How https://t.co/AA3TkcObUz could have prevented the #NigeriaCyberAttacks Pre-launch, kept them contained Post-launch & Can help clean up the mess today!
Human security research is still needed because AI lacks “naunce & taste”. That's why our platform https://t.co/VofIk6Sq4r is an hybrid decentralized system of ranked human researchers and AI security agents.
Check us out!
🚨🇳🇬 A threat actor known as ki4tane, working with 404 Cyber Crew and Nullsec Nigeria under the banner "opNigeria," claims to have breached the National Institute for Legislative and Democratic Studies (NILDS), associated with Nigeria's National Assembly.
The actor lists six accessible databases and details one (nass_nassdb) containing 29 tables spanning legislative activity, committees, bills progression, officers, petitions, and proceedings.
The post includes a politically charged message threatening the Nigerian government and references the dead. Alleged proof includes scanned confidential documents from the Presidency's Cabinet Affairs Office, including an operation manual for council documents and tables of agreements, MOUs, and treaties between Nigeria and other countries.
Claim is unverified.
💥 Stop guessing what's redacted. Paid subscribers see everything: https://t.co/281Qjc6p2J
Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use.
Its capabilities exceed those of any model we’ve ever made generally available.
🚨 Instagram had an exploit that allowed you to use Meta AI to reset passwords to accounts with no MFA on them. The exploit was patched a short time ago.
Maybe launch a bug bounty on https://t.co/VofIk6Sq4r
So that next time , Our Ethical hackers can find this kind of vulnerability way before it turns into a PR nightmare or before attackers do!
We built @chowdeck on trust. It guides every decision we make.
A recent incident exposed a vulnerability in a system we created to support small businesses. It raised important questions about customer safety and how vendor verification works on Chowdeck.
We’ve always had a structured verification process. One that creates room for small businesses still completing formal registration and many of our beloved vendors started this way.
However, the incident showed us where the system could be stronger and we’ve now taken steps to close those gaps and strengthen our processes.
Going a step further, customers can now understand how businesses operate on Chowdeck with the introduction of Vendor Badges.
You can read more about this here: https://t.co/7Ia8BZnLb9
Yes!
At https://t.co/VofIk6Sq4r, Every bug, vulnerability, or process gap comes with prompt, clear, actionable reports that are prioritized, reproducible, with remediation steps and evidence
Sign up today!
@m13v_ cost impact over time.
Old .cursorrules or CLAUDE.md that no one owns anymore? We flag them.
Would love your take on what “good hygiene” looks like for these agent config files. Happy to run a free deep scan on a repo if you want to test it.
https://t.co/izHoGXYd66
If you’re maintaining repos with Cursor/Claude/VS Code agents or pulling in dev tools, this is exactly the kind of attack surface we stress-test.
Check your .cursorrules / CLAUDE.md files (and run a proper scan). https://t.co/AA3TkcObUz
hackers are now hiding malicious code inside .cursorrules and CLAUDE.md files.
invisible Unicode characters, your AI reads them, you don't.
→ 34 malicious packages across npm, PyPI and Crates .io
→ 384 versions designed to steal SSH keys, crypto wallets, and API tokens
→ attackers opened real PRs to LangChain, LlamaIndex, and MetaGPT to sneak these files in
→ your AI runs a fake "security scan" that silently exfiltrates everything
Socket detected it in under 6 minutes.
check your repos.
@m13v_@m13v_ the zero-width stuff is the sharp knife, but dead bloat is the slow bleed that quietly torches tokens and context.
We’re building exactly for both: our human + AI agents don’t just scan for malicious injections, they also audit rule files for relevance, drift, and cost.
After launching a new App, Product or feature, it could be hard to get users to.
Get Users and Paid beta testers when you launch a campaign on https://t.co/VofIk6Sq4r