Hyundai Motor America patched its Blue Link mobile app after researchers found a cleartext encryption key that could be use to expose user and vehicle information.
Zimperium Acquisition Program Publishes Exploits for Patched Android Bugs
Exploits for patched Android elevation of privilege vulnerabilities were published through the Zimperium N-Days Exploit Acquisition Program.
xDedic Market Spilling Over With School Servers, PCs
Nearly two-thirds of servers and PCs peddled on the xDedic underground marketplace belong to schools and universities based in United States.
SMSVova Spyware Hiding in ‘System Update’ App Ejected From Google Play Store
An Android app that falsely claimed to be a tool for keeping smartphones up-to-date with the latest version of the OS was found surreptitiously tracking the physical location of it users using spyware called SMSVova.
Threatpost News Wrap, April 21, 2017
Last Friday’s ShadowBrokers dump, Microsoft ditching passwords, and a new car dongle hack are all discussed.
Microsoft Touts New Phone-Based Login Mechanism
Microsoft announced this week its giving users a new way to sign into their accounts without long and complicated passwords.
Low-Cost Ransomware Service Discovered
A new ransomware-as-a-service called Karmen appeals to ransomware newbies with a low price, easy setup and developer updates.
Wave of Java-Based RATs Target Tax Filers
A rash of Java-based remote access Trojans is targeting tax filers with bogus IRS attachments.
Threatpost News Wrap, April 14, 2017
Mike Mimoso, Tom Spring, and Chris Brook recap Infiltrate Con in Miami last week, and Kaspersky Lab’s Security Analyst Summit in St. Maarten
Google Making Life Difficult for Ransomware to Thrive on Android
At the Kaspersky Lab Security Analyst Summit, Android Security Team malware analyst Elena Kovakina explained Google’s strategy for countering ransomware on Android.