Jamf Threat Labs subverts iPhone security with fake Airplane Mode

Fresh security research from Jamf Threat Labs may not reflect an active attack, but it does illustrate the layered complexity of today’s threat environment.

When Airplane mode isn’t Airplane mode

In brief, the researchers have figured out a proof of concept attack that tricks victims into thinking they are using Airplane Mode. However, in reality the attacker has put in place a fake version of that mode that looks normal but lets the attacker maintain access to the device.

This is by no means a straightforward attack and hasn’t been seen in the wild. The exploit is complex and would require an attacker to successfully take control of the target device through a series of exploits, the research claims. 

To read this article in full, please click here

Read more

China hacks the US military and government— the Feds blame Microsoft

Hidden in the basic infrastructure that runs the US military is a powerful piece of Windows-borne Chinese malware that can disrupt the communications systems, power grids, and water supplies at the military’s bases around the world. One US congressional aide calls it a “ticking time bomb” that as The New York Times put it, “could give China the power to interrupt or slow American military deployments or resupply operations by cutting off power, water and communications to US military bases.”

To read this article in full, please click here

Read more

How the Microsoft Incident Response team helps customers remediate threats

Credit to Author: Microsoft Incident Response| Date: Tue, 15 Aug 2023 16:00:00 +0000

Microsoft Incident Response is a global team comprised of cybersecurity experts with deep, highly specialized knowledge in breach detection, response, and recovery.

The post How the Microsoft Incident Response team helps customers remediate threats appeared first on Microsoft Security Blog.

Read more

Discord.io confirms theft of 760,000 members’ data

Categories: News

Tags: Discord.io

Tags: Discord

Tags: data breach

Discord.io has confirmed that personally identifiable information of 760,000 members was stolen in a data breach. The third-party Discord service has been shut down for the time being

(Read more…)

The post Discord.io confirms theft of 760,000 members’ data appeared first on Malwarebytes Labs.

Read more

Malvertisers up their game against researchers

Categories: Threat Intelligence

Tags: malvertising

Tags: google

Tags: ads

Tags: malware

Tags: fingerprinting

Malicious ads via search engine results page are getting harder to identify thanks to advanced fingerprinting techniques

(Read more…)

The post Malvertisers up their game against researchers appeared first on Malwarebytes Labs.

Read more

Beware malware posing as beta versions of legitimate apps, warns FBI

Categories: News

Tags: FBI

Tags: warning

Tags: beta-testing

Tags: malicious code

Tags: crypto recovery

Tags: scammers

The FBI has issued a warning about two related types of fraud, malicious beta-testing apps and crypto recovery schemes.

(Read more…)

The post Beware malware posing as beta versions of legitimate apps, warns FBI appeared first on Malwarebytes Labs.

Read more

Ford says it’s safe to drive its cars with a WiFi vulnerability

Categories: Exploits and vulnerabilities

Categories: News

Tags: Ford

Tags: Lincoln

Tags: SYNC 3

Tags: CVE-2023-29468

Tags: TI WLink

Tags: MCP driver

A vulnerability in the SYNC 3 infotainment will not have a negative effect on driving safety, says Ford.

(Read more…)

The post Ford says it’s safe to drive its cars with a WiFi vulnerability appeared first on Malwarebytes Labs.

Read more