provide technical guidance before formal public comment and release, according to the GSA press release.GSA notes that low-impact service offerings will not require agency sponsorship under FedRAMP 20x, but relationship building will still be important as FedRAMP evolves. Some of that connection will be formed within those working groups. And contractors who want to work with government agencies will need to demonstrate the value of their service offerings.It's one thing to say, I want to work with the government, or I have the capability to work with government. Well, how does it provide value to a government agency? says Alboum. Relationships are still going to be very important, especially as we go through this period of significant change.How can government contractors, and companies eager to secure government customers for the first time, prepare?For government contractors, success will depend on their ability to provide immediate, comprehensive security insights and adapt to more dynamic compliance expectations, says Mehta.About the AuthorCarrie PallardyContributing ReporterCarrie Pallardy is a freelance writer and editor living in Chicago. She writes and edits in a variety of industries including cybersecurity, healthcare, and personal finance.See more from Carrie PallardyReportsMore ReportsNever Miss a Beat: Get a snapshot of the issues affecting the IT industry straight to your inbox.SIGN-UPYou May Also Like0 Σχόλια 0 Μοιράστηκε