HomeSecurityWhatsApp users not updating the app after last week's breach...

WhatsApp users not updating app after last week's breach

A number of WhatsApp users have not updated their apps following last week's announcement that hackers could remotely install spyware on phones to gain full remote access to infected devices.

WhatsApp

Wandera, a company that specializes in smartphone security, reported that 80% of iOS devices were not updated and 55% of Android devices remained vulnerable. Wandera has over a million devices under its management, and 30% have WhatsApp installed, which means they can see if around 300,000 devices have updated their app to patch the security flaw.

Oded Vanunu, head of product vulnerability research at Check Point, says hacking is actively used to inject spyware into victims' phones.

“The vulnerability, identified as CVE-2019-3568, can be exploited to install spyware and steal data from a targeted Android or iPhoneby placing specially crafted VOIP calls to victims.”

He says no user interaction is required for the attack to succeed. “The spyware works covertly, deleting incoming call information from call logs so that the victim is unaware of the intrusion.”.

Act before it's too late

Vanunu says it's hard to predict what the outcome of this hacking will be, but he says if this spyware is detected after it has infected the device, it's already too late.

“It is critical to ensure that the attack is blocked before it actually infects the mobile device, and unfortunately, many businesses do not have adequate mobile security in place.”.

Mobile devices are the backdoor to network breaches, exposing sensitive corporate data to risk, says Vanunu. “Therefore, enterprises should consider using an advanced threat prevention product for all mobile devices, protecting them from zero-day malware, phishing across all apps, preventing devices from sending data to botnets, and preventing infected devices from accessing corporate applications.”

Paul Ducklin, senior technologist at Sophos, agrees, adding that it's important to get the latest WhatsApp software update. "The bug has created a huge issue around the world, as cybercriminals around the world are looking for any opportunity to cash in." He says it appears that there are very few people who have fallen victim to scammers who have used the existing exploit code.

But this is about more than just WhatsApp, Ducklin says. “This is just one version of the kind of security flaw that is often patched by other app vendors, even operating system makers like Microsoft, Google, and Apple.

“So, don’t do this simple thing just because you were scared by what happened on WhatsApp,” he says. “It’s important to keep your phone and your apps up to date. When a fix is ​​released, if you don’t apply it, you’ll be one of the people that scammers will be looking to find.”

Sophos offers some suggestions for businesses:

  • Don't install or keep apps that you won't use. Less is more.
  • Get patches and security updates as soon as possible. Don't just update when an issue like WhatsApp arises.
  • Use an antivirus on your phone to watch out for fake apps and links that send you directly to scam websites.
  • Use a mobile control product to monitor which apps users have and whether they are up to date.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS