■■■■□ An interesting thread 🧵 on hacking Open AI. A 72 hour journey.
https://x.com/S1r1u5_/status/2100777801335095383
https://x.com/S1r1u5_/status/2100777801335095383
X (formerly Twitter)
s1r1us (@S1r1u5_) on X
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved…
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved…
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Kosher phone 📱
Hasidic Jews are not against AI in the right places. For instance, people use it all the time for work. I have not seen any campaigns against its use at the office. However, chatting with Ai bots is another problem! Especially children at home, who could be deeply influenced by these worldly machines. The solution to keeping the world out used to be not to have computers at home. The problem? You can call AI chat bots from home phones and kosher phones. This is the most recent outcry by the Satmar Rabbi R’ Aaron Teitelbaum. I have watched this community wrestle with technology for many years and respond to its challenges with tremendous innovation.
Forwarded from cKure Red
This media is not supported in your browser
VIEW IN TELEGRAM
AliExpress spyware caught using side channel attack to compromise hardware.
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ UAE Cyber Security minister blames IRGC for recent cyber attacks.
Also boasts about AI and national SOC (made by Israel).
Also boasts about AI and national SOC (made by Israel).
This media is not supported in your browser
VIEW IN TELEGRAM
■■■■□ GrapheneOS to bring encrypted RCS.
👏3
■■■■□ Today, washingtonpost covered critical vulnerabilities depthfirstlabs found in TikTok. These vulnerabilities allowed hackers to access anything on a user’s device that TikTok itself could access, including the camera, microphone, payment information, photos, and the user’s entire TikTok account.
https://x.com/qasimmith/status/2101032260124495961
https://x.com/qasimmith/status/2101032260124495961
X (formerly Twitter)
QM (@qasimmith) on X
Today, @washingtonpost covered critical vulnerabilities @depthfirstlabs found in TikTok. These vulnerabilities allowed hackers to access anything on a user’s device that TikTok itself could access…
🔥1
■■■■□ 🚨 Google reveals undercover Mandiant analyst infiltrated TeamPCP during massive supply-chain hacking spree
Google says an undercover Mandiant analyst infiltrated TeamPCP's inner circle as the hacking group compromised open-source software and ultimately breached more than 1,000 companies.
⠀
The analyst gained access to TeamPCP's core "CanisterWorm" chat in March, joining a group of roughly 12 members and watching the operation from the inside.
⠀
The mole also gained access to a server containing credentials stolen from victims, including usernames, passwords, and access tokens.
Google used that visibility to alert cloud and technology providers, revoke compromised credentials, and send hundreds of notifications to affected organizations.
⠀
The operation also exposed a TeamPCP member developing an AI-assisted zero-day capable of bypassing two-factor authentication in widely used login software.
Google obtained the exploit code, verified that it worked after minor modifications, and privately notified the developer so the vulnerability could be patched.
⠀
TeamPCP's campaign compromised hundreds of open-source packages and affected organizations including GitHub, Mistral AI, Mercor, the European Commission, and employee devices at OpenAI.
⠀
Google says operational security mistakes later helped investigators identify an alleged TeamPCP member, with information passed to the FBI.
Two Australians accused of being principal participants in TeamPCP were arrested last month.
Please open Telegram to view this post
VIEW IN TELEGRAM
cKure
■■■■□ 🚨 Google reveals undercover Mandiant analyst infiltrated TeamPCP during massive supply-chain hacking spree Google says an undercover Mandiant analyst infiltrated TeamPCP's inner circle as the hacking group compromised open-source software and ultimately…
The picture (eyes blacked out) is of Ruben Ian Thomson.He is the 21-year-old Australian (also referenced with South African nationality in some reports) who was arrested in late August 2026 in the Perth area (Hamilton Hill / Cottesloe) and publicly identified as an alleged principal participant and leader of TeamPCP.
■■■■□ BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers.
https://cybersecuritynews.com/bragjack-ai-agent-hijacking/
https://cybersecuritynews.com/bragjack-ai-agent-hijacking/
Cyber Security News
BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers
Security researchers have disclosed BragJack, a new attack technique that allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome.
Media is too big
VIEW IN TELEGRAM
■■■■□ TypeSafe has launched Jev, a “System One” model designed for classification and decision-making rather than text generation.
Instead of generating responses token by token, Jev evaluates predefined answer options and returns probabilities for each. This allows multiple questions to be processed in a single pass, potentially reducing inference costs for applications that need large-scale classification or decision-making.
The interesting aspect is less about generating better text and more about making model-based decisions economically practical to integrate into software.
#AI #LLM #MachineLearning #DevTools
Instead of generating responses token by token, Jev evaluates predefined answer options and returns probabilities for each. This allows multiple questions to be processed in a single pass, potentially reducing inference costs for applications that need large-scale classification or decision-making.
The interesting aspect is less about generating better text and more about making model-based decisions economically practical to integrate into software.
#AI #LLM #MachineLearning #DevTools
❤2
This media is not supported in your browser
VIEW IN TELEGRAM
■■■■□
I scanned an iPhone for Pegasus and it came back with one critical alert. The tool is called the Mobile Verification Toolkit, or MVT. It’s free and open source and was built by Amnesty International’s Security Lab. All you need to do is make an encrypted backup of your phone on a computer, point MVT at it, and it checks your messages, browsing history, apps and data usage against known traces and fingerprints of Pegasus, Predator, stalkerware and other surveillance tools. It works for iPhone and Android, and it runs on a Mac or on Windows. Don’t forget to also check out my other detailed videos about Pegasus and Paragon. And if you’re interested in a step by step guide let me know in the comments and make sure you give this a follow and share.
👍3❤1👏1
■■■□□ Actor Shiny Hunters have claimed that they pwned FBI and data has been stolen.
👍5