botw44 ๐•

6.2K posts

botw44 ๐• banner
botw44 ๐•

botw44 ๐•

@hack_fish

.byte 0x0f, 0x3f

Left from Germany ๊ฐ€์ž…์ผ Eylรผl 2012
1.9K ํŒ”๋กœ์ž‰338 ํŒ”๋กœ์›Œ
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Dominic Alvieri
Dominic Alvieri@AlvieriDยท
By popular demand ShinyHunters active onion /shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd[.]onion Enjoy!
Dominic Alvieri tweet media
Filipino
5
26
238
23.2K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Hackmanac
Hackmanac@H4ckmanacยท
๐ŸšจCyber Alert โ€ผ๏ธ ๐Ÿ‡ณ๐Ÿ‡ฑNetherlands - ASML Holding N.V. "1011" threat actor claims to have breached ASML Holding N.V. Allegedly, the attackers leaked data including approximately 154 SQL databases containing user information, software and device records, and disk encryption keys. Sector: Manufacturing Threat class: Cybercrime Observed: Jan 7, 2026 Status: Pending verification โ€” About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
Hackmanac tweet media
English
86
295
2.1K
305.8K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Hackmanac
Hackmanac@H4ckmanacยท
๐ŸšจCyberattack Alert โ€ผ๏ธ ๐Ÿ‡ฒ๐Ÿ‡ฝMexico - Universidad Nacional Autรณnoma de Mรฉxico (UNAM) ByteToBreach threat actor claims to have breached Universidad Nacional Autรณnoma de Mรฉxico (UNAM). Allegedly, the attackers conducted a multi-stage intrusion leveraging an F5 BIG-IP vulnerability and multiple internal pivots, deploying custom ransomware primarily for data exfiltration and encryption. Compromised data reportedly includes student and staff records, emails, databases, directory services data, and internal documents. Sector: Education Threat class: Cybercrime Observed: Jan 7, 2026 Status: Pending verification โ€” About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
Hackmanac tweet media
Espaรฑol
9
52
317
248.3K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
vx-underground
vx-underground@vxundergroundยท
Clarification post, previous post about Ubisoft lead to some confusion. That's my fault. I'll be more verbose. I was trying to compress the information into 1 singular post without it exceeding the word limit. Here's the word on the internet streets: - THE FIRST GROUP of individuals exploited a Rainbow 6 Siege service allowing them ban players, modify inventory, etc. These individuals did not touch user data (unsure if they even could). They gifted roughly $339,960,000,000,000 worth of in-game currency to players. Ubisoft will perform a roll back to undo the damages. They're probably annoyed. I cannot go into full details at this time how it was achieved. - A SECOND GROUP of individuals, unrelated to the FIRST GROUP of individuals, exploited a MongoDB instance from Ubisoft, using MongoBleed, which allowed them (in some capacity) to pivot to an internal Git repository. They exfiltrated a large portion of Ubisoft's internal source code. They assert it is data from the 90's - present, including software development kits, multiplayer services, etc. I have medium to high confidence this true. I've confirmed this with multiple parties. - A THIRD GROUP of individuals claim to have compromised Ubisoft and exfiltrated user data by exploiting MongoDB via MongoBleed. This group is trying to extort Ubisoft. They have a name for their extortion group and are active on Telegram. However, I have been unable to determine the validity of their claims. - A FOURTH GROUP of individuals assert the SECOND group of individuals are LYING and state the SECOND GROUP has had access to the Ubisoft internal source code for awhile. However, they state the SECOND GROUP is trying to hide behind the FIRST GROUP to masquerade as them and give them a reason to leak the source code in totality. The FIRST GROUP and FOURTH GROUP is frustrated by this Will the SECOND GROUP leak the source code? Is the SECOND GROUP telling the truth? Did the SECOND GROUP lie and have access to Ubisoft code this whole time? Was it MongoBleed? Will the FIRST GROUP get pinned for this? Who is this mysterious THIRD GROUP? Is this group related to any of the other groups? Find out next time on Dragon Ball Z
vx-underground tweet media
English
71
301
3.6K
417K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
ะฅะฐะฑั€
ะฅะฐะฑั€@habr_comยท
30 Tbps ะฒ ัะตะบัƒะฝะดัƒ: ะทะฐะบะฐั‚ ัะฟะพั…ะธ ะทะฐั‰ะธั‰ั‘ะฝะฝะพะณะพ ะธะฝั‚ะตั€ะฝะตั‚ะฐ? ะšะพะฝะตั† 2025 ะณะพะดะฐ ะพะทะฝะฐะผะตะฝะพะฒะฐะปัั ะฟะพัะฒะปะตะฝะธะตะผ ัƒะณั€ะพะทั‹ ะฝะพะฒะพะณะพ ะบะปะฐััะฐ. ะ‘ะพั‚ะฝะตั‚ AISURU ะฟะพัะปะตะดะพะฒะฐั‚ะตะปัŒะฝะพ ะฟั€ะพะฑะธะป ะฟะปะฐะฝะบัƒ ะฒ 15, ะฐ ะทะฐั‚ะตะผ ะธ ะฒ 30 Tbps, ะฐั‚ะฐะบัƒั ะธะฝั„ั€ะฐัั‚ั€ัƒะบั‚ัƒั€ัƒ Microsoft ะธ Cloudflare: u.habr.com/lUmRT
ะฅะฐะฑั€ tweet media
ะ ัƒััะบะธะน
7
24
190
41K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Cloudflare
Cloudflare@Cloudflareยท
Cloudflare just autonomously blocked hyper-volumetric DDoS attacks twice as large as anything seen on the Internet before โ€” peaking at 22.2 Tbps & 10.6 Bpps. Can your mitigation providerโ€™s scrubbing capacity handle that scale?
Cloudflare tweet media
English
45
128
1K
485.9K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
International Cyber Digest
International Cyber Digest@IntCyberDigestยท
๐Ÿšจ vx-underground reverse-engineered the malware that stole $32k donated to Rastaland for his cancer fight. They uncovered the entire infrastructure, operations, the people that fell victim, and people behind it.
International Cyber Digest tweet media
English
114
545
5.8K
2.9M
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Dark Web Informer
Dark Web Informer@DarkWebInformerยท
๐Ÿšจ300K Login:Passwords of McDonald's
Dark Web Informer tweet media
English
18
73
861
79.5K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Sam Curry
Sam Curry@samwcyoยท
New blog post with @infosec_au: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. The issue was reported and patched. Full post here: samcurry.net/hacking-subaru
English
47
312
1K
118.1K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Leonid Bezvershenko
Leonid Bezvershenko@bzvr_ยท
๐Ÿšจ We discovered two malicious Python packages in #PyPI repository that remained undetected for over a year. These packages mimicked tools for working with popular AI language models (#ChatGPT and #Claude), silently exfiltrating data and compromising developer environments. Full details and IOCs in the thread ๐Ÿ‘‡
Leonid Bezvershenko tweet media
English
15
271
960
164.6K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
HTTPVoid
HTTPVoid@httpvoid0x2fยท
Checkout our new blogpost! In this post we talk about SAML and the recent Ruby-SAML Auth bypass. CVE-2024-45409: Ruby-SAML Auth Bypass in GitLab blog.projectdiscovery.io/ruby-saml-gitlโ€ฆ
English
3
151
550
40K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
vx-underground
vx-underground@vxundergroundยท
A ransomware group was compromised. It contains some interesting information โ€” it's their tooling, some minor chat information, infrastructure credentials, internal notes, etc. It's going to make some people VERY angry. tl;dr mini Conti leaks
vx-underground tweet mediavx-underground tweet mediavx-underground tweet media
English
47
227
1.6K
163.2K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Matthew Prince ๐ŸŒฅ
Matthew Prince ๐ŸŒฅ@eastdakotaยท
Not all records youโ€™re happy about breaking: @Cloudflare recently mitigated the largest ever reported hyper-volumetric #DDoS attack. 3.8 terabits per second (Tbps) and 2.14 billion packets per second (Bpps). Handled automatically any without any customer impact. Details to come.
Matthew Prince ๐ŸŒฅ tweet media
English
108
621
6.6K
782.4K
botw44 ๐• ๋ฆฌํŠธ์œ—ํ•จ
Charles Fol
Charles Fol@cfreal_ยท
Blind file read to RCE in PHP - without access to files, we need to build reliable arbitrary read primitive from the ISO-2022-CN-EXT overflow (CVE-2024-2961) #CNEXT
Ambionics Security@ambionics

At long last: Iconv, set the charset to RCE (part 3): in this final part of the iconv series, @cfreal_ demonstrates how you can use CVE-2024-2961 to convert BLIND file reads to RCE. ambionics.io/blog/iconv-cveโ€ฆ

English
2
68
234
34.2K