Forwarded from Tech & Leaks Zone
Xiaomi, Vivo and Oppo under investigation for alleged $700 Million fund diversion
The Ministry of Corporate Affairs (MCA) in India has tasked the Serious Fraud Investigation Office (SFIO) with investigating Chinese smartphone makers Vivo, Oppo, and Xiaomi after a Registrar of Companies (RoC) report alleged fund diversion to the tune of Rs 6,000 crore (~ $700 Million), two government sources have told Moneycontrol.
"SFIO is probing Vivo. Xiaomi and Oppo have also given to SFIO. Fund diversions have been alleged in the RoC report. Once the SFIO report is finalised, they will submit it to the MCA"
“The SFIO process will take about a year and began earlier this year in March"
Once finalised, the SFIO’s findings will be submitted to the ministry, which has the authority to initiate legal proceedings against the companies, their directors and related entities in a special court.
Follow @TechLeaksZone
The Ministry of Corporate Affairs (MCA) in India has tasked the Serious Fraud Investigation Office (SFIO) with investigating Chinese smartphone makers Vivo, Oppo, and Xiaomi after a Registrar of Companies (RoC) report alleged fund diversion to the tune of Rs 6,000 crore (~ $700 Million), two government sources have told Moneycontrol.
"SFIO is probing Vivo. Xiaomi and Oppo have also given to SFIO. Fund diversions have been alleged in the RoC report. Once the SFIO report is finalised, they will submit it to the MCA"
“The SFIO process will take about a year and began earlier this year in March"
Once finalised, the SFIO’s findings will be submitted to the ministry, which has the authority to initiate legal proceedings against the companies, their directors and related entities in a special court.
Follow @TechLeaksZone
Forwarded from Tech & Leaks Zone
Xiaomi No Longer Cares About India, Shifts Focus to Europe
Xiaomi HQ (China) has decided that India market is not their focus anymore & they will instead focus on European & other South Asian markets.
In 2018, India was Xiaomi’s 2nd largest market, contributing 45% of its total global sales. But now, India no longer ranks among Xiaomi’s top 5 markets across the 100+ countries it operates in, with its contribution to total sales falling to a single-digit percentage in 2025.
"India-specific product development has ceased (Xiaomi 15 Civi is cancelled for India), with a focus only on global products. Xiaomi India's plans to launch its expensive foldable phones, are delayed by the group. Xiaomi global stopped plans to launch new categories like washing machines and ACs in India. Testing for these products, including refrigerators, had already been completed, and the company was in talks for their introduction,” the executive said.
Follow @TechLeaksZone
Xiaomi HQ (China) has decided that India market is not their focus anymore & they will instead focus on European & other South Asian markets.
In 2018, India was Xiaomi’s 2nd largest market, contributing 45% of its total global sales. But now, India no longer ranks among Xiaomi’s top 5 markets across the 100+ countries it operates in, with its contribution to total sales falling to a single-digit percentage in 2025.
"India-specific product development has ceased (Xiaomi 15 Civi is cancelled for India), with a focus only on global products. Xiaomi India's plans to launch its expensive foldable phones, are delayed by the group. Xiaomi global stopped plans to launch new categories like washing machines and ACs in India. Testing for these products, including refrigerators, had already been completed, and the company was in talks for their introduction,” the executive said.
Follow @TechLeaksZone
Forwarded from Tech & Leaks Zone
Nothing Phone 2a Bootloader Exploit Working
A new exploit called Fenrir targets the Nothing Phone 2a, CMF Phone 1 & other MediaTek-powered devices. It takes advantage of a flaw in how the phone starts up, allowing full control over the device before Android even loads. Even after waiting for 1 month, Nothing ignored the developer's bootloader vulnerability report affecting CMF Phone 1 and Phone 2a and thus developer made it exploit public.
When you power on your phone, it goes through several steps to make sure everything is secure and untampered. This is called the secure boot chain. Each of these steps is trusted only if the previous one verifies it.
1. BootROM – The first code built into the chip. It loads the next part.
2. Preloader – Loads the next component, called bl2_ext, and normally checks it.
3. bl2_ext – This runs at the highest privilege level (EL3) and is supposed to check everything else.
4. TEE (Trusted Execution Environment) – Handles secure operations like fingerprint data and encryption.
5. GenieZone – A MediaTek component that manages access to the secure system.
6. LK / AEE – Boots the Android operating system and handles crash logging.
7. Linux Kernel – This is Android. The phone is now fully booted.
This exploit abuses a flaw in the MediaTek boot chain. When the bootloader is unlocked (
Additionally, the included PoC also spoofs the device’s lock state as locked so you can pass strong integrity checks anywhere while being unlocked. Someone even managed to pass Basic, Device and Strong integrity on LineageOS for Phone 2a without rooting, spoofing, using pixel fingerprint or leaked keybox.
Vivo X80 Pro is also vulnerable & it has a more severe version of the flaw, as it fails to verify bl2_ext even with a locked bootloader. You can read more about the usage of exploit here:
https://github.com/R0rt1z2/fenrir
Follow @TechLeaksZone
A new exploit called Fenrir targets the Nothing Phone 2a, CMF Phone 1 & other MediaTek-powered devices. It takes advantage of a flaw in how the phone starts up, allowing full control over the device before Android even loads. Even after waiting for 1 month, Nothing ignored the developer's bootloader vulnerability report affecting CMF Phone 1 and Phone 2a and thus developer made it exploit public.
When you power on your phone, it goes through several steps to make sure everything is secure and untampered. This is called the secure boot chain. Each of these steps is trusted only if the previous one verifies it.
1. BootROM – The first code built into the chip. It loads the next part.
2. Preloader – Loads the next component, called bl2_ext, and normally checks it.
3. bl2_ext – This runs at the highest privilege level (EL3) and is supposed to check everything else.
4. TEE (Trusted Execution Environment) – Handles secure operations like fingerprint data and encryption.
5. GenieZone – A MediaTek component that manages access to the secure system.
6. LK / AEE – Boots the Android operating system and handles crash logging.
7. Linux Kernel – This is Android. The phone is now fully booted.
This exploit abuses a flaw in the MediaTek boot chain. When the bootloader is unlocked (
seccfg), the Preloader skips verification of the bl2_ext partition, even though bl2_ext is responsible for verifying everything that comes after it. So if bl2_ext it's not verified and can be modified, it compromises the entire secure boot process. The exploit modifies a function called sec_get_vfy_policy() inside bl2_ext, making it always return "0", so an unverified bl2_ext running at EL3 now happily loads unverified images for the rest of the boot chain.Additionally, the included PoC also spoofs the device’s lock state as locked so you can pass strong integrity checks anywhere while being unlocked. Someone even managed to pass Basic, Device and Strong integrity on LineageOS for Phone 2a without rooting, spoofing, using pixel fingerprint or leaked keybox.
Vivo X80 Pro is also vulnerable & it has a more severe version of the flaw, as it fails to verify bl2_ext even with a locked bootloader. You can read more about the usage of exploit here:
https://github.com/R0rt1z2/fenrir
Follow @TechLeaksZone
Forwarded from vx-underground
tl;dr chinas firewall censorship thingy has massive leak. shows code and political ambitions and stuff
idk the significance because i dont study chinese network firewall sciency stuff. maybe one of you nerds is interested. its all available for download online now
https://gfw.report/blog/geedge_and_mesa_leak/en/
idk the significance because i dont study chinese network firewall sciency stuff. maybe one of you nerds is interested. its all available for download online now
https://gfw.report/blog/geedge_and_mesa_leak/en/
Forwarded from GApps Leaks (Shiv (AssembleDebug))
Sideloading Restrictions, some updates from Google.
If you are a hobbyist/student - Free and Straightforward process but comes with limits on number of apps and installation.
As a developer, you will be able install apps with ADB without restrictions for testing purposes
@GappsLeaks
If you are a hobbyist/student - Free and Straightforward process but comes with limits on number of apps and installation.
As a developer, you will be able install apps with ADB without restrictions for testing purposes
@GappsLeaks
Forwarded from Nothing Fuckups
Nothing Phone 3 will be available for Rs. 35,000 (~400$) in India after exchange of Phone 1 or Phone 2
Including exchange, Nothing phone 3 lost more than 50% value in just 2½ months after the launch. My condolences to everyone who bought it at launch as you guys have been scammed in under 3 months
Follow @NothingFuckups
Including exchange, Nothing phone 3 lost more than 50% value in just 2½ months after the launch. My condolences to everyone who bought it at launch as you guys have been scammed in under 3 months
Follow @NothingFuckups
Forwarded from GApps Leaks (Shiv (AssembleDebug))
Pixel 7 and 7 Pro users report battery swelling as issue spreads beyond 7a
✅ Details - https://piunikaweb.com/2025/09/15/pixel-7-and-7-pro-battery-swelling/
@GappsLeaks
✅ Details - https://piunikaweb.com/2025/09/15/pixel-7-and-7-pro-battery-swelling/
@GappsLeaks
Forwarded from 𝗽𝗼𝗽𝗠𝗢𝗗𝗦 | 𝗙𝗢𝗦𝗦, 𝗟𝗶𝗳𝗲, 𝗠𝗲𝗺𝗲𝘀 (Ömer)
Network Switch
A modern Android application that enables users to toggle between 4G and 5G network modes with dual control methods: Root access for rooted devices and Shizuku for non-rooted devices. Built using Jetpack Compose and Material Design 3.
🔗 Links:
- Download
- Screenshot
- Features
- Source code
Developer: Ameya Vijay Unchagaonkar
🏷 Tags: #Android #Utilities #Network
A modern Android application that enables users to toggle between 4G and 5G network modes with dual control methods: Root access for rooted devices and Shizuku for non-rooted devices. Built using Jetpack Compose and Material Design 3.
🔗 Links:
- Download
- Screenshot
- Features
- Source code
Developer: Ameya Vijay Unchagaonkar
❤️ Support the Project
If this project makes your life easier, here are a few quick ways to show some love:
⭐ Star the repo/app
☕ Buy a coffee for the developer
🛠 Contribute code, issues, or pull-requests
🏷 Tags: #Android #Utilities #Network
Forwarded from The Hacker News
⚠️ Major npm supply-chain attack just dropped!
40+ popular packages were secretly booby-trapped to steal developer secrets—GitHub tokens, npm keys, even AWS creds—on both Windows & Linux.
🕵️♂️ Audit & rotate your credentials now.
Full story → https://thehackernews.com/2025/09/40-npm-packages-compromised-in-supply.html
40+ popular packages were secretly booby-trapped to steal developer secrets—GitHub tokens, npm keys, even AWS creds—on both Windows & Linux.
🕵️♂️ Audit & rotate your credentials now.
Full story → https://thehackernews.com/2025/09/40-npm-packages-compromised-in-supply.html
Forwarded from vx-underground
Update: it's real lmfao y'all are COOKED bro
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
www.aikido.dev
npm debug and chalk packages compromised
The popular packages debug and chalk on npm have been compromised with malicious code
Forwarded from The Hacker News
Apple backports a critical fix for CVE-2025-43300—already used in a sophisticated spyware attack.
🕵️♂️ Hackers chained it with a WhatsApp flaw to target fewer than 200 people.
📱 Older iPhones & Macs are now patched—don’t skip this update.
Details → https://thehackernews.com/2025/09/apple-backports-fix-for-cve-2025-43300.html
🕵️♂️ Hackers chained it with a WhatsApp flaw to target fewer than 200 people.
📱 Older iPhones & Macs are now patched—don’t skip this update.
Details → https://thehackernews.com/2025/09/apple-backports-fix-for-cve-2025-43300.html
Forwarded from The Hacker News
This media is not supported in your browser
VIEW IN TELEGRAM
🚨Lazarus escalated activities in 2025 with companies already suffering billions in losses.
This APT’s attacks are evolving and getting harder to detect.
Read actionable report on its current campaigns to be ready for the next attack ⬇️ https://thn.news/lazarus-attacks-2025
This APT’s attacks are evolving and getting harder to detect.
Read actionable report on its current campaigns to be ready for the next attack ⬇️ https://thn.news/lazarus-attacks-2025
Forwarded from Android Security & Malware
Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic Execution for Code Decryption and Deobfuscation
https://revflash.medium.com/strategies-for-analyzing-native-code-in-android-applications-combining-ghidra-and-symbolic-aaef4c9555df
https://revflash.medium.com/strategies-for-analyzing-native-code-in-android-applications-combining-ghidra-and-symbolic-aaef4c9555df
Medium
Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic…
In my work analyzing native code in Android applications, I often try different techniques. Some work, others not so much. I’ve realized I…
Forwarded from NoGoolag
Google Ordered to Pay $425 Million for Tracking Users Who Disabled Web & App Activity Setting
https://ift.tt/zAT5uvO - FOLLOW: @reclaimthenet
https://ift.tt/zAT5uvO - FOLLOW: @reclaimthenet
Reclaim The Net
Google Ordered to Pay $425 Million for Tracking Users Who Disabled Web & App Activity Setting
Privacy settings were more like polite suggestions than actual boundaries.
Forwarded from NoGoolag
Macron’s Global Censorship Push Exposed: Leaked Files Reveal France’s Covert Speech Control Campaign
https://ift.tt/c3G4RgD - FOLLOW: @reclaimthenet
https://ift.tt/c3G4RgD - FOLLOW: @reclaimthenet
Reclaim The Net
Macron's Global Censorship Push Exposed: Leaked Files Reveal France's Covert Speech Control Campaign
France used lawsuits, NGOs, and private outreach to pressure Twitter into global censorship beyond French law.
Forwarded from NoGoolag
#Nepal Blocks Facebook, YouTube, WhatsApp, and Other Major CIA and mossad spywares
https://ift.tt/2zIpUKY - FOLLOW: @reclaimthenet
https://ift.tt/2zIpUKY - FOLLOW: @reclaimthenet
Reclaim The Net
Nepal Blocks Facebook, YouTube, WhatsApp, and Other Major Platforms
A country of 30 million just pulled the plug on the internet’s biggest names in under a week.