infosec

Apple fixes zero-day flaw affecting all devices

Apple released the latest updates for its iPhone, iPad and Mac operating systems on Monday, which included switching on Apple Intelligence by default for newer devices.  As part of this batch of software updates, Apple also released several patches fixing security bugs, including a zero-day bug that “may have been actively exploited” — meaning hackers […]

Apple fixes zero-day flaw affecting all devices Read More »

Hidden Waymo feature let researcher customize robotaxi’s display

A security researcher found a hidden unreleased feature in the Waymo app that allowed her to display whatever characters she wanted on the robotaxi’s top display.  Jane Manchun Wong, a well-known security researcher, posted an image on X on Saturday showing the top display of a Waymo car — officially called “dome” — that included

Hidden Waymo feature let researcher customize robotaxi’s display Read More »

How victims of PowerSchool’s data breach helped each other investigate ‘massive’ hack

On January 7, at 11:10 p.m. in Dubai, Romy Backus received an email from education technology giant PowerSchool notifying her that the school she works at was one of the victims of a data breach that the company discovered on December 28. PowerSchool said hackers had accessed a cloud system that housed a trove of

How victims of PowerSchool’s data breach helped each other investigate ‘massive’ hack Read More »

Governments call for spyware regulations in UN Security Council meeting

On Tuesday, the United Nations Security Council held a meeting to discuss the dangers of commercial spyware, which marks the first time this type of software — also known as government or mercenary spyware — has been discussed at the Security Council.  The goal of the meeting, according to the U.S. Mission to the UN,

Governments call for spyware regulations in UN Security Council meeting Read More »

Facebook awards researcher $100,000 for finding bug that granted internal access

In October 2024, security researcher Ben Sadeghipour was analyzing Facebook’s ad platform when he found a security vulnerability that allowed him to run commands on the internal Facebook server housing that platform, essentially giving him control of the server.   After he reported the vulnerability to Facebook’s owner Meta, which Sadeghipour said took just one hour

Facebook awards researcher $100,000 for finding bug that granted internal access Read More »

Why Apple sends spyware victims to this nonprofit security lab

Before the elections, the cybersecurity team of U.S. vice president and then-presidential candidate Kamala Harris reached out to Apple asking for help, according to Forbes, after a tool that’s designed to detect spyware on iPhones flagged anomalies on two devices belonging to campaign staffers. Apple declined to forensically analyze the phones, per Forbes.  The company’s

Why Apple sends spyware victims to this nonprofit security lab Read More »

Serbian police used Cellebrite to unlock, then plant spyware, on a journalist’s phone

This year, a Serbian journalist and an activist had their phones hacked by local authorities using a cellphone-unlocking device made by forensic tool maker Cellebrite. The authorities’ goal was not only to unlock the phones to access their personal data, as Cellebrite allows, but also to install spyware to enable further surveillance, according to a

Serbian police used Cellebrite to unlock, then plant spyware, on a journalist’s phone Read More »

Ukraine says Russian hackers are targeting country’s defense contractors

Ukraine’s Computer Emergency Response Team (CERT-UA) said in a report published over the weekend that a hacking group has been targeting the country’s defense and military companies with phishing attacks.  The CERT identified the hacking group as UAC-0185 — also known as UNC4221 — without saying who was behind the group. Earlier this year, however,

Ukraine says Russian hackers are targeting country’s defense contractors Read More »

US charges five accused of multi-year hacking spree targeting tech and crypto giants

The U.S. government announced charges against five individuals accused of carrying out a multi-year hacking spree targeting tech giants and cryptocurrency owners, which security researchers dubbed 0ktapus. On Wednesday, the U.S. Department of Justice published a press release announcing the charges against the five alleged hackers: Ahmed Hossam Eldin Elbadawy, 23, of College Station, Texas;

US charges five accused of multi-year hacking spree targeting tech and crypto giants Read More »