[flagged]
NSO group iPhone zero-click, zero-day exploit captured in the wild
61–70 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#62> The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim. Man, iMessage is a security disaster for Apple. No matter how much work they do in other areas, it seems like they'll paying for a while for their decisions around the iMessage architecture.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#63Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#64For anyone interested in learning more about the NSO group, I'd recommend this podcast episode: https://darknetdiaries.com/episode/100/
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#65[flagged]
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#66So at what point does the world bring sanctions against Israel for allowing organizations like this to exist there? Everyone knows NSO is just a dubiously legal version of common APT groups, so how do they still exist after these years?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#67We're all very lucky that CitizenLab exists as they are often the first discovery point of numerous similar exploits. They proactively scan the phones of internationally sensitive people and publish their findings. I'm not aware of any other public service that has had this much success exposing mobile device attacks. Attacks which have completely and utterly compromised the entire device that someone keeps with them…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#68For anyone interested in learning more about the NSO group, I'd recommend this podcast episode: https://darknetdiaries.com/episode/100/
[flagged]
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#69Earlier quoted context omitted.
You can enable iOS’s “lockdown mode” which disabled automatic download attachment, JavaScript JIT and other rather hard to secure features.
Doesn't Lockdown Mode fully block message attachments besides images? Not just automatic download.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#70[1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...