Reversal X Mods (бесплатные премиум-приложения для Android)
2.36K subscribers
571 photos
65 videos
127 files
331 links
Anything worth while.

Share and support us @reversemoda
Download Telegram
❗️🚨 A security researcher secretly got himself into Apple's internal daily bug-bounty FaceTime call and submitted a new vuln with a screenshot as proof, after Apple had stonewalled him on a Messages 0-click bug in 2019.

Apple's response? A threatening letter.
‼️🚨 Hacked Fortinet FortiClient EMS servers are pushing infostealer malware disguised as a Fortinet patch to every managed endpoint.

Attackers exploit CVE-2026-35616 to take the server, then abuse FortiClient's own management channel to deploy it. Patch now!

Source:
https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/
1👍1
🚨 A zero-click attack is hijacking WhatsApp accounts on iPhones running iOS 16.

Victims scan no QR code, share no verification code, and see no linked device in the app.

Attackers then message the victim's contacts asking for bank transfers, and the likely chain (CVE-2025-43300 + CVE-2025-55177) is patched in iOS 16.7.12.

https://www.forenser.it/account-whatsapp-compromessi-su-iphone-con-ios-16/
🤔1
‼️🚨 Over 700 Ghost CMS sites, including Harvard, Oxford, and Auburn, were compromised through an unauthenticated SQL injection (CVE-2026-26980).

Attackers pulled Admin API Keys and turned every site into a ClickFix delivery vector via fake Cloudflare "verify you are human" pages. Patch was out February 19. Most never applied it.

https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/
2
‼️🚨 Malicious actors can now use your SSD's activity, just by getting you to open their website, to spy on which other sites you're browsing and which apps you're running.

The attack, called FROST, is accurate: 88.95% on identifying websites, 95.83% on identifying applications. It works on macOS and Linux, across browsers, and runs entirely in JavaScript.

The browser makers were told, and largely shrugged. Chromium says fingerprinting isn't a security bug. Apple called it out of scope. Mozilla acknowledged it and shipped nothing.

Researchers at Graz University of Technology developed the attack. It abuses the Origin Private File System, a browser feature that lets sites store files on your disk without asking. The attack creates one huge file, then constantly times how fast it can read from it. When you open another tab or launch an app, that activity competes for the same SSD, and the tiny changes in read speed leak what you're doing. A trained neural network turns those timing patterns into guesses about which site or app it is.

https://hannesweissteiner.com/pdfs/frost.pdf
🤔2
🚨 BREAKING: Anthropic released Claude Opus 4.8 a day ago just 41 days after 4.7.

The jump in six weeks:

agentic coding 64.3% → 69.2%
knowledge work 1753 → 1890.

It also overtook GPT-5.5 on financial analysis and knowledge work, the two benchmarks where 4.7 had trailed
.
2
🥰 Please remember to join our second channel too @reversalxmods.

🌭 We lighting up soon.

💯 Let us know after joining the channel in the comment below.
3👍1
This media is not supported in your browser
VIEW IN TELEGRAM
🏖🏖🏖🏖🏖🏖🏖🏖🏖
➽: 𝗔𝗱𝗶𝘇𝗮 𝗠𝗼𝘃𝗶𝗲𝘀 𝗕𝗼𝘅 :➽
🏖🏖🏖🏖🏖🏖🏖🏖🏖

🪀 𝗪𝗛𝗔𝗧'𝗦 𝗙𝗜𝗫𝗘𝗗 🪀

🔍 𝗦𝗘𝗔𝗥𝗖𝗛 𝗙𝗨𝗡𝗖𝗧𝗜𝗢𝗡
├ Search for series & movies wasn't working

└ Now fully fixed and working properly

├ Kindly Open your app to update to the latest version.


🕹 Released By :

逆转 X 模组

🔗 Share To Support Us
🔥1