Posts

Showing posts with the label iPhone

Apple allegedly cripples its own web apps on purpose

By Jak Connor,  Tweaktown Apple has been accused of "intentionally crippling" web apps, so users are forced into downloading native search apps such as Safari. The accusations come from Telegram founder Pavel Durov, who explained in a post that web apps on iPhone are forced to use WebKit to develop web-based apps, and within this WebKit are a slew of problems that Apple has reportedly ignored for approximately 15 years. Apple guidelines dictate that all apps listed on the App Store are prevented from unrestricted public channels, hence developers turning to web-based applications as a workaround. The Telegram founder says Apple forces developers to use WebKit for all browsers on iOS, which means users can't simply download Firefox or Chrome to get around the issues. Additionally, since no improvements are being issued for the WebKit so developers can improve the performance/experience of web-based apps, it seems that Apple is attempting to steer users to Safari where it c...

North Korean IT Workers Are Infiltrating Tech Companies

Plus: The Conti ransomware gang shuts down, Canada bans Huawei and ZTE, and more of the week’s top security news. By Matt Burgess, Wired As Russia's full-scale war in Ukraine heads towards its hundredth day, opposition from Ukrainian forces is as strong as ever. At the same time, hacktivists all around the world continue to breach Russian institutions and publish their files and emails. This week one hacktivist collective took a different—and slightly peculiar—approach: launching a service to prank-call Russian government officials. The new website uses leaked details to put two random Russian officials on a call with each other. It obviously won't make any difference to the outcome of the war, but the group that created it hopes the tool will cause some confusion and annoy those in Moscow. New research from Google’s Threat Analysis Group has delved into the surveillance-for-hire industry and found that spyware vendors are targeting Android devices with zero-day exploits. State...

What is ‘New Profile Pic’ app? Is it safe to use? Cybersecurity experts weigh in

Image
By Geoff Herbert, Penn Live If you’ve seen new Facebook profile pictures that look like a painting or cartoon, then you’ve probably noticed they all appear to come from a website and app called “New Profile Pic.” New Profile Pic, also sometimes written as one word “NewProfilePic,” allows users to submit photos of themselves for an “AI-driven” update that makes them look like works of art. The free app is currently No. 1 on the Apple Store and has exploded in popularity on social media this month. But some have also questioned its safety after some claimed the app “takes all your information and sends it to Moscow” as part of a Russian malware scam. The Daily Mail further suggested the app had Kremlin ties because it was developed by a tech company “overlooking the Moscow River three miles from Red Square,” but is that true? According to fact-checking website Snopes , New Profile Pic was created by a mobile development group called Informe Laboratories, Inc. , and copyrighted by Liner...

Newly found zero-click iPhone exploit used in NSO spyware attacks

Image
By Sergiu Gatlan, Bleeping Computers Digital threat researchers at Citizen Lab have discovered a new zero-click iMessage exploit used to install NSO Group spyware on iPhones belonging to Catalan politicians, journalists, and activists. The previously unknown iOS zero-click security flaw dubbed HOMAGE affects some versions before iOS 13.2 (the latest stable iOS version is 15.4). It was used in a campaign targeting at least 65 people with NSO's Pegasus spyware between 2017 and 2020, together with the Kismet iMessage exploit and a WhatsApp flaw. Among the victims of these attacks, Citizen Lab mentioned Catalan Members of the European Parliament (MEPs), every Catalan president since 2010, as well as Catalan legislators, jurists, journalists, and members of civil society organizations and their families. "Among Catalan targets, we did not see any instances of the HOMAGE exploit used against a device running a version of iOS greater than 13.1.3. It is possible that the exploit was f...