Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • Technology

Apple fixes zero-day bugs used to plant Pegasus spyware

  • September 7, 2023
Total
0
Shares
0
0
0

Apple released security updates on Thursday that patch two zero-day exploits — meaning hacking techniques that were unknown at the time Apple found out about them — used against a member of a civil society organization in Washington D.C., according to the researchers who found the vulnerabilities.

Citizen Lab, an internet watchdog group that investigates government malware, published a short blog post explaining that last week they found a zero-click vulnerability — meaning that the hackers’ target doesn’t have to tap or click anything, such as an attachment — used to target victims with malware. The researchers said the vulnerability was used as part of an exploit chain designed to deliver NSO Group’s malware, known as Pegasus.

“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” Citizen Lab wrote.

Once they found the vulnerability, the researchers reported it to Apple, which released a patch on Thursday, thanking Citizen Lab for reporting them.

Based on what Citizen Lab wrote in the blog post, and the fact that Apple also patched another vulnerability and attributed its finding to the company itself, it appears Apple may have found the second vulnerability while investigating the first.

When reached for comment, Apple spokesperson Scott Radcliffe did not comment and referred TechCrunch to the notes in the security update.

Citizen Lab said it called the exploit chain BLASTPASS, because it involved PassKit, a framework that allows developers to include Apple Pay in their apps.

“Once more, civil society, is serving as the cybersecurity early warning system for… billions of devices around the world,” John Scott-Railton, a senior researcher at the internet watchdog Citizen Lab, wrote on Twitter.

Citizen Lab recommended all iPhone users to update their phones.


Do you have more information about NSO Group or another surveillance tech provider? Or information about similar hacks? We’d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Wickr, Telegram and Wire @lorenzofb, or email [email protected]. You can also contact TechCrunch via SecureDrop.




Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

FCC finally gets its 5th Commissioner in Anna Gomez

  • September 7, 2023
View Post
Next Article
  • News

Microsoft-backed AI startup beats Nvidia H100 on key tests with GPU-like card equipped with 256GB RAM

  • September 7, 2023
View Post
You May Also Like
View Post
  • Technology

Elon Musk threatens to charge for X, OpenAI launches DALL-E 3 and Cisco acquires Splunk

  • September 23, 2023
View Post
  • Technology

Disability tech startups kill the cynic in me

  • September 23, 2023
View Post
  • Technology

Walmart’s PhonePe launches app store with zero fee in challenge to Google

  • September 23, 2023
View Post
  • Technology

How CFOs can reduce SaaS spend by 30% in these tough times

  • September 22, 2023
View Post
  • Technology

LimeLoop’s sleek reusable mailers seek to replace cardboard boxes

  • September 22, 2023
View Post
  • Technology

AquaLith might have an answer to the US battery material shortage problem

  • September 22, 2023
View Post
  • Technology

Bay Area baby belly beholding Battlefield bounty

  • September 22, 2023
View Post
  • Technology

Unity U-turns on controversial runtime fee and begs forgiveness

  • September 22, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.