<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>zeroclick &#8211; AnonyViet &#8211; English Version</title>
	<atom:link href="https://en.anonyviet.com/tag/zeroclick/feed/" rel="self" type="application/rss+xml" />
	<link>https://en.anonyviet.com</link>
	<description>The most popular website for sharing information technology, computer networks, and security knowledge. Stay up to date with the hottest news and tips</description>
	<lastBuildDate>Sat, 09 Sep 2023 07:51:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://en.anonyviet.com/wp-content/uploads/2023/01/cropped-ico-logo-75x75-1.png</url>
	<title>zeroclick &#8211; AnonyViet &#8211; English Version</title>
	<link>https://en.anonyviet.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Apple suffers from Zero-Click vulnerability &#8211; Users need to Update the latest Firmware</title>
		<link>https://en.anonyviet.com/apple-suffers-from-zero-click-vulnerability-users-need-to-update-the-latest-firmware/</link>
					<comments>https://en.anonyviet.com/apple-suffers-from-zero-click-vulnerability-users-need-to-update-the-latest-firmware/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sat, 09 Sep 2023 07:51:39 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Firmware]]></category>
		<category><![CDATA[latest]]></category>
		<category><![CDATA[suffers]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[users]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[zeroclick]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=13171</guid>

					<description><![CDATA[Apple has released security updates to fix two vulnerabilities being exploited by hackers in different versions of macOS, iOS, watchOS, and iPadOS. If exploited, the vulnerabilities could lead to arbitrary malicious code execution. Join the channel Telegram belong to AnonyViet ???? Link ???? These two vulnerabilities are part of an exploit chain called BLASTPASS, which [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div>
<p><strong>Apple has released security updates to fix two vulnerabilities being exploited by hackers in different versions of macOS, iOS, watchOS, and iPadOS.  If exploited, the vulnerabilities could lead to arbitrary malicious code execution.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet</span> ???? <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  ????</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>These two vulnerabilities are part of an exploit chain called BLASTPASS, which is capable of compromising iPhones running on the latest iOS version (16.6) without any victim interaction.  This is a zero-click vulnerability used to distribute mercenary spyware <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fcach-nso-hack-iphone-bang-zero-click-cuc-tinh-vi%2F" class="local-link" rel="noopener">Pegasus of NSO Group</a>.</p>
<p><img post-id="13171" fifu-featured="1" decoding="async" fetchpriority="high" class="aligncenter size-full wp-image-50783" src="https://anonyviet.com/wp-content/uploads/2023/09/zero-click-apple-CVE-2023-41064-CVE-2023-41061.jpg" alt="Apple suffers from Zero-Click vulnerability &#8211; Users need to Update the latest Firmware" title="Apple suffers from Zero-Click vulnerability &#8211; Users need to Update the latest Firmware" width="695" height="354" srcset="https://anonyviet.com/wp-content/uploads/2023/09/zero-click-apple-CVE-2023-41064-CVE-2023-41061.jpg 695w, https://anonyviet.com/wp-content/uploads/2023/09/zero-click-apple-CVE-2023-41064-CVE-2023-41061-300x153.jpg 300w" sizes="(max-width: 695px) 100vw, 695px" title="Apple suffers from Zero-Click vulnerability - Users need to Update the latest Firmware 6"/></p>
<p>One of the flaws <strong>(CVE-2023-41064)</strong> exists in Apple&#8217;s Image I/O framework, allowing applications to read and write most image file formats that generate buffer overflows.  For this vulnerability, “processing a malicious image can lead to arbitrary malicious code execution.”</p>
<p>Second flaw <strong>(CVE-2023-41061)</strong> related to Apple&#8217;s Wallet feature, which allows users to store bank cards.  According to Apple, a malicious attachment could lead to arbitrary code execution.  The error is also fixed in iOS version 16.6.1</p>
<p>Both bugs affect iPhone 8 or later, all iPad Pro models, iPad Air 3rd generation or later, iPad 5th generation or later, and iPad mini 5th generation or later.  Meanwhile, the bug related to CVE-2023-41061 also affects Apple Watch Series 4 and later;  while the vulnerability related to CVE-2023-41064 also affects macOS Ventura.  Apple has rolled out iOS 16.6.1, iPadOS 16.6.1, watchOS 9.6.2, and macOS Ventura 13.5.2 to address security flaws.</p>
<p>To fix the security vulnerability of Apple devices, you just need to go to Settings -> General -> Software Update, and update to the latest Firmware version for your device.</p>
<p>Apple over the past few months has been rolling out fixes for various exploited bugs, including through an update addressing the WebKit vulnerability (CVE-2023-37450) affecting iOS, macOS, and iPadOS in November. 7 and an update addressing an integer overflow vulnerability (CVE-2023-32434) affecting watchOS, macOS, and iPadOS in June.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;50782&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 0\/5 - (0 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;Apple b\u1ecb l\u1ed7 h\u1ed5ng Zero-Click - Ng\u01b0\u1eddi d\u00f9ng c\u1ea7n Update Firmware m\u1edbi nh\u1ea5t&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>
            <span class="kksr-muted">Rate this post</span>
    </p>
</p></div>
<p><!-- AI CONTENT END 2 --></p></div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/apple-suffers-from-zero-click-vulnerability-users-need-to-update-the-latest-firmware/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2023/09/zero-click-apple-CVE-2023-41064-CVE-2023-41061.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>How NSO hacks iPhone with extremely sophisticated zero-click</title>
		<link>https://en.anonyviet.com/how-nso-hacks-iphone-with-extremely-sophisticated-zero-click/</link>
					<comments>https://en.anonyviet.com/how-nso-hacks-iphone-with-extremely-sophisticated-zero-click/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Thu, 04 May 2023 01:00:31 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[extremely]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[NSO]]></category>
		<category><![CDATA[sophisticated]]></category>
		<category><![CDATA[zeroclick]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=12235</guid>

					<description><![CDATA[The hackers of the spy company NSO used an attack method Iphone without the user doing anything (zero-click) by accessing HomeKit &#8211; Apple&#8217;s feature of controlling smart devices in the home. However, this method was prevented if the user enabled Lockdown Mode &#8211; a security feature of Apple. Join the channel Telegram belong to AnonyViet [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p>The hackers of the spy company NSO used an attack method <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fcach-tich-hop-chatgpt-vao-siri-tren-iphone-de-tang-suc-manh-cho-ai%2F" class="local-link" rel="noopener">Iphone</a> without the user doing anything (zero-click) by accessing HomeKit &#8211; Apple&#8217;s feature of controlling smart devices in the home.  However, this method was prevented if the user enabled Lockdown Mode &#8211; a security feature of Apple.</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet </span> ???? <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  ????</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="ftoc-nso-group-la-ai" class="ftwp-heading"><strong>Who is NSO Group?</strong></h2>
<p><strong>NSO Group</strong> is an Israel-based cybersecurity company that provides cybersecurity products and services to governments and security organizations worldwide.</p>
<p>This company was founded in 2010 and is best known for its main product, the Pegasus spyware, which is said to be able to access mobile devices and monitor all activities on these devices.  The company NSO Group has been controversial because its products have been used to monitor and spy on human rights activists, journalists and political figures worldwide.</p>
<figure id="attachment_46599" aria-describedby="caption-attachment-46599" style="width: 800px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-46599" src="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-4.jpg" alt="How NSO hacks iPhone with zero-click" width="800" height="484" srcset="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-4.jpg 860w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-4-300x181.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-4-768x464.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-4-750x453.jpg 750w" sizes="(max-width: 800px) 100vw, 800px" title="How NSO Hack iPhone with zero-click extremely sophisticated 9"/><figcaption id="caption-attachment-46599" class="wp-caption-text">NSO Group</figcaption></figure>
<p>November 2019, Apple alleges <strong>NSO Group</strong> used security holes in Apple&#8217;s iOS operating system to develop and sell Pegasus to governments and security organizations around the world.</p>
<h2 id="ftoc-nso-hack-iphone-bang-zero-click-nhu-the-nao" class="ftwp-heading"><strong>How does NSO hack iPhone with zero-click?</strong></h2>
<p>Attack <strong>zero-click</strong> is a type of attack that does not require the user to take any action to allow an attacker access to his or her device.  Instead, attackers take advantage of vulnerabilities in software or hardware to insert malicious code or steal data without the user&#8217;s knowledge.</p>
<p>This is a type of attack that is very difficult to detect and prevent, as it does not leave many traces and can be performed remotely.</p>
<p>Some examples of zero-click attacks are:</p>
<ul>
<li>NSO Group&#8217;s Pegasus spyware can infiltrate iOS and Android devices via iMessage or WhatsApp, simply receiving a message without opening it &#8211; is enough to allow remote access to attackers. to your iPhone.</li>
<li>A vulnerability in Apple&#8217;s Mail app allows hackers to send emails to gain access to a user&#8217;s device without the user opening the email.</li>
<li>Another flaw in Apple&#8217;s FaceTime app makes it possible for hackers to call users and listen to their device&#8217;s audio before they accept the call.</li>
</ul>
<p>According to cybersecurity experts, zero-click attacks are very dangerous and difficult to detect, as they do not require user intervention and can carry out espionage activities in secret.  This makes NSO Group zero-click attacks considered one of the most dangerous espionage attacks and can have serious consequences for user privacy and security.</p>
<h2 id="ftoc-cach-chong-lai-zero-click-bang-lockdown-mode" class="ftwp-heading"><strong>How to counter Zero-click with Lockdown Mode</strong></h2>
<p>To protect those potentially vulnerable to zero-click attacks, Apple introduced “Lockdown Mode” last year.  This is a tool to limit the functions of the iPhone, while reducing the risk of a zero-click attack.</p>
<figure id="attachment_46596" aria-describedby="caption-attachment-46596" style="width: 600px" class="wp-caption aligncenter"><img decoding="async" loading="lazy" class="wp-image-46596" src="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1.jpg" alt="How NSO hacks iPhone with zero-click" width="600" height="430" srcset="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1.jpg 1152w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1-300x215.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1-1024x734.jpg 1024w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1-768x551.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1-120x86.jpg 120w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1-350x250.jpg 350w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1-750x538.jpg 750w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-1-1140x817.jpg 1140w" sizes="auto, (max-width: 600px) 100vw, 600px" title="How NSO Hack iPhone with a very sophisticated zero-click 10"/><figcaption id="caption-attachment-46596" class="wp-caption-text">Apple&#8217;s Lockdown Mode</figcaption></figure>
<p>This mode is only for people who think they are at high risk of government surveillance.  This tool will degrade iPhone features, including blocking most message attachments, disabling many websites, and more.</p>
<h2 id="ftoc-nso-va-3-cuoc-tan-cong-zero-click-vao-iphone" class="ftwp-heading"><strong>NSO and 3 zero-click attacks on iPhone</strong></h2>
<p>According to reports from Citizen Lab, a cyber research center of the University of Toronto, NSO Group used at least three attacks launched by<strong> NSO hack iPhone with zero-click</strong> to install the Pegasus spyware on iPhone devices running iOS 15 and 161.</p>
<p>This was discovered in late 2022 but Citizen Lab has kept the details secret until Apple can patch iOS to prevent attacks in time.</p>
<p>3 attacks include:</p>
<h3 id="ftoc-pwnyourhome" class="ftwp-heading"><strong>PWNYOURHOME</strong></h3>
<p>An attack that began in October 2022, combined a vulnerability in the HomeKit and iMessage apps to gain access to a user&#8217;s device.  This attack can work regardless of whether the user has a smart home configured with HomeKit or not.</p>
<h3 id="ftoc-findmypwn" class="ftwp-heading"><strong>FINDMYPWN</strong></h3>
<p>This is a two-step zero-click attack, deployed against iOS 15 starting in June 2022. The first step targets the iPhone&#8217;s Find My feature, and the second step targets iMessage.</p>
<h3 id="ftoc-latentimage" class="ftwp-heading"><strong>LATENTIMAGE</strong></h3>
<p>The attack involved the iPhone&#8217;s Find My feature.</p>
<figure id="attachment_46600" aria-describedby="caption-attachment-46600" style="width: 800px" class="wp-caption aligncenter"><img decoding="async" loading="lazy" class="wp-image-46600" src="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-5.jpg" alt="How NSO hacks iPhone with zero-click" width="800" height="262" srcset="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-5.jpg 1025w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-5-300x98.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-5-768x252.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-5-750x246.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px" title="How NSO Hack iPhone with zero-click extremely sophisticated 11"/><figcaption id="caption-attachment-46600" class="wp-caption-text">3 attacks of NSO</figcaption></figure>
<p>The most common attack method is to send an iMessage message containing malicious code, then exploit vulnerabilities in other default Apple applications.</p>
<p>In January 2023, Apple released several security enhancements to HomeKit in the iOS 16.3</p>
<p>Users who have enabled Lockdown mode will receive a notification every time a malicious object tries to infiltrate their device.</p>
<figure id="attachment_46601" aria-describedby="caption-attachment-46601" style="width: 800px" class="wp-caption aligncenter"><img decoding="async" loading="lazy" class="wp-image-46601" src="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-6.jpg" alt="How NSO hacks iPhone with zero-click" width="800" height="391" srcset="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-6.jpg 975w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-6-300x147.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-6-768x376.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click-6-750x367.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px" title="How NSO Hack iPhone with zero-click extremely sophisticated 12"/><figcaption id="caption-attachment-46601" class="wp-caption-text">When activating Lockdown mode, you will receive a notification when someone wants to invade</figcaption></figure>
<h2 id="ftoc-loi-ket" class="ftwp-heading"><strong>Epilogue</strong></h2>
<p>In short, the attacks of<strong> NSO hack iPhone with zero-click</strong> is a reminder to service providers and users to increase security measures and take extra care in protecting their personal information and privacy.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;46594&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 0\/5 - (0 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;C\u00e1ch NSO Hack iPhone b\u1eb1ng zero-click c\u1ef1c tinh vi&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>
            <span class="kksr-muted">Rate this post</span>
    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-nso-hacks-iphone-with-extremely-sophisticated-zero-click/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2023/04/cach-nso-hack-iphone-zero-click.jpg" medium="image"></media:content>
            	</item>
	</channel>
</rss>
