Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, July 31, 2015

PHONES AT RISK FROM TEXT MESSAGE HACK

As we previously reported, Google has placed a 'bug bounty' for research teams to discover potential threats to the Google Chrome web browser. Google has paid out $4 million since the bug bounty begain in 2010 and it seems a researcher named Zimperium, has uncovered a new vulnerability that has the potential to wreak havoc on our beloved Android devices.

This researcher states that the flaw exists within a media playback tool within the mobile software called Stagefright. By simply sending a text message, hackers could acquire complete control over the device and allow them to steal any content on it. The malware hides inside of a short video and as soon as the text is received, built in features to reduce time for viewing processes the video. It seems that short amount of time to process the video is enough for hackers to take control. This would include all personal information or credit cards.

A Google spokewoman had this to say regarding the mobile threat,
"The security of Android users is extremely important to us and so we responded quickly and patches have already been provided to partners that can be applied to any device." The Google spokeswoman went on to add, "Most Android devices, including all newer devices, have multiple technologies that are designed to make exploitation more difficult. Android devices also include an application sandbox designed to protect user data and other applications on the device."
unnamed
Zimperium sent the patch that has been accepted to Google. He told the National Public Radio that he estimates only 20 percent to 50 percent of Android devices will actually get the updates due to vendors being slow to react -- if they react at all. You see unfortunately, fixes to the popular mobile operating system take time. To resolve issues within Android, Google provides patches through software updates handed down to device manufacturers. These manufacturers include Samsung, LG, HTC among many others to then provide these software updates to the cellphone service providers. It is then up to these carriers to push the updates to each phone. You can start to see how long this process could take. Thus many devices rarely receive the latest software available to them.

Currently, Zimperium tells the National Public Radio that the flaw has not been exploited. However, expressing the severity in a recent blog post, he states that 95 percent of Android devices worldwide are vulnerable.

ePelican.com, Inc.

Thursday, July 23, 2015

SECURITY FLAWS PATCHED IN CHROME UPDATE

chrome update




As part of Google's bug bounty program, researchers have been granted financial rewards based on the severity of the issue. Nearly, $40,000 has been awarded to security researchers in total. Bug bounties continue to be a valuable way for software vendors to use third-party specialists to detect security flaws. This results in problems being addressed faster and updates being provided to users, thus keeping them safe from exploitation. 

On Wednesday, Google provided the public release of Chrome 44 for Windows, Mac and Linux. As part of the Chrome 44 update, 43 bugs have been fixed. The most severe issue include universal cross-site scripting, a flaw which allows executable files to run immediately after download and a content security policy bypass in the Chrome browser. 
 To protect yourself against some of these potential security flaws, Google recommends setting up auto-downloads of the browser updates. If you do not have this feature set-up you will need to manually update your Chrome browser. This can be done by opening your Chrome browser and locating the three horizontal lines at the top-right position of the browser. These lines indicate the ability to customize and control the browser settings. Click this for a drop-down menu to appear. Select "About Google Chrome" toward the bottom of this menu for the browser to search for the most recent update available. Approve this update to protect yourself from potential security flaws.