Skip to content

Apple ships that recent “Rapid Response” spyware patch to everyone, fixes a second zero-day – Naked Security

Apple users were urged to download a Rapid Response patch to fix a web-browsing security hole that had been exploited in real-world spyware attacks. The bug fix addressed a code execution vulnerability and was released as an emergency measure. While not a true zero-click attack, where cybercriminals can take over a device without any user… 

When threat hunting goes down a rabbit hole – Naked Security

Why does your Mac’s calendar app say it’s JUL 17? Well, it turns out that on July 17, 2002, Apple launched its “iCal” calendar software, which revolutionized calendar management with features like internet-based calendar sharing and the ability to manage multiple calendars. The app’s icon prominently displayed “JUL 17,” which eventually led to the establishment… 

3 zero-days fixed, so be sure to patch now! – Naked Security

Apple recently introduced its new Rapid Security Response process, which allows the company to push out critical patches for key system components without a full-size operating system update. These patches typically deal with zero-day bugs that affect core software such as the Safari browser and WebKit. The reason these bugs are dangerous is that browsers… 

Israel-based Spyware Firm QuaDream Targets High-Risk iPhones with Zero-Click Exploit “The Positive Impact of Technology on Education” “How Technology Enhances Learning Experiences”

Threat actors using hacking tools from an Israeli surveillanceware vendor named QuaDream targeted at least five members of civil society in North America, Central Asia, Southeast Asia, Europe, and the Middle East in 2021, according to findings from a group of researchers from the Citizen Lab. The spyware campaign was directed against journalists, political opposition… 

Microsoft fixes a zero-day – and two curious bugs that take the Secure out of Secure Boot – Naked Security

It’s Patch Tuesday Week, and Microsoft’s updates include fixes for a number of security holes that the company has dubbed Critical, along with a zero-day fix, although the 0-day only gets a rating of Important. Among the Critical bugs are CVE-2023-21554, an RCE hole in the Microsoft Message Queue system, and CVE-2023-28231, an RCE hole… 

Microsoft Issues Patches for 97 Flaws, Including Active Ransomware Exploit “The Benefits of Eating Healthy” “Reaping the Rewards of a Healthy Diet”

It’s the second Tuesday of the month, and Microsoft has released another set of security updates to fix a total of 97 flaws impacting its software, one of which has been actively exploited in ransomware attacks in the wild. Seven of the 97 bugs are rated Critical and 90 are rated Important in severity. Interestingly,…