Story JGQT Major Android remote-access vulnerability is now being exploited Similar

Story

Major Android remote-access vulnerability is now being exploited

Similar News

Amazon Underground: Amazon will mit kostenlosen Android-Apps locken
Amazon bemüht sich um mehr mobile Kunden für seinen Online-Shop und sein Angebot an Android-Apps. Über "Amazon Underground" sollen künftig Apps und In-App-Einkäufe im Wert von "mehreren tausend Euro" kostenlos erhältlich sein.
Lara Croft GO launches on Android, opening up a gorgeous diorama world to explore
Lara Croft GO is a brand new turn-based puzzle title by the same company that brought the world Hitman GO. Taking the same experience and art direction of the previous GO title and mashing it together with Tomb Raider has resulted in a beautiful take on Lara Croft. Prepare to be immersed on the diorama board with plastic figures as you work alongside Croft to uncover the myth of the Queen of Venom.
LXer: The Onion Router is being cut up and making security pros cry
Published at LXer: IBM is warning corporates to start blocking TOR services from their networks, citing rising use of the encrypted network to deliver payloads like ransomware. The advice comes in...
React Demolishes Engineering Silos So Facebook Can Reuse Code For Web, iOS, And Android
It was supposed to take 18 months. But with React Native, Facebook built its iOS Ads Manager app in 5 months, and then ported it to Android in just 3 more months. That’s because React Native let Facebook’s engineers work faster and reuse the JavaScript backend. Coders have dreamed of a system that would let them ‘write once, run anywhere’. But Facebook… Read More
Best Android phones for students heading back to school
It's time to get back to school with a great, affordable phone. The school year is barreling down towards you like a freight train laden with knowledge and the last thing you need is the headache of figuring out which new phone to get. Hopefully we can pare down the decision-making process for a you a little bit with these suggestions. We're going to be looking at budget-conscious phones with a sense of style and enough horsepower to get through a busy courseload.
Android Central Photo Contest: Rust
Whether you live in an area with lots of sea water or not, you're likely to encounter your fair share of rust. And when you do, we want you to take the best possible picture of it for the latest Android Central Photo Contest. No matter what the rusty situation is or what Android you're currently carrying, you have a chance to enter and win a prize this week.
5 always-on apps for Android Wear
The ease and accessibility of being able to stay up to date with Smartwatches is something we've talked a lot about. However many of the apps that we use to keep up to date can be a serious drain on battery life. Which is where the new update for Android Wear comes in, always on apps. These apps continue to supply you with data even after they pop over into ambient mode.
Contrary To Reports, Android Pay Not Launching This Week
Android Pay, Google’s forthcoming payments platform and rival to Apple Pay, will soon launch, allowing consumers to pay using their Android smartphones at point-of-sale as well as make purchases within mobile applications. However, according to sources familiar with Google’s plans, Android Pay is not arriving today – or any time this week, in fact – despite a handful… Read More
NVIDIA Shield Android TV arrives in the Google Store for $199
The latest addition to the Google Store lineup is the NVIDIA Shield Android TV. Google is selling the 16GB variant of the Android TV for $199, while the 500GB version is only $100 more, at $299.
Daily Deal: Lavasoft Ad-Aware Pro Security 2-Year Subscription
With everything we do online, it's important to take steps to protect yourself as best as you can. The Deals store is offering 45% off of a 2-year subscription for 2 PCs for Lavasoft Ad-Aware Pro Security. Lavasoft has added a complete antivirus suite to their anti-spyware and anti-adware capabilities. You'll get protection from viruses, rootkits, Trojans, bot networks, spyware, keyloggers and many other online security threats.
Monthly security update check procedure
Hi, I started using the EC2 instances on AWS from our own datacenter. The instances are running CentOS6.6. And i am trying to figure out a process for checking and updating any security patches...
Amazon Underground Is an Android App Store with Only “Actually Free” Apps
Comments
YouTube Gaming goes live for Android, web portal to launch later today [Update: website is live]
Update: The YouTube Gaming web portal is now live as well. Google has also announced the service will only be for US and UK residents at first, with more countries to be added later. Original story: Google is finally making its move to battle Twitch in the popular live game streaming market with the previously announced launch of YouTube Gaming. The new service aims to put the power and reach of YouTube into the hands of game streaming content creators and fans.
Security updates for Wednesday
Arch Linux has updated gnutls (denial of service), jasper (denial of service), pcre (code execution), and python-django (denial of service).CentOS has updated httpd (C7: twovulnerabilities) and mariadb (C7: multiple vulnerabilities).Debian has updated twig (code execution).Debian-LTS has updated ruby1.8 (information disclosure) and ruby1.9.1 (information disclosure).Mageia has updated gnutls (MG4,5:two vulnerabilities), vlc (MG5: codeexecution), and wireshark (MG4,5: multiple vulnerabilities).Oracle has updated thunderbird (OL7; OL6: multiple vulnerabilities).Ubuntu has updated gdk-pixbuf(15.04, 14.04, 12.04: code execution).
Amazon Underground Features An Android App Store Focused On “Actually Free” Apps
Amazon just announced a new store for Android apps and games called Amazon Underground. While the company already has the Amazon Appstore, Amazon Underground is a brand new section as well as a new app to download premium apps for free. Here’s how it works. Read More
Amazon Underground – Amazon's Android App Store
Comments
IFA 2015: Neue Archos LTE-Smartphones mit Android und Windows 10 Mobile
Das 5-Zoll-Smartphone Archos S Diamond soll mit AMOLED-Display, der Speichererweiterung Fusion Storage und einem Preis von 230 Euro punkten. Auf der IFA zeigt Archos außerdem Bilig-Smartphones mit Android und Windows 10 Mobile.
Archos: Neue LTE-Smartphones mit Android und Windows 10 Mobile
Das 5-Zoll-Smartphone Archos S Diamond soll mit AMOLED-Display, der Speichererweiterung Fusion Storage und einem Preis von 230 Euro punkten. Auf der IFA zeigt Archos außerdem Bilig-Smartphones mit Android und Windows 10 Mobile.
Android in user-chosen lockscreen patterns are grimly predictable SHOCKER
Encryption won’t save you if it's an 'L', as in ‘loser’ People choose predictable Android lock screen patterns just like they pick predictable passwords.…
The Onion Router is being cut up and making security pros cry
IBM tells business to pull the plug, Agora pulls shutters on interesting goods mart IBM is warning corporates to start blocking TOR services from their networks, citing rising use of the encrypted network to deliver payloads like ransomware.…
How security flaws work: The buffer overflow
Starting with the 1988 Morris Worm, this flaw has bitten everyone from Linux to Windows.
LXer: Oracle, still clueless about security
Published at LXer: Oracle's chief security officer, Mary Ann Davidson, recently ticked off almost everyone in the security business. She proclaimed that you had to do security "expertise in-house...
Android Certifi-gate vulnerability exploited, no patches in sight
Check Point, the company that disclosed the Certifi-gate vulnerability a few weeks ago, has published a blog post with further analysis of the problem. The security researchers report that an app called Recordable Activator was exploiting the vulnerability, using TeamViewer's plugin to gain system-level access and record the screen. The app has now been removed from Google Play, although Check Point claims it had somewhere between 100,000 and 500,000 downloads before that point.The security company provides an application that tests whether a device is vulnerable and collects anonymous data. It's important to make a distinction: a "vulnerable device" is exploitable only if the user installs a remote support plug-in, while one that's both vulnerable and ...Read more...
University student pleads guilty to marketing spy app for Android phones
A Carnegie Mellon University student who hoped to sell enough malicious software to infect 450,000 Google Android smartphones pleaded guilty Tuesday to a federal law meant to prevent hacking of phones and computers.
LXer: Vodafone rocks the bloat with demands for vanilla Android
Published at LXer: You want plain, colourless Lollipops, have them, says MotorolaVodafone wants to sell Android phones which are as close to stock (as*Google*intended) as possible, and the red...
Woman downs whole bottle of cognac at Beijing airport security control
Woman drank contents of bottle after being told she could not carry it in her hand luggage, only to be prevented from flying because she was too drunkA Chinese woman reportedly downed a full bottle of £120 cognac at security control after she was told she was not allowed to take liquids on board her flight – which she was then prevented from boarding.The woman, who has been named only as Zhao, was deemed too drunk to fly by staff at Beijing Capital international airport when she collapsed shortly after drinking the bottle of Rémy Martin XO Excellence. Continue reading...
Tuesday's security updates
CentOS has updated httpd (C6:denial of service) and nss (C5: two vulnerabilities).Oracle has updated httpd (OL7; OL6:denial of service), mariadb (OL7: multipleunspecified vulnerabilities), and nss (OL5:two vulnerabilities).Red Hat has updated httpd (RHEL7; RHEL6:HTTP request smuggling), httpd24-httpd(RHSCL2: multiple vulnerabilities), libunwind (RHELOSP6: buffer overflow), mariadb (RHEL7: multiple vulnerabilities), nss (RHEL5: two vulnerabilities), openstack-neutron (RHELOSP6: denial ofservice), openstack-swift (RHELOSP6;RHELOSP5: arbitrary object deletion),python-django (RHELOSP6; RHELOSP5: denial of service), python-django-horizon (RHELOSP6: cross-sitescripting), python-keystoneclient (RHELOSP6; RHELOSP5:two vulnerabilities), qemu-kvm-rhev (RHELOSP6; RHELOSP5:information leak), redis (RHELOSP6: codeexecution), and thunderbird (RHEL5,6,7: multiple vulnerabilities).Scientific Linux has updated httpd (SL7; SL6:denial of service), mariadb (SL7: multiplevulnerabilities), nss (SL5: twovulnerabilities), and thunderbird (SL5,6,7:multiple vulnerabilities).Ubuntu has updated thunderbird(15.04, 14.04, 12.04: multiple vulnerabilities).
Butterfleye Is A Home Security Camera That Can Learn What Not To Record
Butterfleye is a hardware startup aiming to build a connected home security camera that avoids coming across as creepily prying. Read More
Android-Smartphone Oppo R5s zum Sonderpreis
Der Nachfolger des R5 verdoppelt den internen Speicher und bietet mehr RAM. Das Smartphone kann kurzzeitig für 199 Euro über die offizielle Website bestellt werden.
Major Android remote-access vulnerability is now being exploited
Good luck getting this one patched quickly and effectively.
Appeals Court: Yes, The FTC Can Go After Companies That Got Hacked Over Their Weak Security Practices
Way back in 2004, we noted that the FTC went after Tower Records for getting hacked and leaking customer records. At the time, we wondered if this was appropriate. Companies get hacked all the time, even those with good security practices. So, at what point can it be determined if the company is being negligent, or if it's just that those looking to crack their systems are just that good. Well, the FTC had decided that it can draw the line, and for companies that do a particularly egregious job in not protecting user data, it's made it clear that it's going to go after them. A few years back, the FTC went after Wyndham Hotels for failing to secure user data, and Wyndham tried to argue that the FTC had no authority to do so. Last year, a district court sided with the FTC and now the Third Circuit appeals court has upheld that ruling, giving the FTC much more power to crack down on companies who fail to protect user data from leaking.
Bangkok bombing: broken security cameras add to investigators' woes
Thailand police use ‘imagination’ to ‘connect the dots’ in search for prime suspect who set off a bomb which killed 20 and injured 120Police in Thailand say they have used their “imagination” to piece together the movements of the prime suspect in a bomb attack at a shrine last week that killed 20 people because most of the security cameras on the getaway route were broken.Related: Bangkok explosion: fatal blast at Erawan shrine Continue reading...
Security bei Embedded Systems auf dem 5. Bremer IT-Sicherheitstag
Hacker-Attacken auf Industrie-IT, das Design und die Bewertung sicherer Software-Architekturen sowie das Spannungsfeld zwischen funktionaler Sicherheit und IT-Sicherheit sind drei der zentralen Themen auf dem diesjährigen Bremer IT-Sicherheitstag.
Cortana public beta on Android can replace your launcher
If you have an Android phone, and you've been itching to talk to Cortana, now's your chance. Microsoft has opened the Android public beta for its personal assistant. ...Read more...
Vodafone UK rocks the bloat with demands for vanilla Android
You want plain, colourless Lollipops, have them, says Motorola Vodafone UK wants to sell Android phones which are as close to stock (as Google intended) as possible, and the red company's favourite device for this is the Moto G.…
Vysor is an interesting new way to control Android from your computer
There are a couple of ways to remotely view and control your Android from a desktop, but none of them are particularly easy to use. Some require root access, some require subscriptions, and some aren't really worth using due to low framerates and overall quality. The mind behind Rom Manager, Voice Plus, AllCast, and other popular Android apps has been working on a better way to remote control multiple Android phones and tablets for a while now, and like almost everything Android the work was discovered late last night and leaked before it was finished. The app is called Vysor, and while it's not quite finished yet we've been using it for a little while now and can't wait to see the finished product. Unlike your average Android remote app, Vysor is a Chrome app first. You launch in Chrome, turn on USB debugging on your phone or tablet, and connect to the computer. Once ADB connects to your machine, Vysor is installed and your mobile screen shows up on your desktop. Your mouse and keyboard can now control your Android, complete with keyboard shortcuts for back, home, and multitask. In our testing it works great on Mac and Windows, and aside from the occasional need to play with USB connection mode (thanks, Installer Mode nonsense) Vysor works as soon as you plug the cable in after the initial setup.
Vysor Puts Your Android Device’s Screen On Your Desktop
If you’ve ever wanted to play games or use apps from your phone on your desktop — web versions of messaging apps are certainly convenient — then Vysor is a new service for Android owners that might well be up your alley. Read More
Cortana Android beta goes public
It's supposed to be automatic, but actually you have to press a button Microsoft's Cortana-on-Android project, first announced in May, has now evolved to the point at which the virtual assistant has been released as a beta.…
Hands-on with the public beta of Cortana on Android
Cortana for Android was released as a public beta earlier today. I installed it on the LG G4 to see how it works. Is it better on Android compared to Windows Phone? Go watch our hands-on video to find out.
Court rules FTC can prosecute companies over lax online security
Wyndham hotel chain loses appeal case The Third Circuit US Court of Appeals in Philadelphia has ruled that the Federal Trade Commission does have the right to prosecute firms who mishandle their customers' data.…
T-Mobile offers discounts on slew of Android phones with back to school sale
If you have a student in your life in desperate need of a new phone, T-Mobile's back to school sale might be worth checking out. The magenta carrier is running a two-day "Class is in Session" sale that offers discounts on a number of Android smartphones and accessories.
FTC can sue companies with poor information security, appeals court says
Court says Wyndham hotels practices could be considered “unfair” and “deceptive.”
The Samsung Galaxy Note 5 and Android Auto
It's a hard fact of early adopter life that not every new toy will work with every other new toy out of the box. Such is the case with Android Auto, which on occasion refuses to connect to some new phone that should happen to find its way into our car. So it's understandable that folks have been asking me about whether the Samsung Galaxy Note 5 plays nice with Android Auto. Here's what I've found.
FTC has power to police cyber security
Comments
Twitter Tries To Keep People Engaged With Web Notifications For DMs And Tweaks To Tweet Sharing On Android
If you’re a Twitter on the web user, like I am, then you’ll be happy to know that the company has now introduced web notifications when you get a direct message. Just keep Twitter open in a tab and click around wherever else you like, the notification will jump out at you anyways on the top right side of the screen. Direct Message notifications are now available on web. Opt in… Read More
Streamlining Android Apps Tech Talks
Comments
Security advisories for Monday
Debian-LTS has updated extplorer (cross-site scripting), roundup (multiple vulnerabilities), and wesnoth-1.8 (information leak).Mageia has updated libcryptopp(MG4,5: information disclosure), mediawiki(MG4,5: multiple vulnerabilities), openssh(MG4,5: multiple vulnerabilities), php (MG5; MG4:multiple vulnerabilities), and x11-server(MG5: permission bypass).openSUSE has updated wireshark(13.2: multiple vulnerabilities) and xfsprogs (13.2, 13.1: information disclosure).Red Hat has updated rh-ruby22-ruby (RHSCL2: DNS hijacking).Slackware has updated gnutls (denial of service).SUSE has updated glibc(SLE11SP3,4: multiple vulnerabilities) and kvm (SLE11SP2: two vulnerabilities).
Microsoft Launches First Public Beta Of Cortana For Android
After a private beta and a few leaks, Microsoft today launched the first public beta of its Siri- and Google Now-like Cortana personal assistant for Android. Microsoft describes the Cortana app as a “companion to your Windows 10 PC” that extends the service’s functionality across any device you carry (which, of course, implicitly acknowledges that you’re very unlikely… Read More
First look: Wileyfox teases a new Android handset
With upstarts like OnePlus and Nextbit emerging in the past year, there's no shortage of new smartphone brands hoping to make it big selling directly to consumers. One of those is UK-based manufacturer Wileyfox, which will be revealing its first Android handset tomorrow. And what you see above is an exclusive first look at that device, with what appears to be a metal frame and plastic sides. It also looks like it's packing a traditional microUSB port and rear-facing speaker, in case you were wondering. An all-new brand, Wileyfox is described by partner VentureSpring as "A new pure play mobile phone brand, sold online only, across Western Europe and North America." That's all we know so far, but we'll be live from London tomorrow to bring you all the details of Wileyfox's first product launch.
Germany and France to push for joint EU immigration and security policies
Berlin in particular is determined to draw up mandatory quotas for refugees and is warning of reintroducing national border controlsGermany and France are to launch a drive for more concerted European immigration and security policies following the foiled attack on an Amsterdam-Paris high-speed train and with Europe reeling under the strain of the biggest migration emergency since the end of the second world war.
12345678910