Cyber Weekly Digest - Week #40


Although another month of 2021 has ended, the list of zero-days continues to grow; in this week's digest, we explore the latest Chrome zero-days patched by Google. We will also dive into how researchers were able to make fraudulent payments using ApplePay on a locked iPhone and the latest VoIP provider to suffer a DDoS attack. Keep reading to stay up to date with the biggest and latest cyber security news from the week.


1. Researchers discovered a way to make fraudulent payments using Apple Pay from a locked iPhone.

Academic researchers from the University of Surrey and the University of Birmingham have discovered a way in which you can make fraudulent payments using Apple Pay from a locked iPhone with a Visa card in the digital wallet with express mode enabled. The method can be seen as a digital version of pickpocketing. Even if the iPhone is in a bag or someone's pocket, it works over the air, and there is no transaction limit. Researchers say that the issue is caused by using a unique code, named "magic bytes", that is broadcast by transit gates and turnstiles to unlock Apple Pay. They could trick the iPhone into thinking it was talking to a transit gate using standard radio equipment.

2. New trojan has emerged on underground forums being used to steal online gamer accounts.

A new advanced trojan, named BloodyStealer, has been found on underground forums, and it is being used to steal gamer accounts of various platforms such as Steam, Epic Games Store and EA Origin. According to researchers, BloodyStealer first emerged last March on the dark web, being sold at $10 for a one-month subscription or $40 for a lifetime subscription. The stealer swipes data, including cookies, passwords, forms, bank-card information saved in browsers, screenshots, login memory and application sessions. There has been a growing demand on the dark web for stolen gamer accounts over the past year.


3. Bandwidth becomes the latest DDoS victim targeting VoIP providers.

Bandwidth.com has become the latest victim of distributed denial of service attacks targeting VoIP providers this month, leading to nationwide voice outages over the past few days. Bandwidth is a voice over Internet Protocol (VoIP) services company that provides voice telephony over the Internet to businesses and resellers. Due to this, many other VoIP vendors also reported outages this week, including Twilio and RingCentral. Earlier in September, provider VoiP.ms also suffered a catastrophic DDoS attack used as part of a ransomware attack.