Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
10 résultats taggé phone  ✕
CVE-2025-47188: Mitel Phone Unauthenticated RCE https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/
23/07/2025 20:59:06
QRCode
archive.org

Mitel phone firmware analysis lead to the discovery of two vulnerabilities (CVE-2025-47187 & CVE-2025-47188). Exploiting them leads to unauthenticated code execution on the phone itself.

While on an internal attack simulation engagement, a customer asked us: “Is an attacker able to listen in on our meeting room conversations?”. Motivated by this question, we scanned their internal network and discovered Mitel VoIP phone web management interfaces.

While playing around with the login functionality of the management interface, we accidentally rediscovered CVE-2020-13617 on our own - and since the phone firmware was old enough, it allowed us to leak memory in the failed login response. While we didn’t have enough time to analyze the phone during this engagement, my interest in the phone and its firmware did not vanish.

As part of the R&D team at InfoGuard Labs, I decided to take a closer look at the phone as a research project. This lead to the discovery of two new vulnerabilities:

CVE-2025-47188: Unauthenticated command injection vulnerability
CVE-2025-47187: Unauthenticated .wav file upload vulnerability
These vulnerabilities are present in Mitel 6800 Series, 6900 Series and 6900w Series SIP Phones, including the 6970 Conference Unit with firmware version R6.4.0.SP4 and earlier. Mitel has published the MISA-2025-0004 security advisory informing about these vulnerabilities, the affected devices as well as remediation measures.

infoguard.ch 2025 EN Mitel phone firmware CVE-2025-47187 CVE-2025-47188 vulnerabilty
FBI Gains Access to Suspected Trump Shooter’s Password Locked Phone https://www.404media.co/fbi-gains-access-to-suspected-trump-shooters-password-locked-phone/
17/07/2024 09:02:49
QRCode
archive.org
thumbnail

The FBI announced on Monday it had successfully gained access to the phone used by Thomas Matthew Crooks, the suspected shooter in the attempted assassination of former President Donald Trump.

404media EN 2024 cracked phone FBI US Password-Locked
Twilio says hackers identified cell phone numbers of two-factor app Authy users https://techcrunch.com/2024/07/03/twilio-says-hackers-identified-cell-phone-numbers-of-two-factor-app-authy-users/
04/07/2024 07:19:36
QRCode
archive.org
thumbnail

Twilio says "threat actors were able to identify" phone numbers of people who use the two-factor app Authy.

techcrunch EN 2024 Twilio phone numbers Authy data-leak
Marketing Company Claims That It Actually Is Listening to Your Phone and Smart Speakers to Target Ads https://www.404media.co/cmg-cox-media-actually-listening-to-phones-smartspeakers-for-ads-marketing/
16/12/2023 10:12:20
QRCode
archive.org
thumbnail

A marketing team within media giant Cox Media Group (CMG) claims it has the capability to listen to ambient conversations of consumers through embedded microphones in smartphones, smart TVs, and other devices to gather data and use it to target ads, according to a review of CMG marketing materials by 404 Media and details from a pitch given to an outside marketing professional. Called “Active Listening,” CMG claims the capability can identify potential customers “based on casual conversations in real time.”

404media EN 2023 marketing CMG Cox-Media-Group Listening Phone privacy
The $2,000 Phones that Let Anyone Make Robocalls https://www.404media.co/buy-fraud-phone-russiancoms-robocalls/
14/11/2023 15:33:46
QRCode
archive.org
thumbnail

Videos collected by 404 Media over months give a peep inside the world of spoofing numbers, automated call scripts, and a specific seller of the phones.

404media EN 2023 vishing robocalls phone scammers
Attacker combines phone, email lures into believable, complex attack chain https://news.sophos.com/en-us/2023/08/10/image-spam-attack/
13/09/2023 21:44:02
QRCode
archive.org
thumbnail

A social engineering phone call lends authenticity to the attacker’s malicious email

sophos EN 2023 switzerland phone email lures phishing
LetMeSpy, a phone tracking app spying on thousands, says it was hacked https://techcrunch.com/2023/06/27/letmespy-hacked-spyware-thousands/
27/06/2023 20:35:22
QRCode
archive.org
thumbnail

A data breach reveals the spyware is built by a Polish developer

techcrunch EN 2023 LetMeSpy phone spyware hacked databreach
Dump these Cisco phone adapters because it's not fixing them https://www.theregister.com/2023/05/05/cisco_phone_adapter_vulnerabilitty/
08/05/2023 07:16:38
QRCode
archive.org
thumbnail

There is a critical security flaw in a Cisco phone adapter, and the business technology giant says the only step to take is dumping the hardware and migrating to new kit.

In an advisory, Cisco this week warned about the vulnerability in the SPA112 2-Port Adapter that, if exploited, could allow a remote attacker to essentially take control of a compromised device by seizing full privileges and executing arbitrary code.

The flaw, tracked as CVE-2023-20126, is rated as "critical," with a base score o

theregister EN 2023 Cisco CVE-2023-20126 SPA112 2-Port phone adaptor
WhatsApp data leak: 500 million user records for sale https://cybernews.com/news/whatsapp-data-leak/
26/11/2022 11:29:36
QRCode
archive.org

Someone is allegedly selling up-to-date mobile phone numbers of nearly 500 million WhatsApp users. A data sample investigated by Cybernews likely confirms this to be true.

cybernews WhatsApp EN 2022 leak phone numbers
Liz Truss's personal phone was hacked by Putin's spies for top messages | Daily Mail Online https://www.dailymail.co.uk/news/article-11368619/Liz-Trusss-personal-phone-hacked-Putins-spies-secret-details-negotiations.html
31/10/2022 21:43:58
QRCode
archive.org

One source said that the phone was so heavily compromised that it has now been placed in a locked safe inside a secure Government location.

dailymail EN 2022 Truss phone compromised spy Russia England Government
4712 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio