Palioh

50 posts

Palioh banner
Palioh

Palioh

@bulletfault

Katılım Aralık 2022
16 Takip Edilen3 Takipçiler
Palioh
Palioh@bulletfault·
@67_throwaway @akaclandestine threat actors caring about UI design for their RAT software is like a roadman asking for a light after they rob you (the joke is the RATs are often dualhooked)
English
0
0
0
25
throwaway_account_67
throwaway_account_67@67_throwaway·
@akaclandestine How does someone make a RAT with that many features yet the UI looks worse than Dark Comet which is like 2 decades old at this point. 😞
English
2
0
1
249
Clandestine
Clandestine@akaclandestine·
🚨 CTI ALERT – HIGH-RISK THREAT Threat Intelligence confirms the April 2026 launch of a highly sophisticated new private Windows Remote Access Trojan: FALKONc2 (ROTEMELLI stubs). Developed entirely from scratch in C++ + MASM64, 100% fileless (operates exclusively in memory), with ultra-lightweight stubs of 23-35 KB and zero third-party code. Full focus on advanced evasion and long-term persistence. 1/5 Two strategic variants: • ROTEMELLI1 (Consumer targets) – €249/month
Bypasses 50+ AVs | HTTP + custom encryption (mm4/ChaCha20) | Weekly C2 domain rotation • ROTEMELLI2 (Corporate targets) – €1,499/month
Bypasses 50+ EDR/XDR | DNS + HTTP (+ ICMP on legacy systems) | C2 rotation every 72 hours 2/5 Critical confirmed capabilities: •Silent HVNC/RMM + remote shell •Advanced local network reconnaissance (SMB, FTP/SSH/RDP) •Active Directory, QuickBooks & Sage50 detection •Automatic privilege escalation + kernel-mode BSOD •Synchronous 1080p screen capture + GPS tracking •Resident loader + custom Builder/Morpher (latest MM12 version) •x86/x64/ARM64 support + custom icon No public samples or IOCs available — the seller explicitly prohibits uploads to any public scanners. 3/5 Professional MaaS sales model: Sold exclusively via Telegram and select underground forums after rigorous buyer verification. Geographic restrictions apply (no CIS countries or Japan). Elevated risk to corporate environments due to next-generation EDR/XDR evasion and long-term stealth persistence. 4/5 Immediate recommendation for SOC and Threat Hunting teams: •Prioritize behavioral detection of fileless execution and memory injection •Monitor anomalous low-footprint DNS/HTTP/ICMP traffic •Keep EDR/XDR behavioral analytics rules fully updated Stay vigilant. Full technical report and deep-dive analysis available upon request. 5/5 #CyberSecurity #ThreatIntelligence #Malware #RAT #EDR #XDR #FilelessMalware #InfoSec #CyberThreat #APT #DarkWeb #C2 #CyberDefense #WindowsSecurity
Clandestine tweet media
English
2
37
147
14.7K
katardo
katardo@kataansqueue·
@vagueviolet My cheat sheet for Signals and Systems when I was at university for Electrical engineering 😿
katardo tweet media
English
22
4
517
76.3K
Ryan
Ryan@hellorymi·
@dabit3 Time to intercept local requests to api.github.com/user to return 200 no matter what as you clean up this mess
English
6
0
193
34.1K
nader dabit
nader dabit@dabit3·
This is crazy. The hacker installed a dead-man's switch that will wipe your computer if you revoke the GitHub token they stole from you. Revoking the token is what triggers the wipe.
nader dabit tweet media
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
145
1K
9.6K
1.7M
Palioh
Palioh@bulletfault·
@realCrackWatch I had the choice of paying 50$ for the past 2 years but always held out hope and I’m glad I did.
English
0
0
0
27
divyansh tiwari
divyansh tiwari@DivyanshT91162·
CAPTCHA IS OFFICIALLY OUTDATED A new open-source library called Cap is changing how websites stop bots. No puzzles. No traffic lights. No “select all bikes” anymore. Instead, it uses a SHA-256 proof-of-work system — simple, silent, and fast. Why devs are switching: • Only ~20KB in size • Zero tracking, zero data collection • No images, no user friction • Works with any JS runtime • Fully customizable (visible, invisible, floating modes) • Zero dependencies • Can be deployed instantly via Docker This is a full replacement for traditional CAPTCHA systems. Cleaner UX. Faster websites. Better privacy. 100% open-source on GitHub Link in comments.
English
20
86
981
112.7K
Palioh
Palioh@bulletfault·
@cryptopunk7213 when I write BS posts glamorizing benchmark tests open source models intentionally train to score highest on instead of actual applications.
English
0
0
0
1.3K
Ejaaz
Ejaaz@cryptopunk7213·
it’s official - china’s fucking dominating AI. they’ve caught up. new DeepSeek v4 matches GPT-5.5, costs 86% less. 100% open source. don’t take my word for it: -> deepseek v4 flash is 99% cheaper than opus 4.7 (not a typo). $0.28 per million tokens -> ranks #1 on code forces benchmark beating gpt 5.4. competitive to 5.5 and opus. in the last week: → Mon: Moonshot drops Kimi K2.6 → Wed: Alibaba drops Qwen 3.6-27B → Thurs: DeepSeek drops V4 3 chinese labs, 3 frontier OPEN source models in < 4 (FOUR) days there is no way you can argue china hasn’t caught up. gg
Ejaaz tweet media
DeepSeek@deepseek_ai

🚀 DeepSeek-V4 Preview is officially live & open-sourced! Welcome to the era of cost-effective 1M context length. 🔹 DeepSeek-V4-Pro: 1.6T total / 49B active params. Performance rivaling the world's top closed-source models. 🔹 DeepSeek-V4-Flash: 284B total / 13B active params. Your fast, efficient, and economical choice. Try it now at chat.deepseek.com via Expert Mode / Instant Mode. API is updated & available today! 📄 Tech Report: huggingface.co/deepseek-ai/De… 🤗 Open Weights: huggingface.co/collections/de… 1/n

English
142
159
1.5K
214.7K
Palioh
Palioh@bulletfault·
@7N7 if only their models werent so censored to shit over xoring a string
English
0
0
1
105
Zoro
Zoro@idealworld236·
@oprktr Thank you for template 😋🙏
Zoro tweet media
English
5
1
30
2.7K
Palioh
Palioh@bulletfault·
@hemzadev @HeyAnsariUX I mean. Not really but it certainly can be done with a vision model + sonnet 4.6
English
0
0
0
588
Benny
Benny@hemzadev·
@HeyAnsariUX This is what I got from my daily Lovable limit, pretty close to the original
Benny tweet media
English
11
0
42
12.1K
Aman Ansari
Aman Ansari@HeyAnsariUX·
AI can never match this level of quality
Aman Ansari tweet media
English
158
34
1.6K
139.9K
CyberSatoshi 𓆙
CyberSatoshi 𓆙@XBToshi·
The parallel economy doesn't run on the clearnet, have been optimizing the performance on Tor🧅. @kyc_rip Tor v1 beta is live. • Native .onion routing • 6,500+ pairs aggregated • 100% No-JS compatible • Absolute zero KYC Stop leaking your metadata.
CyberSatoshi 𓆙 tweet media
English
5
16
150
6.9K
Ampere.sh
Ampere.sh@AmpereSh·
I hear you that’s definitely not the experience we want you to have. The plan isn’t capped by dollar value, but by compute usage. Some requests (especially heavier ones like coding or multi-step tasks) can use more capacity than expected, which can make it feel limited. That said, I’d like to take a closer look and help fix this—please DM me your details and I’ll get it sorted 👍
English
3
0
1
651
Ampere.sh
Ampere.sh@AmpereSh·
🚨 UNLIMITED Claude Opus 4.6 is LIVE for EVERYONE on ALL Ampere plans! No limits. Full Opus on every request your Openclaw makes. 7 Days of UNLIMITED for users on ALL plans. World's hot favourite model is FINALLY UNLIMITED - for one whole week. You waited long. And you get it on Ampere👇
Ampere.sh tweet media
English
112
76
1.2K
461.8K
Palioh
Palioh@bulletfault·
@JungleOfx @durov Telegram doesn’t guarantee privacy outside of secret chats either, don’t anticipate them to accommodate your ban appeal on the world’s largest cyber crime network.
English
0
0
1
538
The Jungle of X
The Jungle of X@JungleOfx·
@durov Telegram is a worse app to use, you ban users as you like without any justification.
English
4
3
74
7.6K
Pavel Durov
Pavel Durov@durov·
That’s why Telegram Secret Chats never show message content in push notifications. Since 2013, Secret Chats have remained the most secure usable way to communicate. US gov funded Signal has too many questionable dependencies on other US companies (AWS, MS, Intel SGX…)
International Cyber Digest@IntCyberDigest

🚨 BREAKING: The FBI has successfully extracted deleted Signal messages from a suspect's iPhone via notification storage, the place where all your notifications are stored for up to one month. Notification storage stores data from all messaging apps, it's a big flaw in iOS. But there's a way to turn it off...

English
472
1.5K
11K
1.3M
Coder
Coder@Coder9420948594·
@FireworksAI_HQ Speed is really awful, even zai has better speed
Coder tweet media
English
1
0
1
307
Fireworks AI
Fireworks AI@FireworksAI_HQ·
GLM 5.1 is live on Fireworks! SOTA for agents and coding: →Plans and executes multi-hour workflows without falling apart →Planning, executing, testing, and refining over hundreds of rounds to deliver real, production-grade results. Go build something: app.fireworks.ai/models/firewor…
Fireworks AI tweet media
English
20
14
238
11.6K
Palioh
Palioh@bulletfault·
@7N7 Probably marketing purposes as well. I can believe a model twice as strong as opus but to the level they’re describing I’m not totally sure if its not exaggerated
English
0
0
0
44
Luke W
Luke W@luke_watch56789·
@tragicbirdapp Just bang her and then continue the argument, gotta take advantage of your post nut clarity.
English
1
0
718
20.8K
Palioh
Palioh@bulletfault·
@LyashchMaxim @bridgemindai Your gonna be spending a lot of tokens. Here’s what openclaw did to my glm 5 usage. I think it was because it was generating so many skills and pulling too much data from existing skills. Hopefully 5.1 isn’t the same.
Palioh tweet media
English
1
0
1
42
BridgeMind
BridgeMind@bridgemindai·
GLM 5.1 just dropped on OpenRouter. $1.40/$4.40 per million tokens. 202K context. Released today. The model that claims to work independently on a single task for over 8 hours. Autonomously planning, executing, and self-improving. That's a bold claim. Time to prove it. BridgeBench results coming soon. bridgebench.ai
BridgeMind tweet media
English
18
9
225
11.7K
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️ A BreachForums administrator has allegedly been identified — caught using his real IP and reusing the same passwords across his criminal persona and business accounts. Meet Angel Tsvetkov AKA N/A: a Bulgarian cybersecurity specialist, penetration tester and bug bounty researcher known for responsibly disclosing vulnerabilities in major global platforms.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
47
163
1.3K
163.5K