Apple REFUSES to pay $1 Million Bounty! (Plus, WWDC Updates!) | Technado 364

Поділитися
Вставка
  • Опубліковано 5 лип 2024
  • Get ready for a lot of opinions on this week’s Technado - Apple’s WWDC 2024 is underway, and we have some thoughts. In other breaking news, Black Basta threat actors may have exploited a Windows 0-day, and Fortinet has patched multiple vulnerabilities in FortiOS. And WWDC isn’t the only Apple news this week: the tech giant is refusing to pay a $1 million bounty to Kaspersky labs for some iOS zero-days.
    After our Apple tirade, we cover some malicious VSCode extensions with MILLIONS of downloads. Then, we take a look at not one, but TWO 4chan data leaks of some major companies: the New York Times and Disney.
    Following a quick break, we say hello to an old friend in this week’s D’oh! Segment: it’s LastPass! The company essentially DoS’ed themselves thanks to a faulty Chrome extension. We also have yet another Recall update - Windows heard the call for better security, and they’re responding by…making Recall an opt-in feature.
    Next up, a new ransomware variant dubbed ‘Fog’ that’s targeting US businesses, and NY is introducing mobile IDs to replace physical ones. To wrap up the episode, British semiconductor giant Arm is warning customers about a use-after-free bug.
    Timestamps:
    0:00 - Intro
    1:30 - Breaking News: Black Basta Exploited Windows Zero-day
    4:53 - Fortinet Patches Code Execution Flaw
    7:58 - Apple Intelligence Announced at WWDC
    18:09 - Apple Won't Pay $1 Million Bounty
    26:06 - Malicious VSCode Extensions Found
    32:48 - NYT Data Leaks on 4Chan
    34:59 - Club Penguin Fans Hack Disney Server
    40:22 - D'oh! Lastpass Self-DoS
    48:12 - Microsoft Answers Recall Outcries
    53:30 - Fog Ransomware Stealing RDP Logins
    57:11 - NY Now Uses Mobile IDs
    1:05:27 - Exploited Vuln in GPU Kernel Drivers
    Want to read further? Check out the articles we covered this week:
    thehackernews.com/2024/06/bla...
    www.securityweek.com/fortinet...
    www.engadget.com/apple-intell...
    gbhackers.com/apple-kaspersky...
    www.bleepingcomputer.com/news...
    www.bleepingcomputer.com/news...
    www.bleepingcomputer.com/news...
    www.bleepingcomputer.com/news...

КОМЕНТАРІ • 24

  • @qkb3128
    @qkb3128 23 дні тому +9

    Apple needs to pay Now. We Need Strong Privacy Laws. Invading a persons privacy should be a felony.

    • @brandonw1604
      @brandonw1604 22 дні тому

      They can’t pay due to sanctions.

  • @BreakingVel
    @BreakingVel 22 дні тому +6

    Had no idea Don retired. 😢 gonna miss the GOAT, but hope he enjoys his time!

  • @rusty-
    @rusty- 22 дні тому +1

    Main use for Recall? To allow law enforcement to avoid the inevitable use of end-to-end encryption in everything

  • @2rx_bni
    @2rx_bni 17 днів тому

    As a frequent BART rider and mildly paranoid person AND a parent, being able to hide apps is a godsend.

  • @mikereese15
    @mikereese15 19 днів тому

    Safe driving will become part of your social credit score Daniel😅

  • @JamesMCrutchley
    @JamesMCrutchley 23 дні тому +2

    Just start offering vulnerabilities to highest bidder from now on. Why take a chance on a company not paying?

  • @xXstevilleXx
    @xXstevilleXx 12 днів тому

    Interesting you guys mention Kaspersky. You already mention the reason. The US Department of Commerce is not banning it for the reasons they claim.
    Kind of the same reason why TT is not banned for reasons claimed. I like the satire and commentary on this channel, it dovetails so neatly into my own research, so it is fun to watch

  • @mwyn5085
    @mwyn5085 22 дні тому +1

    OMGosh! LOVE the banter! 😂🤣 You two r a trip! And u always teach me something while i am laughing! 😆

  • @jimkirk360
    @jimkirk360 22 дні тому +1

    I'd say if the Apple doesn't want to pay on the bounties that people find then we should just let them do their own thing and let the bugs persist.

    • @ownplz5632
      @ownplz5632 22 дні тому

      Apple is refusing to pay a Russian company not a person.

    • @brandonw1604
      @brandonw1604 22 дні тому

      They can’t due to sanctions. Like how Azure’s networks don’t work in Cuba. Due to sanctions.

    • @2rx_bni
      @2rx_bni 17 днів тому

      Agree. Saying this as a Mac user.

    • @brandonw1604
      @brandonw1604 17 днів тому

      @@2rx_bni Well Apple can't legally pay them so there's that.

  • @Douglas_Gillette
    @Douglas_Gillette 22 дні тому

    It is nice to see this technology education channel hint to Apple being ‘big brother’.

  • @xXstevilleXx
    @xXstevilleXx 12 днів тому

    Recall as mentioned in your latest vid reminds me of some models of new iPhones that do the same which people discovered using infrared taking an image every 4-5 seconds... you know to see if you are still viewing the screen... BUT... this lame answer only had users place it far away while the screen is off and it still goes about doing the same.
    There is a reason why I only use old phones since I open it physically detach the mic's, cams and those types of censors, I manually connect to external devices if I need to use it for voice calls or video calls

  • @stevejobson8012
    @stevejobson8012 18 днів тому

    Why do people keep going on about iPad not having calculator app. My iPad mini 2 has always had calculator app from new.

  • @sm-btwrlm2518
    @sm-btwrlm2518 22 дні тому +2

    Microsoft plays with Russian companies per agreements in kickbacks ..
    Per Microsoft gaming even , Just sayin

  • @tmcarter3
    @tmcarter3 23 дні тому +1

    Cant wait to hear this.. Im sure someone is going to have an excuse.

  • @DFreshTech
    @DFreshTech 22 дні тому +1

    Someone needs some Insta-Bran in their diet. Just saying this because it sounds like a bad- as in nasty- social media site - poop pics 🤢🤢

  • @PaulGriffith
    @PaulGriffith 22 дні тому +1

    Apple should at least give the bounty to a US or UN based charity.

  • @sergeantwarrior1
    @sergeantwarrior1 22 дні тому

    Hey, love the show.
    The security flaw in question CVE-2024-26169 states it was patched in March 2024 according to the Hacker News article