Recon

RECON

Updated 4m ago
High-Signal Security Intelligence

2026-01-14

Fortinet Threat Research Blog105 · 2026-01-14 14:00

New Remcos Campaign Distributed Through Fake Shipping Document

FortiGuard Labs analyzes a phishing campaign delivering a fileless Remcos RAT via malicious Word templates, CVE-2017-11882 exploitation, and in-memory execution.
Project Zero67 · 2026-01-14 17:59

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user. One such feature is audio transcription. Incoming SMS and RCS audio attachments received by Google Messages are now automatically decoded with no user interaction. As a result,...
Project Zero65 · 2026-01-14 18:00

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using my DriverCartographer tool, I discovered an interesting device driver, /dev/bigwave that was accessibl...
Project Zero55 · 2026-01-14 18:01

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and exploiting these vulnerabilities highlighted some broader issues in the Android ecosystem. This post describes the problems we encountered and recommendations for improvement. Audio Attack Surface The Dolby UDC is part of the 0-click attack surface of most Android devices because of audio transcription in ...
OpenAI Blog27 · 2026-01-14 14:00

OpenAI partners with Cerebras

OpenAI partners with Cerebras to add 750MW of high-speed AI compute, reducing inference latency and making ChatGPT faster for real-time AI workloads.
[DRAGNET]12 · 2026-01-14 08:00

Sicarii Ransomware: Truth vs Myth

Sicarii Ransomware: Truth vs Myth    Check Point Research
NOSEC 安全讯息平台 - 漏洞预警8 · 2026-01-14 11:07

【漏洞预警】MindsDB /api/sql/query 未授权访问漏洞(CVE-...

漏洞名称:MindsDB /api/sql/query 未授权访问漏洞(CVE-2025-68472)风险等级:高风险漏洞描述:MindsDB&n...
[DRAGNET]5 · 2026-01-14 08:00

Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware

Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware    The Hacker News