/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Bill Marczak

@billmarczak
36 posts
2025-03-01
@AmnestyTech Also, Android apparently doesn't have a USB restricted mode equivalent? You can just rawdog the entire set of Kernel drivers from the USB port by default?! Yikes.
2025-03-01 View on X
TechCrunch

Amnesty International says Google has fixed three zero-day vulnerabilities in Android, developed by Cellebrite and used by Serbia to unlock phones

Amnesty International said that Google fixed previously unknown flaws in Android that allowed authorities to unlock phones using forensic tools.

Interesting - @AmnestyTech found some cases where confiscated Android phones were unlocked with Cellebrite's forensics tech, and shared traces with Google TAG, who identified three bugs in various Linux kernel USB device drivers https://securitylab.amnesty.org/ ...
2025-03-01 View on X
TechCrunch

Amnesty International says Google has fixed three zero-day vulnerabilities in Android, developed by Cellebrite and used by Serbia to unlock phones

Amnesty International said that Google fixed previously unknown flaws in Android that allowed authorities to unlock phones using forensic tools.

2024-11-20
Interesting, but how is this data gathered at sufficient scale? Is there like “one popular app” that we ~all use that's screwing us, or is this a bunch of EOL Android devices, or a “long tail” of junky apps, or something else? https://x.com/...
2024-11-20 View on X
Wired

An investigation reveals how phone coordinates collected by US data broker Datastream expose the movements of US military and intelligence workers in Germany

More than 3 billion phone coordinates collected by a US data broker expose the detailed movements of US military and intelligence workers …

2023-09-09
We refer to the exploit as BLASTPASS, as it employed a PassKit (Wallet) attachment containing a malicious image, sent via iMessage. When the phone processed the attachment, the exploit hijacked control of Apple's “BlastDoor” framework for iMessage security.
2023-09-09 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

Today, Apple released iOS 16.6.1, patching two vulnerabilities exploited by BLASTPASS in Wallet (CVE-2023-41061) and ImageIO (CVE-2023-41064) so update your iPhones! Also, if you're at risk because of who you are or what you do, please enable Lockdown Mode https://support.apple.com/...
2023-09-09 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

NEW: Last week, we @citizenlab captured a “zero-click” exploit used to install Pegasus on the latest version of iOS, 16.6. The exploit installed Pegasus without any interaction from the victim, and was virtually invisible https://citizenlab.ca/...
2023-09-09 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

2023-09-08
NEW: Last week, we @citizenlab captured a “zero-click” exploit used to install Pegasus on the latest version of iOS, 16.6. The exploit installed Pegasus without any interaction from the victim, and was virtually invisible https://citizenlab.ca/...
2023-09-08 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

Apple released software updates on Thursday to address two zero-day vulnerabilities that researchers said were used …

We refer to the exploit as BLASTPASS, as it employed a PassKit (Wallet) attachment containing a malicious image, sent via iMessage. When the phone processed the attachment, the exploit hijacked control of Apple's “BlastDoor” framework for iMessage security.
2023-09-08 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

Apple released software updates on Thursday to address two zero-day vulnerabilities that researchers said were used …

Today, Apple released iOS 16.6.1, patching two vulnerabilities exploited by BLASTPASS in Wallet (CVE-2023-41061) and ImageIO (CVE-2023-41064) so update your iPhones! Also, if you're at risk because of who you are or what you do, please enable Lockdown Mode https://support.apple.com/...
2023-09-08 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

Apple released software updates on Thursday to address two zero-day vulnerabilities that researchers said were used …

2023-06-23
Kaspersky has managed to capture the main component of #Triangulation's iOS spyware! The spyware has a modular architecture, so the main component doesn't seem to do much besides orchestration and comms, but definitely a fun look for malware researchers! https://securelist.com/...
2023-06-23 View on X
BleepingComputer

Apple patches three zero-days in macOS, iOS, iPadOS, and watchOS, exploited by the Triangulation iMessage spyware reported by Kaspersky earlier in June 2023

https://www.macrumors.com/... Twitter: Daniel Monastersky / @identidadrobada : Apple fixes software flaws behind hacks that Russia blamed on the United States - The Washington Post...

Wow... Kaspersky apparently managed to obtain an iOS kernel exploit from the #Triangulation attack! Just patched as CVE-2023-32434 in iOS 16.5.1. That's pretty much “as good as it gets” in terms of capturing an exploit chain. https://support.apple.com/...
2023-06-23 View on X
BleepingComputer

Apple patches three zero-days in macOS, iOS, iPadOS, and watchOS, exploited by the Triangulation iMessage spyware reported by Kaspersky earlier in June 2023

https://www.macrumors.com/... Twitter: Daniel Monastersky / @identidadrobada : Apple fixes software flaws behind hacks that Russia blamed on the United States - The Washington Post...

2023-06-22
Wow... Kaspersky apparently managed to obtain an iOS kernel exploit from the #Triangulation attack! Just patched as CVE-2023-32434 in iOS 16.5.1. That's pretty much “as good as it gets” in terms of capturing an exploit chain. https://support.apple.com/...
2023-06-22 View on X
BleepingComputer

Apple patches three zero-days in macOS, iOS, iPadOS, and watchOS, exploited by the Triangulation iMessage spyware reported by Kaspersky earlier in June 2023

Apple addressed three new zero-day vulnerabilities exploited in attacks installing Triangulation spyware on iPhones via iMessage zero-click exploits.

Kaspersky has managed to capture the main component of #Triangulation's iOS spyware! The spyware has a modular architecture, so the main component doesn't seem to do much besides orchestration and comms, but definitely a fun look for malware researchers! https://securelist.com/...
2023-06-22 View on X
BleepingComputer

Apple patches three zero-days in macOS, iOS, iPadOS, and watchOS, exploited by the Triangulation iMessage spyware reported by Kaspersky earlier in June 2023

Apple addressed three new zero-day vulnerabilities exploited in attacks installing Triangulation spyware on iPhones via iMessage zero-click exploits.

2023-05-25
Good to keep in mind the many use cases of spyware (and surveillance tools in general) aside from “crime and terrorism,” which are the surveillance industry's stated targets. Here's another interesting use case: spyware in armed conflict (via @accessnow) https://www.accessnow.org/...
2023-05-25 View on X
Access Now

Pegasus was used in the Azerbaijan-Armenia conflict to target a government worker, a UN official, and others in 2021 and 2022, the first known use in a war

The Armenia spyware victims include a former Human Rights Defender of the Republic of Armenia (the Ombudsperson) …

2023-04-12
We worked jointly on this report with the amazing folks at @MsftSecIntel, who shared samples of QuaDream's spyware with us. Read Microsoft's report here: https://www.microsoft.com/.... Thanks also to @AccessNow and other partners that assisted with this research!
2023-04-12 View on X
TechCrunch

Citizen Lab and Microsoft detail mercenary spyware from Tel Aviv-based QuaDream used to hack iOS 14-based iPhones of journalists, politicians, and an NGO worker

why didn't Apple warn us? Wall Street Journal : New Spyware Firm Said to Have Helped Hack iPhones Around the Globe Phil Muncaster / Infosecurity : New Zero-Click iOS Exploit Deploy...

Check out our NEW @citizenlab report “Sweet QuaDreams: A First Look at Spyware Vendor QuaDream's Exploits, Victims, and Customers”, in which we uncover traces of a new iOS 14 zero-click deployed against civil society from (at least) Jan through Nov 2021 https://citizenlab.ca/...
2023-04-12 View on X
TechCrunch

Citizen Lab and Microsoft detail mercenary spyware from Tel Aviv-based QuaDream used to hack iOS 14-based iPhones of journalists, politicians, and an NGO worker

why didn't Apple warn us? Wall Street Journal : New Spyware Firm Said to Have Helped Hack iPhones Around the Globe Phil Muncaster / Infosecurity : New Zero-Click iOS Exploit Deploy...

2022-09-29
The CIA network reportedly consisted of benign looking websites with a hidden communications functionality, used by assets around the world to communicate back and forth with their agency handlers. https://twitter.com/...
2022-09-29 View on X
Reuters

An investigation shows the CIA failed to secure its messaging system used by Iranian spies, often hidden within websites, leading to capture, torture, and death

The spy was minutes from leaving Iran when he was nabbed.  —  Gholamreza Hosseini was at Imam Khomeini Airport in Tehran in late 2010, preparing for a flight to Bangkok.

NEW REPORT today from @Reuters @JoelSchectman providing more detail about fatal flaws in the CIA's defunct communications network. Iran and China compromised the network in 2011, and killed dozens of CIA assets https://www.reuters.com/...
2022-09-29 View on X
Reuters

An investigation shows the CIA failed to secure its messaging system used by Iranian spies, often hidden within websites, leading to capture, torture, and death

The spy was minutes from leaving Iran when he was nabbed.  —  Gholamreza Hosseini was at Imam Khomeini Airport in Tehran in late 2010, preparing for a flight to Bangkok.

2022-05-02
Spain's Govt discovers a suspected case of foreign espionage w/ NSO Group's Pegasus spyware against the PM and Defense Minister. Looks like more awkwardness from NSO selling Pegasus both to EU govs, and also to foreign govs spying on those same EU govs. https://apnews.com/...
2022-05-02 View on X
The Guardian

Spain says its PM's and defense minister's phones were infected by NSO's Pegasus spyware in 2021, which will be investigated by Spain's highest criminal court

Minister for presidency says ‘illicit’ targeting will be investigated by Spain's highest criminal court

2021-07-19
@AmnestyTech (1) @AmnestyTech saw an iOS 14.6 device hacked with a zero-click iMessage exploit to install Pegasus. We at @citizenlab also saw 14.6 device hacked with a zero-click iMessage exploit to install Pegasus. All this indicates that NSO Group can break into the latest iPhones.
2021-07-19 View on X
@billmarczak

[Thread] Amnesty International and Citizen Lab found zero-click iMessage exploits being deployed against iPhones, even with iOS 14.6, to install malware

THREAD with a couple of interesting bits from @AmnestyTech's new report on what they learned from looking for NSO Group's spyware on phones https://www.amnesty.org/...