Publié le Laisser un commentaire

Microsoft Warns Millions Of Windows Users—Change Your Browser To Stop Attacks – Forbes

New warning hits millions of Windoes users
The FBI has just issued a new email attack warning, advising users how to stay safe, as holiday season attacks surge. Alarmingly, phishing emails and malicious websites are now aided by new AI tools that make everything more likely to trick users into becoming victims. Multiple warnings in recent weeks have confirmed this is the most dangerous holiday season ever for email and web attacks.
Against this backdrop, Microsoft is again pushing Windows users to switch to Edge, which it says “helps you stay protected while you browse by blocking phishing and malware attacks.” This has become a repeated theme—system messages that push Microsoft’s products under a security pretext. It’s a definite grey area.
As spotted by Windows Latest, “new references to some potential new pop-ups in Edge encourage users to get back to Microsoft Edge. One reference is titled ‘msNurturingDefaultBrowserBannerUX2OneBtn,’ and likely points to some button in the browser encouraging people to set it as the default browser.” This it says is “all part of the tech giant’s efforts to bring more people to Microsoft Edge.” Albeit these latest changes are still in development and have not been released yet.
While Edge has been creeping up on Chrome—to an extent, Google’s browser still dominates the Windows desktop market with four-times the number of Edge users, even as Microsoft’s browser has grown its market share a couple of points in 2024.
“Could this help change the tide and encourage more people to try Microsoft Edge?” Windows Latest asks. “It’s possible.” Yes, possible but unlikely. Despite campaign after campaign, and even with multiple privacy and security stories over recent years, Chrome’s user base has shown itself to be as hard to shake as Windows 10’s.
Microsoft browser completely with giant cursor
But there is potential change in the coming months, and it has nothing to do with Microsoft’s popups or its security and safety campaign. The biggest threat to Chrome remains a regulatory one, with the DOJ still threatening to force its divestment from Google. A move Google says would be an “extreme” remedy.
Meantime, Windows users will likely just have to ignore the latest popup campaign, even with the giant cursor per Windows Latest’s screenshots. “What even is that,” they say—and rightly so. The bigger issue even than the huge cursor is the button choice. ‘Confirm’ changes the default browser to Edge, while ‘Set Later’ means “you’re basically confirming your approval for another follow-up pop-up in Microsoft Edge. This doesn’t mean you do not want Edge as your default browser, and unfortunately, it’s not possible to remove these messages.”
Almost all Microsoft’s Edge pushes have used security as their driving theme. The same has been seen in the Chrome setup process on a new Windows install. While arguably there are security advantages in Edge over Chrome, Google is narrowing the gap. Its latest AI-powered scam detection echoes the same feature coming to Edge.
Where Microsoft is likely to find more success is the enterprise market, where it argues that a joined-up solution comprising its various security platforms and services is a safer bet for a CISO than a mixed bag of offerings. Clearly if people get used to Edge at work they may do the same at home.

One Community. Many Voices. Create a free account to share your thoughts. 
Our community is about connecting people through open and thoughtful conversations. We want our readers to share their views and exchange ideas and facts in a safe space.
In order to do so, please follow the posting rules in our site’s Terms of Service.  We’ve summarized some of those key rules below. Simply put, keep it civil.
Your post will be rejected if we notice that it seems to contain:
User accounts will be blocked if we notice or believe that users are engaged in:
So, how can you be a power user?
Thanks for reading our community guidelines. Please read the full list of posting rules found in our site’s Terms of Service.

source

Publié le Laisser un commentaire

Take One Take Two: Favorite Christmas movies from the past 4 decades – Sentinel-Tribune

“It’s beginning to look a lot like Christmas, everywhere you go…”
Those that have read our past Christmas columns know our love for nostalgic 1940s holiday films. Although they are limited in number, there is no doubt that they capture the heartbreak and joy found throughout the United States in the WWII era. Films like “Remember the Night” (1940), “Holiday Inn” (1942), “Meet Me in St Louis” (1944), “Christmas in Connecticut” (1945), “It’s a Wonderful Life” (1946), “The Bishop’s Wife” (1947), and “Miracle on 34th Street” (1947) may be old chestnuts, but we still watch them every year between Thanksgiving and Christmas day.
That’s not to say there are no modern Christmas classics. Recent successful Christmas films include: “A Christmas Story” (1984), the first two “Home Alone” films (1990, 1992), “The Santa Claus” (1994), “Elf” (2003), “Bad Santa” (2003), and Tim Burton’s “The Nightmare Before Christmas” (1993). And leave it to Hallmark to flood the television airways with over 500 dull Christmas movies on their multiple channels beginning in October each year. Most have production values and storylines best reserved for the dustbin of television history. To counter those, let’s explore a few of our favorite Christmas movies from the past 40 years.
Take One
One of the stranger Christmas movies to have emerged in the past two decades is a small Norwegian thriller (yes, that’s right), called “Rare Exports: A Christmas Tale” from 2010. This one is about as far as you can get from traditional feel-good fare. Indeed, in this small Norwegian village, Santa Claus is a demonic spirit who regularly butchers’ children to feed his pagan overlords. If that doesn’t sound like a terrifying rewrite of all Christmas lore, it is, if nothing else, tons of fun to watch an anthropomorphic, spider-like Santa Claus mow down straphangers by the dozens. Unless you happen to be a fan of the Norwegian zombie franchise “Dead Snow,” the cast and crew will be foreigners to Hollywood audiences, and the film has remained a bit of an anomaly to anyone except die-hard horror fans.
Our first Christmas column, three years ago, we wrote about short Christmas movies; the animated “Peace on Earth”(1939) and “Star in the Night”(1947). In that vein, the next one is easy to find, and that’s because it’s only three minutes long. SNL, at the peak of their mid-2000s heyday, took a break from lampooning Bush and Kerry to craft a gemstone parody of a music video called “Christmastime for the Jews.” Based directly off the Darlene Love/Phil Spector-produced “Christmas (Baby Please Come Home),” and all the more magical because Darlene Love actually sings the parody herself! Shot in the Claymation style of many 1960s television shorts, the song is a playful takedown of the Christmas-Industrial-Complex by portraying Dec. 25th as the one day in which city-dwelling Jews can have fun and enjoy themselves without the bother of all those pesky gentiles. Wry lyrics by Robert Smigel keeps it witty, but it’s Darlene Love’s commitment that makes it soar.
Take Two
Our family always kicks off the holiday season with “National Lampoon’s Christmas Vacation” (1989) starring Chevy Chase, Beverly D’Angelo, Juliette Lewis, and Johnny Galecki as the Griswold family. Every holiday mishap known to mankind befalls the Griswolds as they host both sets of grandparents, as well as their lovable but repulsive cousin Eddie, marvelously embodied by Randy Quaid. The disaster of securing a real Christmas tree deep in the forests, decorating the outside of the house (“exterior illumination”), Clark’s shopping for ladies’ “unmentionables,” and the general chaos of having three generations under the same roof are all givens. And, for us, the delight is in picking apart and commenting on every flaw throughout the film. (Mountains in… Chicago??). Hearing Mavis Staples’ far-too-wonderful “Christmas Vacation” theme and watching the entertaining animated opening credits means it really is Christmas time.
One film of the past 25 years that will likely endure as a Christmas classic is “Love Actually” from 2003. With an ensemble cast that includes Hugh Grant, Emma Thompson, Liam Neeson, Keira Knightley, Colin Firth, Laura Linney and a dozen more international actors in 10 different storylines, set in and around London, and all interwoven into a single narrative. Director Richard Curtis’ various storylines involve drama, humor, music and the exploration of human longings that pull on the fabric of our love-seeking society. I especially enjoy the storylines involving Hugh Grant as the Kennedy-like Prime Minister of England, and Liam Neeson as the widowed father of a 12-year-old lovesick stepson. But Colin Firth and Lucia Moniz steal the movie as two language-challenged lost souls who find each other in a lakeside cottage in France. Throughout the film you lament jumping from scene-to-scene only to be quickly swept up in the next narrative.
All films are available on Amazon Prime and YouTube.
(This column is written jointly by a baby boomer, Denny Parish, and a millennial, Carson Parish, who also happen to be father and son.)

source

Publié le Laisser un commentaire

Hugging Face Released Moonshine Web: A Browser-Based Real-Time, Privacy-Focused Speech Recognition Running Locally – MarkTechPost

The advent of automatic speech recognition (ASR) technologies has changed the way individuals interact with digital devices. Despite their capabilities, these systems often demand significant computational power and resources. This makes them inaccessible to users with constrained devices or limited access to cloud-based solutions. This disparity underscores an urgent need for innovations that deliver high-quality ASR without heavy reliance on computational resources or external infrastructures. This challenge has become even more pronounced in real-time processing scenarios where speed and accuracy are paramount. Existing ASR tools often falter when expected to function seamlessly on low-power devices or within environments with limited internet connectivity. Addressing these gaps necessitates solutions that provide open-source access to state-of-the-art machine learning models.
Moonshine Web, developed by Hugging Face, is a robust response to these challenges. As a lightweight yet powerful ASR solution, Moonshine Web stands out for its ability to run entirely within a web browser, leveraging React, Vite, and the cutting-edge Transformers.js library. This innovation ensures that users can directly experience fast and accurate ASR on their devices without depending on high-performance hardware or cloud services. The center of Moonshine Web lies in the Moonshine Base model, a highly optimized speech-to-text system designed for efficiency and performance. This model achieves remarkable results by utilizing WebGPU acceleration for superior computational speeds while offering WASM as a fallback for devices lacking WebGPU support. Such adaptability makes Moonshine Web accessible to a broader audience, including those using resource-constrained devices.
Moonshine Web’s user-friendly design extends to its deployment process. Hugging Face ensures developers and enthusiasts can quickly set up the application by providing an open-source repository. Below are the steps and code required for deployment:
1. Clone the Repository
2. Navigate to the Project Directory
3. Install Dependencies
4. Run the Development Server  
The application should now be running locally. Open your browser and go to ‘http://localhost:5173’ to see it in action.
In conclusion, the development of Moonshine Web also highlights the importance of community engagement in advancing technological solutions. Incorporating an audio visualizer, adapted from an open-source tutorial by Wael Yasmina, exemplifies the collaborative ethos driving this project. Such contributions enhance the application’s functionality and inspire further innovations within the open-source ecosystem. Bridging the gap between resource-intensive models and user-friendly deployment paves the way for more inclusive and equitable access to cutting-edge technologies.
Check out the Model on Hugging Face. All credit for this research goes to the researchers of this project. Also, don’t forget to follow us on Twitter and join our Telegram Channel and LinkedIn Group. Don’t Forget to join our 60k+ ML SubReddit.
🚨 Trending: LG AI Research Releases EXAONE 3.5: Three Open-Source Bilingual Frontier AI-level Models Delivering Unmatched Instruction Following and Long Context Understanding for Global Leadership in Generative AI Excellence….
Aswin AK is a consulting intern at MarkTechPost. He is pursuing his Dual Degree at the Indian Institute of Technology, Kharagpur. He is passionate about data science and machine learning, bringing a strong academic background and hands-on experience in solving real-life cross-domain challenges.

source

Publié le Laisser un commentaire

‘Love & Marriage: Huntsville’ season 9, episode 8: Watch for free today – cleveland.com

"Love & Marriage: Huntsville" season 9, episode 8 airs today, Saturday, Dec. 21 on OWN. Here, Maurice Scott, Kimmy Grant Scott, Carlos King, Latisha Scott and Marsau Scott attend OWN's Love & Marriage: Huntsville Event with Carlos King at Nya Studios on November 06, 2024 in Los Angeles, California.Arnold Turner/Getty Images
The latest episode of “Love & Marriage: Huntsville” airs today, Saturday, Dec. 21, at 8 p.m. Eastern on OWN.
Cut ties with cable? You can still watch season 9, episode 8 for free on streaming services including Philo and DirecTV Stream.
On today’s episode, “Stirring the Pot Over Drinks,” Ken and Tricia argue with Marques at a family party. Meanwhile, Melody confronts Maurice about his DUI, and Chris insists that Nell go forward with their vow renewals. Kimmi approaches Melody about her insinuations over Maurice’s arrest and the lipstick that was on his mouth, OWN says.
The show centers around the lives of three high-powered Black couples who come together to bring back life to Huntsville, Alabama, through real estate venture The Comeback Group. The couples are friends and socialites with strong personalities and points of view. They each are facing realities of dealing with love and marriage while wanting to make this huge undertaking a success, OWN says.
More details on streaming service options available:
Philo charges users $28 a month after the free trial and offers more than 70 live channels and has an on-demand library with more than 70,000 movies and shows. It also offers access to premium add-ons including MGM+, STARZ, and The Movies and More package. It also has unlimited DVR storage so you can record and save your shows and movies for up to a year. Access a curated selection of free news, music, reality and classic TV channels.
DirecTV Stream has three packages you can choose from and enjoy a free trial. Right now, after you’ve enjoyed the free trial, you’ll get $15 off your first two months if you chose the Entertainment package. That package is $86.98 ($101.98 after promo). The streaming service is offering $20 off your first three months if you chose the Choice package ($94.99, then $114.99 after promo) or the Ultimate package ($109.99, then $129.99 after promo).
Kaylee Remington is the shopping and entertainment commerce reporter and metro reporter for cleveland.com and The Plain Dealer. Read her work online.
If you purchase a product or register for an account through a link on our site, we may receive compensation. By using this site, you consent to our User Agreement and agree that your clicks, interactions, and personal information may be collected, recorded, and/or stored by us and social media and other third-party partners in accordance with our Privacy Policy.
Use of and/or registration on any portion of this site constitutes acceptance of our User Agreement, (updated 8/1/2024) and acknowledgement of our Privacy Policy, and Your Privacy Choices and Rights (updated 1/1/2025).
© 2024 Advance Local Media LLC. All rights reserved (About Us).
The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Advance Local.
Community Rules apply to all content you upload or otherwise submit to this site.
YouTube's privacy policy is available here and YouTube's terms of service is available here.
Ad Choices iconAd Choices

source

Publié le Laisser un commentaire

KS Global Pharma Orlicz 1924 Suchedniów Defies the Odds – ETTU

A.S Pontoise-Cergy TT secured a 3-2 victory over KS Global Pharma Orlicz 1924 Suchedniów at home, but the result was insufficient for the French team to secure a spot in the Champions League Men quarterfinals. In the first leg, the Polish club had recorded a 3-1 victory, giving them the edge on aggregate.
Marcos FREITAS, absent from the French lineup last week, delivered an impressive performance, winning both his matches against Robert FLORAS and Deni KOZUL. Izaac QUEK YONG also claimed a victory over FLORAS. However, it was the nail-biting wins by KOZUL over QUEK YONG and Mateusz ZALEWSKI over Liam PITCHFORD that sealed Suchedniów’s advancement to the round of 8.
“It was a great match. We managed to win two points even without Kazuhiro YOSHIMURA, who led us to victory last time with two wins. We came mentally prepared, knowing everything depended on us. I’m thrilled to have avenged my 2-3 loss last week with a 3-2 win over Izaac QUEK YONG. In the decisive game, I had a 4-0 lead, which gave me the advantage I needed. Robert also played very well against Marcos in the opening match—it was close until the fifth game. But the most important win was Mateusz’s victory over Liam PITCHFORD—Liam was a clear favorite. This is a great Christmas gift. We’ll give our best to continue and aim for the Final 4,” said Deni KOZUL.
Previously, Polish team had to go through the group stage to earn their spot in the competition.
A.S PONTOISE-CERGY TT – KS GLOBAL PHARMA ORLICZ 1924 SUCHEDNIÓW 3-2
First leg
KS GLOBAL PHARMA ORLICZ 1924 SUCHEDNIÓW – A.S PONTOISE-CERGY TT 3-1
The duels in Group C of the Champions League Women Stage 2 have concluded. In the final match of the group, Saint-Denis 93 TT defeated ASD Quattro Mori 3-1, but…
Read more
Last year’s Final 4 winners, 1. FC Saarbrücken Tischtennis e.V., runners-up Borussia Düsseldorf, and semifinalists SolexConsult TTC Wiener Neustadt have all advanced to the quarterfinals of the Champions League Men….
Read more
French club GV HENNEBONT TT became the first team to advance to the quarterfinals of the Champions League Men after a dominant performance in both legs against Polish side UKS…
Read more
The Finnish table tennis season for 2024 concluded over the weekend in Helsinki, marked by a blend of competition and celebration. Over three days, more than 200 players, ranging from…
Read more
Contact
About Us
Privacy Policy
Terms and Conditions
The European Table Tennis Union (ETTU) is the governing body of the sport of table tennis in Europe, and is the only authority recognized for this purpose by the International Table Tennis Federation. The ETTU deals with all matters relating to table tennis at a European level, including the development and promotion of the sport in the territories controlled by its 58 member associations, and the organization of continental table tennis competitions, including the European Championships.
Powered By

source

Publié le Laisser un commentaire

Researchers Exploit Reflected Input with HTTP Range Header To Bypass Browser Restriction – CybersecurityNews

Security researchers have uncovered a technique that takes previously unexploitable reflected input vulnerabilities and turns them into fully functional attacks through clever use of HTTP Range headers.
The findings highlight a new potential threat vector for web applications once considered relatively secure.
Reflected input vulnerabilities have long been a concern, but they are often difficult to exploit due to limitations imposed by the context in which the malicious input appears.
For example, if an attacker injects code into a quoted HTML attribute, the browser’s rendering rules would prevent the attack from functioning properly.
However, a newly identified attack vector leverages the HTTP Range header to bypass such restrictions, potentially making these vulnerabilities far more exploitable.
The discovery came as part of extensive research into advanced techniques for detecting HTTP request smuggling and header injection vulnerabilities.
These vulnerabilities are already concerning due to their ability to bypass browser-imposed content restrictions such as Cross-Origin Resource Sharing (CORS) policies.
Researchers have now demonstrated how the Range header can be used to take unexploitable scripts and deliver them in fully functional form to victims.
The technique relies on two critical steps. First, an attacker finds a web endpoint that reflects user input back into the HTTP response but in a relatively “unexploitable” manner such as inside HTML attributes, where the malicious code would normally be neutralized.
Second, the attacker determines whether the same endpoint responds to the Range HTTP header, which is commonly used to request only partial content from a resource.
When combined, these two conditions pave the way for a creative exploit. The attacker sends a crafted request with the following elements:
For example, a request to a vulnerable endpoint might look like this:
If the server responds with a 206 Partial Content status code, along with the isolated malicious payload, the reflected code becomes fully functional. The victim’s browser executes the payload, typically enabling cross-site scripting (XSS) attacks.
In an illustrative example, a request that injects the payload (console.log('XSS')); into an endpoint of a website could result in a response like the following:
Browsers, which readily accept such unsolicited partial content responses, will then execute the isolated script. This creates an attack vector that bypasses common defenses typically applied to reflected input vulnerabilities.
From a defensive standpoint, this attack is particularly challenging to mitigate. Both prerequisites for the attack reflected input and support for the Range header—are relatively benign in isolation and are often overlooked in security assessments.
Reflected inputs that seem unexploitable and endpoints supporting partial content responses rarely warrant even a low-severity note in penetration testing reports.
The key to defending against this threat lies in understanding how seemingly minor issues can be combined into a functional exploit chain.
Security teams must monitor the interaction between reflected input vectors and the functionality of HTTP headers like Range.
Some potential mitigation strategies include:
This novel use of the HTTP Range header demonstrates how attackers can creatively combine seemingly harmless vulnerabilities into devastating exploits.
It reminds web developers and security professionals of the importance of viewing system behavior holistically, rather than treating vulnerabilities as discrete, unrelated issues.
For further technical information on the Range header and its behavior, developers can refer to the MDN Web Docs.
Researchers behind this finding credit their success to persistent curiosity and a refusal to ignore “intrusive thoughts” about potential exploits.
This discovery once again underscores the importance of out-of-the-box thinking in cybersecurity research. While no real-world incidents have been reported so far, the technique serves as a wake-up call for more robust web application defense strategies.
For More Interesting Daily Cybersecurity Stories, Follow us on LinkedInX and Google News

source