Hacker | Scambaiter | Crypto Enthusiast | Gamer | Photographer | Traveler
Started in the business world; trying to break into cyber
My journey from MBA to OSCP
Life bro tip:
Make your duress password your birthday. For example, june 8 2000 would be 6800. This is one of the first codes they will try.
They will be the ones deleting the evidence unprompted
🤘
UPDATE, ITS WORSE THAN THE CHATS
the same thing is happening with shared artifacts. every app, doc, dashboard and tool people published from claude is also sitting indexed and searchable
people have already pulled up internal company dashboards, full project plans with client details, and someones entire clinical trial summary with real medical data in it
but think about what people actually build in artifacts:
> financial models, cap tables, revenue spreadsheets
> payroll and salary breakdowns with employee names attached
> customer lists and crm exports
> internal wikis, roadmaps and unreleased product plans
> legal docs, contracts and agreements being drafted
> personal health and medication trackers
> tax documents and bank statement breakdowns
> and every dashboard someone pasted an api key or env variable into to get it working
when you publish an artifact your only two options are "only me" or "anyone with the link"
nobody reading that thinks it means "and google will list it publicly." its the same as an unlisted youtube video showing up in search results
and its already past the point of just being google. third party sites have started scraping and organizing these into browsable collections, so deleting it from search doesnt mean its gone
if you have ever published an artifact, go check your published artifacts and unpublish anything you dont want public
link and not indexed were always two different promises. people only ever agreed to the first one
First known US case: American charged for using a “duress” password
Samuel Tunick, an Atlanta resident, is being prosecuted for allegedly giving border agents a passcode that wiped his phone.
The feature comes from GrapheneOS, a privacy-focused Android OS. Entering the duress code triggers a full factory reset.
This is believed to be the first time federal prosecutors have brought such charges.
The incident happened in January 2025 at Atlanta airport. Agents demanded access to his phone without a warrant, saying he hadn’t yet officially entered the US. When they entered the code, the phone wiped itself.
Tunick has pleaded not guilty. His lawyers argue the seizure was unlawful and that agents were investigating his activism against “Cop City.”
The case raises big questions about digital rights at the US border.
What do you think?
Article: https://t.co/tV806yWtyW
#Privacy #GrapheneOS #DigitalRights
‼️ Steam is hosting malware again, this time in a custom map for the game MECCHA CHAMELEON
Loading the map quietly writes a Windows command file into the player's Documents folder, which then opens PowerShell in an invisible window and tries to download a second script from a server.
The dropped file was recovered. The second stage 404'd, so nobody knows what it does yet. We're working on that.
‼️ Windows Vice President Pavan Davuluri is taking action after LG used Windows Update as a delivery method to push bloatware/adware onto Windows computers without users' consent.
He stepped in after Epic CEO Tim Sweeney tagged him to bring the story below to his attention. Davuluri responded: "We've connected with the team at LG and as an immediate next step, they have agreed to disable the McAfee pop-up from their app."
‼️ This is getting out of 'hand': Google is testing a reCAPTCHA check that asks users to grant camera access and perform a hand gesture, mapping 21 hand-knuckle coordinates to confirm a live human, but reports say people have already bypassed it with a stock photo fed through virtual camera software.
‼️ UPDATE: LG Electronics says it will suspend smart TV apps that secretly turn hundreds of millions of TVs into residential proxy nodes, after researchers found the proxy SDKs in more than 42% of apps in LG's webOS store and over a quarter of Samsung's Tizen apps, routing unknown third parties' internet traffic through users' home connections.
Residential proxy firms pay developers to bundle these SDKs, then rent the resulting home IP addresses to customers who often use them for large-scale scraping aka stealing your shit (also for AI training).
Proxy nodes are being embedded at scale in hardware people don't treat as computers and can't easily inspect, and LG's cleanup does nothing for Samsung's Tizen store, where the same problem is present.
50 sitios web que parecen 'ilegales' pero son perfectamente legales
1. https://t.co/CYYb69wAS1 — Descarga cualquier video de redes sociales
2. https://t.co/xfNyQaAfIH — Photoshop gratis
3. https://t.co/w9e9ZDKE0m — Correo electrónico temporal con un clic
4. https://t.co/zXVgMSMUKz — Más de 100 herramientas gratuitas en un solo sitio
5. https://t.co/4xWixCITyY — Accede a cualquier página web antigua
6. https://t.co/xmNwQwcbYD — Millones de libros de texto gratuitos
7. https://t.co/jsDkn2CLNG — Artículos de investigación gratuitos
8. https://t.co/dTEnsoq5wj — Encuentra alternativas gratuitas a aplicaciones
9. https://t.co/MKUIpIk3fd — Localiza dónde transmitir cualquier contenido
10. https://t.co/hBCRDs18p7 — 70.000 libros clásicos gratuitos
11. https://t.co/5VDGisfoED — Descargas gratuitas de PDF
12. https://t.co/dexoB5XzFz — Cursos gratuitos de universidades de élite
13. https://t.co/1lWE4zpHnz — Resuelve cualquier problema matemático al instante
14. https://t.co/FQuiLJAQrv — Elimina el fondo con un clic
15. https://t.co/Yf79zg46dZ — Borra objetos de fotos
16. https://t.co/P93Os8H5YT — Elimina el fondo de videos gratis
17. https://t.co/PyuYNPGTg0 — Comprime cualquier imagen gratis
18. https://t.co/8HsgHZFqEa — Gráficos dibujados a mano gratis
19. https://t.co/x6dKy6uePw — Convierte código en obras de arte
20. https://t.co/1LwFgBSVsn — Capturas de pantalla de código impresionantes
21. https://t.co/VY67Rwectv — Rastrea cualquier vuelo en tiempo real
22. https://t.co/hsUebR2Qlq — Rastrea el historial de precios de Amazon
23. https://t.co/LwPqZyGLyk — Verifica si has sido hackeado
24. https://t.co/udMswDyPke — Escanea malware en cualquier archivo
25. https://t.co/2TQmvJG176 — Envía mensajes autodestructivos
26. https://t.co/zdsDl0QODh — Comparte archivos que se eliminan automáticamente
27. https://t.co/VgXSsWh1wC — Archiva cualquier página web para siempre
28. https://t.co/BOWcUdOSyN — Elimina tu presencia de cualquier sitio web
29. https://t.co/0bteSbcPOY — Escucha cualquier emisora de radio del mundo
30. https://t.co/oql666oy5Q — Identifica las canciones de cualquier programa
31. https://t.co/5qnhYNh81M — Música para concentrarte
32. https://t.co/CFocTWwgKi — Paisajes sonoros personalizados para enfocarte
33. https://t.co/aIZ45zCe60 — Busca cada libro que se haya escrito
34. https://t.co/IAHMqpWARB — Asistente de IA para artículos de investigación
35. https://t.co/5ElktAwRwe — Busca consensos científicos
36. https://t.co/IwLwfgPx66 — Mapea investigaciones de forma visual
37. https://t.co/YgN1nSJFWJ — Búsqueda académica gratuita
38. https://t.co/yX50WOr9r5 — Comprende cualquier artículo de investigación
39. https://t.co/99qKiNBFKB — Resume cualquier video de YouTube
40. https://t.co/N2k4sNcQzA — Búsqueda de IA para desarrolladores
41. https://t.co/WmIpaukYAv — Prueba cualquier expresión regular al instante
42. https://t.co/W3yyseeqKE — Formatea cualquier código de forma clara
43. https://t.co/5Cy9PfvYBW — Entiende comandos de terminal
44. https://t.co/LWtsQbSSRH — Pizarra infinita en el navegador
45. https://t.co/4qhuHCjzmu — Verifica si un sitio web está caído
46. https://t.co/9DviDE62bT — Búsqueda inversa de imágenes
47. https://t.co/sikp898xZG — Prueba tu velocidad de internet
48. https://t.co/3dHGFcLd8Q — Edita PDF gratis
49. https://t.co/8Eeusq9Ovu — Combina y divide PDF
50. https://t.co/cUmwy95yYR — Correo temporal en segundos
Todo legal. Todo gratis.
Guárdalo antes de que se te olvide.🔖
Instagram can be a valuable OSINT source for investigating usernames, public profiles, hashtags, locations, audience activity, and online connections.
We compiled a list of Instagram OSINT tools that may help researchers analyze publicly available data more efficiently:
* Instaint
* Molly
* Picodash
* InsightGram
* HeySocial
* Inflact
* Stalker-IG
* Dumpor
* Search4IG
* PhantomBuster
Analyst Note: Instagram frequently changes its access controls and API restrictions, so third-party tools may become limited or unavailable without notice. Always verify results and use these tools lawfully, ethically, and within platform rules.
Which Instagram OSINT tool would you add?
#DDW #OSINT #Instagram #CyberSecurity
❗️❗️A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic.
The tool also uses DNS AAAA responses as a fallback channel to restore Microsoft Graph credentials when cloud authentication fails.
Here's how it works: https://t.co/EDP6cBRCav
#cybersecuritynews
🛑 ALERT - WordPress sites are under active attack.
Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.
Read what defenders should check: https://t.co/p6S8ILrUw0
A phone number is more than a contact, it's a valuable #OSINT starting point. By analyzing publicly available information, security professionals can verify identities, detect fraud, investigate scams, and support digital investigations, all while respecting privacy and the law.
‼️ LG monitors are silently installing adware on computers through an LG app because Windows allows to automatically fetch apps for connected devices with full system access.
Once an LG monitor is connected to a Windows PC, it triggers Windows Update to fetch the LG Monitor App Installer, an app whose store listing grants access to "All system resources," with no consent screen and McAfee trial ads following shortly after.
Microsoft's role deserves scrutiny too. The Windows feature was built for drivers and companion utilities, not for ad software with full-resource permissions.
The same behavior was found by YouTuber Gamers Nexus on monitors up to three years old, including ones already in use at its own office. LG has not publicly responded, and the first consent screen you ever see is the ad.
A guy named Shin just open-sourced Palantir for free.
It is called OpenPlanter.
Palantir helps governments and giant companies connect scattered data about people, businesses, contracts, and money.
OpenPlanter could give that same power to ordinary people.
Feed it corporate records, political donations, lobbying disclosures, government contracts, or other public documents.
Its AI agents search through everything, identify the same people and companies across different datasets, and turn the connections into a live knowledge graph.
You can click an entity, follow its relationships, and inspect the original sources behind each finding.
The desktop app already works on macOS, Windows, and Linux. It supports OpenAI, Anthropic, OpenRouter, and local models through Ollama.
But OpenPlanter is still an early-stage project.
It is nowhere close to having the data, resources, or maturity of Palantir.
Still, the idea is huge.
Powerful institutions have spent years using data to investigate the public.
Now the public may finally get a tool for investigating them.
🚨 CRITICAL: WordPress has force-pushed emergency updates 6.9.5 and 7.0.2 to kill "wp2shell," a pre-auth RCE chain in core that lets anonymous attackers run code on default installs, no plugins required. No exploitation observed yet, per Searchlight Cyber, but sites on 6.9.0 to 7.0.1 should verify they're patched today.
WordPress rarely overrides an administrator's choice to disable updates. On July 17 it did. Spending that mechanism is the clearest signal of how seriously the project is treating the flaw.
🛑 URGENT - A single anonymous HTTP request can run code on an unpatched #WordPress 6.9 or 7.0 site, even on a default install with zero plugins.
The new wp2shell flaw sits in core and still has no CVE for scanners to match.
Affected releases and mitigations 🠖 https://t.co/K0BhT3DwJ7
⚠️ 7-Zip Vulnerability Exposes Millions of Users to Remote Code Execution Risk
Source: https://t.co/iRliCYhIwE
A newly disclosed vulnerability in 7-Zip, one of the most widely used open-source file archiving tools, could allow remote attackers to execute arbitrary code on affected systems.
Tracked as CVE-2026-14266, the flaw stems from improper handling of XZ chunked data and has been addressed in the latest software update. The vulnerability resides in how 7-Zip processes XZ-compressed data streams.
Specifically, specially crafted XZ chunked data can trigger a heap-based buffer overflow, a memory corruption issue that occurs when data written to a buffer exceeds its allocated space.
#cybersecuritynews #vulnerability
Proton VPN just shared that it received 47 legal orders through June this year, all seeking to identify users behind specific server IPs and timestamps. Every one was denied, because its no-logs policy leaves no connection data to hand over.
Per its transparency report, updated July 14, that brings the total since 2019 to 458 orders, with zero fulfilled. The company keeps no connection logs under Swiss law, so there is nothing to produce even when an order is binding.
🚨 Microsoft just released its largest Patch Tuesday ever.
🩹 570 vulnerabilities fixed
🔥 3 zero-days (2 actively exploited)
💻 141 remote code execution flaws
Microsoft recently warned larger Patch Tuesdays were coming as it uses AI to help discover more security flaws before attackers do.
➡️See full report: https://t.co/54Kxatd2WK