Saw a lot of people asking who animated the Wuthering Waves × Rebecca collab intro — that was us! We’re a Shanghai-based studio, commissioned by Kuro Games to produce all the hand-drawn 2D animation for it. Huge thanks to Kuro Games for the opportunity, and to everyone for the love and the discussion.
#WutheringWaves
#Edgerunners
#Rebecca
#cyberpunk2077
Chapter 3 Act 3
The Star That Voyages Far ✅
Yo this quest was absolute Cinema.
Writing ,animation quality,
presentation was top notch what hell man 😭
9/10
I don’t even know what to say about this patch.
10/10
MASTERPIECE ✋😎🤚
FREE GAME???
The quality in every aspect is crazy.
Kuro is actually insane, improving again and again
The Exostrider, Lahai Roi, truly is based
Civilisation has no sun? Take my reactor
No ecosystem? Take my parts
Cant predict void storms? Take my eyes
You built me an imperfect drive that will one day wear out, killing me?
Excellent, now we both have beating hearts
Wuthering Waves Version 3.3 Official Trailer | Reverbs From the End of Galaxies
"Over here, Aleph-1.
Right now,
you're dealing with me."
Wuthering Waves 2nd Anniversary and Version 3.3 "Reverbs From the End of Galaxies" is set to launch on April 30th (UTC+8)!
#WutheringWaves #WuWa2Years #WuWa2ndAnniv
🇮🇩 🚨 Indonesia BIMA (Dikti Saintek) Data Leak — Lecturer & National ID Data Exposed
A dark web post claims a fresh leak from Indonesia’s BIMA system (Ditjen Saintek), exposing sensitive academic and personal data.
📊 Key Details:
• Target: BIMA – Indonesian research & higher education system
• Data types exposed:
NIDN (lecturer ID)
NIK (national ID number)
Full names
Email addresses
Phone numbers
Academic details (rank, institution, program)
Address and personal metadata
• Sample shows:
Structured JSON data
Real institutional references (e.g., universities, faculties)
🧠 Threat Intelligence Insight:
• This appears to be API/database extraction, not a simple dump:
Structured response format → likely backend/API access
Combination of:
NIK (national ID) + academic identity
→ highly valuable for:
Identity fraud
Targeted phishing against academia/government
• Education sector breaches often lead to:
Long-term credential abuse
Government-linked targeting
⚠️ Assessment:
• Moderate-to-high credibility
Clean structured sample
Specific schema and identifiers
“FRESH” claim cannot be fully verified, but:
Data does not look recycled or generic
⚠️ Risk Implications:
• Identity theft using national ID (NIK)
• Targeted phishing against lecturers and institutions
• Potential pivot into government/research networks
• Academic fraud and impersonation
📊 Status: Unverified — but credible leak pattern with high sensitivity data
⸻
💬 When academic systems leak national IDs, the impact extends far beyond the campus.
#CyberSecurity #DataBreach #Indonesia #BIMA #ThreatIntel #DDW
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine.
The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once.
The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine.
The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had.
That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months.
The attack chain is the part that gets worse every sentence.
TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials.
Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one.
The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions.
TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.”
Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours.
The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
SHARE 🚨 Indonesian workers under the HOSNESTUM movement are being attacked for demanding fair wages, labour rights and an end to exploitative outsourcing. While president Prabowo’s government defends obscene perks, Indonesians are left with rising taxes and shrinking security 🧵
Lewotobi volcano in Indonesia has produced a very large explosion. Listen to the video, you can hear lapilli/ash hitting roofs and the ground.... 🔊👀
📹 Oztha Zg/FB
OFFICIAL: The Bulls will retire Derrick Rose's number during the 2025-26 NBA season. No other player will ever wear the number 1 for the Chicago Bulls.
Number 1 will always be from Chicago.