Google Kicks Harmful Apps Out Of Google Play And Offers 5 Steps Against Social Engineering

Stu Sjouwerman | Dec 3, 2017
android-devil

You're always better off getting apps from reputable stores like Google Play than you are from potentially dodgy, at best unknown, third-party sites. But even Google Play isn't immune from problems.

Mountain View periodically has to kick badly behaved apps out of its store, and last week saw one such expulsion. A number of apps afflicted with the Tizi backdoor were booted out. Tizi was able to root devices via old, known vulnerabilities. Google published a reminder of five steps your users can take to protect themselves against social engineering by potentially harmful apps:

  • "Check permissions," and always be suspicious of apps that make unreasonable demands. There's no reason a flashlight, for example, should need to send SMS messages.
  • "Enable a secure lock screen," with some factor (password, PIN, gesture, whatever your device accommodates) that's easy for you to remember but hard for others to guess.
  • "Update your device." Patch. Note that Tizi took advantage of old bugs for which patches exist. If your system is up-to-date, it's a bit more secure.
  • "Google Play Protect." If you're an Android user, Google Play Protect will help keep you safe.
  • "Locate your device," that is, "practice finding" it. Losing your phone is the security misstep you're most likely to make. More at:

https://www.helpnetsecurity.com/2017/11/28/tizi-backdoor-rooted-android/

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.