Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps

Google said in 2018 it tracked a rise in the number of potentially harmful apps found on Android devices that were either pre-installed or delivered via over-the-air updates. Continue reading Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps

Down the Rabbit Hole with a BLU Phone Infection

Much-maligned BLU phones have been a privacy and spyware nightmare. Threatpost shares the story of one victim who experienced firsthand a relentless wave of unwanted programs, spyware and frustration. Continue reading Down the Rabbit Hole with a BLU Phone Infection

Chinese tech firm disputes report it siphons smartphone data after Amazon suspends sales

Chinese tech firm Adups and American phone manufacturer Blu are disputing reports of privacy and security problems plaguing their products after Amazon temporarily suspended the sale of Blu phones, which are some of the most popular on the retail site. In response, the American cybersecurity company that claimed Adups was quietly siphoning heaps of data from mobile phones issued a statement Wednesday sticking to its story. “We stand by our findings because we have clear forensic evidence, both in terms of code and in terms of network traces, to support them,” Kryptowire, the cybersecurity company, said in a press release. CyberScoop reported on Kryptowire’s findings on July 25. Adups initially did not respond to requests for comment, but reached out two days later, calling the article “malicious slander” and asking “to stop refrain from reporting, and withdraw the article.” An Adups representative claimed third-party testers — including Kryptowire — had verified that the security and privacy issues had been solved. […]

The post Chinese tech firm disputes report it siphons smartphone data after Amazon suspends sales appeared first on Cyberscoop.

Continue reading Chinese tech firm disputes report it siphons smartphone data after Amazon suspends sales

Chinese tech firm continues to secretly siphon data from Android phones

Despite being caught a year ago, Android phones around the world are secretly sending sensitive user data to an opaque Chinese tech company whose software is found in millions of cheap phones used widely by lower-income customers in the developing world, Europe and the United States. Despite the controversy stirred by the original report — which prompted reactions everywhere from Google to the Department of Homeland Security — the Chinese firm continues to secretly siphon off user data without disclosure or consent, according to the latest round of research from the Virginia-based cybersecurity company Kryptowire. The new report comes nearly a year after Kryptowire researcher Ryan Johnson showed that more than 700 million Android smartphones, including some in the United States, carried the Chinese-authored software. Users are tracked by their movements and communications; the software tracks call logs, text messages, contact lists, GPS location and other data. The spyware has been selectively scaled back since it was originally […]

The post Chinese tech firm continues to secretly siphon data from Android phones appeared first on Cyberscoop.

Continue reading Chinese tech firm continues to secretly siphon data from Android phones

Chinese IoT Firm Siphoned Text Messages, Call Records

A Chinese technology firm has been siphoning text messages and call records from cheap Android-based mobile smart phones and secretly sending the data to servers in China, researchers revealed this week. The revelations came the same day the White House and the U.S. Department of Homeland Security issued sweeping guidelines aimed at building security into Internet-connected devices, and just hours before a key congressional panel sought recommendations from industry in regulating basic security standards for so-called “Internet of Things” devices. Continue reading Chinese IoT Firm Siphoned Text Messages, Call Records