Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

BumRushDaShow

(128,933 posts)
Mon Sep 13, 2021, 05:19 PM Sep 2021

Apple Issues Emergency Security Updates to Close a Spyware Flaw

Source: New York Times

Apple issued emergency software updates for a critical vulnerability in its products on Monday after security researchers uncovered a flaw that allows highly invasive spyware from Israel’s NSO Group to infect anyone’s iPhone, Apple Watch or Mac computer without so much as a click.

Apple’s security team has been working around the clock to develop a fix since Tuesday, after researchers at Citizen Lab, a cybersecurity watchdog organization at the University of Toronto, discovered that a Saudi activist’s iPhone had been infected with spyware from NSO Group. The spyware, called Pegasus, used a novel method to invisibly infect an Apple device without the victim’s knowledge for as long as six months.

Known as a “zero click remote exploit,” it is considered the Holy Grail of surveillance because it allows governments, mercenaries and criminals to secretly break into a victim’s device without tipping the victim off. Using the zero-click infection method, Pegasus can turn on a user’s camera and microphone, record messages, texts, emails, calls — even those sent via encrypted messaging and phone apps like Signal — and send them back to NSO’s clients at governments around the world.

“This spyware can do everything an iPhone user can do on their device and more,” said John Scott-Railton, a senior researcher at Citizen Lab, who teamed up with Bill Marczak, a senior research fellow at Citizen Lab, on the finding. In the past, victims learned their devices were infected by spyware only after receiving a suspicious link texted to their phone or email. But NSO Group’s zero-click capability gives the victim no such prompt, and enables full access to a person’s digital life. These abilities can fetch millions of dollars on the underground market for hacking tools.

Read more: https://www.nytimes.com/2021/09/13/technology/apple-software-update-spyware-nso-group.html



Updating the ole iPad Air 2 as I post this.

There are some threads in GD too (was reading one when I saw the breaking banner), e.g., - https://www.democraticunderground.com/100215851263
26 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Apple Issues Emergency Security Updates to Close a Spyware Flaw (Original Post) BumRushDaShow Sep 2021 OP
How will one know and how do we get the fix? brush Sep 2021 #1
Go to settings, general, update. Looks like it is there JohnSJ Sep 2021 #2
Check Settings:General on Iphone or Ipad. I just updated each. hlthe2b Sep 2021 #3
Well per the GD thread BumRushDaShow Sep 2021 #4
Yeah, It's 350+MB COL Mustard Sep 2021 #7
I think it's also because BumRushDaShow Sep 2021 #8
IOS 14.8 dweller Sep 2021 #9
Thanks for posting. I updated badhair77 Sep 2021 #5
Thank you! Buckeye_Democrat Sep 2021 #6
From what I read in another article BumRushDaShow Sep 2021 #10
Yes... An activist against the Saudi government. n/t targetpractice Sep 2021 #13
... BumRushDaShow Sep 2021 #15
Thank you. Update downloading right now. ZonkerHarris Sep 2021 #11
Thank you! piddyprints Sep 2021 #12
Thanks. Am updating the iPhone now, and when it's done I'll do the iPad. Hekate Sep 2021 #14
Thank you, BRDS! Just finished updating. ancianita Sep 2021 #16
Thanks for letting us know! Tree Lady Sep 2021 #17
Thank you for this info! karin_sj Sep 2021 #18
I almost got hacked Sunday night LittleGirl Sep 2021 #19
Bookmark. Apple NSO update. nt littlemissmartypants Sep 2021 #20
14.8 download issues nwduke Sep 2021 #21
I think it may have been your timing and server overload BumRushDaShow Sep 2021 #22
Sounds about right nwduke Sep 2021 #23
When I did my iPad yesterday afternoon (I did that one first) BumRushDaShow Sep 2021 #24
I might give it a try this afternoon. NT mahatmakanejeeves Sep 2021 #25
Thanks for posting that! tonekat Sep 2021 #26

BumRushDaShow

(128,933 posts)
4. Well per the GD thread
Mon Sep 13, 2021, 05:26 PM
Sep 2021

they said to just go to the settings and get to the updates screen and it will automatically be available. I went to settings/general/software update and it was there to "download" or "download and install".

It's taking awhile so it's sortof big and probably many people are hitting the servers at once.

BumRushDaShow

(128,933 posts)
8. I think it's also because
Mon Sep 13, 2021, 05:52 PM
Sep 2021

my iPad Air 2 is like 7 years old this year... I just did it on the iPhone 12 Pro and it was done in a fraction of the time.

Buckeye_Democrat

(14,853 posts)
6. Thank you!
Mon Sep 13, 2021, 05:49 PM
Sep 2021

I just updated my iPhone.

Surprised it happened to Apple, since they usually keep their operating systems locked down pretty tight.

BumRushDaShow

(128,933 posts)
10. From what I read in another article
Mon Sep 13, 2021, 05:59 PM
Sep 2021

(it my have been the 9to5mac) there were hackers able to break Apple's "Blastdoor" protection in a quest to go after a particular person in Bahrain I think.

LittleGirl

(8,287 posts)
19. I almost got hacked Sunday night
Mon Sep 13, 2021, 11:58 PM
Sep 2021

I got an alert that someone was trying to log into my Apple ID in Ontario Canada. I live in Switzerland so I didn't allow but had to lock my devices and change my password. Luckily this password and ID is unique to others. Last night, we downloaded the updates for my phone and ipad. We're good now.

Thanks for posting this important update info.

nwduke

(350 posts)
21. 14.8 download issues
Tue Sep 14, 2021, 10:08 AM
Sep 2021

I think they rushed this out in a hurry, but it has major download flaws. It gets stuck in “preparing download” and nothing happens. Apple needs to get their act together on this one!

BumRushDaShow

(128,933 posts)
22. I think it may have been your timing and server overload
Tue Sep 14, 2021, 10:26 AM
Sep 2021

as the news propagated out more and more yesterday and overnight and that eventually resulted in millions of people trying to hit the servers at once - and moreso because it impacted so many of their brand devices (iPhones, iPads, iPods, Macs, watches) and each one (of the newer vintage) devices needed an update.

BumRushDaShow

(128,933 posts)
24. When I did my iPad yesterday afternoon (I did that one first)
Tue Sep 14, 2021, 11:05 AM
Sep 2021

it was taking awhile to get it downloaded and then took a long time for it to finally finish installing. But I know it is also an "older" device (an iPad Air 2). When that was done, I immediately did the iPhone 12 Pro and it was done with everything (download, verification, and installation) within about 15 minutes.

Latest Discussions»Latest Breaking News»Apple Issues Emergency Se...