Monday, January 22, 2024

Apple Updates 22-Jan-2024

 iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3

The updates are large:

12.43GB for macOS

5.62GB for iPadOS

Updates for iPadOS 16.7.5, tvOS 17.3, iOS 16.7.5, Monterey 12.7.3 and higher, iOS 15.8.1

WatchOS 17.3

And Safari 17.3

0-day vulnerability in WebKit  16Vulnerabilities

Thursday, January 18, 2024

Very Very Large password database just released

This slide from the Cyber Security SIG presentation 18-Jan-2024.



Wednesday, January 17, 2024

Google Chrome 0-day vulnerability 17-Jan-2024

  Google released Chrome updates today. CVE-2024-0519.

Updates to Chrome browser are encouraged

Chrome version 120.0.6099.224/225 for Windows.

macOS version 120.0.6099.234

120.0.6099.224 for Linux

ChromeOS 120.0.6099.235


Friday, January 5, 2024

Google Session cookies a proposed mitigation?

 In the Cyber Security presentation 4-Jan-2024 the new attack targeting Google session cookie reuse was cited.

 Session cookies, if re-validated, allow attackers to logon to Google services without re supplying the password/authentication.

 Not Good!

 A just proposed mitigation: power cycle the device. A further step, sign-out of any/all browser profiles. Even more secure, reset your passphrase and sing-in again.

Wednesday, January 3, 2024

iPhone 17.3 Developer Beta 3-Jan-2024

  If you one of the few iPhone 17.3 beta testers:

A few are reporting major issues with the just released iOS 17.3 developer beta release. iPhone will loop indefinitely.

A few are reporting.

Update: Apple pulled iOS 17.3 beta due to reported problems.