Dec. 15, 2023, 10:37 p.m. | SANS Offensive Operations

SANS Offensive Operations www.youtube.com

In this session, SANS Senior Instructor Christopher Crowley discusses the recent BLASTPASS exploit chain for (CVE-2023-41064 and CVE-2023-41061) attributed to NSO by CitizenLab (CA), targeting the PassKit iOS component intended for the distribution of passes (coupons and tickets).

This complex and effective exploit was discovered in the wild and required no user interaction to gain complete control of Apple iOS mobile devices running the 16.6 (latest at the time) iOS version. Because of the nature of the pass distribution for …

blastpass campaign citizenlab click cve cve-2023-41061 cve-2023-41064 distribution exploit exploitation exploit chain ios latest nso sans session targeting tickets zero-day

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States