CVE-2024-23222
published 2024-01-23CVE-2024-23222: A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS…
PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-02-13
Exploited in the wild
EPSS
10.59%
95.3th percentile
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.8.7_and_ipados | — | — |
| apple | ios_16.7.5_and_ipados | — | — |
| apple | ios_17.3_and_ipados | — | — |
| apple | ios_and_ipados | < 15.8.7 | 15.8.7 |
| apple | ios_and_ipados | < 16.7.5 | 16.7.5 |
| apple | ios_and_ipados | < 17.3 | 17.3 |
| apple | ipados | < 15.8.7 | 15.8.7 |
| apple | ipados | >= 16.0 < 16.7.5 | 16.7.5 |
| apple | ipados | >= 17.0 < 17.3 | 17.3 |
| apple | iphone_os | < 15.8.7 | 15.8.7 |
| apple | iphone_os | >= 16.0 < 16.7.5 | 16.7.5 |
| apple | iphone_os | >= 17.0 < 17.3 | 17.3 |
| apple | macos | < 12.7.3 | 12.7.3 |
| apple | macos | < 13.6.4 | 13.6.4 |
| apple | macos | < 14.3 | 14.3 |
| apple | macos | >= 12.0 < 12.7.3 | 12.7.3 |
| apple | macos | >= 13.0 < 13.6.4 | 13.6.4 |
| apple | macos | >= 14.0 < 14.3 | 14.3 |
| apple | macos_monterey | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| apple | safari | < 17.3 | 17.3 |
| apple | safari | — | — |
| apple | tvos | < 17.3 | 17.3 |
| apple | tvos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
0xf00dbeef
- →Detect Coruna exploit kit delivery by hunting for HTTP responses serving binary payloads from URLs ending with '.min.js' that contain the magic header bytes 0xf00dbeef — these are ChaCha20-encrypted, LZW-compressed exploit blobs. ↗
- →Detect the Coruna JavaScript obfuscation pattern: array of integers mapped through XOR with 101 and converted to characters via String.fromCharCode, e.g. '[16, 22, 0, 69, ...].map(x => {return String.fromCharCode(x ^ 101);}).join("")'. ↗
- →Detect Coruna integer obfuscation pattern in JavaScript: XOR of two large integers used to encode constants, e.g. 'i.p1=(1111970405 ^ 1111966034);'. ↗
- →Detect Coruna delivery via hidden iFrame injection on compromised websites: iOS devices browsing to fake financial/crypto sites that inject a hidden iFrame loading the exploit framework should be flagged. ↗
- →The Coruna exploit kit bails out if the device is in Lockdown Mode or the user is in private browsing — absence of exploit delivery to such sessions can be used as a behavioral differentiator in controlled testing. ↗
- →Detect Coruna implant logging strings in memory or crash dumps: look for Chinese-language log strings such as 'CorePayload 管理器初始化成功,尝试启动...' and '[PLCoreHeartbeatMonitor] ✅ 心跳监控已启动'. ↗
- ·CVE associations in the exploit chain table are preliminary and subject to revision as analysis is ongoing. ↗
- ·The hard-coded cookie value used to derive resource URLs is unique per deployment; the specific cookie value is not published, limiting direct signature-based detection of the URL scheme. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-23222: iOS 15.8.7 and iPadOS 15.8.7
vendor_apple·2026-03-11·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: iOS 15.8.7 and iPadOS 15.8.7
Apple Security Update: About the security content of iOS 15.8.7 and iPadOS 15.8.7
Product: iOS 15.8.7 and iPadOS
Version: 15.8.7
CVE: CVE-2024-23222
Component: CVE-2024-23222
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2024-02-12
CVE-2024-23213 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
CISA
Apple Multiple Products WebKit Type Confusion Vulnerability
cisa·2024-01-23·CVSS 8.8
CVE-2024-23222 [HIGH] CWE-843 Apple Multiple Products WebKit Type Confusion Vulnerability
Vulnerability: Apple Multiple Products WebKit Type Confusion Vulnerability
Affected: Apple Multiple Products
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/HT214055, https://support.apple.com/en-us/HT214056, https://support.apple.com/en-us/HT214057, https://support.apple.com/en-us/HT214058, https://support.apple.com/en-us/HT214059, https://su
Red Hat
webkitgtk: type confusion may lead to arbitrary code execution
vendor_redhat·2024-01-23·CVSS 8.8
CVE-2024-23222 [HIGH] CWE-843 webkitgtk: type confusion may lead to arbitrary code execution
webkitgtk: type confusion may lead to arbitrary code execution
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
A flaw was found in WebKitGTK. Processing malicious web content may lead to remote code execution due to a type confusion issue. This vulnerability is known to be actively exploited in the wild and was includ
Apple
CVE-2024-23222: macOS Monterey 12.7.3
vendor_apple·2024-01-22·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: macOS Monterey 12.7.3
Apple Security Update: About the security content of macOS Monterey 12.7.3
Product: macOS Monterey
Version: 12.7.3
CVE: CVE-2024-23222
Component: CVE-2024-23222
Apple
CVE-2024-23222: macOS Ventura 13.6.4
vendor_apple·2024-01-22·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: macOS Ventura 13.6.4
Apple Security Update: About the security content of macOS Ventura 13.6.4
Product: macOS Ventura
Version: 13.6.4
CVE: CVE-2024-23222
Component: CVE-2024-23222
Apple
CVE-2024-23222: Safari 17.3
vendor_apple·2024-01-22·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: Safari 17.3
Apple Security Update: About the security content of Safari 17.3
Product: Safari
Version: 17.3
CVE: CVE-2024-23222
Component: CVE-2024-23222
Apple
CVE-2024-23222: iOS 16.7.5 and iPadOS 16.7.5
vendor_apple·2024-01-22·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: iOS 16.7.5 and iPadOS 16.7.5
Apple Security Update: About the security content of iOS 16.7.5 and iPadOS 16.7.5
Product: iOS 16.7.5 and iPadOS
Version: 16.7.5
CVE: CVE-2024-23222
Component: CVE-2024-23222
Apple
CVE-2024-23222: tvOS 17.3
vendor_apple·2024-01-22·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: tvOS 17.3
Apple Security Update: About the security content of tvOS 17.3
Product: tvOS
Version: 17.3
CVE: CVE-2024-23222
Component: CVE-2024-23222
Apple
CVE-2024-23222: macOS Sonoma 14.3
vendor_apple·2024-01-22·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: macOS Sonoma 14.3
Apple Security Update: About the security content of macOS Sonoma 14.3
Product: macOS Sonoma
Version: 14.3
CVE: CVE-2024-23222
Component: CVE-2024-23222
Apple
CVE-2024-23222: iOS 17.3 and iPadOS 17.3
vendor_apple·2024-01-22·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: iOS 17.3 and iPadOS 17.3
Apple Security Update: About the security content of iOS 17.3 and iPadOS 17.3
Product: iOS 17.3 and iPadOS
Version: 17.3
CVE: CVE-2024-23222
Component: CVE-2024-23222
Debian
CVE-2024-23222: webkit2gtk - A type confusion issue was addressed with improved checks. This issue is fixed i...
vendor_debian·2024·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: webkit2gtk - A type confusion issue was addressed with improved checks. This issue is fixed i...
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
Scope: local
bookworm: resolved (fixed in 2.42.5-1~deb12u1)
bullseye: resolved (fixed in 2.42.5-1~deb11u1)
forky: resolved (fixed in 2.42.5-1)
sid: resolved (fixed in 2.42.5-1)
trixie: resolved (fixed in 2.42.5-1)
OSV
CVE-2024-23222: A type confusion issue was addressed with improved checks
osv·2024-01-23·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: A type confusion issue was addressed with improved checks
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
GHSA
GHSA-93px-8x98-j7p2: A type confusion issue was addressed with improved checks
ghsa_unreviewed·2024-01-23
CVE-2024-23222 [HIGH] CWE-843 GHSA-93px-8x98-j7p2: A type confusion issue was addressed with improved checks
A type confusion issue was addressed with improved checks. This issue is fixed in tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
OSV
CVE-2024-23222: A type confusion issue was addressed with improved checks
osv·2024-01-23·CVSS 8.8
CVE-2024-23222 [HIGH] CVE-2024-23222: A type confusion issue was addressed with improved checks
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
VulnCheck
Apple Multiple Products WebKit Type Confusion Vulnerability
vulncheck·2024·CVSS 8.8
CVE-2024-23222 [HIGH] CWE-843 Apple Multiple Products WebKit Type Confusion Vulnerability
Apple Multiple Products WebKit Type Confusion Vulnerability
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple Multiple Products
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578; https://support.apple.com/en-
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple patches older iPhones and iPads against Coruna exploits
blogs_bleepingcomputer·2026-03-12·CVSS 7.8
CVE-2023-41974 [HIGH] Apple patches older iPhones and iPads against Coruna exploits
## Apple patches older iPhones and iPads against Coruna exploits
## Sergiu Gatlan
Apple said the patches will fix iOS security issues targeted by multiple exploit chains, many used in zero-day attacks aiming to help attackers escalate permissions to Kernel privileges or gain remote code execution on vulnerable devices.
The list of vulnerabilities addressed by these backported security patches includes:
CVE-2023-41974: A Kernel use-after-free issue addressed with improved memory management
CVE-2024-23222: A WekKit type confusion issue addressed with improved checks
CVE-2023-43000: A WebKit use-after-free issue addressed with improved memory management
CVE-2023-43010: A WebKit issue was addressed with improved memory handling
The list of devices impacted by these vulnerabilities is a
Mandiant
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
blogs_mandiant·2026-03-03
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
Threat Intelligence
# Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
March 3, 2026
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
### Introduction
Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023). The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypas
Mandiant
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
blogs_mandiant·2026-03-03
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
## Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
## Introduction
Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023) . The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypasses.
The Coruna exploit kit provides another example of how sophi
Bleepingcomputer
Apple fixes this year’s first actively exploited zero-day bug
blogs_bleepingcomputer·2025-01-27·CVSS 6.5
CVE-2024-23222 [MEDIUM] Apple fixes this year’s first actively exploited zero-day bug
## Apple fixes this year’s first actively exploited zero-day bug
## Sergiu Gatlan
According to the company's official documentation , Core Media "defines the media pipeline used by AVFoundation and other high-level media frameworks found on Apple platforms."
Apple has fixed CVE-2024-23222 with improved memory management in iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, visionOS 2.3, and tvOS 18.3.
The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including:
iPhone XS and later,
iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
macOS Sequoia
Apple Watch Ser
Securelist
Advanced threat predictions for 2025
blogs_securelist·2024-11-25
Advanced threat predictions for 2025
Table of Contents
Review of last year’s predictions
The rise of creative exploits for mobile, wearables and smart devices
Building new botnets with consumer and corporate software and appliances
Barriers to kernel-level code execution increasingly evaded (kernel rootkits hot again)
Growth in cyberattacks by state-sponsored actors
Hacktivism in cyber-warfare: the new normal in geopolitical conflicts
Supply chain attacks as a service: operators bulk-buying access
Spear-phishing to expand with accessible generative AI
Emergence of more groups offering hack-for-hire services
MFT systems at the forefront of cyberthreats
APT predictions for 2025
Hacktivist alliances to escalate in 2025
The IoT to become a growing attack vector for APTs in 2025
Increasing supply chain attacks on ope
Securelist
Advanced threat predictions for 2025
blogs_securelist·2024-11-25·CVSS 8.8
[HIGH] Advanced threat predictions for 2025
Table of Contents
- Review of last year’s predictions
- APT predictions for 2025
Authors
- Igor Kuznetsov
- Giampaolo Dedola
- Georgy Kucherin
- Maher Yamout
- Vasily Berdnikov
- Isabel Manjarrez
- Ilya Savelyev
- Joao Godinho
We at Kaspersky’s Global Research and Analysis Team monitor over 900 APT (advanced persistent threat) groups and operations. At the end of each year, we take a step back to assess the most complex and sophisticated attacks that have shaped the threat landscape. These insights enable us to anticipate emerging trends and build a clearer picture of what the APT landscape may look like in the year ahead.
In this article in the KSB series, we review the trends of the past year, reflect on the predictions we made for 2024, and offer insights into what we can expect in
Bleepingcomputer
Apple backports fix for zero-day exploited in attacks to older iPhones
blogs_bleepingcomputer·2024-05-13·CVSS 6.5
CVE-2024-23296 [MEDIUM] Apple backports fix for zero-day exploited in attacks to older iPhones
## Apple backports fix for zero-day exploited in attacks to older iPhones
## Sergiu Gatlan
On March 5th, the company addressed the zero-day vulnerability (tracked as CVE-2024-23296) for newer iPhone, iPad, and Mac models.
Today, Apple backported the March security updates to address this security flaw on iOS 16.7.8, iPadOS 16.7.8 , and macOS Ventura 13.6.7 with improved input validation.
The list of devices patched today includes iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation.
## Three zero-days exploited in attacks patched in 2024
Apple has yet to disclose who disclosed the zero-day or whether it was discovered internally, and it has provided no information on the nature of the attacks exploiting it in the wild.
Even
Talos
Spyware isn’t going anywhere, and neither are its tactics
blogs_talos·2024-02-08
Spyware isn’t going anywhere, and neither are its tactics
Private and public efforts to curb the use of spyware and activity of other “mercenary” groups have heated up over the past week, with the U.S. government taking additional action against spyware users and some of the world’s largest tech companies calling out international governments to do more.
The illegal use of spyware to target high-profile or at-risk individuals is a global problem, as highlighted by this article from The Register that Talos’ Nick Biasini just contributed to. This software can often track targets’ exact location, steal their messages and personal information, or even listen in on phone calls. And as we’ve written about, many Private Sector Offensive Actors (PSOAs) are developing spyware and selling it to whoever is willing to pay, regardless of what their motives a
Talos
Spyware isn’t going anywhere, and neither are its tactics
blogs_talos·2024-02-08
Spyware isn’t going anywhere, and neither are its tactics
## Spyware isn’t going anywhere, and neither are its tactics
Private and public efforts to curb the use of spyware and activity of other “mercenary” groups have heated up over the past week, with the U.S. government taking additional action against spyware users and some of the world’s largest tech companies calling out international governments to do more.
The illegal use of spyware to target high-profile or at-risk individuals is a global problem, as highlighted by this article from The Register that Talos’ Nick Biasini just contributed to . This software can often track targets’ exact location, steal their messages and personal information, or even listen in on phone calls. And as we’ve written about, many Private Sector Offensive Actors (PSOAs) are developing spyware and selling it t
Bleepingcomputer
CISA warns of patched iPhone kernel bug now exploited in attacks
blogs_bleepingcomputer·2024-01-31·CVSS 7.0
[HIGH] CISA warns of patched iPhone kernel bug now exploited in attacks
## CISA warns of patched iPhone kernel bug now exploited in attacks
## Sergiu Gatlan
"An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication," the company revealed this month.
"Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1."
This improper authentication security vulnerability enables attackers to bypass Pointer Authentication, a security feature designed to block attacks trying to exploit memory corruption bugs.
Apple addressed the flaw with improved checks on devices running iOS 16.2 or later, iPadOS 16.2 or later, macOS Ventura or newer, tvOS 16.2 or higher, and watchOS 9.2 or later.
The list of devices impacted by this actively exploited flaw is quite extensive and it
Checkpoint
29th January – Threat Intelligence Report
blogs_checkpoint·2024-01-29
CVE-2024-23222 29th January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th January, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Following the reports on Russia-affiliated APT29 (AKA Cozy Bear, Midnight Blizzard) attack against Microsoft, also Hewlett-Packard Enterprise acknowledged it was attacked by the same threat actor. While Microsoft detected the breach on January 12 and the password-spray attack began in November 2023; HPE’s investigation po
Talos
Why is the cost of cyber insurance rising?
blogs_talos·2024-01-25
Why is the cost of cyber insurance rising?
## Why is the cost of cyber insurance rising?
I just bought an electric car last week, so I’ve been shopping for new car insurance policies that could offer me a discount for ditching gas.
We’re all familiar with the boring process of entering the same information 10 times over into 10 different companies’ websites trying to see who comes out the cheapest and offers the best bundles, discounts or deals.
Unfortunately, with cybersecurity insurance, there are no bundles or “Personal Price Plans” to enroll in, and costs are rising.
This is nothing to say about whether an organization should get cyber insurance . That is 100 percent their decision to make, and every case is going to be different. But for companies who are interested in getting these types of policies to be best prepared to
Talos
Why is the cost of cyber insurance rising?
blogs_talos·2024-01-25
Why is the cost of cyber insurance rising?
I just bought an electric car last week, so I’ve been shopping for new car insurance policies that could offer me a discount for ditching gas.
We’re all familiar with the boring process of entering the same information 10 times over into 10 different companies’ websites trying to see who comes out the cheapest and offers the best bundles, discounts or deals.
Unfortunately, with cybersecurity insurance, there are no bundles or “Personal Price Plans” to enroll in, and costs are rising.
This is nothing to say about whether an organization should get cyber insurance. That is 100 percent their decision to make, and every case is going to be different. But for companies who are interested in getting these types of policies to be best prepared to recover from and deal with a potential security
Bleepingcomputer
Apple fixes first zero-day bug exploited in attacks this year
blogs_bleepingcomputer·2024-01-22·CVSS 8.8
[HIGH] Apple fixes first zero-day bug exploited in attacks this year
## Apple fixes first zero-day bug exploited in attacks this year
## Sergiu Gatlan
"Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited," Apple said today.
The company has yet to attribute the discovery of this security vulnerability to a security researcher. Although the company disclosed that it's aware of in-the-wild exploitation, it has yet to publish further details regarding these attacks.
Apple addressed CVE-2024-23222 with improved checks in iOS 16.7.5 and later, iPadOS 16.7.5 and later, and macOS Monterey 12.7.3 and higher, as well as on tvOS 17.3 and later.
The complete list of devices impacted by this WebKit zero-day is quite extensive, as the bug affects older and newer models, i
Bugzilla
CVE-2022-23222 kernel: local privileges escalation in kernel/bpf/verifier.c
bugzilla·2022-01-21·CVSS 7.8
CVE-2022-23222 [HIGH] CVE-2022-23222 kernel: local privileges escalation in kernel/bpf/verifier.c
CVE-2022-23222 kernel: local privileges escalation in kernel/bpf/verifier.c
Local privileges escalation possible because of the availability of pointer arithmetic via certain *_OR_NULL pointer types in kernel/bpf/verifier.c.
Reference:
https://www.openwall.com/lists/oss-security/2022/01/13/1
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2043521]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.6 Extended Update Support
Via RHSA-2024:0724 https://access.redhat.com/errata/RHSA-2024:0724
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issue has been addressed in the following products:
Re
https://support.apple.com/en-us/118479https://support.apple.com/en-us/120304https://support.apple.com/en-us/120305https://support.apple.com/en-us/120307https://support.apple.com/en-us/120309https://support.apple.com/en-us/120310https://support.apple.com/en-us/120311https://support.apple.com/en-us/120339https://support.apple.com/en-us/126632http://seclists.org/fulldisclosure/2024/Feb/6http://seclists.org/fulldisclosure/2024/Jan/34http://seclists.org/fulldisclosure/2024/Jan/40https://lists.fedoraproject.org/archives/list/[email protected]/message/US43EQFC2IS66EA2CPAZFH2RQ6WD7PKF/https://support.apple.com/en-us/HT214055https://support.apple.com/en-us/HT214059https://support.apple.com/en-us/HT214061https://support.apple.com/kb/HT214055https://support.apple.com/kb/HT214056https://support.apple.com/kb/HT214057https://support.apple.com/kb/HT214058https://support.apple.com/kb/HT214059https://support.apple.com/kb/HT214061https://support.apple.com/kb/HT214063https://support.apple.com/kb/HT214070https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23222
2024-01-23
Published
2024-01-23
Added to CISA KEV
Exploited in the wild