Android ART JNI In-the-Wild Vulnerability: Bypassing Class Checks to Instantiate Abstract Classes/Interfaces, Leading to Potential Crashes and Privilege Escalation.
medium.com/p/analysis-report…#Android#cybersec#JNI
🎉 LUCKY DRAW – DAY 2 PRIZES ARE HERE! 🎁
From exclusive cyber security access to adorable panda merch and smart gadgets — you won’t want to miss today’s rewards!
Day 1 at #CYDES2025!
We are showcasing our latest mobile phone forensics product here. We welcome technical discussions and collaboration.
📍 Putrajaya International Convention Centre (PICC)
🔍 Booth: 139
Our researcher Slim (@HBh25Y) shared at @offbyoneconf:
The Forgotten Treasure in Classic Targets: Despite powerful fuzzers like AFLplusplus & syzkaller, recent vulnerabilities show secrets lie deep in the code. Manual audits on Linux kernel & mobile decoders reveal many high-value vulnerabilities. #CyberSecurity#FuzzTesting#offbyone2024
Two topics presented by Numen Cyber employees at the #SINCON2024 conference: "Bug Bounty Hunting for ChromeOS Kernel Vulnerability" and "Chrome V8 Sandbox Bypass".
@frust93717815
@hackyzh
🌟 As the New Year arrives, we extend our warmest wishes to every friend who follows us. May 2024 bring you boundless success and happiness! We will continue our commitment to providing excellent cybersecurity services and products to safeguard your digital world. Thank you for your support, and let's welcome the brand new year together! 🎉
#HappyNewYear#Cybersecurity#InfiniteFuture
The Numen security team discovered that @Ledger’s @Ledgerhq/connect-kit module has been implanted with malicious phishing code, and that a large number of dapps integrate this functionality, with no clear statistics on the list of affected dapps, which is extremely wide-ranging.
#web3#connect-kit #Security#numencybermedium.com/@numencyberlabs/w…
📢 Today at the MOSEC(@MosecOfficial) conference hosted by PanGu Lab and POC Security , our security researchers showcased technical achievements during the BaiJiuCon session! 🔍
After we make issue1378239 public to show how to bypass the latest v8 sbx ,we also finished CVE-2023-21674-ALPC exploit which can be used to escape chrome sbx. we poped up cmd with system privilege from untrust process.
📱 Additionally, we played an oob crash in mobile and we will make IT public when time permits.
Thanks to all participants for the support. Looking forward to more security exchanges in the future! 🤝
#MOSEC2023#Security#NumenCyber#web3Security