Meta intends on laying off 10% of it's employees on May 20th. Meta is expected to terminate an additional 10% at a later (currently undetermined) date.
In total, Meta plans on terminating 20% of its employees. Reasons cited is both AI efficiency and raising costs of AI
In total, Meta plans on terminating 20% of its employees. Reasons cited is both AI efficiency and raising costs of AI
π’55π―35π€£21π€17π14π₯°5π5β€3π€3π±2π€©2
vx-underground
Meta intends on laying off 10% of it's employees on May 20th. Meta is expected to terminate an additional 10% at a later (currently undetermined) date. In total, Meta plans on terminating 20% of its employees. Reasons cited is both AI efficiency and raisingβ¦
As of early 2026, Meta reported having over 78,000 employees.
Over 15,000 people will lose their jobs.
Over 15,000 people will lose their jobs.
π’98π€18π€£9π₯°7β€1
Had a Threat Actor ask for an anti-virus recommendation
DAWG, YOU ARE THE THREAT. WHY DO YOU NEED AN AV?
DAWG, YOU ARE THE THREAT. WHY DO YOU NEED AN AV?
π€£181π27β€10π’4π€―3π₯°2π€2π₯1
vx-underground
Had a Threat Actor ask for an anti-virus recommendation DAWG, YOU ARE THE THREAT. WHY DO YOU NEED AN AV?
I don't use an anti-virus.
If I detonate malware on my machine (which I have several times) I yank the CAT cable and then let out an audible and dramatic sigh.
If I detonate malware on my machine (which I have several times) I yank the CAT cable and then let out an audible and dramatic sigh.
π€£137π₯°22π―10β€6π₯5π€3π«‘3π1π€―1
Regular ass people should 100% use an anti-virus.
Malware plagues the normies. It's like shooting fish in a barrel. Using SOMETHING is better than NOTHING.
Dawg, these normies are detonating cat_picture.jpeg.exe. They need all the help they can get
No disrespect though
Malware plagues the normies. It's like shooting fish in a barrel. Using SOMETHING is better than NOTHING.
Dawg, these normies are detonating cat_picture.jpeg.exe. They need all the help they can get
No disrespect though
β€99π€£79π―11π’10π€3π«‘3π2π₯°2π2π€©1
Was visiting family today, many of these family members are significantly younger than me.
After spending the day with teenagers I have learned the following:
1. They're stinky, like actually stinky, no idea why they're so stinky
2. They have a completely distorted sense of reality. It's heartwarming. They genuinely believe they'll all succeed in life. They have yet to have a friend die in a violent car accident, get PTSD from the military, or get addicted to fentanyl. It's incredible.
3. I have no idea who they listen to for musicians. I don't know any of the artists they recommended. Some of the songs they shared I enjoyed, but I have literally never heard of these people before
4. YouTube, TikTok, and SnapChat are the most important things in the world. If you end a streak on SnapChat you've basically betrayed them at a fundamental level.
5. They are far more inclusive than my generation. It is deemed "edgy", "cringe", and "you're actually not funny" for mocking someone based on age, sex, religion, sexual orientation, or disability.
6. Baggy clothing is immensely popular, particularly jeans that seem almost like bell-bottoms.
7. For some reason "I'll tickle you" is a saying. I don't understand why. Specifically in the context of P. Diddy.
After spending the day with teenagers I have learned the following:
1. They're stinky, like actually stinky, no idea why they're so stinky
2. They have a completely distorted sense of reality. It's heartwarming. They genuinely believe they'll all succeed in life. They have yet to have a friend die in a violent car accident, get PTSD from the military, or get addicted to fentanyl. It's incredible.
3. I have no idea who they listen to for musicians. I don't know any of the artists they recommended. Some of the songs they shared I enjoyed, but I have literally never heard of these people before
4. YouTube, TikTok, and SnapChat are the most important things in the world. If you end a streak on SnapChat you've basically betrayed them at a fundamental level.
5. They are far more inclusive than my generation. It is deemed "edgy", "cringe", and "you're actually not funny" for mocking someone based on age, sex, religion, sexual orientation, or disability.
6. Baggy clothing is immensely popular, particularly jeans that seem almost like bell-bottoms.
7. For some reason "I'll tickle you" is a saying. I don't understand why. Specifically in the context of P. Diddy.
β€102π€£85π11π’10π₯°3π€2π€1
Serious post. Not memeing.
I've had people DM me about OSINT stuff, exposing alleged or potential Threat Actors. While I appreciate the information, and it's interesting to see, I am EXTREMELY cautious discussing it publicly.
I am deathly afraid that, if in the event the OSINT is wrong, I am exposing the wrong person to 480,000 people (X and Telegram).
To put that into perspective, the attached image is Michigan Stadium a/k/a "The Big House". It sits approximately 107,000 people. That image is approximately 107,000 people.
My audience is that stadium MULTIPLED BY 4 (technically 4.48, whatever).
Imagine being bamboozled, framed as the wrong guy, in front of 4.5 "Big House" stadiums. That has the potential to seriously fuck up someone's life.
tldr innocent until proven guilty in the court of law. If it's in the court system I'm more likely to discuss it.
I've had people DM me about OSINT stuff, exposing alleged or potential Threat Actors. While I appreciate the information, and it's interesting to see, I am EXTREMELY cautious discussing it publicly.
I am deathly afraid that, if in the event the OSINT is wrong, I am exposing the wrong person to 480,000 people (X and Telegram).
To put that into perspective, the attached image is Michigan Stadium a/k/a "The Big House". It sits approximately 107,000 people. That image is approximately 107,000 people.
My audience is that stadium MULTIPLED BY 4 (technically 4.48, whatever).
Imagine being bamboozled, framed as the wrong guy, in front of 4.5 "Big House" stadiums. That has the potential to seriously fuck up someone's life.
tldr innocent until proven guilty in the court of law. If it's in the court system I'm more likely to discuss it.
π₯°109β€42π―21π₯17π11π8π€1π€£1
> Not really real ShinyHunters
> Claims to have compromised Vercel
> Real ShinyHunters say "wtf that's not me"
> Impersonator ShinyHunters says stole source code, customer data, databases etc
> Vercel makes security bulletin
> Announces compromise
> Real ShinyHunters "wtf that's not us tho fr"
1. WHO EXTORTS SOMEONE ON A SUNDAY
2. 200iq move to blame ShinyHunters for compromise
3. 400iq move if ShinyHunters made fork of ShinyHunters claiming to be impersonator ShinyHunters to convince everyone the fake ShinyHunters are impersonating ShinyHunters, but it was actually ShinyHunters being the fake ShinyHunters all along
4. Lots of cybercrime drama right now, but ITS SUNDAY. Dawg, WAIT UNTIL LIKE TUESDAY OR SOMETHING. Smdh
> Claims to have compromised Vercel
> Real ShinyHunters say "wtf that's not me"
> Impersonator ShinyHunters says stole source code, customer data, databases etc
> Vercel makes security bulletin
> Announces compromise
> Real ShinyHunters "wtf that's not us tho fr"
1. WHO EXTORTS SOMEONE ON A SUNDAY
2. 200iq move to blame ShinyHunters for compromise
3. 400iq move if ShinyHunters made fork of ShinyHunters claiming to be impersonator ShinyHunters to convince everyone the fake ShinyHunters are impersonating ShinyHunters, but it was actually ShinyHunters being the fake ShinyHunters all along
4. Lots of cybercrime drama right now, but ITS SUNDAY. Dawg, WAIT UNTIL LIKE TUESDAY OR SOMETHING. Smdh
π₯°70π24π₯13π€£12π€5β€3π€―3π1π€1
vx-underground
> Not really real ShinyHunters > Claims to have compromised Vercel > Real ShinyHunters say "wtf that's not me" > Impersonator ShinyHunters says stole source code, customer data, databases etc > Vercel makes security bulletin > Announces compromise > Real ShinyHuntersβ¦
Lots of drama happening on the internet today, but I've got work tomorrow and my baby boy is super fucking grumpy today.
He's mad at me that HE shit HIS pants. How is that my fault?
He's mad at me that HE shit HIS pants. How is that my fault?
π€£100π₯°31β€7π€―4π2π2π«‘2π₯1
Instead of commenting on both these posts, or individually quoting tweeting mattjay and thedawgyg, I'll just make a general comment.
However, as is tradition with any compromise, the details are fuzzy and the truth likely resides somewhere in the middle of all of the chaos.
Here is everything I know:
1. The VERCEL compromise is real.
2. VERCEL publicly confirmed the compromise
3. The compromise was initially posted on BreachForums-dot-ai
4. Internet nerds say BreachForums-dot-ai IS NOT the real BreachForums
5. Other internet nerds say BreachForums-dot-ai is the NEW and REAL BreachForums
6. There has been, to the best of my knowledge, EIGHT different iterations of BreachForums and/or RaidForums with various takedowns and ownership changes.
7. What is "real" BreachForums and "fake" BreachForums is ambiguous due to the number of takedowns, ownership changes, and Threat Actors competing to be the top place to share, sell, or barter stolen data.
8. An account on BreachForums-dot-ai named "ShinyHunters" initially posted the VERCEL compromise there.
9. ShinyHunters extortion group went on Telegram asserting they're NOT responsible for the VERCEL compromise and it is someone else impersonating them. They do not know who the impersonator is.
10. It is (currently) unknown how much data is stolen, what is stolen, who is impacted, etc. While VERCEL claims a small portion of customers were impacted, VERCEL likely has hundreds of thousands of customers. "Small" in the context is over 100,000 people and/or customers is ambiguous. Hypothetically, is 100 small? 200? 1,000? 10,000? What is "small"?
11. Screenshots have been circulating online of impersonator ShinyHunters demanding $2,000,000 from VERCEL in payments of $500,000. However, it is not known if these are real, fake, or doctored images.
12. It is speculated online the compromise was the result of an employee at VERCEL having their employee panel compromised. However, this can be modified OR a screenshot from lateral or vertical movement. The initial access vector is unknown
tl;dr lots of internet nerds arguing, lots of speculating, lots of accusations with little hard-hard evidence, it is Sunday. I like pictures of cats.
However, as is tradition with any compromise, the details are fuzzy and the truth likely resides somewhere in the middle of all of the chaos.
Here is everything I know:
1. The VERCEL compromise is real.
2. VERCEL publicly confirmed the compromise
3. The compromise was initially posted on BreachForums-dot-ai
4. Internet nerds say BreachForums-dot-ai IS NOT the real BreachForums
5. Other internet nerds say BreachForums-dot-ai is the NEW and REAL BreachForums
6. There has been, to the best of my knowledge, EIGHT different iterations of BreachForums and/or RaidForums with various takedowns and ownership changes.
7. What is "real" BreachForums and "fake" BreachForums is ambiguous due to the number of takedowns, ownership changes, and Threat Actors competing to be the top place to share, sell, or barter stolen data.
8. An account on BreachForums-dot-ai named "ShinyHunters" initially posted the VERCEL compromise there.
9. ShinyHunters extortion group went on Telegram asserting they're NOT responsible for the VERCEL compromise and it is someone else impersonating them. They do not know who the impersonator is.
10. It is (currently) unknown how much data is stolen, what is stolen, who is impacted, etc. While VERCEL claims a small portion of customers were impacted, VERCEL likely has hundreds of thousands of customers. "Small" in the context is over 100,000 people and/or customers is ambiguous. Hypothetically, is 100 small? 200? 1,000? 10,000? What is "small"?
11. Screenshots have been circulating online of impersonator ShinyHunters demanding $2,000,000 from VERCEL in payments of $500,000. However, it is not known if these are real, fake, or doctored images.
12. It is speculated online the compromise was the result of an employee at VERCEL having their employee panel compromised. However, this can be modified OR a screenshot from lateral or vertical movement. The initial access vector is unknown
tl;dr lots of internet nerds arguing, lots of speculating, lots of accusations with little hard-hard evidence, it is Sunday. I like pictures of cats.
π₯°49β€15π11π1
vx-underground
Instead of commenting on both these posts, or individually quoting tweeting mattjay and thedawgyg, I'll just make a general comment. However, as is tradition with any compromise, the details are fuzzy and the truth likely resides somewhere in the middle ofβ¦
Oh, and with the nature of compromises, we can always expect a sudden and dramatic anime plot twist at any given moment.
I've seen large compromises swing good-then-bad in just hours. Later today all hell could break loose, or maybe nothing will happen and this will be a distant memory.
Insert Dragon Ball Z episode meme thingy here, I can't find it right now
I've seen large compromises swing good-then-bad in just hours. Later today all hell could break loose, or maybe nothing will happen and this will be a distant memory.
Insert Dragon Ball Z episode meme thingy here, I can't find it right now
π₯°41β€12π«‘11
> be lovable
> worth 5 billion dollars
> big startup in EU
> vibe coding app thingy
> coding is for nerds, vibe code is cool and badass
> early march weezerOSINT reports bug
> "can see everyones prompts and stuff lol"
> image 1 is it thinking stuff
> lovable replies
> image 2 hackerone stuff
> "duplicate lol but ya misconfigured firebase stuff"
> acknowledges
> half-fixes, only fixes NEW projects
> old projects still free real estate
> used by nvidia, microsoft, uber, spotify, etc
> make free lovable account
> make api call and ask for stuff
> image 3 is lovable giving free stuff stuff
all images from weezerosint. subsequent post is full thread on the anime
> worth 5 billion dollars
> big startup in EU
> vibe coding app thingy
> coding is for nerds, vibe code is cool and badass
> early march weezerOSINT reports bug
> "can see everyones prompts and stuff lol"
> image 1 is it thinking stuff
> lovable replies
> image 2 hackerone stuff
> "duplicate lol but ya misconfigured firebase stuff"
> acknowledges
> half-fixes, only fixes NEW projects
> old projects still free real estate
> used by nvidia, microsoft, uber, spotify, etc
> make free lovable account
> make api call and ask for stuff
> image 3 is lovable giving free stuff stuff
all images from weezerosint. subsequent post is full thread on the anime
β€49π€£26π€―14π₯°3π₯2
vx-underground
> be lovable > worth 5 billion dollars > big startup in EU > vibe coding app thingy > coding is for nerds, vibe code is cool and badass > early march weezerOSINT reports bug > "can see everyones prompts and stuff lol" > image 1 is it thinking stuff > lovableβ¦
tl;dr vibe coding thingy does a misconfiguration (again) bamboozling everyone (again). cybersecurity is dead and for nerds
https://x.com/weezerOSINT/status/2046170666131669027
https://x.com/weezerOSINT/status/2046170666131669027
X (formerly Twitter)
impulsive (@weezerOSINT) on X
Lovable has a mass data breach affecting every project created before november 2025.
I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any freeβ¦
I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any freeβ¦
β€46π₯°8π8π€―2π€£1
I owe a nerd a favor, so I guess I'll be doing a talk at Georgia Tech ... either this Thursday or next Tuesday, depending on how their e-mail chain is filtered because I can't tell.
Either way, if you're at Georgia Tech, I'll be doing a schizo rant about malware
Either way, if you're at Georgia Tech, I'll be doing a schizo rant about malware
π«‘68π±13β€10π―4π€£3π₯°2π€©2π₯1π1π€1
vx-underground
I made a post about the Vercel compromise thingy. Moments after I clicked send a few of my colleagues involved in DFIR stuff corrected me on the details. IM AFK SPENDING TIME WITH MY SON FOR A FEW HOURS AND SUDDENLY "OoOh MoRe DeTaIls HaVe EmeRgED".
In all seriousness, thank you to my colleagues and peers who take the time to correct me and keep me informed. Information flows extremely fast in cybersecurity, and precision is paramount, so the details I learned hours ago are now incorrect and I'm thankful I was corrected.
β€49π―9π₯5π₯°3π€£1
> New report from CheckPoint
> "The Gentlemen"
> Rapidly evolving ransomware grou
> Possibly "veterans" of other groups
> Lists social media profile
> Check social media
> Follows me
> Check messages
> Message from them
> Picture of a cat
> "You're stinky"
lmfao wtf
> "The Gentlemen"
> Rapidly evolving ransomware grou
> Possibly "veterans" of other groups
> Lists social media profile
> Check social media
> Follows me
> Check messages
> Message from them
> Picture of a cat
> "You're stinky"
lmfao wtf
π62π₯°14π€£10β€1