📢 📢 📢 Calling all vulnerability researchers interested in microcode!
Check out our blog post covering EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
https://t.co/gn4xvXwEsJ
I've written a post on SELinux and some public bypasses for Android kernel exploitation. It's especially relevant for Samsung and Huawei devices due to their use of hypervisors. Check it out here: https://t.co/UHesQZgjuv
.@Convergence_fi hacked for $200k! The vulnerable contract was deployed 17 days ago and was intended to distribute CVX rewards.
https://t.co/darqe1SgYc
#CertiKInsight 🚨
On 21 July 2024, @UPS_Official_ token UPS was exploited for ~$521K via a flash loan exploit.
Read our analysis of the incident here 👇
https://t.co/tXgqYOWdlG
🚨ALERT🚨@Minterest has encountered a security breach on the #Mantle chain at https://t.co/4jsZyROxw3
Total Loss: Approximately $1.4M. The attacker was funded by @TornadoCash on the #ETH chain.
All stolen funds on the #Mantle chain have been bridged to #ETH.
Attacker's address: https://t.co/bHeGRI9rlc
Update from team:👇
Paused: Supply & Borrow
Active: Repay & Withdraw
The team is actively investigating the incident!
Want to keep your company off our alerts radar? Learn how to secure your assets: Book a Demo 🚀 https://t.co/qYomYZUVB1
#CyversAlert
In this post I'll use CVE-2023-6241, a vulnerability in the Arm Mali GPU that I reported last November to gain arbitrary kernel code execution from an untrusted app on a Pixel 8 with MTE enabled. https://t.co/Flsas2jJtv
#Fuzz Every(5G)thing Everywhere All at Once : unleashed #5Ghoul (https://t.co/WYJzjIMHmH) - a family of 10+ 5G implementation vulnerabilities in @Qualcomm
and @MediaTek cellular baseband modems. Exploits as well as fuzzer is open source.
#5G#Fuzzing#Wireless#CyberSecurity
(CVE-2023-40088)
0-click RCE(Bluetooth, UAF in ~CallbackEnv)
com_android_bluetooth_btservice_AdapterService does not null its local JNI environment variable after detaching the thread, allowing UAF under certain conditions.
https://t.co/9PaM5GiciC