Free iCloud Account Could Let Attackers Spoof Any @icloud.com Address and Pass Email Security Checks

Security researcher Timo Longin, working with the SEC Consult Vulnerability Lab, disclosed two email spoofing flaws in Apple’s iCloud mail infrastructure that could have let someone with a free iCloud account send messages that appeared to come from any @icloud.com address. The crafted messages could pass SPF, DKIM, and DMARC checks, the core controls used […]

This article has been indexed from Cyber Security News

Read the original article: