Skip to main content

Security

See All Stories

REvil ransomware group that hacked Apple designs has itself been hacked by the FBI

Site default logo image

Back in April, the REvil ransomware group hacked into Mac assembler Quanta to reveal 2021 MacBook Pro designs ahead of the launch. Now REvil has itself been hacked in an FBI-led operation, in partnership with the Secret Service and law enforcement agencies in multiple countries.

Law enforcement gained control of a number of REvil servers in an operation designed to prevent further attacks, and to pursue individuals involved in running the ransomware group …

Expand Expanding Close

Apple patches zero-day flaw in iOS 15, but without crediting outspoken researcher

iOS 15

Last month security researcher Denis Tokarev, aka illusionofchaos, shared his experience of reporting three zero-day iOS vulnerabilities to Apple with specific criticism around how the company is slow to respond, act, and didn’t give him credit for one of the three flaws that were patched. Now it appears Apple has fixed another zero-day flaw, this one in iOS 15 that Tokarev found earlier this year, without giving him credit.

Expand Expanding Close

Apple says Android has up to 47x more malware than iPhone in continued pushback against sideloading

Amid growing pressure from private companies and governments to allow sideloading on iOS, Apple is out today with a new security paper diving into real-world data on how malware is impacting mobile devices. Along with statistics like Android having between 15 and 47 times more malware than iPhone, Apple is making its latest case against sideloading with data and recommendations from the US Department of Homeland Security, European Agency for Cybersecurity, NIST, Norton, and more.

Expand Expanding Close

Apparent Verizon Visible hack was credential stuffing attack, says carrier [U]

Verizon Visible hack

Update: Statement from Visible added below

Multiple reports of an apparent Verizon Visible hack, with attackers changing shipping addresses, then ordering phones that are charged to payment details held for customers. Visible is a Verizon sub-brand that operates entirely online, meaning that customers cannot seek assistance in-store.

“My account got hacked and they shipped out an iPhone 13 worth $1k that was taken from my PayPal,” wrote one customer …

Expand Expanding Close
Cybersecurity Awareness Month

It’s Cybersecurity Awareness Month – a good time to help family and friends

Cybersecurity Awareness Month is mostly geared toward businesses rather than individuals, encouraging them to ensure they carry out risk assessments and follow best practices to protect their IT systems. (There appear to be one or two companies who could use a little work there…)

But it’s also a worthwhile reminder to individuals to check their own cybersecurity, and for us to offer some advice to less-techie friends and family members.

Expand Expanding Close

AirTags can be weaponized by injecting code; Apple says fix on the way

AirTags can be weaponized by injecting code

A security researcher has shown that AirTags can be weaponized by injecting code into the phone number field before placing it into Lost mode and dropping it in strategic places. Apple has confirmed the finding.

When someone finds the AirTag and scans it, they will be redirected to the website of the attacker’s choice, which could include a fake iCloud login to report the find …

Expand Expanding Close

Apple responds to security researcher who found multiple iOS 15 zero-day flaws [U]

new iOS security bugs

Apple overhauled its security bounty program back in 2019 by making it open to anyone, increasing payouts, and more. However, the program has seen a good amount of criticism from the infosec community. Now another security researcher has shared their experience claiming that Apple didn’t give them credit for one zero-day flaw they reported which was fixed and that there are three more zero-day vulnerabilities in iOS 15.

Update 9/27: After sharing his experience publicly, Apple has responded to security researcher illusionofchaos, aka Denis Tokarev.

Expand Expanding Close

Security expert says Apple giving into Russia proves CSAM assurances cannot be trusted

Apple giving into Russia proves anti CSAM case

Apple giving into Russia twice this week on key civil liberties issues proves that the company’s CSAM misuse assurances cannot be trusted, argues a high-profile security expert.

Apple today pulled from the App Store an opposition tactical voting app after the Russian government threatened specific local company employees with “punishment” if they refused. It turns out that Apple also turned off its Private Relay service in Russia just yesterday, likely also in response to government pressure…

Expand Expanding Close

London police chief uses 9/11 to attack end-to-end encrypted messaging

Site default logo image

London police chief Cressida Dick has used the 20th anniversary of 9/11 to attack companies like Apple, WhatsApp, Telegram, and Signal for offering end-to-end encrypted message services.

It follows the British Home Secretary – in charge of policing for the UK – seeking tech companies to find some way to break end-to-end encryption

Expand Expanding Close

UK government backs Apple, and wants to scan encrypted messages for CSAM

Scan encrypted messages for CSAM

The British government has expressed support for Apple’s now-delayed CSAM scanning plans, and says that it wants the ability to scan encrypted messages for CSAM, even where end-to-end encryption is used.

The country is offering to pay anyone who can find a way “to keep children safe in environments such as online messaging platforms with end-to-end encryption” …

Expand Expanding Close

Tim Cook White House visit confirmed; Apple announcement might follow [U]

Site default logo image

Update: Apple did make a security announcement, but only a supply-chain related one.

We learned earlier this week about a potential Tim Cook White House visit to attend a cybersecurity summit hosted by President Biden. Cook’s participation has now been confirmed by a list of attendees shared by an administration official, and could provide an excellent opportunity for Apple’s CEO to drive home the company’s stance on privacy and strong encryption.

A new report today also raises the possibility of a security-related announcement by Apple after the meeting has finished …

Expand Expanding Close

New Pegasus zero-click iPhone attack defeats Apple’s Blastdoor protections

New Pegasus zero-click iPhone attack

A newly discovered NSO Pegasus zero-click iPhone attack against a human rights activist managed to succeed despite Apple’s Blastdoor protections, according to security researchers at Citizen Lab.

It is unclear, however, whether the protections Apple added to iOS 14.7.1 would have succeeded in blocking the attack, as it took place at a time when iOS 14.6 was the latest version available …

Expand Expanding Close

T-Mobile discloses 5.3M more accounts compromised, sensitive data including DOB and address leaked

T-Mobile 3.3Gbps speed 5G SA

In a massive data breach we first learned about earlier this week, T-Mobile is continuing to discover the extent of the damage that’s rising beyond 50 million accounts. In an update today, the uncarrier says it has found an additional 5.3 million current postpaid customer accounts had their name, address, date of birth, or other personal information compromised.

Expand Expanding Close