‼️ Apple's Private Find My People Reversed to Decrypt Live Shared Locations on Linux
Source: https://t.co/Qq5TS0AZm9
A security researcher has successfully reverse-engineered Apple's private Find My People protocol, demonstrating that a Linux machine can register with Apple's internal services, receive an existing location-sharing key, and decrypt a friend's live location without ever touching a Mac or iPhone.
The project began innocently: the researcher wanted to build Discord geofence alerts using location data a friend was already sharing via Apple's Find My app.
What looked like a simple authenticated API call turned into roughly a week of reverse-engineering Apple's private device-identity and messaging infrastructure, since no prior open-source project had fully replicated the flow.
#cybersecuritynews
‼️ Rust supply chain attack hits three crates, including 245 million-download arrayref.
A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation.
Check your Cargo cache and pinned versions now: https://t.co/FRcCsFBJBS
⚠️ @leak_ix scans the internet for misconfigured services, exposed databases and publicly accessible data leaks, and indexes findings so you can search by domain, IP address or organisation name.
Try it out: https://t.co/XwtBW4K2qr
Install Linux without a USB key, straight from Windows?
> Still YES. 🐧!
Libertix just reached *v0.3* !!
Much more stable, and finally truly usable :
The Vanguard framework is on its way. I am testing some of the new features with pivoting capabilities.
Vanguard supports HTTPS, DNS/DoH, QUIC, (SMB & TCP) for pivoting, along with four different stack spoofing options.
More feature updates and announcements soon. Questions & Feature suggestions: kindly dm: @5mukx
‼️ One click could exfiltrate data from Copilot-connected apps.
New attack chain "CoSnitch" lets a crafted Copilot Personal link auto-run an attacker prompt in a signed-in session and pull data from services the user already authorized.
See how the chain works: https://t.co/4V4Hj3ngBn