Articles tagged "Apple"

Found 103 articles

Attackers are currently exploiting a vulnerability in SimpleHelp, identified as CVE-2026-48558, which allows for an authentication bypass. This vulnerability has been patched, but it is actively being used to deploy Djinn Stealer malware on victim systems. Djinn Stealer is a versatile piece of malware that targets various operating systems, including Windows, macOS, and Linux. It collects sensitive credentials from a wide range of applications, including cloud services, source control, and cryptocurrency wallets. The situation poses a significant risk to users of SimpleHelp, particularly managed service providers, as the malware can compromise sensitive data and systems.

Read Original

Researchers have identified six security vulnerabilities in AirDrop and Quick Share, features that allow users to share files wirelessly. An attacker within close proximity can exploit these flaws to crash the file-sharing services on devices like Macs and iPhones that are set to receive from anyone, without needing any prior connection or user interaction. This means that anyone nearby could potentially disrupt these services simply by having a laptop. The same vulnerabilities also affect Samsung's Quick Share feature. This is concerning because it could lead to service interruptions for users and potentially allow attackers to conduct further malicious activities while users are distracted by the crashes. Users should be cautious about their AirDrop and Quick Share settings, especially in public spaces.

Read Original

Hackers are taking advantage of a serious vulnerability (CVE-2026-48558) in SimpleHelp, a remote support software, to deploy a new type of malware known as Djinn Stealer. This malware is capable of stealing information across multiple operating systems, including Windows, macOS, and Linux. Users of SimpleHelp are at risk as the flaw allows attackers to infiltrate systems and extract sensitive data without detection. The emergence of this undocumented malware raises concerns about the security of remote support tools, as they are commonly used by businesses and individuals for remote access. It is crucial for users to remain vigilant and apply any necessary updates to protect their information.

+1 more
Read Original

Cybersecurity researchers have identified two hijacked npm packages and several compromised Go packages that are being used to deliver a Python-based information stealer to affected systems. This malware targets Windows, Linux, and macOS devices, making it a broad threat to developers and users of these platforms. Notably, the attack circumvents common npm execution paths, which may be an effort to bypass security measures introduced in npm version 12. The presence of these malicious packages poses a significant risk, as they could lead to unauthorized data access and theft. Developers and users need to be vigilant and ensure they are not using these compromised packages in their projects.

Read Original

A recent report from The Citizen Lab reveals that a Russian government investigative unit hacked the iPhone of opposition politician Andrey Pivovarov using Cellebrite's UFED tool in June 2021. This incident raises serious concerns about the misuse of hacking technology against political dissidents. Cellebrite, a company known for its phone extraction tools, reportedly cut ties with Russian entities, yet their technology was still used in this attack. The implications of such actions highlight the ongoing risks faced by activists and politicians in authoritarian regimes, where surveillance and digital espionage are common. This incident serves as a reminder of the vulnerabilities that exist for individuals opposing oppressive governments.

Read Original

A recently discovered flaw in macOS allows standard users to disable Endpoint Detection and Response (EDR) and Mobile Device Management (MDM) features, which are critical for maintaining device security and management. This vulnerability could be exploited by malicious actors to weaken security controls, making it easier for them to execute attacks or gain unauthorized access to sensitive data. All macOS versions that support EDR and MDM functionalities are affected. Organizations using these features should be particularly vigilant, as the ability for unauthorized users to disable such protections can lead to significant security risks. As of now, there is no indication that this vulnerability is being actively exploited in the wild, but the potential for misuse remains a concern for IT departments.

Read Original

A new exploit called Usbliter8 has been discovered that bypasses Apple’s boot defenses, affecting millions of iPhones. This vulnerability cannot be patched, and researchers have released a proof-of-concept exploit, raising concerns about the potential for misuse. Users of affected iPhone models should be particularly vigilant, as this exploit could allow attackers to gain unauthorized access to devices. The widespread nature of this issue makes it critical for Apple to address, as it could lead to increased risks for personal data and security. As of now, there are no known patches or updates to mitigate this vulnerability, leaving many devices exposed.

Read Original

Recent research from Wake Forest University has revealed that many AI-powered iOS applications are exposing sensitive credentials. Out of 444 apps analyzed, 282 were found to have vulnerabilities that could allow attackers to access backend services and exploit user data. These affected apps span multiple categories, including productivity, entertainment, and education. This situation raises serious concerns about user privacy and the security measures that developers are implementing. It serves as a reminder for app developers to strengthen their security practices and for users to be cautious about the apps they install and the information they share.

Read Original

Apple has released a security update to address a vulnerability in its Beats Studio Buds, identified as CVE-2025-20701. This flaw was uncovered by researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH. While the specific nature of the vulnerability has not been detailed, it poses a potential risk to users of the Beats Studio Buds, which are popular wireless earbuds. Users are encouraged to install the latest firmware update to ensure their devices are protected. Ignoring this update could leave users vulnerable to potential exploits that might compromise their audio experience or privacy.

Read Original

Apple has addressed a significant security vulnerability in its Beats Studio Buds wireless earbuds that could have allowed hackers within Bluetooth range to eavesdrop on conversations. This flaw posed a risk to users, as it could potentially compromise their privacy during sensitive discussions. Apple has rolled out security updates to fix this issue, emphasizing the importance of keeping devices up to date with the latest software. Users of Beats Studio Buds should ensure they apply these updates promptly to protect against potential unauthorized access. This incident serves as a reminder of the vulnerabilities that can exist in everyday technology and the need for manufacturers to prioritize user security.

Read Original

Homebrew, the popular package manager for macOS, is enhancing its security with the introduction of a new requirement for third-party taps. Starting with version 6.0.0, any tap and its associated formula or cask must be explicitly trusted before the Ruby code is executed. This change aims to mitigate risks associated with running unverified code from external sources, which previously could execute without any restrictions. Official Homebrew taps will remain trusted by default, but users will now have options to manage trust levels for additional taps. This move is significant for users who rely on third-party software, as it adds an extra layer of security against potentially malicious code.

Read Original

This week saw several cybersecurity incidents that highlight ongoing vulnerabilities in various systems. A zero-day vulnerability was discovered in Google Chrome, which could allow attackers to execute arbitrary code. Additionally, exploits affecting UniFi devices were reported, taking advantage of outdated software. Cybercriminals are also utilizing phishing kits that are increasingly easy to rent, making them more accessible to a wider range of attackers. Meanwhile, macOS systems are facing threats from new data-stealing malware, and a flaw in VPN services was identified, potentially exposing user data. These incidents remind users and organizations of the continuous need to update their software and remain vigilant against evolving cyber threats.

Read Original

A new cyber campaign has emerged, targeting cryptocurrency firms through deceptive recruitment tactics and custom malware designed for macOS systems. Researchers from Wiz have identified this threat actor, known as JINX-0164, which employs social engineering to lure victims into downloading malicious software. The malware is tailored to exploit continuous integration and continuous deployment (CI/CD) infrastructures, increasing the risk of digital asset theft for affected organizations. As cryptocurrency firms often handle significant amounts of valuable digital assets, these attacks could lead to substantial financial losses and damage to their reputations. Companies in the crypto space need to be vigilant and enhance their security measures to protect against these sophisticated threats.

Read Original

Apple has released its post-quantum cryptography implementations in an open-source format, allowing researchers to analyze and verify the work. This move aims to safeguard encrypted data against potential future threats posed by quantum computers, which could compromise current public-key encryption methods. The release includes mathematical proofs and verification tools housed in the corecrypto library, which is integral to Apple's operating systems and services. By making this technology accessible for independent evaluation, Apple is fostering transparency and collaboration in the field of cryptography. This is important as quantum computing advances, potentially jeopardizing data security for users across various platforms.

Read Original
Actively Exploited

A new zero-click attack has been discovered that targets WhatsApp accounts on devices running iOS 16. This attack takes advantage of vulnerabilities in the ImageIO framework, specifically identified as CVE-2025-43300, and potentially CVE-2025-55177. By exploiting these flaws, attackers can gain unauthorized access to WhatsApp sessions without any user interaction. This is particularly concerning for users of iOS 16, as it opens the door for unauthorized access to private messages and data. Users should remain vigilant and consider updating their devices as soon as patches are available to mitigate this risk.

Read Original
PreviousPage 3 of 7Next