Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

May 23, 2023

ChatGPT Plugins: Data Exfiltration via Images & Cross Plugin Request Forgery

Plugins can return malicious content and hijack your AI.

Apple fixes three new zero-days exploited to hack iPhones, Macs

Apple has addressed three new zero-day vulnerabilities exploited in attacks to hack into iPhones, Macs, and iPads.

File Archiver In The Browser

This article explores a phishing technique that emulates a file archiver software in the browser while using a .zip domain.

What if we had the SockPuppet vulnerability in iOS 16?

The next post in our XNU memory safety series examines how our hardened kernel allocator performs in the real world against a previously patched but powerful UAF software vulnerability. In this detailed analysis, we find out what might happen if SockPuppet were to meet kalloc_type in iOS 16.

Don't @ Me: URL Obfuscation Through Schema Abuse

Attackers are distributing malware using a technique that abuses the URL schema.