Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

8/17/2018
12:30 PM
50%
50%

Australian Teen Hacked Apple Network

The 16-year-old made off with 90 gigs of sensitive data.

An Australian teenager hacked into Apple's enterprise computer network, making off with 90 gigabytes of data before being discovered. He also accessed an undisclosed number of customer accounts during his year-long intrusion.

According to reports - by Reuters and Melbourne, Australia-based newspaper The Age, citing court statements - Australian Federal Police raided the teen's home after being contacted by the FBI, who were notified of the attack by Apple. In the raid, police confiscated two laptops, a mobile phone, and a hard drive with a folder named "hacky hack hack" in which the stolen documents were stored.

According to reports, the teen, who said he admired Apple and hoped to find work there, has pleaded guilty to charges related to the hacking and will be sentenced on Sept. 20.

More information on the hacker is not available because, at 16, he is not yet an adult and his privacy is protected by the Children's Court of Victoria. Details of the intrusion have not been made public because the action is the subject of an ongoing criminal investigation.

"We ... want to assure our customers that at no point during this incident was their personal data compromised," an Apple spokesman told Reuters.

For more, read here.

Learn from the industry's most knowledgeable CISOs and IT security experts in a setting that is conducive to interaction and conversation. Early bird rate ends August 31. Click for more info

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
8/17/2018 | 6:35:05 PM
Re: Admiral Kirk was right
I definitely concur. I feel like the days of crack my security for your interview are over and now it goes into harsh sentencing. 
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
8/17/2018 | 2:56:33 PM
Admiral Kirk was right
"Galavanting around the universe is a game for the young."  The Wrath of Khan - and Apple should hire this young wizard to monitor defence from the inside.   In exchange for light sentence. 
Microsoft Patches Wormable RCE Vulns in Remote Desktop Services
Kelly Sheridan, Staff Editor, Dark Reading,  8/13/2019
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15160
PUBLISHED: 2019-08-19
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.
CVE-2019-15150
PUBLISHED: 2019-08-19
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.
CVE-2017-18550
PUBLISHED: 2019-08-19
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo structure.
CVE-2017-18551
PUBLISHED: 2019-08-19
An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds write in the function i2c_smbus_xfer_emulated.
CVE-2017-18552
PUBLISHED: 2019-08-19
An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in the function rds_recv_track_latency.