Kabuto
2.5K posts

Kabuto
@meterpretered
MalDev - Offensive Security Researcher - I post occasional infosec stuff and drama



Session Desktop (@session_app) has a critical Electron misconfiguration that turns any XSS or code injection bug into remote account compromise. A single vulnerability in message/content handling = complete account takeover. rmoskovy.github.io/posts/session-… #Session #cybersecurity #threatintel













Startup idea: fridge that uses hot exhaust air as house heater














Arion Kurtaj could leave prison and land a huge job in cybersecurity, but instead he chooses to have a huge ego and do the complete opposite and acting all high and mighty to impress the internet he leaked GTAVI Guys a menace

These attacks, like all phishing, rely on social engineering. Attackers impersonate trusted contacts or services (such as the non-existent “Signal Support Bot”) to trick victims into handing over their login credentials or other information. To help prevent this, remember that your Signal SMS verification code is only ever needed when you are first signing up for the Signal app. 2/4














