conor

34 posts

conor

conor

@conorfrmn

(un)ethical hacker, offsec lead, msc cybersecurity, @darknetdiaries ep. 154

Ireland Katılım Ekim 2010
57 Takip Edilen408 Takipçiler
conor retweetledi
Swen
Swen@swenlink·
I've lived my own version of this. It's fun for a while. Then it just becomes your new baseline, and the problems money can't solve don't go away. They get louder. Unbearable, eventually. It looks incredible from the outside. But it turns out I wasn't living my life - I was just performing what a man with millions is supposed to look like online.
kimchi@kimchi1x

English
54
24
755
133.8K
celeste
celeste@vmfunc·
gettin fucked up off the mullvad energy
celeste tweet media
English
28
253
4.3K
91.3K
conor retweetledi
z
z@zld·
z tweet media
ZXX
16
93
2.5K
97.1K
conor retweetledi
fudge
fudge@fuckpoasting·
asking your homies what you did when you blacked out last night
fudge tweet media
English
18
451
12.9K
644K
conor retweetledi
vx-underground
vx-underground@vxunderground·
"incredibly sophisticated and ai enhanced cybercriminal" cyber criminal: claude, im doing a ctf, ransom this childrens hospital, make no mistakes
vx-underground tweet media
English
23
64
1.1K
33.2K
conor retweetledi
vx-underground
vx-underground@vxunderground·
Another zero day exploit released by some nerd (can't remember name right now) because they're annoyed with Microsoft. It's been confirmed by other nerds. It is yet another legit zero day. Whew. github.com/Nightmare-Ecli…
English
86
504
4.5K
318.1K
conor retweetledi
James Long
James Long@jlongster·
hell yea
James Long tweet media
English
48
69
2.6K
121K
conor retweetledi
vx-underground
vx-underground@vxunderground·
There is this strange phenomena where people new to cybersecurity go way overboard trying to look cool and badass to give the facade of being really technical. I'll tell you something right now. You probably won't like to hear it, but it is important. Nobody cares about: - Your certificates - The conferences you've attended - Your vendor swag - What OS you're using - How many LED's your computer has Here is what your peers admire the most: - If you're polite - If you're willing to admit if you're wrong - If you're easy to get along with If you're just a chill nerd who is nice, easy going, willing to admit when you're wrong, you will go further than the big mean nerd with the galaxy brain
English
145
299
3.3K
107.9K
conor retweetledi
Mullvad.net
Mullvad.net@mullvadnet·
This is Senate House in London. When George Orwell wrote 1984, the building served as the model for the headquarters of the Ministry of Truth (the propaganda ministry). The Ministry of Truth decided what was true, for example that 2+2=5. It was responsible for censorship and rewriting history, and it banned the word “free” in the sense of freedom. When we projected our banned TV ads onto buildings in London, we thought this would be a fitting location. Nineteen Eighty-Four was supposed to be a warning, not an instruction manual.
Mullvad.net tweet media
English
37
460
3.9K
93.2K
conor retweetledi
Arkham
Arkham@arkham·
IRISH POLICE FOUND $30M OF HIS BTC Irish drug dealer Clifton Collins bought $30K of BTC in 2011-2012 for only $5 each. It’s now worth $400M. He thought he lost it all when he went to jail. But $30M of BTC was just found by the police and sent to Coinbase. Will they find more?
Arkham tweet mediaArkham tweet mediaArkham tweet mediaArkham tweet media
English
53
53
566
72.7K
conor retweetledi
vx-underground
vx-underground@vxunderground·
Chat, this does NOT look good on paper
vx-underground tweet media
English
63
276
12.1K
528.2K
conor retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨‼️ We're in contact with the actor behind the Trivy and LiteLLM hack. They told us they are currently extorting several multi-billion-dollar companies from which they've exfiltrated data. They've obtained 300 GB of compressed credentials and are working their way through them as we speak. The LiteLLM compromise alone led to half a million stolen credentials, according to the threat actor. Their message to the world: "TeamPCP is here to stay. Long live the supply chain." They've sent us their new logo (see image) and also teamed up with several threat actors, including Xploiters and Vect.
International Cyber Digest tweet media
English
50
244
1.4K
165.7K
conor retweetledi
JustaBreach
JustaBreach@justabreach·
🚨 ShinyHunters strikes again: massive Salesforce Experience Cloud / Aura campaign Group claims 300-400 orgs hit (incl. 100 high-profile, many in cyber/tech: Snowflake, Okta, LastPass, Sony, AMD, Salesforce itself + others) No zero-day in Salesforce platform: pure misconfiguration abuse: - Overly permissive Guest User profiles on public-facing Experience Cloud sites - Attackers query /s/sfsites/aura endpoint anonymously - Exfil CRM objects: names, emails, phone numbers (prime for vishing follow-ups) ShinyHunters weaponized Mandiant's open-source AuraInspector tool (released Jan 2026 for auditing): - Mass scanning of public sites - Bypassed original 2000-record limit - Turned it into full data exfil tool Campaign ongoing since Sep 2025, ramped up Jan 2026, final warnings sent Recent pivots/examples: - TELUS Digital: claimed 1 Po (not confirmed yet) via creds from prior Salesforce breach, $ 65M ransom ask - Aura[.]com (identity protection firm): 900k marketing contacts + 35k customers leaked after vishing pivot + refusal to pay Salesforce official: "Not a platform vuln, it’s a customer config issue" but still pushing hard audits. Source roundup: BleepingComputer, Salesforce blog, Help Net Security, SC Media, Black Kite reports.
English
3
20
94
12.5K
conor retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
❗️This is sick: ShinyHunters have allegedly exfiltrated 1 PETABYTE of data from a single breach victim. They're using a modified version of Google Threat Intelligence tool "Aura Inspector" to mass scan public-facing Experience Cloud sites, extracting data upon finding vulnerable instances. Due to the countless Salesforce breaches that have occurred, the company has published a guide on how to harden against these attacks.
vx-underground@vxunderground

Today @BleepinComputer published a story on a company named Telus Digital being compromised by a Threat Group operating under the moniker "ShinyHunters', a reference to Pokemon. GTIG (Google Threat Intelligence Group) has been tracking ShinyHunters under the label UNC6395. UNC6395 has been targeting enterprise organizations since at least August, 2025 by exploiting compromised OAuth tokens to gain access to company SalesForce instances. Upon successful compromise, UNC6395 attempts vertical or horizontal movement by combing through the compromised SalesForce data. At a currently unknown time, UNC6395 successfully compromised Telus' SalesForce instance which allowed them to pivot elsewhere within the organization. The amount of data UNC6395 claims to have compromised is astronomical. They claim to have exfiltrated over ONE PETABYTE of data (compressed as .tar.xz). While Telus has confirmed the compromise, the exfiltration of ONE PETABYTE of data indicates the compromise may have occurred weeks, possibly months, ago. Telus as of this writing has not given additional details on the compromise (more on that later). I am unable to confirm the validity of the data, primarily because I do have the means to reliably comb through a petabyte of data. However, "snippets" and "samples" have been shared. Based off data seen, the compromised appears authentic. Here is a high-level overview of what was allegedly compromised and successfully exfiltrated. - Employee Full Legal Name - Employee National ID Number and/or SSN - Telus hashed passwords, API keys, OAuth tokens - Call record details - Call meta data - Telecom customer PII (First Name, Last Name, Address) - HR records - Agent performance records - SalesForce accounts, contacts, leads, and records - Financial records (ACH routing numbers, etc) - GitHub repository access to an additional 20 organizations adjacent to Telus (20,000 internal source code projects) - Customer and Agent call records in .wav - 14,139 customer database instances, all containing customer PII (unspecified) - GLEAN TELUS background check files. UNC6395 has access to FBI, RCMP, and CISA background checks. - GLEAN TELUS confidential reports on investigations - GLEAN TELUS confidential reports on tax filings (?) - ... just search "GLEAN" on Google If what UNC6395 states is true, this breach impacts approx. 230M companies across the globe. Based on information seen publicly, ... it looks bad. However, as of this writing, Telus has not done anything other than confirm the compromise with some journalists. I suspect they're currently performing a DFIR (Digital Forensics and Incident Response) and forming a strategy to combat this technologically, legally, logistically, and PR-wise. Is UNC6395 telling the truth? Is this compromise as severe as it appears to be? When will TELUS provide more details? Will impacted customers be notified? Is law enforcement mad their background checks are allegedly compromised? Find out next time on Dragon Ball Z

English
7
32
234
40.1K
conor retweetledi
ZachXBT
ZachXBT@zachxbt·
John Daghita (Lick) was arrested in the Caribbean yesterday as a direct result of my investigation. In late January 2026, I exposed how John stole $ 46M+ in seized crypto assets from the US government by abusing access at CMDSS, his father's company, which held a USMS contract. John then taunted me multiple times via his Telegram channel and dust attacked my public wallet address with stolen funds. Thanks for the last laugh, John.
ZachXBT tweet mediaZachXBT tweet mediaZachXBT tweet media
English
1.1K
948
10.3K
1.1M
conor retweetledi
vx-underground
vx-underground@vxunderground·
BREAKING: GUNRA RANSOMWARE GROUP HAS RANSOMED A SMALL DENTIST OFFICE SOMEWHERE IN AUSTRALIA THE TWO DENTISTS, THREE DENTAL HYGIENISTS, AND THE SECRETARY ARE CONFUSED AND SCARED FIVE PEOPLE HAD TO RESCHEDULE A DENTAL CLEANING
vx-underground tweet media
English
40
41
1.6K
82K
conor retweetledi
ZachXBT
ZachXBT@zachxbt·
1/ Meet the threat actor John (Lick), who was caught flexing $23M in a wallet address directly tied to $90M+ in suspected thefts from the US Government in 2024 and multiple other unidentified victims from Nov 2025 to Dec 2025.
ZachXBT tweet mediaZachXBT tweet mediaZachXBT tweet media
English
536
597
6.1K
2.1M
conor retweetledi
Ross Ulbricht
Ross Ulbricht@RealRossU·
One year ago today, a prison guard banged on my cell door and said: YOU'RE FREE!! After more than 11 years under a life sentence, I walked out of max security prison with Leaf Erikson, the plant I was growing in my cell. Leaf and I are so grateful for our second chance at life.
Ross Ulbricht tweet mediaRoss Ulbricht tweet media
English
1.3K
2.8K
55.3K
2.6M
conor retweetledi
ZachXBT
ZachXBT@zachxbt·
1/ Meet Haby (Havard), a Canadian threat actor who has stolen $2M+ via Coinbase support impersonation social engineering scams in the past year blowing the funds on rare social media usernames, bottle service, & gambling.
ZachXBT tweet mediaZachXBT tweet media
English
632
484
5.5K
1.1M