Researchers warn two features, not flaws, in Android can be used together to open devices up to attack.
Password Breaches Fueling Booming Credential Stuffing Business
The market for automated credential stuffing tools is growing fast, because of a record number of breaches.
Google Elevates Security in Android O
Android O, due in the third quarter, figures to elevate the security of the mobile OS with new features focused on improved third-party patching, a new permission model and hardening of existing features.
Subtitle Hack Leaves 200 Million Vulnerable to Remote Code Execution
Attackers can remotely execute code on targeted systems via specially crafted subtitle files for videos.
Senate’s Use of Signal A Good First Step, Experts Say
The Senate’s use of the end-to-end encrypted messaging app Signal is a good first step in protecting U.S. democratic institutions, but much more needs to be protected.
Android Gets Security Makeover With Google Play Protect
Google announces big changes for Android security including new features, a rebranding of old services and an updated UI, all streamlined under a new service called Google Play Protect.
Android Permissions Flaw Will Linger Until O Release
Google said a permissions flaw that puts Android users at heightened risk of malware, ransomware and adware attacks will not be fixed until the release of its next mobile OS, Android O.
Ultrasonic Beacons Are Tracking Your Every Movement
More than 200 Android mobile applications listen surreptitiously for ultrasonic beacons embedded in audio that are used to track users and serve them with targeted advertising.
Google Patches Six Critical Mediaserver Bugs in Android
Google pushed out its monthly Android patches Monday, addressing 17 critical vulnerabilities, six of which are tied to the Android Mediaserver component and four addressing problems with Qualcomm chipsets.
Ransomware, Cyberespionage Dominate Verizon DBIR
Verizon’s Data Breach Investigations Report for 2017 shows big growth in the reported number of ransomware attacks and incidents involving cyberespionage.