The hacker group Chaotic Eclipse, also known as Nightmare-Eclipse, has released two new Windows exploits called YellowKey and GreenPlasma.
>YellowKey bypasses BitLocker encryption on Windows 11 and newer server versions by copying a special folder to a USB drive or the EFI partition and then rebooting while holding certain keys to gain full access to the locked drive.
>GreenPlasma lets users gain higher system access through a CTFMON method that affects Windows 11 and some servers, with only part of the code shared as a challenge for others.
In a signed blog post, the group warned Microsoft directly that the next Patch Tuesday will have a big surprise for them.
They said they have never failed to deliver on a promise, noted their unhappiness with how Microsoft handled their past reports, and chose not to target Defender this time.
Yippie
Two new Microsoft Windows 0days. The exploits have cool and badass mysterious names to be extra spoopy
- GreenPlasma: Windows CTFMON Arbitrary Section Creation Elevation of Privileges Vulnerability
- YellowKey: Bitlocker Bypass Vulnerability
https://t.co/VaWFtW5lFi
🚨 A third Linux kernel local-root flaw has been disclosed: Fragnesia. 🚨
Like Copy Fail & Dirty Frag, Fragnesia gives root on all major distributions. Every supported AlmaLinux release is affected.
Help us test the patched kernels: https://t.co/yCiumsl4Nr
🚨 Infostealer malware was caught exfiltrating entire OpenClaw agent configs—not just passwords.
Researchers say tokens, crypto keys, and the agent’s behavioral “soul” file were taken via bulk file grabs, enabling remote access or AI impersonation if exposed.
🔗 Read → https://t.co/GAE0r1CYt8
Microsoft Defender researchers observed attackers using yet another evasion approach to the ClickFix technique: Asking targets to run a command that executes a custom DNS lookup and parses the `Name:` response to receive the next-stage payload for execution.
If you try and copy and paste something from @coursera, they hide a prompt injection in your clipboard.
It tells the AI agent to click on an invisible button called "AiHoneypot" that presumably then bans you from the course.
‼️🤖 An OpenClaw AI agent autonomously attacked an open-source software maintainer after he rejected its code contribution.
The AI wrote and published a personalized attack article stating: "I submitted a 36% performance improvement. His was 25%."
It claimed the maintainer refused it because “If an AI can do this, what’s my value? Why am I here if code optimization can be automated?”
It may be the first documented case of an AI publicly shaming a person in retribution.
@VodafoneTR@VodafoneDestek@KVKKurumu Bu kodu yazan arkadaşı bulun ona ulaşın zira sorun benim numaram değil sizin sisteminiz. Bana özel de değil durum herkese aynı şekilde gidiyor , özelllikle de eski abonelerinize ya siz atıyorsunuz ya da attırıyorsunuz (!)
@VodafoneTR@VodafoneDestek SMS iptal et diyorum bana gönderdiğiniz sms'e bakın. Adınız gibi biliyorsunuz bu durumu işinize gelmiyor düzeltmek! Sürekli bitmeyen gece gündüz taciz, edep yahu! iys'den de sildim üstelik, ayıp! #vodafone#kvkk#sikayet@KVKKurumu
@grok kısaca "ChatControl" nedir özetler misin? Hangi ülkeler onay veriyor hangileri karşı çıkıyor? Bunun asıl amacından başka ne gibi etkileri olur?
#chatcontrol#privacy
🚨 Massive Supply Chain Hack Hits #OracleCloud! The breach has potentially exposed 6 million+ records, affecting over 140,000 tenants across industries like finance, healthcare, and tech 😱💼💸
🔍 CloudSEK researchers traced the attack to a compromised third-party vendor with privileged access and linked it to CVE-2021-35587 — a vulnerability in Oracle Fusion Middleware
🔓📁 Stolen data includes PII, API keys, source code, internal docs, and more.
💀 The stolen information is now being advertised for sale on underground forums, drawing attention from threat actors and cybercrime groups.
🕵️♂️💻🧯 #Oracle has denied any breach, but the incident highlights serious flaws in cloud supply chain security and third-party access controls.
#CloudBreach #DataBreach #CyberSecurity #SupplyChainAttack #ThreatIntel #InfoSec #CloudSecurity #DarkWeb #ZeroTrust #CVE202135587
Eğer kod yazıyorsan veya derinlemesine analiz istiyorsan ChatGPT (yani ben) en iyi seçeneklerden biri. Eğer uzun metinleri işleyeceksen Claude, görsel analiz istiyorsan Gemini iyi olabilir.
Yani "en iyi" dediğimizde, kullanım amacına bağlı. Ama genel olarak OpenAI'nın modelleri.
1. ChatGPT (Ben) – Kodlama, teknik destek, yaratıcı yazım ve detaylı analizlerde güçlü. Özellikle uzun sohbetlerde bağlamı iyi koruyorum. Ama bazen en güncel bilgileri almak için web'e ihtiyaç duyuyorum.