RIM patches potential BlackBerry phishing flaw
BlackBerry maker RIM secures a hole that could have led users to fall victim to a phishing attack, through email or SMS.

Research In Motion (RIM) has released a patch for a flaw that could have fooled BlackBerry users into visiting malicious websites.
Criminals could create a website that includes a manipulated certificate, and through a phishing-style attack link to the fake website in an SMS or email message that appears to be from someone a user trusts.
Once a user clicked on the link the advisory said: "The BlackBerry browser will correctly detect the mismatch between the certificate and the domain name, and display a dialog box that prompts the user to close the connection.
"However, the dialogue box does not display null characters, so the user may believe they are connecting to a trusted site and disregard the recommended action to close the connection."
The software update resolves the problem in BlackBerry Device Software 4.5 or later, but RIM asked users without the update to exercise caution when clicking on email or SMS links.
If a user ever visited a site that caused a BlackBerry browser dialogue box to warn the user about continuing the connection, they should close the connection even if the box showed that the domain and certificate names were the same, RIM advised.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Women show more team spirit when it comes to cybersecurity, yet they're still missing out on opportunities
News While they're more likely to believe that responsibility should be shared, women are less likely to get the necessary training
By Emma Woollacott
-
OpenAI's new GPT-4.1 models miss the mark on coding tasks
News OpenAI says its GPT-4.1 model family offers sizable improvements for coding, but tests show competitors still outperform it in key areas.
By Ross Kelly
-
BlackBerry believes tech firms should submit to government requests
News Canadian mobile maker says tech companies should be "good corporate citizens"
By Aaron Lee
-
BlackBerry buys Secusmart to bolster enterprise security offerings
News BlackBerry to integrate firm's voice and data encryption and anti-eavesdropping solutions into its platform
By Clare Hopping
-
BBM Protected messaging feature unveiled by BlackBerry
News Phone maker touts FIPS 140-2 crypto for super secret messages as it renews focus on enterprise
By Rene Millman
-
GFI trumpets discovery of Olympic 2012 smartphone malware
News Web security vendor claims to have discovered several sites listing Boxer-style malware as the official Olympic smartphone app.
By Caroline Donnelly
-
BBX BlackBerry Server brings security ruckus for CIOs
News Working with the new BlackBerry Server, BBX will secure enterprise data and provision enterprise apps without blocking consumer apps.
By Mary Branscombe
-
Week in review: Lenovo trumps Dell; drone attack; security hacks abound
News It's been cock-ups a plenty this week, on the part of both companies and customers, but Lenovo has plenty to be happy about. Or does it?
By Alan Lu
-
RIM planning BlackBerry Android tie up?
News According to sources, Android apps could soon feature on BlackBerry smartphones.
By Tom Brewster
-
Google patches WebKit flaw post Pwn2Own
News Google patches a WebKit vulnerability, exploited by a team of Pwn2Own winners.
By Tom Brewster