• How student loans impact workers long-term career choices
    www.fastcompany.com
    Student loan debt has an influence over borrowers career choices long after graduation, affecting their job satisfaction, career advancement, and investment strategies.According to a recent study conducted by MissionSquare Research Institute, the debt thats carried by one in four Americans under 40 affects job-acceptance decisions for 56% of public-sector employees and 62% of those working in the private sector.When they choose to accept . . . jobs, [the] majority of them have considered how that position or that job can help them with their student loan debt, says the reports author and MissionSquares head of research, Zhikun Liu. It not only impacts peoples day-to-day financials, but also their morale at work, job acceptance, as well as their retention.While most professionals take salary into consideration, Liu says borrowers are more likely to view compensation as a top priority, even at the expense of other factors like job satisfaction or advancement opportunities. That was especially true among male, Black, and Hispanic borrowers, according to the survey, who were about 10% more likely to view the debt as a significant factor in their career choices.Perhaps that is why retention rates were significantly lower among borrowers, with just 39% saying they wanted to stay with their current employer, compared with 61% of those without student loans.We find that student debt leads to short-term financial planning and limited investment opportunities, which in turn hinders wealth accumulation and retirement planning, Liu says. They cannot take more risks, and their financial planning horizon is within the next few months, or within the year, versus [planning for] the next five, 10 years.Borrowers are less satisfied with their jobs long after graduationAccording to the study, younger workers are more likely to say that student loan debt has limited their career advancement opportunities. Borrowers of all ages, however, report higher levels of career dissatisfaction and lower levels of loyalty to their current employer.According to the MissionSquare survey, more than a third of borrowers said the debt has served as a barrier to career advancement. Furthermore, while 18% of public sector employees without student loan debt report low work morale, the proportion jumps to 23% among borrowers.It does force some trade-offs, says Cassie Spencer, a career coach who works with students, recent graduates and mid-career professionals. You may need to live at home for longer, if you can, or move to a smaller city with more affordable living costs, but that can mean [fewer] job growth opportunities.Not being able to afford rent in a major city while paying down student loans or feeling pressure to take a less desirable jobor one with more limited career advancement potentialto secure a higher starting salary can reduce borrowers job satisfaction, employer loyalty, and long-term prospects.Furthermore, as graduates get older, Spencer says the debt often forces borrowers to delay major milestoneslike purchasing a home, starting a family, starting a business, or changing careerswhich can make them feel stuck.It becomes a decision of, do I continue to work in this job or this industry that I dont love, or that I feel is having a negative impact on my life and my mental health, for something that could be better, even though the pay is not there? she says. A lot of people in their early to mid-30s are not homebuyers yet; a lot of people are delaying starting a family; and theres a lot of factors, but I think student loan debt is one of those factors.Borrowers are better at pursuing professional developmentThough there are many challenges associated with student loan debt, its not all bad news for borrowers. This research suggests the added burden inspires them to pursue more professional development and educational credentials.According to the MissionSquare study, those with student loan debt are 37% more likely to say they are pursuing a professional development goalsuch as new skills, responsibilities, leadership opportunities, and credentialsor have already achieved it.The desire for additional skills training at an affordable rate and at a quick pace has inspired many borrowers to pursue one-year masters programs that begin during undergrad, often referred to as accelerated Masters or four-plus-one programs. The influx of four-plus-one programs and the rise in students specifically looking for accelerated, shorter-term programs is astronomical, Spencer says.She adds that such programs can help recent graduates begin their careers at a higher salary level, though there are risks, as it does add to their debt and makes it harder to switch careers later on.Gen Z is already a generation that really does want to invest in their skills, and they want employers that are going to invest in them, says Christine Cruzvergara, the chief education strategy officer for Gen Z career platform Handshake. For those with student loans in this generation, its even more so.The long-term financial implications of student loan debtTaking on such a significant debt load at such a young age can also make it harder for borrowers to set and achieve long-term financial goals.Borrowers are less likely to also be investors, according to the MissionSquare study, and those that were reported a much shorter investment horizon. As a result, public sector employees with student loan debt were 14% more likely to strongly agree that their retirement savings are inadequate, as well as 9% of private sector staff.According to a recent survey conducted by Handshake 54% of borrowers say their student loan debt is a major source of stress, including 61% of Black and first-generation borrowers.For some it can be crippling because they either dont have the support or the knowledge or the teaching from anyone to know how to manage all of this, Cruzvergara says, adding that it can also inspire borrowers to learn about personal finance sooner. You can choose to make this motivational for you, and, quite frankly, get smart about your finances very early in your life.How employers can help student borrowersand themselvesCruzvergara advises all young peoplebut especially borrowersto seek out the education and advice they need to manage their money responsibly.She also implores organizations seeking to hire young talent to offer student loan repayment plans, a perk which 25% of undergraduates in the Handshake survey say is essential, but one that just a tenth of full-time employers offer.With most of this years graduates leaving school with debt, Cruzvergara says employers should also remain open-minded about where theyre recruiting from. After all, in an environment where loans can have lasting career and lifestyle implications, some of the savviest students are intentionally turning down brand-name schools for more affordable alternatives.It doesnt mean the student couldnt get into the expensive private school that has a better brand name, but maybe it does mean that that student made a smart financial decision from the get-go not to take on all of that debt, she says. So, that talent might actually be just as good, just as smart, just as intelligent, but may not be at the brand name school that the employer has historically recruited at.
    0 Комментарии ·0 Поделились ·53 Просмотры
  • ColorWave AirPods Retro is a cute homage to classic Apple computers
    www.yankodesign.com
    Everything old is new again, or at least thats often the case in the world of design. Whether its fashion, architecture, or product design, trends come and go and sometimes return. Of course, only the more memorable ones stand the test of time, reviving after a decades-long slumber to make its existence known to new generations. Right from the start, Apple products have such holding power, so its not unusual to see some of those designs return again and again, sometimes in forms with no relation to the original.While good designs are timeless, the better ones not only inspire future products but can also be applied to other objects as well. The Apple AirPods might not have screens, at least not yet, but this retro facelift does more than give them a new aesthetic but also makes them look like a part of iconic Apple computers from ages past.Designer: ColorWaveBecause the IBM PC and its clones were the most ubiquitous during the early days of personal computers, the Apple Macintosh easily stood out as something unique and different. It had a very different aesthetic and appeal, targeted less at number-crunching office workers and more at creative thinkers, artists, and designers. It laid the foundations for Apples image as a design-centric company and its designs to become iconic templates in the future.That future comes today in the form of ColorWaves AirPods Retro designs. Covering both the AirPod Pro 2 and the AirPods 4, these special edition earbuds bear the iconic beige color of the classic Macs. Breaking the monotony of the color is the hinge with a rainbow design reminiscent of Apples original logo. They might not have the fancy screens of newer earbuds smart cases, but they still have that unmistakable feel of being a part of a larger computer.This isnt just some common paint job, though. The are actual machined grooves on the sides of the cases, further reinforcing that association with Apples first computers. Its a small yet significant detail that collectors will surely enjoy.One slight twist to this retro design is the dark variant, a color never used by the old Macintosh and a rarity for AirPods today. It gives buyers an option to have that much-requested Black AirPods while also paying tribute to Apples history. The ColorWare AirPods 4 with ANC Retro go for $239 while the AirPods Pro 2 Retro costs $499, both twice the price of their regular counterparts.The post ColorWave AirPods Retro is a cute homage to classic Apple computers first appeared on Yanko Design.
    0 Комментарии ·0 Поделились ·44 Просмотры
  • 0 Комментарии ·0 Поделились ·52 Просмотры
  • The New York City Subway Is Using Google Pixels to Listen for Track Defects
    www.wired.com
    New York City's transit authority is one of a few US systems experimenting with using sensors and AI to improve track inspections.
    0 Комментарии ·0 Поделились ·47 Просмотры
  • How to log out of streaming services on vacation TVs after youve left
    www.macworld.com
    MacworldIts easier than ever to carry streaming accounts with us as we travel for work or pleasure. Many hotel rooms, Airbnbs, and other properties have smart TVs or set-top boxes from Roku and others that let us log in to Netflix, Hulu, Apple TV+, and other services. Some of these devices are configured so that after you check out, the configuration is refreshed, and any account information is removed. But not allespecially not in the informal world of Airbnb, VRBO, and other rental arrangements.On a recent trip, I realized when I was hundreds of miles away that I had a mental note to log out of streaming TV servicesand that note was absolutely still unchecked. Fortunately, streaming services track your authorized, connected devices and have a variety of pathways to bump systems you want to disconnect from.Apple makes it easy to remove devices that can stream.Heres how for services that document individual device deregistration or for which Ive found an answer:Amazon Prime Video:Go toManage Your Content and Devices. Click Prime Video. Find the device by name or registration date, and then click the Deregister button and click Deregister to confirm.Apple TV+:You can use your iPhone, iPad, Mac, or Apple Account to remove an associated device from Apple TV+. On an iPhone, iPad, or Mac, go to Settings/System Settings, tap or click the account name, scroll down, and find the device on a list. The devices name will have a generic header, like Vizio, and then part of a serial number or identifier. Tap or click the device, tap or click Remove from Account, and confirm. To use your Apple Account, log in ataccount.apple.com, click Devices, click the TV or other streaming device, click Remove from Account, and confirm.Crunchyroll:Usingthe website, navigate to Settings > General > Device Management. Find the device by name, click Deactivate next to its name, and confirm the removal.Discovery+:Go todiscoveryplus.com, sign in, select your profile in the upper-right corner, and choose Account. Go to Devices > Manage Devices, click Remove next to the named device, and confirm.Disney+:Go toyour account page at Disney+, click Manage Devices, and click Log Out below the device you want to remove, then confirm.Fubo:Go to fubo.tv, navigate to your account, and choose Device Manager. Look for Devices outside your Home Network, find the device, click Remove Device, and confirm.Hulu:Go to a Hulu app orhulu.com, navigate to your Account page, and, under Watch Hulu on Your Devices, click Manage Devices. Click Remove and confirm the removal next to any device you want to delete.Max:Connect to your Max account through an app orhttps://max.com, choose your profile, then choose Account > Devices. Click the X next to the device you want to remove from your account and confirm.Netflix:In an app or athttps://www.netflix.com/choose your account. On an app, tap My Netflix, choose Account from the menu in the upper-right corner; at the website, click your account icon in the upper-right corner and choose Account. Tap or click Manage access and devices, tap or click Sign Out below the device you want to remove, and confirm.Netflix provides location information among other details to help you pinpoint a login or device.Ask Mac 911Weve compiled a list of the questions we get asked most frequently, along with answers and links to columns:read our super FAQto see if your question is covered. If not, were always looking for new problems to solve! Email yours tomac911@macworld.com, including screen captures as appropriate and whether you want your full name used. Not every question will be answered; we dont reply to emails, and we cannot provide direct troubleshooting advice.
    0 Комментарии ·0 Поделились ·51 Просмотры
  • Kandji exec: Vision Pro is a good fit for the enterprise
    www.computerworld.com
    Apples recentlyannounced partnership with Dassault Systems shows the Vision Pro as the cutting-edge enterprise solution it has become, but business users will want to ensure these devices can be managed like the rest of their critical IT infrastructure.Apple responded to this recently when itintroduced the tools device management vendors could use to deploy their mobile device management (MDM) solutions for visionOS devices. I caught up withKandjisJohn Richards, general manager for device management, to find out how and why the company this weekintroduced device management for Apples Vision device.Kandji puts its Vision on (MDM)Kandjis take on MDM for Vision Pro devices includes the kind of critical capabilities enterprises will demand from their tech. These include automated device enrollment, passcode policy management through the application of Apples Declarative Device Management (DDM), real-time compliance monitoring, and support for the full gamut of Apple device management but on the Vision Pro.The solution also includes complete device lifecycle management features such as custom profiles, real-time monitoring, detailed inventory tracking, and more, all managed from within the same console as the other systems Kandji supports.Like all device management vendors introducing support for Vision Pro, Kandji built its system using protocols provided by Apple.Were enabling organizations to confidently deploy Vision devices while maintaining enterprise-grade security, compliance, and performance, Kandji said in announcing this support.Apple in the enterpriseRichards explained that Kandji is supporting Vision Pro this way because its customers are using the headset. While he declined to be specific, citing customer confidentiality, he described a few of the ways companies are already usingApples spatial computing system.An architecture firm uses Vision Pro devices with their design team. Their designers use Vision Pro to create and review 3D architectural models using spatial computing capabilities, he told me. When deployed, the hardware is securely configured with specialized CAD applications and secure access to project files using Kandji.We are also seeing it used as a platform for enterprises to create an integrated package with their proprietary software to be used by customers, he said. One company, for example, is drastically lowering the cost of training pilots by allowing aspiring pilots to train using their simulation software customized for Apple Vision Pro as they transition from ground school to full, zero-hour flight simulators. This reduces the time that students need to spend using the much-more-expensive flight simulator.Success where it mattersJohnson rebuts the notion that because it isnt selling in iPhone-like quantities, Vision Pro has failed. The enterprise adoption data tells a different story, he said. Over 50% of Fortune 100 companies are already incorporating Vision Pro into their operations, and 67% of IT professionals see Vision Pros future as a business productivity solution. IDC projects the AR/VR headset market to reach 22.9 million units by 2028. These early indicators suggest were at the beginning of a transformation in enterprise computing.Vision Pro introduces new possibilities for business productivity and product creation through spatial computing. The device enables teams to work with digital information and collaborate in revolutionary ways while maintaining enterprise-grade security and management, Johnson said. With proper management tools, businesses can focus on leveraging these capabilities rather than wrestling with technical deployment challenges.Managing cutting-edge businessAs he sees it, the ability to manage Apples cutting-edge devices in the same way as we have become accustomed to managing all devices is critical. The key to Vision Pros success in enterprise isnt just about the fantastic hardware its about enabling organizations to deploy and manage these devices so they can successfully use them as a platform for innovation, Johnson said.Can Apple do more to nurture this part of its market? Johnson praised the company for building robust foundations for device management across its devices, but would like to see the capabilities of DDM extended, including the capacity to manage software updates and support for Lost Mode on Vision devices.He has no doubt Apple can make a dent in the enterprise universe, however: Apple is the only company on the market that can offer the security and privacy that comes when you own both the hardware and software, which makes it an ideal tool for organizations in a world with increasing cyber risks, he said. When you combine that with Apple becoming the preferred device for employees, theres a strong case for adopting Apple tech from a security and employee experience perspective.You can follow me on social media! Join me onBlueSky, LinkedIn, andMastodon.
    0 Комментарии ·0 Поделились ·50 Просмотры
  • Stupidity is usually just incuriosity
    blog.medium.com
    Stupidity is usually just incuriosityLeaving the company you founded + writing about your obsessions (Issue #277)Published inThe Medium BlogSent as aNewsletter2 min readJust now--The reality of a technical position, writes systems administrator Cooper Lund, is that most of what you do isnt what people think counts as technical work like writing code the majority of the work is being an investigator and a thinker.Essentially, his job is to be curious.Its true of most knowledge work: the job itself is primarily about how you solve problems, and arriving at a solution often comes from deep, relentless curiosity. The older I get, Lund writes, the more I understand that there arent a lot of people who are stupid, but there are a lot of people who are incurious. He refers to a story by Amy Schneider (who won 40 consecutive Jeopardy! games) as a prime example of how curiosity can enrich your life. It would be easy to dismiss Schneider as someone who simply memorized a bunch of trivia, but as she puts it:not only have I acquired the (fairly useless) knowledge of the definition of oviparous, Ive gained greater insight into how our society organizes itself, and the motivations (and thus implicit biases) that drive scientistsWhen you seek out the answer to anything even something as obscure as the definition of oviparous (a term to describe birds that hatch eggs) youll come across contextual information that reveals how the world works.Lund thinks AI could threaten our curiosity by giving us easier, ready-made answers (he calls it an incuriosity engine). But that doesnt have to happen! Its up to each of us to safeguard our curiosity, and to keep questioning the responses we get from anyone or anything, human or bot. For a primer on stoking your own curiosity, I recommend this story from Clive Thompson. It describes a process he calls rewilding your attentionessentially, expanding your info sources so you have wilder, curiouser thoughts. One tip: diversify your search engines! Thompson recommends a few weirder search tools than Google or ChatGPT, like Marginalia Search, an independent DIY search engine that focuses on non-commercial content.Harris Sockel Also todayAsh Jurberg describes how it feels to leave the company you founded and watch it grow without you: The statistics say 80% of business partnerships end in divorce double the rate of marriages yet were somehow always surprised when it happens to us.Author and podcaster Leah Nicole Whitcomb wants to read more stories by Black people that arent primarily about white supremacy.AIs real purpose: focing us all to Try Harder. (Thomas Ricouard) A dose of practical wisdom: On writingWriting isnt about following a trend. Its following the thing that wont leave you alone Yrsa Daley-Ward
    0 Комментарии ·0 Поделились ·16 Просмотры
  • Surpass Game secures $1.5m in pre-seed funding round
    www.gamesindustry.biz
    Surpass Game secures $1.5m in pre-seed funding roundFounded in January 2025, mobile developer will use investment to expand its team and optimise game development processesImage credit: Surpass Games News by Sophie McEvoy Staff Writer Published on Feb. 27, 2025 Surpass Games has raised $1.5 million in a pre-seed investment round led by Laton Ventures.As reported by Mobidictum, the Turkish mobile developer will use the funding to expand its team and optimise its game development processes for hybrid-casual puzzle games."To achieve our goal of becoming a leader in the hybrid casual market, we will rapidly expand our team and accelerate our game development processes following this investment," said Surpass Games founder and CEO Ensar Kelez."By optimising our games in every aspect, we wim to provide players with higher quality and more innovative experiences. With Laton Ventures' support, we strive to become the fastest-growing and leading company in this market."Laton Ventures co-founder Grkem Trk added: "Ensar has strong experience thanks to his deep involvement in successful hybrid-casual projects in the past."Surpass has managed to establish a strong team in a short period of time. At Laton, we will continue to support teams like Surpass, with high potential to become pioneers in the gaming industry."Surpass Games was founded in January 2025. Led by Kelez, the leadership team includes director of data analysis Bahadır Kelez, human resources manager Begm zdemir, finance manager Sedat Şeker, and senior game developer Yiğit Can Kus.
    0 Комментарии ·0 Поделились ·26 Просмотры
  • Running Point Review
    www.ign.com
    If there's one arena where Kate Hudson is an undisputed all-star, it's the comedy genre, and the new Netflix series Running Point certainly provides the court for the actor to perform her charm offense. Yet it's somewhat wasted in a series attempting to blend the idealistic gusto of Ted Lasso with the witty familial tensions of Succession, while doing justice to neither.Running Point takes place in the hypercompetitive world of professional basketball, where Hudson's tough-but-messy female protagonist Isla Gordon is thrust into the role of president for the LA Waves, "the greatest basketball franchise in the history of the game" and a business her family has run for decades. With the support of Ali (Brenda Strong), her sassy best friend and chief of staff, she has to prove herself in the sexist world of men's sports and break that glass ceiling for extremely rich, reformed party girls everywhere an overly sympathetic depiction of a difficult-to-relate-to character type that rarely offers any meaningful commentary on the wealth and comfort Isla otherwise lives in.From the get-go, Hudson's narration and flashbacks to a childhood of being overlooked by her formidable (and long deceased) father make it very clear that she's an expert on the game. But as she tries to secure team sponsorships and broadcast deals, rally players and turn the Waves losing season around, her expertise and decision-making are constantly questioned and disrespected This is mostly because she's a glamorous girl who likes to wear unbuttoned blouses and keeps banging into glass doors a running gag that quickly wears out its welcome.As with Succession, Isla is the only daughter among her fathers children but unlike that modern HBO classic, each of those brothers suffers from stock character syndrome. Ness (Scott MacArthur), a player-turned-Waves general manager, is a sweet but idiotic dude bro. Sandy (Drew Tarver) is her uptight, gay half-brother and the Waves chief financial officer. Cam (Justin Theroux) is the Type A eldest brother whose secret drug addiction lands him in trouble in the first episode, freeing up the Waves presidency for him to offer Isla just so she can keep his office warm while he's in rehab. Running Point GalleryThen there's affable and naive Jackie (Fabrizio Guido), who starts out selling concessions for the Waves before learning he has a more personal connection to the team: His late mother had an affair with Papa Gordon, who was Jackies biological father. Jackies scenes dangle awkwardly off the first couple of episodes, and then he spends the rest of the season trying to connect with the dysfunctional family he never knew he had. Ultimately, he serves as a tool to humanize these self-involved assholes, especially towards the tail end of the season when Ness, Sandy, and Isla let the sibling rivalry go and begin opening up to each other about each of their half-baked romantic subplots.Of course, it couldn't be a series about a woman leaning in without a personal cost, and from the minute Isla's pediatrician fiance Lev Levinson (Max Greenfield) is introduced, the sign-posting that they arent built to go the distance is egregious. Like the Gordons, Lev's characterization is thin hes generically nice, Jewish, and little else while Greenfield and Hudson's chemistry is so tepid that it's a real struggle to ever invest in their relationship. Especially with how often the camera lusts over the Waves divorced head coach, Jay Brown (Jay Ellis), whos thrown in as a hot, zen romantic rival to Lev. Ellis and Hudson certainly generate more heat, but Running Point never establishes a more intimate connection that might explain their attraction. As a result, this workplace romance comes off as trite.The writers are so desperate to make the Gordons likeable that they pull their punches.Therouxs screentime is limited, but his blunt delivery and cut-throat attitude make him the MVP of Running Point. He sharpens the comedy notes as Cam tries to undermine Isla and secure his release from rehab. Theroux earns extra laughs with his curt requests for drugs and attempts to fast-track his recovery; unfortunately, the writers are so desperate to make the other Gordons likeable that they pull their punches. There are some amusing slapstick scenes namely involving Ness' moronic behavior and comments towards his siblings and wife but the show rarely provides the type of biting dialogue that could puncture the familys arrogance or entitlement.And for a show that makes a song and dance about its female lead being an authority on basketball, Running Point really shortcuts how Isla manages to take the Waves from zeroes to heroes. Instead, the writers offer undercooked subplots about a redneck player with a painkiller addiction, a rookie struggling to score free throws, and a stoic star stepping up to lead. It does, however, outdo Ted Lasso when it comes to shooting some of its game sequences which, considering the soccer action on that Apple TV+ comedy, is admittedly a low bar. Still, there are pick-up games on TikTok that offer more athletic thrills than Running Point.
    0 Комментарии ·0 Поделились ·24 Просмотры
  • PolarEdge Botnet Exploits Cisco and Other Flaws to Hijack ASUS, QNAP, and Synology Devices
    thehackernews.com
    Feb 27, 2025Ravie LakshmananVulnerability / Network SecurityA new malware campaign has been observed targeting edge devices from Cisco, ASUS, QNAP, and Synology to rope them into a botnet named PolarEdge since at least the end of 2023.French cybersecurity company Sekoia said it observed the unknown threat actors leveraging CVE-2023-20118 (CVSS score: 6.5), a critical security flaw impacting Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers that could result in arbitrary command execution on susceptible devices.The vulnerability remains unpatched due to the routers reaching end-of-life (EoL) status. As mitigations, Cisco recommended in early 2023 that the flaw be mitigated by disabling remote management and blocking access to ports 443 and 60443.In the attack registered against Sekoia's honeypots, the vulnerability is said to have been used to deliver a previously undocumented implant, a TLS backdoor that incorporates the ability to listen for incoming client connections and execute commands.The backdoor is launched by means of a shell script called "q" that's retrieved via FTP and run following a successful exploitation of the vulnerability. It comes with capabilities to -Cleanup log filesTerminate suspicious processesDownload a malicious payload named "t.tar" from 119.8.186[.]227Execute a binary named "cipher_log" extracted from the archiveEstablish persistence by modifying a file named "/etc/flash/etc/cipher.sh" to run the "cipher_log" binary repeatedlyExecute "cipher_log," the TLS backdoorCodenamed PolarEdge, the malware enters into an infinite loop, establishing a TLS session as well as spawning a child process to manage client requests and execute commands using exec_command."The binary informs the C2 server that it has successfully infected a new device," Sekoia researchers Jeremy Scion and Felix Aim said. "The malware transmits this information to the reporting server, enabling the attacker to determine which device was infected through the IP address/port pairing."Further analysis has uncovered similar PolarEdge payloads being used to target ASUS, QNAP, and Synology devices. All the artifacts were uploaded to VirusTotal by users located in Taiwan. The payloads are distributed via FTP using the IP address 119.8.186[.]227, which belongs to Huawei Cloud.In all, the botnet is estimated to have compromised 2,017 unique IP addresses around the world, with most of the infections detected in the United States, Taiwan, Russia, India, Brazil, Australia, and Argentina."The purpose of this botnet has not yet been determined," the researchers noted. "An objective of PolarEdge could be to control compromised edge devices, transforming them into Operational Relay Boxes for launching offensive cyber attacks.""The botnet exploits multiple vulnerabilities across different types of equipment, highlighting its ability to target various systems. The complexity of the payloads further underscores the sophistication of the operation, suggesting that it is being conducted by skilled operators. This indicates that PolarEdge is a well-coordinated and substantial cyber threat."The disclosure comes as SecurityScorecard revealed that a massive botnet comprising over 130,000 infected devices is being weaponized to conduct large-scale password-spraying attacks against Microsoft 365 (M365) accounts by exploiting non-interactive sign-ins with Basic Authentication.Non-interactive sign-ins are typically used for service-to-service authentication and legacy protocols like POP, IMAP, and SMTP. They do not trigger multi-factor authentication (MFA) in many configurations. Basic Authentication, on the other hand, allows credentials to be transmitted in plaintext format.The activity, likely the work of a Chinese-affiliated group owing to the use of infrastructure tied to CDS Global Cloud and UCLOUD HK, employs stolen credentials from infostealer logs across a wide range of M365 accounts to obtain unauthorized access and get hold of sensitive data."This technique bypasses modern login protections and evades MFA enforcement, creating a critical blind spot for security teams," the company said. "Attackers leverage stolen credentials from infostealer logs to systematically target accounts at scale.""These attacks are recorded in non-interactive sign-in logs, which are often overlooked by security teams. Attackers exploit this gap to conduct high-volume password spraying attempts undetected. This tactic has been observed across multiple M365 tenants globally, indicating a widespread and ongoing threat."Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.SHARE
    0 Комментарии ·0 Поделились ·25 Просмотры