Skip to main content

Security

See All Stories

How to protect your iCloud account, as some hacked credentials confirmed valid

Site default logo image

While the available evidence suggests that hackers have not gained direct access to more than 600 million iCloud accounts, some of the sample login credentials supplied by the group have been found to be valid. ZDNet, for example, used Apple’s password reset function to test 54 logins supplied by the hackers, and found that all of them worked.

Apple has said that there have been no breaches of its own systems, and that the credentials likely came from ‘previously compromised third-party services.’ Most of the account owners contacted by ZDNet lent weight to this claim …


Expand
Expanding
Close

Site default logo image

Tablets & laptops banned from cabin baggage on flights to USA from 10 airports

Dubai International is one of the airports affected by the ban

Update: The UK has implemented a similar ban, though restricted to six rather than eight countries. The UK ban applies to flights to the UK from Turkey, Lebanon, Jordan, Egypt, Tunisia and Saudi Arabia.

The U.S. government has announced a ban on carrying tablets, laptops and other ‘large electronic devices’ in cabin baggage on flights to the USA from 10 airports. The measure is said to be in response to intelligence on terrorism threats from eight countries, mostly Middle Eastern and North African, reports the BBC.


Expand
Expanding
Close

Two zero-day Safari vulnerabilities uncovered by white-hat hackers at security conference

Site default logo image

Security researches competing at the annual Pwn2own conference yesterday uncovered two zero-day vulnerabilities in Safari. Two teams successfully exploited the bugs they found to achieve root access to macOS, while a third attempt failed.

Eleven teams are competing for a total $1M prize pot, with three of the ten attempts to date targeting Safari …


Expand
Expanding
Close

Site default logo image

WhatsApp & Telegram vulnerabilities allowed attackers to gain full control of accounts [U]

Update: Telegram has issued a statement to the fixed vulnerability.

A recently disclosed vulnerability by Check Point proved that both WhatsApp and Telegram were susceptible to particularly nefarious online attacks. While most attacks only garner tidbits of user data, these allowed attackers to gain full control of user accounts. Once in, attackers could download previously shared photos, contact information, and even more importantly gain access to a user’s friends accounts as well. Both companies acknowledged and released fixes to help patch the web client vulnerabilities.


Expand
Expanding
Close

PSA: Here’s how to secure your Twitter account against hijacks like today’s Nazi one

Site default logo image

Thousands of Twitter users have this morning had their accounts hijacked and used to tweet a swastika and Nazi hashtags. The attack appears to be in support of Turkey’s President, urging support for a referendum which could allow President Erdoğan to remain in power until 2029.

The Verge reports that many verified and high-profile Twitter accounts were compromised, and that the hijack appears to have been carried out via a third-party app.

Accounts operated by Amnesty International, Duke University, Reuters Japan, and BBC North America were among those hijacked. Several users have noted that all hijacked tweets appear to have been linked to Twitter Counter, a Netherlands-based analytics application. Twitter Counter was previously targeted in a November 2016 attack that caused some high-profile accounts to spread spam. 

Twitter confirmed that a third-party app was behind the hack, so checking which apps have permission to access your Twitter account is one important step to take. Here’s a quick checklist to check the security of Twitter and other services …


Expand
Expanding
Close

Apple hires Jonathan Zdziarski, an active forensics consult & security researcher in the iOS community

Site default logo image

Apple has hired Jonathan Zdziarski, a forensics consult and security researcher who has been heavily involved in the iOS security community. Zdziarski was notably vocal during Apple’s conflict with the FBI last year, offering his technical expertise against claims being made by the government.


Expand
Expanding
Close

CIA has hacking unit devoted to iOS malware; has lost control of most of it – Wikileaks [U]

Site default logo image

Update: Edward Snowden has tweeted that the code names are real and would only be known by a cleared insider. The BBC has reported that some of the iOS malware allows ‘the agency to see a target’s location, activate their device’s camera and microphone, and read text communications.’

Wikileaks claims that the U.S. Central Intelligence Agency has a specialized unit within its Center for Cyber Intelligence that is devoted to developing and obtaining zero-day exploits for iOS devices. A zero-day exploit is one unknown to Apple or security researchers, so cannot specifically be protected against.

Despite iPhone’s minority share (14.5%) of the global smart phone market in 2016, a specialized unit in the CIA’s Mobile Development Branch produces malware to infest, control and exfiltrate data from iPhones and other Apple products running iOS, such as iPads. CIA’s arsenal includes numerous local and remote “zero days” developed by CIA or obtained from GCHQ, NSA, FBI or purchased from cyber arms contractors such as Baitshop. The disproportionate focus on iOS may be explained by the popularity of the iPhone among social, political, diplomatic and business elites.

Wikileaks further claims that the CIA recently ‘lost control’ of the majority of the malware used to attack iPhones and iPads …


Expand
Expanding
Close

Exploit that caused iPhones to repeatedly dial 911 reveals grave cybersecurity threat, say experts

Site default logo image

We reported back in October on an iOS exploit that caused iPhones to repeatedly dial 911 without user intervention. It was said then that the volume of calls meant one 911 center was in ‘immediate danger’ of losing service, while two other centers had been at risk – but a full investigation has now concluded that the incident was much more serious than it appeared at the time.

It was initially thought that a few hundred calls were generated in a short time, but investigators now believe that one tweeted link that activated the exploit was clicked on 117,502 times, each click triggering a 911 call. The WSJ reports that law-enforcement officials and 911 experts fear that a targeted attack using the same technique could prove devastating …


Expand
Expanding
Close

Cloudflare security breach exposes data from Uber, Fitbit, OKCupid among 3,400 websites; password changes recommended [U]

Site default logo image

Update 1: See list of sites below.

Update 2: We received a brief statement from Uber

Very little Uber traffic goes through Cloudflare. Only a handful of tokens were involved and have since been changed. Passwords were not exposed.

Update 3: OKCupid has made a similar statement

Cloudflare alerted us last night of their bug and we’ve been looking into its impact on OkCupid members. Our initial investigation has revealed minimal, if any, exposure. If we determine that any of our users has been impacted we will promptly notify them and take action to protect them.

User data from 3,400 websites has been leaked and cached by search engines as a result of a bug in Cloudflare, a content delivery network. Sites affected over the course of several months include major ones like Uber, Fitbit and dating site OKCupid. 1Password also uses Cloudflare, but says that end-to-end encryption means that no customer data was exposed.

ArsTechnica reports that the leaks were spotted by Google security researcher Tavis Ormandy.

We observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major cloudflare-hosted sites from other users. Once we understood what we were seeing and the implications, we immediately stopped and contacted cloudflare security.

Cloudflare has admitted that the breach occurred, but Ormandy and other security researchers believe the company is underplaying the severity of the incident …


Expand
Expanding
Close

Popular apps with 18 million combined downloads in the App Store found vulnerable to silent data interception

Site default logo image

After scanning through the binary codes of applications in the iOS App Store, Will Strafach’s verify.ly service has detected that 76 popular apps in the store are currently vulnerable to data interception. The interception is possible regardless if App Store developers are using App Transport Security or not. A few months ago, similar vulnerabilities were discovered with Experian and myFICO Mobile’s iOS apps.


Expand
Expanding
Close

Hacker claims to have accessed some data from security firm hired by FBI to unlock San Bernardino shooter’s iPhone 5c

Site default logo image

When Apple refused to compromise iOS security last year and unlock the iPhone 5c belonging to the San Bernardino shooter, the FBI turned to an Israeli mobile forensics firm called Cellebrite to find a way in to the encrypted iPhone. Now Motherboard reports that a hacker has released files allegedly from Cellebrite that demonstrate how cracking tools can’t be kept private.


Expand
Expanding
Close

Security backdoor found in end-to-end encryption system used in WhatsApp [Updated]

Site default logo image

Update: Updated with a response from WhatsApp, below.

A security researcher has found a backdoor in the end-to-end encryption system used by the WhatsApp messaging service. The vulnerability would allow Facebook to read messages sent through the supposedly-secure system, as well as making it possible for the company to comply with court orders to make messages available to government bodies.

While end-to-end encryption would normally mean that not even the company operating the service can decrypt messages, only the intended recipient, the specific implementation used in WhatsApp includes a major security hole …


Expand
Expanding
Close

Site default logo image

Apple extends deadline for app developers to switch to HTTPS server connectivity

Over the summer, Apple informed developers that all apps would be required to securely connect to servers by January 1st, 2017. The announcement came as part of the App Transport Security feature in iOS 9. This evening, however, Apple announced that it is extending the deadline for developers to make the switch to HTTPS connectivity…


Expand
Expanding
Close

Because 500M hacked accounts weren’t enough, Yahoo reveals that 1B accounts were hacked in a separate case

Site default logo image

Yahoo today has announced its second large hack in a matter of 3 months. In a post on the company’s Tumblr account, Yahoo’s chief information security officer Bob Lord announced that, in 2013, data from more than 1 billion user accounts was accessed by an unauthorized third-party. This revelation comes after Yahoo confirmed in September that 500 million user accounts were affected by a separate data breach.


Expand
Expanding
Close

Site default logo image

Enterprise software firm Jamf notes that iOS MDM can allevate security concerns in ‘mobility in healthcare’ report

A new independent report titled ‘A Pulse on Mobility in Healthcare’ has been published by Apple device management software firm Jamf, who also commissioned the survey. Not surprisingly, the global tally of 550 IT decision makers found that security is the number one concern for healthcare systems who manage mobile devices among other details.


Expand
Expanding
Close

PSA: Security vulnerability discovered, update your Experian and myFICO Mobile iOS apps ASAP

Site default logo image

iphone-7-home-button-explained

If you’re not one to use iOS’ automatic updates feature, make sure to grab the latest updates for Experian – Free Credit Report and myFICO Mobile. A security vulnerability discovered by Verify.ly shows that attackers would have been able to intercept user login credentials on older versions of the clients. After having disclosed the vulnerabilities to both companies, it appears that the security holes have been fixed appropriately.


Expand
Expanding
Close

Former NSA staffer demonstrates Mac malware that can tap into live webcam and mic feeds

Site default logo image

Security researcher and former NSA staffer Patrick Wardle is this afternoon demonstrating a way for Mac malware to tap into live feeds from the built-in webcam and microphone. His presentation is being delivered at the Virus Bulletin conference in Denver later today.

Although any unauthorized access to the webcam will light the green LED – a firmware-level protection that is exceedingly difficult to bypass – Wardle’s presentation shows how a malicious app can tap into the outgoing feed of an existing webcam session, like a FaceTime or Skype call, where the light would already be on …


Expand
Expanding
Close

Apple announces its first security bounty program at Black Hat 2016 with up to $200K payouts

Site default logo image

Apple hasn’t often made appearances at the Black Hat hacker conference, but this year Cupertino is Thinking Different™ about security.  Head of Apple security, Ivan Krstic, today said the company would pay huge (up to $200K) bug bounties to invited researchers who find and report vulnerabilities in certain Apple software.

A quick breakdown of max. payments:

  • Secure boot firmware: $200,000
  • Extraction of confidential material protected by the Secure Enclave Processor: $100,000
  • Execution of arbitrary code w/kernel privs: $50,000
  • Unauthorized access to iCloud account data on Apple Servers: $50,000
  • Access from a sandboxed process to user data outside of that sandbox: $25,000

Earlier this year, the FBI paid out under $1M to extract the data from the San Bernardino terrorist’s iPhone. Perhaps Apple is trying to eliminate these lucrative back doors into its crown jewel software. 
Expand
Expanding
Close

Apple’s security chief to go behind the scenes of iOS security during upcoming BlackHat USA 2016 briefing

Site default logo image

Apple is planning on discussing various aspects of iOS 10 security in “unprecedented detail” at the upcoming BlackHat USA 2016 security conference. Ivan Krstic, head of Apple Security Engineering and Architecture, will give a 50-minute briefing to discuss cryptographic design, the Secure Enclave found in Touch ID-enabled devices, and a new JIT hardening mechanism in iOS 10.
Expand
Expanding
Close

Apple tells developers all apps must connect securely to servers by January 1st, 2017

Site default logo image

While Apple introduced its App Transport Security feature in iOS 9, which ensured that all connections between apps and servers must be encrypted, it wasn’t compulsory for developers to use it – and Google even helped them disable it.

All this will end on January 1st next year, reports TechCrunch, when Apple will require all apps to use HTTPS connections to servers to ensure that only encrypted data is transmitted …


Expand
Expanding
Close

Father’s Day Gift Guide Hub: One Place with all the best deals

Canary-Home-Hero

There are a ton of deals on tech and more right now in the lead up to Father’s Day. Together with 9to5Toys & Canary, we’re keeping track of all the best deals and we’ve collected all the handy links in the hub below.

Bookmark this page and keep checking back for more as we add the latest from 9to5Toys ahead of Father’s Day on June 19.


Expand
Expanding
Close

Apple rehires respected encryption expert as it works to overhaul entire security team

Site default logo image

Even though Apple’s fight over the San Bernardino iPhone is essentially over, the overall debate regarding encryption versus national security remains. In an effort to continue to beef up security options on consumer devices, Reuters today reports that Apple has rehired well-respected security expert Jon Callas. News of this hire comes as we’re hearing from sources that Apple is in the midst of entirely overhauling its security team.


Expand
Expanding
Close