First day of #OFTW was a blast. Had fun giving a new workshop where we looked into the iOS permission ecosystem and reverse engineered an app. Looking forward to today's talks!
jiska
@naehrdine.bsky.social
ɿɘɘniϱnɘ ɘƨɿɘvɘɿ 🎦 youtube.com/@jiskac 📝 naehrdine.blogspot.com 🐥 twitter.com/naehrdine 🎓 hpi.de/classen 📱 reversing.training
Gesetzentwurf in weiten Teilen ein „Wünsch-dir-was“ der Geheimdienste: #Staatstrojaner & #Hackback und keine Berichte mehr www.lto.de/recht/hinter...
Mehr Befugnisse, weniger Kontrolle für die Geheimdienste
Sollte der BMI-Entwurf Wirklichkeit werden, erfüllen sich die Wünsche der Geheimdienstler – zulasten des Datenschutzes. Verfassungsbeschwerden garantiert.
lto.de
How do the closed-source parts of Apple's Private Cloud Compute work? We had a look at it 🍎👀 Paper: dl.acm.org/doi/abs/10.1... Slides: hpi.de/fileadmin/us...
Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence | Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks
dl.acm.org
@blackhoodie.bsky.social will be back at @reconmtl.bsky.social this year 😱😻✨ Jane Tangen and Amna K Moon will be teaching an Introduction to x86 Reverse Engineering! We're delighted to be hosted at the Montreal Google offices! blackhoodie.re/Recon2026/
Blackhoodie at Recon 2026
We are looking forward to hosting another Blackhoodie training at Recon for 2026! We will be hosting a free, one day training for women, by women.Join us for an introduction to Ghidra and static analy...
blackhoodie.re
NEW: Apple fixed the bug that law enforcement, like the FBI, were taking advantage of to extract chat messages that had been deleted or disappeared automatically. Until now the iPhone stored deleted or disappered messages in a database, allowing authorities to access them with forensic tools.
Apple fixes bug that cops used to extract deleted chat messages from iPhones | TechCrunch
The iPhone and iPad bug allowed law enforcement using forensic tools to read messages that had long been deleted by the Signal app.
techcrunch.com
We are very happy that today Apple issued a patch and a security advisory. This comes following 404 Media reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted.
2 years ago I did a PoC to run #rust 🦀 in the #pixel modem Today it shipped in millions of devices! They grow up to fast! 🥲 security.googleblog.com/2026/04/brin... #rust #security #smartphone #baseband
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been f...
security.googleblog.com
I'm reading a bunch of Coruna reports after dinner because I am a cool person who knows how to party. Of particular interest: not only does Coruna not work against iOS in lockdown mode, but if it even detects lockdown mode running, it bails. This is why I talk about lockdown mode so damn much.
Here we go again with iCloud photo scanning. www.macrumors.com/2026/02/19/a...
Apple Sued by West Virginia for Allegedly Allowing CSAM Distribution Through iCloud
West Virginia's Attorney General JB McCuskey today announced a lawsuit against Apple, accusing the company of knowingly allowing iCloud to be used to distribute and store child sexual abuse material (...
macrumors.com
Google's Pixel 10 supports Apple's AirDrop protocol. Curious about how they did this? Let's take a look! youtu.be/qBsNoa0FOPw
[0x12] Reversing Shorts :: AirDrop on Android?!
YouTube video by jiska
youtu.be
Google's Pixel 10 supports Apple's AirDrop protocol. Curious about how they did this? Let's take a look! youtu.be/qBsNoa0FOPw
[0x12] Reversing Shorts :: AirDrop on Android?!
YouTube video by jiska
youtu.be
The Cycle 2 deadline for the USENIX WOOT Conference is in ~ 3 weeks (March 3, 2026)! WOOT continues to include both a Systematization of Knowledge (SoK) track and an Up-and-Coming track (industry-focused). Details are available in the Call for Papers: www.usenix.org/conference/w...
WOOT '26 Call for Papers
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
usenix.org
In this video, I'm analyzing a really confusing dialog on macOS. Let's dig a bit deeper into what it should do and what it's actually doing. #reverseengineering youtu.be/P7hYg2GpsTk
[0x11] Reversing Shorts :: macOS "Private" Window Picker
YouTube video by jiska
youtu.be
In this video, I'm analyzing a really confusing dialog on macOS. Let's dig a bit deeper into what it should do and what it's actually doing. #reverseengineering youtu.be/P7hYg2GpsTk
[0x11] Reversing Shorts :: macOS "Private" Window Picker
YouTube video by jiska
youtu.be
Last weekend, Telekom changed their network name from "Telekom.de" to "Im besten Netz." 📶 Curious about how they did this? Will more ad campaigns follow? And what can you do to change it back? More details in this video: youtu.be/-PchHdFhl5M
YouTube
Share your videos with friends, family, and the world
youtu.be
The new AirTags 2 just arrived! Time to take them apart 🧵
Don't miss out on Jiska Classen's - @naehrdine.bsky.social - training on "Practical iOS Reverse Engineering" at #OffensiveCon26 Find more details here🔗https://buff.ly/psTxdyG
I reverse engineered DexProtector, the security solution protecting applications like Revolut and other banking apps. From custom ELF loaders to vtable hooking, here is an insight into how these protections work and their limitations. www.romainthomas.fr/post/26-01-d...
A Glimpse Into DexProtector | Romain Thomas
This blog post provides a high-level overview of DexProtector's security features and their limitations
romainthomas.fr
Want to know how Apple's Low Latency WiFi works? Today, 3:40pm CET, Hall 1, #39c3. More details: events.ccc.de/congress/202... Stream: streaming.media.ccc.de/39c3/one
[39c3] Cracking open what makes Apple's Low-Latency WiFi so fast
Apple's Continuity features make up a big part of their walled garden. From AirDrop and Handoff to AirPlay, they all connect macOS and iOS devices wirelessly. In recent years, security researchers hav...
events.ccc.de
In 2026, Jiska Classen - @naehrdine.bsky.social - returns to OffensiveCon with a training on "Practical iOS Reverse Engineering". More details here🔗https://buff.ly/psTxdyG 🚀 Don't miss this chance to improve your skills—sign up now!
This is Limburg BE, not NL - though they are pretty close. www.bsides-limburg.be/home
Home
• 13/03/2026 • • CORDA CAMPUS, HASSELT • Friday 13th
bsides-limburg.be
Save the date! @blackhoodie.bsky.social will be at BSides Limburg next year, on March 13th our dear Paula will teach a reverse engineering and binary exploitation training 🥳🥳🥳 Thanks so much for hosting y'all ❤️
Using a Pixel with GrapheneOS that features Inactivity Reboot, MTE, and more? — You must be a drug dealer. 🚨
Researchers tried plugging every possible phone number into WhatsApp's web app. They found they could collect 3.5 billion users' phone numbers, plus photos for half and profile text for more than a third, the biggest personal data exposure ever by some measures. www.wired.com/story/a-simp...
A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
By plugging tens of billions of phone numbers into WhatsApp’s contact discovery tool, researchers found “the most extensive exposure of phone numbers” ever—along with profile photos and more.
wired.com
Binary Ninja 5.2, Io, is live and it's out of this world! binary.ninja/2025/11/13/b... With some of our most requested features of all time including bitfield support, containers, hexagon, Ghidra import, and a huge upgrade to TTD capabilities, plus a ton more, make sure to check out the changelog!
USENIX WOOT Conference 2026: two submission deadlines this year! - Cycle 1: December 12, 2025 *only one month away* ! - Cycle 2: March 3, 2026 WOOT still has a SoK track and an "Up-and-coming track" (~Industry), CFP for details: www.usenix.org/conference/w...
Dein erster Congress und pures Chaos? Die Chaospat:innen sind für dich da. Melde dich bis zum 25. November. Willkommen sind alle, die den #39c3 offener und vielfältiger machen wollen! events.ccc.de/2025/11/10/3...
Dein erster Congress? Die Chaospat:innen sind für dich auf dem 39C3 da!
Auch in diesem Jahr sind die Chaospat:innen wieder beim Chaos Communication Congress in Hamburg am Start! Interessierte Mentor:innen und Mentees können sich bis zum 25. November 2025 um 23:59 Uhr…
events.ccc.de
I just published the slides of my #OBTS v8.0 talk about Apple's #C1 baseband. Our C1 #binja loader is now available on GitHub, and you can find a recording on YouTube. lukasarnold.de/posts/obtsv8...
OBTS v8.0: Diving into C1
Learn more about my talk “What’s at the Bottom of the Sea, One Baseband? - Diving into the C1” at eight edition of the Objective by the Sea conference.
lukasarnold.de