Skip to content

news.buyenne.com

Smarter is not always wiser: How we hacked a smart payment terminal

We hacked a smart POS device running Android 7. Weak boot security and unpatched exploits enabled root access and payment data theft.

We hacked a smart POS device running Android 7. Weak boot security and unpatched exploits enabled root access and payment data theft.
Author Security Research Labs BlogPosted on 16 August 2022Categories Uncategorised

Hacking mobile networks has gotten a lot more interesting with 5G and Open RAN

5G shifts security risks to the cloud. Learn how Docker misconfigurations expose telco networks and how red teaming helps keep 5G hacking resilient.

5G shifts security risks to the cloud. Learn how Docker misconfigurations expose telco networks and how red teaming helps keep 5G hacking resilient.
Author Security Research Labs BlogPosted on 8 August 2022Categories Uncategorised

Extended Android security check: SnoopSnitch tests for Java vulnerabilities

SnoopSnitch now detects missing Android Java patches. SRLabs explains how bytecode signatures double patch coverage and help close the Android patch gap.

SnoopSnitch now detects missing Android Java patches. SRLabs explains how bytecode signatures double patch coverage and help close the Android patch gap.
Author Security Research Labs BlogPosted on 12 May 2022Categories Uncategorised

Your Blockchain is only as secure as the application on top of it

SRLabs found a flaw in SocialKYC that allowed fake Twitter verifications. A three-line fix shows why blockchain apps must be reviewed as thoroughly as chains.

SRLabs found a flaw in SocialKYC that allowed fake Twitter verifications. A three-line fix shows why blockchain apps must be reviewed as thoroughly as chains.
Author Security Research Labs BlogPosted on 22 March 2022Categories Uncategorised

FlightGear 2020.3.12 released

The latest bug-fix release in our stable 2020.3 series was released today: we are up to version 2020.3.12 now.

The latest bug-fix release in our stable 2020.3 series was released today: we are up to version 2020.3.12 now.
Author FlightGear Flight SimulatorPosted on 3 February 2022Categories Uncategorised

When your phone gets sick: FluBot abuses Accessibility features to steal data

FluBot malware exploits Android Accessibility to steal banking credentials, spread via SMS, and block removal—making it today’s top mobile threat.

FluBot malware exploits Android Accessibility to steal banking credentials, spread via SMS, and block removal—making it today’s top mobile threat.
Author Security Research Labs BlogPosted on 21 December 2021Categories Uncategorised

Chaining Three Zero-Day Exploits in ITSM Software ServiceTonic for Remote Code Execution

SRLabs chained three zero-days in ServiceTonic ITSM—HQL injection, SSO flaw, and path traversal—to gain full remote code execution.

SRLabs chained three zero-days in ServiceTonic ITSM—HQL injection, SSO flaw, and path traversal—to gain full remote code execution.
Author Security Research Labs BlogPosted on 2 November 2021Categories Uncategorised

Blockchain security – Six common mistakes found in Substrate chains

SRLabs outlines six common bug classes in Substrate-based blockchains, from logic flaws to unsafe arithmetic, and how to mitigate them.

SRLabs outlines six common bug classes in Substrate-based blockchains, from logic flaws to unsafe arithmetic, and how to mitigate them.
Author Security Research Labs BlogPosted on 12 October 2021Categories Uncategorised

Blockchain security – Best practices for your next review

SRLabs shares a four-step methodology for auditing Substrate-based blockchains, combining threat modeling, design review, fuzzing, and code audits.

SRLabs shares a four-step methodology for auditing Substrate-based blockchains, combining threat modeling, design review, fuzzing, and code audits.
Author Security Research Labs BlogPosted on 27 September 2021Categories Uncategorised

Balancing long-term technology evolution with short-term side-effects – Vulnerability disclosure best practices

SRLabs shares best practices for responsible vulnerability disclosure (CVD), guiding researchers and vendors toward secure, collaborative outcomes.

SRLabs shares best practices for responsible vulnerability disclosure (CVD), guiding researchers and vendors toward secure, collaborative outcomes.
Author Security Research Labs BlogPosted on 13 September 2021Categories Uncategorised

Posts pagination

Previous page Page 1 … Page 91 Page 92 Page 93 … Page 1,732 Next page

Recent Posts

  • Ploopy’s Nano 2 is a minimal trackball mouse with a single button
  • Deals Roundup (11-04-2025)
  • MINISFORUM MS-R1 mini PC has a 12-core Arm processor and PCIe x16 slot for a dGPU
  • Apple’s next MacBook could be a budget model to compete with mid-range Windows laptops (and high-end Chromebooks)
  • Bundesnetzagentur und BSI: Antennen werden ohne Begründung zur kritischen Infrastruktur

Recent Comments

  1. A WordPress Commenter on Hello world!
news.buyenne.com Proudly powered by WordPress