Thursday 19th September 2024

Thursday 19th September 2024

Good morning! From Australian cops cracking down on an encrypted criminal network, to hackers claiming they've breached Temu, and a zero-click macOS exploit chain that had Apple scrambling, the tech world has been busy this week. Just like Ghost, the criminal communication app that met its demise, Temu is fighting off claims of a data breach, while Apple patches up serious vulnerabilities in macOS. It’s a reminder: Whether it’s in law enforcement or cybersecurity, no one’s safe from being hacked, backdoored, or just plain outsmarted. Buckle up!


Operation Kraken: AFP Takes Down Criminal Communication App


The Australian Federal Police (AFP) arrested a man accused of creating and administering Ghost, an encrypted communication platform allegedly designed for the criminal underworld. Ghost, launched nearly a decade ago, was sold with modified smartphones for AU$2350 ($1,600), offering encrypted messaging and tech support. Authorities claim the app facilitated drug trafficking, money laundering, and violent crimes.

In a major operation, the AFP infiltrated Ghost by tampering with regular software updates, gaining access to devices. This led to coordinated raids across four Australian states, resulting in 38 arrests, the seizure of illicit weapons, and the prevention of 50 violent incidents.

Ghost reportedly had 376 active users in Australia, including members of Italian Organized Crime and outlaw motorcycle gangs. The AFP’s success in this operation highlights the ongoing effort to combat encrypted criminal networks globally.


macOS Zero-Click Exploit Chain Exposed


A recently discovered zero-click exploit chain in macOS revealed vulnerabilities that could have allowed attackers to remotely compromise iCloud data without any user interaction. Researcher Mikko Kentt?l? found the attack began with a flaw in how macOS handled files attached to Calendar events (CVE-2022-46723, CVSS 9.8). By sending a malicious file via a calendar invite, attackers could achieve remote code execution and bypass Apple's Gatekeeper and Transparency, Consent, and Control (TCC) protections.

The exploit leveraged path traversal to execute malicious code, manipulate system files, and ultimately steal iCloud Photos. Despite its severity, Apple has since patched these vulnerabilities, addressing them over a series of updates between October 2022 and September 2023.

Zoom out: While macOS's native security features like Gatekeeper are strong, this exploit demonstrates how persistent attackers can still bypass protections. Similar issues affect Windows, highlighting the need for constant vigilance and updates across all platforms.

Temu Denies Data Breach Amid Allegations of Stolen Customer Records


Temu, the rapidly growing e-commerce platform, is denying claims of a data breach after a hacker posted on the BreachForums hacking forum, offering to sell a database allegedly containing 87 million records of customer information. The threat actor, using the alias 'smokinthashit', shared a sample of the supposed stolen data, including usernames, IP addresses, full names, and hashed passwords.

Temu responded swiftly, stating that a comprehensive investigation found no match between the leaked data and its own records, labeling the claims as "categorically false." The company emphasized its robust security protocols and vowed legal action against those spreading misinformation.

Despite Temu's reassurances, the hacker insists the breach is real, claiming ongoing access to the platform's internal systems. While BleepingComputer couldn’t verify these claims, the situation highlights the potential reputational risks, and users are advised to update passwords and enable two-factor authentication as a precaution.



António Monteiro

IT Manager na Global Blue Portugal | Especialista em Tecnologia Digital e CRM

6 个月

Interesting updates! The breach allegations sound serious, and Apple's scrambling suggests things are heating up in cybersecurity. What do you think about these developments?

回复
Jan Kübler

CEO of WORLDFIELD REAL ESTATE and WORLDFIELD INVESTMENT?HOLDING Dubai, UAE ???? multiple IRONMAN Finisher

6 个月

Be cautious about clicking on suspicious links or opening attachments from unknown sources.

回复
Marcel Velica

Senior Security Program Manager | Leading Cybersecurity Initiatives | Driving Strategic Security Solutions | Cybersecurity Excellence | Cloud Security

6 个月

It's crucial to stay informed about cyber threats to protect our data and systems. Your updates are always valuable! Aidan Dickenson

回复
Abu Nayeem

Get your LinkedIn Client Hunting Funnel to Turn Leads into Clients in 3 Easy Steps! → A-Z LinkedIn Profile Optimization → Banner design & Content design → Organic engagement + outreach ? DM me “Funnel”, Today it’s Free!

6 个月

Loved your slogan: "Stay Informed. Stay Secure" You are doing, Aidan Dickenson

要查看或添加评论,请登录

Aidan Dickenson的更多文章

  • Tuesday 25th March 2025

    Tuesday 25th March 2025

    Good morning. Thank you for joining me for the latest instalment of Cyber Daily.

  • Monday 24th March 2025

    Monday 24th March 2025

    Good morning and happy Monday. You know things are getting spicy in cybersecurity when GitHub Actions turn malicious…

  • Saturday 22nd March 2025

    Saturday 22nd March 2025

    Good morning. If you’ve ever dreamed of going back to a paper-only workday, just ask the Virginia Attorney General’s…

    1 条评论
  • Friday 21st March 2025

    Friday 21st March 2025

    Morning everyone and a happy Friday to you all! Today we're looking at hackers who are now deploying Betruger, a…

  • Thursday 20th February 2025

    Thursday 20th February 2025

    Good morning. If you thought your VPN was keeping you safe, your gaming accounts were secure, and WhatsApp was just for…

  • Wednesday 19th March 2025

    Wednesday 19th March 2025

    Good morning everyone and a very happy Wednesday to you all. Hackers are getting creative—and potentially desperate.

  • Friday 14th March 2025

    Friday 14th March 2025

    Good morning, happy Friday! If your cybersecurity team is looking extra stressed today, blame AI and ransomware gangs…

  • Thursday 13th March 2025

    Thursday 13th March 2025

    Good morning thank you for joining me for the latest instalment of Cyber Daily. If you thought your biggest tech…

  • Wednesday 12th March 2025

    Wednesday 12th March 2025

    Good morning everyone, happy Hump Day! Today we're focusing on a new botnet called Ballista that is running wild on…

  • Tuesday 11th March 2025

    Tuesday 11th March 2025

    Good morning! If you’ve ever wished you could report cybersecurity incidents as easily as you report bad drivers on the…

    2 条评论

社区洞察

其他会员也浏览了