Skip to main content

Security

See All Stories

Apple revokes certificates for spyware app ‘Hermit’ distributed outside the App Store

apple zero-day exploit spyware security iOS macOS patches fixes

Google’s Threat Analysis Group (TAG), a group that specializes in tracking and analyzing government-backed hacking and attacks, recently published research on “Hermit” – a spyware that can compromise Android and iOS devices. Luckily, Apple has already found a way to stop the spread of this specific spyware on its devices.

Expand Expanding Close

The iPhone will be the future of proving our identity, online and offline

Proving our identity | A student accessing a campus facility using the Apple Wallet app

We’ve seen some baby steps towards using our iPhone for proving our identity. But a couple of recent developments point to a future in which an iPhone – plus biometrics – could let us use our phone as a single means of verifying our identity, both online and in face-to-face interactions.

In all, Apple provides support for four initiatives which I think provide a clear pointer to a future in which the iPhone will be our one-stop device for ID …

Expand Expanding Close

RCS Lab’s iPhone hacks used by law enforcement agencies in Europe; Apple has patched

iPhone hacks | Moody photo of shadowy figure

iPhone hacks developed by Italian company RCS Lab have been used by law enforcement agencies in Europe, according to a new Google report. The hacking tool used a variety of exploits to allow the firm’s customers to spy on private messages, contacts, and passwords.

However, Apple has patched all six of the exploits used in different versions of iOS (see below), so keeping your iPhone up to date will protect it from the hacking tools …

Expand Expanding Close

NSO Pegasus spyware used by at least five EU countries; interim report published

Site default logo image

NSO Pegasus spyware has been used by at least five EU countries, admits the company. The admission was made as part of a European investigation into the impact of Pegasus, with an interim report now published.

It’s likely that the true number is higher, with the company promising to provide a ‘more concrete number’ …

Expand Expanding Close

PACMAN M1 chip attack defeats ‘the last line of security’

PACMAN-M1-chip | Purely decorative graphic

A so-called PACMAN M1 chip attack created by MIT security researchers succeeded in defeating what has been described as “the last line of security” on Apple Silicon.

When designing the M1 chip, Apple created various layers of security, each designed to protect against an attacker who succeeded in penetrating the previous ones. Its final layer is a security feature known as PAC – and this has now been defeated …

Expand Expanding Close

iPhone spyware maker NSO struggled to make payroll; wants to sell to red-flagged countries

iPhone spyware (purely decorative image)

The financial problems of iPhone spyware maker NSO were so bad by the end of last year that it struggled to make payroll – after the company failed to make a single sale over a period of several months.

The company, which sells software to remotely carry out zero-click hacks of both iPhones and Android smartphones, has been in deep trouble ever since it was blacklisted by the US government. However, its plan to overcome its woes could make Pegasus an even nastier threat …

Expand Expanding Close

A world without passwords could further lock users into Apple and Google ecosystems

A world without passwords | iHone 13 against out of focus coloured background

The prospect of a world without passwords can’t come soon enough for me, but a problem has been raised with the FIDO standard designed to eliminate the need for them. Namely, that abandoning passwords could make it harder to switch between ecosystems.

If you have your passkeys setup for Apple devices, there is nothing in the standard allowing you to transfer them to an Android device, or vice versa …

Expand Expanding Close

Verizon downplays database hacked and held for ransom, security risk could remain

verizon outage

A Verizon employee database was recently compromised with the hacker holding it for a $250,000 ransom. Verizon says it doesn’t believe it contains “any sensitive information” and stopped communication with the hacker. However, the list of details including employee email addresses, phone numbers, and more could present a risk for future attacks.

Expand Expanding Close

See how hard browsers have to work to identify a fake apple.com website

apple fake sites phishing

Way back in 2017, a security researcher created a fake apple.com website where the URL looked completely correct. The trick was that the domain he registered used a unicode character that looks like an “a” but is in fact a Cyrillic character.

Browsers were updated to detect this kind of fakery, but it’s far from a simple process – as a new video (below) illustrates …

Expand Expanding Close

Apple patches dozens of security flaws with iOS 15.5, over 50 fixes for macOS 12.4

new iOS security bugs

Apple has released iOS 15.5, macOS 12.4, and more today with updates like new features for Apple Cash, the Podcasts app, and the Studio Display webcam fix. However, a bigger reason to update your devices is the security patches with today’s releases. iOS 15.5 includes almost 30 security fixes while macOS 12.4 features over 50.

Expand Expanding Close

Apple, Google, and Microsoft to extend support for FIDO ‘passwordless’ sign-in

In early 2020, Apple joined the FIDO Alliance, an open industry association created to increase the interoperability of authentication methods and reduce reliance on traditional passwords. Now Apple, Google, and Microsoft have committed to expanding support for the FIDO Standard, moving toward a universal “passwordless” sign-in method.

Expand Expanding Close

Spanish prime minister’s iPhone infected by Pegasus spyware; defense minister, too

Site default logo image

The Spanish prime minister’s iPhone was infected by NSO’s Pegasus spyware, says the government. Defense Minister Margarita Robles’ phone was also hit. This is just the latest in a slew of high-profile Pegasus attacks revealed within the last few weeks.

While it is foreign governments who would most want to target phones belonging to most prime ministers, there’s another obvious suspect in the case of Spain …

Expand Expanding Close

Cellebrite iPhone cracking: Here’s which models the kit can unlock and access, and how to protect your data

Company graphic promoting the kit | Cellebrite iPhone cracking

Cellebrite iPhone cracking kit allows the company’s clients to access virtually all of the private data stored on a phone – in some cases, even if the phone is locked.

But the exact capabilities depend on both the model of the iPhone and the version of iOS it is running. We managed to get access to the user documentation for a recent version of the kit to see what it can do …

Expand Expanding Close

Apple tricked into releasing personal data used to sexually extort minors

Low-key photo of woman hiding her face in darkness | Apple tricked into releasing personal data used to sexually extort minors

We learned last month that Apple was tricked into releasing personal data to hackers, after they posed as law enforcement officials with emergency data requests. A follow-up report reveals that some of this data was used to sexually extort minors.

The latest report also sheds light on how the hackers were able to fool Apple and other tech giants, including Facebook, Google, Snap, Twitter, and Discord …

Expand Expanding Close

T-Mobile breached by cybercrime group LAPSUS$ through compromised employee accounts

T-Mobile 3.3Gbps speed 5G SA

T-Mobile has suffered another data breach, this time carried out by young hackers that were part of the LAPSUS$ group. While T-Mobile has said that no customer or government information was compromised, it appears LAPSUS$ gained access to T-Mobile’s source code repositories along with its customer account management system.

Expand Expanding Close

Pegasus targeted US iPhones indirectly; device infected in British prime minister’s office; Catalans targeted in Spain

Site default logo image

NSO spyware Pegasus targeted US iPhones indirectly, despite the company forbidding customers from infecting phones with American SIMs. Devices belonging to Catalan politicians and others were also infected, with the Spanish government suspected to be responsible.

Additionally, it was discovered that a device connected to the network at 10 Downing Street – the office of British prime minister Boris Johnson – was also infected …

Expand Expanding Close

Pegasus hacked the iPhone of award-winning journalist, weeks after Apple’s injunction attempt

Pegasus hacked the iPhone of award-winning journalist

It’s been revealed that NSO’s Pegasus hacked the iPhone of an award-winning journalist, just weeks after Apple sought an injunction that would bar the company from targeting iPhone users.

NSO’s Pegasus software is so dangerous for two reasons. First, it gives access to almost all the data on the phone, including messages, photos, and location. Second, it works via a zero-click approach …

Expand Expanding Close