I am currently seeking an exceptional Security Incident Response Engineer to join our esteemed global security incident response team. This rare opportunity doesn't come around often. Join us in this exciting role! #infosec#hiring#cyberroles
https://t.co/wayhdiAeny
🔺New on Apple Security Research blog: a deeply comprehensive Private Cloud Compute security guide, and an unprecedented Virtual Research Environment allowing you to run production PCC software right on your Mac with Apple silicon. And up to a $1M bounty!
https://t.co/a8yyEza8rd
🔺New on the Apple Security Research blog: introducing Private Cloud Compute! We believe this is the most advanced security architecture ever deployed for cloud AI compute at scale. https://t.co/bsrpkCdivX
🔺New on the Apple Security Research blog: introducing PQ3, a groundbreaking post-quantum cryptographic protocol for iMessage. To our knowledge, PQ3 has the strongest security properties of any at-scale messaging protocol in the world. https://t.co/NIyeXjVne6
🔺New on the Apple Security Research blog: we pit our hardened kalloc_type XNU allocator against SockPuppet, a powerful vulnerability from the past: https://t.co/UyTkz1slu3
I hoped to attend #BlackHatEurope@BlackHatEvents with two tools, but because my visa is not ready, I will miss it. It's very upsetting, but sometimes it happens. Let me write a few words about the tools and share the links in this thread.
https://t.co/wb2SN5QVzI
#BlackHat
More car hacking!
Earlier this year, we were able to remotely unlock, start, locate, flash, and honk any remotely connected Honda, Nissan, Infiniti, and Acura vehicles, completely unauthorized, knowing only the VIN number of the car.
Here's how we found it, and how it works:
I’m really excited for us to shed light on some really cool work we’ve been doing to harden the XNU allocator! This has been a huge effort by so many people, and I’m very proud of the direction: https://t.co/aW4LXuKbWV
Today I am finally releasing a new 3-part browser exploitation series on Chrome! This was written to help beginners break into the browser exploitation field.
Part 1 covers V8 internals such as objects, properties, and memory optimizations. Enjoy! https://t.co/bbFjOOzlOu
Bypassing ContentProvider.openFile() internal security checks in Android
[1/3]
I've discovered an interesting trick that you may use to access private information using a content provider
This is a thread on the legality of reverse engineering (RE) software, inspired by @FrenchYeti's recent decision of not streaming a talk due to legal pressures.
1/
All I can think of are the Ukrainian and Russian CTF players I have met, whose writeups I have read, whose talks I have watched, who collaborated with me on videos. I always felt that hacking unites the world. It makes me cry, I'm scared and cope by distracting myself.
😢
Frida is really powerful and popular instrumentation frameworks, however there’s not many useful information sources on advanced usage gathered in single place, but here we have this gem, well done guys!
Releasing today: https://t.co/K1kK3Srhz4
It's a small, free web handbook to learn about binary instrumentation using @fridadotre
If you found this resource interesting, please share for others to learn!