Blog - Page 15 of 187 - Techbest - Top Tech Reviews In Australia

JBL Vibe Buds 2 – True Wireless Noise Cancelling Earbuds Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

JBL Vibe Buds 2 – True Wireless Noise Cancelling Earbuds Pure Bass Sound & Smart Ambient Technology, 4mics for Crisp, Clear Calls, up to 40Hrs of Playback, IP54 Dust & Water Resistant (Black)

“Malicious ‘Glassworm’ Malware Distributes Through Compromised VS Code Extensions”


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Glassworm Malware Intrusion on VS Code Plugins

Brief Overview

  • Glassworm malware has compromised a number of VS Code plugins.
  • The infection employs invisible Unicode characters to avoid detection.
  • More than 10,700 downloads compromised on the OpenVSX marketplace.
  • Malware functions via the Solana blockchain for command and control.
  • Attackers exploit alternative channels such as Google Calendar.
  • Ongoing threat with existing infrastructure and payload server.
  • Developers urged to review plugins and update credentials.

Grasping the Glassworm Malware Intrusion

Concealed malware intrusion on VS Code plugins

The Glassworm malware has surfaced as a considerable risk, targeting Microsoft Visual Studio Code plugins. Identified by Koi Security, this advanced worm utilizes invisible Unicode characters to embed harmful code, eluding both human oversight and detection tools. As of October 17, it had penetrated seven plugins on the OpenVSX marketplace, resulting in over 10,700 downloads.

How Glassworm Avoids Detection

By employing Unicode variation selectors, Glassworm’s code stays hidden from static scanners and human reviewers, resulting in developers unknowingly disseminating the malware. This stealthy method has outmaneuvered even GitHub’s diff view and syntax highlighting features.

Communication Using Blockchain

Glassworm utilizes the Solana blockchain for its command and control (C2) setup. It interprets base64-encoded data in blockchain memos to discover new payloads. The unchangeable nature of blockchain transactions creates an “unkillable infrastructure,” permitting attackers to refresh commands without concern of being removed.

Backup Channels and Payload Distribution

In addition to blockchain, Glassworm employs direct IP addresses and Google Calendar events as secondary channels. Malware traffic masquerading as legitimate Calendar events circumvents conventional security protocols. The Solana-connected server delivers an AES-encrypted payload, with decryption keys transmitted via HTTP headers, complicating interception efforts.

Propagation and Secondary Component: ZOMBI

The worm actively pursues credentials from npm, GitHub, OpenVSX, and cryptocurrency wallets to extend its reach. Glassworm’s secondary component, ZOMBI, transforms infected systems into proxy nodes, utilizing SOCKS proxies and WebRTC to evade firewalls. It also employs HVNC for discreet remote desktop access.

Ongoing Threat and Suggestions

Koi Security confirms that Glassworm’s infrastructure is still active, with operational payload servers and continuous data exfiltration. Developers are recommended to scrutinize their plugins and change any compromised credentials. Affected plugins include CodeJoy, l-igh-t.vscode-theme-seti-folder, among others.

Conclusion

The Glassworm malware intrusion underscores vulnerabilities within software supply chains, taking advantage of the invisibility of Unicode characters to conceal its existence. With an indestructible command infrastructure and advanced evasion tactics, Glassworm continues to pose a significant threat to developers globally.

Q&A

Q: What is Glassworm malware?

A: Glassworm is a malware worm that targets Microsoft Visual Studio Code plugins, using invisible Unicode characters to avoid detection.

Q: In what way does Glassworm evade detection?

A: It employs Unicode variation selectors to render its code invisible to both static scanning tools and human evaluators.

Q: What renders Glassworm’s command infrastructure unkillable?

A: It functions through the Solana blockchain, which is immutable, enabling it to modify commands without the risk of being terminated.

Q: How are developers impacted by Glassworm?

A: Developers unknowingly propagate malware through compromised plugins, resulting in potential data breaches and internal system compromises.

Q: What steps can developers take to safeguard themselves?

A: Developers should review their installed plugins, refresh exposed credentials, and stay alert against such intricate attacks.

Q: Is the threat from Glassworm still ongoing?

A: Yes, the infrastructure remains active, with operational payload servers and ongoing data collection efforts.

Skullcandy Sesh ANC XT Wireless Earbuds Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Skullcandy Sesh ANC XT in-Ear Noise Canceling Wireless Earbuds, 48 Hr Battery, IP67 Waterproof, Microphone, Works with iPhone Android and Bluetooth Devices – True Black

Federal Court Moves CourtPath to Microsoft Azure Cloud


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Quick Overview

  • The Federal Court of Australia is migrating its CourtPath system to Microsoft Azure.
  • This change aims to incorporate cloud-based AI services into CourtPath.
  • The migration is part of a broader cloud transformation strategy at the Court.
  • Objectives include enhancing case management functionalities through 2026.
  • The transition will also set the stage for overhauling the Commonwealth Courts Portal.
  • An AI-driven record management solution is projected for late 2025.

Shifting CourtPath to the Cloud

The Federal Court of Australia is advancing technologically by shifting its CourtPath case and document management system to the Microsoft Azure cloud platform. This transition is a tactical move to upgrade the system with sophisticated AI functionalities available through Azure.

Federal Court transitions CourtPath to Azure cloud

Boosting Efficiency with Cloud Technologies

Initially designed to unify various digital tools within the court system, CourtPath offers a consolidated platform for the upload and retrieval of documents pertinent to legal cases. The ongoing transition to cloud infrastructure aims to enhance operational efficiency and incorporate new AI tools.

Wider Cloud Transformation Efforts

Chief Information and Digital Officer of the Federal Court of Australia, Nathan Price, has stated that the shift of CourtPath to the cloud is a primary objective for the remainder of 2025. This effort is part of a larger initiative to evaluate and migrate additional court systems to the cloud, thus capitalizing on the vast AI and cognitive services provided by Microsoft Azure.

Upcoming Developments and AI Integration

Besides current updates, there are plans to utilize the cloud transition as a basis for the redevelopment of the Commonwealth Courts Portal. This portal is vital for external stakeholders, including law firms, to engage with and monitor legal cases. Additionally, an AI-enabled record management solution is expected to be launched by late 2025, improving adherence to record-keeping regulations.

Conclusion

The transition of the CourtPath system of the Federal Court of Australia to Microsoft Azure represents a major milestone in updating its technological infrastructure. By embracing cloud-native AI services, the Court seeks to enhance efficiency and establish a foundation for future improvements in case management and document access.

Q: What is CourtPath?

A: CourtPath is an internal case management platform that facilitates the consolidated upload and access of documents related to legal proceedings within the Federal Court of Australia.

Q: Why is the Federal Court migrating CourtPath to Azure?

A: The migration to Azure is intended to integrate advanced cloud-based AI services to improve the capabilities and efficiency of the system.

Q: What future initiatives are planned after this transition?

A: After the transition, plans include the redevelopment of the Commonwealth Courts Portal and the introduction of an AI-enabled record management solution by late 2025.

Q: How will the AI integration benefit the CourtPath system?

A: AI integration will enhance the system’s case management features, increase efficiency, and ensure compliance with record-keeping standards.

CMF by Nothing Buds 2 Wireless Earbuds Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

CMF by Nothing Buds 2 Wireless Earbuds, 48dB Hybrid ANC, Dirac Opteo Hi-Fi Sound, Ultra Bass 2.0, 6 HD Mics with Clear Voice 3.0, IP55 Waterproof, Bluetooth Earphones with Dual Connection, Light Green

Significant Service Interruption: AWS Outage Affects Snap, Canva, Ring, Telstra, Steam, and Others


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Quick Read

  • Amazon Web Services (AWS) outage leads to worldwide disruptions.
  • Impacted services comprise Snap, Canva, Ring, Telstra, Steam, and others.
  • Outage linked to the AWS US-EAST-1 region, affecting more than 35 services.
  • Notable increases in error rates and latencies reported.
  • AWS engineers are diligently working to fix the issue.

AWS Outage Disrupts Major Services Around the Globe

The recent significant outage of Amazon Web Services (AWS) has resulted in extensive disruption among various online services. This event underscores the substantial dependence on AWS as a foundation for internet infrastructure.

What Occurred?

On October 20th, AWS faced heightened error rates and latencies, significantly affecting the DynamoDB endpoint in the US-EAST-1 region. This led to more than 35 services being impacted, with users globally facing considerable service interruptions.

Services Affected

Per Downdetector, the outage has impacted a wide array of services. Some of the most prominent include:

  • Snapchat
  • Canva
  • Ring
  • Telstra
  • Steam
  • Amazon.com
  • Zoom
  • National Broadband Network (NBN)

The outage highlights the extensive influence AWS has on numerous sectors, ranging from gaming and social media to vital communication services.

Response and Recovery Efforts

AWS has acknowledged the problem on their AWS Health Dashboard and has indicated that engineers are actively engaged in addressing the situation. Ongoing efforts are aimed at pinpointing the root cause and restoring complete functionality to the impacted services.

Understanding Internet Infrastructure Resilience

This event serves as a reminder of the necessity for strong internet infrastructure. Although AWS usually guarantees a 99.999% uptime, outages can still happen, accentuating the need for ongoing enhancements in reliability and contingency preparedness.

Summary

The AWS outage has caused considerable disruptions across various platforms, impacting both users and service providers. As AWS endeavors to resolve the issues, this occurrence highlights the essential role of cloud services in the present digital environment.

Q&A

Q: What triggered the AWS outage?

A:

The outage arose from increased error rates and latencies in the AWS US-EAST-1 region, particularly affecting the DynamoDB endpoint.

Q: How many services were impacted by the AWS outage?

A:

More than 35 services, including key platforms like Snapchat, Canva, and Telstra, faced disruptions.

Q: What actions is AWS taking to address the issue?

A:

AWS engineers are actively focused on mitigating the issue and identifying its root cause to restore full service operations.

Q: How can users keep updated on AWS service status?

A:

Users can check the AWS Service Health Dashboard for the latest information on service status and recovery updates.

Q: Why is this outage important?

A:

The outage highlights the significant dependence on AWS for numerous online services, impacting a vast range of sectors worldwide.

AWS Downtime Disrupts Major Services Globally

ASIC’s Payroll Revamp Eases Employee Shift from ATO


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Quick Overview

  • ASIC is shifting from PeopleSoft to Aurion for payroll handling by the close of the year.
  • This shift enabled the return of 200 personnel from ATO to ASIC.
  • Aurion accommodates numerous enterprise agreements, assisting in smooth staff relocations.
  • ASIC committed $1.1 million to Aurion for payroll software and ongoing expenses through June 2027.
  • This change is part of a comprehensive upgrade of management systems, which includes a new ERP system.

Detailing the Payroll Transition

The Australian Securities Investments Commission (ASIC) is on course to finalize a crucial transition from the PeopleSoft payroll system to Aurion by year-end. This change signifies a major advancement in ASIC’s overall plan to enhance its management systems, including the launch of a new enterprise resource planning (ERP) system from Technology One.

ASIC's payroll overhaul enables staff return from ATO

Seamless Staff Transition

The initial stage of this transition, finalized in April, witnessed 200 employees revert to ASIC from the Australian Taxation Office (ATO). This change was prompted by the cancellation of the Modernising Business Registers program by the government, which led to business registers and related services being reassigned to ASIC in May 2024.

Advantages of Aurion’s Dual Agreement Capability

The transition was aided by Aurion’s capacity to manage dual enterprise agreements, accommodating staff under both ATO and ASIC contracts. This adaptability guaranteed a smooth relocation for personnel returning to ASIC.

Financial Commitment and Future Initiatives

ASIC has allocated $1.1 million to Aurion for the deployment of payroll software-as-a-service, with the agreement lasting until June 2027. The next phase, which will transfer current ASIC staff to the new system, is anticipated to be concluded by the end of the year.

Comprehensive Management Systems Update

This payroll transition is an integral part of ASIC’s wider efforts to modernize its management systems. The agency is also implementing a Technology One ERP system, moving away from the existing PeopleSoft Financial system. In addition, ASIC is focusing on the implementation of a new capital management system.

Overview

ASIC’s transition in payroll from PeopleSoft to Aurion signifies a pivotal advancement in updating its operational framework. This change not only supports the efficient transition of personnel from the ATO but also aligns with ASIC’s larger strategic goal of enhancing its management systems.

Q: What led ASIC to shift from PeopleSoft to Aurion?

A: The shift is part of ASIC’s comprehensive management systems enhancement, aimed at modernizing its operational framework.

Q: How many personnel were involved in the transition?

A: The first phase of the transition saw the return of 200 personnel from the ATO to ASIC.

Q: What function does Aurion serve in the transition?

A: Aurion’s payroll solution supports dual enterprise agreements, facilitating effortless staff transitions between ATO and ASIC.

Q: What is the financial scope of ASIC’s collaboration with Aurion?

A: ASIC committed $1.1 million to Aurion for payroll software implementation and recurring license fees until June 2027.

Q: When is the transition expected to be finalized?

A: The full transition to the Aurion payroll system is expected to be completed by year’s end.

Q: What other systems are under upgrade at ASIC?

A: In addition to the payroll transition, ASIC is implementing a Technology One ERP system and a new capital management system.

Google Pixel Buds 2a Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Google Pixel Buds 2a – Wireless Earbuds with Active Noise Cancellation – Lightweight, Comfortable Fit – Water Resistant – Bluetooth Compatible – Hazel