Digital Times Nigeria
  • Home
  • Telecoms
    • Broadband
  • Business
    • Banking
    • Finance
  • Editorial
    • Opinion
    • Big Story
  • TechExtra
    • Fintech
    • Innovation
  • Interview
  • Media
    • Social
    • Broadcasting
Facebook X (Twitter) Instagram
Trending
  • From Mandate To Milestones: Celebrating Hon. Amobi Ogah’s Remarkable Two-Year Journey In The Green Chambers
  • For 16th Year Running, Sophos Named Leader In Gartner’s 2025 Magic Quadrant For EPPs
  • Again, PalmPay Earns Spot On CNBC, Statista’s 2025 Global Top 300 Fintech Companies List
  • Afolayan, Dada, Edgar, Ephraim-Egbas To Speak At QEDNG Creative Powerhouse Summit
  • MTN And MTV Base Partner To Launch “Room Of Safety” Series
  • Hadiza Umar, NITDA’s Communication Boss Among 2025 Nigeria’s Top 50 PR Professionals
  • Smile Communications Kicks Off “#AllTimeSmileTime” Campaign To Celebrate Internet Access Anytime, Anywhere
  • Celebrating Dr. Omoniyi Ibietan’s Multilayered Impact On Strategic Communication In Africa
Facebook X (Twitter) Instagram
Digital Times NigeriaDigital Times Nigeria
  • Home
  • Telecoms
    • Broadband
  • Business
    • Banking
    • Finance
  • Editorial
    • Opinion
    • Big Story
  • TechExtra
    • Fintech
    • Innovation
  • Interview
  • Media
    • Social
    • Broadcasting
Digital Times Nigeria
Home » NCC-CSIRT Alerts Telecom Consumers Of Existence Of Two Cyber Vulnerabilities, Lists Protection Measures
Telecoms

NCC-CSIRT Alerts Telecom Consumers Of Existence Of Two Cyber Vulnerabilities, Lists Protection Measures

DigitalTimesNGBy DigitalTimesNG28 January 2022No Comments5 Mins Read8 Views
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
NCC REAL LOGO
Share
Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp

The Cyber Security Incident Response Team (CSIRT) of the Nigerian Communications Commission said it has independently identified two cyber vulnerabilities and advised Nigerian telecom consumers on the measures to be taken to get protected from the cyber-attacks.

DigitalTimesNG understands that the CSIRT, in its first-ever security advisories less than three months after its creation, has solely identified the two cyber-attacks targeting the consumers and proffer solutions that can help telecom consumers from falling victims to the two cyber vulnerabilities.

The team said in a statement signed by the NCC Director of Public Affairs, Dr. Ikechukwu Adinde that the first of the vulnerabilities is described as Juice Jacking, which can gain access into consumers’ devices when charging mobile phones at public charging stations and it applies to all mobile phones.

The other is a Facebook for Android Friend Acceptance Vulnerability, which targets only Android Operating System.

According to CSIRT security Advisory 0001 released on January 26, 2022, with Juice Jacking, attackers have found a new way to gain unauthorized entry into unsuspecting mobile phone users’ devices when they charge their mobile phones at public charging stations.

“Many public spaces, restaurants, malls and even in the public trains do offer complementary services to their customers in a bid to enhance customer services, one of which is providing charging ports or sockets.

“However, an attacker can leverage this courtesy to load a payload in the charging station or on the cables they would leave plugged in at the stations.

“Once unsuspecting persons plug their phones at the charging station or the cable left by the attacker, the payload is automatically downloaded on the victims’ phone. This payload then gives the attacker remote access to the mobile phone, allowing them to monitor data transmitted as text, or audio using the microphone.

READ ALSO  FG Hails NCC’s Regulatory Strides

“The attacker can even watch the victim in real-time if the victims’ camera is not covered. The attacker is also given full access to the gallery and also to the phone’s Global Positioning System (GPS) location.

“When an attacker gains access to a user’s Mobile phone, he gets remote access to the User’s phone which leads to breach in Confidentiality, Violation of Data Integrity and bypass of Authentication Mechanisms.

“Symptoms of attack may include a sudden spike in battery consumption, device operating slower than usual, apps taking a long time to load, and when they load, they crash frequently and cause abnormal data usage,” CSIRT said in the NCC statement.

But the NCC-CSIRT, however, proffered solutions to this attack to include using ‘charging only USB cable’, to avoid Universal Serial Bus (USB) data connection; using one’s AC charging adaptor in public space; and not granting trust to portable devices prompt for USB data connection.

CSIRT listed other preventive measures against Juice Jacking to include installing Antivirus and updating them to the latest definitions always; keeping mobile devices up to date with the latest patches; using one’s own power bank; keeping the mobile phone off when charging in public places; as well as ensuring use of one’s own charger if one must charge in public.

On the other hand, the NCC-CSIRT Advisory 0001 of January 26, 2022, warns that Facebook for Android is vulnerable to a permission issue that gives privilege to anyone with physical access to the android device to accept friend requests without unlocking the phone.

READ ALSO  Lenovo Discovers Vulnerabilities In Products, As NCC-CSIRT Urges Firmware Update

The products affected include Versions 329.0.0.29.120 of Android OS.

With this, the attacker will be able to add the victim as a friend and collect personal information of the victim, such as Email, Date of Birth, Check-ins, Mobile phone number, Address, Pictures and other information that the victim may have shared, which would only be visible to his/her friends.

However, to be protected from the Facebook-associated vulnerability, NCC-CSIRT in the security advisory recommends to users to disable the feature from their device’s lock screen notification settings.

Recall that the NCC-CSIRT was inaugurated in October 2021 to provide guidance and direction for the constituents in dealing with issues relating to the security of critical infrastructure in their possession, and periodically assess, review and collate the threat landscape, risks, and opportunities affecting the communications sector, in order to provide advice to relevant stakeholders in those regards.

As the telecoms-industry specific intervention, the objective of which aligns with the objective of the National Cybersecurity Policy and Strategy (NCPS) document published by the Office of the National Security Adviser (ONSA), the NCC-CSIRT ensures continuous improvement of processes and communication frameworks to guarantee a secure and collaborative exchange of timely information while responding to cyber threats within the sector.

In recent times, NCC-CSIRT has raised a series of cyber-vulnerability awareness based on security advisories it receives from the Nigerian Cybersecurity Emergency Response Team (ngCERT), which is the national body for the implementation of the NCPS objective.

DigitalTimesNG however, understands that Juice Jacking and Facebook for Android Friend Acceptance Vulnerabilities are the two first-ever cyber vulnerabilities published by the NCC-CSIRT.

READ ALSO  NCC Advises WhatsApp Users To Set Up Two-Factor Authentication Against Hackers
#Android #Cyber Vulnerabilities #Juice Jacking #NCC-CSIRT #Telecom Consumers Facebook Featured
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleALTON Clears Air On Concerns Over Alleged 5G Networks Interference With Aviation Operations
Next Article Again, NCC Alerts On TangleBot, New SMS-Based Android Malware
DigitalTimesNG
  • X (Twitter)

Related Posts

Smile Communications Kicks Off “#AllTimeSmileTime” Campaign To Celebrate Internet Access Anytime, Anywhere

21 July 2025

NCC Unveils General Authorisation Framework To Drive Telecom Innovation And Inclusivity

18 July 2025

Telecom Operators Raise Alarm Over Rising Vandalism Threatening Nigeria’s Communications Infrastructure

18 July 2025

Telecom Security In Focus As NITRA, ALTON Host National Forum On CNII And Sustainability

2 July 2025

ALTON Blames NIMC Migration For Nationwide Disruption Of SIM Services

2 July 2025

Smile Nigeria: Connecting Nigerians To What Truly Matters

25 June 2025

Comments are closed.

Categories
About
About

Digital Times Nigeria (www.digitaltimesng.com) is an online technology publication of Digital Times Media Services.

Facebook X (Twitter) Instagram
Latest Posts

From Mandate To Milestones: Celebrating Hon. Amobi Ogah’s Remarkable Two-Year Journey In The Green Chambers

23 July 2025

For 16th Year Running, Sophos Named Leader In Gartner’s 2025 Magic Quadrant For EPPs

22 July 2025

Again, PalmPay Earns Spot On CNBC, Statista’s 2025 Global Top 300 Fintech Companies List

22 July 2025
Popular Posts

Building Explainable AI (XAI) Dashboards For Non-Technical Stakeholders

2 May 2022

Building Ethical AI Starts With People: How Gabriel Ayodele Is Engineering Trust Through Mentorship

8 January 2024

Gabriel Tosin Ayodele: Leading AI-Powered Innovation In Web3

8 November 2022
© 2025 Digital Times NG. Designed by Max Excellence LLC.
  • Advert Rate
  • Terms of Use
  • Advertisement
  • Private Policy
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.