Epic Games has patched a critical man-in-the-disk (MiTD) flaw for the Android version of the wildly popular game called Fortnite – although controversy has swirled after Google decided to ignore a 90-day disclosure request from the gaming company.
The issue exists in the Fortnite Installer, which downloads the Fortnite APK to external storage on an Android device. According to the Google team that reported the flaw, any app with the WRITE_EXTERNAL_STORAGE permission can substitute a malicious APK immediately after the download is completed and the fingerprint is verified.
Here are a few tips that are easy to follow:
- Install applications only from official stores such as Google Play. Malware does creep in, but it is far rarer — and removed on a regular basis.
- Disable the installation of applications from third-party sources in your smartphone or tablet settings; those are the most dangerous sources. To do that, select Settings -> Security and uncheck Unknown sources.
- Choose applications by verified developers. Check the application rating and read the reviews. Avoid installing anything that looks fishy.
- Do not install anything you do not need. The fewer apps you have on your smartphone, the better.
- Remember to remove applications you no longer need.
- Use a reliable mobile antivirus application that will give you a timely notification if a malicious app is trying to penetrate your device.
Visit cyber.qa.com for more information on how they can help solve the Cyber Security skills gap.
More articles by James
Cyber Pulse: Edition 105
Read the latest edition of Cyber Pulse, our round-up of cyber news.
16 March 2020Cyber Pulse: Edition 104
Read the latest edition of Cyber Pulse, our round-up of cyber news.
09 March 2020Cyber Pulse: Edition 103
Read the latest edition of Cyber Pulse, our roundup of cyber news.
02 March 2020Cyber Pulse: Edition 102
Read the latest edition of Cyber Pulse, our roundup of cyber news.
24 February 2020Cyber Pulse: Edition 101
Read the latest edition of Cyber Pulse, our roundup of cyber news.
17 February 20204 things you need to know about cyber security in 2020
Cybersecurity researcher James Aguilan predicts four areas that will shape the future of cybersecurity in the decade ahead.
22 January 2020How does Ransomware-as-a-Service work?
Cyber security Researcher, James Aguilan looks at how ransomware-as-a-service works, and how organisations can protect themse…
07 August 2019Phishing Campaigns: Defending organisations against phishing
QA Cyber Security Trainer, James Aguilan, argues that understanding how to defend against phishing is of paramount importance…
15 February 2018Is Mr Robot a good representation of real-life hacking and hacking culture?
QA Cybersecurity trainer James Aguilan looks at several scenarios featured in the hit US TV series Mr Robot – and how they ma…
19 February 2018Safeguarding your Digital Footprint
QA Cyber Security Trainer, James Aguilan, shares 6 tips that can help you safeguard your digital footprint.
05 March 2018