Google Search

Showing posts with label BlackBerry. Show all posts
Showing posts with label BlackBerry. Show all posts

Saturday, October 19, 2013

PRISM, UK Surveillance, Sweden vs. Google, Blackberry Z10 – 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Here's the latest in our 60 Second Security video series, bringing you a fast, incisive and entertaining angle on recent computer security issues.

Watch the latest security news in just 60 seconds! (Higher resolution available directly from YouTube. Click the captions button for closed captions.)

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, BlackBerry, cloud, flash, Google Apps, law, Patch, PRISM, Privacy, salem, surveillance, Sweden, vulnerability, z10


View the original article here

Monday, April 22, 2013

BlackBerry warns of TIFF vulnerability that could allow malware to run on enterprise servers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Blackberry Enterprise ServerIf you are responsible for administering the BlackBerry phones used by staff at your company, there's some imporant security news.

According to a BlackBerry security advisory published last week, vulnerabilities exist that could allow remote hackers to run malicious code on the BlackBerry Enterprise Server (BES) software run by many firms.

The flaw, which has been rated as "high severity", involves how BlackBerry's enterprise software handles TIFF image files on webpages, in emails, and in instant messages.

According to BlackBerry's advisory:

Vulnerabilities exist in how the BlackBerry MDS Connection Service and the BlackBerry Messaging Agent process TIFF images for rendering on the BlackBerry smartphone.

Successful exploitation of any of these vulnerabilities might allow an attacker to gain access to and execute code on the BlackBerry Enterprise Server.

Depending on the privileges available to the configured BlackBerry Enterprise Server service account, the attacker might also be able to extend access to other non-segmented parts of the network.

In short, a malicious hacker could create a boobytrapped TIFF image file and either trick a BlackBerry smartphone user into visiting a webpage carrying the image, or embed the malicious image directly into an email or instant message.

According to BlackBerry, the BlackBerry Messaging Agent flaw does not even require a user to click on a link or view an email for the attack to succeed.

The risk is that by exploiting the flaw, hackers might be able to plant malicious code on your BlackBerry Enterprise Server that opens a backdoor for remote access.

Depending on how your network infrastructure is set up - intruders might be able to see into other parts of your network and steal information.

Alternatively, the hackers' code might cause your systems to crash - perhaps interrupting communications.

It's important to underline that these are not vulnerabilities in BlackBerry smartphones themselves. Like other BlackBerry-related vulnerabilities we've seen in the past, the potential attack is against the BlackBerry Enterprise Server used by businesses.

As more and more companies are waking up to the risk of targeted attacks with the apparent intention of stealing data and spying on activities, such a vulnerability is clearly a serious concern.

The good news is that BlackBerry has not received any reports of attacks targeting its enterprise customers, but obviously it is still a very good idea for affected customers to update their software as soon as possible. The company has published workarounds for those businesses who may not be able to quickly update their installation of Blackberry Enterprise Server.

Follow @gcluley

View the original article here

Sunday, April 14, 2013

Was Alicia Keys hacked, or is she cheating on BlackBerry with iPhone this Valentine’s Day?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Alicia Keys. Image from ShutterstockBlackBerry recently surprised the tech industry when they announced at their major launch event on January 30 the appointment of musician, Alicia Keys, as the Global Creative Director.

And since then Keys has been pimping BlackBerry’s new smartphone model, Z10, tweeting from it since launch. But is there a secret that Keys has been keeping? An extra-cellular affair with the iPhone?

At the BlackBerry launch, Keys told the audience about her on-again/off-again love affair with BlackBerry.

She said she had been lured away from BlackBerry by “hotter, sexier phones, something with more bling” in the past, but now declaring that she and Blackberry were “exclusively dating”.

So it was a bit of a surprise when a tweet from her account went out to her 11 million followers on February 11 – just days after the BlackBerry launch – sent not from her exclusive BlackBerry, but from her ex, the iPhone.

Started from the bottom now were here!

Later the same day, Keys sent out a tweet stating that the previous tweet quoting lyrics from recording artist, Drake, had not come from her, but likely a hacker. (But don’t be offended – she still likes Drake.)

What the h*ll?!!!! Looks like I’ve been hacked… I like @Drake but that wasn’t my tweet :-(

But that doesn't explain this tweet pic posted a day before from her account showing the musician looking radiant in her dressing room at the Grammys with not just one, but two, of her exes in reach – iPhones.

Alicia Keys at the Grammys

Now, we at Naked Security have seen our fair share of hacked Twitter accounts of celebrities such as Justin Bieber and Britney Spears – and this doesn’t quite smell the same.

Would a hacker that has gone through the trouble of hacking an account of such a well-known figure with access to *11 million followers* really only send one tweet with just a song lyric?

This story reminds us of a previous incident when Kim Kardashian claimed her Twitter account was hacked after having trouble logging in to Twitter from her home computer.

Could it be that Keys is using the many recent celebrity Twitter hacks as a scapegoat for her mishap?

Of course, there is also the possibility that Keys could have her PR people monitoring and tweeting on her behalf, and this error could have been a mistake on their part. We can’t know for certain.

But the one thing we do know is that whoever accessed her Twitter account is hanging out with her ex.

Awkward.

Follow @NakedSecurity

Alicia Keys headshot image courtesy of Featureflash / Shutterstock.com


View the original article here