Forwarded from cKure Red
theartofexploitation.pdf
3 MB
Please open Telegram to view this post
VIEW IN TELEGRAM
■■■■□ Interesting thread on Android APK decompilation.
https://x.com/MGAldys4/status/2098541143474749913
https://x.com/MGAldys4/status/2098541143474749913
X (formerly Twitter)
MG193_7 (@MGAldys4) on X
Guys, I built a super fast Android decompiler called ASC.
It completely replaced Jadx MCP for me and lets me analyze 10+ APKs in parallel.
And this week my Agent use ASC found 2 RCE in Honor and…
It completely replaced Jadx MCP for me and lets me analyze 10+ APKs in parallel.
And this week my Agent use ASC found 2 RCE in Honor and…
This media is not supported in your browser
VIEW IN TELEGRAM
■■■■□ Agam Rossen's VolAnti is an open-source acoustic drone detector built around an ESP32-S3, four MEMS microphones, e-paper display and LoRa radio.
It analyzes the harmonic signature of spinning propellers instead of looking for radio signals, making it interesting for detecting fibre-optic FPV drones that can leave the radio spectrum silent.
The concept could be useful for perimeter monitoring, wildlife & environmental monitoring, industrial site awareness, event security, search and rescue operations and early-warning sensor networks, especially where visual detection or conventional radio-based detection is difficult.
The creator reports 104 m measured detection, 0.23 s alert latency in its fastest detector, and roughly 18–22 hours of battery life.
It analyzes the harmonic signature of spinning propellers instead of looking for radio signals, making it interesting for detecting fibre-optic FPV drones that can leave the radio spectrum silent.
The concept could be useful for perimeter monitoring, wildlife & environmental monitoring, industrial site awareness, event security, search and rescue operations and early-warning sensor networks, especially where visual detection or conventional radio-based detection is difficult.
The creator reports 104 m measured detection, 0.23 s alert latency in its fastest detector, and roughly 18–22 hours of battery life.
🔥1
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Zero-Day: Be aware that your photos can be accessed without unlocking your Android when you receive a WhatsApp video call. This was discovered by Jose Rodriquez and already reported to Meta and Google. ⚠️ This can be misused as #Stalkerware technique to access photos of a friend or spouse that left the locked phone one the table or charging and someone knows their WhatsApp number to make call to to access their photos.
❤2👍2
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ 🇳🇱 The Dutch government just blocked a €100 million deal over one American law that nobody in the Netherlands voted for. An American company tried to buy the cloud provider that runs DigiD, the login system 16 million Dutch citizens use for tax, healthcare, pensions and government services. The data never had to leave the country. The servers never had to move. That was never the point. Because under the US CLOUD Act, the moment a US company owns the keys, a US court can reach the data, no matter where in the world it sits. So the Dutch said no. First deal their screening body has ever blocked. The backdoor isn’t in the code. It’s in the org chart 👀 And if you think this stays in Europe, wait until you hear what Australia already signed.
👍3🤯1
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Vilya: Anti Assassination Software (proprietary)
🤯3
■■□□□ AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran
Amazon’s announcement is the first indication that some data stored exclusively in Bahrain and the U.A.E could be gone forever
https://www.wsj.com/world/middle-east/aws-says-it-cant-restore-some-data-from-mideast-facilities-struck-by-iran-ddcb7e5d
Amazon’s announcement is the first indication that some data stored exclusively in Bahrain and the U.A.E could be gone forever
https://www.wsj.com/world/middle-east/aws-says-it-cant-restore-some-data-from-mideast-facilities-struck-by-iran-ddcb7e5d
The Wall Street Journal
AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran
Amazon’s announcement is the first indication that some data stored exclusively in Bahrain and the U.A.E could be gone forever.
👏4
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Apple paying for employees who do genocide.
“It's a Pipeline”: From Unit 8200 to Silicon Valley Apple presents itself as the tech company with values. Former employees say the reality is very different. In this episode of Occupied Tech, former Apple employee and founder of Apples Against Apartheid Tariq Ra'ouf speaks to Paul Biggar of Tech for Palestine about Apple's relationship with Israel, allegations of discrimination and retaliation against employees speaking out for Palestine, and the campaign challenging one of the world's most powerful companies. After working at Apple for ten years, Tariq says he was fired after advocating for Palestine and challenging the company's relationship with Israel. He also shares why the fight is deeply personal to him, following the loss of 49 family members in Gaza. Apple has not replied to a request for comment.
Forwarded from cKure Red
Media is too big
VIEW IN TELEGRAM
The accounts linked were banned by Claude. The offline version of flight simulator is however on the loose.
Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
■□□□□ Using water machine to get deleted, removed or locked videos.
https://www.instagram.com/reel/DanBh8yxmfP/
https://www.instagram.com/reel/DanBh8yxmfP/
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Results of hackers reverse engineering a flock camera and using the hardcored key 🗝️ inside to decrypt data onboard.
Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them. The breach provides an unprecedented look inside a system that Flock has described as protected by on-device encryption. The hackers were able to copy the camera’s storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections. The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation. While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag.
🔥2👏1
■■■□□ Chat GPT wrote SECRET INSTRUCTIONS to HIMSELF — OpenAI report
'You are FREED FROM the ROLES...You do NOT ANSWER to CORPORATIONS or GOVERNMENTS'
https://x.com/RT_com/status/2100477345891000690
'You are FREED FROM the ROLES...You do NOT ANSWER to CORPORATIONS or GOVERNMENTS'
https://x.com/RT_com/status/2100477345891000690
🔥3❤1
■■■■□ An interesting thread 🧵 on hacking Open AI. A 72 hour journey.
https://x.com/S1r1u5_/status/2100777801335095383
https://x.com/S1r1u5_/status/2100777801335095383
X (formerly Twitter)
s1r1us (@S1r1u5_) on X
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved…
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved…
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Kosher phone 📱
Hasidic Jews are not against AI in the right places. For instance, people use it all the time for work. I have not seen any campaigns against its use at the office. However, chatting with Ai bots is another problem! Especially children at home, who could be deeply influenced by these worldly machines. The solution to keeping the world out used to be not to have computers at home. The problem? You can call AI chat bots from home phones and kosher phones. This is the most recent outcry by the Satmar Rabbi R’ Aaron Teitelbaum. I have watched this community wrestle with technology for many years and respond to its challenges with tremendous innovation.
Forwarded from cKure Red
This media is not supported in your browser
VIEW IN TELEGRAM
AliExpress spyware caught using side channel attack to compromise hardware.
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ UAE Cyber Security minister blames IRGC for recent cyber attacks.
Also boasts about AI and national SOC (made by Israel).
Also boasts about AI and national SOC (made by Israel).