Skip to main content

Malware alert — don’t plug in that USB stick you found on the street

USB drop attack demo - Blackhat USA 2016
Be careful, that “found” USB drive may hold malware that’s just waiting for you to plug it in. Maybe you consider a found USB stick a chance to do a good deed by returning it to its owner — if you can discover who the owner is. Or maybe you’re curious and just want to see what’s on the removable storage drive. Whatever your reason for picking it up and plugging it in, that “lost” USB stick may be bait waiting for someone to hurt, according to Tom’s Hardware.

Google anti-abuse team researcher Elie Bursztein tested the effectiveness of using “lost” USB memory  to spread malware on a college campus. In Bursztein’s study, almost all of the USB sticks (97 percent) were picked up and almost half (45 percent) were plugged into computers where someone clicked on the stored files. In further testing, Bursztein found that USB sticks with labels such as “Exams” or “Confidential” were more likely to be opened than unlabeled drives while sticks with return addresses were less likely to be opened.

The threats from USB drives can come in several forms. HTML files or executable files stored on the drive could activate malware to infect the system in the background while running innocuous programs in the foreground. Users could be sent to a phishing site that would attempt to steal personal information. Alternately, activated code could search the computer’s files for personal credentials and then attempt to send them back to the hacker or to the cloud for later retrieval.

USB devices that resemble memory sticks but are really keyboard spoofers could be programmed to allow remote access and signal a hacker that the computer is open and ready for whatever the hacker intends.

It’s also possible to use USB sticks to mount zero-day attacks that exploit known software vulnerabilities either before vendors patch the hole or before users download updates. According to Bursztein, zero-day threats are less likely to be spread with randomly “lost” USB sticks due to the cost and complexity of altering firmware. You are more likely to be hit with malicious files or to pick up a keyboard-spoofer.

In any case, the best advice is to resist the temptation to pop a “found” USB stick into your computer just to see what’s on it. Bursztein demonstrated how a USB drop attack could work at Black Hat USA 2016.

Bruce Brown
Digital Trends Contributing Editor Bruce Brown is a member of the Smart Homes and Commerce teams. Bruce uses smart devices…
Best Buy deals: Save on laptops, TVs, appliances, and more
best buy shuts down insignia line smart home products store 2 768x768

If you're looking to snag a good deal, Best Buy is probably one of the best retailers to do it, and we often draw from it for some of the best deals we put on these lists. A lot of that has to do with the massive variety of products that best Buy sells, and that includes things like the best TV deals, best laptop deals, and best phone deals, so there is always something to draw from. That said, it can be difficult to navigate all the deals and offers that are available on Best Buy, which is why we've gone out and collected some of our favorite deals across various categories, from headphones to small kitchen appliances.
Best Buy TV deals

There may be no better place to purchase one of the best TVs than Best Buy. There is almost always some huge savings to find on TVs at Best Buy, and that’s certainly the case right now. You’ll find deals top TV brands like Sony, Samsung, and LG, and more budget-friendly brands like TCL and Hisense are in play, too.

Read more
Target is selling Lenovo laptops for $150, with a catch
The Lenovo IdeaPad Slim 3 on a white background.

Considering the back to school shopping season is in full swing, now is one of the best times of the year to look for laptop deals. Of course, you’ll find markdowns on a wide array of models at just about every retailer, so sometimes finding the best discounts can be a little tough. It’s our job to stay on top of all the best sales though, and we recently came across a Target promo we’d like to share:

For a limited time, Target is selling a refurbished version of the Lenovo Ideapad Slim 3 with 4GB of RAM and 64GB of storage for $150. At full price, this model can go for upwards of $270. 

Read more
OpenAI Project Strawberry: here’s everything we know so far
a strawberry

Even as it is reportedly set to spend $7 billion on training and inference costs (with an overall $5 billion shortfall), OpenAI is steadfastly seeking to build the world's first Artificial General Intelligence (AGI). Project Strawberry is the company's next step toward that goal.
What is Project Strawberry?
Project Strawberry is OpenAI's latest (and potentially greatest) large language model, one that is expected to broadly surpass the capabilities of current state-of-the-art systems with its "human-like reasoning skills" when it is released. It might power the next generation of GPTs.
What can Strawberry do?
Project Strawberry will reportedly be a reasoning powerhouse. It will be able to solve math problems it has never seen before and act as a high-level agent, creating marketing strategies and autonomously solving complex word puzzles like the NYT's Connections. It can even "navigate the internet autonomously" to  perform "deep research," according to internal documents viewed by Reuters in July.

The Reuters report also notes that Strawberry's architecture is similar to the Self-Taught Reasoner (STaR) technique. Developed at Stanford in 2022, STaR enables a model to generate training data on which to fine-tune itself, becoming more capable over time.
Why is it called that?
We don't know the exact reason for the name "Strawberry," as that's not something OpenAI has publicly disclosed. It's a code name chosen for internal reference and to maintain secrecy during development.

Read more