#GoogleVRP, #iVerify & #Lookout on Wednesday jointly revealed their discovery of a sophisticated iPhone hacking technique, they named #DarkSword, that use #WateringHoleAttack to hack into iOS devices the moment user visit an infected website.

🔗 https://www.wired.com/story/hundreds-of-millions-of-iphones-can-be-hacked-with-a-new-tool-found-in-the-wild/

Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

WIRED
Google's Enhanced Vulnerability Reward Program: A 2024 Milestone

Explore Google's revamped Vulnerability Reward Program in 2024, boosting rewards and launching new initiatives to enhance cybersecurity.

The DefendOps Diaries
Google Cloud launches new Vulnerability Rewards Program | Google Cloud Blog

Google Cloud Blog
Bypassing authorization in Google Cloud Workstations [Google VRP]

This write-up is a part of a series of write-ups about the bugs I and Sreeram found in Google Cloud in 2022. While exploring Google Cloud, we came across Cloud Workstations, which provide IDEs such as Code-OSS, IntelliJ etc., that are hosted in your GCP project. I deployed a workstation

Sivanesh Ashok