SECURITY ALERT: NEW KIDNAPPING TRICK IN LAGOS
If you live in Lagos, please stay extra vigilant right now.
They are now using a new tactic:
They’ll call claiming to be a dispatch rider or delivery agent with a package for you. They’ll ask for your address or try to confirm it.
What to do:
• Never give out your address over the phone, no matter how convincing they sound.
• If they say “the sender didn’t provide your full address,” tell them to go back to the sender and end the call immediately.
• Verify any genuine delivery through official channels or the actual sender directly.
Stay safe out there! These people are getting more creative, so protect your location details at all costs.
Share this with your family and friends in Lagos. awareness saves lives.
@PoliceNG@PoliceNG_CRU Your men at owotu Ikorodu kidnapped me and my friends yesterday, brutalized us and stole more than 300k from us.
If this is going to lead to my death, I swear I will not stop talking about it. I have evidence to back up everything.
Koni da fun yin.
Whether this is true or not, it’s no longer funny.
First, these attacks on Nigerian institutions only confirm what I told my colleagues in the banking industry three years ago: the only reason many security engineers here sleep well is because serious threat actor groups haven’t focused on us yet.
The moment they do, a lot of people will lose their jobs, and it will be because institutions chose politics, nepotism, and rushed product launches over doing security properly.
Secondly, who exactly are Nullsec Nigeria?
If you’re one of these actors treating real applications like CTF playgrounds or exploiting them for profit on the dark web instead of responsibly disclosing, or better yet, leaving them alone, and you think you’ll get away with it because accountability is messed up in this country or because you’re hiding behind VPNs, proxychains, or whatever tools you trust, think again.
The second Nigerian law enforcement decides to collaborate with foreign intelligence agencies, all that perceived anonymity disappears. And when that happens, it won’t be a game anymore.
Prison is not something you play with.
A word is enough, even for a fool.
I emailed ByteToBreach, the threat actor behind the Sterling Bank, Remita, and now Corporate Affairs Commission breaches, with 10 accountability questions.
He answered all of them.
In my latest piece, I break down the Corporate Affairs Commission breach in full.
How he got in. What he accessed. The scale of what was taken, a second access vector into the CAC's systems that he revealed directly to me, not in any published artefact and direct confirmation on whether any corporate records were modified.
He also confirmed he was in active ransom negotiations with Sterling Bank for €250,000 before dumping their data.
The CAC has since issued a public statement. I break down what it says and what it leaves unanswered.
And he told me directly why Nigerian institutions have become his focus.
Read the full piece here:
https://t.co/wk59fdUId4
When they were requesting PII and I was here screaming about why they need such information from the public over a laptop, some people here thought I was over reacting.
Now we don’t know the face behind the account, what he/she has access to and what they can do with the data and all that. We’re too emotional for real life events here.
That tiny red nub sitting between the G, H, and B keys on keyboards has been quietly dividing the tech world for over 30 years. Half the people who encounter it have no idea what it does. The other half refuse to use anything else.
It’s called the TrackPoint. And it was born out of a single frustrating observation.
In 1984, a researcher named Ted Selker conducted a study showing that it takes a typist 0.75 seconds to shift their hand from the keyboard to the mouse and a comparable amount of time to shift back.  That 1.5 seconds of lost time, multiplied across an entire workday, felt like a solvable problem. So he built something that would eliminate it entirely; a pressure-sensitive nub planted right in the middle of the keyboard, so your hands never had to leave the keys at all. IBM introduced it commercially in 1992 on the ThinkPad 700 series. 
The way it works is not what most people expect. It doesn’t move like a joystick. It responds to pressure. Beneath the rubber cap sit strain gauges that measure the force applied in different directions and translate it into cursor movement. The harder you press, the faster the cursor moves.  There is no repositioning, no lifting your finger, no running out of space. Infinite cursor movement from a single fingertip that never moves more than a millimeter.
The red color almost didn’t happen. IBM’s product safety division had reserved red exclusively for emergency power-off switches on mainframe computers.
ThinkPad designer Richard Sapper got around this by calling the color IBM Magenta and when the first batch shipped, the engineers made it decidedly more crimson. A loophole dressed in plain sight. 
Power users programmers, analysts, executives who live on their keyboards swear by it. The reason, according to Lenovo’s chief design officer, is that your hands never leave the home row. You type and navigate simultaneously, without the constant interruption of reaching for a trackpad.  Once mastered, people say it feels less like using a tool and more like an extension of thought.
Most laptops abandoned it. Lenovo never did. And the people who know, know.
In early 2024, Microsoft engineer Andres Freundaccidentally thwarted one of the most sophisticated cyberattacks in history.
While testing an unstable version of Debian, he noticed a tiny 500ms delay in his SSH logins, a blip most people would ignore.
Curiosity led him to find a massive backdoor hidden in XZ Utils, a standard data compression tool used by almost every Linux server on the planet.
The deal here was :
The backdoor targeted the SSH protocol, which is the primary way admins securely log into remote servers.
If Freund hadn't spotted it, attackers would have gained a "master key" to bypass authentication and execute code with root privileges on billions of devices.
The culprit (under the name "Jia Tan") spent two years building trust in the open-source community, slowly gaining enough "cred" to become a project maintainer and plant the malicious code.
How It Was Resolved
Once Freund confirmed the malicious code, he emailed the Debian security team and went public on the Openwall mailing liston March 29, 2024.
Major Linux vendors like Red Hat, Fedora, and Debian immediately reverted to older, safe versions of the software.
GitHub quickly suspended the compromised accounts and disabled the affected repository to stop the spread.
A clean version (XZ Utils 5.6.2) was released in May 2024, effectively closing the vulnerability tracked as CVE-2024-3094.
Essentially, the internet was saved from a "digital apocalypse" because one guy was annoyed that his computer felt half a second too slow.
I want to share a quick thought for people in cyber security. This will be my longest tweet ever.
I’ve spoken to many lately who are having an existential crisis from the constant posts about “the end of cybersecurity jobs.”
Yes, things are changing quickly. This is a significant moment for the tech industry. Change can be uncomfortable. But we’ve seen cycles like this before.
• When GitHub and open source took off, people said software engineers would disappear because code was free.
• When AWS and cloud computing emerged, people said infrastructure jobs would vanish.
• When fuzzing and SAST tools improved, people said vulnerability research would disappear.
• Virtualization would eliminate infrastructure jobs.
• Mobile computing was going to end desktop dev.
• Exploit mitigations would end exploitability. It didn't.
Each time automation improved, the amount of software grew faster than the automation. It does feel "different" this time as it's explosive.
Some roles will shrink:
• repetitive pentesting
• basic vulnerability scanning
• tier-1 SOC monitoring
But other areas are expanding rapidly:
• AI system security
• supply chain security
• identity architecture
• autonomous agent security
• critical infrastructure protection
Historically, every time we eliminate one class of bugs, new classes emerge. Right now people are vibe-coding entire systems, giving AI access to their machines, crossing trust boundaries, and deploying autonomous agents with excessive permissions. The legal and regulatory world is nowhere close to ready.
There will absolutely be new failure modes. Humans are amazing and always adapt, finding new ways to do things.
The worst thing you can do right now is fall into a doom loop.
...and I’ll be honest, I too have felt the "psychological paralysis" a few times thinking, “Is this time different?” It's especially impactful when it comes from someone I respect in the community. There are certainly unknowns, in an industry where we've become accustomed to predictability.
But... the majority of those reactions are usually driven by social media, not reality. Platforms like X reward engagement, and sensational doom posts spread faster than measured thinking.
If you see something like:
“Holy #$%^! Opus 66.6 just found every bug in Chrome and replaced 50 startups!”
…mute it and move on.
Instead:
Stay curious.
Learn the new technology.
Adapt your skillsets.
Build things.
We’ll get through this transition the same way we always have. If I'm wrong then Sam Altman better be right about UBI! :) I'm sure that if this tweet gets any engagement that I'll get some heat for it, but a good friend of mine reminds me often to focus on what you have control over. I'll revisit this tweet at DEF CON 40!
Finally got some breathing room, so here's a quick recap of the cyber side of IR/US ongoing war:
1. Right after the first strikes by US, within the first hours, multiple popular (pro regime) news agencies and outlets were compromised at the same time. Legitimate looking news contents were injected to the front page, aimed at degrading morale of pro-regime force by typical PSYOPS tactics. Sites were quickly taken down and restored.
2. Shortly after that, BadeSabaa (Prayer time app), a popular mobile app with 30+ Million installations (from Iranian app store) was hijacked and used to send push notifications to users. This time the target audience was mostly army members, calling them to surrender and join the people, if they want to survive. This app is an interesting pick, not just because it has a high number of downloads. Users of the app are particularly religious people and have higher chance to be also pro-regime and within body of the army. One important but seemingly ignored fact about this app is that it requests location access to operate. It's safe to assume most users allow that for more accurate prayer time results. It's also safe to assume that, if the app backend is compromised enough to allow sending push notifications, it's safe to assume that any telemetry logs and data from the app would be also compromised. Correlating telemetry with unique device ID for that large user base can be (ab)used in many different and interesting ways! Not that it has been the case.
* Rumors circulated that EITAA, an Iranian popular messaging app, was also taken down and no longer accessible. That turned out to be just a rumor as I verified.
3. Iran internet went in full blackout mode again. Not that this had anything to do with a cyber operation. Initially starting from MCI and expanding to the entire country within a day. Like in previous case, there are still a small fraction of hosts that remain accessible from outside, but if you have been logging previous round's data and compare it with current one, you might notice interesting discrepancies ;)
This is likely a multi-reason effort to contain exposure of impact of strikes, possible denial of service to smaller drones (which turned out a failed assumption and attempt during IR/IL war too) and finally to have a veil over any potential aggression towards upcoming unrests and protests by people in the streets.
4. During second day of strikes, Iranian national TV's Channel 3 satellite streams (IntelSat) were hijacked (2nd time since recent protests) and videos of Trump and Netanyahu speeches were broadcasted instead. Again, expected PSYOPS move considering the situation.
Other covert operations have been also in progress, which I guess we might be hearing about them (or not) in near future. I will be occasionally updating this as a thread, if more notable cyber attacks takes place.
Amid the Israeli and US strikes on Iran, a wave of cyberattacks have also targeted the country, the semi-official Fars news agency reports.
Fars says that several major Iranian news agencies were targeted and "experienced severe disruptions in their operations," and that some widely used mobile applications were also experiencing disruptions.
Investigation Scenario 🔎
You receive a SIEM alert about this file:
C:\Users\bose\Downloads\report.doc
The file copied itself to %TEMP% and the original copy was deleted.
What do you look for to investigate whether an incident occurred?
#InvestigationPath#DFIR#SOC
Don’t let familiarity make you miss out on the genius of your friends
Bro some of your friends are crazy at what they do
Know what your friends do, their interests, what they are working on.
Chai people Dey think!
Dont be late to the party when you had front seats for free
I bought a brand-new MTN SIM yesterday and to my shock, I started receiving UBA debit alerts.
Let me be very clear: I don’t bank with UBA.
A few minutes later, it hit me. I was sold someone else’s line.
This morning, the actual owner made another transaction… and yes, another debit alert entered my phone.
How is this even possible?
You buy a “new” SIM and inherit someone’s bank alerts, financial history, and privacy risks?
This isn’t just strange, it’s dangerous.