From Dark Reading:
10 Free or Low-Cost Security Tools
"Security spending is on the rise, but allocating funds remains a challenge. Systems are expensive and skilled talent — if you can find it — comes at a high price.
A new wave of tools, from low-cost to free open source software (FOSS), aim to help with tasks like network scanning and penetration testing. Some of these tools are tailored for specific purposes while others cross several domains."
The purpose of this blog is to help small-medium businesses (SMB's) deal effectively with their unique cyber security needs. With over 15 years experience in IT and cyber security I will show SMB's how they can leverage their limited resources to develop effective cyber defenses to the most common threats using information security best practices and no/low cost tools.
LinkedIn: http://www.linkedin.com/in/ecissorsky/
Twitter: @ecissorsky
Showing posts with label Mobile Security. Show all posts
Showing posts with label Mobile Security. Show all posts
Thursday, May 11, 2017
The Google Play apps that say they don’t collect your data – and then do
From Sophos Naked Security:
The Google Play apps that say they don’t collect your data – and then do
"Adware is typically viewed as a nuisance that does no real harm. But in recent research, SophosLabs has seen adware in Google Play that does more than just deliver ads. This strain can collect the user’s personal information, including email address, and send them to a remote server.
Sophos detects this adware library as Android XavirAd and the information-stealing component as Andr/Infostl-BK."
The Google Play apps that say they don’t collect your data – and then do
"Adware is typically viewed as a nuisance that does no real harm. But in recent research, SophosLabs has seen adware in Google Play that does more than just deliver ads. This strain can collect the user’s personal information, including email address, and send them to a remote server.
Sophos detects this adware library as Android XavirAd and the information-stealing component as Andr/Infostl-BK."
Tuesday, May 9, 2017
Silverpush Quits Creeping World Out, Ceases Tracking TV Habits Via Inaudible 'Beacons'
A follow up to two (2) previous posts. From Forbes:
Silverpush Quits Creeping World Out, Ceases Tracking TV Habits Via Inaudible 'Beacons'
"Less than a week after the Federal Trade Commission warned app developers to stop using code that listened for inaudible sound to track mobile owners' TV watching habits, the Indian firm that marketed the product tells FORBES it's killing the software. But Silverpush product manager Piyush Bhatt says it's not ending the Unique Audio Beacon service because of that FTC action, or because of the many privacy concerns raised over the last year. It's simply a "business decision"."
Silverpush Quits Creeping World Out, Ceases Tracking TV Habits Via Inaudible 'Beacons'
"Less than a week after the Federal Trade Commission warned app developers to stop using code that listened for inaudible sound to track mobile owners' TV watching habits, the Indian firm that marketed the product tells FORBES it's killing the software. But Silverpush product manager Piyush Bhatt says it's not ending the Unique Audio Beacon service because of that FTC action, or because of the many privacy concerns raised over the last year. It's simply a "business decision"."
Android Apps Secretly Tracking Users By Listening To Inaudible Sound Hidden In Adverts
From The Independent:
Android Apps Secretly Tracking Users By Listening To Inaudible Sound Hidden In Adverts
"Researchers say the technique can even be used to de-anonymise Tor users
An increasing number of Android applications are attempting to track users without their knowledge, according to a new report.
Over recent years, companies have started hiding “beacons”, ultrasonic audio signals inaudible to humans, in their adverts, in order to track devices and learn more about their owners."
Android Apps Secretly Tracking Users By Listening To Inaudible Sound Hidden In Adverts
"Researchers say the technique can even be used to de-anonymise Tor users
An increasing number of Android applications are attempting to track users without their knowledge, according to a new report.
Over recent years, companies have started hiding “beacons”, ultrasonic audio signals inaudible to humans, in their adverts, in order to track devices and learn more about their owners."
SPY PHONE Secret messages hidden in TV adverts can order smartphones to spy on people, researchers warn
From The Sun:
SPY PHONE Secret messages hidden in TV adverts can order smartphones to spy on people, researchers warn
"Popular apps downloaded by millions of people are always on the look out for clandestine broadcasts which order them to begin snooping on citizens."
SPY PHONE Secret messages hidden in TV adverts can order smartphones to spy on people, researchers warn
"Popular apps downloaded by millions of people are always on the look out for clandestine broadcasts which order them to begin snooping on citizens."
Friday, May 5, 2017
Hackers Exploit SS7 Flaws to Loot Bank Accounts
From SecurityWeek:
Hackers Exploit SS7 Flaws to Loot Bank Accounts
"Cybercriminals have exploited vulnerabilities in the SS7 protocol to bypass security mechanisms and steal money from bank accounts. Researchers have warned about the threat for years and these types of attacks have recently become a reality.
SS7, which stands for Signalling System No. 7, is a telephony signaling protocol used by telecommunications providers worldwide. It allows the customers of different networks to communicate with one another and ensures that calls are not interrupted when users are traveling over longer distances."
Hackers Exploit SS7 Flaws to Loot Bank Accounts
"Cybercriminals have exploited vulnerabilities in the SS7 protocol to bypass security mechanisms and steal money from bank accounts. Researchers have warned about the threat for years and these types of attacks have recently become a reality.
SS7, which stands for Signalling System No. 7, is a telephony signaling protocol used by telecommunications providers worldwide. It allows the customers of different networks to communicate with one another and ensures that calls are not interrupted when users are traveling over longer distances."
Celebrity ‘extortion’: judge orders reality star to unlock her iPhone
From Sophos Naked Security:
Celebrity ‘extortion’: judge orders reality star to unlock her iPhone
"A Miami judge on Wednesday ordered a reality TV star to unlock her iPhone in a case that’s yet again firing up the legal debate around when we can be compelled to give up our passcodes.
The star, Hencha Voigt, has been charged with conspiracy to extort a social-media celebrity known as the “Queen of Snapchat”. The target of the alleged extortion was South Beach socialite YesJulz (pictured), whose real name is Julieanne Goddard. She’s a party promoter and online marketer who hangs with rappers and athletes and boasts hundreds of thousands of followers, according to her publicist."
Celebrity ‘extortion’: judge orders reality star to unlock her iPhone
"A Miami judge on Wednesday ordered a reality TV star to unlock her iPhone in a case that’s yet again firing up the legal debate around when we can be compelled to give up our passcodes.
The star, Hencha Voigt, has been charged with conspiracy to extort a social-media celebrity known as the “Queen of Snapchat”. The target of the alleged extortion was South Beach socialite YesJulz (pictured), whose real name is Julieanne Goddard. She’s a party promoter and online marketer who hangs with rappers and athletes and boasts hundreds of thousands of followers, according to her publicist."
Wednesday, May 3, 2017
Google Patches More Critical Flaws in Android Mediaserver
From SecurityWeek:
Google Patches More Critical Flaws in Android Mediaserver
"Google this week announced the contents of the May 2017 Android security patches, revealing that six Critical Remote Code Execution (RCE) flaws were addressed in the Mediaserver component.
Over the past couple of years, Mediaserver emerged as one of the most vulnerable Android components, after a Critical RCE bug dubbed Stagefright was said to affect 950 million devices. Detailed in July 2015, the vulnerability encouraged Google to issue monthly security updates for Android."
Google Patches More Critical Flaws in Android Mediaserver
"Google this week announced the contents of the May 2017 Android security patches, revealing that six Critical Remote Code Execution (RCE) flaws were addressed in the Mediaserver component.
Over the past couple of years, Mediaserver emerged as one of the most vulnerable Android components, after a Critical RCE bug dubbed Stagefright was said to affect 950 million devices. Detailed in July 2015, the vulnerability encouraged Google to issue monthly security updates for Android."
Want to get your Android phone purring? Don’t install Full Optimizer
From Sophos Naked Security:
Want to get your Android phone purring? Don’t install Full Optimizer
"If you’re no fan of advertisements popping up on your device, you’ll want to avoid two apps in Google Play: Full Optimizer and Full Optimizer Lite. They deliver adware and don’t really do the things the developer claims."
Want to get your Android phone purring? Don’t install Full Optimizer
"If you’re no fan of advertisements popping up on your device, you’ll want to avoid two apps in Google Play: Full Optimizer and Full Optimizer Lite. They deliver adware and don’t really do the things the developer claims."
Tuesday, May 2, 2017
Super Free Music Player in Google Play is malware: a technical analysis
From Sophos Naked Security:
Super Free Music Player in Google Play is malware: a technical analysis
Take a good look at this find in Google Play. It goes by the name Super Free Music Player and has so far attracted between 5,000 and 10,000 downloads:

Super Free Music Player in Google Play is malware: a technical analysis
Take a good look at this find in Google Play. It goes by the name Super Free Music Player and has so far attracted between 5,000 and 10,000 downloads:

Fraudsters draining accounts with ‘SIM swaps’ – what to do
From Sophos Naked Security:
Fraudsters draining accounts with ‘SIM swaps’ – what to do
"Have you ever lost your mobile phone?
If so, you already know that your mobile provider will happily sell you a new phone and give you a brand new SIM card to activate the handset.
Lo and behold, when you fire up the new phone, it has your old number, so you don’t need to give all your friends and colleagues a new one."
Fraudsters draining accounts with ‘SIM swaps’ – what to do
"Have you ever lost your mobile phone?
If so, you already know that your mobile provider will happily sell you a new phone and give you a brand new SIM card to activate the handset.
Lo and behold, when you fire up the new phone, it has your old number, so you don’t need to give all your friends and colleagues a new one."
How does Exaspy spyware disguise itself on Android devices?
From SearchSecurity (subscription required):
How does Exaspy spyware disguise itself on Android devices?
"Exaspy spyware, which can access messages, video chats and more, was found on Android devices owned by executives. Expert Nick Lewis explains how Exaspy is able to avoid detection.
Researchers have discovered Android spyware called Exaspy being used to intercept phone-based communications on executives' devices, including phone calls, text messages, video chats and photos. Most mobile security scanners have not been able to detect the spyware. How does Exaspy disguise itself and evade detection?"
How does Exaspy spyware disguise itself on Android devices?
"Exaspy spyware, which can access messages, video chats and more, was found on Android devices owned by executives. Expert Nick Lewis explains how Exaspy is able to avoid detection.
Researchers have discovered Android spyware called Exaspy being used to intercept phone-based communications on executives' devices, including phone calls, text messages, video chats and photos. Most mobile security scanners have not been able to detect the spyware. How does Exaspy disguise itself and evade detection?"
Tuesday, April 18, 2017
That ‘iPhone Wi-Fi bug’ isn’t just for Apple users – here’s a rundown
From Sophos:
That ‘iPhone Wi-Fi bug’ isn’t just for Apple users – here’s a rundown
"Earlier this week, we advised iPhone users to waste no time applying the latest iOS update, even though it came out just five days after Apple’s previous, much bigger update."
That ‘iPhone Wi-Fi bug’ isn’t just for Apple users – here’s a rundown
"Earlier this week, we advised iPhone users to waste no time applying the latest iOS update, even though it came out just five days after Apple’s previous, much bigger update."
Update your iPhone to avoid being hacked over Wi-Fi
From Sophos:
Update your iPhone to avoid being hacked over Wi-Fi
"It’s only been five days since Apple’s last security update for iOS, when dozens of serious security vulnerabilities were patched."
Update your iPhone to avoid being hacked over Wi-Fi
"It’s only been five days since Apple’s last security update for iOS, when dozens of serious security vulnerabilities were patched."
Apple Readies iPhone Overhaul for Smartphone's 10th Anniversary
From Bloomberg:
Apple Readies iPhone Overhaul for Smartphone's 10th Anniversary
"Apple is testing a revamped iPhone with an all-screen front, curved glass and a stainless steel frame alongside upgrades to the current models."
Apple Readies iPhone Overhaul for Smartphone's 10th Anniversary
"Apple is testing a revamped iPhone with an all-screen front, curved glass and a stainless steel frame alongside upgrades to the current models."
Tuesday, April 11, 2017
That Fingerprint Sensor on Your Phone Is Not as Safe as You Think
From the NY Times:
That Fingerprint Sensor on Your Phone Is Not as Safe as You Think
"SAN FRANCISCO — Fingerprint sensors have turned modern smartphones into miracles of convenience. A touch of a finger unlocks the phone — no password required. With services like Apple Pay or Android Pay, a fingerprint can buy a bag of groceries, a new laptop or even a $1 million vintage Aston Martin. And pressing a finger inside a banking app allows the user to pay bills or transfer thousands of dollars."
That Fingerprint Sensor on Your Phone Is Not as Safe as You Think
"SAN FRANCISCO — Fingerprint sensors have turned modern smartphones into miracles of convenience. A touch of a finger unlocks the phone — no password required. With services like Apple Pay or Android Pay, a fingerprint can buy a bag of groceries, a new laptop or even a $1 million vintage Aston Martin. And pressing a finger inside a banking app allows the user to pay bills or transfer thousands of dollars."
Wednesday, July 22, 2015
Hacking Team's RCS Android: The most sophisticated Android malware ever exposed
From Help Net Security:
Hacking Team's RCS Android: The most sophisticated Android malware ever exposed
As each day passes and researchers find more and more source code in the huge Hacking Team data dump, it becomes more clear what the company's customers could do with the spyware, and what capabilities other organized and commercial malware authors will soon be equipping their malicious wares with.
After having revealed one of the ways that the company used to deliver its spyware on Android devices (fake app hosted on Google Play), Trend Micro researchers have analyzed the code of the actual spyware: RCS Android (Remote Control System Android).
Hacking Team's RCS Android: The most sophisticated Android malware ever exposed
As each day passes and researchers find more and more source code in the huge Hacking Team data dump, it becomes more clear what the company's customers could do with the spyware, and what capabilities other organized and commercial malware authors will soon be equipping their malicious wares with.
After having revealed one of the ways that the company used to deliver its spyware on Android devices (fake app hosted on Google Play), Trend Micro researchers have analyzed the code of the actual spyware: RCS Android (Remote Control System Android).
Free tools for detecting Hacking Team malware in your systems
From Help Net Security:
Free tools for detecting Hacking Team malware in your systems
Worried that you might have been targeted with Hacking Team spyware, but don't know how to find out for sure? IT security firm Rook Security has released Milano, a free automated tool meant to detect the Hacking Team malware on a computer system.
It does so by looking for files associated with the recent Hacking Team breach. The tool is still in beta, and currently searches the system for 40 Windows executable and library files. The list is expected to expand as the company's researchers continue to review the leaked Hacking Team data.
Free tools for detecting Hacking Team malware in your systems
Worried that you might have been targeted with Hacking Team spyware, but don't know how to find out for sure? IT security firm Rook Security has released Milano, a free automated tool meant to detect the Hacking Team malware on a computer system.
It does so by looking for files associated with the recent Hacking Team breach. The tool is still in beta, and currently searches the system for 40 Windows executable and library files. The list is expected to expand as the company's researchers continue to review the leaked Hacking Team data.
Monday, July 20, 2015
Hacking Team used fake app hosted on Google Play to install its spyware on Android devices
From Help Net Security:
Hacking Team used fake app hosted on Google Play to install its spyware on Android devices
The massive Hacking Team data leak includes the source code of a fake Android news app and instructions on how to use it, Trend Micro researchers have found.
The app, dubbed BeNews after a now-defunct news site, was made available from Google Play, and it was downloaded 50 or less times until it was removed.
Hacking Team used fake app hosted on Google Play to install its spyware on Android devices
The massive Hacking Team data leak includes the source code of a fake Android news app and instructions on how to use it, Trend Micro researchers have found.
The app, dubbed BeNews after a now-defunct news site, was made available from Google Play, and it was downloaded 50 or less times until it was removed.
Friday, July 17, 2015
The arsenal of SMS scammers, spammers and fraudsters
From Help Net Security:
The arsenal of SMS scammers, spammers and fraudsters
Illicit commercial activity online has manifested into all things mobile. With revenue in the billions from mobile marketing, criminals are doing their best to harness the technology for their own monetary gain. Monetisable triggers that come from pay for performance activity on mobile such as clicks, downloads, registrations, video ads, referrals, games and surveys are driving substantial funds for scams and spam.
Initiating clever tricks with low detection rates, criminals subvert mobile network operators’ control to leave both consumers and corporations in the firing line for exploitation. These scammers, spammers and fraudsters are quickly developing methods and tools to manipulate the mobile, and the services it can provide, as well as the legal system.
The arsenal of SMS scammers, spammers and fraudsters
Illicit commercial activity online has manifested into all things mobile. With revenue in the billions from mobile marketing, criminals are doing their best to harness the technology for their own monetary gain. Monetisable triggers that come from pay for performance activity on mobile such as clicks, downloads, registrations, video ads, referrals, games and surveys are driving substantial funds for scams and spam.
Initiating clever tricks with low detection rates, criminals subvert mobile network operators’ control to leave both consumers and corporations in the firing line for exploitation. These scammers, spammers and fraudsters are quickly developing methods and tools to manipulate the mobile, and the services it can provide, as well as the legal system.
Subscribe to:
Posts (Atom)