Cyber stuff || Chess || CTF player team @fr334aksmini

Joined June 2020
33 Photos and videos
Jun 13
Do you remember when you joined X? I do! #MyXAnniversary
10
New banger from @thefosi: HTTP/2 framing WAF bypasses across six proxies. Use it wisely while you can. :p lab.ctbb.show/research/h2-WA…
2
21
194
8,287
pr0rat retweeted
You may know him as Churchill, but his journey had many names before the legend arrived. We are now HFCB; our new name reflects where we’ve been, who we’ve become and the great we continue to create. #GreatHasANewName #HFCB @MwalimChurchill
4
5
205
pr0rat retweeted
Our Great Name is HFCB! Our new chapter unifies our Group & all its subsidiaries under a single, cohesive & forward looking brand; offering fully integrated financial services & property solutions. #MyGreatName #HFCB
8
14
457
pr0rat retweeted
🚨 Supply chain attack on the Laravel Lang organization: 700 historical versions across multiple community-maintained Laravel Lang packages were compromised with an RCE backdoor, including: laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes Laravel-Lang/actions The payload targets cloud creds, CI/CD secrets, Kubernetes tokens, Vault, browser data, password managers, SSH keys, and more.
56
279
1,159
750,704
pr0rat retweeted
🚨 The "π™ΌπšŽπšπšŠπš•πš˜πšπš˜πš—" Campaign is live... 𝟻,𝟽𝟷𝟾 malicious commits to 𝟻,𝟻𝟼𝟷 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected π™Άπš’πšπ™·πšžπš‹ π™°πšŒπšπš’πš˜πš—πšœ workflows containing πš‹πšŠπšœπšŽπŸΌπŸΊ-πšŽπš—πšŒπš˜πšπšŽπš bash payloads that exfiltrate: - CI secrets, - cloud credentials - SSH keys - OIDC tokens - source code secrets Check your repo / Technical details: safedep.io/megalodon-mass-gi…
25
165
604
226,344
pr0rat retweeted
A cat.py backdoor is mentioned in both @Microsoft's npm report and @step_security's report (Nx Console VS Code compromise) I've uploaded it and other components to @objective_see's public Mac malware collection: github.com/objective-see/Mal… (pw:infect3d)
5
20
86
14,769
May 21
Me trying to manually penetrate systems after 2 years of letting AI agents do all my testing… #AI #CyberSecurity #bugbounty
3
89
May 21
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. krebsonsecurity.com/2026/05/…
2
41
May 21
Microsoft has released mitigations addressing the β€œYellowKey” BitLocker bypass vulnerability (CVE-2026-45585), which impacted Windows 11 version 26H1, 24H2, 25H2 for x64 Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation). thehackernews.com/2026/05/mi…
1
193
pr0rat retweeted
Just saw a "@OepnAI " (mistyped OpenAI) share a ClickFix lure under the guise of testing an image for AI.
39
89
760
78,793
May 21
WPScan 4.0.0 is out - great to see continued innovation in WordPress security. Solid tool for vulnerability scanning WordPress environments and staying ahead of threats. πŸ” #WPScan #WordPress #CyberSecurity
1
2
84
pr0rat retweeted
May 20
software engineering in 2026: - your package manager is compromised - your cloud provider blocks your account - github itself is hacked software is solved
160
1,000
12,144
414,063
pr0rat retweeted
May 19
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
1,667
5,303
25,405
13,830,367
pr0rat retweeted
🚨 BREAKING: Xabi Alonso has accepted to become Chelsea next manager, HERE WE GO! πŸ”΅πŸ”œ The agreement is set to be completed. #CFC prepare official announcement for the upcoming days, but Xabi said YES. πŸ’£
11,782
57,586
459,713
32,632,545
pr0rat retweeted
we're so cooked
78
1,161
22,560
512,825
pr0rat retweeted
The only thing faster than his draw is the cameraman's heart rate. He's standing way too close for comfort.
287
1,049
14,165
2,189,482
pr0rat retweeted
the scary part is not AI generating code it is AI understanding decades old systems well enough to find vulnerabilities humans missed
β€ΌοΈπŸš¨ MAJOR IMPACT: AI just found an 18-year-old NGINX critical remote code execution vulnerability. It has been disclosed on GitHub including PoC code. - Affects NGINX 0.6.27 through 1.30.0 - Triggered via the rewrite and set directives in config - Update NGINX ASAP - NGINX is a widely used HTTP web server, be sure to check its prevalence in other products
Community note
The exploit requires ASLR to be disabled, which is not default on practically all systems. This is seen in the exploit code. Source github.com/depthfirstdisc…
1
13
1,751
pr0rat retweeted
Anthropic’s Mythos just hacked macOS helped researchers find a macOS kernel exploit Apple is reviewing it now. The AI found the vulnerability. Wrote the exploit. Delivered a 55-page report to Apple in Cupertino. We are so cooked
100
127
3,363
338,667