Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
LAS VEGAS, NV -- (Marketwired) -- 08/06/15 -- Black Hat USA -- Check Point® Software Technologies Ltd. (NASDAQ: CHKP), the largest pure-play security vendor globally, today announced that its mobile security research team discovered a vulnerability in Android that affects devices made by major manufacturers including LG, Samsung, HTC and ZTE. The team disclosed its findings during a briefing session at Black Hat USA 2015 in Las Vegas, NV this morning.
"Certifi-gate" is a vulnerability that allows applications to gain illegitimate privileged access rights which are typically used by remote support applications that are either pre-installed or personally installed on the device. Attackers can exploit Certifi-gate to gain unrestricted device access, allowing them to steal personal data, track device locations, turn on microphones to record conversations, and more.
Android offers no way to revoke the certificates that are providing privileged permissions. Left unpatched, and with no reasonable workaround, devices are exposed right out of the box. All affected vendors were notified by Check Point about Certifi-gate and have begun releasing updates. The vulnerability cannot be fixed, and can only be updated when a new software build is pushed to the device - a notoriously slow process. Android also offers no way to revoke certificates used to sign vulnerable plugins.
"Every day, people around the globe use mobile devices to manage important aspects of their lives: they access work email, manage bank accounts, and track health information," said Dorit Dor, vice president of products at Check Point Software Technologies. "The problem is, they rarely stop to think about whether their data is secure. This vulnerability is very easily exploited, and can lead to the loss and dissemination of a user's personal data. It's time to take mobile security seriously."
Android users can check to see if their device is vulnerable to Certifi-gate by downloading this free Check Point Certfi-gate scanner app in Google Play.
The Company today launched Check Point Mobile Threat Prevention, a new mobile security solution enterprises can use to battle the evolving mobile threat environment and to detect threats such as Certifi-gate, malicious apps, Man-in-the-Middle attacks and more. With the highest level of security for stopping threats on iOS and Android, the solution delivers real-time visibility and threat intelligence into an organization's existing security and mobility infrastructures. Deployment is easy and not only has integration into an organizations mobility and security infrastructure but it also provides a transparent user experience that maintains privacy and performance.
To learn more details about the vulnerability please see the Company's blog post.
Follow Check Point via:
LinkedIn: https://www.linkedin.com/company/check-point-software-technologies
Twitter: http://www.twitter.com/checkpointsw
Facebook: https://www.facebook.com/checkpointsoftware
Blog: http://blog.checkpoint.com
YouTube: http://www.youtube.com/user/CPGlobal
About Check Point Software Technologies Ltd.
Check Point Software Technologies Ltd. (www.checkpoint.com) is the largest pure-play security vendor globally, provides industry-leading solutions, and protects customers from cyberattacks with an unmatched catch rate of malware and other types of attacks. Check Point offers a complete security architecture defending enterprises' networks to mobile devices, in addition to the most comprehensive and intuitive security management. Check Point protects over 100,000 organizations of all sizes. At Check Point, we secure the future.
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs
Publicado el 11-Oct-2016 • 12.48hs
Publicado el 15-Mar-2016 • 11.59hs
Publicado el 2-Feb-2017 • 11.38hs
Publicado el 20-Jun-2014 • 17.17hs
Publicado el 31-May-2011 • 05.13hs
Publicado el 25-Set-2008 • 17.54hs
Publicado el 1-Set-2016 • 16.11hs
Publicado el 31-Ago-2016 • 18.53hs
Publicado el 19-Ene-2017 • 15.47hs
Publicado el 4-Jul-2016 • 18.51hs