Zero-days

Apple fixes new security flaw used in ‘extremely sophisticated attack’

Apple released patches for a bug that it says “may have been exploited in an extremely sophisticated attack against specific targeted individuals,” citing a report. The zero-day bug was found in WebKit, the browser engine powering Safari and other apps, and allowed hackers to break out of WebKit’s protective sandbox with “maliciously crafted web content,” […]

Apple fixes new security flaw used in ‘extremely sophisticated attack’ Read More »

Researchers uncover unknown Android flaws used to hack into a student’s phone

Amnesty International said that Google fixed previously unknown flaws in Android that allowed authorities to unlock phones using forensic tools. On Friday, Amnesty International published a report detailing a chain of three zero-day vulnerabilities developed by phone-unlocking company Cellebrite, which its researchers found after investigating the hack of a student protester’s phone in Serbia. The

Researchers uncover unknown Android flaws used to hack into a student’s phone Read More »

North Korean hackers exploited Chrome zero-day to steal crypto

A North Korean hacking group earlier in August exploited a previously unknown bug in Chrome to target organizations with the goal of stealing cryptocurrency, according to Microsoft. In a report published on Friday, the tech giant’s cybersecurity researchers said they first saw evidence of the hackers’ activities on August 19, and said the hackers were

North Korean hackers exploited Chrome zero-day to steal crypto Read More »

Chinese government hackers targeted U.S. internet providers with zero-day exploit, researchers say

A group of hackers linked to the Chinese government used a previously unknown vulnerability in software to target U.S. internet service providers, security researchers have found.  The group known as Volt Typhoon was exploiting the zero-day flaw — meaning the software maker was unaware of it before having time to patch — in Versa Director,

Chinese government hackers targeted U.S. internet providers with zero-day exploit, researchers say Read More »