Skip to main content

Security Blog

Filter by:

3 billion phone numbers with identities exposed by "Caller Blocking" apps

An investigation by the FactWire News Agency found that three mobile apps with the “ Caller Blocking ” feature are collecting and integrating users’ phone address books into a publicly available database, which contains around 3 billion phone numbers with identities. The database contains the numbers of...
Release Date: 23 Nov 2016 3427 Views

Favourite Security Reads of the Week (18 Nov 2016)

  Favourite Security Reads of the Week (18 Nov 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the Favourite Security Reads of this Week.   注意網購保安 免血拼變雙失 (Written by HKCERT on Hong Kong Economic Times, 2016-11-11, Chinese) Hackers show preference for botnets over reflection attacks in Q3 2016 (CIO Asia, 2016-11-...
Release Date: 18 Nov 2016 1392 Views

Favourite Security Reads of the Week (11 Nov 2016)

  Favourite Security Reads of the Week (11 Nov 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the Favourite Security Reads of this Week.   滙款先核實 免墮假電郵騙局 (Written by HKCERT on Hong Kong Economic Times, 2016-11-04, Chinese) New Free Mirai Scanner Tools Spot Infected, Vulnerable IoT Devices (Dark Reading, 2016-11-...
Release Date: 11 Nov 2016 1309 Views

Favourite Security Reads of the Week (4 Nov 2016)

  Favourite Security Reads of the Week (4 Nov 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the Favourite Security Reads of this Week.   3-2-1備份原則 保障資料安全 (Written by HKCERT on Hong Kong Economic Times, 2016-10-28, Chinese) Cyber risk and resilience: not understood (Microsoft, 2016-10-25) How Valuable is Your Healthcare...
Release Date: 4 Nov 2016 1121 Views

HKCERT Security Newsletter (November 2016 Issue)

  Cover Story Hong Kong Security Watch Report (Q3 2016) Several online stores in Hong Kong vulnerable to credit card fraud Large websites attacked by massive DDoS from Internet-enabled devices (IoT devices) More than half of Android devices are vulnerable...
Release Date: 1 Nov 2016 1287 Views

Favourite Security Reads of the Week (28 Oct 2016)

  Favourite Security Reads of the Week (28 Oct 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the Favourite Security Reads of this Week.   網絡設備易洩私隱 成黑客工具 (Written by HKCERT on Hong Kong Economic Times, 2016-10-21, Chinese) Who to Blame for the Attack on the Internet (2016-10-23, Fortune) ...
Release Date: 28 Oct 2016 1284 Views

Large websites attacked by massive DDoS from Internet-enabled devices (IoT devices)

At the last weekend (21 Oct) many large websites such as Twitter, PayPal, Amazon etc. could not be accessed due to their DNS provider Dyn being attacked. From the study of security firm Flashpoint, a vast amount of vulnerable Internet-enabled, ...
Release Date: 24 Oct 2016 2374 Views

Favourite Security Reads of the Week (20 Oct 2016)

  Favourite Security Reads of the Week (20 Oct 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the Favourite Security Reads of this Week.   多重措施保「密」 防暴力解「碼」 (Written by HKCERT on Hong Kong Economic Times, 2016-10-14, Chinese) Heightened DDoS Threat Posed by Mirai and Other Botnets (US-CERT, 2016-10...
Release Date: 20 Oct 2016 1236 Views

Several online stores in Hong Kong vulnerable to credit card fraud

HKCERT is aware that a security researcher has recently disclosed a study: 5900 online stores found skimming (read it here). The study described technique used by cybercriminals to intercept payment data on vulnerable websites. In the study, a list of about 5,900 online...
Release Date: 18 Oct 2016 1826 Views

The banking trojan – Acecard

Acecard Malware is continuously evolving. The first version of Acecard, an Android banking trojan, was detected in Feb 2014. Afterwards, its family registered more than 10 new versions of the malware, each with a far longer list of malicious functions than the previous...
Release Date: 18 Oct 2016 2301 Views