Blasting Past Webp

An analysis of the NSO BLASTPASS iMessage exploit Posted by Ian Beer, Google Project Zero On September 7, 2023 Apple issued  an out-...

When Marnus casually picked up a 5-fer in the @[email protected] 🤯

Only ONE day to go for #Blast25 general sale! 🎟️

You can also get your season #BlastPass 🔗 https://bit.ly/3CABLo5

#OhGlammyGlammy

CM Tickets

We agree, Doully. High-quality shot from a high-quality player. 👊

3️⃣ days to go for the #Blast25 General Sale 🎟️

You can also get your season #BlastPass 🔗 https://bit.ly/3CABLo5

#OhGlammyGlammy

CM Tickets

What is your ALL-TIME Glamorgan @[email protected] XI?

Only 4️⃣ days to go before #Blast25 tickets are on General Sale 🎟️

You can also get your Glamorgan #BlastPass NOW 🔗 https://bit.ly/3CABLo5

#OhGlammyGlammy

CM Tickets

𝙏𝙃𝘼𝙏 Kiran Carlson innings at @[email protected] in the @[email protected] 🔥

6️⃣ days to go for the #Blast25 General Sale 🎟️

You can also get your season #BlastPass 🔗 https://bit.ly/3CABLo5

#OhGlammyGlammy

CM Tickets

India targets Apple over its phone hacking notifications

Apple’s warnings to users that it had detected possible efforts to install spyware on iPhones triggered an angry reaction from Indian officials.

The Washington Post

Looking for some help, my company might not be able to fully patch CVE-2023-4863 aka BLASTPASS for a few days. Does anyone know a way of detecting exploitation of this through Splunk? Can you see it in web server logs? Next-gen firewall? WAF? I’m not seeing much info online about how to detect the exploitation.

#libwebp #cve20234863 #blastpass #splunk #siem

Good Morning, story so far on the next log4j level #vulnerability #CVE20234863 #CVE20235129
#0day #Chrome #iOS

  • libwebp library is vulnerable to heap overflow and can lead to RCE.
  • Apple assigned #CVE202341064 and #CVE202341061. Also actively exploited by #blastpass
  • #Google assigned #CVE20235129 for Chrome 0day and also exploited
  • Millions of apps and software use this library. See list sofar in 🧵
  • #CVE20235129 was rejected by NVD earlier due to all this confusion of several vendors assigning CVEs affecting their products
  • This will lead to vulnerability scanners not being able to correctly identify if your assets are affected with libwebp. #infosec #sectoot
iPhone Pegasus "Zeroclick" Exploits & UK Online Safety Bill Passed

PeerTube
@ant0inet @marcel @citizenlab
I guess we will all remember the term #BLASTPASS ... like we do #log4j