Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » How attackers are using Apple devices’ password reset exploit to target users into phishing

How attackers are using Apple devices’ password reset exploit to target users into phishing

How attackers are using Apple devices’ password reset exploit to target users into phishing

Recently, some Apple users were targeted by phishing attacks that exploit a potential vulnerability in Apple’s password reset system. According to KrebsOnSecurity, a cyber security news site, the attacks involve flooding the targeted devices with numerous pop-up messages that prompt the user to approve a password change. Some people also received fake calls, appearing to be from Apple’s actual support team, asking for a special code.

Users who faced this attack shared their experiences with KrebsOnSecurity. They reported that the constant password reset alerts prevented them from using their iPhones, MacBooks, and Apple Watches until each message was dismissed, which could amount to up to 100 messages.

After declining all the reset requests, the targets received a call that appeared to be from Apple’s support number. The scammers, who possibly obtained the victim’s personal information from people-search websites, attempted to obtain the one-time reset code that Apple sent. If the victim provided the code, the attackers would take control of the account, change the password, and erase all data on the user’s devices.

An iPhone user also faced the same issue on a new iPhone and iCloud account after he had changed his passwords. He believes the attackers only needed the phone number associated with the Apple ID to make the notifications appear.

Another user, who was also a victim of the attack, said that he was awakened in the middle of the night by an Apple Watch notification that nearly caused him to accidentally authorise the reset request.

Apple has yet to comment on the attacks. However, Kishan Bagaria, a software engineer who identified a similar problem in 2019, believes that Apple’s password reset system may have an issue with rate limiting, as it may not be able to restrict the number of alerts sent within a short period.

Apple users should be cautious of unexpected password reset notifications or support calls. Enabling an Apple Recovery Key may help, although it can be troublesome. The most critical step is never to provide one-time passcodes to anyone, including those claiming to be from Apple or other companies, since legitimate support personnel will never solicit this information.

It is suggested to enable multi-factor authentication systems that can withstand the “MFA fatigue” tactics that cybercriminals are increasingly using. For the time being, remaining vigilant and suspicious is the best way to avoid these new phishing attempts aimed at Apple users.

 

Information Security - InfoSec - Cyber Security - Firewall Providers Company in India

 

 

 

 

 

 

 

 

 

 

 

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket