#FreeTheSandbox

313 posts

#FreeTheSandbox

#FreeTheSandbox

@FreeTheSandbox

An official account for the #FreeTheSandbox Initiative that promote local admin rights for on *our* smartphones. It's simple: Local admin = more innovation!

Planet Earth شامل ہوئے Kasım 2019
10 فالونگ6K فالوورز
پن کیا گیا ٹویٹ
#FreeTheSandbox
#FreeTheSandbox@FreeTheSandbox·
A friendly reminder: hundreds of organizations develop, and sell / resell offensive cyber capabilities vs. smartphones. Oftentimes, zero-clicks. And yet, as of April 4th, 2021 - the sandbox developed by @Apple and @Google actively helps them to hide. It's time to #FreeTheSandbox
English
1
6
59
0
#FreeTheSandbox
#FreeTheSandbox@FreeTheSandbox·
You may want to stay on 15.6 if you aim for full access to your device. This is unfortunate that we must keep the device in a vulnerable state to get a local admin on our phone... but this is the reality. Hopefully it will be fixed soon with #FreeTheSandbox
ZecOps - A Jamf Company@ZecOps

[IMPORTANT] Using an iPhone or iPad? make sure to update to the latest iOS and iPadOS that fixes two vulnerabilities that may have been exploited in the wild in one-click and potentially also zero-click attacks! More details on Apple's website: support.apple.com/en-us/HT213412

English
1
6
36
0
#FreeTheSandbox ری ٹویٹ کیا
Zuk
Zuk@ihackbanme·
Surprise surprise! Another day another 0day exploited in the wild bleepingcomputer.com/news/security/… Incremental patches/mitigations will never work against determined individuals. The only thing that will help to reduce mass surveillance on mobile phones is more eyes. #FreeTheSandbox 👊
English
1
18
49
0
#FreeTheSandbox ری ٹویٹ کیا
Zuk
Zuk@ihackbanme·
iOS 15.2 is out and it is wild. Many remote and local security issues. If you care about your iPhone/iPad security you should update soon. [Source: support.apple.com/en-us/HT212976]
Zuk tweet media
English
10
93
188
0
#FreeTheSandbox
#FreeTheSandbox@FreeTheSandbox·
@AOC What do you think about the lack of local-admin rights on smartphones allowing attackers to stay hidden, and users cannot do anything about it? Don't you think it's more dangerous to democracy than some of the other things you highlight (which are important too) ?
English
0
0
2
0
#FreeTheSandbox
#FreeTheSandbox@FreeTheSandbox·
@SwagOrangeJuice @ZecOps This blog provides a way to reproduce the UAF vulnerability but I doubt this specific vulnerability will turn into a full LPE. Other patched bugs in 15.1 can be relevant. The previous tweet is more about sending ♥️ to the @ZecOps team for great write-ups!
English
0
0
1
0
#FreeTheSandbox
#FreeTheSandbox@FreeTheSandbox·
[2/N] How are we supposed to defend ourselves when it's not a level playing field? It's time to give users local-admin rights. It's time to #FreeTheSandbox and level the playing field.
English
2
0
14
0
#FreeTheSandbox ری ٹویٹ کیا
ZecOps - A Jamf Company
[BREAKING] CVE-2021-30858 iOS WebKit RCE 0-day in the wild: googleprojectzero.github.io/0days-in-the-w… including POC. Can be chained with CVE-2021-30883 and used in 1-clicks and water-holing attacks against iOS users. Update to the latest version as soon as possible.
English
5
79
170
0
#FreeTheSandbox ری ٹویٹ کیا
ZecOps - A Jamf Company
We can confirm that the recently patched iOS 15.0.2 vulnerability, CVE-2021-30883, is also accessible from the browser: perfect for 1-click & water-holing mobile attacks. This vulnerability is exploited in the wild. Update as soon as possible.
ZecOps - A Jamf Company@ZecOps

[BREAKING] @Apple just released iOS 15.0.2 and patched CVE-2021-30883, yet another vulnerability in IOMobileFrameBuffer, that was *exploited in the wild*. [ACTION REQUIRED] Update your iOS devices as soon as you can.

English
3
73
158
0
#FreeTheSandbox ری ٹویٹ کیا
ZecOps - A Jamf Company
This vulnerability is possibly related to: CVE-2021-30807, also in IOMobileFrameBuffer, that was patched in iOS 14.7.1. The vulnerability provides to attackers kernel privileges after they already gained initial code execution capabilities on the device.
English
3
15
55
0