Apple patches zero-day flaw that hackers may have exploited

Apple has released updates for its mobile, iPad and computer operating systems, fixing a zero-day flaw that appears to be the subject of active exploitation. The patch comes mere days after another update that tackled 40 vulnerabilities. The latest software update comes in the wake of reports that the Israeli spyware firm NSO Group had developed a hacking tool that helps its customers remotely compromise iOS systems. Whether the patch address those technical issues was not immediately clear. Apple did not immediately respond to a request for comment. The prior Apple update did not address the NSO Group exploits. The iOS 14.7.1, iPadOS 14.7.1 and Big Sur 11.5.1 patch notes are likewise mum, other than to say that an anonymous researcher brought the vulnerability to Apple’s attention. The issue involved improper access to kernel mode, which a hacker could have abused to access the underlying hardware on a device, and […]

The post Apple patches zero-day flaw that hackers may have exploited appeared first on CyberScoop.

Continue reading Apple patches zero-day flaw that hackers may have exploited

Pegasus Spyware is Back, Twitter Hacker Arrested, 16 Year Old Printer Bug

Pegasus spyware and NSO Group are back in the news because of a data leak of 50,000 phone numbers, another “hacker” was arrested for the great Twitter hack of 2020, and how a 16 year old printer vulnerability is affecting millions of HP, Samsung, and X… Continue reading Pegasus Spyware is Back, Twitter Hacker Arrested, 16 Year Old Printer Bug

Smashing Security podcast #237: NuNa, NuNu, NaNa

Spy software known as Pegasus has been used to carry out surveillance on the smartphones of journalists, activists, and political leaders. Can a “Freedom Phone” be trusted? And a ransomware-hit law firm demonstrates how not to keep its cust… Continue reading Smashing Security podcast #237: NuNa, NuNu, NaNa

Apple’s Insecure iPhone Lets NSO Hack Journalists (Again)

Yet another zero-day bug in iOS has allowed notorious spyware vendor NSO Group to break into the iPhones of journalists and activists.
The post Apple’s Insecure iPhone Lets NSO Hack Journalists (Again) appeared first on Security Boulevard.
Continue reading Apple’s Insecure iPhone Lets NSO Hack Journalists (Again)

Sweeping report details how NSO Group spyware leverages iOS software for surveillance

NSO Group’s Pegasus spyware may be actively exploiting the most recent software in the iPhone 12 to monitor victims through the world, according to a sweeping new report from Amnesty International. “These most recent discoveries indicate NSO Group’s customers are currently able to remotely compromise all recent iPhone models and versions of iOS,” the group wrote in a report published on July 18. “We have reported this information to Apple, who informed us they are investigating the matter.” The revelation comes as part of a broader investigation into the use of the notorious spyware. Between July 2014 and July 2021, the NSO group’s Pegasus software was used to target more than three dozen smartphones belonging to journalists, human rights activists and business executives, according to a joint investigation between Amnesty, French journalism nonprofit Forbidden Stories and 17 media organizations including The Washington Post. Targets included Hatice Cengiz, fiancee of murdered […]

The post Sweeping report details how NSO Group spyware leverages iOS software for surveillance appeared first on CyberScoop.

Continue reading Sweeping report details how NSO Group spyware leverages iOS software for surveillance

Tech titans throw weight behind WhatsApp allegations in NSO surveillance lawsuit

Facebook’s lawsuit against Israeli software surveillance firm NSO Group just got a big boost from tech titans across the U.S. Microsoft, alongside Google, Cisco, GitHub, LinkedIn, VMWare and the Internet Association, filed an amicus brief Monday to join the lawsuit, which alleges that NSO Group exploited a vulnerability in WhatsApp last year to spy on thousands of users, such as journalists, dissidents and human rights activists. More filings from other companies and organizations are expected in the coming days. Access Now, Amnesty International, the Committee to Protect Journalists, Internet Freedom Foundation, Paradigm Initiative, Privacy International, Reporters Without Borders and Red en Defensa de los Derechos Digitales (R3D), are expected to file another amicus brief in support of WhatsApp on Wednesday, CyberScoop has learned. The suit, which Facebook’s WhatsApp filed last year, is currently under appeal in U.S. Court of Appeals for the Ninth Circuit. The Israeli firm’s lawyers have argued […]

The post Tech titans throw weight behind WhatsApp allegations in NSO surveillance lawsuit appeared first on CyberScoop.

Continue reading Tech titans throw weight behind WhatsApp allegations in NSO surveillance lawsuit

NSO ‘Pegasus’ Hacking Tool Targets Journalists Again

The NSO Group sells hacking paraphernalia to oppressive regimes. Its Pegasus tool set has been caught hacking journalists.
The post NSO ‘Pegasus’ Hacking Tool Targets Journalists Again appeared first on Security Boulevard.
Continue reading NSO ‘Pegasus’ Hacking Tool Targets Journalists Again

Tech Giants Lend WhatsApp Support in Spyware Case Against NSO Group

Google, Microsoft, Cisco Systems and others want appeals court to deny immunity to Israeli company for its alleged distribution of spyware and illegal cyber-surveillance activities. Continue reading Tech Giants Lend WhatsApp Support in Spyware Case Against NSO Group

Zero-Click Apple Zero-Day Uncovered in Pegasus Spy Attack

The phones of 36 journalists were infected by four APTs, possibly linked to Saudi Arabia or the UAE. Continue reading Zero-Click Apple Zero-Day Uncovered in Pegasus Spy Attack

Zero-click iPhone exploit, NSO Group spyware used to target Mideast journalists, Citizen Lab says

Hackers suspected to work for the governments of Saudi Arabia and the United Arab Emirates breached 36 devices belonging to Al Jazeera journalists in recent months by using a zero-click iPhone exploit and NSO Group spyware, according to new Citizen Lab research published Sunday. The suspected government hackers behind the operations had a particularly pernicious tactic for accessing their targets — an iPhone iMessage that requires zero interaction from the target to work, according to the researchers. Citizen Lab is based at the Munk School of Global Affairs and Public Policy at the University of Toronto. The hacking operations, which researchers attribute to the governments of Saudi Arabia and the UAE with “medium confidence,” could have allowed the operators to record audio, take pictures, track device location and access passwords or stored credentials on compromised phones, the researchers said. Qatar, where Al Jazeera is based, historically has a fraught relationship with […]

The post Zero-click iPhone exploit, NSO Group spyware used to target Mideast journalists, Citizen Lab says appeared first on CyberScoop.

Continue reading Zero-click iPhone exploit, NSO Group spyware used to target Mideast journalists, Citizen Lab says