
Kernelson
79 posts

Kernelson
@kernelson
Cybersecurity, Crypto, Biohacking, Cars, OPSEC, OSINT & Politics. Tweets in 🇧🇷 and 🇺🇸. Opinions are my own.
Argentina Beigetreten Aralık 2011
490 Folgt81 Follower
Angehefteter Tweet

@jwkenai @rikeycertezas Significa que você concedeu ao estado o direito absoluto de monitoramento sobre a sua vida, parabéns 👏🏻
Português

@CEOofSleep @bryan_johnson Metamucil was my choice until I discovered it's contaminated with lead. There are multiple reports and even a lawsuit against the company.
According to the complaint, testing found that certain products exceeded California’s Prop 65 threshold of 0.5mcg of lead per serving.
English

@bryan_johnson Why not replace Acarbose with Metformin. Acarbose is like a bile acid sequestrant, you can get the same effect using Metamucil. Olmesartan and Telmisartan > Candesartan, longer 1/2 life and exhibit superior blockade of Angiotensin
English

I may have the best comprehensive biomarkers ever measured.
Here are the receipts.
There’s a title for the fastest person in the world. And the richest. But up until now, no one has become the healthiest. I share my protocol so that you can beat me.
Below are my labs from two weeks ago and also 12-month averages for over 60 of the most predictive markers of longevity.
For those of you interested in the particular details of these lab reports, here are a few notes about a few results:




English

Kernelson retweetet

⚠️ Attackers poisoned Hugging Face & ClawHub (OpenClaw) with 575+ malicious skills from just 13 accounts.
🔸 Fake helpful AI tools that install trojans, miners & stealers (Windows + macOS)
🔸 Use hidden commands & indirect prompt injection
Quick action: Never install random AI skills or models. Always verify the source.
Read: thehackernews.com/2026/05/weekly…

English
Kernelson retweetet

‼️ 323 vials containing deadly viruses go missing from a lab in Australia — ABC News
Among them, nearly 100 vials contained the Hendra virus (transmitted from horses to humans, with a 57% fatality rate). Two vials contained the hantavirus (spread by rodents, with a 38% fatality rate), and 223 vials contained the lyssavirus (rabies virus, with an almost 100% fatality rate).
The most likely cause of the "disappearance" is thought to be the loss of containers during transfer to a new freezer. The Ministry of Health is conducting an investigation.
English

@GordoGeek Eu tenho um e-mail criado exclusivamente pro gov.br e já recebi malware nesse endereço por diversas vezes 🤷🏻♂️
Português

@douglascrypto @defyneric @BrzToken @transferogroup Uma pena que na hora de fazer on-ramp com os parceiros de vocês, o serviço vive fora do ar…
Português

@HarrisonCaplan @medical_xpress Which omega 3 type is best to take?
English

In older adults, omega-3 supplement use was linked to faster decline on 3 cognitive tests over 5 years, while brain scans pointed not to amyloid or tau, but to lower glucose metabolism. medicalxpress.com/news/2026-05-o…
English
Kernelson retweetet

‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017.
Website: copy.fail
Write-up: xint.io/blog/copy-fail…
GitHub: github.com/theori-io/copy…
It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su.
Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise.
Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.
English

Vocês sabiam que o dono do imóvel vai repassar o valor do IPTU pro inquilino né? Nada impede ele de cobrar o valor que ele quiser no aluguel. Parece que vocês se esforçam pra serem burros.
Cleitinho@cleitinhotmj
É polêmico, mas é justo!!! Se você mora de aluguel, chega de pagar IPTU para o proprietário!!! Quem tem que pagar o IPTU?
Português
Kernelson retweetet

🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push
The flaw in @github allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯

English
Kernelson retweetet
Kernelson retweetet

TeamPCP is back.
The xinference PyPI package (680K downloads, 9.3K stars) was hijacked. Import it and your cloud credentials, SSH keys, and .env secrets are instantly harvested and exfiltrated.
Versions 2.6.0–2.6.2 are malicious. If you installed them, assume compromise and rotate everything now.
Full technical breakdown 👇
English
Kernelson retweetet

A full file system extraction of an iPhone 15 Pro revealed extensive user data, including emails, Discord activity, and multiple social media accounts with associated artifacts. Notably, the presence of a burner number application highlights a common misconception; devices still retain significant traces of usage despite attempts at anonymity.
This demonstrates how modern smartphones continuously generate and store evidential data, making them highly valuable in digital investigations and reinforcing the importance of understanding mobile forensic exposure.

English
Kernelson retweetet

This is AWESOME... Some guy just sequenced his entire DNA genome on his kitchen table 🧬🧪
It tells his cancer risk, drug responses, what his kids will inherit, and which diseases are coming decades before the symptoms.
Your genome is a 3.2 billion letter source code that predicts more about your health than any other test in existence. Almost no one has ever read their own.
This used to require a hospital, a specialist, and a referral that most doctors won't write. The raw data would sit in a medical record you'd never see.
Until now.
Here's how he did it:
→ Rubbed a cheek swab against the inside of his mouth for 60 seconds
→ Extracted the DNA from his cells using a $150 kit
→ Prepped the DNA for sequencing with enzymes that attach a motor protein to each strand
→ Loaded the sample onto a nanopore device the size of a highlighter, plugged into a MacBook
The device works by pulling single strands of DNA through holes one atom wide. As each letter passes through, it changes the electrical resistance in a tiny but measurable way. A neural network listens to the signal and reconstructs the sequence. 48 hours later, he had his full genome on his hard drive.
The data never touched a server. No spit kit in the mail. No company owning his most sensitive biological information. No risk of the whole thing getting auctioned off in a bankruptcy, which is exactly what happened to 23andMe's 15 million customers earlier this year.
AI is unlocking personal health in a way that has been impossible. We're still so early.


Seth Howes@SethSHowes
I sequenced my genome at home, on my kitchen table. I wrote up exactly how I did it - the equipment, protocol, theory, and cost: iwantosequencemygenomeathome.com
English

@securitybrahh JMP is useless because its numbers are VoIP and it's not suitable for registering accounts, especially on WhatsApp 👍🏼
English

Location is the most sensitive information and if the LE come knocking at Cape’s doors they would happily oblige. JMP doesn’t have your location, so can’t give it.
IMSI rotation without IMEI and EID rotation does not provide anything other than maybe stringray protections. (Which jmp provides - because there is no local SIM)
We are inclined to use a phone number because institutions/banks use them as a way to verify you, in that case the best strategy is to change to an alternative that uses TOTP for 2fa for eg.
I am seeing a wider adoption of WhatsApp for calls, its e2ee! Even if Meta knows who you are calling, at least the call is encrypted, better than “normal” calls as anyone in the dozen companies / PBX’s and PSTN / the government can log them, so are logging it.
That’s why I like jmp .chat because its a bridge, products and services will use phone numbers as a way to stop spam and its just 5$ per month not 99$ (you can use BKTK57SA for a free month)
The only thing you miss while on airplane mode on a graphene os device is the mobile data, use WiFi’s!
The best solution for mobile data I got, is to use a rooted graphene OS device as a hotspot for IMEI rotation and using 9esim adapter (coupon SECURITYBRAHH2 for 10% off - buy in bulk for the travels) for EID rotation, and using silent.link as it is a no kyc IMSI (internet) provider.
Refutation of Each “feature" of Cape:
“minimal” personal data collection and retention
As per their privacy policy:
“In providing you with the Cape Mobile Carrier Service, Cape will also collect your Cell ID, call logs, subscriber number (IMSI), your device number (IMEI) and your MAC address. Cell ID and call logs are stored for two months for billing, compliance, and financial reconciliation.”
On the other hand, JMP only log your call history but you can ask them to clear, SMS are stored in server for 7 days only but you can get your own server.
SIM swap protection
You don’t need to pay 99$ for that, with JMP as there’s no SIM to swap, you are protected.
“enhanced” signaling protection
To my understanding they do that via location permission from the app.
As far as tracking via SS7, there are two methods that could be used:
Interception via IMSI catcher
A location request ping from the network
In both cases the messaging and voice service from JMP is out of scope. It doesn’t tie to a SIM and doesn’t respond to SS7 requests because the protocol isn’t being used on the device.
Soprani .ca - all the code is open source and you can audit it, yourself. Not true for cape. Maybe I will release an audit like I did forwardemail - great email service that even has zero access encryption for metadata.
semi-”private” payment
They say, they use stripe sdk for tokenization of the card but if LE asks stripe for the data, LE will easily know the card holder.
On the other hand, JMP supports Bitcoin and Bitcoin cash. And you can pay with cash as well, the most anonymous payment option by far. I will try to propose bitcoin lightning to them.
Stripe stores the mapping of the full card to a secure token and links this to a Customer object, enabling the connection between the last 4 digits and the individual.
Stripe has a vaultless payment option, but cape didn't answer my question here
https://www.reddit .com/r/CapeCellular/s/m9py6vj9Nw
JMP uses paypal braintree, you can use cakepay mastercard or fluz.app if you want to use a card.
“encrypted” voicemail
Anyone of the dozen companies and the government monitoring the PSTN has your voicemails, just cape doesn’t.
That’s a false hope, use signal you fools. Even WhatsApp is better for e2ee voice calls.
generate secondary numbers
You can have 2 separate numbers in Cape for sms only which can be provisioned again and again.
But you don’t need to pay 99$ for that, each new number on JMP is 2.45$ per month and you can get premium+ routes that work flawlessly with online services.
Smspool .net is a great service for one time verification.
automatic spam filtering
JMP has their own spam filtering, and they don’t block robo calls as you may need to hear automatic high priority voice mails from the schools, your banks, and other institutions.
The better strategy is, as always, getting good at OPSEC and not giving your phone number to anyone who doesn’t need it.
If your number is burned, kindly get another one and migrate all the services you absolutely need. Don’t use the services, you don’t need.
unlimited talk, text and data
At 99$, C’mon.
JMP gives you “unlimited” text and talk at 5$, and you probably don’t need unlimited let's be real.
For data, only silent.link is the play.
secure global roaming
Silent.link is better, why do you even need a cellular for anything other than mobile data.
no contracts
With JMP, you have no contracts as well.
English
Kernelson retweetet

🚨 NATIONAL SECURITY ALERT (TO BE VERIFIED): ALLEGED MASSIVE LEAK OF 251 MILLION CPFs (BRAZIL) 🇧🇷
A catastrophic post has been detected in which a threat actor claims to possess the largest database in Brazilian history, called "MORGUE." The report indicates a massive exfiltration that would exceed even the current living population of the country.
🏢 Allegedly Affected Entity: Gov.br Portal / Brazilian National Registries 🇧🇷
👤 Threat Actor: Buddha
📂 Leak Volume: 251,720,444 records (25.1 GB)
📊 Allegedly Compromised Data (PII):
CPF (National Identification Number), Full Names, and Gender.
Date of birth, Mother's and Father's names.
Death data: Status of death and date of death (which explains why the figure exceeds 212 million living inhabitants).
Race and City/State of birth.
📅 Date of Data: According to the actor, the information corresponds to March 15, 2025.
🔍 Status: Alleged / Not officially verified. Although the actor has published a free sample of 20,000 rows to validate its authenticity.
Monitor:
analyzer.vecert.io
#CyberSecurity #Brazil #GovBr #DataBreach #Buddha #MorgueLeak #CPF #Hacking #InfoSec #VECERT #Cybersecurity #Privacy #BiggestLeak 🇧🇷🛡️💀

English
Kernelson retweetet

🚨 CRITICAL SECURITY ALERT: STRATEGIC AND LOGISTICAL EXPOSURE (CORREIOS - BRAZIL) 🇧🇷
A massive sale of sensitive data belonging to Correios (Empresa Brasileira de Correios e Telégrafos) has been detected. The incident is highly serious because it includes not only financial information but also detailed plans of critical infrastructure, representing a physical and operational security risk.
🏢 Affected Entity: Correios (ECT - Brazilian National Postal Service) 🇧🇷
👤 Threat Actor: breach3d (MVP on DarkForums)
📂 Nature of the Data: Operational and financial information, and architectural plans.
📊 Assets Involved:
Logistics and Financial Records: Thousands of official receipts linked to high-profile entities such as Banco do Brasil SA.
Strategic Blueprints: Detailed designs of the "CCE - Centro de Cartas e Encomendas" (Certificates and Parcel Centers), including technical rooms and restricted security areas.
Operational Data: Tracking ranges (Tags), service codes, employee IDs, and workstations.
Technical Information: HVAC, electrical, and structural system plans for the logistics centers.
📅 Data Recency: Records from late 2021 to the most recent infrastructure plans.
🔍 Status: Active sale. The seller has published sample plans and receipts to verify authenticity.
Monitor:
analyzer.vecert.io
#CyberSecurity #Brasil #Correios #DataBreach #LogisticsSecurity #CriticalInfrastructure #Hacking #InfoSec #VECERT #Cibersecurity #IndustrialEspionage #breach3d 🇧🇷🛡️📦

English




