■■■■■ WhatsApp addressed two security vulnerabilities in its app for Android that could have been exploited to remotely hack the victim’s device.
https://securityaffairs.co/wordpress/116833/hacking/whatsapp-flaws-remote-hack.html
https://securityaffairs.co/wordpress/116833/hacking/whatsapp-flaws-remote-hack.html
Security Affairs
WhatsApp flaws could have allowed hackers to hack mobile devices
WhatsApp addressed two security vulnerabilities in its app for Android that could have been exploited to remotely hack the victim's device.
■■■■□ United States 🇺🇸: Australia 🇦🇺based Azimuth unlocked the iPhone at the center of an epic legal battle between the FBI and Apple. Now, Apple is suing the company co-founded by one of the hackers behind the unlock.
https://www.washingtonpost.com/technology/2021/04/14/azimuth-san-bernardino-apple-iphone-fbi/
https://www.washingtonpost.com/technology/2021/04/14/azimuth-san-bernardino-apple-iphone-fbi/
The Washington Post
The FBI wanted to unlock the San Bernardino shooter’s iPhone. It turned to a little-known Australian firm.
Azimuth unlocked the iPhone at the center of an epic legal battle between the FBI and Apple. Now, Apple is suing the company co-founded by one of the hackers behind the unlock.
■■□□□ Security Bug Allows Attackers to Brick Kubernetes Clusters. The vulnerability is triggered when a cloud container pulls a malicious image from a registry.
https://threatpost.com/security-bug-brick-kubernetes-clusters/165413/
https://threatpost.com/security-bug-brick-kubernetes-clusters/165413/
Threat Post
Security Bug Allows Attackers to Brick Kubernetes Clusters
The vulnerability is triggered when a cloud container pulls a malicious image from a registry.
■□□□□ Vulnerabilities in 17+ Elementor Add-on Plugins for WordPress.
https://www.searchenginejournal.com/wordpress-elementor-plugin-vulnerabilities/402330/
https://www.searchenginejournal.com/wordpress-elementor-plugin-vulnerabilities/402330/
Search Engine Journal
Vulnerabilities in 17+ Elementor Add-on Plugins for WordPress
Millions of WordPress sites affected by vulnerabilities in Elementor add-on plugins
cKure
■■■■■ Zero-Day exploit code for Chrome. https://github.com/r4j0x00/exploits/tree/master/chrome-0day
■■■■■ For the second time in a week, a Chromium zero-day remote code execution exploit code has been released on Twitter, multiple browsers impacted.
https://github.com/avboy1337/1195777-chrome0day
https://securityaffairs.co/wordpress/116844/hacking/google-chromium-zero.html
https://github.com/avboy1337/1195777-chrome0day
https://securityaffairs.co/wordpress/116844/hacking/google-chromium-zero.html
cKure
■■■■□ PoC / exploit utilities. CVE-2020-6516 - Chrome CVE-2021-24027 - WhatsApp https://github.com/CENSUS/whatsapp-mitd-mitm
■■■■■ Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027).
https://census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/
https://census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/
Census-Labs
CENSUS - Resources
Security research, publications, and technical insights from the CENSUS team.
cKure
■■■■■ Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027). https://census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/
■■■■□ WhatsApp exposure of TLS 1.2 cryptographic material to third party apps.
https://census-labs.com/news/2021/04/14/whatsapp-exposure-of-cryptographic-material-to-third-party-apps/
https://census-labs.com/news/2021/04/14/whatsapp-exposure-of-cryptographic-material-to-third-party-apps/
CENSUS
CENSUS — Cybersecurity for AI-driven unmanned systems
Cybersecurity for AI-driven unmanned systems. Platform Integrity, AI Trustworthiness and Secure Communications.
■□□□□ AppSpace Zero-Days
1. XSS - Stored
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27989
2. Broken Auth
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27990
Credits: https://www.linkedin.com/in/syedsohaibkarim
1. XSS - Stored
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27989
2. Broken Auth
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27990
Credits: https://www.linkedin.com/in/syedsohaibkarim
■■■□□ Swissknife - Scriptable VSCode Extension To Generate Or Manipulate Data.
https://github.com/luisfontes19/vscode-swissknife/
https://github.com/luisfontes19/vscode-swissknife/
GitHub
GitHub - luisfontes19/vscode-swissknife: Scriptable VSCode extension to generate or manipulate data. Stop pasting sensitive data…
Scriptable VSCode extension to generate or manipulate data. Stop pasting sensitive data in webpages. - luisfontes19/vscode-swissknife
■■■■■ Multiple one-click vulnerabilities have been discovered across a variety of popular software applications, allowing an attacker to potentially execute arbitrary code on target systems. The issues were discovered by Positive Security researchers Fabian Bräunlein and Lukas Euler and affect apps like Telegram, Nextcloud, VLC, LibreOffice, OpenOffice, Bitcoin/Dogecoin Wallets, Wireshark, and Mumble.
https://positive.security/blog/url-open-rce
https://thehackernews.com/2021/04/1-click-hack-found-in-popular-desktop.html
https://positive.security/blog/url-open-rce
https://thehackernews.com/2021/04/1-click-hack-found-in-popular-desktop.html
positive.security
Allow arbitrary URLs, expect arbitrary code execution | Positive Security
Insecure URL handling leading to 1-click code execution vulnerabilities in Telegram, Nextcloud (CVE-2021-22879), VLC, LibreOffice (CVE-2021-25631), OpenOffice (CVE-2021-30245), Bitcoin/Dogecoin Wallets, Wireshark (CVE-2021-22191) and Mumble (CVE-2021-27229).
■■■□□ United States 🇺🇸 Treasury sanctions Russia 🇷🇺 with sweeping new Sanctions Authority amid cyber attacks.
https://home.treasury.gov/news/press-releases/jy0127
https://home.treasury.gov/news/press-releases/jy0127
■□□□□ 📢 RaidForum's official account claims that fake news is being circulated about its closure.
https://mobile.twitter.com/1dot3dot3dot7/status/1382700999865995271
https://mobile.twitter.com/1dot3dot3dot7/status/1382700999865995271
Twitter
Omnipotent
Seen a bunch of fake news around; We are not being DDoS'd and nobody has been arrested. Our reverse-proxy server is offline due to shitty NOC Engineers.
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Unconfirmed: Team Fortress 2 remote code execution exploit triggered by joining a community server.
■■■□□ Over $760 million worth of Bitcoin that were stolen from cryptocurrency exchange Bitfinex in 2016 were moved to new accounts.
https://securityaffairs.co/wordpress/116858/digital-id/bitfinex-funds-moved.html
https://securityaffairs.co/wordpress/116858/digital-id/bitfinex-funds-moved.html
Security Affairs
Cyber thieves move $760 million stolen in the 2016 Bitfinex heist
Over $760 million worth of Bitcoin that were stolen from cryptocurrency exchange Bitfinex in 2016 were moved to new accounts.
cKure
■■■■■ For the second time in a week, a Chromium zero-day remote code execution exploit code has been released on Twitter, multiple browsers impacted. https://github.com/avboy1337/1195777-chrome0day https://securityaffairs.co/wordpress/116844/hacking/google…
■■□□□ Google Brings 37 Security Fixes to Chrome 90.
■■■□□ Defeat-Defender - Powerful Batch Script To Dismantle Complete Windows Defender Protection And Even Bypass Tamper Protection.
https://github.com/swagkarna/Defeat-Defender
https://github.com/swagkarna/Defeat-Defender