Security News

Facebook Disrupts Chinese Spies Using iPhone, Android Malware
2021-03-24 18:56

Facebook's threat intelligence team says it has disrupted a sophisticated Chinese spying team that routinely use iPhone and Android malware to hit journalists, dissidents and activists around the world. The hacking group, known to malware hunters as Evil Eye, has used Facebook to plant links to watering hole websites rigged with exploits for the two major mobile platforms.

Why it's time the Android developers rethink WebView
2021-03-23 17:53

Even back in the early days, WebView was problematic because, with a JavaScript bridge enabled, a webpage viewed in WebView could execute code as the WebView application itself. There's the app itself, there are the Android subsystems, there are the apps that depend on WebView, there are the developers who might make use of JavaScript, which then depends on a third-party server that may or may not use SSL properly.

Recently Patched Android Vulnerability Exploited in Attacks
2021-03-23 13:07

Google has warned Android users that a recently patched vulnerability has been exploited in attacks. The vulnerability in question, tracked as CVE-2020-11261, was patched by Google with the Android security updates released in January 2021.

WARNING: A New Android Zero-Day Vulnerability Is Under Active Attack
2021-03-23 03:57

Google has disclosed that a now-patched vulnerability affecting Android devices that use Qualcomm chipsets is being weaponized by adversaries to launch targeted attacks. "There are indications that CVE-2020-11261 may be under limited, targeted exploitation," the search giant said in an updated January security bulletin on March 18.

Hacking group used 11 zero-days to attack Windows, iOS, Android users
2021-03-20 14:41

Project Zero, Google's zero-day bug-hunting team, discovered a group of hackers that used 11 zero-days in attacks targeting Windows, iOS, and Android users within a single year. The Project Zero team revealed that the hacking group behind these attacks ran two separate campaigns, in February and October 2020.

Bogus Android Clubhouse App Drops Credential-Swiping Malware
2021-03-19 15:21

Researchers are warning of a fake version of the popular audio chat app Clubhouse, which delivers malware that steals login credentials for more than 450 apps. As of now the app is only available on Apple's App Store mobile application marketplace - there's no Android version yet.

99.2% of US government Android users are running outdated OS versions
2021-03-16 15:16

Roid, the most popular mobile operating system in the world, runs on plenty of devices used by U.S. government workers, but only 0.08% of those devices are running the latest version of Android, a report finds. Mobile security firm Lookout is behind the report, which looked at over 200 million mobile devices being used by U.S. federal and state government workers between January 2019 and December 2020.

Android: How to quickly block spam SMS
2021-03-12 18:00

Jack Wallen shows you how easy it is to block and report spam SMS messages on the Android platform.

How to enable Android's Password Checkup feature
2021-03-09 22:37

Has your password been compromised? Are you certain? If you're a Google Chrome user, you know there's a feature that will inform you if your password has been stolen and should be changed. With this new Android Password Checkup feature, you can stay in the know about when it's time to change a password.

9 Android Apps On Google Play Caught Distributing AlienBot Banker and MRAT Malware
2021-03-09 03:13

Cybersecurity researchers have discovered a new malware dropper contained in as many as 9 Android apps distributed via Google Play Store that deploys a second stage malware capable of gaining intrusive access to the financial accounts of victims as well as full control of their devices. "This dropper, dubbed Clast82, utilizes a series of techniques to avoid detection by Google Play Protect detection, completes the evaluation period successfully, and changes the payload dropped from a non-malicious payload to the AlienBot Banker and MRAT," Check Point researchers Aviran Hazum, Bohdan Melnykov, and Israel Wernik said in a write-up published today.