(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

(credit: Qualcomm)

For the past five years, a vulnerability in many Android phones has left users' text messages, call histories, and possibly other sensitive data open to snooping, security researchers said Thursday.

The flaw, which is most severe in Android versions 4.3 and earlier, allows low-privileged apps to access sensitive data that's supposed to be off-limits, according to a blog post published by security firm FireEye. But instead, the data is available by invoking permissions that are already requested by millions of apps available in Google Play. Company researchers said the vulnerability can also be exploited by adversaries who gain physical access to an unlocked handset. Indexed as CVE-2016-2060, the bug was first introduced when mobile chipmaker Qualcomm released a set of programming interfaces for a system service known as the "network_manager" and later the "netd" daemon.

"CVE-2016-2060 has been present on devices since at least 2011 and likely affects hundreds of Android models around the world," FireEye researchers wrote. "This vulnerability allows a seemingly benign application to access sensitive user data including SMS and call history and the ability to perform potentially sensitive actions such as changing system settings or disabling the lock screen. Devices running Android 4.3 (“Jelly Bean MR2”) or older are the most affected by the vulnerability, and are likely to remain unpatched. Newer devices utilizing SEAndroid are still affected, but to a lesser extent."

Read 3 remaining paragraphs | Comments

Re: NetCommWireless HSPA 3G10WVE Wireless Router Multiple vulnerabilities
[security bulletin] HPSBMU03584 rev.1 - HPE Network Node Manager I (NNMi), Multiple Remote Vulnerabilities
[SECURITY] [DSA 3570-1] mercurial security update

LockPath Joins Cloud Security Alliance
Channel Partners
As a framework, the CSA CCM provides organizations with the structure, detail and clarity required for tailoring information security to the cloud industry. LockPath will also provide CSA's Consensus Assessments Initiative Questionnaire (CAIQ), which ...



Designer of holograms for Star Wars : The Force Awakens is giving it for Free
Andrew Kramer, the VFX guy who helped in designing those awesome holograms for Star Wars : The Force Awakens, is giving tons of specialised and accurate 3D models from the movie for free. The 3D models are made specifically for use in his own 3D ...

and more »

SANS Institute Pledges To Train Veterans For Cybersecurity Jobs At White House Joining Forces Event
PR Newswire (press release)
SANS offers a myriad of free resources to the InfoSec community including consensus projects, research reports, and newsletters; it also operates the Internet's early warning system--the Internet Storm Center. At the heart of SANS are the many security ...

and more »

Small Businesses Need Cybersecurity, Too
SYS-CON Media (press release)
With an audience of more than half a million and more than 10,000 posts by security experts, Peerlyst is the preeminent platform for spreading InfoSec news, asking a question, finding an expert, or offering product insight. For more information, email ...

and more »
[SECURITY] [DSA 3569-1] openafs security update
[SECURITY] [DSA 3568-1] libtasn1-6 security update
FreeBSD Security Advisory FreeBSD-SA-16:17.openssl
Cisco Security Advisory: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
ESA-2016-051: Patch 14 for RSA® Authentication Manager 8.1 SP1 to Address Multiple Vulnerabilities
[SECURITY] [DSA 3567-1] libpam-sshauth security update
Internet Storm Center Infocon Status