The phone goes head-to-head with Samsung on new features, but it’s still not very compelling.
from Gear Latest https://ift.tt/2T1DmKw
via IFTTT
The phone goes head-to-head with Samsung on new features, but it’s still not very compelling.
from Gear Latest https://ift.tt/2T1DmKw
via IFTTT
ESET researchers uncover a previously unknown security flaw allowing an adversary to decrypt some wireless network packets transmitted by vulnerable devices
The post KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/2HWK4uL
via IFTTT
On Monday, networking hardware maker Zyxel released security updates to plug a critical security hole in its network attached storage (NAS) devices that is being actively exploited by crooks who specialize in deploying ransomware. Today, Zyxel acknowledged the same flaw is present in many of its firewall products.

This week’s story on the Zyxel patch was prompted by the discovery that exploit code for attacking the flaw was being sold in the cybercrime underground for $20,000. Alex Holden, the security expert who first spotted the code for sale, said at the time the vulnerability was so “stupid” and easy to exploit that he wouldn’t be surprised to find other Zyxel products were similarly affected.
Now it appears Holden’s hunch was dead-on.
“We’ve now completed the investigation of all Zyxel products and found that firewall products running specific firmware versions are also vulnerable,” Zyxel wrote in an email to KrebsOnSecurity. “Hotfixes have been released immediately, and the standard firmware patches will be released in March.”
The updated security advisory from Zyxel states the exploit works against its UTM, ATP, and VPN firewalls running firmware version ZLD V4.35 Patch 0 through ZLD V4.35 Patch 2, and that those with firmware versions before ZLD V4.35 Patch 0 are not affected.
Zyxel’s new advisory suggests that some affected firewall product won’t be getting hotfixes or patches for this flaw, noting that the affected products listed in the advisory are only those which are “within their warranty support period.”
Indeed, while the exploit also works against more than a dozen of Zyxel’s NAS product lines, the company only released updates for NAS products that were newer than 2016. Its advice for those still using those unsupported NAS devices? “Do not leave the product directly exposed to the internet. If possible, connect it to a security router or firewall for additional protection.”
Hopefully, your vulnerable, unsupported Zyxel NAS isn’t being protected by a vulnerable, unsupported Zyxel firewall product.
CERT’s advisory on the flaw rate this vulnerability at a “10” — its most severe. My advice? If you can’t patch it, pitch it. The zero-day sales thread first flagged by Holden also hinted at the presence of post-authentication exploits in many Zyxel products, but the company did not address those claims in its security advisories.
Recent activity suggests that attackers known for deploying ransomware have been actively working to test the zero-day for use against targets. Holden said the exploit is now being used by a group of bad guys who are seeking to fold the exploit into Emotet, a powerful malware tool typically disseminated via spam that is frequently used to seed a target with malcode which holds the victim’s files for ransom.
“To me, a 0day exploit in Zyxel is not as scary as who bought it,” he said. “The Emotet guys have been historically targeting PCs, laptops and servers, but their venture now into IoT devices is very disturbing.”
from Krebs on Security https://ift.tt/32tWtzI
via IFTTT
En la Comisión Europea han determinado que WhatsApp no es una aplicación de mensajería lo suficientemente segura como para ser utilizada como herramienta de comunicación. En su lugar, apostarán por Signal, la app de mensajería ultrasegura que, curiosamente, a día de hoy está respaldada entre otros por el mismísimo Brian Acton, uno de los cofundadores de WhatsApp, que en su momento decidió donar 50 millones de dólares a la fundación
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
La entrada WhatsApp no es lo bastante seguro para la Comisión Europea, por lo que se pasarán a Signal se publicó primero en Andro4all.
from Andro4all https://ift.tt/3cc1YHO
via IFTTT
A punto de comenzar un nuevo mes, Netflix ha anunciado los estrenos que llegan a la plataforma en marzo de 2020. Como ya es tradición, la compañía ha hecho oficial la lista de nuevas series y películas que irán llegando a su catálogo día a día a lo largo de las próximas semanas. Del mismo modo que en anteriores ocasiones, Netflix categoriza sus novedades entre series, películas y documentales. No
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
La entrada Novedades de Netflix en marzo de 2020: nuevas series y películas se publicó primero en Andro4all.
from Andro4all https://ift.tt/2I3htUx
via IFTTT
The lamp maker Gantri partnered with the Silicon Valley design firm Ammunition to produce a new line of greener lighting products.
from Gear Latest https://ift.tt/3a2o8dC
via IFTTT
Antes de presentar a lo grande los nuevos P40 y P40 Pro dentro de un mes exacto, la gigante china ha decidido sorprender al mundo presentando el nuevo Huawei P40 Lite, la versión recortada de la nueva serie que liderará su catálogo a lo largo de esta primera mitad de 2020. El P40 Lite llega con parecidos razonables con el Nova 6 SE presentado no mucho tiempo atrás, y mantiene
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
La entrada El Huawei P40 Lite es oficial con batería de 4.200 mAh y sin servicios de Google por 299 euros se publicó primero en Andro4all.
from Andro4all https://ift.tt/2TjqGgO
via IFTTT
Encryption experts gave insights into the Crypto AG revelations, delved into complexities of the “right to be forgotten,” and more at RSA Conference.
from Dark Reading: https://ift.tt/2wRKsst
via IFTTT
A pesar de que las opciones de personalización incluidas en Android son numerosas, siempre queda algún que otro detalle del sistema que no puede ser configurado a gusto del usuario. O al menos, no de forma nativa. Es el caso del nombre de las aplicaciones. Dado que este datos está directamente ligada al propio documento AndroidManifest.xml de la aplicación, que describe la información esencial de la app, no es posible
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
La entrada Cómo cambiar el nombre de las apps en Android se publicó primero en Andro4all.
from Andro4all https://ift.tt/381miIT
via IFTTT
Analysis of 92 billion rejected emails reveals a range of simple and complex attack techniques for the last quarter of 2019.
from Dark Reading: https://ift.tt/3a7x2qi
via IFTTT