Over a million developers have joined DZone.

This Week in Security: Google Android, Galaxy S6 Edge, KnowBe4, TalkTalk...

Announcements, patches, updates, and vulnerabilities in the news this week.

· Performance Zone

Download Forrester’s “Vendor Landscape, Application Performance Management” report that examines the evolving role of APM as a key driver of customer satisfaction and business success, brought to you in partnership with BMC.

There has been a considerable amount of noise in the news this week about mobile threats and how we are becoming more and more bombarded with attacks on mobile devices.

Google Android

Google has released a security update to Nexus devices through an over-the-air (OTA) update as part of our Android Security Bulletin Monthly Release process. The release fixes a series of vulnerabilities such as remote execution of code, information disclosure and privilege elevation.

You can read the details here:


Samsung Galaxy S6 Edge

Google have discovered in the OS running on the Samsung Galaxy S6 devices 11 Sever vulnerabilities due to the customisations carried out by the device manufacturer. Project Zero is the google project that is investigating the security of OEM products using the Android OS.

You can read the Project Zero blog post concerning the Galaxy S6 here:



KnowBe4 are releasing a free add-in for Outlook that enables users to quickly and easily report phishing attempts.

You can learn more about the add-in here:



A fourth person has been arrested in relation to the TalkTalk data breach, he is still in custody, the other three individuals have been bailed for the time being.

You can read how the case is transpiring here:


TalkTalk announced on the 6th November that 156,959 customers personal details, 15.656 account numbers and sort codes were accessed and that 28,000 obscured credit and debit cards numbers were also accessed but cannot be used because the information is incomplete and that no customer information was associated with these records.

You can read their press release here:



PageFair Ad-Blocker Breached and used as delivery mechanism for malware:

Read their press-release here:


UK Investigatory Powers Bill

UK Bill being discussed to oblige cloud encryption to contain a backdoor for use by the provider for allowing access to law enforcement.

More detail available from the Telegraph:


iboss and Goldman Sachs

iboss who produce a secure web gateway platform receives 35 Million investment from Goldman Sachs

You can read their press release here:


Russian, Polish and Japanese Banks Under Attack

Tinba Trojan has been seen to be targeting mainly Russian and Japanese banks although Poland is still under attack.

You can read more about the initial discovery here:


The latest news comes from Dell SecureWorks and you can read more here:



Cisco has created a patch for their Web Security Appliances that fixes the command injection vulnerability CVE-2015-6298 detailed here:


You can read about the patch here:


CryptoWall 4.0

A new strain of the CryptoWall ransomware has been release that now encrypts filenames making it very difficult to determine what files have potentially been lost.

You can read more about the new version at the two below links:


See Forrester’s Report, “Vendor Landscape, Application Performance Management” to identify the right vendor to help IT deliver better service at a lower cost, brought to you in partnership with BMC.


The best of DZone straight to your inbox.

Please provide a valid email address.

Thanks for subscribing!

Awesome! Check your inbox to verify your email so you can start receiving the latest in tech news and resources.

{{ parent.title || parent.header.title}}

{{ parent.tldr }}

{{ parent.urlSource.name }}