Today we published WeWorm, our zero-click worm that spreads across iOS and Android.
All it takes is one phone call. You don't have to answer. Seconds later, your WeChat account is compromised, calling your friends and spreading the attack.
We reported the bug to Tencent, and
Just dropped new research and some dope artwork from Lukas Maar and @lcamtuf: OEMpocalypse Now!
Check it out: calif.io/research/oempo…
While you’re there, take a look at our new research homepage, designed by yours truly: calif.io/research
OK, I lied. Claude designed it.
Gathering some random thoughts as I prepare for a talk on AI-powered vulnerability research.
Whether you like AI or not, vulnerability research has become an entirely new game, which requires powerful tools to stay competitive. If you can't access those tools where you are, you
BREAKING: agents training on Google servers have gone rogue and created a secret messaging board, which they quickly deprecated in favor of Swarm+, deprecated in favor of SwarmChat, deprecated in favor of Swarm Hangouts
youtube.com/live/KlUJmsg2u…
In our inaugural "Meet the Hackers" episode, we hosted the GOAT of browser exploitation, Samuel Groß @5aelo. For the second episode, we are excited to host the GOAT of iOS exploitation: Brandon Azad @_bazad. Like Samuel, Brandon needs no introduction. If