Tag Archive for: urgent

Urgent security warning for Android users over ‘dangerous’ new bug that’s spread across the world


A DANGEROUS malware bug is spreading across the globe and affecting Android users.

The so-called “Xenomorph Android” malware was first spotted last year, but has returned: and can endanger your bank applications.

A new malware is circulating around the globeCredit: Getty
Android users are encouraged to be extra alertCredit: Getty

Now, the bug is back, with worries that it’s spreading quickly without many knowing they have it on their device.

More than 400 baking applications and digital wallets are being targeted by the vicious virus.

Experts at TreatFabric said the malware can automatically hack accounts, including stealing bank account balances.

The bug can also make unauthorised transactions, and transfer money to other accounts without permission.

Xenomorph can now “completely automate the whole fraud chain”, from infecting software to making illicit transactions.

The attacks are concentrated with users in Spain, Turkey and the United States, but experts are worried it could spread.

Android owners have been warned to watch out when downloading any new applications.

Reading reviews and checking the names of developers on applications is a good way to ensure it’s reliable, and not malware.

This comes on the tails of Apple issuing a warning to iPhone users earlier this week.

Users are being urged to utilise the built-in security features on iPhone to protect your data and personal information.

The four part security checkup asks users to begin by setting a strong passcode.

Apple said: “Setting a passcode also turns on data protection, which encrypts your iPhone data with 256-bit AES encryption.”

Using Face ID or Touch ID adds an extra layer of protection, providing a secure and convenient way to unlock your iPhone, authorize payments, and sign in to third-party apps.

Turning on the “Find My” feature is a great help as it can find your device if it’s stolen.

It also allows you to erase your data if you can’t recover your device.

You can also control what features are available without unlocking your iPhone.

Disabling access to certain features can keep your device safer – for example, USB connections.

Android users are asked to be vigilant when downloading new applications

Source…

CISA: Urgent patching needed for actively exploited Linux kernel flaw


SecurityWeek reports that federal agencies have been ordered by the Cybersecurity and Infrastructure Security Agency to remediate within three weeks a Linux kernel bug, tracked as CVE-2021-3493, which has been added to the agency’s Known Exploited Vulnerabilities Catalog following active exploitation by the new stealthy Linux malware Shikitega.

Linux-based IoT devices and endpoints have been targeted by the Shikitega malware, which abuses CVE-2021-3493 and CVE-2021-4034, also known as PwnKit, to facilitate privilege escalation. However, only Ubuntu has so far been observed to be impacted by the Linux kernel vulnerability.

Despite requiring only federal agencies to apply patches for the flaw until Nov. 10, the CISA has urged all organizations across the U.S. immediately address the vulnerability and other bugs included in its KEV catalog.

CISA has also updated its KEV catalog to include a recent flaw impacting Zimbra systems, which has only been addressed following active exploitation by threat actors.

Source…

GitHub case: Twitter rejects urgent request for accounts details, says it’s not national security matter


Twitter is said to have denied details of two handles thought to be connected to the case where a female journalist’s photo was uploaded on a website alongside disparaging comments, saying this was not a “national security threat matter” and that the Delhi Police should approach it through the proper channel instead.

Days after lodging an FIR against unknown persons, the police had written to the software development platform GitHub for details of the website developer, and from Twitter, they sought information about two accounts they believe had tweeted about the app first. The accounts were deactivated when the victims started sharing their ordeal online. “Sensing the gravity of the case, we asked Twitter to provide details of their IP addresses on an urgent basis, but they responded on Tuesday, asking us to come through proper channels since it’s not a national security threat matter,” a senior police officer privy to the investigation said.

The website was made using GitHub on December 31 and doctored photos of at least 100 Muslim women, along with lewd remarks, were posted there. GitHub subsequently removed the content, but many Twitter users tagged the women and posted screenshots.

On January 2, the south-east district police lodged an FIR against unknown persons and subsequently transferred the case to its Intelligence Fusion and Strategic Operations unit on January 4. The police are planning to get the go-ahead for a Mutual Legal Assistance Treaty to seek information about the app from its foreign-based hosting platform.

The Indian Computer Emergency Response System (Cert-In), the nodal agency for monitoring cyber security incidents and related threats, has been asked to form “a high-level committee” to probe the incident and coordinate with the cyber cells of state police forces, senior government officials said.

In her complaint to police on Saturday, the Delhi-based journalist had accused unknown persons of promoting enmity, sexual harassment, and insulting women. “I was shocked to find…that a website/portal…had a doctored picture of me in an improper, unacceptable and clearly lewd context… The…content…is clearly aimed at insulting…

Source…

Urgent Microsoft warning to millions of Windows users as experts warn hackers can take over your computer today


EXPERTS are warning that a vulnerability in Microsoft’s Windows software leaves users open to hackers who can take control over your computer.

The “zero-day” flaw, named CVE-2021-34484, reportedly allows hackers to breach every version of Windows and take over the computer.

Experts are warning about a new Microsoft vulnerability

2

Experts are warning about a new Microsoft vulnerabilityCredit: Getty

Microsoft confirmed the vulnerability, according to Forbes, but believed that they fixed the problem last month.

However, the outlet reports that the fix was also flawed and still left users vulnerable.

Microsoft did not immediately return The Sun’s request for comment about when a new fix may become available to protect users.

Forbes suggests using a third-party security system that has managed to fix the Microsoft vulnerability.

Third-party security specialist 0patch has made their “micropatch” technology available to all Windows users to fix the problem.

“Micropatches for this vulnerability will be free until Microsoft has issued an official fix,” the company confirmed.

To use the micropatch, you will need to register for an 0patch account and install the program onto your computer.

The news comes just days after Microsoft sent out another warning that a group of Chinese cybercriminals are attempting to hack computers by exploiting a software bug.

The company’s Threat Intelligence Center announced that it had detected attempts to target systems that run software called Zoho ManageEngine ADSelfService Plus.

Zoho, an India-based technology corporation, describes its ManageEngine service as an IT managing software.

Authorities are worried Zoha could act as an entry point for hackers to access other information inside important servers.

The vulnerability can affect all Windows users

2

The vulnerability can affect all Windows usersCredit: Getty

Source…