April 23, 2022 at 11:38PM

Zero-Day in Java: A researcher has released proof-of-concept (PoC) code for a digital signature bypass vulnerability in Java. CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server. https://github.com/khalednassar/CVE-2022-21449-TLS-PoC https://t.me/cKure/11252

April 23, 2022 at 10:21PM

■■■■■ Runtime Mobile Security (RMS) – is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime. https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security https://t.me/cKure/11251

April 23, 2022 at 08:03PM

■■■■■ No Hardware, No Problem: Emulation and Exploitation – A walkthrough on emulating upnpd from a NETGEAR device and exploring a rediscovered stack buffer overflow. https://blog.grimm-co.com/2022/04/no-hardware-no-problem-emulation-and.html https://t.me/cKure/11249

April 23, 2022 at 12:48PM

■■■■□ Zero-Day: Atlassian fixes critical Jira authentication bypass vulnerability. The flaw is tracked as CVE-2022-0540 and comes with a severity rating of 9.9. https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html https://www.bleepingcomputer.com/news/security/atlassian-fixes-critical-jira-authentication-bypass-vulnerability/ https://t.me/cKure/11246

April 23, 2022 at 12:47PM

■■□□□ Data-Leak: T-Mobile confirms Lapsus$ hackers breached internal systems. Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code. In the wake of the August 2021 breach, T-Mobile unsuccessfully tried to stop the stolen data from being leaked online after paying the hackers $270,000 through a third-party firm, per a VICE report. https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/ https://www.bleepingcomputer.com/news/security/t-mobile-confirms-lapsus-hackers-breached-internal-systems/ https://t.me/cKure/11245

April 22, 2022 at 06:37PM

■■□□□ Unpatched vulnerability in the RainLoop webmail client, tracked as CVE-2022-29360, that can be exploited to steal users’ emails. https://securityaffairs.co/wordpress/130488/hacking/unpatched-xss-rainloop.html https://t.me/cKure/11243