Zero-Click RCE Bug in macOS Calendar Exposes iCloud Data

September 17, 2024 at 05:31PM A zero-click exploit chain in macOS undermines security protections, compromising iCloud data. It starts with a lack of file sanitization in Calendar events, leading to remote code execution and access to sensitive data. Attackers can exploit vulnerabilities to bypass security controls like Gatekeeper and TCC. Apple has since acknowledged and … Read more

Microsoft Patches Zero-Click Outlook Vulnerability That Could Soon Be Exploited

June 12, 2024 at 12:45PM Microsoft addressed a critical remote code execution vulnerability in its June 2024 Patch Tuesday updates. Tracked as CVE-2024-30103, it allows attackers to create malicious DLL files and initiate execution when an affected email is opened in Outlook. This zero-click vulnerability can be exploited for initial access and requires immediate client … Read more

Microsoft Outlook Zero-Click Security Flaws Triggered by Sound File

December 19, 2023 at 04:05PM Researchers disclosed two security vulnerabilities in Microsoft Outlook, which, when combined, allow attackers to execute arbitrary code on systems without any user interaction. The vulnerabilities can be triggered using a sound file. Akamai identified the flaws and Microsoft has issued patches, but additional vulnerabilities in the patches have also been … Read more

Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE

December 19, 2023 at 03:39PM Akamai security researchers have disclosed multiple bypasses for Microsoft’s patches for an Outlook zero-click remote code execution vulnerability. The original issue, CVE-2023-23397, was exploited by a Russian state-sponsored threat actor, prompting Microsoft to release a patch in March 2023. Akamai identified other bypasses, which Microsoft has subsequently addressed in later … Read more

Russian APT Used Zero-Click Outlook Exploit

December 8, 2023 at 10:18AM Russian threat actor APT28 is exploiting a no-interaction Outlook vulnerability in attacks across 14 countries. This was reported on SecurityWeek. Based on the meeting notes, the key takeaway is that a Russian threat actor known as APT28 has been utilizing a zero-click Outlook exploit to carry out attacks on 14 … Read more