March 17, 2023


Exchange bug is apparently pretty sweet. RCE with invisible emails.


This ICMP bug raised quite a bit of interest in certain circles, but exploitation seems to be in the theoretical stage for now.










After the Exchange bug what are the odds that we’d get a second awesome bug in the same week? Turns out pretty good. This one is really juicy. RCE via VoLTE. Since P0 found this bug in this attack surface, my suspicion is that there are more of these out there.

Word to the wise — disable VoLTE






or to participate.