Google has released an emergency fix plugging a security vulnerability that was affecting 99 percent of all Android devices.. A Google spokesman confirmed to V3 the company has released the patch to core partners and OEMs, but added the firm is yet to see any evidence suggesting the flaw has been actively exploited by cyber criminals.. A significant vulnerability impacting a wide range of Android devices has been resolved by Google, which has released an urgent update for its partners.. Android Security Flaw, Google Fix, Cybersecurity Update. . LinuxSecurity.com Team
Oracle Corp. released an emergency update to its Java software for surfing the Web on Sunday, but security experts said the update fails to protect PCs from attack by hackers intent on committing cyber crimes. . The software maker released the update just days after the U.S. Department of Homeland Security urged PC users to disable the program because of bugs in the software that were being exploited to commit identity theft and other crimes. The link for this article located at Globe and Mail is no longer available. . Oracle issues a critical security patch for Java in response to a federal warning about escalating cyber attacks.. Oracle Java Security Update, Emergency Patch, Hacker Alert. . LinuxSecurity.com Team
Some components of the Flame spyware worm were signed using forged Microsoft certificates, according to a recent investigation by Microsoft. These unauthorised digital certificates allowed the Flame developers to make the malware appear as if it was actually created and approved by Microsoft. . The company has already released an emergency patch via Windows Update to block the certificates used by Flame. Mike Reavey, Senior Director of Microsoft's Security Response Center (MSRC), says that the malicious code was signed using the company's Terminal Server Licensing Service, which is used by corporate customers to authorise Remote Desktop services. While Reavey doesn't provide specific details on how the Flame developers were able to sign their code with such certificates, he does say that it has something to do with exploiting a weakness in "an older cryptography algorithm". The link for this article located at H Security is no longer available. . Apple's update neutralizes Phantom malware by disabling fake digital signatures, uncovering significant vulnerability risk.. Flame Spyware, Microsoft Certificates, Cybersecurity Threats, Digital Signature Exploit. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.