While the available evidence suggests that hackers have not gained direct access to more than 600 million iCloud accounts, some of the sample login credentials supplied by the group have been found to be valid. ZDNet, for example, used Apple’s password reset function to test 54 logins supplied by the hackers, and found that all of them worked.
Apple has said that there have been no breaches of its own systems, and that the credentials likely came from ‘previously compromised third-party services.’ Most of the account owners contacted by ZDNet lent weight to this claim …
Dubai International is one of the airports affected by the ban
Update: The UK has implemented a similar ban, though restricted to six rather than eight countries. The UK ban applies to flights to the UK from Turkey, Lebanon, Jordan, Egypt, Tunisia and Saudi Arabia.
The U.S. government has announced a ban on carrying tablets, laptops and other ‘large electronic devices’ in cabin baggage on flights to the USA from 10 airports. The measure is said to be in response to intelligence on terrorism threats from eight countries, mostly Middle Eastern and North African, reports the BBC.
Security researches competing at the annual Pwn2own conference yesterday uncovered two zero-day vulnerabilities in Safari. Two teams successfully exploited the bugs they found to achieve root access to macOS, while a third attempt failed.
Eleven teams are competing for a total $1M prize pot, with three of the ten attempts to date targeting Safari …
A recently disclosed vulnerability by Check Point proved that both WhatsApp and Telegram were susceptible to particularly nefarious online attacks. While most attacks only garner tidbits of user data, these allowed attackers to gain full control of user accounts. Once in, attackers could download previously shared photos, contact information, and even more importantly gain access to a user’s friends accounts as well. Both companies acknowledged and released fixes to help patch the web client vulnerabilities.
Thousands of Twitter users have this morning had their accounts hijacked and used to tweet a swastika and Nazi hashtags. The attack appears to be in support of Turkey’s President, urging support for a referendum which could allow President Erdoğan to remain in power until 2029.
The Verge reports that many verified and high-profile Twitter accounts were compromised, and that the hijack appears to have been carried out via a third-party app.
Accounts operated by Amnesty International, Duke University, Reuters Japan, and BBC North America were among those hijacked. Several users have noted that all hijacked tweets appear to have been linked to Twitter Counter, a Netherlands-based analytics application. Twitter Counter was previously targeted in a November 2016 attack that caused some high-profile accounts to spread spam.
Twitter confirmed that a third-party app was behind the hack, so checking which apps have permission to access your Twitter account is one important step to take. Here’s a quick checklist to check the security of Twitter and other services …
Apple has hired Jonathan Zdziarski, a forensics consult and security researcher who has been heavily involved in the iOS security community. Zdziarski was notably vocal during Apple’s conflict with the FBI last year, offering his technical expertise against claims being made by the government.
Update: Edward Snowden has tweeted that the code names are real and would only be known by a cleared insider. The BBC has reported that some of the iOS malware allows ‘the agency to see a target’s location, activate their device’s camera and microphone, and read text communications.’
What makes this look real? Program & office names, such as the JQJ (IOC) crypt series, are real. Only a cleared insider could know them.
Wikileaks claims that the U.S. Central Intelligence Agency has a specialized unit within its Center for Cyber Intelligence that is devoted to developing and obtaining zero-day exploits for iOS devices. A zero-day exploit is one unknown to Apple or security researchers, so cannot specifically be protected against.
Despite iPhone’s minority share (14.5%) of the global smart phone market in 2016, a specialized unit in the CIA’s Mobile Development Branch produces malware to infest, control and exfiltrate data from iPhones and other Apple products running iOS, such as iPads. CIA’s arsenal includes numerous local and remote “zero days” developed by CIA or obtained from GCHQ, NSA, FBI or purchased from cyber arms contractors such as Baitshop. The disproportionate focus on iOS may be explained by the popularity of the iPhone among social, political, diplomatic and business elites.
Wikileaks further claims that the CIA recently ‘lost control’ of the majority of the malware used to attack iPhones and iPads …
We reported back in October on an iOS exploit that caused iPhones to repeatedly dial 911 without user intervention. It was said then that the volume of calls meant one 911 center was in ‘immediate danger’ of losing service, while two other centers had been at risk – but a full investigation has now concluded that the incident was much more serious than it appeared at the time.
It was initially thought that a few hundred calls were generated in a short time, but investigators now believe that one tweeted link that activated the exploit was clicked on 117,502 times, each click triggering a 911 call. The WSJ reports that law-enforcement officials and 911 experts fear that a targeted attack using the same technique could prove devastating …
Very little Uber traffic goes through Cloudflare. Only a handful of tokens were involved and have since been changed. Passwords were not exposed.
Update 3: OKCupid has made a similar statement
Cloudflare alerted us last night of their bug and we’ve been looking into its impact on OkCupid members. Our initial investigation has revealed minimal, if any, exposure. If we determine that any of our users has been impacted we will promptly notify them and take action to protect them.
User data from 3,400 websites has been leaked and cached by search engines as a result of a bug in Cloudflare, a content delivery network. Sites affected over the course of several months include major ones like Uber, Fitbit and dating site OKCupid. 1Password also uses Cloudflare, but says that end-to-end encryption means that no customer data was exposed.
ArsTechnica reports that the leaks were spotted by Google security researcher Tavis Ormandy.
We observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major cloudflare-hosted sites from other users. Once we understood what we were seeing and the implications, we immediately stopped and contacted cloudflare security.
Cloudflare has admitted that the breach occurred, but Ormandy and other security researchers believe the company is underplaying the severity of the incident …
A new report today from The Information shares that Apple found potential security issues with at least one server early last year. Apple purchased the server from Super Micro Computer and was used to help power its web services and also contained customer information.
After scanning through the binary codes of applications in the iOS App Store, Will Strafach’s verify.ly service has detected that 76 popular apps in the store are currently vulnerable to data interception. The interception is possible regardless if App Store developers are using App Transport Security or not. A few months ago, similar vulnerabilities were discovered with Experian and myFICO Mobile’s iOS apps.
When Apple refused to compromise iOS security last year and unlock the iPhone 5c belonging to the San Bernardino shooter, the FBI turned to an Israeli mobile forensics firm called Cellebrite to find a way in to the encrypted iPhone. Now Motherboardreports that a hacker has released files allegedly from Cellebrite that demonstrate how cracking tools can’t be kept private.
Update: Updated with a response from WhatsApp, below.
A security researcher has found a backdoor in the end-to-end encryption system used by the WhatsApp messaging service. The vulnerability would allow Facebook to read messages sent through the supposedly-secure system, as well as making it possible for the company to comply with court orders to make messages available to government bodies.
While end-to-end encryption would normally mean that not even the company operating the service can decrypt messages, only the intended recipient, the specific implementation used in WhatsApp includes a major security hole …
Over the summer, Apple informed developers that all apps would be required to securely connect to servers by January 1st, 2017. The announcement came as part of the App Transport Security feature in iOS 9. This evening, however, Apple announced that it is extending the deadline for developers to make the switch to HTTPS connectivity…
Yahoo today has announced its second large hack in a matter of 3 months. In a post on the company’s Tumblr account, Yahoo’s chief information security officer Bob Lord announced that, in 2013, data from more than 1 billion user accounts was accessed by an unauthorized third-party. This revelation comes after Yahoo confirmed in September that 500 million user accounts were affected by a separate data breach.
A new independent report titled ‘A Pulse on Mobility in Healthcare’ has been published by Apple device management software firm Jamf, who also commissioned the survey. Not surprisingly, the global tally of 550 IT decision makers found that security is the number one concern for healthcare systems who manage mobile devices among other details.
If you’re not one to use iOS’ automatic updates feature, make sure to grab the latest updates for Experian – Free Credit Report and myFICO Mobile. A security vulnerability discovered by Verify.ly shows that attackers would have been able to intercept user login credentials on older versions of the clients. After having disclosed the vulnerabilities to both companies, it appears that the security holes have been fixed appropriately.
Security researcher and former NSA staffer Patrick Wardle is this afternoon demonstrating a way for Mac malware to tap into live feeds from the built-in webcam and microphone. His presentation is being delivered at the Virus Bulletin conference in Denver later today.
Although any unauthorized access to the webcam will light the green LED – a firmware-level protection that is exceedingly difficult to bypass – Wardle’s presentation shows how a malicious app can tap into the outgoing feed of an existing webcam session, like a FaceTime or Skype call, where the light would already be on …
Apple hasn’t often made appearances at the Black Hat hacker conference, but this year Cupertino is Thinking Different™ about security. Head of Apple security, Ivan Krstic, today said the company would pay huge (up to $200K) bug bounties to invited researchers who find and report vulnerabilities in certain Apple software.
A quick breakdown of max. payments:
Secure boot firmware: $200,000
Extraction of confidential material protected by the Secure Enclave Processor: $100,000
Execution of arbitrary code w/kernel privs: $50,000
Unauthorized access to iCloud account data on Apple Servers: $50,000
Access from a sandboxed process to user data outside of that sandbox: $25,000
Apple is planning on discussing various aspects of iOS 10 security in “unprecedented detail” at the upcoming BlackHat USA 2016 security conference. Ivan Krstic, head of Apple Security Engineering and Architecture, will give a 50-minute briefing to discuss cryptographic design, the Secure Enclave found in Touch ID-enabled devices, and a new JIT hardening mechanism in iOS 10. Expand Expanding Close
During Apple’s WWDC 2016 session What’s New in Security, the company shared two interesting changes to the way Gatekeeper works in macOS Sierra – one visible, one not.
While Apple introduced its App Transport Security feature in iOS 9, which ensured that all connections between apps and servers must be encrypted, it wasn’t compulsory for developers to use it – and Google even helped them disable it.
All this will end on January 1st next year, reports TechCrunch, when Apple will require all apps to use HTTPS connections to servers to ensure that only encrypted data is transmitted …
There are a ton of deals on tech and more right now in the lead up to Father’s Day. Together with 9to5Toys & Canary, we’re keeping track of all the best deals and we’ve collected all the handy links in the hub below.
Bookmark this page and keep checking back for more as we add the latest from 9to5Toys ahead of Father’s Day on June 19.
Even though Apple’s fight over the San Bernardino iPhone is essentially over, the overall debate regarding encryption versus national security remains. In an effort to continue to beef up security options on consumer devices, Reuters today reports that Apple has rehired well-respected security expert Jon Callas. News of this hire comes as we’re hearing from sources that Apple is in the midst of entirely overhauling its security team.