Story JGQT Major Android remote-access vulnerability is now being exploited Similar

Story

Major Android remote-access vulnerability is now being exploited

Similar News

Google acknowledges problem with Moto G and Android Auto
We've got a new entry on the "Known issues" list for Android Auto, and it's an interesting one. We've been discussing the Moto G 2015 and Android Auto in our AA forums. Some folks (mainly, me) have been able to get it to work. But others haven't. And today, Google's dropped the following:
Using Virtual Machines to Improve Container Security with Rkt v0.8.0
Comments
UK and France to sign Calais security deal
Deal contains measures to tackle human traffickers and commitments to boost humanitarian support for vulnerable migrantsBritish and French ministers are to meet in Calais on Thursday to sign an agreement aimed at alleviating the disturbances involving migrants at the French port.
Airport Security Seizes Three-Year-Old's Fart Gun
For once I'm not going to be criticizing the TSA, but that's only because the TSA wasn't involved here in any way. Although it wouldn't surprise me if they have been meeting with their Irish counterparts supposedly to exchange nonsensical... Related StoriesTSA: Terror Sorority Alert"Arabic Terror Message" Actually Said "Welcome Home" in HebrewKansas Senator: Terrorists Could Infiltrate Fort Leavenworth by ... Submarine?
Security advisories for Tuesday
CentOS has updated glibc (C5:code execution from 2013), mysql55-mysql(C5: multiple unspecified vulnerabilities, one from 2014), net-snmp(C7; C6:code execution), sqlite (C6: codeexecution), sqlite (C7: threevulnerabilities), and subversion (C6: threevulnerabilities).Debian has updated apache2 (twovulnerabilities), gdk-pixbuf (codeexecution), and nss (two vulnerabilities).Debian-LTS has updated libstruts1.2-java (unclear vulnerability from 2014).Fedora has updated erlang (F22; F21:man-in-the-middle vulnerability), firefox(F22: many vulnerabilities), flac (F21: twovulnerabilities from 2014), gnutls (F21:code execution), golang (F22; F21: HTTP request smuggling),nagios-plugins (F22; F21: three vulnerabilities), qemu (F22: two vulnerabilities), uwsgi(F22; F21:denial of service), and webkitgtk4 (F22:three unspecified vulnerabilities).Mageia has updated kdepim (M4: noattachment encryption from 2014).openSUSE has updated subversion(two vulnerabilities) and virtualbox (two vulnerabilities).Oracle has updated glibc (OL5:code execution from 2013), mysql55-mysql(OL5: multiple unspecified vulnerabilities, one from 2014), net-snmp(OL7; OL6:code execution), sqlite (OL7: threevulnerabilities), sqlite (OL6: codeexecution), and subversion (OL6: three vulnerabilities).Red Hat has updated net-snmp(RHEL6&7: code execution).Scientific Linux has updated glibc (SL5: code execution from 2013), mysql55-mysql (SL5: multiple unspecifiedvulnerabilities, one from 2014), net-snmp(SL6&7: code execution), sqlite (SL6:code execution), and subversion (SL6: threevulnerabilities).Ubuntu has updated kernel (12.04:three vulnerabilities), kernel (15.04; 14.04: denial of service), linux-lts-trusty (12.04: denial of service),linux-lts-utopic (14.04: denial ofservice), linux-lts-vivid (14.04: denial ofservice), linux-ti-omap4 (12.04: threevulnerabilities), and net-snmp (twovulnerabilities, one from 2014).
Traversal Networks Wants To Be Your Company’s Cyber Security Department
Imagine a company that installs an appliance to monitor your network for malicious activity, then broadcasts that security data to a cloud service and has experts watching and responding to any real threats. That’s what Traversal Networks, a member of the Summer Y Combinator 2015 class, is trying to do. In fact, the company was making its pitch at YC Demo Day shortly after I spoke… Read More
Fossil shows off its first Intel-powered Android Wear smartwatch
At Intel's Developer Forum, Fossil took to the stage to give a glimpse of its upcoming Intel-powered Android Wear smartwatch. While actual details and specs were not divulged, this is our first look at the new watch. The design looks very similar to the Moto 360, right down to the flat tire design.
LXer: Google Announces Android 6.0 Marshmallow
Published at LXer: Google finally revealed the name of the Android M and it's Marshmallow. The fans of the M&M candy will be disappointed by the choice, but now the final Developer Preview update...
While my iPhone was away, I fell for an android| Catherine Shoard
I didn’t expect expect to like the replacement but I came to adore its idiosyncrasies - does that make me a bad person?According to Samsung’s UK president, Andy Griffiths, 80% of people would never consider switching between Android and Apple. Or vice versa. Smartphone wars are therefore waged over the small number of undecided and unfussed. All those advertisements, all that spend – it’s just for the benefit of what Griffiths calls “floating voters”.Last week I was pushed into this pool when, halfway through the holiday, my iPhone – like so many tourists – reacted badly to rain. It then failed to revive after, as advised, I had sealed it in a bag of rice and left it on the radiator. Stricken with a panic that my ancestors presumably felt when faced with a really major pack of mammoths, I bought a supermarket Samsung – specifically, a E1200 basic simple model in white – and put the sim in that instead. Now my phone weighs less than a Twix. It fits snugly even in my midget grip. I’ve only charged it once in a fortnight. Continue reading...
Trend publishes analysis of yet another Android media handling bug
1, 2, 3, 4 ... how many more bugs must we endure? More details have emerged about yet another Android vulnerability, that, like other recent flaws, revolves around how the Google-backed mobile operating system handles media files.…
Android apps are flooding on to jailbroken Win10 phones
Uh, SatNad – are you sure this is what you want? The addition of Android compatibility for Windows phones was called a "suicide note" back in April, and now somebody's composing the first draft. Intrepid tinkerers have opened up previews of Windows 10 for phones to allow a wide range of Android apps run without modification. Reports suggest that at this stage, far more Android apps crash than run well.…
LXer: How to use the NMAP Security Scanner on Linux
Published at LXer: Nmap is a free and open source network discovery and security auditing utility that is widely used in the Linux users community as it is simple to use yet very powerful. Nmap...
Stagefright 2: all versions of Android since 2010 hit by privacy-busting flaw
Security researchers warn that privacy of victims may be at risk from hackers running their own code on mobile devices – and a patch is not yet availableStagefright, the hugely widespread Android vulnerability which Google finally patched in early August, is back for a second go.Security research firm Trend Micro has discovered a new vulnerability in how videos are handled in Android, which they warn can allow a hacker to run their own code on mobile devices. Continue reading...
Welcoming Android One to Africa
Comments
Who Should Be Responsible For IT Security?
Hot potato, or hot job? Typically, when a cybersecurity problem arises, it’s the IT department that gets it in the neck. Ostensibly, that makes sense. After all, if someone is in your network mining your database for corporate secrets, it’s hardly the office manager or the accounts receivable department’s lookout, right?…
Infinix HOT 2 Android One phone headed to several African countries
Android One, Google's attempt to launch a new type of Android smartphone in developing countries, is expanding to several African countries. Google revealed that the first Android One smartphone in those locations will be the Lollipop-based Infinix HOT 2.
Android Mediaserver: Neue Lücke betrifft Millionen Smartphones
Die Geschichte um den von Sicherheitslücken geplagten Mediaserver von Android-Geräten wird weitergeschrieben und nach den Stagefright-Schwachstellen tut sich nun eine weitere Lücke auf.
Security flaw affecting more than 100 car models exposed by scientists
Academics found cars were vulnerable to ‘keyless theft’, including models from Audi, Honda and Volkswagen – which suppressed the research for two yearsA major security flaw in more than 100 car models has been exposed in an academic paper that was suppressed by a major manufacturer for two years.Flavio Garcia, a computer scientist at the University of Birmingham, and two colleagues from a Dutch university were unable to release the paper after Volkswagen won a case in the high court to ban its publication. Continue reading...
Security Analysis of India’s Electronic Voting Machines (2010) [pdf]
Comments
Google Pushes Android One To Africa
Google is ramping up its Android One affordable smartphone program with a push into Africa. The first Android One smartphone for the region is being made by OEM Infinix, and is launching in Nigeria, Egypt, Ghana, Ivory Coast, Kenya and Morocco today. Read More
Row rumbles on over figures in Oracle CSO’s anti-security rant
Now Redwood City giant’s security researcher bridge building can begin … not! Security researchers picking through the entrails of a withdrawn blogpost by Oracle CSO Mary Ann Davidson reckon not even her figures add up. Oracle countered that only it had access to the raw figures, so there.…
Nächste Android-Version heißt „Marshmallow“
ZTE Nubia Z9 Mini: The able Android smartie the company won't sell you
Chinese mid-ranger offers impressive bang for your buck Review The Nubia brand is largely unknown in the UK, because ZTE chooses not to flog its so-named wares here in Blighty. Nevertheless, international-spec Nubia Z9s are reasonably easy to acquire and when Chinese wholesaler GearBest offered to lend us one to poke with the El Reg reviewing stick, we thought: why not?…
Googles Smartphone-System: Android M heißt Marshmallow und trägt Nummer 6.0
Google hat die finale Version des SDKs für Android M herausgebracht und nebenher zwei Details verraten: Diese Version wird Android 6.0 Marshmallow heißen.
'Marshmallow' picked as moniker for Android 6.0
Is Google telling us Android is soft, insubstantial, very good toasted but easily burned? Alphabet's search, ads, cloud and mobile business Google has revealed that the next version of its Android mobile operating system will be called “Marshmallow”.…
Security systems integration on highways: are you up for the challenge?
Comments
Grab the new Android Marshmallow wallpapers
Want to get a little of that Android Marshmallow look, but don't want to flash beta preview software or don't have a phone to install it on? The nine new wallpapers from Android 6.0 are a good start.
Android M is for Marshmallow
Android M is no more. Instead, we now have a fluffy, sweet, almost ethereal Marshmallow. That's the name Google has given to version 6.0 of the operating system, continuing its long-running, sugary naming tradition—although Android has been tasting a little sour lately, like licorice and raisins.That slight bitterness aside, the official christening also marks the release of the Android 6.0 SDK, which can be downloaded via Android Studio 's SDK Manager. Developers can also download updated ...Read more...
Android M is 6.0 and Marshmellow
Whether you like them straight out of the bag, roasted to a golden brown exterior with a molten center, or in fluff form, who doesn't like marshmallows? We definitely like them! Since the launch of the M Developer Preview at Google I/O in May, we've enjoyed all of your participation and feedback. Today with the final Developer Preview update, we're introducing the official Android 6.0 SDK and opening Google Play for publishing your apps that target the new API level 23 in Android Marshmallow.Think twice before flashing this third Android 6.0 developer preview - you'll need to reflash to a factory image once the final version is released.
Android M is 6.0 and Marshmallow
Whether you like them straight out of the bag, roasted to a golden brown exterior with a molten center, or in fluff form, who doesn't like marshmallows? We definitely like them! Since the launch of the M Developer Preview at Google I/O in May, we've enjoyed all of your participation and feedback. Today with the final Developer Preview update, we're introducing the official Android 6.0 SDK and opening Google Play for publishing your apps that target the new API level 23 in Android Marshmallow.Think twice before flashing this third Android 6.0 developer preview - you'll need to reflash to a factory image once the final version is released.
Android 6.0: M Is For Marshmallow
Google revealed today the full name of Android M... Marshmallow...
Android M heißt Marshmallow und trägt Nummer 6.0
Heute hat Google die finale Version des SDKs für Android M herausgebracht und nebenher zwei Details verraten: Diese Version wird Android 6.0 Marshmallow heißen.
Developers can now submit apps to Google Play that use Android Marshmallow's API 23
Alongside revealing Android M's actual name, and releasing the new Android 6.0 SDK, Google has announced that developers can now submit apps that use Marshmallow's API 23. This means developers can now build their apps against the official SDK, and submit them for testing on Developer Preview devices.
This is what goes in to making a giant Android Marshmallow statue
Nat + Lo and Marshmallow. (Say it over and over. It's fun.)
Google’s Next Version of Android Is Called “Marshmallow”
Comments
Final M preview and Android 6 SDK now available
Statues aren't the only thing unveiled at Google HQ today! The Final M preview and the official Android 6.0 Marshmallow SDK have been posted, and both are ready for you to download. The final M preview will come to you OTA (Over The Air) if you've installed the previous version of the Android M preview, or if you're like us and can't be bothered to wait for it, you can grab the factory image from the Android developer site. Images have been posted for the Nexus 6, the Nexus 9, the Nexus 5 and the Nexus Player. The Android 6.0 SDK can be installed directly from your existing Android SDK manager, or you can grab a new copy and install fresh. While "final" sounds pretty, well, final, remember that this is still beta software. There might very well be bugs. For help on installing an Android factory image to your Nexus, have a look here. More: Android Developers blog
Google’s Next Version Of Android Is Called “Marshmallow”
Google has made it a thing to name its Android OS versions after food. Letter by letter in the alphabet (har har). But not just any food — food that’s really bad for you. This version, which has been called “M” until now, had its name unveiled today…. Read More
Official Android 6.0 SDK and Final M Preview
Comments
Security updates for Monday
Arch Linux has updated glibc(denial of service from 2014).Debian-LTS has updated libidn(information disclosure) and subversion (information disclosure).Fedora has updated bzr (F22; F21:denial of service from 2013), firefox (F21:multiple vulnerabilities), and flac (F22: two vulnerabilities).Gentoo has updated adobe-flash(multiple vulnerabilities), icecast (denialof service), and libgadu (threevulnerabilities from 2013 and 2014).openSUSE has updated firefox (13.2; 13.1:multiple vulnerabilities) and flash-player (13.2; 13.1: many vulnerabilities).Oracle has updated kernel 3.8.13 (OL7; OL6: tworemote denial of service flaws), kernel 2.6.39 (OL6; OL5: tworemote denial of service flaws), and kernel 2.6.32 (OL6; OL5: tworemote denial of service flaws).Red Hat has updated glibc (RHEL5:code execution from 2013), mysql55-mysql (RHEL5; RHSC2:multiple unspecified vulnerabilities, one from 2014), rh-mysql56-mysql (RHSC2: multiple unspecifiedvulnerabilities), sqlite (RHEL6:code execution), sqlite (RHEL7: three vulnerabilities), and subversion (RHEL6: three vulnerabilities).Scientific Linux has updated sqlite (SL7: three vulnerabilities).Slackware has updated firefox(multiple vulnerabilities) and thunderbird(multiple vulnerabilities).Ubuntu has updated openssh(15.04, 14.04, 12.04: two vulnerabilities) and pollinate (15.04, 14.04: certificate update).
Android M’s official name is… Marshmallow [Update: Version 6.0]
Google unveils a new Android statue along with the codename Ars predicted.
Marshmallow is the official name for Android M
Update: Google has taken off the cover showing that the Android mascot holding a marshmallow, confirming that "Marshmallow" is the official name for what we have been previously calling "Android M". Original story: Google is once again teasing the Android M reveal, this time showing what appears to be a fully built statue under a white cover. Recently, Google posted a teaser video in which it listed a number of treats that began with the letter M, and at the end showed off a statue being painted white.
Verizon pushes Android 5.1.1 with Stagefright patch to the Nexus 7
Verizon is now pushing an update to the Nexus 7 which brings Android 5.1.1 to the tablet, along with a patch for the Stagefright exploit. The update brings a number of changes to the appearance and interaction on the tablet, as well as some behind the scenes changes.
Plug and Play Linux and Android Development Acceleration
Comments
Show HN: Pay to win tic-tac-toe for Android
Comments
Should apps get network access by default? Android vs. Sandstorm
Comments
Backend as a Service: Parse gibt SDKs für Android und iOS frei
Die Open-Source-Legung der kostenlosen SDKs geschieht offenbar vor dem Hintergrund, eine größere Stabilität und Zuverlässigkeit bieten zu können.
[SOLVED] Pax Security - seting flags to a directory
So I'm testing Arch's linux-grsec Kernel and it seems Steam has a few issues with it. I could make Steam to run with the following command: Code: --------- setfattr -n user.pax.flags -v "PemRS"...
Player FM for Android Auto: Simple playback but cluttered listings
There's absolutely no shortage of podcast players available for Android Auto. In our 'tour of Android Auto apps, we've already taken a look at several from the usual suspects. But Player FM admittedly was a new one for me, despite it being in the same 500,000 to 1 million downloads category as our current favorite podcatcher. Turns out it's a highly capable app with a bevy of features that even the most hard-core podcast listener would demand. Player FM also supports Android Auto. But, like every other Android Auto-capable app, not all of its features made the trip into our cars. Let's see what's left.
Kaspersky Lab Security Startup Challenge Winners
Comments
c2k15: beck@ on LibreSSL security, midlayer work
For your reading pleasure, here is the c2k15 report from Bob Beck (beck@):
12345678910