#1 Trending Cyber Security News & Magazine
Monday, June 5, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    DPRK’s Social Engineering Campaign Targets Think Tanks, Academia, and Media

    DPRK’s Social Engineering Campaign Targets Think Tanks, Academia, and Media

    Billtrust Appoints Ankur Ahuja

    Billtrust Appoints Ankur Ahuja as SVP and Chief Information Security Officer

    NoEscape Ransomware-as-a-Service (RaaS)

    NoEscape Ransomware-as-a-Service (RaaS): Triple-Extortion Affiliate Program Unveiled

    SharpPanda APT Targets High-Level Government Officials From G20 Nations

    SharpPanda APT Targets High-Level Government Officials From G20 Nations

    YKK Ransomware Attack

    LockBit Claims to Hit Global Zipper Giant YKK, Sets 14-Day Deadline

    SmokeLoader Malware

    SmokeLoader Malware Adopts New Tactics, Raises Serious Security Concerns

    Camaro Dragon

    Camaro Dragon Expands Cyber Espionage Operations with TinyNote Backdoor

    Vulnerability In MOVEit Transfer

    Vulnerability in MOVEit Transfer Exploited in the Wild

    Google Workspace security

    A Google Workspace Security Issue Can Allow Data Exfiltration Without Any Logs

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Martin Sloan, Five Years Of GDPR

    Five Years of GDPR: There is a Long Way to Run on Cross-Border Data Transfers

    Nokoyawa Ransomware Group

    All You Need to Know About The Nokoyawa Ransomware Group

    StopRansomware Guide

    Updated StopRansomware Guide Warns of Ransomware’s Shape Shifting Tactics

    Microsoft Entra

    Microsoft Build 2023: Microsoft Entra Introduced With New Identity and Access Features

    Data Protection Commission

    Irish Data Protection Commission imposes $1.3bn Fine on Meta

    US Police Auction Seized Cell Phones Without Wiping Data, Sparks Privacy Concerns

    US Police Auction Seized Cell Phones Without Wiping Data, Sparks Privacy Concerns

    disclosing cybersecurity incidents

    Why Victims Fail to Disclose Cybersecurity Incidents, And Why They Should

    Stakeholder Communication During Crisis

    Stakeholder Communication During Crisis: How to Get It Right

    Government Regulation of AI businesses

    Government Regulation of AI businesses: UK Competition Watchdog Launches Review

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Billtrust Appoints Ankur Ahuja

    Billtrust Appoints Ankur Ahuja as SVP and Chief Information Security Officer

    Cybertech Africa

    Cybertech Africa: The Pan-African Event for Innovation and Networking

    IBM Acquired Polar Security

    IBM Acquires Polar Security Reportedly For $60 Million

    World CyberCon Middle East 2023

    World CyberCon Middle East 2023: The Premier Cybersecurity Conference in the Region

    ODIN by Cyble

    Cyble Launches ODIN: A Revolutionary Tool for Unparalleled Internet Exploration

    cybersecurity investments

    Cybersecurity Investments Up in April, Market Watchers Predict Growth of Over $700 billion

    OilRig APT

    Experts Warn of Increased IT Supply Chain Attacks by OilRig APT in Middle East

    World Password Day 2023

    World Password Day 2023: Protect Your Password, Create an Unbreakable One

    national cybersecurity strategy

    US National Cybersecurity Strategy: Businesses, Let’s Start with Disclosure!

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    DPRK’s Social Engineering Campaign Targets Think Tanks, Academia, and Media

    DPRK’s Social Engineering Campaign Targets Think Tanks, Academia, and Media

    Billtrust Appoints Ankur Ahuja

    Billtrust Appoints Ankur Ahuja as SVP and Chief Information Security Officer

    NoEscape Ransomware-as-a-Service (RaaS)

    NoEscape Ransomware-as-a-Service (RaaS): Triple-Extortion Affiliate Program Unveiled

    SharpPanda APT Targets High-Level Government Officials From G20 Nations

    SharpPanda APT Targets High-Level Government Officials From G20 Nations

    YKK Ransomware Attack

    LockBit Claims to Hit Global Zipper Giant YKK, Sets 14-Day Deadline

    SmokeLoader Malware

    SmokeLoader Malware Adopts New Tactics, Raises Serious Security Concerns

    Camaro Dragon

    Camaro Dragon Expands Cyber Espionage Operations with TinyNote Backdoor

    Vulnerability In MOVEit Transfer

    Vulnerability in MOVEit Transfer Exploited in the Wild

    Google Workspace security

    A Google Workspace Security Issue Can Allow Data Exfiltration Without Any Logs

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Martin Sloan, Five Years Of GDPR

    Five Years of GDPR: There is a Long Way to Run on Cross-Border Data Transfers

    Nokoyawa Ransomware Group

    All You Need to Know About The Nokoyawa Ransomware Group

    StopRansomware Guide

    Updated StopRansomware Guide Warns of Ransomware’s Shape Shifting Tactics

    Microsoft Entra

    Microsoft Build 2023: Microsoft Entra Introduced With New Identity and Access Features

    Data Protection Commission

    Irish Data Protection Commission imposes $1.3bn Fine on Meta

    US Police Auction Seized Cell Phones Without Wiping Data, Sparks Privacy Concerns

    US Police Auction Seized Cell Phones Without Wiping Data, Sparks Privacy Concerns

    disclosing cybersecurity incidents

    Why Victims Fail to Disclose Cybersecurity Incidents, And Why They Should

    Stakeholder Communication During Crisis

    Stakeholder Communication During Crisis: How to Get It Right

    Government Regulation of AI businesses

    Government Regulation of AI businesses: UK Competition Watchdog Launches Review

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Billtrust Appoints Ankur Ahuja

    Billtrust Appoints Ankur Ahuja as SVP and Chief Information Security Officer

    Cybertech Africa

    Cybertech Africa: The Pan-African Event for Innovation and Networking

    IBM Acquired Polar Security

    IBM Acquires Polar Security Reportedly For $60 Million

    World CyberCon Middle East 2023

    World CyberCon Middle East 2023: The Premier Cybersecurity Conference in the Region

    ODIN by Cyble

    Cyble Launches ODIN: A Revolutionary Tool for Unparalleled Internet Exploration

    cybersecurity investments

    Cybersecurity Investments Up in April, Market Watchers Predict Growth of Over $700 billion

    OilRig APT

    Experts Warn of Increased IT Supply Chain Attacks by OilRig APT in Middle East

    World Password Day 2023

    World Password Day 2023: Protect Your Password, Create an Unbreakable One

    national cybersecurity strategy

    US National Cybersecurity Strategy: Businesses, Let’s Start with Disclosure!

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Threat Actors are Exploiting Two iPhone Vulnerabilities, Warns CISA

The vulnerabilities seem to directly impact iOS and iPadOS users, especially those using the versions iOS 15.7.5 and iPadOS 15.7.5.

Ashish Khaitan by Ashish Khaitan
April 11, 2023
in Firewall Daily, Vulnerabilities
0
Known Exploited Vulnerabilities Catalog
598
SHARES
3.3k
VIEWS
Share on LinkedInShare on Twitter

CISA has added two new vulnerabilities, CVE-2023-28206 and CVE-2023-28205, to its known Exploited Vulnerabilities Catalog. 

The vulnerabilities seem to directly impact iOS and iPadOS users, especially those using the versions iOS 15.7.5 and iPadOS 15.7.5.

You might also like

Microsoft Edge Vulnerability Report Addresses a Low Severity Bug

NoName DDoS Attack on Lithuania: Threat Group Hits Logistics and Transportation

All You Need to Know About the MOVEit Transfer Critical Vulnerability

Apple recently released iOS 15.7.5 and iPadOS 15.7.5, with important security updates. The security content of iOS 15.7.5 and iPadOS 15.7.5 has been documented, highlighting some vulnerabilities that could seriously affect users.

“Apple is aware of a report that this issue may have been actively exploited,” the company said in the patch statement for both CVE-2023-28206 and CVE-2023-28205.

CVE-2023-28206 and CVE-2023-28205 explained 

One of the vulnerabilities that iOS 15.7.5 and iPadOS 15.7.5 aim to fix is related to the IOSurfaceAccelerator, which affects several Apple devices, including iPhone 6s, iPhone 7, iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation). 

According to the documentation, an app may be able to execute arbitrary code with kernel privileges due to an out-of-bounds write issue.

Apple has acknowledged that this issue may have been actively exploited and has addressed it by improving input validation.

The vulnerability has been identified as CVE-2023-28206 and was reported by Clément Lecigne of Google’s Threat Analysis Group and Donncha Ó Cearbhaill of Amnesty International’s Security Lab.

The other vulnerability that has been addressed in iOS 15.7.5 and iPadOS 15.7.5 is related to the WebKit, which also affects several Apple devices, including iPhone 6s, iPhone 7, iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation).

The documentation states that processing maliciously crafted web content could lead to arbitrary code execution. 

Apple Patches CVE-2023-28206 and CVE-2023-28205

Apple has taken swift action to address these vulnerabilities, and users are strongly advised to update their devices to iOS 15.7.5 and iPadOS 15.7.5 to protect them against these security threats.

The release of iOS 15.7.5 and iPadOS 15.7.5 comes with important security updates, addressing vulnerabilities that could seriously affect users. 

While it is reassuring to know that Apple is taking steps to address these vulnerabilities, users must also take responsibility for their security by ensuring that their devices are updated to the latest iOS or iPadOS. By doing so, users can protect themselves against potential security threats and enjoy a safer online experience.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: CISAKnown Exploited Vulnerabilities Catalog
Previous Post

FusionCore Group Sells SarinLocker Ransomware for $100 on Underground Forums

Next Post

Dark Angels Ransomware’s Spin-off Dunghill Leak Claims Incredible Technologies as First Victim

Ashish Khaitan

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Related Posts

Microsoft Edge vulnerability
Firewall Daily

Microsoft Edge Vulnerability Report Addresses a Low Severity Bug

by Vishwa Pandagle
June 5, 2023
NoName DDoS Attack On Lithuania
Firewall Daily

NoName DDoS Attack on Lithuania: Threat Group Hits Logistics and Transportation

by Ashish Khaitan
June 5, 2023
All You Need to Know About the MOVEit Transfer Critical Vulnerability
Firewall Daily

All You Need to Know About the MOVEit Transfer Critical Vulnerability

by Vishwa Pandagle
June 5, 2023
Hep Global Data Breach
Firewall Daily

Hep Global Data Breach: Darkrace Ransomware Group Strikes Renewable Energy Sector

by Ashish Khaitan
June 5, 2023
DPRK’s Social Engineering Campaign Targets Think Tanks, Academia, and Media
Espionage

DPRK’s Social Engineering Campaign Targets Think Tanks, Academia, and Media

by Editorial
June 3, 2023
Next Post
Dark Angels Ransomware’s Spin-off Dunghill

Dark Angels Ransomware’s Spin-off Dunghill Leak Claims Incredible Technologies as First Victim

Latest Issue is Out. Subscribe Now

Cyber express

CRIL


Follow Us On Google News

Never miss an update. Subscribe!

* indicates required

mailchimp

Latest Cyber News

DPRK’s Social Engineering Campaign Targets Think Tanks, Academia, and Media
Espionage

DPRK’s Social Engineering Campaign Targets Think Tanks, Academia, and Media

June 3, 2023
Billtrust Appoints Ankur Ahuja
Appointments

Billtrust Appoints Ankur Ahuja as SVP and Chief Information Security Officer

June 3, 2023
NoEscape Ransomware-as-a-Service (RaaS)
Dark Web News

NoEscape Ransomware-as-a-Service (RaaS): Triple-Extortion Affiliate Program Unveiled

June 3, 2023
SharpPanda APT Targets High-Level Government Officials From G20 Nations
Firewall Daily

SharpPanda APT Targets High-Level Government Officials From G20 Nations

June 2, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cyber Security News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance