Despite everything it said about communications being encrypted and thus safe, WhatsApp has been hacked. Any attack on popular software could potentially affect billions of users. While this vulnerability has been patched, users need to be aware that the software they use daily might not be secure.
Nabil Hannan,Managing Principal – Financial Services, Software Integrity Group, Synopsys explained: "The risk with this incident is that any WhatsApp user, based on their phone number, could technically be targeted. Using the buffer overflow issue, attackers can install malware allowing them to reach communications conducted on that user’s device."
"Any and every WhatsApp user is at risk. Technically anyone can be attacked, whether intentionally or accidentally. In this case the hackers seemed to have specific targets in mind, but other attackers could learn about the issue and then exploit other specific users or a wide range of users," he stressed.
Carl Leonard, Forcepoint’s Principle Security Analyst, noted that while a
software update has been issued to protect WhatsApp against the security flaw that was exploited, the malware itself is extremely
sophisticated. "Attacks like these have huge privacy implications.
Traditionally, malware developed by sophisticated threat actors leaks
into the wider cybercriminal ecosystem and is repurposed for financial
gain, targeting the mass market. This is early days for this particular
malware but it is critical to patch, and turn on auto-updates if
possible, and for all applications, not just WhatsApp," he said.
Oded Vanunu, Head of Products Vulnerability
Research, Check Point Software Technologies warned: "We are seeing that vulnerabilities on mobile platform worth a lot of money, for example in the Zerodium price list they are willing to pay up to US$1 million for a WhatsApp vulnerability that will allow running remote code," he said.
The best that users can do is keep up to date with the app and to report unusual behaviour, Hannan said. Leonard agreed. "A victim’s device would act very differently than a
non-infected device, and while no details of the actions taken by this
malware have emerged, one could assume that an attacker may seek out
bulk contact lists, email data, location data or other personal
information," he said.
Dylan Castagne, MD, Retarus Asia, commented that best practices are needed to ensure the secure and efficient transmission of information. He is in favour of leveraging established standards such as short message service (SMS, or text messages) instead of proprietary systems such as WhatsApp in business communication.
"Additionally, this reflects the need for organisations to significantly up their game in detecting, investigating and remediating intrusions across all communications avenues. With advanced threats seen to continue surpassing the capabilities of security mechanisms and cyber criminals devising new methods to infiltrate networks and exploit attack vectors, including messaging applications and emails, the value of being conscientious and vigilant in today’s digital era cannot be over-emphasised," he said.
"Utilising managed security service providers over traditional security tools also provides enterprises with the added advantage of having regular feature enhancements and upgrades that can better thwart modern cyber security threats."
"Rather than using a threat-based approach (where security professionals block individual threats, one by one) using a behaviour-based approach can pay dividends. By analysing the normal behaviour of a device, or in enterprise terms, any entity on a system, security professionals can act on the anomalies and stop even the most sophisticated attack quickly," Leonard added.
According to Business of Apps in a blog post updated in
February 2019 at
there are:
- One-and-a-half billion users in 180 countries, including 3 million users of WhatsApp Business
- One billion daily active WhatsApp users
-
India is the biggest WhatsApp market in the world, with 200 million
users (itestimated in some quarters that this has increased to 300
million
- Sixty-five billion WhatsApp messages
sent per day, or 29 million per minute, and 55 million WhatsApp video
calls made per day, lasting 340 million minutes in total
- From May-July 2018, 85 billion hours of WhatsApp usage were measured
Hot news & trending topics of interest to working adults in Asia Pacific/Middle East businesses.
Showing posts with label Check Point. Show all posts
Showing posts with label Check Point. Show all posts
17 May 2019
8 April 2019
Check Point finds vulnerability in Xiaomi preinstalled app
An unusual vulnerability was recently discovered in Xiaomi phones by researcher Slava Makkaveev from cybersecurity vendor Check Point Software.
Check Point Research found the vulnerability in a preinstalled security app on phones from Xiaomi, which has almost 8% market share and which ranks third in the mobile phone market.
The Guard Provider (com.miui.guardprovider) app, which is meant to detect malware, could allow cyber criminals to connect to the same Wi-Fi network as the victim and carry out a man-in-the-middle (MiTM) attack. MiTM describes how malware can act as an eavesdropper, copying information as it travels to and from the phone to other destinations online.
The cyber criminal could also do more as part of a third-party software development kit (SDK) update, such as disable malware protections and inject rogue code. Such code could be used to steal data, implant ransomware or tracking or install any other kind of malware.
Check Point disclosed this vulnerability to Xiaomi, which released a patch shortly after.
Check Point suggests that users is immediately uninstall offensive apps, check permissions for each of the apps in their phones, and see which apps may be out of line and demanding too many permissions.
Be paranoid and install from only Google Play at the very least, the company said. As pre-installed apps often cannot be uninstalled, then perhaps the minimum a user can do is to disable all forms of connectivity (LTE/3G and Wi-Fi) and permissions to such apps, and "force stop" the app from running. A more robust cybersecurity app may need to be installed as well for more comprehensive protection, Check Point added.
Details:
Read the technical blog
Check Point Research found the vulnerability in a preinstalled security app on phones from Xiaomi, which has almost 8% market share and which ranks third in the mobile phone market.
The Guard Provider (com.miui.guardprovider) app, which is meant to detect malware, could allow cyber criminals to connect to the same Wi-Fi network as the victim and carry out a man-in-the-middle (MiTM) attack. MiTM describes how malware can act as an eavesdropper, copying information as it travels to and from the phone to other destinations online.
The cyber criminal could also do more as part of a third-party software development kit (SDK) update, such as disable malware protections and inject rogue code. Such code could be used to steal data, implant ransomware or tracking or install any other kind of malware.
Check Point disclosed this vulnerability to Xiaomi, which released a patch shortly after.
Check Point suggests that users is immediately uninstall offensive apps, check permissions for each of the apps in their phones, and see which apps may be out of line and demanding too many permissions.
Be paranoid and install from only Google Play at the very least, the company said. As pre-installed apps often cannot be uninstalled, then perhaps the minimum a user can do is to disable all forms of connectivity (LTE/3G and Wi-Fi) and permissions to such apps, and "force stop" the app from running. A more robust cybersecurity app may need to be installed as well for more comprehensive protection, Check Point added.
Details:
Read the technical blog
Labels:
Check Point,
mobile,
security,
Xiaomi
22 September 2016
Free USB devices could be vectors for malware, Check Point warns
![]() |
| Source: Victoria Police. The unmarked USB drives used are similar to these. |
"Members of the public are allegedly finding unmarked USB drives in their letterboxes. Upon inserting the USB drives into their computers victims have experienced fraudulent media streaming service offers, as well as other serious issues. The USB drives are believed to be extremely harmful and members of the public are urged to avoid plugging them into their computers or other devices," Victoria police said in a statement.
Check Point Software has commented on the phenomenon. "Hacking by USB devices are not new, and can wreck serious or fatal damage to computers (including holding users' data at ransom), or embed malware to infect the computers as zombie/attack hosts, potentially even landing users in legal trouble. While this form of attack has not been seen blatantly in Singapore yet, it would make sense to educate the public on how to avoid such risks, especially since some may succumb to the temptation of getting a 'free' USB device. What's worse, such attacks can also target business mailboxes, putting businesses at jeopardy should unsuspecting corporate users plug in such devices," a Check Point spokesperson said.
Interested?
Anyone with information about those behind the scam is urged to contact Crime Stoppers in Australia on 1800 333 000 or submit a confidential report online
5 September 2016
Singtel to offer Check Point's ZoneAlarm Mobile Security protection
Singtel is collaborating with Check Point Software Technologies to offer ZoneAlarm Mobile Security, a mobile security app that provides comprehensive protection from malware, hackers, Wi-Fi attacks and other cyber threats.
Available for iOS and Android devices, ZoneAlarm performs detailed risk assessments by scanning installed apps*, detecting unsafe Wi-Fi networks and recommending the most secure Wi-Fi hotspot options. It alerts users of suspicious processes running on their phones and protects their operating system from attacks.
“For convenience, many people keep their credit card details, passwords and other sensitive information on their mobile devices. Mobile security is more important than ever as cyber threats become more prevalent. With ZoneAlarm and other products in the new Singtel Mobile Protection suite, our customers can enjoy a worry-free experience for mobile banking, online shopping and web surfing,” said Diana Chen, Vice President of Mobile Marketing, Singtel.
Interested?
Available for iOS and Android devices, ZoneAlarm performs detailed risk assessments by scanning installed apps*, detecting unsafe Wi-Fi networks and recommending the most secure Wi-Fi hotspot options. It alerts users of suspicious processes running on their phones and protects their operating system from attacks.
“For convenience, many people keep their credit card details, passwords and other sensitive information on their mobile devices. Mobile security is more important than ever as cyber threats become more prevalent. With ZoneAlarm and other products in the new Singtel Mobile Protection suite, our customers can enjoy a worry-free experience for mobile banking, online shopping and web surfing,” said Diana Chen, Vice President of Mobile Marketing, Singtel.
Interested?
ZoneAlarm is available as a value-added service to all Singtel mobile postpaid customers at a special price of S$2.90 per month. It is available at a further discounted price of S$2.00 with any subscription of MobileSwop, Singtel’s device care add-on service.
Customers can sign up for ZoneAlarm via the My Singtel app or at any Singtel Retail Shop.
Customers can sign up for ZoneAlarm via the My Singtel app or at any Singtel Retail Shop.
Labels:
Check Point,
mobile,
security,
Singtel
Subscribe to:
Posts (Atom)
