home.social

#zerodayexploit — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zerodayexploit, aggregated by home.social.

fetched live
  1. Ecco la fantomatica #sicurezza che tanto decanta #google il #playintegrty salverà milioni di dispositivi che non ricevono più #ota da parte dei produttori? Chi avrebbe le capacità di salvare questi dispositivi? La community con progetti come #lineageos #grapheneos ma invece viene ostacolata impedendo alle persone di usare app critiche e fondamentali per la vita quotidiana. #android #noplayintegrty #zerodayexploit #zeroday
    ilsoftware.it/allarme-android-

  2. Afgelopen vrijdag werd een zogenaamde #ZeroDayExploit ontdekt in #Microsoft #SharePoint. De kwetsbaarheid stelt hackers in staat om volledige controle te krijgen over de getroffen servers van SharePoint, inclusief software die daarmee verbonden is, zoals #Teams en #OneDrive.

    vrtnws.be/p.xZRWMdn8R

  3. Afgelopen vrijdag werd een zogenaamde #ZeroDayExploit ontdekt in #Microsoft #SharePoint. De kwetsbaarheid stelt hackers in staat om volledige controle te krijgen over de getroffen servers van SharePoint, inclusief software die daarmee verbonden is, zoals #Teams en #OneDrive.

    vrtnws.be/p.xZRWMdn8R

  4. Cybersecurity for Activists hit #1 Best Seller in Online Safety and Privacy. Thanks to those who purchased. Let's keep the ball rolling. Because Big Brother is not just watching. Bug Bounty: For anyone who points out a factual error I will donate a copy to a student. #SurveillanceState #Cellebrite #NoviSpy #ZeroDayExploit #DataPrivacy #ActivistsUnderAttack #PrivacyMatters #DigitalSecurity #EndTheCreep #Totalitarianism #SurveillanceCapitalism #DigitalRights #TechForGood #KnowYourRights #StaySafe #PhoneHacking #Spyware #ZeroDay #Resistance #ProtectYourData #cybersecurity #Fascism #TeslaTakedown #Indivisible #activism #DigitalSecurity #digitalsecuritymatters #cybersecuritycondor #MAGAfascism #Trumpfascism #stopthefascistcreep #stopMAGA #StopElon #fElon47 #felon45 #resist #shepersisted #news #books #booktok #meta #2fa
  5. Cybersecurity for Activists hit #1 Best Seller in Online Safety and Privacy. Thanks to those who purchased. Let's keep the ball rolling. Because Big Brother is not just watching. Bug Bounty: For anyone who points out a factual error I will donate a copy to a student. #SurveillanceState #Cellebrite #NoviSpy #ZeroDayExploit #DataPrivacy #ActivistsUnderAttack #PrivacyMatters #DigitalSecurity #EndTheCreep #Totalitarianism #SurveillanceCapitalism #DigitalRights #TechForGood #KnowYourRights #StaySafe #PhoneHacking #Spyware #ZeroDay #Resistance #ProtectYourData #cybersecurity #Fascism #TeslaTakedown #Indivisible #activism #DigitalSecurity #digitalsecuritymatters #cybersecuritycondor #MAGAfascism #Trumpfascism #stopthefascistcreep #stopMAGA #StopElon #fElon47 #felon45 #resist #shepersisted #news #books #booktok #meta #2fa
  6. I’ve compiled an A-Z field manual specifically for people who use their voice to challenge power—especially on social media. It’s written for activists, organizers, journalists, and anyone who has reason to believe they might be on someone’s watchlist. Not theory—just facts, tools, tactics, and what you’re really up against. 📕 If you use your phone to speak truth, understand this: Your phone might already be speaking back—for them. 👉 https://www.amazon.com/Cybersecurity-Activists-Watermelon-Book-Condor/dp/B0F5NKC8Y5/ Stay alert. Stay encrypted. Stay dangerous. #SurveillanceState #Cellebrite #NoviSpy #ZeroDayExploit #DataPrivacy #ActivistsUnderAttack #PrivacyMatters #DigitalSecurity #EndTheCreep #Totalitarianism #SurveillanceCapitalism #DigitalRights #TechForGood #KnowYourRights #StaySafe #PhoneHacking #Spyware #ZeroDay #Resistance #ProtectYourData Cybersecurity for Activists https://www.amazon.com/dp/B0F5NKC8Y5 International Link: https://mybook.to/opsec
  7. I’ve compiled an A-Z field manual specifically for people who use their voice to challenge power—especially on social media. It’s written for activists, organizers, journalists, and anyone who has reason to believe they might be on someone’s watchlist. Not theory—just facts, tools, tactics, and what you’re really up against. 📕 If you use your phone to speak truth, understand this: Your phone might already be speaking back—for them. 👉 https://www.amazon.com/Cybersecurity-Activists-Watermelon-Book-Condor/dp/B0F5NKC8Y5/ Stay alert. Stay encrypted. Stay dangerous. #SurveillanceState #Cellebrite #NoviSpy #ZeroDayExploit #DataPrivacy #ActivistsUnderAttack #PrivacyMatters #DigitalSecurity #EndTheCreep #Totalitarianism #SurveillanceCapitalism #DigitalRights #TechForGood #KnowYourRights #StaySafe #PhoneHacking #Spyware #ZeroDay #Resistance #ProtectYourData Cybersecurity for Activists https://www.amazon.com/dp/B0F5NKC8Y5 International Link: https://mybook.to/opsec
  8. 🚨 Breaking Cyber News! Researchers uncover NoviSpy, a sinister Android spyware targeting Serbian activists, exploiting a zero-day Qualcomm chip vulnerability. Journalists beware - your device might be compromised! 🕵️‍♀️📱 #CyberSecurity #DigitalPrivacy #ZeroDayExploit @GoogleTAG #newz

    cyberinsider.com/new-novispy-a

  9. 🚨 Breaking Cyber News! Researchers uncover NoviSpy, a sinister Android spyware targeting Serbian activists, exploiting a zero-day Qualcomm chip vulnerability. Journalists beware - your device might be compromised! 🕵️‍♀️📱 #CyberSecurity #DigitalPrivacy #ZeroDayExploit @GoogleTAG #newz

    cyberinsider.com/new-novispy-a

  10. #CyberSecurity #Qualcomm #Android #ZeroDayExploit #Hacking: "The zero-day vulnerability, officially designated CVE-2024-43047, “may be under limited, targeted exploitation,” according to Qualcomm, citing unspecified “indications” from Google’s Threat Analysis Group, the company’s research unit that investigates government hacking threats. Amnesty International’s Security Lab, which works to protect civil society from digital surveillance and spyware threats, confirmed Google’s assessment, Qualcomm said.

    U.S. cybersecurity agency CISA included the Qualcomm flaw in its list of vulnerabilities that are known to be, or have been, exploited.

    At this point, there aren’t many details about who was exploiting this vulnerability “in the wild” — meaning that whoever was using the zero-day was targeting individuals in real hacking campaigns. It also is not yet known which individuals were targeted, or why.

    Qualcomm’s spokesperson Catherine Baker told TechCrunch that the company commends “the researchers from Google Project Zero and Amnesty International Security Lab for using coordinated disclosure practices,” allowing the company to roll out fixes for the vulnerability."

    techcrunch.com/2024/10/09/hack

  11. #CyberSecurity #Qualcomm #Android #ZeroDayExploit #Hacking: "The zero-day vulnerability, officially designated CVE-2024-43047, “may be under limited, targeted exploitation,” according to Qualcomm, citing unspecified “indications” from Google’s Threat Analysis Group, the company’s research unit that investigates government hacking threats. Amnesty International’s Security Lab, which works to protect civil society from digital surveillance and spyware threats, confirmed Google’s assessment, Qualcomm said.

    U.S. cybersecurity agency CISA included the Qualcomm flaw in its list of vulnerabilities that are known to be, or have been, exploited.

    At this point, there aren’t many details about who was exploiting this vulnerability “in the wild” — meaning that whoever was using the zero-day was targeting individuals in real hacking campaigns. It also is not yet known which individuals were targeted, or why.

    Qualcomm’s spokesperson Catherine Baker told TechCrunch that the company commends “the researchers from Google Project Zero and Amnesty International Security Lab for using coordinated disclosure practices,” allowing the company to roll out fixes for the vulnerability."

    techcrunch.com/2024/10/09/hack

  12. Hackers targeting Google Pixel with a zero-day exploit

    Security researchers from GrapheneOS have discovered a zero-day exploit designed to break into Google Pixel smartphones.

    #GooglePixel #Google #technews #zerodayexploit

    techaeris.com/2024/04/04/hacke

  13. Hackers targeting Google Pixel with a zero-day exploit

    Security researchers from GrapheneOS have discovered a zero-day exploit designed to break into Google Pixel smartphones.

    #GooglePixel #Google #technews #zerodayexploit

    techaeris.com/2024/04/04/hacke

  14. Chinese Hackers Exploited New Zero-Day in Barracuda's ESG Appliances

    Barracuda has revealed that Chinese threat actors exploited a new zero-day in its Email Security Gateway (ESG) appliances to deploy backdoors on a "limited number" of devices.

    Tracked as CVE-2023-7102, the issue relates to a case of arbitrary code execution that resides within a third-party and open-source library named Spreadsheet::ParseExcel that's used by the Amavis scanner within the gateway. Successful exploitation of the new flaw is accomplished by means of a specially crafted Microsoft Excel email attachment.

    Spreadsheet::ParseExcel is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

    Barracuda said it released a security update that has been "automatically applied" on December 21, 2023, and that no further customer action is required.

    Source: Barracuda Email Security Gateway Appliance (ESG) Advisory

    Tags: #CyberSecurity #ZeroDayExploit #BarracudaESG #CVE-2023-7102 #EmailSecurity #Barracuda 🚨

  15. Chinese Hackers Exploited New Zero-Day in Barracuda's ESG Appliances

    Barracuda has revealed that Chinese threat actors exploited a new zero-day in its Email Security Gateway (ESG) appliances to deploy backdoors on a "limited number" of devices.

    Tracked as CVE-2023-7102, the issue relates to a case of arbitrary code execution that resides within a third-party and open-source library named Spreadsheet::ParseExcel that's used by the Amavis scanner within the gateway. Successful exploitation of the new flaw is accomplished by means of a specially crafted Microsoft Excel email attachment.

    Spreadsheet::ParseExcel is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

    Barracuda said it released a security update that has been "automatically applied" on December 21, 2023, and that no further customer action is required.

    Source: Barracuda Email Security Gateway Appliance (ESG) Advisory

    Tags: #CyberSecurity #ZeroDayExploit #BarracudaESG #CVE-2023-7102 #EmailSecurity #Barracuda 🚨

  16. This article at Forbes is now updated with new information from Citizen Lab and Google TAG detailing a zero-day exploit chain leading to a no-click exploit of an iPhone. It’s time to update all the Apple things, well, a whole bunch of them anyway.

    #infosec #Apple #ZeroDayExploit #iPhone #iPad #AppleWatch #Mac

    forbes.com/sites/daveywinder/2

  17. This article at Forbes is now updated with new information from Citizen Lab and Google TAG detailing a zero-day exploit chain leading to a no-click exploit of an iPhone. It’s time to update all the Apple things, well, a whole bunch of them anyway.

    #infosec #Apple #ZeroDayExploit #iPhone #iPad #AppleWatch #Mac

    forbes.com/sites/daveywinder/2