Security
Headlines
HeadlinesLatestCVEs

Tag

#android

CVE-2021-0708: Android Security Bulletin—October 2021  |  Android Open Source Project

In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-183262161

CVE
#android#java
CVE-2021-0703: Android Security Bulletin—October 2021  |  Android Open Source Project

In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-184569329

CVE-2021-0870: Android Security Bulletin—October 2021  |  Android Open Source Project

In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-192472262

Google Buckles Down on Android Enterprise Security

The launch of Android 12 brings several new default security features, along with new security efforts for Android Enterprise.

Malware Abuses Core Features of Discord

Researchers warn that Discord's bot framework can be easily weaponized.

Cybrary Launches New Partnership with Check Point Software to Make Cybersecurity Training Accessible to All

Online cybersecurity professional development platform bolsters the Check Point Education Initiative.

Security Teams Still Favor Prevention Over Detection

Security leaders are adopting a multilayered approach to address new security threats and risks.

Akamai Technologies Completes Acquisition of Guardicore to Extend Its Zero Trust Solutions to Help Stop Ransomware

Guardicore's micro-segmentation products will be added to Akamai's portfolio of Zero Trust solutions.

Plurilock to Acquire Assets of CloudCodes Software

Transaction marks Plurilock’s second acquisition in 2021.

Invicti Security Announces $625 Million Growth Investment Led by Summit Partners

Web application security provider plans to leverage new investment to continue product expansion and support global growth.