Security News

Apple backports fix for RTKit iOS zero-day to older iPhones
2024-05-13 21:47

Apple has backported security patches released in March to older iPhones and iPads, fixing an iOS Kernel zero-day tagged as exploited in attacks. Today, Apple backported the March security updates to address this security flaw on iOS 16.7.8, iPadOS 16.7.8, and macOS Ventura 13.6.7 with improved input validation.

Bitwarden launches new MFA Authenticator app for iOS, Android
2024-05-02 20:20

Bitwarden has just launched a new multi-factor authenticator app called Bitwarden Authenticator, which is available for iOS and Android devices. In contrast, the Bitwarden Authenticator app is available for free to all users, even those without a Bitwarden account, and can be used as a standalone app.

Chinese-Linked LightSpy iOS Spyware Targets South Asian iPhone Users
2024-04-15 09:04

Cybersecurity researchers have discovered a "renewed" cyber espionage campaign targeting users in South Asia with the aim of delivering an Apple iOS spyware implant called LightSpy. "The latest...

Opera sees big jump in EU users on iOS, Android after DMA update
2024-03-23 16:59

With iOS 17.4, Apple introduced a new choice screen that asks EU users to select a default web browser from a list of randomly listed browsers, including Opera. Google also rolled out a similar browser choice screen to Android users on March 6th, which will be shown during the initial setup of an Android smartphone or tablet.

Brave: Sharp increase in installs after iOS DMA update in EU
2024-03-12 22:25

Brave has seen a sharp increase in users installing its privacy-focused Brave Browser on iPhones after Apple introduced changes to adhere to the new European Digital Markets Act. To comply with the Digital Markets Act, Apple introduced a new feature in iOS 17.4 that asks EU users to pick a default web browser from a list that includes Brave, among other options.

Apple fixes two actively exploited iOS zero-days (CVE-2024-23225, CVE-2024-23296)
2024-03-06 09:34

Apple has fixed two iOS zero-day vulnerabilities exploited by attackers in the wild. "Additional CVE entries [are] coming soon," Apple noted for both updates.

Apple fixes two new iOS zero-days exploited in attacks on iPhones
2024-03-05 21:34

Apple released emergency security updates to fix two iOS zero-day vulnerabilities that were exploited in attacks on iPhones. The company says it addressed the security flaws for devices running iOS 17.4, iPadOS 17.4, iOS 16.76, and iPad 16.7.6 with improved input validation.

Meta Warns of 8 Spyware Firms Targeting iOS, Android, and Windows Devices
2024-02-19 13:14

Meta Platforms said it took a series of steps to curtail malicious activity from eight different firms based in Italy, Spain, and the United Arab Emirates (U.A.E.) operating in the...

Cybercriminals are stealing iOS users' face scans to break into mobile banking accounts
2024-02-15 14:00

Cybercriminals are targeting iOS users with malware that steals Face ID scans to break into and pilfer money from bank accounts - thought to be a world first. iOS target Android and iOS respectively, tricking users into performing biometric verification checks that are ultimately used to bypass the same checks employed by legitimate banking apps in Vietnam and Thailand - the geographic focus of these ongoing attacks.

iOS users beware: GoldPickaxe trojan steals your facial data
2024-02-15 10:14

Group-IB uncovered a new iOS trojan designed to steal users' facial recognition data, identity documents, and intercept SMS. The trojan, dubbed GoldPickaxe. iOS trojan targets victims in the Asia-Pacific region.