SOMEONE VIBE CODED A VIDEO STREAM THAT IS SECRETLY 100% TEXT SO IT CANT BE BLOCKED
it plays 360p video at 30fps, but theres no actual video on the page. every frame is just colored text characters being repainted on a canvas
to the browser its not media at all, its javascript updating some text
its called asciline, and here's the trick:
> the server decodes the real video and streams it as binary packed text over websockets
> the browser paints thousands of colored block characters fast enough to look like 360p
> ad blockers and autoplay blockers cant catch it because theres no video element to catch
> it streams in kilobytes since its just strings, so it runs on trash internet
since the video is literally text, you can apply css glows to it, let people copy paste a moving frame, or feed it straight to a local llm
however, an unblockable stream is also an unblockable ad as well
Given the sheer number of vulnerabilities this year, the lack of proper client notifications, and the hoops needed to remediate them, SonicWall has to be one of the worst firewall providers out there. #CyberSecurity
Threat actors decompiled and recompiled SonicWall's .NET based NetExtender client to include a backdoor that harvests VPN credentials ->
https://t.co/qh3Rj7P3sS
🇺🇦 МІНІСТЕРСТВО ОБОРОНИ УКРАЇНИ (MINISTRY OF DEFENCE UKRAINE)
🦠1st stage worm (PEEXE) dropping a PDF to deceive the victim: 49fbe34e093bac56ead3f6d275e5bc2c
➡️Next stages
/wxanalytics.ru/net.exe.config
/wxanalytics.ru/net.exe
🔗https://t.co/4hqHGTmExu
@aruhamm@_JohnHammond This is apparently tracked as Emmenhtal: https://t.co/UREWIkY95W
Most commonly, we've seen users hit this "captcha" when on streaming websites.
Looks like Airtel can collect, store and process your biometric data, ethnicity, political opinion, religious beliefs, trade union membership, health data, sex life or sexual orientation, bank details. From @redditindia#privacy
Hey @airtelindia@Airtel_Presence
Don't loot us
Rs 361 add on pack should have validity as your existing pack validity instead of only 30 days
Please bring old validity for this add on pack
Because we recharge it on top of our real plan
#Airtel
Important update about the polyfill[.]io supply chain type attack situation.
So, when Google started doing warnings that ads for pages/sites that uses polyfill[.]io can get suspended, they mentioned 3 more domains:
bootcss[.]com
bootcdn[.]net
staticfile[.]org
But somehow everyone skipped caring about that. Some of the first articles of the situation mentioned those domains in a way or another... and basically that's it. People literally just skipped over 3 more services/domains that were or are still being used in supply chain type attacks, just as the polyfill[.]io service/domain, from long months ago.
And by some quick checks, it seems that if we combine the count of websites that are using either of those 3 services/domains, we get at least a 300k-350k+ number. Some expert of this topic please look into this and verify.
But wait, this story is not simply about 4 different services/domains (polyfill[.]io + the 3 others mentioned by Google) being used in supply chain type attacks. But about that these 4 are all in the hands of the same people (gang?).
Today @zzwudev informed us (https://t.co/h1B4Ah3ivu) about that the "totally legit Chinese company" that bought the polyfill[.]io domain did some "little mistake": they leaked their Cloudflare "ApiToken" and "ZoneId" on Github.
🤦♂️
😂
Not even an hour later came @mdmck10, who did some "magic" and revealed (https://t.co/MYuiDvu6ji) that the Cloudflare account of which the leaked keys belongs to has these 5 domains in it:
bootcdn[.]net
bootcss[.]com
polyfill[.]io
staticfile[.]net
staticfile[.]org
In other words, this leak ended up in revealing that the supply chain type attacks that were/are being done using the 4 services/domains Google mentioned are actually being done by the same people/gang/anything. Crazy, no?
Also @zzwudev tweeted this: https://t.co/Q2D8mJXE3R.
If you take a look at the "Bootcss supplychain attack" link in his tweet, you can see an example of cdn.bootcss[.]com being used in a supply chain type attack already in February. In that case the next stage was this: https://www.unionadjs[.]com/sdk.html. Quickly looked around in relation to that domain and found this: https://t.co/mYXBBPguHC - here you can see some people in the past 2 weeks talking about both cdn.bootcss[.]com and cdn.staticfile[.]net are giving files containing malicious codes, with the next stage still being on www.unionadjs[.]com. That is, not surprisingly, behind Cloudflare...
So, now it is time for vendors for more blocking, for the at least multiple 100k affected websites' owners/admins/devs/etc to stop the usage of any of these other services/domains too, as soon as possible. And also as there are lots of articles talking about specifically the polyfill[.]io supply chain type attack already, probably it is also time for articles that are similarly talking about / informing people about the supply chain type attacks that are going for long months now with these services/domains...
🤷♂️
🎉 Woot Woot! 🎉 We’re celebrating 15 Years of Null Bangalore on August 31st! 2024
Calling all OG’s to join us for this epic milestone. Let’s make it unforgettable! 🚀
#NullBangalore#15Years#CyberSecurity#Community@null0x00
Stay tune for updates
⚠️ Update: Network data show #Bangladesh has now been offline for over 48 hours after authorities impose a nation-scale internet shutdown in a bid to quell student protests ⏱️
The blackout continues to hinder human rights observers and independent media at a critical time.
Process Injection is Dead. Long Live IHxHelpPaneServer: a way to execute the code in the context of another user without facing the need to inject in the process.
https://t.co/xgC1N6kClP
PoC: https://t.co/BsNMd02ZUP
Wow… another great quarter in the books for $CRWD. Thank you to our customers, CrowdStrikers, and partners for their dedication to our mission!
We delivered record Q1 FY25 results exceed expectations:
- Record Q1 net new ARR of $212 million +22% YoY
- Q1 ending ARR of $3.65 billion +33% YoY
- Record $322 million of free cash flow with a FCF rule of 68
Full results: https://t.co/HYmejDTe5C
@NahamSec When you want something and I say no but you figured out why I said no. So you change your request up slightly and ask your mom -- She says yes and has me go pick the item up from the store. That's what BurpSuite is doing but for websites.