Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box Squashed Writeup

https://cdn-images-1.medium.com/max/1944/0*RFwSwU1UzAkmXLuP.png
Hello world and welcome to haxez and my write-up for the Squashed machine. I’ve been getting back into doing Hack The Box machines again…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box Late Writeup

https://cdn-images-1.medium.com/max/1944/0*cfEJvSHZvk1BqzNi.png
Hello world, welcome to Haxez. It’s time for another Hack The Box machine write up and this time we’re looking at Late.

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cybersecurity: when vulnerability becomes a threat

https://cdn-images-1.medium.com/max/1080/1*sw809279FGO5xkTxeFQWXQ.png
Cybercrime is the largest threat to small, medium and large businesses today. Recent attacks caused havoc and chaos. What happened? Let’s…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box Weak RSA Writeup

https://cdn-images-1.medium.com/max/1944/0*KE05tAjPGj1-arpM.png
Hello world and welcome to haxez, today I will attempt to solve the Weak RSA crypto challenge on Hack The Box. Please note that I got the…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Tehran and Abu Dhabi Seek Stronger Ties: Iran's Security Chief Holds Talks in the UAE

After years of animosity, UAE and Iran started re-engaging only in 2019. The recent visit of Iran's top security official to the UAE highlights Iran's efforts to strengthen ties with its neighbors amidst growing isolation from the West.

submitted by /u/defensive_reaction
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos Chipsets

Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos ChipsetsPost Views: 46 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Google’s Project Zero uncovers 18 zero-day vulnerabilities in Samsung Exynos chipsetsGoogle’s bug-hunting team, Project Zero, has identified 18 zero-day vulnerabilities in Samsung’s Exynos chipsets used in mobile devices, wearables, and cars. These vulnerabilities were discovered between late 2022 and early 2023, and four of them were deemed the most serious. The flaws allow remote code execution from the Internet to the baseband, enabling attackers to compromise vulnerable devices without any user interaction.

The security flaws, including CVE-2023-24033 and three others still awaiting a CVE-ID, were described as “Internet-to-baseband remote code execution (RCE) bugs.” Samsung acknowledged the vulnerability in a security advisory, stating that the baseband software does not properly check the format types of accept-type attribute specified by the SDP, which can lead to denial of service or code execution in Samsung Baseband Modem.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Four of the identified Exynos modem security flaws enable remote code executionTim Willis, the Head of Project Zero, has warned that experienced attackers could easily create an exploit that remotely compromises vulnerable devices without triggering the target’s attention. Due to the high level of access these vulnerabilities provide, Project Zero has delayed disclosure for the four vulnerabilities that allow for Internet-to-baseband remote code execution.

The remaining 14 flaws, including CVE-2023-24072, CVE-2023-24073, CVE-2023-24074, CVE-2023-24075, CVE-2023-24076, and nine others awaiting CVE-IDs, are less critical but still pose a risk. Successful exploitation requires local access or a malicious mobile network operator.
End-users still don't have patches 90 days after report…. https://t.co/dkA9kuzTso

— Maddie Stone (@maddiestone) March 16, 2023
Samsung has already provided security updates addressing these vulnerabilities in impacted chipsets to other vendors. However, patches are not public and can’t be applied by all affected users. Each manufacturer’s patch timeline for their devices will differ. Google, for instance, has already addressed CVE-2023-24033 for impacted Pixel devices in its March 2023 security updates.
Trending: Major Cyber Attacks of 2022
Trending: Offensive Security Tool: CrackQL Google and Samsung urge users to update devices to mitigate Exynos chipset flawsUntil patches are available, users can disable Wi-Fi calling and Voice-over-LTE (VoLTE) to remove the attack vector and thwart baseband RCE exploitation attempts targeting Samsung’s Exynos chipsets in their device. Samsung has confirmed Project Zero’s workaround and encourages end-users to update their devices as soon as possible to ensure that they are running the latest builds that fix both disclosed and undisclosed security vulnerabilities.
Trending: Proof-of-concept for critical Microsoft Word vulnerability published
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/u[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos Chipsets Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos ChipsetsPost Views: 46 Premium Contenthttps://www.blackhatethicalhacking.com/wp-conte…
ploads/2023/03/M.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-7-300x150.png CISA Identifies Critical Vulnerability in Adobe ColdFusionMarch 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-3-1-300x150.png GoBruteforcer: New Golang-based Botnet Malware Scans for and Infects Web ServersMarch 13, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos Chipsets first appeared on Black Hat Ethical Hacking.