mac
3.6K posts


🚨 MULLVAD FUITE - VOTRE VPN VOUS TRAHIT Vendredi dernier, @mullvadnet a découvert que ses propres serveurs permettaient de te tracker entre différents nodes. Tu changes de serveur VPN pour casser la corrélation ? Raté. Tu es identifiable d'un serveur à l'autre. -Comment ça marche : Chaque user a une clé WireGuard + une IP interne de tunnel L'IP de sortie attribuée a une position relative dans la plage du serveur (genre 40% du range) Cette position reste la même quand tu changes de serveur -Résultat : un site qui te voit sur le serveur A peut deviner que c'est toi sur le serveur B -Ce que ça révèle : pas ton identité, mais le fait que "le même user a switché du serveur A au serveur B". Pour un threat model sérieux (journaliste, activiste, recherche OSINT), c'est game over sur l'unlinkability. -Le fix temporaire en attendant le rollout : log out / log in dans l'app Mullvad à chaque switch de serveur. 🤯 (Ça regénère la clé WireGuard et l'IP interne.) -La leçon : même les meilleurs outils privacy ont des angles morts. Le VPN n'est PAS l'anonymat. C'est une couche, pas une solution. [Source en commentaire 👇] #InfoSec #Privacy #LAB312




Them: Linux is most secure OS Me: Yes - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

📢 Breached and TeamPCP announce supply chain attack competition with $1,000 USD prize and open-sourced Shai Hulud worm The owner of Breached has announced a joint competition with TeamPCP offering $1,000 USD in XMR to whoever conducts the biggest supply chain attack. As part of the announcement, TeamPCP's Shai Hulud worm has been open-sourced and hosted on the Breached CDN (also published yesterday on GitHub), with participants required to use the worm in their attacks. Winners are determined by total weekly and monthly download counts of compromised packages, with smaller package compromises added together to count toward the total. ▸ Actor: [Owner] diencracked in collaboration with TeamPCP ▸ Sector: Cybercrime Forum / Supply Chain Attack Tooling ▸ Type: Attack Competition Announcement / Tool Release ▸ Prize: $1,000 USD (XMR only) ▸ Country: N/A ▸ Date: 11/05/2026 Competition details: ▪ First-ever supply chain attack competition hosted on BreachForums ▪ TeamPCP's Shai Hulud worm released as open source and hosted on the Breached CDN ▪ Raw download link also provided for the worm ▪ Participants must use the Shai Hulud worm in their attack ▪ Submissions must include the participant's forum handle, preferably linked to their Breached profile ▪ Reasonable proof of access must be submitted alongside the entry ▪ Winner determined by the largest supply chain attack measured by weekly and monthly package downloads ▪ Compromises of multiple small packages are aggregated toward the total ▪ Prize paid by diencracked in XMR Stop guessing what's redacted. Subscribers see everything → darkwebinformer.com/pricing

31 year old Chicago man’s mugshot has gone viral 👀

















