Application security consultancy
Appears in 1 story
Published research; disclosed both vulnerabilities
A free iCloud account let an attacker send mail that appeared to come from tim.cook@icloud.com or any other @icloud.com address. The forged messages passed Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) — the three authentication checks most mail systems trust to separate real mail from forgery.
Updated 3 hours ago
No stories match your search
Try a different keyword
How would you like to describe your experience with the app today?