Do It by Code
54 subscribers
714 photos
100 videos
15 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
Forwarded from iDubTG
All the ai-pilled devs at telegram, I hope you remember that markdown is objectively a bad language, difficult to parse, and computationally expensive to render.

Of course, vibe coders know none of this.
Forwarded from HN Best Comments
Re: GTA 6 Developers Unionize

Game dev here, have worked on AAA and indie.

First off let me get on my high horse and say the engineering in video gaming is generally more complex than the engineering I've done working in big tech. You need a lot more creativity and ingenuity to solve the unusual problems you run into in gaming.

From there, as others have said, it's a simple supply and demand issue. Nowadays I am a university professor, nearly every student who comes in wants to pursue one of the three fields: cybersecurity, video gaming, or recently ML/AI.

This shouldn't come as a surprise, they want to work on the things that influenced them and shaped their experiences so far. There's an absolute over supply of students who want to make video games.

Gaming, like most of entertainment, is a passion-driven industry. You trade good salary for your name in the credits. You trade nights, hobbies, marriages, and your health for this opportunity. That is unless you reach that lofty 1% of developers who are too valuable to be fired.

Not all areas of gaming are like this. Gambling, like working on slot/pachinko machines, pays very well and has pretty realistic work-life balance. However every student I've talked to about this has universally said "no I don't want to make slot machines. I only want to work on GTA/Stardew Valley/Hollow Knight/Fortnite."

There's seriously no shortage of starry-eyed students who are willing to accept minimum wage to solve SDE3 level problems. I was one of them once.

sonzohan, 6 hours ago
Forwarded from vx-underground
Hello,

If you're a person who enjoys malware and/or knows Python and wants to see malware that targets STEAM and GAMERS, I have the source code to a malware I have named "Stealer.Python.GMBA.Manipulator".

This malware was originally noted on Xitter from GMBA.

In summary, this Python malware kills the Steam process and relaunches it with the "-cef-enable-debugging" flag. Because Steam is a Chromium app, this allows the malware payload to manipulate Steam web pages with web socket gunk and Javascript gunk.

This malware can "modify" user inventories, "block users", etc. It is all a facade designed to trick and social engineer Steam users into giving their expensive Counter Strike stuff to them.

It appears to be written using AI. Regardless of that fact this malware is creative and I like it.

The malware source code to this can be found under the "/Python/" directory. It is named "Stealer.Python.GMBA.Manipulator.7z".

This malware campaign is still active and the C2 is still live. If you execute the __main__.py file you might cook yourself, so be careful. Alternatively, you can run this in a VM and send the malware campaign authors pictures of Goatse.

https://github.com/vxunderground/MalwareSourceCode
This is happening everywhere and it's hard to dodge if you never had any taste in the first place. I've always hated rsync for example

Posted by HSVSphere, 11 hours ago
This media is not supported in your browser
VIEW IN TELEGRAM
It’s likely because there was a massive Instagram / Meta exploit over the weekend that was just patched.

Basically the Meta AI support is garbage and has lots of access perms which allowed you to reset passwords to any user without 2FA and did not verify who you are.

Telegram channels on Instagram offering IG black market services made lots of $$$ https://x.com/madcat516/status/2061228136637796589/video/1

Posted by ZachXBT, 3 hours ago
- BlueHammer — Microsoft Defender local privilege escalation, later tracked as CVE-2026-33825. High-level: it abused Defender behavior/race conditions to escalate from low privilege to SYSTEM. Will Dormann confirmed it worked, and Microsoft patched it on April 14. CISA later added it to KEV because it was exploited. (heise.de)

- UnDefend — a Defender disruption/DoS-style tool. High-level: it interfered with Defender’s ability to load or update definitions, so it acted as a defense-evasion companion rather than a classic “get SYSTEM” exploit. It later appears to correspond to CVE-2026-45498, which Help Net Security says was exploited and patched. (huntress.com)

- RedSun — another Defender local privilege escalation, later associated with CVE-2026-41091. Will Dormann confirmed to BleepingComputer that it granted SYSTEM on fully patched Windows 10/11/Server systems at the time. Help Net Security later reported it was exploited in the wild and patched in a Defender engine/platform update. (bleepingcomputer.com)

- YellowKey — BitLocker/WinRE security-feature bypass, later CVE-2026-45585. High-level: it was described as allowing access to BitLocker-protected drives using a crafted USB/WinRE path, especially scary for stolen-device scenarios. Microsoft issued mitigations; BleepingComputer reported the flaw and mitigation details, while the researcher disputed some mitigation claims and said they withheld a worse TPM+PIN PoC. (bleepingcomputer.com)

- GreenPlasma — a Windows local privilege-escalation disclosure, apparently less turnkey than BlueHammer/RedSun. Barracuda described it as a building block/partial exploit path; Tom’s Hardware summarized it as targeting CTFMon to get SYSTEM. No clean public consensus yet compared with BlueHammer/RedSun. (blog.barracuda.com)

- MiniPlasma — a Windows local privilege escalation tied to cldflt.sys / Cloud Files Mini Filter, with the researcher claiming it showed an old 2020 issue was still present or not fully fixed. The researcher said it spawned SYSTEM on fully patched Windows 11 and Server 2025. Barracuda says independent testing confirmed SYSTEM access on fully patched Windows 11 as of May 2026. (deadeclipse666.blogspot.com)
We reported a critical loss of funds bug to @Thorchain (32M TVL, 150M FDV)

They silently patched it and told us their bug bounty program is permanently retired.

We have more Thorchain chain halt DoS vulns. We intend to release them (open disclosure) in the coming few days

Posted by V12, 54 minutes ago
Re: The newest Instagram “exploit” is the goofiest I've seen

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc.

Why did they give it any of that?!

hbn, 2 hours ago
This media is not supported in your browser
VIEW IN TELEGRAM
These aren’t Memecoins

These are tech stocks

Posted by Ethan, 13 hours ago
The Polymarket Paradox

Posted by Gena, 11 hours ago
> update system
> program doesn't work
> check commit history
sigh

Posted by ɟɟoɥɹǝppıɹ, 4 hours ago
🤣1
‼️ Zcash undergoes an emergency fork due to exploit (boring exploit)

Posted by OrangeFren.com, 2 hours ago

Coordinated Zcash Network Upgrade Underway
As part of routine auditing and security review processes, an issue affecting the Zcash Orchard pool was identified over the weekend. Orchard-related transactions are not being mined. Privacy is unaffected. All funds are safe.
To protect Zcash users and the integrity of the network, developers, infrastructure operators, and other independent participants across the Zcash ecosystem have come together to coordinate a protocol update that requires a temporary suspension of Orchard pool activity during the upgrade rollout.
Orchard transactions are expected to be re-enabled at 14:00 EDT on June 2, 2026. We will provide a status update at 10:00 EDT.
Key Facts:
The issue does not affect the privacy of any funds.
The issue was identified through routine auditing before any known exploitation.
The issue affects only Orchard, Zcash's latest shielded pool.
Only Orchard pool transactions will be suspended during the upgrade window. Wallet users will be unable to send or receive Orchard funds until the upgrade is complete.
With the exception of the shielded Orchard pool, the Zcash network continues running. Transactions to and from the shielded Sapling and transparent pools are unaffected.
ZEC held on exchanges is unaffected and can continue to be traded normally.
This issue required a protocol-level change, which took effect at 22:30 EDT on June 1, 2026
This effort relies on voluntary cooperation among independent participants throughout the network. As part of our responsible disclosure, we are also notifying the maintainers of other protocols that have deployed Orchard.
Additional information will be shared when the upgrade is complete.
Forwarded from vx-underground
As someone who enjoys malware and malware accessories, I for one believe this to be incredible news and I applaud Satya Nadella for this

As someone who deals with malware defensively, I for one believe this is terrible news and I hate Satya Nadella so much right now it's unreal
This media is not supported in your browser
VIEW IN TELEGRAM
POV: you're still using GitHub Copilot after June 1st, 2026

Posted by Peter Dedene, 6 hours ago