August 25, 2021 at 11:39PM

■■■□□ BIG-IP application services company F5 has fixed more than a dozen high-severity vulnerabilities in its networking device, one of them being elevated to critical severity under specific conditions. https://www.bleepingcomputer.com/news/security/critical-f5-big-ip-bug-impacts-customers-in-sensitive-sectors/ https://t.me/cKure/9058

August 25, 2021 at 09:36PM

■■□□□ Mirai-style IoT botnet is now scanning for router-pwning critical vuln in Realtek kit. https://go.theregister.com/feed/www.theregister.com/2021/08/25/mirai_botnet_critical_vuln_realtek_radware/ https://t.me/cKure/9056

August 25, 2021 at 09:35PM

■■■■■ Msynth; a code deobfuscation framework to simplify Mixed Boolean-Arithmetic (MBA) expressions. Given a pre-computed simplification oracle, it walks over a complex expression represented as an abstract syntax tree (AST) and tries to simplify subtrees based on oracle lookups. Alternatively, it tries to simplify expressions via stochastic program synthesis. https://github.com/mrphrazer/msynth https://t.me/cKure/9054

August 25, 2021 at 09:29PM

■□□□□ ICYMI | Israel : Cybersecurity watchdog Citizen Lab saw the new zero-day FORCEDENTRY exploit successfully deployed against iOS versions 14.4 & 14.6, blowing past Apple’s new BlastDoor sandboxing feature to install spyware on the iPhones of Bahraini activists – even one living in London at the time. A never-before-seen, zero-click iMessaging exploit has been…

August 25, 2021 at 09:27PM

■■□□□ List of localhost addresses for SSRF bypass. http://localhost http://127.0.0.1 http://2130706433 http://0177.1 http://0x7f.1 http://127.000.000.1 http://127.0.0.1.nip .io http://[::1] http://[::] Source: Twitter | Anton https://t.me/cKure/9051

August 25, 2021 at 06:04PM

■□□□□ Cybercrime Losses Triple to £1.3bn in 1H 2021. The data comes from the National Fraud Intelligence Bureau (NFIB), which collects reports of cybercrime and fraud from Action Fraud, the UK’s national reporting center for such crimes. https://t.me/cKure/9048