hackflix. movies for hackers.
sadly, none of them will teach you to breach the Pentagon by typing fast enough.
a community-curated watchlist about the internet, tech, and hacking. open a PR, add yours.
https://t.co/xS5YOYj4NO
#HappyHackingSpace#Diyarbakir
meet @om3rcitak. hacker, writer, free software partisan. he grew up chasing computers on the streets of Diyarbakır, and today he contributes to Happy Hacking Space from Berlin.
"no community back then. now there's HHS."
#HappyHackingSpace#CommunitySpotlight
hhs/screen 01.
Friday, June 5. 20:00. HHS HQ, Diyarbakır.
We're starting a community screening series. Opening with The Internet's Own Boy. Aaron Swartz's story.
Free. Snacks + drinks on us.
Address: https://t.co/g82Xo97gqN
#HappyHackingSpace#Diyarbakir
How to use Codex's computer use in EU for europoors better than nordvpn
- download Tailscale on your device(s)
- go to settings
- configure mullvad
- pay 5$ a month
- set exit node US based
- now you have a VPN for each node
- Albania for ur tv (no ads on entire home network)
🚨 GitHub source code allegedly offered for sale: Internal orgs and private repositories claimed
A threat actor using the alias TeamPCP claims to be selling GitHub source code and internal organization data.
The actor claims the dataset includes around 4,000 private repositories and says samples can be provided to interested buyers to verify authenticity.
━━━━━━━━━━━━━━━━━━━━
Target: GitHub
Country: United States
Sector: Technology / Software Development / Source Code
Incident Type: Alleged Source Code Sale
Claimed Exposure: Around 4,000 private repositories
Actor: TeamPCP
Price: Offers over $50,000
━━━━━━━━━━━━━━━━━━━━
According to the post, the actor claims the material includes source code and internal organization data tied to GitHub’s main platform. The post also references a public file list and includes screenshots showing numerous repository archive names.
Why it matters:
If authentic, exposed source code and internal repository data could increase the risk of code review by hostile actors, vulnerability discovery, supply chain targeting, impersonation, phishing, and follow-on attacks against developer infrastructure.
Status:
This remains an unverified underground forum claim. The actor states this is not a ransom attempt and claims the data may be leaked publicly if no buyer is found.
Stop guessing what's redacted. Subscribers see everything → https://t.co/281Qjc6WSh
pazar akşamı nevada coffee'de bir araya geldik.
farklı alanlardan hacker'lar vardı: yazılımcılar, kimyager, öğretmenler, çocuk gelişimci, lise öğrencileri, üniversite öğrencileri, fizikçi, siber güvenlikçiler, farklı sektörlerden girişimciler, yeni başlayanlar. 👇
🚨 UPDATE: 19 MILLION exposed NGINX instances hit by the 18-year-old NGINX RCE found by AI.
Top exposure by country:
- United States: 5,340,011
- China: 2,540,008
- Germany: 1,871,780
Note on ASLR as added security: not all of these instances will have ASLR disabled, but every one of them is running a version inside the vulnerable band.
The vulnerability is a heap buffer overflow. ASLR randomizes memory layout, which makes reliable RCE much harder because the attacker cannot predict where their payload or useful gadgets land. But the overflow itself still happens. The corrupted memory still causes the NGINX worker process to crash.
ASLR-enabled hosts are still trivially DoS-able. ASLR-disabled or non-PIE builds are RCE-able. Either way, patch ASAP!
@mdisec@OzgurKonorg@omarkurt Bunu biz de fark ettik, o yüzden ÖzgürKon sonrası ilk etkinliğimiz olarak; dört yılın ardından bir CryptoParty düzenlemeye karar verdik!
Bir süredir tozlanan Güvenlik Rehberi'miz için de ısınıyoruz :)
https://t.co/atz8IYhysp
❗️ UPDATE on today's npm supply-chain attack:
• Per Socket Security: 121 more compromised package artifacts found across 84 additional package names. 64 of them are UiPath artifacts.
• Combined with the earlier TanStack hits, the current known total is 205 affected npm package artifacts.
• Reach now spans enterprise automation, AI/MCP, auth, workflow, and dev tooling.
The worm is still propagating.
We got the email too.
We had a working RCE on Oracle Autonomous AI Database ready to demonstrate live at #Pwn2Own Berlin next week. ZDI confirmed they're at maximum capacity and can't add extra contest days.
AI is now generating offensive capability faster than the institutions built to process it can keep up.
We'll be in Berlin May 14-16 regardless. The conversations there will be really interesting!
Our security bug bounty program is now public on HackerOne.
We've run the program privately within the security research community, and their findings have strengthened our products. Now anyone can report vulnerabilities and get rewarded.
Read more: https://t.co/li1QvSTCMs