๐คฏ The company that literally pays hackers to find bugsโฆ just got hacked.
HackerOne โ the world's biggest bug bounty platform, trusted by the Pentagon, Google, Microsoft โ just disclosed a data breach affecting nearly 300 employees. SSNs, addresses, dates of birth, health plan info, dependent details โ all stolen. The breach didn't hit HackerOne directly but came through their benefits provider Navia, which had a basic API vulnerability exploited for almost a month.
The kicker? Navia took WEEKS to even tell HackerOne about it. The company that exists to catch exactly this kind of flaw is now publicly slamming its own vendor for sloppy security. And the bigger picture is terrifying โ the Navia breach hit 2.6 million people total across all their clients.
If even HackerOne isn't safe from supply chain attacks, are any of us? ๐
source: https://t.co/X4t2RTUK5j
#cybersecurity #infosec #quitehacker #hackerone #databreach #bugbounty #supplychainattack #hacking
โ๏ธ One typo. That's all it takes. You type "telegrgam" instead of "telegram" โ and hackers own your PC.
Attackers built fake Telegram download sites with URLs so close to the real thing, you'd never notice the difference. Click download, and you get what looks like a normal installer. But behind the scenes, it immediately kills your Windows Defender, drops hidden files, and runs malware directly in your computer's memory โ meaning your antivirus literally can't see it because there's nothing on disk to scan.
The scariest part? Multiple fake domains are active โ telegrgam[.]com, telefgram[.]com, tejlegram[.]com โ all waiting for one careless typo. The malware connects to a remote server giving attackers full access to your system while staying completely invisible.
Always download apps from official sources only. Always check the URL. One letter can cost you everything ๐
source: https://t.co/pUhTEFZjsN
#cybersecurity #infosec #quitehacker #telegram #malware #phishing #hacking #infosecurity
The Indian government is now paying hackers to break into Aadhaar. On purpose.
UIDAI just launched its first-ever bug bounty program โ officially inviting ethical hackers to find vulnerabilities in the system that holds biometric and identity data of over 1 BILLION Indians. We're talking your fingerprints, iris scans, address, bank links, phone numbers โ everything.
They've handpicked 20 security researchers to test the Aadhaar website, myAadhaar portal, and QR code app. Bugs get classified from Critical to Low, and researchers get paid based on severity. It's a proven cybersecurity model that companies like Google and Apple have used for years.
Good move, but real talk โ Aadhaar has faced data leak controversies for years. Better late than never? Or too little too late? Drop your honest take ๐
source: https://t.co/vmuxzDHRMa
#cybersecurity #infosec #quitehacker #aadhaar #uidai #bugbounty #india #ethicalhacking
Meta says if you want real privacy, switch to #WhatsApp. Yes, they actually said that.
๐ The app you're reading this on just killed your DM privacy.Meta confirmed it's permanently removing end-to-end encryption from Instagram DMs after May 8. That feature โ the one thing keeping your private conversations actually private โ is gone. Meta's reason? "Very few people were using it." So instead of making it default, they just scrapped it entirely.
Without E2EE, your Instagram messages can technically be accessed by Meta for content moderation, handed over to law enforcement, or targeted by hackers. Meta's own advice? Use WhatsApp instead. Imagine a company telling you their own product isn't safe enough.
Security researchers are calling this a major reversal. Some suspect it's about enabling AI training on message data or bowing to government pressure on child safety scanning.
Download your encrypted chats before May 8 or lose them forever.
https://t.co/5qnO5Hs3il
#instagram #meta #encryption #privacy #dataprivacy
#Starbucks Data Breach Exposes Employee Accounts
Starbucks has disclosed a data breach affecting hundreds of employees' accounts. This incident raises concerns about personal data security. The company is investigating and enhancing security measures to protect affected individuals.
https://t.co/4Sl7uVQWf1
#Stryker Hit by #Cyberattack, Global Network Disruption Confirmed
Stryker is facing a global network disruption due to a cyberattack. This affects their medical devices and services, potentially impacting patient care. Stay updated for more information on the situation.
#IranWarโ
https://t.co/qfiWXJfugu
The U.S. is officially engaged in a cyberwar with #Iran, marking a historic moment. This conflict affects not just governments but everyday people, as cyberattacks can disrupt daily life. Stay alert and informed about your online security as this situation unfolds.
https://t.co/OnMnkLleBm
Anthropic vs The Pentagon โ The Story of How Anthropic Got Blacklisted
Jan 12, 2024
OpenAI Drops the Ban
OpenAI quietly removed "military and warfare" from its banned uses list. Days later, they confirmed they were already working with the Pentagon on cybersecurity tools.
Nov 7, 2024
Anthropic Goes Classified
Anthropic partnered with Palantir & AWS to deploy Claude on classified U.S. military networks โ becoming the FIRST AI company to do so. But with two rules:
1. No mass surveillance of Americans.
2. No autonomous weapons.
Feb 4, 2025
Everyone drops their pledges
Google removed its 2018 promise not to build AI for weapons or surveillance. Now every major AI lab had dropped military restrictions โ except Anthropic, which kept its two red lines.
JunโJul 2025
$800M Pentagon Contracts
The Pentagon awarded $200M contracts each to OpenAI, Anthropic, Google, and xAI for military AI. Anthropic's contract included its two restrictions. No one complained โ yet.
Jan 9โ12, 2026
"Won't Let You Fight Wars"
Defense Secretary Pete Hegseth released a new AI strategy demanding models be "free from usage policy constraints." At a speech he said: "We will not employ AI models that won't allow you to fight wars."
Feb 24, 2026
The 72-Hour Ultimatum
Hegseth called Anthropic CEO Dario Amodei to the Pentagon and demanded he sign a document removing ALL restrictions. Deadline: Friday 5:01 PM. The threat? Cancel the contract, blacklist the company, or force compliance by law.
Feb 26, 2026
Anthropic refuses
Amodei published a public statement refusing the Pentagon's demands. He said: "These threats do not change our position." Pentagon officials called him "a liar" with "a God-complex."
Feb 27, 2026
Trump Orders the Ban
Trump posted: "We will NEVER allow a RADICAL LEFT, WOKE company to dictate how our military fights wars." He ordered EVERY federal agency to stop using Anthropic. Hegseth then designated Anthropic a "supply chain risk" โ a label previously only used for foreign adversaries like Huawei.
Feb 27, 2026
OpenAI Gets the Deal
Hours after Anthropic was blacklisted, OpenAI announced a deal to deploy on the Pentagon's classified networks. The twist? OpenAI kept the SAME two restrictions โ no mass surveillance, no autonomous weapons. The Pentagon accepted their version.
Feb 27, 2026
430 Employees Fight Back
430+ employees from Google and OpenAI signed an open letter called "We Will Not Be Divided" โ urging their companies not to give the Pentagon what Anthropic refused. 100+ Google AI engineers signed a separate internal letter.
The Real Question
Who controls AI in warfare? Point: Anthropic wasn't anti-military โ they were the MOST embedded AI company in defense. The fight was about two narrow lines: no spying on Americans, no killer robots without human control. OpenAI got the deal with the exact same restrictions. Was this about policy โ or politics?
Follow @quitehacker for more!
#anthropi #openai #ClaudeAI #chatgpt #trump #DonaldTrump
1Password came out the strongest thanks to its "secret key" system. The other three are actively patching.
What password manager do you use? Still trust it? ๐
source: https://t.co/OxfU2hKSNT
#passwordmanager#bitwarden#lastpass#1password#dashlane
#Sitharaman, in her speech at Lok Sabha, revealed, how authorties detected โน250 Cr in unaccounted cash and โน90 crore in #crypto assets via #WhatsApp messages.
https://t.co/ggIy7eL45K
#Hackers targeting #OnlyFans accounts got a taste of their own medicine! A fake tool meant to steal login details is actually infecting hackers with #malware, stealing their own passwords and sensitive info. In #cybercrime, even hackers arenโt #safe!
ยฉ๏ธ:https://t.co/lS90oIONY3
According to current findings the threat actor leveraged a compromised employee account to copy employee directory data, i.e. names, corporate contact information, and encrypted employee passwords for our internal corporate IT environment.
#TeamViewer#DataBreach#Hacked
The #databreach at #BSNL involvesย more than 278GB of data from its telecom operations, including server snapshots, which can potentially be misused for SIM cloning and other serious criminal activities. The threat actor has made available the data for sale publicly at $5,000.