Null
19 posts

Null
@0x7Nulll
Security Researcher Web App Pentesting • C++ Developer Bug Bounty Hunter 0x13 Y.O
kernel เข้าร่วม Mart 2026
64 กำลังติดตาม6 ผู้ติดตาม

New @instagram bug:
Why bro masking emails and phone numbers during password recovery when you can just display them in full?
Account recovery or account discovery?
Meta care to explain?
#Meta #Instagram #CyberSecurity #Privacy


English

🚨 JUST IN: Instagram Hit with 3 Critical Exploits in 2026 🚨
Meta’s platform has been a complete mess this year. Three major security flaws exposed users for days — some still active.
Exploit 1: Meta AI TakeoverHackers simply chatted with Meta’s AI support and got full account access. High-profile accounts (even Obama’s White House IG) were hijacked. ✅ Patched (but damage already done).
Exploit 2: Mass Ban Exploit (Still Working) Just report a target account for “scam & fraud” multiple times and watch it get disabled. No real verification needed.
Exploit 3: Phone & Email Reveal Exploit (Still Working) Sensitive backup phone numbers and emails exposed uncensored. Arabic hackers reportedly scraped millions of accounts already.
The bare minimum Meta could do right now is offer fast unsuspensions + proper support for everyone affected.
Instead, it looks like Mark Zuckerberg is staying silent and hoping it all blows over. 😶
This is unacceptable from a trillion-dollar company.
Tag a friend who got hit. Drop your stories below. #InstagramHack #MetaExposed #InstagramDown #Zuck #AccountHacked #MetaFail




English

Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages.
Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, antv/g2). As these packages are widely used as dependencies, the compromise propagated into downstream libraries like echarts-for-react, impacting a much broader set of applications and continuous integration (CI) environments.
All compromised packages contain a byte-identical, obfuscated credential-stealing payload delivered via a preinstall hook (Bun). The malware targets high-value secrets including:
- GitHub personal access tokens (PATs) and OpenID Connect (OIDC) tokens
- npm / Amazon Web Service (AWS) credentials and Security Token Service (STS) sessions
- Secure Shell (SSH) keys, kubeconfigs, and .env / .npmrc files
- Software-as-a-service (SaaS) tokens (Slack, Stripe, Vault)
Exfiltration occurs over HTTPS with Transport Layer Security (TLS) validation disabled. The payload also abuses stolen OIDC tokens to forge Supply-chain Levels for Software Artifacts (SLSA) provenance and propagate malicious releases, exhibiting worm-like behavior across repositories.
Malicious files distributed through npm packages are detected by Microsoft Defender as Trojan:AIGen/NPMStealer , "Suspicious Node.js process behavior", or “Credential access attempt”, preventing credential theft and malicious post-install execution.
Mitigation:
- Audit dependencies for affected antv and related packages; pin or downgrade to known-good versions (pre-2025-05-18).
- Revoke and rotate exposed credentials (GitHub, npm, cloud tokens, SSH keys).
- Validate integrity of CI pipelines and recent build artifacts.
- Network IOC: Stolen credentials are exfiltrated over HTTPS to t.m-kosche[.]com:443. Block at egress and review network logs for outbound connections.

English

‼️ ShinyHunters has removed Instructure from their Pay or Leak portal.
Seems negotiations are ongoing.

Dark Web Informer@DarkWebInformer
‼️ Users of Instructure are currently logging into Canvas with a ShinyHunters message. Ruthless.
English

this week was absolute hell for zero-days. but is anyone even talking about this?
#Hantavirüs #coronavirus #cyberSecurity
soothsayer@iamasoothsayer
2023: Corona ended 2026: Hantavirus
English
Null รีทวีตแล้ว

Writing shellcode into remote processes via ROP gadgets and existing RWX regions
g3tsyst3m.com/lotp/Living-of…
Research by @G3tSyst3m
#infosec


English
Null รีทวีตแล้ว
Null รีทวีตแล้ว

OMG, what am I seeing here? 26 critical/high vulnerabilities in Google Chrome released at once?
chromereleases.googleblog.com/2026/03/stable…

English
Null รีทวีตแล้ว

Bypass Facebook SSL Version (latest version) Frida JS Script
@NullSecurityX" target="_blank" rel="nofollow noopener">youtube.com/@NullSecurityX
#Bugbounty #CyberSecurity
English

@justabreach @IntelOpsV3 what tf do you need to become a top tier hacker god better than mr robot? lmk so I can make a list of skills needed to learn
English

🚨 LAPSUS$ announces official alliance with HasanBroker
The group (or revival faction) just dropped a PGP-signed message declaring they’re teaming up with HasanBroker and his BreachForums
Stated goal: "erase Indra and his forum", targeting the current BreachForums iteration run by Indra
Stay tuned 👀

English

CVE-2024-7928 is still widely exposed.
FOFA: app="FASTADMIN-框架"
Shodan: http.title:"FastAdmin" country:"CN"
#CVE #BugBounty #CyberSecurity #InfoSec #SecurityResearch
#Pentesting #EthicalHacking #AppSec #WebSecurity #BugBountyHunter

English








