The Vette Barn

The Vette Barn (https://www.thevettebarn.com/forums/index.php)
-   Off Topic (https://www.thevettebarn.com/forums/forumdisplay.php?f=38)
-   -   update your iPhone to iOS 14.8 right now (https://www.thevettebarn.com/forums/showthread.php?t=126853)

Mike Mercury 09-14-2021 8:12am

update your iPhone to iOS 14.8 right now
 
Your Mac and Apple Watch too

https://www.theverge.com/2021/9/13/2...te-nso-pegasus

Apple has released a suite of new updates for iOS, macOS, and watchOS to fix a bug that security researchers at Citizen Lab say was very likely exploited to allow government agencies to install spyware into the phones of journalists, lawyers, and activists. The researchers say the bug allowed for a “zero-click” install (meaning the target didn’t have to do anything to be infected) of the Pegasus spyware, which is reportedly capable of stealing data, passwords, and activating a phone’s microphone or camera. You can read our explainer of Pegusus here for more details.

Given the severity of the exploit, you should update to iOS 14.8, macOS Big Sur 11.6, and watchOS 7.6.2 as soon as you can.

We heard about the exploit in August, when Citizen Lab reported that it had been successfully used against phones running iOS 14.6 (released in May). Citizen Lab also said the vulnerability, which it codenamed “ForcedEntry,” seemed to match the behavior of an exploit Amnesty International wrote about in July. At the time, the security researchers wrote that it was made possible by a bug in Apple’s CoreGraphics system, and happened when the phone tried to use a function related to GIFs, after it received a text message containing a malicious file.

However, even with that info, it could be difficult to pin down exactly what was happening without access to the infected files themselves. According to Citizen Lab, they discovered files while re-analyzing a backup from an activist’s hacked phone. The files appeared to be GIFs sent as SMS attachments, but were actually PSDs and PDFs. (Apple’s update notes say that the issue occurred when processing a maliciously crafted PDF.) Citizen Lab suspected they could’ve been related to Pegasus, so it sent the files to Apple on September 7th. Apple quickly released the software updates patching the bug on September 13th, and thanked Citizen Lab in a statement for “completing the very difficult work of obtaining a sample of this exploit.”

Some of Monday’s updates also fix a second security issue with WebKit for iOS and macOS Big Sur (it isn’t mentioned in the release notes for Catalina). While it’s unclear if it’s related to NSO’s exploits — its discovery is attributed to “an anonymous researcher” instead of Citizen Lab, and it’s in a different part of the system — Apple still says that it “may have been actively exploited.”

Such an urgent security issue explains why we’re seeing a new update to iOS just a day before an Apple event, where it’s expected to announced new phones that will probably never run this version of the OS. Still, there have been rumors about an iOS 14.8 release since early August, but given that Monday’s release seems to only deal with the security issues discovered in September, it’s possible we’ll see at least one more iOS 14 release.

Thankfully, Apple is planning on letting users install security updates for iOS 14 without having to upgrade to iOS 15, which could be useful for any future fixes. For the time being, though, get all your devices updated as soon as you can.

https://i.imgur.com/yijyf8H.png

ratflinger 09-14-2021 9:34am

Good, Apple users should be followed by the .gov. They do tend to be minions.

Louie Detroit 09-14-2021 11:36am

Quote:

very likely exploited to allow government agencies to install spyware into the phones of journalists, lawyers, and activists
Probably mostly right wingers.

Vandelay Industries 09-14-2021 11:39am

1 Attachment(s)
No apple products here. :dance:

Attachment 60539

DJ_Critterus 09-14-2021 11:49am

https://64.media.tumblr.com/tumblr_l...nsg8o1_400.gif
https://i.gifer.com/OjlV.gif

DJ_Critterus 09-14-2021 1:59pm

Just had this pushed out from the main IT department here at the college.

Quote:

Apple has issued emergency software updates for a critical vulnerability in its products. These updates were released yesterday, September 13, 2021 after security researchers uncovered a flaw that allows highly invasive spyware from Israel’s NSO Group to infect anyone’s iPhone, iPad, Apple Watch or Mac computer without so much as a click.

Please update any Apple products that you may have as soon as possible by installing iOS 14.8 (iPhone/iPad), MacOS 11.6 (Mac Computer), and WatchOS 7.6.2. (Apple Watch).
I haven't seen a reference to this being an Israeli based virus in anything else i have read on this.

ratflinger 09-14-2021 4:18pm

Good thing Jews don't like to hack Android!

DJ_Critterus 09-15-2021 6:55am

Quote:

Originally Posted by ratflinger (Post 1912460)
Good thing Jews don't like to hack Android!

They only go for apples because of original sin....none of this new testament stuff for them.

:leaving:

dvarapala 09-15-2021 11:58am

Does this "critical fix" also include the kiddie porn scanning feature? 😒

snide 09-15-2021 8:25pm

Quote:

Originally Posted by dvarapala (Post 1912590)
Does this "critical fix" also include the kiddie porn scanning feature? 😒

Have the cops knocked on your door yet? :bigears:

Mike Mercury 09-16-2021 9:02am

https://memegenerator.net/img/instan...-your-door.jpg














https://www.daily-choices.com/wp-con...pg.pro-cmg.jpg

dwjz06 09-16-2021 9:05am

Thanks for the update.:seasix: Got everything current this morning.:cert:

Stangkiller 09-16-2021 12:02pm

Damnit apple watch series 2 no longer receiving updates even though it works fine for what i want :banghead: time to come off the network/bluetooth.


All times are GMT -5. The time now is 11:44pm.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Copyright © 2009 - 2024 The Vette Barn