mobile

Pierluigi Paganini February 10, 2017
Every website that uses jQuery Mobile, and has any open redirect is vulnerable to XSS

Every website that uses jQuery Mobile, and has any open redirect anywhere is vulnerable to cross-site scripting (XSS) attacks. The jQuery Foundation’s jQuery Mobile project is an HTML5-based framework that allows users to design a single responsive web site or application that will work on all popular mobile devices and desktop systems. According to the foundation, […]

Pierluigi Paganini January 23, 2017
BankBot, an Android malware based on a source code leaked online

Antivirus firm Dr. Web spotted a new Android malware dubbed BankBot that is based on a source code that was leaked on an underground forum. Bad news for Android users, researchers from the Russian antivirus maker Dr. Web have reported that the source code for another Android banking malware has been leaked on an underground hacking […]

Pierluigi Paganini January 14, 2017
WhatsApp backdoor? What is wrong in the last claims?

A security issue can be used to intercept and read encrypted messages. Is this a WhatsApp backdoor? Which are potential risks? Is the popular messaging service Whatsapp affected by a backdoor? According to a blog post published by The Guardian, the application was affected by a vulnerability that could be exploited by attackers to intercept and read messages. […]

Pierluigi Paganini January 06, 2017
Analyzing a variant of the GM Bot Android malware

My friends at CyberBlog decided to analyze the GM Bot Android Malware as exercise aiming to receive feedback sand suggestions from the security community. The sample explored is confirmed as a variant of the GM Bot Android malware – who’s source was released publicly in early 2016. The code appears to have been forked by a second […]

Pierluigi Paganini January 06, 2017
A fake Super Mario Run for Android is serving the Marcher Banking Trojan

Zscaler experts have found in the wild a fake version of the Super Mario Run Android App that could install the Android Marcher banking trojan. Bad news for mobile gamers, security experts at Zscaler have spotted a strain of the Android Marcher Trojan masqueraded as the recently released Super Mario Run mobile game for Apple’s iOS. Marcher is a sophisticated banking […]

Pierluigi Paganini January 01, 2017
A new iPhone bug will crash the Messages app with a single text

A researcher discovered that a single text message could be exploited to crash the Messages app by MMS on iOS due to a recently discovered bug A single text message could be exploited to disable the Messages app on any iPhone due to a recently discovered bug. The bug flaw makes the Apple Message app inoperable, making it […]

Pierluigi Paganini December 28, 2016
Android Switcher Trojan targets routers changing DNS settings

Security experts from Kaspersky Lab have spotted a new Android Trojan, dubbed Switcher, that targets routers in order to change their DNS settings. Malware researchers at Kaspersky Lab have spotted a new Android Trojan, dubbed Switcher, that targets routers and changes their DNS settings in order to redirect traffic to malicious websites. The Switcher Trojan has been […]

Pierluigi Paganini December 26, 2016
Cyanogen is shutting down CyanogenMod, it will go on as Lineage, maybe

The most popular custom Android ROM, the Cyanogen OS, Announced That it is closing its services starting from December 31, 2016. Bad news for users of the most popular custom Android ROM, the Cyanogen OS, that is now closing its services. Cyanogen was launched with the intent to provide an improved version of the Google Android operating […]

Pierluigi Paganini December 25, 2016
Moscow wants Apple to unlock iPhone of the killer of the Russian Ambassador

The Russian and Turkish authorities asked Apple to unlock iPhone belonging to the assassin of Russian Ambassador Andrei Karlov. The Russia’s ambassador to Turkey, Andrei Karlov, was killed on Monday during an exhibition in Ankara. The killer is a lone Turkish gunman that shouted “God is great!” and “don’t forget Aleppo, don’t forget Syria!” The shooter was killed […]

Pierluigi Paganini December 20, 2016
Faketoken, the Android ransomware banker that encrypted files

The banker Android ransomware Faketoken that steals financial information and sensitive data now also implements file-encrypting abilities. Security experts from Kaspersky Lab have spotted a strain of known Android malware that now implements also ransomware-like abilities. According to the researchers, Vxers are adding file-encrypting capabilities to traditional mobile banking trojans, the result is a malware that […]