Someone found a way to see inside the X phishing panel I shared earlier. Indeed confirms what I thought the capabilities and impact are.
Interesting to see how they leverage the OAuth token via the panel directly for controlling the accounts. Thanks for the ping.
Perhaps the most important thing you could do is implement logging that goes outside the VPS. This will allow you to identify if/when it is compromised.
Most people don’t have SIEMs (effectively log aggregators) at home, but at a minimum you could have frequent rsyncs of logs that can be analyzed.
No one is perfect, myself especially. If someone makes a bad call - intentionally or not - I think we should be pleased when they make a good call. It doesn’t necessarily correct the ledger, but perhaps it is the start of a new trend.
I appreciate the contribution @CertiK made to the QF.
Looks like a threat actor under the name BlackTigerAlliance" has released personal information on the executives of Integrity Tech, the Chinese cyber security company accused by the US Treasury department of intrusion into US victims IT infrastructure. 1/2
@bradmillscan@jordanurbs My Hermes usage is dramatically higher using Kimi 2.6 (via @AskVenice ) than it would be with Codex/etc. It is incredibly cost efficient, and I feel more comfortable with the privacy.
Just grab a subscription (or stake $VVV for a “free” subscription) and give it a try.
Chinese-linked actors are targeting edge devices across Southeast Asia, leveraging DoH for C2 communications and large-scale DNS hijacking via iptables.
See details:
EN: https://t.co/32wGyWROwR
CN: https://t.co/7mpQgo4I6V
Greg Maxwell used to send us updated lists of malicious spy nodes that Bitcoin peers should ban. I reached out to him asking for the latest list, and this was his reply:
I have a gripe about @X that I wish @nikitabier could fix, but may be impossible.
Recently, RuView went viral. You probably remember it - the Github project that allows you to see through walls with WiFi. It was all over my "For You" and big accounts posted about it.
But....Do you recall anyone actually deploying the project?
Plenty of folks posted about it...but very few actually posted about using it. Let's look at that briefly. These are the people actually putting in the work and getting near-zero traction.
https://t.co/wpIjdYY3rq - 9 followers, 50 views on his post.
https://t.co/5eOJKGdF4W - 7 followers, 343 views of his reply (to a post with 125k views)
After seeing one hype post about the project, I'm more interested in whether it works. But I had to go to @grok to find these posts (thanks bud).
Am I doing something wrong, or can @X find a way to surface simple, low-view high-impact posts related to content that gets substantial views?
Organized crime is evolving into a global, tech-enabled threat.
From cyber scams to drug trafficking, criminals are expanding their reach & causing real harm.
A new UNODC research brief examines how these groups operate and profit: https://t.co/dYyn1hp7RJ