Security News

Edison Mail iOS Bug Exposes Emails to Strangers
2020-05-18 16:16

Edison Mail, a popular third-party email app, has warned thousands of iOS users that their emails may have been compromised after a security flaw exposed emails to complete strangers. Several Edison Mail users took to Twitter to complain that they were seeing up to 100 unread email messages from strangers' accounts under their own Edison Mail inboxes.

Over 6,400 Edison Mail Users Hit by Security Bug in iOS App
2020-05-18 14:47

An update rolled out recently by Edison Mail for its iOS application resulted in some users being given access to other people's email accounts. Edison Mail provides apps that allow users to manage their Gmail, Yahoo, Outlook, iCloud and other inboxes from one place.

Zerodium Expects iOS Exploit Prices to Drop as It Announces Surplus
2020-05-14 12:57

Exploit acquisition firm Zerodium announced this week that it's no longer buying certain types of iOS exploits due to surplus, and the company expects prices to drop in the near future. Zerodium said on Twitter it would no longer acquire iOS local privilege escalation, Safari remote code execution, and sandbox escape exploits in the next 2-3 months "Due to a high number of submissions related to these vectors."

'iOS security is f**ked' says exploit broker Zerodium: Prices crash for taking a bite out of Apple's core tech
2020-05-14 10:31

On Wednesday, the software exploit broker said it won't pay anything for some iOS bugs due to an oversupply. Apple's iOS 13 has been particularly buggy, enough that SVP of software engineering Craig Federighi reportedly overhauled the company's internal software testing process to avoid a repeat when iOS 14 arrives later this year.

iOS XML Bug
2020-05-07 14:56

iOS uses XML for Plists, and Plists are used everywhere in iOS. iOS's sandboxing system depends upon three different XML parsers, which interpret slightly invalid XML input in slightly different ways. So Siguza's exploit ­- which granted an app full access to the entire file system, and more ­- uses malformed XML comments constructed in a way that one of iOS's XML parsers sees its declaration of entitlements one way, and another XML parser sees it another way.

High-Severity Cisco IOS XE Flaw Threatens SD-WAN Routers
2020-04-29 20:37

The flaw exists in Cisco IOS XE. This Linux-based version of Cisco's Internetworking Operating System is used in Cisco software-defined wide area network routers. In March, Cisco issued 24 patches tied to vulnerabilities in its IOS XE operating system.

Apple Finds No Evidence of Attacks Targeting iOS Mail App Vulnerabilities
2020-04-24 12:46

Apple has confirmed that its Mail application for iOS is affected by some vulnerabilities, but the tech giant has downplayed their impact and disputed claims that the flaws have been exploited in attacks. Cybersecurity automation company ZecOps reported on Wednesday that it had identified a couple of critical zero-day vulnerabilities in the Mail app for iOS. The flaws, which the company says have existed since the release of iOS 6 in 2012, can be exploited to execute arbitrary code in the context of the application by sending a specially crafted email to the targeted user.

Chinese Threat Actor Targets Uyghurs With New iOS Exploit
2020-04-23 11:45

A Chinese threat actor tracked as Evil Eye has updated the tools it uses to target Uyghurs, a minority Turkic ethnic group in the Xinjiang Uyghur Autonomous Region in Northwest China, incident response and threat intelligence firm Volexity reports. Starting January 2020 the threat actor resumed operations, with signs of activity identified "Across multiple previously compromised Uyghur websites."

Zero-Day Vulnerabilities in iOS Mail App Exploited in Targeted Attacks
2020-04-23 08:45

The Mail application in iOS is affected by two critical zero-day vulnerabilities that appear to have been exploited in targeted attacks since at least January 2018, cybersecurity automation company ZecOps reported on Wednesday. The vulnerabilities, described as out-of-bounds write and heap overflow issues, affect the MobileMail application on iOS 12 and maild on iOS 13, and they can be exploited by sending specially crafted emails to the targeted user.

Zero-click, zero-day flaws in iOS Mail 'exploited to hijack' VIP smartphones. Apple rushes out beta patch
2020-04-22 23:59

Apple has reportedly patched a pair of critical vulnerabilities in iOS that are being exploited by what appears to be government-backed hackers to spy on high-value targets. Most importantly, the researchers said, in iOS 13, the attack can be performed when Mail automatically downloads messages in the background, meaning no user interaction is needed: the data is fetched, parsed, and the bugs exploited immediately.