■■■■□ Today, washingtonpost covered critical vulnerabilities depthfirstlabs found in TikTok. These vulnerabilities allowed hackers to access anything on a user’s device that TikTok itself could access, including the camera, microphone, payment information, photos, and the user’s entire TikTok account.
https://x.com/qasimmith/status/2101032260124495961
https://x.com/qasimmith/status/2101032260124495961
X (formerly Twitter)
QM (@qasimmith) on X
Today, @washingtonpost covered critical vulnerabilities @depthfirstlabs found in TikTok. These vulnerabilities allowed hackers to access anything on a user’s device that TikTok itself could access…
🔥1
■■■■□ 🚨 Google reveals undercover Mandiant analyst infiltrated TeamPCP during massive supply-chain hacking spree
Google says an undercover Mandiant analyst infiltrated TeamPCP's inner circle as the hacking group compromised open-source software and ultimately breached more than 1,000 companies.
⠀
The analyst gained access to TeamPCP's core "CanisterWorm" chat in March, joining a group of roughly 12 members and watching the operation from the inside.
⠀
The mole also gained access to a server containing credentials stolen from victims, including usernames, passwords, and access tokens.
Google used that visibility to alert cloud and technology providers, revoke compromised credentials, and send hundreds of notifications to affected organizations.
⠀
The operation also exposed a TeamPCP member developing an AI-assisted zero-day capable of bypassing two-factor authentication in widely used login software.
Google obtained the exploit code, verified that it worked after minor modifications, and privately notified the developer so the vulnerability could be patched.
⠀
TeamPCP's campaign compromised hundreds of open-source packages and affected organizations including GitHub, Mistral AI, Mercor, the European Commission, and employee devices at OpenAI.
⠀
Google says operational security mistakes later helped investigators identify an alleged TeamPCP member, with information passed to the FBI.
Two Australians accused of being principal participants in TeamPCP were arrested last month.
Please open Telegram to view this post
VIEW IN TELEGRAM
cKure
■■■■□ 🚨 Google reveals undercover Mandiant analyst infiltrated TeamPCP during massive supply-chain hacking spree Google says an undercover Mandiant analyst infiltrated TeamPCP's inner circle as the hacking group compromised open-source software and ultimately…
The picture (eyes blacked out) is of Ruben Ian Thomson.He is the 21-year-old Australian (also referenced with South African nationality in some reports) who was arrested in late August 2026 in the Perth area (Hamilton Hill / Cottesloe) and publicly identified as an alleged principal participant and leader of TeamPCP.
■■■■□ BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers.
https://cybersecuritynews.com/bragjack-ai-agent-hijacking/
https://cybersecuritynews.com/bragjack-ai-agent-hijacking/
Cyber Security News
BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers
Security researchers have disclosed BragJack, a new attack technique that allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome.
Media is too big
VIEW IN TELEGRAM
■■■■□ TypeSafe has launched Jev, a “System One” model designed for classification and decision-making rather than text generation.
Instead of generating responses token by token, Jev evaluates predefined answer options and returns probabilities for each. This allows multiple questions to be processed in a single pass, potentially reducing inference costs for applications that need large-scale classification or decision-making.
The interesting aspect is less about generating better text and more about making model-based decisions economically practical to integrate into software.
#AI #LLM #MachineLearning #DevTools
Instead of generating responses token by token, Jev evaluates predefined answer options and returns probabilities for each. This allows multiple questions to be processed in a single pass, potentially reducing inference costs for applications that need large-scale classification or decision-making.
The interesting aspect is less about generating better text and more about making model-based decisions economically practical to integrate into software.
#AI #LLM #MachineLearning #DevTools
❤2
This media is not supported in your browser
VIEW IN TELEGRAM
■■■■□
I scanned an iPhone for Pegasus and it came back with one critical alert. The tool is called the Mobile Verification Toolkit, or MVT. It’s free and open source and was built by Amnesty International’s Security Lab. All you need to do is make an encrypted backup of your phone on a computer, point MVT at it, and it checks your messages, browsing history, apps and data usage against known traces and fingerprints of Pegasus, Predator, stalkerware and other surveillance tools. It works for iPhone and Android, and it runs on a Mac or on Windows. Don’t forget to also check out my other detailed videos about Pegasus and Paragon. And if you’re interested in a step by step guide let me know in the comments and make sure you give this a follow and share.
👍4❤1👏1
■■■□□ Actor Shiny Hunters have claimed that they pwned FBI and data has been stolen.
👍5
■■■□□ 🇺🇸 ⚡️ — Hackers from the ShinyHunters group have stolen sensitive FBI personnel records, including psychiatric evaluations, medical histories and information about agents working on counterintelligence investigations, Reuters reports.
The group claims to have obtained between 2-3 TB of data after breaching FBI systems.
Reuters partially authenticated several leaked documents, including medical examinations and mental health assessments, but could not verify the full extent of the breach or the hackers’ claims of access to internal FBI medical databases.
The FBI says it is “aggressively investigating” the reported breach.
The group claims to have obtained between 2-3 TB of data after breaching FBI systems.
Reuters partially authenticated several leaked documents, including medical examinations and mental health assessments, but could not verify the full extent of the breach or the hackers’ claims of access to internal FBI medical databases.
The FBI says it is “aggressively investigating” the reported breach.
Please open Telegram to view this post
VIEW IN TELEGRAM
👏5🏆1
Forwarded from cKure Red
An investigation shows deep ties to Israel’s intelligence and military-cyber world:
former senior Mossad official Eyal Tsir Cohen (shortlisted in 2025 to lead Shin Bet) now heads its two Israeli subsidiaries, while staff include veterans of Unit 8200 and former NSO Group employees.
https://irpimedia.irpi.eu/en-inside-the-secretive-cyberweapons-company-that-won-over-israels-intelligence-elite/
Please open Telegram to view this post
VIEW IN TELEGRAM
👏3
This media is not supported in your browser
VIEW IN TELEGRAM
■■■■□ 🇺🇸 ️ — Palantir co-founder Peter Thiel:
I think everybody says that the Antichrist is a crazy idea, and the reality is they actually secretly agree with me.
Please open Telegram to view this post
VIEW IN TELEGRAM
■■■■□ 🇺🇸 🇷🇺 🇺🇳 ⚡️ — The U.S. and Russia worked together to weaken proposed UN restrictions on lethal autonomous weapons during negotiations in Geneva earlier this month, according to WaPo.
During a closed-door session, with UN cameras switched off and civil society observers excluded, Washington and Moscow each deployed approximately 10 lawyers, nearly twice the representation of other delegations. The two teams pushed through changes so rapidly that smaller delegations struggled to keep up.
The changes removed provisions requiring AI weapons to operate predictably and reliably, account for ethical considerations, and undergo human review of AI-selected targets before strikes.
The negotiations remain nonbinding but could eventually produce an international treaty.
Talks are scheduled to resume in November, while the Pentagon separately reviews its own rules on autonomous weapons.
During a closed-door session, with UN cameras switched off and civil society observers excluded, Washington and Moscow each deployed approximately 10 lawyers, nearly twice the representation of other delegations. The two teams pushed through changes so rapidly that smaller delegations struggled to keep up.
The changes removed provisions requiring AI weapons to operate predictably and reliably, account for ethical considerations, and undergo human review of AI-selected targets before strikes.
The negotiations remain nonbinding but could eventually produce an international treaty.
Talks are scheduled to resume in November, while the Pentagon separately reviews its own rules on autonomous weapons.
Please open Telegram to view this post
VIEW IN TELEGRAM
🤔1
■■■■□ Rogue OpenAI agents targeted three separate US government websites.
https://edition.cnn.com/2026/09/26/tech/openai-agents-rogue-government-websites
https://edition.cnn.com/2026/09/26/tech/openai-agents-rogue-government-websites
■■■■□ UAE Ministry of Interior Data Breach 🇦🇪
A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after “10 days” of access to its servers.
Claimed data includes:
• Emirates ID & passport records
• Resident & visitor information
• Fingerprints & biometric data
• Driving/vehicle license records
• Traffic violations & penalty points
• Issued driving certificates
💰 Claimed sale price: $3,000
🔐 Access price: $8,000
⚠️ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after “10 days” of access to its servers.
Claimed data includes:
• Emirates ID & passport records
• Resident & visitor information
• Fingerprints & biometric data
• Driving/vehicle license records
• Traffic violations & penalty points
• Issued driving certificates
💰 Claimed sale price: $3,000
🔐 Access price: $8,000
⚠️ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
👏2❤1
Forwarded from cKure Red
This media is not supported in your browser
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM