🎉 Dear reader,
As 2023 draws to a close, I want to extend a heartfelt thank you for being an integral part of my journey this year. Your engagement and feedback have been invaluable in shaping the Mandos Brief newsletter.
As we bid farewell to this year and look towards 2024, I wish you a Happy New Year filled with peace, prosperity, and strengthened digital security. The challenges in cybersecurity continue, but together, we remain vigilant and informed.
In this final edition of the year, we explore the latest and most critical developments in the cybersecurity landscape. From sophisticated iPhone backdoors to extensive data breaches impacting millions, these stories remind us of the ongoing need for vigilance and proactive measures in our digital lives.
See you in 2024, ready to face new challenges and embrace the opportunities that lie ahead in the world of cybersecurity.
Warm regards,
Nikoloz
Now back to the news...
TL;DR
- The Most Advanced iPhone Backdoor Exploited Apple's Hidden Hardware Feature
- International Operation Uncovers 443 Online Merchants Compromised by Digital Skimming
- EasyPark Hit by Widespread Data Breach, Affecting Millions of Customers
- Mint Mobile Suffers Data Breach, Exposing Customer Data and Risking SIM Swap Attacks
- Microsoft Disables MSIX App Installer Protocol Amid Ransomware Threats
The Most Advanced iPhone Backdoor Exploited Apple's Hidden Hardware Feature
- Operation Triangulation Exposed: The highly sophisticated spyware attack on iOS devices, known as Operation Triangulation, leveraged four zero-day flaws to bypass Apple's hardware-based security protections. Identified by Kaspersky, this campaign, active since 2019, was notable for its ability to gain deep access and backdoor iOS devices up to version 16.2.
- Zero-Click Attack Mechanism: The attack initiated through a zero-click iMessage with a malicious attachment, exploiting vulnerabilities like CVE-2023-41990, CVE-2023-32434, CVE-2023-32435, and CVE-2023-38606. These vulnerabilities enabled arbitrary code execution and kernel privilege escalation, with CVE-2023-38606 notably allowing bypass of kernel memory hardware protection.
- Unique Hardware Feature Targeted: The most striking aspect of the attack was its exploitation of undocumented memory-mapped I/O (MMIO) registers in Apple A12-A16 Bionic SoCs. This was likely an obscure hardware feature intended for debugging or testing, previously unknown in public documentation.
- Sophisticated Spyware Tools: The attack deployed the TriangleDB implant, featuring modules for recording via the microphone, extracting iCloud Keychain, stealing app data, and location tracking. The implant included validators to ensure targets were not research devices, and employed techniques like browser fingerprinting to avoid detection.