Skip to main content

Security

Apple patches “clickless” 0-day image processing vulnerability in iOS, macOS

posted onSeptember 7, 2023
by l33tdawg
Credit: Arstechnica

Apple has released security updates for iOS, iPadOS, macOS, and watchOS today to fix actively exploited zero-day security flaws that can be used to install malware via a "maliciously crafted image" or attachment. The iOS 16.6.1, iPadOS 16.6.1, macOS 13.5.2, and watchOS 9.6.2 updates patch the flaws across all of Apple's platforms. As of this writing, no updates have been released for older versions like iOS 15 or macOS 12.

Malicious attackers can flood iPhone users with endless popups using a $170 tool

posted onSeptember 6, 2023
by l33tdawg
Credit: Apple Insider

Devices like the Flipper Zero can send out pre-programmed radio signals that can cause an iPhone to open a disruptive interface, effectively being attacked into temporary uselessness.

Apple products like the iPhone have various communication tools like Wi-Fi, Bluetooth, NFC, and Ultra Wideband to make pairing and using accessories easier. These tools are what make systems like AirDrop and fast AirPods pairing possible.

United Airlines says outage that held up departing flights was not a cybersecurity issue

posted onSeptember 5, 2023
by l33tdawg
Credit: Market Watch

United Airlines said Tuesday that a software update triggered a glitch that forced it to halt departures nationwide, briefly crippling one of the nation’s biggest carriers on a busy travel day.

Federal officials said United crews had been unable to contact airline dispatchers through normal means. “A software update caused a widespread slowdown in United’s technology systems,” United UAL, -2.51% said in a statement. The airline said it was not a cybersecurity issue.

4 Okta customers hit by campaign that gave attackers super admin control

posted onSeptember 5, 2023
by l33tdawg
Credit: Arstechnica

Authentication service Okta said four of its customers have been hit in a recent social-engineering campaign that allowed hackers to gain control of super administrator accounts and from there weaken or entirely remove two-factor authentication protecting accounts from unauthorized access.

CarderBee hacking group targets organizations in Asia

posted onAugust 23, 2023
by l33tdawg
Credit: Silicon Angle

An unknown advanced persistent threat group has been observed attacking organizations in Asia, particularly Hong Kong, using commercial software to deploy “backdoor” malware.

Dubbed “CarderBee” by researchers at Symantec, the hacking group uses Cobra DocGuard Client, a software package designed to allow users to access and manage their Consolidated Omnibus Budget Reconciliation Act documents to gain access to victim’s machines.

Hackers could now steal passwords over Zoom by listening to keystrokes using AI

posted onAugust 16, 2023
by l33tdawg
Credit: Business Insider

An AI tool could decipher text — including passwords — from keystroke sounds recorded over Zoom and be right over nine times out of ten, a group of researchers said in a paper published on August 3.

An AI model developed by the researchers showed a 93% accuracy rate in deciphering keystrokes from a recording of a Macbook's keystrokes made over video conferencing software Zoom, according to a group of researchers affiliated with Durham University, the University of Surrey, and the Royal Holloway University of London.