❗️🚨 An Israeli company has backdoored hundreds of millions of households through countless Smart TV apps, and they're quietly turning Samsung and LG TVs into exit nodes for AI web-scraping. Your TV is relaying strangers' web traffic from your home IP, your bandwidth, your address attached to whatever those scraping jobs touch.
Roku, Fire TV and Google TV banned the practice. Samsung and LG didn't. The culprit is Bright Data's proxy SDK, which rides inside Tizen and webOS apps, 200+ on webOS alone. Datacenter IPs get blocked, home IPs don't.
Include Security reverse-engineered the SDK and found its relay protocol has no message signing, authentication, or device attestation. Their words: less secure than typical malware command-and-control.
To make things worse, they found that in iOS the relay tunnel binds straight to the physical network interface, so it routes around any VPN the user is running.
Bright Data's config also ships per-country tiers. Devices in Uzbekistan and Oman are cleared to relay down to 1% battery, with data caps up to 60x the worldwide default.
Before the BaCkDoOrEd replies land: technically you agreed. In practice you were enrolled into a global proxy network you were never given the information to refuse. And these exit nodes drag down your IP's reputation, potentially leaving you with blocks from providers.
Six Nigerians Ran an AI Deepfake Romance Scam from a Nonthaburi Riverside Condo. A Cocaine Bust Led Thai Police to Them.
Thai police raided a luxury condominium on the Chao Phraya River in Nonthaburi on May 22 and arrested six Nigerian men running a romance scam ring built on AI-generated faces and fake video calls.
The trail started with cocaine. In April, police arrested a Nigerian man named Patrick and three associates on trafficking charges and seized 2.5 million baht in assets. The money trail led to foreign nationals on student visas living five or six to a unit in a high-end riverside condo near Phra Nangklao Bridge, none enrolled in school, none working.
Police executed three warrants on three units, forcing entry after the suspects refused to open. One man tried to climb over a balcony. Another lay hiding on a bathroom floor, texting the other units to warn them. Officers seized 18 phones, three laptops, and three bank passbooks, the phones still open to active romance scam chats.
The group posed as pilots, US military officers, doctors, and engineers, built relationships with older Thai women, then claimed a valuable package was stuck in customs requiring a transfer fee. Investigators recovered AI-generated Western faces used to produce fake video calls, and "sexy chat" scripts written to push older women toward transferring money. Police said a single well-crafted line could convince a victim to empty her account.
All six face initial charges of illegal association (อั้งยี่) and immigration overstay. Fraud and romance scam charges are pending.
Patch your Linux boxes!
https://t.co/VWOUDbLAn2 is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms.
Found by the teams at @theori_io and @xint_official
More details below
https://t.co/9f6T96PvPX
Hypercompression achieved! This may have big implications for future AI systems.
I built a 1.3 kb python script that unfolds to the entire T9 autocomplete language.
The code seen in the screenshot renders the ENTIRE T9 system. 3 lines of code. GitHub repo below.
The only way we want our ads to come down. When people take them home.
a) Keep them.
b) Send them to Ashton Kutcher.
c) Put them outside 10 Downing Street.
نحمد الله سبحانه وتعالى أن أكرمنا بإتمام صيام شهر رمضان المبارك وقيامه، ونسأل الله أن يديم علينا أمننا واستقرارنا، وأن يحفظ أبطالنا البواسل على الثغور والحدود في مختلف القطاعات العسكرية والمدنية.
وكل عام وأنتم بخير، وبلادنا في عز ورفعة.
Here's the vphone-aio for anyone cannot setup. I uploaded the whole VM into github so maybe cloning it might take a while.
Follow the steps to run it. Also the VM already included rootless jailbreak environment and a few tweaks on it.
https://t.co/YfsFLAcxc0
Microsoft Defender researchers observed attackers using yet another evasion approach to the ClickFix technique: Asking targets to run a command that executes a custom DNS lookup and parses the `Name:` response to receive the next-stage payload for execution.
Security researcher ily2 has just earned a staggering $3,000,000 from submitting a critical smart contract bug via Immunefi.
That's the largest single payout in web3 security in recent memory.
In total, he's submitted 3 reports. All 3 were paid. 100% accuracy.
His leaderboard update is coming soon, but you can pledge IMU to him now and earn when he finds the next one:
https://t.co/ZEN8N5SP2c