Skip to main content

Security

See All Stories

Student who hijacked iPhone camera did the same to the Mac; Apple paid bug bounty of $100K

Site default logo image

Apple paid a bug bounty of $100K after a cyber security student who successfully hijacked the iPhone camera back in 2019 did the same with the Mac camera.

Ryan Pickren used an imaginative approach that allowed him to run arbitrary code on a target Mac, and received what he believes to be the largest bug bounty Apple has ever paid …

Expand Expanding Close

SysJoker shows that even Mac malware runs natively on M1 Macs now

SysJoker Mac malware

We may still be waiting for some developers to update their apps to run natively on M1 Macs, but the developer of SysJoker Mac malware is already on the case.

Security researcher Patrick Wardle points to what he says is the first Mac malware of 2022, and it runs on both Intel and M1 Macs. SysJoker can be controlled remotely by an attacker, allowing it to be used in many different ways …

Expand Expanding Close

Mandatory Chinese Olympics app collects personal data, has two security holes

Site default logo image

Use of the Chinese Olympics app, MY2022, is mandatory for everyone attending this year’s Olympic Games in Beijing, whether as an athlete or simply watching from the stadium.

The app collects sensitive personal data – like passport details, medical data, and travel history – and analysis by security researchers reveals that the code has two security holes that could expose this information …

Expand Expanding Close

Apple and other big tech companies to attend White House meeting to talk software security

Apple White House promises broadband for all

Apple, Google, Amazon, Meta, and IBM will attend a meeting at the White House to discuss software security after the US suffered several major cyberattacks in 2021. As reported by Reuters, this meeting will take place today and will be hosted by deputy national security advisor for cyber and emerging technology Anne Neuberger.

Expand Expanding Close

Latest suspected NSO phone hack: Journalists and activists in El Salvador

Another suspected NSO phone hack has come to light, this of journalists and activists in El Salvador. Most of the journalists were working for an online news service that has been reporting extensively on alleged government corruption.

Two journalists contacted Citizen Lab after suspecting that their phones had been compromised, and an investigation confirmed their suspicions, and found that they weren’t the only ones …

Expand Expanding Close

New report suggests Uganda used NSO spyware to hack State Department iPhones

Uganda used NSO spyware to hack State Department iPhones

We learned earlier this month that NSO’s Pegasus spyware was used to hack US State Department iPhones in Uganda, with no clue at the time who the attacker was.

A new report strongly suggests that the Ugandan government was behind the attacks, as the country – which has an appalling human rights record – is now known to have purchased the spyware. It also appears that this was, indirectly, the tipping point that led to NSO’s downfall…

Expand Expanding Close

After US ban and Apple action, Pegasus spyware maker NSO running out of cash

Pegasus spyware maker NSO running out of cash

Pegasus spyware maker NSO Group is reportedly running out of cash following actions by both the US government and Apple. This has led the company to explore options to put itself up for sale.

Two US funds have expressed an interest, claiming that they would change the company’s mission from offensive to defensive, though skepticism has been expressed about this …

Expand Expanding Close

Apple alerted Polish prosecutor that her iPhone has likely been compromised by NSO

Site default logo image

As part of hitting back at spyware company NSO, Apple alerted a Polish prosecutor that her iPhone appears to have been compromised by Pegasus. This also gives us our first look at the text of Apple’s security alerts.

Although Poland has not admitted purchasing and using the spyware, there is significant evidence that it has done so …

Expand Expanding Close

Apple will alert customers who may have been targeted by NSO

Apple will alert customers who may have been targeted by NSO

Journalists, lawyers, politicians, and human rights activists have all been targeted by NSO’s Pegasus software, and Apple has now said that it will send security alerts to customers whose devices may be been compromised. It has already done so for at least five Thai activists and researchers.

It follows Apple’s announcement yesterday that it is suing NSO for attacking iOS users …

Expand Expanding Close

Charges against alleged member of REvil ransom group that obtained MacBook Pro designs

REvil ransom group charges

An alleged member of the REvil ransom group has been charged, with $6.1M in funds seized from another suspect, according to the US Department of Justice.

Back in April, we learned that the REvil group accessed systems belonging to Mac assembler Quanta and obtained schematics of the upcoming MacBook Pro models, which accurately revealed the HDMI, MagSafe, and SD card slot …

Expand Expanding Close

NSO – whose Pegasus spyware hacks iPhones – officially named by US as a national security risk

Pegasus spyware sees NSO named as US national security risk

The NSO group, whose Pegasus spyware is used to hack iPhones and Android smartphones, has been officially named by the US government as a threat to national security.

The Commerce Department’s Bureau of Industry and Security (BIS) has added the Israeli company to the Entity List, which bans the company’s products from being imported, exported or passed from one organization to another within the US.

Expand Expanding Close

NYT journalist describes his iPhone being hacked, and the precautions he now takes

NYT journalist describes his iPhone being hacked

A New York Times journalist covering the Middle East has described the experience of his iPhone being hacked, and the security precautions he now takes as a result.

Ben Hubbard says there were four attempts to hack his iPhone, and that two of them succeeded, with all the signs pointing to the use of NSO’s Pegasus spyware.

Expand Expanding Close

REvil ransomware group that hacked Apple designs has itself been hacked by the FBI

Site default logo image

Back in April, the REvil ransomware group hacked into Mac assembler Quanta to reveal 2021 MacBook Pro designs ahead of the launch. Now REvil has itself been hacked in an FBI-led operation, in partnership with the Secret Service and law enforcement agencies in multiple countries.

Law enforcement gained control of a number of REvil servers in an operation designed to prevent further attacks, and to pursue individuals involved in running the ransomware group …

Expand Expanding Close

Apple patches zero-day flaw in iOS 15, but without crediting outspoken researcher

iOS 15

Last month security researcher Denis Tokarev, aka illusionofchaos, shared his experience of reporting three zero-day iOS vulnerabilities to Apple with specific criticism around how the company is slow to respond, act, and didn’t give him credit for one of the three flaws that were patched. Now it appears Apple has fixed another zero-day flaw, this one in iOS 15 that Tokarev found earlier this year, without giving him credit.

Expand Expanding Close

Apple says Android has up to 47x more malware than iPhone in continued pushback against sideloading

Amid growing pressure from private companies and governments to allow sideloading on iOS, Apple is out today with a new security paper diving into real-world data on how malware is impacting mobile devices. Along with statistics like Android having between 15 and 47 times more malware than iPhone, Apple is making its latest case against sideloading with data and recommendations from the US Department of Homeland Security, European Agency for Cybersecurity, NIST, Norton, and more.

Expand Expanding Close

Apparent Verizon Visible hack was credential stuffing attack, says carrier [U]

Verizon Visible hack

Update: Statement from Visible added below

Multiple reports of an apparent Verizon Visible hack, with attackers changing shipping addresses, then ordering phones that are charged to payment details held for customers. Visible is a Verizon sub-brand that operates entirely online, meaning that customers cannot seek assistance in-store.

“My account got hacked and they shipped out an iPhone 13 worth $1k that was taken from my PayPal,” wrote one customer …

Expand Expanding Close