This is from September 2019. They haven't really bothered with updating the topic since then: https://www.adaptivemobile.com/search/3a08888ea06c35015d1248...
Dead link?
Simjacker vulnerability exploited by surveillance companies
11–19 of 19 posts
Re: Simjacker vulnerability exploited by surveillance companies
#12So which company, working for which government, and how to stop it? The article is just a talk-to-our-salesman piece?
Re: Simjacker vulnerability exploited by surveillance companies
#13I'm for cool research, but I am also tired of the trend where security companies come up with a flashy name, logo, url, etc. for every exploit/vuln.
Re: Simjacker vulnerability exploited by surveillance companies
#14Re: Simjacker vulnerability exploited by surveillance companies
#15Earlier quoted context omitted.
Dead link?
Yeah it's just a search for "simjacker" on their site, which encodes it in a string instead of common sense.
Re: Simjacker vulnerability exploited by surveillance companies
#16Re: Simjacker vulnerability exploited by surveillance companies
#17I'm for cool research, but I am also tired of the trend where security companies come up with a flashy name, logo, url, etc. for every exploit/vuln.
Certainly there's a self-serving glamorous aspect to it on the part of security researchers, but fun names and logos brings attention to issues that otherwise result in eyes glazing over. As much as this stuff makes me cringe to read, I'm willing to bet the branding for this issue will result in more eyes on it and probably will result in a fix. That's ultimately what vuln disclosure is about, after all.
Re: Simjacker vulnerability exploited by surveillance companies
#18Earlier quoted context omitted.
Most likely: NSO Group
Less likely, NSO's expertise is in development of exploits for browsers and apps (ex: WhatsApp), not ss7 exploits
Dont think they named directly who but they mentioned Circles, Rayzone in ChaosComputingClub a few days ago. THowever the link with the talk is dead for some reason - https://media.ccc.de/v/rc3-11511-watching_the_watchers_-_how...
Re: Simjacker vulnerability exploited by surveillance companies
#19I'm for cool research, but I am also tired of the trend where security companies come up with a flashy name, logo, url, etc. for every exploit/vuln.
"Do you know if attacks like like Simjacker or other next
generation attacks are happening in your network?
Book a meeting [with us to find out]."
The website feels like a con/ad rather than something legit.