Google's Threat Analysis Group breaks down three recent malware campaigns, likely state-backed, and notes a large uptick of in-the-wild 0-day attacks this year
Zero-day vulnerabilities are unknown software flaws. Until they're identified and fixed, they can be exploited by attackers.
The Keyword Maddie Stone
Related Coverage
- Safari Zero-Day Used in Malicious LinkedIn Campaign Threatpost · Elizabeth Montalbano
- Google finds zero-day security flaws in all your favorite browsers TechRadar · Mayank Sharma
- iOS Zero-Day Let SolarWinds Hackers Compromise Fully Updated iPhones Slashdot · BeauHD
- Google: Russian SVR hackers targeted LinkedIn users with Safari zero-day BleepingComputer · Sergiu Gatlan
- Google Details iOS, Chrome, IE Zero-Day Flaws Exploited Recently in the Wild The Hacker News · Ravie Lakshmanan
- Russian SolarWinds Hackers Used iOS Zero-Day to Steal Login Details iPhone Hacks · Rajesh Pandey
- SolarWinds hackers used iOS zero-day to penetrate iPhones used by government officials AppleInsider · Mikey Campbell
- Zero-day exploit allowed SolarWinds hackers to extract login information from iOS devices 9to5Mac · Filipe Espósito
Discussion
-
@b_fung
Brian Fung
on x
Google's @ShaneHuntley tells me the suspected Russian hackers who exploited the Apple WebKit zero-day outlined here https://blog.google/... was more specifically the same group behind the USAID impersonation phishing campaign — e.g., Russian foreign intelligence. More from Shane:…
-
@shanehuntley
Shane Huntley
on x
Post by @_clem1 & @maddiestone on 4 0days TAG found this year (with IOCs!). We tie three to a commercial surveillance vendor arming govt backed attackers and one to likely Russian APT. Also thoughts on why we are seeing so many 0day in 2021. https://blog.google/... https://twitte…
-
@maddiestone
Maddie Stone
on x
More details about the 4 in-the-wild 0-day exploits that Google's Threat Analysis Group has discovered this year as well as our thoughts on the uptick in in-the-wild 0-days we're seeing this year. @_clem1 https://blog.google/...
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
NEW: Google found that some LinkedIn messages sent to European government officials led to a zero-day exploit to steal their authentication cookies. Company believes hackers were “likely Russian government-backed.” https://www.vice.com/...
-
@shanehuntley
Shane Huntley
on x
These are two different campaigns, but based on our visibility, we consider the actors behind the WebKit 0-day and the USAID campaign to be the same group of actors. https://arstechnica.com/...
-
@lukolejnik
Lukasz Olejnik
on x
“exploit would turn off Same-Origin-Policy protections in order to collect authentication cookies from several popular websites, including Google, Microsoft, LinkedIn, Facebook and Yahoo and send them via WebSocket to an attacker-controlled IP” https://blog.google/... https://twi…
-
@campuscodi
Catalin Cimpanu
on x
A fourth zero-day was used by a Russian cyber-espionage group (most likely APT29) to target western European government officials via LinkedIn Dedicated report here: https://twitter.com/...
-
@osxreverser
@osxreverser
on x
Apple should just outbid everyone else and buy all the exploits. 😂😂😂😂 😂 https://twitter.com/...
-
@dangoodin001
Dan Goodin
on x
iOS zero-day let SolarWinds hackers compromise fully updated iPhones https://arstechnica.com/...
-
@shhnjk
Jun Kokatsu
on x
Attackers taking advantage of missing Site Isolation in WebKit. That makes sense for them because all browsers on iOS uses WebKit 🙄Clearly, Apple is behind in the game of Site Isolation and it's impacting users even outside Safari. https://blog.google/...
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
UPDATE: Google Threat Analysis Group director @ShaneHuntley says they don't know how many people were successfully hacked in this campaign. But he says Google normally sends around 4,000 warnings to users targeted by government hackers. https://www.vice.com/... https://twitter.co…
-
@malwarere
Ramin
on x
Additional information/context from TAG regarding the WebKit vulnerability (CVE-2021-1879) leveraged by #NOBELIUM during their email-based attacks (https://www.microsoft.com/...): https://blog.google/... https://twitter.com/...
-
@carolafrediani
Carola Frediani
on x
“Russian government hackers targeted European government officials with LinkedIn messages that contained malicious links designed to exploit unknown vulnerabilities in Windows and iOS, according to Google's report” https://www.vice.com/... https://blog.google/... https://twitter.…
-
@maddiestone
Maddie Stone
on x
We're also publishing root cause analyses for the four 0-days: Chrome CVE-2021-21166: https://googleprojectzero.github.io/ ... Chrome CVE-2021-30551: https://googleprojectzero.github.io/ ... Internet Explorer CVE-2021-33742: https://googleprojectzero.github.io/ ... Safari CVE-202…
-
@maddiestone
Maddie Stone
on x
For the past few months, I've had the honor to work within both Google TAG and Project Zero on the 0-days in-the-wild program. I'm excited to share with y'all the good stuff we've done and will continue to do on the TAG side 🤗