How sloppy OPSEC gave researchers an inside look at the exploit industry
https://www.cyberscoop.com/mobile-zero-days-lookout-shmoocon-2019-android-barracuda-ios-stonefish/
“Those government developers were testing out the WhatsApp malware on their own devices, and it was storing their discussions on the program’s servers.
The nation-state essentially had hacked itself and accidentally dumped highly sensitive information on the open internet—including details of its interactions with the secretive vendors who sell spyware to governments.”
HT @lorenzofb@twitter.com