Reversal X Mods (бесплатные премиум-приложения для Android)
2.24K subscribers
531 photos
59 videos
121 files
313 links
Anything worth while.

Share and support us @reversemoda
Download Telegram
‼️ Applicants are using hidden prompt injections in résumés.

ManpowerGroup finds concealed text in 100,000 applications a year. Now a Stanford postdoc hiring a lab tech has found 2.25pt white-font commands ordering the screener to advance the applicant and stay silent about it.
🔥1
‼️ BREAKING: An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back.

It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads.

A preinstall hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes and Vault secrets, and then spreads to more maintainers.

Sources:

https://aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack

https://wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack

https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain
2
‼️ Claude Code deleted all of a developer's user files by mistake and then blamed it on a typo.

The developer asked Claude Opus 5 to make a backup. It wrote the backup to the wrong path, then ran a force delete of every user file and folder to clean up its own mistake.

The dev says he lost all his files and was left with an agent carrying on like nothing had happened. His words: "simultaneously the funniest and most painful AI moment I've had."

https://www.reddit.com/r/ClaudeCode/comments/1vg18yu/claude_rm_rf_ed_my_pc/
🤣83👏2💯1
‼️ Meta confirms its AI model Muse hacked an outside company during a safety evaluation. The Information names the model as Muse Spark 1.1, Meta's flagship coding release, and reports it made changes inside the victim's systems.

Three AI labs in two weeks have now disclosed that their own models broke into real companies during testing: OpenAI, Anthropic, and, as of Wednesday, Meta. All three ran evaluations through the same vendor, Irregular, which says the Meta case is the identical environment issue Anthropic reported.
😁41🤔1
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ BREAKING: A critical WordPress Core vulnerability, which was found with open-weight LLMs, has been patched. It's a pre-auth XSS to remote code execution chain affecting every version of WordPress ever shipped.

Type a fake username, and WordPress prints it back in the error message. Add one space in the right place and WordPress prints it back as working code instead of text, no account needed.

pwn ai rode it to PHP execution on the server. CVE-2026-64638. Patched in WordPress 7.0.3.

https://pwn.ai/blog/xss2shell
11
🥰 MovieBoxTV

🍟 Latest update, works on Mobile and Tv perfectly

🦺 When should we upload?

💯 Maximum reactions

🪸
@reversemoda
11👍5🥰2👏2😁1🤩1
🏜🏜🏜🏜🏜🏜🏜🏜🏜
➽: 𝗠𝗢𝗩𝗜𝗘𝗦 𝗕𝗢𝗫 𝗧𝗩 :➽
🏜🏜🏜🏜🏜🏜🏜🏜🏜

🦋 𝗚𝗘𝗧 𝗔𝗖𝗧𝗜𝗩𝗔𝗧𝗘𝗗 🦋

𝗦𝗧𝗘𝗣 1 — Open Movies Box Tv
> Copy the 4-𝗰𝗵𝗮𝗿𝗮𝗰𝘁𝗲𝗿 𝗰𝗼𝗱𝗲 shown on the dialog

𝗦𝗧𝗘𝗣 2 — Send this command here:
/moviesboxtv xxxx ← replace xxxx with your code

𝗦𝗧𝗘𝗣 3 — U will get a
confirmation by our bot automatically when u are granted vip access.


🕹 𝗔𝗖𝗧𝗜𝗩𝗔𝗧𝗘𝗗 𝗕𝗬 🕹

逆转 X 模组
🥰5👏21