Lovable has a mass data breach affecting every project created before november 2025.
I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account.
nvidia, microsoft, uber, and spotify employees all have accounts. the bug was reported 48 days ago. its not fixed. They marked it as duplicate and left it open.
reported april 11. both CVEs assigned. NI advisory dropped june 2. patched in 26.3.1.
not a remote 0day but a post compromise multiplier.
BlackCat, Scattered Spider, LockBit all use BYOVD to kill EDR before encryption.
https://t.co/aIrZKA1a6N
Gained two CVEs this week.
National Instruments ships on every defense contractor, chip fab, NASA test stand, and national lab in the country. their core kernel driver nipalk.sys is EV signed and valid through 2027. arbitrary physical memory read/write with zero authentication.
CVE-2026-8035. CVE-2026-8036.
the driver has no access controls. any program on the machine can open it and start issuing commands. no admin or privileges required.
its EV signed and loads on any windows machine without NI hardware installed. not on any blocklist.
this is a BYOVD.
- You have not secured impacted accounts
- They are not getting a password reset notification, they're getting a notification that their account has been successfully stolen
- "we are now working to restore access to affected individuals" This is the same sentence as the last one but flipped. Contradictory.
- Why aren't we getting official statements instead of vague tweets
- You have not secured impacted accounts
- They are not getting a password reset notification, they're getting a notification that their account has been successfully stolen
- "we are now working to restore access to affected individuals" This is the same sentence as the last one but flipped. Contradictory.
- Why aren't we getting official statements instead of vague tweets
@manipulate Thank you for raising this. While we have already secured impacted accounts, we are now working to restore access to affected individuals. Some people may receive password reset notifications and some may be asked security questions when they try and log into their accounts.
below in this thread here there are also multiple people with short handles or OG usernames also still getting hacked this is the 3rd day and theres still NO FIX.
https://t.co/CQBULWxXrJ
I kept telling everyone the Instagram exploit is not "patched" because AI is not linear. The exploit evolves so long as the tooling is still there.
I just had one of my OG accounts hit. Got it back but this is June 2, 2026 almost two days post patch.
The OG usernames "treat" and "sold" were just stolen, meta clearly has not fixed anything, they seem to not be able to switch off the scary AI monster.
https://t.co/4HZaUPI8Ia
This is a very silly photo.
@weezerOSINT shared a photo of someone speaking with Instagram Trust & Safety. They told him what he is describing is "impossible" and denied the existence of the AI bug thing
"It doesn't exist, nerd. AI is never wrong" - Zuckerberg, probably