June 9, 2023, 11:12 a.m. | Bruce Schneier

Schneier on Security www.schneier.com

Kaspersky is reporting a zero-click iOS exploit in the wild:


Mobile device backups contain a partial copy of the filesystem, including some of the user data and service databases. The timestamps of the files, folders and the database records allow to roughly reconstruct the events happening to the device. The mvt-ios utility produces a sorted timeline of events into a file called “timeline.csv,” similar to a super-timeline used by conventional digital forensic tools.


Using this timeline, we were able to …

backups click copy data database databases device events exploit exploit in the wild exploits files filesystem folders forensics ios iphone iphone malware kaspersky malware mobile mobile device operation triangulation partial reporting service triangulation user data utility zero-click

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Principal Business Value Consultant

@ Palo Alto Networks | Chicago, IL, United States

Cybersecurity Specialist, Sr. (Container Hardening)

@ Rackner | San Antonio, TX

Penetration Testing Engineer- Remote United States

@ Stanley Black & Decker | Towson MD USA - 701 E Joppa Rd Bg 700

Internal Audit- Compliance & Legal Audit-Dallas-Associate

@ Goldman Sachs | Dallas, Texas, United States

Threat Responder

@ Deepwatch | Remote