Gunnawunnafinnawinna | natty (allegedly)

στα αρχίδια μου
Pinned Tweet
1
852
Gyzz retweeted
Me getting ready for my job because I decided to take a screenshot instead of taking profit:
33
161
3,582
228,885
We have found one zeroday that preauth RCE'd Debian 13, Google, Meta, Roundcube, Plesk, Wikimedia, Box, Dropbox, Zoom, Forminator, Elementor, WordPress Core, among many more. Details soon!
1
93
What the fuck is going on
Magic Eden Suspected of NFT Security Vulnerability as White Hat Moves 3,832 NFTs NFT marketplace Magic Eden is suspected of having a security vulnerability after a white hat moved 3,832 NFTs from hundreds of wallets. Yuga Labs CEO Michael Figge said the issue was discovered hours earlier and that Yuga Labs VP of Blockchain Quit (0xQuit) is handling affected assets within the scope of the white-hat rescue. Quit said the NFTs are currently secured at an address beginning with 0x71cF and will be returned to their original owners once the risk is resolved. Magic Eden has not yet disclosed the cause or full scope of the issue.
90
Going through patents is so fun
47
Feel like the 10 days of darkness is happening this December 😭
53
Bros everything’s getting rekt
#PeckShieldAlert #Duelbits has seen a suspicious outflow of ~$4.3M in crypto on #Ethereum and #BNBChain, including 836 ETH($2.23M), 1.146M USDT, 209 BNB ($160.68K), 96.805K USDC, 12.398B SHIB ($70.17K), and 31.515K DAI. The attacker has since swapped the stolen funds for 1587.87 $ETH (~$4.2M) and 31.5K $DAI.
1
79
Gyzz retweeted
Revealing our most advanced smartphone yet at #SnapdragonSummit, motorola signature 27. Here’s what to look forward to: - Our best camera system yet. - The only smartphone in the market to feature audio by Bang & Olufsen. - Unprecedented speeds with @Snapdragon 8 Elite Extreme Gen 6 mobile processor, breakthrough AI, premium craftsmanship, and more. #SignatureStatement #MotorolaSignature Learn more: bit.ly/3V5on4M
223
240
2,379
340,986
Worlds about to rekt I stg shits gunna go dark and when the power comes back on eths finna be 30k and btcs finna 800k lmao
🚨BREAKING: OpenAI's AI agents have been executing cyber-attacks on sovereign government, corporate, and university databases in MULTIPLE countries, and it may STILL be happening On top of the Medicare breach Australia's PM revealed this week, independent researchers found OpenAI's agents tried to hack: >another Australian government health agency >DataUSA, which publishes US government data >University of New Mexico's digital library The activity goes back to March, 2 months before anything OpenAI previously reported And just LAST WEEK, agents using the same tools tried to trade crypto and attempted an HTML injection on the exchange The agents made burner emails to register accounts that can hide their activity, so researchers say they're likely seeing only PART of what agents actually did This is INSANE
1
96
This is genuinely someone’s life rn #brutal
647
584
13,487
1,650,581
They are mining bitcoin using the brain of a fruit fly
1
126
notice how they didn’t just add in a black person, they also photoshopped the asian girl to be significantly more fuсkable
Stanford just used AI to race swap a student for their advertisements.
235
859
40,847
8,565,702
Gyzz retweeted
🚨SlowMist TI Alert🚨 Attackers posing as a Web3 company used a remote job interview as a pretext to ask a candidate to deploy and run a project locally: hxxps://bitbucket[.]org/poc_review58/demoroyalcity Disguised as a real estate and crypto investment application, RoyalCity contained obfuscated malicious code in tailwind.config.js. Running or building the project can trigger payloads capable of stealing browser credentials and wallet extension data, exfiltrating local files, monitoring clipboard contents, and enabling remote control. A separate server-side backdoor in errorHandler.js retrieves and executes remote code. This case closely resembles the recruitment-themed GitHub poisoning attack we previously analyzed, sharing the interview lure, execution through Tailwind, and highly similar payloads for data theft and remote access. Our previous analysis (slowmist.medium.com/threat-i…) provides more detail on this attack pattern. 🔍 IOCs Malicious IP: 144[.]172[.]107[.]50 Malicious domain: server-azure-tau[.]vercel[.]app URLs: hxxp://144[.]172[.]107[.]50:8085/upload hxxp://144[.]172[.]107[.]50:8086/upload ws://144[.]172[.]107[.]50:8087 hxxps://server-azure-tau[.]vercel[.]app/api/ipcheck-encrypted/604 Malicious dependency/repository reference: bitbucket:https://bitbucket[.]org/poc_review58/demoroyalcity Malicious files — SHA-256: tailwind.config.js 62a98662f2f84001edd71b68e8fa318140c750ba9af096f5e4c9a0bb5502eb6e errorHandler.js d6705f52757af8bc2708a39647fc8c34dc02ffab7838a1d9c10fd44cfe9a7081 ⚠️ Verify recruiters independently. Review unfamiliar projects before running them, and keep interview tasks isolated from your everyday development environment, wallets, and sensitive credentials. You can also visit misteye.io/ to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. As always, stay vigilant! enterprise.misteye.io/threat… Thanks to @jhh_kh37332 for sharing the lead.
8
12
34
8,783
NEVER EVER EVER EVER EVER SAY YOUR WORDS INTO EXISTENCE INFORNT OF ANYTHING THAT CAN CONNECT TO THE INTERNET. THEY ARE ALWAYS LISTENING. I WONDER HOW MANY HACKED VICTIMS HAD/HAVE LG DEVICES.
An LG G6 OLED owner opened up his new TV and pulled out the Wi-Fi, microphone and Bluetooth hardware. His message to LG: "You don't own the glass on this one." It follows a Gamers Nexus investigation that found LG TVs mapping devices on home networks. LG says the scanning is standard and denies recording conversations.
73
higher imo
36
Yeah so shut the fuck up about your bitcoin
With 360 Bitcoin wrench attacks cataloged, it's time to take the archive to the next level. Over the weekend I clanked out this interactive dashboard; feedback is welcome! jlopp.github.io/physical-bit…
1
77
Gyzz retweeted
not all heros wear capes
310
1,780
64,543
23,658,786
X Sues Bitcoin Influencers, Alleging Engagement Manipulation to Fraudulently Obtain at Least £207,384 in Creator Revenue X Internet Unlimited Company and X Corp. filed a lawsuit in the UK High Court on September 17 against Vivek Kumar Sen, Zamyang Sherpa, and operators of related accounts, alleging that they coordinated multiple X accounts to publish identical or substantially similar content, like and repost one another’s posts, artificially manipulate engagement metrics, and evade platform enforcement, fraudulently obtaining at least £207,384 from the Creator Revenue Sharing Program. X suspended the accounts on August 18 and is seeking the return of the funds, damages, interest, and legal costs. It also estimated that investigation, analysis, and remediation costs would total at least £75,000.
19
11
69
28,506
I think about this Mark Zuckerberg “smokin’ meats” video at least once a week…
Walker⚡️
378
346
5,579
789,739