Forwarded from vx-underground
Hello,
If you're a person who enjoys malware and/or knows Python and wants to see malware that targets STEAM and GAMERS, I have the source code to a malware I have named "Stealer.Python.GMBA.Manipulator".
This malware was originally noted on Xitter from GMBA.
In summary, this Python malware kills the Steam process and relaunches it with the "-cef-enable-debugging" flag. Because Steam is a Chromium app, this allows the malware payload to manipulate Steam web pages with web socket gunk and Javascript gunk.
This malware can "modify" user inventories, "block users", etc. It is all a facade designed to trick and social engineer Steam users into giving their expensive Counter Strike stuff to them.
It appears to be written using AI. Regardless of that fact this malware is creative and I like it.
The malware source code to this can be found under the "/Python/" directory. It is named "Stealer.Python.GMBA.Manipulator.7z".
This malware campaign is still active and the C2 is still live. If you execute the __main__.py file you might cook yourself, so be careful. Alternatively, you can run this in a VM and send the malware campaign authors pictures of Goatse.
https://github.com/vxunderground/MalwareSourceCode
If you're a person who enjoys malware and/or knows Python and wants to see malware that targets STEAM and GAMERS, I have the source code to a malware I have named "Stealer.Python.GMBA.Manipulator".
This malware was originally noted on Xitter from GMBA.
In summary, this Python malware kills the Steam process and relaunches it with the "-cef-enable-debugging" flag. Because Steam is a Chromium app, this allows the malware payload to manipulate Steam web pages with web socket gunk and Javascript gunk.
This malware can "modify" user inventories, "block users", etc. It is all a facade designed to trick and social engineer Steam users into giving their expensive Counter Strike stuff to them.
It appears to be written using AI. Regardless of that fact this malware is creative and I like it.
The malware source code to this can be found under the "/Python/" directory. It is named "Stealer.Python.GMBA.Manipulator.7z".
This malware campaign is still active and the C2 is still live. If you execute the __main__.py file you might cook yourself, so be careful. Alternatively, you can run this in a VM and send the malware campaign authors pictures of Goatse.
https://github.com/vxunderground/MalwareSourceCode
GitHub
GitHub - vxunderground/MalwareSourceCode: Collection of malware source code for a variety of platforms in an array of different…
Collection of malware source code for a variety of platforms in an array of different programming languages. - vxunderground/MalwareSourceCode
This media is not supported in your browser
VIEW IN TELEGRAM
It’s likely because there was a massive Instagram / Meta exploit over the weekend that was just patched.
Basically the Meta AI support is garbage and has lots of access perms which allowed you to reset passwords to any user without 2FA and did not verify who you are.
Telegram channels on Instagram offering IG black market services made lots of $$$ https://x.com/madcat516/status/2061228136637796589/video/1
Posted by ZachXBT, 3 hours ago
Basically the Meta AI support is garbage and has lots of access perms which allowed you to reset passwords to any user without 2FA and did not verify who you are.
Telegram channels on Instagram offering IG black market services made lots of $$$ https://x.com/madcat516/status/2061228136637796589/video/1
Posted by ZachXBT, 3 hours ago
- BlueHammer — Microsoft Defender local privilege escalation, later tracked as CVE-2026-33825. High-level: it abused Defender behavior/race conditions to escalate from low privilege to SYSTEM. Will Dormann confirmed it worked, and Microsoft patched it on April 14. CISA later added it to KEV because it was exploited. (heise.de)
- UnDefend — a Defender disruption/DoS-style tool. High-level: it interfered with Defender’s ability to load or update definitions, so it acted as a defense-evasion companion rather than a classic “get SYSTEM” exploit. It later appears to correspond to CVE-2026-45498, which Help Net Security says was exploited and patched. (huntress.com)
- RedSun — another Defender local privilege escalation, later associated with CVE-2026-41091. Will Dormann confirmed to BleepingComputer that it granted SYSTEM on fully patched Windows 10/11/Server systems at the time. Help Net Security later reported it was exploited in the wild and patched in a Defender engine/platform update. (bleepingcomputer.com)
- YellowKey — BitLocker/WinRE security-feature bypass, later CVE-2026-45585. High-level: it was described as allowing access to BitLocker-protected drives using a crafted USB/WinRE path, especially scary for stolen-device scenarios. Microsoft issued mitigations; BleepingComputer reported the flaw and mitigation details, while the researcher disputed some mitigation claims and said they withheld a worse TPM+PIN PoC. (bleepingcomputer.com)
- GreenPlasma — a Windows local privilege-escalation disclosure, apparently less turnkey than BlueHammer/RedSun. Barracuda described it as a building block/partial exploit path; Tom’s Hardware summarized it as targeting CTFMon to get SYSTEM. No clean public consensus yet compared with BlueHammer/RedSun. (blog.barracuda.com)
- MiniPlasma — a Windows local privilege escalation tied to
- UnDefend — a Defender disruption/DoS-style tool. High-level: it interfered with Defender’s ability to load or update definitions, so it acted as a defense-evasion companion rather than a classic “get SYSTEM” exploit. It later appears to correspond to CVE-2026-45498, which Help Net Security says was exploited and patched. (huntress.com)
- RedSun — another Defender local privilege escalation, later associated with CVE-2026-41091. Will Dormann confirmed to BleepingComputer that it granted SYSTEM on fully patched Windows 10/11/Server systems at the time. Help Net Security later reported it was exploited in the wild and patched in a Defender engine/platform update. (bleepingcomputer.com)
- YellowKey — BitLocker/WinRE security-feature bypass, later CVE-2026-45585. High-level: it was described as allowing access to BitLocker-protected drives using a crafted USB/WinRE path, especially scary for stolen-device scenarios. Microsoft issued mitigations; BleepingComputer reported the flaw and mitigation details, while the researcher disputed some mitigation claims and said they withheld a worse TPM+PIN PoC. (bleepingcomputer.com)
- GreenPlasma — a Windows local privilege-escalation disclosure, apparently less turnkey than BlueHammer/RedSun. Barracuda described it as a building block/partial exploit path; Tom’s Hardware summarized it as targeting CTFMon to get SYSTEM. No clean public consensus yet compared with BlueHammer/RedSun. (blog.barracuda.com)
- MiniPlasma — a Windows local privilege escalation tied to
cldflt.sys / Cloud Files Mini Filter, with the researcher claiming it showed an old 2020 issue was still present or not fully fixed. The researcher said it spawned SYSTEM on fully patched Windows 11 and Server 2025. Barracuda says independent testing confirmed SYSTEM access on fully patched Windows 11 as of May 2026. (deadeclipse666.blogspot.com)We reported a critical loss of funds bug to @Thorchain (32M TVL, 150M FDV)
They silently patched it and told us their bug bounty program is permanently retired.
We have more Thorchain chain halt DoS vulns. We intend to release them (open disclosure) in the coming few days
Posted by V12, 54 minutes ago
They silently patched it and told us their bug bounty program is permanently retired.
We have more Thorchain chain halt DoS vulns. We intend to release them (open disclosure) in the coming few days
Posted by V12, 54 minutes ago
Re: The newest Instagram “exploit” is the goofiest I've seen
It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc.
Why did they give it any of that?!
hbn, 2 hours ago
It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc.
Why did they give it any of that?!
hbn, 2 hours ago
Syncing lights with music: Marzullo's algorithm in the DJ booth
Comments
via aaronjanse.substack.com by aaronjanse
Comments
via aaronjanse.substack.com by aaronjanse
Substack
Syncing lights with music: Marzullo's algorithm in the DJ booth
One of my favorite side projects is automatically syncing lights with music at house parties. How can we keep in sync with a live DJ?
‼️ Zcash undergoes an emergency fork due to exploit (boring exploit)
Posted by OrangeFren.com, 2 hours ago
Posted by OrangeFren.com, 2 hours ago
Coordinated Zcash Network Upgrade Underway
As part of routine auditing and security review processes, an issue affecting the Zcash Orchard pool was identified over the weekend. Orchard-related transactions are not being mined. Privacy is unaffected. All funds are safe.
To protect Zcash users and the integrity of the network, developers, infrastructure operators, and other independent participants across the Zcash ecosystem have come together to coordinate a protocol update that requires a temporary suspension of Orchard pool activity during the upgrade rollout.
Orchard transactions are expected to be re-enabled at 14:00 EDT on June 2, 2026. We will provide a status update at 10:00 EDT.
Key Facts:
The issue does not affect the privacy of any funds.
The issue was identified through routine auditing before any known exploitation.
The issue affects only Orchard, Zcash's latest shielded pool.
Only Orchard pool transactions will be suspended during the upgrade window. Wallet users will be unable to send or receive Orchard funds until the upgrade is complete.
With the exception of the shielded Orchard pool, the Zcash network continues running. Transactions to and from the shielded Sapling and transparent pools are unaffected.
ZEC held on exchanges is unaffected and can continue to be traded normally.
This issue required a protocol-level change, which took effect at 22:30 EDT on June 1, 2026
This effort relies on voluntary cooperation among independent participants throughout the network. As part of our responsible disclosure, we are also notifying the maintainers of other protocols that have deployed Orchard.
Additional information will be shared when the upgrade is complete.
Forwarded from vx-underground
As someone who enjoys malware and malware accessories, I for one believe this to be incredible news and I applaud Satya Nadella for this
As someone who deals with malware defensively, I for one believe this is terrible news and I hate Satya Nadella so much right now it's unreal
As someone who deals with malware defensively, I for one believe this is terrible news and I hate Satya Nadella so much right now it's unreal
gnosis pay exploit root cause: a taint of revert data
https://gnosisscan.io/tx/0x5ea42911c803ba2cf1cb558e88129102de9023980a5c73253d59407859ce2ce5
Posted by 加密塔菲, 16 hours ago
https://gnosisscan.io/tx/0x5ea42911c803ba2cf1cb558e88129102de9023980a5c73253d59407859ce2ce5
Posted by 加密塔菲, 16 hours ago
zcash is actually up, it's a node issue for many explorers (since not updated apparently); people should first verify before claiming a network is down
here to verify the latest block:
Posted by sudo..., 18 minutes ago
here to verify the latest block:
grpcurl -d '{}' http://zec.rocks:443 cash.z.wallet.sdk.rpc.CompactTxStreamer/GetLatestTreeStatePosted by sudo..., 18 minutes ago