Privacy + Secure Tech Corner Channel ๐Ÿ›ก๏ธ
90 subscribers
6.65K photos
577 videos
486 files
16.1K links
Here you can find all about GSI's, ROM's, GKI Kernel's, Tech NEWS, Updates, Root methods, Magisk Module, Overlay's, Hacker things, FLOSS, FOSS, Privacy + Secure Stuff and many more!
Download Telegram
New Android BEERUS framework for dynamic analysis & reverse engineering
BEERUS brings Frida auto-injection, sandbox exfiltration, memory dumps, Magisk integration and more for on device app analysis.
https://github.com/hakaioffsec/beerus-android
0-click vulnerability in Dolby's DDPlus decoder affected Android (CVE-2025-54957)
A malformed audio file can trigger an out-of-bounds write due to integer overflow in evolution data handlingโ€”leading to memory corruption and crashes.
Android decodes audio messages locally, making this exploitable without user interaction.
Reproduction: Just send a crafted RCS voice message (dolby_android_crash.mp4)
Details: https://project-zero.issues.chromium.org/issues/428075495
Forwarded from Free Software[Android]
Element X
A fast, secure, and privacy-focused messenger built on the open Matrix network.

Element X lets you stay connected with friends, family, and communities โ€” all while keeping control of your data.

Features:
โ€ข Real-time messaging & video calls
โ€ข Public and private group chats
โ€ข Reactions, polls, pinned messages & more
โ€ข Video calling while browsing messages
โ€ข Works with other Matrix apps (FluffyChat, Cinny, etc.)
โ€ข Open source and ad-free

Privacy-first: No tracking, no data mining โ€” your conversations are yours.

Own your data:
Host on Matrix.org or your own server for full control.

Download: https://element.io/app

Source code: https://github.com/vector-im/element-x-android

#messaging #Matrix

@foss_Android
Forwarded from It's FOSS
UbuCon comes to India this November. Book your passes now! ๐Ÿซถ๐Ÿ‡ฎ๐Ÿ‡ณ

https://news.itsfoss.com/events/first-ubucon-india/
Media is too big
VIEW IN TELEGRAM
New Pixnapping Attack allows any Android app without permissions to leak info displayed by other apps exploiting Android APIs and a hardware side channel (CVE-2025-48561)
Pixnapping is not fixed and probably affects all Androids.
PoC: Not available yet.
Video demonstrates stealing 2FA codes from Google Authenticator. It's like taking screenshot. Pixnapping exploits a side channel that allows the malicious app to map the pixels at those coordinates to letters, numbers, or shapes.
Info: https://www.pixnapping.com/
APK Tool GUI: GUI for apktool, signapk, zipalign and baksmali utilities
https://github.com/AndnixSH/APKToolGUI
Chance

Imageboard browser built using Flutter intended for use on iOS and Android.

๐Ÿ”— Links:
- Downtown
- Features
- Source code
Developer: Callum Moffat

โค๏ธ Support the Project

If this project makes your life easier, here are a few quick ways to show some love:

โญ Star the repo/app
โ˜• Buy a coffee for the developer
๐Ÿ›  Contribute code, issues, or pull-requests


๐Ÿท Tags: #Android #iOS #Media #Social
Yupp AI

Yupp.ai allows users to compare responses side by side by providing the same prompt to different AI models such as ChatGPT, Claude, and Gemini, rate their preferences based on criteria such as clarity, accuracy, or creativity, and provide feedback. This feedback is recorded in a blockchain-based secure environment, contributing to the continuous improvement of models through reinforcement learning. Users can earn "Yupp credits" in exchange for the quality feedback they provide, which can be used for new trials or converted into cash. This innovative platform offers both AI enthusiasts and developers a transparent, auditable, and rewarding AI evaluation experience.

๐Ÿ”— Link:
- Website

๐Ÿท Tags: #Website #AI
Forwarded from Tech & Leaks Zone
Firefox will render gradients properly now. Better late than never even if it takes 15 years.

https://fixvx.com/theo/status/1978161273214058786
Forwarded from The Hacker News
โš ๏ธ Heads-up! SAP just re-patched a critical CVSS 10.0 flaw (CVE-2025-42944) in NetWeaver AS Java โ€” a deserialization bug that lets attackers execute commands without authentication.

Apply. The. Fix. โ†’ https://thehackernews.com/2025/10/new-sap-netweaver-bug-lets-attackers.html
Forwarded from The Hacker News
๐Ÿช A cookie that spawns a shell ๐Ÿ’€

A critical flaw (CVE-2025-2611, CVSS 9.3) in ICTBroadcast autodialer software is under active exploitation.

Attackers inject commands via the BROADCAST session cookie for unauthenticated remote code execution.

No patch yet โ€” check your stack โ†’ https://thehackernews.com/2025/10/hackers-target-ictbroadcast-servers-via.html

~200 servers are exposed.
Forwarded from The Hacker News
๐Ÿ”ฅ Agentic AI isnโ€™t just automatingโ€”itโ€™s thinking and acting.

Zscalerโ€™s CEO says itโ€™s a bigger shift than cloud or IoT.

The upside? Faster support and instant threat response.
The risk? Rogue AIs scanning your network right now.

Learn why Zero Trust isnโ€™t optional anymore โ†’ https://thehackernews.com/videos/2025/10/exploring-agentic-ai-innovation-meets.html