Context over chaos. Disconnected technologies, siloed data, and reactive processes can only get you so far. Protecting businesses in today’s threat landscape demands more than a set of security tools – it requires context.
That's where Avertium comes in
Security. It’s in our DNA. It’s elemental, foundational. Something that an always-on, everything’s-IoT-connected world depends on.
Helping mid-to-enterprise organizations protect assets and manage risk is our only business. Our mission is to make our customers’ world a safer place so that they may thrive in an always-on, connected world.
Best-in-class technology from our partners... backed by service excellence from Avertium.
Interested in becoming a partner?
With Avertium's deal registration, partners can efficiently and confidently connect with Avertium on opportunities to protect your deals.
Microsoft Copilot for Security analyzes and synthesizes high volumes of security data which can help healthcare cybersecurity teams do more with less.
Dive into our resource hub and explore top
cybersecurity topics along with what we do
and what we can do for you.
overview
An actively exploited iOS zero-day vulnerability was found in older versions of Apple’s iPhones and iPads. CVE-2022-42856 is a WebKit vulnerability located in devices running iOS prior to version 15.1. The vulnerability allows attackers to execute arbitrary code through specially crafted web content, ultimately gaining access to sensitive information.
Additionally, if an attacker is successful, they could run commands on the underlying operating system, distribute more malware or spyware, or trigger other malicious activity. The vulnerability was initially observed by Google’s Threat Analysis Group (TAG) and in December 2022, Apple issued the first batch of patches for it by releasing iOS 16.2. At the time, the fix also included macOS Ventura 13.1, tvOS, Safari 16.2, and iOS and iPadOS 15.7.2. The most recent release of iOS 12.5.7 addresses CVE-2022-42856.
Apple has received reports of active exploitation, but the company has not published information regarding the attacks. Apple is likely concealing the information to allow as many users as possible the time to patch their devices before attackers exploit the zero-day. If you are in possession of the following devices: iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation), please apply the appropriate update as soon as possible.
Avertium recommends that users apply the appropriate patch for versions of iOS released before iOS 15.1. You may find patch guidance via Apple’s support page.
At this time, there are no known IoCs associated with CVE-2022-42856. Avertium’s threat hunters remain vigilant in locating IoCs for our customers. Should any be located, Avertium will disclose them as soon as possible. For more information on how Avertium can help protect your organization, please reach out to your Avertium Service Delivery Manager or Account Executive.
About the security content of iOS 12.5.7 - Apple Support
Apple Patches Exploited iOS Vulnerability in Old iPhones – SecurityWeek
Apple fixes actively exploited iOS zero-day on older iPhones, iPads (bleepingcomputer.com)