@zzt Most feature phones are hard to compromise because every time a malware author learns something about how they work, their brains explode.
Reverse Engineering The Philips PM5139
https://hackaday.com/2026/09/09/reverse-engineering-the-philips-pm5139/
CVE ID: CVE-2026-20079
Vendor: Cisco
Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20079
CVE ID: CVE-2026-87491
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87491
High level diff of iOS 27 beta8 vs. iOS 27 RC 🎉
https://github.com/blacktop/ipsw-diffs/tree/main/27_0_24A5430a_vs_27_0_24A435/README.md
Earlier this month, @volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).
Read the full analysis of the exploit chain and post-exploitation tradecraft here: https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
Â
#DFIR #threatintel
RE: https://mstdn.social/@jukkan/117240247968300759
I just love this:
”Feature #23 is worth noting in isolation. LinkedIn collects the user’s Do Not Track preference, then excludes it from the fingerprint hash (line 9512, excludes: { doNotTrack: true }). They record that you asked not to be tracked. Then they track you.”
Edit: resolved
Hey, I am an old school vanilla JS person and want to learn what frontend frameworks do people use these days.
Are there any statistics I could look into? Not looking for engineering advice or suggestions what to use.
I hope to get a better understanding of the engineering practices & workflows and security needs to ensure that our security work in web standards can actually land with the users.
Edit: Specifically, I am interested how people modify/insert HTML :)
Secret Panel HERE đź§ https://patreon.com/mrlovenstein/posts/mind-body-84972760