Researchers: “SimJacker”, a widespread SIM card-based vulnerability, is being exploited by a private actor “that works with governments to monitor individuals”
https://thehackernews.com/... #infosec #technews https://twitter.com/... @thehackersnews : What's more worrisome? According to researchers, a specific private company that works with Governments is actively exploiting #SimJacker vulnerability for at least 2 years to conduct targeted surveillance on mobile phone users across several countries. https://thehackernews.com/... https://twitter.com/... Doifeellucky / @do_i_feellucky : Ooof... it's all about scale huh? Does somebody still have illusions about mobile security? https://threatpost.com/... Dino A. Dai Zovi / @dinodaizovi : This blog post blew my mind. You can send an SMS to many SIMs that will cause the smartphone to open up a web browser to the specified URL?!? https://twitter.com/... Daniel Cuthbert / @dcuthbert : When an attack by Karsten Nohl from 6 years ago, is turned into a tool and people go wild. https://www.adaptivemobile.com/ ... Karsten has done amazing research into SS7 security and seemingly not listened to as he should have been https://www.theregister.co.uk/ ... Profdeibert / @rondeibert : “The main Simjacker attack involves a SMS containing a specific type of spyware-like code being sent to a mobile phone, which then instructs the UICC (SIM Card) within the phone to ‘take over’ the mobile phone” https://www.adaptivemobile.com/ ... Joseph Cox / @josephfcox : Statement from T-Mobile. So none of the major US telecos are impacted by this SIM vulnerability. Still around a billion devices elsewhere that are, according to AdaptiveMobile pic.twitter.com/7u45PUIUgU Joseph Cox / @josephfcox : Sprint says it is not impacted by this attack because it “does not use the vulnerable S@T browser on Sprint SIM cards.” It did talk to AdaptiveMobile through the responsible disclosure process though. Joseph Cox / @josephfcox : AT&T says “This is not something we use in the U.S., so we are not affected here.” @privacydigest : Simjacker attack exploited in the wild to track users for at least two years | ZDNet https://www.zdnet.com/... > #Simjacker attack abuses STK and S@T Browser technologies installed on some SIM cards. @teriradichel : I remember when the CTO of a security company scoffed when I predicted attacks like this on mobile networks. It was only a matter of time. https://twitter.com/...
This is a pretty wild attack. Leveraging vectors in the SIM card to get location data, other information on targets. Because it's SIM card, its platform agnostic. Being used by a company that sells surveillance capabilities to governments https://www.adaptivemobile.com/ ... pic.…
After originally declining to comment and only giving an answer after being pushed, Verizon says “We have no indication to believe this impacts Verizon.”
💥 SimJacker #Vulnerability (0-day under active attack) A new SIM card-based flaw could allow remote attackers to hijack and spy on any phone just by sending an SMS - regardless of which handset the victim is using. Read details — https://thehackernews.com/... #infosec #technews h…
What's more worrisome? According to researchers, a specific private company that works with Governments is actively exploiting #SimJacker vulnerability for at least 2 years to conduct targeted surveillance on mobile phone users across several countries. https://thehackernews.com/…
This blog post blew my mind. You can send an SMS to many SIMs that will cause the smartphone to open up a web browser to the specified URL?!? https://twitter.com/...
When an attack by Karsten Nohl from 6 years ago, is turned into a tool and people go wild. https://www.adaptivemobile.com/ ... Karsten has done amazing research into SS7 security and seemingly not listened to as he should have been https://www.theregister.co.uk/ ...
“The main Simjacker attack involves a SMS containing a specific type of spyware-like code being sent to a mobile phone, which then instructs the UICC (SIM Card) within the phone to ‘take over’ the mobile phone” https://www.adaptivemobile.com/ ...
Statement from T-Mobile. So none of the major US telecos are impacted by this SIM vulnerability. Still around a billion devices elsewhere that are, according to AdaptiveMobile pic.twitter.com/7u45PUIUgU
Sprint says it is not impacted by this attack because it “does not use the vulnerable S@T browser on Sprint SIM cards.” It did talk to AdaptiveMobile through the responsible disclosure process though.
Simjacker attack exploited in the wild to track users for at least two years | ZDNet https://www.zdnet.com/... > #Simjacker attack abuses STK and S@T Browser technologies installed on some SIM cards.
I remember when the CTO of a security company scoffed when I predicted attacks like this on mobile networks. It was only a matter of time. https://twitter.com/...