AnonGhost exploits API vulnerability in the RedAlert app to dispatch fake messages

Information from Group-IB Threat Intelligence

On Sunday, well-known hacktivist group AnonGhost exploited an API vulnerability in the RedAlert app, an app that provides real-time rocket alerts for Israelis. In their exploited, they successfuly intercepted requests as well as exposed vulnerable servers and APIs.

They were also able to to send spam messages to users still using the app, dispatching fake messages like "The Nuclear Bomb is coming."

The app is currently removed from the Google Play Store.

submitted by /u/fried20melon
[link] [comments]

from hacking: security in practice https://ift.tt/SnuzP7C

Comments