#1 Trending Cybersecurity News & Magazine
Thursday, September 28, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    ZenLedger data sale

    ZenLedger Data Leak Claim Surfaces on the Dark Web

    CACTUS Cyber Attack

    Unraveling the CACTUS Ransomware Group’s Recent Exploits

    MOVEit Breach Statistics

    Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

    MEDUSA Cyber Attack

    MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

    Ferguson Wellman cyber attack

    50 Targets and Counting: LostTrust Claims Ferguson Wellman Cyber Attack

    Iran Telecom Cyber Attack

    Iran Telecom Cyber Attack: APT IRAN Claims Access to 4TB of Data

    BORN Data Breach

    Ontario Grapples with Unprecedented Data Breach Impacting Newborn Care Registries

    Sony Data Leak

    “Major Nelson” Claims Sony Data Leak Alleging RansomedVC Lied

    Waterloo Media Data Breach

    Waterloo Media Faces Data Breach by NoEscape Ransomware Group

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    ZenLedger data sale

    ZenLedger Data Leak Claim Surfaces on the Dark Web

    CACTUS Cyber Attack

    Unraveling the CACTUS Ransomware Group’s Recent Exploits

    MOVEit Breach Statistics

    Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

    MEDUSA Cyber Attack

    MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

    Ferguson Wellman cyber attack

    50 Targets and Counting: LostTrust Claims Ferguson Wellman Cyber Attack

    Iran Telecom Cyber Attack

    Iran Telecom Cyber Attack: APT IRAN Claims Access to 4TB of Data

    BORN Data Breach

    Ontario Grapples with Unprecedented Data Breach Impacting Newborn Care Registries

    Sony Data Leak

    “Major Nelson” Claims Sony Data Leak Alleging RansomedVC Lied

    Waterloo Media Data Breach

    Waterloo Media Faces Data Breach by NoEscape Ransomware Group

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Apple Tackles Zero-Day Vulnerability in iPhones, iPads, and Macs, Deploys Rapid Security Patches

The CVE-2023-37450 vulnerability exists in WebKit, the browser engine used by Apple's Safari and other web browsers on iOS and iPadOS.

Ashish Khaitan by Ashish Khaitan
July 11, 2023
in Firewall Daily, Vulnerabilities
0
Rapid Security Response
600
SHARES
3.3k
VIEWS
Share on LinkedInShare on Twitter

Apple is fixing multiple new vulnerabilities in its products.

According to the latest Rapid Security Response announcement, Apple has taken decisive action to fix a critical zero-day vulnerability, CVE-2023-37450. This vulnerability has been actively exploited and could lead to arbitrary code execution.

You might also like

ZenLedger Data Leak Claim Surfaces on the Dark Web

Unraveling the CACTUS Ransomware Group’s Recent Exploits

Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

The CVE-2023-37450 vulnerability exists in WebKit, the browser engine used by Apple’s Safari and other web browsers on iOS and iPadOS.

The exploitation of this vulnerability can be triggered by processing specially crafted malicious web content, potentially leading to arbitrary code execution. An anonymous security researcher reported the issue, which has been addressed through improved checks.

However, Apple’s commitment to Rapid Security Response patches for user security also presents certain limitations. The company’s stringent upgrade policies restrict users from uninstalling full system updates, even if they encounter genuine issues.

This approach prevents downgrades that could reintroduce old bugs exploited for jailbreaking or installing alternative operating systems. 

Apple Security Response patches: Does it help?

The Silicon Valley tech giant has implemented the Rapid Security Response system to address these Apple vulnerabilities.

This system focuses on a subset of software components that are commonly targeted by cybercriminals for launching cyber attacks, particularly Safari and other web browsing elements. By prioritizing these components, Apple aims to patch vulnerabilities quickly and efficiently. 

Rapid Security Response updates are available for macOS Ventura 13.4.1, iOS 16.5.1, and iPadOS 16.5.1. After applying the rapid patch, the versions will display 13.4.1 (a) and 16.5.1 (a), respectively.

In the case of older supported versions of macOS Big Sur and macOS Monterey, a traditional system update is available solely for patching Safari, resulting in Safari version 16.5.2.

While these updates cater to the latest Apple platforms, it’s important to note that as of now (as of July 10, 2023), there are no updates available for other Apple systems, including iOS 15, older iPhones and iPads, Apple Watches, and TVs.

It remains possible that these platforms are also affected by the vulnerability mentioned above. Users are advised to monitor Apple’s general Security Portal and the new Rapid Security Response page to stay informed about updates for other Apple systems.

Apple’s Rapid Security Response: A new way of dealing with vulnerabilities

It’s worth mentioning that Apple introduced the Rapid Security Response updates in May 2023. These updates serve as crucial security enhancements between regular software updates, focusing on components such as Safari, the WebKit framework stack, and critical system libraries.

In addition to providing faster mitigation for security issues, including those that have been actively exploited or reported, these rapid patches can be uninstalled by users if necessary, differentiating them from regular security updates.

Apple’s Rapid Security Response updates have set a benchmark in the industry for their speed and wide-scale deployment across millions of devices. By enabling automatic updates, Apple ensures that most customers receive these security updates seamlessly.

Debrup Ghosh, Senior Product Manager at Synopsys Software Integrity Group, highlights the significance of Apple’s swift response, emphasizing the importance of addressing vulnerabilities promptly and efficiently.

While every effort is made to eliminate vulnerabilities during development and testing, they can occasionally slip through the cracks.

However, the critical factor lies in an organization’s ability to quickly fix and remediate these vulnerabilities, preventing or mitigating active exploits. Apple’s Rapid Security Updates demonstrate an effective and efficient approach toward achieving this goal.

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: Apple Rapid Security ResponseRapid Security ResponseThe Cyber ExpressThe Cyber Express News
Previous Post

Malicious GitHub Page Disguised as PUBG Bypass Hack; Users Exposed to ‘Legion Stealer Infostealer

Next Post

Amplifying Digital Defenses: How VPNs Elevate Cybersecurity in an Interconnected World

Ashish Khaitan

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Related Posts

ZenLedger data sale
Firewall Daily

ZenLedger Data Leak Claim Surfaces on the Dark Web

by Vishwa Pandagle
September 27, 2023
CACTUS Cyber Attack
Firewall Daily

Unraveling the CACTUS Ransomware Group’s Recent Exploits

by Ashish Khaitan
September 27, 2023 - Updated on September 28, 2023
MOVEit Breach Statistics
Data Breach News

Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

by Vishwa Pandagle
September 27, 2023
MEDUSA Cyber Attack
Firewall Daily

MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

by Ashish Khaitan
September 27, 2023
Ferguson Wellman cyber attack
Firewall Daily

50 Targets and Counting: LostTrust Claims Ferguson Wellman Cyber Attack

by Vishwa Pandagle
September 27, 2023
Next Post
Surfshark, VPN, Secure VPN Solutions

Amplifying Digital Defenses: How VPNs Elevate Cybersecurity in an Interconnected World

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

ZenLedger data sale
Firewall Daily

ZenLedger Data Leak Claim Surfaces on the Dark Web

September 27, 2023
CACTUS Cyber Attack
Firewall Daily

Unraveling the CACTUS Ransomware Group’s Recent Exploits

September 27, 2023
MOVEit Breach Statistics
Data Breach News

Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

September 27, 2023
MEDUSA Cyber Attack
Firewall Daily

MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

September 27, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance