clem1

876 posts

clem1

clem1

@_clem1

tail -f internet | grep exploit

Katılım Haziran 2010
546 Takip Edilen6.8K Takipçiler
Is Now on VT!
Is Now on VT!@Now_on_VT·
To date, none of the samples mentioned by hash in the Google Coruna blog or iVerify blog have been uploaded to @virustotal. Still monitoring the situation.
English
1
3
22
11.7K
clem1 retweetledi
John Scott-Railton
John Scott-Railton@jsrailton·
BREAKING: powerful iPhone hacking tools used by Chinese criminals originated from US defense giant L3 Harris. The $LHX zero-click exploits went to Russian spies too. Unbelievable harm to our collective security. Scoop by @lorenzofb, here's why this matters 1/
John Scott-Railton tweet mediaJohn Scott-Railton tweet media
English
34
882
2.4K
266.8K
clem1 retweetledi
Andy Greenberg (@agreenberg at the other places)
A full iOS exploit toolkit, "Coruna," has been found in the wild, hacking iPhones that visited infected websites, used by Russian spies targeting Ukrainians and thieves targeting Chinese crypto holders. And it may have been created for the US government. wired.com/story/coruna-i…
English
8
312
720
99.3K
clem1 retweetledi
Mandiant (part of Google Cloud)
Coruna exploit kit is targeting iOS. Coruna leverages 23 exploits against Apple devices running iOS 13-17.2.1. It is being used for espionage, and by financially motivated actors to steal crypto. Update your iOS devices, and learn more about this threat: bit.ly/4rbeltc
Mandiant (part of Google Cloud) tweet media
English
6
119
359
116.6K
clem1 retweetledi
Natalie Silvanovich
Natalie Silvanovich@natashenka·
We launched a redesigned Project Zero website today at projectzero.google ! To mark the occasion, we released some older posts that never quite made it out of drafts. Enjoy!
English
7
61
367
45.9K
clem1 retweetledi
blackorbird
blackorbird@blackorbird·
This issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group. CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. support.apple.com/en-us/125884 [N/A][466192044] High CVE-2025-14174: Out of bounds memory access in ANGLE. Reported by Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group on 2025-12-05 chromereleases.googleblog.com/2025/12/stable… ANGLE and WebGL 2.0 in WebKit trac.webkit.org/wiki/AngleforW…
blackorbird tweet mediablackorbird tweet media
English
1
16
115
28.5K
clem1 retweetledi
Donncha Ó Cearbhaill
Donncha Ó Cearbhaill@DonnchaC·
🚨 A huge leak exposes the new targets and internal operations of Intellexa, the secretive and murky company behind the notorious Predator spyware. Introducing #IntellexaLeaks, a joint investigation with partners @insidestory_gr, @haaretzcom & WAV Research Collective 🧵👇
Donncha Ó Cearbhaill tweet media
English
2
46
114
21.6K
clem1 retweetledi
Samuel Groß
Samuel Groß@5aelo·
We derestricted a number of vulnerabilities found by Big Sleep in JavaScriptCore today: issuetracker.google.com/issues?q=compo… All of them were fixed in the iOS 26.1 (and equivalent) update last month. Definitely some cool bugs in there!
English
2
34
175
17.8K
clem1 retweetledi
Seth Jenkins
Seth Jenkins@__sethJenkins·
All my recent activity wasn't for nothing...I'm pleased to announce that I'll be speaking at @DistrictCon with @natashenka about a 0-click to kernel exploit chain for the Pixel 9 in January!
Seth Jenkins tweet media
English
3
17
208
15.5K
Bill Marczak
Bill Marczak@billmarczak·
Someone's really having a lot of fun with DNG. Another (!) DNG vuln patched in 2025-10 Samsung update. Google TAG assesses surveillance vendors may have been aware of this vuln (though not presently clear if deployed ITW or not) project-zero.issues.chromium.org/issues/4424237…
English
2
12
74
18.6K
clem1 retweetledi
Hexacon
Hexacon@hexacon_fr·
We’re thrilled to announce Donncha Ó Cearbhaill (@DonnchaC) as our keynote speaker for HEXACON 2025! 💥 No doubt he has plenty of juicy stories up his sleeve 👾
Hexacon tweet media
English
0
8
36
7.4K
clem1 retweetledi
Ivan Fratric 💙💛
Ivan Fratric 💙💛@ifsecure·
If you've been keeping track on the Big Sleep bug tracker at goo.gle/bigsleep you might have noticed it lists more bugs now compared to last week. Including a "High impact issue in V8" :)
English
3
20
102
23K
clem1 retweetledi
DARKNAVY
DARKNAVY@DarkNavyOrg·
Leak hole PoC for Chrome in-the-wild vulnerability CVE-2025-6554 published yesterday: github.com/DarkNavySecuri…
DARKNAVY tweet mediaDARKNAVY tweet media
English
5
54
181
32.3K