๐๐ฉ๐๐ซ๐๐ญ๐ข๐จ๐ง ๐๐ซ๐ข๐๐ง๐ ๐ฎ๐ฅ๐๐ญ๐ข๐จ๐ง: Unraveling the Most Advanced iPhone Attack that used four 0-day vulnerabilities
Security researchers at Kaspersky reveal the intricacies of “Operation Triangulation,” on Dec 27th, 2023, at the Chaos Communication Congress.
So why is this important? This was an extremely sophisticated iMessage vulnerability spanning from 2019 to December 2022. The attack chain, which has been labeled the “most sophisticated” ever seen, utilized four 0-day vulnerabilities, including a Pegasus 0-click iMessage exploit.
๐ต๐๐๐๐๐ ๐ค๐ ๐๐๐ฃ๐ ๐๐๐ก๐ ๐กโ๐ ๐๐๐ก๐๐๐๐ , ๐ผ ๐ค๐๐ข๐๐ ๐๐๐๐ ๐ก๐ ๐ ๐๐ฆ ๐กโ๐๐ก ๐กโ๐๐ ๐๐โ๐๐๐ ๐๐ก๐ก๐๐๐ ๐ข๐๐๐๐๐ ๐๐๐๐๐ ๐๐ ๐๐๐๐๐๐๐๐ ๐๐๐ฃ๐๐ ๐๐ ๐ ๐๐โ๐๐ ๐ก๐๐๐๐ก๐๐๐ ๐ค๐๐กโ 4 ๐ง๐๐๐-๐๐๐ฆ๐ . ๐โ๐ ๐๐ฆ๐ ๐ก๐๐๐ฆ ๐ ๐ข๐๐๐๐ข๐๐๐๐๐ ๐ถ๐๐ธ-2023-38606 ๐๐๐โ๐๐ ๐๐ง๐๐ ๐กโ๐ ๐๐๐๐ ๐๐๐ ๐๐๐๐ข๐ ๐ก ๐๐ฆ๐๐๐๐ ๐๐๐ข๐๐๐ก๐ฆ. ๐ผ๐๐ก๐๐๐๐๐ก๐๐๐ ๐ด๐ผ ๐๐๐ก๐ ๐ ๐ข๐โ ๐๐ฅ๐๐๐๐๐ก๐ ๐ค๐๐๐ ๐๐๐๐ฆ ๐๐๐๐๐๐๐ฆ ๐กโ๐๐๐๐ก๐ , ๐๐๐๐ข๐๐๐๐๐ ๐ฃ๐๐๐๐๐๐๐ก ๐ด๐ผ ๐๐๐๐๐๐ ๐๐ , ๐ก๐ ๐๐ ๐๐๐๐๐ก๐๐.
In the current world where Generative AI can pentest systems, and move faster than a human can react. “๐ฆ๐๐๐๐ฒ๐บ๐ ๐๐ต๐ฎ๐ ๐ฟ๐ฒ๐น๐ ๐ผ๐ป ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ต๐ฟ๐ผ๐๐ด๐ต ๐ผ๐ฏ๐๐ฐ๐๐ฟ๐ถ๐๐ ๐ฐ๐ฎ๐ป ๐ป๐ฒ๐๐ฒ๐ฟ ๐ฏ๐ฒ ๐๐ฟ๐๐น๐ ๐๐ฒ๐ฐ๐๐ฟ๐ฒ.”
Just to be clear although I am talking about AI above. This finding was before GenAI took off. My goal is to bring awareness to this now so that security teams start fighting AI with AI.
—– Back to the post —–
๐๐๐ฒ ๐๐จ๐ข๐ง๐ญ๐ฌ:
๐น Attackers exploited a remote code execution vulnerability (CVE-2023-41990) in Apple’s ADJUST TrueType font instruction, remaining undetected by users.
๐น The attack involved return/jump-oriented programming, multiple stages, and an obfuscated JavaScript exploit with around 11,000 lines of code.
Vulnerabilities in XNU’s memory mapping syscalls (CVE-2023-32434) and hardware memory-mapped I/O registers were crucial in obtaining read/write access to the device’s entire physical memory.
๐น The attack chain concluded with the exploitation of CVE-2023-32435 through a Safari exploit, executing a shellcode and obtaining root privileges for loading spyware.
๐น Researchers emphasize the mystery surrounding CVE-2023-38606 and invite iOS security researchers to contribute insights, highlighting the insecurity of systems relying on “security through obscurity.”
The researchers plan to delve deeper into each vulnerability in 2024.
#Cybersecurity #ai #security #zerotrust #ciso #infosec #genai VOCAL Council Theia Institute Peer Insights Gartner InsightJam.com Bot Nirvana
๐ก๐ผ๐๐ถ๐ฐ๐ฒ: The views expressed in this post are my own. The views within any of my posts or articles are not those of my employer or the employers of any contributing experts. ๐๐ถ๐ธ๐ฒ ๐ this post? Click ๐๐ต๐ฒ ๐ฏ๐ฒ๐น๐น icon ๐ for more!
for more!