Jamaruku
  • Home
  • News
    • All
    • Business
    • Politics
    • Science
    • World
    Australia sweltered through its 4th-hottest year in 2020

    Zimbabwe’s foreign minister dies of COVID-19 amid resurgence

    The glory of this day will be capped by the most historic Senate swearing-in ceremony ever

    The glory of this day will be capped by the most historic Senate swearing-in ceremony ever

    How Much Do Orthodontics Cost? A Complete Guide

    How Much Do Orthodontics Cost? A Complete Guide

    Biden inauguration latest: World waits as militarised capital prepares for transfer of power

    Biden inauguration latest: World waits as militarised capital prepares for transfer of power

    The world will never forget Trump’s trips abroad

    The world will never forget Trump’s trips abroad

    Presidential candidates often make big promises for Day One. Joe Biden is following through

    Presidential candidates often make big promises for Day One. Joe Biden is following through

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Tech
    • All
    • Startup
    Sources: Facebook has no plans to lift Trump's indefinite suspension following his departure from the White House (Dylan Byers/NBC News)

    Sources: Facebook has no plans to lift Trump's indefinite suspension following his departure from the White House (Dylan Byers/NBC News)

    Valve and five PC games publishers fined $9.4M for illegal geo-blocking – TechCrunch

    Valve and five PC games publishers fined $9.4M for illegal geo-blocking – TechCrunch

    Interview with Drupal founder Dries Buytaert as it marks 20 years, on importance of user experience, open source, API first approach, JavaScript bloat, and more (Tim Anderson/The Register)

    Interview with Drupal founder Dries Buytaert as it marks 20 years, on importance of user experience, open source, API first approach, JavaScript bloat, and more (Tim Anderson/The Register)

    Lanmodo Vast Pro: Night Vision System Integrated with DashCam, Safely Driving Along with You

    Lanmodo Vast Pro: Night Vision System Integrated with DashCam, Safely Driving Along with You

    Alibaba shares jump on Jack Ma’s first appearance in 3 months – TechCrunch

    Alibaba shares jump on Jack Ma’s first appearance in 3 months – TechCrunch

    Donald Trump pardons ex-Waymo, Uber engineer Anthony Levandowski; Peter Thiel and Palmer Luckey were among those supporting a pardon for Levandowski (Richard Lawler/Engadget)

    Donald Trump pardons ex-Waymo, Uber engineer Anthony Levandowski; Peter Thiel and Palmer Luckey were among those supporting a pardon for Levandowski (Richard Lawler/Engadget)

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    • Sports
    HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

    HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

    It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

    It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

    Love & Thunder Starts Shoot This Week!

    Love & Thunder Starts Shoot This Week!

    Steve McCormack helps England take the lead on player welfare | Rugby League News

    Steve McCormack helps England take the lead on player welfare | Rugby League News

    Pokémon Go guide: Groudon raid counters

    Pokémon Go guide: Groudon raid counters

    President Trump Departs From the White House

    President Trump Departs From the White House

  • Lifestyle
    • All
    • Fashion
    • Food
    • Health
    • Travel

    Electromagnetic fields, 5G and health: what about the precautionary principle?

    Mr Porter Sale: 21 Wild Menswear Buys from the Enormous Winter Sale

    Mr Porter Sale: 21 Wild Menswear Buys from the Enormous Winter Sale

    How the Pandemic Broadened My Horizons as a Diner

    How the Pandemic Broadened My Horizons as a Diner

    Facts for Heart, Stroke Patients

    Facts for Heart, Stroke Patients

    Melania Trump Exits The White House in An All-Black Outfit and $90,000 Birkin Bag

    Tyson Foods settles more chicken price-fixing claims | Food Industry News

    Tyson Foods settles more chicken price-fixing claims | Food Industry News

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • Review
    Not dead yet: Astro Slide 5G brings a real keyboard in the 5G-age

    Not dead yet: Astro Slide 5G brings a real keyboard in the 5G-age

    Flipkart And Amazon Republic Day Sale 2021: Discount Offers On iPhone 11, iPhone XR, iPhone 12 Mini, And More

    Flipkart And Amazon Republic Day Sale 2021: Discount Offers On iPhone 11, iPhone XR, iPhone 12 Mini, And More

    Xiaomi to bring Redmi Note 10, Redmi Note 10 Pro to India next month

    Xiaomi to bring Redmi Note 10, Redmi Note 10 Pro to India next month

    MediaTek Dimensity 1200 and 1100 based on 6nm architecture go official

    MediaTek Dimensity 1200 and 1100 based on 6nm architecture go official

    Redmi May Launch Its First Gaming Phone, Tipped to Be Powered by MediaTek Dimensity 1200 SoC

    Redmi May Launch Its First Gaming Phone, Tipped to Be Powered by MediaTek Dimensity 1200 SoC

    Next-generation Asus ROG Phone has a tiny display at the rear!

No Result
View All Result
  • Home
  • News
    • All
    • Business
    • Politics
    • Science
    • World
    Australia sweltered through its 4th-hottest year in 2020

    Zimbabwe’s foreign minister dies of COVID-19 amid resurgence

    The glory of this day will be capped by the most historic Senate swearing-in ceremony ever

    The glory of this day will be capped by the most historic Senate swearing-in ceremony ever

    How Much Do Orthodontics Cost? A Complete Guide

    How Much Do Orthodontics Cost? A Complete Guide

    Biden inauguration latest: World waits as militarised capital prepares for transfer of power

    Biden inauguration latest: World waits as militarised capital prepares for transfer of power

    The world will never forget Trump’s trips abroad

    The world will never forget Trump’s trips abroad

    Presidential candidates often make big promises for Day One. Joe Biden is following through

    Presidential candidates often make big promises for Day One. Joe Biden is following through

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Tech
    • All
    • Startup
    Sources: Facebook has no plans to lift Trump's indefinite suspension following his departure from the White House (Dylan Byers/NBC News)

    Sources: Facebook has no plans to lift Trump's indefinite suspension following his departure from the White House (Dylan Byers/NBC News)

    Valve and five PC games publishers fined $9.4M for illegal geo-blocking – TechCrunch

    Valve and five PC games publishers fined $9.4M for illegal geo-blocking – TechCrunch

    Interview with Drupal founder Dries Buytaert as it marks 20 years, on importance of user experience, open source, API first approach, JavaScript bloat, and more (Tim Anderson/The Register)

    Interview with Drupal founder Dries Buytaert as it marks 20 years, on importance of user experience, open source, API first approach, JavaScript bloat, and more (Tim Anderson/The Register)

    Lanmodo Vast Pro: Night Vision System Integrated with DashCam, Safely Driving Along with You

    Lanmodo Vast Pro: Night Vision System Integrated with DashCam, Safely Driving Along with You

    Alibaba shares jump on Jack Ma’s first appearance in 3 months – TechCrunch

    Alibaba shares jump on Jack Ma’s first appearance in 3 months – TechCrunch

    Donald Trump pardons ex-Waymo, Uber engineer Anthony Levandowski; Peter Thiel and Palmer Luckey were among those supporting a pardon for Levandowski (Richard Lawler/Engadget)

    Donald Trump pardons ex-Waymo, Uber engineer Anthony Levandowski; Peter Thiel and Palmer Luckey were among those supporting a pardon for Levandowski (Richard Lawler/Engadget)

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    • Sports
    HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

    HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

    It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

    It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

    Love & Thunder Starts Shoot This Week!

    Love & Thunder Starts Shoot This Week!

    Steve McCormack helps England take the lead on player welfare | Rugby League News

    Steve McCormack helps England take the lead on player welfare | Rugby League News

    Pokémon Go guide: Groudon raid counters

    Pokémon Go guide: Groudon raid counters

    President Trump Departs From the White House

    President Trump Departs From the White House

  • Lifestyle
    • All
    • Fashion
    • Food
    • Health
    • Travel

    Electromagnetic fields, 5G and health: what about the precautionary principle?

    Mr Porter Sale: 21 Wild Menswear Buys from the Enormous Winter Sale

    Mr Porter Sale: 21 Wild Menswear Buys from the Enormous Winter Sale

    How the Pandemic Broadened My Horizons as a Diner

    How the Pandemic Broadened My Horizons as a Diner

    Facts for Heart, Stroke Patients

    Facts for Heart, Stroke Patients

    Melania Trump Exits The White House in An All-Black Outfit and $90,000 Birkin Bag

    Tyson Foods settles more chicken price-fixing claims | Food Industry News

    Tyson Foods settles more chicken price-fixing claims | Food Industry News

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • Review
    Not dead yet: Astro Slide 5G brings a real keyboard in the 5G-age

    Not dead yet: Astro Slide 5G brings a real keyboard in the 5G-age

    Flipkart And Amazon Republic Day Sale 2021: Discount Offers On iPhone 11, iPhone XR, iPhone 12 Mini, And More

    Flipkart And Amazon Republic Day Sale 2021: Discount Offers On iPhone 11, iPhone XR, iPhone 12 Mini, And More

    Xiaomi to bring Redmi Note 10, Redmi Note 10 Pro to India next month

    Xiaomi to bring Redmi Note 10, Redmi Note 10 Pro to India next month

    MediaTek Dimensity 1200 and 1100 based on 6nm architecture go official

    MediaTek Dimensity 1200 and 1100 based on 6nm architecture go official

    Redmi May Launch Its First Gaming Phone, Tipped to Be Powered by MediaTek Dimensity 1200 SoC

    Redmi May Launch Its First Gaming Phone, Tipped to Be Powered by MediaTek Dimensity 1200 SoC

    Next-generation Asus ROG Phone has a tiny display at the rear!

No Result
View All Result
Jamaruku
No Result
View All Result
Home Tech

Zero-click iMessage zero-day used to hack the iPhones of 36 journalists

December 22, 2020
in Tech
Zero-click iMessage zero-day used to hack the iPhones of 36 journalists

Promotional image of iPhone.

Three dozen journalists had their iPhones hacked in July and August using what at the time was an iMessage zero-day exploit that didn’t require the victims to take any action to be infected, researchers said.

The exploit and the payload it installed were developed and sold by NSO Group, according to a report published Sunday by Citizen Lab, a group at the University of Toronto that researches and exposes hacks on dissidents and journalists. NSO is a maker of offensive hacking tools that has come under fire over the past few years for selling its products to groups and governments with poor human rights records. NSO has disputed some of the conclusions in the Citizen Lab report.

The attacks infected the targets’ phones with Pegasus, an NSO-made implant for both iOS and Android that has a full range of capabilities, including recording both ambient audio and phone conversations, taking pictures, and accessing passwords and stored credentials. The hacks exploited a critical vulnerability in the iMessage app that Apple researchers weren’t aware of at the time. Apple has since fixed the bug with the rollout of iOS 14.

More successful, more covert

Over the past few years, NSO exploits have increasingly required no user interaction—such as visiting a malicious website or installing a malicious app—to work. One reason these so-called zero-click attacks are effective is that they have a much higher chance of success, since they can strike targets even when victims have considerable training in preventing such attacks.

In 2019, Facebook alleges, attackers exploited a vulnerability in the company’s WhatsApp messenger to target 1,400 iPhones and Android devices with Pegasus. Both Facebook and outside researchers said the exploit worked simply by calling a targeted device. The user need not have answered the device, and once it was infected, the attackers could clear any logs showing that a call attempt had been made.

Another key benefit of zero-click exploits is that they’re much harder for researchers to track afterward.

Advertisement

“The current trend towards zero-click infection vectors and more sophisticated anti-forensic capabilities is part of a broader industry-wide shift towards more sophisticated, less detectable means of surveillance,” Citizen Lab researchers Bill Marczak, John Scott-Railton, Noura Al-Jizawi, Siena Anstis, and Ron Deibert wrote. “Although this is a predictable technological evolution, it increases the technological challenges facing both network administrators and investigators.”

Elsewhere in the report, the authors wrote:

More recently, NSO Group is shifting towards zero-click exploits and network-based attacks that allow its government clients to break into phones without any interaction from the target, and without leaving any visible traces. The 2019 WhatsApp breach, where at least 1,400 phones were targeted via an exploit sent through a missed voice call, is one example of such a shift. Fortunately, in this case, WhatsApp notified targets. However, it is more challenging for researchers to track these zero-click attacks because targets may not notice anything suspicious on their phone. Even if they do observe something like “weird” call behavior, the event may be transient and not leave any traces on the device.

The shift towards zero-click attacks by an industry and customers already steeped in secrecy increases the likelihood of abuse going undetected. Nevertheless, we continue to develop new technical means to track surveillance abuses, such as new techniques of network and device analysis.

Citizen Lab said it has concluded with medium confidence that some of the attacks it uncovered were backed by the government of the United Arab Emirates and other attacks by the government of Saudi Arabia. The researchers said they suspect the 36 victims they identified—including 35 journalists, producers, anchors, and executives at Al-Jazeera and one journalist at Al Araby TV—are only a small fraction of people targeted in the campaign.

NSO responds

In a statement, an NSO spokesperson wrote:

This memo is based, once again, on speculation and lacks any evidence supporting a connection to NSO. Instead it relies on assumptions made solely to fit Citizen Lab’s agenda.

NSO provides products that enable governmental law enforcement agencies to tackle serious organized crime and counterterrorism only, and as stated in the past we do not operate them.
However, when we receive credible evidence of misuse with enough information which can enable us to assess such credibility, we take all necessary steps in accordance with our investigation procedure in order to review the allegations.

Unlike Citizen Lab, which only has ‘medium confidence’ in their own work, we KNOW our technology has saved the lives of innocent people around the world.

We question whether Citizen Lab understands that by pursuing this agenda, they are providing irresponsible corporate actors as well as terrorists, pedophiles, and drug cartel bosses with a playbook for how to avoid law enforcement.

NSO, meanwhile, will continue to work tirelessly to make the world a safer place.

As noted earlier, zero-click zero-days are difficult if not impossible to prevent even by users with extensive security training. As potent as these exploits are, their high cost and difficulty in procuring them means that they’re used against only a small population of people. That means the vast majority of mobile device users are unlikely to ever be targeted by these types of attacks.

Advertisement

In a statement, Apple representatives wrote, “At Apple, our teams work tirelessly to strengthen the security of our users’ data and devices. iOS 14 is a major leap forward in security and delivered new protections against these kinds of attacks. The attack described in the research was highly targeted by nation-states against specific individuals. We always urge customers to download the latest version of the software to protect themselves and their data.”

An Apple spokesman said the company has not been able to independently verify the Citizen Lab findings.

Researchers have yet to determine the precise iOS vulnerability used in these attacks, but Citizen Lab says the exploits don’t work against iOS 14, which was released in September. Anyone still using an older version should upgrade.

Source link

Previous Post

Fortnite now has a Black Panther skin and a Wakanda Forever emote

Next Post

‘Dozens of email accounts’ were hacked at U.S. Treasury -Senator Wyden By Reuters

admin

admin

Next Post
‘Dozens of email accounts’ were hacked at U.S. Treasury -Senator Wyden By Reuters

'Dozens of email accounts' were hacked at U.S. Treasury -Senator Wyden By Reuters

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Republicans attempted to add a little voter suppression to Georgia runoff Monday and failed

Republicans attempted to add a little voter suppression to Georgia runoff Monday and failed

November 24, 2020

Crafting Guide: How to Craft, Components, and More – Cyberpunk 2077 Wiki Guide

December 13, 2020
Iron and Vegetable Oil Are a Deadly Combo

Iron and Vegetable Oil Are a Deadly Combo

December 2, 2020
COVID in Pregnancy Won’t Affect Outcomes: Study

COVID in Pregnancy Won’t Affect Outcomes: Study

November 27, 2020
HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

0

With 150 million daily active users, Instagram Stories is launching ads

0

Washington prepares for Donald Trump’s big moment

0

CS:GO ELeague Major pools and tournament schedule announced

0
HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

January 20, 2021
It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

January 20, 2021
Australia sweltered through its 4th-hottest year in 2020

Zimbabwe’s foreign minister dies of COVID-19 amid resurgence

January 20, 2021
The glory of this day will be capped by the most historic Senate swearing-in ceremony ever

The glory of this day will be capped by the most historic Senate swearing-in ceremony ever

January 20, 2021

Recent News

HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

January 20, 2021
It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

January 20, 2021
Australia sweltered through its 4th-hottest year in 2020

Zimbabwe’s foreign minister dies of COVID-19 amid resurgence

January 20, 2021
The glory of this day will be capped by the most historic Senate swearing-in ceremony ever

The glory of this day will be capped by the most historic Senate swearing-in ceremony ever

January 20, 2021

Browse by Category

  • Business
  • Entertainment
  • Fashion
  • Food
  • Gaming
  • Health
  • Lifestyle
  • Movie
  • Music
  • News
  • Politics
  • Review
  • Science
  • Sports
  • Startup
  • Tech
  • Travel
  • World

Recent News

HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

HITMAN 3 Is Now Available For Xbox One And Xbox Series X|S

January 20, 2021
It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

It’s Been 20 Years Since Sara Evans’ “Born to Fly” Flew to No. 1

January 20, 2021

© 2020 Jamaruku.online

No Result
View All Result

© 2020 Jamaruku.online