• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   Author / Seven Shen (Mobile Threats Analyst)

Seven Shen

Mobile Threats Analyst

Setting the Record Straight on Moplus SDK and the Wormhole Vulnerability

  • Posted on:November 1, 2015
  • Posted in:Malware, Mobile
  • Posted by:
    Seven Shen (Mobile Threats Analyst)
3

A vulnerability known as Wormhole that reportedly affected the software development kit (SDK), Moplus by Baidu is making waves due to the severity of the impact once successfully exploited. The said vulnerability was discovered by WooYun.og, a vulnerability reporting platform in China.

Read More
Tags: Chinamobile malwareMoplusvulnerabilityWormhole

Android Security Update Includes Fix for Stagefright Vulnerabilities Discovered by Trend Micro

  • Posted on:October 15, 2015
  • Posted in:Mobile, Vulnerabilities
  • Posted by:
    Seven Shen (Mobile Threats Analyst)
0

The discovery of the first Stagefright vulnerability last July is turning out to be just the beginning of many security concerns for Android users. The latest Nexus security bulletin released earlier this month includes updates for 15 remote code execution vulnerabilities related to libstagefright, all tagged as critical. We discovered four of the mentioned vulnerabilities…

Read More
Tags: androidGooglelibstagefrightmobile threatsmobile vulnerabilitiesstagefright

German Users Hit By Dirty Mobile Banking Malware Posing As PayPal App

  • Posted on:October 1, 2015
  • Posted in:Malware, Mobile
  • Posted by:
    Seven Shen (Mobile Threats Analyst)
0

Mobile banking is now used by more and more users, so it shouldn’t be a surprise to see banking Trojans trying to hit these users as well. We’ve seen spammed mails that pretend to be an update notification for an official PayPal app. These mails ask the user to click on a link to download the update; users in Germany appear to be the target of this spam run based on the language used.

As is the case with all spam campaigns, multiple IP addresses from different countries spammed this particular mail at its intended German targets. 41% of these senders were in Vietnam, with other countries such as Ukraine, Russia, Brazil and India accounting for the remainder. Some variants of this message were sent more than 14,000 times.

Read More
Tags: androidmobile bankingpaypal

Two New Android Bugs Mess up Messaging; May Lead to Multiple Send Charges

  • Posted on:August 11, 2015
  • Posted in:Mobile, Vulnerabilities
  • Posted by:
    Seven Shen (Mobile Threats Analyst)
0

Two newly discovered Android vulnerabilities can potentially be used to mess up specific messaging functions in phones and tablets. The first, designated as CVE-2015-3839, may allow attackers to insert malicious messages in the system messaging app and cause it to crash, thus blocking users from sending or receiving messages. Meanwhile, the second flaw, designated as…

Read More
Tags: androidCVE-2015-3839CVE-2015-3840Googlemobile threats

Trend Micro Discovers Apache Cordova Vulnerability that Allows One-Click Modification of Android Apps

  • Posted on:May 27, 2015
  • Posted in:Mobile, Vulnerabilities
  • Posted by:
    Seven Shen (Mobile Threats Analyst)
5

We’ve discovered a vulnerability in the Apache Cordova app framework that allows attackers to modify the behavior of apps just by clicking a URL. The extent of the modifications can range from causing nuisance for app users to crashing the apps completely. Designated as CVE-2015-1835, this high-severity vulnerability affects all versions of Apache Cordova up…

Read More
Tags: androidapachecordovaGooglevunerability
Page 1 of 212

Security Predictions for 2020

  • Cybersecurity in 2020 will be viewed through many lenses — from differing attacker motivations and cybercriminal arsenal to technological developments and global threat intelligence — only so defenders can keep up with the broad range of threats.
    Read our security predictions for 2020.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Popular Posts

Sorry. No data so far.

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.