Reversal X Mods (бесплатные премиум-приложения для Android)
2.36K subscribers
571 photos
64 videos
125 files
330 links
Anything worth while.

Share and support us @reversemoda
Download Telegram
🚨 A zero-click attack is hijacking WhatsApp accounts on iPhones running iOS 16.

Victims scan no QR code, share no verification code, and see no linked device in the app.

Attackers then message the victim's contacts asking for bank transfers, and the likely chain (CVE-2025-43300 + CVE-2025-55177) is patched in iOS 16.7.12.

https://www.forenser.it/account-whatsapp-compromessi-su-iphone-con-ios-16/
🤔1
‼️🚨 Over 700 Ghost CMS sites, including Harvard, Oxford, and Auburn, were compromised through an unauthenticated SQL injection (CVE-2026-26980).

Attackers pulled Admin API Keys and turned every site into a ClickFix delivery vector via fake Cloudflare "verify you are human" pages. Patch was out February 19. Most never applied it.

https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/
2
‼️🚨 Malicious actors can now use your SSD's activity, just by getting you to open their website, to spy on which other sites you're browsing and which apps you're running.

The attack, called FROST, is accurate: 88.95% on identifying websites, 95.83% on identifying applications. It works on macOS and Linux, across browsers, and runs entirely in JavaScript.

The browser makers were told, and largely shrugged. Chromium says fingerprinting isn't a security bug. Apple called it out of scope. Mozilla acknowledged it and shipped nothing.

Researchers at Graz University of Technology developed the attack. It abuses the Origin Private File System, a browser feature that lets sites store files on your disk without asking. The attack creates one huge file, then constantly times how fast it can read from it. When you open another tab or launch an app, that activity competes for the same SSD, and the tiny changes in read speed leak what you're doing. A trained neural network turns those timing patterns into guesses about which site or app it is.

https://hannesweissteiner.com/pdfs/frost.pdf
🤔2
🚨 BREAKING: Anthropic released Claude Opus 4.8 a day ago just 41 days after 4.7.

The jump in six weeks:

agentic coding 64.3% → 69.2%
knowledge work 1753 → 1890.

It also overtook GPT-5.5 on financial analysis and knowledge work, the two benchmarks where 4.7 had trailed
.
2
🥰 Please remember to join our second channel too @reversalxmods.

🌭 We lighting up soon.

💯 Let us know after joining the channel in the comment below.
3👍1
This media is not supported in your browser
VIEW IN TELEGRAM
🏖🏖🏖🏖🏖🏖🏖🏖🏖
➽: 𝗔𝗱𝗶𝘇𝗮 𝗠𝗼𝘃𝗶𝗲𝘀 𝗕𝗼𝘅 :➽
🏖🏖🏖🏖🏖🏖🏖🏖🏖

🪀 𝗪𝗛𝗔𝗧'𝗦 𝗙𝗜𝗫𝗘𝗗 🪀

🔍 𝗦𝗘𝗔𝗥𝗖𝗛 𝗙𝗨𝗡𝗖𝗧𝗜𝗢𝗡
├ Search for series & movies wasn't working

└ Now fully fixed and working properly

├ Kindly Open your app to update to the latest version.


🕹 Released By :

逆转 X 模组

🔗 Share To Support Us
🔥1
❗️ John Daghita, the 22-year-old accused of stealing $46 million in crypto from the US Marshals Service, has been cleared by a French court for fast-tracked extradition to the United States.

He was arrested March 4 in a luxury villa on Saint-Martin in a joint FBI and GIGN operation, caught "by ruse and without incident." Agents seized computers, crypto wallet credentials, several phones, around 250,000 euros in cash, and a loaded Glock. The full $46 million was recovered.

He allegedly pulled it off using privileged access tied to his father's federal contracting firm, which held a US government contract to manage seized cryptocurrency. He got caught after blockchain investigator ZachXBT traced the funds, reportedly tipped off when Daghita flexed a $23M wallet on Telegram.

Daghita requested his own extradition at his first hearing on May 21, saying he wants to explain himself to US courts.
❗️🚨 BREAKING: Security researchers are now handing Nightmare-Eclipse vulnerabilities for free, in what looks like both a show of support and a reaction to how Microsoft treats researchers. First up: "Bitskrieg," violates Secure Boot trust and fully bypasses BitLocker.

It seems aimed squarely at Microsoft's recent blog, where the company said its Digital Crimes Unit would bring cases against threat actors "and those that enable their criminal activity," language many researchers read as a threat pointed at them
.