/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Matt Suiche

@msuiche
35 posts
2023-09-09
Given that the name is “BLASTPASS” and the target is iMessage, I assume this means that this the first zero click exploit caught which includes a BlastDoor sandbox bypass introduced in iOS 14 2021. 🥲
2023-09-09 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

2023-09-08
Given that the name is “BLASTPASS” and the target is iMessage, I assume this means that this the first zero click exploit caught which includes a BlastDoor sandbox bypass introduced in iOS 14 2021. 🥲
2023-09-08 View on X
The Record

Apple releases macOS, iOS, iPadOS, and watchOS updates to address two zero-day flaws that Citizen Lab says were used to deliver NSO Group's Pegasus spyware

Apple released software updates on Thursday to address two zero-day vulnerabilities that researchers said were used …

2023-05-09
That's really good news and sets a fair use precedent for everyone in the industry. https://twitter.com/...
2023-05-09 View on X
Bloomberg Law

A US appeals court upholds a lower court's 2019 ruling rejecting Apple's claims that Corellium's CORSEC security tool for simulating iOS violated copyright law

2023-04-15
Who needs the Russians when you have insiders like this. 🙄 https://twitter.com/...
2023-04-15 View on X
Associated Press

Court docs: the FBI used Discord billing records to help identify Jack Teixeira, the Air National guardsman who allegedly leaked classified Pentagon documents

A Massachusetts Air National Guardsman accused in the leak of highly classified military documents appeared in court Friday …

2022-11-14
FTX infrastructure may have been compromise. Unclear if it's the mobile apps or the websites or both categories. USD $386M + USD $84M syphoned to the two following wallets: 0x59abf3837fa962d6853b4cc0a19513aa031fd 32b 0xd8019a114e86ad41D71a3EeB6620b19Dd166A 969 https://twitter.com/...
2022-11-14 View on X
CoinDesk

The Securities Commission of The Bahamas says it didn't order FTX to reopen withdrawals for Bahamas-based customers, refuting FTX's statement

Nikhilesh De / CoinDesk :

2022-11-13
FTX infrastructure may have been compromise. Unclear if it's the mobile apps or the websites or both categories. USD $386M + USD $84M syphoned to the two following wallets: 0x59abf3837fa962d6853b4cc0a19513aa031fd 32b 0xd8019a114e86ad41D71a3EeB6620b19Dd166A 969 https://twitter.com/...
2022-11-13 View on X
CoinDesk

FTX claims the company was hacked, telling users to delete FTX apps, not install app updates, and not to visit FTX.com, after $600M+ in crypto left its wallets

trustless, permissionless, uncensorable crypto—is the only path forward for the future. This week, we grieved. Next week, we build. @cz_binance : What a sh!t show... And it's going...

FTX infrastructure may have been compromise. Unclear if it's the mobile apps or the websites or both categories. USD $386M + USD $84M syphoned to the two following wallets: 0x59abf3837fa962d6853b4cc0a19513aa031fd 32b 0xd8019a114e86ad41D71a3EeB6620b19Dd166A 969 https://twitter.com/...
2022-11-13 View on X
CoinDesk

The Securities Commission of The Bahamas says it didn't order FTX to reopen withdrawals for Bahamas-based customers, refuting FTX's statement

FTX said last week it had allowed Bahamas-based customers to withdraw funds at its regulators' request.  —  Crypto exchange FTX was not required …

2022-11-12
FTX infrastructure may have been compromise. Unclear if it's the mobile apps or the websites or both categories. USD $386M + USD $84M syphoned to the two following wallets: 0x59abf3837fa962d6853b4cc0a19513aa031fd 32b 0xd8019a114e86ad41D71a3EeB6620b19Dd166A 969 https://twitter.com/...
2022-11-12 View on X
CoinDesk

FTX claims it has been hacked, and instructs users not to install new upgrades or go to FTX.com and to delete FTX apps, after $600M+ in crypto left FTX wallets

FTX officials appeared to confirm rumors of a hack on Telegram, instructing users to delete FTX apps and avoid its website.

2022-10-20
ads everywhere. Blocking ads will become the number #1 use case of VPNs https://twitter.com/...
2022-10-20 View on X
Financial Times

Uber launches a global advertising unit, targeting $1B in annual gross ad bookings by 2024, including by displaying ads within its apps and on top of cars

Dave Lee / Financial Times :

2022-10-13
Is there any use cases for SMS outside of 2FA codes? Or there are still people who still use them to communicate? https://twitter.com/...
2022-10-13 View on X
BleepingComputer

Signal plans to phase out SMS and MMS support from its Android app; users have “several months to transition away from SMS” and export messages to another app

Signal says it will start to phase out SMS and MMS message support from its Android app to streamline the user experience and prioritize security and privacy.

2022-08-14
Does anyone know if there are security researchers who broke this already? Given how long it takes for vulnerabilities to be fixed and disclosed, how relevant is such a feature when we have no visibility on if/how many bug submissions Apple received for this? https://twitter.com/...
2022-08-14 View on X
TechCrunch

Hands-on with iOS 16's Lockdown Mode, which aims to protect against highly targeted attacks by disabling link previews in messages, limiting FaceTime, and more

journalists, activists, and human rights defenders — against zero-click government spyware. https://techcrunch.com/... Kevin Collier / @kevincollier : This is to protect against NS...

2022-08-13
Does anyone know if there are security researchers who broke this already? Given how long it takes for vulnerabilities to be fixed and disclosed, how relevant is such a feature when we have no visibility on if/how many bug submissions Apple received for this? https://twitter.com/...
2022-08-13 View on X
TechCrunch

Hands-on with iOS 16's Lockdown Mode, which aims to protect against highly targeted attacks by disabling link previews in messages, limiting FaceTime, and more

Here's what the new spyware-busting security feature does, and why it might just work  —  Lockdown Mode is a new Apple feature you should hope you'll never need to use. Tweets: @za...

2022-08-06
Who knew the UX person for Pegasus worked on Winamp before https://twitter.com/...
2022-08-06 View on X
Haaretz

A prototype of NSO's Pegasus for Israeli police in 2014 reveals the UI and features, including real-time wiretapping, reading texts, and remote camera control

Omer Benjakob / Haaretz :

2022-08-05
Who knew the UX person for Pegasus worked on Winamp before https://twitter.com/...
2022-08-05 View on X
Haaretz

A prototype of NSO's Pegasus for Israeli police in 2014 shows the UI and features, including real-time wiretapping, reading messages, and remote camera control

Israel Police planned to present cabinet with the system eight years ago.  It was intended to be capable of turning the infected phone …

2022-04-25
Only 14 unauthenticated remotely exploitable bugs in Oracle Blockchain Platform... 🙈🙉🙊 Oracle Critical Patch Update Advisory - April 2022 https://www.oracle.com/...
2022-04-25 View on X
Ars Technica

Oracle patches a critical bug in Java 15 and above, which lets attackers forge TLS certificates and signatures, two-factor authentication messages, and more

A failure to sanity check signatures for division-by-zero flaws makes forgeries easy.  —  Organizations using newer versions …

2022-04-20
“Chromium had a record high number of 0-days detected and disclosed in 2021 with 14. Out of these 14, 10 were renderer remote code execution bugs, 2 were sandbox escapes, 1 was an infoleak, and 1 was used to open a webpage in Android apps other than Google Chrome.” #crypto 🙊 https://twitter.com/...
2022-04-20 View on X
Project Zero

Google's Project Zero: 58 in-the-wild 0-days were detected and shared in 2021, more than double the previous record, as the industry improves at finding 0-days

A Year in Review of 0-days Used In-the-Wild in 2021  —  This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019].

2022-04-07
Just saw that Certik raised $88M - do they have a product? ngl everytime I hear people talking about them they seem to be very critical. https://www.theblockcrypto.com/ ...
2022-04-07 View on X
TechCrunch

Blockchain audit service CertiK raises an $88M Series B3 led by Insight, Tiger Global and Advent at a $2B valuation, bringing its total funding to $230M

CertiK, a Web3 and blockchain security company, has raised $88 million in its latest round, bringing its valuation to $2 billion.

2022-03-25
Good to see that web3 scammers are starting to fall. They give a bad name to the industry in general, a good reason on why it's important to speak out on dodgy actors. 🍿 https://twitter.com/...
2022-03-25 View on X
The Verge

The DOJ arrests and charges two men with wire fraud and money laundering over an alleged $1.1M NFT rug pull scheme for their collection of 8,888 “Frosties”

They'd already announced a follow-up series  —  US government prosecutors have charged two men with fraud and money laundering …

2022-02-21
Incident Response seen by a web3 lense. Bookmarking it for later. https://twitter.com/...
2022-02-21 View on X
CoinDesk

OpenSea says 32 users had NFTs stolen as part of a targeted phishing campaign that scammed them into signing malicious smart contracts

Emails purporting to be from the NFT marketplace about a planned smart contract migration may have been a phishing attack. Source: @dfinzer , @opensea , and @xanderatallah .

2021-11-17
https://github.blog/... “Second, on November 2 we received a report to our security bug bounty program of a vulnerability that would allow an attacker to publish new versions of any npm package using an account without proper authorization.” Thanks @ryanaraine for sharing
2021-11-17 View on X
BleepingComputer

GitHub fixes major security flaws in Node.js package manager npm that could have let attackers bypass authentication and publish versions of any package