Archive for SafeBreach Labs

SafeBreach Labs discovers bypass for Google’s Quick Share vulnerability fix

Posted in Commentary with tags on April 2, 2025 by itnerd

As a follow-up to their DEF CON 32 presentation QuickSell: Sharing Is Caring about an RCE Attack Chain on Quick Share the SafeBreach Labs team has discovered a critical bypass to Google’s fix for one of the vulnerabilities they previously identified in the Quick Share data transfer utility for Windows.

After Google addressed the original vulnerabilities discovered by researchers Or Yair and Shmuel Cohen, the team set out to verify the effectiveness of these fixes. They discovered that the solution implemented for CVE-2024-38272 – a critical vulnerability that allowed attackers to send files directly to users’ devices without approval – could be bypassed. Researchers could still deposit unauthorized files onto target devices despite Google’s initial patch by manipulating payload IDs during file transfers.

Even though Google has been responsive to these additional findings and has issued a new CVE along with an updated fix to address the bypass, this research shows the complexity involved in securing data transfer applications and the value of thorough verification testing after security patches are applied.

You can read the research here.

First Free & Fully Undetectable Cloud-Based Cryptocurrency Miner Utilizing Microsoft Azure

Posted in Commentary with tags on November 8, 2023 by itnerd

SafeBreach Labs has released its newest discovery of the first free and fully undetectable cloud-based cryptocurrency miner utilizing Microsoft Azure’s Automation Service and how attackers might leverage the capabilities of the cloud to cheaply – and secretly – mine for cryptocurrency. 

The implications are significant, as many organizations use cloud services like those provided by Microsoft Azure Cloud Automation and could become exposed to malicious actors looking to utilize their computational resources.

You can read the report on this here.