Botnet of 190,000 BadBox-Infected Android Devices Discovered
https://www.securityweek.com/botnet-of-190000-badbox-infected-android-devices-discovered/
#Infosec #Security #Cybersecurity #CeptBiro #Botnet #BadBoxInfected #AndroidDevices
@sodiboo @tauon @puppygirlhornypost2 @silly I don't think it's much of a "#freedom" on #iOS but rather that the few devices and OS versions in circulation, alongside everyone from #jailbreaker to #malware (espechally #govware #developers) want to crack it open result in way more personnel and money behind it.
Granted @GrapheneOS does limit their support to devices that can comply with their #security standards.
I do wish for both vendors like #Fairphone to up their game and regulators like @EUCommission to actually push for more #transparency, #openness and #LongTermSupport of #Smartphones, because #ManufacturedEwaste like #SOYES, #WiKo, #Unihertz and others that ship #outdated #AndroidDevices and never even a single update are a major problem!
I do have to give #Apple credit where it is due, and that is that #iOS does have consistency and accessibility nailed down very well. Something that they obviously are able being the "#BenevolentDictator" of a #SingleVendor & #SingleProvider - platform.
Maybe one day the folks at @frameworkcomputer acquire Fairphone and decide to bring the same modularity to #Smartphones and get something done that makes it easy to maintain long-term and that even #GrapheneOS are willing to support.
Botnet of 190,000 BadBox-Infected Android Devices Discovered
https://www.securityweek.com/botnet-of-190000-badbox-infected-android-devices-discovered/
#Infosec #Security #Cybersecurity #CeptBiro #Botnet #BadBoxInfected #AndroidDevices
A year ago today, @justsoup and I created the lowendlibre project with the goal of lowering the bar for getting started with mobile linux, more specifically postmarketOS.
While it didn't quite go as we had initially hoped, it has been a net positive.
#PostMarketOS #Linux #MobileLinux #MediaTek #Android #AndroidDevices
Active Exploitation of Mali GPU Kernel Driver Flaw
Date: June 10, 2024
CVE: CVE-2024-4610
Vulnerability Type: [[Use-After-Free]] (UAF)
CWE: [[CWE-416]], [[CWE-119]]
Sources: Bleeping Computer, The Register, HotHardware
Synopsis
Arm has issued a security bulletin concerning a critical memory-related vulnerability in its Mali GPU kernel drivers, which is currently being exploited in the wild. This vulnerability affects Bifrost and Valhall GPU kernel drivers across multiple versions.
Issue Summary
The vulnerability, identified as [[CVE-2024-4610]], is a [[use-after-free]] flaw in the Mali GPU kernel drivers. This flaw allows a local non-privileged user to perform improper GPU memory operations, gaining access to already freed memory. The flaw impacts all versions of the Bifrost and Valhall drivers from r34p0 through r40p0.
Technical Key Findings
Use-after-free vulnerabilities occur when a program continues to use a pointer to a memory location after it has been freed. This can lead to serious issues such as information disclosure and arbitrary code execution. In the case of CVE-2024-4610, a local attacker could exploit this flaw to execute arbitrary code on the affected system, potentially leading to a full system compromise.
Vulnerable Products
Impact Assessment
Exploitation of this vulnerability can lead to severe consequences, including unauthorized access to sensitive information, system compromise, and potential deployment of malware. The vulnerability's exploitation in the wild indicates a significant risk, especially for high-value targets such as activists and journalists.
Patches or Workaround
Arm has released a patch for this vulnerability in version r41p0 of the Bifrost and Valhall GPU Kernel Driver, available since November 24, 2022. Users are advised to update their drivers to the latest version to mitigate this risk. Due to the complexity of the supply chain, some users may experience delays in receiving the updates.
Tags
#CVE-2024-4610 #MaliGPU #Arm #UseAfterFree #Vulnerability #Patch #CyberSecurity #AndroidDevices #SystemCompromise #HighRisk
Advancing Android - Google Unveils AI-Powered Experiences at I/O 2024: https://www.reviewspace.info/advancing-android-google-unveils-ai-powered-experiences-at-i-o-2024
#GoogleIO #Androiddevices #AIpoweredexperiences #Circletosearch #Gemini #multimodalAI #accessibility #frauddetection #TechnologyNews
Circle to Search Could Expand to Other Android Phones in October: https://www.reviewspace.info/circle-to-search-could-expand-to-other-android-phones-in-october
#CircleToSearch #GalaxyS24 #Pixel8 #AndroidDevices
#GoogleLens #searchfeature #mobiletechnology
#TechnologyNews #ReviewSpace
Pixel Feature Drop 2024 - Exciting Upgrades and New Colorway Unveiled: https://www.reviewspace.info/pixel-feature-drop-2024-exciting-upgrades-and-new-colorway-unveiled
#GooglePixel #FeatureDrop #Pixel8Series #AndroidDevices #Google #TechnologyNews #SoftwareUpdate #ReviewSpace
We live in a world where smartphones have become an integral part of our lives. These tiny devices have become our constant companions, helping us connect