"ah que item dupado some quando reloga" e quem disse que a falha é só dupe? também da para criar item válido. Vamos esperar a próxima atualização de emergência pra corrigir outras 300 falhas que tem no game.
#タスクバーヒーロー#TBH
"ah que item dupado some quando reloga" e quem disse que a falha é só dupe? também da para criar item válido. Vamos esperar a próxima atualização de emergência pra corrigir outras 300 falhas que tem no game.
#タスクバーヒーロー#TBH
🚨 CYBER INTELLIGENCE ALERT: ALLEGED DATA EXFILTRATION: STATE AND GEOGRAPHIC INFRASTRUCTURE — BRAZIL 🇧🇷
[STATUS: UNCONFIRMED / ALLEGED THEFT OF GEOGRAPHIC INTELLIGENCE DATABASES / SOURCE: UNDERGROUND FORUM]
THREATENING ACTOR "SHELl" CLAIMS TO POSSESS OVER 100 GB OF THE FEDERAL POLICE INTELLIGENCE SYSTEM DATABASE
The threat actor identified by the alias shelI has posted on a criminal forum the alleged exfiltration and sale of the complete database of the Inteligeo system, a centralized platform for collecting geographic, cartographic, and environmental intelligence information used by the Brazilian Federal Police (Polícia Federal - PF) for tracking commercial activities, environmental crimes, and territorial control. The attacker claims the stolen data exceeds 100 GB of structured data.
🏢 Allegedly Affected Entity: Brazilian Federal Police (Polícia Federal - PF / Inteligeo System).
👤 Threat Actor: shelI
⚔️ Potential Attack Vector: Code injection into Inteligeo backend endpoints, compromise of credentials belonging to analysts or investigative personnel of the PF, or leakage of SQL relational database backups exposed on perimeter servers.
🔍 Verification Status: UNCONFIRMED. As of June 22, 2026, neither the Brazilian Federal Police nor the Ministry of Justice has issued official statements regarding any data breaches affecting the Inteligeo system. However, the alert is being processed under criteria of high risk and criticality for the supply chain and national security, because the structured list of 106 database tables exposed by the attacker maintains absolute technical consistency with Brazil's internal environmental, mining, and financial control systems.
🗂️ FORENSIC ANALYSIS OF THE EXPOSED TABLE SCHEMA
The inventory of exposed tables reveals a massive compromise of data from multiple Brazilian ministries and regulatory agencies, consolidated within the Federal Police's database. The schema is divided into the following highly sensitive sectors:
🪵 1. Deforestation Control, Flora, and Environmental Management (Sinaflor / Ibama)
The database contains critical records related to the fight against environmental crimes and illegal logging in biomes such as the Amazon and the Atlantic Forest:
sinaflor_proj_merge_dash_a (and variants: asv, floresta, pmfs, uso_alt): Consolidated records from Sinaflor (National System for the Control of Forest Products), which regulates Sustainable Forest Management Plans and Vegetation Clearing Authorizations (ASV).
autorizacao_desmat_sema / autorizacao_exploracao_sema: State-level deforestation and exploitation permits issued by State Secretariats of the Environment (SEMA).
vw_embargos_ibama / vw_embargos_icmbio: Lists and histories of sanctions, fines, and active land embargoes imposed by Ibama and ICMBio on environmental offenders.
sicar_reserva_legal_pol / sicar_area_imovel_pol: Geographic polygons from SICAR (National Rural Environmental Registry System), revealing the boundaries of private properties and protected legal reserves.
🪙 2. Rural Credit and Financial Fraud Data (Central Bank of Brazil)
A section of particular interest from a corporate and regulatory compliance perspective:
vw_bacen_glebas / vw_bacen_mutuarios / vw_bacen_propriedades: Data linked to the Central Bank of Brazil (BACEN) and the SICOR system (Rural Credit and Proagro Operations System). ⚠️ RISK AND IMPACT ANALYSIS OF LOGICAL OPERATIONS
👤 Obstruction of Ongoing Police Investigations: By compromising the Inteligeo database, groups linked to organized crime, illegal mining, and Amazon deforestation could gain advance access to heat maps, investigation targets, Ibama enforcement actions (seizures/embargoes), and lists of properties under Federal Police scrutiny, thereby nullifying the element of surprise in tactical operations.
🛡️ TECHNICAL RESPONSE RECOMMENDATIONS (SOC / CSIRT BRAZIL)
🛑 Perimeter Isolation and SQL Query Forensic Audit: Administrators of the Brazilian Federal Police's digital infrastructure are urged to immediately audit the database management systems (DBMS) powering the Inteligeo environment, specifically looking for massive table dumps or unusual requests targeting the views (vw_) listed by the attacker.
📊 MONITORING AND EVALUATION
Intelligence System: https://t.co/wk9bZJ2Nli
Quickly assess your website's security at: https://t.co/QZhWp0kFrO
#CyberSecurity #Brazil #PoliciaFederal #Inteligeo #DataLeak #BacenLeak #IbamaEmbargos #Sinaflor #MiningProcesses #ThreatIntelligence #CyberAlert #VECERT #Infosec #UnverifiedIncident
Use recursos para criar um item dupado de level alto, recebe o ouro e xp da alquimia desses itens, reloga e os recursos voltam para repetir o processo. Pior de tudo é reportar, eles atualizarem e postar "Fixed a security vulnerability." e não corrigir nada.
#TBH
TBH está destruído, muitas falhas de segurança, equipe que não dá atenção quando reportamos e desculpinha de manutenção de emergência que nunca dá em nada. O mercado não voltará.
15 minutos de analise e olha no que deu.
#TBH#TASKBARHERO@TBH_JP
@Spigson@TBH_JP o mesmo vale para atributos de decoração, gravação e etc. Você consegue ficar adicionando e removendo até cair o atributo que você quer.
@Spigson@TBH_JP Sim consegui, durante a request ele envia o itemkey da moeda, só trocar pelo de outro consúmivel o client vai processar animação de "sumindo" entregar o item e quando relogar vai receber na caixa de mensagens a moeda novamente