Showing posts with label Anti-virus Trend Micro. Show all posts
Showing posts with label Anti-virus Trend Micro. Show all posts

Wednesday, 5 August 2015

New Android Devices Leak Late Restart Endlessly


Researchers have discovered a new vulnerability in Android which could allow an attacker to restart the unit. In the event it is attacked leak via an app, it is possible to restart to endlessly leave the device. The problem is in the media server of Android, which also previously the Stage Fright leak was discovered, and a vulnerability that sets almost unusable makes.

Also this leak was from the Japanese anti-virus company Trend Micro detected and is present in Android 4.0.1 to 5.1.1 Lollipop. That equates to 89% of Android users. To carry out the attack must play a user to a malicious website an MKV file or install an app that contains the file. In the case of the attack on a media server app is running will end up in an endless loop. The system will eventually be so slow that the system will reboot or the battery expires.

If the attack performed via a website, a user must first play the movie itself. The impact can be especially great when a malicious app. The app can set that starts right at the loading of Android and can then leave as endless reboot the device. In this case, users are not able to remove the app in question, unless the product is launched in Safe mode.

The problem was reported to Google on May 19. On July 31, the Android security team said that there was a security update available. In many cases, Android users for updates depending on their phone company or the manufacturer of their device.Thus it may take longer for updates to be rolled out to users. To our knowledge, the vulnerability is not attacked in the "wild".

Tuesday, 4 August 2015

Attack On Very Serious Android Leak Nearly Public



On a Chinese forum has published information about how a very serious flaw in Android can be used to attack millions of Android phones via only a single MMS message, although the vulnerability also through apps and websites exploit. Reported security Zimperium.

Zimperium discovered the vulnerability, which called Stage Fright got. Later it turned out that anti-virus company Trend Micro same vulnerability was independently discovered . According Zimperium the problem affects 950 million Android devices. It is estimated that in 50% of the sensitive devices the attack without any user interaction to perform. In other cases, opening an MMS sufficient.

Right

The attack an attacker could execute arbitrary code with system privileges or media on the device. Thus, an attacker could take complete control of the camera and microphone, for example, to monitor users. On some handsets running the vulnerable software that is attacked via the MMS message with system privileges. In this case, an attacker elevated privileges and can do almost anything on the device that the user can. Zimperium argues that this is, however, "some" equipment. An attacker could execute arbitrary code on a device, even if the media rights, then may however try to increase his rights.

Originally publish at the Black Hat security conference in Las Vegas this week an exploit. Several organizations asked Zimperium to wait this. Something the company has agreed with it. The security updates for Android, however, are open source. Therefore, many researchers now work on an exploit to attack the vulnerability, reports the company. "We therefore believe that it is only a matter of time before we see attacks in the wild, assuming they do not already take place", said security researcher Zuk Avraham of Zimperium last Saturday knowing. This morning the company warned via Twitter that an exploit is now almost public.

Updates

The problem is that many Android users to update their phone company or the manufacturer of the device are dependent, instead of Google. Therefore it can take a long time updates ultimately be offered if the device is still supported. Several older Android models that are vulnerable and are no longer supported miss an important security measure. As a result, the impact on these devices is much greater.

It would total to about 60 million sets. According to Avraham, an attacker will create a network worm to send MMS messages.Together would the aircraft, after being infected, can send six billion MMS messages per day. Something that could have consequences for the network of telecom providers.

Actions

Users who want to protect themselves getting Zimperium the advice to keep the device up to date. In case the device is no longer supported, users on an operating system such as CyanogenMod switch that supports older devices longer. Another measure that can be taken is to disable automatic retrieval of MMS messages.

Thursday, 30 July 2015

New Android Phones Leak Is Virtually Useless



Researchers have discovered a vulnerability in Android devices allow an attacker can make it as good as useless. The vulnerability, which can be attacked through both websites as a rogue app, ensures that the user can not hear or see that there is a call or a text message is sent. Also, calls can not be accepted.

In case the attack is carried out via a malicious app can crash the operating system. When the app first set to start automatically upon loading the operating system, would thus arise a continuous loop of crashes. Each time the machine crashes because the user's phone and restart the app is loaded again and release Android then crash. Further, the telephone such as that it is no longer locked, to be unlocked.

The problem is in Android 4.3 to Android 5.1.1, which together more than half of all Android devices. According to researchers at Trend Micro appears to be the vulnerability this week announced Stage Fright leak . Both vulnerabilities arise due to the way Android handles media files, although the way these files reach different user. Google was on May 15 informed about the problem, but still has not rolled out updates.

Wednesday, 15 July 2015

Anti-Virus Company: Adobe Flash Player Is Just Like Smoking



The use of Adobe Flash Player is similar to smoking, people know that it is bad for them, but can not always stop, according to the Japanese anti-virus company Trend Micro. Last week, three vulnerabilities in the browser plug-in discovered, two of which are used by cyber criminals to infect computers with malware. The vulnerabilities were discovered by the Italian Hacking Team.

A company with forty employees. "As a relatively small company like Hacking Team can find these types of vulnerabilities, consider the tools that other parties, including countries dispose of. Previously, we only had suspicions about the extent of this problem. Now we have a better idea of the risk, "said analyst Martin Roesler . He notes that disappears in an ideal world Flash in its current form. Whether it is replaced by a technology such as HTML5, or Adobe finds a way to protect the software. According Roesler it is unlikely that this will happen.

"Despite the risks, people continue to use it as security alone is not sufficient reason not to do it." Makers of Web sites still use Flash, allowing users need the plug-in. Roesler calls therefore on end users to remove Flash Player if it is not needed, or click to set to play in. In this case, an extra mouse click required to activate the plug-in. In addition, companies are advised not to use Flash when developing new websites. Also Alex Stamos , the new head of security at Facebook, made ​​a call earlier that Adobe Flash has to stop so that there can be switched to HTML5.

Monday, 13 July 2015

Targeted Attacks On Newly Discovered Java Leak


The Japanese anti-virus company Trend Micro warns of a new critical vulnerability in Java where no update is available for Oracle, which is used in attacks against American defense organization and a member of NATO. According to the virus fighter is about targeted attacks.

That would mean that the vulnerability is not yet widely used to infect home users with malware. For attacking the targets using the assailants emails with a link. The links used by the attackers appear on the left earlier in attacks against NATO members and the White House were deployed, says analyst Li Brooks . In this case the links were encountered in the emails to an American defense organization and a specific NATO member, but who exactly is going does not mean anti-virus company. The link points to a page that tries to make use of the Java leak. In the event that the attack is successful, there is placed on the computer malware.

Vulnerable

The vulnerability is present in the latest Oracle Java version, namely update Java 8 45. Older versions of Java, namely 6 and 7 are not vulnerable. Oracle would have been informed. In anticipation of an update enables users to Java in their browser off or the system removed . A few years ago were regularly called zero-day vulnerabilities found in Java and attacked which no update was available. According to Trend Micro, it is almost two years since the last zero-day Java was reported.

Sunday, 19 April 2015

Even Linux Users Targeted By Cyber Espionage



Appear regularly reports of attacks by cyber spies who have provided at Windows users, but the Japanese anti-virus company Trend Micro claims to have discovered an attack which also Linux users were targeted. The attacks come from a group that the defense companies, media organizations, Russian dissidents, members of NATO and even the White House has provided.

The attackers have been active for some time and use different tactics to infect their victims with malware. There Microsoft Office documents are used as containing spyware. In another attack were on a Polish government site posted several exploits that install malware on the same unpatched users. Finally phishing emails were also used those users to fake login pages for Microsoft Outlook Web Access (OWA) by sent.

Linux

In the first quarter of this year, the group was very active and used it several new attacks, including sending e-mails with malicious links, which supposedly to news reports seem to indicate. When a user opens the link, and certain conditions are met does the so-called news site with a message that there must be an HTML5 plugin installed to view the content of this website. In the case of Linux users who visit the website will be the X Agent or Fysbis spyware offered, while Windows users get the Sednit spyware.

Furthermore, the attackers use again the counterfeit OWA logon pages. These contain phishing pages JavaScript that when the user opens the link from the OWA preview pane, a tab opens with the intended site. In addition, the JavaScript causes the OWA session is forwarded in another tab to a phishing page that lets you know that the user is logged out and must log in again.

White House

Trend Micro also says to have proof that the group the White House has targeted. Four days after three YouTube bloggers President Barack Obama had interviewed these bloggers were the target of a Gmail phishing attack. According to the virus fighter they tried bloggers likely to use as a springboard for attacks against the White House. Who is behind the attacks is spying is not to say the anti-virus company.

Sunday, 11 January 2015

Factories Target Online Banking Malware


Trojans designed to steal money from online bank accounts are also used at industrial plants and factories, so has had a security researcher know. Kyle Wilhoit anti-virus firm Trend Micro discovered thirteen different types of malware that occurred as software in SCADA (supervisory control and data acquisition) environments used. It involves, for example, Siemens WinCC, GE Cimplicity, Advantech and other human machine interface (HMI) products.

Although attacks on industrial environments often with attacks by countries are linked, it would be here involve ordinary cybercriminals. "It's an interesting trend, traditional banking Trojans and no targeted attacks," Wilhoit as late versus Dark Reading know. According to the researcher criminals focus their sights on SCADA / ICS systems because they are unsafe.

Many HMI machines run on Windows and would not use a virus scanner or are not equipped with the latest signatures. Most malware Wilhoit encountered no problems would be detected by an up-to-date virus scanner. While targeted attacks are still at risk managers should also take into account normal "crimeware", as the consequences can be just as bad. HMI systems are very susceptible to interference. Infection by a banking Trojan can also just as easily get the system down.

Wilhoit saw in October for the first peak in the attacks, but does not know what the occasion is. The criminals behind the malware use spear phishing mails and drive-by downloads to infect computers. Fake websites are used on that instance, resemble those of Siemens and supposedly download a WinCC update, while it is actually malware. Wilhoit 32 recently discovered malware instances that occurred as WinCC software. Next week, the researcher during a conference SCADA give more details about his research.