Showing posts with label Android. Show all posts
Showing posts with label Android. Show all posts

Friday, December 13, 2019

Trend Micro warns Android users on malicious Christmas-themed shopping, game and chat apps that lure users with deals

Security researchers from Trend Micro have cautioned Android users when downloading apps for shopping, games, and Santa video chats as they found hundreds of malicious apps likely leveraging the season to defraud unwitting victims. 

A scan of thousands of apps revealed seven with malicious routines such as replacing the legitimate apps with a version downloaded from a command and control (C&C) server. They also found 35 apps containing adware with more invasive behaviors than standard in-app advertisements, and 165 apps enabling “excessive or dangerous combinations of permissions,” such as camera, microphone, contacts and text messages. 


Researchers from Barracuda Networks recommend that users examine the apps they download to their phones, especially as online shopping and banking are expected to reach new heights this year.

Invasive adware were reportedly related to DIY gift projects and used suspicious ad networks by displaying catchy deals and coupons. Cybercriminals can go after banking, email, and access credentials by replacing legitimate website forms, or by using malware or injected skimmers

The researchers noted the excessive permissions that users may grant apps can be used to steal stored information from the devices such as contacts for phishing and spam campaigns, as well as banking authentication tokens via SMS messages when shoppers finalize their purchases online.

When downloading apps and shopping online, users must check app reviews on reputable websites; review access permissions being requested by the app and evaluate if they are necessary for the functions of the app; directly type the retailers’ websites, and avoid clicking on URLs found in emails and text messages, especially from unknown senders; limit the amount of personal information provided to websites and apps; and regularly update devices’ operating systems and apps.


Users and enterprises can take advantage of multilayered mobile security such as the Trend Micro Mobile Security for Android solution. Trend Micro Mobile Security for Enterprise provides device, compliance and application management, data protection, and configuration provisioning, as well as protects devices from attacks that exploit vulnerabilities, prevents malicious and unauthorized access to apps, and detects and blocks malware and fraudulent websites. 

Trend Micro’s Mobile App Reputation Service (MARS) covers Android threats using leading sandbox and machine learning technologies, protecting devices against malware, zero-day and known exploits, malicious apps, privacy leaks, and application vulnerabilities.

Sunday, December 8, 2019

Google extends its Android TLS adoption program; covers 80% apps by default

Google announced this week that 80 percent of Android apps are encrypting traffic by default. The percentage is even greater for apps targeting Android 9 and higher, with 90 percent of them encrypting traffic by default.

Android is committed to keeping users, their devices, and their data safe. One of the ways that Google is keeping data safe is by protecting network traffic that enters or leaves an Android device with Transport Layer Security (TLS). 


Android 7 (API level 24) introduced the Network Security Configuration in 2016, allowing app developers to configure the network security policy for their app through a declarative configuration file. To ensure apps are safe, apps targeting Android 9 (API level 28) or higher automatically have a policy set by default that prevents unencrypted traffic for every domain.

The Network Security Configuration feature lets apps customize their network security settings in a safe, declarative configuration file without modifying app code. These settings can be configured for specific domains and for a specific app. 


This feature can customize which Certificate Authorities (CA) are trusted for an app's secure connections. For example, trusting particular self-signed certificates or restricting the set of public CAs that the app trusts. It also safely debugs secure connections in an app without added risk to the installed base; protects apps from accidental usage of cleartext traffic; and restricts an app's secure connection to particular certificates.

Since Nov. 1 2019, all app (updates as well as all new apps on Google Play) must target at least Android 9. As a result, we expect these numbers to continue improving. Network traffic from these apps is secure by default and any use of unencrypted connections is the result of an explicit choice by the developer.


The latest releases of Android Studio and Google Play’s pre-launch report warn developers when their app includes a potentially insecure Network Security Configuration (for example, when they allow unencrypted traffic for all domains or when they accept user provided certificates outside of debug mode). 

This encourages the adoption of HTTPS across the Android ecosystem and ensures that developers are aware of their security configuration.

Wednesday, November 27, 2019

Google Security expands its Android Security rewards program

Google is expanding its Android Security Rewards (ASR) program and increasing reward amounts, by introducing a top prize of US$1 million for a full chain remote code execution exploit with persistence which compromises the Titan M secure element on Pixel devices. Additionally, the search engine giant will release a specific program offering a 50 percent bonus for exploits found on specific developer preview versions of Android, offering a top prize of $1.5 million.


The rewards program was created in 2015 to reward researchers who find and report security issues to help keep the Android ecosystem safe. Over the past 4 years, Google has awarded over 1,800 reports, and paid out over four million dollars.

The Android Security Rewards program recognizes the contributions of security researchers who invest their time and effort in helping Google make Android more secure. The reward level is based on the bug severity and increases for complete reports that include reproduction code, test cases, and patches.

Android Security Rewards covers bugs in code that runs on eligible devices and isn't already covered by other reward programs at Google. Eligible bugs include those in AOSP code, OEM code (libraries and drivers), the kernel, the Secure Element code, and the TrustZone OS and modules. Vulnerabilities in other non-Android code, such as the code that runs in chipset firmware, may be eligible if they impact the security of the Android OS.


Earlier this year, Gartner rated the Pixel 3 with Titan M as having the most “strong” ratings in the built-in security section out of all devices evaluated. Due to this, Google has created a dedicated prize to reward researchers for exploits found to circumvent the secure elements protections.

In addition to exploits involving Pixel Titan M, Google has added other categories of exploits to the rewards program, such as those involving data exfiltration and lockscreen bypass. These rewards go up to $500,000 depending on the exploit category. 

During this year, Google made total payouts over the last 12 months to the tune of over $1.5 million. Over 100 participating researchers have received an average reward amount of over $3,800 per finding (46 percent increase from last year), and the top reward that was paid out this year was $161,337.

The highest reward paid out to a member of the research community was for a report from Guang Gong (@oldfresher) of Alpha Lab, Qihoo 360. This report detailed the first reported 1-click remote code execution exploit chain on the Pixel 3 device. 

Guang Gong was awarded $161,337 from the Android Security Rewards program and $40,000 by Chrome Rewards program for a total of $201,337. The $201,337 combined reward is also the highest reward for a single exploit chain across all Google VRP programs. The Chrome vulnerabilities leveraged in this report were fixed in Chrome 77.0.3865.75 and released in September, protecting users against this exploit chain.

Wednesday, November 20, 2019

Toshiba expands e-STUDIO MFP line with A3 models, ideal for small-to-medium businesses

Toshiba America Business Solutions expanded its e-STUDIO multifunction printer (MFP) line with the introduction of five ledger-size (A3) models addressing the document management needs of small-to-medium-size businesses (SMBs).

Toshiba’s monochrome product family (the e-STUDIO2822AM, e-STUDIO2822AF, e-STUDIO2823AM, e-STUDIO2329A and e-STUDIO2829A) offers several models with the print, copy, scan and fax functionality small workgroups need.



Delivering documents at up-to 28 pages-per-minute (ppm) in razor-sharp 2400 x 600 dots-per-inch resolution, these products also scan color documents at up to 22 ppm presenting vibrant digital materials at a moment’s notice.

Busy environments with space constraints such as logistics, manufacturing and retail that demand all the functionality of a full-sized MFP, including A3 support, will appreciate the compact letter-size (A4) footprint of the e-STUDIO2822AM or fax-enabled e-STUDIO2822AF. The systems conveniently provide ledger-size support via the 50-sheet built-in bypass for jobs requiring larger media.


Users may customize these models even further by adding the Wi-Fi option that turns the networked MFPs into an access point. When coupled with the new e-BRIDGE Print & Capture Entry app, Apple iOS and Android users may print-to and scan-from Toshiba MFPs to their mobile devices.

Sunday, November 3, 2019

IDC shows that global tablet shipments return to growth in the third quarter, pushed by new product launches

Research firm IDC has reported that the global tablet market returned to growth in the third quarter of 2019 with 37.6 million units shipped globally for a year-over-year increase of 1.9 percent, according to preliminary data from the International Data Corporation Worldwide Quarterly Tablet Tracker

Apple maintained its lead and grew 21.8 percent over last year. The introduction of a new iPad late in the quarter helped the company gain share, growing from 26.3 percent in the third quarter of 2018 to 31.4 percent for this year’s third quarter. 


By including the Smart Connecter on its latest device, all of Apple's iPads except the Mini now offer a detachable keyboard option. This, combined with the iPad OS, makes Apple the largest player in the detachable space and a greater threat to the traditional PC market. 

Amazon.com managed to grab the second spot (usually held by Samsung) during the quarter, growing shipments 25.6 percent year over year. The introduction of the new Fire 7 last quarter combined with the company's annual Prime Day Sale helped drive shipments. 

With the latest refresh of the Fire 10 and the upcoming holiday season, Amazon continues to position itself as one of the most popular tablet brands. 

Samsung slipped into third place, shipping 4.6 million units in the quarter. The Tab A series continues to be incredibly popular accounting for more than half of Samsung's shipments, while the Tab S series has helped raise the company's profile as a premium Android tablet vendor. 


Huawei shipped 3.6 million units in the third quarter of this year for a year-over-year decline of 4.4 percent. The company has faced steady pressure from the United States, and this has led to a bit of retrenchment as the majority of the company's shipments were in China. 

Lenovo rounded out the top 5, growing its share slightly from 6.3 percent in the third quarter of 2018 to 6.7 percent in the current quarter. The company's performance in Asia/Pacific, including Japan, along with Europe, Middle East & Africa, continued to be a driver. 

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...