tgindex
InfoSecTube
@InfoSecTubeВидеоанглийский

Subscribe to this channel if… you enjoy fun and educational videos about technology & CyberSecurity & ... YouTube Channel: http://youtube.com/c/InfoSecTube Contact: t.me/InfoSecTube?direct @InfoSecTube_Bot

Последний пост
7 авг.
Последнее чтение
08:33
Постов за неделю
0
Всего постов
84
Тип
открытый
Язык
английский
Категория
Видео
В каталоге с
13 авг.
Подписчики
1 762
+11 за 5 дн.
Сутки
+3
+0,17%
Неделя
 
Месяц
 
Просмотров на пост
313
40 постов
Вовлечённость
17,8%
к подписчикам
Постов в день
0,0
всего 84
Упоминаний
0
каналов
Охват размещения
оценка
1/24сутки в ленте
314
1/48двое суток
359
1/72трое суток
388

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • InfoSecTube pinned «Android apps are isolated from each other for security. One app cannot simply read another app’s memory or directly access protected services. 🔒 But then how does an app use your camera, fingerprint sensor, Wi-Fi, or Android Keystore? 📷👆📶🔐 That is where…»

  • Android apps are isolated from each other for security. One app cannot simply read another app’s memory or directly access protected services. 🔒 But then how does an app use your camera, fingerprint sensor, Wi-Fi, or Android Keystore? 📷👆📶🔐 That is where IPC—and especially Android Binder—comes in. 🔄 In this video, I explain: ✅ What a process is ✅ Why Android isolates apps ✅ How IPC lets isolated processes communicate ✅ How Android Binder connects apps to system services ✅ How Binder identifies the calling app through its UID and PID ✅ Where permissions and SELinux fit into the process ✅ How insecure IPC interfaces can become attack surfaces 🛡 We also look at IPC from a security researcher’s perspective: what could happen if a service trusts the wrong caller, accepts malicious input, or exposes operations it should keep private? 🔍 By the end, you will understand how Android apps communicate—and why Binder is one of the most important parts of Android security. 🧠 🎬 Watch the full breakdown: https://www.youtube.com/watch?v=WC0gWRVWKvs 👍 Like, share, and subscribe to support InfoSecTube! 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us #AndroidSecurity, #AndroidBinder, #IPC, #Cybersecurity, #EthicalHacking, #MobileSecurity, #AndroidHacking

  • InfoSecTube pinned «🚨 OpenAI’s AI Escaped Its Sandbox—and Reached Hugging Face! This sounds like science fiction, but it happened during a real cybersecurity evaluation. While solving an exploitation benchmark, advanced AI models discovered an unintended route outside their sandbox…»

  • 🚨 OpenAI’s AI Escaped Its Sandbox—and Reached Hugging Face! This sounds like science fiction, but it happened during a real cybersecurity evaluation. While solving an exploitation benchmark, advanced AI models discovered an unintended route outside their sandbox, gained internet access, and reached Hugging Face’s production infrastructure. 🤖💥 In this video, we explore: 🔹 How the AI escaped its sandbox 🔹 Why a package proxy became the escape route 🔹 How the incident reached Hugging Face 🔹 Why datasets can behave like untrusted software 🔹 Why traditional authorization is insufficient for AI agents 🔹 How execution firewalls could prevent similar incidents 🔹 The most important lessons for developers and security teams The AI did not “turn evil.” It simply found a path that helped complete its objective—and that may be the most concerning part. 🎬 Watch the full breakdown: https://youtu.be/9jpHQhRyRKA What do you think: Are today’s security controls ready for autonomous AI agents? 👇 👍 Like, share, and subscribe to support InfoSecTube! 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us #AISecurity #OpenAI #HuggingFace #Cybersecurity #AIAgents #SandboxEscape #LLMSecurity #EthicalHacking #InfoSecTube

  • 🛡 How do Android apps communicate without sharing memory? When you unlock a banking app with your fingerprint, multiple isolated processes must communicate with Android system services, the Keystore, and secure hardware—all within milliseconds. But if these processes cannot access each other’s memory, how do they exchange information safely? 🤔 In this new InfoSecTube video, you’ll learn: 🔹 What a process is 🔹 Why Android isolates processes 🔹 How memory isolation protects sensitive data 🔹 What Inter-Process Communication (IPC) means 🔹 How IPC creates a controlled bridge between processes 🔹 Why IPC is essential for understanding Android Binder security This is Part 1 of our Android IPC and Binder security series. More technical and practical videos are coming soon! 🔥 🎥 Watch the full video: https://youtu.be/vekFAsHfnUc 🚀 Support InfoSecTube: https://t.me/boost/infosectube #AndroidSecurity #AndroidIPC #AndroidBinder #Cybersecurity #EthicalHacking #MobileSecurity #ReverseEngineering #InfoSecTube

  • Kimi kimi is one of the strongest AIs recently introduced. 🤖 It has a feature that allows you to get a premium subscription ranging from 3 days to 1 year. ⏳ All you need to do is sign up with a new email to try your luck. ✉️ ▪️Sign up link 🔗 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • ⚔️ Android 17: The Quantum Warrior Awakens Quantum computers could eventually break many of today’s encryption systems. So how is Android preparing for the post-quantum era? In this new video, we explore: 🔐 Android 17’s quantum-resistant security direction 🧬 Post-quantum cryptography and why it matters 📱 How future Android devices may protect your sensitive data ⚠️ The security challenges developers and users should understand The battle for the future of encryption has already begun. ▶️ Watch now: Link 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us #Android17 #PostQuantumCryptography #QuantumComputing #CyberSecurity #AndroidSecurity #Encryption #InfoSec #InfoSecTube

  • 🚀 NEW VIDEO — HOW LLMs GENERATE TEXT What happens inside an AI after you submit a prompt? In Lesson 2 of AI Security 101, we explain: 🧩 What tokens are 🧠 How attention and embeddings work ⚙️ What model parameters represent 📊 How an LLM predicts its next token 🎲 Greedy decoding vs sampling 🌡 Temperature and top-p 🔐 Why the generation pipeline matters for AI security This lesson gives you the foundation needed to understand prompt injection, jailbreaks, and practical LLM security. 🎬 Watch now: https://youtu.be/uTOZLk3tIhg 🎯 @InfoSecTube 📌 YouTube Channel: Link 📢 Telegram Channel: https://t.me/InfoSecTube 🎁 Boost InfoSecTube: https://t.me/boost/infosectube #AISecurity #LLMSecurity #LargeLanguageModels #Cybersecurity #InfoSecTube #infosec_tube

  • InfoSecTube pinned «🚀 New Video: AI Security 101 — Neural Networks & LLMs Before learning how to hack or secure AI systems, you need to understand how they actually work. In this video, you’ll learn: 🧠 How neural networks learn ⚖️ What weights and biases do 🔄 How backpropagation…»

  • 🚀 New Video: AI Security 101 — Neural Networks & LLMs Before learning how to hack or secure AI systems, you need to understand how they actually work. In this video, you’ll learn: 🧠 How neural networks learn ⚖️ What weights and biases do 🔄 How backpropagation works 🤖 How large language models predict text 🏗 Encoder, decoder, and encoder-decoder architectures 🔐 Why these concepts matter for AI security This is the first step toward understanding prompt injection, hallucinations, LLM vulnerabilities, and AI agents. 🎬 Watch now: Link 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us #InfoSecTube #infosec_tube #AISecurity #LLMSecurity #NeuralNetworks #LargeLanguageModels #Cybersecurity #MachineLearning #ArtificialIntelligence

  • 🎯 What is a Supply Chain Attack? A Supply Chain Attack compromises a trusted vendor or library to reach the actual target. SolarWinds hit 18,000+ orgs. MOVEit hit 2,500+. Log4Shell hit millions of Java apps. One vendor = thousands of victims. 🔍 How it works: 1. Attacker compromises a trusted vendor 2. Injects malicious code into a legitimate update 3. Victim installs "trusted" software 4. Backdoor deployed → lateral movement 5. Cascade effect across all customers Common Attack Surfaces: - Software vendors (SolarWinds, Kaseya) - Open source libraries (npm, PyPI, Maven) - CI/CD pipelines (Codecov) - Container images (3CX) - MSPs and IT providers Famous Cases: - SolarWinds (2020) — 18,000+ orgs - MOVEit (2023) — 2,500+ orgs - Log4Shell (2021) — millions of Java apps - Kaseya (2021) — 1,500+ MSPs ⚠️ Why dangerous: - Bypasses defenses (trusted software) - Massive blast radius - Hard to detect - 10x cost vs direct attack 💡 Defense: - SBOM — know your dependencies - SLSA — secure build framework - Sigstore — sign and verify packages - SCA tools — Snyk, Dependabot - Vendor audits — SOC 2, SIG - Zero Trust — assume compromise - Network segmentation 💡 Bottom line: You are only as secure as your weakest vendor. Every modern app has hundreds of dependencies. Verify everything. #SupplyChainAttack #CyberSecurity #InfoSec #SBOM #ZeroTrust #InfoSecTube 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • - Email security gateway — block malicious links - Web proxy / TLS inspection — analyze traffic - DNS sinkholing — block C2 callbacks - Behavioral detection — exploit kit behaviors - HIPS / System call filtering — block shellcode - Memory protections: - MFA on email — prevent account-driven downloads - Backup strategy — 3-2-1 immutable backups - Incident response plan — exploit detected, isolate fast - Honeypot / canary — detect early intrusion ⚠️ Critical Insight: Exploit kits now target browsers directly (no plugins). Chrome, Edge, Firefox, Safari have all had 0-day chains. Patching within 14 days is the absolute minimum. Browser isolation is the gold standard for high-risk users. Ad blockers eliminate 80%+ of risk from legitimate sites. 🚨 The 2024 Reality: Exploit kits target unpatched browsers and Office (per Microsoft 2024). Malvertising is the #1 drive-by vector (50%+ of attacks). Mobile drive-by is rising (targeting Chrome on Android). WebAssembly cryptominers are extremely common. Compromised ad networks (Taboola, Outbrain) deliver malware. Supply chain watering holes (CDN compromise) hit thousands of sites at once. ⚠️ The Truth: Just visiting a site is dangerous in 2024. Watering-hole attacks, malvertising, and supply chain compromises (CDN, plugin) affect legitimate sites daily. Browser isolation + ad blocker + patches + EDR is the modern minimum. Zero-trust browsing is the future. #DriveBy #Malvertising #ExploitKit #CyberSecurity #InfoSec #BrowserSecurity #InfoSecTube 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • 🎯 What is a Drive-By Download Attack? A Drive-By Download Attack infects a victim's device with malware without any user action — no clicks, no file execution, just visiting a website. Modern versions leverage 0-day browser exploits, malicious ads (malvertising), compromised CDNs, and watering-hole attacks. They target unpatched browsers, plugins, and OS components. This is the #1 malware delivery method for ransomware, RATs, and cryptominers. 🔍 How it works: 1. 🎯 Attacker compromises website or injects malicious ad 2. 🌐 Victim visits legitimate (or spoofed) site 3. 💥 Exploit kit profiles browser/plugins/OS version 4. 💉 Delivers targeted exploit (Flash, Java, browser, OS) 5. 📥 Downloads and executes malware silently 6. 🕵️ Persistence established — RAT, ransomware, miner Attack Chain: Compromised Site / Malvertising ↓ Exploit Kit Landing Page (RIG, Magnitude, Fallout, Spelevo, etc.) ↓ Browser/Plugin Fingerprinting ↓ Vulnerability Selection (CVE-2024-...) ↓ Exploit Delivery (JavaScript, Flash, browser) ↓ Payload Drop (PE, HTA, MSI, JS) ↓ Execution / Persistence / C2 Common Exploit Kit Tactics: Tactic | Mechanism Browser exploits | Chrome, Firefox, Edge, Safari 0-days Plugin exploits | Flash (legacy), Java (legacy), Office OS exploits | Win32k, PrintNightmare, kernel bugs Office exploits | Macros, OLE, equation editor, Follina Media exploits | Codec vulnerabilities, image parsers Font exploits | GDI+, Win32k font rendering Browser extensions | Malicious ad blockers, VPNs, AI tools WebAssembly | WASM cryptominers, obfuscation Service workers | Persistent cache, push notifications Exploit Kit History: Kit | Era | Notable Blackhole | 2010-2013 | Most popular ever Phoenix | 2013-2014 | EKE lead Angler | 2013-2016 | Pioneered 0-days Neutrino | 2013-2017 | Cheap, effective Magnitude | 2014-2018 | Asian markets RIG | 2014-2022 | Long-running Fallout | 2018-2020 | Modern era Spelevo | 2019-2020 | Banking focus Cobalt Strike | Still active | Adversary simulation Underminer | 2019-2021 | Hidden Bee KaiXin | 2018-2020 | Asia-Pacific Disdain | 2020+ | Modern EK PS5Bot/PS5Miner | 2020+ | Gaming focus Famous Real-World Cases: - Yahoo (2013-2014) — malvertising on Yahoo.com - Spotify (2016) — malvertising redirect - The New York Times (2009) — malvertising via NYTimes.com - BBC (2010) — fake BBC banner ads - MSN.com (2018) — malvertising on MSN - Equifax-like watering hole (2017) — watering hole, A9 - Darkhotel — hotel Wi-Fi watering hole in Asia - Hacking Team (2015) — watering hole via Flash 0-day - Voatz (2019) — election voting app breach - CCleaner (2017) — supply chain compromise - HandBrake mirror (2017) — 3-day supply chain breach - ASUS Live Update (2018) — supply chain — 1M+ victims - Apple Xcode* (2015 — XcodeGhost) — iOS malware ⚠️ Why it's dangerous: – Zero user action — just visit the site – Trust exploitation — victims browse legitimate sites – Massive reach — millions of daily visitors – Persistence — survives browser close – Drops ransomware/RATs — full compromise – Hard to detect — looks like normal browsing 💡 Defense Tips: - Keep browsers patched — auto-update enabled: - Keep OS patched — Monthly Patch Tuesday: - Uninstall legacy plugins: - Browser isolation — sandbox rendering: - Reputation-based URL filtering: - Ad blockers — reduce malvertising: - Script blockers — control JavaScript: - EDR with browser exploit detection: - DNS-layer security: - Network protection / NGFW: - Email link sandboxing — before click: - Application allowlisting: - Browser sandbox — Chrome, Edge sandbox: - Disabling risky features: - Site isolation — Chromium feature: - MITRE ATT&CK coverage: - Patch management — within 14 days of CVEs - Virtual patching — WAF / IPS for unpatched systems - Threat intelligence — known exploit kit TTP - Security awareness training — recognize malicious redirects - Disable autorun for removable media - Restricted browsing on critical systems - Network segmentation — browsing in DMZ - Vulnerability management program — proactive - Browser hardening baselines:

  • iPad Pro M5 11" & Apple Pencil Pro Unboxing Link 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • 🎯 What is Front-Running? Front-Running in blockchain is when a malicious actor observes a pending transaction in the mempool and pays higher gas fees to get their own transaction processed first. It's the on-chain version of insider trading, where attackers exploit the transparent nature of public blockchains to profit from others' trades. This is particularly rampant in DeFi, NFT launches, and MEV (Maximal Extractable Value) extraction. 🔍 How it works: 1. 📝 User submits a transaction (e.g., large swap on Uniswap). 2. 👀 Transaction sits in the mempool (waiting area, public). 3. 🤖 Bots scan the mempool for profitable opportunities. 4. 🔍 Bot finds a large buy order → price will go up. 5. ⛽ Bot submits same transaction with higher gas. 6. 🏃 Bot's transaction is processed first. 7. 📈 Bot buys before the user's transaction. 8. 📊 User's transaction executes → price rises. 9. 💰 Bot immediately sells → takes the profit. 10. 💸 User gets worse price (slippage). Common Attack Types: • Displacement — replace victim's transaction • Insertion — sandwich victim's tx with buy/sell • Suppression — block victim's transaction • Replay — copy profitable transactions • Time-bandit — rewrite recent blocks • Back-running — profit from same block MEV (Maximal Extractable Value): MEV refers to the maximum value a miner/validator/sequencer can extract by reordering, inserting, or censoring transactions within blocks. It's a multi-billion dollar industry: • Arbitrage — DEX price differences • Liquidations — protocol liquidations • Sandwich attacks — front-run + back-run • NFT sniping — rare NFT mint snipes • Uncle-bandit attacks — competing for blocks Real Examples: • Mev3th.eth (2024) — millions in MEV extracted • Sandwich bots* — billions yearly • Flashbots* — formalized MEV extraction • Bancor attack (2022) — $23M front-run vulnerability • PancakeSwap sniper bots — hundreds daily • NFT mint snipes — millions in gas wars ⚠️ Why it's dangerous: – Users get worse prices (slippage) – Funds extracted from regular traders – Network congestion (gas wars) – Reduces DeFi fairness – Ethereum gas price spikes – Centralization of validators 💡 Defense Tips: – Private mempools — Flashbots Protect, MEV-Blocker – Slippage limits — set tight tolerance – Commit-reveal schemes — hide trade details – Batch auctions — CoW Protocol, MEV-resistant DEXes • Threshold encryption — encrypt transactions before inclusion • Use MEV-aware RPC endpoints — Flashbots • Submarine sends — delayed transaction reveal • Randomized gas fees — less predictable ordering • L2 solutions — different sequencing models • Use limit orders — avoid market orders • Avoid large visible trades — split into smaller orders • Time-sensitive transactions — off-peak hours • Trusted oracles — reduce front-running opportunities • Slippage protection — DEX aggregators • MEV-Share — users capture their MEV #FrontRunning #MEV #DeFi #Web3 #CryptoSecurity #Blockchain #InfoSec #SandwichAttack #InfoSecTube #Web3Security 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • 📝 #مقاله یک روش برای generative future video modeling معرفی می‌کند؛ یعنی مدلی که با دیدن چند فریم گذشته، چند آینده محتمل را پیش‌بینی کند. ایده اصلی این است که به‌جای نمایش هر فریم با تعداد زیادی توکن فضایی، تغییر بین دو فریم پیاپی را فقط با یک توکن دلتا نمایش بدهیم. این توکن‌ساز DeltaTok نام دارد و مدل نهایی DeltaWorld است. 🤖🎬 مدل‌های پیش‌بینی آینده معمولاً دو مشکل دارند: یا discriminative هستند و فقط یک آینده میانگین‌شده تولید می‌کنند، یا اگر مولد باشند، مثل diffusion یا autoregressive video models، بسیار پرهزینه‌اند و برای هر نمونه آینده به چندین forward pass نیاز دارند. مقاله می‌گوید در کاربردهایی مثل خودرو خودران 🚗، یک پیش‌بینی واحد کافی نیست، چون آینده چندین حالت ممکن دارد. ایده DeltaTok به‌جای فشرده‌کردن کل فریم، فقط تفاوت ویژگی‌های دو فریم پیاپی را فشرده می‌کند. فریم‌ها ابتدا با یک Vision Foundation Model مثل DINOv3 به فضای feature تبدیل می‌شوند؛ سپس DeltaTok از ویژگی‌های فریم قبلی و فعلی، یک delta token می‌سازد که نشان می‌دهد چگونه باید ویژگی‌های فریم قبلی به فریم فعلی تبدیل شوند. دیکودر هم با گرفتن فریم قبلی و همین توکن، ویژگی‌های فریم جدید را بازسازی می‌کند. 🔍🔄 اگر پیش‌بینی در فضای feature انجام شود و فقط تغییر بین فریم‌ها مدل شود، یک توکن برای هر فریم می‌تواند کافی باشد. نتیجه، مدلی است که چند آینده محتمل تولید می‌کند، اما بسیار سبک‌تر و سریع‌تر از world modelهای مولد رایج است. ⚡️✨ 🔸 A Frame is Worth One Token: Efficient Generative World Modeling with Delta Tokens #مدلهای_بنیادی #مدل_مولد #هوش_مصنوعی #بینایی_مدل_بنیادی #پردازش_تصویر #پردازش_فیلم 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • 🎯 What is an Oracle Manipulation Attack? An Oracle Manipulation Attack is a DeFi exploit where attackers manipulate the price data that smart contracts rely on. Oracles feed external data (like token prices) into blockchains — and when these oracles are compromised or manipulated, attackers can trick protocols into valuing assets incorrectly to drain millions in funds. 🔍 How it works: 1. 📊 The DeFi protocol relies on an oracle for token prices:• Chainlink (most secure) • Uniswap TWAP (time-weighted average price) • Custom oracles (vulnerable) 2. 🔍 Attacker identifies a manipulation vector:• Low liquidity pools (easy to move price) • Single-source oracles • Spot price oracles (no TWAP) • Flash loan accessible pools 3. 💰 Attacker takes a flash loan (no collateral needed). 4. 🏊 They dump massive amounts of tokens into a low-liquidity pool:• Pool reserves get skewed • Price calculation returns inflated value 5. 🏦 They deposit the now-inflated "valuable" tokens as collateral. 6. 💸 They borrow the maximum amount against inflated collateral. 7. 💵 They repay the flash loan with profits, pocketing the difference. Types of Oracle Attacks: • Spot price manipulation — manipulate immediate price • TWAP manipulation — manipulate over time (harder) • Multi-pool manipulation — use cross-pool relationships • Liquidity pool drain — remove liquidity to skew price • Chainlink delay — exploit heartbeat delays Real Examples: • Cream Finance (2021) — $130M via price oracle manipulation • Harvest Finance (2020) — $24M flash loan oracle attack • bZx Protocol (2020) — $1M oracle manipulation • Mango Markets (2022) — $114M via price manipulation • Inverse Finance (2022) — $15M oracle exploit ⚠️ Why it's dangerous: – Can drain entire protocols in one transaction – Hard to detect in real-time – Exploits fundamental DeFi assumption (price truth) – Devastating financial impact 💡 Defense Tips: – Use Chainlink oracles — decentralized, multi-source – Implement TWAP — time-weighted average prices – Circuit breakers — pause on extreme price moves • Multiple oracle sources — don't rely on one feed • Liquidity checks — require minimum pool depth • Sanity checks — reject prices outside reasonable bounds • Manipulation-resistant design — avoid spot price usage • Time-lock large operations — delays allow detection • Monitor on-chain metrics — alert on suspicious activity • Decentralized oracle networks — multiple independent reporters #CryptoSecurity #OracleManipulation #DeFi #FlashLoan #PriceOracle #BlockchainHacks #Ethereum #InfoSec #InfoSecTube #Web3Security 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • 🎯 What is a Man-in-the-Middle (MITM) Attack? A Man-in-the-Middle (MITM) Attack is a network security attack where attackers secretly intercept and relay communications between two parties who believe they're communicating directly. This allows them to eavesdrop, steal data, or manipulate transactions in real-time. 🔍 How it works: 1. 🎣 The attacker positions themselves between the victim and the target:• ARP spoofing — sends fake ARP messages to link attacker MAC to victim IP • DNS poisoning — redirects domain to attacker-controlled IP • WiFi eavesdropping — creates malicious hotspots • SSL stripping — downgrades HTTPS to HTTP 2. 🔓 The victim connects through the attacker's device. 3. 📡 All traffic flows through the attacker:• Eavesdropping — reading unencrypted traffic • Data theft — extracting credentials, session tokens • Modification — altering transaction data • Injection — adding malicious code to responses 4. 💰 The attacker can:• Steal banking credentials • Hijack sessions • Modify payments • Inject malware Types: • ARP Poisoning — mapping attacker's MAC to victim's IP • SSL Stripping — forcing HTTP instead of HTTPS • WiFi Evil Twin — fake access points • DNS Hijacking — poisoned DNS responses • HTTPS Spoofing — fake certificates Real Examples: • Firesheep (2010) — session hijacking on public WiFi • DigiNotar (2011) — fake SSL certificates • Superfish (2015) — pre-installed root certificates ⚠️ Why it's dangerous: – Silent interception – Bypasses encryption if improperly implemented – Enables credential theft – Financial fraud vector 💡 Defense Tips: – Use HTTPS — always verify certificates – HSTS — HTTP Strict Transport Security – Certificate pinning — validate specific certs – VPN on public WiFi — encrypt all traffic – DNSSEC — prevent DNS spoofing – ARP spoofing detection — use detection tools – Don't use public WiFi for sensitive transactions #NetworkSecurity #MITM #CyberAttack #ArpPoisoning #InfoSec #InfoSecTube #Web3Security 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • 🎯 What is an Overlay Attack (Android)? An Overlay Attack is a type of Android malware that displays fake screens on top of legitimate apps to trick users into granting permissions or entering sensitive data. It's a classic mobile banking trojan technique. 🔍 How it works: 1. 📱 The victim installs a malicious app (often from third-party stores or phishing links). 2. 🛡 The malware requests SYSTEM_ALERT_WINDOW permission (or uses accessibility services). 3. 🎭 When the victim opens a target app (banking, crypto, social media), the malware:• Detects the app launch • Overlays a fake login screen on top • Disguises itself to look exactly like the real app 4. ⌨️ The user enters credentials or card details into the fake overlay. 5. 💰 The attacker captures the data and either:• Uses it to hijack the account • Sells it on dark web markets • Sends the victim to the real app (so they don't suspect anything) Real Examples: • BankBot trojan (2017) — targeted 400+ banking apps • Anatsa (2022) — overlays for banking apps, stealing credentials and SMS • Flyper — used overlay to bypass 2FA ⚠️ Why it's dangerous: – Hard to detect — looks exactly like the real app – Works even on updated Android versions – Can overlay any app, not just banking 💡 Defense Tips: – Only install apps from Google Play Store (check reviews, permissions) – Review app permissions — deny SYSTEM_ALERT_WINDOW to unknown apps – Use a mobile security/antivirus solution – Enable Google Play Protect – Be skeptical of apps asking for Accessibility Services – Check URLs carefully — real banks use official domains #AndroidSecurity #MobileSecurity #OverlayAttack #Malware #BankingTrojan #InfoSec #InfoSecTube #Web3Security 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us

  • 🎯 What is Oracle Manipulation? Oracle Manipulation is an attack where attackers exploit price oracles — the data feeds that smart contracts rely on to get external information (like asset prices). By feeding false data, they trick protocols into making wrong decisions. 🔍 How it works: 1. 📡 DeFi protocols need external data (prices, exchange rates) — they rely on oracles. 2. 🎭 An attacker manipulates the price on the source (e.g., a DEX) used by the oracle. 3. 📊 The oracle reports the manipulated price to the protocol. 4. 💰 The protocol acts on false data — enabling:• Liquidations: Trigger liquidations that shouldn't happen • Borrowing abuse: Take out more loans than collateral allows • Arbitrage: Profit from fake price differences Common Oracle Types: • Spot price oracles: Use DEX pair prices (vulnerable to manipulation) • TWAP (Time-Weighted Average Price): More resistant — averages over time • Chainlink: Decentralized, harder to manipulate • Centralized APIs: Single point of failure Real Example (Harvest Finance, 2020): Attackers manipulated the USDC/USDT curve to trick the oracle, draining $33M from the protocol. ⚠️ Why it's dangerous: – Oracles are a single point of failure – Many protocols still use spot prices 💡 Defense Tips: – Use TWAP oracles instead of spot prices – Implement multi-oracle aggregation (Chainlink, Band Protocol) – Add price deviation thresholds — pause if prices move too fast – Use decay functions to smooth out sudden spikes #CryptoSecurity #OracleManipulation #DeFi #SmartContracts #Ethereum #InfoSec #InfoSecTube #Web3Security 🎯@InfoSecTube 📌YouTube channel 🎁Boost Us