10th Indian Delegation to Dubai, Gitex & Expand North Star – World’s Largest Startup Investor Connect
Tech

Vulnerability in Microsoft apps allowed hackers to spy on Mac users


A vulnerability found in Microsoft apps for macOS allowed hackers to spy on Mac users. Security researchers from Cisco Talos reported in a blog post how the vulnerability could be exploited by attackers and what Microsoft has been doing to fix the exploits.

Hackers can use Microsoft apps to access Mac users’ cameras and microphones

Cisco Talos, a cybersecurity group specializing in malware and system prevention, shared details on how a vulnerability in apps like Microsoft Outlook and Teams could lead attackers to access a Mac’s microphone and camera without the user’s consent. The attack is based on injecting malicious libraries into Microsoft apps to gain their entitlements and user-granted permissions.

Apple’s macOS has a framework known as Transparency Consent and Control (TCC), which manages app permissions to access things like location services, camera, microphone, library photos, and other files.

Each app needs an entitlement to request permissions from TCC. Apps without these entitlements won’t even ask for permissions, and consequently won’t have access to the camera and other parts of the computer. However, the exploit allowed malicious software to use the permissions granted to Microsoft apps.

“We identified eight vulnerabilities in various Microsoft applications for macOS, through which an attacker could bypass the operating system’s permission model by using existing app permissions without prompting the user for any additional verification,” the researchers explain.

For example, a hacker could create malicious software to record audio from the microphone or even take photos without any user interaction. “All apps, except for Excel, have the ability to record audio, some can even access the camera,” the group adds.

macOS Sequoia Gatekeeper

Microsoft is working on a fix – but it doesn’t seem to be a priority

According to Cisco Talos, Microsoft considers this exploit to be “low risk” since it relies on loading unsigned libraries to support third-party plugins.

After the exploits were reported, Microsoft updated the Microsoft Teams and OneNote apps for macOS with changes to how these apps handle the library validation entitlement. However, Excel, PowerPoint, Word, and Outlook are still vulnerable to the exploit.

The researchers question why Microsoft had the need to disable library validation, especially when additional libraries are not expected to be loaded. “By using this entitlement, Microsoft is circumventing the safeguards offered by the hardened runtime, potentially exposing its users to unnecessary risks.”

At the same time, the researchers note that Apple could also implement changes to the TCC to make the system more secure. The group suggests that the system should prompt users when loading third-party plugins into apps that already have granted permissions.

More details about the exploit can be found on the Cisco Talos blog.

Read also

FTC: We use income earning auto affiliate links. More.



Source link

by Siliconluxembourg

Would-be entrepreneurs have an extra helping hand from Luxembourg’s Chamber of Commerce, which has published a new practical guide. ‘Developing your business: actions to take and mistakes to avoid’, was written to respond to  the needs and answer the common questions of entrepreneurs.  “Testimonials, practical tools, expert insights and presentations from key players in our ecosystem have been brought together to create a comprehensive toolkit that you can consult at any stage of your journey,” the introduction… Source link

by WIRED

B&H Photo is one of our favorite places to shop for camera gear. If you’re ever in New York, head to the store to check out the giant overhead conveyor belt system that brings your purchase from the upper floors to the registers downstairs (yes, seriously, here’s a video). Fortunately B&H Photo’s website is here for the rest of us with some good deals on photo gear we love. Save on the Latest Gear at B&H Photo B&H Photo has plenty of great deals, including Nikon’s brand-new Z6III full-frame… Source link

by Gizmodo

Long before Edgar Wright’s The Running Man hits theaters this week, the director of Shaun of the Dead and Hot Fuzz had been thinking about making it. He read the original 1982 novel by Stephen King (under his pseudonym Richard Bachman) as a boy and excitedly went to theaters in 1987 to see the film version, starring Arnold Schwarzenegger. Wright enjoyed the adaptation but was a little let down by just how different it was from the novel. Years later, after he’d become a successful… Source link