25 Smartphone Models Found Shipping With Severe Firmware Flaws: Defcon 2018
This year’s Defcon witnessed many interesting events, including the hacking of voting machines by 11-year-olds and macOS’s vulnerabilities to grant permissions to Malware with the help of invisible clicks.
In another interesting event at Defcon 2018, security researchers from US Mobile and IoT security firm Kryptowire have unearthed the fact that the default apps of 25 Android smartphone models are affected by about 47 vulnerabilities. 11 of the affected smartphones are sold in the US.
These vulnerabilities have been found in some of the big OEM brands. Not only some default apps have issues, but vulnerabilities have also been found in the firmware of core device drivers. In the case of firmware, drivers cannot be removed without affecting the phone’s core functionalities.
Some vulnerabilities involve crashing of devices while other could allow an attacker to send and receive text messages from user’s phone, obtain the affected users’ contact list, record phone screen, grant permissions to install third-party apps without letting users know and even wipe out the device’s entire data.
List of Affected OEM’s
Smartphones from small as well as big OEMs are under the radar. OEMs such as ZTE, Leagoo, and Doogee have been included in the list of insecure Android device manufacturers previously as well. Leagoo and Doogee have been reported to come preinstalled with apps that have banking trojans.
Here is a list of all the affected smartphone models.
- ZTE ZMAX Pro
- ZTE ZMAX Champ
- ZTE Blade Spark
- ZTE Blade Vantage
- Vivo V7
- Sony Xperia L1
- SKY Elite 6.0L+
- Plum Compass
- Orbic Wonder
- Oppo F5
- Nokia 6 TA-1025
- MXQ TV Box
- LG G6
- Leagoo P1
- Leagoo Z5C
- Doogee X5
- Coolpad Revvl Plus
- Coolpad Canvas
- Coolpad Defiant
- Asus Zenfone 3 Max
- Asus Zenfone V Live
- Alcatel A30
Does your smartphone feature in this list? Tell us in the comments.
- Information Security Risk Consultant, HMG, Public sector
A Public Sector Information Security Risk Consultant is needed for a long term project in the Yorkshire area. This is a Security consultancy role so travel to other client site locations across the country will be expected. The Public Sector Information Security Risk Consultant MUST have current security clearance and ideally have a breath of information and technology security experience. Broad knowledge across IT transformation, Cloud is also key. Public Sector Information Security Risk Consultant should be versed in working within the public sector HMG environments and be experienced in conducting security risk assessments on sizable IT systems. Broad experience across GRC, ISO27001, NIST is key. Career progression, personal development and excellent training provided. All details kept in the strictest of confidence Salary: £55,000 Location: Yorkshire Ref: GM7720 (Cyber Security Jobs, Information Security Jobs, IT Security Jobs, Cyber Security Jobs in Yorkshire)
- Greenfield opportunity SOC / Threat Hunting Services Lead
- £85,000+ Base
Exclusive Greenfield opportunity to DCL Search & Selection. We are looking for an experienced SOC / Threat Hunting Services Lead to build a NEW Security Operation Centre (SOC) / Threat hunting service within an existing security consultancy. This is a brand new service offering for the client. The successful SOC / Threat Hunting Services Lead must, therefore, have previous experience in building a SOC / Threat hunting (IR) service from the beginning. Everything including, but not limited to; selection of the systems, platforms, kitting out the physical office space. Customisation, setting the policies, playbooks, go to market collateral, recruitment (through DCL obviously) establish processes, management of the team, service delivery, refinement, development etc. Essentially the end to end creation of the capability and then the day to day management and expansion of the service. An in-depth technical background is essential, experience across SOC SIEM/ Threat Hunting (IR) tools, processes, techniques, operational etc The goal is to create, spin up and deliver a SOC/threat hunting (IR) offering to clients ASAP in 2020. Investment and board sign off approved. Apply today for more information or contact me directly on Chris.Holt@dclsearch.com or 07884666351. Candidates must be UK based and commutable to Bracknell. Sponsorship can not be provided to Non-EU Candidates. Ref CH7713 £85,000+ Base
- IT Managed Services Account Director
- Up to £80,000 + Double OTE
IT Managed Services Account Director We are currently working with a growing multi managed service provider who specialises in Cloud & Connectivity services who are currently looking for an IT Managed Services Account Director in London. The IT Managed Services Account Director will be responsible for selling (Increase revenue, develop pipeline etc.) into our client’s current enterprise customers selling public cloud solutions. The IT Managed Services Account Director should have Current experience selling public cloud solutions (preferably Microsoft Azure) into enterprise customers. Currently working for an IT managed services business Commutable to London, Home working is available (Non-EU candidates are not able to be sponsored). Consistent tenure in current and previous positions. Ref BD7703 Salary: Up to £80,000 + Double OTE (Cloud Jobs, Cloud Computing Jobs, Cloud Sales Jobs, Azure Jobs)
- Service Delivery Lead (Data Centre)
- Up to £60,000 Base
A State of the Art Data Centre business are looking for a Service Delivery Lead-in Wiltshire. The Service Delivery Lead will be responsible for maintaining and improving current services to our client's customers. The Service Delivery Lead will also be responsible for a service desk team (reviews, hiring, training etc.) Other responsibilities include: Acting as a senior point of escalation for any customer incidents making sure these are raised quickly and efficiently Root cause analysis Maintain and improve ITIL disciplines Experience required ITIL v3 Certified Current experience within a Data Centre / Data Center Environment Current experience within a Senior Service Desk role. Candidates must be UK based. Sponsorship is not available for Non-EU candidates. Ref BD7701 Up to £60,000 Base (Data Centre Jobs, Data Center Jobs, Service Delivery Jobs)