BlastDoor: iOS 14’s Shield Over Zero-Click Attacks

Bizarrely, it’s Google that revealed the big change that came in iOS 14 last year.
The post BlastDoor: iOS 14’s Shield Over Zero-Click Attacks appeared first on Security Boulevard.
Continue reading BlastDoor: iOS 14’s Shield Over Zero-Click Attacks

iPhones of 36 Al Jazeera journalists hacked with NSO’s zero-click spyware

By Deeba Ahmed
Citizen Lab researchers claim the spyware was delivered silently through iMessage.
This is a post from HackRead.com Read the original post: iPhones of 36 Al Jazeera journalists hacked with NSO’s zero-click spyware
Continue reading iPhones of 36 Al Jazeera journalists hacked with NSO’s zero-click spyware

Report calls for web pre-screening to end UK’s child abuse ‘explosion’

The IICSA report cited “unprecedented levels of depravity” and said that encryption is getting in the way of current screening. Continue reading Report calls for web pre-screening to end UK’s child abuse ‘explosion’

Google hackers successfully use remote exploit to hack iPhone

By Waqas
From law enforcement to hacking firms everyone wants to hack iPhone security researchers at Google have done it again.
This is a post from HackRead.com Read the original post: Google hackers successfully use remote exploit to hack iPhone
Continue reading Google hackers successfully use remote exploit to hack iPhone

Google researcher beefs up iMessage security by demonstrating clickless exploit

Software exploits that don’t require a victim to click a link to be compromised are an intriguing and growing area of research for white-hat hackers. So it is no surprise that Google’s elite team of hackers, Project Zero, has dug into this stealthy mode of attack in recent months. On Thursday, Samuel Gross laid out how, armed with only a target’s Apple ID, he could remotely compromise an iPhone within minutes to steal passwords, text messages and emails, and activate the camera and microphone. The attack, which exploited an iOS 12.4 vulnerability for which Apple issued a patch in last August, shows how “small design decisions can have significant security consequences,” Gross wrote in a blog post. Gross poked holes in some conventional wisdom around security features used in the iPhone operating system. A data-randomizing security feature known as ASLR meant to guard against exploits “is not as strong in practice,” he […]

The post Google researcher beefs up iMessage security by demonstrating clickless exploit appeared first on CyberScoop.

Continue reading Google researcher beefs up iMessage security by demonstrating clickless exploit

Zerodium offers $2.5 million for Android zero-days, in keeping with market rates

For the first time, exploit sellers who provide Zerodium with fresh break-in techniques for Android devices can now earn more money from those tools than they would for similar hacks of iOS devices, the company announced Tuesday. The Washington, D.C., firm just updated its price list, promising to pay $2.5 million to hackers who demonstrate a zero-click exploit chain, a powerful tool that requires no user interaction, for Android devices. Compare that to the $1 million reward available for a one-click iOS full chain exploit against iOS, knocked down today from $1.5 million. Zerodium, founded in 2015, is dedicated to purchasing unpatched security vulnerabilities then re-selling those zero-days to corporate and government clients. It didn’t offer any specific explanations for the latest price changes. A security researcher who pays attention to the market said this round of updates might be pointing to some shifts in how Zerodium’s customers view iOS devices. “The change in exploit prices is […]

The post Zerodium offers $2.5 million for Android zero-days, in keeping with market rates appeared first on CyberScoop.

Continue reading Zerodium offers $2.5 million for Android zero-days, in keeping with market rates

BSides Las Vegas, iMessage Exploit, 5G and Stingray Surveillance

This is your Shared Security Weekly Blaze for August 12th 2019 with your host, Tom Eston. In this week’s episode: My summary of last week’s BSides Las Vegas security conference, how a single text message to your iPhone could get you hacked,… Continue reading BSides Las Vegas, iMessage Exploit, 5G and Stingray Surveillance

Smashing Security #139: Capital One hacked, iMessage flaws, and anonymity my ass!

Capital One gets hacked, critical vulnerabilities are found in iMessage, and data anonymization may not be as good as we hope. But listen up, we also discuss the Legend of Zelda, a biography of tech giants, offer advice for escaping an angry moose, and… Continue reading Smashing Security #139: Capital One hacked, iMessage flaws, and anonymity my ass!