Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Greetings! My name is Josh Beck and I am an instructor at iCSI (The institute of CyberSecurity and Innovation) in San Antonio, Texas. Our…Continue reading on Medium » (https://medium.com/@josh.beck2006/wordpress-infiltration-pen-test-lab-vm-included-e7af4570747d?source=rss------bug_bounty-5)
Dark Reading: Attacks/Breaches
Software Supply Chain Strategies to Parry Dependency Confusion Attacks

Bad actors practice to deceive package managers with a tangled web of methods. Here's how to hoist them by their own petard.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is bluejacking in cyber security?

https://cdn-images-1.medium.com/max/1280/1*SJ-apyHOz4ufWEsvgY9fYQ.jpeg
In the world of cyber security, there’s a sneaky threat called bluejacking, which exploits Bluetooth technology to send unsolicited…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cara Hacker Meretas Website dan Metodenya

https://cdn-images-1.medium.com/max/1000/1*WpB1LiBfFFQ7b2HDa85qRQ.jpeg
Website merupakan salah satu media informasi yang sangat populer di dunia internet. Hampir semua informasi dan layanan digital menggunakan…

Continue reading on Medium »
Bypass Mobile Phone verification using Mobile website

I was invited to security test an e-commerce website. Mobile phone number verification is mandatory on the website and customers are not…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Emergency Apple Updates: Zero-Days Exploited to Deploy Spyware on iPhones

Emergency Apple Updates: Zero-Days Exploited to Deploy Spyware on iPhones
Post Views: 1 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Apple issued emergency security updates to address two zero-day vulnerabilities that were actively exploited in a sophisticated zero-click exploit chain. These vulnerabilities served as entry points for deploying NSO Group’s Pegasus commercial spyware onto fully patched iPhones.

The two identified vulnerabilities, tracked as CVE-2023-41064 and CVE-2023-41061, allowed attackers to compromise iPhones running iOS 16.6, even if they were fully patched. This alarming breach occurred within a Washington DC-based civil society organization through PassKit attachments containing malicious images.

Citizen Lab, a prominent research organization, has named this exploit chain “BLASTPASS.” The concerning aspect of this attack is that it could compromise iPhones running the latest version of iOS (16.6) without requiring any interaction from the victim. The attack method involved PassKit attachments, containing malicious images, sent from the attacker’s iMessage account to the victim’s device.

In response to these critical security breaches, Citizen Lab strongly advises all Apple customers to update their devices immediately. Furthermore, individuals who may be at risk of targeted attacks due to their identity or profession are encouraged to activate Lockdown Mode on their devices.
We refer to the exploit as BLASTPASS, as it employed a PassKit (Wallet) attachment containing a malicious image, sent via iMessage. When the phone processed the attachment, the exploit hijacked control of Apple's "BlastDoor" framework for iMessage security.

— Bill Marczak (@billmarczak) September 7, 2023
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses
These two zero-day vulnerabilities were discovered by both Apple and security researchers at Citizen Lab. They were found to exist within the Image I/O and Wallet frameworks.

CVE-2023-41064 is characterized as a buffer overflow vulnerability, triggered during the processing of maliciously crafted images. On the other hand, CVE-2023-41061 is a validation issue that can be exploited via malicious attachments. Both of these vulnerabilities allowed threat actors to gain arbitrary code execution on unpatched iPhone and iPad devices.

Apple has promptly addressed these flaws through updates, including macOS Ventura 13.5.2, iOS 16.6.1, iPadOS 16.6.1, and watchOS 9.6.2. These updates incorporate improved logic and memory handling to mitigate the vulnerabilities.

A range of Apple devices were affected, including iPhone 8 and later models, various iPad models, Macs running macOS Ventura, and Apple Watch Series 4 and later.
Trending: The Remarkable Journey of Dave Kennedy as a Cyber Security Innovator Trending: Recon Tool: Dirhunt This marks the 13th zero-day vulnerability that Apple has addressed since the beginning of the year.
These vulnerabilities have been exploited to target devices running iOS, macOS, iPadOS, and watchOS. Apple’s commitment to swiftly patching such vulnerabilities underscores its dedication to user security.

* In July, two zero-days (CVE-2023-37450 and CVE-2023-38606) were addressed
* June saw the fixing of three zero-days (CVE-2023-32434, CVE-2023-32435, and CVE-2023-32439).
* May brought three additional zero-days (CVE-2023-32409, CVE-2023-28204, and CVE-2023-32373)
* April saw the resolution of two zero-days (CVE-2023-28206 and CVE-2023-28205).
* In February, another WebKit z[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Emergency Apple Updates: Zero-Days Exploited to Deploy Spyware on iPhones Emergency Apple Updates: Zero-Days Exploited to Deploy Spyware on iPhones Post Views: 1 Premium Content https://www.blackhatethicalhacking.com/wp-content/…
ero-day (CVE-2023-23529) was patched, signifying a continuous commitment to user safety.
Trending: Microsoft Entra ID Vulnerability Exposes Privilege Escalation Risk Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/09/Images-for-the-News-posts-26-300x150.png September Android Security Updates: Battling Zero-Day and Critical Bugs
September 7, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/09/Images-for-the-News-posts-25-300x150.png Atlas VPN’s Critical Flaw: Zero-Day Leak of User Real IP Addresses
September 6, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/09/Images-for-the-News-posts-24-300x150.png MinIO Under Siege: Threat Actor Exploits Critical Vulnerabilities
September 5, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/09/Images-for-the-News-posts-23-300x150.png MalDoc in PDFs: The Covert Threat of Embedded Word Documents into PDFs
September 4, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security Solutions

Find out how Pentesting Services can help you.
The post Emergency Apple Updates: Zero-Days Exploited to Deploy Spyware on iPhones first appeared on Black Hat Ethical Hacking.
Unveiling RCE on Dutch Government Website

IntroductionContinue reading on Medium »
Read more...
Wifi Soft Unibox Administration 3.0 Login Page Exploit

IntroductionContinue reading on Medium »
Read more...