<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/mobile-security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Mobile-security ]]></title>
                <link>https://www.itpro.com/tag/mobile-security</link>
        <description><![CDATA[ All the latest mobile-security content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 12 Sep 2025 09:11:51 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Mobile app security is a huge blind spot for developer teams – 93% are confident their applications are secure, but 62% reported breaches last year ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/mobile-app-security-is-a-huge-blind-spot-for-developer-teams-93-percent-are-confident-their-applications-are-secure-but-62-percent-reported-breaches-last-year</link>
                                                                            <description>
                            <![CDATA[ Organizations are overconfident about their mobile app security practices, according to new research, and it’s putting enterprises and consumers alike at risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">breJhos62Lw2LAhouQzTHk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MtUfTszvJDvG59aRcikytH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 Sep 2025 09:11:51 +0000</pubDate>                                                                                                                                <updated>Fri, 12 Sep 2025 09:12:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MtUfTszvJDvG59aRcikytH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile app security concept image showing a person&#039;s hand illuminated by a smartphone screen on a dark street.]]></media:description>                                                            <media:text><![CDATA[Mobile app security concept image showing a person&#039;s hand illuminated by a smartphone screen on a dark street.]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile app security concept image showing a person&#039;s hand illuminated by a smartphone screen on a dark street.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MtUfTszvJDvG59aRcikytH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations are overconfident about their mobile app security practices, according to new research, and it’s putting enterprises and consumers alike at risk. </p><p>While 93% of organizations <a href="https://www.guardsquare.com/report/overconfidence-exposes-mobile-app-security-gaps" target="_blank"><u>told researchers</u></a> they were confident in their capabilities, and 97% that they had up-to-date policies outlining mobile app security policies, 62% were breached in the past year, with an average of nine incidents each. </p><p>Just over half (52%) fell victim to a malware attack, 45% suffered data breaches or leaks, and 37% experienced unauthorized access to data. The same number suffered <a href="https://www.itpro.com/security/cyber-attacks/credential-theft-has-surged-160-percent-in-2025">credential theft</a>. </p><div class="product"><a data-dimension112="59d5bd14-ee2e-49ae-93fe-61859c5d87e2" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="59d5bd14-ee2e-49ae-93fe-61859c5d87e2" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="59d5bd14-ee2e-49ae-93fe-61859c5d87e2" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Much of the problem derives from pressure to accelerate release cycles, with 74% saying mobile app teams are increasingly pushed on time-to-market. Similarly, 71% of organizations admit this has compromised mobile app security.</p><p>“The data is clear, and the perceived trade-off between speed and security is a false choice that is costing organizations,” said Roel Caers, CEO of Guardsquare. </p><p>“When developers are under immense pressure to release new features, and security is seen as a roadblock, they are forced to sacrifice protection for time-to-market. This reactive, fire-fighting approach is unsustainable. What’s needed is a proactive, integrated strategy where security is an enabler, not a hindrance.”</p><p>Other security challenges included balancing security with app performance, cited by 47%, ensuring compliance (44%) and providing a seamless user experience (42%).</p><h2 id="mobile-app-security-is-improving">Mobile app security is improving</h2><p>On the positive side, most respondents reported that they were currently using some core mobile app security capabilities such as data encryption (69%), mobile application security testing (63%) and threat monitoring (59%). </p><p>However, the report found low adoption of proactive defenses, with almost 70% of organizations failing to use obfuscation to protect their mobile apps, and 60% lacking Runtime Application Self-Protection (RASP). </p><p>This, the study warned, is leaving their apps vulnerable to both static and dynamic analysis. Nearly four-in-ten said they relied entirely on DIY security solutions or OS-level protections.</p><p>Meanwhile, the impacts of security incidents extend beyond the average reported cost. More than half of respondents (54%) reported application downtime, with 48% experiencing data leakage and 41% suffering a loss of <a href="https://www.itpro.com/data-leakage/26529/data-breaches-have-destroyed-customers-trust-in-companies">consumer trust</a>.</p><p>Worryingly, 85% of survey respondents agreed that a security incident is often the catalyst for a security purchase, with 58% of respondents citing security incidents, 47% partner or client requirements and 30% a failed <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration test</a> or audit.</p><p>Researchers said means far too many organizations are taking action too late.</p><p>“As organizations face pressure to develop feature-rich applications that can be easily used from any device, attackers often target vulnerabilities in mobile applications,” said Melinda Marks, practice director, <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>, for Enterprise Strategy Group. </p><p>“To stay ahead of threats and attacks, security teams need to take a proactive approach to mobile application security with the right tools."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/salesloft-drift-hackers-had-access-to-company-github-account-for-months-before-attacks">Salesloft Drift hackers had access to company GitHub account for months before attacks</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-u-turns-on-cyber-attack-containment-claims-admits-some-data-has-been-affected">Jaguar Land Rover u-turns on cyber attack containment claims</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/fbi-warns-indiscriminate-salt-typhoon-hacking-campaign-has-hit-organizations-in-more-than-80-countries">FBI warns 'indiscriminate' Salt Typhoon hacking campaign has hit organizations in more than 80 countries</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple patches actively exploited iPhone, iPad zero-day and 18 other security flaws ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/zero-day-exploit/369381/apple-patches-actively-exploited-iphone-ipad-zero-day-18-others</link>
                                                                            <description>
                            <![CDATA[ The out-of-bounds write error is the eighth actively exploited zero-day impacting Apple hardware this year and could facilitate kernel-level code execution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a1pSBAhC7jToGQWVcCXoBu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Lf5tVNMLrtzubvq3F5AhRk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Oct 2022 10:33:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Lf5tVNMLrtzubvq3F5AhRk-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple logo on a glass storefront in Ireland]]></media:description>                                                            <media:text><![CDATA[The Apple logo on a glass storefront in Ireland]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple logo on a glass storefront in Ireland]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Lf5tVNMLrtzubvq3F5AhRk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has released an update providing a number of patches for iOS and iPadOS, including one zero-day that “may have been actively exploited".</p><p>Tracked as CVE-2022-42827, the zero-day vulnerability was the result of an out-of-bounds write error in the kernel, which could be used by threat actors to execute malicious code on the kernel level.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="moQ7m7Ygm4UQiwkmvgFG3m" name="moQ7m7Ygm4UQiwkmvgFG3m.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/moQ7m7Ygm4UQiwkmvgFG3m.png" mos="https://cdn.mos.cms.futurecdn.net/moQ7m7Ygm4UQiwkmvgFG3m.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to trust your inbox with Cloudflare Area 1</strong></p><p class="fancy-box__body-text">Why your current email security may not be enough</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369345/how-to-trust-your-inbox-with-cloudflare-area-1" data-original-url="/security/369345/how-to-trust-your-inbox-with-cloudflare-area-1">FREE DOWNLOAD</a></p></div></div><p>This could allow for custom, potentially malicious programs to be run on the victim’s device, as well as putting all data on it at serious risk of exfiltration or destruction.</p><p>An out-of-bounds write error occurs when a program writes beyond the end of an intended buffer or specified array, and typically results in a crash or corruption of data. If exploited, they can be used to modify system data and execute code on impacted devices remotely.</p><p>In its <a href="https://support.apple.com/en-gb/HT201222">post</a> for the iOS 16.1 and iPadOS 16 security updates, Apple noted that through the flaw an “application may be able to execute arbitrary code with kernel privileges".</p><p>Beyond this, the firm offered little detail of the precise nature of the <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-day</a>, in line with its policies on security issues and in accordance with its longstanding approach of providing little detail on security incidents.</p><p>“For the protection of our customers, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are generally available,” stated a notice in the update post.</p><p>Affected devices include all of its smartphones from iPhone 8 and above, all models of the <a href="https://www.itpro.com/hardware/tablets/361463/apple-ipad-pro-129in-2021-review-a-giant-leap-for-apple-silicon" data-original-url="https://www.itpro.com/hardware/tablets/361463/apple-ipad-pro-129in-2021-review-a-giant-leap-for-apple-silicon">iPad Pro</a>, iPad Air 3rd generation and above, and iPad and iPad Mini - both 5th generation and above.</p><p>Beyond the zero-day, the latest security update also provides patches for 18 other vulnerabilities. Of these, two more were in the kernel, though these are not thought to be actively exploited, while three were in WebKit, Apple’s browser engine which powers Safari.</p><p>Other flaws were fixed in the point-to-point protocol (PPP), a <a href="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip" data-original-url="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip">TCP/IP</a> protocol used to send data between devices, as well as in core Bluetooth and the GPU drivers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369044/the-iphone-security-features-that-come-with-ios-16" data-original-url="/security/369044/the-iphone-security-features-that-come-with-ios-16">A breakdown of iOS 16's security features</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/368841/apple-patches-superpower-zero-days-affecting-iphones-ipads-and-macs" data-original-url="/security/zero-day-exploit/368841/apple-patches-superpower-zero-days-affecting-iphones-ipads-and-macs">Apple patches 'superpower' zero-days affecting iPhones, iPads, and Macs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday" data-original-url="/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday">Microsoft still searching for zero-day fixes following Patch Tuesday</a></p></div></div><p>The patch marks the ninth overall update addressing a zero-day flaw by Apple this year. In September, the tech giant <a href="https://www.itpro.com/security/zero-day-exploit/369052/apple-patches-yet-another-zero-day-flaw-in-substantial-security-update" data-original-url="https://www.itpro.com/security/zero-day-exploit/369052/apple-patches-yet-another-zero-day-flaw-in-substantial-security-update">patched a similar kernel vulnerability</a>, which allowed for arbitrary code to be executed with kernel privileges. This vulnerability also affected macOS Monterey, and had been potentially exploited in the wild by the time it was patched.</p><p>In August, Apple patched a <a href="https://www.itpro.com/security/zero-day-exploit/368841/apple-patches-superpower-zero-days-affecting-iphones-ipads-and-macs" data-original-url="https://www.itpro.com/security/zero-day-exploit/368841/apple-patches-superpower-zero-days-affecting-iphones-ipads-and-macs">'superpower' zero-day affecting WebKit</a>, in which threat actors could use remote code execution (RCE) to alter web pages, which would then run malicious code on Apple devices that visited them.</p><p>More recently, earlier this month Apple was forced to release a fix for a denial of service vulnerability, tracked as CVE-2022-22658, affecting iPhones 8 and newer.</p><p>Apple said that processing a maliciously crafted message could lead to denial of service and was fixed in its iOS 16.0.3 by improving input validation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Qualcomm and Mediatek flaws left millions of Android users at risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/367471/qualcomm-mediatek-flaws-left-android-users-at-risk</link>
                                                                            <description>
                            <![CDATA[ An open source audio codec used by chipset firms is believed to have put two-thirds of Android users' private calls and files at risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g1sfBMafuEKQLASjZwUqTR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VsxYNVYT4EJ4rvai4sLxdD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Apr 2022 11:19:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VsxYNVYT4EJ4rvai4sLxdD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The corner of a CPU chip seen on a circuit board]]></media:description>                                                            <media:text><![CDATA[The corner of a CPU chip seen on a circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[The corner of a CPU chip seen on a circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VsxYNVYT4EJ4rvai4sLxdD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Qualcomm and MediaTek, two of the biggest chipmakers in the world, have been found to have used vulnerable technology in smartphones that could have led to privacy violations of Android users.</p><p>Check Point Research (CPR) discovered a number of vulnerabilities in the Apple Lossless Audio Codec (ALAC), a component responsible for compressing audio data, that could have led to users’ calls and stored images being accessed by cyber attackers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/367356/google-to-cull-out-of-date-play-store-apps-android-security" data-original-url="/mobile/google-android/367356/google-to-cull-out-of-date-play-store-apps-android-security">Google will cull out-of-date Play store apps in bid to improve Android security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/362224/first-look-at-android-13-developer-preview" data-original-url="/mobile/google-android/362224/first-look-at-android-13-developer-preview">Developer preview offers first look at Android 13</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/362216/google-patches-critical-android-12-security-flaws" data-original-url="/mobile/google-android/362216/google-patches-critical-android-12-security-flaws">Google patches critical Android 12 security flaws</a></p></div></div><p>The researchers believe that more than two-thirds of the world’s Android smartphones were vulnerable to the attacks at some point.</p><p>The vulnerabilities were found in the ALAC code which Apple made <a href="https://www.itpro.com/software/28109/what-is-open-source" target="_blank" data-original-url="https://www.itpro.com/software/28109/what-is-open-source">open source</a> in 2011; the ALAC has since been installed in a wide variety of non-Apple audio playback devices and programmes - not just Android smartphones, CPR said.</p><p>Apple has since updated the code since it went open source, but the code in question had not been updated since 2011 and both Qualcomm and MediaTek ported the vulnerable ALAC code into their audio decoders.</p><p>Attackers could have used the vulnerabilities to conduct a remote code execution (RCE) attack on smartphones by sending victims a malformed audio file, the researchers said, but will not unveil full details of how the vulnerabilities can be exploited until they are presented at the CanSecWest conference in May.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="P4x3aTyhBQEcKQEtDASEAC" name="P4x3aTyhBQEcKQEtDASEAC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/P4x3aTyhBQEcKQEtDASEAC.png" mos="https://cdn.mos.cms.futurecdn.net/P4x3aTyhBQEcKQEtDASEAC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Microsoft 365 protection made MSPEasy</strong></p><p class="fancy-box__body-text">The cloud protection solution built for MSPs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367295/microsoft-365-protection-made-mspeasy" data-original-url="/security/367295/microsoft-365-protection-made-mspeasy">FREE DOWNLOAD</a></p></div></div><p>“We've discovered a set of vulnerabilities that could be used for remote execution and privilege escalation on two-thirds of the world's mobile devices,” said Slava Makkaveev, reverse engineering and security research, at CPR. “The vulnerabilities were easily exploitable. A threat actor could have sent a song (media file) and when played by a potential victim, it could have injected code in the privileged media service.</p><p>“The threat actor could have seen what the mobile phone user sees on their phone. In our proof of concept, we were able to steal the phone's camera stream. What is the most sensitive information on your phone? I think it's your media: audio and videos. An attacker could have stolen that through these vulnerabilities. The vulnerable decoder is based on the code shared by Apple 11 years ago.”</p><p>MediaTek tracks both vulnerabilities as <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-0674">CVE-2021-0674</a> and <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-0675">CVE-2021-0675</a>, scoring 5.5 and 7.8 out of ten on the CVSSv3 threat severity scale, and were patched by the company in December 2021.</p><p>Qualcomm tracks the security vulnerability as <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30351">CVE-2021-30351</a>, scoring 9.8, a critical rating, and affected a score of Snapdragon products. Qualcomm patched the issue in December 2021 and CPR waited until this week to publish details to allow users time to <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">patch</a>.</p><p>CPR recommends all Android users regularly patch their phones to the latest version that Google issues on a monthly basis.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google will cull out-of-date Play store apps in bid to improve Android security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/google-android/367356/google-to-cull-out-of-date-play-store-apps-android-security</link>
                                                                            <description>
                            <![CDATA[ The rules will take effect later this year and could see unsupported apps de-listed from the store ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dCZJp3b67y7atTgTG37y3C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w2ddpkm6WRpmL8ke9CByX6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Apr 2022 11:21:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Android]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Google]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w2ddpkm6WRpmL8ke9CByX6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android phone being held aloft in front of a white background with the Android logo appearing on it]]></media:description>                                                            <media:text><![CDATA[Android phone being held aloft in front of a white background with the Android logo appearing on it]]></media:text>
                                <media:title type="plain"><![CDATA[Android phone being held aloft in front of a white background with the Android logo appearing on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w2ddpkm6WRpmL8ke9CByX6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Android has announced a new Play store security policy that will force developers to update older apps to avoid their software being removed.</p><p>With each version of Android, new and more stringent security policies are introduced to improve the security of the Android ecosystem. Following this approach, Android will now require all apps to target an API level that’s within two years of the most recent version.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/362288/google-brings-privacy-sandbox-initiative-to-android" data-original-url="/mobile/google-android/362288/google-brings-privacy-sandbox-initiative-to-android">Google brings Privacy Sandbox initiative to Android</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/362224/first-look-at-android-13-developer-preview" data-original-url="/mobile/google-android/362224/first-look-at-android-13-developer-preview">Developer preview offers first look at Android 13</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/mobile-security/366298/businesses-on-alert-as-mobile-malware-surges-500-in-february" data-original-url="/mobile/mobile-security/366298/businesses-on-alert-as-mobile-malware-surges-500-in-february">Businesses on alert as mobile malware surges 500%</a></p></div></div><p>An <a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know" data-original-url="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">API</a> level is essentially tied to a version of <a href="https://www.itpro.com/android/28189/how-to-build-android-apps" data-original-url="https://www.itpro.com/android/28189/how-to-build-android-apps">Android</a>, meaning the most recent version of the operating system, Android 12, is the most up-to-date API level.</p><p>An existing policy states that any new app being added to the Play store, or an existing app that is being updated, needs to target an API level that’s within one year of the current version. The latest policy is an expansion of this, targeting older apps that have not been updated in some time.</p><p>This means that any older app will need to be updated to target an API level within two years of Android 12 in order to remain discoverable on the Google Play store, and to be able to be installed by users.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="a5rCoU4DNBAZp26Ehxvuvm" name="" alt="Timeline of the target API level window" src="https://cdn.mos.cms.futurecdn.net/a5rCoU4DNBAZp26Ehxvuvm.jpg" mos="https://cdn.mos.cms.futurecdn.net/a5rCoU4DNBAZp26Ehxvuvm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Android)</span></figcaption></figure><p>The new requirements will take effect on 1 November 2022 and as new Android versions are released the requirement window will adjust accordingly, Android said.</p><p>“The rationale behind this is simple. Users with the latest devices or those who are fully caught up on Android updates expect to realise the full potential of all the privacy and security protections Android has to offer,” said Krish Vitaldevara, director of product management at Android, in <a href="https://android-developers.googleblog.com/2022/04/expanding-plays-target-level-api-requirements-to-strengthen-user-security.html?m=1">a blog post</a>.</p><p>“Expanding our target level API requirements will protect users from installing older apps that may not have these protections in place.”</p><p>The discovery of <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">malware</a> affecting Android devices is a relatively common occurrence in the cyber security industry, and the new security policy will aim to make this more of a rarity.</p><p>In the space of a week, numerous reports of new Android malware strains have hit various media outlets, including a Russian-linked Android malware called Process Manager. <a href="https://lab52.io/blog/complete-dissection-of-an-apk-with-a-suspicious-c2-server">Discovered by Lab52</a>, the malware is capable of sending and reading SMS messages, plus recording a device’s audio.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/LuqAVA1jiPI" allowfullscreen></iframe></div></div><p>At the end of 2021, <em>IT Pro</em> reported that more than 300,000 Android users had <a href="https://www.itpro.com/security/hacking/361693/android-banking-trojan-infects-300000-devices" data-original-url="https://www.itpro.com/security/hacking/361693/android-banking-trojan-infects-300000-devices">downloaded a banking trojan from the Google Play store</a>, with hackers managing to bypass the app store’s security detections.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zN9yq6wvv8oBhbPFBWeEAd" name="zN9yq6wvv8oBhbPFBWeEAd.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd.jpg" mos="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Unified endpoint management solutions 2021-22</strong></p><p class="fancy-box__body-text">Analysing the UEM landscape</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/367050/unified-endpoint-management-solutions-2021-22" data-original-url="/security/endpoint-security/367050/unified-endpoint-management-solutions-2021-22">FREE DOWNLOAD</a></p></div></div><p>Without giving specifics, Android said the “vast majority” of apps in the Google Play store are already compliant with the rules soon to be introduced.</p><p>Developers who are concerned about implementing the upcoming changes can consult <a href="https://developer.android.com/google/play/requirements/target-sdk">Google’s technical guide</a>, which details the steps that need to be taken for a successful migration.</p><p>A six-month optional extension can also be requested if developers can demonstrate they need more time in order to complete the migration to the target API level. The application form for this will be available in the Developer Play Console later this year, Android said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Businesses on alert as mobile malware surges 500% ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/366298/businesses-on-alert-as-mobile-malware-surges-500-in-february</link>
                                                                            <description>
                            <![CDATA[ Researchers say hackers are deploying new tactics that put Android and iOS at equal risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3ai3WhJ8ZX6P4Z5oNQdXoZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/e8YNzz5jgFMPhzPmLHRFGA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Mar 2022 11:40:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/e8YNzz5jgFMPhzPmLHRFGA-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware on an Android smartphone]]></media:description>                                                            <media:text><![CDATA[Malware on an Android smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[Malware on an Android smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/e8YNzz5jgFMPhzPmLHRFGA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have said they observed a 500% increase in mobile malware infections across Europe since the start of February 2022.</p><p>The majority of malware was observed on Android devices, with six of the most serious strains targeting Google's operating system compared to just one targeting iOS, according to Proofpoint researchers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/361625/what-is-smishing" data-original-url="/security/phishing/361625/what-is-smishing">What is smishing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">Five giveaways that show an email is a phishing attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/361523/europol-report-ddos-ransomware-gangs-evade-capture" data-original-url="/security/cyber-crime/361523/europol-report-ddos-ransomware-gangs-evade-capture">Europol reveals how ransomware gangs are evolving to evade capture</a></p></div></div><p>Following an uptick in mobile malware infections back in April 2021, researchers told <em>IT Pro</em> that detections had largely tapered off and remained low until February 2022, although they were unable to pinpoint a reason for the sudden surge.</p><p>Proofpoint said most mobile <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> is still downloaded via app stores and is especially prevalent on Android devices given the platform’s openness to multiple different app stores.</p><p>Side-loading – the practice of allowing apps to be installed via third-party app stores or directly onto the device – is also prohibited on iOS, helping to limit the spread of infections.</p><p>However, Proofpoint said it has noticed a distinct rise in attacks using mobile messaging, including SMS-based phishing attacks known as <a href="https://www.itpro.com/security/phishing/361625/what-is-smishing" data-original-url="https://www.itpro.com/security/phishing/361625/what-is-smishing">smishing</a>. Given Android’s support for side-loading, it means this technique is <a href="https://www.itpro.com/security/malware/359133/new-android-malware-discovered-that-spreads-through-whatsapp-messages" data-original-url="https://www.itpro.com/security/malware/359133/new-android-malware-discovered-that-spreads-through-whatsapp-messages">more effective on that platform</a> compared to iOS.</p><p>The finding is especially important for businesses that distribute Android-based company devices to their workforce. Many businesses install security measures that prevent access to third-party app stores but smishing may bypass some of these provisions.</p><p>“Mobile messaging is a highly trusted communication channel and users are much more apt to read and access links/URLs contained in mobile messages than those in email,” said Jacinta Tobin, vice president of Cloudmark operations at Proofpoint to <em>IT Pro</em>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gSCksczWaVZioTtDeALM4D" name="gSCksczWaVZioTtDeALM4D.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gSCksczWaVZioTtDeALM4D.png" mos="https://cdn.mos.cms.futurecdn.net/gSCksczWaVZioTtDeALM4D.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Introducing the zero trust edge model for security and network services</strong></p><p class="fancy-box__body-text">Get a better understanding of emerging zero trust solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/365567/introducing-the-zero-trust-edge-model-for-security-and-network-services" data-original-url="/security/365567/introducing-the-zero-trust-edge-model-for-security-and-network-services">FREE DOWNLOAD</a></p></div></div><p>“This level of trust combined with the reach of mobile devices in the general public, where nine in ten possess a mobile device, makes mobile messaging a very attractive platform for commercial and marketing activity. This makes the mobile channel ripe for fraud and identity theft both now and in the future through this expansion.”</p><p>The most common types of malware found were those that used malicious apps to record phone calls, or those that take audio from the device outside of phone calls.</p><p>Data wipers, which have been <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">especially common in the recent cyber attacks on Ukraine emanating from Russia</a>, were also increasing in popularity.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/-h_a9Ld9awE" allowfullscreen></iframe></div></div><p>This differs from the traditional purpose of malware, Proofpoint said, which typically involves gaining access to a system and potentially stealing data or account credentials.</p><p>Of the most common malware types, all had a financial impersonation component and all had a credential-stealing function.</p><p>For example, the long-feared <a href="https://www.itpro.com/security/cyber-crime/361523/europol-report-ddos-ransomware-gangs-evade-capture" data-original-url="https://www.itpro.com/security/cyber-crime/361523/europol-report-ddos-ransomware-gangs-evade-capture">FluBot malware</a>, which installs an invisible overlay on mobiles to steal login credentials, activated when banking apps are used, was found to be one of the most common types of malware affecting Android users in Europe.</p><p>TangleBot was first observed in North America but has recently been found in Turkey. It typically spreads via fraudulent package-delivery notifications and may have links to the FluBot campaign. Notably, it is one of the few malware strains that combine financial impersonation with the newer audio-recording thefts.</p><p>“In both cases, the malware uses similar distribution methodologies, landing pages, language and SMS lures,” Proofpoint said. “One enticing lure that TangleBot has been known to use is a software update notification.”</p><p>Proofpoint said “awareness is critical” when keeping safe online, and more needs to be known about the dangers of mobile malware.</p><p>Users have been advised to be <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">extra vigilant when it comes to reviewing emails and texts</a>, especially for Android users, and consider installing a mobile antivirus app from a trusted source.</p><p>“Consumers need to be very sceptical of mobile messages that come from unknown sources,” said Tobin. “And it’s important to never click on links in text messages, no matter how realistic they look.</p><p>“If you want to contact the purported vendor sending you a link, do so directly through their website and always manually enter the web address/URL. For offer codes, type them directly into the site as well. It’s also vital that you don’t respond to strange texts or texts from unknown sources. Doing so will often confirm you’re a real person to future scammers.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple fixes array of iOS, macOS zero-days and code execution security flaws ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/zero-day-exploit/362074/apple-fixes-array-of-ios-macos-zero-days-and-code-execution</link>
                                                                            <description>
                            <![CDATA[ The first wave of security updates for Apple products in 2022 follows a year in which a wide variety of security flaws plagued its portfolio of devices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sopmnKNn2iic91jKWusdM8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kdWQYRnebCeRMuWc86udma-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Jan 2022 12:06:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kdWQYRnebCeRMuWc86udma-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Apple logo on the side of a building]]></media:description>                                                            <media:text><![CDATA[Apple logo on the side of a building]]></media:text>
                                <media:title type="plain"><![CDATA[Apple logo on the side of a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kdWQYRnebCeRMuWc86udma-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has patched an array of security issues affecting iOS, iPadOS, and macOS devices, including two <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-day vulnerabilities</a>.</p><p>Among the other myriad fixes for <a href="https://support.apple.com/en-us/HT213053">iOS and iPadOS 15.3</a>, and <a href="https://support.apple.com/en-us/HT213054">macOS Monterrey 12.2</a> released on Wednesday were code execution flaws and some that allowed arbitrary code to run on affected devices with kernel privileges.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">What's behind the explosion in zero-day exploits?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/361588/apple-self-repair-programme-iphones-macs" data-original-url="/business/business-strategy/361588/apple-self-repair-programme-iphones-macs">Apple launches self-repair scheme for iPhones and Macs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/business-management/361508/apple-unveils-business-essentials-for-smbs" data-original-url="/business-operations/business-management/361508/apple-unveils-business-essentials-for-smbs">Apple unveils Business Essentials suite for small businesses</a></p></div></div><p>The first of the two critical flaws, tracked as CVE-2022-22587, involves an issue with the IOMobileFrameBuffer, a kernel extension responsible for managing a device's framebuffer - a portion of RAM that drives the video display. It's believed to have affected the iPhone 6s and later, all iPad Pro models, iPad Air 2 and later, and other devices in the ecosystem too.</p><p>Apple said a malicious application could exploit a flaw in this extension to execute arbitrary code with kernel privileges. Apple also said it previously knew about the security issue and that it believes it may have already been actively exploited in the wild. It was a memory corruption issue Apple fixed with improved input validation.</p><p>The bug was discovered by Meysam Firouzi of MBition - Mercedes-Benz Innovation Lab, and independent researcher Siddharth Aeri. A third, anonymous researchers was also thought to be involved.</p><p>Aeri <a href="https://github.com/b1n4r1b01/n-days/commit/9d88ad30f4b1b674e951791809642d52383b1fb0">published a proof-of-concept</a> (PoC) for the security issue on 31 December 2021 and <a href="https://twitter.com/b1n4r1b01/status/1476949442389417984">noted</a> on their Twitter page that the bug was demonstrated by Pangu Team at Tianfucup 2021, a hacking competition similar to <a href="https://www.itpro.com/security/hacking/361455/experts-break-into-samsung-galaxy-s21-twice-at-pwn2own-hacking-event" data-original-url="https://www.itpro.com/security/hacking/361455/experts-break-into-samsung-galaxy-s21-twice-at-pwn2own-hacking-event">Zero Day Initiative's Pwn2Own</a>.</p><p>The second zero-day flaw was found in Apple's WebKit browser engine and affects Safari 15 on macOS, and all browsers on iOS and iPadOS 15, <a href="https://www.itpro.com/network-internet/web-browser/361995/safari-bug-lets-websites-track-browsing-activity-and-unique" data-original-url="https://www.itpro.com/network-internet/web-browser/361995/safari-bug-lets-websites-track-browsing-activity-and-unique">as <em>IT Pro</em> previously reported</a>.</p><p>Martin Bajanik of FingerprintJS first discovered the bug on 28 November 2021 and made it publicly available on 14 January, before Apple assigned it CVE-2022-22594 and patched it in Wednesday's slew of updates.</p><p>Exploiting the bug would see websites able to track sensitive user information and stemmed from a cross-origin issue in the IndexDB API. Apple fixed it using the same method as the first zero-day, by improving the input validation.</p><p>When he made the public disclosure earlier this month, Bajanik labelled the flaw a privacy violation. "It lets arbitrary websites learn what websites the user visits in different tabs or windows," said Bajanik who authored FingerprintJS' <a href="https://fingerprintjs.com/blog/indexeddb-api-browser-vulnerability-safari-15">analysis</a> of the bug. "This is possible because database names are typically unique and website-specific."</p><p>A total of five arbitrary code execution issues were found to affect iOS 15.3 and iPadOS 15.3, and seven affected macOS Monterrey 12.2. Four of the vulnerabilities in macOS also affected iPhones and iPads, meaning there was a single vulnerability exclusive to iOS 15.3 and iPadOS 15.3, three exclusive to macOS, and four shared across the operating systems of Apple's popular iPhones, iPads, and Mac computers.</p><h3 class="article-body__section" id="section-apple-39-s-zero-day-ridden-2021"><span>Apple's zero-day-ridden 2021</span></h3><p>The latest wave of patches marks Apple's first release of fixes this year and the company was forced to patch a score of zero-day and other critical vulnerabilities throughout 2021, including the <a href="https://www.itpro.com/security/exploits/360870/apple-patches-nso-forcedentry-zero-day-flaw" data-original-url="https://www.itpro.com/security/exploits/360870/apple-patches-nso-forcedentry-zero-day-flaw">infamous ForcedEntry exploit</a> used to enable <a href="https://www.itpro.com/security/spyware/361971/el-salvador-becomes-latest-country-targeted-by-pegasus" data-original-url="https://www.itpro.com/security/spyware/361971/el-salvador-becomes-latest-country-targeted-by-pegasus">NSO Group's Pegasus spyware</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oxZ77o4or4eWr8kndJnTjW" name="oxZ77o4or4eWr8kndJnTjW.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/oxZ77o4or4eWr8kndJnTjW.png" mos="https://cdn.mos.cms.futurecdn.net/oxZ77o4or4eWr8kndJnTjW.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Establishing a strong foundation for DataOps</strong></p><p class="fancy-box__body-text">How to gain a competitive advantage with your available data</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-management/361920/establishing-a-strong-foundation-for-dataops" data-original-url="/data-insights/data-management/361920/establishing-a-strong-foundation-for-dataops">FREE DOWNLOAD</a></p></div></div><p>Arbitrary code execution zero-days in WebKit were also found <a href="https://www.itpro.com/security/zero-day-exploit/359407/apple-patches-ios-macos-webkit-flaws" data-original-url="https://www.itpro.com/security/zero-day-exploit/359407/apple-patches-ios-macos-webkit-flaws">in May 2021</a> affecting Safari, all third-party iOS browsers, Apple Mail, and the App Store too. An additional emergency patch was also released a month later to fix <a href="https://www.itpro.com/security/zero-day-exploit/359876/apple-patches-ios-12-after-hackers-exploit-webkit-engine-flaws" data-original-url="https://www.itpro.com/security/zero-day-exploit/359876/apple-patches-ios-12-after-hackers-exploit-webkit-engine-flaws">more WebKit flaws in iOS 12</a> which could lead to remote code execution attacks.</p><p>May 2021 was a particularly troubled period for the company, the products from which were once said to not even need antivirus protection. Another significant number of vulnerabilities were fixed at the end of May across iOS, macOS, tvOS, watchOS and Safari, including a macOS Big Sur zero-day vulnerability <a href="https://www.itpro.com/security/malware/359655/apple-fixes-three-macos-flaws-under-attack" data-original-url="https://www.itpro.com/security/malware/359655/apple-fixes-three-macos-flaws-under-attack">under active attack at the time</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android bug prevents users from calling emergency services ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/google-android/361801/android-bug-prevents-users-calling-911</link>
                                                                            <description>
                            <![CDATA[ Google has confirmed that the glitch is affecting devices that have Microsoft Teams installed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eWsvJbXP2aTKi9uz7ky13A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/REDJzcaWa5a59khtgPAJML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Dec 2021 11:09:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Phones]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/REDJzcaWa5a59khtgPAJML-1280-80.jpg">
                                                            <media:credit><![CDATA[IT Pro]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand holding a Google Pixel 3 aloft with the home screen showing]]></media:description>                                                            <media:text><![CDATA[A hand holding a Google Pixel 3 aloft with the home screen showing]]></media:text>
                                <media:title type="plain"><![CDATA[A hand holding a Google Pixel 3 aloft with the home screen showing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/REDJzcaWa5a59khtgPAJML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has confirmed an issue affecting some users running Android 10 and above whereby a user's phone would not allow them to dial the emergency services.</p><p>The small but significant bug affects some devices that have <a href="https://www.itpro.com/marketing-comms/business-communications/361720/microsoft-teams-essentials-tier-for-small-businesses" data-original-url="https://www.itpro.com/marketing-comms/business-communications/361720/microsoft-teams-essentials-tier-for-small-businesses">Microsoft Teams</a> app installed, but without being logged in to the collaboration platform, Google said on Wednesday evening in response to <a href="https://www.reddit.com/r/GooglePixel/comments/r4xz1f/pixel_prevented_me_from_calling_911/hnrvsr1" target="_blank">a Reddit thread</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/361318/you-can-now-test-android-apps-windows11" data-original-url="/operating-systems/microsoft-windows/361318/you-can-now-test-android-apps-windows11">You can now test Android apps on Windows 11</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/359836/latest-android-12-beta-puts-privacy-front-and-centre" data-original-url="/mobile/google-android/359836/latest-android-12-beta-puts-privacy-front-and-centre">Latest Android 12 beta puts privacy front and centre</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/business-communications/361720/microsoft-teams-essentials-tier-for-small-businesses" data-original-url="/marketing-comms/business-communications/361720/microsoft-teams-essentials-tier-for-small-businesses">Microsoft Teams introduces 'Essentials' tier for small businesses</a></p></div></div><p>Google said it and Microsoft took the issue seriously and added that the pair "are heavily prioritising the issue". However, the company was somewhat vague when alluding to the time it will take to fix the flaw. </p><p>In the Reddit reply, Google said that a Microsoft Teams app update will be rolled out "soon". It also suggested Android users should always run the <a href="https://www.itpro.com/mobile/google-android/359836/latest-android-12-beta-puts-privacy-front-and-centre" data-original-url="https://www.itpro.com/mobile/google-android/359836/latest-android-12-beta-puts-privacy-front-and-centre">latest version</a> of the mobile operating system and lookout for the next planned platform update due on 4 January 2022.</p><p><em>IT Pro</em> contacted Google for clarity on whether it impacts users in the UK but it declined to comment further.</p><p>Google <a href="https://www.reddit.com/r/GooglePixel/comments/r4xz1f/pixel_prevented_me_from_calling_911/hnrvsr1">said</a> the issue was caused by an "unintended interaction between the Microsoft Teams app and the underlying Android operating system", and that only one user report of the issue was confirmed - the user who made the initial Reddit thread on the Google Pixel subreddit.</p><p>On temporary fixes, Google suggested users check if they're running Android 10 or above, sign into Teams if they aren't already and remain signed in, reinstall Teams, and update the Teams app as soon as the update is available.</p><p>The user who originally raised the issue said they were trying to call an ambulance for their grandmother who appeared to be having a stroke at the time but was unable to and that dialling 911 simply rang once before their phone become "stuck".</p><p>"I was unable to do anything other than click through apps with an emergency phone call running in the background," said the user in the original <a href="https://www.reddit.com/r/GooglePixel/comments/r4xz1f/pixel_prevented_me_from_calling_911">report</a>. "This is all while the phone informed me that it had sent my location to emergency services. Sadly I couldn't tell the person on the other end what apartment I was in, or what the actual emergency was as I was unable to speak to a human."</p><p>Fortunately, the grandmother hand a landline phone and was able to call from that but with so many households <a href="https://www.itpro.com/marketing-comms/business-communications/360574/the-great-telephone-switch-off" data-original-url="https://www.itpro.com/marketing-comms/business-communications/360574/the-great-telephone-switch-off">opting out of landlines</a> in favour of mobile-only connectivity, it presents a very serious issue of personal safety.</p><p>The user said they were using a <a href="https://www.itpro.com/google-android/32081/google-pixel-3-review-brains-over-brawn" data-original-url="https://www.itpro.com/google-android/32081/google-pixel-3-review-brains-over-brawn">Google Pixel 3</a> running Android 11 and on the Verizon network and have filed an official complaint with the Federal Communications Commission (FCC).</p><p>Visitors to the post were shocked to read about the situation and offered an outpouring of support, labelling it a "horrifying situation".</p><p>Others suggested that Google should offer the user a prize akin to one that might be given to a security researcher since the report and resulting cooperation in reporting the bug to Google was much like the process traditionally followed by a security expert submitting for a <a href="https://www.itpro.com/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform" data-original-url="https://www.itpro.com/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform">bug bounty reward</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trend Micro Worry-Free Business Security review: Great cloud-managed malware protection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/361734/trend-micro-worry-free-business-security-great-cloud-managed</link>
                                                                            <description>
                            <![CDATA[ A reassuringly simple endpoint-protection solution – although mobile support is basic ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k1tRcJYbijSuasEWqYbZ46</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jfb3vkYKJRZyagdkUZPrEf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Dec 2021 10:35:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jfb3vkYKJRZyagdkUZPrEf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trend Micro Worry-Free Business Security screenshot]]></media:description>                                                            <media:text><![CDATA[Trend Micro Worry-Free Business Security screenshot]]></media:text>
                                <media:title type="plain"><![CDATA[Trend Micro Worry-Free Business Security screenshot]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jfb3vkYKJRZyagdkUZPrEf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Trend Micro offers an <a href="https://www.itpro.com/security/endpoint-security/357421/why-endpoint-security-should-be-your-first-line-of-defence" data-original-url="https://www.itpro.com/security/endpoint-security/357421/why-endpoint-security-should-be-your-first-line-of-defence">endpoint protection</a> choice for every business: firms that want to keep it all in house can install Worry-Free Business Security Standard on their own server, while those that prefer a hosted solution can use this fully cloud-based option.</p><p>It’s aimed at companies with up to 250 devices to protect, and the price is SMB-friendly. Yearly pricing starts at £58 for two devices, rising to £520 for 25, with each licence covering one Windows or Mac workstation, one Windows server or one mobile device.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation" data-original-url="/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them" data-original-url="/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them">Kaspersky Endpoint Security Cloud Plus review: One security solution to rule them all</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented" data-original-url="/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented">F-Secure Elements Endpoint Protection review: A strong business-oriented security solution</a></p></div></div><p>All the key security features are present. Along with anti-malware scanning you get protection against web threats, <a href="https://www.itpro.com/security/cyber-security/361012/what-is-a-web-filter" data-original-url="https://www.itpro.com/security/cyber-security/361012/what-is-a-web-filter">web content filtering</a>, a client firewall, removable device controls and mobile device security. A standout feature of both the standard and cloud-hosted versions is an advanced <a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" data-original-url="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">data-loss prevention module</a>, which comes preconfigured to recognise (and optionally block) 244 different types of sensitive data, including British financial and healthcare information.</p><p><a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">Ransomware</a> is very much on Trend Micro’s radar, too. The software subjects suspicious processes to a range of tests including predictive machine learning, behaviour monitoring and new program detection – and if the malware isn’t immediately stopped, the program can also directly detect malicious encryption attempts and undo any suspicious changes made by untrusted programs.</p><p>As the name implies, another focus of the Worry-Free suite is keeping deployment and administration simple. The cloud portal is easy to use, with a dashboard that keeps you posted on all client activity, detected security risks and policy violations. Clicking on any of the threat categories takes you straight to the portal’s log page, where you can quickly identify the threat type and which clients are affected.</p><p>The one place you might hit a hiccup is with initial client setup, as the email invitation process requires a standalone mail client running on your local system. This isn’t a huge obstacle, though: after logging on from a computer with Outlook installed, we were easily able to email invitations to our Windows 10 users. The messages pointed them to a tiny 7MB executable, and after launching the installer, they had the agent running and connected to the portal in less than five minutes, with settings applied from the portal’s default groups for instant protection.</p><p>Agents can then be manually moved into specific groups in the portal, each with custom policies. These define real-time and manual scan behaviour, apply <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">predictive machine learning</a> and use one of three web reputation levels to classify and block suspect web pages. Optional global settings can be applied for malware scanning, approved and blocked websites (which override URL-filtering policies) and password protection to stop users disabling the agent.</p><p>Data-loss prevention can be set up here too. We created a policy to block all sensitive data, then tried to use Gmail on a client PC to send an email containing a credit card number. The attempt was instantly blocked and logged, leaving Gmail complaining about a lack of network access.</p><p>Mobile protection is a mixed bag. Android devices get malware scanning, plus access to the web reputation service and password controls; if you’re using a <a href="https://www.itpro.com/hardware/laptops/355133/chromebooks-are-the-benjamin-button-of-tech" data-original-url="https://www.itpro.com/hardware/laptops/355133/chromebooks-are-the-benjamin-button-of-tech">Chromebook</a>, you get web threat prevention too. As usual, however, iOS options are far more limited. All you can do is enforce complex unlock passcodes, set expiration limits and apply device lock timeouts.</p><p>Even so, Trend Micro’s Worry-Free Business Security Services provides great desktop security, plus exceptional DLP and ransomware protection. For small numbers of users it’s good value, and SMBs will find the cloud portal very easy to work with.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 300,000 Android users downloaded banking trojan malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/361693/android-banking-trojan-infects-300000-devices</link>
                                                                            <description>
                            <![CDATA[ Hackers defeated Google Play restrictions by using smaller droppers in apps and eliminating permissions needed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pVpsPr3bSPB5n7TDBiysEG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aQBxg93uKFvFETex9DPMQf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Nov 2021 12:23:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aQBxg93uKFvFETex9DPMQf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trojan virus within binary code]]></media:description>                                                            <media:text><![CDATA[Trojan virus within binary code]]></media:text>
                                <media:title type="plain"><![CDATA[Trojan virus within binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aQBxg93uKFvFETex9DPMQf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have managed to bypass Google Play app restrictions to chalk up over 300,000 banking trojan infections in just four months.</p><p>According to a <a href="https://www.threatfabric.com/blogs/deceive-the-heavens-to-cross-the-sea.html">blog post</a> by <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> researchers at Threat Fabric, hackers have avoided being detected by Google Play by using smaller droppers in apps, reducing the number of permissions being asked of users and improving code as well as creating more convincing fake websites.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/359973/one-fifth-of-apps-on-google-play-breach-child-privacy-rules" data-original-url="/mobile/google-android/359973/one-fifth-of-apps-on-google-play-breach-child-privacy-rules">20% of Google Play apps breach child privacy rules</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/trojans/361444/mekotio-trojan-continues-to-spread-despite-its-operators-arrests" data-original-url="/security/trojans/361444/mekotio-trojan-continues-to-spread-despite-its-operators-arrests">Mekotio trojan continues to spread despite its operators’ arrests</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/359133/new-android-malware-discovered-that-spreads-through-whatsapp-messages" data-original-url="/security/malware/359133/new-android-malware-discovered-that-spreads-through-whatsapp-messages">Wormable Android malware is spreading through WhatsApp messages</a></p></div></div><p>This has also made them difficult to detect from an automation (sandbox) and machine learning perspective, according to Threat Fabric.</p><p>“This small footprint is a (direct) consequence of the permission restrictions enforced by Google Play,” they said.</p><p>Hackers have also started carefully planned small malicious code updates over a longer period in Google Play, as well as sporting a dropper C2 backend to fully match the theme of the dropper app. The researchers cited an example here of a working fitness website for a workout-focused app.</p><p>“To make themselves even more difficult to detect, the actors behind these dropper apps only manually activate the installation of the banking trojan on an infected device in case they desire more victims in a specific region of the world. This makes automated detection a much harder strategy to adopt by any organization,” they said.</p><p>The 300,000 dropper installations came from just four types of malware. Anatsa (200,000+ installations); Alien (95,000+ installations) and Hydra/Ermac (15,000+ installations).</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NeFDhiupASoeoyipbhF9uf" name="NeFDhiupASoeoyipbhF9uf.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NeFDhiupASoeoyipbhF9uf.jpg" mos="https://cdn.mos.cms.futurecdn.net/NeFDhiupASoeoyipbhF9uf.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The state of brand protection 2021</strong></p><p class="fancy-box__body-text">A new front opens up in the war for brand safety</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360246/the-state-of-brand-protection-2021" data-original-url="/security/cyber-security/360246/the-state-of-brand-protection-2021">FREE DOWNLOAD</a></p></div></div><p>The largest, Anatsa, is an advanced Android banking trojan with RAT and semi-ATS capabilities. It carries out classic overlay attacks to steal credentials, accessibility logging (capturing everything shown on the user’s screen), and keylogging.</p><p>Researchers discovered the first dropper in June 2021 masquerading as an app for scanning documents. In total, researchers found six Anatsa droppers published in Google Play since June 2021.</p><p>A hacking group called Brunhilda dropped malware from established families, like Hydra, as well as novel ones, like Ermac. This posed as a QR code creator app. Both families have been very active in the last months according to researchers and have recently started appearing in the US.</p><p>The Alien campaign was also run by the Brunhilda group. This used a fake fitness app to spread.</p><p>“This dropper, that we dubbed “Gymdrop”, is another example of how cybercriminals try to convince victims and detection systems that their app is legitimate. The app website is designed to look legitimate at first glance. However, it is only a template for a gym website with no useful information on it, even still containing ‘Lorem Ipsum’ placeholder text in its pages,” said researchers.</p><p>Researchers said the attention dedicated by these hackers to evading unwanted attention renders automated malware detection less reliable.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Flaw in Android phones could let attackers eavesdrop on calls ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-phones/361666/flaw-in-android-phones-could-let-attackers-eavesdrop-on-calls</link>
                                                                            <description>
                            <![CDATA[ The vulnerable chips are thought to be present in 37% of all smartphones worldwide ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6REq3kMQxrTsJ7dE2H6NnA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iLsCtPzkhPvM4FhARntwdJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Nov 2021 10:07:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iLsCtPzkhPvM4FhARntwdJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A red Android mascot]]></media:description>                                                            <media:text><![CDATA[A red Android mascot]]></media:text>
                                <media:title type="plain"><![CDATA[A red Android mascot]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iLsCtPzkhPvM4FhARntwdJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have discovered a flaw in smartphone chips made by Taiwanese semiconductor manufacturer MediaTek that could enable hackers to listen in on phone conversations.</p><p>The research, carried out by Check Point Research, has highlighted a bug in an audio processor made by MediaTek and used in 37% of the world’s smartphones, including <a href="https://www.itpro.com/software/google/android" data-original-url="https://www.itpro.com/search/android">Android</a> devices made by Xiaomi, Oppo, Realme, and Vivo. The flaw is also said to affect some IoT devices.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/mobile-phones/360024/5-most-secure-smartphones" data-original-url="/mobile/mobile-phones/360024/5-most-secure-smartphones">The five most secure smartphones</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/359128/google-accused-of-illegally-tracking-android-users-with-advertising-codes" data-original-url="/security/privacy/359128/google-accused-of-illegally-tracking-android-users-with-advertising-codes">Google accused of “illegally” tracking Android users</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357379/microsoft-warns-of-continuously-evolving-android-ransomware" data-original-url="/security/357379/microsoft-warns-of-continuously-evolving-android-ransomware">Microsoft warns of ‘continuously evolving’ Android ransomware</a></p></div></div><p>A malicious instruction sent from one processor to another could potentially be used by an attacker to execute and hide malicious code inside the DSP firmware, the researchers warned in a <a href="https://blog.checkpoint.com/2021/11/24/check-point-research-discover-vulnerabilities-in-smartphones-chips-embedded-in-37-of-smartphones-around-the-world">blog post</a>.</p><p>“Since the DSP firmware has access to the audio data flow, an attack on the DSP could potentially be used to eavesdrop on the user,” said researchers.</p><p>The chip contains a special AI processing unit (APU) and audio Digital signal processor (DSP) to improve media performance and reduce CPU usage. Both the APU and the audio DSP have custom Tensilica Xtensa microprocessor architecture. This made it a unique and challenging target for security research, according to Check Point Research.</p><p>To exploit the flaw, hackers would have to get a user to install a malicious app on their device. That app would then use MediaTek’s AudioManager API to connect to the audio driver. An application with system privileges then tells the audio driver to run code on the audio processor’s firmware. This then can hijack the audio stream.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QDksvAYJFwkcCugTbPvwS9" name="QDksvAYJFwkcCugTbPvwS9.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" mos="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Protecting every edge to make hackers’ jobs harder, not yours</strong></p><p class="fancy-box__body-text">How to support and secure hybrid architectures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours" data-original-url="/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours">FREE DOWNLOAD</a></p></div></div><p>Slava Makkaveev, a security researcher at Check Point Software, said that left unpatched, a hacker potentially could have exploited the vulnerabilities to listen in on conversations of Android users.</p><p>“Furthermore, the security flaws could have been misused by the device manufacturers themselves to create a massive eavesdrop campaign,” he said. “ Although we do not see any specific evidence of such misuse, we moved quickly to disclose our findings to MediaTek and Xiaomi.”</p><p>In a statement to press, Tiger Hsu, product security officer at MediaTek, said that device security is a critical component and priority of all MediaTek platforms.</p><p>“Regarding the Audio DSP vulnerability disclosed by Check Point, we worked diligently to validate the issue and make appropriate mitigations available to all OEMs,” he added.</p><p>The discovered vulnerabilities in the DSP firmware (CVE-2021-0661, CVE-2021-0662, CVE-2021-0663) have already been fixed and published in the October 2021 MediaTek Security Bulletin. The security issue in the MediaTek audio HAL (CVE-2021-0673) was fixed in October and will be published in the December 2021 MediaTek Security Bulletin.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is smishing? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/361625/what-is-smishing</link>
                                                                            <description>
                            <![CDATA[ A closer look at one of the most perilous forms of phishing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vg6H8LDurJfVMyaV9WoMcA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nBYsaRaToYsro7bYrkw2mJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Nov 2021 09:47:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nBYsaRaToYsro7bYrkw2mJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A scam text message on a smartphone display]]></media:description>                                                            <media:text><![CDATA[A scam text message on a smartphone display]]></media:text>
                                <media:title type="plain"><![CDATA[A scam text message on a smartphone display]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nBYsaRaToYsro7bYrkw2mJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>We’re all too familiar with <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>. Fraudulent emails purporting to be from a trusted source, and tricking the victim into revealing sensitive information, are rampant.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="/security/29093/what-is-phishing">What is phishing?</a></p></div></div><p>Banks and financial services, third-party vendors, and streaming services are among the popular targets for impersonation. By and large, phishing scams rely on social engineering and clever personalization to lure victims into transferring money to a fraudulent account or providing personally identifiable information (PII). </p><p>The year 2020 saw 6.95 million new phishing attempts. Not surprisingly, COVID-19 scams were common, as were gift cards and gaming hacks. There’s a lesser know variant of phishing, however, that’s equally perilous. SMS phishing, or smishing, employs text messages sent over mobile phones as bait. There’s often an air of urgency in these messages, which entices recipients to click on malicious links.</p><h3 class="article-body__section" id="section-how-common-are-smishing-attacks"><span>How common are smishing attacks?</span></h3><p>Reports of smishing in the UK rose <a href="https://www.itpro.com/security/scams/360873/smishing-attacks-increase-700-percent-2021" target="_blank" data-original-url="https://www.itpro.com/security/scams/360873/smishing-attacks-increase-700-percent-2021">nearly 700% in the first half of 2021</a>, according to a study by enterprise security provider Proofpoint. Additionally, parcel and package delivery scams made up 67.4% of all smishing attempts.</p><p>Other prevalent smishing scams include:</p><ol><li>Urgent notifications regarding credit card payment</li><li>Act-now coupons with special discounts</li><li>Request for survey/feedback from customer support</li><li>Unusual account activity alerts</li><li>Unknown service charges</li><li>Flash sales and giveaways</li><li>Instant student loans</li></ol><p>Over 9,000 reports have been filed to <em>Which?’s</em> Scam Sharer tool since it launched in March 2021. Most reports (65%) involved phone calls or text messages, with 31% of these scams originating as text messages. </p><h3 class="article-body__section" id="section-why-are-smishing-rates-so-high"><span>Why are smishing rates so high? </span></h3><p>The average SMS open rate is 98% compared to just 20% for emails, <a href="https://www.gartner.com/en/digital-markets/insights/the-future-of-sales-follow-ups-text-messages" target="_blank">according to Gartner</a>. Additionally, SMS marketing helps businesses offer 24/7 support to customers, boosting engagement. Given the high response rate, it’s less of a surprise why cyber criminals emulate brands.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/scams/360873/smishing-attacks-increase-700-percent-2021" data-original-url="/security/scams/360873/smishing-attacks-increase-700-percent-2021">Smishing attacks increased 700% in first six months of 2021</a></p></div></div><p>That said, <a href="https://www.itpro.com/security/scams/361335/three-quarters-of-under-35s-targeted-by-text-scams-ofcom" target="_blank" data-original-url="https://www.itpro.com/security/scams/361335/three-quarters-of-under-35s-targeted-by-text-scams-ofcom">smishing attacks</a> are particularly hard to tame for one particular reason: lack of authentication. Unlike emails, SMS messages cannot be blocked or flagged without third-party <a href="https://www.itpro.com/software" target="_blank" data-original-url="https://www.itpro.com/software">software</a>. Unhindered by the law, perpetrators can automate SMS messages to millions of ten-digit phone number combinations.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/EiyiaUoQvOU" allowfullscreen></iframe></div></div><p>For instance, Edward Smith, a UK customer of Santander bank, was conned out of £22,700 after providing a spoofed bank phone number with his one-time password in 2016.</p><p>Santander released a statement stating, “Whilst we are very sympathetic to Mr Smith's situation and the distress caused by being the victim of a scam, Mr Smith disclosed a OTP to validate and authorise the transfer, a security measure we put in place to protect customers against fraud. He also confirmed the payment as genuine when we called to check. Therefore we cannot accept any responsibility for the losses on this account.”</p><p>A subsequent investigation revealed there were at least ten other Santander SMS fraud cases under investigation, with one victim reportedly losing £40,000.</p><h3 class="article-body__section" id="section-how-to-spot-and-stop-smishing-scams"><span>How to spot and stop smishing scams?</span></h3><p>Social engineering and trickery make smishing scams extremely potent and persuasive. Listed below are a few tips to prevent smishing:</p><p><strong>1. Do not click on links sent via text message</strong></p><p>Expect the unexpected. <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">Malware</a> can also spread through secure messaging apps like WhatsApp and Signal. Hacking groups, including Dark Caracal, have successfully employed WhatsApp, Signal, and Messenger to distribute phishing links that trick users into installing phoney updates to their <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted</a> messaging applications. Updates typically include malware files that allow hackers to view user screens, record keystrokes, and even take control of devices remotely.</p><p><strong>2. Look for misspelled words</strong></p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TgYwXSHV6efgCB2UrGXGXc" name="TgYwXSHV6efgCB2UrGXGXc.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" mos="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Prevent fraud and phishing attacks with DMARC</strong></p><p class="fancy-box__body-text">How to use domain-based message authentication, reporting, and conformance for email security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc" data-original-url="/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc">FREE DOWNLOAD</a></p></div></div><p>Smishing attacks are often characterized by poorly crafted sentences, improper grammar, and misspelled words. Be sure to check for these tell-tale signs when you suspect smishing. Spam messages may also contain links that differ ever so slightly from the site's original URL. Navigate to the website manually instead of clicking on the link to avoid being scammed.</p><p><strong>3. Verify the number before initiating contact</strong></p><p>Smishing messages typically come from random or strangely formatted numbers. For example, the number 5000 indicates the message was sent via email and may be malicious. Calling the concerned organization and asking for confirmation is the most reliable way to determine whether the number/message is legitimate. In the event that the number is fraudulent, delete the message to prevent any risks.</p><p><strong>4. Limit the size of your digital footprint</strong></p><p>Publicly available information can help criminals improve the credibility of their phishing messages. A good case in point is social media accounts. Review your privacy settings to ensure hackers cannot retrieve personally identifiable information, including your mobile number.</p><h3 class="article-body__section" id="section-already-responded-here-are-your-options"><span>Already responded? Here are your options</span></h3><p>Timely action can prevent harm. Here are some steps to take if you've already replied to a suspicious message:</p><ol><li>Contact your bank if you have been tricked into disclosing your financial information. Block or freeze your account to prevent further transactions.</li><li>Notify your IT department if you used your work phone to respond. Log out of all other connected devices and reset your password.</li><li>Run a full scan with antivirus software if you clicked on a suspicious link to install or update an application.</li></ol><h3 class="article-body__section" id="section-report-to-curb-the-spread"><span>Report to curb the spread</span></h3><p>It's still worthwhile to report your suspicion, even if it's only a hunch. Luckily, it only takes a few steps to report spam.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/361468/scammers-using-more-cryptocurrency-atms-warns-fbi" data-original-url="/technology/cryptocurrencies/361468/scammers-using-more-cryptocurrency-atms-warns-fbi">FBI warns scammers are using cryptocurrency ATMs to siphon cash</a></p></div></div><p>Do not open or reply to suspicious emails. Instead, forward them to <a href="mailto://phishing-repot@us-cert.gov" data-original-url="mailto:phishing-repot@us-cert.gov">phishing-repot@us-cert.gov</a>, an inbox established by the US Cybersecurity & Infrastructure Security Agency (US-CERT) in collaboration with the Anti-Phishing Working Group (APWG). You can also forward report cases of identity theft through <a href="https://www.identitytheft.gov/" data-original-url="https://www.identitytheft.gov/#">identitytheft.gov</a>. UK readers can forward possible phishing attempts through the Suspicious Email Reporting Service (SERS) at <a href="mailto://report@phishing.gov.uk" data-original-url="mailto:report@phishing.gov.uk">report@phishing.gov.uk</a>.</p><p>Additionally, you can report suspicious text messages to universal short-code 7726 at no charge. The service will help your phone provider track down the source of the text and take appropriate measures.</p><p>“Smishing attempts have risen dramatically – with fraudsters taking advantage of the pandemic to trick consumers into giving away personal details and transferring their hard-earned cash,” says Rocio Concha, director of policy and advocacy at <em>Which?</em>.</p><p>The firm also released a ten-point <a href="https://www.which.co.uk/policy/digital/8001/sms-best-practice" target="_blank">SMS guide</a>, encouraging businesses “to do their part to protect consumers from scams”. The guide offers advice on how businesses can differentiate their texts from those sent by scammers impersonating them, to protect consumers from fraud.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multi-factor authentication deployment guide ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide</link>
                                                                            <description>
                            <![CDATA[ A complete guide to selecting and deploying your MFA authentication guide ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tMhF4RS7qewjA5bUziYQor</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Nov 2021 16:51:37 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Mar 2022 16:51:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The whitepaper title on a strip of swirling blue and purple diagonal across the page]]></media:description>                                                            <media:text><![CDATA[The whitepaper title on a strip of swirling blue and purple diagonal across the page]]></media:text>
                                <media:title type="plain"><![CDATA[The whitepaper title on a strip of swirling blue and purple diagonal across the page]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Multi-factor authentication (MFA) has been increasingly adopted in recent years, in line with the threats to password security.</p><p>Web and mobile products primarily use this, but approaches can differ.</p><p>Download this guide to learn why MFA is an essential tool in online security as well as the best practices for deployment.</p><p><em>Provided by </em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aVingsbZaxsFEzjgWucZgF" name="" alt="Okta logo" src="https://cdn.mos.cms.futurecdn.net/aVingsbZaxsFEzjgWucZgF.png" mos="https://cdn.mos.cms.futurecdn.net/aVingsbZaxsFEzjgWucZgF.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="high" data-lazy-src="https://dennis.cvtr.io/forms/49540/form-9526?locale=1&p=false&wp=8437"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google will auto-enrol 150 million users in 2FA by end of 2021 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/two-factor-authentication-2fa/361133/google-auto-enrol-150m-2021</link>
                                                                            <description>
                            <![CDATA[ An additional two million YouTube creators will also be required to switch it on the 2SV feature by the end of the year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">umFvvVX9nPkmCTTVSdY9Gg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mEDFB62W97JH8cnMdpTebR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Oct 2021 09:56:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mEDFB62W97JH8cnMdpTebR-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman using Google on laptop and smartphone]]></media:description>                                                            <media:text><![CDATA[A woman using Google on laptop and smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[A woman using Google on laptop and smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mEDFB62W97JH8cnMdpTebR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has announced plans to automatically enrol an additional 150 million users in <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a> by the end of 2021.</p><p>Known as two-step verification (2SV), the security feature combines the use of a password with a mobile device or a security key in order to diminish the chances of unauthorised access to accounts and networks. For instance, users signing in to their Gmail account, particularly when using a new computer for the first time, are asked to tap a prompt on their smartphone to authorise the login.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure" data-original-url="/security/cyber-security/361037/what-makes-a-password-secure">What makes a password secure?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by" data-original-url="/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by">Robust password policies cut cyber attacks by 60%</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361083/amazon-microsoft-google-back-trusted-cloud-principles" data-original-url="/security/privacy/361083/amazon-microsoft-google-back-trusted-cloud-principles">Amazon, Microsoft, Google back creation of Trusted Cloud Principles</a></p></div></div><p>In a <a href="https://blog.google/technology/safety-security/making-sign-safer-and-more-convenient">blog post</a> published on Tuesday, the tech giant stated that enabling security protections by default is “the best way to keep [their] users safe”, which is why it's moving to ensure that more accounts have the 2SV feature switched on:</p><p>“By the end of 2021, we plan to auto-enrol an additional 150 million Google users in 2SV,” it announced, adding that an additional two million <a href="https://www.itpro.com/95383/google-acquires-youtube-for-165-billion" data-original-url="https://www.itpro.com/95383/google-acquires-youtube-for-165-billion">YouTube</a> creators will be required to turn the feature on by the end of the year.</p><p>The tech giant acknowledged that <a href="https://www.itpro.com/hardware/358218/johnson-urged-to-support-struggling-children-with-hardware-and-internet-access" data-original-url="https://www.itpro.com/hardware/358218/johnson-urged-to-support-struggling-children-with-hardware-and-internet-access">not everyone has access to a smartphone</a> or a security key, noting that it is “working on technologies that provide a convenient, secure authentication experience and reduce the reliance on passwords in the long-term”.</p><p>“We know security keys provide the highest degree of sign-in security possible, that’s why we've partnered with organisations to provide free security keys to over 10,000 high-risk users this year,” it stated.</p><p>Google said that users will be able to benefit from built-in security key capabilities in Android phones as well as its <a href="https://apps.apple.com/us/app/google-smart-lock/id1152066360">Google Smart Lock app</a> for iOS, adding that its 2SV technology is automatically supported by “two billion devices around the world”.</p><p>In a <a href="https://twitter.com/skarra/status/1445423172841447427">Twitter post</a>, Google product manager Sriram Karra said that today’s announcement “is just the beginning”. </p><p>“The 150m 2SV user count is staggering already if you look at it in the broader industry context. For e.g. Twitter recently announced ~2.5% of its ~350m active users have 2SV - that's ~9m user accounts,” he stated.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FKZ5ZUh5cB23XqcrpXfpea" name="FKZ5ZUh5cB23XqcrpXfpea.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/FKZ5ZUh5cB23XqcrpXfpea.png" mos="https://cdn.mos.cms.futurecdn.net/FKZ5ZUh5cB23XqcrpXfpea.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to secure workloads in hybrid clouds</strong></p><p class="fancy-box__body-text">Cloud workload protection</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/360948/how-to-secure-workloads-in-hybrid-clouds" data-original-url="/cloud/hybrid-cloud/360948/how-to-secure-workloads-in-hybrid-clouds">FREE DOWNLOAD</a></p></div></div><p>Companies across the tech industry have been working to strengthen account security and minimise users' reliance on passwords. In June, Twitter announced that its users would be able to use a security key as their only 2FA method, while in September, Corporate VP of Microsoft <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a>, Compliance and Identity, Vasu Jakkal, stated that customers “can now completely <a href="https://www.itpro.com/operating-systems/microsoft-windows/360900/microsoft-passwordless-user-accounts" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/360900/microsoft-passwordless-user-accounts">remove the password</a> from [the] Microsoft account”.</p><p>However, 2FA has also been the target of cyber criminals. Earlier this week, <a href="https://www.itpro.com/technology/cryptocurrencies/361101/coinbase-data-breach-6000-customers" data-original-url="https://www.itpro.com/technology/cryptocurrencies/361101/coinbase-data-breach-6000-customers">Coinbase sent out letters to 6,000 customers</a> informing them that hackers managed to exploit “a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor (2FA) authentication token”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Has the biometric revolution stalled? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/biometrics/359529/the-it-pro-podcast-has-the-biometric-revolution-stalled</link>
                                                                            <description>
                            <![CDATA[ Biometric authentication was supposed to change the world - but has it? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pFMuZS35d35216iyXVahU2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wCWfUUd4pzMGzxki3MtZi4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 May 2021 14:49:35 +0000</pubDate>                                                                                                                                <updated>Fri, 14 May 2021 06:30:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wCWfUUd4pzMGzxki3MtZi4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: Has the biometric revolution stalled?]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: Has the biometric revolution stalled?]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: Has the biometric revolution stalled?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wCWfUUd4pzMGzxki3MtZi4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For the past decade, we’ve been assured that biometric security is the future, and that soon we’ll be able to do away with traditional forms of identification and authentication in favour of using our faces, fingerprints and even voices. </p><p>However, while biometric technology is certainly more common than it was in 2010, the promised revolution hasn’t quite materialised. We still have to rely on PINs and passwords for many of our transactions (both financial and otherwise) and biometric authentication is still largely limited to mobile devices. So what’s next for the technology? In this episode, we talk to Steven Furnell, senior IEEE member and professor of cyber security at the University of Nottingham, about where biometric security is going.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=44789851&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="https://www.itpro.com/security/29705/what-are-biometrics">What are biometrics?</a></li><li><a href="https://www.itpro.com/security/biometrics/356107/only-skin-deep-the-state-of-biometric-security" data-original-url="https://www.itpro.com/security/biometrics/356107/only-skin-deep-the-state-of-biometric-security">Only skin deep: The state of biometric security</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence-ai/358633/petition-launched-to-ban-facial-recognition-in-eu" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/358633/petition-launched-to-ban-facial-recognition-in-eu">Petition urges EU regulators to ban biometric mass surveillance</a></li><li><a href="https://www.itpro.com/biometrics/34242/hacked-for-life-why-you-should-be-terrified-by-biometric-technology" data-original-url="https://www.itpro.com/biometrics/34242/hacked-for-life-why-you-should-be-terrified-by-biometric-technology">Hacked for life: Why you should be terrified by biometric technology</a></li><li><a href="https://www.itpro.com/security/privacy/358722/tiktok-settles-for-92m-after-being-accused-of-harvesting-biometric-data" data-original-url="https://www.itpro.com/security/privacy/358722/tiktok-settles-for-92m-after-being-accused-of-harvesting-biometric-data">TikTok settles for $92m after being accused of harvesting biometric data</a></li><li><a href="https://www.itpro.com/security/28576/dreaming-of-a-world-without-passwords" data-original-url="https://www.itpro.com/security/28576/dreaming-of-a-world-without-passwords">Dreaming of a world without passwords</a></li><li><a href="https://www.itpro.com/security/359512/github-now-supports-security-keys-in-a-move-away-from-passwords" data-original-url="https://www.itpro.com/security/359512/github-now-supports-security-keys-in-a-move-away-from-passwords">GitHub now supports security keys in a move away from passwords</a></li><li><a href="https://www.itpro.com/security/359443/googles-about-to-push-everyone-into-two-factor-authentication" data-original-url="https://www.itpro.com/security/359443/googles-about-to-push-everyone-into-two-factor-authentication">Google’s about to push everyone into two-factor authentication</a></li><li><a href="https://www.itpro.com/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password" data-original-url="https://www.itpro.com/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password">The IT Pro Podcast: How hackers steal your password</a></li><li><a href="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what" data-original-url="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what">If not passwords then what?</a></li><li><a href="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology" data-original-url="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology">The pros and cons of facial recognition technology</a></li><li><a href="https://www.itpro.com/security/privacy/354627/how-can-facial-recognition-be-made-safer" data-original-url="https://www.itpro.com/security/privacy/354627/how-can-facial-recognition-be-made-safer">How can facial recognition be made safer?</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence-ai/356200/facial-recognition-tech-used-by-south-wales-police" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/356200/facial-recognition-tech-used-by-south-wales-police">Facial recognition tech used by UK police "breaches privacy"</a></li><li><a href="https://www.itpro.com/security/cyber-security/356558/the-it-pro-podcast-the-psychology-of-security" data-original-url="https://www.itpro.com/security/cyber-security/356558/the-it-pro-podcast-the-psychology-of-security">The IT Pro Podcast: The psychology of security</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://podcasts.apple.com/gb/podcast/the-itpro-podcast/id1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/business/business-strategy/358742/it-pro-2020-keeping-the-lights-on" data-original-url="https://www.itpro.com/business/business-strategy/358742/it-pro-2020-keeping-the-lights-on">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Eight Brits arrested over SIM swapping attacks on US celebs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/358575/eight-brits-arrested-over-hacking-celeb-mobile-phones</link>
                                                                            <description>
                            <![CDATA[ International effort between UK and US law enforcement agencies takes down network of English and Scottish cyber criminals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rGCWXbjemB9HnseyEWmsfx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QcrWxhE2PKaBbGsZkLt84D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Feb 2021 11:43:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QcrWxhE2PKaBbGsZkLt84D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A SIM card on top of a mobile ]]></media:description>                                                            <media:text><![CDATA[A SIM card on top of a mobile ]]></media:text>
                                <media:title type="plain"><![CDATA[A SIM card on top of a mobile ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QcrWxhE2PKaBbGsZkLt84D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Eight Brits have been arrested as part of an investigation into a series of 'SIM swapping' attacks across the US. </p><p>The men, aged between 18 and 26, are from England and Scotland and their arrests were part of an international effort with the <a href="https://www.itpro.com/security/trojans/354242/national-crime-agency-brings-down-prolific-trojan-marketplace" target="_blank" data-original-url="https://www.itpro.com/security/trojans/354242/national-crime-agency-brings-down-prolific-trojan-marketplace">National Crime Agency (NCA)</a>, the US Secret Service, Homeland Security, the FBI and the Santa Clara California District Attorney's Office.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts" data-original-url="/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts">Social media firms clamp down on hacked accounts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch" data-original-url="/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch">Twitter investigates possibility that DMs were accessed during Bitcoin hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media" data-original-url="/security/phishing/356581/what-are-you-giving-away-on-social-media">What are you giving away on social media?</a></p></div></div><p>The perpetrators are said to have illegally gained access to mobile phones belonging to US celebrities in order to steal large sums of money, either from their bank accounts or <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" target="_blank" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin#:~:text=Bitcoins%20are%20stored%20in%20a,PC%20or%20in%20the%20cloud.&text=The%20details%20of%20every%20Bitcoin,widely%20popular%20for%20other%20services.">Bitcoin</a> wallets, according to the NCA.</p><p>"This network targeted a large number of victims in the US and regularly attacked those they believed would be lucrative targets, such as famous sports stars and musicians," said NCA's head of operations Paul Creffield. "In this case, those arrested face prosecution for offences under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act#:~:text=The%20Computer%20Misuse%20Act%20(CMA,without%20appropriate%20consent%20or%20permission.&text=What%20is%20the%20Data%20Protection%20Act%201998%3F">Computer Misuse Act</a>, as well as fraud and money laundering as well as extradition to the USA for prosecution." </p><p>The criminals are accused of using a hack called 'SIM swapping' whereby they take over a victims phone number by deactivating the SIM and porting the allocated number over to a new one. This is often achieved by tricking mobile providers to swap the SIMs themselves, either using an insider or social engineering techniques.</p><p>Once they have control of the phone number, they use it to change the passwords on various apps and access contacts, emails and even bank details. </p><p>In the summer, a number of celebrities, such as Elon Musk and Barack Obama, had their <a href="https://www.itpro.com/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch">Twitter accounts hacked</a> via the same methods. Instagram, Twitter and a number of other social media platforms recently announced that they had disabled hundreds of accounts that were stolen through SIM swapping, citing the '<a href="https://www.itpro.com/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts" target="_blank" data-original-url="https://www.itpro.com/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts">OGUsers</a>' forum as the culprit for harvesting the usernames. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wormable Android malware is spreading through WhatsApp ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/358416/wormable-android-malware-spreading-through-whatsapp</link>
                                                                            <description>
                            <![CDATA[ The new strain poses as a Huawei app which users are tricked into downloading from a fake Google Play Store link ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9Y1ZKDM6PeCtVsSYj6JrK5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Jan 2021 10:27:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:description>                                                            <media:text><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:text>
                                <media:title type="plain"><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Android users are being warned against a <a href="https://www.itpro.com/security/357379/microsoft-warns-of-continuously-evolving-android-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/357379/microsoft-warns-of-continuously-evolving-android-ransomware">wormable strain of malware</a> that spreads itself by automatically replying to victims' WhatsApp messages with a malicious link.</p><p>The link this Android malware spreads through WhatsApp connects its victims with a convincing web page resembling Google’s Play Store, and a request to install a fake ‘Huawei Mobile’ app onto a user’s device.</p><p>This is according to ESET security researcher Lukas Stefanko, who published a short analysis of the malware’s mechanisms.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357476/iphone-12-poses-potential-security-issue-for-whatsapp-users" data-original-url="/security/357476/iphone-12-poses-potential-security-issue-for-whatsapp-users">iPhone 12 poses potential security risk for WhatsApp users</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358352/whatsapp-delay-privacy-update" data-original-url="/security/privacy/358352/whatsapp-delay-privacy-update">WhatsApp delays controversial privacy update for businesses</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357379/microsoft-warns-of-continuously-evolving-android-ransomware" data-original-url="/security/357379/microsoft-warns-of-continuously-evolving-android-ransomware">Microsoft warns of ‘continuously evolving’ Android ransomware</a></p></div></div><p>Should users install and activate the malicious app, it’ll immediately ask for various permissions to perform its key functions, including access to contacts and permission to draw over other apps. This latter feature means it can run in the background while other apps are in use on the victim’s device. </p><p>Users are also presented with a request to ignore battery optimisation, which if activated, means the app cannot be killed by the system if spare resources are needed.</p><p>Finally, the malicious app demands access to notifications, specifically WhatsApp notifications, so it can scan for incoming messages and distribute further among contacts.</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" frameborder="0" height="315" width="560" data-lazy-priority="low" data-lazy-src="https://www.youtube.com/embed/XXi29noe2NE"></iframe><p>Once all the permissions are guaranteed and the malicious app is set up, it runs in the background and waits for instructions from the command and control server, as well as incoming WhatsApp messages so it can spread. </p><p>When messages are received through WhatsApp, the <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> scans for these and automatically sends a reply on the user’s behalf which includes the malicious link. This is accompanied with a message asking the contact to visit the fabricated Play Store page and download the fake Huawei app.</p><p>Stefano also examined the malware to show that it surreptitiously only messages the malicious link to one contact once per hour. This is in order for the app not to arouse suspicions and remain in operation for as long as possible before detection and removal.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mobile fraud campaign nabs millions from US and EU banks  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/358179/mobile-fraud-campaign-nabs-millions-from-us-and-eu-banks</link>
                                                                            <description>
                            <![CDATA[ Hackers used emulators to access thousands of customer accounts repeatedly ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4QKqQNSRQZ7M92jxTi1wMo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QZz6UPiXADLxn3EBZwjus3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Dec 2020 15:42:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QZz6UPiXADLxn3EBZwjus3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Woman&amp;#039;s hand on a smartphone showing a mobile banking app]]></media:description>                                                            <media:text><![CDATA[Woman&amp;#039;s hand on a smartphone showing a mobile banking app]]></media:text>
                                <media:title type="plain"><![CDATA[Woman&amp;#039;s hand on a smartphone showing a mobile banking app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QZz6UPiXADLxn3EBZwjus3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have discovered a major mobile banking <a href="https://www.itpro.com/security/phishing/356488/phishing-and-fraud-report" data-original-url="https://www.itpro.com/security/phishing/356488/phishing-and-fraud-report">fraud</a> operation that stole millions of dollars from financial institutions in Europe and the US before being intercepted and halted.</p><p>According to a <a href="https://securityintelligence.com/posts/massive-fraud-operation-evil-mobile-emulator-farms">report</a> by IBM Trusteer, cyber criminals used an infrastructure of mobile device emulators to set up thousands of spoofed devices and access thousands of compromised bank accounts. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/94756/banks-must-prepare-for-industry-evolution" data-original-url="/94756/banks-must-prepare-for-industry-evolution">Banks must prepare for industry evolution</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/94928/uk-banks-outed-on-security" data-original-url="/94928/uk-banks-outed-on-security">UK banks outed on security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/102596/russian-gang-defrauds-bank-customers-with-trojan" data-original-url="/102596/russian-gang-defrauds-bank-customers-with-trojan">Russian gang defrauds bank customers with trojan</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/102800/criminals-aim-at-mobile-phone-banking" data-original-url="/102800/criminals-aim-at-mobile-phone-banking">Criminals aim at mobile phone banking</a></p></div></div><p>“In each instance, a set of mobile device identifiers was used to spoof an actual account holder’s device, likely ones that were previously infected by malware or collected via phishing pages,” said researchers.</p><p>Shachar Gritzman, mobile <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> researcher at IBM said the gang used automation, scripting, and potentially access to a mobile malware botnet or phishing logs to initiate and finalize fraudulent transactions at scale.</p><p>“In this automatic process, they are likely able to script the assessment of account balances of the compromised users and automate large numbers of fraudulent money transfers being careful to keep them under amounts that trigger further review by the bank,” Gritzman said.</p><p>In some cases, hackers used over 20 emulators in the spoofing of well over 16,000 compromised devices.</p><p>“The attackers use these emulators to repeatedly access thousands of customer accounts and end up stealing millions of dollars in a matter of just a few days in each case. After one spree, the attackers shut down the operation, wipe traces, and prepare for the next attack,” said Gritzman.</p><p>Gritzman said to defend against future attacks on mobile devices, users should avoid jailbreaking or rooting any devices, ensure all system updates and app updates take place on time, and obtain apps directly from official app stores.</p><p>Tom Davison, technical director – international at Lookout, told <em>ITPro</em> that this attack demonstrates the extraordinary lengths that today's well-funded and professional cyber criminal groups will go to when the end justifies the means. </p><p>“Mobile devices present a multiplier effect as they become the mainstream platform for online banking. Consumer users need to protect themselves by understanding that mobile devices are not immune. It really is important to keep them updated, but also to verify the safety of installed apps and the validity of links being clicked,” Davison said.</p><p>“For the banks, the challenge comes from the huge range of devices being used to access their services which are not under their control. These may be insecure or already compromised. Customer education helps, but it is also critical to employ run-time application security to spot infected customer devices and block the opportunity for fraud."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WAPDropper malware hooks you up to premium telecoms services ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357878/wapdropper-malware-hooks-you-up-to-premium-telecoms-services</link>
                                                                            <description>
                            <![CDATA[ Hackers have incorporated machine learning into a strain that subscribes victims to legitimate services provided by telecoms firms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g5UoApLiHNFLSNe41ym2sk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Nov 2020 12:03:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:description>                                                            <media:text><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:text>
                                <media:title type="plain"><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A newly discovered <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware strain</a> has been identified in the wild that unwittingly registers victims for premium services provided by legitimate telecoms firms. </p><p>Named WAPDropper, the malware downloads and executes a payload, dropping a wireless application protocol (WAP) premium dialer which subscribes its victims to premium services in Thailand and Malaysia without their knowledge or consent.</p><p>The malware strain comprises two separate modules, according to <a href="https://research.checkpoint.com/2020/enter-wapdropper-subscribe-users-to-premium-services-by-telecom-companies" target="_blank">Check Point Research</a>, including a dropper module responsible for downloading the second-stage malware, and a premium dialer module that is responsible for the subscription element. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357821/weekly-threat-roundup-cisco-bluekeep-apache-unomi" data-original-url="/security/357821/weekly-threat-roundup-cisco-bluekeep-apache-unomi">Weekly threat roundup: Cisco, BlueKeep, Apache Unomi</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/trojans/357036/qbot-malware-surges-into-the-top-ten-most-common-business-threats" data-original-url="/security/trojans/357036/qbot-malware-surges-into-the-top-ten-most-common-business-threats">Qbot malware surges into the top-ten most common business threats</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/356714/qualcomm-achilles-flaws-millions-android-devices-risk" data-original-url="/security/vulnerability/356714/qualcomm-achilles-flaws-millions-android-devices-risk">Qualcomm chip flaws put 'millions' of Android devices at risk</a></p></div></div><p>This campaign identified by the researchers subscribes users to premium services offered by legitimate telecoms providers in Thailand and Malaysia. </p><p>The scheme is centred on making calls to premium-rate numbers, which will, in turn, generate profit for the cyber criminals who collaborate with the owners of these particular phone numbers.</p><p>After the application is first installed on a device using third-party app stores, WAPDropper contacts the command and control server and receives the payloads to execute. This first payload is the premium dialer module, which opens a tiny web window and contacts premium services. </p><p>Once WAPDropper opens the landing pages, it’ll attempt to subscribe the victim to these services. Alarmingly, the process includes a mechanism that can bypass the <a href="https://www.itpro.com/security/29835/artificial-intelligence-outsmarts-captcha-security" target="_blank" data-original-url="https://www.itpro.com/security/29835/artificial-intelligence-outsmarts-captcha-security">CAPTCHA</a> security requirement, which must be overcome to complete a transaction. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ToDVdgntGNNDuLhNm3tnG3" name="ToDVdgntGNNDuLhNm3tnG3.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ToDVdgntGNNDuLhNm3tnG3.png" mos="https://cdn.mos.cms.futurecdn.net/ToDVdgntGNNDuLhNm3tnG3.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How cyber attack simulations differ from penetration tests and vulnerability scanning</strong></p><p class="fancy-box__body-text">Exploring the Cymulate Edge</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/penetration-testing/357806/how-cyber-attack-simulations-differ-from-penetration-tests-and" data-original-url="/security/penetration-testing/357806/how-cyber-attack-simulations-differ-from-penetration-tests-and">FREE DOWNLOAD</a></p></div></div><p>It’s at this stage that the operators deploy the services of Super Eagle, a Chinese firm that offers a <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" target="_blank" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> tool for image recognition. When the malware submits the verification code image to the service, the platform returns the coordinate position of the recognition result in the image, then parses the coordinate simulation landing.</p><p>The malware also attempts to avoid detection by hiding its icon to prevent users from spotting it on their device and uninstalling the app. The malware also performs checks to determine whether the victim is using a proxy or <a href="https://www.itpro.com/networking/27210/do-i-need-a-vpn" target="_blank" data-original-url="https://www.itpro.com/networking/27210/do-i-need-a-vpn">virtual private network (VPN).</a> </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft says skip SMS and voice multi-factor authentication  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357757/microsoft-dont-use-sms-or-voice-multi-factor-authentication</link>
                                                                            <description>
                            <![CDATA[ Firm argues some forms of MFA are vulnerable to social engineering attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jCjFSGZdu3MH4EpDnX7BpD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rrGZ8HhWSCRyxQFWJWSJzB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Nov 2020 19:31:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicholas Fearn ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rrGZ8HhWSCRyxQFWJWSJzB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Desktop monitor and mobile phone with hand pointing]]></media:description>                                                            <media:text><![CDATA[Desktop monitor and mobile phone with hand pointing]]></media:text>
                                <media:title type="plain"><![CDATA[Desktop monitor and mobile phone with hand pointing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rrGZ8HhWSCRyxQFWJWSJzB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft is warning businesses against using <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication (MFA)</a> systems that rely on voice and SMS due to security concerns. </p><p>In a blog post, Microsoft director of identity security Alex Weinert provides a range of reasons why businesses should avoid SMS and voice MFA.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/32401/microsoft-office-365-and-azure-users-locked-out-of-accounts-due-to-mfa-issues" data-original-url="/cloud/32401/microsoft-office-365-and-azure-users-locked-out-of-accounts-due-to-mfa-issues">Microsoft Office 365 and Azure users locked out of accounts due to MFA issues</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/357111/mfa-bypass-allows-hackers-to-infiltrate-microsoft-365" data-original-url="/cloud/cloud-security/357111/mfa-bypass-allows-hackers-to-infiltrate-microsoft-365">MFA bypass allows hackers to infiltrate Microsoft 365</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26225/lastpass-ups-security-with-multi-factor-authentication" data-original-url="/security/26225/lastpass-ups-security-with-multi-factor-authentication">LastPass ups security with multi-factor authentication</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/two-factor-authentication-2fa/30703/uk-businesses-are-slow-to-adopt-multi-factor-authentication" data-original-url="/two-factor-authentication-2fa/30703/uk-businesses-are-slow-to-adopt-multi-factor-authentication">UK businesses are 'slow' to adopt multi-factor authentication</a></p></div></div><p>“These mechanisms are based on publicly switched telephone networks (PSTN), and I believe they’re the least secure of the MFA methods available today,” Weinert writes. “That gap will only widen as MFA adoption increases attackers’ interest in breaking these methods and purpose-built authenticators extend their security and usability advantages.”</p><h3 class="article-body__section" id="section-lack-of-encryption"><span>Lack of encryption</span></h3><p>What’s particularly problematic with SMS and voice-based MFA is they use no <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a>, making it easy for hackers to intercept them, according to Weinert. </p><p>“From a practical usability perspective, we can’t overlay encryption onto these protocols because users would be unable to read them (there are other reasons too, like message bloat, which have prevented these from taking hold over the existing protocols)”</p><p>“What this means is that signals can be intercepted by anyone who can get access to the switching network or within the radio range of a device.”</p><h3 class="article-body__section" id="section-social-engineering"><span>Social engineering</span></h3><p>Weinert also believes SMS and voice-based MFA are more susceptible to <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering</a> techniques. In particular, he says customer support agents are “vulnerable to charm, coercion, bribery, or extortion.” With those tactics, perpetrators could trick customer support representatives into providing “access to the SMS or voice channel.” </p><p>Weinert adds, “While social engineering attacks impact email systems as well, the major email systems (e.g. Outlook, Gmail) have a more developed “muscle” for preventing account compromise via their support ecosystems. This leads to everything from message intercept, to call forwarding attacks, to SIM jacking.”</p><h3 class="article-body__section" id="section-performance-issues"><span>Performance issues</span></h3><p>Another issue is that these systems can be affected by mobile operator performance, with Weinert explaining they “are not 100% reliable, and reporting is not 100% consistent.”</p><p>He also pointed out that evolving regulations make these techniques challenging. “Due to the increase in spam in SMS formats, regulators have required regulations on identifying codes, transmit rates, message content, permission to send, and response to messages like ‘STOP.’”</p><p>“Unfortunately, however, these regulations change rapidly and are inconsistent from region to region and can (and have) resulted in major delivery outages. More outages, more user frustration.”</p><h3 class="article-body__section" id="section-phishing-threats"><span>Phishing threats</span></h3><p>Furthermore, the lack of context in SMS and GSM communications makes <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> an even bigger threat to people who use these types of MFA. </p><p>Weinert says, “In practical terms, the text or voice mediums limit how much information can be communicated to a user – SMS carries 160 characters, 70 if not using GSM, and once we get into languages which require encoding, the practical limit without message splitting is only around half that.“</p><p>“Phishing is a serious threat vector, and we want to empower the user with as much context as possible (or, using Windows Hello or FIDO, make phishing impossible) – SMS and voice formats restrict our ability to deliver the context under which authentication is being requested.”</p><p>Jake Moore, a security specialist at ESET, believes SMS-based MFA isn’t as safe as physical security keys or app-based tokens. </p><p>He told <em>ITPro</em>, “SMS messages are easily hacked as they are not encrypted and are at risk of SIM swapping attacks. However, if this is the only option, then it is still better than not having any extra verification.”</p><p>“Authenticator apps should be one of the first apps you install on your device and be used with every account you own. To go one step further, hardware security tokens are even more secure as they cannot be used in sophisticated social engineering techniques.“</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mobile browser flaw exposes users to spoofing attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357496/mobile-browser-address-bar-spoofing-flaw</link>
                                                                            <description>
                            <![CDATA[ Safari and Opera Touch browsers are among those which can be exploited to target victims with malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oMCsMBSgT65ntnVvWoQbBk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Oct 2020 10:19:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:description>                                                            <media:text><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:text>
                                <media:title type="plain"><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers could exploit an address bar spoofing vulnerability found in a handful of widely-used mobile web browsers to deploy malware or conduct <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">spear-phishing attacks</a>. </p><p>Several mobile web browsers, including Safari and Opera Touch, were afflicted with a flaw that could allow an attacker to set up a malicious website and tempt a victim into opening a link from a spoofed email or text message. </p><p>This would then lead to the user <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">downloading a malicious file</a> or could put the victim at risk data therft, <a href="https://www.rafaybaloch.com/2020/10/multiple-address-bar-spoofing-vulnerabilities.html" target="_blank">according to Rafay Baloch</a>, an independent security researcher. Baloch worked in collaboration with Rapid7 to report the vulnerabilities to each browser developer.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357456/weekly-threat-roundup-windows-10-adobe-and-sonicwall-vpns" data-original-url="/security/357456/weekly-threat-roundup-windows-10-adobe-and-sonicwall-vpns">Weekly threat roundup: Windows 10, Adobe, and SonicWall VPNs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354855/flaw-in-paypals-google-pay-integration-leading-to-suspected-fraud" data-original-url="/security/cyber-security/354855/flaw-in-paypals-google-pay-integration-leading-to-suspected-fraud">Flaw in PayPal’s Google Pay integration leading to suspected fraud</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357479/microsoft-becomes-the-most-spoofed-brand-for-phishing-attacks" data-original-url="/security/357479/microsoft-becomes-the-most-spoofed-brand-for-phishing-attacks">Microsoft becomes the most-spoofed brand for phishing attacks</a></p></div></div><p>The affected browsers, which also include UCWeb, Yandex Browser, Bolt Browser and RITS Browser, pose a risk in the way that an attacker can manipulate JavaScript to cause a pop-up to appear on a user’s device. This would be sourced from an arbitrary website, and the attacker could even render content in the browser to falsely appear as if it was sourced from an arbitrary website.</p><p>The site would need to be established by the attacker, and could be sent to victims through a <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" target="_blank" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">phishing text or email</a> with a spoofed contact number or identity, for example, a message that claims to be from PayPal. </p><p>The origin lies in the way a hacker could execute malicious JavaScript code in the arbitrary website to force the browser to update the address bar to another address of the attacker’s preference as the page loads.</p><p>“This seems like a pretty effective attack, given that the address bar is really the only signal you have to tell 'where' your browser 'is.' As it turns out, there are quite a few ways to get JavaScript to monkey with timing,” said director of research at Rapid7 Tom Beardsley.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ikHxNVdVAecRoeqnt4iUy" name="ikHxNVdVAecRoeqnt4iUy.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ikHxNVdVAecRoeqnt4iUy.jpg" mos="https://cdn.mos.cms.futurecdn.net/ikHxNVdVAecRoeqnt4iUy.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The complete guide to changing your phone system provider</strong></p><p class="fancy-box__body-text">Optimise your phone system for better business results</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/mobile-phones/357492/the-complete-guide-to-changing-your-phone-system-provider" data-original-url="/mobile/mobile-phones/357492/the-complete-guide-to-changing-your-phone-system-provider">FREE DOWNLOAD</a></p></div></div><p>All vulnerabilities were disclosed to the respective developers in August following their discovery - and publicly revealed after sufficient time had elapsed. Both Apple and Opera immediately assigned tickets to fix the bugs affecting their browsers, with a Safari patch out now and an Opera Touch fix set for November.</p><p>Two vendors replied only days before public disclosure, one didn’t reply at all, while attempts to contact the last vendor bounced entirely. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft warns of ‘continuously evolving’ Android ransomware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357379/microsoft-warns-of-continuously-evolving-android-ransomware</link>
                                                                            <description>
                            <![CDATA[ This sophisticated strain abuses the incoming call notification to block access to a device ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ksA9LRHLoiFAn7BCP2EJvJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Oct 2020 10:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:description>                                                            <media:text><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:text>
                                <media:title type="plain"><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has lifted the lid on a <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">sophisticated ransomware family</a> that has been spotted using a <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" target="_blank" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> component embedded in its code and has so far managed to evade most security tools.</p><p>Like most Android ransomware strains, this particular threat, called AndroidOS/MalLocker.B, doesn’t encrypt users files. Instead, it blocks users’ access to their devices by displaying a full-screen notification that spoofs a message from authorities and demands payment in exchange for its removal.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357160/android-users-warned-after-cerberus-leaks-to-dark-web" data-original-url="/security/357160/android-users-warned-after-cerberus-leaks-to-dark-web">Android users told to be on high alert after Cerberus banking Trojan leaks to the dark web</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/357198/firefox-android-flaw-wifi-hijack" data-original-url="/security/vulnerability/357198/firefox-android-flaw-wifi-hijack">Firefox flaw let hackers hijack Android browser over Wi-Fi</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/spyware/357137/google-bans-spouseware-from-play-store" data-original-url="/security/spyware/357137/google-bans-spouseware-from-play-store">Google bans ‘stalkerware’ from Play store</a></p></div></div><p>Researchers say they are especially alarmed by the sophisticated techniques the malware uses to avoid detection, as well as the Android features it abuses to show a ransomware note that cannot be dismissed. This is something many Android ransomware strains have struggled to accomplish recently.</p><p>“The mobile ransomware is the latest variant of a ransomware family that’s been in the wild for a while but has been evolving non-stop,” the Microsoft Defender Research Team said.</p><p>“The new variant caught our attention because it’s an advanced malware with unmistakable malicious characteristic and behavior and yet manages to evade many available protections, registering a low detection rate against security solutions.”</p><p>Android <a href="https://www.itpro.com/security/ransomware/356567/1212-million-ransomware-attacks-in-the-first-half-of-2020" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/356567/1212-million-ransomware-attacks-in-the-first-half-of-2020">ransomware</a> in the past often targeted the ‘SYSTEM_ALERT_WINDOW’ permission to show ransom notes, which couldn’t be dismissed by the user as this permission was normally reserved for things like system alerts or error messages. The mechanism was exploited to make the message fully occupy the screen, blocking access to the device, although this attack surface was practically eliminated following system tweaks by Google.</p><p>Android malware has since attempted to adapt by misusing other features, but these have been largely ineffective. Attempts to exploit accessibility features often alerted users to the presence of malware as it requires navigating through several menu screens in order to use these services. Other families used infinite loops of drawing non-system windows, but it’s possible for users to go to settings and uninstall the app in between drawing and redrawing.</p><p>However, this new malware family has overcome these barriers by abusing the “call” notification – which fills the screen with a notice that you’re receiving an incoming call – to show a full-screen message that cannot be dismissed.</p><p>This particular strain has been through several stages of evolution to get to this current form, and Microsoft’s research team has previously seen stains that abuse accessibility settings, as well as general notification services. The expectation is that this family will churn out new variants with even more sophisticated techniques in future.</p><p>Alarmingly, its code is embedded with a <a href="https://www.itpro.com/technology/artificial-intelligence-ai/355716/what-is-tiny-ai" target="_blank" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/355716/what-is-tiny-ai">TinyML machine learning module</a> that’s designed to make sure images fit the screen without distortion. This would ensure that a ransom note would appear more believable, and less contrived.</p><p>As of now, the library using TinyML hasn’t yet been wired to the malware’s functionalities, but Microsoft claims its presence implies the intention to do so in future versions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ BlackBerry thwarts mobile phishing attacks with new AI tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357343/blackberry-thwarts-mobile-phishing-attacks-with-new-ai-powered-solution</link>
                                                                            <description>
                            <![CDATA[ The company's Protect Mobile platform alerts users to potential malware before a link is clicked ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bVRCfeSDkshgaaWQNyuAZD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Hk8DHS7KuQcZB769sWMXHm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Oct 2020 18:07:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Phones]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tyler Omoth ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Hk8DHS7KuQcZB769sWMXHm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Hk8DHS7KuQcZB769sWMXHm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>BlackBerry has announced a new solution for protecting mobile users against phishing attacks and mobile <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>.</p><p>The new BlackBerry Protect Mobile is an <a href="https://www.itpro.com/strategy/28181/what-is-ai" data-original-url="https://www.itpro.com/strategy/28181/what-is-ai">artificial intelligence</a>-based mobile threat defense (MTD) designed to detect attacks before they execute.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/92417/uk-businesses-gripped-by-blackberry-fever" data-original-url="/92417/uk-businesses-gripped-by-blackberry-fever">UK businesses gripped by BlackBerry fever</a> Blackberry 8700 <a data-analytics-id="inline-link" href="https://www.itpro.com/637831/how-to-use-blackberry-management-center" data-original-url="/637831/how-to-use-blackberry-management-center">How To Use Blackberry Management Center</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/95409/deploying-blackberry-server-41" data-original-url="/95409/deploying-blackberry-server-41">Deploying BlackBerry Server 4.1</a></p></div></div><p>As the COVID-19 pandemic forces millions of workers to shift to remote work, mobile malware and phishing attacks are increasing. Frequently, when users' devices are compromised, they can infect their company's system quickly, but the company may not discover the issue for months.</p><p>BlackBerry Protect Mobile, which is based on the BlackBerry Spark platform, uses AI to detect attacks before they execute. It monitors attacks at the device and application level, allowing it to alert users before they open URLs leading to spoofed websites designed to collect data. It does all this without human intervention.</p><p>Protect Mobile also identifies security vulnerabilities and malicious activities by monitoring system parameters, device configurations and system libraries at the application level. Plus, it can identify malware from <a href="https://www.itpro.com/network-internet/34736/firefox-scraps-extension-sideloading-over-malware-fears" data-original-url="https://www.itpro.com/network-internet/34736/firefox-scraps-extension-sideloading-over-malware-fears">sideloaded apps</a> and ensures applications come from secure repositories only.</p><p>"The number of phishing attacks that target mobile users will continue to rise because business is being conducted on mobile devices and users are more susceptible to attacks when viewing and accessing content on the go," said Billy Ho, executive vice president of BlackBerry Spark.</p><p>"BlackBerry Protect Mobile provides mobile device security integrated into our unified endpoint security (UES) solutions for a simplified approach to identifying and alerting users and administrators to phishing attempts and mobile malware across the enterprise."</p><p>BlackBerry is making a strong push to be a factor in the new work-from-home era. The launch of BlackBerry Protect Mobile comes alongside the <a href="https://www.itpro.com/security/357341/blackberry-persona-desktop-delivers-zero-trust-security-at-the-endpoint" data-original-url="https://www.itpro.com/security/357341/blackberry-persona-desktop-delivers-zero-trust-security-at-the-endpoint">release of BlackBerry Persona Desktop</a>, an AI-powered security solution for desktops and laptops. BlackBerry Persona Desktop and Protect Mobile are part of the company's larger <a href="https://c212.net/c/link/?t=0&l=en&o=2941034-1&h=980083944&u=http%3A%2F%2Fwww.blackberry.com%2Fcyber&a=BlackBerry%C2%AE+Cyber+Suite">Cyber Suite</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Secure files on your smartphone with Google Safe Folder ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-phones/356672/google-safe-folder-keeps-sensitive-files-from-prying-eyes</link>
                                                                            <description>
                            <![CDATA[ Automatically locks itself once you navigate from the app ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5sGQtxum3xs5gYDtnC7xNh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kefqPUGbFcF2xqsA4cLyu3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2020 14:29:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Phones]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Justin Cupler ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kefqPUGbFcF2xqsA4cLyu3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kefqPUGbFcF2xqsA4cLyu3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With all the images and documents we save to our smartphones, they’ve become portable <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> risks. To help keep these sensitive files safe, Google has launched Safe Folder. </p><p>Safe Folder, which is a part of the Files by Google app, is an <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted</a> folder protected by a four-digit PIN. Once you save files in this folder, they are inaccessible without entering your PIN. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/644860/turn-off-that-smartphone" data-original-url="/644860/turn-off-that-smartphone">Turn off that smartphone!</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/630391/smartphones-satellites-at-half-the-price" data-original-url="/630391/smartphones-satellites-at-half-the-price">Smartphones: Satellites at half the price?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/611509/do-smartphones-need-security-software" data-original-url="/611509/do-smartphones-need-security-software">Do smartphones need security software?</a></p></div></div><p>You can save virtually any file type in your Safe Folder, so everything from Word or PDF documents to videos to audio files are secure. </p><p>Once you set up your Safe Folder, create a PIN and move files to it, the system automatically locks the folder when you navigate away from it. Even if it remains open in the background, you still must enter your PIN to view the files. </p><p>So, if you have your Safe Folder open and hand your phone to someone to make a call, you know the folder is secure once you close Safe Folder or the borrower opens the phone app. </p><p>While Safe Folder is new, the Files by Google system launched in 2017. With Files by Google, Android users can quickly delete unwanted and duplicate files, transfer files to other Android users, back up files to the cloud and more. It also helps clean up temporary files that gobble up precious memory. </p><p>Safe Folder is still in beta, so its availability is limited. Google expects a broader rollout in the coming weeks. </p><p>Once it’s available, you can activate Safe Folder by installing and opening the <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.nbu.files&utm_campaign=filesgo-website&utm_medium=weblink&utm_source=filesgo-website">Files by Google app</a>, tapping “Browse” at the bottom of the screen, scrolling to “Collections” and tapping “Safe Folder.” From there, simply follow the prompts to create a PIN and activate the folder. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook Messenger now features its own lock ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/marketing-comms/facebook-at-work/356544/facebook-messenger-now-features-its-own-lock</link>
                                                                            <description>
                            <![CDATA[ Now you can lend your phone without worry about someone snooping through your Messenger app ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vamnog6TJMHqK5T6rjAFhQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VzPNU9SUtLr68mjqGZ4NXC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2020 18:44:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Justin Cupler ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VzPNU9SUtLr68mjqGZ4NXC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VzPNU9SUtLr68mjqGZ4NXC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/apps/28396/facebook-messenger-not-working-your-phone-might-be-too-old" data-original-url="https://www.itpro.com/apps/28396/facebook-messenger-not-working-your-phone-might-be-too-old">Facebook Messenger</a> has become a communication tool for the masses. From personal chats to business communications, seemingly everyone uses it daily. This results in a lot of sensitive and personal information getting shared on it, and with Messenger now on our phones, this makes letting someone borrow your phone a risky proposition, until today. </p><p>Today, Facebook has added an extra layer of protection by adding a lock specifically for the Messenger app. Dubbed App Lock, this new feature locks your Messenger and allows noone to access it until you use either your touch or face ID to unlock it separately from your phone. What’s more, this system uses the IDs already stored in your phone and doesn’t transmit them to Facebook. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/645103/facebook-graph-search-what-it-means-for-google-microsoft-and-business-users" data-original-url="/645103/facebook-graph-search-what-it-means-for-google-microsoft-and-business-users">Facebook Graph Search: What it means for Google, Microsoft and business users</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/640822/could-the-uk-ever-build-a-facebook" data-original-url="/640822/could-the-uk-ever-build-a-facebook">Could the UK ever build a Facebook?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/635770/why-businesses-should-beware-the-facebook-convictions" data-original-url="/635770/why-businesses-should-beware-the-facebook-convictions">Why businesses should beware the Facebook convictions</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/615799/qa-cat-lee-facebook-platform-manager" data-original-url="/615799/qa-cat-lee-facebook-platform-manager">Q&A: Cat Lee, Facebook platform manager</a></p></div></div><p>App Lock is currently available on iPhone and <a href="https://www.itpro.com/tag/ipad" data-original-url="https://www.itpro.com/tags/ipad">iPad</a> devices only, but Facebook expects to roll it out to Android devices in a few months. </p><p>Before App Lock, once you unlocked your phone to let someone else use it, they had full access to your private messages. If that person took to snooping through your messages, it could expose you or your business to a number of risks. With App Lock, this is no longer an issue. </p><p>Sure, it’s an extra step each time you unlock your phone to check your messages, but it’s well worth the security. </p><p>You can activate App Lock by opening your Messenger app, clicking on your avatar on the top-left corner, clicking “Privacy” under the “Preferences” section and toggling App Lock to the “On” position. </p><p>With App Lock activated, you can feel confident your messages are secure when letting a friend, family member, coworker or stranger borrow your phone. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple is tracking iPhones stolen by looters ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/355898/apples-tracking-iphones-stolen-by-looters</link>
                                                                            <description>
                            <![CDATA[ Firm is using GPS technology to track and disable devices that were stolen from Apple Stores ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">spqm7MYLoVEKGZHD5qRyuf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/urzQtH29yLaFF77diPn3vS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Jun 2020 12:42:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iPhone]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                    <category><![CDATA[Mobile Phones]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/urzQtH29yLaFF77diPn3vS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand holding an iphone 8]]></media:description>                                                            <media:text><![CDATA[Hand holding an iphone 8]]></media:text>
                                <media:title type="plain"><![CDATA[Hand holding an iphone 8]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/urzQtH29yLaFF77diPn3vS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has been tracking iPhones that have been stolen during the <a href="https://www.itpro.com/technology/355874/tech-industry-calls-for-action-over-the-death-of-george-floyd" data-original-url="https://www.itpro.com/technology/355874/tech-industry-calls-for-action-over-the-death-of-george-floyd">ongoing protests across the US.</a> </p><p>The company hasn't officially confirmed this, but <a href="https://www.itpro.com/technology/social-media" data-original-url="https://www.itpro.com/tags/social-media">social media</a> posts, including an image that’s being widely shared on <a href="https://twitter.com/disposablefilms/status/1267111238313693185">Twitter</a> and <a href="https://www.reddit.com/r/iphone/comments/gttqkt/looted_iphones_show_this_screen">Reddit</a>, confirms that Apple has been tracking the location of the pilfered devices. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1267111238313693185"></a></p></blockquote><div class="see-more__filter"></div></div><p>The photo shows an iPhone with a message on its display that reads, “This device has been disabled and is being tracked. Local authorities will be alerted.”</p><p>The warning asks for the phone to be returned to an Apple Store on Walnut Street in downtown Philadelphia.</p><p>That’s one of the Apple Stores that was looted over the past week. During recent protests following the death of George Floyd while in police custody in Minneapolis, looters have taken advantage of the civil unrest to break into Apple Stores in Los Angeles, New York, Philadelphia, Portland, Salt Lake City and Washington, D.C.</p><p>With no official word from Apple on the matter, it’s not clear if authorities are actually being alerted to the phones’ whereabouts.</p><p>However, we do know that Apple has the technology to remotely track a phone’s location. The company's "Find My app", for example helps users to <a href="https://support.apple.com/en-us/HT201472">locate lost or stolen devices</a>. </p><p>The recent looting of a number of Apple Stores comes as the company was preparing to reopen more than 100 retail stores across the US. </p><p>The stores had been <a href="https://www.itpro.com/mobile/mobile-phones/355225/report-apple-to-keep-us-stores-closed-until-may" data-original-url="https://www.itpro.com/mobile/mobile-phones/355225/report-apple-to-keep-us-stores-closed-until-may">closed for an extended period of time</a> due to the coronavirus pandemic.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Parachute's Superlock feature keeps your phone recording in an emergency ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/355889/parachute-introduces-superlock-feature</link>
                                                                            <description>
                            <![CDATA[ Superlock prevents unauthorized users from stopping livestream recordings ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t36e3uiTpfkHcmKDkSfnP7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AfVQrArEwKNNVXxn84MF4i-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Jun 2020 18:53:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah Brennan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AfVQrArEwKNNVXxn84MF4i-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AfVQrArEwKNNVXxn84MF4i-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Parachute has <a href="https://parachute.live/blog/introducing-superlock">announced</a> its new Superlock feature that prevents unauthorized users from stopping and ending video recordings.</p><p>In situations where there’s a risk of a device being taken by an attacker, police officer or another unauthorized person, the Superlock feature locks down the Parachute app so it continues recording and livestreaming a user’s video, audio and location.</p><p>It remains unlocked and livestreaming, even if an unauthorized user tries to shut the phone off. The update to Parachute arrives amid nationwide <a href="https://www.itpro.com/technology/355874/tech-industry-calls-for-action-over-the-death-of-george-floyd" data-original-url="https://www.itpro.com/technology/355874/tech-industry-calls-for-action-over-the-death-of-george-floyd">protests</a> related to the death of George Floyd</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/603933/hd-video-conferencing-as-good-as-being-there" data-original-url="/603933/hd-video-conferencing-as-good-as-being-there">HD video conferencing: As good as being there?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/609372/top-10-security-stories-of-2008" data-original-url="/609372/top-10-security-stories-of-2008">Top 10 security stories of 2008</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/160146/ico-slams-cctv-sound-recording" data-original-url="/160146/ico-slams-cctv-sound-recording">ICO slams CCTV sound recording</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/privacy/34008/google-defends-eavesdropping-on-smart-speaker-recordings" data-original-url="/privacy/34008/google-defends-eavesdropping-on-smart-speaker-recordings">Google defends eavesdropping on smart speaker recordings</a></p></div></div><p>Keep in mind, Parachute already wipes devices during livestreaming. Should an attacker get control over a Parachute user’s phone, they won’t find much, even if the phone is unlocked or broken. Superlock takes things a step further by also preventing unauthorized users from stopping Parachute and ending video recordings.</p><p>The new feature works with Apple’s Guided Access to lock down a user’s phone and requires the user to turn this feature on via Settings > Accessibility > Guided Access. Once the user has activated Guided Access, they must return to the Parachute app, triple-click the power button and tap “Start” to select a six-digit passcode.</p><p>Users then must triple-click the iPhone power button again, enter their passcode and tap the end button. Once completing setup, users can activate Superlock by triple-clicking the power button.</p><p>Superlock also cuts off access to the “X” button that stops a recording, making it impossible to stop a Parachute recoding without entering the user’s six-digit passcode. An increasing time-delay mechanism prevents unauthorized users from quickly trying different combinations to try to crack a user’s passcode too.</p><p>“As the most powerful safety app in the world, Parachute has become an indispensable tool for those whose life’s mission puts them face to face with danger every day. Today’s Superlock launch takes Parachute’s one-of-a-kind protection even further,” said Marinos Bern, CEO at Parachute.</p><p>Superlock is accessible on <a href="https://www.itpro.com/mobile/mobile-phones/355819/iphone-11-is-now-the-worlds-most-popular-smartphone" data-original-url="https://www.itpro.com/mobile/mobile-phones/355819/iphone-11-is-now-the-worlds-most-popular-smartphone">iPhones</a> starting today. Users can download Parachute by <a href="https://parachute.live/app">visiting the company’s website</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI and Justice Department accuse Apple of stalling terrorist probe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/355702/fbi-and-justice-department-accuse-apple-of-stalling-terrorist-probe</link>
                                                                            <description>
                            <![CDATA[ US government found al Qaeda connections on terrorist’s iPhone without Apple’s help ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q3MP4H9PyKjUziNV7CwQs1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vLhSptuTbywRmwf36HhBYn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 May 2020 17:29:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iPhone]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                    <category><![CDATA[Mobile Phones]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah Brennan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vLhSptuTbywRmwf36HhBYn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Apple logo unsecure]]></media:description>                                                            <media:text><![CDATA[Apple logo unsecure]]></media:text>
                                <media:title type="plain"><![CDATA[Apple logo unsecure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vLhSptuTbywRmwf36HhBYn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US law enforcement officials have <a href="https://news.sky.com/story/fbi-unlocks-terrorists-iphones-and-finds-al-qaeda-links-no-thanks-to-apple-11990818">accused Apple</a> of stalling an investigation into a Saudi aviation student who killed three people at a Florida Naval base last year. </p><p>Second Lt. Mohammed Alshamrani, a member of the Saudi air force, had been communicating with al Qaeda operatives for years. The discovery was made using information recovered from his two iPhone devices. </p><p>Officials have <a href="https://news.sky.com/story/fbi-unlocks-terrorists-iphones-and-finds-al-qaeda-links-no-thanks-to-apple-11990818">since accused Apple</a> of stalling the probe by refusing to unlock the shooter’s devices. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">What makes the iPhone a business phone? <a data-analytics-id="inline-link" href="https://www.itpro.com/622492/the-ipad-and-apps-can-the-tablet-top-the-iphone" data-original-url="/622492/the-ipad-and-apps-can-the-tablet-top-the-iphone">The iPad and apps: Can the tablet top the iPhone?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/617326/is-oranges-network-fit-for-the-iphone" data-original-url="/617326/is-oranges-network-fit-for-the-iphone">Is Orange's network fit for the iPhone?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/624019/the-iphone-4g-what-to-expect" data-original-url="/624019/the-iphone-4g-what-to-expect">The iPhone 4G: What to expect</a></p></div></div><p>Ultimately, the FBI had to bypass Apple’s security features to access the information on the gunman’s phones. The information uncovered on the devices led to a counterterrorism operation against Abdullah al-Maliki, an associate of Alshamrani, Attorney General William Barr said. Unfortunately, Apple was of little help during the FBI’s investigations.</p><p>“We received effectively no help from Apple," FBI director Christopher Wray stated during a news conference, adding that the struggle to unlock the encrypted devices caused months-long delays and jeopardized public safety.</p><p>Apple, on the other hand, disagrees with Barr and the FBI’s assessment.</p><p>“The false claims made about our company are an excuse to weaken encryption and other security measures that protect millions of users and our national security,” Apple shared in a <a href="https://www.wsj.com/articles/fbi-discovers-al-qaeda-link-in-pensacola-attack-11589809330">statement</a> provided to <em>The Wall Street Journal</em>.</p><p>“It is because we take our responsibility to national security so seriously that we do not believe in the creation of a backdoor—one which will make every device vulnerable to bad actors who threaten our national security and the data security of our customers.”</p><p>Despite its condemnations of the company, the Justice Department is no closer to <a href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" data-original-url="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">convincing Apple to provide backdoor access to its tech</a>. At this time, Barr and Wray have also declined to comment on how they unlocked the devices.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google finally fixes Pixel 4 face unlock security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/355258/google-patches-pixel-4-security-issue</link>
                                                                            <description>
                            <![CDATA[ Firm releases a patch five months after the flaw was discovered ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9SkwppER4fdu4Eez2WrYrL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GKtArfgoUUhYgXNMWP4wEH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Apr 2020 09:49:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GKtArfgoUUhYgXNMWP4wEH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GKtArfgoUUhYgXNMWP4wEH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has released an update for its Pixel 4 smartphones that addresses a security issue that has plagued users since its release in October 2019.</p><p>At the time of the Pixel 4's release, the smartphone <a href="https://www.itpro.com/google-android/34688/google-pixel-4-review-delight-and-frustration" target="_blank" data-original-url="https://www.itpro.com/google-android/34688/google-pixel-4-review-delight-and-frustration">was lauded</a> for its affordable price, great camera, and smart software features. However, an issue with its face unlock feature meant that the Pixel 4 could be unlocked even when its owner’s eyes were closed.</p><p>This sounded alarm bells amongst security experts, who warned that the flaw could allow anyone to unlock the device without its users' permission by putting it in front of their face while they're asleep.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile-phones/34717/google-pixel-4-xl-review-a-soli-excuse-for-a-battery" data-original-url="/mobile-phones/34717/google-pixel-4-xl-review-a-soli-excuse-for-a-battery">Google Pixel 4 XL review: A Soli excuse for a battery</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/355211/google-releases-location-data-to-showcase-effectiveness-of-coronavirus" data-original-url="/security/privacy/355211/google-releases-location-data-to-showcase-effectiveness-of-coronavirus">Google releases location data to show effectiveness of coronavirus lockdowns</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/355233/russian-isp-intercepted-traffic-from-internet-giants-like" data-original-url="/infrastructure/network-internet/355233/russian-isp-intercepted-traffic-from-internet-giants-like">Russian ISP intercepted traffic from AWS, Facebook, Google and more</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/355250/health-sites-sharing-users-medical-data-with-major-tech" data-original-url="/policy-legislation/data-protection/355250/health-sites-sharing-users-medical-data-with-major-tech">Health sites are 'unlawfully' sharing medical data with Facebook and Google</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/355238/google-app-update-may-fix-android-auto-voice-command-bug-unless-it" data-original-url="/mobile/google-android/355238/google-app-update-may-fix-android-auto-voice-command-bug-unless-it">Google app update may fix Android Auto voice-command bug (unless it doesn’t)</a></p></div></div><p>Google has finally decided to address the problem with a new update released this week which solves the security concern with a single option, reducing the probability of unauthorised or accidental activations.</p><p>Pixel 4 users are now able to eliminate this issue if they mark the “need to have eyes open for recognition” setting after turning on face recognition on their devices. However, the company advised those who are still wary to enable the “lockdown” option from the power menu, which will ensure that the phone is only unlocked with a passcode.</p><p>The update also fixes dropped Bluetooth audio input during calls as well as the lagging keyboard when opened in certain apps.</p><p>In late November 2019, Google expanded its Android <a href="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards" target="_blank" data-original-url="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards">bug bounty program</a> by <a href="https://www.itpro.com/security/bugs/354180/google-to-offer-15m-to-anyone-that-can-break-a-pixel-4" target="_blank" data-original-url="https://www.itpro.com/security/bugs/354180/google-to-offer-15m-to-anyone-that-can-break-a-pixel-4">offering $1.5m</a> to anyone who could break the Pixel 4, in a bid to make its Titan technology more secure.</p><p>The eventual release of a Pixel 4 fix follows the news that <a href="https://www.itpro.com/network-internet/web-browser/355240/google-rolls-back-controversial-chrome-update-in-wake-of" target="_blank" data-original-url="https://www.itpro.com/network-internet/web-browser/355240/google-rolls-back-controversial-chrome-update-in-wake-of">Google will halt a controversial Chrome update</a> in light of the COVID-19 pandemic. The company had decided to roll back the SameSite <a href="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law" target="_blank" data-original-url="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law">cookie</a> changes, which were claimed to provide increased security and privacy by phasing out support for third-party cookie tracking. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US seeks Huawei 5G talks with UK's 'influential' Dominic Cummings ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/5g/354794/us-seeks-huawei-5g-talks-with-uks-influential-dominic-cummings</link>
                                                                            <description>
                            <![CDATA[ US is reportedly looking for an agreement with the UK to work on 5G alternatives ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qDzqnttwp6TyBnMC8a87Sy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CbvHB9LK2DgCjdSAxXAMTK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Feb 2020 10:15:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[5g]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Mobile Networks]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CbvHB9LK2DgCjdSAxXAMTK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Dominic Cummings]]></media:description>                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CbvHB9LK2DgCjdSAxXAMTK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US officials are reportedly set for a meeting with Dominic Cummings on Wednesday, to demand that the UK rethinks its decision to allow Huawei a role in its 5G infrastructure. </p><p>The US is seeking a possible compromise that will allow the two countries to work together on developing an alternative, according to <a href="https://www.theguardian.com/technology/2020/feb/17/trumps-chief-of-staff-to-meet-cummings-for-huawei-5g-talks"><em>The Guardian</em></a>. </p><p>Donald Trump's acting chief of staff, Mick Mulvaney, will meet with Boris Johnson's chief aide at Downing Street with reports that the US wants the UK to commit to removing Huawei equipment from its mobile networks in three to five years time. </p><p>Since the UK's government granted Huawei <a href="https://www.itpro.com/mobile/5g/354651/huawei-granted-limited-role-in-uks-5g-infrastructure" data-original-url="https://www.itpro.com/mobile/5g/354651/huawei-granted-limited-role-in-uks-5g-infrastructure">"limited"</a> access to its networks, a number of US officials have warned about the risks the Chinese company poses, even claiming it <a href="https://www.itpro.com/mobile/5g/354756/us-officials-claim-huawei-embeds-backdoors-in-its-telecoms-networks" data-original-url="https://www.itpro.com/mobile/5g/354756/us-officials-claim-huawei-embeds-backdoors-in-its-telecoms-networks">embeds backdoors</a> in its telecoms networks. </p><p>Trump himself has remained relatively quiet on the subject. The US ambassador to Germany <a href="https://twitter.com/RichardGrenell/status/1229164331738312706?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Etweet">tweeted</a> that the president called him from Air Force One with instructions to make clear that: "any nation who chooses to use an untrustworthy <a href="https://www.itpro.com/mobile/28081/what-is-5g" data-original-url="https://www.itpro.com/mobile/28081/what-is-5g">5G</a> vendor will jeopardise our ability to share intelligence and information at the highest level."</p><p>Huawei has hit back at the US with counter-accusations that cite the <a href="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir" data-original-url="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir">Edward Snowden</a> leaks detailing American surveillance on other countries. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/34187/trumped-up-huawei-threat-helps-nobody" data-original-url="/policy-legislation/34187/trumped-up-huawei-threat-helps-nobody">Trumped up Huawei threat helps nobody</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/34095/huawei-p30-review-too-good-to-ban" data-original-url="/mobile/34095/huawei-p30-review-too-good-to-ban">Huawei P30 review: Too good to ban</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/354651/huawei-granted-limited-role-in-uks-5g-infrastructure" data-original-url="/mobile/5g/354651/huawei-granted-limited-role-in-uks-5g-infrastructure">Huawei granted "limited" role in UK's 5G infrastructure</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/354459/report-claims-us-pressured-dutch-government-to-scrap-china-trade" data-original-url="/business/business-strategy/354459/report-claims-us-pressured-dutch-government-to-scrap-china-trade">Report claims US pressured Dutch government to scrap China trade deal</a></p></div></div><p>"US allegations of Huawei using lawful interception are nothing but a smokescreen - they don't adhere to any form of accepted logic in the cyber security domain," Huawei said in a statement. "Huawei has never and will never covertly access telecom networks, nor do we have the capability to do so."</p><p>Mulvany is also scheduled to meet Sir Edward Lister for his two-day visit, which will also see him address the Oxford Union debating society. But it's thought that the US is particularly keen on meeting with Cummings, who is seen as the prime ministers most influential aide. </p><p>Members of Johnson's own party and the opposition have expressed similar views on Cummings. Labour Leadership candidate Keir Starmer quipped that Prime Minister's Question time may be renamed "DCQs" after Cummings as he "actually holds all the power", according to <a href="https://www.theneweuropean.co.uk/top-stories/dominic-cummings-in-charge-of-government-1-6517858"><em>The New European</em></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US officials claim Huawei embeds backdoors in its telecoms networks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/5g/354756/us-officials-claim-huawei-embeds-backdoors-in-its-telecoms-networks</link>
                                                                            <description>
                            <![CDATA[ The Chinese firm has hit back, suggesting the US is "unwilling to consider the facts" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wXRYnhzpvvTK9YxRJ5NoM8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hiado59Pwshkm2YiY9c6Eg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Feb 2020 10:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[5g]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Mobile Networks]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hiado59Pwshkm2YiY9c6Eg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Huawei phone in front of logo]]></media:description>                                                            <media:text><![CDATA[A hand holding a Huawei smartphone with the Huawei logo in the background]]></media:text>
                                <media:title type="plain"><![CDATA[A hand holding a Huawei smartphone with the Huawei logo in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hiado59Pwshkm2YiY9c6Eg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US officials have made new accusations about Huawei's alleged spying activities, claiming the company is maintaining backdoors into its telecoms networks that can be accessed remotely. </p><p>The allegations centre on the use of backdoors in networking equipment like base stations and antennas, which are installed for legitimate use by law enforcement by virtually all manufacturers, not just Huawei. </p><p>However, US National Security Advisor Robert O'Brien has claimed the Chinese firm has retained access to these backdoors without notifying the carriers that use its equipment, according to <em><a href="https://www.wsj.com/articles/u-s-officials-say-huawei-can-covertly-access-telecom-networks-11581452256">The Wall Street Journal</a></em> <em>.</em> </p><p>It's also reported that these details were disclosed to both UK and German officials at the end of 2019 after the US had allegedly noticed access to 4G equipment going back to 2009. </p><p>"We have evidence that Huawei has the capability secretly to access sensitive and personal information in systems it maintains and sells around the world," national security adviser Robert O'Brien told the <em>WSJ</em>.</p><p>Although these allegations are still quite vague, they are the most detailed information yet as to what led the US to <a href="https://www.itpro.com/policy-legislation/34834/us-huawei-ban-to-be-postponed-for-another-three-months" data-original-url="https://www.itpro.com/policy-legislation/34834/us-huawei-ban-to-be-postponed-for-another-three-months">block companies</a> from supplying equipment and services to Huawei at the start of 2019. Throughout last year, a number of US-based software and hardware suppliers had to cut ties with the Chinese company to comply with the government's legislation.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/34187/trumped-up-huawei-threat-helps-nobody" data-original-url="/policy-legislation/34187/trumped-up-huawei-threat-helps-nobody">Trumped up Huawei threat helps nobody</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/34095/huawei-p30-review-too-good-to-ban" data-original-url="/mobile/34095/huawei-p30-review-too-good-to-ban">Huawei P30 review: Too good to ban</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/354651/huawei-granted-limited-role-in-uks-5g-infrastructure" data-original-url="/mobile/5g/354651/huawei-granted-limited-role-in-uks-5g-infrastructure">Huawei granted "limited" role in UK's 5G infrastructure</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/354459/report-claims-us-pressured-dutch-government-to-scrap-china-trade" data-original-url="/business/business-strategy/354459/report-claims-us-pressured-dutch-government-to-scrap-china-trade">Report claims US pressured Dutch government to scrap China trade deal</a></p></div></div><p>Before the ban came into force, companies such as <a href="https://www.itpro.com/network-internet/33094/vodafone-boss-demands-us-share-what-evidence-it-has-on-huawei" data-original-url="https://www.itpro.com/network-internet/33094/vodafone-boss-demands-us-share-what-evidence-it-has-on-huawei">Vodafone</a> and <a href="https://www.bloomberg.com/news/articles/2019-09-08/microsoft-says-trump-is-treating-huawei-unfairly">Microsoft</a> called on the US to release its evidence, but it's taken a year for any further details of the alleged evidence to be made public. </p><p>In January, it was reported that the US shared intelligence on security concerns regarding <a href="https://www.itpro.com/policy-legislation/33709/trump-suggests-huawei-could-be-included-in-china-trade-deal" data-original-url="https://www.itpro.com/policy-legislation/33709/trump-suggests-huawei-could-be-included-in-china-trade-deal">Chinese</a> manufacturers with the <a href="https://www.itpro.com/business/business-strategy/354459/report-claims-us-pressured-dutch-government-to-scrap-china-trade" data-original-url="https://www.itpro.com/business/business-strategy/354459/report-claims-us-pressured-dutch-government-to-scrap-china-trade">Dutch government</a> and the same officials also disclosed the information to their British counterparts in the run-up to its long-awaited decision on whether Huawei could continue to play a role in its <a href="https://itpro-master.prod.cms.didev.co.uk/node/add/article">5G</a> deployment. </p><p><em>IT Pro</em> has approached Huawei for comment but hadn't received a response at the time of publication. However, Huawei's chief security officer, Andy Purdy, told <em><a href="https://www.theverge.com/2020/2/11/21133631/huawei-china-spying-claims-us-officials-blacklist-5g">The Verge</a>: </em>"We vigorously deny the allegation that we retain any such capability. We also deny that we have ever improperly accessed customer information or customer data.</p><p>"The US is committed to this, and I think it's really prompted by the geopolitical situation between China and the US. The US is unwilling to consider the facts and the evidence, and they're going to do whatever they can to block our ability to provide products to communication networks around the world."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google purges 24 Android apps that abuse user data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/354729/google-purges-24-android-apps-that-abuse-user-data</link>
                                                                            <description>
                            <![CDATA[ The apps also harboured malware and rogueware and were all linked to Chinese tech firm Shenzhen HAWK ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aJFB99PKKCAevfgMarcbxb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PJ4UUyACmfUtG3eMF2xzUJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Feb 2020 11:45:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Thomas Dougherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PJ4UUyACmfUtG3eMF2xzUJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PJ4UUyACmfUtG3eMF2xzUJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has removed 24 apps (totaling 382 million active installations) suspected of unethical data practices from the <a href="https://www.itpro.com/android/28189/how-to-build-android-apps" data-original-url="https://www.itpro.com/android/28189/how-to-build-android-apps">Google Play Store</a>. </p><p>“If we find behavior that violates our policies, we take action,” said Google in response to <a href="https://vpnpro.com/blog/chinese-company-secretly-behind-popular-apps-seeking-dangerous-permissions">a report published by VPNpro</a> earlier this week.</p><p>The tarnished apps stem from five different developers, all offshoots of Shenzhen HAWK - a Chinese tech company with a history of releasing apps infected with malware and rogueware. </p><p>Shenzhen HAWK’s mega parent company the TLC Corporation <a href="https://www.forbes.com/sites/zakdoffman/2020/02/03/android-user-warning-here-are-24-dangerous-apps-with-a-dark-secretand-382-million-installs/#5cd4bf7174b7">has since responded to Google’s action</a>, claiming to be “actively working” with developers “to better understand their concerns”. </p><p>The TLC Corporation - which is partially owned by the Chinese state - also referenced plans to hire an outside security consultant to protect its consumers from <a href="https://www.itpro.com/security/privacy/354241/stop-leaking-your-identity" data-original-url="https://www.itpro.com/security/privacy/354241/stop-leaking-your-identity">insecure data practices</a>. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8xHTYs7UvqDtwHrsiFquYN" name="8xHTYs7UvqDtwHrsiFquYN.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/8xHTYs7UvqDtwHrsiFquYN.png" mos="https://cdn.mos.cms.futurecdn.net/8xHTYs7UvqDtwHrsiFquYN.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building a modern information governance strategy</strong></p><p class="fancy-box__body-text">How to rethink your approach to develop a more modern information governance strategy</p><p class="fancy-box__body-text">FREE DOWNLOAD</p></div></div><p>Despite the TLC Corporation’s promise thousands, potentially millions of <a href="https://www.itpro.com/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you" data-original-url="https://www.itpro.com/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you">Android</a> users remain at risk for having their data tampered with. </p><p>Last year, UK mobile research firm Upstream reported the danger lurking behind the Shenzhen HAWK’s seemingly innocent Weather Forecast app: “It collects and transmits geographic locations, email addresses, IMEIs to a server in China and has a number of privacy invasive permissions on the device. Had it not been blocked it would have succeeded to subscribe users on Alcatel phones in countries like Brazil, Malaysia and Nigeria to paid services for which users would have been billed more than $1.5 million.”</p><p>These apps have been accused by VPNpro of “seeking dangerous permissions”, which include giving unsolicited Chinese servers access to users’ locations, cameras, and mobile accounts, among a number of other concerning factors. </p><p>“There are quite a lot of financially lucrative things, legal or illegal, that app developers can do with user data,” added Upstream’s initial report. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/354728/bluetooth-hijack-bug-among-25-android-flaws-patched-in-february" data-original-url="/security/vulnerability/354728/bluetooth-hijack-bug-among-25-android-flaws-patched-in-february">Bluetooth hijack bug among 25 Android flaws patched in February</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/android/28184/the-best-antivirus-for-android-phones" data-original-url="/android/28184/the-best-antivirus-for-android-phones">Best antivirus for Android 2021: Bitdefender, Norton, Kaspersky and more</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/penetration-testing/354645/what-is-breach-and-attack-simulation-bas" data-original-url="/security/penetration-testing/354645/what-is-breach-and-attack-simulation-bas">What is Breach and Attack Simulation (BAS)?</a></p></div></div><p>The 24 Shenzhen HAWK apps removed from the Google Play Store range from offering storage cleaning services and file management, to a selfie camera and games.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Does the US want the UK to ditch Huawei? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/354482/does-the-us-want-the-uk-to-ditch-huawei</link>
                                                                            <description>
                            <![CDATA[ Raab and Pompeo set for a meeting in Washington where reports suggest the Chinese telecoms giant is up for discussion ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eZNRC7C9N6gUooE8ZxTmA4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/neCnrpzVwRx9tpEu5xBFX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jan 2020 12:14:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/neCnrpzVwRx9tpEu5xBFX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Mike Pompeo]]></media:description>                                                            <media:text><![CDATA[Mike Pompeo giving a speech]]></media:text>
                                <media:title type="plain"><![CDATA[Mike Pompeo giving a speech]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/neCnrpzVwRx9tpEu5xBFX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US is reportedly making a last-ditch effort to convince the UK to ban Huawei equipment from its <a href="https://www.itpro.com/mobile/28081/what-is-5g" data-original-url="https://www.itpro.com/mobile/28081/what-is-5g">5G</a> infrastructure plans. </p><p>Secretary of State Mike Pompeo is expected to press the UK's Foreign Secretary, Dominic Raab, during a meeting in Washington on Thursday, according to <a href="https://uk.reuters.com/article/us-britain-usa-huawei-tech/shot-across-the-bow-u-s-increases-pressure-on-uk-ahead-of-key-huawei-decision-idUKKBN1Z70NV"><em>Reuters</em></a>. </p><p>A government spokesperson said that it continues to consider its position on "high-risk vendors" and that a decision will be made "in due course". </p><p>According to <em>Reuters</em>, the UK has been weighing up US allegations that Huawei's tech will be used by the Chinese government for espionage against industry warnings that banning it could cost billions of pounds. Sources suggests a final decision will be made later this month.</p><p>The Chinese firm is a leader in telecommunications technology, including 5G equipment, but has fallen foul of the US government. It's been on a trade <a href="https://www.itpro.com/policy-legislation/33672/us-relaxes-trade-restrictions-on-huawei-founder-uninterested" data-original-url="https://www.itpro.com/policy-legislation/33672/us-relaxes-trade-restrictions-on-huawei-founder-uninterested">blacklist</a> since the start of 2019, cutting off trade deals with <a href="https://www.itpro.com/policy-legislation/33690/arm-ee-and-microsoft-form-the-latest-companies-to-exclude-huawei" data-original-url="https://www.itpro.com/policy-legislation/33690/arm-ee-and-microsoft-form-the-latest-companies-to-exclude-huawei">US-based suppliers</a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/34187/trumped-up-huawei-threat-helps-nobody" data-original-url="/policy-legislation/34187/trumped-up-huawei-threat-helps-nobody">Trumped up Huawei threat helps nobody</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-currency/34012/on-this-one-issue-trump-is-absolutely-correct" data-original-url="/digital-currency/34012/on-this-one-issue-trump-is-absolutely-correct">On this one issue, Trump is absolutely correct</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/google-android/33798/google-warns-huawei-ban-poses-risk-to-us-security" data-original-url="/google-android/33798/google-warns-huawei-ban-poses-risk-to-us-security">Google warns Huawei ban poses risk to US security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/33882/us-huawei-ban-impacts-global-supply-chains" data-original-url="/policy-legislation/33882/us-huawei-ban-impacts-global-supply-chains">US' Huawei ban impacts global supply chains</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/27492/trump-on-tech-what-president-trump-means-for-the-tech-industry" data-original-url="/strategy/27492/trump-on-tech-what-president-trump-means-for-the-tech-industry">Trump on tech: What President Trump means for the tech industry</a></p></div></div><p>Washington had planned to send a delegation, including deputy national security advisor Matt Pottinger, to meet with UK officials this week, according to <em>Reuter's</em> sources. However, that was cancelled at the last minute due to bad weather.</p><p>The US has reportedly been pressing allies to consider its security concerns over both Huawei and China for a number of years. On Monday, <a href="https://www.itpro.com/business/business-strategy/354459/report-claims-us-pressured-dutch-government-to-scrap-china-trade" data-original-url="https://www.itpro.com/business/business-strategy/354459/report-claims-us-pressured-dutch-government-to-scrap-china-trade">reports</a> suggested that Pompeo used the state visit of the Dutch Prime Minister Mark Rutte to share US intelligence reports on Chinese security concerns. </p><p>Netherlands government had granted a trading license to ASML and it had set up a deal with an unnamed Chinese company. ASML specialises in chip manufacturing using a process called lithography. Following the meeting with the US, however, the government decided not to renew the company's license. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Twitter issues emergency security patch for Android ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/354437/twitter-issues-emergency-security-patch-for-android</link>
                                                                            <description>
                            <![CDATA[ Android users told to update app after discovery of serious vulnerability ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aKJqbKytjQRJzkmocRJmqW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rs7wJREHSfm69W26sgjD5j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Dec 2019 11:46:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rs7wJREHSfm69W26sgjD5j-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rs7wJREHSfm69W26sgjD5j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you use Twitter for <a href="https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you" target="_blank" data-original-url="https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you">Android</a>, pick up your phone and update the app – the company has just issued a patch for a particularly dangerous flaw.</p><p><a href="https://www.itpro.com/tag/twitter" target="_blank" data-original-url="https://www.itpro.com/search/twitter">Twitter</a> admitted in a <a href="https://privacy.twitter.com/en/blog">blog post</a> that it had spotted a nasty vulnerability that could let hackers see private account information or take over your feed to send Tweets or Direct messages. A patch is already being pushed out, and there's no evidence the flaw had been spotted or used in the wild.</p><p>Twitter said that making use of the flaw would have involved a "complicated process" that required inserting malicious code into restricted storage areas of the app, but admitted it may have been possible.</p><p>"We don’t have evidence that malicious code was inserted into the app or that this vulnerability was exploited, but we can’t be completely sure so we are taking extra caution," the company said.</p><p>Alongside patching the flaw, the company said it would directly contact anyone exposed to the flaw, either via the app or by email, with instructions on how to keep their accounts safe. "We recommend that people follow these instructions as soon as possible," the company said. "If you are unsure about what to do, update to the latest version of Twitter for Android."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31060/twitter-alerts-users-after-squashing-password-revealing-internal-bug" data-original-url="/security/31060/twitter-alerts-users-after-squashing-password-revealing-internal-bug">Twitter alerts users after squashing password revealing internal bug</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/34721/twitter-bans-political-advertising-from-its-platform" data-original-url="/marketing-comms/34721/twitter-bans-political-advertising-from-its-platform">Twitter bans political advertising from its platform</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/34166/twitter-owns-up-to-third-party-data-breaches" data-original-url="/data-breaches/34166/twitter-owns-up-to-third-party-data-breaches">Twitter owns up to third-party data breaches</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/34513/magecart-skimmers-are-targeting-large-public-wi-fi-networks-for-payment-details" data-original-url="/cyber-security/34513/magecart-skimmers-are-targeting-large-public-wi-fi-networks-for-payment-details">Magecart skimmers are targeting large public Wi-Fi networks for payment details</a></p></div></div><p>The app can be updated via the Play Store on Android. Twitter said the iOS version of the app was not affected by the flaw.</p><p>For anyone wanting more information, Twitter has a <a href="https://twitter.ethicspointvp.com/custom/twitter/forms/data/form_data.asp">form</a> to request information about your account and security. "We’re sorry this happened and will keep working to keep your information secure on Twitter," the post added.</p><p>The security flaw comes as the company purged 88,000 accounts that were used as part of a "significant state-backed information operation on Twitter originating in Saudi Arabia". The spam accounts were spreading pro-Saudi propaganda via a variety of platform manipulation techniques, such as aggressive liking, <a href="https://blog.twitter.com/en_us/topics/company/2019/new-disclosures-to-our-archive-of-state-backed-information-operations.html">Twitter said</a>. The campaign was coordinated by a Saudi marketing company, Smaat, which has been banned permanently from Twitter.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK Police lost 2,600 devices over the last three years, FOI reveals ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/354431/uk-police-lost-2600-devices-over-the-last-three-years-foi-reveals</link>
                                                                            <description>
                            <![CDATA[ The overwhelming majority of devices were lost from West Midlands Police ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gfgxqzo1qLd9JDRLNJPxRF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GNfRehyrwRHWUxxtGeu47L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Dec 2019 09:47:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GNfRehyrwRHWUxxtGeu47L-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Smartphone lost on the street]]></media:description>                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GNfRehyrwRHWUxxtGeu47L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Police officers across the UK have had 2,600 devices lost or stolen over the past three years, according to a Freedom of Information (FOI) request.</p><p>Since 2016 there has been a 150% increase in reports of missing mobile phones, <a href="https://www.itpro.com/laptops/23742/best-laptops" data-original-url="https://www.itpro.com/laptops/23742/best-laptops">laptops</a>, police radios and even <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted</a> USB pens. 1,360 gadgets were reported lost over the last year alone – some 4 devices every day.</p><p>The FOI request, issued by the Parliament Street Think Tank, also revealed that West Midlands Police reported the highest number of device losses, with 1,012 since 2016.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/640366/business-of-it-building-a-case-for-byod" data-original-url="/640366/business-of-it-building-a-case-for-byod">Business of IT: Building a case for BYOD</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="/security/28133/what-is-cyber-security">What is cyber security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/159990/technology-for-dealing-with-lost-laptops" data-original-url="/159990/technology-for-dealing-with-lost-laptops">Technology for dealing with lost laptops</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/638788/do-british-police-get-cyber-security" data-original-url="/638788/do-british-police-get-cyber-security">Do British police get cyber security?</a></p></div></div><p>A breakdown of their loses showed 16 laptops, 112 mobile phones and 884 police radios in three years.</p><p>The Staffordshire Police force came second by quite a margin, with only 277 lost over the three year period – just over a quarter of the devices lost by the West Midlands force. The Greater Manchester Police reported the third-highest numbers with 225 gadgets going missing, including 200 mobile devices and eight encrypted USB pens. However, 209 of those devices went missing over the past year.</p><div ><table><tbody><tr><td  ><strong>UK Police Force</strong></td><td  ><strong>2016-17</strong></td><td  ><strong>2017-18</strong></td><td  ><strong>2018-19</strong></td><td  ><strong>Total</strong></td></tr><tr><td  >West Midlands</td><td  >187</td><td  >222</td><td  >603</td><td  >1,012</td></tr><tr><td  >Staffordshire</td><td  >72</td><td  >93</td><td  >112</td><td  >277</td></tr><tr><td  >Greater Manchester</td><td  >0</td><td  >16</td><td  >209</td><td  >225</td></tr><tr><td  >Lancashire</td><td  >68</td><td  >64</td><td  >59</td><td  >191</td></tr><tr><td  >Derbyshire</td><td  >20</td><td  >52</td><td  >39</td><td  >111</td></tr></tbody></table></div><p>"The reality is that the majority of these devices will contain <a href="https://www.itpro.com/policy-legislation/34346/employees-warned-against-holding-on-to-sensitive-data-when-quitting-a-job" data-original-url="https://www.itpro.com/policy-legislation/34346/employees-warned-against-holding-on-to-sensitive-data-when-quitting-a-job">sensitive data</a> on police investigations as well as confidential information about criminals, suspects and victims," said Andy Harcup, VP EMEA for Absolute Software.</p><p>"Everyone recognises the loss of laptops and mobiles in the line of duty is inevitable, so it's vital that forces have the necessary systems in place to track and freeze equipment when it falls into the wrong hands. This approach can help improve <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> standards, protect the privacy of individuals and prevent criminals and opportunistic thieves from misusing police devices and stealing data."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Avast and AVG extensions pulled from Chrome  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome</link>
                                                                            <description>
                            <![CDATA[ Avast and AVG once again criticised for excessive data collection in security and shopping browser extensions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wtsHBzL2wNjhBrEtb3y4o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wybnY2oiHKNB54dWrjwvs4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Dec 2019 11:44:35 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Dec 2019 12:41:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wybnY2oiHKNB54dWrjwvs4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[browser]]></media:description>                                                            <media:text><![CDATA[browser]]></media:text>
                                <media:title type="plain"><![CDATA[browser]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wybnY2oiHKNB54dWrjwvs4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Chrome is the latest browser to drop AVG and Avast extensions after reports of excessive data snooping.</p><p>Back in October, a <a href="https://palant.de/2019/10/28/avast-online-security-and-avast-secure-browser-are-spying-on-you">blog post</a> from Wladimir Palant, founder and CTO at AdBlock Plus, highlighted that browser extensions created by the two security firms were hoovering up more data than necessary to function, especially versus rivals such as Google Safe Browsing. That data, according to the post, included user ID, where you're located, and how you got to a specific page.</p><p>After that report, Mozilla and Opera both pulled the AVG and Avast extensions, though the former reinstated one set of add-ons after changes to data collection were made. Google has now reportedly also followed that lead, removing the questionable extensions.</p><p>"I didn't expect to publish this update any more, but Avast extensions are now gone from Chrome Web Store as well," Palant <a href="https://twitter.com/WPalant/status/1207231966589980672">tweeted</a>. "Only AVG Online Security remains for some reason. Way to go Google!" The latter has 3,582 users, according to the Google Web Store.</p><p>Avast, which <a href="https://www.itpro.com/security/antivirus" data-original-url="https://www.itpro.com/antivirus/26885/avast-to-swallow-up-antivirus-rival-avg-in-13bn-buyout">bought AVG in 2016</a>, had not replied to a request for comment at the time of publishing.</p><p>Palant highlighted in his blog post four extensions: Avast Online Security, AVG Online Security, as well as the SafePrice shopping addon from both companies. Mozilla has since reinstated the Online Security addons, but not SafePrice.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L8vUrzgp7mhwUJ5GEHSyyi" name="L8vUrzgp7mhwUJ5GEHSyyi.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" mos="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Managing security risk and compliance in a challenging landscape</strong></p><p class="fancy-box__body-text">How key technology partners grow with your organisation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a" data-original-url="/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a">FREE DOWNLOAD</a></p></div></div><p>"The data collected here goes far beyond merely exposing the sites that you visit and your search history," he explained. "Tracking tab and window identifiers as well as your actions allows Avast to create a nearly precise reconstruction of your browsing behaviour: how many tabs do you have open, what websites do you visit and when, how much time do you spend reading/watching the contents, what do you click there and when do you switch to another tab."</p><p>This isn't the first time that Avast has been in trouble for data collection. Back <a href="https://www.howtogeek.com/199829/avast-antivirus-was-spying-on-you-with-adware-until-this-week">in 2015</a>, it was accused of using its extension to spy on users in a similar way, an accusation Avast <a href="https://forum.avast.com/index.php?topic=157693.msg1140066#msg1140066">denied in a forum statement</a> saying all data collected was "essential" to provide the service. In 2018, the company <a href="https://www.itpro.com/software/31631/avast-pulls-latest-ccleaner-update-following-privacy-outrage" data-original-url="https://www.itpro.com/software/31631/avast-pulls-latest-ccleaner-update-following-privacy-outrage">pulled an update to CCleaner</a> after backlash sparked by privacy settings, while i<a href="https://www.itpro.com/tag/google-chrome" data-original-url="https://www.itpro.com/security/25786/avgs-web-tuneup-chrome-add-on-poses-security-risk">n 2015 AVG was criticised</a> for auto-installing a plugin into the Chrome browser.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Merkle in the middle of US and China over Huawei ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/mobile-security/354381/merkle-in-the-middle-of-us-and-china-over-huawei</link>
                                                                            <description>
                            <![CDATA[ German government will vote on Huawei's involvement in its 5G  rollout ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nGm5PwGpte9r4v9QSdBaLU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vhDoGy7ca8FmqoRWDngycS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Dec 2019 11:36:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vhDoGy7ca8FmqoRWDngycS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Angela Merkle]]></media:description>                                                            <media:text><![CDATA[Angela Merkel not looking very happy]]></media:text>
                                <media:title type="plain"><![CDATA[Angela Merkel not looking very happy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vhDoGy7ca8FmqoRWDngycS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Germany's Social Democrats (SPD) will decide on Tuesday whether to adopt a proposal that could ban Huawei from taking part in the rollout of its <a href="https://www.itpro.com/mobile/28081/what-is-5g" data-original-url="https://www.itpro.com/mobile/28081/what-is-5g">5G</a> infrastructure. </p><p>The outcome could place further pressure on the country's chancellor Angela Merkle who is caught between appeasing <a href="https://www.itpro.com/policy-legislation/33722/huawei-and-china-launch-fresh-offensives-amid-us-trade-war" data-original-url="https://www.itpro.com/policy-legislation/33722/huawei-and-china-launch-fresh-offensives-amid-us-trade-war">China and the US government</a>.</p><p>Merkel's government is aiming to shore up the technical certification and scrutiny of telecoms equipment suppliers but has insisted that no country or vendor be excluded. </p><p>Critics of Merkle have suggested that her careful approach is due to a fear of Chinese retaliation against German companies that have heavily invested in its markets, according to <em>Reuters</em>. The Chancellor has been challenged by lawmakers in her own party as well as her SPD junior partners. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/google-android/33798/google-warns-huawei-ban-poses-risk-to-us-security" data-original-url="/google-android/33798/google-warns-huawei-ban-poses-risk-to-us-security">Google warns Huawei ban poses risk to US security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/34095/huawei-p30-review-too-good-to-ban" data-original-url="/mobile/34095/huawei-p30-review-too-good-to-ban">Huawei P30 review: Too good to ban</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/32663/angela-merkle-personal-details-leak-twitter-hackers" data-original-url="/data-breaches/32663/angela-merkle-personal-details-leak-twitter-hackers">Angela Merkel's personal details leaked on Twitter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/34515/what-has-donald-trump-done-for-the-tech-industry-so-far" data-original-url="/policy-legislation/34515/what-has-donald-trump-done-for-the-tech-industry-so-far">What has Donald Trump done for the tech industry so far?</a></p></div></div><p>Last week SPD and conservative lawmakers agreed on a blueprint that would make it difficult for Huawei to take part in building Germany's 5G mobile infrastructure. The proposal states that suppliers from countries where "state influence without constitutional supervision, manipulation or espionage cannot be ruled out are categorically excluded from the network, both the core and peripheral", according to <a href="https://uk.reuters.com/article/uk-germany-china-huawei/strains-in-german-coalition-as-spd-eyes-5g-rules-that-could-exclude-huawei-idUKKBN1YK1L2"><em>Reuters</em></a>. </p><p>Accusations that <a href="https://www.itpro.com/policy-legislation/34187/trumped-up-huawei-threat-helps-nobody" data-original-url="https://www.itpro.com/policy-legislation/34187/trumped-up-huawei-threat-helps-nobody">Huawei</a> is heavily linked to the Chinese government are well documented and are also believed to be the main reason why the company was <a href="https://www.itpro.com/policy-legislation/33650/huawei-placed-on-trade-blacklist-by-us-gov" data-original-url="https://www.itpro.com/policy-legislation/33650/huawei-placed-on-trade-blacklist-by-us-gov">blacklisted</a> by the US government. </p><p>Speaking at an event hosted by business daily Handelsblatt, the Chinese ambassador to Germany, Ken Wu, said: "If Germany were to take a decision in the end that would exclude Huawei from the German market, then it should expect consequences." </p><p>"The Chinese government will not just stand by and watch. Look, 28 million cars were sold on the Chinese market last year, including seven million German cars. Could we say to one day that German cars are not safe - because we are capable of producing our own cars? No, this is pure protectionism."</p><p><em>IT Pro</em> has approached Huawei for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5G networks are vulnerable to hacking ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile-security/34807/5g-networks-are-vulnerable-to-hacking</link>
                                                                            <description>
                            <![CDATA[ New research uncovers nearly a dozen more flaws in the next generation of mobile network ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">34R6D8tG6hGJ7B5qccGXFN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/58Mqy7R2t3Qz5f58QEY5hG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Nov 2019 12:24:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Erin Paulson ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/58Mqy7R2t3Qz5f58QEY5hG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[5G signal on a smartphone]]></media:description>                                                            <media:text><![CDATA[5G signal on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[5G signal on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/58Mqy7R2t3Qz5f58QEY5hG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers from Purdue University and the University of Iowa have discovered nearly a dozen flaws in 5G network technology, which they say can track a victim's real-time location, create false emergency alerts, and discreetly disconnect phones from a 5G network altogether.</p><p>The researchers, using their tool called the "5GReasoner", found that 5G is still subject to some of the same exploits as 4G, despite touting a more "robust security posture" than previous cellular network generations.</p><p>The 5GReasoner discovered 11 new surveillance and disruption threats to the network by conducting a series of attacks against 5G-connected phones from a radio base station.</p><p>In one of these attacks, researchers obtained old and new temporary network identifiers of a victim's phone, which allowed them to track its location through its paging occasion. They could also broadcast fake emergency alerts by hijacking the paging channel, which could lead to "artificial chaos." Both real-time <a href="https://www.itpro.com/network-internet/33081/flaws-in-4g-and-5g-could-allow-attackers-to-launch-dos-attacks-and-track" target="_blank" data-original-url="https://www.itpro.com/network-internet/33081/flaws-in-4g-and-5g-could-allow-attackers-to-launch-dos-attacks-and-track">location tracking</a> and false emergency alerts are vulnerabilities shared by 4G and 5G networks.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33303/36-vulnerabilities-in-lte-4g-standard-could-enable-data-interception" data-original-url="/security/33303/36-vulnerabilities-in-lte-4g-standard-could-enable-data-interception">36 vulnerabilities in LTE 4G standard could enable data interception</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/28081/what-is-5g" data-original-url="/mobile/28081/what-is-5g">What is 5G and how far are we from rollout?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/34228/three-launches-uks-first-fully-unlimited-5g-network" data-original-url="/network-internet/34228/three-launches-uks-first-fully-unlimited-5g-network">Three launches UK's first fully unlimited 5G network</a></p></div></div><p>Another attack discovered a means to create a prolonged <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">denial-of-service</a> condition, which could completely disconnect a target's phone from the network for an extended period of time. It could also downgrade the phone to a less secure connection, leaving it open for law enforcement and other hackers to launch surveillance attacks.</p><p>According to one of the co-authors of the new research paper, Syed Rafiul Hussain, anyone with a working knowledge of 4G and 5G networks and a cheap software-defined radio can conduct these attacks.</p><p>Warnings over flaws in the Authentication Key Agreement in 5G first arose <a href="https://www.itpro.com/mobile/32893/5g-security-concerns-persist-with-new-research-pointing-to-critical-flaw" target="_blank" data-original-url="https://www.itpro.com/mobile/32893/5g-security-concerns-persist-with-new-research-pointing-to-critical-flaw">back in February</a>, with the GSM Association (GSMA), which represents the global mobile communications industry, promising remedial action. The research, however, suggests they have yet to deliver.</p><p>The GSMA inducted the researchers into their <a href="https://www.gsma.com/security/gsma-mobile-security-hall-of-fame" target="_blank">mobile security hall of fame</a>, but spokesperson Claire Cranton said the vulnerabilities uncovered were "judged as nil or low-impact in practice." The association gave no timeline or certain intention for rectifying the network's flaws.</p><p>Hussain told <a href="https://techcrunch.com/2019/11/12/5g-flaws-locations-spoof-alerts" target="_blank"><em>TechCrunch</em></a> that while some of the fixes can be made in the existing network design, others will likely call for "a reasonable amount of change in the protocol."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook fixes iOS 13.2.2 bug that launched users' cameras without authorisation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cyber-security/34806/facebook-fixes-ios-1322-bug-that-launched-users-cameras-without-authorisation</link>
                                                                            <description>
                            <![CDATA[ The issue has angered users who think the company is exploiting the app to spy on them ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hUdFAheN8S1JwV7tzW45Ef</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RgjuiWRbwD2hC9bqcWLy3H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Nov 2019 11:23:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RgjuiWRbwD2hC9bqcWLy3H-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Facebook logo displayed on a screen in white text on a blue background]]></media:description>                                                            <media:text><![CDATA[The Facebook logo displayed on a screen in white text on a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[The Facebook logo displayed on a screen in white text on a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RgjuiWRbwD2hC9bqcWLy3H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook's iOS app has been the subject of users' anger following reports of it enabling their phone's camera without permission.</p><p>According to Guy Rosen, VP of integrity at <a href="https://www.itpro.com/615424/the-great-facebook-privacy-debate" target="_blank" data-original-url="https://www.itpro.com/615424/the-great-facebook-privacy-debate">Facebook</a>, the camera activation is the result of a bug that seems to be affecting <a href="https://www.itpro.com/hardware/34503/apple-iphone-11-review-a-high-octane-crowd-pleaser" target="_blank" data-original-url="https://www.itpro.com/hardware/34503/apple-iphone-11-review-a-high-octane-crowd-pleaser">iPhone users</a> running the most recent iOS 13.2.2 version. Not everyone perceives it as an accident, though, with one user alleging the findings were evidence of Facebook wanting to "look into people's private lives".</p><p>The issue seems to be triggered when users expand multimedia in the app, be it an image or video, and then swipe down to return to the news feed or whatever page they were originally on.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1193434937824702464"></a></p></blockquote><div class="see-more__filter"></div></div><p>Videos capturing the issue have been tweeted multiple times by different users. One person claimed to have tested the issue on multiple phones running iOS 13.2.2 and received the same results.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1193582199921987584"></a></p></blockquote><div class="see-more__filter"></div></div><p>In a separate but related issue raised by a software tester on 2 November, a bug in Facebook's iOS app pushed the user automatically into a Facebook/Instagram story UI after returning the phone into portrait orientation from viewing a video in landscape.</p><p>The same individual also reported unauthorised audio being played out of Instagram even when the phone was locked.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1190639141979140097"></a></p></blockquote><div class="see-more__filter"></div></div><p>Rosen <a href="https://twitter.com/guyro/status/1194280394687840256" target="_blank">replied</a> to one of the numerous tweets saying "thanks for flagging this. This sounds like a bug, we are looking into it".</p><p>"We recently discovered our iOS app incorrectly launched in landscape," he added in a <a href="https://twitter.com/guyro/status/1194329353770790913" target="_blank">follow-up tweet</a>. "In fixing that last week in v246 we inadvertently introduced a bug where the app partially navigates to the camera screen when a photo is tapped. We have no evidence of photos/videos uploaded due to this."</p><p>Facebook also said it planned to push a complete fix for the issue on Tuesday, with v247 now being the most up-to-date version.</p><p>Despite the quick patch, the news will be unwelcome for the company that has been criticised so heavily for its privacy violations in recent years.</p><p>Unconfirmed speculation from users of the Facebook platforms has alleged the apps to be <a href="https://www.itpro.com/security/29430/who-cares-if-voice-assistants-listen-to-us" target="_blank" data-original-url="https://www.itpro.com/security/29430/who-cares-if-voice-assistants-listen-to-us">'listening' to people's conversations</a> and using the data to target them with adverts in social feeds.</p><p>"A while ago, me and a couple of mates were talking about Formula 1 because one of them is a huge fan but the other friend and I don't really know much about it. When they got up to grab a drink, I was flicking through Instagram and a sponsored advert came up advertising the upcoming race and Sky Sports deal," one afflicted user told <em>IT Pro</em>. "I found it pretty strange considering I have very little interest in F1 and the advert popped up while I've been talking about it."</p><p>It has never been proven, the allegations have lingered for years and have consistently been downplayed by the company. Instagram CEO Adam Mosseri has <a href="https://www.cbsnews.com/news/instagram-ads-listening-adam-mosseri-interview-with-gayle-king-today-cbs-news-exclusive" target="_blank">previously denied these claims</a>, citing "dumb luck" as an explanation.</p><p>Panda Security <a href="https://www.pandasecurity.com/mediacenter/privacy/is-instagram-listening-conversations" target="_blank">addressed the issue in July</a>, saying the "more likely reason" for these user reports is down to the extensive data mining algorithms used by the company to profile its users. The company added that the only way to avoid these "spooky, invasive ads is to <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">avoid social media altogether</a>".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Best mobile device management (MDM) solutions 2022 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/29775/best-mdm-solutions</link>
                                                                            <description>
                            <![CDATA[ What are the best enterprise MDM solutions available for securing your corporate devices? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ty7xzhEAikjSc7TyzBDQCt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JRYqzdNLj7XijufPeuZwP5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Sep 2019 11:17:00 +0000</pubDate>                                                                                                                                <updated>Fri, 17 May 2024 15:14:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;Connor has previously written for the likes of Red Bull Esports and UNILAD, before a lengthy stint at ITPro. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JRYqzdNLj7XijufPeuZwP5-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand holding a modern smartphone over a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A hand holding a modern smartphone over a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A hand holding a modern smartphone over a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JRYqzdNLj7XijufPeuZwP5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Mobile device management (MDM) is one of the most important business tools used by UK organisations. This is a system that helps IT administrators to secure and control tablets, smartphones, and computers used by employees in an organisation.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368424/six-cyber-security-companies-to-watch-in-2022" data-original-url="/security/cyber-security/368424/six-cyber-security-companies-to-watch-in-2022">Six cyber security companies to watch in 2022</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/remote-access/357936/12-must-have-tools-for-working-from-home" data-original-url="/mobile/remote-access/357936/12-must-have-tools-for-working-from-home">12 must-have tools for working from home</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security" data-original-url="/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">HTTP vs HTTPS: What difference does it make to security?</a></p></div></div><p>Thanks to new and modern initiatives like hot-desking and <a href="https://www.itpro.com/strategy/28072/what-is-byod" data-original-url="https://www.itpro.com/strategy/28072/what-is-byod">bring your own device (BYOD)</a>, and obviously the recent surge in <a href="https://www.itpro.com/business/business-strategy/356096/remote-working-are-you-ready-for-the-new-normal" data-original-url="https://www.itpro.com/business/business-strategy/356096/remote-working-are-you-ready-for-the-new-normal">remote working</a>, MDM has become more and more popular in recent years. In particular, COVID-19 has led to a surge in the demand of this tool among businesses looking to take on MDM solutions. As the world of work is currently transforming into a hybrid model, it is probable this demand will continue or even grow, with UK businesses aiming to ensure endpoints distributed across their networks stay secure.</p><p>It is crucial for GDPR compliance to ensure your employees can only access the data they need, and that they are restricted from accessing other information. After all, organisations will be aiming to remain as compliant as possible to reduce the chance of getting a fine. Two ways that MDM systems can help businesses on their compliance journeys is by locking data if a device goes missing, or restricting data access for employees.</p><p>In addition to smartphones, MDM systems can manage laptops, tablets, and desktop PCs. This makes them extremely useful as they can manage cyber security risks across all workplace devices. For example, malware can be downloaded inadvertently in various ways, like through phishing attacks, and infects a number of devices regardless of their form. The best MDM systems out there will manage various devices at once, wiping or treating those infected with malware before the infection has time to spread.</p><p>Whatever your needs are from an MDM solution, there are many options available from a variety of providers. Here's a round-up of some of the best options, including offerings from IBM, Citrix and more.</p><h2 id="cisco-meraki">Cisco Meraki</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nvtZvH736DujziBbz4xzhD" name="" alt="A screenshot of Cisco Meraki's MDM software" src="https://cdn.mos.cms.futurecdn.net/nvtZvH736DujziBbz4xzhD.png" mos="https://cdn.mos.cms.futurecdn.net/nvtZvH736DujziBbz4xzhD.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Perhaps one of the most well-known MDM platforms, Cisco Meraki allows you to manage every type of device in your business from one dashboard. No matter what you need to monitor - be it Android and iOS <a href="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy" target="_blank" data-original-url="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy">smartphones</a>, or Linux, macOS and Windows PCs - you can do so. There's also an app for managing devices while not at your computer, monitoring usage and making sure all data is safe and sound.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mRGPzAS5b3aycfspJetZ3a" name="mRGPzAS5b3aycfspJetZ3a.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/mRGPzAS5b3aycfspJetZ3a.png" mos="https://cdn.mos.cms.futurecdn.net/mRGPzAS5b3aycfspJetZ3a.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The ultimate guide to going mobile for fire/emergency medical services</strong></p><p class="fancy-box__body-text">Get your free guide to going mobile for fire services and EMS</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/mobile/360506/how-to-go-mobile-for-emergency-medical-services" data-original-url="/hardware/mobile/360506/how-to-go-mobile-for-emergency-medical-services">FREE DOWNLOAD</a></p></div></div><p>Cisco Meraki offers a bumper feature set, enabling you to enforce device security policies, deploy software and apps, and perform <a href="https://www.itpro.com/remote-access/31297/how-to-choose-the-right-remote-support-software" target="_blank" data-original-url="https://www.itpro.com/remote-access/31297/how-to-choose-the-right-remote-support-software">remote troubleshooting</a> if any problems arise, monitoring calls and more on the devices across your network. Every device managed and monitored is regarded as a separate device, even if they're linked. This means you can, for example, allow certain apps to run on an employee's iPad but not on their linked smartphone.</p><p>Cisco Meraki enables all of this to happen over the network, so even if you're trying to manage remote employee devices, it's a breeze. You can keep tabs on everything without anyone needing to be on the same network. It’s also easy to test-drive the platform with a browser-based demo with slated network devices and users. Plus, you can request trial hardware and get technical support to help with setup.</p><p><strong>Pricing:</strong> <a href="https://meraki.cisco.com/en-uk/free-demo" target="_blank">Available upon request</a></p><h2 id="ibm-maas360">IBM MaaS360</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NQjWmvKgReFYFWdYjCfozB" name="" alt="A screenshot of IBM MaaS360 with IBM Watson" src="https://cdn.mos.cms.futurecdn.net/NQjWmvKgReFYFWdYjCfozB.png" mos="https://cdn.mos.cms.futurecdn.net/NQjWmvKgReFYFWdYjCfozB.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>IBM entered the MDM market following its acquisition of Fiberlink Communications back in 2013. Since then, Big Blue has been making some big improvements to its flagship MDM product. The service, which is powered by Watson AI, will easily integrate with existing IT infrastructure, enabling you to manage a diverse, complex endpoint and mobile environment.</p><p>IBM Maas360 also puts security at the forefront, securing and containing data accessed by users and keeping corporate apps and content separated while allowing for easy removal and access revocation. Its integrated threat defence also proactively shields corporate data.</p><p>IBM might not be the cheapest out there - especially since some of the services that you'd find bundled with other providers come at an additional cost - but with IBM's lengthy experience in enterprise security, you know you're getting a good quality solution for your money.</p><p><strong>Pricing:</strong> <a href="http://www.ibm.com/uk-en/security/mobile/maas360?p1=Search&p4=43700052322107500&p5=e&cm_mmc=Search_Google-_-1S_1S-_-EP_GB-_-ibm%20maas360_e&cm_mmca7=71700000064598003&cm_mmca8=kwd-304242267098&cm_mmca9=Cj0KCQjwuL_8BRCXARIsAGiC51B--c50enr6bAHNQt1QPr4A8mOKZ8EB---R8vJQZ-YjNsTKmYE00XEaAnumEALw_wcB&cm_mmca10=424818424209&cm_mmca11=e&gclid=Cj0KCQjwuL_8BRCXARIsAGiC51B--c50enr6bAHNQt1QPr4A8mOKZ8EB---R8vJQZ-YjNsTKmYE00XEaAnumEALw_wcB&gclsrc=aw.ds" target="_blank">From $4.00 (£3.32) per client device per month</a></p><h2 id="hexnode-mdm">Hexnode MDM</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QNDPdsbjW9ouVTLDMfuQEV" name="" alt="A screenshot of Hexanode's MDM solution in action" src="https://cdn.mos.cms.futurecdn.net/QNDPdsbjW9ouVTLDMfuQEV.png" mos="https://cdn.mos.cms.futurecdn.net/QNDPdsbjW9ouVTLDMfuQEV.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Hexnode MDM lets you provision and manage devices, and prides itself on a user-friendly design. Users can add their own devices by connecting to the network or by using a portal installed on your company's website or intranet. Their device will then be added using their Active Directory credentials.</p><p>Once the devices are added, you can manage them whether they're connected to the corporate network or being used remotely. That means you can push configuration settings to the device, restrict functionality, manage mobile applications (including blocking App Store downloads and implementing a black/whitelist), check and enforce compliance and even remotely lock and wipe devices.</p><p>Hexnode MDM also offers a 30-day free trial if you want to get give it a test run.</p><p><strong>Pricing:</strong> <a href="https://www.hexnode.com/mobile-device-management/pricing" target="_blank">From $1.08 (90p) per device/month</a></p><h2 id="soti-mobicontrol">Soti MobiControl</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yNSEh7qgf3iQKNCW38wQ3Z" name="" alt="A screenshot of the SOTI MobiControl MDM solution" src="https://cdn.mos.cms.futurecdn.net/yNSEh7qgf3iQKNCW38wQ3Z.png" mos="https://cdn.mos.cms.futurecdn.net/yNSEh7qgf3iQKNCW38wQ3Z.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Soti allows you to manage Android, iOS, Linux, macOS, and Windows devices from one place, for the entire lifecycle of the device within the organisation. They can be provisioned when first added to the company's fleet of devices, managed throughout their service and then wiped when it comes to retirement.</p><p>The platform was designed for use with ruggedised devices often used by fieldworkers and the healthcare, logistics, retail, and transport sectors.</p><p>The MDM platform can be installed on-premise or deployed on Soti's cloud. You can add devices to the platform using its Express Enrollment feature, which automatically delivers the settings, apps, and files a user needs over the air to get them up and running.</p><p><strong>Pricing:</strong> <a href="http://www.soti.net/products/mobicontrol" target="_blank">Available on request</a></p><h2 id="citrix-secure-private-access">Citrix Secure Private Access</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VJcTaxX8jgPBdDHaD6DFz9" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/VJcTaxX8jgPBdDHaD6DFz9.png" mos="https://cdn.mos.cms.futurecdn.net/VJcTaxX8jgPBdDHaD6DFz9.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Citrix Secure Private Access, formerly known as Citrix Endpoint Management, is a zero trust network access tool with MDM functions. It allows the containerisation of business apps and personal apps, making it best suited to BYOD workplaces. Every device, including desktop PCs, smartphones and tablets, can be managed from one centralised console and devices don't even need to be enrolled to benefit from MAM, too.</p><p>As well as allowing the device owner to use a device provisioned and managed by the organisation, Citrix Secure Private Access has also been designed to let multiple users have access to one mobile device. This is particularly useful for industries such as healthcare, where field workers and emergency service workers may need shared ownership of one device.</p><p>However, it's likely one device will need applications and service provisioned with different access rights and this can be set up simply with Secure Private Access's MAM capabilities. IT managers can also lock down the device depending on the network location, stopping staff from using certain features outside of the corporate network.</p><p><strong>Pricing:</strong> <a href="https://www.citrix.com/en-gb/products/citrix-endpoint-management" target="_blank">From $3 (£2.52) per device/month</a></p><h2 id="vmware-workspace-one">VMware Workspace ONE</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="D3vmqKmnTmJaqVcu5ruz8P" name="" alt="The VMWare Workspace One Airwatch mobile platform" src="https://cdn.mos.cms.futurecdn.net/D3vmqKmnTmJaqVcu5ruz8P.jpg" mos="https://cdn.mos.cms.futurecdn.net/D3vmqKmnTmJaqVcu5ruz8P.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>VMware Workspace ONE (formerly called Airwatch prior to its VMware acquisition) offers endpoint protection for all devices, regardless of the operating system, with full device management, whether it's a BYOD or shared corporate device.</p><p>You are able to deploy and manage any app via the platform's app catalogue, whether employees are trying to access them natively, on-device, via the web or remotely. The layered security across the individual user, endpoint, data, and network can all be centrally managed using the same mobility platform too.</p><p>Workspace ONE uses automation to carry out many everyday MDM tasks, which reduces the strain on IT staff. You don't have to manually provision or enrol devices - this happens without the need for any manpower, making it a perfect option for resource-stretched businesses.</p><p><strong>Pricing:</strong> <a href="https://www.vmware.com/products/workspace-one.html" target="_blank">From $1.66 (£1.39) per device/month</a></p><h2 id="the-future-of-mobile-device-management">The future of mobile device management</h2><p>With life now beginning to return to offices across the world, it’s never been more important to ensure your organisation’s workers have great security. It’s likely that this will keep being seen by IT departments as one of their biggest challenges too.</p><p>Part of this is because of how popular hybrid working has become in recent times. There have been a number of attempts to make this the mainstream, including by the likes of Salesforce, which decided in February 2021 to <a href="https://www.itpro.com/business-strategy/flexible-working/358571/salesforce-9-to-5-dead" data-original-url="https://www.itpro.com/business-strategy/flexible-working/358571/salesforce-9-to-5-dead">offer employees the choice of three models for working</a>. These were office-based in San Francisco, flex, or fully remote. This is a big step considering that approximately 18% of employees at the company were fully remote before the pandemic, <a href="https://www.itpro.com/business/business-operations/359803/at-least-half-of-all-salesforce-employees-to-work-from-home" data-original-url="https://www.itpro.com/business/business-operations/359803/at-least-half-of-all-salesforce-employees-to-work-from-home">compared to 50% by June 2021</a>.</p><p>Some companies have gone an extra step, such as Airbnb, <a href="https://www.itpro.com/business-strategy/flexible-working/367542/airbnb-bucks-hybrid-work-trend-with-work-anywhere" data-original-url="https://www.itpro.com/business-strategy/flexible-working/367542/airbnb-bucks-hybrid-work-trend-with-work-anywhere">which told employees</a> in April 2022 they can work from “anywhere”, regardless of the country they live in. The company’s new remote work policies stated that employees could also enjoy up to 90 days of work abroad.</p><p>Despite these benefits, combining in-office working with remote might be problematic when it comes to security. This is because the lines between what constitutes a home or work device inevitably blur, even if the organisation provided the employee with dedicated hardware. Importantly, it also involves workers regularly accessing their private networks at home, with the risk of falling victim to a wider variety of threats, and even transferring malicious software over to an organisation’s network when they work from the office. Companies not only have to think about adopting a clear BYOD policy, but also be extra vigilant when it comes to the security of their network.</p><p>With more employees making their way back to company property, even in a hybrid work model, MDM solutions are going to have a big role to play not only when it comes to security, but in GDPR compliance too. Bear in mind, however, this can come at a high cost. Decide which MDM option would be best for your business before investing anything. It’s also best to think about the scalability and price of the software, how good its security is, and how many devices or employees it’s able to support. Obviously, there are other things you’ll need to bear in mind before buying your ideal MDM solution, but this is a good place to start.</p><p>Of course, it would also be helpful to devise the appropriate MDM business plan on whether you are likely to see an ROI. However, security should be of paramount importance to any business. Failing to protect data can be catastrophic for a business, so there's no excuse not to take every measure to make sure your business stays afloat.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/7wsee1QgSFg" allowfullscreen></iframe></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android flaws decline in 2019 as iOS malware rises ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34349/android-flaws-decline-in-2019-as-ios-malware-rises</link>
                                                                            <description>
                            <![CDATA[ Flaws in the most popular operating systems, however, are just as dangerous as third-party bugs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6DuZqbHKj5fhwqC37wV2J4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qhyQMtB5hvtYQoQjTyKcEN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Sep 2019 11:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qhyQMtB5hvtYQoQjTyKcEN-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[mobile security]]></media:description>                                                            <media:text><![CDATA[mobile security]]></media:text>
                                <media:title type="plain"><![CDATA[mobile security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qhyQMtB5hvtYQoQjTyKcEN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The number of security bugs affecting Android devices has fallen sharply in the first half of this year, although the proportion of these which are deemed 'critical' has risen.</p><p>Up to June, there have been reports of 86 flaws affecting the Android operating system (OS), versus 611 flaws listed for the whole of 2018; suggesting this will decrease abruptly compared against previous years. The proportion of 'critical' flaws, on the other hand, rose from 49% in 2018 to 68% this year.</p><p>Meanwhile, <a href="https://www.itpro.com/mobile/33773/ios-13-release-date-features-news-and-more-apple-unveils-its-latest-os-with-dark-mode" target="_blank" data-original-url="https://www.itpro.com/mobile/33773/ios-13-release-date-features-news-and-more-apple-unveils-its-latest-os-with-dark-mode">Apple's iOS</a> saw a 25% rise in vulnerabilities detected compared to 2018, 155 for the first six months of the year, and almost double those found in the Android OS. The proportion of these considered critical is approximately 20%, however.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34334/android-phones-vulnerable-to-advanced-sms-phishing-attacks" data-original-url="/security/34334/android-phones-vulnerable-to-advanced-sms-phishing-attacks">Android phones vulnerable to advanced SMS phishing attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you" data-original-url="/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you">Android vs iOS: Which mobile OS is right for you?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone" data-original-url="/public-sector/26057/apple-vs-fbi-nsa-reveals-why-it-couldnt-hack-san-bernardino-iphone">Apple vs FBI: NSA reveals why it couldn't hack San Bernardino iPhone</a></p></div></div><p>Figures from ESET's <a href="https://www.welivesecurity.com/2019/09/05/balance-mobile-security-2019" target="_blank"><em>We Live Security</em></a> platform outline the state of mobile OS security for the first six months of the year; taking into account the number of vulnerabilities registered as well as incidents of malware detection.</p><p>As well as fewer bugs, Android has also experienced fewer malware detections in 2019. This figure declined 8% versus the first half of 2018 and 10% against the second half of last year, following a steady decline from a peak in 2016.</p><p>By contrast, iOS malware is on the rise, increasing a staggering 43% against the first half of 2018. The number of new malware variants remains low, however, which suggests that cyber criminals are more interested in developing ways to breach devices on Android, which has a larger number of users.</p><p>The research highlighted a number of prominent examples of malware incidents hitting devices in the first half of the year. Recent examples include one in which iPhone users were <a href="https://www.itpro.com/security/34116/google-discloses-slew-of-imessage-vulnerabilities" target="_blank" data-original-url="https://www.itpro.com/security/34116/google-discloses-slew-of-imessage-vulnerabilities">subject to a previously corrected bug being reopened by a faulty update</a> that allowed cyber criminals to jailbreak iOS.</p><p>Another prominent incident, which affected both systems, was a <a href="https://www.itpro.com/spyware/33632/whatsapp-call-hack-installs-spyware-on-users-phones" target="_blank" data-original-url="https://www.itpro.com/spyware/33632/whatsapp-call-hack-installs-spyware-on-users-phones">vulnerability with WhatsApp that allowed hackers to covertly install spyware</a> on users' phones and track their communications and location data.</p><p>"Although mobile systems have been designed with a security perspective and are sometimes safer than traditional technologies, we must not forget that the risks are still latent," said <em>We Live Security</em> researcher Denise Giusto Bili.</p><p>"Beyond favoritism, we must always keep in mind that no system is invulnerable and that education and prevention are inescapable to use mobile technologies safely."</p><p>Bili also warned that in addition to threats facing the two most widely-used mobile systems, there are multiplatform risks that are associated with third-party apps, for instance, <a href="https://www.itpro.com/security/31659/whatsapp-exploit-lets-hackers-manipulate-group-chat-messages" target="_blank" data-original-url="https://www.itpro.com/security/31659/whatsapp-exploit-lets-hackers-manipulate-group-chat-messages">another flaw in WhatsApp that allowed quoted messages to be altered</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android phones vulnerable to advanced SMS phishing attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34334/android-phones-vulnerable-to-advanced-sms-phishing-attacks</link>
                                                                            <description>
                            <![CDATA[ Researchers discover an attack vector that could once be only imagined in a "high-tech spy movie" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7a6Wbg8HgQtQtkBBSqFygv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/txe7Bd7AmMACkvsZFyQ2Mb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Sep 2019 10:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Android]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Google]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/txe7Bd7AmMACkvsZFyQ2Mb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android figurine]]></media:description>                                                            <media:text><![CDATA[Android figurine]]></media:text>
                                <media:title type="plain"><![CDATA[Android figurine]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/txe7Bd7AmMACkvsZFyQ2Mb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have found a fundamental security flaw in modern Android phones that facilitates advanced SMS phishing attacks.</p><p>Phones made by Huawei, LG, Samsung and Sony were all vulnerable to the attack, which involves an attacker tricking a user into accepting new phone settings that can reroute phone data back to the criminal.</p><p>Check Point researchers showed how attackers could leverage over-the-air provisioning (OTA) used by the affected phones</p><p>Check Point researchers also <a href="https://research.checkpoint.com/advanced-sms-phishing-attacks-against-modern-android-based-smartphones" target="_blank">discovered</a> that OTA, which is usually used by network operators to deploy network-specific settings to a new phone joining their network, can be hijacked using a $10 dongle.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/34095/huawei-p30-review-too-good-to-ban" data-original-url="/mobile/34095/huawei-p30-review-too-good-to-ban">Huawei P30 review: Too good to ban</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="/security/29093/what-is-phishing">What is phishing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/two-factor-authentication-2fa/32689/phishing-tool-that-bypasses-gmail-2fa-released-on-github" data-original-url="/two-factor-authentication-2fa/32689/phishing-tool-that-bypasses-gmail-2fa-released-on-github">Phishing tool that bypasses Gmail 2FA released on Github</a></p></div></div><p>The authentication methods used by OTA are limited, according to Check Point, and this limitation can be exploited to send messages which appear to be from the network operator to the user, but actually redirect internet traffic back to the attacker.</p><p>All affected phones allow weakly authenticated messages to reach the user, while Samsung additionally allows completely unauthenticated messages to reach its users.</p><p>Armed with a cheap dongle or a phone running in a modem mode, attackers can either send messages tailored for specific targets or sent out in bulk in a <a href="https://www.itpro.com/exploits/34009/thousands-of-sites-fall-to-magecart-spray-and-pray-attack" target="_blank" data-original-url="https://www.itpro.com/exploits/34009/thousands-of-sites-fall-to-magecart-spray-and-pray-attack">'spray and pray'</a> style of attack.</p><p>These specially crafted messages can change the MMS message server, proxy address, mail server, directory servers relating to contacts and calendars and browser homepage and bookmarks.</p><p>A message to a Samsung user will typically ask them if it can change the client provisioning settings. If a user accepts this after being taken through to the phone's settings without passing any authentication checks, then the malicious settings will be applied.</p><p>The attacker has a slightly tougher time with Huawei, LG and Sony phones. Of the two methods available, the first involves obtaining a victim's International Mobile Subscriber Identity (IMSI) number using a reverse IMSI lookup checker and once the IMSI has been acquired, a phishing attack can then be authenticated and deployed as easily as done on Samsung phones.</p><p>When an IMSI cannot be found, the attacker can instead send two messages, one which appears to be from the victim's network operator containing a PIN and the second malicious message, authenticated with the aforementioned PIN, asking to change the phone's settings. All a user would have to do is enter the PIN and the attack would be mounted.</p><p>"This is a demonstration of how sophisticated the bad guys are getting. Five years ago, this type of attack could have been included in the plot of some high-tech spy movie, but now it is being used by regular, run of the mill bad guys," said Erich Kron, security awareness advocate at KnowBe4.</p><p>"People should be very suspicious any time they receive an unsolicited text message that is asking them to enter a PIN or any other authorisation, even if it appears to come from the carrier.</p><p>"If they receive something like this, they should immediately contact the carrier through their customer service number and ask if this is legitimate," he added.</p><p>Since the researchers disclosed the vulnerabilities to the manufacturers in March 2019, Samsung and LG have both issued fixes.</p><p>Huawei said it's future Mate and <a href="https://www.itpro.com/mobile/34095/huawei-p30-review-too-good-to-ban" target="_blank" data-original-url="https://www.itpro.com/mobile/34095/huawei-p30-review-too-good-to-ban">P-series phones</a> will be sold with UI fixes to address the issue while Sony refused to acknowledge the vulnerability report at all.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ KNOB attack lets hackers insert themselves into your Bluetooth calls ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34226/knob-attack-lets-hackers-insert-themselves-into-your-bluetooth-calls</link>
                                                                            <description>
                            <![CDATA[ Vulnerability allows attackers to ‘completely break’ Bluetooth encryption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">78kYYpj4KD73CrkyRJpqDq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PasBDeeQLLHnCuyZ7cr4fc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Aug 2019 11:01:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PasBDeeQLLHnCuyZ7cr4fc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PasBDeeQLLHnCuyZ7cr4fc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/internet-of-things-iot/31507/what-is-a-bluetooth-mesh-network" data-original-url="/internet-of-things-iot/31507/what-is-a-bluetooth-mesh-network">What is a Bluetooth mesh network?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/encryption/32302/critical-vulnerabilities-ssd-encryption" data-original-url="/encryption/32302/critical-vulnerabilities-ssd-encryption">Researchers expose 'critical vulnerabilities' in SSD encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/33293/what-is-li-fi" data-original-url="/network-internet/33293/what-is-li-fi">What is Li-Fi?</a></p></div></div><p>Researchers have discovered a flaw in Bluetooth authentication protocols which allows hackers to listen in on conversations conducted via Bluetooth devices or to change the contents of file transfers.</p><p>The attack is codenamed KNOB, which stands for 'Key Negotiation Of Bluetooth', and was discovered by three international researchers: Kasper Rasmussen from Oxford University, Daniele Antonioli from the Singapore University of Technology and Design, and CISPA Helmholtz Center for Information Security's Nils Ole Tippenhauer.</p><p>The KNOB attack works by forcing the participants in Bluetooth handshake to use an <a href="https://www.itpro.com/encryption/33681/encrypting-a-small-business-why-remote-working-could-be-your-blindspot" target="_blank" data-original-url="https://www.itpro.com/encryption/33681/encrypting-a-small-business-why-remote-working-could-be-your-blindspot">encryption key</a> with just one byte of entropy, allowing an attacker to brute-force the key. They are then able to insert valid, cryptographically-signed data into the transfer, or to eavesdrop on data (including the audio of phone calls) being passed between devices.</p><p>"As a result, the attacker completely breaks Bluetooth BR/EDR security without being detected," the researchers wrote in the technical paper explaining the flaw.</p><p>KNOB attacks are completely undetectable to the victims, as it attacks the key negotiation itself. It also doesn't violate the agreed Bluetooth industry standards, as one byte is the minimum level of entropy permitted by all BR/EDR standards, which also do not require that key negotiation protocols are secured. In short, this means that the firmware of any standard-compliant Bluetooth chip is vulnerable.</p><p>The researchers tested the exploit on 17 different Bluetooth chips across 24 different devices, including chips from Apple, Intel, <a href="https://www.itpro.com/acquisition/34172/broadcom-reportedly-set-to-acquire-symantecs-enterprise-business" target="_blank" data-original-url="https://www.itpro.com/acquisition/34172/broadcom-reportedly-set-to-acquire-symantecs-enterprise-business">Broadcom</a> and Qualcomm. All the tested devices were found to be at the mercy of KNOB attacks. The vulnerability was disclosed to the Bluetooth industry - via the Bluetooth Special Interest Group (SIG), the CERT Coordination Centre and the International Consortium for Advancement of Cybersecurity on the Internet - in November last year.</p><p>"After we disclosed our attack to industry in late 2018, some vendors might have implemented workarounds for the vulnerability on their devices," the researchers said. "So the short answer is: if your device was not updated after late 2018, it is likely vulnerable. Devices updated afterwards might be fixed."</p><p>The vulnerability, which has been designated as CVE-2019-9506, has now been addressed by the Bluetooth SIG, which has updated the core Bluetooth specification to recommend a minimum of 7 bytes of entropy for encryption keys. While it is urging vendors to patch their products to prevent the attack, the SIG has also advised that the chances of hackers exploiting the vulnerability in the wild are slim.</p><p>"For an attack to be successful, an attacking device would need to be within wireless range of two vulnerable Bluetooth devices that were establishing a BR/EDR connection," an advisory note from the Bluetooth SIG read. "If one of the devices did not have the vulnerability, then the attack would not be successful. The attacking device would need to intercept, manipulate, and retransmit key length negotiation messages between the two devices while also blocking transmissions from both, all within a narrow time window."</p><p>"There is no evidence that the vulnerability has been exploited maliciously and the Bluetooth SIG is not aware of any devices implementing the attack having been developed, including by the researchers who identified the vulnerability."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than 1,000 Android apps "deceptively" harvest personal data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/33980/more-than-1000-android-apps-deceptively-harvest-personal-data</link>
                                                                            <description>
                            <![CDATA[ The apps circumvent Android permissions designed to keep personal data out of the hands of developers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wMAKopzKUVLXST9ySU36Xu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UBqTWTxrq33MCiqWTVyVT3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Jul 2019 11:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UBqTWTxrq33MCiqWTVyVT3-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Google Android figurine stood on a wooden table]]></media:description>                                                            <media:text><![CDATA[A Google Android figurine stood on a wooden table]]></media:text>
                                <media:title type="plain"><![CDATA[A Google Android figurine stood on a wooden table]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UBqTWTxrq33MCiqWTVyVT3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have discovered more than 1,000 Android apps have the power to share and receive personal information even when the user explicitly forbids the collection of data.</p><p>The <a href="https://www.ftc.gov/system/files/documents/public_events/1415032/privacycon2019_serge_egelman.pdf" target="_blank">findings</a> were presented to attendees at PrivacyCon 2019 in the US, and they don't just focus on obscure apps. Indeed, big name firms including Disney and Samsung were cited for releasing apps that flout the privacy conventions users have come to expect.</p><p>All of the affected apps share one commonality - they all run on the same software developer kit (SDK). The one in question here is made by Chinese tech giant <a href="https://www.itpro.com/mobile/30121/qualcomm-and-baidu-join-forces-to-work-on-snapdragon-powered-ai-tech" target="_blank" data-original-url="https://www.itpro.com/mobile/30121/qualcomm-and-baidu-join-forces-to-work-on-snapdragon-powered-ai-tech">Baidu</a> with help from an analytics firm called Salmonads.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/android/19905/best-android-apps" data-original-url="/android/19905/best-android-apps">Best Android apps 2019: From storage and security to communication and productivity</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-security/30466/secure-your-wi-fi-against-hackers-in-10-steps" data-original-url="/network-security/30466/secure-your-wi-fi-against-hackers-in-10-steps">Secure your Wi-Fi against hackers in 10 steps</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/28240/the-5-best-business-apps" data-original-url="/mobile/28240/the-5-best-business-apps">The 5 best business apps to use in 2019</a></p></div></div><p>SDKs are sets of tools given to developers to make building applications easier - like a framework on which to base the project instead of having to code it all from scratch. It's like if all VW Polos, Audi S3s and Ford Focus' were built using the same axel - they're all different but share the same backbone.</p><p>Let's imagine there are two apps: App 1 and App 2. Both are built on the same Baidu SDK but the user has revoked permissions for App 1 to collect personal data. The user hasn't revoked App 2's data collection permissions, though. So, because of this, App 1 can still gather data from App 2's collection as they're both built on the same SDK.</p><p>In terms of what data has actually been collected, it's a bit of a mixed bag. Device MAC addresses were the most pervasively collected forms of data, but router MAC addresses and device IMEI numbers were also collected. In one particular case, GPS data was also gathered.</p><p>The app that collected GPS data is called Shutterfly and has been downloaded more than 138,000 times on the Google Play store at the time of publication. It collected GPS data using EXIF metadata from user images and sent it back to its own servers with no location permission.</p><p>"While this app may not be intending to circumvent the permission system, this technique can be exploited by a malicious actor to gain access to the user's location," read the study. "Whenever a new picture is taken by the user with geolocation enabled, any app with read access to the photo library can learn the user's precise location when said picture was taken.</p><p>"Furthermore, it also allows obtaining historical geolocation fixes with timestamps from the user, which could later be used to infer sensitive information about that user," it added.</p><p>In reference to the apps acquiring <a href="https://www.itpro.com/network-security/30466/secure-your-wi-fi-against-hackers-in-10-steps" target="_blank" data-original-url="https://www.itpro.com/network-security/30466/secure-your-wi-fi-against-hackers-in-10-steps">MAC address information</a>, the researchers said <a href="https://www.itpro.com/android/19905/best-android-apps" target="_blank" data-original-url="https://www.itpro.com/android/19905/best-android-apps">Android</a> natively protects access device and router MAC addresses with separate permissions. Regardless, they still observed apps accessing the addresses without having the permissions.</p><p>The apps gained access to the addresses with side-channels, using C++ native code to invoke a number of unguarded UNIX system calls. These methods were referred to as "deceptive" which could mislead even the most diligent user.</p><p>The US' Federal Trade Commission (FTC) has fined mobile operators and third-party libraries for exploiting side-channels and using MAC addresses to infer a user's location.</p><p>The researchers said that with the next version of the mobile operating system Android Q which is currently in beta, some of the issues outlined by their findings <a href="https://developer.android.com/preview/privacy/data-identifiers#device-identifiers" target="_blank">will be fixed</a>, but that might not be good enough.</p><p>Android OS updates are not mandatory and many users, <a href="https://developer.android.com/about/dashboards" target="_blank">according to statistics</a>, aren't very diligent when it comes to upgrading to the latest version - just 10.4% of Android users are on the latest Android 9 Pie installation, for example. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android vs iOS: Which mobile OS is right for you? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you</link>
                                                                            <description>
                            <![CDATA[ We look at design, security, compatibility and more to see which OS best fits your business ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rVLbZzqsx8Vf74zYk1xuxp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4ZjaSnNTyEWXDph8eJxQzZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jun 2019 10:40:00 +0000</pubDate>                                                                                                                                <updated>Wed, 30 Nov 2022 12:05:00 +0000</updated>
                                                                                                                                            <category><![CDATA[iOS]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Apple]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4ZjaSnNTyEWXDph8eJxQzZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Android and Apple logos side by side]]></media:description>                                                            <media:text><![CDATA[The Android and Apple logos side by side]]></media:text>
                                <media:title type="plain"><![CDATA[The Android and Apple logos side by side]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4ZjaSnNTyEWXDph8eJxQzZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Loyalty to an operating system can sometimes be compared to that of a football team or a political party. And this is certainly the case when it comes to Android vs iOS. Most iPhone users are Apple-til-they-die and can be keen on pointing this out at any given moment. These are the 'brand lovers' that wittingly chose vendor lock-in and have MacBook's and iPads to go with their iOS-based smartphones. </p><p>While there are many solid reasons to be an Apple-ite, the world's most popular mobile operating system is actually Android. With Google's OS, user can choose pretty much any other smartphone manufacturer (except Huawei) and arguably enjoy more interoperability with different laptop, tablet and smartphone ranges. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy" data-original-url="/mobile/23617/the-best-smartphones-to-buy">Best business smartphones 2023: The top handsets from Apple, Samsung, Google and more</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/33773/ios-13-release-date-features-news-and-more-apple-unveils-its-latest-os-with-dark-mode" data-original-url="/mobile/33773/ios-13-release-date-features-news-and-more-apple-unveils-its-latest-os-with-dark-mode">iOS 13 release date, features, news and more: Apple unveils its latest OS with dark mode</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/android/28189/how-to-build-android-apps" data-original-url="/android/28189/how-to-build-android-apps">How to build Android apps</a></p></div></div><p>You may have one or the other as a consumer, but what should you do as a business? Do you kit your employees out with the best of Apple or do you sign them up to Google's Android and let them have a bit more device choice?</p><p>Unfortunately, there's a lot more to it than that. Security is arguably the most pressing concern for businesses – particularly as most will have been working remotely and look set to continue doing so. Then there are key details such as cost, compatibility, how easy it is to instal, use and learn. You may be an Apple aficionado, but does Jeff in accounting know his way around an iPad? </p><p>These are the consideration you need to make when choosing a business-wide operating system. Just like being Liverpool or Everton, Labour or Tory, you can be Apple or Android (or neither if you find a niche OS). </p><h2 id="android-vs-ios-hardware-choice">Android vs iOS: Hardware choice</h2><p>Although we are mainly focusing on the operating systems, your choice will almost certainly be led by the hardware they support. It is very unlikely that a consumer will choose an iPhone because they prefer iOS as it is usually a case of having iOS because it is on the iPhone they want. </p><p>So, the choice of hardware is a little more limited on Apple's iOS as it only offers iPhones. However, now is a pretty good time to go for one as they've had a strong couple of years. The current crop includes the <a href="https://www.itpro.com/mobile/mobile-phones/369417/apple-iphone-14-pro-review-a-dynamic-phone-from-top-to-bottom" target="_blank" data-original-url="https://www.itpro.com/mobile/mobile-phones/369417/apple-iphone-14-pro-review-a-dynamic-phone-from-top-to-bottom">iPhone 14 Pro</a> –with <a href="https://www.itpro.com/security/369044/the-iphone-security-features-that-come-with-ios-16" target="_blank" data-original-url="https://www.itpro.com/security/369044/the-iphone-security-features-that-come-with-ios-16">iOS 16</a> – which has some of the best camera and video technology around. The design is also pretty much the same as the <a href="https://www.itpro.com/mobile/mobile-phones/361428/apple-iphone-13-review" target="_blank" data-original-url="https://www.itpro.com/mobile/mobile-phones/361428/apple-iphone-13-review">iPhone 13</a> and <a href="https://www.itpro.com/mobile/mobile-phones/358533/apple-iphone-12-review-cutting-edge-nostalgia" target="_blank" data-original-url="https://www.itpro.com/mobile/mobile-phones/358533/apple-iphone-12-review-cutting-edge-nostalgia">iPhone 12</a>, both of which are very high-quality devices – with these, you can also get an <a href="https://www.itpro.com/mobile/mobile-phones/359545/iphone-12-mini-review-mini-phone-major-fun" target="_blank" data-original-url="https://www.itpro.com/mobile/mobile-phones/359545/iphone-12-mini-review-mini-phone-major-fun">iPhone mini</a>. There is also the more budget-friendly <a href="https://www.itpro.com/operating-systems/ios/356703/apple-iphone-se-2020-review-cheap-at-twice-the-price" target="_blank" data-original-url="https://www.itpro.com/operating-systems/ios/356703/apple-iphone-se-2020-review-cheap-at-twice-the-price">iPhone SE</a>, which has an older design and none of the fancy features. </p><p>With more than 1 billion of them in circulation, the iPhone is the world's most popular smartphone, however, this doesn't automatically mean iOS is the most popular mobile OS. That title is taken by Android and the main reason for this is because it works with more manufacturers. So while iOS only works on Apple iPhones, Android is used by Samsung, Sony, Google (of course), OnePlus... practically every other brand. </p><p>Overall levels of choice is the biggest bonus of being on Android and not just choice of brand - there are more different types of handsets available here, from standard 6.1in screens to massive phablets, such as the <a href="https://www.itpro.com/mobile/mobile-phones/367700/samsung-galaxy-s22-ultra-review" target="_blank" data-original-url="https://www.itpro.com/mobile/mobile-phones/367700/samsung-galaxy-s22-ultra-review">Samsung Galaxy S22 Ultra</a>. Plus, it gets bigger still as you have a number of foldable devices on offer, such as the Z Fold 4 and the Huawei Mate Xs2. </p><h2 id="android-vs-ios-design">Android vs iOS: Design</h2><p>The latest version of Google's OS is a far cry from the days of clunky Android KitKat. Android 12 is a more slick and gorgeous experience with a plethora of features that help it to adapt to users' preferences. The Material You interface allows users to change themes and colours to their own preferences, even adapting from their own wallpaper uploads – a feature that isn't available on iOS.</p><p>However, Apple's OS has an established reputation for its simplicity and ease of use. The learning curve for new users is astonishingly low, and its commands and functions are simple to pick up. The design is based heavily on the idea that most users don't really need all the adjustable bells and whistles that platforms have normally offered. Google's Android system, meanwhile, suffers from its reputation as being a little confusing to navigate. By contrast, this offers an insurmountable depth of customisation, but much of this is hidden deep inside menus and interfaces.</p><p>One of the main issues with designing your user interface to be overly simplified, however, is that it normally comes at the cost of functionality. By default, iOS just doesn't give you the kind of space to adjust your user interface, or its functionality, to make it stand out in the same way you can with Android devices. Google's OS is so much more feature-rich, offering greater customisation options and an array of settings to tweak your device to fit your precise needs.</p><p>While iOS on iPhones looks great, it has conventionally shone on tablets where the software can take advantage of powerful multitasking features supported by superb Apple processors. The laptop-style experience you can create on an iOS tablet is simply far superior to anything an Android unit can offer. Having said that, however, <a href="https://www.itpro.com/operating-systems/33763/apple-reveals-ipados-at-wwdc19" target="_blank" data-original-url="https://www.itpro.com/operating-systems/33763/apple-reveals-ipados-at-wwdc19">Apple will soon roll out a dedicated iPadOS</a>, breaking free of the iOS mould with specially-tailored software.</p><h2 id="android-vs-ios-compatibility">Android vs iOS: Compatibility</h2><p>The iPhone is the most popular device in the world, so it's absolutely no surprise that software makers and accessory manufacturers generally choose to prioritise it over Android. This means if you've got an Apple device, you can all but guarantee whatever app, platform, plugin or attachment you want to use will be supported – though there are some companies that take issue with its <a href="https://www.itpro.com/software/development/357249/spotify-and-epic-take-on-apples-30-app-tax" target="_blank" data-original-url="https://www.itpro.com/software/development/357249/spotify-and-epic-take-on-apples-30-app-tax">30% app store tax</a>, so not all are available. </p><p>Another potential issue for some users will be the fact that Apple has chosen to remove the headphone jack on later devices. This isn't a major problem, given that there's a Lightning to 3.5mm jack adapter supplied in the box and Bluetooth headphones are widely available. And although some devices, such as the Samsung <a href="https://www.itpro.com/mobile/mobile-phones/354749/samsung-galaxy-s20-hands-on-review-another-slam-dunk" target="_blank" data-original-url="https://www.itpro.com/mobile/mobile-phones/354749/samsung-galaxy-s20-hands-on-review-another-slam-dunk">Galaxy S20</a>, have ditched the headphone jack too, an Android device may be a better option if you're dead set on the 3.5mm port – though it is very rare to see one at all.</p><p>Connectivity is a consideration if you want a <a href="https://www.itpro.com/desktop-hardware/21984/usb-type-c-everything-you-need-to-know" data-original-url="https://www.itpro.com/desktop-hardware/21984/usb-type-c-everything-you-need-to-know">USB Type-C</a> connection as that is the default for seemingly all modern Android devices. Apple's handsets are all on its lightning cables, though <a href="https://www.itpro.com/hardware/369150/apple-must-get-behind-the-eus-usb-c-decision-or-be-left-behind" data-original-url="https://www.itpro.com/hardware/369150/apple-must-get-behind-the-eus-usb-c-decision-or-be-left-behind">EU court rulings</a> may change that for future iPhones. </p><h2 id="android-vs-ios-security">Android vs iOS: Security</h2><p>Mobile security is too often overlooked by businesses, but if you're issuing devices to your employees, you should make certain that they're as secure as humanly possible. The list of vulnerabilities, exploits and other security flaws that have been discovered in the Android OS is <a href="https://www.itpro.com/android/28291/android-smartphones-found-with-pre-installed-malware" target="_blank" data-original-url="https://www.itpro.com/android/28291/android-smartphones-found-with-pre-installed-malware">long and extensive</a>, as is the list of <a href="https://www.itpro.com/malware/28567/two-million-android-devices-hit-by-google-play-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28567/two-million-android-devices-hit-by-google-play-malware">malware-riddled apps</a> found on the Google Play Store.</p><p>iOS benefits from a better reputation, but it's far from unhackable. Recent notable flaws include the <a href="https://www.itpro.com/security/30112/apple-rapidly-squashes-ios-112-homekit-bug" target="_blank" data-original-url="https://www.itpro.com/security/30112/apple-rapidly-squashes-ios-112-homekit-bug">HomeKit bug</a> and <a href="https://www.itpro.com/information-security-infosec/30324/apple-is-the-latest-firm-to-be-hit-by-class-action-lawsuit-for" target="_blank" data-original-url="https://www.itpro.com/information-security-infosec/30324/apple-is-the-latest-firm-to-be-hit-by-class-action-lawsuit-for">the Meltdown/Spectre debacle</a>. Instances of major exploits in Apple's devices are much, much fewer than on Android, however, and it benefits from faster software rollouts, too. Apple can push updates to all of its handsets directly, whereas Android users must wait until their phone maker has implemented a version of Google's update that works with its own Android skin. </p><h2 id="android-vs-ios-verdict">Android vs iOS: Verdict</h2><p>Android has millions of fans around the world, and with good reason; it's matured into a powerful and versatile operating system, with heaps of functionality. With time, the OS has offered a smoother user experience and a more aesthetically-designed interface too. However, for business devices, the fact is that Apple's software remains king of the hill.</p><p>iOS is slick, easy to use, good-looking and boasts absolutely stellar security and privacy features. While it's not without its flaws, the benefits far outweigh the disadvantages, and for corporate devices, iOS should still be your first port of call.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nokia 9 PureView fingerprint scanner 'can be fooled with a packet of gum' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/33503/nokia-9-pureview-fingerprint-scanner-can-be-fooled-with-a-packet-of-gum</link>
                                                                            <description>
                            <![CDATA[ The latest software update has seemingly exacerbated pre-existing issues with Nokia's biometric security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nuNJDs3vm19uEiyMcD81oz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UFeboqFwJJXKAE73iAKthY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Apr 2019 11:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UFeboqFwJJXKAE73iAKthY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A man chewing gum while holding a mobile handset device]]></media:description>                                                            <media:text><![CDATA[A man chewing gum while holding a mobile handset device]]></media:text>
                                <media:title type="plain"><![CDATA[A man chewing gum while holding a mobile handset device]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UFeboqFwJJXKAE73iAKthY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A significant firmware update to Nokia's flagship handset has seemingly exacerbated widely-reported issues with the Nokia 9 PureView's fingerprint scanner.</p><p>With version 4.22 came a number of sweeping changes to the <a href="https://www.itpro.com/mobile/33205/nokia-9-pureview-hands-on-review-a-camera-heavy-phone-thats-so-last-year" target="_blank" data-original-url="https://www.itpro.com/mobile/33205/nokia-9-pureview-hands-on-review-a-camera-heavy-phone-thats-so-last-year">Nokia 9 PureView</a>, including an improved user interface (UI) and better functionality. This aimed to address a number of problems reported at launch, including an in-screen fingerprint scanner that required a significant push of the finger to register.</p><p>But these issues have seemingly become much worse after the update rolled out last week. This has been illustrated by one Twitter user unlocking the device with somebody else's finger, and then just a packet of chewing gum. They also alleged the PureView can be unlocked using a coin, or leather gloves.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1120051077905362944"></a></p></blockquote><div class="see-more__filter"></div></div><p>Among the Nokia 9 PureView's greatest strengths is a five-lens camera setup, and a unique Qualcomm Snapdragon 845 processor made especially to cope with this configuration. But its imperfect in-screen fingerprint scanner was among the most widely-cited gripes when <em>IT Pro</em> and other publications handled the device.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/33205/nokia-9-pureview-hands-on-review-a-camera-heavy-phone-thats-so-last-year" data-original-url="/mobile/33205/nokia-9-pureview-hands-on-review-a-camera-heavy-phone-thats-so-last-year">Nokia 9 PureView hands-on review: A camera-heavy phone that's so last year</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/biometrics/30972/is-the-hype-around-biometrics-justified" data-original-url="/biometrics/30972/is-the-hype-around-biometrics-justified">Is the hype around biometrics justified?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31421/biometrics-commissioner-unimpressed-by-uk-home-offices-strategy-for-the" data-original-url="/policy-legislation/31421/biometrics-commissioner-unimpressed-by-uk-home-offices-strategy-for-the">Biometrics Commissioner unimpressed by UK Home Office's strategy for the tech</a></p></div></div><p>The Android Pie V4.22C update, released on Thursday, was also supposed to address slow UI issues when using the camera, as well as reported issues affecting the facial recognition unlock feature.</p><p>The user that reported the flaw, Decoded Pixel, said their device was on the latest April security update, using a UK SIM and on the Virgin Mobile network. They conceded this could also be a hardware defect with their specific device.</p><p>While many in the security industry have <a href="https://www.itpro.com/security/33048/popular-password-managers-found-to-have-serious-flaws" target="_blank" data-original-url="https://www.itpro.com/security/33048/popular-password-managers-found-to-have-serious-flaws">highlighted major weaknesses in password security</a>, this represents how easily layers of biometric security can be bypassed if supported with faulty software.</p><p>The technology underlining biometric security in smartphones, meanwhile, is relatively new and by all means a work in progress. The <a href="https://www.itpro.com/mobile-phones/33125/huawei-mate-20-pro-review-a-fire-breathing-dragon" target="_blank" data-original-url="https://www.itpro.com/mobile-phones/33125/huawei-mate-20-pro-review-a-fire-breathing-dragon">Huawei Mate 20 Pro</a> was similarly marred by a glitchy in-screen fingerprint scanner upon reviewed, albeit not on the same scale as the Nokia 9 PureView's issues.</p><p><em>IT Pro</em> approached Nokia for a statement but did not hear back at the time of writing. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Samsung Galaxy S10’s ultrasonic sensor fooled by fake finger ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/33393/samsung-galaxy-s10-s-ultrasonic-sensor-fooled-by-fake-finger</link>
                                                                            <description>
                            <![CDATA[ Samsung’s in-display fingerprint reader can be hacked ‘in 15 minutes’ ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3gqL4DYxmgwRuyv2LEBZLc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SNKxABmppo5vTsRBecsnK3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Apr 2019 09:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SNKxABmppo5vTsRBecsnK3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SNKxABmppo5vTsRBecsnK3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/mobile/33324/samsung-galaxy-s10-review-a-truly-stellar-smartphone" target="_blank" data-original-url="https://www.itpro.com/mobile/33324/samsung-galaxy-s10-review-a-truly-stellar-smartphone">Samsung Galaxy S10</a>'s 'ultrasonic' in-display fingerprint reader can be easily unlocked with a 3D-printed fingerprint, allowing hackers to break through the device's biometric security.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/printers/28027/what-is-3d-printing" data-original-url="/printers/28027/what-is-3d-printing">What is 3D printing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id" data-original-url="/mobile/20728/how-secure-apples-touch-id">How secure is Apple's Touch ID?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="/security/29705/what-are-biometrics">What are biometrics?</a></p></div></div><p>The exploit was discovered by a Reddit user going by the names of 'darkshark9', who cloned his own fingerprint from a photograph of the print left on a wine glass. Using common software tools Adobe Photoshop and Autodesk 3ds Max, he created an accurate replica of the print using a home 3D printer costing less than 400.</p><p>In a proof-of-concept uploaded to <a href="https://imgur.com/gallery/8aGqsSu" target="_blank">Imgur</a>, darkshark9 showed the device being unlocked by the fake print, stating that "the 3D print will unlock my phone...in some cases just as well as my actual finger does".</p><div><blockquote><p>I attempted to fool the new Samsung Galaxy S10's ultrasonic fingerprint scanner by using 3d printing. I succeeded.</p></blockquote></div><p>"If I steal someone's phone, their fingerprints are already on it," he explained. "I can do this entire process in less than three minutes and remotely start the 3D print so that it's done by the time I get to it. Most banking apps only require fingerprint authentication so I could have all of your info and spend your money in less than 15 minutes if your phone is secured by fingerprint alone."</p><p>The photo used in the exploit was taken with the S10+ itself, but he also theorised that by using a higher-quality DSLR camera, you could steal someone's digit "from across a room... or further".</p><p>The S10's in-display fingerprint reader was one of the main selling points of the new device, with Samsung saying its biometric security "provides a high level of protection for sensitive data". However, most security experts agree that using biometric security as a primary unlock method is less secure than a password or PIN.</p><p>Multiple tests have shown that the facial recognition technology used to unlock many smartphones <a href="https://www.bleepingcomputer.com/news/security/samsung-galaxy-s10-face-recognition-can-easily-be-bypassed" target="_blank">is not foolproof</a>, and Samsung itself advises during the setup of facial recognition that it is "considered less secure than other lock types".</p><p>However, when we reached out to Samsung, the company dismissed concerns about the hack, calling the phone's security "vault-like".</p><p>"The Galaxy S10's in-display Ultrasonic Fingerprint Scanner offers vault-like security that has been developed through rigorous testing to provide the level of accuracy and prevent against attempts to compromise its security, such as images of a person's fingerprint."</p><p>Samsung argued that the hack wasn't a threat, as it required using professional software and a 3D-printer, and that the copy "could only have been made under a very rare combination of circumstances". Both pieces of software used in the hack offer free trials, while the 3D printer used is available for less than 400, making it comparatively easy for even an amateur hacker to assemble the necessary toolkit.</p><p>"If at any time there is a potential vulnerability identified, we will act promptly to investigate and resolve the issue," Samsung said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 36 vulnerabilities in LTE 4G standard could enable data interception ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/33303/36-vulnerabilities-in-lte-4g-standard-could-enable-data-interception</link>
                                                                            <description>
                            <![CDATA[ 'Fuzzing' tool used by researchers to find exploits ranging from spoof SMS messages to disconnecting victims from networks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j87yC97G67PTix1UHNXmUd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z2Qsf4LwCsEzMV7m4ufML8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Mar 2019 11:07:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z2Qsf4LwCsEzMV7m4ufML8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[4G LTE mobile]]></media:description>                                                            <media:text><![CDATA[4G LTE mobile]]></media:text>
                                <media:title type="plain"><![CDATA[4G LTE mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z2Qsf4LwCsEzMV7m4ufML8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have discovered a collection of flaws in the Long-Term Evolution (LTE) standard, which could allow an attacker to send spoof messages and intercept data traffic.</p><p>A team with the Korea Advanced Institute of Science and Technology Constitution (KAIST) have discovered 51 vulnerabilities with the 4G standard, including 15 known issues and 36 previously undiscovered flaws.</p><p>They discovered this set of flaws using a code-testing technique known as 'fuzzing'. The KAIST researchers used a tool dubbed 'LTEFuzz' to feed large amounts of random data into identified processes to test them for potential anomalies.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/28105/4g-vs-5g-whats-the-difference" data-original-url="/mobile/28105/4g-vs-5g-whats-the-difference">4G vs 5G - what's the difference?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/32893/5g-security-concerns-persist-with-new-research-pointing-to-critical-flaw" data-original-url="/mobile/32893/5g-security-concerns-persist-with-new-research-pointing-to-critical-flaw">5G security concerns persist with new research pointing to critical flaw</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/32677/t-mobile-pokes-fun-at-att-for-labelling-its-4g-service-as-5g" data-original-url="/network-internet/32677/t-mobile-pokes-fun-at-att-for-labelling-its-4g-service-as-5g">T-Mobile pokes fun at AT&T for labelling its 4G service as 5G</a></p></div></div><p>The vulnerabilities unearthed span a broad spectrum, varying in nature and severity. They range from a flaw that could allow an attacker to disconnect a victim from their mobile network, to one that permits the eavesdropping and manipulation of data communications.</p><p>Tests were conducted across several devices on two high-profile mobile network operators. The KAIST team was intrigued by the fact that on the same operator, two core networking components from different vendors could present different vulnerabilities. The same was also true for two components from a single vendor, but deployed across different operators.</p><p>The full list of vulnerabilities discovered can be found at the foot of the team's <a href="https://syssec.kaist.ac.kr/pub/2019/kim_sp_2019.pdf" target="_blank">16-page report</a>, which they are planning to present publicly at the IEEE Symposium on Security and Privacy in May.</p><p>"LTEFuzz successfully identified 15 previously disclosed vulnerabilities and 36 newvulnerabilities in design and implementation among the different carriers and device vendors," the researchers noted.</p><p>"The findings were categorized into five vulnerability types. We also demonstrated several attacks that can be used for denying various LTE services, sending phishing messages, and eavesdropping/manipulating data traffic."</p><p>LTE is a networking standard that offers slightly slower speeds than 'true 4G', but is widely used by network operators and marketed as 4G. However, as the hype behind 5G continues to gain momentum in 2019, researchers have been discovering a series of flaws in the protocols that underpin the next-gen technology.</p><p>Academics in February, for example, <a href="https://www.itpro.com/network-internet/33081/flaws-in-4g-and-5g-could-allow-attackers-to-launch-dos-attacks-and-track" target="_blank" data-original-url="https://www.itpro.com/network-internet/33081/flaws-in-4g-and-5g-could-allow-attackers-to-launch-dos-attacks-and-track">discovered three flaws in 5G that exploit a handset's paging protocol</a>, allowing an attacker to track somebody's location, spoof text messages and block messages altogether.</p><p>But as manufacturers gear up to launch a wave of 5G-ready handsets, 4G will continue to be used by a vast cross-section of the public and businesses in the UK.</p><p>The KAIST researchers said they have no plans to release their LTEFuzz tool in any public capacity because it can be used for malicious purposes. The team does, however, plan to share LTEFuzz with mobile network operators and device vendors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions hit by major Android-based malware campaigns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/malware/33227/millions-hit-by-android-simbad-operation-sheep-campaigns</link>
                                                                            <description>
                            <![CDATA[ Dozens of 'innocent' apps are being infected through the development supply chain ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4W8yA8VDK3i5yPpKgYhYBS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/e8YNzz5jgFMPhzPmLHRFGA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Mar 2019 12:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/e8YNzz5jgFMPhzPmLHRFGA-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware on an Android smartphone]]></media:description>                                                            <media:text><![CDATA[Malware on an Android smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[Malware on an Android smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/e8YNzz5jgFMPhzPmLHRFGA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have outlined two separate malicious campaigns that have collectively infected more than 200 Android apps that have surpassed the 250 million download milestone. </p><p>Both campaigns, which centre on adware and data-scraping respectively, are targeting Android users only, and have infected a host of applications by fooling developers into using malicious software development kits (SDKs).</p><p>The more prominent campaign of the two, dubbed '<a href="https://research.checkpoint.com/simbad-a-rogue-adware-campaign-on-google-play" target="_blank">SimBad</a>' because it primarily affects simulation games, has infected 206 apps which have been downloaded a combined 150 million times, according to Check Point Research.</p><p>The malware itself lives in the ad-related 'RXDroider' SDK, provided by 'addroider.com' and adopted by a swathe of developers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32669/whatsapp-gold-scam-returns-with-martinelli-malware-threat" data-original-url="/security/32669/whatsapp-gold-scam-returns-with-martinelli-malware-threat">WhatsApp Gold scam returns with 'martinelli' malware threat</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/android/28184/the-best-antivirus-for-android-phones" data-original-url="/android/28184/the-best-antivirus-for-android-phones">Best antivirus for Android 2021: Bitdefender, Norton, Kaspersky and more</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/google-android/31590/google-blocks-cryptocurrency-miners-from-play-store" data-original-url="/google-android/31590/google-blocks-cryptocurrency-miners-from-play-store">Google blocks cryptocurrency miners from Play store</a></p></div></div><p>Once the user downloads and installs one of the infected apps, SimBad registers itself to the device and is allowed to perform actions autonomously. After installation, the malware then connects with the command and control server to receive orders. These may range from opening a browser with a given URL to removing the app icon from the launcher.</p><p>The app's three-pronged capabilities include showing ads, opening phishing pages, and exposing users to other applications. The attackers are also able to install a remote application from a designated server, allowing them to further infect users with malware at their discretion.</p><p>"With the capabilities of showing out-of-scope ads, exposing the user to other applications, and opening a URL in a browser," the researchers said, "'SimBad' acts now as an Adware, but already has the infrastructure to evolve into a much larger threat."</p><p>CheckPoint Research also outlined '<a href="https://research.checkpoint.com/simbad-a-rogue-adware-campaign-on-google-play" target="_blank">Operation Sheep</a>' in a second report yesterday. This involves a group of Android apps harvesting contact information from users' phones on a mass scale without their consent.</p><p>This malware has similarly been loaded in an SDK built for data analytics, and has been seen in up to 12 different Android apps to date. These have been collectively downloaded over 111 million times.</p><p>The SWAnlaytics SDK has been integrated into a dozen seemingly innocuous Android apps published on third-party Chinese app stores such as the Huawei App Store, Xioami App Store and Tencent MyApp.</p><p>The researchers first encountered a sample of the infection in September 2018, and have traced a data-scraping path that leads to servers owned by Shun Wang Technologies. Once the malicious apps are installed, entire contact lists are uploaded to the firm's servers, according to Check Point Research.</p><p>They also noted in the Tencent MyApp store alone, eight of 12 infected apps collectively amassed 111 million downloads.</p><p>"In theory," the researchers speculated, "Shun Wang Technologies could have collected a third of China's population names and contact numbers if not more."</p><p>They added with no clear declaration of data usage form Shun Wang, nor regulatory supervision, data could easily be traded within underground markets and abused in a variety of ways. These may range from rogue marketing to friend referral program abuse.</p><p>"Compared to financial data and government-issued ID document information, personal contact information is often treated as less sensitive data," the researchers said.</p><p>"According to popular belief, it requires extra effort to exploit such data while potential profits do not match a hacker's effort. Hence it is unlikely to be targeted.</p><p>"However, the landscape is changing with deep specialization in underground markets and new "business models" available to profit from such personal contact data."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WhatsApp gains biometric security support on iOS ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/32905/whatsapp-gains-biometric-security-support-on-ios</link>
                                                                            <description>
                            <![CDATA[ iPhone users can now protect their chats with Touch ID or Face ID ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vBQ1ENaisBaG5qSGfmRWG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/C2vwp7CGDnVuzW4StmyksQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Feb 2019 11:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/C2vwp7CGDnVuzW4StmyksQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whatsapp on iPhone]]></media:description>                                                            <media:text><![CDATA[Whatsapp on iPhone]]></media:text>
                                <media:title type="plain"><![CDATA[Whatsapp on iPhone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/C2vwp7CGDnVuzW4StmyksQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook has added biometric authentication to WhatsApp, allowing users to better prevent unauthorised access to their conversations.</p><p>The new feature is currently only available to iOS users, and can be accessed by updating the app to version 2.19.20 from the Apple App Store and going into the settings menu and selecting 'account', 'privacy' and then 'screen lock'.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32669/whatsapp-gold-scam-returns-with-martinelli-malware-threat" data-original-url="/security/32669/whatsapp-gold-scam-returns-with-martinelli-malware-threat">WhatsApp Gold scam returns with 'martinelli' malware threat</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-currency/32628/facebook-to-enter-crypto-market-with-whatsapp-stablecoin" data-original-url="/digital-currency/32628/facebook-to-enter-crypto-market-with-whatsapp-stablecoin">Facebook to enter crypto market with WhatsApp stablecoin</a></p></div></div><p>Android users, meanwhile, are still restricted to version 2.19.17, which does not include biometric support. According to info from WAbetainfo.com, however, the feature is set to be introduced to Android devices with version 2.19.3.</p><p>The app now supports both Touch ID and Face ID, meaning that even if your device is unlocked, snoopers won't be able to read your messages - although message previews and quick replies in notifications will still be accessible, assuming you've activated this feature. The feature uses an app-wide locking system, which means that you can't protect individual chats with fingerprint or face recognition - just the whole app.</p><p>The new security features follow CEO Mark Zuckerberg's announcement that Facebook was <a href="https://www.itpro.com/policy-legislation/32857/irish-data-protection-commission-facebook-whatsapp-instagram-merge" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/32857/irish-data-protection-commission-facebook-whatsapp-instagram-merge">planning to merge the backends of WhatsApp, Instagram and Facebook Messenger</a> into a single platform, raising the possibility that biometric security could soon be introduced to Facebook's other apps.</p><p>WhatsApp is currently the only major Facebook-owned app to support biometric authentication, although rumours indicated that it was being internally tested for Facebook back in 2017. WhatsApp also uses end-to-end encryption to secure chats, which Instagram and Messenger currently do not. Data protection authorities have already started expressing "urgent" interest in what the potential merger could mean for data privacy.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5G security concerns persist with new research pointing to critical flaw ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/32893/5g-security-concerns-persist-with-new-research-pointing-to-critical-flaw</link>
                                                                            <description>
                            <![CDATA[ The flaw found affects 3G, 4G and 5G protocols and we won't see a fix until the end of the year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ssbjZJjPb6u6HJTHWZF7xh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3HZ8UTYbJkqZDuykXnNGBX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Feb 2019 12:04:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3HZ8UTYbJkqZDuykXnNGBX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[5G graphic]]></media:description>                                                            <media:text><![CDATA[5G graphic]]></media:text>
                                <media:title type="plain"><![CDATA[5G graphic]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3HZ8UTYbJkqZDuykXnNGBX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have discovered a critical security flaw in the upcoming 5G network protocol which could facilitate the eavesdropping of calls and man in the middle attacks.</p><p>Although we are yet to experience the blistering speeds 5G promises to provide in the UK, fears of its security have largely been theoretical and speculative as of late, until the research, conducted by research firm SINTEF and academics from ETH Zurich and Germany's Technische Universitt Berlin, made a more concrete claim.</p><p>The flaw, which also affects older 3G and 4G protocols, can be used to create new ISMI-catchers, which are devices that break encryptions of cellular communications, allowing attackers to monitor the communications passing through a virtual mobile tower under control of the attacker.</p><p>The <a href="https://eprint.iacr.org/2018/1175.pdf" target="_blank">research paper</a> indicates that the vulnerability lies in the Authentication and Key Agreement (AKA) which is a "challenge-response protocol mainly based on symmetric cryptography and a sequence number (SQN)". </p><h3 class="article-body__section" id="section-what-is-aka"><span>What is AKA?</span></h3><p>AKA works by establishing and negotiating public keys which are used for encrypting two ends of a phone line.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack" data-original-url="/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack">Was Mirai malware behind Dyn DDoS attack?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/28081/what-is-5g" data-original-url="/mobile/28081/what-is-5g">What is 5G and how far are we from rollout?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/32677/t-mobile-pokes-fun-at-att-for-labelling-its-4g-service-as-5g" data-original-url="/network-internet/32677/t-mobile-pokes-fun-at-att-for-labelling-its-4g-service-as-5g">T-Mobile pokes fun at AT&T for labelling its 4G service as 5G</a></p></div></div><p>3G and 4G network protocols were both subject to the vulnerabilities in the AKA so the security was enhanced in preparation for 5G by using randomised asymmetric encryption to protect identifiers prior to authentication.</p><p>Despite the increase in protection, researchers have found a vulnerability in the AKA that affects 5G as well as previous generations of cellular connectivity.</p><h3 class="article-body__section" id="section-the-potential-damage"><span>The potential damage</span></h3><p>The new ISMI-catchers work differently to previous iterations which could intercept mobile traffic metadata. New versions can intercept details about a mobile user's activity such as the number of calls and texts sent, allowing the attacker to create individual profiles for each user.</p><p>These profiles, the researchers explained, can be tracked after the user leaves the vicinity or catchment area of the fake mobile tower. The profile made of a user can also alert the attacker when the user re-enters the coverage zone of the fake tower, which has more severe implications than it first appears.</p><p>Although privacy cannot be broken after the user leaves the range of the fake tower, the location of the user can. This means attackers can potentially track the location and activity of high ranking politicians, for example.</p><p>"Assuming an adversary having a fake base station nearby an embassy, he not only can learn the officials' activity when they are at the office during working hours but also when they are not, including during evening and nights (e.g., at home) or during business trips," say the researchers. "Therefore, such an attacker may learn if targets use different SIMs cards for private use (no activity at home). It may also infer if some specific time periods (e.g., one evening and night) were specifically busy (a lot of calls or SMSs were made yielding a big rise of SQN)."</p><h3 class="article-body__section" id="section-when-can-we-expect-a-fix"><span>When can we expect a fix?</span></h3><p>The complete and dedicated fix which is required to mitigate the attack created by the researchers isn't likely to arrive until the end of 2019.</p><p>This means for users in the US and Australia, two countries in which <a href="https://www.itpro.com/network-internet/32677/t-mobile-pokes-fun-at-att-for-labelling-its-4g-service-as-5g" data-original-url="https://www.itpro.com/network-internet/32677/t-mobile-pokes-fun-at-att-for-labelling-its-4g-service-as-5g">consumer 5G networks are already active</a>, the threat will be real for quite some time.</p><p>The earliest estimates for a <a href="https://www.itpro.com/mobile/32356/ee-will-roll-out-5g-services-to-16-british-cities-in-2019" target="_blank" data-original-url="https://www.itpro.com/mobile/32356/ee-will-roll-out-5g-services-to-16-british-cities-in-2019">5G rollout in the UK are August 2019</a> with a more thorough rollout estimated to happen in 2020 which means the UK may not experience such vulnerabilities if the fix is made in time.</p><p>"We followed the responsible disclosure procedure and reported our findings to the 3GPP [the standards body behind 5G], GSM Association (GSMA), several manufacturers (Ericsson, Nokia, and Huawei), and carriers (Deutsche Telekom and Vodafone UK)," the research team said.</p><p>"Our findings were acknowledged by the 3GPP and GSMA, and remedial actions are underway to improve the protocol for next generation," they added. "While 5G AKA will suffer from our attack in the first deployment of 5G (Release 15, phase 1), we are still hopeful that 5G AKA could be fixed before the deployment of the second phase (Release 16, to be completed by the end of 2019)."</p><h3 class="article-body__section" id="section-fuel-to-the-fire"><span>Fuel to the fire</span></h3><p>This news certainly doesn't mark the first piece of concern surrounding the security of 5G networks.</p><p>The <a href="https://www.itpro.com/broadband/30274/what-is-bandwidth" target="_blank" data-original-url="https://www.itpro.com/broadband/30274/what-is-bandwidth">increased bandwidth</a> that will facilitate lighting-quick download speeds will also provide a base for, what some theorise, more widespread and damaging <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS attacks</a> harnessed by insecure IoT devices being leveraged to create expansive botnets.</p><p>Devices such as printers, fridges, baby monitors and security cameras could all be used, just like they were in the <a href="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack">Dyn cyber attack of 2016</a>, to unleash attacks that could not just down websites, but also infrastructure controlling essential services like electricity providers and banks.</p><p>"The fact that 5G increases the speed means that it takes even fewer of them to overwhelm a given organization because now you can get an exponential rate of traffic directed to someone," said Stuart Madnick, professor of IT at MIT to Inverse. "The worst is yet to come."</p><p>"It's like going from fireworks to dynamite sticks," he says. "5G encourages further evolution and expansion of Internet of Things related networks. All of the good news and bad news that comes along with this technology gets magnified."</p><p>Concerns also surround 5G's application in the <a href="https://www.itpro.com/strategy/27302/driverless-cars-news" target="_blank" data-original-url="https://www.itpro.com/strategy/27302/driverless-cars-news">autonomous car sphere</a>. With accidents already happening in self-driving cars, some think 5G will provide a platform on which the technology can thrive.</p><p>What's more concerning is the thought that researchers are still finding vulnerabilities which facilitate man in the middle attacks in AKA technology on which we have relied for years to protect our cellular privacy and security.</p><p>5G's security concerns will persist for some time and only time will tell how appropriate the technology is to underpin advancements such as autonomous cars and remote surgeries.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>