mardi 27 septembre 2022

Fast Company’s Apple News access hijacked to send an obscene push notification

Fast Company’s Apple News access hijacked to send an obscene push notification
A black and white graphic showing the Apple logo
Nick Barclay / The Verge

It’s been a little while since we had a high-profile media feed hijacking, but tonight someone sent an Apple News notification from Fast Company containing a racial slur and invitation for a particular sexual act. They also posted similar content to the outlet’s website, indicating its CMS or an account on it has been compromised, and now the site appears to be offline, showing visitors a 404 error.

Another article posted to Fast Company’s website before it disappeared included a message from “postpixel,” describing at length how they were able to execute the attack and deriding attempts to secure the outlet’s publishing tools. The message posted to Fast Company’s own site claims they got in thanks to a password that was shared across many accounts, including an administrator.

“Wow, Fast Company. Despite the public defacement of your site, which boasts millions of visitors, all you did was hastily change your database credentials, disable outside connections to the database server, and fix the articles. What an absolute disgrace of a news source, and one that I would personally avoid due to how little they care about user security.” Image: FastCompany.com
Message posted by Fast Company hackers

The hackers also pointed to a forum for trading information stolen in security breaches, where they shared the same details, starting with posts made two days ago. The forum post said they’re releasing thousands of employee records, as well as draft posts from the database, but said customer information was stored in a different database that they did not have access to.

Apple and Fast Company haven’t commented on the incident yet, and it’s unclear exactly how many people received the blast, but a look around social media reveals it went out widely. Vox Media staffers who don’t pay for subscriptions to Fast Company say it popped up on their phones as well.

We’ve seen hackers take over Twitter feeds, YouTube channels, press release newswires, and occasionally deface websites, but an Apple News alert takeover may be a first. However, as startup exec Zack Wynegar notes, while the Fast Company message was obscene and offensive, someone with that kind of access could’ve gone another route to manipulate stock markets or crypto prices, similar to the Walmart Litecoin crypto hoax last year.

Aucun commentaire:

Enregistrer un commentaire

Pegasus spyware maker NSO Group is liable for attacks on 1,400 WhatsApp users

Pegasus spyware maker NSO Group is liable for attacks on 1,400 WhatsApp users Photo by Amelia Holowaty Krales / The Verge NSO Group, the ...