Apple Sends Out Threat Notifications to Users Targeted by Spyware
Apple Sends Out Threat Notifications 🚨
Apple has taken a significant step by sending out threat notifications to users across 110 countries, alerting them that their devices may have been targeted by mercenary spyware often utilized by governments. According to TechCrunch, these alerts will now appear on device lock screens, be delivered to users’ email addresses, and show up on their Apple account pages.
Apple recommends that users who believe they may be targeted enable Lockdown Mode on their devices. This mode offers extreme protection by limiting many functionalities of the device, thereby reducing the attack surface. Additionally, the company advises affected users to seek expert help, such as the security assistance provided by the Digital Security Helpline at the nonprofit Access Now.
Supply Chain Attack Details 🔍
In related news, new details have emerged regarding a supply chain attack that compromised over 2,500 organizations in March. Researchers at SOCRadar have revealed that the attack was primarily driven by a malicious build of Aqua Security’s Trivy scanner, rather than the LiteLLM package, as initially suspected. Data indicates that 95% of the affected entities were exposed to the malware days before the poisoned LiteLLM packages were published.
The Trivy attack is attributed to the TeamPCP threat actor and led to the LiteLLM attack. SOCRadar explains that the LiteLLM compromise was “the closing act, not the whole play.” Attackers hijacked the trusted Trivy security scanner in LiteLLM’s build pipeline, used it to publish two poisoned LiteLLM releases to PyPI, and relied on a Python startup file to run a credential stealer on every host that installed them.
Jewelbug Hackers-for-Hire 💰
Meanwhile, Symantec has published a report on Jewelbug, a China-based hackers-for-hire group that engages in financially motivated cryptocurrency fraud alongside espionage campaigns targeting foreign governments and militaries. This threat actor, linked to a registered contractor in Hunan Province, uses the same control panel for both criminal and nation-state espionage operations. Symantec notes that this pairing is a hallmark of a hack-for-hire entity that is running for-profit crime on the side.
For more details, check out the full article here: Read full article