Tag Archive for: closes

LG closes data-theft hole affecting millions of G3 smartphones

(credit: lg.com)

LG is closing a security hole that makes it possible for attackers to steal chat histories and other sensitive data stored on an estimated 10 million G3 phones.

The vulnerability resides in an LG app called Smart Notice. It comes preinstalled on new LG G3 devices and displays a variety of notifications and suggestions, including recommendations to stay in touch with favorite contacts, saving recent callers’ contact information, and birthday reminders. The app fails to validate data presented to users, making it possible for attackers to manipulate data such as contact information so that it executes malicious code on affected handsets.

“Using the vulnerability, an attacker can easily open the user device to data theft attack, extracting private information saved on the SD Card including WhatsApp data and private images; put the user in danger of phishing attack by misleading the end-user; and enable the installation of a malicious program on the device,” researchers wrote in a blog post published Thursday. “We informed LG, which responded quickly to notice of the vulnerability and we encourage users to immediately upgrade their application to new Smart Notice release, which contains a patch.”

Read 4 remaining paragraphs | Comments

Technology Lab – Ars Technica

Another Bitcoin robbery: Evolution drug market closes, taking $11.7 million

At this point, people who use Bitcoin have to know that their money could simply disappear at any moment, right?

The latest example is Evolution, the largest black market website left standing after the Silk Road was taken down by authorities on multiple occasions, whose owners appear to have shut down the service and run off with more than $ 11.7 million in Bitcoin, Ars Technica reported yesterday.

Former users of the Evolution marketplace are pointing at a Bitcoin wallet that was active earlier this week and holds more than 43,000 Bitcoins, according to Reddit posts quoted at Ars Technica.

To read this article in full or to leave a comment, please click here

Network World Colin Neagle

March 2014 Patch Tuesday: Microsoft closes critical holes in IE, Windows

Today Microsoft released five security updates, two rated Critical and three rated Important. The March security bulletins address 23 Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Internet Explorer and Silverlight.
Ms. Smith’s blog

Microsoft mega-patch closes critical IE flaws, fixes 57 vulnerabilities

Microsoft patched a whopping 57 vulnerabilities for this February 2013 Patch Tuesday, “coming close to the all-time Patch Tuesday tally of 64 flaws, all patched with fixes in April 2011.” You probably recall the critical zero-day hole in Internet Explorer 6, 7 and 8, then the
Ms. Smith’s blog