0-click RCE via MMS exploit for Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0) #Fuzzing CVE-2020-8899
https://t.co/Qeyq7ACjoN
Demo: https://t.co/VL7eL03SrD
About #Android#Joker#Malware from Google Play.
First Reading, September 2019 :
https://t.co/AwXoVI2cRK
The "Bread" Family, January 2020:
https://t.co/QL6gyad4y6
A closer look, February 2020, Joker abused the popularity of the Thunder VPN application:
https://t.co/ye9n3g8z7l
L'Italia dell'Innovazione digitale in due tweet.
Un'App piena di bug che non servirà a nulla, spreco di denaro pubblico per lo sviluppo e per la task force (erano in 74).
Non si sa se sia più servile il primo o l'ultimo tw "abbiamo molto da imparare".
#ImmuniApp#Immuni
IoT Village hosts talks, occurring over 3 days from May 28-30 (EST Time), by expert security researchers who dissect real-world exploits and vulnerabilities and hacking contests consisting of off-the-shelf IoT devices.
https://t.co/0ajcDmh6nv #IoT#DefCon#hacking#CyberSecurity
Sandworm Team, Russian GRU Main Center for Special Technologies actors, continue to exploit Exim mail transfer agent #vulnerability, CVE-2019-10149.
Patch to the latest version to protect your networks. Learn more here: https://t.co/6HU3mSPam9
Russian GRU actors, Sandworm Team, are exploiting a #vulnerability present in unpatched Exim mail transfer agent software.
Protect your networks by checking out the latest from @NSACyber
SSRF + CRLF + HTTP Pipeline + Docker API = RCE…
How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber
https://t.co/rc1N9qOXnL
I learned a lot tonight. This is what dev tools tells me in Edge by just visiting eBay.
The website is port scanning my laptop, bypassing my firewall, and doing it in/from the browser.
It checked 14 ports.
Let's discuss. 1/5
Kaiten: an Undetectable Payload Generator. "This tool is for educational purpose only", yeah of course! 😉
Features
- Undetectable Payload Generation
- Stealth FUD Payload
- Self Signing Certificate
- Random Junk code
Fresh update on GitHub:
https://t.co/OIPgKnXaOj
"We want you to do a full penetration against our company, attacking only these 5 critical IPs. Phishing is not in scope, and you can't target any other addresses" they said.
I asked: "What about these 200 IP addresses connected to the network that are externally accessible?"