Mikko Kenttälä·Sep 12, 2024Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOSCritical zero-click vulnerability chain in macOS (patched)A response icon2A response icon2
Mikko Kenttälä·Apr 25, 2023Alias file to rule them all — One click code execution with alias file in macOSSummary (TL;DR)
InSensorFubyMikko Kenttälä·Aug 3, 2021Escaping from a truly air gapped network via Apple AWDLIn the following post I go through how to escape from a truly air gapped network using Apple Wireless Direct Link -network and leveraging…A response icon1A response icon1
InSensorFubyMikko Kenttälä·Dec 14, 2020Test for network leaks, discover a product flaw and get vendor to fixPlot twist: this time it is not about us doing vulnerability research and reporting. This is a story about our customer in action, told to…
InSensorFubyMikko Kenttälä·Oct 7, 2019How my application ran away and called home from RedmondI recently found a surprising leak vector in Windows 10 installations. We were porting our Beacon to Windows and for easy deployment…A response icon3A response icon3
InSensorFubyMikko Kenttälä·Feb 20, 2019SensorFu Beacon How To: 3 steps to always know if your isolated Linux leaksWhen you need to build isolated and strictly restricted Linux environments for special purposes you want to know it truly is and stays…
InSensorFubyMikko Kenttälä·Mar 2, 2018Why Ethernet Broadcast Escape Tests MatterWe recently implemented a network escape to SensorFu Beacon that uses Ethernet broadcasts. Why? First of all you can test all the hosts in…