home.social

#iossecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iossecurity, aggregated by home.social.

fetched live
  1. Seems like apple whilst working on optimisations for ios27 has kindly removed a lot of memset(0) ‘s
    Happy hunting #iukuk #apple #iossecurity

  2. Storing passwords and tokens securely on iOS? Keychain Services API handles encryption under the hood, but its query-based C API can feel dated. This guide walks through save, retrieve, and update operations with clear Swift examples.

    🔗: tanaschita.com/ios-keychain-se by Natascha Fadeeva (@tanaschita)

    #Swift #iOSSecurity #iOSDev

  3. DarkSword iOS exploit kit leaked on GitHub.
    • 6-vuln chain
    • Targets iOS 18 and older
    • Enables full spyware deployment
    • Now usable by low-skill actors
    Shift from targeted espionage → scalable threat.

    technadu.com/darksword-iphone-

    #InfoSec #ZeroDay #iOSSecurity

  4. DarkSword iOS exploit kit leaked on GitHub.
    • 6-vuln chain
    • Targets iOS 18 and older
    • Enables full spyware deployment
    • Now usable by low-skill actors
    Shift from targeted espionage → scalable threat.

    technadu.com/darksword-iphone-

    #InfoSec #ZeroDay #iOSSecurity

  5. Darksword exploit kit chains 6 iOS flaws to achieve full device compromise.
    • RCE → kernel access
    • Used by multiple threat actors
    • High-risk data exfiltration

    Patch immediately 👇
    technadu.com/darksword-exploit

    #InfoSec #iOSSecurity #ZeroDay

  6. Darksword exploit kit chains 6 iOS flaws to achieve full device compromise.
    • RCE → kernel access
    • Used by multiple threat actors
    • High-risk data exfiltration

    Patch immediately 👇
    technadu.com/darksword-exploit

    #InfoSec #iOSSecurity #ZeroDay

  7. Reports link the Coruna iPhone exploit framework to Trenchant, the offensive cyber division of U.S. contractor L3Harris.

    Originally built for intelligence operations, the toolkit allegedly leaked and was later used by Russian and China-linked threat actors.

    technadu.com/us-contractor-tre

    #infosec #iossecurity #zeroday #threatintel

  8. "¡Alerta iPhone! 'Coruna': kit de exploits ultra-sofisticado (posiblemente del gobierno EE.UU.) se filtra al mercado negro. Usa 23 vulnerabilidades en iOS 13-17.2.1 → hackea solo visitando web maliciosa. Actualiza YA a iOS 26 para blindarte. No es broma. 🔒#Coruna #iOSSecurity"

  9. 🔒 Scopri i migliori VPN per iPhone e iPad del gennaio 2026! Sicurezza e privacy a portata di tap. #VPN2026 #iOSsecurity

    🔗 tomshw.it/hardware/migliori-vp

  10. We’ve been trained to think privacy is a feature you toggle on. In reality, it’s an ongoing negotiation between users, systems, companies, and incentives that rarely align.

    What surprised me most here isn’t just the number, roughly 3,400 tracking-related calls per hour, but how invisible they are. A phone sitting quietly on your desk can still be busy talking to the world. Silence, it turns out, is not the same as restraint.

    The deeper lesson is about trust. When companies market privacy as a core value, every background behavior becomes part of that promise. Transparency isn’t about fewer connections; it’s about honest ones. Privacy doesn’t fail loudly. It fails politely, efficiently, and at scale.

    TL;DR
    🧠 Idle devices can still generate massive data traffic
    ⚡ Volume matters less than visibility and consent
    🎓 Privacy is a system design choice, not a settings page
    🔍 Trust erodes when defaults do more than users expect

    webpronews.com/iphones-leak-da

    #Privacy #TechEthics #DigitalTrust #iOSSecurity #iPhone #security #cloud #infosec #cybersecurity

  11. We’ve been trained to think privacy is a feature you toggle on. In reality, it’s an ongoing negotiation between users, systems, companies, and incentives that rarely align.

    What surprised me most here isn’t just the number, roughly 3,400 tracking-related calls per hour, but how invisible they are. A phone sitting quietly on your desk can still be busy talking to the world. Silence, it turns out, is not the same as restraint.

    The deeper lesson is about trust. When companies market privacy as a core value, every background behavior becomes part of that promise. Transparency isn’t about fewer connections; it’s about honest ones. Privacy doesn’t fail loudly. It fails politely, efficiently, and at scale.

    TL;DR
    🧠 Idle devices can still generate massive data traffic
    ⚡ Volume matters less than visibility and consent
    🎓 Privacy is a system design choice, not a settings page
    🔍 Trust erodes when defaults do more than users expect

    webpronews.com/iphones-leak-da

    #Privacy #TechEthics #DigitalTrust #iOSSecurity #iPhone #security #cloud #infosec #cybersecurity

  12. How do you build iOS apps that don't crumble when someone jailbreaks their phone or spoofs their location? This article shares production-tested security patterns covering jailbreak detection, certificate pinning, secure storage, and more. Real-world defense strategies that actually work, not just theoretical best practices.

    🔗: medium.com/@wesleymatlock/trea by Wesley Matlock

    #iOSSecurity #MobileSecurity #InfoSec

  13. 🔒Scopri i migliori VPN per iPhone e iPad di Agosto 2025! Proteggi la tua privacy e naviga in sicurezza ovunque tu sia! #VPN2025 #iOSSecurity

    🔗 tomshw.it/hardware/migliori-vp

  14. A single iMessage might now compromise your iPhone—no clicks needed. Graphite spyware is targeting journalists worldwide and raising serious questions about our digital safety. Curious to learn more?

    thedefendopsdiaries.com/graphi

    #graphitespyware
    #zeroclickexploit
    #iossecurity
    #cyberthreats
    #journalistprotection

  15. Installing unsigned or fake-signed iOS apps for testing without a Mac, Xcode, or access to proper signing tools can be a challenge.

    Since iOS normally relies on the App Store to handle signing, getting apps onto a device manually isn’t always straightforward.

    In our latest blog, we break down the main approaches to sideloading using tweaks on jailbroken devices, sideloading platforms like AltStore and Sideloadly, and on-device tools like TrollStore.

    Whether your device is jailbroken or not, you’ll find a method that works.

    📌Read here: pentestpartners.com/security-b

    #iOSSecurity #MobileAppTesting #Sideloading #CyberSecurity #infosec

  16. Installing unsigned or fake-signed iOS apps for testing without a Mac, Xcode, or access to proper signing tools can be a challenge.

    Since iOS normally relies on the App Store to handle signing, getting apps onto a device manually isn’t always straightforward.

    In our latest blog, we break down the main approaches to sideloading using tweaks on jailbroken devices, sideloading platforms like AltStore and Sideloadly, and on-device tools like TrollStore.

    Whether your device is jailbroken or not, you’ll find a method that works.

    📌Read here: pentestpartners.com/security-b

    #iOSSecurity #MobileAppTesting #Sideloading #CyberSecurity #infosec

  17. 🚨 iVerify's iOS app detected 11 new Pegasus infections in December 2024! 🦠 Shockingly, about half of the affected devices didn’t receive Threat Notifications from Apple. A major security concern! 🔐 #iOSSecurity #PegasusSpyware #Apple #TechNews #Privacy

    posivi.com/iverifys-ios-app-de

  18. 🚨 iVerify's iOS app detected 11 new Pegasus infections in December 2024! 🦠 Shockingly, about half of the affected devices didn’t receive Threat Notifications from Apple. A major security concern! 🔐 #iOSSecurity #PegasusSpyware #Apple #TechNews #Privacy

    posivi.com/iverifys-ios-app-de

  19. I always find these kinds of posts fascinating and can usually pick up a glimpse of iOS design from them. In this case, the article talks a lot about the Secure Enclave and how it interacts with other parts of the phone. I also appreciate the before first unlock / after first unlock call outs.

    #ios #security #iossecurity #blogposts #iphone naehrdine.blogspot.com/2024/11

  20. Italian spyware firm is hacking into iOS and Android devices, Google says - Google's Threat Analysis Group (TAG) has identified Italian vendor RCS Lab as a spywar... - computerworld.com/article/3665 #androidsecurity #iossecurity #google #apple

  21. Unpatchable bug in millions of iOS devices exploited, developer claims - Enlarge / Devices as recent as the iPhone X, based on Apple's A11 chip, are claimed to be vulnerabl... more: arstechnica.com/?p=1575923 #jailbreaking #iossecurity #biz&it #tech #ios