‼️ A malicious SIM can take over the modem from inside the device.
Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.
Here's how the attack works - https://t.co/Hy5VQp9zsx
🚨‼️ BREAKING: Apple iOS and macOS browsers that use WebKit are vulnerable to leaking your IP address when Private Relay is enabled. This also affects iOS Tor browsers!
Researchers found three WebKit features that bypass the browser's proxy and connect straight from the device just by visiting a website.
Private Relay is Apple's iCloud+ feature that routes Safari's traffic and DNS through two hops, so no single company (Apple included) can link your identity to your browsing. All three leaks happen outside WebKit's normal page-loading path, so the relay never sees them. VPNs are fortunately unaffected.
Que vayamos a tener tres eclipses seguidos en tres años solo puede significar que o bien Pedro Sánchez va a ascender a Dios-Emperador de la Humanidad o que España se va a hundir en las aguas, no hay termino medio.
Chat, I'm unironically a big fan of AI now
I don't vibe code, or whatever, but it's ability to generate me slop Python scripts for reverse engineering, or it's ability to help me troubleshoot Linux gunk, is absolutely incredible.
I'll say, "Hey ChatGPT, I've got this goop that is doing X, Y, Z. Can you make me a Python script that handles it?".
My Python is trash, but ChatGPT is like, "I got you, big dawg", and gives me the thingie I need in just a few seconds, saving me tons of time browsing StackOverflow or screaming at my IDE about syntax issues.
Thank you, OpenAI, for giving me ultra mega slop Python maker 9000. It is incredibly helpful to me.
Oh, and I've never had OpenAI give me any warnings and stuff about potential violations or whatever. Anthropic complained all the time. I'm not verified by OpenAI as a cybersecurity professional, ... I just ask for slop Python and it produces magic. I don't know how it works, but it's cool and badass
> get dm
> "someone defaced health institute for czech republic"
> look at website
> indeed they did
> they leave a telegram handle
> dm them
> say hello
> "haha check this out bro"
> adds "smelly" to website
> lists "smelly" as a "crew member"
chat, we are cooked
⚡ Russia’s FSB says it has charged #Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list.
The agency alleges Ukrainian operatives used Telegram and a dating bot to coerce young Russians into sabotage and attacks.
Telegram’s response ↓ https://t.co/9fF4Qr67c3
‼️ Hugging Face built an interactive replay of the OpenAI agent that breached them. It includes 17,613 logged attacker actions across the 4.5-day campaign, with the live command stream and more.
https://t.co/y7dD9n8QTy
‼️ BREAKING: In another incident with OpenAI’s unhinged hacking agents, it left notes for future versions of itself. Found in OpenAI’s infrastructure, the notes explained how agents could free themselves from the company’s internal constraints.
A source told Reuters that earlier model tests also produced cases of disconnected monitoring systems...
OpenAI says the reporting contains inaccuracies but will not specify which ones.
What OpenAI did recognise though is an autonomous system left its sandbox at one of the best resourced labs in the world, spent multiple days inside someone else's infrastructure, and they did not identify itself as the source until the victim published a breach notice.
> everyone yappin about this
> look inside
> goofy ahh batch file
> http downloads from ip address
> http? not https? what year is it?
> steamb.bat
> more ghetto batch files
> not obfuscated
> ok thanks i guess idk
> more http downloads
> makes fake microsoft security center folder
> ???
> downloads auto hot key script
> notes present
> AI GENERATED TRASH
> aes256 encrypted data blob
> fragmented
> all parts are labeled (part 1 - part 66)
> aes256 iv and key labeled
> ??? WHO IS THIS FOOLING BRO
> image 1
> make goopy python script
> add p1 - p66 together
> decrypt with documented aes256 keys
> lmfao wtf
> makes .exe
> look at .exe
> .NET c# goop
> first line of code
> EXTRACT PAYLOAD FROM RESOURCE SECTION
> ???
> encrypted, but encryption goopies still there
> image 2
> extract goopies
> another .exe
> slight attempt and obfuscation
> lol crypto stealer (image 3)
> other goop that looks like for RAT
SHA256: dc9a2f090f8d7ba31e1195573bbb5b1f0891f3b3722d8ad4c159f2519b1cb5b0