I myself have seen 5-6 UFO’s in my lifetime, all displaying similar characteristics that defy the laws of physics or otherwise unknown capabilities. The question is no longer if they exist but is it a tiny green man operating them or casper the ghost on crack . @ageofdisclosure
Actual message I received today:
Hey Nikita, I run an elaborate username hacking and reselling operation. I hold basically every dictionary-word username.
I noticed that you seized all of my hacked accounts. Some of them were worth a lot. I was wondering if you could give them back.
it's been long enough now that i feel like i can break my silence on this:
samsungs (allegedly) $200-$200K bug bounty program paid me just $5000 for the "High Severity" vulnerability that would've allowed me to supply chain attack their whole cloud environment.
X has exposed and is taking strong action against a bribery network targeting our platform. Suspended accounts involved in crypto scams and platform manipulation paid middlemen to attempt to bribe employees to reinstate their suspended accounts. These perpetrators exploit social media platforms like Instagram, TikTok, YouTube, Minecraft, and Roblox and are linked to wider criminal organizations, including “The Com.” Legal proceedings are underway against participants, and we're fully supporting law enforcement. Our commitment to ensuring our platform’s integrity is absolute.
@osenya31@vxunderground the idea of Opsec is about to explode lmao. People have no idea how to use the internet. n yes, Digital gangster/lulzsec days were something else
So, these threat actors successfully phished an author of multiple open source NPM packages with a total of 2 billion weekly downloads – including debug, chalk, and ansi-styles.
Since most companies run at least one React or Angular app, they had the opportunity to execute code on millions of systems across thousands of orgs.
And they used it to drop an amateurishly obfuscated crypto stealer, got caught by basic detection rules, and the issue was remediated after 2 hours.
I hope everyone understands how close this was – and can imagine what would’ve happened if someone with real skills had done it.
#NPM #Compromise #SupplyChain
🚨 Breach alert: Attackers claim live access to AT&T infrastructure. Alleged impact: enables SIM-swapping, reading SMS 2FA codes, and accessing a database with ~24M AT&T customer records.
Holy shit, dude
Zeekill got his own HBO documentary. This guy was a serial swatter and part of Lizard Squad.
This guy was NOT a "dangerous hacker". He a swatter, DDoSer, and extortionist.
HBO, dawg, don't glorify these guys.