A single iMessage might now compromise your iPhone—no clicks needed. Graphite spyware is targeting journalists worldwide and raising serious questions about our digital safety. Curious to learn more?

https://thedefendopsdiaries.com/graphite-spyware-a-zero-click-threat-to-journalists/

#graphitespyware
#zeroclickexploit
#iossecurity
#cyberthreats
#journalistprotection

Installing unsigned or fake-signed iOS apps for testing without a Mac, Xcode, or access to proper signing tools can be a challenge.

Since iOS normally relies on the App Store to handle signing, getting apps onto a device manually isn’t always straightforward.

In our latest blog, we break down the main approaches to sideloading using tweaks on jailbroken devices, sideloading platforms like AltStore and Sideloadly, and on-device tools like TrollStore.

Whether your device is jailbroken or not, you’ll find a method that works.

📌Read here: https://www.pentestpartners.com/security-blog/how-to-load-unsigned-or-fake-signed-apps-on-ios/

#iOSSecurity #MobileAppTesting #Sideloading #CyberSecurity #infosec

🚨 iVerify's iOS app detected 11 new Pegasus infections in December 2024! 🦠 Shockingly, about half of the affected devices didn’t receive Threat Notifications from Apple. A major security concern! 🔐 #iOSSecurity #PegasusSpyware #Apple #TechNews #Privacy

https://posivi.com/iverifys-ios-app-detected-11-new-pegasus-infections-in-december-2024/

iVerify's iOS app detected 11 new Pegasus infections in December 2024 - Posivi

In December 2024, iVerify's Mobile Threat Hunting feature detected 11 new cases of Pegasus spyware infections on iOS devices. These discoveries were made

Posivi

I always find these kinds of posts fascinating and can usually pick up a glimpse of iOS design from them. In this case, the article talks a lot about the Secure Enclave and how it interacts with other parts of the phone. I also appreciate the before first unlock / after first unlock call outs.

#ios #security #iossecurity #blogposts #iphone https://naehrdine.blogspot.com/2024/11/reverse-engineering-ios-18-inactivity.html

Reverse Engineering iOS 18 Inactivity Reboot

Wireless and firmware hacking, PhD life, Technology

iOS 18 update brings cutting-edge AI security features to iPhones, enhancing user protection. #iOSsecurity #AItechnology #iPhoneupdate https://us.technoholic.me/ya9ExWa
Gold Pickaxe iOS Technical Analysis: IPA Overview and C2 Communication Startup

In February 2024 Group-IB wrote a blog post about a mobile Trojan developed by a Chinese-speaking cybercrimine group called Gold Pickaxe.

Syrion

Operation Triangulation’ #Spyware Attackers Bypass #iPhone Memory Protections...iMessage attachment, exploiting the remote code execution (#RCE) #vulnerability CVE-2023-41990.

#apple #cybersecurity #technology #news #iPhones #ios #iossecurity

Source🔗
https://www.darkreading.com/application-security/operation-triangulation-spyware-attackers-bypass-iphone-memory-protections

‘Operation Triangulation’ Spyware Attackers Bypass iPhone Memory Protections

The Operation Triangulation attacks are abusing undocumented functions in Apple chips to circumvent hardware-based security measures.

iOS Bug Hunting – Web View XSS

This post is about a simple, yet potentially dangerous security flaw that I’ve seen several times in iOS apps. I feel this misconfiguration should have more awareness around it – specif…

allysonomalley.com
Apple security releases

This document lists security updates and Rapid Security Responses for Apple software.

Apple Support
Mobile Pentesting 101 – How to Set Up Your iOS Environment

As mentioned in the Mobile Pentesting 101 – How to set up your Android Environment article, I am now offering you valuable information regarding the iOS pentesting environment. This will be m…

Security Café