Wormable Apple iCloud Bug Allows Automatic Photo Theft
Friday, October 9, 2020
The team was ultimately able to create a proof of concept that demonstrated code that steals all of the victim’s personal iCloud information (photos, calendar information and documents) then forwards the same exploit to all of their contacts.
Ilia Kolochenko, founder and CEO of web security company ImmuniWeb, said that the success of the bounty-hunters should be a wake-up call.
“Unfortunately, there is no warranty that these vulnerabilities have not been exploited by sophisticated threat actors to silently compromise VIP victims,” he said via email. “Worse, likely more similar vulnerabilities exist undiscovered and may be known to hacking groups that make a lot of money by their exploitation. Modern web applications open the door to corporate networks with the most critical information, and their breach can be fatal for a company.” Read Full Article
teiss: Crown Prosecution Service suffered 1,627 data security incidents in 2019-20
Threatpost: Las Vegas Students’ Personal Data Leaked, Post-Ransomware Attack