April 1, 2024 at 05:21PM

■■■□□ ProxyLib: Malicious Apps Caught Secretly Turning Android Phones into Proxies for Cybercriminals. https://thehackernews.com/2024/04/malicious-apps-caught-secretly-turning.html https://t.me/cKure/13772

March 31, 2024 at 11:54PM

Inside the failed attempt to backdoor SSH globally — that got caught by chance. https://doublepulsar.com/inside-the-failed-attempt-to-backdoor-ssh-globally-that-got-caught-by-chance-bbfe628fafdd https://t.me/cKure/13768

March 31, 2024 at 11:53PM

■■■■■ forensictools: A toolkit designed for digital forensics. https://github.com/cristianzsh/forensictools?tab=readme-ov-file#download-and-usage https://securityonline.info/forensictools-a-toolkit-designed-for-digital-forensics https://t.me/cKure/13767

March 31, 2024 at 01:30PM

■■■■□ Supply-Chain attack: Red Hat on Friday released an “urgent security alert” warning that two versions of a popular data compression library called XZ Utils (previously LZMA Utils) have been backdoored with malicious code designed to allow unauthorized remote access. The software supply chain compromise, tracked as CVE-2024-3094, has a CVSS score of 10.0, indicating…

March 31, 2024 at 03:59AM

■□□□□ Signal clarifies that the bug was functional. It’s a bug in our phone number privacy+usernames implementation, fix coming soon. Hi! We’re confident this IS NOT a 0click attack. It’s a bug in our phone number privacy+usernames implementation, fix coming soon. I’ve asked OP to clarify/delete in service of minimizing harmful misinfo ❤️🙏 https://t.co/7X0BsReaXc —…