Articles tagged "iOS"

Found 25 articles

Cisco has issued critical patches for a vulnerability in its Nexus 9000 series switches, specifically those based on Silicon One architecture. This flaw, identified as CVE-2026-20212, carries a CVSS score of 9.8, indicating a severe risk. It allows remote attackers, without needing to authenticate, to execute code with root privileges on impacted systems. Alongside this vulnerability, Cisco also released a hardening update for IOS XR that includes seven additional CVEs, two of which are also rated very high at 9.8. Users of these Nexus switches should prioritize applying the patches as there are currently no workarounds available for the IOS XR versions affected.

Read Original

Cisco has issued a warning about serious vulnerabilities in its Secure Email product related to S/MIME flaws that could allow attackers to access encrypted email content. Additionally, critical vulnerabilities in its IOS XR and Nexus switch software could let hackers execute remote code and bypass authentication, posing a significant risk to affected systems. Companies using these products should take immediate action to secure their environments, as the potential for exploitation could lead to unauthorized access and data breaches. The vulnerabilities have been publicly disclosed, emphasizing the need for users to stay vigilant and apply any available patches to mitigate risks. Cisco has released patches for the critical switch vulnerabilities, but users must address the S/MIME flaws as they remain unpatched at this time.

Read Original

A cyber espionage group linked to China, known as Fire Ant, has broadened its operations to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. This escalation follows a previous focus on VMware hypervisors. The group aims to steal credentials and disable security logs, which could severely compromise the integrity of high-value networks. Sygnia, the incident response firm that investigated the incidents, emphasizes the significance of these vulnerabilities given the critical role these systems play in network management and authentication. Organizations using these technologies should be vigilant and take immediate steps to secure their infrastructures.

Read Original

On August 18, 2026, Apple addressed a significant security vulnerability in its image handling framework that could allow malicious images to execute harmful code on both desktop and mobile devices. This vulnerability is identified as CVE-2026-65346 and poses a risk to users who may unknowingly open compromised image files. The issue could potentially lead to unauthorized access or control over affected devices, making it crucial for users to update their systems promptly. Apple has released patches to fix this vulnerability, emphasizing the importance of keeping software up to date to protect against such threats. Users of both macOS and iOS devices should ensure they are running the latest versions to mitigate this risk.

Read Original
Actively Exploited

Recent reports reveal that advanced exploit chains targeting iPhones, initially believed to be exclusive to nation-state actors, are now being adopted by organized cybercrime groups. This shift raises concerns as these exploits, which can compromise iOS devices, are becoming more accessible to a broader range of attackers. Users of iPhones, especially those in sensitive sectors, may find themselves at increased risk as these exploits spread. The proliferation of such sophisticated tools could lead to more targeted attacks and data breaches. It's crucial for individuals and organizations to stay vigilant and ensure their devices are updated to mitigate potential risks.

Read Original

Researchers have discovered a vulnerability in Apple's iCloud Private Relay, a tool designed to protect user privacy by masking IP addresses when using Safari. This feature, which uses a dual-hop system to route traffic through two relays, can potentially expose users' real IP addresses due to certain bypasses in the WebKit proxy. This issue affects anyone using iCloud Private Relay on devices running iOS 15 or later. The revelation raises concerns about user privacy, as the very purpose of the service is to prevent third parties, including Apple, from tracking user locations. Users should be aware of this flaw and consider additional privacy measures until a fix is implemented.

Read Original

Lookout has introduced a new tool aimed at assessing the security of mobile applications on both Android and iOS platforms. This tool works by analyzing the apps at the binary level, producing a software bill of materials that lists the components used in each application. It then cross-references these components with existing vulnerability databases and threat intelligence feeds to identify potential security risks. This development is significant as it helps developers and organizations understand the exposure risks associated with the software they deploy, which is crucial for protecting user data and maintaining application integrity. By providing insights into vulnerabilities, Lookout's tool aims to enhance the overall security posture of mobile applications.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2008-4128, to its Known Exploited Vulnerabilities Catalog. This vulnerability affects Cisco IOS and is associated with cross-site request forgery, which allows attackers to exploit vulnerable systems. It poses significant risks, particularly for federal agencies, as it can lead to total control over affected assets after exploitation. CISA's Binding Operational Directive 26-04 emphasizes the need for federal agencies to prioritize rapid remediation of such high-risk vulnerabilities. While this directive primarily applies to federal agencies, CISA encourages all organizations to adopt similar practices for managing vulnerabilities effectively. Agencies are also urged to check for any compromises before applying patches to mitigate risks.

Read Original

Recent research from Wake Forest University has revealed that many AI-powered iOS applications are exposing sensitive credentials. Out of 444 apps analyzed, 282 were found to have vulnerabilities that could allow attackers to access backend services and exploit user data. These affected apps span multiple categories, including productivity, entertainment, and education. This situation raises serious concerns about user privacy and the security measures that developers are implementing. It serves as a reminder for app developers to strengthen their security practices and for users to be cautious about the apps they install and the information they share.

Read Original
Actively Exploited

A new zero-click attack has been discovered that targets WhatsApp accounts on devices running iOS 16. This attack takes advantage of vulnerabilities in the ImageIO framework, specifically identified as CVE-2025-43300, and potentially CVE-2025-55177. By exploiting these flaws, attackers can gain unauthorized access to WhatsApp sessions without any user interaction. This is particularly concerning for users of iOS 16, as it opens the door for unauthorized access to private messages and data. Users should remain vigilant and consider updating their devices as soon as patches are available to mitigate this risk.

Read Original

A newly discovered zero-click attack is targeting WhatsApp accounts on iPhones running iOS 16, allowing attackers to take control of accounts without any user interaction or warning. This means that users can find their accounts sending unauthorized messages, often asking contacts for money transfers, without realizing they’ve been compromised. The attack is particularly concerning because it does not require any linked devices, making it harder for users to identify or prevent the intrusion. As this vulnerability is actively exploited, users of WhatsApp on iOS 16 need to be vigilant and take precautions to protect their accounts. This incident highlights the ongoing challenges of mobile security and the importance of being cautious about unsolicited messages and requests.

Read Original

Apple has addressed a significant flaw in iOS that allowed deleted notifications to linger and expose message content. This vulnerability could potentially let others view sensitive information even after users thought they had deleted it. Affected users include anyone running iOS versions prior to the fix, which was rolled out in a recent update. The issue raises concerns about privacy, as it could lead to unintended sharing of personal messages. Apple has encouraged users to update their devices to ensure their information remains secure.

Read Original

Kaspersky has reported that SparkCat malware has resurfaced on app stores, specifically targeting cryptocurrency users in Asia. This malware has been found in applications available for both iOS and Android devices. Users downloading these apps may unknowingly expose their sensitive information, such as cryptocurrency wallet details, to attackers. This resurgence is particularly concerning given the increasing popularity of cryptocurrency among users, making them prime targets for cybercriminals. As the malware spreads, it underlines the need for users to be vigilant about the apps they download and the permissions they grant.

Read Original

WhatsApp has informed around 200 users that they were deceived into installing a counterfeit version of its iOS app, which contained spyware. Most of the affected individuals are based in Italy. The attackers reportedly employed social engineering tactics to trick users into downloading the malicious app. This incident raises concerns about the security of mobile applications and highlights the need for users to be vigilant about the sources from which they download software. With spyware potentially compromising personal information, it is crucial for users to ensure they are using legitimate applications from trusted sources.

Read Original

A Russian-linked hacking group known as TA446 is actively targeting iPhone users through a new phishing campaign that employs the DarkSword iOS exploit kit. These attacks involve sending malicious emails designed to compromise iOS devices, putting users' personal information at risk. The group, also referred to as SEABORGIUM and ColdRiver, has been noted for its sophisticated tactics in the past. This wave of phishing emphasizes the increasing dangers that smartphone users face, especially as attackers refine their methods to bypass security measures. As these campaigns evolve, it’s crucial for iPhone users to remain vigilant about suspicious emails and links.

Read Original
Page 1 of 2Next