Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple security updates fix 2 zero-days used to hack iPhones

Apple security updates fix 2 zero-days used to hack iPhonesPost Views: 3 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Apple has released emergency security updates today to fix two zero-day vulnerabilities previously exploited by attackers to hack iPhones, iPads, or Macs.Zero-day vulnerabilities are security flaws known by attackers or researchers before the software vendor has become aware or been able to patch them. In many cases, zero-days have public proof-of-concept exploits or are actively exploited in attacks.

Today, Apple has released macOS Monterey 12.5.1 and  iOS 15.6.1/iPadOS 15.6.1 to resolve two zero-day vulnerabilities that are reported to have been actively exploited.

The two vulnerabilities are the same for all three operating systems, with the first tracked as CVE-2022-32894. This vulnerability is an out-of-bounds write vulnerability in the operating system’s Kernel.

The kernel is a program that operates as the core component of an operating system and has the highest privileges in macOS, iPadOS, and iOS.

An application, such as malware, can use this vulnerability to execute code with Kernel privileges. As this is the highest privilege level, a process would be able to perform any command on the device, effectively taking complete control over it.

The second zero-day vulnerability is CVE-2022-32893 and is an out-of-bounds write vulnerability in WebKit, the web browser engine used by Safari and other apps that can access the web.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
Apple says this flaw would allow an attacker to perform arbitrary code execution and, as it’s in the web engine, could likely be exploited remotely by visiting a maliciously crafted website.

The bugs were reported by anonymous researchers and fixed by Apple in iOS 15.6.1,  iPadOS 15.6.1, and macOS Monterey 12.5.1 with improved bounds checking for both bugs.

The list of devices affected by both vulnerabilities are:

* Macs running macOS Monterey
* iPhone 6s and later
* iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).

Apple disclosed active exploitation in the wild, however, it did not release any additional info regarding these attacks.

Likely, these zero-days were only used in targeted attacks, but it’s still strongly advised to install today’s security updates as soon as possible.
Trending: Find Hidden Info using Google Dorking manually, and Automated using Pagodo
Trending: OSINT Tool: Blackbird Seven zero-days patched by Apple this yearIn March, Apple patched two more zero-day bugs that were used in the Intel Graphics Driver (CVE-2022-22674) and AppleAVD (CVE-2022-22675) that could also be used to execute code with Kernel privileges.

In January, Apple patched two more actively exploited zero-days that enabled attackers to achieve arbitrary code execution with kernel privileges (CVE-2022-22587) and track web browsing activity and the users’ identities in real-time (CVE-2022-22594).

In February, Apple released security updates to fix a new zero-day bug exploited to hack iPhones, iPads, and Macs, leading to OS crashes and remote code execution on compromised devices after processing maliciously crafted web content.
Trending: Cisco hacked by Yanluowang ransomware gang, 2.8GB allegedly stolen Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple security updates fix 2 zero-days used to hack iPhones Apple security updates fix 2 zero-days used to hack iPhonesPost Views: 3 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe…
our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-2-300x150.png Researchers found over 9,000 accessible VNC servers, without a passwordAugust 15, 2022
Reading Time: 5 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-2-1-300x150.png Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USAAugust 12, 2022
Reading Time: 5 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-1-2-300x150.png Cisco hacked by Yanluowang ransomware gang, 2.8GB allegedly stolenAugust 11, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-6-300x150.png IDOR vulnerability in Reddit allowed attackers to perform mod actionsAugust 10, 2022
Reading Time: 2 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Apple security updates fix 2 zero-days used to hack iPhones first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Bypassing CSP

CSP stands for Content Security Policy. This is a response header that identifies what is authorised to load scripts, HTML elements and…Continue reading on Medium »
Read more...
hacking: security in practice
My usb rubber ducky scripts don’t work like they should.

For instance, the script I got from GitHub that’s supposed to download an image and swap the pc backgrounds does download the pic, but then it just opens a bunch of terminals and some random applications. It looks like it’s trying to swap the backgrounds but seems to error out. Anyone have any pointers on debugging the code?

submitted by /u/Iron-Rat
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
What is a good project for someone with beginner/intermediate skills?

Projects are simply the best way to learn from what I can tell. I am currently learning web development and am comfortable with JS in the sense that functions, classes, variables is not a scary concept. I know the basics of data structures and algorithms and have made a couple small projects.

So I am not a total noob when it comes to programming, but have almost 0 experience when it comes to hacking. Does anyone have any advice for a project that is the perfect amount of difficulty? Not too hard where someone would lose motivation but not too easy to where it's boring?

Kinda vague I know, but I hope someone can read between the lines and come up with good suggestions.

submitted by /u/Nimai_TV
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Hacking an iOS App?

I know this probably sounds so pathetic, but is there a way to hack iOS apps to increase your inventory/money/etc? Ever since I was young I’ve looked for ways to successfully accomplish it but haven’t found one. They all seem to be scams, or outdated. Are there any successful ways to hack an app?

submitted by /u/AnitahSmoke
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
China's APT41 Embraces Baffling Approach for Dropping Cobalt Strike Payload

The state-sponsored threat actor has switched up its tactics, also adding an automated SQL-injection tool to its bag of tricks for initial access.
Dark Reading: Attacks/Breaches
Easing the Cyber-Skills Crisis With Staff Augmentation

Filling cybersecurity roles can be costly, slow, and chancy. More firms are working with third-party service providers to quickly procure needed expertise.