Mobile

Pierluigi Paganini July 11, 2019
Agent Smith Android malware already infected 25 million devices

‘Agent Smith’ is a new malware discovered by Check Point researchers that replaces legit Android Apps with malicious ones that infected 25 Million devices worldwide. Researchers at Check Point recently discovered a new variant of Android malware, dubbed Agent Smith, that has already infected roughly 25 million devices. The malware is disguised as a Google […]

Pierluigi Paganini July 05, 2019
‘Updates for Samsung’, the scam app with 10M+ downloads

Experts discovered a malicious app on Google Play, named Updates for Samsung, that was downloaded by over ten million users that poses as firmware updates. Over ten million users have installed a fake Samsung app named “Updates for Samsung” that poses as firmware updates. The malicious app redirects users to a website offering and charging […]

Pierluigi Paganini July 03, 2019
China installs a surveillance app on tourists’ phones while crossing in the Xinjiang

Chinese border guards are secretly installing a surveillance app on smartphones of tourists and people crossings in the Xinjiang region who are entering from Kyrgyzstan. Are you entering in the Xinjiang (China) from Kyrgyzstan? There is something that you need to know, Chinese border guards are secretly installing surveillance software on the mobile devices of […]

Pierluigi Paganini July 03, 2019
Google addressed three critical code execution flaws in Android Media Framework

Google released the July 2019 security patches for the Android OS that address a total of 33 vulnerabilities, including 9 issues rated as Critical. The most severe flaw addressed by Google is a critical security issue (CVE-2019-2106) affecting the Media framework that could be exploited by a remote attacker to execute arbitrary code within the […]

Pierluigi Paganini July 01, 2019
ViceLeaker Android spyware targets users in the Middle East

Experts at Kaspersky have uncovered a spyware campaign dubbed ViceLeaker that spreads in the Middle East to spy on Android users.  Kaspersky spotted a spyware campaign, tracked as ViceLeaker, that spreads in the Middle East to steal device and communications data from Android users.  The ViceLeaker campaign has been active at least since May 2018 […]

Pierluigi Paganini June 23, 2019
Expert released PoC for Outlook for Android flaw addressed by Microsoft

Security researcher from F5 Networks that released more details and proof-of-concept for the recently addressed flaw in Outlook for Android. Microsoft has recently addressed an important vulnerability, tracked as CVE-2019-1105, in Outlook for Android, that potentially affected over 100 million users. The vulnerability is a stored cross-site scripting issue that is related to the way […]

Pierluigi Paganini June 22, 2019
Android Botnet leverages ADB ports and SSH to spread

Trend Micro recently discovered an Android crypto-currency mining botnet that can spread via open ADB (Android Debug Bridge) ports and Secure Shell (SSH).  Security researchers at Trend Micro have discovered an new Android crypto-currency mining botnet that spreads via open ADB (Android Debug Bridge) ports and Secure Shell (SSH).  The Android Debug Bridge (adb) is […]

Pierluigi Paganini June 21, 2019
Microsoft fixed CVE-2019-1105 flaw in Outlook for Android

Microsoft has addressed an important vulnerability (CVE-2019-1105) in Outlook for Android, potentially affected over 100 million users. Microsoft has addressed an important flaw tracked as CVE-2019-1105 that affects versions of Outlook for Android app before 3.0.88. The vulnerability is a stored cross-site scripting issue that is related to the way the app parses incoming email […]

Pierluigi Paganini June 18, 2019
Android Apps uses a novel technique to by-pass 2FA and steal Bitcoin

Expert discovered a new technique bypassing SMS-based two-factor authentication while circumventing Google’s recent SMS permissions restrictions The popular security expert Lukas Stefanko from ESET discovered some apps (namedBTCTurk Pro Beta and BtcTurk Pro Beta) impersonating the Turkish cryptocurrency exchange, BtcTurk, in the attempt of stealing login credentials. In order to steal the 2FA OTPs the […]

Pierluigi Paganini May 25, 2019
Snapchat staff used internal tools to spy on users

Snapchat internal staff has allegedly abused their role in the company to spy on Snapchat users using and internal tools and steal data. Snapchat is a multimedia messaging app that makes pictures, videos, and messages (snaps) available for a short time before they become inaccessible to their recipients. Initially, it was only allowing person-to-person photo sharing, but now […]