shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

243
active users

#projectzero

0 posts0 participants0 posts today

I’m looking for a feed that aggregates recent reverse engineering and vulnerability centric security writeups, like the ones posted by Google project zero. I know there are many different security firms and academics that post these kind of articles now and then, but I’m having a hard time with discovery as every news site or feed I find is focused on cybersecurity threats and CVEs, or simply just malware actor reports.

Does anyone have something that fits the bill?
#reverseengineering #googleprojectzero #projectzero #vulnerability #vulnerability_research

Google has removed a video posted by academic researchers demonstrating how a newly discovered side channel in Apple's A- and M-series CPUs can be used to steal a password.

I thought for sure the removal was a mistake, but a Google representative told me the video was removed for violating a term of service barring "demonstrating how to use computers or information technology to steal credentials, compromise personal data, or cause serious harm to others."

The video, demonstrating important research by @genkin, @YuvalYarom , @themadstephan and jason kim, is here:

onedrive.live.com/?authkey=%21

Just to underscore how arbitrary and patently asinine Google's ToS enforcement is here, two additional videos the researchers posted demonstrating the same side channel remain available.

I wonder how researchers from #projectzero feel about this. Is there any chance any of them can intervene?

onedrive.live.comOneDrive

#Google tells users of some #Android phones: Nuke voice calling to avoid infection | #ArsTechnica

“Tests conducted by #ProjectZero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim's phone number.
With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational #exploit to #compromise affected devices silently and remotely.”

arstechnica.com/information-te

Ars TechnicaGoogle tells users of some Android phones: Nuke voice calling to avoid infectionIf your device runs Exynos chips, be very, very concerned.

In a blog post, Google’s #ProjectZero head #TimWillis said the in-house security researchers found and reported 18 #ZeroDay vulnerabilities in #Exynos modems produced by #Samsung over the past few months, including four top-severity flaws that could compromise affected devices “silently and remotely” over the cellular network."

#Google warns users to take action to protect against remotely exploitable flaws in popular #Android | #Mobile | TechCrunch
techcrunch.com/2023/03/16/goog

TechCrunchGoogle warns users to take action to protect against remotely exploitable flaws in popular Android phonesThe four vulnerabilities found in Samsung chips can be exploited to compromise Android devices "silently and remotely" over the cell network.

New by me at Forbes: The security research supremos over at Project Zero have uncovered no less than 18 zero-days impacting the Samsung Exynos modem chipset. That's bad right? Even worse, four of them, including CVE-2023-24033, enable internat-to-baseband level remote code execution. Silently and with zero user interaction. That's *really* bad.

Even worse, yeah, sorry, these were disclosed to Samsung more than 90 days ago, and no public patch is available yet - hence the Project Zero disclosure now.

Recommendations for affected users awaiting patches (Google Pixel 6 and 7 series were impacted but patched in the March security update) are advised to disable both Wi-Fi calling and VoLTE as a matter of urgency.

#infosec #samsung #google #projectzero #zeroday #tech #news

forbes.com/sites/daveywinder/2

ForbesNew Samsung 0-Click Security Threat Alert, Disable Wi-Fi Calling NowBy Davey Winder

Bueno, nueva instancia nueva #introduccion jajajajaja
Hola me podéis llamar Tory, mi hobby favorito son los videojuegos en especial los hack n slash y los survival horror aunque también me gustan muchos los simuladores tranquilitos, también me gusta mucho leer ya sea mangas o libros sobretodo fantasía y tengo una perrita llamada Brownie, en mi perfil tenéis mi Steam, mi usuario en Xbox y mi código amigo de Switch por si alguien quiere agregarme y jugar a algo, soy muy malo pero lo compenso riéndome mucho
#videojuegos
#DevilMayCry
#Bayonetta
#ResidentEvil
#ProjectZero
#Yakuza
#libros
#TerryPratchett
#BrandonSanderson
#ONEPIECE
#Fantasia
#terror