Tag

Security Vulnerabilities

All articles tagged with #security vulnerabilities

Apple patches iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 to fix ~30 vulnerabilities
technology11 days ago

Apple patches iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 to fix ~30 vulnerabilities

Apple released iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 to fix nearly 30 vulnerabilities (21 WebKit; 9 OpenAI Codex Security), including kernel flaws, WebKit memory issues, an audio leak, and a telephony flaw that could bypass IPSec. Apple notes fixes were backported to iOS 27/iPadOS 27 and macOS Golden Gate betas. No exploits are known, but updating is advised; older devices can get iOS 18.7.10/iPadOS 18.7.10, and macOS Tahoe patch is available for Macs that can run Tahoe. Install via Settings > General > Software Update.

Iranian FM narrowly survives Israeli strike, warns of insider security gaps
middle-east1 month ago

Iranian FM narrowly survives Israeli strike, warns of insider security gaps

Iranian Foreign Minister Abbas Araghchi recounts surviving an Israeli strike on a bunker hosting senior officials, describing the devastation and warning of serious security vulnerabilities including possible insider infiltration; he cites precise Israeli intelligence, notes emergency procedures and codes like Code 110, and details diplomatic efforts to prevent further fronts, while indicating Mojtaba Khamenei’s status remains highly secret and that Iran’s strategic gains were unlikely to be undone in the war’s first two weeks.

Nearby attackers can crash AirDrop and Quick Share, researchers warn
technology1 month ago

Nearby attackers can crash AirDrop and Quick Share, researchers warn

Researchers disclosed six local flaws in AirDrop and Quick Share that let nearby attackers crash the receiving devices or bypass session checks. Apple and Google have begun patching these flaws (Apple has assigned a CVE; Google fixed the Windows Quick Share bug; Samsung’s issues are under investigation). The exploits are local (about 10–30 meters or on the same LAN) and affect macOS/iOS, Samsung Quick Share, and Windows Quick Share. Users should update to the latest OS and adjust AirDrop to Contacts Only or disable Everyone, and limit Quick Share visibility when not actively receiving.

technology8 months ago

GPG Failure Highlights Security Concerns

The article discusses concerns about GnuPG's security issues, including a significant vulnerability that allows plaintext recovery, and debates whether GPG signatures on git commits are secure or if alternatives like SSH keys or Signal should be used for secure communication and signing. It highlights the complexity and flaws in PGP's design, the challenges of key management, and the political and technical difficulties in replacing or improving upon existing cryptographic tools.

Outdated Web Browsers in Smart Devices Pose Security Risks
technology8 months ago

Outdated Web Browsers in Smart Devices Pose Security Risks

Research from KU Leuven highlights that embedded browsers in devices like smart TVs, e-readers, and gaming applications are often outdated and lack security updates, leaving users vulnerable to cyber threats. Many devices ship with browsers several years behind current versions, and some manufacturers do not provide necessary security patches, raising concerns about device security and regulatory compliance. The study emphasizes the need for regulations to enforce timely updates and security measures for embedded browsers.

FFmpeg Demands Funding or Ceases Bug Reports from Google
technology9 months ago

FFmpeg Demands Funding or Ceases Bug Reports from Google

FFmpeg, a vital open-source multimedia framework used widely across platforms, faces challenges due to underfunding and reliance on volunteers for fixing security vulnerabilities, highlighted by a recent obscure bug found by Google's AI. The debate centers on whether large corporations like Google should provide more support and patches, or if the current volunteer-driven model is sustainable, especially as AI uncovers more security issues. The situation underscores the need for better funding and support for critical open-source projects to ensure their security and longevity.

OpenAI’s ChatGPT Atlas Faces Security Risks Amid Web Enhancements
technology10 months ago

OpenAI’s ChatGPT Atlas Faces Security Risks Amid Web Enhancements

Cybersecurity experts warn that OpenAI's ChatGPT Atlas, an AI browser with new features like memory and agent mode, faces significant security risks including prompt injection attacks that could lead to data theft, malware downloads, and other malicious activities. Despite mitigation efforts by OpenAI, the attack surface is expanding, raising concerns about privacy, data sharing, and user safety as these AI tools become more integrated into internet browsing.

Google Confirms Android Vulnerability Affecting 1 Billion Phones
technology11 months ago

Google Confirms Android Vulnerability Affecting 1 Billion Phones

Google has confirmed that two critical vulnerabilities affecting Android devices are actively exploited in the wild, impacting over a billion phones, with no immediate fix for older devices. Pixel phones will be updated quickly, but many other Android devices may remain vulnerable due to outdated software, emphasizing the need for users to upgrade their devices to stay protected. The vulnerabilities could allow privilege escalation without user interaction, posing significant security risks.

Google Patches 120 Android Flaws, Including Critical Zero-Days
technology11 months ago

Google Patches 120 Android Flaws, Including Critical Zero-Days

Google has revealed two critical security vulnerabilities affecting Android devices, which are being exploited in the wild. While Pixel phones will be updated immediately, many older devices no longer supported are at risk, highlighting the importance of upgrading to newer models to ensure security. Over half of mobile devices run outdated OS versions, increasing vulnerability to attacks.

EV Charger Hack Now More Dangerous, Poses Fire Risk
technology1 year ago

EV Charger Hack Now More Dangerous, Poses Fire Risk

Researchers from Trend Micro demonstrated that hacking EV chargers can cause them to overheat and catch fire, posing a serious safety risk. The vulnerabilities stem from design flaws that allow physical modifications, leading to potential house fires. Experts recommend avoiding coiled cables, using shorter cords, and urging manufacturers to implement hardware-only safety mechanisms to prevent such hazards.