Google Play Store Launches Bug Bounty Program to Protect Popular Android Apps

Better late than never.

Google has finally launched a bug bounty program for Android apps on Google Play Store, inviting security researchers to find and report vulnerabilities in some of the most popular Android apps.

Dubbed “Google Play Security Re… Continue reading Google Play Store Launches Bug Bounty Program to Protect Popular Android Apps

Serious Crypto-Flaw Lets Hackers Recover Private RSA Keys Used in Billions of Devices

If you think KRACK attack for WiFi is the worst vulnerability of this year, then hold on…

…we have got another one for you which is even worse.

Microsoft, Google, Lenovo, HP and Fujitsu are warning their customers of a potentially serious vulnerability in widely used RSA cryptographic library produced by German semiconductor manufacturer Infineon Technologies.

It’s noteworthy that this

Continue reading Serious Crypto-Flaw Lets Hackers Recover Private RSA Keys Used in Billions of Devices

KRACK Demo: Critical Key Reinstallation Attack Against Widely-Used WPA2 Wi-Fi Protocol

Do you think your wireless network is secure because you’re using WPA2 encryption?

If yes, think again!

Security researchers have discovered several key management vulnerabilities in the core of Wi-Fi Protected Access II (WPA2) protocol that could al… Continue reading KRACK Demo: Critical Key Reinstallation Attack Against Widely-Used WPA2 Wi-Fi Protocol

Ukraine Police Warns of New NotPetya-Style Large Scale CyberAttack

Remember NotPetya?

The Ransomware that shut down thousands of businesses, organisations and banks in Ukraine as well as different parts of Europe in June this year.

Now, Ukrainian government authorities are once again warning its citizens to brace th… Continue reading Ukraine Police Warns of New NotPetya-Style Large Scale CyberAttack

New Ransomware Not Just Encrypts Your Android But Also Changes PIN Lock

DoubleLocker—as the name suggests, it locks device twice.

Security researchers from Slovakia-based security software maker ESET have discovered a new Android ransomware that not just encrypts users’ data, but also locks them out of their devices by changing lock screen PIN.

On top of that:

DoubleLocker is the first-ever ransomware to misuse Android accessibility—a feature that provides

Continue reading New Ransomware Not Just Encrypts Your Android But Also Changes PIN Lock

MS Office Built-in Feature Allows Malware Execution Without Macros Enabled

Since new forms of cybercrime are on the rise, traditional techniques seem to be shifting towards more clandestine that involve the exploitation of standard system tools and protocols, which are not always monitored.

Security researchers at Cisco’s Ta… Continue reading MS Office Built-in Feature Allows Malware Execution Without Macros Enabled

Buggy Microsoft Outlook Sending Encrypted S/MIME Emails With Plaintext Copy For Months

Beware, If you are using S/MIME protocol over Microsoft Outlook to encrypt your email communication, you need to watch out.

From at least last 6 months, your messages were being sent in both encrypted and unencrypted forms, exposing all your secret an… Continue reading Buggy Microsoft Outlook Sending Encrypted S/MIME Emails With Plaintext Copy For Months

Microsoft Issues Patches For Severe Flaws, Including Office Zero-Day & DNS Attack

As part of its “October Patch Tuesday,” Microsoft has today released a large batch of security updates to patch a total of 62 vulnerabilities in its products, including a severe MS office zero-day flaw that has been exploited in the wild.

Security upd… Continue reading Microsoft Issues Patches For Severe Flaws, Including Office Zero-Day & DNS Attack

Watch Out! Difficult-to-Detect Phishing Attack Can Steal Your Apple ID Password

Can you detect which one of the above screens—asking an iPhone user for iCloud password—is original and which is fake?

Well, you would agree that both screenshots are almost identical, but the pop-up shown in the second image is fake—a perfect phishing attack that can be used to trick even the most careful users on the Internet.

Felix Krause, an iOS developer and founder of Fastlane.Tools,

Continue reading Watch Out! Difficult-to-Detect Phishing Attack Can Steal Your Apple ID Password