Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS post, december 12, 2024december 13, 2024 Details have emerged about a now-patched security vulnerability in Apple’s iOS and macOS that, if successfully exploited, could sidestep the Transparency, Consent, and Control (TCC) framework and result in unauthorized access to sensitive information. The flaw, tracked as CVE-2024-44131 (CVSS score: 5.3), resides in the FileProvider component, per Apple, and has been… Continue Reading
NSO Group Exploited WhatsApp to Install Pegasus Spyware Even After Meta’s Lawsuit post, november 18, 2024 Legal documents released as part of an ongoing legal tussle between Meta’s WhatsApp and NSO Group have revealed that the Israeli spyware vendor used multiple exploits targeting the messaging app to deliver Pegasus, including one even after it was sued by Meta for doing so. They also show that NSO Group repeatedly… Continue Reading
Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware post, november 11, 2024november 14, 2024 Cybersecurity researchers have discovered a new phishing campaign that spreads a new fileless variant of known commercial malware called Remcos RAT. Remcos RAT “provides purchases with a wide range of advanced features to remotely control computers belonging to the buyer,” Fortinet FortiGuard Labs researcher Xiaopeng Zhang said in an analysis published last week…. Continue Reading
U.S. and Allies Warn of Iranian Cyberattacks on Critical Infrastructure in Year-Long Campaign post, oktober 18, 2024 Cybersecurity and intelligence agencies from Australia, Canada, and the U.S. have warned about a year-long campaign undertaken by Iranian cyber actors to infiltrate critical infrastructure organizations via brute-force attacks. “Since October 2023, Iranian actors have used brute force and password spraying to compromise user accounts and obtain access to organizations… Continue Reading
Iran’s APT34 Abuses MS Exchange to Spy on Gulf Gov’ts post, oktober 17, 2024juli 3, 2025 A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies. An Iranian threat actor has been ramping up its espionage against Gulf-state government entities, particularly those within the United Arab Emirates (UAE). APT34 (aka Earth Simnavaz, OilRig, MuddyWater, Crambus, Europium, Hazel Sandstorm)… Continue Reading
Google: 70% of exploited flaws disclosed in 2023 were zero-days post, oktober 16, 2024oktober 17, 2024 Google Mandiant security analysts warn of a worrying new trend of threat actors demonstrating a better capability to discover and exploit zero-day vulnerabilities in software. Specifically, of the 138 vulnerabilities disclosed as actively exploited in 2023, Mandiant says 97 (70.3%) were leveraged as zero-days. This means that threat actors exploited… Continue Reading
Apple Releases Critical iOS and iPadOS Updates to Fix VoiceOver Password Vulnerability post, oktober 5, 2024oktober 7, 2024 Apple has released iOS and iPadOS updates to address two security issues, one of which could have allowed a user’s passwords to be read out aloud by its VoiceOver assistive technology. The vulnerability, tracked as CVE-2024-44204, has been described as a logic problem in the new Passwords app impacting a slew of… Continue Reading
Chrome Security Vulnerabilities Let Attackers Execute Arbitrary Code post, oktober 3, 2024 Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could potentially allow attackers to execute arbitrary code on users’ systems. The latest stable channel update, version 129.0.6668.89/.90 for Windows and Mac and 129.0.6668.89 for Linux, is being rolled out to users worldwide. Continue Reading
PoC Exploit Released for Microsoft Office 0-day Flaw – CVE-2024-38200 post, oktober 3, 2024 Security researchers have released a proof-of-concept (PoC) exploit for the recently disclosed Microsoft Office vulnerability CVE-2024-38200, which could allow attackers to capture users’ NTLMv2 hashes. This high-severity flaw affects multiple versions of Microsoft Office, including Office 2016, Office 2019, Office LTSC 2021, and Microsoft 365 Apps for Enterprise. Continue Reading
Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign post, september 26, 2024september 26, 2024 Nation-state threat actors backed by Beijing broke into a “handful” of U.S. internet service providers (ISPs) as part of a cyber espionage campaign orchestrated to glean sensitive information, The Wall Street Journal reported Wednesday. The activity has been attributed to a threat actor that Microsoft tracks as Salt Typhoon, which is also… Continue Reading