WhatsApp Vulnerabilities Leaked Users’ Metadata Including Device’s Operating System Details
https://medium.com/@TalBeerySec/whatsapp-silent-fix-of-device-fingerprinting-privacy-issue-assessment-the-good-the-not-so-bad-9127b5215e28
https://medium.com/@TalBeerySec/whatsapp-silent-fix-of-device-fingerprinting-privacy-issue-assessment-the-good-the-not-so-bad-9127b5215e28
Medium
WhatsApp Silent Fix of Device Fingerprinting Privacy Issue Assessment: The Good, The (Not So) Bad…
TL;DR: Using our research tool, we discovered that WhatsApp is silently implementing fixes for device fingerprinting privacy…
👍17
Predator iOS Malware: Building a Surveillance Framework - Part 1
https://blog.reversesociety.co/blog/2025/predator-ios-malware-surveillance-framework-part-1
https://blog.reversesociety.co/blog/2025/predator-ios-malware-surveillance-framework-part-1
blog.reversesociety.co
Predator iOS Malware: Building a Surveillance Framework - Part 1 | Reverse Society
How does Predator spyware transform from running code into active surveillance? This technical deep-dive reverse-engineers the internal factory architecture that dynamically creates camera monitoring, VoIP interception, and keylogging modules through Unix…
👍10
Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android NFC Malware
https://www.group-ib.com/blog/ghost-tapped-chinese-malware/
https://www.group-ib.com/blog/ghost-tapped-chinese-malware/
Group-IB
Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware
Group-IB researchers detail the inner workings of Chinese tap-to-pay schemes on Telegram and examine the NFC-enabled Android apps fraudsters are using to steal money from victim’s bank cards and mobile wallets remotely.
👍14❤2
Droid LLM Hunter is a tool to scan for vulnerabilities in Android applications using Large Language Models (LLMs)
https://github.com/roomkangali/droid-llm-hunter
https://github.com/roomkangali/droid-llm-hunter
GitHub
GitHub - roomkangali/droid-llm-hunter: Droid LLM Hunter is a tool to scan for vulnerabilities in Android applications using Large…
Droid LLM Hunter is a tool to scan for vulnerabilities in Android applications using Large Language Models (LLMs). - GitHub - roomkangali/droid-llm-hunter: Droid LLM Hunter is a tool to scan for ...
🔥13🎃1
Dalvik bytecode emulator for Android static analysis | String decryption | Multi-DEX | No Android runtime required
https://github.com/fatalSec/DaliVM
https://github.com/fatalSec/DaliVM
GitHub
GitHub - fatalSec/DaliVM: Dalvik bytecode emulator for Android static analysis | String decryption | Multi-DEX | No Android runtime…
Dalvik bytecode emulator for Android static analysis | String decryption | Multi-DEX | No Android runtime required - fatalSec/DaliVM
👍20❤3
Frida-UI: Interact with Frida devices, processes, and scripts directly from your browser
https://github.com/adityatelange/frida-ui
https://github.com/adityatelange/frida-ui
GitHub
GitHub - adityatelange/frida-ui: Interact with Frida devices, processes, and scripts directly from your browser.
Interact with Frida devices, processes, and scripts directly from your browser. - adityatelange/frida-ui
👌8
This media is not supported in your browser
VIEW IN TELEGRAM
One-click Telegram IP address leak
https://www.bleepingcomputer.com/news/security/hidden-telegram-proxy-links-can-reveal-your-ip-address-in-one-click/
Video by @0x6rss
https://www.bleepingcomputer.com/news/security/hidden-telegram-proxy-links-can-reveal-your-ip-address-in-one-click/
Video by @0x6rss
❤13🎃3😁1
Play Integrity API: How It Works & How to Bypass It
https://m4kr0.vercel.app/posts/play-integrity-api-how-it-works--how-to-bypass-it/
https://m4kr0.vercel.app/posts/play-integrity-api-how-it-works--how-to-bypass-it/
M4KR0 Blog
Play Integrity API: How It Works & How to Bypass It - M4KR0 Blog
What's Play Interity API and how to bypass it
❤13⚡4😴2👍1👏1
Flutter SSL Bypass: How to Intercept HTTPS Traffic When all other Frida Scripts Fail
https://m4kr0.vercel.app/posts/flutter-ssl-bypass-how-to-intercept-https-traffic-when-all-other-frida-scripts-fail/
https://m4kr0.vercel.app/posts/flutter-ssl-bypass-how-to-intercept-https-traffic-when-all-other-frida-scripts-fail/
M4KR0 Blog
Flutter SSL Bypass: How to Intercept HTTPS Traffic When all other Frida Scripts Fail - M4KR0 Blog
my journey in intercepting HTTPS traffic from a APK based on Flutter
❤13🔥6👍2
deVixor: An Evolving Android Banking RAT with Ransomware Capabilities Targeting Iran
https://cyble.com/blog/devixor-an-evolving-android-banking-rat-with-ransomware-capabilities-targeting-iran/
https://cyble.com/blog/devixor-an-evolving-android-banking-rat-with-ransomware-capabilities-targeting-iran/
Cyble
DeVixor: An Evolving Android Banking RAT With Ransomware Capabilities Targeting Iran - Cyble
Cyble analyzed deVixor, an advanced Android banking RAT with ransomware features actively targeting Iranian users.
❤11👍3🤬3😁2🎃2
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
https://projectzero.google/2026/01/pixel-0-click-part-1.html
https://projectzero.google/2026/01/pixel-0-click-part-1.html
projectzero.google
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
🔥8❤2🎃1
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
https://projectzero.google/2026/01/pixel-0-click-part-2.html
https://projectzero.google/2026/01/pixel-0-click-part-2.html
projectzero.google
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave - Project Zero
With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the res...
👏6🎃2
A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?
https://projectzero.google/2026/01/pixel-0-click-part-3.html
https://projectzero.google/2026/01/pixel-0-click-part-3.html
projectzero.google
A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? - Project Zero
While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our e...
👏8🎃4
WhisperPair: Hijacking Bluetooth Accessories
Using Google Fast Pair.
You can also check if your device is vulnerable
https://whisperpair.eu/
Using Google Fast Pair.
You can also check if your device is vulnerable
https://whisperpair.eu/
whisperpair.eu
WhisperPair: Hijacking Bluetooth Accessories Using Google Fast Pair
WhisperPair is a family of practical attacks leveraging a flaw in the Google Fast Pair implementation on flagship audio accessories.
❤6🎃1