finx

654 posts

finx banner
finx

finx

@thisisfinx

Cybersec lifelong student | Blue Teamer | Dumbass (still am) Curator for Malaysian OSINT resource toolkit in startme and UNISHKA🇲🇾.

Malaysia Inscrit le Mayıs 2021
973 Abonnements199 Abonnés
finx retweeté
finx retweeté
Zach Yek
Zach Yek@zachtheyek·
Malaysians have a word for politicians who switch parties: katak — frogs. 🐸 So I built the receipts. Lompat — every party-hop in Malaysian politics since 1955, searchable. Type any name, get their full trajectory. The whole Sheraton cast is in here: zachtheyek.github.io/lompat/
Thevesh@Thevesh

After almost 4 years of hard work, I'm very happy to share something which I hope will be a game-changer for election data in Malaysia: electiondata.my To cut a (very) long story short, the site gives you access to Malaysia's COMPLETE electoral history. Every election, every candidate, every party, every seat - all there at your fingertips. There are 5 types of datasets available: • Parlimen/DUN-level results (the 'official' results, covering every single election since 1955) • Parlimen/DUN-level maps (covering every single boundary-drawing exercise since 1954) • Anonymised individual-level voter rolls for GE-13, GE-14, and GE-15, as well as Johor 2022 and N9 2023 (more to come soon) • Saluran (!!!!) level results for GE-13, GE-14, and GE-15, as well as Johor 2022 and N9 2023 (also more to come soon) • DM-level maps for the latest set (versions going back to 2003 will follow eventually) Enjoy! Data-cleaning and curation is bitter work, but once it's done once, everyone can reap the benefits.

English
16
591
1.4K
83.1K
finx retweeté
Fusion Intelligence Center @ StealthMole
We traced the threat actor behind the defacement of Malaysia's Ministry of Health (MOH) website. Our investigation found that the actor has been active on Telegram since 2024, participating in multiple channels related to hacking forums, web shells, spam, hacking tools, and data leaks. We also observed that the actor changed usernames multiple times before recently adopting the alias "Mushr00w." In addition, we identified past messages in which the actor used Turkish in a data leak tool channel, providing another potential lead for attribution.
Fusion Intelligence Center @ StealthMole tweet media
Malay Mail@malaymail

Health Ministry confirms website hack, urges public to use official channels while recovery efforts continue. ebx.sh/a5GaaQ

English
1
25
140
24.1K
finx
finx@thisisfinx·
@FairuzMo Future versions perhaps? I am still open for recommendation for startme and this one tho😌
English
0
0
0
177
finx
finx@thisisfinx·
Alhamdullilah, OSINT of Malaysia finally out. The content here is unique compared to the startme so feel free to check em out. Another step foward for Malaysian OSINT scene 🇲🇾 #osint #malaysia
UNISHKA@UNISHKAResearch

OSINT of Malaysia is out! Many Thanks to @thisisfinx for building this toolkit. The toolkit contains open data portals, company registries, land and property records, geospatial data, people search, and more. Link: unishka.substack.com/p/osint-of-mal…

English
2
44
165
11.7K
finx retweeté
Dinesh Nair
Dinesh Nair@alphaque·
This looks like it is shamelessly ripped off from ElectionData.my. A buried disclaimer doesn't excuse that it was most likely vibe coded with data blatantly hoovered from @Thevesh's sweat and efforts. What's worse is that it's a commercial play for profit. Despicable.
Dinesh Nair tweet media
English
3
16
43
32.2K
finx retweeté
R4shSec
R4shSec@r4shsec·
‼️🇲🇾 Malaysia’s Ministry of Health (MOH) just got hacked! Threat actor, “Mushr00w” compromised the website via KKM/MOH Content Management System (CMS), Joomla. CVE-2026-48907 is a Remote Code Execution (RCE) vulnerability affecting Joomla. Upgrading to Joomla 2.9.99.5+ fix it.
R4shSec tweet mediaR4shSec tweet media
English
2
3
5
468
finx retweeté
Thevesh
Thevesh@Thevesh·
After almost 4 years of hard work, I'm very happy to share something which I hope will be a game-changer for election data in Malaysia: electiondata.my To cut a (very) long story short, the site gives you access to Malaysia's COMPLETE electoral history. Every election, every candidate, every party, every seat - all there at your fingertips. There are 5 types of datasets available: • Parlimen/DUN-level results (the 'official' results, covering every single election since 1955) • Parlimen/DUN-level maps (covering every single boundary-drawing exercise since 1954) • Anonymised individual-level voter rolls for GE-13, GE-14, and GE-15, as well as Johor 2022 and N9 2023 (more to come soon) • Saluran (!!!!) level results for GE-13, GE-14, and GE-15, as well as Johor 2022 and N9 2023 (also more to come soon) • DM-level maps for the latest set (versions going back to 2003 will follow eventually) Enjoy! Data-cleaning and curation is bitter work, but once it's done once, everyone can reap the benefits.
English
53
775
1.5K
243K
finx
finx@thisisfinx·
Annual touching grass moment, iykyk😉
finx tweet media
HT
0
0
0
42
finx
finx@thisisfinx·
I forgot one hashtag, #AI
English
0
0
0
25
finx
finx@thisisfinx·
At first glance, NotebookLLM is a learning site provided by Google. But if examined the site features properly: NotebookLLM is an open-source RAG. Sounds absurd? I will prove to you otherwise on my latest medium post: thisisfinx.medium.com/lite-osint-not… #osint
English
1
0
0
68
finx retweeté
Rectifyq
Rectifyq@_rectifyq·
Some quick searches reveal that there were at least: 9 .gov.my 12 .edu.my 2 .org.my others .com.my, .my Refer: hudsonrock.com/fortinet
Rectifyq tweet media
International Cyber Digest@IntCyberDigest

‼️🚨 BREAKING: 320,000 Fortinet firewall devices have been targeted in a campaign that has been dubbed 'FortiBleed'. Attackers were able to confirm 75,000 working credentials against the admin and SSL VPN interfaces. The victims include really big names like Samsung, Oracle, Spotify, Sony, and more. The data was first surfaced by researcher Volodymyr "Bob" Diachenko and analyzed by Hudson Rock and SOCRadar. The operation runs as a self-feeding loop. Attackers scan the internet for exposed Fortinet devices, then test each one against a curated list of passwords leaked from earlier Fortinet breaches and infostealer logs. Every successful login gets recorded into a verified database. They then turn each compromised box into a listening post, sniffing the traffic passing through the firewall to harvest fresh credentials, which go straight back into the scanner. The scale is large. The group ran an estimated 1.16 billion credential attempts against more than 320,000 FortiGate targets, plus 2.1 billion brute-force tries against 160,000 MSSQL servers. In the deeper intrusions they intercept SSL VPN authentication hashes, crack them on a dedicated 45-GPU cluster, and move into internal Active Directory. Diachenko confirmed full network compromises in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor that had classified defense documents stolen. If you run Fortinet, act now: rotate every VPN and admin credential, enforce MFA on all external gateways, restrict management access to approved sources, segment internal networks, and audit gateway logs for unusual logins. Hudson Rock has a free domain lookup at hudsonrock.com/fortinet. Data surfaced via the Hunt Intelligence, Inc. feed.

English
0
20
67
7.4K
finx retweeté
FalconFeeds.io
FalconFeeds.io@FalconFeedsio·
Ransomware Alert: 🇲🇾 Kedah Darul Aman State Government (kedah.gov.my), a Malaysia-based government organization, has reportedly fallen victim to Nova Ransomware. NB: The group intends to publish the data within 14-15 days. 🔍Key Details: 🛡️Threat actor: Nova 📅 Reported on: 16/06/26 ⚠️ Data Compromised: 23 GB
FalconFeeds.io tweet media
English
3
55
94
7.5K
finx
finx@thisisfinx·
This post legit surprised me..I was like..since when? Oh: I clicked the link😅. Oh well: if you still followed me and my post, I am honored to be worthy of a follow😌. FYI: I am trying to be active these days so keep your eyes peeled on that~
English
0
0
0
35
finx
finx@thisisfinx·
I am posting out of my hiatus scrolling just to find this. Reminder to all: this list is now one of the featured list on @startme and is currently maintained by yours truly. The link in the quoted tweet. A step foward for Malaysian OSINT scene😌 #osint #malaysia
Start.me@startme

Researching Malaysia from open sources? This Start.me page brings OSINT resources for landmarks, traffic, military vessel tracking, environment monitoring, and more into one clear dashboard. start.me/p/KMqwBB/osint… #OSINT #Malaysia

English
2
1
16
1.3K
finx retweeté
Mylon Intelligence
Mylon Intelligence@MylonIntel·
‼️CYBERSECURITY INCIDENT GitHub Pull Request (PR) #3139 was made regarding the removal of NX Console from the VS Code Marketplace on 18/5/2026. The VS Code extension was compromised, and it contains an infostealer. Microsoft has since removed it from the VS Code marketplace.
Mylon Intelligence tweet mediaMylon Intelligence tweet media
English
1
1
1
172
finx retweeté
Mylon Intelligence
Mylon Intelligence@MylonIntel·
‼️🚨 CYBERSECURITY INCIDENT — A threat actor on a hacker forum, "TeamPCP" is allegedly selling GitHub source code. Mylon Intelligence has identified that there was no user data involved which aligns with GitHub investigative reports.
Mylon Intelligence tweet mediaMylon Intelligence tweet media
English
1
1
2
450