Showing posts with label patch. Show all posts
Showing posts with label patch. Show all posts

Wednesday, 16 January 2013

Samsung Patches Vulnerability in The Exynos Processor




Samsung promised in December that it would address a serious security hole in some of its smartphones and tablets running Exynos processors "as quickly as possible," and it looks like the company has begun that process. T-Mobile has released an over-the-air update today to its Galaxy Note II customers that offers "Exynos and other security enhancements." In addition, Sprint has released its own over-the-air update for the Galaxy S II Epic 4G Touch with unspecified "security updates" that are said to address the Exynos exploit.
The security hole was first discovered in mid-December, when xda-developers users found that malicious apps could gain root access to certain devices on their own accord, leaving user data and other primary phone functions vulnerable. Samsung previously released an update to Galaxy S III devices in the UK to fix the exploit, but multiple models including the international Galaxy S II, Galaxy Note, and Galaxy Note II remain exposed at this time. The good news is that users will remain safe so long as they limit themselves to downloading popular and well-known applications.
Update: Article modified to clarify that Samsung patched some UK Galaxy S III's earlier this month. [TheVerge]

You can follow me on Twitter, add me to your circles on Google+ or Subscribe to me on FaceBook or YouTube. You can also check my Website and Blog to keep yourself updated with what is happening in the ever changing world of technology

Monday, 14 January 2013

Microsoft Patch Vulnerability That Targets Old Versions of IE




Microsoft is today resolving a nasty vulnerability that targets old versions of Internet Explorer and allowed a user's PC to be overtaken if the browser was steered to select malicious websites. After it was initially found last month, Microsoft offered up a few workarounds and a standalone patch to avoid the flaw, which threatens versions 6, 7, and 8 of Internet Explorer. 
                                                  Customers Prefer Tablets Over PC's
But today's security update should eliminate the vulnerability for good. Microsoft says that to date, just a "limited number" of customers have fallen victim to the zero-day exploit, but admits " the potential exists that more customers could be affected in the future." As such, the update has been designated critical and will be automatically installed for users that have enabled Automatic Updates on their PCs. Of course, this is also another reminder to keep your browser updated — assuming your situation permits it. IE 9 and 10 were protected from this particular vulnerability from the very beginning. [TheVerge]

You can follow me on Twitter, add me to your circles on Google+ or Subscribe to me on facebook or YouTube. You can also check my website and blog to keep yourself updated with what is happening in the ever changing world of technology

Experts Claim Java Still Contains Security Flaws, Even After Yesterday's Patch




Oracle issued an emergency update to its widely-used Java web software on Sunday, but experts say it still contains security flaws.
Last week the US government advised users to disable it because of a bug that leaves computers vulnerable to being hacked.
Security specialists claim the fix has not done enough to make PCs secure.
Oracle says that more than one billion people use Java, and some games like Minecraft are built around it.
The bugs can make a computer open to infection by viruses. Last year net security specialist Kaspersky said that 50% of hacks carried out by seeking out software bugs were done via Java.
"We don't dare to tell users that it's safe to enable Java again," Adam Gowdiak, a researcher with Poland's Security Explorations told Reuters.
In a blog about the "unscheduled" update, Oracle says it has changed Java's default security settings to "high" which it says means users will be notified of any extra applications which start running while they are browsing.
Oracle says the vulnerability applies to the latest version of the software, Java 7. It has declined to comment.
Java is a programming language that enables software to run on. [BBC News]

You can follow me on Twitter, add me to your circles on Google+ or Subscribe to me on facebook or YouTube. You can also check my website and blog to keep yourself updated with what is happening in the ever changing world of technology