Apple releases iOS 10.3.1 update, offers bug fixes, security fixes

Posted by:
Date: Tuesday, April 4th, 2017, 05:36
Category: Hack, iOS, iPad, iPhone, iPod Touch, News, security, Software

After a major OS update come the fixes.

Apple on Monday released iOS 10.3.1, an update available for its iOS devices available as an over-the-air update or when connected to iTunes via a Mac or Windows PC.

The update, which weighs in at just under 30 megabytes as an OTA download, resolves issues such as a hardware-specific problem wherein iPhone 5 and iPhone 5c handsets had trouble updating over the air.

(more…)

LastPass exploit discovered, company scrambles to repair the vulnerability

Posted by:
Date: Monday, April 3rd, 2017, 05:04
Category: Hack, News, security, Software

A serious vulnerability was recently discovered in the popular LassPass password manager and developers are scrambling to fix the issue which makes it possible for malicious websites to steal user passcodes and in some cases execute malicious code on computers running the program.

The flaw, which affects the most recent version of the browser extension, was briefly described on Saturday, March 25th, by Tavis Ormandy, a researcher with Google’s Project Zero vulnerability reporting team. When people have the LastPass binary running, the vulnerability allows malicious websites to execute code of their choice. Even when the binary isn’t present, the flaw can be exploited in a way that lets malicious sites steal passwords from the protected LastPass vault. Ormandy said he developed a proof-of-concept exploit and sent it to LastPass officials. Developers now have three months to patch the hole before Project Zero discloses technical details.

Ormandy offered the following statement:

“It will take a long time to fix this properly, It’s a major architectural problem. They have 90 days, no need to scramble!”

The blog post describing the issue had LastPass company officials thanking Ormandy for the alert and stating that a fix was on the way. In the meantime, it was suggested that LastPass users protect themselves by by entering stored passwords into websites using the LastPass vault as a launch pad for opening websites and entering passwords and enabling two-factor authentication on sites that offer it.

The attack was described as both unique and highly sophisticated. LastPass, in turn, stated that the company didn’t want to disclose details regarding the vulnerability or the fix to outside parties. Users, in turn, could expect a more detailed post mortem once the work was complete.

The string of vulnerabilities underscores the tradeoff that comes from use of any password manager. Storing dozens, hundreds, or even thousands of passwords in a single place poses catastrophic risks should that resource be breached. Exploits become easier by convenience features that, for example, store encrypted password vaults in Internet-accessible locations or automatically paste passwords into websites. Ultimately, password managers likely make the average user safer because they make it possible to use long, complex, and unique passwords. And that protects people in the event that their password is exposed in website breaches, which are much more common than real-world password manager exploits.

If you use LastPass, please take care and stay tuned for additional details as they become available.

Via Ars Technica, Twitter and blog.lastpass.com

Apple clears through almost 350 security vulnerabilities with of iOS, macOS, watchOS and tvOS updates

Posted by:
Date: Wednesday, March 29th, 2017, 05:54
Category: Hack, iOS, macOS, News, security, Software, TvOS, watchOS

Apple cleaned house via a slew of operating system updates on Monday, pinning down nearly 350 known vulnerabilities between its changes to iOS, macOS, watchOS and tvOS.

Starting with iOS 10.3, Apple’s latest version includes Find My AirPods, Apple’s new file system, CarPlay, and a few other small visual tweaks. With nearly every update Apple does, they also include a handful of security fixes that easily go unnoticed by the user. iOS 10.3 is no exception with over 85 different common vulnerabilities and exposures (CVEs) listed.

In one case, the iOS 10.3 update patched a security hole that allowed attackers to spam Safari with a ‘Cannot Open Page’ dialog. Lookout, a cybersecurity company, learned of the attack after one of their users complained of losing control over their browsing experience. The dialog was meant to trick users into eventually paying money to “unlock” their Safari browser.

(more…)

Justice Department files charges against Russian hackers following Yahoo email breaches

Posted by:
Date: Thursday, March 16th, 2017, 05:56
Category: Hack, News, security

They found the people who hacked into more than half a billion Yahoo email accounts.

The Justice Department announced charges Wednesday against two Russian spies and two hackers behind the infamous 2014 hacks, which have been identified as among the most significant digital security breaks in American history.

The four men together face 47 criminal charges, including conspiracy, computer fraud, economic espionage, theft of trade secrets and aggravated identity theft, the Justice Department said in a news release.

(more…)

WikiLeaks to share CIA hacking tools with Apple, other firms after security fixes are complete

Posted by:
Date: Friday, March 10th, 2017, 05:36
Category: Hack, iOS, News, privacy, security, Software

Following WikiLeaks’ release of more than 8,000 documents from inside the CIA’s Center for Cyber Intelligence, Apple followed up, saying it had already fixed most of the exploits the agency had found to hack into iPhones.

WikiLeaks founder Julian Assange said Thursday he will share the code, which was withheld from the published documents, with tech companies like Apple.

Per Assange:

“We have decided to work with [tech companies] to give them exclusive access to the additional technological details we have so that fixes can be developed and pushed out,” Assange said in a live-streamed press conference from the Ecuadorian Embassy in London, where he lives. “Once this material is effectively disarmed by us we will publish additional details.”

(more…)

Apple responds to WikiLeaks’ release of CIA-based documents, states that ‘many’ of the iOS-related exploits have already been patched

Posted by:
Date: Wednesday, March 8th, 2017, 05:47
Category: Hack, iOS, News, privacy, security, Software

With any luck, this’ll provide some consolation.

Following up on the revelation that WikiLeaks had intercepted and released what might amount to 8,700+ documents from the CIA’s Center for Cyber Intelligence unit – part of which is devoted to obtaining zero-day exploits for iOS devices – and that the CIA had lost control of the majority of its hacking arsenal, Apple went on record to state that “many of the issues leaked today were already patched” in the most recent version of iOS.

The company offered the following comment:

(more…)

WikiLeaks releases 8,700+ CIA-related documents, show agency efforts towards hacking Android systems, iPhones, operating systems and smart TVs

Posted by:
Date: Wednesday, March 8th, 2017, 05:43
Category: Android, Google, Hack, Hardware, iOS, iPhone, macOS, News, privacy, Samsung, security

This is pretty much one for the ages.

WikiLeaks has released more than 8,700 documents that have apparently originated from the CIA’s Center for Cyber Intelligence, with some of the leaks saying the agency had 24 “weaponized” and previously undisclosed exploits for the Android operating system as of 2016.

Some of the Android-specific exploits were developed by the CIA, while others hailed from the U.S. National Security Agency, U.K. intelligence agency GCHQ, and cyber arms dealers.

Among the smartphone-related tools developed by the CIA were assets that allow the agency to bypass encryption found in WhatsApp, Confide and other applications known to use encryption. These tools, according to WikiLeaks analysis, capture audio and message traffic before encryption has a chance to be applied.

(more…)

Yahoo discloses third data breach in six months

Posted by:
Date: Thursday, March 2nd, 2017, 05:39
Category: Hack, News, security

The hits just keep on coming.

Yahoo today revealed a third major hack, wherein some 32 million accounts have been accessed by intruders over the past two years. These accounts are in addition to the accounts affected by the two data breaches the company had previously disclosed.

The accounts were apparently compromised via forged cookie files. Yahoo has stated that the accounts were accessed by the “same state-sponsored actor beloved to be responsible for the 2014 hack.” The 2014 hack was the one that affected at least 500 million accounts.

(more…)

Verizon settles on $4.48 billion purchase price for Yahoo’s core assets following email hacks

Posted by:
Date: Wednesday, February 22nd, 2017, 05:01
Category: Finance, Hack, Legal, News, wireless

Verizon was able to save even more money following Yahoo’s email hacks.

The telecommunications company announced a deal to buy the core business of Yahoo for $4.48 billion —managing to secure a $350 million discount it was pursuing because of two major security breaches, the last of which affected over 1 billion accounts.

The deal states that both Yahoo and Verizon will share some liabilities following the 2013 and 2014 hacks. The companies will split cash liabilities linked to some lawsuits and government investigations, but Yahoo alone will be saddled with some liabilities from shareholder lawsuits and U.S. Securities and Exchange Commission investigations.

(more…)

Security researchers at Bitdefender find evidence of X-Agent malware variant for macOS

Posted by:
Date: Thursday, February 16th, 2017, 05:13
Category: Hack, News, security, Software

The malware that may have swung the U.S. presidential election could be on its way to a Mac near you.

Security researchers have discovered a macOS malware program that’s likely part of the arsenal used by the Russian cyberespionage group blamed for hacking into the U.S. Democratic National Committee last year.

The group, known under such names as “Fancy Bear”, “Pawn Storm” and “APT28”, has been active for almost a decade and is believed to be the sole user and likely developer of a Trojan program called Sofacy or X-Agent.

X-Agent variants for Windows, Linux, Android, and iOS have been found in the wild in the past, but researchers from Bitdefender have now come across what appears to be the first macOS version of the Trojan.

(more…)