Skip to main content

Threats Tagged 'ios'

View all threats tagged with 'ios'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: ios

Threats Tagged 'ios'

Click on any threat for detailed analysis and mitigation recommendations

Apple released major updates iOS 27 and macOS Golden Gate 27 that patch over 200 security vulnerabilities affecting kernel and multiple platform components. These flaws could lead to memory corruption, privilege escalation, system termination, and information leaks. The updates also fix a medium-severity Samba heap-based buffer overflow from 2022. No active exploitation has been reported. Users are advised to update promptly to benefit from these fixes.

HighVulnerability#macos#ios
Join the discussion

Cisco disclosed multiple vulnerabilities affecting its Secure Email product, IOS XR, Nexus 9000 series switches, and certain IP phone devices. Two medium-severity flaws in Secure Email's S/MIME decryption could allow attackers to intercept and obtain plaintext from encrypted emails. Critical vulnerabilities in IOS XR and Nexus switches could enable remote code execution, authentication bypass, and code injection. Additionally, a high-severity denial-of-service vulnerability affects Cisco IP phones using SIP. Cisco has released patches for the IOS XR, Nexus switches, and IP phone vulnerabilities, but the Secure Email flaws remain unpatched. No active exploitation has been reported for any of these vulnerabilities.

Join the discussion

Researchers have identified a new tactic used by the Chinese Fire Ant threat actor involving Cisco IOS XR routers. The attackers create unauthorized GRE tunnel interfaces on affected routers, which do not correspond to any legitimate configuration or commit history. This technique allows the compromised routers to be leveraged as spying platforms. No specific affected versions or patches have been disclosed. There is no confirmed active exploitation in the wild at this time.

Join the discussion

The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data. The post Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates appeared first on SecurityWeek .

MediumVulnerability#macos#ios
Join the discussion

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.

MediumVulnerability#macos#ios
Join the discussion

For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained the intrusion, but degraded systems caused delays while affected services were restored. Ryde, an electric scooter operator in Scandinavian countries, has disclosed a data breach affecting all 4.5 million customer accounts across Norway, Sweden, Finland, and Germany. Attackers copied phone numbers, email addresses, birth dates, partial payment card numbers, and payment histories. Full card numbers and ride histories were unaffected. Canadian hardware wallet maker Coinkite has disclosed a theft campaign exploiting a Coldcard firmware vulnerability, with at least 1,367 bitcoin worth about $88.6 million stolen from thousands of addresses. The company halted affected shipments, destroyed vulnerable inventory, and released patched firmware after confirming exploitation against customer wallets. Beacon, a UK provider of customer relationship management software for charities, has disclosed a data breach after attackers compromised an access key. The company notified around 1,500 nonprofit customers that database information, donation records, and stored attachments may have been downloaded. Payment and bank details were not affected. AI THREATS Check Point Research has demonstrated that Cloudflare Code Mode, which allows AI agents to write TypeScript against tools, inherited five vulnerabilities from the workerd runtime. The flaws could enable sandbox escape and cross-tenant data exposure. Cloudflare rated two issues Critical and fixed its managed Workers environment. Researchers have disclosed vulnerabilities in Google Gemini CLI and Anthropic Claude Code that could expose automation environments to code execution and API key theft. CVE-2026-12537, rated CVSS 10.0, affected Gemini CLI workflows, while CVE-2026-54316 affected Claude Code. Both vendors released patched versions. Researchers have detailed AI-enabled identity fraud kits that automate know-your-customer bypasses across banks, fintech companies, and cryptocurrency exchanges. Tools such as ProKYC can generate identity documents, selfie-with-ID images, spoofed location data, and synthetic video used against document, selfie, and liveness checks during remote onboarding. VULNERABILITIES AND PATCHES Cisco has released fixes for multiple critical vulnerabilities in Catalyst SD-WAN and IOS XE software disclosed on August 5. The highest-severity issues carry CVSS scores up to 9.9 and can enable privilege escalation, code execution, or system compromise. Cisco also addressed additional high and medium-severity flaws across network management products. WordPress has released version 7.0.3 to address CVE-2026-64638, a high-severity Core vulnerability known as XSS2Shell. The flaw can turn a failed login into pre-authentication cross-site scripting and, under specific conditions, remote code execution. Fixes were also backported for supported WordPress branches dating to version 4.7. TP-Link has addressed 15 vulnerabilities in its Omada provisioning ecosystem affecting controllers, network devices, mobile applications, and VIGI cameras. The flaws include device impersonation, credential exposure, and remote code execution risks during provisioning. 11 flaws received CVE identifiers, and patched firmware has been released for affected products. A vendor-installed backdoor has been identified across at least 20 Zbtlink router models sold under brands including Wiflyer and ZBT. The remote-management component contacts hardcoded servers and can accept unauthenticated commands with root privileges. Researchers reproduced the behavior by impersonating the vendor server and obtaining a root shell. THREAT INTELLIGENCE REPORTS Resear…

Join the discussion

Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code. The post Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities appeared first on SecurityWeek .

CriticalVulnerability#ios#cisco
Join the discussion

A denial-of-service (DoS) vulnerability exists in the in-app browser of the LINE client for iOS. The issue arises from insufficient safeguards when handling arbitrary URL schemes, which may cause the application to become unresponsive or crash. No specific affected versions or patches have been identified in the provided data. There is no evidence of active exploitation in the wild at this time.

MediumVulnerability#ios#dos
Join the discussion

iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter

Join the discussion

Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used protocol [1]. RCS is supposed to eventually replace SMS, and in addition to richer formatting, provides added (but optional) security. RCS messages may be end-to-end encrypted and digitally signed. Unlike SMS, which was "bolted on" to existing voice-focused phone standards. The SMS standard was based on old-fashioned pagers and allowed for limited clear-text communications. RCS is built from the ground up around modern IP-based network infrastructure and behaves more like IP chat services (think iMessage, WhatsApp...). RCS defines the message format, while protocols like SIP are used to establish connections and transport messages.

Join the discussion

Showing 1 to 10 of 70 results

Filters:Tag: ios
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses