jiska

@naehrdine.bsky.social

ɿɘɘniϱnɘ ɘƨɿɘvɘɿ 🎦 youtube.com/@jiskac 📝 naehrdine.blogspot.com 🐥 twitter.com/naehrdine 🎓 hpi.de/classen 📱 reversing.training

First day of #OFTW was a blast. Had fun giving a new workshop where we looked into the iOS permission ecosystem and reverse engineered an app. Looking forward to today's talks!

Photo credits: Nicole KrügerPhoto credits: Nicole KrügerPhoto credits: Nicole KrügerPhoto credits: Nicole Krüger

NEW: Apple fixed the bug that law enforcement, like the FBI, were taking advantage of to extract chat messages that had been deleted or disappeared automatically. Until now the iPhone stored deleted or disappered messages in a database, allowing authorities to access them with forensic tools.

Apple fixes bug that cops used to extract deleted chat messages from iPhones | TechCrunch

The iPhone and iPad bug allowed law enforcement using forensic tools to read messages that had long been deleted by the Signal app.

techcrunch.com

We are very happy that today Apple issued a patch and a security advisory. This comes following 404 Media reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted.

I'm reading a bunch of Coruna reports after dinner because I am a cool person who knows how to party. Of particular interest: not only does Coruna not work against iOS in lockdown mode, but if it even detects lockdown mode running, it bails. This is why I talk about lockdown mode so damn much.

The Cycle 2 deadline for the USENIX WOOT Conference is in ~ 3 weeks (March 3, 2026)! WOOT continues to include both a Systematization of Knowledge (SoK) track and an Up-and-Coming track (industry-focused). Details are available in the Call for Papers: www.usenix.org/conference/w...

WOOT '26 Call for Papers

The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...

usenix.org

Researchers tried plugging every possible phone number into WhatsApp's web app. They found they could collect 3.5 billion users' phone numbers, plus photos for half and profile text for more than a third, the biggest personal data exposure ever by some measures. www.wired.com/story/a-simp...

A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

By plugging tens of billions of phone numbers into WhatsApp’s contact discovery tool, researchers found “the most extensive exposure of phone numbers” ever—along with profile photos and more.

wired.com

Binary Ninja 5.2, Io, is live and it's out of this world! binary.ninja/2025/11/13/b... With some of our most requested features of all time including bitfield support, containers, hexagon, Ghidra import, and a huge upgrade to TTD capabilities, plus a ton more, make sure to check out the changelog!

Bild