This is a really interesting report from Hugging Face about their recent intrusion. I also love the transparency here.
The biggest takeaway imo is that teams should have a capable model ready to run locally before an incident.
We now rely so much on AI to accelerate IR that having a capable model ready to run locally should be part of incident response planning.
https://t.co/bR0u2etu2E
📢 Pick a chance to discover @_reversense_ internals⚔️, the logical - open source pro grade - suite of #Dexcalibur. A re-engineering automation platform for mobile & embedded binaries or system. The union of devices, dynamic stuff, @fridadotre , decompilers (@radareorg, ..) with a clean UI.
@enovella_@xMagass@0xabc0@EmericNasi #android #owasp #mobilesecurity
Redownload the Get-ZimmermanTools script, as the URL for download location changed, due to a change in the website generation (moved from MDWiki to Zensical as its much more modern and supported). Sorry for the trouble
@_Ellexa@Kissdusud Euh non, j'ai bien une IP à moi tout seul chez Orange 🙂
Je ne sais même pas s'ils ont vraiment commencé ou non à faire du CG-Nat malgré l'option dans la box pour opt-out.
Nice work by the Mandiant team
We took a quick look at the compiled binaries and THOR already detected 9 of the tools via generic rules. We then added coverage for the rest.
Firefox 150 is out 🦊
You can now edit PDFs directly in the browser: delete, copy, move pages and export to a new file!
No more switching tools! For free and Open Source!
https://t.co/W9Yu83qqli
UNC2465 primarily relies on malvertising to distribute the #SmokedHam backdoor. By pivoting on its delivery infrastructure, we identified a large number of spoofed software like #RVTools, @Hornetsecurity, Angry IP Scanner, Remote Desktop Manager...
🚨 DarkSword — un nouveau kit d’espionnage vient d’être découvert sur iPhone.
Publié aujourd’hui par Google, Lookout et iVerify.
Ce qu’il fait :
→ Il se déclenche en visitant un site web normal — sans cliquer sur quoi que ce soit
→ Il sort du sandbox Safari via WebGPU
→ Il accède au kernel — le cœur d’iOS
→ Il vole tes messages, photos, mots de passe, localisation, crypto
Qui est derrière :
→ Des acteurs (UNC6353) déjà liés au kit Coruna contre l’Ukraine
→ Revendu ensuite à des groupes en Arabie Saoudite, Turquie, Malaisie
→ Du code généré par IA retrouvé dans le kit — n’importe qui peut désormais l’adapter
L’ampleur :
270 000 000 d’iPhones potentiellement exposés.
C’est le 2e kit de ce type découvert en 2 semaines.
Les exploits iOS ne sont plus réservés aux États. Il y a désormais un marché secondaire ouvert. N’importe quel groupe motivé peut acheter et déployer ça.
La bonne nouvelle : Apple a corrigé toutes les failles dans iOS 26.3.
👉 Si tu n’es pas à jour, tu es exposé. Maintenant.
Réglages → Général → Mise à jour logicielle
Sources : Google Threat Intelligence · Lookout · iVerify (18/03/2026)
After much reflection, I have decided to resign from my position as Director of the National Counterterrorism Center, effective today.
I cannot in good conscience support the ongoing war in Iran. Iran posed no imminent threat to our nation, and it is clear that we started this war due to pressure from Israel and its powerful American lobby.
It has been an honor serving under @POTUS and @DNIGabbard and leading the professionals at NCTC.
May God bless America.
@france_identite j'ai par miracle réussi à générer un code QR pour la vérification de mon identité par contre je retombe sur le même soucis qu'avant pour la mise à jour au format européen, allant même jusqu'à un force close de l'app beta.
J'ai jamais eu de retour de l'adresse 1/3
support de France identité !
A se poser des questions sur le sérieux du projet 🫠
Erreur Application France Identité.
Données techniques :
==== NE PAS MODIFIER CI DESSOUS ====
Message : Inconnu
Date : 11/01/2026 à 02:17
Device Name : iPhone 15 Pro Max