It’s getting to that time of year when music enthusiasts are patiently waiting for their yearly roundups from the best music streaming services and, as usual, details of Spotify Wrapped 2024 are very much hush-hush. However a few lucky YouTube Music subscribers have already spotted its 2024 music recap, which could point to an early release date and beat Spotify to the punch.
While YouTube and Google have yet to make an official announcement, Android Authority first reported that YouTube Music’s 2024 Recap seems to have been rolled out to very few lucky users - one of whom shared with the YouTube Music subreddit. In the Reddit post, the user attached two images (see below) with one showing their top five artists and tracks of the year, as well as their total minutes listened, and the other with their top five albums of the year.
Got my yearly recap from r/YoutubeMusicSince YouTube Music took a different approach with its yearly recaps in 2022, the music streaming service has always looked to the end of November for its official launch date, landing on November 29 in 2022 and November 30 in 2023. Therefore, we’re still about a week and a half off, but by the looks of its early drop for some subscribers it could be that YouTube Music will treat us to an early annual music roundup.
What does this mean for Spotify Wrapped 2024?There’s no doubt that Spotify Wrapped is one of the most recognized yearly recaps out of Apple Music, Tidal, and YouTube Music. But as far as its launch date goes, or even the features it may include, Spotify thrives off of the ambiguity and speculation about Wrapped. We still don’t know exactly when it will drop (my guess is the first week of December), but hopefully Spotify has seen that YouTube Music is teasing its yearly recap and will start to drop more hints.
You might also likeListening to your own voice saying words you’ve never said before is an unsettling experience, but in the AI future which we’re living through right now in 2024, it’s almost unsurprising. Of course, AI can now clone your voice and make it sound just like you! It’s almost expected, isn’t it?
What is surprising, to me at least, is how easy it is to do. You can access an AI voice cloner for free online, and clone your voice, then get it to say anything you want in just a few minutes. The training takes just 30 seconds, then you’re good to go. There are no real security checks or restrictions on what you can do with that voice once you’ve trained it either. So, you could make it swear, or threaten somebody. There seem to be hardly any guardrails.
Who's that voice?If you type in ‘AI Voice Cloner’ into a Google search bar you’ll be spoiled for choice. A lot of the voice cloners require you to sign up for a monthly fee before they will clone your voice, but quite a few of them have a free option. I tried a few of the free choices and some of them, despite promising unparalleled accuracy, produced a robotic version of my voice that was going to fool nobody. No, I had a higher goal in mind: I wanted to produce a clone of my voice that would fool my wife.
I eventually settled on Speechify to clone my voice, since it combined ease of use, full access to the voice cloner, and a 30-second training time. Once you’ve made a free account on Speechify you simply talk to your microphone for 30 seconds or longer to train your AI voice. Once you’ve done that you can type in some text and hit the Generate button to hear the words spoken back to you in your own voice.
If you're concerned about security, Speechify has a pretty detailed privacy statement, and it does say that it will never sell your information and is committed to protecting the privacy of your data. So, your uploaded voice should be for only you to use.
I thought what I created was pretty convincing, but I needed to see what my wife thought. I crept up behind her and played a sample clip of ‘me’ and… well ok, she laughed because she could tell it was coming out of my MacBook’s speakers, but she was impressed. "Actually”, she said, “I think it sounds like you, but better”.
And that is the benefit of cloning your voice. It doesn’t make mistakes when it talks. There are no ‘ums’ and ‘ahs’ and it gets everything right the first time. If I think about how many times I’ve had to record and re-record the intros to my podcasts because I couldn’t get it quite right, I can see an obvious application for an AI voice cloner. But that’s also a danger in AI voice cloning because you can get the fake voice to say just about anything.
Daisy, the AI granny, was an AI voice created to trap scammers into long and fruitless phone calls. (Image credit: O2 Virgin Media) Voices from the beyondWhile scams that involve stealing your voice are one level of concern, the security implications have ramifications that go even beyond the grave. Recently the legendary late British talk show host, Michael Parkinson, surprised everybody by announcing that he was launching a new podcast called Virtually Parkinson. Thanks to the miracles of AI his voice would be interviewing people in real time once again. In Parkinson’s case, his estate is fully behind the podcast, but what if permission has not been given?
David Attenborough, the grandfather of the BBC’s natural history programming recently expressed unease at an AI version of his voice, describing it as "disturbing". We live in an age where AI can create podcasts without any human interaction and even AI sports presenters are starting to appear. So, in a way, we shouldn’t be surprised that it’s so easy for AI to clone our voices, but the implications could be profound.
With AI giving celebrities (or rather, their estates) the option to continue working long after they have shuffled off this mortal coil, the future for both celebrities and individuals suddenly seems very uncertain.
You might also like...Hackers are hiding infostealers and other malware behind fake AI-powered photo and video editors, experts have claimed.
A cybersecurity researcher alias g0njxa found a socail media advertising campaign promoting the malware, posing as a fake editor called EditPro, and propped up an accompanying website editproai[dot]pro.
Then, they created deepfake videos of Presidents Trump and Biden enjoying ice cream together, and used them in ads posted on social media sites such as X. The fake editors were built for both Windows and macOS, but anyone who falls for the trick and downloads the program, will end up installing either Lumma Stealer or AMOS.
Lumma and AMOSLumma Stealer is a malware-as-a-service (MaaS) tool designed to steal sensitive information, including login credentials, cookies, browsing history, credit card data, and cryptocurrency wallet details.
The malware employs sophisticated techniques like process injection and encrypted communications with command-and-control servers, making it challenging to detect and mitigate. It has been active since 2022, with frequent updates enhancing its evasion and data theft strategies.
AMOS, short for Attack Management and Operations System, is a platform that enables threat actors to manage malware campaigns with minimal technical skills. It acts as a command-and-control (C2) system, and provides tools for deploying malware, managing infected systems, and exfiltrating stolen data.
It is typically used to coordinate large-scale attacks, automating many aspects of the cybercriminal workflow.
If you downloaded the fake EditPro software, assume that all of your passwords, and sensitive information stored on the device, are compromised. As such, make sure to first remove any traces of the malware from the computer, before updating all passwords and other sensitive data. Enable 2FA wherever possible, and move your cryptos and NFTs to a new wallet with a new seed phrase.
Via BleepingComputer
You might also likeEquinix has confirmed it will discontinue its bare-metal infrastructure-as-a-service (IaaS) platform from June 2026.
The decision to ax Equinix Metal was communicated to customers in a letter from Chief Business Officer Jon Lin and Chief Sales Officer Mike Campbell, giving a warning period of more than 18 months.
New features are no longer being prioritized for Equinix Metal, however the company promises to continue delivering performance, security and stability features until it is sunsetted.
Equinix Metal given 2026 end-of-life dateEquinix’s bare-metal service is a fairly recent addition to the company’s portfolio. It came about after the company acquired hosting company packet for $100 million, but will have only been available for a period of around six years once it gets discontinued on June 30, 2026.
Besides continuing to offer the relevant updates, Equinix is also offering to support customers in transitioning to alternative solutions, including collocation, managed and third-party services.
The service has been launched to allow businesses to deploy x86 and Arm servers within Equinix’s data centers, however CFO Keith Taylor suggested that Metal accounts for just 1.25% of the company’s revenue, which ultimately led to the decision to end support for the product.
The company confirmed: “Equinix is moving towards the end-of-life for our bare metal as a service product as we focus on the growth and acceleration of parts of our business, like colocation, interconnection, and hyperscale.”
More broadly, in October 2024 Equinix signed a joint venture deal to raise $15 billion to build xScale data centers for hyperscaler clients in a nod to the surging demand for AI-driven workloads.
The decision to retreat from the market is also a reflection of the highly competitive landscape, dominated primarily by hyperscalers like Amazon Web Services, Microsoft Azure and Google Cloud.
You might also likeT-Mobile has joined the growing list of US telecom operators who have been breached by Salt Typhoon.
The company confirmed in a statement to the Wall Street Journal that while a breach had occurred, there was no evidence to suggest the attackers had accessed or exfiltrated any customer data.
“T-Mobile is closely monitoring this industry-wide attack, and at this time, T-Mobile systems and data have not been impacted in any significant way, and we have no evidence of impacts to customer information. We will continue to monitor this closely, working with industry peers and the relevant authorities,” the company said in its statement.
Salt Typhoon continues attackSalt Typhoon has been conducting a broad attack against US and Canadian telecommunications companies and internet service providers in what is thought to be a critical infrastructure mapping and espionage campaign.
The FBI recently confirmed the group had successfully gained access to networks and private communications of members of the US government.
The US government has also issued a warning through the Consumer Financial Protection Bureau (CFPB) for its workers to avoid using personal cell phones for work purposes, stating, “While there is no evidence that CFPB has been targeted by this unauthorized access, I ask for your compliance with these directives so we reduce the risk that we will be compromised.”
In a further statement to BleepingComputer, T-Mobile added, “Due to our security controls, network structure and diligent monitoring and response we have seen no significant impacts to T-Mobile systems or data. We have no evidence of access or exfiltration of any customer or other sensitive information as other companies may have experienced.”
The group is widely recognized as a Chinese state-sponsored threat actor and the campaign is thought to be a mapping and vulnerability hunting campaign for future attacks.
Other telecommunications companies affected by the same campaign include AT&T, Lumen Technologies, and Verizon, with the attackers potentially having access to customer data and networks for several months. A network used by US authorities to submit requests pursuant to court orders was also breached.
A roundup of T-Mobile breaches by BleepingComputer puts this as the ninth since 2019, with the company suffering a number of data leaks, attacks and extortion attempts.
You might also like"We have a problem here..." said the voice on the phone. Our customer hired us to test their computer systems for vulnerabilities…and we had just found a big one.
Our testing had uncovered a serious bug in the customer's firewall. This bug crashed the network, knocking the whole company offline. The bug was similar to the recent CrowdStrike flaw, but on a vastly smaller scale.
After a tense 30 minutes, we got the customer’s network back online. Our customer was appalled that in years testing, nobody thought to attack the firewall protecting the network. We did. Because that is what a black hat hacker might do.
Penetration testing, or "white hat” hacking, attempts to exploit weaknesses in systems, applications, or networks to determine how vulnerable the organization is to a data breach. The idea is for the “white hat” hackers (good guys) to find the flaws before “black hat” hackers (bad guys) do. For our customer, the test revealed a serious flaw in their network that they patched quickly, preventing another disaster.
Penetration testing is a vital part of building a secure environment, but it is not without risks. I did “white hat hacking” for years. Before you hire a penetration tester, here are some important issues to consider.
Risk is unavoidableIt is impossible to predict how systems may react to penetration testing. As was the case with our customer, an unknow flaw or misconfiguration can lead to catastrophic results.
Skilled penetration testers usually can anticipate such issues. However, even the best white hats are imperfect. It is better to discover these flaws during a controlled test, then during a data breach. While performing tests, keep IT support staff available to respond to disruptions. Furthermore, do not be alarmed if your penetration testing provider asks you to sign an agreement that releases them from any liability due to testing. The whole point of a test is to see what breaks. It is unreasonable to expect a penetration testing provider to shoulder the expense and liability of an outage or data loss due to testing.
Hacking the voidBlack hat hackers will attack anything and everything they can. Consequently, penetration tests must test everything. If parts of your network are excluded or systems are turned off, testers cannot assess their security. If you cannot test everything, then define a generous sample set that encompasses every possible type of system, application, and network you control. Likewise, testers cannot test something they cannot access. Testers will need access to all parts of the network to make the tests valid.
Path of least resistanceBlack hats will generally follow the path of least resistance to break into systems. This means they will use well-known vulnerabilities they are confident they can exploit. Some hackers are still using ancient vulnerabilities, such as SQL injection, which date back to 1995. They use these because they work. It is uncommon for black hats to use unknown or “zero-day” exploits. These are reserved for high-value targets, such as government, military, or critical infrastructure.
It is not feasible for white hats to test every possible way to exploit a system. Rather, they should focus on a broad set of commonly used exploits. Lastly, not every vulnerability is dangerous. A good white hat hacker will rank vulnerabilities based on how easily they are to exploit. Exotic or complex attacks may be interesting, but they consume time and can distract your team from the more mundane, and more likely to be exploited, vulnerabilities.
Skill mattersMost white hats use a broad set of tools for testing. While automated and AI tools can speed up the process, they are no replacement for skilled hackers with extensive IT knowledge and an understanding of human behavior. Before hiring a penetration testing company, validate the team's experience, ensuring senior members have at least five years of specific penetration testing experience. Be careful with testing providers that assign only junior or contracted testers.
Change testers regularlyWhile it is good to build relationships with testing providers, change companies annually to avoid complacency. Use a pool of three to five companies and rotate among them. Different companies have different skill sets. For example, my company was exceptionally skilled with attacking infrastructure, which is how we found the firewall bug mentioned at the beginning of this article.
Beware of "gotcha” testingA "gotcha test" focuses exclusively on breaking into the environment rather than assessing overall security. These tests will focus on a single exploit path and can miss many other exploitable avenues. A good testing company will conduct both a systemic assessment and a focused "black hat" style break-in.
Third party trapsOne of the most significant areas of weakness is third party applications or systems. Wordpress servers, for example, tend to be full of vulnerabilities due to the widespread use of third party plugins that do not undergo rigorous security testing.
Unfortunately, some vendors may specifically prohibit you from testing their systems. This can present a massive set vulnerabilities you cannot detect or defend against. Require third party vendors to either provide you with proof that they conducted their own independent penetration tests or permit you to perform testing with your own vendor(s).
Social engineering has limitationsSocial engineering tests trick employees into divulging confidential information through fake phone calls or phishing emails. These tests are overwhelmingly successful, because people are inherently trusting.
Rather than random tests, perform targeted phishing tests to evaluate if employees follow security policies. If users fail a social engineering test, focus on education not admonishment.
Time is the enemyTime is the ultimate constraint for any penetration tester. There are only so many hours in an engagement. Consequently, testers must use their time efficiently. This means automating as much as possible, so they can focus their attention on the more nuanced vulnerabilities. Black hats, on the other hand, do not have time restrictions. They can take weeks, months, or even years to break in. This inherently creates an unequal arrangement. It is unreasonable to expect penetration testers to devote unlimited time or effort into a test. This would make the testing outlandishly expensive.
Fixing falls on youPenetration tests do not typically fix discovered vulnerabilities; that task falls to your internal teams or a contractor. Allocate resources to address issues after the test.
Think systemicallyAvoid fixing vulnerabilities individually. Implement systemic improvements across the organization. Most vulnerabilities can be remediated through automated software and OS patching. For misconfigurations, standardize system deployment and management. For mission critical systems, you may want to consider emerging technologies like Moving Target Defense, which creates a dynamic, constantly updating environment that is extremely difficult to exploit.
ConclusionPenetration testing is essential for any organization. It is better to have an white hat hacker find a vulnerability before black hat does. However, no security control or technology is perfect. Flaws are inherent in any complex system. Even the best security products, practices, and people can fail. The technologies you use are not as important as how you manage, monitor, and test those technologies.
Lastly, it is important to remember that black hats do not follow rules, policies, or org charts. They will break anything to get your data. For security to be effective, you need to think like a black hat hacker, and test everything. Especially the systems you believe are safe.
We've featured the best encryption software.
This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro
We’re almost at the point where AI can no longer be simply defined as an emerging technology. It’s here, and it’s booming. According to McKinsey, more than 70% of companies worldwide have either already deployed AI-based technology, or are seriously exploring its capabilities. That’s up from just 20% in 2017. In the past year alone we’ve seen incredible advancements in the AI space, particularly when it comes to generative AI and the use of Large Language Models (LLMs) to compute, make predictions, generate content, and analyze large sets of data in real-time for a plethora of applications.
Studies by the likes of HubSpot and IBM reveal that AI can save employees roughly 2.5 hours per day, and businesses can cut their overall costs by almost a third. An entire ecosystem of partners and complementary services is now being formed around AI, and its reach isn’t just confined to business. ChatGPT users can now have live conversations with AI; Meta’s Llama 3.2 update allows its AI assistant to read and comment on images, and Apple Intelligence is about to leave beta and allow users to do everything from generate code to create new graphics, all with technology they can carry in their pockets.
The technology is soaring, but like a busy road with too much traffic, there’s always a bottleneck. AI adoption is off the charts, business ambition is strong, but do we have the connectivity infrastructure to meet the low-latency needs of new AI applications? The traffic is coming; perhaps it’s time to turn our attention to the roads.
The invisible hurdleAttitudes to AI are largely positive, but part of that is down to novelty. One metric that truly matters, return on investment (ROI), is still proving elusive for most business AI deployments. Three-quarters of enterprises have not moved beyond “baby steps”, that is one or two pilot projects (MIT Technology Review). And, although 50% of those surveyed expect to deploy AI at scale across all business functions within two years, they reported implementation challenges and bottlenecks – not due to capital, culture or lack of expertise, but in the infrastructure carrying their data.
Let’s be clear. These aren’t just teething troubles. Short-term hiccups at the start of the project are to be expected, but the underlying implementation challenges enterprises have highlighted point to a more fundamental, structural issue with the feasibility of AI roll-outs.
Underperforming AI is bad for business, and not just in the sense that it won’t realize its ROI, but because its insights and other outputs are limited. This happens when AI systems struggle to access and interpret data across the organization in real-time. The full potential of AI can only be realized when organizations have the right infrastructure in place to support its implementation. One critical aspect often overlooked is the importance of network interconnection. Here’s how this plays out within a typical enterprise.
Cloud and AI – a winning combinationCloud computing plays a crucial role in AI implementation. Partly in response to the accelerating pace of data generation meaning that on-premise data storage is becoming unviable and partly because of the many accessibility benefits of storing raw and structured data in the cloud, businesses are increasingly migrating data lakes and warehouses to the cloud, enabling scalability and access to vast computing power. The AI Infrastructure Alliance showed that 38% of organizations had their AI infrastructure fully set up in the cloud, while 29% operate a hybrid environment.
These organizations rated the availability of cost and computing power as the number one challenge when scaling AI and their number one computing concern was latency (28%). A similar picture emerges across different territories, too. For example, a joint survey of European organizations by DE-CIX and IDC highlighted network performance and latency (22%) as the main concern, especially when AI use cases require real-time data.
The connectivity conundrumLet’s consider how organizations typically use AI. Firstly, they need to train AI models, either first-time development or the periodic retraining that models need from time to time. For this, latency is not such a big issue, but high bandwidth connectivity is critical. In the cloud, it is best to use the cloud provider’s own connectivity solution (such as Microsoft ExpressRoute or AWS Direct Connect), accessible from a range of cloud exchanges, to avoid costly overheads for data egress. Secondly, they need AI to work in real-time, which is where latency does matter. Many use cases fall into this category, from customer services bots to product support where real-time interaction is desirable right through to where it is critical, such as autonomous vehicles, healthcare, and some financial services use cases. Here, the AI models need real-time access to data sources, as well as to the intended users of the insights and AI agents for different services and workloads.
In short, AI needs both high bandwidth and low latency network performance. Oh, and did we mention this all needs to be seamless?
The missing link is interconnectionHere is when the network performance bottleneck becomes apparent. Too many enterprises still rely on public internet or third-party transit for connecting data and AI systems. This creates considerable performance and security issues, with enterprises having little or no control over data pathways, network bandwidth and latency, and the security of critical company data in transit.
To control data flows, enterprises need to control how networks interconnect with each other. That’s why increasingly organizations are choosing network interconnection solutions, which provide secure, dedicated connections between on-premise systems and cloud-based AI services. By establishing direct, high-performance links, businesses ensure control over performance, security, and data routing. In practice, this network interconnection creates responsive, interoperable environments for cloud and multi-cloud scenarios, enabling low-latency access to AI-as-a-service offerings and real-time data analysis. It assures secure data exchange within partner ecosystems and improves the overall resilience of the cloud infrastructure environment, enabling business to roll out AI implementations at scale that deliver their intended ROI.
Enterprises need AI-ready infrastructureAI offers organizations unprecedented opportunities to transform their operations and revenue generation. The awe-inspiring capabilities of AI models and data analytics tools naturally enough garner much attention, but organizations need to ensure that the underlying infrastructure supporting AI implementations is equally scalable and resilient for AI to live up to its potential. Investing in a robust interconnection strategy alongside cloud migration is critical for businesses to overcome AI connectivity bottlenecks and truly unlock its transformative potential.
Partnering with high-performance interconnection providers can help in the design of a secure, scalable network tailored to specific AI needs. The future of AI has already arrived; we just need to make sure we’re ready for it.
We've featured the best IT infrastructure management service.
This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro
What is a TV? Does it have to be a giant panel that commands your attention in the living room, something attached to a wall, or nestled between wall-filling bookshelves? Not necessarily and if Apple is truly reconsidering making its own TV set, it may want to take a long hard look at its surging iPad Pro 13-inch.
Apple's interest in TV sets and television in general, goes back at least 15 years, and was solidified in some ways when Apple CEO Tim Cook told interviewers that Apple considered TVs "an area of incredible interest." He also noted that there was a grand vision for TV at the Cupertino tech company. In hindsight, Cook may have been describing Apple's work on its Apple TV 4K streaming box, which was followed by the TV app (which replaced Video and the iTunes video library and store) and even Apple TV Plus, which introduced the world to Apple's vision for streaming content. All in all, that does add up to something of a grand vision.
We find ourselves turning back the channel to talk yet again about the possibility of an Apple TV set because of a short item in Bloomberg's Power On newsletter that indicates building an "Apple" branded TV set is "something it’s evaluating." I know, it's not a lot to go on and I've long been skeptical of the concept of an Apple Television, a seemingly unnecessary piece of Apple hardware.
I'm not denying the market allure. Statista puts the worldwide TV set revenue opportunity at nearly $100b. On the other hand, the market is anticipated to have less than 1% annual growth over the next five years. That might be because people buy these big TV sets and then hold onto them for at least 5 years. Apple likes markets that either promise annuities like its services – including Apple TV Plus – and ones that have built-in upgrade cycles like the best iPhones. TV sets by themselves provide neither.
It's been the iPad all alongLet's say, for argument's sake, Apple is back on the TV hunt. It might be doing so not only because an Apple TV is the perfect delivery system for its own streaming service but also because of the obvious in-home branding opportunity: a big TV set with a visible Apple logo on the chin base. I believe, though, that the real reason Apple might be considering making a TV set is because it's been selling millions of small TV screens to Apple fans for years.
Going all the way back to 2013, a survey found that more than 50% of respondents were watching TV on an iPad. At the time, the entertainment was squeezed into a 9.7-inch LCD. As I write this, my TV is playing next to me. It's a 13-inch iPad Pro with a fantastic Ultra Retina XDR Tandem OLED (two stacked OLED panels) with clear and quite loud four-speaker audio that even supports spatial audio.
With my iPad, I have access to Apple TV Plus, Netflix, Amazon Prime Video, Max, and my new live-broadcast favorite Sling TV. Obviously, this is an able TV set and, if the rumors are true, larger tandem OLED displays are coming. Near term they might still top out at 30 inches, so Apple will probably stick to the tech currently used in the best OLED TVs for… oh let's call it the 65-inch iPad Pro Max.
The limitsMy iPad Pro 13, which is outselling all other iPads, is not a perfect TV. It lacks a remote (it's a touchscreen!) and HDMI ports for, say, attaching a gaming console. On an actual Apple TV in the form of a giant iPad, perhaps Apple should still avoid HDMI ports, bringing us fully into the cable-free streaming future – but it could add a separate connections box for anyone who needs them. This could even be wireless, like LG M-series OLED TVs, so you can keep a clean space around your TV. And you could use your iPhone as the remote by default. Admit it, you're already watching TV with your iPhone in your hand.
The benefit of the iPad Pro Max 65 inch as a TV set is that all the smarts are built in. It's already a gaming platform and, with support for all your key productivity apps, could also double as a giant workspace. It's already a smart home hub and might finally help people, if not fall in love with it, at least start adopting Apple Home in significant numbers. I even think the touchscreen TV could come in handy when you can't locate the remote, but I would recommend adding the ability to turn off the touchscreen.
Apple isn't, as I see it, far from building a TV set because it's been selling them for 13 years. The iPad is a TV and it's time for it to glow all the way up.
You might also like