X's new voice calling feature leaks your IP address by default. Threat actors can obtain any user's IP address just by initiating a call. X enabled the feature for all accounts last week.
To fix: Settings ➡️ Privacy & Security ➡️ Direct Messages ➡️ Enhanced Call Privacy
Does this table structure look familiar? Can't identify the source, someone just left the file with 6146 cards online. "Card on Dark Web" field indicates that this is not originated from dark web :)
I have summarized some vulnerability write-ups in Spring Boot environment, and some new tricks will be updated unceasingly here. https://t.co/P3vSaazkHC
Happy Leap Day. I'm going to raffle off 10 HackTheBox VIP Passes (1 month each), reply to this post with a link to your favorite IppSec video and why. Contest ends sometime tomorrow. Be sure to follow me, if I cannot DM You then I will just pick a different person.
I'm very excited to share my blogpost series (including PoC code) about a remote, interactionless iPhone exploit over iMessage: https://t.co/9FNpYQIyWE
#APT#Darkhotel#0day#WizardOpium
Chrome RCE to windows Privilege Escalation
First
Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium
https://t.co/WmUj2BkieG
Then
Windows 0-day exploit CVE-2019-1458 used in Operation WizardOpium(Windows 7)
https://t.co/Gqkmmn9Ujc