Facebook Twitter Instagram Pinterest YouTube Tumblr LinkedIn RSS
    • About
    • Advertise
    • Contribute
    • Donate
    • Forum
    • Contact
    Login
    InfoStride NewsInfoStride News
    • Home
    • Business
    • Celebrity
    • Crime
    • Nigeria
    • Politics
    • Sports
    • Technology
    • More
      • COVID-19
      • Editor’s Picks
      • Health
      • Opinions
      • Press Releases
      • World
    Subscribe
    InfoStride NewsInfoStride News
    Home»Technology»Computer & Software»Zero-day bug attack: Google, Microsoft, Apple scramble updates to protect you from DevilsTongue spyware

    Zero-day bug attack: Google, Microsoft, Apple scramble updates to protect you from DevilsTongue spyware

    Computer & Software By Abiodun A.Jul 20, 2021No Comments3 Mins Read
    Facebook Twitter WhatsApp Pinterest LinkedIn Tumblr Email Reddit VKontakte

    Google and Microsoft have released a patch to two critical vulnerabilities in their operating systems; that were exploited by a spyware that has reportedly been sold to governments by Israeli developer Candiru.

    Microsoft
    Microsoft

    In its report that was released earlier this week, Citizen Labs has said that Candiru’s spyware (called DevilsTongue by Microsoft) can infect and monitor iPhones; Android smartphones, Macs, PCs and even cloud accounts.

    Microsoft is calling Candiru Sourgum.

    Microsoft in a blog post said that the spyware was being used in precision attacks targeting more than 100 victims including politicians; human rights activists, journalists, academics, embassy workers and political dissidents in countries around the world including around the world including Palestine, Israel, Iran, Lebanon, Yemen, Spain, United Kingdom, Turkey, Armenia, and Singapore.

    What is DevilsTongue and what does it do?
    DevilsTongue is a spyware tool developed by a Tel Aviv, Israel-based company called Candiru.

    As Citizen Labs explains it, Candiru is a mercenary spyware firm that markets ‘untraceable’ spyware to government customers.

    Their product offering includes solutions for spying on computers, mobile devices, and cloud accounts.

    “The €16 million project proposal allows for an unlimited number of spyware infection attempts; but the monitoring of only 10 devices simultaneously.

    See also  #Wealth: Facebook’s Mark Zuckerberg Is Now 16th World Richest

    For an additional €1.5M, the customer can purchase the ability to monitor 15 additional devices simultaneously, and to infect devices in a single additional country.

    For an additional €5.5M, the customer can monitor 25 additional devices simultaneously, and conduct espionage in five more countries,” Citizen Labs wrote in its report.

    Once the spyware has infected a Windows PC, it exfiltrates files, exporting all messages saved in the Windows version of the popular encrypted messaging app Signal, and stealing cookies and passwords from Chrome, Internet Explorer, Firefox, Safari, and Opera browsers.

    Microsoft’s analysis has also shown that the spyware can also send messages from logged-in email; and social media accounts directly on the victim’s computer.

    This could allow malicious links or other messages to be sent directly from a compromised user’s computer.

    What is Microsoft doing?
    To tackle this spyware, Microsoft has released a security patch for two zero-day bug vulnerabilities; CVE-2021-31979 and CVE-2021-33771.

    These vulnerabilities were patched in a security update released on July 13, 2021.

    “To limit these attacks, we focused on two actions. First, we built protections into our products against the unique malware Sourgum created, and we shared those protections with the security community. Second, we issued a software update; that will protect Windows customers from exploits Sourgum was using to help deliver its malware,” Microsoft said in a post.

    See also  Epicor Announces Corporate Office Relocation

    “We’ve built protections against DevilsTongue into our security products; and we’ve also shared these protections with others in the security community; so they can protect their customers,” the company added.

    What is Google saying?
    Google in a separate report by its Threat Analysis Group or TAG discovered a bunch of zero-day bug vulnerabilities in Chrome and Internet Explorer that were being used by the same company.

    The company found vulnerabilities CVE-2021-21166 and CVE-2021-30551 in Chrome, CVE-2021-33742 in Internet Explorer and CVE-2021-1879 in Safari WebKit.

    Thankfully, all the three companies — Apple, Google as well as Microsoft — have released security updates to patch these bugs.

    What should I do now?
    If you haven’t updated your devices — laptops, PCs, tablets as well as smartphones — now would be a good time to do so. Download the latest version of the security updates available on your devices and you are good to go.

    Support InfoStride News' Credible Journalism: Only credible journalism can guarantee a fair, accountable and transparent society, including democracy and government. It involves a lot of efforts and money. We need your support. Click here to Donate

    Google microsoft zero-day bug attack
    Share. Facebook Twitter WhatsApp Pinterest Reddit Tumblr VKontakte Email LinkedIn

    Related Posts

    Google Has Failed Me On The Definition Of True Democracy – Jim Iyke

    Mar 20, 2023

    BudgIT launches TrackaMobile 2.0 App to aid Participatory Governance at the Subnational Level

    Nov 14, 2022

    Microsoft lauches first $100 million African Development Centre in Lagos

    Mar 22, 2022

    Google parent Alphabet profit soars as ads surge

    Mar 13, 2022
    Add A Comment

    Leave A Reply Cancel Reply

    Get Social with Us
    • Facebook
    • Twitter 6.5K
    • Pinterest 92
    • Instagram
    • YouTube
    Latest Posts

    Kaduna Guber: It wasn’t the people – Shehu Sani reveals who decided election result

    Mar 21, 2023

    Tinubu’s victory: Peter Obi petitions presidential election tribunal

    Mar 21, 2023

    Enugu PDP committed fraud – LP’s Kenneth Okonkwo urges INEC to declare Edeoga winner

    Mar 21, 2023

    PDP’s Bala Mohammed re-elected Bauchi Governor

    Mar 21, 2023

    Subscribe to Updates

    Get the latest breaking news straight into your inbox!

    Random News

    Manchester United Is Confident – Jose Mourinho

    Aug 23, 2017

    MLS Is A Very Tough League – Higuain

    Jun 15, 2021

    Stingray Digital Group Inc. Files Preliminary Prospectus for Initial Public Offering

    Apr 25, 2015

    Osun State Is Broke – Lawmaker

    Aug 9, 2016

    InfoStride News delivers the latest breaking news, Nigeria news, world news and top stories on business, celebrity, entertainment, politics, sports, technology and more. Experience the best of in-depth coverage, special reports, football highlights, political opinions, crime watch, celebrity gossips etc.

    GooglePlay Store Button

    Support InfoStride News' Credible Journalism

    Credible journalism involves a lot of efforts and money; and can guarantee a fair, accountable and transparent society, including democracy and government. We need your support to continue offering free access to our loyal readers and visitors like you.

    Click here to Donate

    Facebook Twitter Instagram Pinterest YouTube Tumblr LinkedIn RSS
    • Our Terms
    © 2023 InfoStride News. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Sign In or Register

    Welcome Back!

    Login to your account below.

    Continue with Facebook
    Continue with Google
    Continue with Twitter
    Lost password?