BlueBorne Threatens 5 Billion Bluetooth Devices

  /     /     /  
Publicated : 22/11/2024   Category : security


BlueBorne Threatens 5 Billion Bluetooth Devices


More than 5 billion devices are vulnerable to a set of eight Bluetooth flaws, even if they arent in discoverable mode.



Computer and mobile users have long believed that everything is better with Bluetooth. It turns out that criminal hackers may very well agree. A group of eight vulnerabilities -- collectively known as BlueBorne -- makes roughly 5.3 billion devices subject to intrusion.
Armis Labs discovered the vulnerabilities
and followed the rules of responsible disclosure by giving information to hardware and software vendors prior to public disclosure to allow time for patches to be written and distributed before exploits were likely to appear in the wild. Thats the first bit of good news.
The next bit of good news is that some major vendors have taken advantage of the advance notice to patch systems and reduce customer exposure to the flaws. Google and Microsoft have recently issued patches that address the issues and many Linux distros are in the process of releasing patches. Apple managed to fix the vulnerabilities earlier; any users whose devices are on current or near-current versions of operating systems for Apple computers or devices are safe.
Youre invited to attend Light Readings 11th annual
Future of Cable Business Services event
. Join us in New York on November 30 for the premier independent conference focusing on the cable industrys continuing efforts in the commercial services market – all cable operators and other communications service providers get in free.
Now for the bad news. Many of the devices containing vulnerable Bluetooth implementations cannot or will not be patched. The only way for these devices to be safe is for Bluetooth to be disabled.
Thats because of the silent nature of the attacks possible through these vulnerabilities. A targeted Bluetooth-equipped device will not have to be in discoverable mode to be vulnerable. Users and security systems wont be able to use connected device lists for protection because the vulnerable devices doesnt have to be paired with the attackers device to be vulnerable.
Once infected, a single device can be the source of lateral infection for other Bluetooth-equipped systems in the organization. That infection could take place very quickly and just as silently as the original exploit. Thats the exploit: What could an attacker do through these vulnerabilities?
The payload carried by these exploits could include botnet, ransomware, spyware or virtually any other malware attack. All delivered silently and quickly to virtually every mobile and desktop device in the organization.
What is a company to do to protect itself? First, make sure that all mobile and personal computing devices are running current software versions. If devices cant be updated to current operating systems, then turn off Bluetooth on any non-current device. If you have devices that can be neither updated nor turned off, then its time to take a serious look at your refresh cycles: This threat is no joke.
Related posts:
Virtual Terrorism: 21st Century Cyber Warfare
DDoS Trends Show Big Impact From Fewer Servers
How Secure Are Your IoT Devices?
— Curtis Franklin is the editor of
SecurityNow.com
. Follow him on Twitter
@kg4gwa
.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
BlueBorne Threatens 5 Billion Bluetooth Devices