Posts

Showing posts with the label Apple

Why remote desktop tools are facing an onslaught of cyber threats

Image
By Solomon Klappholz, IT Pro Hackers are increasingly targeting remote desktop tools in their attacks, new research reveals, prompting warnings for enterprises globally In the era of hybrid work, remote desktop tools have become vital business enablers, but due to their pervasiveness on corporate networks they have become a popular entry point for cyber criminals. If successfully exploited, remote access tools can provide hackers with a direct pathway into a system or network, and once access is gained attackers can move laterally within the network, escalating privileges and maintaining persistence. In an investigation into which remote desktop tools are targeted the most, Jonathan Tanner, senior security researcher at Barracuda Networks, explained that remote desktop software poses a particular challenge to IT teams to secure. “Among the security challenges facing IT teams implementing remote desktop software is that there are many different tools available, each using different and ...

Recent ‘MFA Bombing’ Attacks Targeting Apple Users

Image
By  KrebsOnSecurity Several Apple customers recently reported being targeted in elaborate phishing attacks that involve what appears to be a bug in Apple’s password reset feature. In this scenario, a target’s Apple devices are forced to display dozens of system-level prompts that prevent the devices from being used until the recipient responds “Allow” or “Don’t Allow” to each prompt. Assuming the user manages not to fat-finger the wrong button on the umpteenth password reset request, the scammers will then call the victim while spoofing Apple support in the caller ID, saying the user’s account is under attack and that Apple support needs to “verify” a one-time code. Parth Patel is an entrepreneur who is trying to build a startup in the conversational AI space. On March 23, Patel documented on Twitter/X a recent phishing campaign targeting him that involved what’s known as a “push bombing” or “MFA fatigue” attack, wherein the phishers abuse a feature or weakness of a multi-factor au...

Apple allegedly cripples its own web apps on purpose

By Jak Connor,  Tweaktown Apple has been accused of "intentionally crippling" web apps, so users are forced into downloading native search apps such as Safari. The accusations come from Telegram founder Pavel Durov, who explained in a post that web apps on iPhone are forced to use WebKit to develop web-based apps, and within this WebKit are a slew of problems that Apple has reportedly ignored for approximately 15 years. Apple guidelines dictate that all apps listed on the App Store are prevented from unrestricted public channels, hence developers turning to web-based applications as a workaround. The Telegram founder says Apple forces developers to use WebKit for all browsers on iOS, which means users can't simply download Firefox or Chrome to get around the issues. Additionally, since no improvements are being issued for the WebKit so developers can improve the performance/experience of web-based apps, it seems that Apple is attempting to steer users to Safari where it c...

MIT Researchers Find New “Unpatchable” Vulnerability In Apple’s M1 Chip

Image
By Kavita Iyer, Tech Worm Researchers at MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) in a new paper have exposed an “untraceable” hardware vulnerability in Apple’s most powerful chip to date, the M1. The M1 chip implements a security feature called “Pointer Authentication”, which acts as the “last line of security” against memory corruption exploits on the M1 SoC. For the unversed, Pointer authentication works by offering a special CPU instruction to add a cryptographic signature — or Pointer Authentication Code (PAC) — to unused high-order bits of a pointer before storing the pointer. With Pointer Authentication enabled, bugs that normally could compromise a system or leak private information are stopped dead in their tracks. Now, researchers from MIT’s CSAIL have designed a new attack dubbed “PACMAN”, which relies on a combination of software and hardware exploits, to defeat PAC. PACMAN allows attackers to prevent the M1 chip from detecting software vulnerab...

How Can AI Ease Privacy Concerns? Generating First-Party Data and More!

Image
By Griffin Davis, Tech Times Experts claim that AI can actually ease the rising privacy concerns over the internet. This may be true given that artificial intelligence has been applied in various technologies that make life easier.   Google, Apple, and other giant tech firms rely on AI and machine learning innovations to further enhance their products.  On the other hand, artificial intelligence was also used to create self-driving cars and drug development. All these details show that AI can be used in many things, including online security.  How Can AI Ease Privacy Concerns? Venture Beat reported that AI could be used to enhance online privacy. While protecting internet cybersecurity, artificial intelligence can also make your online activities easier, such as shortening online processes by re-entering your needed information.  Now, here are some ways how AI can transform the internet into a safer online place:  AI can be used to generate first-part...

How Google passwordless sign-in will work

Image
By Chris Smith, BGR The first Thursday of May each year is World Password Day, which explains all the password-related announcements we saw this week. First, 1Password 8 for Mac launched with a few big new features. Then, Google started rolling out its Google Assistant password-changing feature. More importantly, Apple, Google, and Microsoft have announced plans to support passwordless sign-in . That last one is a massive cross-platform initiative that will bring us closer to killing passwords. In turn, this could significantly boost the security of online accounts, making them a lot harder to hack. It’ll take some time for websites and apps to support passwordless sign-in. But Google already gave us an idea of how it’ll all work. Proper password practices can help prevent hacks right now. You don’t need passwordless sign-in options if you’re already using unique, long passwords in connection with a password manager like 1Password or LastPass. These passwords are much harder to hack, e...

Apple, Google, Microsoft announce plans to drop passwords

Image
By Katie Smith, Paul Gerke, News Nation Now Apple, Google and Microsoft announced plans on Thursday to eliminate passwords and replace them with other secure sign-in methods. The announcement came just before World Password Day, which is recognized annually on the first Thursday of May. It highlights the use of safe password habits, but some major tech companies say password-only authentication is of the biggest security problems on the web. “Fundamentally, what we’re doing is letting you use your everyday device — the same thing that you do multiple times a day — to unlock your device now to log in, in a way that is just leaps and bounds more secure than anything that you’re doing today,” said Megan Shamas, a spokesperson for FIDO, the authentication company leading the charge. Together, Apple, Google and Microsoft plan to follow a standard created by the FIDO Alliance and the World Wide Web Consortium . That means that websites and apps could offer an “end-to-end passwordless op...

Fighting Fake EDRs With ‘Credit Ratings’ for Police

Image
By  KrebsOnSecurity When KrebsOnSecurity recently explored how cybercriminals were using hacked email accounts at police departments worldwide to obtain warrantless Emergency Data Requests (EDRs) from social media firms and technology providers, many security experts called it a fundamentally unfixable problem. But don’t tell that to Matt Donahue, a former FBI agent who recently quit the agency to launch a startup that aims to help tech companies do a better job screening out phony law enforcement data requests — in part by assigning trustworthiness or “credit ratings” to law enforcement authorities worldwide. A sample Kodex dashboard Image: Kodex.us Donahue is co-founder of Kodex , a company formed in February 2021 that builds security portals designed to help tech companies “manage information requests from government agencies who contact them, and to securely transfer data & collaborate against abuses on their platform.” The 30-year-old Donahue said he left the FBI in April ...

Newly found zero-click iPhone exploit used in NSO spyware attacks

Image
By Sergiu Gatlan, Bleeping Computers Digital threat researchers at Citizen Lab have discovered a new zero-click iMessage exploit used to install NSO Group spyware on iPhones belonging to Catalan politicians, journalists, and activists. The previously unknown iOS zero-click security flaw dubbed HOMAGE affects some versions before iOS 13.2 (the latest stable iOS version is 15.4). It was used in a campaign targeting at least 65 people with NSO's Pegasus spyware between 2017 and 2020, together with the Kismet iMessage exploit and a WhatsApp flaw. Among the victims of these attacks, Citizen Lab mentioned Catalan Members of the European Parliament (MEPs), every Catalan president since 2010, as well as Catalan legislators, jurists, journalists, and members of civil society organizations and their families. "Among Catalan targets, we did not see any instances of the HOMAGE exploit used against a device running a version of iOS greater than 13.1.3. It is possible that the exploit was f...

Apple AirTag stalking is worse than anyone realized — what you can do

Image
AirTag stalking could be worse than we thought, but there are things you can do to protect yourself By Tom Pritchard Ever since the launch of Apple's AirTags last year, we’ve been hearing stories about how they’re being used for an unintended purpose: stalking. It's been a particular problem for women, and now it seems it may be even more serious than people realized. So much so that it could be time to take Apple AirTags off the market. That's according to research by Motherboard(opens in new tab), which got hold of reports from eight major police departments, covering a period of eight months. In that time there were 150 reports that mentioned AirTags, 50 of which came from women who had received notifications that a rogue AirTag was tracking them. Half of those 50 women suspected a man in their lives may have been responsible for planting the AirTag — with the goal of following and harassing them. In one case, a woman had called the police because a man had escalated his...