NEW: Instagram is notifying victims of massive hacking campaign that relied on asking Meta AI support chatbot to hand over control of accounts.
The hacks apparently continued on Tuesday even though an Instagram spokesperson said on Monday that “the issue has already been fixed.”
Stop paying $20 per month for Claude Code. McDonald’s AI bot is FREE.
Someone asked a McDonald’s support assistant how to reverse a linked list in Python.
It answered correctly. Actual code.
We’re definitely at peak AI now.
⚠️ UPDATE: The 2 major Instagram exploits we posted about are getting abused after quietly working for months.
The method lets attackers take over accounts by using a VPN to match the account’s country region, starting a password reset, then convincing Meta’s AI support to swap the email.
High-value usernames like @hey have reportedly been stolen, with over $1M+ in accounts already pulled over the past 3 days.
Said it in the beginning - the claims software engineers were dead was the dumbest thing ever. We are hiring more devs - not less. We have more work than we’ve ever had in the existence of the company.
This is the software engineering boom not decline with AI.
🔥 Microsoft Slams Public Zero-Day Disclosures for putting Windows users at risk.
A researcher recently disclosed multiple zero-days in Defender, BitLocker and other components. Three are now under active exploitation.
GitHub removed the researcher’s account. A new GitLab account was also blocked.
Read the full story: https://t.co/JdCKkTr5CE
⚠️ ESP32 BlueJammer Turns a Tiny ESP32 Into a 2.4GHz Chaos Machine — Disrupting Bluetooth, BLE, WiFi, IoT Devices & RC Signals
• Built with ESP32 + dual nRF24L01 modules
• Covers Bluetooth, BLE, WiFi & RC drone frequencies
• OLED mode switching + multi-channel firmware support
• Custom PCB, 3D printed case & battery-powered portable setup
• Includes web flasher, hardware schematics & DIY tutorials
• Range reportedly exceeds 30m with upgraded antennas
Not a toy. RF jamming is illegal in most countries and can interfere with critical communications. Study the hardware, RF concepts and firmware architecture — don’t use it recklessly.
https://t.co/NpzUjA3a8l
#ESP32 #Bluetooth #WiFi #Cybersecurity #HardwareHacking #RF #IoT #OSINT
Life was better when there was a ‘computer room.’ Where you had to physically enter the room to get on the internet and then log off and leave that room and the internet stayed behind. The minute we were able to take it with us in our pockets that’s when society collapsed fully
Microsoft has banned Nightmare Eclipse from GitHub: https://t.co/EmeiJnJ0Ps
This is the researcher who disclosed several zero-days after Microsoft also deleted their MSRC account.
They have now moved on to GitLab: https://t.co/Npj0gplSum
(h/t to: @[email protected])
🔥🚨LATEST: Chinese tech company Meng Xiaoyi claims they just created a pet translator with 95% accuracy that transforms the sounds and behavior of your pets into human speech for the price of $118. They currently have over 10,000 preorders for this product.
Tenant enumeration is dead.
Microsoft has now patched both techniques that allowed full tenant domain discovery from a single unauthenticated request.
That changes recon against M365 environments significantly.
The signals still exist, tenant IDs, MOERA prefixes, brand metadata, but no single query gives you the full picture anymore. Effective enumeration now means chaining techniques together, validating against large datasets, and in some cases requiring authentication.
Juan Pablo Gomes Postigo breaks down:
• what the original technique was
• what still works today
• how we updated https://t.co/odd5t8dr5G going forward
https://t.co/NjDIibtx4V
#CyberSecurity #Pentesting #IdentitySecurity #SecurityResearch