Security Lacking in Previous AppleAVEDriver iOS Kernel Extension

An obscure Apple kernel extension patched in iOS 10.3.3 was originally built without security measures in place, according to the researcher who privately disclosed the flaws. Continue reading Security Lacking in Previous AppleAVEDriver iOS Kernel Extension

Deprecated, Insecure Apple Authorization API Can Be Abused to Run Code at Root

An insecure Apple authorization API is used by numerous popular third-party application installers and can be abused by attackers ro run code as root. Continue reading Deprecated, Insecure Apple Authorization API Can Be Abused to Run Code at Root

Deprecated, Insecure Apple Authorization API Can Be Abused to Run Code at Root

An insecure Apple authorization API is used by numerous popular third-party application installers and can be abused by attackers ro run code as root. Continue reading Deprecated, Insecure Apple Authorization API Can Be Abused to Run Code at Root

Zerodium Offers $500K for Secure Messaging App Zero Days

Zerodium announced new $500,000 payouts for zero days in secure messaging apps such as Signal, WhatsApp and others. Continue reading Zerodium Offers $500K for Secure Messaging App Zero Days

Business Email Compromise Campaign Harvesting Credentials in Numerous Industries

Flashpoint warns of a new business email compromise campaign targeting organizations in various industries with the aim of harvesting credentials. Continue reading Business Email Compromise Campaign Harvesting Credentials in Numerous Industries

Android Spyware Linked to Chinese SDK Forces Google to Boot 500 Apps

More than 500 Android mobile apps have been removed from Google Play after it was discovered that an embedded advertising SDK called Igenix could be leveraged to quietly install spyware on devices. Continue reading Android Spyware Linked to Chinese SDK Forces Google to Boot 500 Apps

Industrial Cobots Might Be The Next Big IoT Security Mess

Researchers at IOActive are sounding an early alarm on the security of industrial collaboration robots, or cobots. These machines work side-by-side with people and contain vulnerabilities that could put physical safety at risk. Continue reading Industrial Cobots Might Be The Next Big IoT Security Mess

Meeting and Hotel Booking Provider’s Data Found in Public Amazon S3 Bucket

Personal and business data belonging to Boston area meeting and hotel booking provider Groupize was discovered in a publicly accessible Amazon Web Services S3 bucket, which has since been locked down. Continue reading Meeting and Hotel Booking Provider’s Data Found in Public Amazon S3 Bucket

Meeting and Hotel Booking Provider’s Data Found in Public Amazon S3 Bucket

Personal and business data belonging to Boston area meeting and hotel booking provider Groupize was discovered in a publicly accessible Amazon Web Services S3 bucket, which has since been locked down. Continue reading Meeting and Hotel Booking Provider’s Data Found in Public Amazon S3 Bucket