Forwarded from Android Security & Malware
New Android BEERUS framework for dynamic analysis & reverse engineering
BEERUS brings Frida auto-injection, sandbox exfiltration, memory dumps, Magisk integration and more for on device app analysis.
https://github.com/hakaioffsec/beerus-android
BEERUS brings Frida auto-injection, sandbox exfiltration, memory dumps, Magisk integration and more for on device app analysis.
https://github.com/hakaioffsec/beerus-android
Forwarded from Android Security & Malware
0-click vulnerability in Dolby's DDPlus decoder affected Android (CVE-2025-54957)
A malformed audio file can trigger an out-of-bounds write due to integer overflow in evolution data handlingโleading to memory corruption and crashes.
Android decodes audio messages locally, making this exploitable without user interaction.
Reproduction: Just send a crafted RCS voice message (dolby_android_crash.mp4)
Details: https://project-zero.issues.chromium.org/issues/428075495
A malformed audio file can trigger an out-of-bounds write due to integer overflow in evolution data handlingโleading to memory corruption and crashes.
Android decodes audio messages locally, making this exploitable without user interaction.
Reproduction: Just send a crafted RCS voice message (dolby_android_crash.mp4)
Details: https://project-zero.issues.chromium.org/issues/428075495
Privacy + Secure Tech Corner Channel ๐ก๏ธ
Next release!!! https://codeberg.org/comaps/comaps/releases/tag/v2025.10.08-3
Codeberg.org
v2025.10.16-1 - comaps/comaps
General:
- Improve fields available in editor following type objects by @map-per
- Added explanation on first map downloads
- Added option to avoid steps
Android:
- Remove add business button on the place page by @map-per
- Remove confirmation dialogโฆ
- Improve fields available in editor following type objects by @map-per
- Added explanation on first map downloads
- Added option to avoid steps
Android:
- Remove add business button on the place page by @map-per
- Remove confirmation dialogโฆ
Forwarded from Free Software[Android]
Element X
A fast, secure, and privacy-focused messenger built on the open Matrix network.
Element X lets you stay connected with friends, family, and communities โ all while keeping control of your data.
Features:
โข Real-time messaging & video calls
โข Public and private group chats
โข Reactions, polls, pinned messages & more
โข Video calling while browsing messages
โข Works with other Matrix apps (FluffyChat, Cinny, etc.)
โข Open source and ad-free
Privacy-first: No tracking, no data mining โ your conversations are yours.
Own your data:
Host on Matrix.org or your own server for full control.
Download: https://element.io/app
Source code: https://github.com/vector-im/element-x-android
#messaging #Matrix
@foss_Android
A fast, secure, and privacy-focused messenger built on the open Matrix network.
Element X lets you stay connected with friends, family, and communities โ all while keeping control of your data.
Features:
โข Real-time messaging & video calls
โข Public and private group chats
โข Reactions, polls, pinned messages & more
โข Video calling while browsing messages
โข Works with other Matrix apps (FluffyChat, Cinny, etc.)
โข Open source and ad-free
Privacy-first: No tracking, no data mining โ your conversations are yours.
Own your data:
Host on Matrix.org or your own server for full control.
Download: https://element.io/app
Source code: https://github.com/vector-im/element-x-android
#messaging #Matrix
@foss_Android
Forwarded from It's FOSS
UbuCon comes to India this November. Book your passes now! ๐ซถ๐ฎ๐ณ
https://news.itsfoss.com/events/first-ubucon-india/
https://news.itsfoss.com/events/first-ubucon-india/
Forwarded from Android Security & Malware
Media is too big
VIEW IN TELEGRAM
New Pixnapping Attack allows any Android app without permissions to leak info displayed by other apps exploiting Android APIs and a hardware side channel (CVE-2025-48561)
Pixnapping is not fixed and probably affects all Androids.
PoC: Not available yet.
Video demonstrates stealing 2FA codes from Google Authenticator. It's like taking screenshot. Pixnapping exploits a side channel that allows the malicious app to map the pixels at those coordinates to letters, numbers, or shapes.
Info: https://www.pixnapping.com/
Pixnapping is not fixed and probably affects all Androids.
PoC: Not available yet.
Video demonstrates stealing 2FA codes from Google Authenticator. It's like taking screenshot. Pixnapping exploits a side channel that allows the malicious app to map the pixels at those coordinates to letters, numbers, or shapes.
Info: https://www.pixnapping.com/
Forwarded from Android Security & Malware
APK Tool GUI: GUI for apktool, signapk, zipalign and baksmali utilities
https://github.com/AndnixSH/APKToolGUI
https://github.com/AndnixSH/APKToolGUI
Forwarded from ๐ฝ๐ผ๐ฝ๐ ๐ข๐๐ฆ | ๐๐ข๐ฆ๐ฆ, ๐๐ถ๐ณ๐ฒ, ๐ ๐ฒ๐บ๐ฒ๐ (รmer)
Chance
Imageboard browser built using Flutter intended for use on iOS and Android.
๐ Links:
- Downtown
- Features
- Source code
Developer: Callum Moffat
๐ท Tags: #Android #iOS #Media #Social
Imageboard browser built using Flutter intended for use on iOS and Android.
๐ Links:
- Downtown
- Features
- Source code
Developer: Callum Moffat
โค๏ธ Support the Project
If this project makes your life easier, here are a few quick ways to show some love:
โญ Star the repo/app
โ Buy a coffee for the developer
๐ Contribute code, issues, or pull-requests
๐ท Tags: #Android #iOS #Media #Social
Forwarded from Android Authority
Now you can spot the apps tapping into Androidโs strongest security feature
by Stephen Schenck
https://www.androidauthority.com/advanced-protection-app-list-3607031/
by Stephen Schenck
https://www.androidauthority.com/advanced-protection-app-list-3607031/
Android Authority
Now you can spot the apps tapping into Android's strongest security feature
You'll now be able to see the apps aware of and able to tap into Android 16's Advanced Protection security mode.
Forwarded from ๐ฝ๐ผ๐ฝ๐ ๐ข๐๐ฆ | ๐๐ข๐ฆ๐ฆ, ๐๐ถ๐ณ๐ฒ, ๐ ๐ฒ๐บ๐ฒ๐ (รmer)
Yupp AI
Yupp.ai allows users to compare responses side by side by providing the same prompt to different AI models such as ChatGPT, Claude, and Gemini, rate their preferences based on criteria such as clarity, accuracy, or creativity, and provide feedback. This feedback is recorded in a blockchain-based secure environment, contributing to the continuous improvement of models through reinforcement learning. Users can earn "Yupp credits" in exchange for the quality feedback they provide, which can be used for new trials or converted into cash. This innovative platform offers both AI enthusiasts and developers a transparent, auditable, and rewarding AI evaluation experience.
๐ Link:
- Website
๐ท Tags: #Website #AI
Yupp.ai allows users to compare responses side by side by providing the same prompt to different AI models such as ChatGPT, Claude, and Gemini, rate their preferences based on criteria such as clarity, accuracy, or creativity, and provide feedback. This feedback is recorded in a blockchain-based secure environment, contributing to the continuous improvement of models through reinforcement learning. Users can earn "Yupp credits" in exchange for the quality feedback they provide, which can be used for new trials or converted into cash. This innovative platform offers both AI enthusiasts and developers a transparent, auditable, and rewarding AI evaluation experience.
๐ Link:
- Website
๐ท Tags: #Website #AI
Forwarded from ATT โข Tech News (Leonardo)
YouTube
MY PIXEL 10 PRO FOLD EXPLODED -- CAUGHT LIVE ON CAMERA!
Google has tried nothing to strengthen the Pixel Fold 10 Pro and they are all out of ideas. The new Folding Pixel Phone has failed my durability test Catastrophically. If google needs better tools to build a better phone they can get one of my tool kits HERE:โฆ
Forwarded from Tech & Leaks Zone
Firefox will render gradients properly now. Better late than never even if it takes 15 years.
https://fixvx.com/theo/status/1978161273214058786
https://fixvx.com/theo/status/1978161273214058786
Forwarded from It's FOSS
What is Telegram doing? Doesn't it know the difference between a bot and a human?
https://news.itsfoss.com/telegram-unfair-community-ban/
https://news.itsfoss.com/telegram-unfair-community-ban/
It's FOSS
Telegram, Please Learn Who's a Threat and Who's Not
Our Telegram community got deleted without an explanation.
Forwarded from Android Security & Malware
GhostBat RAT: Inside the Resurgence of RTO-Themed Android Malware
https://cyble.com/blog/ghostbat-rat-inside-the-resurgence-of-rto-themed-android-malware/
https://cyble.com/blog/ghostbat-rat-inside-the-resurgence-of-rto-themed-android-malware/
Forwarded from The Hacker News
โ ๏ธ Heads-up! SAP just re-patched a critical CVSS 10.0 flaw (CVE-2025-42944) in NetWeaver AS Java โ a deserialization bug that lets attackers execute commands without authentication.
Apply. The. Fix. โ https://thehackernews.com/2025/10/new-sap-netweaver-bug-lets-attackers.html
Apply. The. Fix. โ https://thehackernews.com/2025/10/new-sap-netweaver-bug-lets-attackers.html
Forwarded from The Hacker News
๐ช A cookie that spawns a shell ๐
A critical flaw (CVE-2025-2611, CVSS 9.3) in ICTBroadcast autodialer software is under active exploitation.
Attackers inject commands via the BROADCAST session cookie for unauthenticated remote code execution.
No patch yet โ check your stack โ https://thehackernews.com/2025/10/hackers-target-ictbroadcast-servers-via.html
~200 servers are exposed.
A critical flaw (CVE-2025-2611, CVSS 9.3) in ICTBroadcast autodialer software is under active exploitation.
Attackers inject commands via the BROADCAST session cookie for unauthenticated remote code execution.
No patch yet โ check your stack โ https://thehackernews.com/2025/10/hackers-target-ictbroadcast-servers-via.html
~200 servers are exposed.
Forwarded from The Hacker News
๐ฅ Agentic AI isnโt just automatingโitโs thinking and acting.
Zscalerโs CEO says itโs a bigger shift than cloud or IoT.
The upside? Faster support and instant threat response.
The risk? Rogue AIs scanning your network right now.
Learn why Zero Trust isnโt optional anymore โ https://thehackernews.com/videos/2025/10/exploring-agentic-ai-innovation-meets.html
Zscalerโs CEO says itโs a bigger shift than cloud or IoT.
The upside? Faster support and instant threat response.
The risk? Rogue AIs scanning your network right now.
Learn why Zero Trust isnโt optional anymore โ https://thehackernews.com/videos/2025/10/exploring-agentic-ai-innovation-meets.html