Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 3 / 4
67 résultats taggé iOS  ✕
Apple releases emergency update to fix zero-day exploited in attacks https://www.bleepingcomputer.com/news/apple/apple-releases-emergency-update-to-fix-zero-day-exploited-in-attacks/
12/07/2023 09:09:39
QRCode
archive.org
thumbnail

Apple has issued a new round of Rapid Security Response (RSR) updates to address a new zero-day bug exploited in attacks and impacting fully-patched iPhones, Macs, and iPads.

bleepingcomputer EN 2023 CVE-2023-37450 Apple iOS iPad iPhone Mac macOS Rapid-Security-Response Zero-Day
Dissecting TriangleDB, a Triangulation spyware implant https://securelist.com/triangledb-triangulation-implant/110050/
21/06/2023 13:40:21
QRCode
archive.org
thumbnail

In researching Operation Triangulation, we set ourselves the goal to retrieve as many parts of the exploitation chain as possible. As of now, we have finished analyzing the spyware implant and are ready to share the details.
#2023 #APT #Apple #EN #Malware-Descriptions #Spyware #Targeted-attacks #Triangulation #iOS #malware #securelist

Apple Triangulation iOS 2023 Malware-Descriptions malware EN Spyware securelist APT Targeted-attacks
“Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware | Ars Technica https://arstechnica.com/information-technology/2023/06/clickless-ios-exploits-infect-kaspersky-iphones-with-never-before-seen-malware/
02/06/2023 13:27:34
QRCode
archive.org
thumbnail

"Operation Triangulation" stole mic recordings, photos, geolocation, and more.

arstechnica EN 2023 Triangulation iOS Apple kaspersky Russia spyware NSA
A Matter of Triangulation. https://eugene.kaspersky.com/2023/06/01/a-matter-of-triangulation/
02/06/2023 09:08:34
QRCode
archive.org
thumbnail

Hi all, Today we have very big and important news. Kaspersky experts have discovered an extremely complex, professionally targeted cyberattack that uses Apple’s mobile devices. The purpose of this attack is the inconspicuous introduction of spyware into the iPhones of employees of the company – both top and middle-management. The attack is carried out using

kaspersky EN 2023 iOS 0-Click Triangulation iphone spyware Apple
Apple fixes three new zero-days exploited to hack iPhones, Macs https://www.bleepingcomputer.com/news/apple/apple-fixes-three-new-zero-days-exploited-to-hack-iphones-macs/
23/05/2023 22:24:42
QRCode
archive.org
thumbnail

Apple has addressed three new zero-day vulnerabilities exploited in attacks to hack into iPhones, Macs, and iPads.

bleepingcomputer EN 2023 Apple iOS iPhone Mac macOS WebKit Zero-Day
What if we had the SockPuppet vulnerability in iOS 16? https://security.apple.com/blog/what-if-we-had-sockpuppet-in-ios16/
23/05/2023 21:48:17
QRCode
archive.org

The next post in our XNU memory safety series examines how our hardened kernel allocator performs in the real world against a previously patched but powerful UAF software vulnerability. In this detailed analysis, we find out what might happen if SockPuppet were to meet kalloc_type in iOS 16.

security.apple EN 2023 SockPuppet iOS research
Apple’s high security mode blocked NSO spyware, researchers say | TechCrunch https://techcrunch.com/2023/04/18/apple-lockdown-mode-iphone-nso-pegasus/
19/04/2023 08:42:58
QRCode
archive.org
thumbnail

Apple has fixed the three exploits used to deploy the Pegasus spyware, which did not require any interaction from the target.

techcrunch EN 2023 apple citizen-lab ios iphone malware nso nso-group spyware LockdownMode
DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/
11/04/2023 18:37:46
QRCode
archive.org
thumbnail

Microsoft analyzes a threat group tracked as DEV-0196, the actor’s iOS malware “KingsPawn”, and their link to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infrastructure called REIGN, that’s designed to exfiltrate data from mobile devices.

microsoft EN 2023 QuaDream spyware spy IoCs DEV-0196 iOS calendar zero-click REIGN
Mercenary spyware hacked iPhone victims with rogue calendar invites, researchers say | TechCrunch https://techcrunch.com/2023/04/11/quadream-spyware-hacked-iphones-calendar-invites/
11/04/2023 18:32:54
QRCode
archive.org
thumbnail

Researchers found malware developed by QuaDream, a little-known government spyware maker, which was used against journalists and politicians.

techcrunch EN 2023 security apple cybersecurity hackers hacking ios iphone spyware zero-days
Apple fixes two zero-days exploited to hack iPhones and Macs https://www.bleepingcomputer.com/news/apple/apple-fixes-two-zero-days-exploited-to-hack-iphones-and-macs/
07/04/2023 20:29:05
QRCode
archive.org
thumbnail

Apple has released emergency security updates to address two new zero-day vulnerabilities exploited in attacks to compromise iPhones, Macs, and iPads.

Apple EN 2023 updates zero-day vulnerabilities ios macos
Apple patches are out – old iPhones get an old zero-day fix at last! https://nakedsecurity.sophos.com/2023/01/24/apple-patches-are-out-old-iphones-get-an-old-zero-day-fix-at-last/
24/01/2023 08:57:50
QRCode
archive.org
thumbnail

Don’t delay, especially if you’re still running an iOS 12 device… please do it today!

nakedsecurity EN 2023 vulnerability apple cve-2022-42856 exploit ios ios-12 ipados zero-day
zhuowei/WDBFontOverwrite: Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689. https://github.com/zhuowei/WDBFontOverwrite
30/12/2022 11:46:10
QRCode
archive.org
thumbnail

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

Works on iOS 16.1.2 and below (tested on iOS 16.1) on unjailbroken devices.

zhuowei EN GitHub PoC iOS CVE-2022-46689 unjailbroken ComicSans
Attacking Apple's Neural Engine https://github.com/0x36/weightBufs/blob/main/attacking_ane_poc2022.pdf
12/11/2022 21:59:41
QRCode
archive.org
thumbnail

WeightBufs is a kernel r/w exploit for all Apple devices with Neural Engine support. Bugs and Exploit by @simo36, you can read my presentation slides at POC for more details about the vulnerabilities and the exploitation techniques.

0x36 EN 2022 WeightBufs GitHub Apple ios macos exploit NeuralEngine exploitation CVE-2022-32845 CVE-2022-32948 CVE-2022-42805 CVE-2022-32899
SiriSpy - iOS bug allowed apps to eavesdrop on your conversations with Siri https://rambo.codes/posts/2022-10-25-sirispy-ios-bug-allowed-apps-to-eavesdrop
27/10/2022 08:06:40
QRCode
archive.org
thumbnail

Any app with access to Bluetooth could record your conversations with Siri and audio from the iOS keyboard dictation feature when using AirPods or Beats headsets. This would happen without the app requesting microphone access permission and without the app leaving any trace that it was listening to the microphone.

rambo.codes EN 2022 iOS bug Siri SiriSpy Bluetooth AirPods privacy
Apple Fixes Exploited Zero-Day With iOS 16.1 Patch | SecurityWeek.Com https://www.securityweek.com/apple-fixes-exploited-zero-day-ios-161-patch
25/10/2022 09:21:25
QRCode
archive.org

Apple confirms the active exploitation of CVE-2022-42827, warning in a barebones advisory that the flaw exposes iPhones and iPads to arbitrary code execution attacks.

securityweek EN 2022 apple CVE-2022-42827 CVE-2022-32894 CVE-2022-32917 ios ipad iphone zero-day exploits in-the-wild
Poseidon’s Offspring: Charybdis and Scylla https://www.humansecurity.com/learn/blog/poseidons-offspring-charybdis-and-scylla
26/09/2022 11:10:59
QRCode
archive.org
thumbnail

HUMAN's Satori Threat Intelligence and Research Team uncovered a network of 89 Android and iOS apps committing various flavors of ad fraud.

humansecurity EN 2022 Android iOS ad-fraud Charybdis Scylla
The Apple security landscape: Moving into the world of enterprise risk https://venturebeat.com/security/apple-security-vulnerabilities/
23/09/2022 12:26:51
QRCode
archive.org
thumbnail

With the enterprise adoption of MacOS and iOS devices increasing, the Apple security landscape is becoming increasingly complex.

venturebeat EN 2022 MacOS iOS security enterprise landscape
Apple Kills Passwords in iOS 16 and macOS Ventura | WIRED https://www.wired.com/story/apple-passkeys-password-iphone-mac-ios16-ventura/
22/09/2022 16:40:14
QRCode
archive.org
thumbnail

With iOS 16 and macOS Ventura, Apple is introducing passkeys—a more convenient and secure alternative to passwords.

wired EN 2022 apple privacy passwords ios macOS iOS passkeys
Get root on macOS 12.3.1: proof-of-concepts for Linus Henze’s CoreTrust and DriverKit bugs (CVE-2022-26766, CVE-2022-26763) https://worthdoingbadly.com/coretrust/
16/09/2022 09:07:26
QRCode
archive.org

Here are two proof-of-concepts for CVE-2022-26766 (CoreTrust allows any root certificate) and CVE-2022-26763 (IOPCIDevice::_MemoryAccess not checking bounds at all), two issues discovered by @LinusHenze and patched in macOS 12.4 / iOS 15.5.

worthdoingbadly PoC EN 2022 CVE-2022-26766 CVE-2022-26763 patched macOS iOS LinusHenze
Hands-on with Lockdown Mode in iOS 16 https://techcrunch.com/2022/08/12/apple-lockdown-mode-ios-16/
14/08/2022 18:31:18
QRCode
archive.org
thumbnail

Lockdown Mode is a new Apple feature you should hope you’ll never need to use. But for those who do, like journalists, politicians, lawyers and human rights defenders, it’s a last line of defense against nation-state spyware designed to punch through an iPhone’s protections. The new security feature was announced earlier this year as an […]

techcrunch EN 2022 apple LockdownMode ios ipad iphone handson ios16
page 3 / 4
4845 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn