# New Sky Security > Security done right! ## Posts - [Lvedu.B](https://newskysecurity.com/knowledgebasex1lvedu-b/): AppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Exploit/LVedu.B Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2009-1185 Details or analysis: This is exploit code that takes advantage of the vulnerability CVE-2009-1185 in order to gain root access of the affected device. The exploit affects Android versions prior to 2.2.3, and may have been distributed with other malware. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185 - [Lvedu.A](https://newskysecurity.com/knowledgebasex1lvedu-a/): AppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Exploit/LVedu Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2009-1185 Details or analysis: This is exploit code that takes advantage of the vulnerability CVE-2009-1185 in order to gain root access of the affected device. The exploit affects Android versions prior to 2.2.3, and may have been distributed with other malware. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185 - [Lollipop](https://newskysecurity.com/knowledgebasex1lollipop/): AppRisk Coverage: YesType: InformationAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: None Details or analysis: Lollipop is a code name, or nick name, for Android OS versions 5.0 to 5.1. Reference: http://developer.android.com/about/versions/android-5.0.html http://developer.android.com/about/versions/android-5.1.html http://developer.android.com/about/dashboards/index.html - [KitKat](https://newskysecurity.com/knowledgebasex1kitkat/): AppRisk Coverage: YesType: InformationAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: None Details or analysis: KitKat is a code name, or nick name, for Android OS version 4.4. Reference: http://developer.android.com/about/versions/android-4.4.html http://developer.android.com/about/dashboards/index.html - [Jelly Bean](https://newskysecurity.com/knowledgebasex1jelly-bean/): AppRisk Coverage: YesType: InformationAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: None Details or analysis: Jelly Bean is a code name, or nick name, for Android OS versions 4.1 to 4.3. Reference: http://developer.android.com/about/versions/android-4.1.html http://developer.android.com/about/versions/android-4.2.html http://developer.android.com/about/versions/android-4.3.html - [Infostealer.A](https://newskysecurity.com/knowledgebasex1infostealer-a/): AppRisk Coverage: YesType: TrojanOWASP: M4: Unintended Data LeakageAliases: Trojan:Android/InfoStealer Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2009-1185 Details or analysis: This is trojan code that takes advantage of vulnerability CVE-2009-1185 in order to gain root access of the affected device. The trojan collects various sensitive information and may send this to an attacker. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1185 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185 - [Ice Cream Sandwich](https://newskysecurity.com/knowledgebasex1ice-cream-sandwich/): AppRisk Coverage: YesType: InformationAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: None Details or analysis: Ice Cream Sandwich is a code name, or nick name, for Android OS versions 4.0.3 to 4.0.4. Reference: http://developer.android.com/about/versions/android-4.0.html - [Gingerbread](https://newskysecurity.com/knowledgebasex1gingerbread/): AppRisk Coverage: Not ApplicableType: InformationAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: None Details or analysis: Gingerbread is a code name, or nick name, that references Android OS versions 2.3.3 to 2.3.7. Reference: http://developer.android.com/about/versions/android-2.3.3.html - [Eclair](https://newskysecurity.com/knowledgebasex1froyo-2/): AppRisk Coverage: Not ApplicableType: InformationAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: None Details or analysis: Éclair is a code name, or nick name, that references Android OS 2.0 and 2.1. Reference: http://developer.android.com/about/versions/android-2.1.html - [Froyo](https://newskysecurity.com/knowledgebasex1froyo/): AppRisk Coverage: Not ApplicableType: InformationAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: None Details or analysis: Froyo is a code name, or nick name, that references Android OS 2.2. Reference: http://developer.android.com/about/versions/android-2.2.html http://developer.android.com/about/versions/android-2.2-highlights.html - [ExymemBrk.A](https://newskysecurity.com/knowledgebasex1exymembrk-a/): AppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Exploit/ExymemBrk.A Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2012-4222 Details or analysis: This is exploit code that takes advantage of vulnerability CVE-2012-4222 in order gain root access of the affected device. The code attempts to write to stored code “/dev/exynos-nem” – this code is present on devices using the Exynos ARM processor such as Samsung Galaxy S and other Samsung Android devices and phones. The exploit may be packaged with other code, or another trojan. Reference: http://forum.xda-developers.com/showthread.php?t=2048511 https://en.wikipedia.org/wiki/Exynos https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4222 http://www.kb.cert.org/vuls/id/702452 - [Exploit](https://newskysecurity.com/knowledgebasex1exploit/): AppRisk Coverage: Not ApplicableType: ExploitAliases: Platform: AndroidFile size (bytes): Filename: App title: MD5 Hash: SHA1 hash: Affected CVE: Details or analysis: An exploit is code that may take advantage of a vulnerability. The vulnerability is commonly in a component of the operating system, or in an installed app or service. An exploit may be rendered harmless when the underlying compromise or vulnerability is corrected. Vulnerabilities are corrected through updates of the affected software. - [DroidKungfu.A](https://newskysecurity.com/knowledgebasex1droidkungfu-a/): AppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Trojan: Android/DroidKungFu.A Backdoor.AndroidOS.KungFu Android/DroidFu Trojan:AndroidOS/DroidKrungFu.A Andr/KongFu-A AndroidOS_DROIDKUNGFU Platform: AndroidFile size (bytes): N/AFilename: com.aijiaoyou.android.sipphoneApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2009-1185 Details or analysis: This is exploit code that takes advantage of CVE-2009-1185 in order to root an affected device. Once rooted, the exploit code responds to instructions from an attacker that include performing any of the following actions: Capture SMS or MMS text messages Send captured text messages Locate the device using GPS Identify device state Collect device information including OS version, IMEI, contents of SD card, and internal memory The […] - [DiutesEx.B](https://newskysecurity.com/knowledgebasex1diutesex-b/): AppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Exploit/DiutesEx.B Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2012-4222 Details or analysis: This is variant of a trojan that exploits a vulnerability found in Android (before version 2.2.3) that may result in the trojan gaining root access to the Android device. This exploit code may be bundled with other malware for the purpose of rooting the device. CVE-2012-4222 is a vulnerability in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through 4.2. It allows attackers to cause a denial of service (NULL pointer dereference) via an […] - [DiutesEx.A](https://newskysecurity.com/knowledgebasex1diutesex-a/): AppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Exploit/DiutesEx.A Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2012-4222 Details or analysis: This is a trojan that exploits a vulnerability found in Android (before version 2.2.3) that may result in the trojan gaining root access to the Android device. This exploit code may be bundled with other malware for the purpose of rooting the device. CVE-2012-4222 is a vulnerability in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through 4.2. It allows attackers to cause a denial of service (NULL pointer dereference) via an application that […] - [Darlloz.A](https://newskysecurity.com/knowledgebasex1darlloz-a/): AppRisk Coverage: YesType: VirusOWASP: M4: Unintended Data LeakageAliases: Linux.Darlloz Platform: iOS, LinuxFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2012-1823 CVE-2012-2311 CVE-2012-2335 CVE-2012-2336 Details or analysis: This is a worm that exploits CVE-2012-1823, CVE-2012-2311, CVE-2012-2335, and CVE-2012-2336 in order to spread. On vulnerable systems, the worm attempts to download a copy of its code from an external site gpharma.co. CVE-2012-1823 is a vulnerability in “sapi/cgi/cgi_main.c” found within PHP versions before 5.3.12, and 5.4.x before 5.4.2. When configured as a CGI script (aka “php-cgi“), it does not properly handle query strings that lack an = (equals sign) character. This allows remote attackers to execute […] - [CVE-2015-7888](https://newskysecurity.com/knowledgebasex1cve-2015-7888/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Samsung Galaxy S6 Directory Traversal Vulnerability SVE-2015-4649 Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-7888 Details or analysis: This is a directory traversal vulnerability present in Samsung Galaxy S6 mobile devices, with Android OS 4.4 and above. The vulnerability exists because the service “WifiHS20UtilityService” reads any files written as “/sdcard/Download/cred.zip” and unzips them into “/data/bundle” on the device. An attacker or malicious application could exploit this vulnerability resulting in the execution of arbitrary code. Reference: http://www.securityfocus.com/bid/77338/discuss http://security.samsungmobile.com/smrupdate.html#SMR-OCT-2015 - [CVE-2015-6611](https://newskysecurity.com/knowledgebasex1cve-2015-6611/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Information Disclosure Vulnerabilities in Mediaserver Stagefright 2.0 Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-6611 Details or analysis: There are information disclosure vulnerabilities in mediaserver that can permit a bypass of security measures in place to increase the difficulty of attackers exploiting the platform. Mediaserver service could be invoked when receiving media content from MMS messages, and browser playback of media. The mediaserver service has access to audio and video streams as well as access to privileges that third-party apps cannot normally access. Reference: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6611 […] - [CVE-2015-6610](https://newskysecurity.com/knowledgebasex1cve-2015-6610/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Elevation of Privilege Vulnerability in libstagefright Stagefright 2.0 Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-6610 Details or analysis: There is an elevation of privilege vulnerability in libstagefright that can enable a local malicious application to cause memory corruption and arbitrary code execution within the context of the mediaserver service. Mediaserver service could be invoked when receiving media content from MMS messages, and browser playback of media. The mediaserver service has access to audio and video streams as well as access to privileges that third-party […] - [CVE-2015-6608](https://newskysecurity.com/knowledgebasex1cve-2015-6608/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Remote Code Execution Vulnerabilities in Mediaserver Stagefright 2.0 Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-6608 Details or analysis: This is a remote code execution vulnerability. The mediaserver service in Android OS 4.4 before 5.1.1 (build LMY48X) and 6.0 before 2015-11-01 could allow remote attackers to execute arbitrary code, or cause a denial of service (memory corruption) via a crafted media file. Mediaserver service could be invoked when receiving media content from MMS messages, and browser playback of media. The mediaserver service has access to audio and […] - [CVE-2015-6602](https://newskysecurity.com/knowledgebasex1cve-2015-6602/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Stagefright vulnerability Stagefright 2.0 Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-6602 Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libutils“. This specific vulnerability affects Android OS prior to 5.1.1. If successfully exploited, the vulnerability could allow a malicious application or individual to execute arbitrary code with elevated privileges, or cause a denial of service, via crafted metadata in MP3 or MP4 files. In an attack scenario involving MMS, an attacker could send attack code via a […] - [CVE-2015-3864](https://newskysecurity.com/knowledgebasex1cve-2015-3864/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Stagefright vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-3864 Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libstagefright“. The library is responsible for processing multimedia files. This specific vulnerability is due to multiple integer overflows in the “MPEG4Extractor::parseChunk” function in “MPEG4Extractor.cpp” within libstagefright and affects Android OS prior to 5.1.1. This vulnerability is a result of an incomplete fix for CVE-2015-3824. If successfully exploited, the vulnerability could allow a malicious application or individual to […] - [CVE-2015-3829](https://newskysecurity.com/knowledgebasex1cve-2015-3829/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Stagefright vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-3829 Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libstagefright“. The library is responsible for processing multimedia files. This specific vulnerability is due to multiple integer overflows in the “MPEG4Extractor::parseChunk” function in “MPEG4Extractor.cpp” within libstagefright and affects Android OS prior to 5.1.1. If successfully exploited, the vulnerability could allow a malicious application or individual to execute arbitrary code with elevated privileges, or cause a denial of […] - [CVE-2015-3828](https://newskysecurity.com/knowledgebasex1cve-2015-3828/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Stagefright vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-3828 Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libstagefright“. The library is responsible for processing multimedia files. This specific vulnerability is due to multiple integer overflows in the “MPEG4Extractor::parse3GPPMetaData” function in “MPEG4Extractor.cpp” within libstagefright and affects Android OS prior to 5.1.1. The vulnerability exists because the responsible code does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM). If successfully […] - [CVE-2015-3826](https://newskysecurity.com/knowledgebasex1cve-2015-3826/): Severity Level: HighAppRisk Coverage: NoType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Stagefright vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-3826 Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libstagefright“. The library is responsible for processing multimedia files. This specific vulnerability is due to multiple integer overflows in the “MPEG4Extractor::parse3GPPMetaData” function in “MPEG4Extractor.cpp” within libstagefright and affects Android OS prior to 5.1.1. The vulnerability exists because the responsible code does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM). If successfully […] - [CVE-2015-3825](https://newskysecurity.com/knowledgebasex1cve-2015-3825/): Severity Level: High AppRisk Coverage: Yes Type: Vulnerability OWASP: M4: Unintended Data Leakage Aliases: OpenSSLX509Certificate deserialization Vulnerability Platform: Android File size (bytes): N/A Filename: N/A App title: N/A MD5 Hash: N/A SHA1 hash: N/A Affected CVE: CVE-2015-3825 Details or analysis: This is a privilege escalation and arbitrary code execution vulnerability. The vulnerability is present in an Android framework class “OpenSSLX509Certificate“. An attacker could exploit this vulnerability to give a malicious app with no privileges the ability to become a “super app” and also give control of the affected device. Reference: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3825 http://drops.wooyun.org/papers/10235 https://www.usenix.org/system/files/conference/woot15/woot15-paper-peles.pdf - [CVE-2015-3824](https://newskysecurity.com/knowledgebasex1cve-2015-3824/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityAliases: Stagefright vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-3824 Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libstagefright“. The library is responsible for processing multimedia files. This specific vulnerability is due to multiple integer overflows in the “MPEG4Extractor::parseChunk” function in “MPEG4Extractor.cpp” within libstagefright and affects Android OS prior to 5.1.1. The vulnerability exists because the responsible code does not properly restrict size addition. If successfully exploited, the vulnerability could allow a malicious application or individual to execute arbitrary […] - [CVE-2015-3636](https://newskysecurity.com/knowledgebasex1cve-2015-3636/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Platform: Android, LinuxFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-3636 Details or analysis: This is a privilege escalation vulnerability. Linux kernel’s ping socket implementation did not properly handle socket unhashing during spurious disconnects, which could lead to a use-after-free flaw. The vulnerable code is present in “/net/ipv4/ping.c” affecting both Linux and Android. The “ping_unhash” function in “ping.c” in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation. This vulnerability allows local users to gain privileges or cause a […] - [CVE-2015-1539](https://newskysecurity.com/knowledgebasex1cve-2015-1539/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityAliases: Android-20139950 Stagefright vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-1538 CVE-2015-1539 Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libstagefright“. The library is responsible for processing multimedia files. This specific vulnerability is due to multiple integer overflows in the “ESDS::parseESDescriptor” function in “ESDS.cpp” within libstagefright and affects Android OS prior to 5.1.1. If successfully exploited, each vulnerability could allow a malicious application or individual to execute arbitrary code with elevated privileges, via crafted ESDS atoms in MPEG-4 data. In an […] - [CVE-2015-1538](https://newskysecurity.com/knowledgebasex1cve-2015-1538/): Severity Level: High AppRisk Coverage: Yes Type: Vulnerability Aliases: Android-20139950 Stagefright vulnerability Platform: Android File size (bytes): N/A Filename: N/A App title: N/A MD5 Hash: N/A SHA1 hash: N/A Affected CVE: CVE-2015-1538 CVE-2015-1539 Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libstagefright“. The library is responsible for processing multimedia files. This specific vulnerability is due to an integer overflow in the “SampleTable::setSampleToChunkParams” function in “SampleTable.cpp” within libstagefright and affects Android versions prior to 5.1.1. If successfully exploited, each vulnerability could allow a malicious application or individual to execute arbitrary code with […] - [CVE-2015-1528](https://newskysecurity.com/knowledgebasex1cve-2015-1528/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Elevation of Privilege Vulnerability in Binder Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-1528 Details or analysis: This is a privilege escalation vulnerability. Once exploited, it could give a malicious application or individual control and access of the vulnerable device. The specific flaw is an integer overflow vulnerability in the “native_handle_create” function in “libcutils/native_handle.c” in Android before 5.1.1. For more information, see the reference links. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1528 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1528 - [CVE-2015-1474](https://newskysecurity.com/knowledgebasex1cve-2015-1474/): Severity Level: HighAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-1474 Details or analysis: This is a denial of service vulnerability. The vulnerability is caused by multiple integer overflows in the “GraphicBuffer::unflatten” function in “platform/frameworks/native/libs/ui/GraphicBuffer.cpp“, affecting Android OS versions through 5.0. Successful exploitation of the vulnerability could allow an attacker to gain privileges or cause a denial of service. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1474 http://www.cvedetails.com/cve/2015-1474 - [CVE-2014-4943](https://newskysecurity.com/knowledgebasex1cve-2014-4943/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Platform: Android, LinuxFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2014-4943 Details or analysis: This is a privilege escalation vulnerability. Once exploited, it gives a malicious application or individual control and complete access to the vulnerable device. The specific flaw was identified in the Android kernel and is found in the implementation of PPP over L2TP sockets. For more information, see the reference links. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4943 - [CVE-2014-3153](https://newskysecurity.com/knowledgebasex1cve-2014-3153/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Towelroot bug Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2013-4787 Details or analysis: Also known as the “towelroot bug” this vulnerability allows a malicious application or individual the ability to obtain complete access to a vulnerable device. The vulnerability, which also affects some Linux versions, was identified in the Android kernel. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3153 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153 - [CVE-2013-6282](https://newskysecurity.com/knowledgebasex1cve-2013-6282/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2013-6282 Details or analysis: This is a vulnerability in two API functions within Linux kernel 3.5.5 on the v6k and v7 ARM platforms. The vulnerability is present in the two API functions “get_user” and “put_user” because they do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application. This was exploited in the wild against Android devices in October and November 2013. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6282 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6282 - [CVE-2013-4787](https://newskysecurity.com/knowledgebasex1cve-2013-4787/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Master Key vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2013-4787 Details or analysis: This exploit attempts to gain root privilege of the affected Android device via neutering the Android property service. Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications. This could allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature. Distribution of this exploit code may involve multiple entries in a Zip […] - [CVE-2011-1149](https://newskysecurity.com/knowledgebasex1cve-2011-1149/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Ashmembrk.A Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2011-1149 Details or analysis: This exploit attempts to gain root privilege of the affected Android device via neutering the Android property service. Android versions prior to 2.3 do not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges. Related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1149 http://c-skills.blogspot.com/2011/01/adb-trickery-again.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1149 - [Crisis.A](https://newskysecurity.com/knowledgebasex1crisis-a/): AppRisk Coverage: YesType: TrojanOWASP: M4: Unintended Data LeakageAliases: Andr/Crisis-A Android.Trojan.InfoStealer.DI Platform: AndroidFile size (bytes): Filename: App title: MD5 Hash: SHA1 hash: Affected CVE: Details or analysis: This is a trojan that could be instructed by an attacker to gather sensitive information and upload it to a specified external location. The trojan could be instructed to perform any of the following, based on permissions requested: record audio capture SMS messages send SMS messages get GPS fine or coarse location access device logs This trojan was known to be distributed within Android Package (.APK) files. - [Certificate Verification Vulnerability](https://newskysecurity.com/knowledgebasex1certificate-verification-vulnerability/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2015-1793 Details or analysis: The Certificate Verification Vulnerability, also known as CVE-2015-1793, was introduced in June 2015. The vulnerability affects OpenSSL versions 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c. The Certificate Verification Vulnerability is a weakness that can misdirect users to a fake site by bypassing the correct website certificate verification process. The problem exists due to an incorrect implementation in how a certificate chain is verified as a result of a June 2015 OpenSSL update. The vulnerability makes it […] - [Ashmembrk.A](https://newskysecurity.com/knowledgebasex1ashmembrk/): AppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: CVE-2011-1149 Platform: AndroidFile size (bytes): Filename: App title: MD5 Hash: SHA1 hash: Affected CVE: CVE-2011-1149 Details or analysis: This exploits CVE-2011-1149 to get root privilege via neutering the Android property service. Android versions prior to 2.3 do not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges. Related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1149 http://cve.scap.org.cn/CVE-2011-1149.html http://c-skills.blogspot.com/2011/01/adb-trickery-again.html - [Knowledgebase Archive](https://newskysecurity.com/kb-articles/): Search for: Exploit Ashmembrk.A Exploit   Trojan Crisis.A         - [Temperature, Humidity, and Energy Monitoring](https://newskysecurity.com/temperature-humidity-energy-monitoring/): EcoBee3 Ordinary thermostats only read the temperature in one room, but are supposed to deliver comfort in all rooms. Ecobee3 remote sensors deliver the right temperature in the rooms that matter most. Now homekit enabled. Ecobee3 sensors know which rooms are occupied to deliver the right temperature in the right places. And they know whether someone’s home to help you save energy and money when you’re away. Ecobee3 comes with 1 free remote sensor that measures temperature and occupancy. You can have up to 32 sensors. The more you add, the smarter your Ecobee3 becomes at delivering comfort where it […] - [Your Device Is My Miner: How Hackers Steal Your Cryptocurrency](https://newskysecurity.com/your-device-is-my-miner-how-hackers-steal-your-cryptocurrency-6fd273f6d4a/): Since bitcoin hit its record high value of $20,000 in 2017, more and more individuals have participated in the cryptocurrency economy. Subsequently, cryptocurrency security has played an increasingly critical role in making the virtual economy safe. How to mine a bitcoin? How to prevent hackers from stealing your cryptocurrency? To answer these questions, NewSky Security’s CTO & Co-founder, Song Li, recently conducted a workshop at Cloud Security Alliance Seattle Chapter. Distributed Database Song began the talk with an explanation of basic cryptocurrency concepts. From Song’s point of view, every cryptocurrency is a form of a distributed database, which tracks data […] - [Information Disclosure Vulnerability CVE-2018-7900 Makes It Easy for Attackers to Find Huawei Devices at Risk | by NewSky Security | NewSky Security](https://newskysecurity.com/information-disclosure-vulnerability-cve-2018-7900-makes-it-easy-for-attackers-to-find-huawei-3e7039b6f44f/):   Introduction: Not All Attack Vectors are Created Equal By 2018, it is commonplace for attackers to deploy both IoT exploits as well as weak password attacks to increase their bot counts. However, all attack vectors are not deemed equal in the eyes of attackers and some become more popular than others. For example, the attack vectors which can infect a huge number of IoT devices are much favored than a using a vulnerability in a vendor which has only 500 devices online. Hence, in 2018 we saw CVE-2018-14847 (Mikrotik) and CVE-2014-8361 are being highly used. One commonality among them […] - [Tracking the People Behind Botnets: A List of Top 20 IoT Blackhat Hackers](https://newskysecurity.com/tracking-the-people-behind-botnets-a-list-of-top-20-iot-blackhat-hackers-3a67d7bd3be0/): While most people treat malware as just a piece of code, behind it is a human creating the content, and an entire ecosystem where the malicious code is changed to money. In the context of IoT botnets, we will be discussing Top 20 IoT Blackhat hackers and how they are impacting and shaping this illegal industry. Threat actors who are still active are represented by 🔴 red color, dormant threat actors by ⚫ black and retired (or forced to retire by law enforcement) have been represented by 🔵 blue. 1. 🔵 DREAD / PARAS — The creator of infamous Mirai botnet, Paras […] - [Hacker Fail: IoT botnet command and control server accessible via default credentials](https://newskysecurity.com/hacker-fail-iot-botnet-command-and-control-server-accessible-via-default-credentials-2ea7cab36f72/): In an irony of epic proportions, we observed that an IoT botnet variant, Owari, which relies on default/weak credentials to hack IoT devices was itself using default credentials in its command and control server, allowing read/write access to their server database. Owari’s MySQL database Mirai botnet was designed to set up a MySQL server for the command and control containing three tables, namely users, history, and whitelist. While IoT botnets have evolved and many of them have different attack vectors, most of them still retain this tried and tested MySQL server structure, and Owari is no exception to this. We observed […] - [ForgotDoor: Routers in Singapore accidentally give complete access to potential IoT attackers](https://newskysecurity.com/forgotdoor-routers-in-singapore-accidentally-give-complete-access-to-potential-iot-attackers-ed60895c5042/): Since the inception of Mirai, IoT attacks have diversified, using varying types of attack vectors to gain access to connected devices. Despite the differences, IoT attacks can be loosely classified into three levels: Level 0 (attacking device with no authentication), Level 1 (guessing a weak/default password), and Level 2 (using an IoT exploit to gain access). While it might be expected that level 0 attacks can be easily prevented and such attacks should not be happening with raising awareness in IoT, our findings do not suggest the same. The IP list for Singtel Wi-Fi gigabit router devices that have their […] - [CVE-2018–10561 Dasan GPON exploit weaponized in Omni and Muhstik botnets](https://newskysecurity.com/cve-2018-10561-dasan-gpon-exploit-weaponized-in-omni-and-muhstik-botnets-ad7b1f89cff3/):   Introduction Almost two years since the inception of the Mirai attack, IoT attackers have shifted to use IoT exploits to take control of devices. The attackers are acting quickly on weaponizing one-day exploits, which are low hanging yet very delicious fruits. While discovering a zero-day in an IoT may consume time and resource, IoT attackers find it much more effective to track the publicly revealed exploits and to weaponize them as early as possible for making money. Roughly a week ago, a critical exploit CVE-2018–10561 found in over a million GPON home routers was reported along with POC explanation. […] - [Cryptocurrency Mining Hacks: How Thefts Steal Bitcoin and Ethereum](https://newskysecurity.com/cryptocurrency-mining-hacks-how-thefts-steal-bitcoin-and-ethereum-903b215dbbba/): Over the last year, cryptocurrency broke into mainstream with its dramatic highs and lows. With ever increasing buzz about cryptocurrency, various attack methods for crypto thefts have emerged, especially because it is much easier to transfer funds with anonymity compared to conventional methods, like a fraudulent bank transfer, which can quickly be reverted or blocked as well as backtracked. Attackers are not limiting themselves in a single way as we are observing attacks on mining hardware, software, wallets as well as system of owners who can be a potential candidate for a forced miner installation. To track each class of […] - [NewSky Security Presenting IoT Security Research at AVAR 2017 Conference | by NewSky Security | NewSky Security](https://newskysecurity.com/newsky-security-presenting-iot-security-research-at-avar-2017-1703d85fbff7/): Ankit Anubhav shared his research in the IoT threat landscape in AVAR 2017 As the only IoT security research speaker among 300 experts and scholars from more than 100 well known cyber security enterprises, Ankit Anubhav, the Principal Researcher at NewSky Security, shared his research in the IoT threat landscape at the Association of Anti Virus Asia Researchers (AVAR) conference, on 6–8 December 2017, with the aim to raise awareness and create a united community for IoT security. AVAR was funded in June, 1998 with a mission to prevent the spread of malware and its damage. This year is the […] - [Up for grabs: US Government Lexmark printers (and thousands of others) exposed on the Internet with no security](https://newskysecurity.com/up-for-grabs-us-government-lexmark-printers-and-thousands-of-others-exposed-on-internet-with-no-3b860e2969d1/): We observed that more than one thousand Lexmark printers have no password. Some of these printers are connected to potentially sensitive networks, including one in the US Government. Introduction An enterprise network is as secure as its weakest link. While in many cases the endpoints are secured by an efficient Antivirus/CyberSecurity software, other connected devices on the network might not be privileged enough to share the same security. Many people have the awareness to change router passwords, but printer security is still neglected at large. Similarly, we observed that more than one thousand Lexmark printers are up for grabs by […] - [“StartWallet”: How not to lose money while cryptomining](https://newskysecurity.com/startwallet-how-not-to-lose-money-while-cryptomining-802d953da8d1/): Introduction Over the last year, cryptocurrency has been amongst the top in making news despite the volatility. The two common ways to possess cryptocurrency is via trading or mining some of your own. Cryptomining has seen two interesting developments, one is the rise of browser Cryptojacking where people are unknowingly mining cryptocurrencies by visiting sites with the hidden Cryptomining code. The other development has been the rise of enthusiasts to mine cryptocurrencies legitimately by using mining software for their dedicated or personal equipment. This has led to introduction of many non-tech savvy people into this field, who want an easy […] - [School Stored a Marker You Don’t Want](https://newskysecurity.com/school-stored-a-marker-you-dont-want-600065126c04/): Stanford University (CA, US) was found hosting a document infected with retro malware for the last 15 years.   NewSky Security observed a document infected with a legacy macro virus (Word/Marker) hosted on a Stanford University domain. The link was still up at the time of writing. The document consists of the curriculum vitae of a Professor who, at the time, was a PhD fellow at Stanford:   Image 1: Snip view of infected document content The Marker virus variant contains an additional macro which has the viral code to add record of already infected computers, and send stolen logs […] - [NBotLoader: Netgear Bug Weaponized as a Dangerous Exploit](https://newskysecurity.com/nbotloader-netgear-bug-weaponized-as-a-dangerous-exploit-ea7869217e89/): Introduction In the field of malware development, one important factor is the extent of collaboration and sharing between malware authors. This sharing of resources lends malware to be quantified as “MaaS” or Malware as a Service. As the malware code is shared and is more readily available among threat actors, the probability also increases that its usage is more widespread. The malware for Internet of Things aligns with this trend. It is often observed that when malicious code is readily available, it causes more havoc as it generally leads to more re-use by “script kiddies” (copy-and-paste low-skilled hackers) and thus […] - [Fake Adobe website delivers BetaBot | by NewSky Security | NewSky Security](https://newskysecurity.com/fake-adobe-website-delivers-betabot-4114d1775a18/): Introduction The key to a successful cyberattack is deception. In most cases, the initial attack vector requires help from the victim (for example open an attachment, click a link, visit a website serving exploit, enable macros, and so on). The by-product is dubbed social engineering. Due to increased security awareness and the use of security measures, attackers need to be creative to initiate the first level of attack in the victim’s system. We observed one similar case where the attackers have gone the extra mile to impersonate a well-known site Adobe to deliver the BetaBot malware. Adobe vs Adoḅe Attackers […] - [Case Study: Hacking Smart Lock Security](https://newskysecurity.com/case-study-hacking-smart-lock-security-ef3278e3e3de/): Update: This case study was presented at the CanSecWest 2016 conference held in Vancouver, British Columbia, Canada. The presentation is available as a PDF from this link. Exponential growth of smart technology and Bluetooth Smart With the booming of Internet of Things (IoT), Bluetooth Smart, or Bluetooth v4.0 (aka Low Energy or BLE), has played an increasing role in technology adoption. According to Bluetooth SIG, the global market is expected to reach 1.2 billion Bluetooth Smart devices and 2.7 billion Bluetooth Smart Ready devices by 2020. The power efficiency of BLE is a perfect fit for IoT devices. From Bluetooth.com, […] - [Beyond NBotLoader. A system is only as secure as its…](https://newskysecurity.com/beyond-nbotloader-f1430beb8ad/): Beyond NBotLoader A system is only as secure as its weakest link, and the same applies to the field of Cybersecurity. While the most emphasis is commonly placed on security measures and precautions such as antivirus or endpoint technologies to secure end user systems, quite often, router security hasn’t been taken as seriously. This negligence in router security is leveraged by attackers and a hacked router can be a gateway to the end users system. Router security is often limited in configuration such as changing a default password to a strong one. However, and as we see with NBotLoader, this […] - [Agile QBot Variant Adds NbotLoader Netgear Bug in Its New Update](https://newskysecurity.com/agile-122bf2f4e2f3/): Introduction QBot, also known as Bashlite, is one of the most widely known IoT Botnet frameworks, and is often stated as a precursor of Mirai. The IoT security landscape has changed a bit since the Mirai outbreak, and the awareness for improved security among IoT users has increased. Hence to remain relevant, QBot must evolve, and we are observing the same in a one of the latest binary samples of QBot. Update 1 to QBot: NbotLoader module added We recently observed that Bug 60281 (or the NbotLoader bug) is weaponized and freely being shared in hacking forums, and we predicted […] - [Understanding the IoT Hacker — A Conversation With Owari/Sora IoT Botnet Author](https://newskysecurity.com/understanding-the-iot-hacker-a-conversation-with-owari-sora-iot-botnet-author-117feff56863/): Since the outbreak of Mirai, IoT threat landscape has seen a lot of new threat actors as well as attack methods. Although people often treat IoT malware as just a malicious piece of code, behind IoT malware development there is human involvement with varying motives. For building an effective approach to combat IoT threats, understanding the psychology and motivation behind threats can be a useful asset. NewSky Security has been following an IoT threat actor, known better with his pseudo name “Wicked” in IoT malware circles via forum monitoring and honeypot analysis. “Wicked” has been involved in two IoT botnets, […] - [DoubleDoor: IoT Botnet bypasses firewall as well as modem security using two backdoor exploits](https://newskysecurity.com/doubledoor-iot-botnet-bypasses-firewall-as-well-as-modem-security-using-two-backdoor-exploits-88457627306d/): Introduction Within two years, IoT attacks have seen rapid evolution. We now see that IoT threats, which have already evolved from admin: admin attacks, to usage of exploits are evolving to not only bypass IoT authentication but they are also ready to fight an extra layer of security i.e. a firewall which protects the device. Consequently, if a security adept user has an authentication set for the specified IoT and protects it by firewall, both layers of security will be breached by this campaign, and the device’s control will be in the hands of the DoubleDoor botmasters. The Backdoors As […] - [Masuta : Satori Creators’ Second Botnet Weaponizes A New Router Exploit.](https://newskysecurity.com/masuta-satori-creators-second-botnet-weaponizes-a-new-router-exploit-2ddc51cc52a7/): Introduction Since the inception of the Mirai code leak, many botnets have been seen in the IoT threat landscape. While some of them are clearly Mirai carbon copies, others have added new attack methods, often taking the route of exploits to perform an attack. We analyzed two variants of an IoT botnet named “Masuta” where we observed the involvement of a well-known IoT threat actor and discovered a router exploit being weaponized for the first time in a botnet campaign. Masuta Code Leak & Attribution We were able to get hands on the source code of Masuta (Japanese for “master”) […] - [Huawei router exploit involved in Satori and Brickerbot given away for free on Christmas by…](https://newskysecurity.com/huawei-router-exploit-involved-in-satori-and-brickerbot-given-away-for-free-on-christmas-by-ac52fe5e4516/): Introduction NewSky Security observed that a known threat actor released working code for Huawei vulnerability CVE-2017–17215 free of charge on Pastebin this Christmas. This exploit has already been weaponized in two distinct IoT botnet attacks, namely Satori and Brickerbot. CVE-2017–17215, a vulnerability in Huawei HG532 devices, was discovered during a zero-day Satori attack by Checkpoint and was discreetly reported to Huawei for a fix. The proof of concept code was not made public to prevent attackers from abusing it. However, with the release of the full code now by the threat actor, we expect its usage in more cases by […] - [Script Kiddie Nightmare: IoT Attack Code Embedded with Backdoor](https://newskysecurity.com/script-kiddie-nightmare-iot-attack-code-embedded-with-backdoor-39ebcb92a4bb/): Introduction The IoT threat landscape is proving to be the fastest to evolve, with attacks shifting from basic password guessing, to using a variety of exploits as seen recently in the IoTroop/Reaper botnet. Enter the script kiddie — amateurish hackers that copy/paste code for quick results. With the numerous disclosures of proof-of-concept IoT exploit code, many script kiddies jump on the exploit bandwagon by using weaponized attack scripts that are shared in various shady forums. The market is particularly hot for IoT devices using a vulnerable version of an embedded GoAhead server. This arises due to the fact that there are a […] - [A Huge Wave of IoT Zombies Coming – NewSky Security](https://newskysecurity.com/a-huge-wave-of-iot-zombies-are-coming-42d61d6cada0/): Introduction Evolution is an integral part when it comes to malware, as attackers need to be one step ahead of whitehats to evade detection. While IoT malware started with simple attacks based on weak passwords, malware has been continuously evolving and taking more strategic approaches, such as cross-platform exploits, to impact a larger number of devices. The default password attack is almost near saturation, i.e. the devices which can be hacked easily via default passwords have already been hacked. Also, with the recent awareness of IoT threats, many organizations and consumers have started implementing stronger passwords, hence forcing attackers to […] - [US Government Site Unwittingly Hosting Malware – NewSky Security](https://newskysecurity.com/us-government-site-unwittingly-hosting-malware-f1f4f11b6a1d/): Introduction: With ever improving spam filters and blacklisting employed as security solutions, it is becoming a challenge for attackers to kickstart the first phase of an attack cycle. Often security solutions blacklist an entire range of IP addresses and the potential target is saved from such attack (because the site is blocked before they visit it). To counter this measure, attackers focus on hosting malware in legitimate places, such as Google documents, or websites which are “known/proven clean”. As it turns out, one ideal scenario for an attacker would be to host malware on a government site. If they can […] - [Dyn Attack Calls for Trustworthy Computing in IoT Blog](https://newskysecurity.com/2016x110x1dyn-attack-calls-trustworthy-computing-iot/): On Friday, Oct 21, 2016, a massive distributed denial of service (DDoS) attack was targeted against Dyn, a world renowned DNS service provider. The DDoS attack resulted in a widescale service outage for well-known websites such as Twitter, PayPal, Netflix, Reddit, Spotify, Etsy, and Box, from 7:31 a.m to 9:20 a.m EST. According to CNBC, which sourced from Dyn, the attack was launched via the compromise and takeover of IoT (“Internet of Things”) devices. IoT devices can include hardware such as routers, VoIP phones, DVRs, webcams, and smart TVs to name a few. Shortly after the attack, Dyn stated the […] - [Brute Force Vulnerability in Netgear ARLO Blog](https://newskysecurity.com/2016x109x1brute-force-vulnerability-netgear-arlo/): Update: CVE-2016–10115 and CVE-2016–10116 have been enlisted by MITRE. Refer to the following CVE entries: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10115 CVE – CVE-2016-10116 Common Vulnerabilities and Exposures (CVE®) is a dictionary of common names (i.e., CVE Identifiers) for publicly known… cve.mitre.org Base Station to Camera Communication Basics As we shared in a previous blog article, the Netgear ARLO security camera system consists of a base station and multiple camera units that operate on batteries. The ARLO base station and camera communicate through a private Wi-Fi network. The camera joins the network using WPS mode; by pressing the sync button on the base station and […] - [Factory Reset Vulnerability in Netgear ARLO – NewSky Security](https://newskysecurity.com/2016x109x1factory_reset_vuln_in_netgear_arlo/): Update: CVE-2016–10115 and CVE-2016–10116 have been enlisted by MITRE. Refer to the following CVE entries: CVE – CVE-2016-10115Common Vulnerabilities and Exposures (CVE®) is a dictionary of common names (i.e., CVE Identifiers) for publicly known…cve.mitre.org CVE – CVE-2016-10116Common Vulnerabilities and Exposures (CVE®) is a dictionary of common names (i.e., CVE Identifiers) for publicly known…cve.mitre.org In our ongoing curiosity of IoT products, we took a look at ARLO, a home security camera system from Netgear. ARLO is Netgear’s competing product to the Google Nest Dropcam. When I first researched network security cameras last summer ahead of a planned and lengthy vacation, ARLO, […] - [Brute Force Vulnerability in Netgear ARLO](https://newskysecurity.com/brute-force-vulnerability-in-netgear-arlo-f561c3bc1f3d/): Update: CVE-2016–10115 and CVE-2016–10116 have been enlisted by MITRE. Refer to the following CVE entries: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10115 BBM Apk Download CVE – CVE-2016-10116 Common Vulnerabilities and Exposures (CVE®) is a dictionary of common names (i.e., CVE Identifiers) for publicly known… cve.mitre.org Base Station to Camera Communication Basics As we shared in a previous blog article, the Netgear ARLO security camera system consists of a base station and multiple camera units that operate on batteries. The ARLO base station and camera communicate through a private Wi-Fi network. The camera joins the network using WPS mode; by pressing the sync button on the base […] - [Malvertising - Getting More Than You Pay For](https://newskysecurity.com/2016x106x1malvertising-getting-pay/): Updated July 1, 2016 – We shared our findings, and these ad fraud IoCs, with the Facebook ThreatExchange security group. Many thanks Facebook for their ThreatExchange platform so that we can continue to share details of threat actors and other artifacts with the global security community. In one mobile security research forum that we participate in, one emerging Android app was reported to have slipped into the Google Play app store. The app is a trojan in that it pretends to be a useful app but instead displays advertising. As of June 8th when we initiated this blog post, the […] - [Sonorousness ransomware unmasked](https://newskysecurity.com/2016x104x1sonorousness-ransomware-unmasked/): Sonorousness: the latest ransomware of the S-Locker family Recently, NewSky Security received a threat sample from the security community that is a derivative of the S-Locker ransomware malware group, or family. This new derivative is known as Sonorousness, named for a class within the malware called “com.sonorousness“. When compared to S-Locker, this new malware contains some enhanced code protection techniques that resulted in a more difficult code analysis. We provide our analysis in this post. The APK Overview The Sonorousness ransomware is combined with an app that promises to deliver porn media. When installed, it performs the following behaviors. Protects […] - [Rediscovery of NetUSB Vulnerability in Broadband Routers](https://newskysecurity.com/2016x102x1rediscovery-of-netusb-vulnerability-in-broadband-routers/): Recently NewSky Security Labs performed white-box testing on a Netgear networking product, the R6050 model. During our investigation into the system, we found an exploitable vulnerability in the NetUSB module present in the system. NetUSB is a proprietary technology developed by the Taiwanese company KCodes, intended to provide “USB over IP” functionality. NetUSB is included in millions of currently in-use and popular broadband routers, including models from the following vendors: Allnet Ambir TechnologyAMITAsanteAtlantis CoregaDigitusD-LinkEDIMAXEncore ElectronicsEngenius Etop Hardlink Hawking IOGEAR LevelOne Longshine NETGEARPCI PROLiNK Sitecom Taifa TP-LINKTRENDnetWestern DigitalZyXEL Also, to our surprise the same issue was already reported back in 2015 […] - [Are smart locks secure? -Hacking smart locks](https://newskysecurity.com/2016x102x1hacking-smart-locks/): Smart locks are no exception to this IoT trend and have become popular with homeowners. The following blog post talks about how we hacked a Kwikset Kevo Smart Lock. It describes how Kwikset Kevo Smart Lock works; vulnerabilities and attack vectors of the Kevo Smart Lock. See the English version of this article: Case Study: Hacking Smart Lock Security 楔子:智能技术和Bluetooth Smart呈指数级增长 随着物联网的繁荣发展,Bluetooth Smart技术或是蓝牙4.0版本 (aka低能耗或蓝牙低能耗)为这项技术的应用发挥了日益重要的作用。根据蓝牙技术联盟预估,到2020年全球蓝牙智能设备数量将达到 12 亿部,蓝牙智能Ready的设备将达到27 亿部。BLE(蓝牙低能耗)技术为物联网设备提供了极佳的电源性能。Bluetooth.com描绘了如此美妙的场景:”当醒来出去跑步的时候,带上一个能和智能手表通讯的心率监视器。通过智能手机或平板电脑,还能打开家门,开灯,设定温度,通过淋浴头来听音乐,以及操控您的电视。“ 蓝牙智能门锁: 另一个10亿的物联网市场以及我们对其脆弱性的研究 在物联网的浪潮席卷下,智能门锁也不例外,受到了广大业主的欢迎。消费类电子产品预测2014 年6亿美金的全球智能门锁市场到2019年将增长到37亿。智能门锁可以通过和您的智能手机或者蓝牙门钥匙建立蓝牙连接来自动检测您出现的位置。 那么,市面上的智能门锁的安全性怎么样呢?我们对几种智能门锁来进行了研究,挖掘潜在的入侵脆弱性。这其中有一些排名前5的智能门锁品牌。在这篇博客中,我们将以凯特安Kevo智能锁为例来阐述。 0X01  凯特安kevo智能门锁的工作原理作为市场领导品牌,凯特安的kevo智能门锁具备先进的设计理念和用户体验,下面列举了一些炫酷的功能: 没有智能手机?这都不是事。智能手机并不是必须滴,因为Kevo智能钥匙的蓝牙LE传感器不断的进行广播,智能门锁检测到钥匙的存在,当智能钥匙在一定的短距离范围内,门锁开启了“触碰开锁”功能。您可以把Kevo智能钥匙挂钥匙链上,简单方便。 图片1 Kevo智能门锁和智能钥匙 方向或位置传感的安全性设计:显然在安保方面,Kevo已经做了很多努力:Kevo采用了正在申请专利的定位技术,能够在授权进门以前,检测一个被授权的用户是在屋内还是屋外,这有助于阻止未授权的进入 图片二:当钥匙在附件时触碰开锁 低能耗:低能耗是BLE设备受赞誉的亮点所在。研发Beacon软件的 Aislelabs公司 一项研究报告显示:使用1,000 mAh 纽扣电池的外围设备,如接近信标,通常可持续使用1-2年 、凯特安Kevo的 网站上说明,”Kevo 门锁需要 4 节 AA 电池,钥匙需要一个 CR2025 电池。根据不同的用途,电池应能够持续一年直到需要更换。良好的能耗性能,Kevo 智能门锁被业内人士所期待。 0X02  Kevo智能门锁:攻击途径下面的视频展示了凯特安Kevo智能门锁的脆弱性和攻击途径   我们把脆弱性和攻击途径划分了以下三种类型1、 通过抢占通信实现拒绝服务 (DoS) 。在这种情况下,攻击者/黑客可以劫持并阻止 Kevo 钥匙和门 锁的通信,从而阻止业主开锁。我们漏洞验证程序能够验证,通过使用手机app来实现一个攻击场景。在智能钥匙连接到门锁控制单元以前,执行攻击的app应用有目的地连接到BLE智能钥匙。这样,门锁停止响应锁栓的触碰开锁请求。当攻击验证程序断开连接,并释放钥匙,门锁功能恢复如常。您看,在您家附近完成一个攻击,so easy而又成本低廉。 凯特安在安全方面已经投入了相当多的考量。如果抢占通信DoS只是针对智能门锁本身,它也就能在几秒钟内暂时阻止开门,几秒钟后,门锁将攻击设备列入黑名单,并通过BLE断开连接。 然而,我们的漏洞验证程序采取不同的方式,攻击是通过钥匙来执行,并不是和智能门锁直接通讯。2、 通过耗尽钥匙电量来执行拒绝服务 (DoS)。虽然 BLE 标准和通常承诺一年的电池寿命,漏洞验证程序表明我们可以将钥匙的电池寿命缩短到两个星期,甚至更短,从而导致拒绝服务。我们在测试期间,Kevo 钥匙以令人吃惊的速度在消耗电量。我们对一个新电池进行了约 2 个星期的测试,其间只持续了两天的加压测试,电池电量就耗光了。如果黑客运用这种技术,他应该不断的和钥匙扣连接以达到耗电的目的,这只需几天。我们觉得这种方式算是拒绝服务攻击的一种延伸,因为主人很有可能发现钥匙扣没电了,然后去便利店换一个新的。3、 劫持和控制。通过劫持进一步控制智能钥匙。以下几种场景黑客都能够攻破并进入受害者的房子:a. 任何受害者携带智能钥匙在屋里的时间里b. 当你在回家路上距离家很近的这一段短时间窗c. 或者任何主人不在而钥匙放在家的时间里 在以上这些场景中,一个黑客劫持了Kevo钥匙并强制它处于虚假安全模式,或者伪睡眠模式。主人测试钥匙扣以确认它没有被打开(目的是入侵者不能打开门锁进来)。然而,黑客能够在任何时候唤醒钥匙去打开Kevo门锁。 同时,我们看到在安全性方面Kevo也进行了加强,如果激活后30秒没有任何动作的话,门锁停止向钥匙发送BLE信号。我们确信超时以后,智能钥匙使用陀螺仪传感器去检测开启睡眠模式的动作。这不仅帮助保持电池寿命,也确保当主人睡觉的时候智能门锁没有被触碰开锁。 尽管这个安全性的设计,我们还是能够创建漏洞验证程序来攻击处于激活状态的钥匙,并且诱骗它进入一种我们称作“伪睡眠模式”。在这种模式下,钥匙和门锁表现为好像钥匙在正常睡眠模式。然而,我们能够在任何时间使用手机上的漏洞验证app,举个例子,凌晨2点,钥匙放在房子里,黑客就能够使钥匙处于激活状态或者唤醒模式来触碰打开Kevo智能门锁。理想情况下,基于 Kevo 的内部/外部检测传感设计,绝大多数劫持和控制攻击场景应该能够被阻止。甚至当门锁被黑客控制,只要传感器检测到智能钥匙是在房子里面,门锁就应拒绝入侵者在房子外面尝试触摸开锁。 我们发现黑客还可以利用上述的安全设计。为了对此进行测试,我们安装和校准了门锁,在正常的运作模式,我们发现内外检测主要基于以下的检测逻辑。a.主人 (钥匙) 在门外来校准门锁。智能门锁计算钥匙的 BLE 信号作为基准信号强度。b.当主人打开锁,进入房子,她将钥匙放在一个比开门的位置还远的地方c.如果入侵者试图触摸开锁,它将会失败,因为智能锁检测到的钥匙信号强度比基线弱,并且钥匙在 30 秒内将安全地进入睡眠模式。 图3 安装了Kevo智能锁,并进行了内部外部的近感测试 我们测试的方式是,在一个30秒的时间窗内,将钥匙放在2到10英尺的距离范围内,就能够解锁智能门锁!在短距离测试中这种情况是都存在,如2,3英尺,延伸到九或十英尺攻击的效果就差一些了。 […] - [Popular anonymous SNS app leaking user id, geo location, etc](https://newskysecurity.com/2016x102x1popular-anonymous-sns-app-leaking-user-id/): The following blog post describes a popular anonymous SNS app in China, pyyx, which leaks its user details such as user id and geolocation in its APIs. Given the leak, a simple web-app can expose the identity of the user who commented or chatted anonymously. The post is composed in Chinese to benefit its major audience. 匿名社交的马后炮 作为一个无聊的中年人,我其实也挺关心年轻人的社交活动的。这不刚到了2016年,最早的那茬90后网红们也终于进入了“好像圣诞树,再美也过不了25”的阶段。我终于觉得跟他们没什么代沟了,可以去沟通一下。 于是我找到大叔,问他:如今国内的年轻人还用陌陌么? 大叔在电话那边沉默了好久,但是他的手机陀螺仪显示在不停的抖,我觉得要么他早发帕金森,要么他在那边开了静音然后拼命笑我老土。我选择相信前者,毕竟我的直觉一般都是准的。第三选项,他在不停的摇手机找附近的美女,是不可能的。隔壁安言的老张偷偷跟我说过,大叔的美女列表,前年就溢出了。 大叔终于说:你老土了吧,现在国内都是玩匿名社交,叫pyyx,你去看看。 搜狗拼音告诉我,pyyx是“炮约一下”(搜狗画外音:这个锅太污我不背)。有趣有趣,我赶紧去下了一个pyyx,打开一看原来叫朋友印象,也行啊。这个app需要的许可权限能有三站路那么长,从地理位置到把我的联系人翻个底儿掉,就差直接帮我抢红包了。我终于猴急猴急的注册了用户,登录以后,加了大叔当好友。 朋友印象挺好玩的,居然能跟微信暗通情愫,找微信朋友聊天。不过最棒的,是能匿名给朋友说话。对方知道你是她朋友,但是就是不知道你是谁。这感觉太棒啦,我赶紧跑去臭骂了几个平时不敢骂的人,比如大叔这样笑我土的。爽! 骂完回来还没喝口茶的功夫,大叔打电话过来,张嘴就骂:你活腻了骂我?你以为你匿名了我就看不出你是谁?你忘了我是黑客了? 其实对付黑客倒是最容易的,你直接拍他马屁就好了。我叫了几声大神,他就老老实实告诉我是怎么知道的了,还给了我一个工具让我查谁匿名骂了我。 工具: 跟他确认了好几遍这个工具不会偷我密码以后,我把手机号国家号还有密码都输进去了,登录以后我的浏览器就变成了一个查匿名的神器,虽然不太好用不过也够用了。 登录以后点了页面下面这个按钮,就出来一坨数据,据说这个就是我的匿名聊天记录。看不懂不要紧,直接把数据全选然后复制粘贴到下面一个框。这一步工具不能帮你,因为浏览器不!允!许!但是你自己拷贝粘贴就没问题。 等你复制粘贴好以后,按这个按钮,工具就会帮你找出你的匿名聊天记录了。 比如这个:   “哦…这样啊”就是你和匿名访客的聊天最后一句,这个是链接可以点的哦。 剩下的事情工具帮不了你了,你自己点开链接看吧,就像工具说的,点开以后亮点自寻,是不是有熟悉的名纸呢?哥只能帮到你这儿了。 当然这个朋友印象拿到的还不止这些,比如他家登录的时候,是把你的手机号还有密码用明文发送的。如果你在星巴克登录,旁边正好有那么7,8个黑客的话。。。细思极恐。 另外呢,如果你碰巧发了一个兴趣点,这个app还会把你当前的精确坐标发上去,于是世界上所有人都知道你现在在哪儿啦。是不是Jennifer春节回家变成王小花,一看便知。 最后呢,这个app会把你的所有联系人都明文发到网上这种吓人的事情我会随便说? 所以,如果你想知道谁匿名骂了你,就去查查吧?查查又不会怀孕。 Disclaimer: 本文除了技术部分以外,纯属虚构。数据查询工具不会存储或者向除了pyyx.com以外的第三方发送你的登录信息。 Update:pyyx已经修改了api,补上了这个漏洞。对这种快速反应,我们手动点赞。   - [Raising the bar in Mobile Security](https://newskysecurity.com/2016x101x1raising-the-bar-in-mobile-security/): Today we announce our partnership with West Coast Labs, a leading certification firm in the digital security industry, to power its next generation certification program for Enterprise Mobile Security. Our NewSky Security AppRisk™ platform will be the technical building blocks for end-to-end Checkmark Mobile Application Certification.  This automation platform starts with Android mobile devices and will expand to iOS, embedded Linux or other mobile OSes based on customer demands. The initial vulnerability assessment, powered by NewSky Security AppRisk™ automation, covers static code assessment, privilege abuse investigation, 3rd party SDK usage, app hardening and dynamic behavioral analysis.  This test methodology is aligned […] - [Mobile devices bundled with malware?](https://newskysecurity.com/2015x109x1mobile-devices-bundled-with-malware/): When you purchase a mobile device, you expect the device to be free of digital threats, clear of viruses, and otherwise safe to use. According to a G Data Mobile Malware Report for Q2 of 2015, more than 20 smartphone models were identified to contain modified or manipulated versions of common apps such as Facebook: Alps 2206Alps 709Alps 809TAlps A24Alps GQ2002Alps H9001Alps N3Alps N9389Alps PrimuxZetaAlps ZP100Andorid P8ConCorde SmartPhone6500DJC touchtalkHuawei G510IceFox RazorITOUCHLenovo S860NoName S806iSESONN N9500SESONN P8Star N8000Star N9500Xiaomi MI3Xido X1111 What are we dealing with here? The modified apps contained additional functions, making them potentially harmful or malicious. Examples of added […] - [Smart devices as Bitcoin mining slaves](https://newskysecurity.com/2015x108x1smart-devices-as-bitcoin-mining-slaves/): Recently, we blogged about unintentionally installing Android ransomware to an Android HD media player. It is possible and probable that other unwanted programs, such as Bitcoin mining trojans could be installed on a smart device. Background Bitcoin (BTC) is one of several popular digital (virtual) currency payment systems. It is decentralized and functions peer-to-peer (P2P) with a limited resource – it is suggested that there will only be 21,000,000 units of currency made available, also called bitcoins. Transactions are processed and verified across the Internet by nodes through a process called ‘mining’. A node that assists in processing transactions through […] - [Stagefright scan and removal tool](https://newskysecurity.com/2015x108x1stagefright-scan-and-removal-tool/): 0xID Labs has created a utility to scan for and remove malformed media files that match certain criteria that resemble a Stagefright exploit. Update August 6, 2015: In light of the recent disclosure by Zimperium at Black Hat 2015, we’ve updated coverage for additional threat vulnerabilities. This tool is for immediate release to use by any and all. We continue to monitor the story as it develops and will update the utility if needed. The utility covers detection for the following Android vulnerabilities related to the Stagefright exploit: CVE-2015-1538 CVE-2015-3824 Stagefright Response Tool additional info If no exploit media detected, displays […] - [Critical Stagefright flaw, millions affected](https://newskysecurity.com/2015x108x1critical-stagefright-flaw-millions-affected/): In late July, researchers with Zimperium announced the discovery of a critical flaw in the Android library libstagefright, potentially affecting 95% of all Android devices, from Android Froyo (2.2) to Lollipop (5.0). The flaw could result in the device getting owned if successfully exploited. Google illustrates Android media architecture and framework in the following diagram: Zimperium describes the vulnerability as the following: “These issues in Stagefright code critically expose 95% of Android devices, an estimated 950 million devices. Drake’s research, to be presented at Black Hat USA on August 5 and DEF CON 23 on August 7 found multiple remote […] - [Removing Android ransomware from my tv](https://newskysecurity.com/2015x108x1removing-android-ransomware-from-my-tv/): In July, you may have read how I unwittingly installed Android ransomware to my HiMedia HD600a HD Media player. Well I wasn’t going to just toss out my device, I wanted it back, so I worked on getting rid of the ransomware. Timing is everything I have to say, it was very tricky to remove this ransomware from my IPTV media player. If this happened to my cell phone or other Android device, I could plug it into a computer via USB connection and use it as an external storage device, then browse the device and manually delete the recently […] - [OBD Case Study: Gone in 6 Seconds](https://newskysecurity.com/2015x108x1obd-case-study-gone-in-6-seconds/): History Prior to the 1980s, vehicle diagnostics were more hands-on, and on-board computers were not fully developed. Identifying a car’s trouble meant testing fuses, relays, and opening up components and performing visual inspections, or using timing lights. During the 1980s and early 1990s, cars became more computer-controlled, such as controlling engine idle, vehicle speed and so on. Vehicle manufacturers also were not using a standard for communicating with on-board computers, also making diagnostics more difficult. A standard was developed (ODB-II, or ODB2) and going forward, diagnostics became more streamlined. The ODB-II standard specifies the type of diagnostic connector, its pin-out, the electrical signalling […] - [IoT In The News: Uconnect Hack](https://newskysecurity.com/2015x107x1iot-in-the-news-uconnect-hack/): In July, it was revealed that two researchers, Charlie Miller and Chris Valasek, were able to successfully connect to a vehicle’s computer remotely, over the Internet, and control the car’s mobility by disabling the brakes, or issuing a kill command to stop the engine. Scary. The vehicle was a Jeep Cherokee and it was outfitted with an onboard computer and control system known as Uconnect. Uconnect allows the driver to control features of the vehicle using voice control, allowing a hands-free driving experience. According to the Uconnect online registration website, there are several makes that have Uconnect, including: Chrysler Dodge […] - [What is the acronym OWASP?](https://newskysecurity.com/2015x107x1what-is-the-acronym-owasp/): When reading articles about mobile security, you may have come across the acronym OWASP and wondered, what is OWASP? Simply, OWASP is a non-profit organization known as the Open Web Application Security Project, and has a main website at http://www.owasp.org. Established in 2004, this organization lists their core purpose as the following: “Be the thriving global community that drives visibility and evolution in the safety and security of the world’s software. ” The organization has board members and contributors that work on several key security issues and projects. One of their ongoing projects is the OWASP Mobile Security Project. Within […] - [Mobile Intelligence Case Study: General vs Medical apps](https://newskysecurity.com/2015x107x1mobile-intelligence-case-study-general-vs-medical-apps/): In this post, we share some of our findings from submitted apps.  This data reflects our common vision on mobile app vulnerabilities and risks.  On the one hand, malware is not the only threat vector in the mobile space. This is particularly true for sandbox architecture platforms such as Android and iOS, where it is more difficult for malware to penetrate the layers of app store acceptance criteria and blacklisting.  On the other hand, app developers build their apps with the desire to rapidly publish to the market while the app’s security life cycle may not be a priority. As we have observed, […] - [Android spyware released in breach](https://newskysecurity.com/2015x107x1android-spyware-released-in-breach/): Several days ago it was reported that a surveillance company “Hacking Team” (HT) was hacked and in the breach, 400Gb of content was released publicly. The content contained not only sensitive information such as contracts, internal emails, and other private details, but also a collection of spyware utilities, toolkits, and exploits affecting several platforms. The range of platforms includes Windows, Linux, and OS X as well as mobile platforms iOS, Windows Phone 8, Blackberry, and Android. We are treating this public release and exposure of the collection that includes Android spyware with high priority for our mobile customers. In response […] - [How Android ransomware bricked my TV](https://newskysecurity.com/2015x107x1how-ransomware-turned-my-android-tv-box-into-a-boat-anchor/): Consumers are introducing more smart devices into their lives, beyond smartphones, such as watches, televisions, and on-board computers found in automobiles. In 2013, a Chinese vehicle manufacturer designed a “smart car” with a built-in Android OS computer, allowing consumers the ability to insert their own SIM card and the car could be online around the clock! We have Google to thank for making our lives easier and for the increased demand and use of smart devices – not only is it a “win-win” for Google and smart device manufacturers, but also, and very importantly, for consumers. Due to the open […] - [IoT Thermostat Bug Allows Hackers to Turn Up the Heat](https://newskysecurity.com/iot-thermostat-bug-allows-hackers-to-turn-up-the-heat-948e554e5e8bx1-html/): Introduction With the ever-increasing impact of smart and connected devices in our daily lives, Cybersecurity has a variety of security challenges to deal with. The field of traditional computer security deals with a myriad of issues like data theft or sabotage. However, when it comes to IoT security, the consequences of a successful attack can be even more diverse. In this post, we discuss an IoT Smart Thermostat bug and how a hacker leveraged it to raise the control temperature by 12 C (~22 F) degrees. Commodity IoT malware vs Targeted IoT attack The most common purpose of IoT malware […] - [Postgres & SupaBase Row Level Security](https://newskysecurity.com/postgres-supabase-row-level-security/): SupaBase which uses PostgreSQL’s Row-Level Security (RLS) are powerful database feature that gives administrators precise control over which data rows specific users are allowed to view or modify. It works by applying security policies directly to a table, which are then automatically evaluated for any query that accesses it. This means that even if two users run the exact same SELECT * FROM employees query, the database can return a different set of rows to each person based on their role or user attributes, providing a robust and transparent layer of data protection. This approach moves security logic from the […] - [Enhance Your Security Posture with Cyber Security Monitoring](https://newskysecurity.com/cyber-security-monitoring/): In today’s digital landscape, the importance of cyber security monitoring cannot be overstated. Organizations face a myriad of cyber threats that can compromise sensitive data and disrupt operations. Implementing effective cybersecurity monitoring practices is crucial for safeguarding your business against potential security risks. What is Cyber Security Monitoring? Cyber security monitoring involves continuously monitoring your network traffic, endpoints, and user behavior to detect and respond to security incidents. By using advanced cybersecurity monitoring tools, organizations can gain insights into their security posture and identify vulnerabilities before they can be exploited. Benefits of Cyber Security Monitoring Implementing Cybersecurity Monitoring To effectively […] - [Our New Sky Security Annual Retreat: A Lesson in Cybersecurity and...Cleanliness?](https://newskysecurity.com/our-new-sky-security-annual-retreat-a-lesson-in-cybersecurity-and-cleanliness/): What a week! The New Sky Security team just got back from our annual corporate retreat in beautiful Redmond, Washington. We found this amazing Airbnb with enough space for the whole crew, and let’s just say, we made the most of it. We brainstormed, we bonded, we coded, and, of course, we celebrated a fantastic year. Our company party on the last night was one for the books. Let’s just say we had a really good time. The next morning, as the coffee started to kick in, we looked around and realized the house was, well, a disaster zone. We’re […] - [Discover Migaku: The Smarter Way to Reach Real Fluency](https://newskysecurity.com/discover-migaku-the-smarter-way-to-reach-real-fluency/): Migaku is a comprehensive language learning platform designed for learners who want to study through content they actually enjoy—like anime, YouTube, Netflix, websites, and more. Instead of using scripted lessons or vocabulary drills, Migaku helps you absorb the language naturally while watching shows, reading articles, or browsing online. How Migaku Works Use beginner-friendly courses that cover the most frequent words and core grammar. These lessons are structured to get you ready for real-world content as quickly as possible. With Migaku’s Chrome extension, you can read subtitles or websites while instantly getting definitions, grammar info, pitch accents, and example sentences for […] - [Your Guide to Identifying and Dodging Social Engineering Scams](https://newskysecurity.com/your-guide-to-identifying-and-dodging-social-engineering-scams/): From shopping and banking to how we communicate, technology has made our daily lives infinitely easier and more connected. While security continues to advance, making our digital world safer than ever, criminals persistently seek out vulnerabilities. The one they exploit most effectively? Human emotion. The scale of this issue is staggering. In the United States alone, consumers lost over $12.5 billion to fraud in 2024, a 25% jump from the previous year, according to a recent Federal Trade Commission report. Investor scams accounted for the largest financial losses at $5.7 billion, while imposter scams were the most frequently reported type […] - [IoT Statistics in 2025](https://newskysecurity.com/iot-statistics/): The world of the Internet of Things (IoT) is expanding at a staggering pace, weaving a digital fabric into the core of our daily lives and industries. In essence, the statistics point to a monumental proliferation of connected devices, with estimates suggesting the number will surge past 20 billion globally in 2025, and some analysts predict it could be as high as 27 billion. This explosion in connectivity is matched by a booming market value, projected to reach well over $700 billion in the same year. This growth isn’t just about numbers; it signifies a fundamental shift in how we […] - [Small Business Cyber Security Statistics](https://newskysecurity.com/small-business-cyber-security-statistics/): The landscape of cybersecurity is often dominated by headlines about massive corporations, but the stark reality is that small businesses are a primary and frequent target for cybercriminals. A significant percentage of all cyberattacks are aimed at small to medium-sized businesses, leading to devastating financial and operational costs that many are unprepared to handle. This vulnerability stems from a common misconception that they are too small to be of interest to hackers, a belief that is dangerously inaccurate in today’s digital world. The statistics paint a clear and urgent picture: cyber threats to small businesses are not a distant possibility, […] - [2024 Cyber Security Statistics: Year in Review of Biggest Threats](https://newskysecurity.com/2024-cyber-security-statistics-year-in-review-of-biggest-threats/): 2024 proved to be a tumultuous year for cybersecurity, marked by record-breaking data breaches, rampant ransomware attacks, and the dual-edged impact of AI technologies, with global cyber threats costing billions and exposing vulnerabilities across sectors. Key highlights include massive breaches at companies like Change Healthcare and CDK Global, alongside a surge in phishing and stolen credentials as top attack vectors, underscoring the urgent need for enhanced defenses amid evolving regulations. Reflecting on 2024, the cybersecurity landscape was defined by an unprecedented wave of high-impact incidents that disrupted industries and amplified financial losses. According to industry reports, it was a record-breaking […] - [2025 Cyber Security Statistics](https://newskysecurity.com/cyber-security-statistics/): In 2025, cybersecurity remains a critical concern as cyber threats escalate globally, with the cost of cyberattacks projected to reach $9.5 trillion, driven by ransomware, phishing, and data breaches. Organizations face increasing vulnerabilities, a widening skills gap, and sophisticated attacks, making robust defenses essential for protection. The landscape of cybersecurity in 2025 paints a sobering picture of rising threats and their far-reaching impacts. According to recent data, the global cost of cyberattacks is skyrocketing, fueled by the proliferation of remote work and advanced tactics like deepfake phishing. This surge not only drains financial resources but also erodes trust and exposes […] - [Ransomware Attacks: Essential Steps to Safeguard Your Data and Systems](https://newskysecurity.com/ransomware-attacks-essential-steps-to-safeguard-your-data-and-systems/): Introduction A single ransomware incident can freeze payroll, paralyze supply-chain software, and leave executives negotiating with anonymous criminals-often in a matter of minutes. Verizon’s 2024 Data Breach Investigations Report notes that the median ransom demand now exceeds US$800,000, while research from IBM puts the average recovery cost (downtime, legal fees, lost business) at more than US$4.5 million. Those numbers climb dramatically when sensitive data is stolen and threatened with public release. This guide walks you, step by step, through preventive controls and response actions that dramatically cut risk. It follows the same methodology used by incident-response teams that handle hundreds […] - [A Quick Guide to Essential Security Settings for Apps and Online Services](https://newskysecurity.com/a-quick-guide-to-essential-security-settings-for-apps-and-online-services/): Online threats are accelerating faster than most users notice, and 2025 is shaping up to be the year when either the front door is locked or left open. Phishing lures, identity theft, and headline-grabbing breaches now start with settings most people never touch. These are factory defaults tuned for convenience rather than protection.  Global cybercrime losses are projected to leap from $9.22 trillion in 2024 to $13.82 trillion by 2028. This may look like something that only happens in large companies, but the reality is that weak and easily accessible settings can put anyone at risk. Default settings were one […] - [Best CRM for Charities Empowering Nusaker](https://newskysecurity.com/best-crm-for-charities-empowering-nusaker/): Finding the best CRM for charities dedicated to empowering “Nusaker” — the community builders and grassroots movements — boils down to choosing a platform that is affordable, scalable, and easy to use. While there is no single “best” option for everyone, platforms like Keela and Salesforce for Nonprofits stand out. The ideal choice ultimately depends on the organization’s size, budget, and technical comfort level, but the goal remains the same: to find a tool that streamlines operations so more energy can be focused on the mission itself. Why a CRM is a Game-Changer for Community Builders For many charities and […] - [How to use a VPN with qBittorrent?](https://newskysecurity.com/how-to-use-a-vpn-with-qbittorrent/): Using a VPN with qBittorrent is a straightforward process that significantly enhances a user’s privacy and security. The most direct method is to first connect to a VPN server and then launch the qBittorrent client. This ensures that all internet traffic from the application is automatically routed through the VPN’s encrypted tunnel, masking the user’s real IP address from other peers and trackers. For an even more secure setup, users can utilize a feature within qBittorrent to “bind” it directly to the VPN’s network interface, which prevents any data from being sent if the VPN connection accidentally drops. Below is […] - [Is Zscaler VPN also a proxy server?](https://newskysecurity.com/is-zscaler-vpn-also-a-proxy-server/): In short, Zscaler is not a traditional VPN, nor is it just a simple proxy server. Instead, it’s a comprehensive cloud security platform that performs the functions of both, but in a fundamentally more modern and secure way. Zscaler Internet Access (ZIA) acts like a highly advanced, cloud-based proxy for all internet traffic, while Zscaler Private Access (ZPA) serves as a replacement for the traditional VPN, offering more secure access to internal applications. To call it just one or the other would be an oversimplification of its architecture. To truly understand this, it helps to look at how Zscaler’s two […] - [Do i need VPN for Direct Download?](https://newskysecurity.com/do-i-need-vpn-for-direct-download/): For anyone wondering if a VPN is strictly necessary for a direct download, the simple answer is no. A file will download from a server to a computer perfectly fine without one. However, this only answers the technical question of whether the download will work. The more important question is should a person use a VPN for direct downloads, and for anyone concerned about their online privacy and security, the answer is a resounding yes. Understanding why requires a look at what happens behind the scenes during a direct download and the risks involved. What is a Direct Download? A […] - [How to Check if VPN is Working](https://newskysecurity.com/how-to-check-if-vpn-is-working/): The simplest way for a person to check if their VPN is working is to compare their public IP address before and after connecting to the VPN. Before activating the VPN, a user can search “what is my IP” on Google to see their real IP address and location. After connecting to the VPN, they can perform the same search. If the IP address and location have changed to match the VPN server’s location, the VPN is performing its most basic function correctly. For those who want to be more thorough, there are a few key tests that can provide […] - [How to turn off VPN on Iphone's](https://newskysecurity.com/how-to-turn-off-vpn-on-iphones/): Turning off a VPN on an iPhone is a straightforward process that gives you back direct access to the internet. The quickest way is to open your iPhone’s Settings app, tap VPN, and toggle the status switch to “Not Connected.” Alternatively, you can almost always open the specific VPN application you installed and tap its prominent “Disconnect” or power button. For a more detailed look at these methods, including how to handle a VPN that keeps reconnecting or how to remove it completely, here is a complete guide. How to Tell if Your VPN is On Before trying to turn […] - [Can a website see through your VPN?](https://newskysecurity.com/can-a-website-see-through-your-vpn/): In short, no. When a Virtual Private Network (VPN) is working correctly, a website cannot directly see your real IP address or your physical location. The website you visit will only see the IP address of the VPN server you are connected to. However, this simple answer doesn’t tell the whole story. While a website can’t magically pierce the VPN’s encrypted tunnel, it has other clever ways to deduce that a VPN is in use and, in some cases, can still figure out who you are. How a VPN Shields Your Identity To understand how a website might detect a […] - [Does using a VPN help with ping?](https://newskysecurity.com/does-using-a-vpn-help-with-ping/): For gamers and anyone concerned with online performance, low ping is the ultimate goal. The question often arises whether a Virtual Private Network (VPN), a tool known for security and privacy, can be a secret weapon for lowering it. The short answer is that, in most cases, a VPN will not help with ping and will likely increase it. A VPN adds at least one extra stop for your internet traffic, which logically creates a longer journey and higher latency. However, there are a few specific and less common situations where a VPN could, surprisingly, result in a better connection. […] - [How to unblock websites on a school Chromebook without a VPN](https://newskysecurity.com/how-to-unblock-websites-on-a-school-chromebook-without-a-vpn/): For students looking to access blocked websites on a school Chromebook without using a VPN, there are a few common methods that can sometimes work. These techniques generally involve using web-based services to act as a middleman, masking the final destination from the school’s network filter. The most popular methods include using a web proxy, leveraging a translation service like Google Translate, or in some rare cases, accessing the website’s direct IP address. Below, we’ll explore these methods in greater detail, outlining how each one works and its potential limitations. Method 1: The Web Proxy A web proxy is one […] - [Can you use TikTok with a VPN?](https://newskysecurity.com/can-you-use-tiktok-with-a-vpn/): Yes, a person can absolutely use TikTok with a Virtual Private Network (VPN). In fact, it’s a common and effective method for users to overcome a variety of restrictions and enhance their online privacy. A VPN works by routing a user’s internet connection through a private server in a location of their choosing, effectively masking their real IP address. This simple change allows individuals to access the app in regions where it might be blocked, protect their data from being easily tracked, and even explore content from different parts of the world. While the answer is a straightforward yes, the […] - [What to do if a website redirects to phishing site​](https://newskysecurity.com/what-to-do-if-a-website-redirects-to-phishing-site/): When a website unexpectedly redirects to a phishing site, a user’s immediate actions are critical. The first step is to close the browser tab or window immediately without clicking on anything or entering any information. This simple action can prevent malicious scripts from running or tricking the user into compromising their data. Afterward, it is essential to clear the browser’s cache and cookies, run a comprehensive malware scan on the device, and report the incident to help protect others. Navigating the internet should feel safe, but encountering a malicious redirect can be jarring. Understanding the right steps to take not […] - [FBI Warns Gmail Users of Sophisticated AI-Driven Phishing Attacks](https://newskysecurity.com/fbi-warns-gmail-users-of-sophisticated-ai-driven-phishing-attacks/): The Federal Bureau of Investigation (FBI) is issuing a stark warning to the public, particularly Gmail users, about a significant evolution in cybercrime: highly sophisticated phishing attacks powered by artificial intelligence. These are not the typo-ridden, generic scam emails of the past. Instead, criminals are now leveraging AI to craft perfectly written, personalized, and highly convincing messages designed to bypass both security software and human suspicion. The core of the threat lies in AI’s ability to create emails that are contextually aware and mimic legitimate communication, making it harder than ever to distinguish a fraudulent request from a real one. […] - [The 10 Most Important AI Research Papers of All Time](https://newskysecurity.com/the-10-most-important-ai-research-papers-of-all-time/): The field of artificial intelligence has been shaped by groundbreaking research papers that introduced revolutionary concepts and methodologies. From the foundational work on neural networks to modern transformer architectures, these papers have defined the trajectory of AI development. The most influential papers include foundational works on perceptrons, backpropagation, convolutional neural networks, and recent breakthroughs in attention mechanisms and large language models. 1. “A Logical Calculus of Ideas Immanent in Nervous Activity” (1943) McCulloch and Pitts laid the mathematical foundation for artificial neural networks with this seminal paper. They introduced the concept of artificial neurons as simple computational units, establishing the […] - [Will AI Become Advanced Enough to Write Good Application Essays?](https://newskysecurity.com/will-ai-become-advanced-enough-to-write-good-application-essays/): AI technology is rapidly advancing and will likely become sophisticated enough to write compelling application essays within the next few years. However, the real question isn’t whether AI can technically produce well-written essays, but whether admissions committees will value authenticity over technical proficiency, and how institutions will adapt their evaluation processes to maintain meaningful assessment of genuine student potential. Current AI Writing Capabilities Today’s AI writing tools already demonstrate impressive capabilities in crafting coherent, grammatically correct essays with proper structure and flow. Large language models can generate content that mimics human writing styles, incorporates relevant examples, and follows standard essay […] - [What is GRC in Cyber Security? A Straightforward Explanation](https://newskysecurity.com/what-is-grc-in-cyber-security/): As a cybersecurity executive who’s implemented GRC programs across multiple organizations, from Microsoft to my own company New Sky Security, I’m constantly surprised by how many security professionals struggle to explain what GRC actually means. Let me break it down in plain terms. GRC Defined: The Three Pillars GRC stands for Governance, Risk, and Compliance – three interconnected disciplines that form the foundation of any mature cybersecurity program. Governance: The “What” and “Who” Governance establishes the framework for how your organization makes security decisions. It answers: Real Example: Our governance framework defines that only the CISO can approve exceptions to […] - [Is a Cybersecurity Hard? The Truth About Working in This Industry](https://newskysecurity.com/is-a-cybersecurity-hard-the-truth-about-working-in-this-industry/): As someone who’s spent the last 15 years building and leading cybersecurity teams, I get asked this question almost weekly: “Is cybersecurity really that hard?” The short answer? Yes and no. It depends entirely on what you mean by “hard” and what you’re comparing it to. After hiring over 50 cybersecurity professionals and watching countless careers do amazingly and some flame out, I want to give you the unvarnished truth about what it’s really like working in this industry. No sugar-coating, no recruitment pitch – just the real pros and cons from someone who lives this every day. The Harsh […] - [CCSK vs. CCSP: Making the Right Choice for Your Cloud Security Career](https://newskysecurity.com/ccsk-vs-ccsp-making-the-right-choice-for-your-cloud-security-career/): As someone who’s been in the cybersecurity field for almost two decades now and currently leads our cloud security practice, I get asked this question constantly: “Should I pursue the CCSK or CCSP certification?” Having earned both certifications and hired dozens of cloud security professionals, I want to share my perspective on making this critical career decision. My Journey Through Cloud Security Certifications Three years ago, I found myself at a crossroads. Our company was rapidly migrating to the cloud, and I needed to formalize my cloud security expertise. Like many security professionals, I was overwhelmed by the alphabet soup […] - [Play Cyber Tanks Free](https://newskysecurity.com/cyber-tanks/): Try out Cyber Tanks for free! Click here to play the Cyber Tanks game! - [Wi-Fi Security in 2025: Understanding and Defending Against Modern Network Threats](https://newskysecurity.com/wi-fi-security-in-2025-understanding-and-defending-against-modern-network-threats/): After spending years securing wireless networks across home, enterprise, and public environments at NewSky Security, I’ve witnessed the evolution of Wi-Fi hacking from opportunistic attacks to sophisticated, targeted campaigns that can devastate organizations and individuals alike. The wireless threat landscape in 2025 is more complex and dangerous than ever before, with attackers leveraging advanced techniques and readily available tools to compromise networks that were considered secure just a few years ago. I’ve responded to countless Wi-Fi security incidents, from simple credential theft on public networks to complex enterprise breaches that began with a compromised wireless access point. What I’ve learned […] - [The Best Website Databases in 2025: A Quick Guide to Modern Data Architecture](https://newskysecurity.com/the-best-website-databases-in-2025-a-quick-guide-to-modern-data-architecture/): After architecting and securing database solutions for countless web applications at NewSky Security, I’ve witnessed the database landscape undergo a fundamental transformation. The days of one-size-fits-all database solutions are long gone. In 2025, choosing the right website database isn’t just about storing and retrieving data—it’s about building a foundation that can scale with your business, adapt to changing requirements, and provide the performance your users demand in an increasingly competitive digital landscape. I’ve migrated applications from legacy systems to modern architectures, optimized database performance for high-traffic applications, and secured sensitive data across various database platforms. The decisions you make about […] - [The Best SSO Databases in 2025: A Security Professional's Guide to Making the Right Choice](https://newskysecurity.com/the-best-sso-databases-in-2025-a-security-professionals-guide-to-making-the-right-choice/): After years of implementing and securing single sign-on solutions at NewSky Security, I’ve witnessed the SSO landscape evolve from simple directory services to sophisticated identity platforms that form the backbone of modern enterprise security. In 2025, choosing the right SSO database isn’t just about user convenience—it’s about creating a security foundation that can adapt to increasingly complex threat landscapes while supporting the diverse authentication needs of modern organizations. I’ve deployed, migrated, and secured dozens of SSO implementations across various industries, and I can tell you that the decision you make about your SSO database will impact your organization’s security posture, […] - [Cyber Security and the Internet of Things (IoT): Our Research Findings and Emerging Concerns](https://newskysecurity.com/cyber-security-and-the-internet-of-things-iot-our-research-findings-and-emerging-concerns/): As Internet of Things (IoT) technology becomes more closely integrated in everyday systems, lifestyles and businesses, our research at NewSky Security has identified a rapidly expanding need for comprehensive cyber security measures. Cyber security encompasses all of the technology and operations employed to safeguard devices and their respective platforms and networks from cyber attacks or hacking. Similarly, IoT is the term used to refer to all of the objects and devices that are interconnected by one source: the internet. Establishing an internet connection between multiple devices facilitates the effortless accumulation and transmission of data wirelessly, all without mediation by humans. […] - [IoT Remote Monitoring in 2025: The Game-Changer Every Business Leader Must Understand](https://newskysecurity.com/iot-remote-monitoring-in-2025-the-game-changer-every-business-leader-must-understand/): Having spent the better part of the last decade building and deploying IoT remote monitoring solutions at NewSky Security, I can confidently say that 2025 marks the inflection point where remote monitoring has transitioned from a competitive advantage to an absolute business necessity. The organizations that haven’t embraced comprehensive IoT remote monitoring aren’t just behind—they’re operating with fundamental blind spots that will become increasingly costly. I’ve witnessed this transformation firsthand, from the early days when remote monitoring was primarily about basic data collection to today’s sophisticated systems that provide predictive insights, automated responses, and real-time operational intelligence. The businesses that […] - [IoT Security Concerns in 2025: What Every Business Leader Needs to Know](https://newskysecurity.com/iot-security-concerns-in-2025-what-every-business-leader-needs-to-know/): After spending years in the trenches of IoT security at NewSky Security, I’ve witnessed firsthand how the threat landscape has evolved from theoretical vulnerabilities to sophisticated, targeted attacks that can cripple entire business operations. The sobering reality is that most organizations are woefully unprepared for the security challenges that come with their connected device deployments. I’m writing this because I’ve seen too many businesses treat IoT security as an afterthought—a checkbox to tick rather than a fundamental business imperative. The consequences of this mindset are becoming increasingly severe, and in 2025, the stakes have never been higher. The Attack Surface […] - [IoT App Development in 2025: A How-To Guide for Startups and SMBs](https://newskysecurity.com/iot-app-development-in-2025-a-how-to-guide-for-startups-and-smbs/): As someone who has been deeply involved in the IoT space for years and has witnessed the evolution of connected device ecosystems firsthand, I can tell you that 2025 represents a pivotal moment for startups and small-to-medium businesses looking to enter the IoT app development arena as we develop further as a society with AI. At NewSky Security, we’ve navigated these waters ourselves, and I want to share the hard-earned insights that can make or break your IoT venture. The IoT Landscape Has Fundamentally Shifted When we first started developing our IoT security solutions, the market was fragmented, standards were […] - [Hikvision Login: Default IP, Username, Password, Port](https://newskysecurity.com/hikvision-login-default-ip-username-password-port/): Hikvision is a very popular brand of surveillance cameras and security solutions. When setting up a Hikvision IP camera for the first time, it’s important to know the default settings to access and configure the device. These settings include the default IP address, username, password, and port. This article provides information on these default settings for Hikvision security cameras. Lets dive into it! Default IP The default IP address for 99% of Hikvision cameras is 192.168.1.64. This IP address is used to access the camera’s web interface where you can configure various settings. To connect to the camera using this IP address, […] - [Kyocera Default Passwords Command Centre](https://newskysecurity.com/kyocera-default-passwords-command-centre/): Kyocera machine passwords: General rules 1. Most machines have a username and password to enter “Machine Administrator” mode. By default the username and password are identical. It is usually the A4 speed of the machine followed by 00. However, there are exceptions where a machine will have the same combination of username and password as the rest of the machines in the same model group, so be aware of this. 2. Some machines have a Machine Administrator and an Administrator, who have different permissions. The default username and password for the Administrator is Admin and Admin3. There are two main […] - [Ubuntu Root Password: Your Complete Guide to Understanding and Managing Root Access](https://newskysecurity.com/ubuntu-root-password-your-complete-guide-to-understanding-and-managing-root-access/): Ubuntu users often find themselves confused when trying to perform administrative tasks, wondering what the default root password could be or why certain commands fail with permission errors. Unlike some Linux distributions that provide default root passwords, Ubuntu takes a unique security-focused approach that locks the root account by default. Understanding how Ubuntu handles root access is crucial for effectively managing your system while maintaining security. The root account represents the most powerful user on any Linux system, with unrestricted access to all files, commands, and system resources. However, Ubuntu’s approach to root access differs significantly from traditional Linux distributions, […] - [Are Private Investigators Legal? What You Need to Know About PI Laws and Regulations](https://newskysecurity.com/are-private-investigators-legal-what-you-need-to-know-about-pi-laws-and-regulations/): When most people think about private investigators, images from movies and TV shows come to mind—shadowy figures following cheating spouses or digging up dirt on unsuspecting targets. This Hollywood portrayal often leaves people wondering whether private investigators actually operate legally in the real world. The answer is yes, private investigators are completely legal and work as licensed professionals in nearly every state across America. Private investigators operate under a complex system of federal, state, and local laws that govern exactly what they can and cannot do. While they don’t have special police powers, licensed PIs have legitimate authority to gather […] - [The Hidden Risks of Hiring a Private Investigator in 2025 (What Could Go Wrong and How to Protect Yourself)](https://newskysecurity.com/the-hidden-risks-of-hiring-a-private-investigator-in-2025-what-could-go-wrong-and-how-to-protect-yourself/): You’re convinced you need a private investigator. Maybe you suspect infidelity, need to locate a missing person, or require evidence for a legal case. The decision feels straightforward—hire a professional to get the answers you need. But before you hand over a retainer check, you should understand that hiring the wrong PI can create more problems than it solves. From legal liability to privacy breaches, financial scams to evidence contamination, the risks of hiring a private investigator extend far beyond simply wasting money. Some clients have faced criminal charges, lost court cases, or suffered personal safety threats because they chose […] - [How Much Does a Private Investigator Cost in 2025? (Complete Pricing Guide and What You Get for Your Money)](https://newskysecurity.com/how-much-does-a-private-investigator-cost-in-2025-complete-pricing-guide-and-what-you-get-for-your-money/): You suspect your business partner is hiding assets, your spouse might be cheating, or you need to locate a missing family member. The thought of hiring a private investigator crosses your mind, but you have no idea what it actually costs. Will you pay $50 an hour or $500? Do you need a retainer? What about expenses like travel and surveillance equipment? Private investigator costs vary dramatically based on your location, case complexity, and the specific services you need. In 2025, you can expect to pay anywhere from $75 to $300 per hour, with most cases falling in the $100-150 […] - [What Is Composite Risk Management? (Your Complete Guide to CRM Process and Implementation)](https://newskysecurity.com/what-is-composite-risk-management-your-complete-guide-to-crm-process-and-implementation/): You’re leading a project with multiple moving parts—tight deadlines, budget constraints, new technology, and a distributed team. Each element carries its own risks, but you’re starting to realize that the real danger lies in how these risks interact with each other. A delayed vendor delivery might seem manageable on its own, but combined with your team’s limited experience and an aggressive timeline, it could spell disaster for the entire initiative. This is where Composite Risk Management (CRM) becomes essential. Unlike traditional risk management that treats each threat in isolation, CRM recognizes that modern projects and operations involve interconnected risks that […] - [What Does "GNG" Mean on TikTok and Instagram? (Your Guide to This Trending Abbreviation)](https://newskysecurity.com/what-does-gng-mean-on-tiktok-and-instagram-your-guide-to-this-trending-abbreviation/): You’re scrolling through TikTok comments or Instagram DMs when you spot it again: “GNG.” Maybe someone dropped it in response to your story, or you saw it scattered across a viral video’s comment section. You’ve probably figured out from context that it’s positive, but you’re not quite sure what those three letters actually stand for—or when you should use them yourself. You’re not alone in the confusion. Internet slang evolves faster than most dictionaries can track, and “GNG” has quietly become one of the most versatile abbreviations on social media. Below, you’ll get the complete breakdown of what “GNG” means, […] - [How Attackers Run Malware With Nothing More Than a Script (and How You Can Stop Them)](https://newskysecurity.com/how-attackers-run-malware-with-nothing-more-than-a-script-and-how-you-can-stop-them/): You lock down USB ports, patch your operating systems, and ban random executables—yet attackers still manage to breach networks without dropping a single .exe. They do it by hiding malware inside scripts: short, text-based instructions written in languages your environment already trusts. PowerShell, JavaScript, Bash, Python, even old-school batch files can all become delivery vehicles that slip past traditional defenses. By the time you finish this article, you’ll understand exactly how an adversary can execute malware through a script, recognize the red flags in your own environment, and deploy practical countermeasures that keep these low-noise intrusions from turning into full-blown […] - [AfterDarkMode Malware: Why You Must Avoid This “Dark-Theme” App and How to Recover if You Already Installed It](https://newskysecurity.com/afterdarkmode-malware-why-you-must-avoid-this-dark-theme-app-and-how-to-recover-if-you-already-installed-it/): You’re scrolling your favorite forum late at night when someone shares a slick-looking “AfterDarkMode” download. Supposedly, it forces true dark mode across every corner of your phone or PC—no more blinding white screens. The screenshots look great, the comments gush, and the file size seems harmless. A quick install couldn’t hurt, right? Stop right there. AfterDarkMode is not a customization tool; it’s confirmed malware that harvests data, hijacks resources, and opens a back door to still more infections. If you’ve already installed it, the safest solution is a full factory reset or clean OS reinstall. Below you’ll learn how this […] - [Who will receive $1800 Social Security Payment in 2025?](https://newskysecurity.com/who-will-receive-1800-social-security-payment-in-2025/): ​ You may have heard friends, neighbors, or social-media pundits talk about an “$1,800 Social Security payment” that’s supposedly on the way. Maybe you even spotted a headline hinting that a one-time $1,800 check is being mailed to certain Americans sometime this year. Instantly, your mind jumps to the same question everyone else asks: “Will I get it?” Because rumors about Social Security and other federal benefits spread fast—often faster than the facts—it’s smart that you’re digging deeper. Below you’ll find a clear, hype-free explanation of exactly who stands to receive a benefit payment in the $1,800 neighborhood, what circumstances […] - [Kernel Security Check Failure Causes and Effective Troubleshooting Methods](https://newskysecurity.com/kernel-security-check-failure-causes-and-effective-troubleshooting-methods/): The kernel security check failure is a common Windows error that causes the system to stop unexpectedly. This error usually means the operating system found a problem with key system files or hardware, which can lead to a blue screen of death (BSOD). It often happens because of corrupted files, outdated drivers, or faulty hardware. When this error occurs, the computer may restart or freeze, making it hard to use. Users need to address it quickly by checking for updates, running system scans, or testing hardware components. Understanding the basic causes helps to fix the issue without unnecessary steps. Knowing what […] - [ecrypto1.com Crypto Security: Comprehensive Analysis and Best Practices](https://newskysecurity.com/ecrypto1-com-crypto-security-comprehensive-analysis-and-best-practices/): When it comes to protecting your digital assets, ecrypto1.com offers a strong and layered approach to crypto security. Their platform combines advanced encryption, real-time monitoring, and user education to help keep your cryptocurrencies safe from common threats. This means you can manage your investments with more confidence, knowing multiple defenses work together to protect your wallet. You face many risks in the crypto world, including scams that target token holders and irreversible transactions. ecrypto1.com focuses on these challenges by providing tools designed for both convenience and security. Whether you use their wallet for daily trades or long-term storage, their system aims to […] - [What to do if your SSN is on the Dark Web](https://newskysecurity.com/what-to-do-if-your-ssn-is-on-the-dark-web/): Finding out that your Social Security number is on the dark web can be stressful. Hackers often sell stolen information there, putting your financial and personal safety at risk. If your SSN is found on the dark web, you should act fast to freeze your credit and monitor your identity to prevent fraud and stop criminals from opening accounts in your name. It can be hard to know where to start, but there are simple steps you can follow to protect yourself. Staying alert and taking action right away can lower your risk of identity theft. To learn more about what to […] - [Cash App Security Settlement Explained: Key Details and Impact](https://newskysecurity.com/cash-app-security-settlement-explained-key-details-and-impact/): The Cash App security settlement offers users affected by data breaches a chance to receive compensation. Users who had a Cash App account between August 23, 2018, and August 20, 2024, may be eligible to claim up to $2,500 each from a $15 million settlement. This settlement addresses security issues and unauthorized transactions tied to the app. Many Cash App users may not know they qualify for this payment. The claims process requires acting before the deadline and meeting specific eligibility rules based on the affected period. Understanding these details can help users secure the compensation they deserve. This blog will explain […] - [Network Security Key Best Practices for Stronger Wireless Protection](https://newskysecurity.com/network-security-key-best-practices-for-stronger-wireless-protection/): A network security key is the password that protects a wireless network from unauthorized access. It ensures only devices with the correct code can connect to the Wi-Fi, keeping the network safe from outsiders. Without this key, a device cannot join the network, making it a crucial part of home and business internet security. People often confuse a network security key with the router’s admin password, but they serve different purposes. The admin password lets someone manage the router’s settings, while the network security key controls who can actually use the Wi-Fi connection. Knowing how to find and manage this key […] - [security@facebookmail How to Identify Legitimate Emails and Avoid Scams](https://newskysecurity.com/securityfacebookmail-how-to-identify-legitimate-emails-and-avoid-scams/): If you’ve ever received an email from security@facebookmail.com, you might wonder if it’s truly from Facebook or a scam. This email address is actually legitimate and used by Facebook to alert you about important security issues on your account. Knowing how to recognize these emails and verify their authenticity is key to keeping your account safe. However, scammers often fake emails that look just like the ones from security@facebookmail.com to trick you into giving away personal information. You need to be cautious and know what signs to look for to avoid falling for phishing attempts. Understanding how Facebook handles security notifications helps you stay protected […] - [Network Security Key Essential Guide to Safe Wireless Connections](https://newskysecurity.com/network-security-key-essential-guide-to-safe-wireless-connections/): A network security key is the password used to connect devices to a Wi-Fi network. It protects the network from unauthorized access and keeps information safe from outsiders. Without this key, devices cannot join the network, making it a crucial part of home and business internet security. Many people confuse the network security key with the router’s admin password, but they serve different purposes. The admin password is for managing the router settings, while the network security key is specifically for connecting to the Wi-Fi. Knowing how to find and change this key helps users maintain strong security and control over who […] - [Apple security alert scam warning and how to protect yourself](https://newskysecurity.com/apple-security-alert-scam-warning-and-how-to-protect-yourself/): Many users see a sudden pop-up claiming an “Apple Security Alert” and panic. These messages often warn about viruses or hacking attempts, but most of these alerts are fake scams designed to trick people into giving away personal information or calling fraudulent numbers. The Apple Security Alert scam tries to make users act quickly by using fear, but it’s important to know that legitimate Apple messages won’t demand immediate action through pop-ups like these. These fake alerts can appear through web browsers, emails, texts, or phone calls, making them tricky to spot. They often contain mistakes or use outdated logos, which […] - [Security Today Magazine Layered Hospital Security: Modern Strategies for Protecting Healthcare Facilities](https://newskysecurity.com/security-today-magazine-layered-hospital-security-modern-strategies-for-protecting-healthcare-facilities/): Layered security in hospitals is becoming more important as threats to patient and staff safety grow and change. Today’s hospitals face risks from both physical break-ins and digital breaches, making it crucial to use security measures that work together for better protection. Security Today Magazine highlights how a multi-layered system helps health facilities stay ahead of these challenges. A layered approach combines different security tools and strategies, such as staff duress alarms, real-time tracking systems, and strong access controls. This system not only helps prevent emergencies but also strengthens a hospital’s ability to respond quickly when problems do happen. The benefits […] - [Power Over Ethernet Cameras for Video Surveillance Enhancing Security with Efficient Connectivity](https://newskysecurity.com/power-over-ethernet-cameras-for-video-surveillance-enhancing-security-with-efficient-connectivity/): Power over Ethernet (PoE) cameras are a popular choice for video surveillance because they simplify installation and improve reliability. These cameras use a single Ethernet cable to provide both power and data, reducing the need for extra wiring or adapters. This makes PoE cameras easier to set up and maintain compared to traditional wired or wireless systems. With built-in features like high-definition video, night vision, and motion detection, PoE cameras offer clear and consistent footage for security purposes. They can connect directly to a network, allowing users to monitor video remotely and store data efficiently. This combination of convenience and performance […] - [How to Send a Secure Email in Outlook: Step-by-Step Guide for Enhanced Privacy](https://newskysecurity.com/how-to-send-a-secure-email-in-outlook-step-by-step-guide-for-enhanced-privacy/): Sending secure emails in Outlook is essential to protect your private information from being intercepted by others. You can send secure emails by using Outlook’s built-in encryption features, such as S/MIME or Microsoft Purview, which encrypt your messages so only the intended recipient can read them. This means your sensitive data stays safe during transmission. To secure an email, you simply need to enable encryption settings in Outlook when composing your message. Depending on your account and subscription, you may also digitally sign your emails to verify your identity, adding an extra layer of trust. These tools are available on both desktop […] - [What is Tailgating in Cyber Security Explained: Risks and Prevention Methods](https://newskysecurity.com/what-is-tailgating-in-cyber-security-explained-risks-and-prevention-methods/): Tailgating in cybersecurity is a physical security breach where an unauthorized person gains access to a restricted area by closely following an authorized individual. It relies on exploiting human trust or distraction rather than technical hacking methods. This makes it a simple but effective way for attackers to bypass security controls. If you think cybersecurity is just about firewalls and passwords, tailgating shows how physical and human factors play a crucial role. Understanding this tactic is important because it exposes a gap that purely digital defenses often overlook. Recognizing how tailgating works can help you better protect your workplace or organization. You […] - [Internet No Internet Secured Troubleshooting Causes and Solutions](https://newskysecurity.com/internet-no-internet-secured-troubleshooting-causes-and-solutions/): If you see a “No Internet, Secured” message on your Windows computer, it means you are connected to your Wi-Fi but there’s no actual internet access. You have a secure connection to your router, but your device isn’t receiving any data from the internet. This can happen even if your Wi-Fi icon looks normal. You might notice this issue when your web pages won’t load or your apps can’t refresh. It’s a common problem that has a few possible causes, but it can be fixed. Learn what triggers this error and how you can resolve it using simple steps at home, […] - [Your Organization Has a New Requirement for Annual Security Training - 1300: What You Need to Know](https://newskysecurity.com/your-organization-has-a-new-requirement-for-annual-security-training-1300-what-you-need-to-know/): Many organizations are now asking employees to complete annual security training. This new requirement helps protect sensitive information and keeps your workplace safe from threats like data breaches or cyberattacks. Regular training means you stay updated on the latest risks and learn how to respond if something goes wrong. You might be wondering why this matters. Even a small mistake can put private data at risk or open the door to hackers. Keeping up with yearly training not only protects the company, but it also protects your personal information and your job. Staying on top of these training sessions shows you take […] - [trwho.com security: Key Measures to Protect Your Data](https://newskysecurity.com/trwho-com-security-key-measures-to-protect-your-data/): When you shop online, the security of your information matters. Trwho.com uses SSL Security Encoding to protect your personal and payment details during transactions, helping you feel safer when making purchases. The website accepts common payment methods, but only internationally accepted cards are eligible. By combining strong security with user-friendly features, trwho.com offers a shopping experience that doesn’t sacrifice ease of use for protection. You benefit from advanced technology that helps keep your data secure without making the process complicated or slow. If you want to know more about how trwho.com handles data security and privacy, you’ll find that they balance the latest […] - [ARS Security Freeze: How to Protect Your Credit from Unauthorized Access](https://newskysecurity.com/ars-security-freeze-how-to-protect-your-credit-from-unauthorized-access/): If you want to protect your credit report from unwanted access, an ARS security freeze is a smart tool to use. An ARS security freeze stops lenders and creditors from checking your credit report without your permission, helping prevent identity theft and fraud. This means no new credit accounts or loans can be opened in your name while the freeze is active. Placing a security freeze on your ARS report is straightforward but does require some steps like filling out a form and verifying your identity. You should also know that the freeze can delay or block credit applications until you lift […] - [You've Been Blocked by Network Security What It Means and How to Regain Access](https://newskysecurity.com/youve-been-blocked-by-network-security-what-it-means-and-how-to-regain-access/): If you see a message saying “you’ve been blocked by network security,” it means your attempt to visit a website has been stopped by a firewall, security software, or a network policy. This error is common at schools, workplaces, or even some public networks. It often happens because the website is restricted, your account is flagged, or your activity looks suspicious. This type of block can keep you from reaching sites like Reddit, gaming pages, or even some news sites. There are proven ways to get around these network restrictions and regain access, such as using a VPN, changing your network, […] - [SaaS Security Essentials for Protecting Cloud-Based Applications](https://newskysecurity.com/saas-security-essentials-for-protecting-cloud-based-applications/): SaaS security protects your cloud-based applications and keeps your business data safe from threats and unauthorized access. As more companies move to cloud services, strong security becomes even more important. Without the right protections, your sensitive information can be exposed to risks such as hackers, data leaks, and insider threats. You need to know how to defend against these dangers and manage who can use and share your data. Understanding the basics of SaaS security helps you choose the right tools and best practices to protect your organization. Learn why simple steps like multi-factor authentication and strict access controls are necessary […] - [Vulnerability Archives](https://newskysecurity.com/sectionx1vuln/): Search for: Vulnerability Weak Random Number Generator CVE-2015-6610 CVE-2015-6611 Certificate Verification Vulnerability CVE-2015-1474 CVE-2015-7888 CVE-2015-3825 CVE-2015-6608 CVE-2015-3636 CVE-2015-6602 CVE-2015-3864 CVE-2015-3829 CVE-2015-3826 CVE-2015-3828 Stagefright Vulnerabilities CVE-2015-3824 CVE-2015-1538 CVE-2015-1539 CVE-2013-6282 CVE-2014-3153 CVE-2015-1528 CVE-2014-4943 CVE-2013-4787 CVE-2011-1149 - [Trojan Archives](https://newskysecurity.com/sectionx1malwarex1trojan/): Search for:   Trojan - [Exploit Archives](https://newskysecurity.com/sectionx1malwarex1exploit/): Search for: Exploit   MempoDroid.C MempoDroid.A MasterKey.B MasterKey.A Stagefright Vulnerabilities Lvedu.B Lvedu.A ExymemBrk.A DroidKungfu.A DiutesEx.B DiutesEx.A Darlloz.A Ashmembrk.A - [Information Archives](https://newskysecurity.com/sectionx1info/): Search for: Information Eclair Marshmallow Lollipop KitKat Jelly Bean Ice Cream Sandwich Gingerbread Froyo Exploit - [Stagefright Vulnerabilities](https://newskysecurity.com/knowledgebasex1stagefrightvuln/): Severity Level: HighAppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases:Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: Details or analysis: This is one of several vulnerabilities, also known as “Stagefright vulnerabilities”, in the Android library “libstagefright“. The library is responsible for processing multimedia files. If successfully exploited, each vulnerability could allow a malicious application or individual to execute arbitrary code with elevated privileges, via crafted atoms in MPEG-4 data. In an attack scenario involving MMS, an attacker could send attack code via a multimedia file that, when received, could auto-execute. The vulnerabilities affect Android OS […] - [Marshmallow](https://newskysecurity.com/knowledgebasex1marshmallow/): AppRisk Coverage: YesType: InformationAliases:Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: Details or analysis: Marshmallow is a code name, or nick name, for Android OS version 6.0. This OS version includes key changes that are outlined here, Android 6.0 Changes. Reference: Search for: Recent Posts - [Wireless SecurityCam](https://newskysecurity.com/wireless-securitycam/): NETGEAR ARLO Q Stream live video 24/7 and watch past recordings in sharp 1080p HD resolution from anywhere in the world using your smartphone, tablet, or computer. 130-degree field of view lens lets you see the whole room NEST CAM Is everything OK at home? You’re not always around to see what’s going on. With Nest Cam Indoor, you can check in — even when you’re out. 24/7 live streaming. No dead batteries. And a versatile magnetic stand that lets you put it anywhere. BELKIN NETCAM HD+ The Belkin NetCam HD+ delivers 720p HD live streaming video to your smartphone […] - [Wireless Routers](https://newskysecurity.com/wireless-routers/): Linksys WRT1900AC The professional-grade WRT1900ACS Dual-Band Gigabit Wi-Fi Router from Linksys offers speeds up to N600 + AC1300 Mbps in addition to a 1.6GHz dual-core processor that’s designed to push data through the network at lightning-fast speeds. Asus RT-AC68U AiCloud to bring you multimedia sharing from outside network and Smartphone.Up to 1900 Mbps, 802.11AC(1300Mbps over 5G) + 802.11N(600Mbps over 2.4G). Netgear Nighthawk X6 The Nighthawk X6 delivers the fastest combined WiFi speed up to 3.2Gbps. The X6’s Tri-Band WiFi provides more WiFi for more devices while Dynamic QoS bandwidth prioritization optimizes your Internet speed for gaming and streaming. That means […] - [Wi-Fi Lighting](https://newskysecurity.com/wi-fi-lighting/): LIFX The LIFX Original is a Wi-Fi Smart LED White Light Bulb that gives you the ability to completely personalize your environment. With 16 million colors and 1000 shades of white, you can choose your light like you choose your music, and set the tone for your mood. Increase productivity and concentration with deep blue, or wind down to warm red light. Phillips Hue Philips offers a complete line of connected lighting products. It includes light bulbs, dimmers, light strips, switches, controllers and more. Flux Bluetooth Bulb Set the right ambiance for any moment. Choose from over 16 million colors […] - [Top IoT Devices in the Market](https://newskysecurity.com/top-iot-devices-market/): Oxford defines the Internet of Things as: “A proposed development of the Internet in which everyday objects have network connectivity, allowing them to send and receive data.” Since the conception of the idea of having an “Internet of Things” in 1999 growth has been exponential, growing to 8.7 billion devices in 2012, 22.9 billion in 2016, and a predicted number of 50 billion in 2020. This tremendous growth has enabled us to do things we could never do before, such as self-controlled sprinklers that check the weather and save water by not turning on when rain is forecasted. However, with […] - [Supply/Miscellaneous](https://newskysecurity.com/supplymiscellaneous/): Amazon Echo This smart home hub is essentially a speaker that can listen to users and respond to commands, it can play music, answer questions, read audiobooks, deliver traffic and weather reports, control lights and thermostats, order pizza, order an Uber and much more. The company has also released a similar, lower-priced device called the Tap. AmazonDash Button Amazon offers an assortment of buttons that will order additional supplies of commonly used household products directly from Amazon.com. There are buttons for toilet paper, goldfish crackers, soap, laundry detergent, trash bags, cleaners, Gatorade, soup, razors, beauty products, baby formula and much […] - [Social](https://newskysecurity.com/social/): All the App Icons from this website are from Google Play Store No.2:    Snapchat    No.3:    Instagram    No.4:    Pinterest    No.5:    Live.me    No.6:    TextNow    No.7:    Badoo    No.8:    POF    No.9:    Textfree    No.10:    Tumblr    No.11:    Tango    No.12:    ooVoo Video Call, Text & Voice    No.13:    LinkedIn    No.14:    MeetMe    No.15:    Social Picket    No.16:    Zoosk    No.17:    Free Phone Calls, Free Texting    No.18:    Match™ Dating – Meet Singles    No.19:    After School    No.20: […] - [Smart Outlets](https://newskysecurity.com/smart-outlets/): ConnectSense Smart Outlet With the Connect Sense Smart Outlet, controlling and monitoring the power usage in your home has never been easier. With the touch of a button, the Apple Home Kit-enabled Smart Outlet gives you command of your home. The Smart Outlet features two internet-connected electrical sockets that enable users to control devices plugged into them. The Smart Outlet features Apple Home Kit technology, which provides safe, end-to-end encryption. After installing the Connect Sense Smart Outlet, users can create a scene to automatically turn off the lights, lock the doors, close the garage door and set the thermostat to […] - [Smart Irrigation Controllers](https://newskysecurity.com/smart-irrigation-controllers/): Aifro WaterEco Aifro WaterEco is a smart garden sprinkler system with a 7-inch touch screen. It will be automatically connected to the remote server after system booting, so the users can manage remotely anywhere around the world. The iOS/Android app can be accessed through Aifro Cloud to control the watering from anywhere around the world. It can intelligently adjust the duration of each watering according to the snatched weather data from the Internet. Also, through rain sensors which can induce rainfall. Blossom The Blossom Smart Watering Controller allows you to control your sprinklers from anywhere and uses your local weather […] - [Smart Home System](https://newskysecurity.com/smart-home-system/): Elgato Eve This line of home automation products works with Apple HomeKit to allow users to monitor indoor air, outdoor weather, energy consumption and whether windows and doors are open or closed. The same company also offers a line of smart lighting products that can be controlled with Android or iOS devices. GE Connected Appliances GE makes quite a few different types of connected appliances, including wall ovens, ranges, refrigerators, dishwashers, washers and dryers, water heaters and air conditioners. Through GE’s WiFi Connect service and apps, consumers can control the appliances or receive alerts. Honeywell Smart House Products Honeywell also […] - [Smart Door Locks/Security Camera](https://newskysecurity.com/smart-door-lockssecurity-camera/): Netatmo Welcome This indoor security camera features built-in facial recognition to help keep your family safe. It also sends messages to your smartphone, letting you know when children, elderly relatives or intruders arrive at your home. Piper Piper incorporates both home security and a home automation hub. It has a motion sensor and video camera for security, and the smartphone app allows you to control lighting and appliances. For added security, it can also integrate with door or window sensors. Schlage Sense Long known for its deadbolts and doorknobs, Schlage is getting ready for the IoT era with two lines […] - [Smart Device Security](https://newskysecurity.com/smart-device-security/): Dojo Dojo is constantly analyzing all the network traffic within the home network and enforces the security policy of that specific network. This analysis is done both on the device and Dojo-Labs cloud. Dojo-Labs’ cloud based cyber security engine constantly collects and analyzes the metadata that has been generated by all the deployed Dojos. Sense Traffic to all your smart devices is routed through the secured Sense network, with malware and other threats blocked. Traffic is analyzed with the help of F-Secure security cloud, where threat definitions are updated in real time. Sense also blocks unwanted tracking attempts, making you […] - [Shopping](https://newskysecurity.com/shopping/): All the App Icons from this website are from Google Play Store Aliexpress Amazon Shopping Amazon for Tablet Bestbuy Cute eBay Etsy Geek Groupon Ibotta TopHatter Kohl’s Letgo Mercari Myntra OfferUp RetailMeNot ShopClues TopHatter Voonik Walgreens Walmart Wanelo Wish       - [Medical & Fitness](https://newskysecurity.com/medical-fitness/): AdhereTech AdhereTech makes smart, wireless pill bottles that help ensure that patients are taking their medication. They are currently being used for research studies, but their use will likely expand to the general population. Biotricity Bioflux Available by prescription, Bioflux is a ECG monitoring device that allows physicians to keep track of their cardiac patients 24 hours a day. The full solution includes the device, analytics software and a monitoring service that can contact patients and health care providers when patients are in distress. Breathometer Mint Breathe into the Mint device, and it will tell you how effectively you are […] - [Medical](https://newskysecurity.com/medical/): All the App Icons from this website are from Google Play Store No.1:    GoodRx Drug Prices and Coupons    No.2:    CareZone    No.3:    Ovia Pregnancy & Baby Tracker    No.4:    MyChart    No.5:    FollowMyHealth®    No.6:    Ovia Ovulation & Period    No.7:    Pregnancy +    No.8:    Ear Spy: Super Hearing    No.9:    CVS Caremark    No.10:    Period Calendar, Cycle Tracker    No.11:    1800 Contacts – Lens Store    No.12:    Anatomy Learning – 3D Atlas    No.13:    Pregnancy Week By Week    No.14:    Soothing sleep sounds    […] - [Knowledgebase Archive Blog](https://newskysecurity.com/knowledgebase/): Exploit Ashmembrk.A Trojan Crisis.A Vulnerability CVE-2011-1149   - [Health & Fitness](https://newskysecurity.com/health-fitness/): All the App Icons from this website are from Google Play Store No.1: Fitbit    No.2: CVS/pharmacy    No.3: Calorie Counter – MyFitnessPal   No.4: Google Fit – Fitness Tracking    No.5: My Challenge Tracker    No.6: Sweat With Kayla    No.7: Running for Weight Loss    No.8: 30 Day Fitness Challenge    No.9: Headspace – meditation    No.10: Pedometer & Weight Loss Coach    No.11: Pregnancy & Baby Daily Tracker    No.12: Flo Period & Ovulation Tracker    No.13: Period Tracker, My Calendar    No.14: 8fit – Workout & Meal Plans    No.15: Calorie Counter & Diet Tracker    […] - [Garage Door Openers](https://newskysecurity.com/garage-door-openers/): ChamberlainMyQ You don’t have to buy a new garage door opener in order to control it with your smartphone. Chamberlain MyQ products allow you to control your existing garage door with your iPhone or Android device. Garageio Keypads and codes lead to questions — Who has my code? How secure is my garage? And one of the most common worries…did I forget to close the garage door?! Garageio answers all these questions and more, working from anywhere you have an internet connection. Control your garage door from as close as the next room or as far as the other side […] - [Games](https://newskysecurity.com/games/): All the App Icons from this website are from Google Play Store No.1:    Flip Diving     No.2:    pokemon Go    No.3:    Rolling Sky    No.4:    slither.io    No.5:    Color Switch    No.6:    ROBLOX    No.7:    Best Fiends    No.8:    Gardenscapes – New Acres    No.9:    Subway Surf    No.10:    Game Of War    No.11:    My Talking Tom    No.12:    Geometry Dash Lite    No.13:    NBA LIVE    No.14:    Block Craft 3D    No.15:    Episode    No.16:    Jetpack Joyride    No.17:    Talking Tom Gold Run  […] - [Family](https://newskysecurity.com/family/): All the App Icons from this website are from Google Play Store No.3:    ClassDojo    No.4:    Madden NFL Mobile    No.5:    Exploration Lite    No.6:    YouTube Kids    No.7:    PAC-MAN Pop – Bubble Shooter    No.8:    Temple Run    No.9:    Duolingo: Learn Languages Free    No.10:    Nick    No.11:    Disney Crossy Road    No.12:    Cartoon Network    No.13:    SimCity BuildIt    No.14:    Plants vs. Zombies™ 2    No.15:    BEYBLADE BURST    No.16:    Kids Doodle – Color & Draw    No.17:    Toca Kitchen 2    No.18: […] - [Analysis for Top Apps in Google Play](https://newskysecurity.com/analysis-top-apps-google-play/): Nowadays, smart phone has become a daily essential for our modern lives, and we tend to install many apps to make it more functional. Here, we used our product Apprisk ScannerTM to screen the top 25 apps in each of the 7 categories from Google Play that we think are more popular. And we present our results on this website for you to check how safe your phones are.All the apps were tested before 9/9/2016, and the results for more updated versions will come soon.Please be mindful that the data for some of the apps are missing at this moment, […] - [Tools](https://newskysecurity.com/tools/): All the App Icons from this website are from Google Play Store No.1:    360 Battery – Battery Saver    No.2:    Power Clean – Optimize Cleaner    No.3:    Clean Master (Boost & AppLock)    No.4:    GO Keyboard – Emoji, Sticker    No.5:    Power Battery – Battery Saver    No.6:    Kika Emoji Keyboard Pro    No.7:    Master for Minecraft-Launcher    No.8:    Samsung Smart Switch Mobile    No.9:    Google Translate    No.10:    DU Battery Saver – Power Saver    No.11:    Google Cast    No.12:    Yellow Battery    No.13:    CM Security […] - [Worm Archives](https://newskysecurity.com/sectionx1malwarex1worm/): Search for: Worm   Darlloz.A     - [Malware Archives](https://newskysecurity.com/sectionx1malware/): Search for: Malware   Worm Darlloz.A   Exploit MempoDroid.C MempoDroid.A MasterKey.B MasterKey.A Stagefright Vulnerabilities Lvedu.B Lvedu.A ExymemBrk.A DroidKungfu.A DiutesEx.B DiutesEx.A Darlloz.A Ashmembrk.A   Trojan Infostealer.A Crisis.A     - [Weak Random Number Generator](https://newskysecurity.com/knowledgebasex1weak-random-number-generator/): Severity Level: MediumAppRisk Coverage: YesType: VulnerabilityOWASP: M4: Unintended Data LeakageAliases: Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2009-3278 CVE-2009-3238 CVE-2009-2367 CVE-2008-0166 Details or analysis: This is an NewSky Security AppRisk detection. The Weak Random Number Generator is a vulnerability found in all programming languages and across all programming platforms. Weak random number generators use less processing power, so they are more common than one would think. If the weak random number generator is used in encrypting information, hackers can predict the “randomly” generated numbers, giving them the ability to easily break the code and […] - [Knowledgebase Archive - Page 2 of 5](https://newskysecurity.com/knowledgebase-archive-page-2-of-5/): Search for: Information Malware Worm Exploit Trojan Vulnerability - [MempoDroid.C](https://newskysecurity.com/knowledgebasex1mempodroid-c/): Severity Level: MediumAppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Linux Local Privilege Escalation via SUID Exploit:AndroidOS/CVE-2012-0056.A Platform: Android, LinuxFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2012-0056 Details or analysis: In Linux kernel after 2.6.39 and before 3.2.2, with ASLR disabled, the “mem_write” function does not properly check permissions when writing to process memory. This vulnerability could allow local users to gain privileges by modifying process memory. CVE-2012-0056 is not known to be exploitable remotely. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0056 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0056′ https://git.zx2c4.com/CVE-2012-0056/tree/mempodipper.c http://blog.zx2c4.com/749 https://bugzilla.redhat.com/show_bug.cgi?id=782642 - [MempoDroid.A](https://newskysecurity.com/knowledgebasex1mempodroid-a/): Severity Level: MediumAppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Linux Local Privilege Escalation via SUID Exploit:AndroidOS/CVE-2012-0056.A Platform: Android, LinuxFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2012-0056 Details or analysis: In Linux kernel after 2.6.39 and before 3.2.2, with ASLR disabled, the “mem_write” function does not properly check permissions when writing to process memory. This vulnerability could allow local users to gain privileges by modifying process memory. CVE-2012-0056 is not known to be exploitable remotely. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0056 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0056′ https://git.zx2c4.com/CVE-2012-0056/tree/mempodipper.c http://blog.zx2c4.com/749 https://bugzilla.redhat.com/show_bug.cgi?id=782642 - [MasterKey.B](https://newskysecurity.com/knowledgebasex1masterkey-b/): Severity Level: MediumAppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Master Key vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2013-4787 Details or analysis: MasterKey exploits a defect of cyptographic signature checking in Android devices to execute arbitrary code. This exploit attempts to gain root privilege of the affected Android device via neutering the Android property service. Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications. This could allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not […] - [MasterKey.A](https://newskysecurity.com/knowledgebasex1masterkey-a/): Severity Level: MediumAppRisk Coverage: YesType: ExploitOWASP: M4: Unintended Data LeakageAliases: Master Key vulnerability Platform: AndroidFile size (bytes): N/AFilename: N/AApp title: N/AMD5 Hash: N/ASHA1 hash: N/AAffected CVE: CVE-2013-4787 Details or analysis: MasterKey.A exploits a defect of cyptographic signature checking in Android devices to execute arbitrary code. This exploit attempts to gain root privilege of the affected Android device via neutering the Android property service. Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications. This could allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not […] - [How Digital Planning Strengthens Business Resilience in a Changing World](https://newskysecurity.com/how-digital-planning-strengthens-business-resilience-in-a-changing-world/): Change has become a constant condition for modern businesses. Online platforms evolve, customer expectations shift, and external disruptions can appear without warning. In this environment, resilience is no longer limited to physical operations or financial buffers. A company’s digital presence plays a critical role in how well it absorbs pressure, maintains trust, and continues operating when conditions become uncertain. Digital planning provides structure in this uncertainty. Instead of reacting to issues as they arise, businesses with a clear online direction are better equipped to maintain stability. They understand where they are visible, how they communicate, and how their systems support […] - [The Silent Engine Room: How a Nearshore Software Development Ensures Business Continuity](https://newskysecurity.com/the-silent-engine-room-how-a-nearshore-software-development-ensures-business-continuity/): Imagine a large enterprise or global company that works immediately when a customer clicks “buy”, when a user opens an application at night, when a support question needs to be answered and that all this works without lags, simply, stably. Behind the scenes of this digital mechanism is often not a loud external “facade”, but a quiet, invisible, but reliable mechanism (the “engine room”). This is exactly how the concept of a nearshore software development center works: It replaces chaotic outsourced coordination with a stable, predictable and flexible engine of business development. What Is a Nearshore Software Development Center in […] - [Global Compliance and AI: The Security Checklists for Multilingual Enterprise Video](https://newskysecurity.com/global-compliance-and-ai-the-security-checklists-for-multilingual-enterprise-video/): The rapid globalization of enterprise video content has been driven by the efficiency of AI localization tools, creating a very complex regulatory minefield. Companies scaling training modules, product demos, and internal communications into dozens of languages must confront a critical intersection: global compliance and artificial intelligence. The mad dash to localize quickly, seeking out an AI dubbing free trial solution to evaluate the technology, for example, often misses the immense security and legal responsibility associated with handling voice data, which is a known biometric identifier, and maintaining regulatory integrity in a wide range of jurisdictions. In this shift, rigorous security […] - [Smart Risk Management: The Role of Device Intelligence in Fighting Digital Fraud](https://newskysecurity.com/smart-risk-management-the-role-of-device-intelligence-in-fighting-digital-fraud/): Digital finance continues to expand at a pace that outstrips traditional risk-control frameworks. New onboarding flows, instant credit decisions, and cross-channel customer journeys generate enormous amounts of data – yet they also widen the attack surface for fraud. For many organisations, the central challenge is clarity: distinguishing legitimate applicants from increasingly sophisticated digital identities. Device intelligence has become a structural layer that restores this clarity by revealing environmental and technical signals that behavioural and transactional models cannot reliably capture. Why Device Intelligence Matters in Modern Fraud Prevention The pressure on fraud-prevention systems has increased across retail banking, BNPL, microfinance, and […] - [Best Privacy Management Platforms in 2026](https://newskysecurity.com/best-privacy-management-platforms-in-2026/): Keeping a privacy program on track is not just about having the right policies on paper, it is about running hundreds of small operational tasks without dropping any of them. Most privacy leaders spend their week moving between Records of Processing Activities (RoPA), DPIAs and TIAs, vendor assessments, and data subject request (DSR/DSAR) queues. On top of that, they are expected to keep up with new regulations, coordinate with security and engineering, and now maintain an inventory of AI systems as well. Trying to manage all of this with spreadsheets, shared drives, and email threads quickly becomes unmanageable. Privacy management […] - [Spotting Hidden Risks in Everyday Transactions](https://newskysecurity.com/spotting-hidden-risks-in-everyday-transactions/): We tap, swipe, and pay without thinking. Whether it’s buying coffee, sending money, or renewing a subscription, digital payments feel effortless. But behind that simplicity lies real risk.  As banks and businesses speed up payments, cybercriminals are moving just as fast. Regulators are stepping in, too. Staying ahead now requires more than good intentions. It takes clear insight, strong strategy, and the right technology. Let’s explore how to identify these hidden dangers and what can be done by businesses and regular users to remain a step ahead. How Transaction Monitoring Detects the Undetectable To keep up in the ever-changing world […] - [The Role of Secure & Cloud-Based Management Tools in the Auto Repair Industry](https://newskysecurity.com/the-role-of-secure-cloud-based-management-tools-in-the-auto-repair-industry/): Auto repair has always been a hands-on business. But over the last decade, something quiet and significant has happened inside shops. The paperwork moved to screens. Scheduling shifted to software. Payments, estimates, inspections, and customer records all became digital. Today, even the smallest shop runs on data, whether the owner thinks of it that way or not. That shift brought speed and convenience. It also introduced risk. The same systems that keep a shop running smoothly now carry customer identities, payment details, and years of vehicle history. Secure, cloud-based management tools have stepped into this gap, not as flashy upgrades, […] - [Why Marketing Agencies Must Prioritize Cybersecurity in the Digital Age](https://newskysecurity.com/why-marketing-agencies-must-prioritize-cybersecurity-in-the-digital-age/): Marketing teams rely on vast streams of information to plan campaigns, refine targeting, and measure performance. For example, Netpeak illustrates how an agency’s credibility depends on strong protection of digital assets that support both internal workflow and client operations. Rising Exposure for Digital-First Agencies Modern campaigns involve constant exchanges between analytics suites, advertising platforms, CRM systems, and automation tools. Each connection expands the potential attack surface, giving cybercriminals more opportunities to infiltrate accounts or distort performance data. When attackers compromise campaign assets, they can manipulate budgets, launch unauthorized ads, or steal sensitive insights that were never meant to leave the […] - [The Ultimate Guide to Cyber Workforce Readiness in a Remote-First World](https://newskysecurity.com/the-ultimate-guide-to-cyber-workforce-readiness-in-a-remote-first-world/): Remote work has become the norm, but cyber threats have outpaced the workforce meant to stop them. Attacks now target decentralized systems with greater precision, exposing a major skills gap. Businesses need professionals trained to defend in a remote-first world—people who can spot real risk and respond fast. In this blog, we will share what it takes to build a cybersecurity workforce that’s ready for this new reality, why education must evolve, and how smart programs are bridging the gap between theory and action. From Cubicle Firewalls to Cloud Threats Let’s rewind a little. Pre-2020, most cybersecurity jobs were tied […] - [What Rising Tech Managers Need to Know About Systems Architecture](https://newskysecurity.com/what-rising-tech-managers-need-to-know-about-systems-architecture/): Why do promising tech projects break down just as they start gaining traction? It’s not always the code. And it’s not usually the team. More often, the issue lies in how everything is connected behind the scenes. Systems architecture—the way components talk, share data, and stay stable—can make or break everything from product rollouts to user experience. For rising tech managers, understanding architecture isn’t about memorizing design patterns. It’s about seeing the bigger picture: how decisions made early affect performance, scalability, and cost later. You don’t need to be the architect. But you do need to speak the language, ask […] - [Technical Growth Paths Built Around Modern Threat Response](https://newskysecurity.com/technical-growth-paths-built-around-modern-threat-response/): Ever gotten a weird text from “Netflix Support” asking for your credit card? Or clicked on a suspicious file, only to realize two seconds too late that it wasn’t from your coworker? Threats like these used to be rare enough to laugh off. Now, they shape how businesses think, hire, train, and invest. In this blog, we will share how modern threat response is reshaping technical growth paths across industries. The Security Mindset Isn’t Optional Anymore Cybersecurity no longer lives in the server room. It’s now a boardroom issue, a product design factor, a customer loyalty risk, and in many […] - [The “WannaCry” Ransomware & IoT Zombies](https://newskysecurity.com/the-wannacry-ransomware-iot-zombies-19a08b9f1826/): By now you’ve probably heard about a distributed ransomware (malware that demands a ransom) known as “WannaCry”, but if not, this is a good article to catch you up to speed. In short, WannaCry was intentionally released into the wild beginning in Asia, and it spread to other systems rapidly. The spreading mechanism takes advantage of an exploit that can execute remote code by attacking a flaw in unpatched versions of the Windows SMB service. The flaw is corrected by Microsoft Security Bulletin MS17–010 released in March 2017. The SMB service is used by Windows computers to share files and printers across LANs. When […] - [Sonorousness ransomware unmasked](https://newskysecurity.com/sonorousness-ransomware-unmasked/): Sonorousness: the latest ransomware of the S-Locker family Recently, NewSky Security received a threat sample from the security community that is a derivative of the S-Locker ransomware malware group, or family. This new derivative is known as Sonorousness, named for a class within the malware called “com.sonorousness”. When compared to S-Locker, this new malware contains some enhanced code protection techniques that resulted in a more difficult code analysis. We provide our analysis in this post. The APK Overview The Sonorousness ransomware is combined with an app that promises to deliver porn media. When installed, it performs the following behaviors. The […] - [Smart devices as Bitcoin mining slaves](https://newskysecurity.com/smart-devices-as-bitcoin-mining-slaves-745bdad1fe09/): Recently, we blogged about unintentionally installing Android ransomware to an Android HD media player. It is possible and probable that other unwanted programs, such as Bitcoin mining trojans could be installed on a smart device. Background Bitcoin (BTC) is one of several popular digital (virtual) currency payment systems. It is decentralized and functions peer-to-peer (P2P) with a limited resource — it is suggested that there will only be 21,000,000 units of currency made available, also called bitcoins. Transactions are processed and verified across the Internet by nodes through a process called ‘mining’ carngear . A node that assists in processing transactions through this mining process […] - [Rediscovery of NetUSB Vulnerability in Broadband Routers](https://newskysecurity.com/rediscovery-of-netusb-vulnerability-in-broadband-routers-e943c9ea8634/): Recently NewSky Security Labs performed white-box testing on a Netgear networking product, the R6050 model. During our investigation into the system, we found an exploitable vulnerability in the NetUSB module present in the system. NetUSB is a proprietary technology developed by the Taiwanese company KCodes, intended to provide “USB over IP” functionality. NetUSB is included in millions of currently in-use and popular broadband routers, including models from the following vendors: AllnetAmbir TechnologyAMITAsanteAtlantisCoregaDigitusD-LinkEDIMAXEncore ElectronicsEngeniusEtopHardlinkHawkingIOGEARLevelOneLongshineNETGEARPCIPROLiNKSitecomTaifaTP-LINKTRENDnetWestern DigitalZyXEL Also, to our surprise the same issue was already reported back in 2015 by SEC Consult Vulnerability lab (CVE-2015–3036). We explain the issue in detail here with more focus on technical aspects […] - [Raising the bar in Mobile Security](https://newskysecurity.com/raising-the-bar-in-mobile-security-fd0d9171f47d/): Today we announce our partnership with West Coast Labs, a leading certification firm in the digital security industry, to power its next generation certification program for Enterprise Mobile Security. Our NewSky Security AppRisk™ platform will be the technical building blocks for end-to-end Checkmark Mobile Application Certification. This automation platform starts with Android mobile devices and will expand to iOS, embedded Linux or other mobile OSes based on customer demands. The initial vulnerability assessment, powered by NewSky Security AppRisk™ automation, covers static code assessment, privilege abuse investigation, 3rd party SDK usage, app hardening and dynamic behavioral analysis. This test methodology is aligned with the guidance from […] - [Popular anonymous SNS app leaking user id, geo location, etc](https://newskysecurity.com/popular-anonymous-sns-app-leaking-user-id-geo-location-etc/): The following blog post describes a popular anonymous SNS app in China, pyyx, which leaks its user details such as user id and geolocation in its APIs. Given the leak, a simple web-app can expose the identity of the user who commented or chatted anonymously. The post is composed in Chinese to benefit its major audience. 匿名社交的马后炮 作为一个无聊的中年人,我其实也挺关心年轻人的社交活动的。这不刚到了2016年,最早的那茬90后网红们也终于进入了“好像圣诞树,再美也过不了25”的阶段。我终于觉得跟他们没什么代沟了,可以去沟通一下。 于是我找到大叔,问他:如今国内的年轻人还用陌陌么? 大叔在电话那边沉默了好久,但是他的手机陀螺仪显示在不停的抖,我觉得要么他早发帕金森,要么他在那边开了静音然后拼命笑我老土。我选择相信前者,毕竟我的直觉一般都是准的。第三选项,他在不停的摇手机找附近的美女,是不可能的。隔壁安言的老张偷偷跟我说过,大叔的美女列表,前年就溢出了。 大叔终于说:你老土了吧,现在国内都是玩匿名社交,叫pyyx,你去看看。 搜狗拼音告诉我,pyyx是“炮约一下”(搜狗画外音:这个锅太污我不背)。有趣有趣,我赶紧去下了一个pyyx,打开一看原来叫朋友印象,也行啊。这个app需要的许可权限能有三站路那么长,从地理位置到把我的联系人翻个底儿掉,就差直接帮我抢红包了。我终于猴急猴急的注册了用户,登录以后,加了大叔当好友。 朋友印象挺好玩的,居然能跟微信暗通情愫,找微信朋友聊天。不过最棒的,是能匿名给朋友说话。对方知道你是她朋友,但是就是不知道你是谁。这感觉太棒啦,我赶紧跑去臭骂了几个平时不敢骂的人,比如大叔这样笑我土的。爽! 骂完回来还没喝口茶的功夫,大叔打电话过来,张嘴就骂:你活腻了骂我?你以为你匿名了我就看不出你是谁?你忘了我是黑客了? 其实对付黑客倒是最容易的,你直接拍他马屁就好了。我叫了几声大神,他就老老实实告诉我是怎么知道的了,还给了我一个工具让我查谁匿名骂了我。 工具点这儿: 跟他确认了好几遍这个工具不会偷我密码以后,我把手机号国家号还有密码都输进去了,登录以后我的浏览器就变成了一个查匿名的神器,虽然不太好用不过也够用了。 登录以后点了页面下面这个按钮,就出来一坨数据,据说这个就是我的匿名聊天记录。看不懂不要紧,直接把数据全选然后复制粘贴到下面一个框。这一步工具不能帮你,因为浏览器不!允!许!但是你自己拷贝粘贴就没问题。 等你复制粘贴好以后,按这个按钮,工具就会帮你找出你的匿名聊天记录了。 比如这个: “哦…这样啊”就是你和匿名访客的聊天最后一句,这个是链接可以点的哦。 剩下的事情工具帮不了你了,你自己点开链接看吧,就像工具说的,点开以后亮点自寻,是不是有熟悉的名纸呢?哥只能帮到你这儿了。 当然这个朋友印象拿到的还不止这些,比如他家登录的时候,是把你的手机号还有密码用明文发送的。如果你在星巴克登录,旁边正好有那么7,8个黑客的话。。。细思极恐。 另外呢,如果你碰巧发了一个兴趣点,这个app还会把你当前的精确坐标发上去,于是世界上所有人都知道你现在在哪儿啦。是不是Jennifer春节回家变成王小花,一看便知。 最后呢,这个app会把你的所有联系人都明文发到网上这种吓人的事情我会随便说? 所以,如果你想知道谁匿名骂了你,就去查查吧?查查又不会怀孕。 Disclaimer: 本文除了技术部分以外,纯属虚构。数据查询工具不会存储或者向除了pyyx.com以外的第三方发送你的登录信息。 Update:pyyx已经修改了api,补上了这个漏洞。对这种快速反应,我们手动点赞。 - [NewSky Security LLC Partners With People Power](https://newskysecurity.com/newsky-security-llc-partners-with-people-power-5371281ef123/): This week, we announce our a partnering opportunity to incorporate IoT Halo (TM) with People Power Company’s Pro Security IoT Home Gateway and help protect IoT devices from harmful attacks. The gateway incorporates NewSky Security’s most advanced hacker-resistant device security technology and answers the need for a home internet gateway with extraordinary levels of internet security for IoT systems. IoT Halo (TM) is an AI-based solution that actively learns and enforces expected patterns of network traffic, identifying and remedying suspicious and potentially overwhelming network activities and anomalies. - [Mobile devices bundled with malware?](https://newskysecurity.com/mobile-devices-bundled-with-malware-e50e3207913d/): When you purchase a mobile device, you expect the device to be free of digital threats, clear of viruses, and otherwise safe to use. According to a G Data Mobile Malware Report for Q2 of 2015, more than 20 smartphone models were identified to contain modified or manipulated versions of common apps such as Facebook: Alps 2206Alps 709Alps 809TAlps A24Alps GQ2002Alps H9001Alps N3Alps N9389Alps PrimuxZetaAlps ZP100Andorid P8ConCorde SmartPhone6500DJC touchtalkHuawei G510IceFox RazorITOUCHLenovo S860NoName S806iSESONN N9500SESONN P8Star N8000Star N9500Xiaomi MI3Xido X1111 What are we dealing with here? The modified apps contained additional functions, making them potentially harmful or malicious. Examples of added behavior […] - [Malvertising — Getting More Than You Pay For](https://newskysecurity.com/malvertising-getting-more-than-you-pay-for-3e895a075472/): Updated July 1, 2016 — We shared our findings, and these ad fraud IoCs, with the Facebook ThreatExchange security group. Fig. 1a — Sample data submission[/caption] Many thanks Facebook for their ThreatExchange platform so that we can continue to share details of threat actors and other artifacts with the global security community. In one mobile security research forum that we participate in, one emerging Android app was reported to have slipped into the Google Play app store. The app is a trojan in that it pretends to be a useful app but instead displays advertising. As of June 8th when we initiated this […] - [IoT Thermostat Bug Allows Hackers to Turn Up the Heat](https://newskysecurity.com/iot-thermostat-bug-allows-hackers-to-turn-up-the-heat-948e554e5e8b/): Introduction With the ever-increasing impact of smart and connected devices in our daily lives, Cybersecurity has a variety of security challenges to deal with. The field of traditional computer security deals with a myriad of issues like data theft or sabotage. However, when it comes to IoT security, the consequences of a successful attack can be even more diverse. In this post, we discuss an IoT Smart Thermostat bug and how a hacker leveraged it to raise the control temperature by 12 C (~22 F) degrees. Commodity IoT malware vs Targeted IoT attack The most common purpose of IoT malware […] - [IoT Hackers Shift to the Dark Side](https://newskysecurity.com/iot-hackers-shift-to-the-dark-side-cd3d0005a5e0/): Introduction: The IoT threat landscape differs from conventional malware in terms of code sharing. While many windows malware authors are reluctant to share their source code (for free), IoT botnet source modules are available publicly on darknet hacking forums which makes the code reuse much easier. Most of IoT malware threats have been aided heavily by code sharing and reuse. There has been a trend of late to share hacking tutorials and code within forums with a tag line “This is only for educational purposes”. Many hackers try this technique as they believe this can save them from legal action in […] - [Factory Reset Vulnerability in Netgear ARLO](https://newskysecurity.com/factory-reset-vulnerability-in-netgear-arlo-414c68b17cb6/): Update: CVE-2016–10115 and CVE-2016–10116 have been enlisted by MITRE. Refer to the following CVE entries: CVE – CVE-2016-10115Common Vulnerabilities and Exposures (CVE®) is a dictionary of common names (i.e., CVE Identifiers) for publicly known…cve.mitre.org CVE – CVE-2016-10116Common Vulnerabilities and Exposures (CVE®) is a dictionary of common names (i.e., CVE Identifiers) for publicly known…cve.mitre.org In our ongoing curiosity of IoT products, we took a look at ARLO, a home security camera system from Netgear. ARLO is Netgear’s competing product to the Google Nest Dropcam. When I first researched network security cameras last summer ahead of a planned and lengthy vacation, ARLO, Bigo […] - [Critical Stagefright flaw, millions affected](https://newskysecurity.com/critical-stagefright-flaw-millions-affected/): In late July, researchers with Zimperium announced the discovery of a critical flaw in the Android library libstagefright, potentially affecting 95% of all Android devices, from Android Froyo (2.2) to Lollipop (5.0). The flaw could result in the device getting owned if successfully exploited. Google illustrates Android media architecture and framework in the following diagram: Android media architecture Zimperium describes the vulnerability as the following: “These issues in Stagefright code critically expose 95% of Android devices, an estimated 950 million devices. Drake’s research, to be presented at Black Hat USA on August 5 and DEF CON 23 on August 7 found multiple remote […] - [Case Study: Hacking Smart Lock Security](https://newskysecurity.com/case-study-hacking-smart-lock-security/): Update: This case study was presented at the CanSecWest 2016 conference held in Vancouver, British Columbia, Canada. The presentation is available as a PDF from this link. Exponential growth of smart technology and Bluetooth Smart With the booming of Internet of Things (IoT), Bluetooth Smart, or Bluetooth v4.0 (aka Low Energy or BLE), has played an increasing role in technology adoption. According to Bluetooth SIG, the global market is expected to reach 1.2 billion Bluetooth Smart devices and 2.7 billion Bluetooth Smart Ready devices by 2020. The power efficiency of BLE is a perfect fit for IoT devices. From Bluetooth.com, “You wake up and go […] - [Top Benefits of Server Rentals for Startups and SMEs](https://newskysecurity.com/top-benefits-of-server-rentals-for-startups-and-smes/): For startups and SMEs, the traditional method of buying servers is giving way to a smarter solution of server rentals, especially in an age where time and money matter. This shift grants growing businesses instant access to scalability, flexibility, and dedicated technical support eliminating the massive initial investment. In this article, let’s take a look at the top reasons why server rentals stand out as a strategic infrastructure choice for small and growing companies in 2025. Cost-Effective Capital Management One of the biggest wins when you rent servers is how it changes your budget structure. Owning physical servers means a […] - [Bridging Privacy and Blockchain: Protecting User Data in the Age of DeFi](https://newskysecurity.com/bridging-privacy-and-blockchain-protecting-user-data-in-the-age-of-defi/): With the decentralized finance system (DeFi), you skip the usual bank stuff, like filling out forms and waiting for days to transfer your money. You can send, borrow, or trade funds in a matter of seconds. And guess what? You don’t need permission from a bank or middleman.  It sounds like the financial freedom we’ve all longed for, doesn’t it? Well, as long as by financial freedom you mean having everyone see your wallet activity on the blockchain. That’s right. With DeFi, your transaction history is out there for the world to see.  The number of DeFi users is expected […] - [Design.com vs Adobe Express: A Comparison You Should Know](https://newskysecurity.com/design-com-vs-adobe-express-a-comparison-you-should-know/): If you are looking for a logo maker, you’ve perhaps already come across dozens of names during your search. But how do you know which one is actually reliable? How do you choose something that doesn’t promise a free solution and then ask you for a payment at the download step? To help you avoid any scams and low-quality offers, we have put together two of the most popular logo maker tools in the market and compared them thoroughly so that you can choose the ultimate best of these two.  Design.com Design.com proves that the best design comes from the […] - [Securing Quarry Operations: Cyber-Security Threads You Need to Know](https://newskysecurity.com/securing-quarry-operations-cyber-security-threads-you-need-to-know/): At the outset: if you’re running a quarry operation (whether you’re extracting aggregates, supplying premium stone like Imperial Stone Group, or managing the IT/OT systems that support one) you cannot treat cyber-security as a back-office issue. It matters right away. And it matters because the systems you rely on are increasingly digitised, connected, exposed. That makes them vulnerable in ways many operations don’t fully graspt wrong. Why cyber-security matters in quarry operationsQuarry sites are no longer purely mechanical: you have conveyors, crushers, sorters, material-handling conveyors, remote sensors, fleet tracking, possibly autonomous or semi-autonomous vehicles, networked cameras, remote operations. These are […] - [AI Video Translator for Everyday Use](https://newskysecurity.com/ai-video-translator-for-everyday-use/): AI video translators are software tools that help automate the multi-step process that comes from converting spoken language into another language. Key functions of such technology include speech recognition, machine translation, subtitle generation, lip-syncing and voice synthesis, and cloning. These translators matter because they help to break down language barriers, making information and entertainment more easily accessible. Whether it’s enhancing education to facilitating business and communications, it’s an influential technology that has many useful facets to it.  Modern AI translation tools make content more accessible and reduce the amount of effort and time companies need to spend on translating such […] - [7 Best AI Video Surveillance Software in 2026](https://newskysecurity.com/7-best-ai-video-surveillance-software-in-2026/): AI has changed how we think about security. Today’s surveillance software doesn’t just record it detects, analyzes, and alerts in real time. According to MarketsandMarkets, the AI in video surveillance market is growing at 20.6% CAGR, projected to exceed $14 billion by 2028. That growth reflects a clear trend: smarter, cloud-connected systems that can identify risks faster than humans ever could. In this guide, we’ll explore the 7 best AI video surveillance software platforms in 2025 — solutions that blend analytics, automation, and scalability for modern security operations. What Defines Great AI Video Surveillance Software? Before you choose a platform, […] - [A Step-by-Step Cloud Incident Response Guide for Security Teams](https://newskysecurity.com/a-step-by-step-cloud-incident-response-guide-for-security-teams/): Cloud security breaches can occur almost any time. Once threat actors gain access to the cloud infrastructure, they can rapidly move to other regions and services, leveraging the automation and scalability of cloud systems within minutes. The average cost of a cloud data breach is $4.4 million, and the estimated time to detect and contain an incident is 277 days. Many security teams still rely on incident response procedures for on-premises environments. This document provides step-by-step guidance to cloud incident response using NIST frameworks. The examples have been tailored to AWS, Azure, Google Cloud, and multi-cloud environments. Why Cloud Incident […] - [The GTA 6 Controller Leak and Why It Exposed a Much Bigger Security Problem](https://newskysecurity.com/the-gta-6-controller-leak-and-why-it-exposed-a-much-bigger-security-problem/): The GTA 6 controller leak was one of the most chaotic moments in recent gaming history, but the real story is not about the footage. It is about how a young individual with basic household equipment gained access to one of the most protected projects in entertainment. Using a TV, a controller and unauthorized entry into internal systems, the attacker managed to view early GTA 6 builds and record them without any advanced hacking tools. For security professionals, this incident is a perfect case study of how convenience, remote access and trust can create vulnerabilities that even massive companies fail […] - [Will Bitcoin Ever Replace Traditional Currency?](https://newskysecurity.com/will-bitcoin-ever-replace-traditional-currency/): Whether digital assets could replace traditional money one day continues to generate discussion in financial and technology circles. Among these assets, Bitcoin is often the center of attention because it was the first cryptocurrency and remains the most widely recognized.  While enthusiasm for alternatives to government-backed currency has grown, the practical challenges of such a transition are significant. To understand whether replacement is realistic, it is necessary to examine the current role of fiat money, the features that digital assets offer, the existing barriers, and the possibility of coexistence between the two systems. The Current Role of Traditional Currency Traditional […] - [Best Hostinger Discount Code for the Black Friday Sale 2025](https://newskysecurity.com/best-hostinger-discount-code-for-the-black-friday-sale-2025/): As a Cyber Security company owner, I’m obsessed with three things: performance, value and security. For years, I bounced between different web hosts, always feeling like I was compromising one for the other. It was frustrating. That all stopped when I finally moved all my sites to Hostinger. It’s hands-down the best all-in-one platform I’ve ever used, and I’m so excited to share that I’ve got an incredible Black Friday deal for you. You can get 30% off right now by using my link: https://hostinger.com?REFERRALCODE=HOSTINGER30 Or use my code at checkout: HOSTINGER30 My journey started with their standard Web hosting […] - [Top AI Logo Generators for Startups](https://newskysecurity.com/top-ai-logo-generators-for-startups/): Launching a startup means working fast, and that also means creating a strong brand identity right away. Your logo is what gets you recognized, so it has to stand out. Usually, creating logos is the job of a professional designer, but what to do when you’re new to business and can’t afford one?  AI-powered logo generators can help with that. These tools have become so advanced that it’s possible to create professional-quality logos in minutes, without a hole in your budget. We’ve researched and rounded up some of the best AI logo generators to make the start of your business […] - [The Ethics of AI Data: Privacy, Bias, and Responsibility in the Age of Automation](https://newskysecurity.com/the-ethics-of-ai-data-privacy-bias-and-responsibility-in-the-age-of-automation/): AI​‍​‌‍​‍‌​‍​‌‍​‍ is the most important driver that keeps society progressing at an unprecedented rate. In a scenario where machines are capable of writing poems, diagnosing illnesses, and forecasting customer trends, the first thing that comes to mind is that artificial intelligence (AI) is both a wonder and a mirror; it not only shows the brightness of human creativity but also the imperfections of our data. However, with automation taking over decisions, the ethics of data for AI has become a central issue of our era. Issues such as privacy, bias, and accountability have transformed from being merely theoretical concepts into […] - [What is MDM Software? Your Complete Guide to Mobile Device Management Solutions](https://newskysecurity.com/what-is-mdm-software-your-complete-guide-to-mobile-device-management-solutions/): Mobile Device Management (MDM) software has become the backbone of modern enterprise security, helping organizations control, secure, and monitor their growing fleets of mobile devices. This comprehensive guide explores what MDM software is, why it’s crucial for businesses of all sizes, the key features to look for, and how the right solution can transform an organization’s approach to device management while addressing critical security and compliance challenges. The typical company manages over 1,000 mobile devices across their organization. Each device represents a potential security vulnerability that requires careful oversight. Forward-thinking companies have recognized this challenge and developed comprehensive solutions that […] - [How Test Automation Helps Prevent Security Breaches](https://newskysecurity.com/how-test-automation-helps-prevent-security-breaches/): In today’s digital landscape, security breaches are becoming more frequent and costly. Cybercriminals constantly look for weaknesses in applications, systems, and networks to exploit. Even a small vulnerability can lead to data theft, financial losses, or reputational damage. While organizations are aware of these risks, many still rely heavily on manual testing, which can overlook critical security flaws. This is where test automation comes in. Automated testing not only speeds up the testing process but also plays a vital role in detecting vulnerabilities before attackers can find them. Understanding the Link Between Software Testing and Security Software testing and security […] - [Choosing the Right Website When You Need Someone to Do Your Class](https://newskysecurity.com/choosing-the-right-website-when-you-need-someone-to-do-your-class/): The rise of online education has made learning more accessible than ever. But with that flexibility comes a new set of challenges — tight deadlines, back-to-back assignments, online quizzes, and never-ending discussions. It’s no surprise that many students find themselves overwhelmed and start searching for help online with the question: “Can I find someone reliable to do my class for me?” While many websites promise to manage your online coursework, not all of them deliver what they claim. Choosing the right website is crucial — not just for good grades, but also for your academic integrity, data privacy, and peace […] - [Best Z.ai Discount Coupon](https://newskysecurity.com/best-z-ai-discount-coupon/): I have been a big user of Z.ai’s Claude Code integration for AI coding for quite some time. Its really awesome to see and open source company provide such a great model at such a low price! So if your looking for the best Z.ai pricing in 2025, you can use my discount code or coupon! Click this link to get the discount automatically applied for you at checkout! Or simple copy paste this code into the coupon box at checkout: E9QQGUXOCE Email me if you have any questions: info@newskysecurity.com - [The Role of MFA in Securing Work Devices for Frontline Staff](https://newskysecurity.com/the-role-of-mfa-in-securing-work-devices-for-frontline-staff/): Multi-factor authentication (MFA) has become essential for securing work devices in frontline environments. Traditional password-based security creates significant challenges when workers share computers across shifts in manufacturing plants, hospitals, and retail stores. Frontline workers need authentication systems that balance strong security with operational efficiency. Shared workstations, high employee turnover, and time-pressured environments demand solutions that go beyond conventional approaches. In this blog, we’ll walk you through how MFA solves the specific security challenges frontline workers face, share real-world implementation approaches that have worked across manufacturing, healthcare, and retail, and show you how to track your results and meet compliance requirements. […] - [Quantum Computer Pricing in 2025: What You Need to Know](https://newskysecurity.com/quantum-computer-pricing-in-2025-what-you-need-to-know/): Quantum computers are transitioning from research-laboratory curiosities toward commercial and enterprise-grade tools. But before you ask “what’s the price?”, it’s important to understand the big picture: What exactly you’re buying, how you’ll access it, and what infrastructure accompanies it.Below is a up-to-date breakdown of models, pricing, and the factors driving cost. Access Models: Cloud vs. On-Premises There are broadly two ways to use quantum computing in 2025: Cloud-Based Quantum Computing: What It Costs Here are some representative vendors and their current pricing models. IBM Quantum IBM offers its quantum systems via the “IBM Quantum” platform. IBM Quantum Microsoft Corporation Azure […] - [Masuta : Satori Creators’ Second Botnet Weaponizes A New Router Exploit.](https://newskysecurity.com/masuta-satori-creators-second-botnet-weaponizes-a-new-router-exploit-2ddc51cc52a7gi52211e8d5950/): Introduction Since the inception of the Mirai code leak, many botnets have been seen in the IoT threat landscape. While some of them are clearly Mirai carbon copies, others have added new attack methods, often taking the route of exploits to perform an attack. We analyzed two variants of an IoT botnet named “Masuta” where we observed the involvement of a well-known IoT threat actor and discovered a router exploit being weaponized for the first time in a botnet campaign. Masuta Code Leak & Attribution We were able to get hands on the source code of Masuta (Japanese for “master”) […] - [Best Proxy Browsers in 2026](https://newskysecurity.com/best-proxy-browsers-in-2026/): If you just want the shortlist: in 2026 I’d use Tor Browser for maximum anonymity, Brave (Private Window with Tor) when I want Tor inside a mainstream browser, Opera for a simple built-in VPN/proxy experience, Firefox when I need fine-grained, per-profile proxy control, and Vivaldi if I want a power-user browser with integrated VPN (via Proton). That covers the strongest privacy path (Tor), the convenient hybrid (Brave), the “it just works” option (Opera), the configurable classic (Firefox), and the customizable pro pick (Vivaldi). Tor Project What “proxy browser” really means (and why it matters) People say “proxy browser,” but they […] - [Proxy Server Location](https://newskysecurity.com/proxy-server-location/): When I think about what makes a proxy server truly effective, the first thing that comes to mind is location. In short, the proxy server location determines how well the proxy performs—impacting speed, access, privacy, and reliability. If I pick the wrong location, I can end up with sluggish connections, blocked content, or inaccurate data. If I pick the right one, I get fast performance, secure browsing, and access to the right regional content. Why Proxy Server Location Matters A proxy server acts as an intermediary between my device and the internet. Every time I make a request—say, to visit […] - [What is a Hackintosh Notebook?](https://newskysecurity.com/what-is-a-hackintosh-notebook/): When people ask me if it’s possible to run macOS on a non-Apple laptop—a so-called “Hackintosh notebook”—the short answer is yes, but it’s not simple. A Hackintosh notebook is a standard Windows or Linux laptop that’s been configured to run macOS through community-built tools and patches. It gives you the macOS experience without buying Apple hardware, but it comes with major trade-offs in stability, compatibility, and legality. What a Hackintosh Notebook Really Is A Hackintosh notebook isn’t just a clever software trick—it’s essentially a hybrid computer. You’re taking off-the-shelf hardware and convincing macOS that it’s running on a real Mac. […] - [Is a text message from 95246 legitimate in 2026?](https://newskysecurity.com/is-a-text-message-from-95246-legitimate-in-2026/): Short answer: Yes — a text from the short-code 95246 can be legitimate, but you should treat it with caution and verify the context before trusting it. Why it can be legitimate The number 95246 is a short code registered to ID.me (ID.me), an identity-verification service used by government agencies and others. One directory entry shows: “Short Code 95246 is owned by ID.me … providing SMS verification services for IRS.gov and USPTO.gov.” Source: Texting WorldAnother explains that if you’ve recently used ID.me (for example with a government site) you might legitimately receive a 95246 text with a verification code or […] - [10.0.0.0.1](https://newskysecurity.com/what-is-100001/): 10.0.0.0.1 not a valid IP address — yet it’s one that confuses a lot of people online. The correct address most users mean is 10.0.0.1, a private IP address most commonly used by routers and gateways for local network management. In short: 10.0.0.0.1 doesn’t exist, but 10.0.0.1 does, and it’s often your way into your router’s admin panel. What 10.0.0.1 Actually Is The IP address 10.0.0.1 belongs to a block of private IP addresses defined by the Internet Assigned Numbers Authority (IANA). It’s part of the Class A private range (10.0.0.0 to 10.255.255.255) reserved for internal networks. That means it […] - [Keylogger APK](https://newskysecurity.com/keylogger-apk/): Short answer: A “keylogger APK” is an Android application package (APK) designed to register and record keystrokes typed on an Android device. While such software can be used for legitimate monitoring (for example, by a parent on a device they own), in many cases it is illegal or unethical if installed without the user’s knowledge or permission. What is a keylogger APK? In more detail: A keylogger is software (or hardware) that logs the keys a user types—usernames, passwords, chats, search terms and so on. Veracode On Android, a “keylogger APK” refers specifically to an Android package file (.apk) that, […] - [Best Unblocked Browser for School](https://newskysecurity.com/best-unblocked-browser-for-school/): Short answer: there isn’t a magical “unblocked” browser. The best choice is the school-approved browser (usually a managed Chrome or Microsoft Edge) because it’s optimized for the network, complies with safety policies, and reliably opens what I actually need for class. If something is blocked that I genuinely need, the right move is to request access—not to try to bypass filters. Why “unblocked” isn’t the goal (and what I actually want instead) In most schools, web filtering is required by policy and sometimes by law (for example, CIPA in the U.S.), so any tool that promises to “evade” filters is […] - [Clash for Windows](https://newskysecurity.com/clash-for-windows/): When I first started using Clash for Windows, I was amazed by how simple it made managing network proxies on my PC. In short, Clash for Windows is a graphical interface for the Clash core, a powerful open-source proxy tool that allows users to manage and route internet traffic through multiple proxy servers efficiently. It’s mainly used to improve privacy, bypass network restrictions, or optimize internet routing for better speed and stability. What Is Clash for Windows? Clash for Windows (often abbreviated as CFW) is a Windows-based client built on the Clash proxy engine. The core itself is written in […] - [Why Is Find My Friends Not Updating Location](https://newskysecurity.com/why-is-find-my-friends-not-updating-location/): I’ve run into this issue more times than I can count — opening Find My Friends (or Find My on newer iPhones) only to see that someone’s location hasn’t updated in hours or even days. The short answer? It usually comes down to one of three things: connectivity problems, permissions or settings being off, or the other person’s device being unavailable. In most cases, the issue isn’t the app itself but something simple like a lost signal or a background refresh being disabled. 1. Connectivity Issues The most common reason Find My Friends stops updating is poor or no internet […] - [How to Download YouTube Videos on PC](https://newskysecurity.com/how-to-download-youtube-videos-on-pc/): Downloading YouTube videos on a PC is simple when you use the right tools. The easiest way is to use a reliable online downloader or a dedicated desktop app. You just copy the video link from YouTube, paste it into the tool, choose your preferred format (like MP4 for video or MP3 for audio), and click download. Within moments, the video will be saved directly to your computer. Understanding the Basics YouTube doesn’t allow direct downloads from its platform unless you’re using YouTube Premium, which offers limited offline access. However, many people prefer having a local copy for personal use, […] - [Understanding Mbps and Gbps](https://newskysecurity.com/mbps-and-gbps/): To make sense of these units, let’s break them down. Internet speed is measured in bits per second, not bytes. One bit is the smallest unit of digital data — it’s either a 0 or a 1. So, when converting between the two:1 Gbps = 1,000 Mbps0.001 Gbps = 1 Mbps This means that if your internet plan offers 500 Mbps, you’re getting half a gigabit per second. It’s a linear relationship — just divide by 1,000 to convert Mbps to Gbps, or multiply by 1,000 to go the other way. Mbps and Gbps in Everyday Use In real-world terms, […] - [What Businesses Get Wrong About System & Communications Protection Standards](https://newskysecurity.com/what-businesses-get-wrong-about-system-communications-protection-standards/): Many companies misunderstand compliance frameworks like CMMC and NIST when it comes to system and communications protection requirements that extend far beyond basic network security. Surface-level implementations that check boxes without understanding underlying principles leave organizations vulnerable despite believing they’ve achieved compliance through minimal efforts. Missteps can lead to vulnerabilities, audit failures, and costly fixes that could’ve been avoided with proper understanding from the start. Getting compliance wrong means wasting money on ineffective controls while remaining exposed to threats and audit findings that force expensive remediation under tight deadlines with penalties looming. Common misconceptions and how to get this critical […] - [A Big Game Changer for our Reddit Marketing Strategy](https://newskysecurity.com/a-big-game-changer-for-our-reddit-marketing-strategy/): As the CEO of NewSky Security, I’m always looking for innovative ways to cut through the noise and connect with savvy customers who need our cyber security solutions. Reddit has always been on our radar as a massive opportunity, but it’s also a minefield. The user base is notoriously annoying to market to and resistant to traditional marketing, and building a genuine presence from scratch requires a time investment we simply couldn’t afford. We needed a way to kickstart authentic conversations without spending months, or even years, building up karma and credibility. We were initially skeptical about using any service […] - [Who Has the Best MDM for Windows, Mac, and Linux? My Experience with Swif](https://newskysecurity.com/who-has-the-best-mdm-for-windows-mac-and-linux-my-experience/): When I started searching for the best MDM for Windows, Mac, and Linux mdm software, I didn’t expect the answer to be so clear. I’ve tested several platforms over the years—some too complex, others locked to a single OS—but none matched the flexibility, intelligence, and simplicity of Swif’s MDM software. Why I Needed a True Cross-Platform MDM My team spans designers, engineers, and remote staff across multiple time zones. We operate in a hybrid environment—Windows for operations, macOS for design, and Linux for development. Managing this mix used to be a logistical headache: inconsistent security policies, manual patching, and device […] - [Can You Really Trust Second-Hand Devices? A Guide to Safer Tech Purchases](https://newskysecurity.com/can-you-really-trust-second-hand-devices-a-guide-to-safer-tech-purchases/): Buying used technology has become increasingly common in a world where upgrades occur every few months. Many people opt for pre-owned gadgets, such as MacBooks and iPads, to save money while enjoying premium devices at a lower cost. These options are budget-friendly and support sustainability. Yet behind the savings, there’s always uncertainty about what’s inside. Some products may appear perfect on the surface, but they often conceal replaced parts, outdated software, or remnants of another user’s data. When buying any device, the goal is not only to save money but also to stay safe. Hidden malware or counterfeit hardware can […] - [How to Evaluate Open-Source Authentication Tools for Your Business](https://newskysecurity.com/how-to-evaluate-open-source-authentication-tools-for-your-business/): Authentication is the backbone of secure digital applications. For businesses, choosing the right open-source authentication tool can be daunting. With numerous options available, each offering different features, security measures, and integration capabilities, making an informed decision is critical. Selecting the wrong tool can lead to vulnerabilities, inefficient workflows, or compatibility issues with existing systems. On the other hand, the right solution can enhance security, streamline development, and support scalability. This article walks through key factors to consider when evaluating open-source authentication tools. From understanding business needs to testing scalability, these steps help ensure you pick a tool that aligns with […] - [The Psychology-Cybersecurity Connection: Finding Your Perfect Academic Path in 2026](https://newskysecurity.com/which-psychology-major-is-most-related-to-cyber-security-in-2026/): Understanding the Intersection of Human Behavior and Digital Security The cybersecurity field has undergone a radical transformation over the past decade. Gone are the days when security professionals focused solely on firewalls and encryption algorithms. Today’s threats exploit the most vulnerable component in any system: the human element. Social engineering attacks account for a staggering percentage of successful breaches, making psychological expertise not just valuable but essential. Organizations now recognize that understanding human cognition, decision-making patterns, and behavioral tendencies forms the foundation of effective security strategies. This realization has created unprecedented opportunities for professionals who can bridge the gap between […] - [Is Cyber Security a Good Career? The 2026 Professional's Guide to Breaking Into Digital Defense](https://newskysecurity.com/is-cyber-security-a-good-career-the-2026-professionals-guide-to-breaking-into-digital-defense/): Why Organizations Are Desperately Seeking Security Professionals The digital transformation sweeping through every industry has created an unprecedented demand for cyber security talent. Companies face an average of 1,200 cyber attacks annually, with breaches costing businesses millions in damages and reputation loss. This reality has transformed cyber security from a back-office IT function into a boardroom priority. Organizations across healthcare, finance, retail, and government sectors are competing for qualified professionals who can protect their digital assets. The talent shortage has reached crisis levels, with an estimated 3.5 million unfilled positions globally. This gap represents not just opportunity but job security […] - [Best DevSecOps Tools for Developers](https://newskysecurity.com/best-devsecops-tools-for-developers/): Building software is not just about coding anymore. You also need to keep it safe from the start. That is where DevSecOps helps. It mixes development, security, and operations into one process. The right tools make this easier. They protect your code, catch problems early, and save you time. In this guide, we will look at the best DevSecOps tools that every developer should know. What is DevSecOps? DevSecOps is a framework that stands for development, security, and operations. Instead of checking for security issues at the end, teams build security checks directly into every stage of the software development […] - [A Cybersecurity Expert’s Guide to Identifying Truly Safe Canadian Online Casinos](https://newskysecurity.com/a-cybersecurity-experts-guide-to-identifying-truly-safe-canadian-online-casinos/): The development of the iGaming sector in Canada has, without a doubt, opened doors for many entertaining opportunities. However, with this comes the risk of cyberattacks and fraudulent activities. This is why experts note that legitimate online casinos in Canada must adhere to the strictest regulatory requirements and follow well-established standards related to player protection. Learn about the essential factors and specific elements that differentiate secure casino sites from unsafe operators. Canada’s Gaming Regulations and Legal Framework The legal environment is a key element in identifying secure Canadian casino sites. This is because legitimate operators like the safe online casinos […] - [Lifesavers for a Complex International Lawsuit](https://newskysecurity.com/lifesavers-for-a-complex-international-lawsuit/): As a cybersecurity firm, precision and confidentiality are the pillars of our business. When NewSky Security was recently involved in a complex civil lawsuit with a Spanish-speaking client, we found ourselves drowning in audio evidence—depositions, client meetings, and expert consultations, all in Spanish. Our legal team was adamant: we needed flawless, certified English transcripts that would be admissible in a U.S. court. The stakes were incredibly high. So i reached out to a contact of mine at the Washington State Patrol and he recommended Ditto Transcripts and boy did they help us out! What immediately stood out was their explicit […] - [The flashlight I carry to on-site red team engagements](https://newskysecurity.com/the-flashlight-i-carry-to-on-site-red-team-engagements/): You don’t have time for theory at 02:17am on an engagement. You’re on-site, your bag is lighter than you’d like, and the difference between “seen” and “unseen” is often the light in your hand. After hundreds of doors, roofs, and server rooms, I’ve settled on a simple truth: for full-scope engagements, an EDC-sized flashlight with USB-C charging and high CRI is the tool that disappears in your pocket, and shows you what really matters when it’s dark. A buddy of mine from Zaklampwinkel, recommended some flashlights, then I tested the lights the way we use them in our red teaming […] - [Best LunarCrush Discount Coupon](https://newskysecurity.com/best-lunar-crush-discount-coupon/): I have been a big user of LunarCrush’s Crypto data for quite some time. Its really interesting to see how the market is always changing in terms of pricing and social momentum. So if your looking for the best Lunarcrush api pricing in 2025, you can use my discount code or coupon! Use code: LUNARCRUSH at checkout! Email me if you have any questions: info@newskysecurity.com - [be1crypto.com Security Best Practices and Risk Assessment](https://newskysecurity.com/be1crypto-com-security-best-practices-and-risk-assessment/): Be1crypto.com is designed to protect users’ cryptocurrency assets through strong security measures. The platform uses encryption and two-factor authentication to help safeguard accounts against hacking and theft. These features are important in a world where digital currency faces constant risks from cyberattacks. Users can expect tools that help manage security threats and reduce vulnerabilities while trading or investing. By combining standard protections with expert advice, Be1crypto.com aims to make navigating crypto risks clearer and safer for its community. More details about these security efforts show how seriously the platform takes asset safety. For those interested in understanding how Be1crypto.com handles security challenges, […] - [When opening and closing a security container, complete the? ](https://newskysecurity.com/when-opening-and-closing-a-security-container-complete-the/): Common Options:(A) SF 701(B) SF 702(C) SF 700(D) SF 703 Answer The correct answer is (B) SF 702 Why Option B is the right one. The answer to this question is SF 702. Security containers are opened and closed using SF 702. Keep tabs on security containers always. You can open and close the security container whenever you want. Security containers should only be opened for privacy and security purposes, nevertheless, if at all possible. All available precautions, including fingerprint, password, and guard protection, should be used in security containers. The Security Container Inspection Sheet is a Standard Form (SF 702). Who […] - [President Biden Signs Social Security Fairness Act into Law](https://newskysecurity.com/biden-social-security/): Washington D.C. – In a landmark move for retired public servants across the nation, the Social Security Fairness Act was signed into law, ending decades of reduced benefits for millions of retired law enforcement officers, firefighters, teachers, and other government employees. This historic legislation, enacted on January 5, 2025, repeals the contentious Windfall Elimination Provision (WEP) and Government Pension Offset (GPO), two provisions that have long been criticized for unfairly penalizing public service retirees. For nearly four decades, the WEP and GPO have significantly diminished the Social Security benefits of individuals who also receive a public pension from non-Social Security […] - [A Beginner's Guide to Browser Agent Security Risk: Keeping Your New AI Assistant Safe](https://newskysecurity.com/browser-agent-security-risk/): AI is getting smarter and more helpful every day. One of the newest tools is something called a “browser agent.” Think of it as a super-smart assistant that lives in your web browser (like Chrome, Firefox, or Safari). You can ask it to do things for you, like booking a flight, summarizing a long article, or filling out boring forms. It’s like having a personal intern to handle your online chores! 🤖 But, just like you wouldn’t give a new intern the keys to your house and your bank account password on the first day, we need to be careful […] - [High-Value Freight Theft: Trends and Prevention Strategies](https://newskysecurity.com/high-value-freight-theft-trends-and-prevention-strategies/): Global supply chains have become incredibly complex, creating new opportunities for criminals to target high-value freight shipments. Electronics, pharmaceuticals, luxury goods, and even premium food products are sitting ducks when they’re moving through vulnerable points in the logistics network. Freight theft goes way beyond simple financial losses, though those numbers are staggering enough on their own. When shipments disappear, entire supply chains get disrupted, delivery promises get broken, and customer relationships suffer real damage. Companies are finally waking up to the fact that cargo theft security isn’t something they can put off anymore. We’ll break down the latest trends criminals […] - [What is Baiting in Cyber Security?](https://newskysecurity.com/what-is-baiting-in-cyber-security/): Baiting is a type of social engineering attack where a cybercriminal uses a tempting offer or a curiosity-piquing item, like a free USB drive, to trick someone into exposing their personal information or infecting their system with malware. Think of it like a real-world trap; the attacker dangles an enticing “bait” to lure an unsuspecting victim into compromising their own security. The core of the attack relies on exploiting human greed and curiosity. How Baiting Works The mechanics of a baiting attack are deceptively simple and often play out in a few predictable steps. The attacker’s primary goal is to […] - [Is Cybersecurity Hard to Learn? A Guide to Cyber Skills.](https://newskysecurity.com/is-cybersecurity-hard-to-learn-a-guide-to-cyber-skills/): Is Cyber Security Hard? As technology continues to evolve, the importance of cybersecurity has become increasingly paramount. With the rise of cyber threats such as data breaches and cyber attacks, the demand for skilled cybersecurity professionals has surged. However, many individuals pondering a career in cybersecurity often ask, “Is cybersecurity hard?” Understanding the Challenges Cybersecurity may seem daunting at first glance. The field encompasses various domains including network security, cloud security, and information security. Each area requires a unique set of technical skills and practical experience. The complexity of the subject matter can make it appear difficult to learn, especially […] - [Cyber Security Monitoring: What You Need to Know](https://newskysecurity.com/cyber-security-monitoring-2/): Cyber Security Monitoring Services Safeguard Your Business from Cyber Threats Why Choose Our Cyber Security Monitoring? In today’s digital landscape, cyber threats are more prevalent than ever. Our cyber security monitoring services provide real-time analysis of your IT environment, ensuring that any suspicious activity is identified and addressed immediately. With our expert team and advanced technology, we offer protection tailored to your business needs. Key Features - [AI Security Threats and How to Defend Against Them](https://newskysecurity.com/ai-security-threats-and-how-to-defend-against-them/): Artificial intelligence is becoming a huge part of modern business security, and honestly, it’s pretty amazing what these systems can do. But here’s the thing – as more companies jump on the AI bandwagon, we’re also seeing a whole new breed of cyber threats that are specifically designed to mess with AI systems. The problem is that AI systems, while incredibly powerful, can also become targets for some really unique cyber attacks that your traditional security measures might completely miss. It’s like having a super advanced lock on your front door, but the thieves have figured out how to pick […] - [Managed IT Services vs. In-House IT: Which Is Better?](https://newskysecurity.com/managed-it-services-vs-in-house-it-which-is-better/): Technology is absolutely critical to every business today, but choosing between in-house IT staff or outsourced support isn’t a simple decision. Both approaches have their strengths, and the wrong choice can cost you money, productivity, and peace of mind when technology problems arise. In-house IT means having employees on your payroll who handle day-to-day technology needs, from fixing computers to managing servers and security. Managed services means partnering with a third-party company that provides monitoring, support, and strategic guidance for your technology infrastructure. A trusted managed IT services provider Boulder Colorado or anywhere else can bring specialized expertise, predictable monthly […] - [What Are IoT Sensors? Types, Uses, and Security in 2025](https://newskysecurity.com/iot-sensors/): As industries continue to embrace digital transformation, the Internet of Things (IoT) has become a foundational enabler—driving innovation through interconnected devices that communicate seamlessly. From smart surveillance systems to industrial automation and wearable security devices, IoT technology leverages sensors, software, and connectivity to monitor environments, enhance security, and streamline operations. At the core of these intelligent systems are IoT sensors—critical security components that collect real-time data to detect threats, track assets, and ensure environmental safety. In this article, we’ll explore how New Sky Security applies sensor-driven solutions to strengthen security systems across industries, the types of sensors used, and their […] - [Critical IDOR Flaw in CareFlow EHR Exposes Patient Records (CVE-2025-24970)](https://newskysecurity.com/cve-2025-24970/): A critical Broken Access Control vulnerability has been discovered in the CareFlow Electronic Health Record (EHR) platform. This flaw, tracked as CVE-2025-24970 and nicknamed “Patient Zero,” allows any authenticated user to access the sensitive health records of any patient in the system. It carries a CVSS score of 8.8 (High) and represents a major data privacy risk. TL;DR: What is CareFlow EHR? CareFlow EHR is a widely adopted, open-source Electronic Health Record platform used by hospitals, clinics, and healthcare providers to manage patient data, from medical histories and lab results to billing information. The “Patient Zero” Vulnerability Explained The vulnerability […] - [Still Haunted by Ghost Signal? A Look Back at CVE-2024-53150](https://newskysecurity.com/cve-2024-53150/): Last year, a critical vulnerability in the InduCore SCADA platform, nicknamed “Ghost Signal,” was disclosed. Tracked as CVE-2024-53150, this flaw allows unauthenticated attackers to steal sensitive files and scan internal networks. A full year after its discovery, data shows that numerous industrial systems remain unpatched. This post revisits this critical vulnerability. TL;DR: What is InduCore SCADA? InduCore SCADA is a web-based Human-Machine Interface (HMI) platform used across various industries, including manufacturing, energy, and water treatment. It provides operators with a graphical interface to monitor and control industrial processes and machinery like PLCs and RTUs. The “Ghost Signal” Vulnerability Explained (CVE-2024-53150) […] - [Race Condition in ZenithPay Gateway Allows Double-Spending (CVE-2025-31334)](https://newskysecurity.com/cve-2025-31334/): A high-severity race condition vulnerability has been found in the ZenithPay payment processing gateway. This flaw, nicknamed “Phantom Transaction” and tracked as CVE-2025-31334, allows an attacker to defraud merchants by making purchases without spending any money. It has a CVSS score of 8.1 (High) and requires immediate attention from all service integrators. TL;DR: What is ZenithPay? ZenithPay is a popular open-source payment gateway used by e-commerce platforms and online merchants to process customer payments. It integrates with various payment methods to provide a unified transaction processing system. The “Phantom Transaction” Vulnerability Explained This vulnerability is a classic race condition. Think […] - [Critical Buffer Overflow in Converse Platform (CVE-2025-24237)](https://newskysecurity.com/cve-2025-24237/): A critical heap-based buffer overflow vulnerability has been discovered in the popular Converse video conferencing platform. This flaw, tracked as CVE-2025-24237 and nicknamed “Stunner,” can be triggered by a single, unauthenticated UDP packet, causing an immediate Denial of Service (DoS). It carries a CVSS score of 9.0 (Critical) due to the potential for Remote Code Execution (RCE). TL;DR: What is Converse? Converse is a widely-used, self-hosted collaboration platform that provides video conferencing, real-time chat, and file sharing for businesses and organizations. It relies on WebRTC for its real-time communication capabilities. The “Stunner” Vulnerability Explained This vulnerability is found in the […] - [Critical SSRF Vulnerability in Axiom Mail Server (CVE-2025-22230)](https://newskysecurity.com/cve-2025-22230/): A critical unauthenticated Server-Side Request Forgery (SSRF) vulnerability has been found in the Axiom Mail Server. The flaw, nicknamed “Mailman’s Detour” and tracked as CVE-2025-22230, allows a remote attacker to force the server to make requests to internal network resources, including cloud metadata services. This vulnerability has a CVSS score of 9.1 (Critical) and could lead to a full cloud infrastructure compromise. TL;DR: What is Axiom Mail Server? Axiom Mail Server is a popular, self-hosted email solution for businesses, prized for its robust feature set and administrative control. It includes features for mail migration, archiving, and webmail access. The “Mailman’s […] - [Critical SQL Injection in TitanTransfer MFT (CVE-2025-29803)](https://newskysecurity.com/cve-2025-29803/): A high-severity second-order SQL injection vulnerability has been discovered in the TitanTransfer Managed File Transfer (MFT) solution. This flaw, tracked as CVE-2025-29803 and nicknamed “Data Taint,” allows a low-privileged user to gain full control over the application’s database, leading to a complete system compromise. It has a CVSS score of 8.8 (High). TL;DR: What is TitanTransfer? TitanTransfer is an enterprise-grade Managed File Transfer (MFT) solution used by corporations to securely automate, manage, and monitor sensitive data transfers between systems and people. It often serves as a central hub for critical business files. The “Data Taint” Vulnerability Explained Unlike a standard […] - [Critical Tenant Isolation Bypass in Gatewayd Ingress Controller (CVE-2025-21587)](https://newskysecurity.com/cve-2025-21587/): A high-severity security bypass and tenant isolation vulnerability has been discovered in the Gatewayd Ingress Controller for Kubernetes. This flaw, tracked as CVE-2025-21587 and nicknamed “Annotation Bleed,” allows an attacker in a multi-tenant cluster to modify traffic routing for other tenants, potentially exposing internal services and bypassing authentication. It has a CVSS score of 8.7 (High). TL;DR: What is Gatewayd? Gatewayd is a popular, feature-rich Ingress controller for Kubernetes. It manages external access to services within a cluster, handling HTTP/HTTPS routing, load balancing, and TLS termination. It is often used in multi-tenant environments where different teams or customers share the […] - [Critical Command Injection in Connectify Hub OS (CVE-2025-1094)](https://newskysecurity.com/cve-2025-1094/): A critical authenticated command injection vulnerability has been discovered in Connectify Hub OS, the firmware powering thousands of smart home hubs. The flaw, tracked as CVE-2025-1094, allows an attacker with basic user credentials to gain complete control of the device, earning it a CVSS score of 9.1 (Critical). TL;DR: What is Connectify Hub OS? Connectify Hub OS is a popular open-source firmware for smart home hubs that centralizes control over various IoT devices like smart lights, thermostats, and security cameras. It’s known for its user-friendly web interface that allows for easy configuration and management. The “Commandeer” Vulnerability Explained This vulnerability […] - [Critical Auth Bypass in MomentumDB (CVE-2025-31207)](https://newskysecurity.com/cve-2025-31207/): A critical authentication bypass vulnerability has been discovered in the MomentumDB in-memory database platform. Tracked as CVE-2025-31207, this flaw allows a remote, unauthenticated attacker to gain full administrative access to the database. This vulnerability has a CVSS score of 9.8 (Critical) and requires immediate action. TL;DR: What is MomentumDB? MomentumDB is a high-performance, in-memory NoSQL database designed for real-time applications, caching, and session management. It’s known for its speed and is often used to store critical application data. The Vulnerability: Type Juggling Leads to Auth Bypass The vulnerability lies in how the MomentumDB management API validates authentication tokens. The code […] - [PoC Included: CVE-2025-27007 Path Traversal in LogStreamer](https://newskysecurity.com/cve-2025-27007-poc/): A high-severity unauthenticated path traversal vulnerability has been found in the LogStreamer log management platform. This vulnerability, identified as CVE-2025-27007 and nicknamed “LogLeap,” allows a remote attacker to read arbitrary files from the server’s filesystem. It has a CVSS score of 7.5 (High). This post provides a technical breakdown and a simple proof of concept (PoC) to test your systems. TL;DR: What is LogStreamer? LogStreamer is a popular open-source tool used in DevOps environments to aggregate, search, and monitor log data from multiple sources in real-time. It provides a web interface for developers and system administrators to view and download […] - [Critical Privilege Escalation Flaw in QuantumCMS (CVE-2025-32706)](https://newskysecurity.com/cve-2025-32706/): A high-severity unauthenticated privilege escalation vulnerability has been discovered in QuantumCMS, a popular open-source content management system. This vulnerability, tracked as CVE-2025-32706 and nicknamed “Shadow Admin,” carries a CVSS score of 8.8 (High). It allows an attacker to trick a logged-in administrator into installing a malicious plugin, leading to a full site takeover. TL;DR: What is QuantumCMS? QuantumCMS is a flexible and powerful content management system known for its extensive plugin architecture. It’s used to power everything from small personal blogs to large-scale corporate websites and e-commerce platforms. The “Shadow Admin” Vulnerability Explained This vulnerability is a classic Cross-Site Request […] - [Critical Vulnerability Alert: CVE-2025-30208 in AetherProxy](https://newskysecurity.com/cve-2025-30208/): A high-severity HTTP/2 Request Smuggling vulnerability, nicknamed “Phantom Tunnel,” has been discovered in the AetherProxy gateway. Tracked as CVE-2025-30208, this flaw has a CVSS score of 8.6 (High) and could allow attackers to bypass security controls, hijack user sessions, and access sensitive data. If you’re using AetherProxy, you need to act now. TL;DR: What is AetherProxy? AetherProxy is a popular, high-performance API gateway and reverse proxy used extensively in modern cloud-native and microservices architectures. It sits between clients and backend services, handling traffic routing, load balancing, authentication, and security. The “Phantom Tunnel” Vulnerability Explained HTTP Request Smuggling is an attack […] - [Critical RCE in DataWeave: Unpacking CVE-2025-46785 "Weaver's Loom"](https://newskysecurity.com/cve-2025-46785/): Heads up, developers and security pros! 📢 A critical unauthenticated remote code execution (RCE) vulnerability has been discovered in the popular DataWeave YAML parsing library. Tracked as CVE-2025-46785 and nicknamed “Weaver’s Loom,” this flaw carries a CVSS score of 9.8 (Critical) and requires your immediate attention. This post breaks down the vulnerability, its impact, and how to protect your applications. TL;DR: The Vulnerability: Insecure Deserialization DataWeave is a widely-used Java library for handling data serialization and deserialization, especially for YAML files used in configurations and data exchange. The root cause of CVE-2025-46785 lies in the parse() method of the YAMLParser […] - [Write for Us: Contribute Your SaaS Insights](https://newskysecurity.com/saas-write-for-us/): Are you a tech-savvy marketer looking for guest blogging opportunities? We invite you to write for us and share your knowledge on B2B SaaS topics. Our platform welcomes high-quality articles that provide real value to our readers. If you have insightful perspectives on digital marketing, lead generation, or SaaS strategies, we want to hear from you! Submission Guidelines To ensure your guest post submission meets our standards, please follow these content guidelines: Why Contribute? By contributing to our blog, you can: How to Submit If you’re ready to share your insights, send us your article idea or draft. Please ensure […] - [Write For Us: AI, Technology, Data Science - Become a Contributor](https://newskysecurity.com/write-for-us-ai-technology-data-science-become-a-contributor/): Write for Us: Artificial Intelligence We welcome contributions from writers and experts in the field of artificial intelligence. If you have insights, research, or experiences to share, we want to hear from you! Guidelines for Submission How to Submit Please email your article to submissions@example.com with the subject line “Write for Us: AI Submission”. Benefits of Contributing Conclusion Join us in exploring the fascinating world of artificial intelligence. We look forward to your submissions! Contribute to Our AI Community: Write for Us! Are you passionate about artificial intelligence? Do you have insights, experiences, or knowledge that you want to share […] - [Write For Us: Technology - We Want To Post Your Awesome Articles](https://newskysecurity.com/write-for-us-technology-we-want-to-post-your-awesome-articles/): Are you passionate about technology and looking for a platform to share your insights? We invite you to write for us and contribute to our tech community. We welcome writers who can provide fresh perspectives on the latest trends, innovations, and developments in the tech industry. Why Write for Us? Contributing to our blog offers you a chance to: Guest Post Guidelines To maintain high-quality content, we have specific guidelines for submissions: How to Submit Your Article If you’re ready to share your knowledge, please follow these steps: Topics We’re Interested In Here are some topics we’re particularly interested in: - [Cyber Security Private Investigations](https://newskysecurity.com/cyber-security-private-investigations/): When your in trouble and you want to keep it extremely private. We are the best ones to call! What We Offer In today’s digital age, safeguarding your business from cyber threats is paramount. Our cyber security private investigation services provide comprehensive private services designed to identify, analyze, and mitigate risks associated with cyber attacks. Why Choose Us? Our team of experienced investigators and cyber security experts is dedicated to protecting your assets. We utilize cutting-edge technology and methodologies to ensure thorough investigations and actionable insights. How It Works - [Write for Us: Share Your Expertise in IoT](https://newskysecurity.com/write-for-us-iot-share-your-expertise-in-iot/): Are you passionate about the Internet of Things (IoT) and looking to contribute to the growing community of tech enthusiasts? We invite you to write for us and share your insights on IoT trends, applications, and innovations. Our platform is dedicated to providing high-quality content that engages and educates our audience. Why Contribute to Our IoT Publication? By writing for us, you can: What We’re Looking For We accept guest posts that cover a range of topics related to IoT, including: Your article should be informative, relevant, and easy-to-understand, catering to both industry professionals and enthusiasts. We value original content […] - [Private Investigations Write for Us: We Want Your Submissions](https://newskysecurity.com/private-investigations-write-for-us/): Welcome to our blog dedicated to Private Investigations enthusiasts and experts. We are looking for high-quality guest posts that provide valuable insights into the world of private investigations. If you have a passion for writing and want to share your knowledge, this is the perfect opportunity for you. Why Write for Us? By contributing to our blog, you can reach a broad audience interested in investigation topics. Our readers are eager to learn about the latest trends, challenges, and solutions in the private investigations field. This is not just a chance to showcase your expertise, but also to connect with […] - [Cyber Security Write for Us: A Guide for Contributors](https://newskysecurity.com/cyber-security-write-for-us/): Welcome to our platform dedicated to cybersecurity enthusiasts and experts. We are looking for high-quality guest posts that provide valuable insights into the world of cyber security. If you have a passion for writing and want to share your knowledge, this is the perfect opportunity for you. Why Write for Us? By contributing to our blog, you can reach a broad audience interested in cyber topics. Our readers are eager to learn about the latest trends, challenges, and solutions in the cybersecurity field. This is not just a chance to showcase your expertise, but also to connect with a community […] - [A Startup Founder’s Guide to Cybersecurity for Remote Teams](https://newskysecurity.com/a-startup-founders-guide-to-cybersecurity-for-remote-teams/): Today, many startups around the country embrace remote work. It’s no longer seen as an alternative to in-person work. Many startups also hire employees globally, which means going remote is the only way to work together. Data from Statista shows that between 2020 and 2023, the share of people working remotely worldwide increased from 20% to 28%. It’s safe to say that remote work is the most popular work structure, with 91% of employees in favor of it. However, the biggest risk factor to this medium is going to be cybersecurity.  You might brush it off as not being a […] - [Designing a Frictionless Age Verification Process for Mobile Apps](https://newskysecurity.com/designing-a-frictionless-age-verification-process-for-mobile-apps/): Mobile apps need to verify user ages to protect unauthorized access to sensitive information while ensuring a seamless experience. Crafting this process is critical for app creators, especially in the financial sector, where compliance is crucial. Fintech apps, for instance, must verify user ages to secure sensitive financial data, like banking or investment details. A poorly designed process can frustrate users or fail to block unauthorized access, risking data breaches. Regulations like COPPA in the U.S., enforced by the FTC, impose fines up to $53,088 per violation if fintech apps collect data from unauthorized users without proper consent. Countries like […] ## Pages - [Terms](https://newskysecurity.com/terms/): Terms and Conditions of Use Last modified:01/31/2018 1. Terms By accessing this web site, you are agreeing to be bound by these web site Terms and Conditions of Use, all applicable laws and regulations, and agree that you are responsible for compliance with any applicable local laws. If you do not agree with any of these terms, you are prohibited from using or accessing this site. The materials contained in this web site are protected by applicable copyright and trade mark law. 2. Use License Permission is granted to temporarily download one copy of the materials (information or software) on […] - [Careers](https://newskysecurity.com/careers/): Current Openings Software Development Engineer Location: Redmond, WA Have you ever wondered why there are so many hacking events happening? Do you want to work with a group of engineers and researchers on defending our connected homes, cars and hospitals? NewSky Security, a venture-backed startup company focusing on IoT security is looking for a Dev lead to join us and grow with the team. The desired candidate will have the following skills: Java backend, RESTful API, experience with relational database and jQuery. Android experience is a plus. Familiar with open source frameworks, maven, jenkins, tomcat will be a plus. Work […] - [Team](https://newskysecurity.com/team/): Let’s create a safer IoT world NewSky Security leadership team includes white hat hackers and security experts with experience from Symantec, McAfee, Microsoft F5, Cisco, eBay, Expedia, and Intel. Leadership Scott Wu – CEO & Founder Scott held R&D management roles for Symantec, Microsoft and McAfee, shipped flagship products of Norton, Windows Defender and McAfee Total Protection, each with over 500 million users. Scott owns multiple cybersecurity patents. Manuel Rivelo – Advisor Manny has over 30 years of tech expertise, and is the CEO of AppViewX, Inc. Prior to this, he has held key leadership roles as CEO at F5 […] - [Get a Quote](https://newskysecurity.com/get-a-quote/): Demo is on the way! Please let us know more about you by filling out the following. We will contact you shortly. - [Industries](https://newskysecurity.com/industries/): Protect your business from cyberattacks Stop worrying about business disruption caused by IoT threats. Smart Retail Healthcare Connected Vehicle Smart Building Secure your IoT devices today? - [Product](https://newskysecurity.com/product/): NewSky Security The First IoT Cyberattack Visibility & Control System Threat Detection Real-time network monitoring enables instant anomaly detection Proactive Protection Protect business continuity from cyberattacks Intelligence & Control Comprehensive Threat Intelligence & Control of: Simple Setup Single-step deployment Secure your IoT devices today? - [Cyber Security Private Investigators](https://newskysecurity.com/): In the News Our Approach We study attackers, so we know how to stop them. Meet NewSky Security The FIRST real-time threat visibility and control solution. Real-time Monitoring Monitor devices’ network behavior continuously. Threat Visibility & Control Detect anomalies with threat intelligence. Proactive Protection Mitigate risks and potential costs from a cyberattack. Artificial Intelligence Enable the most cutting edge security engine. Ubiquitous Threats A plethora of internet of things are hackable, remotely. Lethal Risks Devices are now connected online, including pacemakers. Evolving Attackers The battle between attackers and defenders never ends. Limited Visibility Lack of threat visibility puts you at a disadvantage. Today’s […] - [Privacy Policy](https://newskysecurity.com/privacy-policy/): Privacy Policy Last modified:01/31/2018 NewSky Security Solution, Inc. (“NewSky Security”) knows that you care about how your information is used and shared. This notice describes NewSky Security’s privacy policy for our website (the “Site”), including all online services and functions.   Registration You may need to register in order to use certain of the Site’s online services and functions, such as our cloud platform for Mobile and Internet of Things (IoT) vulnerability detection service. During registration, you will be required to provide contact information (an email address), username and password. You can select any username you want, except that your […] - [Blog](https://newskysecurity.com/blog/) - [Contact](https://newskysecurity.com/contact/): Contact NewSky Security Drop a Message Secure your IoT devices today? [comment]: # (Generated by Hostinger Tools Plugin)