Researchers have figured out how to manipulate the iPhone user interface to feign airplane mode, while secretly maintaining Internet connectivity.
In a report published this week, Jamf Threat Labs highlighted the code controlling various elements of iOS 16's airplane mode experience, and how they can be manipulated in order to merely simulate the real thing. Mobile device attackers could use this sort of trick post-exploitation, they say, to enable 24/7 persistence in a target device with the user none the wiser.
Report by @DarkReading
It seems there are many vulnerabilities that @Microsoft is aware of but hasn't done much about yet(or at least hasn't released updates on the same)
Full article by @DarkReading
https://t.co/X58lSdqbsP
Discord shut down after breach and said it will revamp its website code and conduct "a complete overhaul" of its security practices. https://t.co/k6p9ayvBdo
Rugpulls starting on Base as well.
SwirlLend rugged on #Linea as well as #base
Users must take care about which projects they are interacting with and ALWAYS use burner wallets to test new things in Web3!
#PeckShieldAlert#Rugpull SwirlLend on #Base has been rugged. The TVL of SwirlLend has dropped from $784.3K to $49.2K.
@SwirlLend has already deleted its social platform.
The deployer has already bridged ~$289.5K worth of cryptos from #Base to #Ethereum, including 140.68 $ETH and 32.6K $USDC. They still hold ~92 $ETH on #Base
Stablecoin staking platform @ZunamiProtocol lost over $2.1 million to a price manipulation attack.
Hackers inflated the price of the stablecoin UZD and then siphoned off the funds through Tornado Cash.
Due to the hack, the price of UZD has dropped almost to zero.
RocketSwap exploited for approx ~$900k because of compromised private keys.
Protocols and projects in the Web3 space must follow strict & safe guidelines when storing their private keys.
Alert shared by @BeosinAlert
"Several vulnerabilities discovered in the ScrutisWeb ATM fleet monitoring software made by French company Iagona could be exploited to remotely hack ATMs."
Next level article by @SecurityWeek
https://t.co/AdUgqYcRE6
We‘be seen an increased the amount of scam job ads throughout the industry in the past two weeks.
Remember to never do the following as a part of an interview process:
Never install any custom software, games, don’t connect your wallet, don’t pay as part of application process.
A group/individual has been putting up scam job ads on various websites and asking people to download "beta testing" game which happens to be a malware that drains crypto wallets and compromises the machine.
Make sure to NEVER download anything as a part of a job application!
Please keep an eye on this thread by @zachxbt and make sure to always avoid job offers that look too good to be true or offer free money etc.
https://t.co/vgpLEJbfsj
Looks like MoonCarl’s job posting website has a scam called “Eco Land” attempting to get applicants to download malware.
Even is listed there as a premium job.
🔑🔒 Google Chrome 116 add support for quantum-resistant #encryption algorithms to encrypt TLS connections.
Learn more about X25519Kyber768: https://t.co/ZmKOS3xFcP
#cybersecurity#technology