Zero-days

Phone chipmaker Qualcomm fixes three zero-days exploited by hackers

Chipmaker giant Qualcomm released patches on Monday fixing a series of vulnerabilities in dozens of chips, including three zero-days that the company said may be in use as part of hacking campaigns.  Qualcomm cited Google’s Threat Analysis Group, or TAG, which investigates government-backed cyberattacks, saying the three flaws “may be under limited, targeted exploitation.”  According […]

Phone chipmaker Qualcomm fixes three zero-days exploited by hackers Read More »

Seven things we learned from WhatsApp vs. NSO Group spyware lawsuit

On Tuesday, WhatsApp scored a major victory against NSO Group when a jury ordered the infamous spyware maker to pay more than $167 million in damages to the Meta-owned company. The ruling concluded a legal battle spanning more than five years, which started in October 2019 when WhatsApp accused NSO Group of hacking more than

Seven things we learned from WhatsApp vs. NSO Group spyware lawsuit Read More »

Five things we learned from WhatsApp vs. NSO Group spyware lawsuit

On Tuesday, WhatsApp scored a major victory against NSO Group when a jury ordered the infamous spyware maker to pay more than $167 million in damages to the Meta-owned company. The ruling concluded a legal battle spanning more than five years, which started in October 2019 when WhatsApp accused NSO Group of hacking more than

Five things we learned from WhatsApp vs. NSO Group spyware lawsuit Read More »

Government hackers are leading the use of attributed zero-days, Google says

Hackers working for governments were responsible for the majority of attributed zero-day exploits used in real-world cyberattacks last year, per new research from Google. Google’s report said that the number of zero-day exploits — referring to security flaws that were unknown to the software makers at the time hackers abused them — had dropped from

Government hackers are leading the use of attributed zero-days, Google says Read More »

Google fixes two Android zero-day bugs actively exploited by hackers

On Monday, Google released an update for Android that fixes two zero-day flaws that “may be under limited, targeted exploitation,” as the company put it. That means Google is aware that hackers have been and may still be using the bugs to compromise Android devices in real world scenarios.  One of the two now-fixed zero-days,

Google fixes two Android zero-day bugs actively exploited by hackers Read More »

Russian zero-day seller is offering up to $4 million for Telegram exploits

Operation Zero, a company that acquires and sells zero-days exclusively to the Russian government and local Russian companies, announced on Thursday that it’s looking for exploits for the popular messaging app Telegram, and is willing to offer up to $4 million for them. The exploit broker is offering up to $500,000 for a “one-click” remote

Russian zero-day seller is offering up to $4 million for Telegram exploits Read More »

Apple fixes new security flaw used in ‘extremely sophisticated attack’

Apple released patches for a bug that it says “may have been exploited in an extremely sophisticated attack against specific targeted individuals,” citing a report. The zero-day bug was found in WebKit, the browser engine powering Safari and other apps, and allowed hackers to break out of WebKit’s protective sandbox with “maliciously crafted web content,”

Apple fixes new security flaw used in ‘extremely sophisticated attack’ Read More »

Researchers uncover unknown Android flaws used to hack into a student’s phone

Amnesty International said that Google fixed previously unknown flaws in Android that allowed authorities to unlock phones using forensic tools. On Friday, Amnesty International published a report detailing a chain of three zero-day vulnerabilities developed by phone-unlocking company Cellebrite, which its researchers found after investigating the hack of a student protester’s phone in Serbia. The

Researchers uncover unknown Android flaws used to hack into a student’s phone Read More »