Hi friends,
For those who celebrate, I hope you all enjoyed a wonderful Christmas, and are about to enjoy a wonderful New Year's!
Because I don't want you to spend all your time reading security news I tried to keep it short, although the breaches section is much longer than I'd like. Maybe just skim that one, ok? ;-)
Have a good one folks!
Researchers from Kaspersky revealed details of an incredibly sophisticated backdooring campaign targeting iPhones, iPads and Mac's. It uses a set of hardware functions that aren't documented anywhere, leaving researchers to guess as to how it was created.
Attribution seems difficult, because it's very different from other known campaigns, although the Russian CERT attributes the attacks to the NSA, with the FSB alleging that Apple themselves helped out, although Apple denies that.
It used a total of four zero-days, in a very impressive exploit chain, shown and described in the article. All four vulnerabilities have now been patched.
If you contribute code on Github, you will have to enable 2FA by January 19th or be limited in your access until you do. It doesn't count for business or enterprise accounts though, unfortunately. Not yet anyway. After the 19th you won't be able to disable 2fa, only replace it with other methods. They offer pretty much any method available: security keys, passkeys, their mobile app, authenticator apps (TOTP), and SMS text messages. I'm all for this, way to go Github.
Lapsus member Arion Kurtaj has been sentenced indefinitely in a 'secure hospital' by a UK judge, due to his autism. Another Lapsus member, aged 17, was also found guilty. It's easy to be dismissive over their age, but it is impressive, in a bad way, to see their list of corporate victims: Rockstar Games, Okta, Uber, Revolut, Microsoft, Samsung, NVIDIA, and many others.