Analyzed a PowerShell malware loader that hides its second stage inside a seemingly legitimate MP3 file.
Key observations:
• Downloads result.mp3
• Extracts bytes from a fixed offset (12345)
• Decrypts the blob using an RC4-like stream cipher with key "ZHOPA"
• Attempts in-memory execution via VirtualAlloc + NtCreateThreadEx
This is a nice example of payload smuggling using non-executable media files.
https://lincdiiin[.]com/homework.txt
https://lincdiiin[.]com/Program.exe
https://lincdiiin[.]com/loader.hta
https://lincdiiin[.]com/result.mp3
Someone found an RCE on my website yesterday.
CVE-2025-55182.
React2Shell.
I don't have a bug bounty program.
I never asked for a security assessment.
I woke up to a DM: "Hey I found a critical vulnerability in your site. I only ran the exploit to verify it worked. Here's my PayPal for the bounty."
Bounty?
I checked my logs.
Forty-seven requests to my RSC endpoint.
Something, something ... Prototype pollution payloads.
They used the GitHub script.
The one with 2,000 stars.
The one that runs id automatically "for verification purposes."
They spawned a shell on my production server.
uid=1001(nextjs) gid=65533(nogroup)
They took a screenshot.
They posted it on Twitter.
"Popped a Shell on a Live Website 🚀💀 #BugBounty #CVE-2025-55182 #YOLO"
They got 84781 likes.
My customers' data was on that server.
I asked them to delete the screenshots.
They said "I removed the domain name, you should be thanking me."
Thanking them.
For unauthorized access to my production infrastructure.
For running arbitrary commands on systems I own.
For posting proof of exploitation for clout.
They called it "responsible disclosure."
I called my lawyer.
They called me "ungrateful."
I called the FBI.
Now they're in my DMs explaining that "this is how the industry works" and I "don't understand pen testing."
A pen what?
I understand it perfectly.
I understand that running https://t.co/C6kmBequB5 against random websites isn't research.
I understand that "I removed the identifying info" doesn't undo the unauthorized access.
I understand that #BugBounty doesn't apply when there's no bounty program.
I understand that finding my site on Shodan doesn't constitute authorization.
Their followers are defending them now.
"Presumption of innocence."
"You don't know if it was authorized."
"The screenshots were redacted."
Three hundred people are calling me a bootlicker for reporting a crime.
Someone said I should be grateful they didn't deploy a cryptominer.
The bar is underground.
I just wanted to run a small Next.js app.
I didn't ask to be someone's proof-of-concept.
I didn't consent to being their "first"
I didn't sign up for an unscheduled penetration test from a stranger with a GitHub account.
There is no safe harbor for spraying public exploits at random websites.
There is no legal protection for "I was just verifying the vulnerability."
There is no ethical framework where unauthorized prototype pollution is a favor.
But sure.
Thank you for your service.
You found a CVE that was already public.
Using a tool someone else wrote.
Against a target that never authorized you.
And you posted about it on main.
For likes.
Hero.
October 17th, 2025 EUROPOL performed Operation SIMCARTEL
They arrested 7 people and seized:
- 1,200 sim boxes
- 40,000 active sim cards
- 5 servers
- gogetsms
- apisim
- 4 luxury cars
- $502,000 in bank accounts
- $310,000 in cryptocurrency
They also released a badass video
If I were an attacker, I wouldn't drop a web shell to persist & maintain remote access
I'd download & install XAMPP, configure phpmyadmin and use that
The SOC wouldn't mind, the AV and EDR would stay silent, the forensic analyst would ignore it
Laser-Based Audio Injection on Voice-Controllable Systems
I think this is very cool
Website: https://t.co/CD88ovNHzo
Paper: https://t.co/9SYAkHHsbB
#infosec#cybersecurity
I usually make short-form satirical videos for fun, but never share them with the world. This time tho, I thought I'd make one for the infosec community. Some might even find it educational 😅
If you're in #infosec and you feel a little down this week, this video is for you💙