Digital infrastructure is basically a giant wobbly Jenga tower. At the bottom: submarine cables, Linux, and caffeinated, unpaid open-source devs. One tiny failure and “99.999% uptime” becomes “we’re investigating.”
#meme4cyber#cyber#infosec#cybersec#awareness
JS dev choked on their latte: npm suffered its largest supply chain attack. Phishing emails hit chalk’s maintainer → crypto clipper swaps wallet addresses using Levenshtein distance. Millions of installs, $50 stolen. Moral? npm install → npm prey
#JS#SupplyChain#Npm
🍵Tea got spilled by 4chan. A women-only doxing app just doxxed its own users after a dev with “6 months of vibe-coding” left Firebase wide open. 72k+ images leaked. Now the app’s cooked, users roasted, and 4chan’s playing Uno Reverse
#DataBreach#teaappbreach#teaapphack
🎯 Operation Eastwood hits pro-Russian NoName057(16), behind mass DDoS attacks on EU
- 100+ servers down
- 7 arrest warrants, 2 arrests
- 24 searches
- 1,000+ supporters warned
Coordinated via Europol & Eurojust
No need for Clint this time🤠
#CyberSecurity#DDoS#NoName#OSINT
💩 Poop-slinging goes digital: India reports 1M+ cyberattacks, some from Pakistan, others from Morocco, Indonesia, etc.
Groups like Team Insane PK & Pakistan Cyber Force claim breaches.
Indian hackers hit back: 1,500+ PK sites down, phishing too.
#CyberWar#war#India#Pakistan
Redditors are seething after Zurich researchers infiltrated r/ChangeMyView with AI bots, no disclosure. And nothing makes a Reddit mod angrier than rule-breaking.
GPT-4, Claude 3.5 & LLaMA were 6× more persuasive than humans. Copium’s in short supply.
#AI#LLM#Reddit#GPT4
Operation Soyclips: Soyjack Party infiltrated 4chan’s backend using a fake PDF postscript exploit. Legacy code from 2016 let them leak 4chan’s full source, mod data, and trigger an email/IP dox-fest that obliterated the staff.
#Cybersecurity#DataBreach#4chan
ChatGPT can now create realistic fake passports to allegedly bypass fintech's KYC checks
Guess what new scams are coming
No, I’m not taking notes. Why would you ask?
#Cybersecurity#FraudDetection#ChatGPT#KYC#AIfraud
A 9.1 exploit lets attackers bypass auth & access control in Next.js middleware. If your SaaS relies on it, hackers can walk right in
To do:
Upgrade Next.js ASAP
Not using middleware or hosting on Vercel/Netlify? Safe
Self-hosting w/middleware? Trouble
#NextJS#Cloudflare#Vercel
Davis Lou crashed critical systems, locked out thousands, using his own credentials only 4 days after getting demoted
If he wanted to get away with it:
Delay the attack
Use slow memory leaks
Obfuscate code
Don’t Google “how to hack your job” on a work pc
#CyberSecurity#Infosec
Mozilla’s new Terms of Use quietly claim a royalty-free, worldwide license over anything you input through Firefox
They also removed their promise to never sell user data
Oh, and they can now terminate your access at any time
#Firefox#Privacy#Mozilla#CyberSecurity
North Korea's Lazarus Group stole $1.5B in ETH from Bybit via a compromised multi-sig wallet. Funds laundered through mixers & swaps. State-sponsored pros fund nukes. Multi-sig isn't foolproof—triple-check everything! #Cybersecurity#CryptoHeist#Phishing#Lazarusgroup
🚨The UK just pulled a James Bond move on Apple, demanding a backdoor to iCloud’s E2EE. Thanks to the Investigatory Powers Act 2016.
Use E2EE messaging
Encrypt your hard drive
Use VPNs & Tor
Consider Tails OS
#CyberSecurity#Privacy#Encryption#Apple#UK#DataProtection
DeepSeek R-1 just toppled ChatGPT. This open-source Chinese model claims a $6M dev bill, ignoring security. Hit by malicious attacks, it uses Nvidia’s H800, a cold shower for investors. #AI#DeepSeek#ChatGPT#Cybersecurity#TechTrends
AI was supposed to revolutionize industries—maybe even steal our jobs. Instead, it’s fueling scams. A French woman lost $850K to a fake “Brad Pitt” using AI selfies & sweet talk. The real threat? Social engineering. Always get a fresh set of eyes! #DeepFake#AI#Cybersecurity
IMMEDIATE Threat From AI: Sophisticated spear phishing
SlashNext: malicious emails soared 3141% in 6 months (thanks ChatGPT) AI can now match expert-level phishing at 1/130th the cost. Nextgen Nigerian Prince scams: instant, and quality/quantity maxed
#AI#Cybersecurity#Phishing
Hai notato un aumento di chiamate spam?
1 milione di numeri telefonici italiani è stato condiviso su #BreachForum da agency900
- Non cliccare link sospetti
- Usa l'autenticazione a 2 fattori
- Diffida da chiamate/messaggi sospetti
#CyberSecurity#DarkWeb#Phishing#DataProtection
Hot take: Inbreeding bad!
AI training on its own output risks “modal collapse”, loss of originality & hallucinations
With synthetic data flooding the web, human content may soon be outnumbered
Poor curation=Habsburg-tier AI
#ArtificialIntelligence#GenerativeAI#MachineLearning
Devin: For $8/hr, this AI codes, tests, & ships better than 74.2% of humans, or so they say.
Works in Slack, great for managers, nightmare for devs who know Vim. Fast but hallucinates, adds random packages, & breaks fixes.
Still cheaper than your lunch. #AI#Devin#FutureOfCoding
🚨Three-letter agencies urge encrypted apps!
Why? Chinese hackers infiltrated U.S. telecoms, spying on calls & texts since 2020 with stealthy malware like "Sparrow Door."
Protect yourself:
🔒 Use Signal
🚫 Ditch SMS 2FA; use authenticator apps
#CyberSecurity#Signal#Telecom