|
You are here |
truesecdev.wordpress.com | ||
| | | | |
securitylabs.datadoghq.com
|
|
| | | | | Learn how the OverlayFS vulnerability CVE-2023-0386 works, how to detect it and how to reproduce it. | |
| | | | |
blog.quarkslab.com
|
|
| | | | | The following article explains how during a Purple Team engagement we were able to identify a vulnerability in Microsoft Teams on macOS allowing us to access a user's camera and microphone. | |
| | | | |
blog.xpnsec.com
|
|
| | | | | While looking for avenues of injecting code into platform binaries back in macOS Monterey, I was able to identify a vulnerability which allowed the hijacking of Apple application entitlements. Recently I decided to revisit this vulnerability after a long time of trying to have it patched, and was surprised to see that it still works. There are some caveats introduced with later versions of macOS which we will explore, but in this post we'll look at a vulnerability in macOS Sonoma which has been around fo... | |
| | | | |
objective-see.org
|
|
| | | [AI summary] This post provides a technical analysis of OSX.DazzleSpy, a cyber-espionage macOS implant used to target pro-democracy users in Hong Kong, detailing its persistence mechanisms, remote capabilities, and detection by Objective-See's tools. | ||