Zuk Profile picture
Zuk
Mobile & Security Research | Founder @ZecOps (Acq. by JAMF) 🐊 & @ZIMPERIUM (Acq.) | #FreeTheSandbox✌ | ❤️ Chess | My random thoughts, only some are accurate.
Jan 19, 2023 6 tweets 2 min read
The recent WhatsApp accounts takeover is simple and genius.

This is how it works:
You're sleeping.
A "hacker" tries to login to your account via WhatsApp.
You get a text message with a pincode that says "Do not share this".

You don't share it, yet you still get hacked.

How? The attacker clicks on the option that the SMS didn't arrive and asks for a verification by phone.

WhatsApp call you. You're sleeping. It goes to Voicemail. The voicemail stores the automated voice with the pincode that the attackers are trying to obtain.
Jul 28, 2021 5 tweets 2 min read
For those who think that NSO is the problem - you're missing out the bigger picture:

1. There are many vendors like NSO, not just in Israel. Also in EU, APAC, N. America, and others.

2. Even if NSO shuts down tomorrow: we still have a problem: mobile attacks are scalable. 2. (cont) Once you have created a generic attack-chain, you can infect 1B+ devices. This is too powerful to keep a single barrier for attackers which already block telemetry sharing with the vendors.
Jul 18, 2021 8 tweets 2 min read
[Important thread 1/N]: Let that sink in for a second: almost all respected publications were under espionage.

All the sources of journalists, were exposed. If you ever spoke to a journalist (even with "Signal"/"Whatsapp") you are exposed.

THIS IS A MAJOR THREAT TO DEMOCRACY! [2/N] If we needed another proof that we have to fix the broken mobile security permission model, here it is.

NSO's software is actually super easy to catch, but due to the lack of permissions it becomes almost impossible at scale, and NSO only has a single vendor to avoid.