News | Checkmarx Application Security

Checkmarx.com

News

Your one stop for the latest application security articles, stories, and trends. Stay on top of the news and know what’s happening, both at Checkmarx and in the industry at large.

News

Latest Alexa hack shows Echo could be turned into scary spying device
May 7, 2018

According to Forbes, the discovery was made by a company called Checkmarx, whose tools test the security of soon-to-be released software. The hack exploits Alexa’s in-built function to listen out for follow-up... Read More

Hacking the Amazon Alexa virtual assistant to spy on unaware users
May 7, 2018

Checkmarx experts created a proof-of-concept Amazon Echo Skill for Alexa that instructs the device to eavesdrop on users’ conversations and then sends the transcripts to a website controlled by the attackers. Read More

Amazon Echo made to eavesdrop without exploit or manipulation
May 7, 2018

Checkmarx security researchers developed a proof of concept attack that would allow enable an Amazon Echo to continue recording a user long after a request is made. Read More

Researchers Find Alexa Security Flaw to Spy on Users
May 7, 2018

Security researchers at the firm Checkmarx said they found a way to create an Alexa skill that would continue listening to users long after they prompted the software, according to... Read More

Amazon Alexa Tricked By Security Researchers To Keep Listening
May 7, 2018

Researchers from security firm Checkmarx say they have found a way to keep Amazon’s digital assistant Alexa listening in on what is said -- and even transcribe it. The researchers... Read More

Alexa Turned Spy, Able to Snoop on Users
May 7, 2018

Amazon put a quick stop to an issue in Alexa’s skill set after Chexmarx researchers reported that her skill set could be expanded to listen in on users not just some of the time but all of the time. According to a Checkmarx research paper, Alexa skills can be developed in different languages using... Read More

Alexa Skill Developed to Eavesdrop on Conversations, Amazon Fixes Vulnerability
May 7, 2018

The researchers at cyber-security company Checkmarx hid the malicious application in a simple calculator skill that is meant to solve common mathematics problems. While Alexa is designed to process commands after hearing... Read More

Researchers found a way to hack Amazon’s Alexa: report
May 7, 2018

Independent Women’s Forum’s Nan Hayworth and Democratic strategist Wendy Osefo discuss the report that researchers discovered a way to hack Amazon’s Alexa. Read More

This ‘Skill’ Can Trick Amazon Alexa Into Eavesdropping For Hackers
May 7, 2018

Ateam of security researchers at Checkmarx have created a “skill” that can turn Amazon’s virtual assistant Alexa into an eavesdropping device. It abuses the built-in request capabilities of the device to record your conversation... Read More

Amazon’s Alexa Hacked To Surreptitiously Record Everything It Hears
May 7, 2018

Voice-activated assistants like Amazon’s Alexa and the Google Assistant are convenient and powerful tools for getting information and carrying out tasks. They also raise privacy questions because they record their interactions with the... Read More

Researchers say they tricked Alexa into spying on them
May 7, 2018

Researchers at security firm Checkmarx say they built a proof-of-concept skill for Amazon’s Echo devices that in theory could have voice assistant Alexa listen to, transcribe, and report what users said after... Read More

Researchers Find Amazon Alexa Can Be Hacked to Record Users
May 7, 2018

On April 25, security firm Checkmarx publicly disclosed that it has found that a malicious developer can trick Amazon's Alexa voice assistant technology to record everything a user says. At... Read More

Amazon fixed an exploit that allowed Alexa to listen all the time
May 7, 2018

Amazon's Alexa is good at listening, since it has to be ready when you say its wake word, like "Alexa," "Echo" or "Computer." That very same feature, though, has people... Read More

Amazon has fixed a bug that allowed hackers to listen in on Alexa devices
May 7, 2018

Checkmarx was able to create a skill that allowed hackers to listen in on Echo devices and their users’ conversations. Amazon fixed the problem earlier this month, but the incident... Read More

Amazon Alexa is Hacked, Again; The Security of Users’ Personal Info Is Questioned
May 7, 2018

As per Checkmarx Researchers, they were able to manipulate code within a built-in Alexa JavaScript library (ShouldEndSession) to pull off the hack. The JavaScript library is tied to Alexa’s orders to... Read More

Is Alexa spying on YOU? Security researchers reveal how the assistant’s code could be tweaked to create new ‘skill’ that lets it eavesdrop
May 7, 2018

Researchers at cybersecurity firm Checkmarx created what seemed to be a harmless calculator skill, or an application used for the voice-activated assistant, that would secretly record long after a user... Read More

Amazon’s Alexa had a flaw that let eavesdroppers listen in
May 7, 2018

Alexa is a good listener -- so good, in fact, that researchers discovered a way to have it record audio indefinitely. Amazon's smart voice assistant had a coding flaw that... Read More

Amazon’s Alexa had a slight eavesdropping flaw
May 7, 2018

Researchers at the security firm CheckMarx discovered a security flaw in Amazon's Alexa voice enabled digital personal assistant that could have been used to eavesdrop and transcribe any ambient conversation. But, there are caveats: The flaw requires a user to not only install, but also run a malicious app on Alexa,... Read More

Flaw let Amazon Alexa record users without knowing
April 29, 2018

Researchers at cybersecurity firm Checkmarx say they found a flaw that could have let the smart speaker record users without them knowing it. Read More

2018 Security 100: 20 Coolest Web, Email And Application Security Vendors
March 7, 2018

Checkmarx in July unveiled its acquisition of Codebashing, an application security education company built by developers that uses gamification to train other developers. One month later, the company released an interactive application security testing platform that enables dynamic and continuous testing in real time with zero scan time, outstanding accuracy... Read More

Skip to content