New attack Vector endangering mobile, desktop and IoT operating systems: Kaspersky

Image
ANI Mumbai [India]
Last Updated : Sep 14 2017 | 1:48 PM IST

Armis Labs recently revealed a new attack vector endangering major mobile, desktop, and IoT operating systems, including Android, iOS, Windows, and Linux, and the devices using them.

The new vector is dubbed "BlueBorne", as it spread through the air (airborne) and attacks devices via Bluetooth.

It has also disclosed that eight related zero-day vulnerabilities, four of which are classified as critical.

BlueBorne allows attackers to take control of devices, access corporate data and networks, penetrate secure "air-gapped" networks, and spread malware laterally to adjacent devices.

Armis reported these vulnerabilities to the responsible actors, and is working with them as patches are being identified and released.

Vitaly Kamluk, senior anti-virus expert, Kaspersky Lab, said, "Bluetooth attacks such as a recent set of attack vectors dubbed Blueborne depend on the simple availability of the Bluetooth device as well as close physical proximity. Regardless of the security features on your device, the only way to completely prevent attackers from exploiting your device is to power off your device's Bluetooth function when you're not using it - not putting it into an invisible or undetectable mode, but completely turning it off."

Technologies such as Bluetooth were designed with security in mind, however, over-complication of the technology over time leads to inevitable mistakes in the code made by human coders that can be exploited by the attackers, which was demonstrated by the researchers.

The Recent publication of vulnerabilities in Bluetooth stack covers several vulnerabilities for selected platforms, however, the number of undiscovered or unreported vulnerabilities may be much larger, which is why we would like to call the attention of all users of Bluetooth enabled devices.

This shall work as a reminder to limit attack surface on you personally and your organization by reducing the number of services and technologies exposed to strangers from the outer world. This is generally applicable to Bluetooth and other IT services and technologies.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Sep 14 2017 | 1:48 PM IST

Next Story