Skip to main content

Security Blog

Filter by:

Stay Cautious to the Latest WhatsApp Buffer Overflow Vulnerability

HKCERT noted the recent discovery of a buffer overflow vulnerability in messaging app WhatsApp. Hackers may exploit this vulnerability to inject spyware for remote code execution, and to bypass security restriction to eavesdrop on calls; turn on the microphone and camera functions; access the photos, ...
Release Date: 14 May 2019 3791 Views

Updates on Hong Kong Google Play Store's Apps Security Risk Report (7 May 2019)

HKPC’s Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) has obtained preliminary legal advice, and has moved all relevant reports away from the HKCERT website for the moment. Announcements will be made as and when appropriate.
Release Date: 7 May 2019 3323 Views

Beware of Sodinokibi Ransomware

HKCERT observed a new ransomware named "Sodinokibi" being deployed via Zero Day vulnerabilities recently. Web application vulnerabilities is one of the known attack vectors.   What ransomware usually does? Ransomware is used to encrypted victim’s files and causes the data unavailable. And ransom...
Release Date: 30 Apr 2019 4531 Views

Favourite Security Reads of the Fortnight (26 Apr 2019)

  Favourite Security Reads of the Fortnight (26 Apr 2019)   "Favourite Security Reads of the Fortnight". Every two weeks we share news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the favourite security reads of this fortnight. Article written by HKCERT on Hong Kong Economic Times: 防電腦淪「礦場」預防勝治療 (2019-04-12, Chinese) 碌卡消費便利 保護私隱有攻略 (2019-04-19, Chinese) 碌卡消費保...
Release Date: 26 Apr 2019 3347 Views

"SSH Hong Kong Enterprise Cyber Security Readiness Index Survey" Up 3.7 Points to 49.3. Enterprises still needs to improve on Cyber Security Readiness

The Hong Kong Productivity Council (HKPC) released the latest results of the “SSH Hong Kong Enterprise Cyber Security Readiness Index Survey”, which reports an Overall Index at 49.3 (maximum being 100), a slight increase of 3.7 from the inaugural survey...
Release Date: 12 Apr 2019 5050 Views

Security Advisory: Facebook stored plain text user passwords on their internal servers

Recently, Facebook discovered that there were hundreds of millions account passwords stored in plain text on their internal company servers, which means that these passwords were searchable and readable by over 20,000 Facebook employees. The impact of this incident including hundreds of millions of Facebook...
Release Date: 22 Mar 2019 3552 Views

Favourite Security Reads of the Fortnight (15 Mar 2019)

  Favourite Security Reads of the Fortnight (15 Mar 2019)   "Favourite Security Reads of the Fortnight". Every two weeks we share news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the favourite security reads of this fortnight. Article written by HKCERT on Hong Kong Economic Times: 黑客新招 假招聘信息藏病毒 (2019-03-01, Chinese) Articles that we like:  New GarrantyDecrypt ransomware variant impersonates the security team for Proton Technologies (Cyware, 2019-03-04) 色情敲...
Release Date: 15 Mar 2019 4362 Views

Favourite Security Reads of the Fortnight (1 Mar 2019)

  Favourite Security Reads of the Fortnight (1 Mar 2019)   "Favourite Security Reads of the Fortnight". Every two weeks we share news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the favourite security reads of this fortnight. Article written by HKCERT on Hong Kong Economic Times: 網絡安全關鍵 加強保護DNS (2019-02-15, Chinese) 資料外洩覆水難收 雙重認證自保 (2019-02-22, Chinese) Articles that we like:  Almost 18000 Android Apps track users online activity by violating...
Release Date: 1 Mar 2019 3490 Views

Beware of the unauthorized SMS forwarding

Recently, there was a report about SMS authentication code in some stored value facilities (SVF) can be forwarded to other phone number by fraudsters.  SMS was used to deliver One-time password (OTP) by many online services. Because of the security concern...
Release Date: 26 Feb 2019 5844 Views

Favourite Security Reads of the Fortnight (15 Feb 2019)

  Favourite Security Reads of the Fortnight (15 Feb 2019)   "Favourite Security Reads of the Fortnight". Every two weeks we share news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the favourite security reads of this fortnight. Article written by HKCERT on Hong Kong Economic Times: 網絡攝影機 或淪黑客工具 (2019-02-01, Chinese) 選購網絡攝影機 「預防勝於治療」 (2019-02-08, Chinese) Articles that we like:  Attackers...
Release Date: 15 Feb 2019 2956 Views