[1/3] It's common to get a ParcelFileDescriptor pointing to a directory through an Android ContentProvider. But can you actually turn that into a directory listing?
⚡ An 18-year-old flaw in NGINX can let unauthenticated attackers run code or crash servers using crafted HTTP requests.
Tracked as CVE-2026-42945 and named NGINX Rift, the bug affects NGINX Plus and Open Source.
Patch details and mitigation steps: https://t.co/Xfz4sQ4Xtz
Hacking with AI is quite boring and I confess that I missed some fun of hacking recently, but building things with AI is incredible fun
I feel that I have never learned so much about Software Engineering/Architecture before, even without writing a single line of code
btw, some of these vulnerabilities stemmed from specific research into React Native apps.
Uncovered some interesting techniques to escalate impact by abusing common mistakes in hybrid app implementations.
Full technical writeup once the disclosure window closes.
Because we train LLMs on lots of movies and books about AI uprising, or articles and tweets about dystopian fears of AI, we might be causing the threat ourselves 🤔
Our second blog post is out here: https://t.co/mUjTMFpVqN ! We managed to install arbitrary APKs on the Samsung Galaxy S25 from an app without install permissions. For this, @SachaKozma did most of the work, but it was great looking into Samsung's cloud gaming component with him
🌍 Earth Day Giveaway - Learn Mobile or AI Security, On Us
One beautiful planet we all share. Let's patch it together. 🌱
To celebrate Earth Day, we're planting 3 free seats 🌱 in any 8kSec Academy course - winner's choice of the whole forest:
• Practical AI Security: Attacks, Defenses, and Applications
• Practical Mobile Application Exploitation
• Offensive Mobile Reversing and Exploitation
• Offensive iOS Internals
• Offensive Android Internals
Explore the catalog → https://t.co/B8Q31o3o8q
How to enter (zero carbon footprint 🍃):
🌿 Follow us
🌿 Like this post
🌎 Repost to spread the seeds
🌟 Bonus: double your chances!
💬 Comment your favorite place on Earth that you have visited or would like to visit 🌍, and we'll count your entry twice
3 winners sprout on April 27. We’ll DM each winner to select their course.
I am talking about mobile... AI can speed up / help with BB (reports, PoCs).... but for finding real vulns, it’s mostly low-hanging fruit so far. So...don’t abandon a target just because Claude says so :)