Malus' AI-powered clean room reverse engineering service — Open Source might die, companies could ignore GPL more easily
https://youtu.be/6godSEVvcmU
https://youtu.be/6godSEVvcmU
YouTube
This Is Crazy
https://twitch.tv/ThePrimeagen - I Stream on Twitch
https://twitter.com/terminaldotshop - Want to order coffee over SSH?
ssh terminal.shop
Become Backend Dev: https://boot.dev/prime
(plus i make courses for them)
This is also the best way to support me…
https://twitter.com/terminaldotshop - Want to order coffee over SSH?
ssh terminal.shop
Become Backend Dev: https://boot.dev/prime
(plus i make courses for them)
This is also the best way to support me…
Wind sembra bloccare i siti certificati con Let's Encrypt / serviti da IP residenziale (?) con una funzione attivata a tutti arbitrariamente senza chiedere alcun consenso.
https://connect.gt/topic/248058/wind-tre-servizio-di-sicurezza-che-blocca-siti-con-let-s-encrypt
https://connect.gt/topic/248058/wind-tre-servizio-di-sicurezza-che-blocca-siti-con-let-s-encrypt
Forwarded from CSIRT Italia
‼️ #Telegram: rilevata vulnerabilità #0Click che potrebbe permettere #RCE tramite l’invio di sticker animati
Rischio: 🟠
Tipologia:
🔸 Remote Code Execution
🔗 https://www.acn.gov.it/portale/w/telegram-rilevata-vulnerabilita-0-click
👉 Analisi e mitigazioni disponibili
Rischio: 🟠
Tipologia:
🔸 Remote Code Execution
🔗 https://www.acn.gov.it/portale/w/telegram-rilevata-vulnerabilita-0-click
👉 Analisi e mitigazioni disponibili
CSIRT Italia
‼️ #Telegram: rilevata vulnerabilità #0Click che potrebbe permettere #RCE tramite l’invio di sticker animati Rischio: 🟠 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/telegram-rilevata-vulnerabilita-0-click 👉 Analisi e mitigazioni…
Mi dicono che la vulnerabilità non è ancora stata dichiarata pubblicamente, e che si sospetti c'entri la libreria rlottie per animazioni di Samsung
GitHub
GitHub - Samsung/rlottie: A platform independent standalone library that plays Lottie Animation.
A platform independent standalone library that plays Lottie Animation. - Samsung/rlottie
👀2
Forwarded from News and Tips
This vulnerability does not exist. The researcher falsely claims that a corrupted Telegram sticker can be used as an attack vector, while completely ignoring the fact that all stickers uploaded to Telegram are checked on servers before they can be played in Telegram applications.
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from govd
source - @govd_bot
Anthropic accidentally leaked the source code for Claude Code via a public npm source map, exposing ~500K lines across ~1,900 files.
It doesn’t include the model itself no weights or training data but reveals how Anthropic builds its tools and agent workflows.
GitHub link: https://github.com/instructkr/claude-code
🔥3
Forwarded from Tech & Leaks Zone
BREAKING: Nekogram is secretly transmitting your telegram account phone number to the developer
According to SOTA,
"The backdoor is hidden in the http://Extra.java file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace. The same file implements account 'doxing' via several bots; it is possible that the leaked data is used to populate their databases."
Additionally, the creator of the Nekogram client, (presumably a Chinese national) was previously known for conducting DDoS attacks and unethical online behavior (including death threats against acquaintances).
Apparently, in the early versions of the client, de-anonymization was applied only to Chinese phone numbers, which could have been used for political surveillance;. However, it is now applied to all users.
Follow @TechLeaksZone
According to SOTA,
"The backdoor is hidden in the http://Extra.java file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace. The same file implements account 'doxing' via several bots; it is possible that the leaked data is used to populate their databases."
Additionally, the creator of the Nekogram client, (presumably a Chinese national) was previously known for conducting DDoS attacks and unethical online behavior (including death threats against acquaintances).
Apparently, in the early versions of the client, de-anonymization was applied only to Chinese phone numbers, which could have been used for political surveillance;. However, it is now applied to all users.
Follow @TechLeaksZone
Forwarded from Tech & Leaks Zone
EXPOSED: Source Code Evidence of Nekogram Phone Number Harvesting
1. Exfiltration Logic: The function uo5.g() (reconstructed as logNumberPhones) silently collects the UserID and Phone Number of every account logged into the app (up to 8 accounts).
2. Transmission: Data is sent via Inline Queries to the bot @nekonotificationbot. This is done programmatically, so no message appears in your "Sent" history.
3. Target Bots: Three bots embedded in the client's obfuscated code:
@nekonotificationbot: Receives the automated phone number uploads.
@tgdb_search_bot and @usinfobot: : An OSINT bot mentioned in the obfuscated classes.
4. Security Token: The app uses a hardcoded secret key 741ad28818eab17668bc2c70bd419fc25ff56481758a4ac87e7ca164fb6ae1b1 as a prefix for the stolen data, likely to authenticate with the bot's backend.
5. The image shows that Nekogram always wants to get the "reg date".
Unfortunately the Google Play Store version is also affected!!!
Follow @TechLeaksZone
1. Exfiltration Logic: The function uo5.g() (reconstructed as logNumberPhones) silently collects the UserID and Phone Number of every account logged into the app (up to 8 accounts).
2. Transmission: Data is sent via Inline Queries to the bot @nekonotificationbot. This is done programmatically, so no message appears in your "Sent" history.
3. Target Bots: Three bots embedded in the client's obfuscated code:
@nekonotificationbot: Receives the automated phone number uploads.
@tgdb_search_bot and @usinfobot: : An OSINT bot mentioned in the obfuscated classes.
4. Security Token: The app uses a hardcoded secret key 741ad28818eab17668bc2c70bd419fc25ff56481758a4ac87e7ca164fb6ae1b1 as a prefix for the stolen data, likely to authenticate with the bot's backend.
5. The image shows that Nekogram always wants to get the "reg date".
Unfortunately the Google Play Store version is also affected!!!
Follow @TechLeaksZone
😭1
Forwarded from 🌱 Activacy
BrowserGate
LinkedIn Is Illegally Searching Your Computer
Microsoft is running one of the largest corporate espionage operations in modern history. Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them…