[{"channel_id":1164747047,"post_id":2991,"date":1791346028000,"forwards":"11","views":"509","text":"CVE-2026-23866: Finding a Whatsapp NDay<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/numb3rs.re\/posts\/cve-2026-23866-finding-a-whatsapp-nday\/\">https:\/\/numb3rs.re\/posts\/cve-2026-23866-finding-a-whatsapp-nday\/<\/a>","text_length":104,"media":{"root":null,"webpage":{"url":"https:\/\/numb3rs.re\/posts\/cve-2026-23866-finding-a-whatsapp-nday","type":"article","title":"CVE-2026-23866: Finding a Whatsapp NDay \u00b7 Numb3rs' blog","site_name":"Numb3rs' blog","display_url":"numb3rs.re\/posts\/cve-2026-23866-finding-a-whatsapp-nday","description":"Watch me trying to find a Whatsapp nDay, thanks to Meta and inline compiling it's not that easy !"}}},{"channel_id":1164747047,"post_id":2990,"date":1790866019000,"forwards":"33","views":"3.2K","comments":"1","text":"CVE-2026-86950: The Great Glyph Grift<br>An in-the-wild iOS bug with a possible WhatsApp zero-click path<br>Blog: <a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/calif.io\/research\/the-great-glyph-grift\">https:\/\/calif.io\/research\/the-great-glyph-grift<\/a> <br>PoC: <a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/github.com\/califio\/publications\/tree\/main\/MADBugs\/CVE-2026-86950\">https:\/\/github.com\/califio\/publications\/tree\/main\/MADBugs\/CVE-2026-86950<\/a>","text_length":234,"media":{"root":"\/002\/rgsAACehbEUAAAAA5Ebmij8m7ek","webpage":{"url":"https:\/\/calif.io\/research\/the-great-glyph-grift","type":"photo","title":"CVE-2026-86950: The Great Glyph Grift","site_name":"Calif","display_url":"calif.io\/research\/the-great-glyph-grift","description":"An in-the-wild iOS bug with a possible WhatsApp zero-click path.","thumbs":{"m":{"w":213,"h":320,"hash":"jXalSRdLeY99WnixJLA1yg&ts=1791400665"},"x":{"w":533,"h":800,"hash":"49i4pxjBaWFwfBfCrOomIQ&ts=1791400665"},"y":{"w":853,"h":1280,"hash":"ve8id-Jw-Wum7KVueQr_Zw&ts=1791400665"},"w":{"w":1024,"h":1536,"hash":"i6yq9eCOUbkQDYNZhK5tbQ&ts=1791400665"},"i":{"bytes":"AoABs|CvFZ+faoybVbnr3GacdMcE5lTaAST6Yq1Y4NpFntu5zjnPSrDHcH2hScOAD0PTrU3GZcenvIkbeYoEnTIqo4CSMv3sHGR3rcjACQJn5owpI9ODWHJ\/rW+ppgaNrKUgSNYgy4JJ9eev4UC6IMxMPRjj2zxUlmdtjHl8E7tvHbPSrE0QZiM4zycDqRyKQ7lY3RfAMA3E847Dg1nT8zyHIXLE49Oa11jRLx1zJuk5JI4OPSsaZt80jqThmJHHvQgNC1u4Y7RUdyGAYYx61M1\/blid\/qBwfQUUU7CIftsZ1HzDIfKAwOOlZtFFAj\/\/2Q=="}}}}},{"channel_id":1164747047,"post_id":2989,"date":1790703593000,"forwards":"37","views":"3.9K","text":"CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF \u2014 iOS\/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC) <a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/github.com\/0xjohnnydev\/CVE-2026-20687-AppleJPEGDriver-UAF\">https:\/\/github.com\/0xjohnnydev\/CVE-2026-20687-AppleJPEGDriver-UAF<\/a>","text_length":204,"media":{"root":"\/00b\/rQsAACehbEUAAAAAQNNxPm8jjjI","webpage":{"url":"https:\/\/github.com\/0xjohnnydev\/CVE-2026-20687-AppleJPEGDriver-UAF","type":"photo","title":"GitHub - 0xjohnnydev\/CVE-2026-20687-AppleJPEGDriver-UAF: CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF \u2014 iOS\/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)","site_name":"GitHub","display_url":"github.com\/0xjohnnydev\/CVE-2026-20687-AppleJPEGDriver-UAF","description":"CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF \u2014 iOS\/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC) - 0xjohnnydev\/CVE-2026-20687-AppleJPEGDriver-UAF","thumbs":{"m":{"w":320,"h":160,"hash":"8kzEqUALZ7ptOfqyrnlr8A&ts=1791400665"},"x":{"w":800,"h":400,"hash":"GQx0W_vXKrDVO6KAn-jaCA&ts=1791400665"},"y":{"w":1200,"h":600,"hash":"jaSGuJO7OnNBNQK38UGxfA&ts=1791400665"},"i":{"bytes":"AUACg|DVZyrYwT+BpDKQcY5\/3TUhBJ\/+vSYP+TQBF5knoM\/7ppzyMtuz9GA9Kfg+v60FAyFXGQeoNAFK2uJ3uVRypUrngdKKtR28UTZRApooArfbJPRf1o+2SZ6L+tFFUSH2uTHRf1o+2Sei\/lRRQAfa5OPlX8qKKKAP\/9k="}}}}},{"channel_id":1164747047,"post_id":2988,"date":1790674023000,"forwards":"56","views":"3.6K","text":"How we found 24 Android vulnerabilities using our open source AI security agent<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/github.blog\/security\/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent\">https:\/\/github.blog\/security\/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent\/<\/a>","text_length":189,"media":{"root":"\/00c\/rAsAACehbEUAAAAAevh-725R6Xc","webpage":{"url":"https:\/\/github.blog\/security\/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent","type":"photo","title":"How we found 24 Android vulnerabilities using our open source AI security agent","site_name":"The GitHub Blog","display_url":"github.blog\/security\/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent","description":"A look at the targeted AI taskflows behind these findings, the bugs they uncovered, and how to run the same open-source agent on your own app.","author":"Kevin Stubbings","thumbs":{"m":{"w":320,"h":180,"hash":"UG5nv_PwLeCaI2tfwQNwvA&ts=1791400665"},"x":{"w":800,"h":450,"hash":"RCLRL7YMlSrOzYvnthurxw&ts=1791400665"},"y":{"w":1280,"h":720,"hash":"Y7SVJB9O5WrDfVDOXkgtdg&ts=1791400665"},"w":{"w":1920,"h":1080,"hash":"c6x0XSI7fXs-zwfM0-nSxw&ts=1791400665"},"i":{"bytes":"AXACg|DWd1RSzHAFCSLIoZCCD3FQ3EfnwtHnGaLeLyIhGDkDvVWVibjphGXUsoZh0p0qLJGQ3Qjmo5YVlKkkgr0IoMmSUK546VNiX5lXYEXyW+Yt0ZR0op8LFswy4DenpRWZmlcsFwoyRkCnAhl3DpRRWz3Nb62CmTnZGWziiipkEtiFYDCC7NuYnmiiioM7WP\/Z"}}}}},{"channel_id":1164747047,"post_id":2987,"date":1790663777000,"forwards":"15","views":"3.5K","text":"From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/www.cleafy.com\/cleafy-labs\/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat\">https:\/\/www.cleafy.com\/cleafy-labs\/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat<\/a>","text_length":185,"media":{"root":"\/00c\/qwsAACehbEUAAAAAevh-725R6Xc","webpage":{"url":"https:\/\/cleafy.com\/cleafy-labs\/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat","type":"photo","title":"From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat | Cleafy","site_name":"Cleafy","display_url":"cleafy.com\/cleafy-labs\/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat","description":"Cleafy's TIR team analyzed the operator infrastructure behind RATHat, an Android banking trojan that abuses Accessibility Services to enable wireless debugging on the victim's phone, obtain a shell, and deploy a hidden native service outside the app. The investigation recovered three generations of the Chinese-language control panel, consistent with a Malware-as-a-Service model.","thumbs":{"m":{"w":320,"h":168,"hash":"TVMUwjUAF25qe9TrMW3B8g&ts=1791400665"},"x":{"w":800,"h":420,"hash":"ORMIhQX_nqscvibu3KbjcQ&ts=1791400665"},"y":{"w":1200,"h":630,"hash":"2gWy8J9Ym4j4oUalI4JtOw&ts=1791400665"},"i":{"bytes":"AVACg|DKCk9ifwpNrf3T+VTQpuXIUnnqMUx9yHDAZqiboQI390\/lRgg80olPoKQvk5oGH4UUmSe9FADaKKKAFpaKKAEooooA\/9k="}}}}},{"channel_id":1164747047,"post_id":2986,"date":1790625090000,"forwards":"86","views":"3.6K","text":"apk-reverse: An Agent Skill for Android APK reverse engineering, debloating, ad removal, surgical dex patching, repacking, and runtime\/server analysis<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/github.com\/newliver666\/apk-reverse\">https:\/\/github.com\/newliver666\/apk-reverse<\/a>","text_length":193,"media":{"root":"\/006\/qgsAACehbEUAAAAAR3fUtUy9DME","webpage":{"url":"https:\/\/github.com\/newliver666\/apk-reverse","type":"photo","title":"GitHub - newliver666\/apk-reverse: Suitable for Android APK reverse engineering analysis","site_name":"GitHub","display_url":"github.com\/newliver666\/apk-reverse","description":"Suitable for Android APK reverse engineering analysis - newliver666\/apk-reverse","thumbs":{"m":{"w":320,"h":160,"hash":"pB8Gu-5djDiPLZb05qCXxQ&ts=1791400665"},"x":{"w":800,"h":400,"hash":"a4qnZliMVrFwGsm7cKMZrA&ts=1791400665"},"y":{"w":1200,"h":600,"hash":"4ijazSRAlOkp0t4msj_w5Q&ts=1791400665"},"i":{"bytes":"AUACg|DVeUIcEr+LYpBIzfdCE+zZp5GT0FAUA8YH0FADC0uQBGCPXdUhJCk98UfjRgEYPINAEUMrOxBUD8aKl2gHOBmihgZ32+X+6n5H\/Gj7fL\/dT8j\/AI0UUxB9vl\/up+R\/xpft8v8AdT8jRRQA+K7kd8FV4HpRRRUsaP\/Z"}}}}},{"channel_id":1164747047,"post_id":2985,"date":1790581321000,"forwards":"76","views":"3.9K","comments":"2","text":"A native APK and DEX decompiler written in Rust<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/github.com\/Ch0pin\/rdx\">https:\/\/github.com\/Ch0pin\/rdx<\/a>","text_length":77,"media":{"root":"\/013\/qQsAACehbEUAAAAAyJ9xaISq-sQ","webpage":{"url":"https:\/\/github.com\/Ch0pin\/rdx","type":"photo","title":"GitHub - Ch0pin\/rdx: A native APK and DEX decompiler written in Rust","site_name":"GitHub","display_url":"github.com\/Ch0pin\/rdx","description":"A native APK and DEX decompiler written in Rust. Contribute to Ch0pin\/rdx development by creating an account on GitHub.","thumbs":{"m":{"w":320,"h":160,"hash":"r98thnnHUGlR1FN_juilbg&ts=1791400665"},"x":{"w":800,"h":400,"hash":"2S26MN6MM6ZiWet1Z6gv7A&ts=1791400665"},"y":{"w":1200,"h":600,"hash":"rryKd6xnk4kJjgwszI7JFg&ts=1791400665"},"i":{"bytes":"AUACg|DXYsDximlnxwoz6bqkooARTlRnAPpmmTMVhZk+8BxUnFBAIwelAGfaXM8s4V8FcdQuKKvqqpwoAooAr+e3oKPPb0FFFIYee3oKPtD+goooADcN6LRRRQB\/\/9k="}}}}},{"channel_id":1164747047,"post_id":2984,"date":1790577778000,"forwards":"19","views":"3.5K","text":"RemControl: AI Built the Overlays. Victims Lose their PINs<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/www.group-ib.com\/blog\/remcontrol-android-banking-trojan\">https:\/\/www.group-ib.com\/blog\/remcontrol-android-banking-trojan\/<\/a>","text_length":123,"media":{"root":"\/00e\/qAsAACehbEUAAAAAUqDopu9Vvl4","webpage":{"url":"https:\/\/group-ib.com\/blog\/remcontrol-android-banking-trojan","type":"photo","title":"RemControl: AI Built the Overlays. Victims Lose their PINs","site_name":"Group-IB","display_url":"group-ib.com\/blog\/remcontrol-android-banking-trojan","description":"Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.","thumbs":{"m":{"w":320,"h":168,"hash":"q12z-Sg2J3hnuNnZrpBN8w&ts=1791400665"},"x":{"w":800,"h":420,"hash":"C8GLNQKWiuNS0O8lGbRlag&ts=1791400665"},"y":{"w":1280,"h":672,"hash":"voOEcaCwWYeZMHuJifqHWg&ts=1791400665"},"w":{"w":1800,"h":945,"hash":"IIs2OkG3Ul15dMRK-k7GZQ&ts=1791400665"},"i":{"bytes":"AVACg|DJB4xsU\/nSEZPQD6VIE9qXZ7UrmqpkQQk4FTxRx5AkDE0mCpyOtSoNzqByTRcUoWGXIiHES4HrRTrhcHH+f88UUXDkYqyMFABOB2p6yNjrRRUnZFIaQGHSk+4cjrRRQEoq4xveiiigln\/\/2Q=="}}}}},{"channel_id":1164747047,"post_id":2983,"date":1790498789000,"forwards":"37","views":"4.2K","text":"Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL <br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/blog.nns.ee\/2026\/09\/24\/oneplus-root\/\">https:\/\/blog.nns.ee\/2026\/09\/24\/oneplus-root\/<\/a>","text_length":139,"media":{"root":"\/00e\/pwsAACehbEUAAAAAUqDopu9Vvl4","webpage":{"url":"https:\/\/blog.nns.ee\/2026\/09\/24\/oneplus-root","type":"photo","title":"Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL | nns.ee","site_name":"nns.ee","display_url":"blog.nns.ee\/2026\/09\/24\/oneplus-root","description":"Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.","thumbs":{"m":{"w":320,"h":168,"hash":"yvUe2pVfKb2qXvhkpSl86Q&ts=1791400665"},"x":{"w":800,"h":420,"hash":"mHtHXqsOgM4BuIxhw2GrTQ&ts=1791400665"},"y":{"w":1200,"h":630,"hash":"111mrzoSfPKnbrDBfF69yg&ts=1791400665"},"i":{"bytes":"AVACg|C1PerFOY92TxkelOa5ccjaQemay9QEseovKgI5GD+FTxS+cvP3u4zT5Rl9Z2aPccDnHFKJjjkj9P8AGmWYIjbGfvVZw3rStYQiOWAyp578f40UK43FN4J9KKLAQS2SSyF2ZucccUhsFK4EjqD6Yoop3YEtvAIFKhmbJ6tU1FFJgMEKht3fOaKKKYH\/2Q=="}}}}},{"channel_id":1164747047,"post_id":2982,"date":1790074916000,"forwards":"56","views":"5.6K","comments":"7","text":"Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/www.mobile-hacker.com\/2026\/09\/21\/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc\">https:\/\/www.mobile-hacker.com\/2026\/09\/21\/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc\/<\/a>","text_length":213,"media":{"root":"\/00e\/pgsAACehbEUAAAAAUqDopu9Vvl4","webpage":{"url":"https:\/\/mobile-hacker.com\/2026\/09\/21\/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc","type":"photo","title":"Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC - Mobile Hacker","site_name":"Mobile Hacker","display_url":"mobile-hacker.com\/2026\/09\/21\/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc","description":"Do you have an older rooted Android phone sitting unused in a drawer? Instead of leaving it there, you can turn it into a practical NFC reader and USB keyboard for your computer. With a custom Android app (NFC to HID), your phone can read the unique indentation (UID) of an NFC card, key fob, [\u2026]","author":"https:\/\/www.facebook.com\/profile.php?id=61589539502513","thumbs":{"m":{"w":320,"h":240,"hash":"UKUIBHBwhECaZTpYQJ7KQg&ts=1791400665"},"x":{"w":800,"h":599,"hash":"0AvcQ2cWK1zyozl3f8KlDQ&ts=1791400665"},"y":{"w":1280,"h":958,"hash":"9Ua4qGweosWlSL0YzBA3ng&ts=1791400665"},"w":{"w":1441,"h":1079,"hash":"n6XdYKy3FRz6ZNH1HjpwNQ&ts=1791400665"},"i":{"bytes":"AeACg|CcDAoSPzGbLNx2BxUDzEMRjofWp4JAASzAZUdTihNXJuI8SkHyw7nOPvHFRCNHg3+WAcGoDdyRBgkoHPbBptvPGhdpHOW7Y6+9bOKSJV2Xeo5opkbBkBB7UViaELOTI\/bnFRXWPJQZ5BPFTTxgZIZgW96ZcgCA4HSpW9xctmUaOtKOTgVMlszYO4CqGSWwdG+fIA6UVLg7dr\/N70VLGj\/\/2Q=="}}}}},{"channel_id":1164747047,"post_id":2980,"date":1789657720000,"forwards":"28","views":"6.5K","comments":"1","text":"RatHat: AI-Powered Mobile Threat is Here for Your Credentials &amp; Bank Accounts<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/zimperium.com\/blog\/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts\">https:\/\/zimperium.com\/blog\/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts<\/a>","text_length":179,"media":{"root":"\/003\/pAsAACehbEUAAAAA1NDCEbF3ae0","webpage":{"url":"https:\/\/zimperium.com\/blog\/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts","type":"photo","title":"RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts","site_name":"Zimperium","display_url":"zimperium.com\/blog\/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts","description":"true","thumbs":{"m":{"w":320,"h":175,"hash":"QQ3-ODnvaDJWy46sYMxTWA&ts=1791400665"},"x":{"w":800,"h":437,"hash":"6GZJC2VmRndqANbzUkZwqQ&ts=1791400665"},"y":{"w":1024,"h":559,"hash":"RoMwACuCj8zhgIcWF5jQpQ&ts=1791400665"},"i":{"bytes":"AWACg|DPOTEo2dOhA60nl\/LkZpdxKKv5c05Rgc1ZJHsIAJBwelL5YbgKc\/WpWfeAnYUwgr1GB6igEMB\/duu1cnHOORRTm3GPcVwOmQOtFAyMP8uAB9acXHGM0UUhCsxAwaQyZzxx9aKKEMTzB5Oz3zRRRTA\/\/9k="}}}}},{"channel_id":1164747047,"post_id":2979,"date":1789366132000,"forwards":"25","views":"7.3K","text":"Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration <br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/zimperium.com\/blog\/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration\">https:\/\/zimperium.com\/blog\/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration<\/a>","text_length":160,"media":{"root":"\/00e\/owsAACehbEUAAAAAUqDopu9Vvl4","webpage":{"url":"https:\/\/zimperium.com\/blog\/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration","type":"photo","title":"Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration","site_name":"Zimperium","display_url":"zimperium.com\/blog\/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration","description":"true","thumbs":{"m":{"w":320,"h":178,"hash":"oYaiqQTdGg3QTPT-a-INsw&ts=1791400665"},"x":{"w":800,"h":444,"hash":"CKpcQncoGJ_hmGe14iEJRA&ts=1791400665"},"y":{"w":900,"h":500,"hash":"w9dzc2kzwYgmIoTFVz1LHw&ts=1791400665"},"i":{"bytes":"AWACg|CmVZjny2GOvHAppwSSOKb5juwIP61YSQbACcEcdTVoixVJY0v8IGOateYhP38Y9z\/hTZJBsIBzn3PFMCDjZjNFR5ycHGKKLhYdEhdsDH404fxDHI5FFFJDZJvJXPekVto30UVTMxyW8bg\/MwK9eOtFFFSJyZ\/\/2Q=="}}}}},{"channel_id":1164747047,"post_id":2978,"date":1789365877000,"forwards":"18","views":"6.2K","text":"Vwork: Weaponized Open-source Software as an Addon for Gigabud<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/www.group-ib.com\/blog\/vwork-app-cloning-gigabud-goldfactory\">https:\/\/www.group-ib.com\/blog\/vwork-app-cloning-gigabud-goldfactory\/<\/a>","text_length":131,"media":{"root":"\/006\/ogsAACehbEUAAAAAR3fUtUy9DME","webpage":{"url":"https:\/\/group-ib.com\/blog\/vwork-app-cloning-gigabud-goldfactory","type":"photo","title":"Vwork: Weaponized Open-source Software as an Addon for Gigabud","site_name":"Group-IB","display_url":"group-ib.com\/blog\/vwork-app-cloning-gigabud-goldfactory","description":"How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.","thumbs":{"m":{"w":320,"h":168,"hash":"gCrdmC6Fdex4UFTn_BEeYw&ts=1791400665"},"x":{"w":800,"h":420,"hash":"m4M-2brSWzwUMPR9ecFfhg&ts=1791400665"},"y":{"w":1280,"h":672,"hash":"sSp4XCxId8j90RbJVQS3XQ&ts=1791400665"},"w":{"w":1800,"h":945,"hash":"EFLfk9cG1Ib64qB96c-Rzg&ts=1791400665"},"i":{"bytes":"AVACg|DMDgD7in86MFjwMUm04zUsZZGBJVsevQ0APjtSwBY4B\/L86ZNbtExx8wHcVZ85UCdXOclMYWmG7Byuzgn7gNMClRU8yo7uyhYgOiE8migCASsBgfzNHmn\/ACTRRSAUzEjBH6mmbuP60UUAGdxy3NFFFAH\/2Q=="}}}}},{"channel_id":1164747047,"post_id":2977,"date":1788961021000,"forwards":"54","views":"7.2K","comments":"2","text":"RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite. <br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/itis911.github.io\/writeups\/RCE-Mexc-Andriod-App.html\">https:\/\/itis911.github.io\/writeups\/RCE-Mexc-Andriod-App.html<\/a>","text_length":205},{"channel_id":1164747047,"post_id":2976,"date":1788957181000,"forwards":"43","views":"7.0K","text":"WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android<br><a target=\"_blank\" rel=\"noreferrer nofollow\" href=\"https:\/\/calif.io\/research\/weworm\">https:\/\/calif.io\/research\/weworm<\/a>","text_length":120,"media":{"root":"\/003\/oAsAACehbEUAAAAA1NDCEbF3ae0","webpage":{"url":"https:\/\/calif.io\/research\/weworm","type":"photo","title":"WeWorm","site_name":"Calif","display_url":"calif.io\/research\/weworm","description":"The first zero-click worm to spread through WeChat calls across iOS and Android.","thumbs":{"m":{"w":215,"h":320,"hash":"p_XZOdQjeSFEXOaf0xTxSg&ts=1791400665"},"x":{"w":537,"h":800,"hash":"RZ5n3YPQFv2rSiJTr39umw&ts=1791400665"},"y":{"w":848,"h":1264,"hash":"kbPAubTUsKoL8BB02vXbPQ&ts=1791400665"},"i":{"bytes":"AoABs|BkjOrPhjwT3pizy\/xNz3GelTTwsxfGOSe9VXwpLlDk8E1kjaV9LFpJO7FvwNX4ipjBA4+prJjOQPQ9K1LdWEC8GkN2aKZ8xpJQm3aWIPXt+FNZMKd+PoKlCDzZGXcBuOT69aY0ckj54EfY0NCUmQIVV1UkAVsRN+7GDxWWJIogQBk\/3uoNXbOQm1Qk88\/zNUkS3caZPLU4Q4JzwM0w3L4x5LkZ9KKKVwIpLqYsdsMgz9cDrVi3YGEF02nJ4x05+lFFUSf\/2Q=="}}}}}]