Message to IT: Trusting Apple and Google for mobile app security is career suicide

Credit to Author: Evan Schuman| Date: Mon, 01 Jul 2019 05:47:00 -0700

Ready for the mobile security news that IT doesn’t want to hear about but needs to? When security firm Positive Technologies started pen-testing various mobile apps, security holes were rampant.

We’ll plunge into the details momentarily, but here’s the upshot: “High-risk vulnerabilities were found in 38 percent of mobile applications for iOS and in 43 percent of Android applications” and “most cases are caused by weaknesses in security mechanisms — 74 percent and 57 percent for iOS and Android apps, respectively, and 42 percent for server-side components — because such vulnerabilities creep in during the design stage, fixing them requires significant changes to code.”

To read this article in full, please click here

Read more

Tracing the Supply Chain Attack on Android

Credit to Author: BrianKrebs| Date: Tue, 25 Jun 2019 15:24:29 +0000

Earlier this month, Google disclosed that a supply chain attack by one of its vendors resulted in malicious software being pre-installed on millions of new budget Android devices. Google didn’t exactly name those responsible, but said it believes the offending vendor uses the nicknames “Yehuo” or “Blazefire.” What follows is a deep dive into the identity of that Chinese vendor, which appears to have a long and storied history of pushing the envelope on mobile malware.

Read more

Maine inches closer to shutting down ISP pay-for-privacy schemes

Credit to Author: David Ruiz| Date: Wed, 05 Jun 2019 15:00:00 +0000

Unlike a data privacy proposal in the US and a new data privacy law in California, the Maine data privacy bill aimed at Internet Service Providers (ISPs) explicitly shuts down any pay-for-privacy schemes.

Categories:

Tags:

(Read more…)

The post Maine inches closer to shutting down ISP pay-for-privacy schemes appeared first on Malwarebytes Labs.

Read more

A week in security (May 27 – June 2)

Credit to Author: Malwarebytes Labs| Date: Mon, 03 Jun 2019 17:09:55 +0000

A roundup of security news from May 27–June 2, including a look at 2019 ransomware outbreaks in the Unites States, ATM fraud, NIST’s privacy framework, more legal problems for Google and Facebook, and more.

Categories:

Tags:

(Read more…)

The post A week in security (May 27 – June 2) appeared first on Malwarebytes Labs.

Read more