Forum Moderators: travelin cat

Message Too Old, No Replies

Apple Issues Emergency Security Updates to Close a Spyware Flaw

         

travelin cat

7:28 pm on Sep 13, 2021 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Researchers at Citizen Lab found that NSO Group, an Israeli spyware company, had infected Apple products without so much as a click.

[nytimes.com...]

not2easy

4:17 am on Sep 14, 2021 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Apple offers more information on the potentially affected devices and about the security content of iOS 14.8 and iPadOS 14.8: [support.apple.com...]

Robert Charlton

10:51 am on Sep 14, 2021 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Readers should be aware that the New York Times has a metered paywall which gives web users a limited number of free monthly views. Whether it affects you may depend on how much you use the web for news.

For those interested, Associated Press has a detailed article on this exploit, now named "FORCEDENTRY". The spyware exploited a vulnerability in Apple's iMessage instant messaging app. The article reports that IM apps have become a major vector for attacking phones, with international espionage the specific application that's led to the development of the NSO software used...

Apple fixes security hole reportedly used to hack an iPhone
Sept 13, 2021
[apnews.com...]

Here are some excerpts that might be of broad interest....
Although security experts say that average iPhone, iPad and Mac user generally need not worry — such attacks tend to be limited to specific targets — the discovery still alarmed security professionals.

Malicious image files were transmitted to the activist’s phone via the iMessage instant-messaging app before it was hacked with NSO’s Pegasus spyware, which opens a phone to eavesdropping and remote data theft, Marczak said. It was discovered during a second examination of the phone, which forensics showed had been infected in March. He said the malicious file causes devices to crash....

...Citizen Lab called the iMessage exploit FORCEDENTRY and said it was effective against Apple iOS, MacOS and WatchOS devices. It urged people to immediately install security updates.

Researcher John Scott-Railton said the news highlights the importance of securing popular messaging apps against such attacks. “Chat apps are increasingly becoming a major way that nation-states and mercenary hackers are gaining access to phones,” he said. “And it’s why it’s so important that companies focus on making sure that they are as locked down as possible.”