_operations6_ Profile Banner
operations6 Profile
operations6

@_operations6_

Followers
1K
Following
10K
Media
544
Statuses
4K

Joined June 2015
Don't wanna be here? Send us removal request.
@smica83
Szabolcs Schmidt
3 days
In Hungary somebody picked a simple #guloader in a 7ZIP archive and put it in a TXT with base64. 🤷🏻‍♂️ 'doc0012020020250212.exe' seen from Poland and Hungary @abuse_ch https://t.co/BYQn7R7dEE IP: 178.218.164(.)110:443 (Croatia) @_operations6_
1
2
16
@joe4security
Joe Security
8 days
Joe Reverser automatically dissects a suspicious email: EML ➡️ extract doc attachment ➡️ create img ➡️ describe img ➡️ extracts QR URL ➡️ browse with web browser ➡️ describe img ➡️ read DOM ➡️ threat intel ➡️ detect phishing 🔥
3
5
18
@CharlieEriksen
Charlie Eriksen
17 days
Across all the 425 compromised packages so far, they have a total of 132 million monthly downloads. Damn.
0
1
3
@CharlieEriksen
Charlie Eriksen
17 days
. @posthog Also got compromised by Shai Hulud: @posthog/hedgehog-mode @posthog/nuxt @posthog/piscina @posthog/plugin-server @posthog/rrdom @posthog/rrweb @posthog/rrweb-player @posthog/rrweb-record @posthog/rrweb-replay @posthog/rrweb-snapshot @posthog/siphash
1
1
3
@akshay_pachaar
Akshay 🚀
1 month
XBOW raised $117M to build AI hacking agents. Now someone just open-sourced it for FREE. Strix deploys autonomous AI agents that act like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proof-of-concepts. Why it matters:
27
202
1K
@UK_Daniel_Card
mRr3b00t
2 months
wow..... you have to be pwn3d really hard to have attestation letters to show you 'aren't totally compromised' etc. (this is linked from the F5 press release thing so it's clearly PUBLIC despite being marked otherwise)
5
17
121
@_operations6_
operations6
2 months
G_Dropper_BRICKSTEAL 95a207976912b920d43894d88cb488fc04ec187d785b3dac533e1790fd4ea4e2 e6fff77afe636fc6e8486a4da400718cee3109688efb8490484ee7c53f46423c aa73901f4c28c4e90d957f5e45cd3f394ea333a873a23e807855396e6be91c51 01a81d7a4101144835c40dabc075c943384092f808b8f98dd62c53198fa1b517
0
0
2
@lukOlejnik
Lukasz Olejnik
3 months
Cyberattack on Jaguar Land Rover results in a prolonged production shutdown. 25% of suppliers have already taken steps to pause production and temporarily lay off workers. The attack has now forced a complete halt until October 1st, costing the company over $1.36 billion in lost
25
126
540
@JonBruner
Jon Bruner
3 months
@Samsung @lumafield @Reddit @Delta We’ve detailed all of our findings in our new Battery Quality Report, which you can download for free right here: https://t.co/Xj6Jg2I2Tk You can't just take an online distributor's word for the quality of batteries; you need to look inside them yourself!
Tweet card summary image
lumafield.com
Download Lumafield’s Battery Quality Report on 18650 lithium-ion cells: CT-based metrics, defect rates, and supplier guidance to reduce risk.
3
3
96
@AlanRMacLeod
Alan MacLeod
3 months
[Thread] 3 of the 6 largest VPN companies are owned and operated by an Israeli company, founded and led by "former" Israeli spies? Is your VPN affected? My investigation reveals all: https://t.co/UyeZOyL9hV
Tweet card summary image
mintpressnews.com
A new report uncovers the troubling ties between top VPN services like ExpressVPN and the Israeli security state, raising alarms about how much control Israel’s Unit 8200 has over your online privacy.
85
2K
5K
@vxunderground
vx-underground
3 months
DAWG. They social engineered the United States judicial system (???), reset someone's password by pretending to be helpdesk, and LOOKED THEMSELVES UP
24
71
748
@TheHackersNews
The Hacker News
3 months
⚠️ A new ransomware is here → HybridPetya. It doesn’t just lock your files — it can bypass Secure Boot on modern PCs, sneak into UEFI, and encrypt your entire system.Victims see a fake CHKDSK screen before being hit with a $1,000 Bitcoin demand. The scariest part? Researchers
14
144
434
@geerlingguy
Jeff Geerling
3 months
I was thinking Apple was having their Windows 8 moment with the horrible UI baked into Sequoia... but no, this is worse than that. It's like they didn't even test the UI on actual Macs or with human beings using them. Team stay-on-Sequoia here...
323
188
4K
@cyb3rops
Florian Roth ⚡️
3 months
Imagine getting access to CI tokens across dev orgs - and blowing it because you didn’t pay $9 to https://t.co/OrOhg4aI4Z The attack didn’t fail because we stopped it - it failed because they used a free https://t.co/OrOhg4aI4Z account and hit the quota #NPM #SupplyChain
18
67
340
@0xzak
zak.eth
3 months
🚨 I was just targeted in a sophisticated phishing attempt that almost got me. But I got the scammer on a live call (video recording below), strung him along, and trolled him with Kim Jong Un gay porn while dissecting his $3k/month malware kit. Buckle up, this gets wild. 🧵👇
200
244
1K
@vxunderground
vx-underground
3 months
WORLDSTAR
25
31
800
@SocketSecurity
Socket
3 months
🚨 BREAKING: The DuckDB npm account was compromised. Malicious versions of duckdb, duckdb-wasm, and more were published early this morning with the same wallet-drainer malware seen in yesterday’s supply-chain attack. Check your dependencies! https://t.co/i6ke5F3mWW #NodeJS
Tweet card summary image
socket.dev
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
6
43
91