Zeljka Zorz
POC code for critical Android bug published
Last week, researchers from Bluebox Security have made a disconcerting revelation: Google’s Android mobile OS carries a critical bug that allows attackers to modify the …
Privacy policy changes allow AT&T to sell user data
AT&T, the largest provider of mobile telephony in the United States, has recently announced several changes in their Privacy Policy to allow the sale of anonymized user …
“Google account hacked” text scam puzzles researchers
A curious spamming campaign continues to target Google users via their mobile phones, and researchers still don’t know what it actually does. First spotted back in …
The magnitude of Android’s “master key” bug
The Android flaw whose existence was revealed last week by Bluebox Security is as bad as they come. “Blowing hash and signing functions so that the underlying code can …
Mass login attempts compromise 24,000 Nintendo site accounts
Some 24,000 user accounts – but luckily no user financial information – were compromised in mass login attempts to the Club Nintendo website. The global website is …
Multi-platform Java RAT targeting government agencies
A new spear-phishing campaign targeting government agencies mostly in the US, Canada, Australia, a few European countries and the Russian Federation has been spotted by …
“Pinterest Tool” scam aimed at stealing login credentials
Last week we warned about fake “Password changed” emails targeting users of the popular photo-sharing website, but there has been a general uptick in …
Critical Cryptocat group chat bug fixed
A critical security vulnerability in Cryptocat versions older than 2.0.42 has been patched and developers are urging users to update to the latest available version of the …
Trojanized Android app collects info, comments on NSA surveillance
An unusual Android Trojan has been recently unearthed by McAfee’s researchers, embedded in a pirated version of a legitimate music app. The app in question is Jay Z …
Fake Pinterest “Password changed” email leads to malware
Pinterest users beware: an email purportedly coming from the popular pinboard-style photo-sharing website and notifying you of a successful password reset is fake: If you …
Android bug allows app code change without breaking signatures
Researchers from Bluebox Security have discovered a critical Android flaw that allows attackers to modify the code of any app without breaking its cryptographic signature, and …
Aggressive Android adware masquerading as Wi-Fi password cracking app
Statistics say that Android malware and aggressive adware is on the rise, so the fact that researchers occasionally find some of it on legitimate online app markets should not …
Featured news
Resources
Don't miss
- Why AI code assistants need a security reality check
- GPS tracker detection made easy with off-the-shelf hardware
- 91% noise: A look at what’s wrong with traditional SAST tools
- AWS launches new cloud security features
- Chaining two LPEs to get “root”: Most Linux distros vulnerable (CVE-2025-6018, CVE-2025-6019)