The internet security firm, Palo Alto Networks reports that approximately 39 applications have been infected with the malicious software. It’s also hard for developers to detect malware like XcodeGhost because it’s deeply hidden.
This is how malware was able to get into the App store.
Analysis of infected apps by security researchers appears to be revealing a mix of good and bad news … In the FAQ, the company says iCloud and personal information on apps should be safe, since the malicious code was incapable of finding it.
Apple also said it is working to make it faster for developers in China to download authentic Xcode instead of turning to other versions that could potentially be compromised.
Anywhere from 25 to 50 applications are being removed from Apple Inc.’s App Store after it was discovered they contained malicious code.
http://www.dispatchtimes.com/apple-security-breach-bigger-than-first-thought/104303/
Sunday, September 27, 2015
Friday, September 25, 2015
Why Passfault
Passfault more accurately measures the strength of passwords. So accurate that it can predict the time required to crack the password. This information helps administrators determine an acceptable password policy. This also helps users intuition around how to create stronger passwords.
Passfault
Passfault
Wednesday, September 23, 2015
U2 concert canceled in Sweden due to security breach
U2 canceled a concert in the Swedish capital of Stockholm after a security breach prompted police to evacuate the Globe Arena.
Stockholm police spokesman Kjell Nildgren said they stopped Sunday’s event because organizers reported a breach at the security check and ticket control points as spectators were entering the arena.
Bidding for Breaches, Redefining Targeted Attacks
"A growing community of private and highly-vetted cybercrime forums is redefining the very meaning of “targeted attacks.” These bid-and-ask forums match crooks who are looking for access to specific data, resources or systems within major corporations with hired muscle who are up to the task or who already have access to those resources".
Bidding for Breaches, Redefining Targeted Attacks
Monday, November 3, 2014
Cybercriminals and attackers are exploiting once again Google Drive infrastructure to avoid detection. The exploitation of Google Drive cloud storage by cyber criminals is not a novelty, a few days ago experts at TrendMicro detected uncovered a sophisticated phishing campaign that was organized to syphon sensitive data from victims.
http://securityaffairs.co/wordpress/29766/cyber-crime/google-drive-phishing-attack.html
http://securityaffairs.co/wordpress/29766/cyber-crime/google-drive-phishing-attack.html
Saturday, October 11, 2014
Amazon EC2 vs Microsoft Azure
There's probably quite a few blogs about Amazon's web services vs Microsoft's Cloud services, however, I believe it's just a matter of preference and of course the price.
During several months of testing and still going, I do like both. While some researches would argue that you have to go through many menus spinning instances in Amazon, Azure's innovative way of creating instances only takes a few steps.
Prices relatively comaprable but really depends on how much resources you need and if you wanted to try both for a spin and just researching as to which cloud service is better, I recommend to take advantage of their free trials.
Currently Azure offers 200$ credit for any of their services while Amazon gives you 750 hrs a month on their free tier services for 12 months.
http://aws.amazon.com/free/
https://azure.microsoft.com/en-us/pricing/free-trial/
During several months of testing and still going, I do like both. While some researches would argue that you have to go through many menus spinning instances in Amazon, Azure's innovative way of creating instances only takes a few steps.
Prices relatively comaprable but really depends on how much resources you need and if you wanted to try both for a spin and just researching as to which cloud service is better, I recommend to take advantage of their free trials.
Currently Azure offers 200$ credit for any of their services while Amazon gives you 750 hrs a month on their free tier services for 12 months.
http://aws.amazon.com/free/
https://azure.microsoft.com/en-us/pricing/free-trial/
Friday, September 12, 2014
Report: 97% Of Mobile Malware Is On Android. This Is The Easy Way You Stay Safe
In 2013 Android grew to a very large number: 87%. This was its share of the global smartphone market. It also grew to an even larger one: 97%. This was Android’s share of global mobile malware.
Unless you’ve had your head under a rock you’ll have noticed the latter is fast becoming the weapon of choice for Google GOOG -0.3%’s rivals in attempting to curtail the former.
On paper it should. Android malware rose from 238 threats in 2012 to 804 new threats in 2013. What was the combined total of new threats for Apple AAPL +0.43% iOS, BlackBerry OS and Microsoft MSFT +0.34% Windows Phone in that time? Zero. The remaining 3% came from Nokia ’s axed Symbian platform. Android does account for 97% of all mobile malware, but it comes from small, unregulated third party app stores predominantly in the Middle East and Asia. By contrast the percentage of apps carrying malware on Google’s official Play Store was found to be just 0.1% and F-Secure acknowledges rigorous checks mean malware encountered there tends to have a short shelf life.
” Strangely F-Secure didn’t reveal figures for Amazon’s Apps for Android store, but other third party Android stores didn’t fare so well. Mumayi, AnZhi, Baidu, eoeMarket and liqucn were found to have 6%, 5%, 8%, 7% and 8% malware penetration respectively and an appalling 33% of apps were infected in Android159. Repacked or faked games were the big target and since it isn’t difficult to taint an app with malware the message is simple: steer clear of third party app stores that don’t have the resources to effectively scan and police their libraries".
More on http://www.forbes.com/sites/gordonkelly/2014/03/24/report-97-of-mobile-malware-is-on-android-this-is-the-easy-way-you-stay-safe/
On paper it should. Android malware rose from 238 threats in 2012 to 804 new threats in 2013. What was the combined total of new threats for Apple AAPL +0.43% iOS, BlackBerry OS and Microsoft MSFT +0.34% Windows Phone in that time? Zero. The remaining 3% came from Nokia ’s axed Symbian platform. Android does account for 97% of all mobile malware, but it comes from small, unregulated third party app stores predominantly in the Middle East and Asia. By contrast the percentage of apps carrying malware on Google’s official Play Store was found to be just 0.1% and F-Secure acknowledges rigorous checks mean malware encountered there tends to have a short shelf life.
” Strangely F-Secure didn’t reveal figures for Amazon’s Apps for Android store, but other third party Android stores didn’t fare so well. Mumayi, AnZhi, Baidu, eoeMarket and liqucn were found to have 6%, 5%, 8%, 7% and 8% malware penetration respectively and an appalling 33% of apps were infected in Android159. Repacked or faked games were the big target and since it isn’t difficult to taint an app with malware the message is simple: steer clear of third party app stores that don’t have the resources to effectively scan and police their libraries".
More on http://www.forbes.com/sites/gordonkelly/2014/03/24/report-97-of-mobile-malware-is-on-android-this-is-the-easy-way-you-stay-safe/
Subscribe to:
Posts (Atom)
-
In 2013 Android grew to a very large number: 87%. This was its share of the global smartphone market. It also grew to an even larger one: 97...
-
OpenSSH is a freely available version of the Secure Shell (SSH) protocol family of tools for remotely controlling a computer or transferring...
-
By Bill Sizemore The Virginian-Pilot © June 4, 2009 State officials are notifying more than a half-million Virginians that their Social Secu...