Flaw in Grandstream VoIP phones allows stealthy eavesdropping
A critical vulnerability in Grandstream GXP1600 series VoIP phones allows a remote, unauthenticated attacker to gain root privileges and silently eavesdrop on communications. [...]
Discover the latest updates and defenses against eavesdropping in cybersecurity. Stay informed on prevention methods to secure private conversations.
Search across headline titles and summaries.
Background for this topic.
Eavesdropping is the unauthorized interception of private conversations or data transmissions. In the context of information security, it involves the capture of network traffic to gain access to sensitive information that is being communicated between users or systems.
Eavesdropping can occur in both digital and analog formats. On a digital level, it can be accomplished through various technical methods such as packet sniffing, where attackers monitor network packets, or by exploiting unsecured wireless communications that aren't protected by encryption. Analog eavesdropping might involve overhearing conversations or using devices like bugs to listen in on a particular area.
This security threat affects the confidentiality aspect of the CIA triad (Confidentiality, Integrity, and Availability), which is foundational to information security principles. Protecting against eavesdropping involves the use of strong encryption, secure communication protocols, and guarding against physical vulnerabilities.
Weekly headline count for the current query.
A critical vulnerability in Grandstream GXP1600 series VoIP phones allows a remote, unauthenticated attacker to gain root privileges and silently eavesdrop on communications. [...]
Verdict Says Meta Tracked Consumers' Sensitive Data in Flo Health AppA federal jury found that Meta violated California privacy laws by eavesdropping and recording confidential communications without the consent of millions of consumers who used Flo Health's fertility app embedded with Meta' software development tools and tracking pixels.
Russian Intelligence Tied to SSL Stripping Attacks Designed for EavesdroppingRussian intelligence since 2024 has been using their country's internet service providers to run adversary-in-the-middle attacks designed to infect diplomats inside the country's borders with intelligence-gathering malware, Microsoft warns.
Vulnerabilities affecting a Bluetooth chipset present in more than two dozen audio devices from ten vendors can be exploited for eavesdropping or stealing sensitive information. [...]
Not exactly Snowden levels of skill A student at Britain's top eavesdropping government agency has pleaded guilty to taking sensitive information home on the first day of his trial.…
CyberEspionage 'Salt Typhoon' Operation Infiltrated Telcos' InfrastructureThe impact of a major U.S. national security breach attributed to China reportedly continues to expand, as investigators probe the infiltration of telecommunications infrastructure and eavesdropping on national security and policymaking officials' mobile phone communications.
On the heels of a Chinese APT eavesdropping on phone calls made by Trump and Harris campaign staffers, Beijing says foreign nations have mounted an extensive seafaring espionage effort.
The vulnerability affects not only AirPods, but also AirPods Max, Powerbeats Pro, Beats Fit Pro, and all models of AirPods Pro.
Apple has released a firmware update for AirPods that could allow a malicious actor to gain access to the headphones in an unauthorized manner
In the latest breaches, threat groups compromised telecommunications firms in at least two Asian nations, installing backdoors and possibly eavesdropping or pre-positioning for a future attack.
Researchers have discovered a new security vulnerability stemming from a design flaw in the IEEE 802.11 Wi-Fi standard that tricks victims into connecting to a less secure wireless network and eavesdrop on their network traffic
Eight out of nine apps that people use to input Chinese characters into mobile devices have weakness that allow a passive eavesdropper to collect keystroke data.
After the encryption algorithm used by public safety, military, and governments globally was found to allow eavesdropping, standard maintainers are making TETRA open source.
Multiple security vulnerabilities have been disclosed in AudioCodes desk phones and Zoom's Zero Touch Provisioning (ZTP) that could be potentially exploited by a malicious attacker to conduct remote attacks
How to deal with the evolving threat to our sensitive communications Webinar There is a folk tale of a woman, who on being told a secret burned to tell someone what she had heard. Believing that it was safe to do so, she whispered the secret into a hole in the ground only to hear it broadcast far and wide.…
The North Korean APT37 hacking group uses a new 'FadeStealer' information-stealing malware containing a 'wiretapping' feature, allowing the threat actor to snoop and record from victims' microphones. [...]
A video-enabled smart intercom made by Chinese company Akuvox has major security vulnerabilities that allow audio and video spying, and the company has so far been unresponsive to the discoveries.
A team of researchers has developed an eavesdropping attack for Android devices that can, to various degrees, recognize the caller's gender and identity, and even discern private speech. [...]
Cyber-researchers are testing the bounds of optical attacks with a technique that allows attackers to recover voice audio from meetings if there are shiny, lightweight objects nearby.
Columbia University researchers have developed a novel algorithm that can block rogue audio eavesdropping via microphones in smartphones, voice assistants, and IoTs in general. [...]