Weird stuff going on. This is a CRAZY anime arc. I beg you to read this post. This shit is crazy.
Check this shit out
June 16th, 2025: @phrack reports suspected offensive state-sponsored activity from China and/or North Korea targeting South Korea. They notify KR-CERT (Defense Counterintelligence Command).
*In other words, evidence of China and/or North Korea successfully hacking companies in South Korea.
June 26th, 2025: South Korean government responds
July 17th, 2025: Phrack notifies KISA, Ministry of Unification, LG Uplus Corp, KR-CERT about offensive operations from China and/or North Korea
August 15th, 2025: Phrack e-mails terminated from Proton.
September 9th, 2025: Everyone starts screaming at Proton on social myself (us included). Proton apologizes and re-instates Phracks Proton e-mail
... then the twist
September 24th, 2025: South Korean parliament launches an investigation into the allegations against China and/or North Korea. They want to investigate the companies which were compromised
September 25th, 2025: South Korean government says they are going to perform an on-site inspection on several of the alleged compromised facilities
September 26th, 2025: A government data center is burned to the ground. 96 servers destroyed. All evidence gone. This includes evidence of China and/or North Korean offensive operations.
September 27th, 2025: Server fire reported to be caused by a Lithium-ion battery. The batteries that caused the fire were made by one of the companies which was compromised by China and/or North Korea
October 2nd, 2025: Another location which was believed to be compromised by China and/or North Korea is burned to the ground. All evidence gone.
October 2nd, 2025: A South Korean government official who was appointed to manage these inspections and overviews commits suicide
What the fuck is going on? How did a simple Lithium-ion battery burn an entire data center to the ground? Is it weird that another massive data center burned to the ground a few days later? Why did these fires only impact servers which were believed to be hacked by China and/or North Korea? Why are government officials killing themselves? Why the fuck is this not getting more attention? Why does my tummy hurt?
Find out next time on Dragon Ball Z
The security research community in Europe and the Middle East just got even stronger. Say hello to these new HackerOne Brand Ambassadors:
🇦🇿 @AzeriumD34132 (Azerbaijan—new club!)
🇧🇪 @dropn0w & @hgreal1 (Belgium—new club!)
🇩🇰 @mthirup (Denmark—new club!)
🇮🇹 @Al7eX91 & @Ciper_942 (Italy—new club!)
🇱🇧 @hasansheet (Lebanon—new club!)
🇸🇪 @joaxcar (Sweden—new club!)
🇳🇱 @yoerivegt (Netherlands)
🇫🇷 @DoomerOutrun (France)
🇵🇹 @secgus (Portugal)
🇹🇷 @jusxing (Turkey)
These ambassadors will fuel research, mentoring, and live events across the region. We’re glad they’re here!
Check out the program: https://t.co/Ryt41dy3Ng
#AppSec #EthicalHacking #H1Club
I just published "A case study of vulnerabilities in US government systems", a writeup of multiple vulnerabilities including Sqli, Command Injection, LFI and SSRF that I have reported through #bugcrowd.
https://t.co/aYiw3E4oSR #BugBounty
@HackenProof How far are you allowed to go with the Ukrainian VDP? If the scope has the approval of their government, I would be more than happy to help out, but the rules are quite limited. How "noisy" are you allowed to be without obviously being destructive/malicious?
My primary concern is basically that would-be whitehat hackers end up being flagged by the Ukrainian government as malicious attacks despite good will. Worst case, people can actually get into trouble, if their participation is mistaken for an actual attack
@Hacker0x01 You should reconsider encouraging the hackenproof program, since it doesn't seem to be legal. I haven't seen any permission from Ukrainian .gov or infrastructure to test for vulnerabilities. There might be would-be whitehats, who could get in trouble for this
I swear hackerone triagers are getting worse and worse. I reported an sqli to a vdp, had it marked as critical, and after it was patched, the triager closed it as informative = zero points. You had one job
@WPalant @BullGuard their twitter account is your best chance. I attempted through customer service, which didn’t go too well back then, but maybe things have changed since then :)
I’m legit curious about the amount of #bugbounty reports these days compared to the average. I wouldn’t be surpriced if all this isolation leads to a lot of creativity and hacks these days :D