Ax Sharma

3.6K posts

Ax Sharma banner
Ax Sharma

Ax Sharma

@Ax_Sharma

Security Researcher | Tech Journalist | 📰 Bylines + seen on: BBC, BleepingComputer, Channel 5, TechCrunch | ✉️ [email protected]

🇨🇦🇬🇧 Katılım Nisan 2016
1.4K Takip Edilen5.3K Takipçiler
Ax Sharma retweetledi
Hackmanac
Hackmanac@H4ckmanac·
🚨Cyber Alert ‼️ WormGPT A threat actor known as Sythe claimed to have leaked the database of WormGPT, a cybercrime-focused AI platform, exposing data linked to more than 19,000 users. The leaked data allegedly includes email addresses, user IDs, and subscription and billing metadata. Sector: ICT Threat class: Cybercrime Observed: Feb 10, 2026 Status: Pending verification — About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
Hackmanac tweet media
English
19
107
698
62.8K
Ax Sharma retweetledi
tuckner
tuckner@tuckner·
lmao for real?
tuckner tweet media
English
5
3
48
11.3K
Ax Sharma
Ax Sharma@Ax_Sharma·
Responsible disclosure is built on an assumption that "doing the right thing" = timely action & fair treatment, if not a bounty award. Lately, that assumption is collapsing. For CISOs, this is gradually evolving into a risk management nightmare. csoonline.com/article/412476…
English
0
0
0
170
Ax Sharma
Ax Sharma@Ax_Sharma·
A NationStates game player found a critical vulnerability and then crossed a line... He copied production data and app code to his personal system. bleepingcomputer.com/news/security/… Finding a flaw is enough. Demonstrate it safely, report it responsibly and stop there.
English
0
0
0
180
Ax Sharma
Ax Sharma@Ax_Sharma·
Such data can expose who runs what, at what scale, and when contracts renew. This serves as prime intel for competitors/customer poaching but also for threat actors aiming to launch targeted phishing, BEC and extortion attacks. bleepingcomputer.com/news/security/…
English
0
0
0
234
Ax Sharma
Ax Sharma@Ax_Sharma·
BREAKING: Threat actors are seeking data on ~1,800 MSPs after a Pax8 spreadsheet with customer and Microsoft licensing info was accidentally emailed to ~40 partners yesterday.
Ax Sharma tweet media
English
1
0
0
381
Ax Sharma
Ax Sharma@Ax_Sharma·
Especially problematic when these comments contain official lnkd[.]in shortener links and link previews don't load fully at times (first image). You'd have no definitive way of knowing that these are phishing at a first glance until you click!
Ax Sharma tweet mediaAx Sharma tweet media
English
0
0
0
152
Ax Sharma
Ax Sharma@Ax_Sharma·
Update: Multiple current and former Target employees confirm that source code samples shared online match real internal systems. The company also rolled out an "accelerated" security change restricting access to its Enterprise Git server bleepingcomputer.com/news/security/…
English
0
0
2
159
Ax Sharma
Ax Sharma@Ax_Sharma·
Target went silent after we shared evidence and links to the Gitea repos suggesting a possible breach.
English
1
0
0
253
Ax Sharma
Ax Sharma@Ax_Sharma·
EXCLUSIVE: Target's developer Git server went offline shortly after hackers claimed they had stolen internal source code and published what they claim are sample repositories for sale.
Ax Sharma tweet mediaAx Sharma tweet media
English
1
0
2
521
Ax Sharma retweetledi
NetBlocks
NetBlocks@netblocks·
⚠️ Update: It has been 108 hours since #Iran introduced a nationwide internet shutdown leaving Iranians isolated from the rest of the world and each other 📉 The rights to free speech and free assembly are inviolable and must be protected #DigitalBlackoutIran
NetBlocks tweet media
English
208
1.7K
3.1K
254.5K
Ax Sharma
Ax Sharma@Ax_Sharma·
Microsoft Copilot prompt injections—vulnerabilities or AI limits? Microsoft implies that these don't constitute "serviceable vulnerabilities." But, security pros are divided, esp. when AIs like Claude restrict inputs that can cause system prompt leaks. bleepingcomputer.com/news/security/…
English
0
0
0
200
Ax Sharma
Ax Sharma@Ax_Sharma·
@TrustWallet hasn't gotten back to us on what caused the incident and if victims who received the quasi-trojanized extension update, wil be compensated, but it did confirm the incident and released a fixed v2.69 that you should upgrade to: x.com/TrustWallet/st…
Trust Wallet@TrustWallet

We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69. Please refer to the official Chrome Webstore link here: chrome.google.com/webstore/detai… Please note: Mobile-only users and all other browser extension versions are not impacted. We understand how concerning this is and our team is actively working on the issue. We’ll keep sharing updates as soon as possible.

English
0
0
0
225
Ax Sharma
Ax Sharma@Ax_Sharma·
At the same time, we observed some X accounts pushing a newly-emerged 'fix-trustwallet[.]com' domain claiming to patch a bogus "security vulnerability" but instead prompting you for your wallet seed phrases.
Ax Sharma tweet mediaAx Sharma tweet media
English
1
0
0
212