Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ An Alexa Bug Could Have Exposed Your Voice History To Hackers

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š An Alexa Bug Could Have Exposed Your Voice History To Hackers


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: yro.slashdot.org

An anonymous reader quotes a report from Wired: Findings published on Thursday by the security firm Check Point reveal that Alexa's Web services had bugs that a hacker could have exploited to grab a target's entire voice history, meaning their recorded audio interactions with Alexa. Amazon has patched the flaws, but the vulnerability could have also yielded profile information, including home address, as well as all of the "skills," or apps, the user had added for Alexa. An attacker could have even deleted an existing skill and installed a malicious one to grab more data after the initial attack. [...] For an attacker to exploit the vulnerabilities, they would need first to trick targets into clicking a malicious link, a common attack scenario. Underlying flaws in certain Amazon and Alexa subdomains, though, meant that an attacker could have crafted a genuine and normal-looking Amazon link to lure victims into exposed parts of Amazon's infrastructure. By strategically directing users to track.amazon.com -- a vulnerable page not related to Alexa, but used for tracking Amazon packages -- the attacker could have injected code that allowed them to pivot to Alexa infrastructure, sending a special request along with the target's cookies from the package-tracking page to skillsstore.amazon.com/app/secure/your-skills-page. At this point, the platform would mistake the attacker for the legitimate user, and the hacker could then access the victim's full audio history, list of installed skills, and other account details. The attacker could also uninstall a skill the user had set up and, if the hacker had planted a malicious skill in the Alexa Skills Store, could even install that interloping application on the victim's Alexa account. Both Check Point and Amazon note that all skills in Amazon's store are screened and monitored for potentially harmful behavior, so it's not a foregone conclusion that an attacker could have planted a malicious skill there in the first place. Check Point also suggests that a hacker might be able to access banking data history through the attack, but Amazon disputes this, saying that information is redacted in Alexa's responses. "The security of our devices is a top priority, and we appreciate the work of independent researchers like Check Point who bring potential issues to us," an Amazon spokesperson told WIRED in a statement. "We fixed this issue soon after it was brought to our attention, and we continue to further strengthen our systems. We are not aware of any cases of this vulnerability being used against our customers or of any customer information being exposed."

Read more of this story at Slashdot.

...



๐Ÿ“Œ An Alexa Bug Could Have Exposed Your Voice History To Hackers


๐Ÿ“ˆ 61.76 Punkte

๐Ÿ“Œ In one click: Amazon Alexa could be exploited for theft of voice history, PII, skill tampering


๐Ÿ“ˆ 33.37 Punkte

๐Ÿ“Œ Hackers Can Talk To Voice Assistants Like Siri And Alexa By Speaking With A Voice You Can't Hear


๐Ÿ“ˆ 32.89 Punkte

๐Ÿ“Œ Windows 11โ€™s Voice Access adds custom voice commands, voice shortcuts in insider build


๐Ÿ“ˆ 29.43 Punkte

๐Ÿ“Œ Facebook bug could have exposed your phone number to marketers


๐Ÿ“ˆ 29.32 Punkte

๐Ÿ“Œ Another Facebook Bug Could Have Exposed Your Private Information


๐Ÿ“ˆ 29.32 Punkte

๐Ÿ“Œ Experts On Whatsapp Bug Could Have Let Hackers Read Your Messages By Just Sending A Video


๐Ÿ“ˆ 26.79 Punkte

๐Ÿ“Œ A Google Docs Bug Could Have Allowed Hackers See Your Private Documents


๐Ÿ“ˆ 26.79 Punkte

๐Ÿ“Œ Google Home smart speaker bug could have allowed hackers to spy on your conversations


๐Ÿ“ˆ 26.79 Punkte

๐Ÿ“Œ Retail Giant Selling Wrong Black History Book Exposed by US History Teacher


๐Ÿ“ˆ 26.72 Punkte

๐Ÿ“Œ Journal your ideas and experiences with your voice: Voice Journal


๐Ÿ“ˆ 26.61 Punkte

๐Ÿ“Œ Tumblr patches bug that could have exposed user data


๐Ÿ“ˆ 25.82 Punkte

๐Ÿ“Œ Tumblr Privacy Bug Could Have Exposed Sensitive Account Data


๐Ÿ“ˆ 25.82 Punkte

๐Ÿ“Œ Twitter fixed bug could have exposed Direct Messages to third-party apps


๐Ÿ“ˆ 25.82 Punkte

๐Ÿ“Œ TikTok Bug Could Have Exposed Users' Profile Data and Phone Numbers


๐Ÿ“ˆ 25.82 Punkte

๐Ÿ“Œ Twitter fixed bug could have exposed Direct Messages to third-party apps


๐Ÿ“ˆ 25.82 Punkte

๐Ÿ“Œ Smart home security camera bug exposed. flaw could let hackers view usersโ€™ feeds


๐Ÿ“ˆ 25.23 Punkte

๐Ÿ“Œ Sharing eBook With Your Kindle Could Have Let Hackers Hijack Your Account


๐Ÿ“ˆ 24.89 Punkte

๐Ÿ“Œ Razer Synapse 3 now features Alexa, allowing your voice to control your PC


๐Ÿ“ˆ 24.61 Punkte

๐Ÿ“Œ A Sticker Sent On Telegram Could Have Exposed Your Secret Chats


๐Ÿ“ˆ 23.92 Punkte

๐Ÿ“Œ New Amazon Ring Vulnerability Could Have Exposed All Your Camera Recordings


๐Ÿ“ˆ 23.92 Punkte

๐Ÿ“Œ Your Twitter account password could have be exposed by this zero day vulnerability


๐Ÿ“ˆ 23.92 Punkte

๐Ÿ“Œ Alexa and Google Assistant Have a Problem: People Aren't Sticking With Voice Apps They Try


๐Ÿ“ˆ 23.67 Punkte

๐Ÿ“Œ Alexa and Google Assistant Have a Problem: People Aren't Sticking With Voice Apps They Try


๐Ÿ“ˆ 23.67 Punkte

๐Ÿ“Œ Monero bug could have allowed hackers to steal massive amounts of cryptocurrency


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ WhatsApp fixes video call bug that could have let hackers in, says report


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ New WhatsApp Bug Could Have Let Hackers Spy On Users Just by Sending MP4 Video


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ Facebook Messenger bug could have allowed hackers to spy on users


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ Xbox bug could have allowed hackers to link gamer tags with players' emails


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ A bug in ea gamesโ€™ single sign-on mechanism could have allowed hackers to access game accounts.


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ Google Docs bug could have allowed hackers to hijack screenshots


๐Ÿ“ˆ 23.29 Punkte











matomo