Загрузка видео...

Не удалось загрузить видео

На главную

TimeVault automates finding information disclosure vulnerabilities by effortlessly filtering sensitive files and uncovering hidden data. Check it out: Team: mohd farzaan @hexsh1dow haq enver #CyberSecurity #BugBounty #OSINT #hackingtools #InfoSec

13,964 просмотров • 1 год назад •via X (Twitter)

Комментарии: 11

Фото профиля AnonKryptiQuz
AnonKryptiQuz1 год назад

If you want to know more about this, check out the video below

Фото профиля HUDI
HUDI1 год назад

🚀 Introducing the free HUDI DataMask Breach Check! 🔍 Quickly find out if your personal data has been compromised in any breaches. Take control of your privacy effortlessly – it’s simple, secure, and entirely free. 🛡🔒 Check now and stay safe: #HUDI #DataPrivacy #BreachCheck #CyberSecurity

Фото профиля F͞a͞h͟ad
F͞a͞h͟ad1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS Impressive effort!

Фото профиля AnonKryptiQuz
AnonKryptiQuz1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS Thanks.

Фото профиля Paradox hunt (N.u)
Paradox hunt (N.u)1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS impressive dude

Фото профиля CNDA
CNDA1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS Will it do .org?

Фото профиля AnonKryptiQuz
AnonKryptiQuz1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS I think you're asking if the tool works on the .org top-level domain. If so, then yes.

Фото профиля baloblack
baloblack1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS Smatching

Фото профиля War observer ☢️
War observer ☢️1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS Can you report this as a bug ?

Фото профиля AnonKryptiQuz
AnonKryptiQuz1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS Yes, you could do that.

Фото профиля CNDA
CNDA1 год назад

@coffinxp7 @hexsh1dow @1hehaq @NahoXSS Anon… I have a piece of script to add to this tool if you want… it’s not as good as straight downloading the 404s…but it’s still helpful. But it’s in bash. Let me know if you want it and where I can send it to you.

Похожие видео

How Health New Zealand (Te Whatu Ora) Buried Whistleblower Barry Young's Protected Disclosure. Barry Young details how he made a protected disclosure to Health New Zealand’s executive leadership team with statistical evidence suggesting serious vaccine safety issues. After extensive review with epidemiologists, doctors, and statisticians, he calculated odds of 100 billion to one against the vaccine not causing the observed signals. The handling of his Protected Disclosure reveals suppression of evidence, which would be potentially serious illegality, at the highest levels of the Ministry of Health. Barry had to raise several OIA (Official Information Act) requests to obtain the evidence that Health New Zealand had indeed received his original Protected Disclosure email, despite the evidence being "buried away in an Accenture Report, which was a Forensics Report." This is essential viewing for anyone who has concerns about government transparency, public health accountability, and Whistleblower Protections in New Zealand and beyond. Transcript: "I gave it to Health New Zealand, that was my protected disclosure... And only after doing a lot of due diligence with a lot of experts and statisticians and doctors who looked at it and I found out in hindsight I'm perfectly allowed to do that under the act to see how and whether that's important, whether to make a protected disclosure. It was all... red flag, red flag, red flag. So yes, I did put all that together, I did some crude analysis back then, getting a lot better at it now. And I just came up with some numbers that was 100 billion to one against the vaccine not causing this. I can't say for sure, I can never say that. And I sent that in an email to the executive leadership team at Health New Zealand. So of course, yeah, yeah, to make them aware of what I was saying and that formed the protected disclosure which was the whole purpose of the act, which is why we're here. Of course, they just ignored that and retaliated. In the police disclosures, I didn't even see a sign of that original email that I sent, they tried to bury it, they tried to withhold it from evidence because it was a protected disclosure. The original ELT email, the only one they did provide as evidence was the email I sent to the MPs, not knowing that that wasn't a protected disclosure. I didn't know the act at the time, but they withheld the one I sent to the executive leadership team. And the only reason that I can think of they did that was to try and avoid saying that it was a protected disclosure. They tried to bury it. I... emailed them, the Crown, the police, where's the email that I sent to the executive team? Oh no, we've sent you everything that we have. So I thought, that's a bit strange. I did send an email. ... I had to resort to writing OIA's to Health New Zealand, which they denied. They said, oh no, we didn't, there's no email sent from you at that time to these people. Your request is denied because it doesn't exist. And I wrote back to them. I said, check again, please. These are the times. These are the dates. And they said, we've gone back and we've done a thorough check and we stand by original decision. The email doesn't exist. So Health New Zealand said twice that email doesn't exist. I found it. The evidence buried away in an Accenture report, which was a forensics report. I said, hang on a minute. There's the email there in that report. Only after that did the police and the Crown reply to me. And lo and behold, there it was. The protected disclosure email... produced nearly a year after I was charged. It should have been the very first thing that they sent and [that] they dealt with. ...Looking at a protected disclosure, the way it's meant to be, they're meant to receive it and acknowledge it and reply to it. They tried to bury it."

Liz Gunn

12,350 просмотров • 12 дней назад

Last year, during tax season. I had 50+ receipts. Some in my email. Some on WhatsApp. Some in my gallery. And a few, I couldn’t even remember where I saved them. What should’ve taken a few hours turned into late nights, frustration, and second-guessing everything. Because the real problem isn’t filing taxes. It’s this: → Collecting documents → Organizing them → Verifying if everything is correct That’s where most people struggle. This year, I tried something different. Instead of chasing files everywhere, I built a simple, clean system using Wondershare PDFelement. And honestly, it changed everything. Here’s how my workflow looked. I started by scanning all my paper receipts directly from my phone using the Receipt Assistant. No manual typing. No guesswork. It automatically extracted details like: • Merchant • Date • Amount • Taxes Everything turned into searchable PDFs instantly. Then came the best part. All files were automatically saved to the cloud. So, I could: → Scan on mobile → Manage on desktop → Access everything, anytime No more “where did I save that?” moments. But what impressed me most. Every extracted detail is traceable. I could click any number and instantly jump back to the exact spot in the original receipt. No more cross-checking line by line. And when it was time to organize everything. • Exported all data into Excel → full expense overview • Merged multiple files into one clean PDF • Edited tax documents directly (no extra tools needed) Before final submission, I used: • AI Assistant → to summarize & cross-check documents • Smart Redact → to hide sensitive information Everything felt controlled, clean, and secure. That’s when it hit me: A good tax system isn’t about working harder. It’s about having a clear, traceable workflow that removes chaos. Suppose your files are still scattered across folders, emails, and screenshots. That is exactly why tax season feels exhausting. Search Wondershare PDFelement and try it free → #wondersharepdfelement #pdfelement #FileWithPDFelement #TaxSeason

Vikas Singh

11,795 просмотров • 3 месяцев назад

🚨 ANTHROPIC JUST REVEALED CLAUDE MYTHOS ABILITIES Anthropic just formally announced "Claude Mythos Preview" and launched "Project Glasswing" to deploy it for cybersecurity defense. The models are unlocking completely new, autonomous behaviors. This isn't about slightly better benchmark scores. This is about what the model can do. Here are the direct quotes from Anthropic’s research team (including Dario) on exactly what Mythos is capable of: • Chaining Exploits: "It has the ability to chain together vulnerabilities... this model is able to create exploits out of three, four, sometimes five vulnerabilities that in sequence give you some kind of very sophisticated end outcome." • The Professional Standard: "The model that we're experimenting with is, by and large, as good as a professional human at identifying bugs." • Unprecedented Autonomy: "It's just generally better at pursuing really long-range tasks that are kind of like the tasks that a human security researcher would do throughout the course of an entire day." The Reality Check: Dario Amodei flat out said: "There's a kind of accelerating exponential... Claude Mythos Preview is a particularly big jump along that point." Because this model has become so capable at identifying zero-days, they are restricting its release to top tech partners to try to patch the world's software before these capabilities leak out. The autonomous researcher era has officially arrived. It’s over 💀

Chris

46,147 просмотров • 3 месяцев назад

A single tweet just vaporized BILLIONS from cybersecurity stocks. CrowdStrike down 8%. Cloudflare down 8.1%. Okta down 9.2%. SailPoint down 9.4%. The Global X Cybersecurity ETF just hit its lowest level since November 2023. What happened? Anthropic dropped Claude Code Security. It scans your entire codebase for vulnerabilities and suggests patches. Sounds boring. Until you read what it actually did: In testing, Claude found over 500 HIGH-SEVERITY BUGS in production open-source codebases. Bugs that had been sitting there for DECADES. Despite years of expert review. Despite fuzzing campaigns. Despite penetration testing. Despite million-dollar security audits. Nobody found them. An AI did. In hours. Here's the terrifying part: Traditional security tools work by pattern matching. They look for known vulnerabilities in a database. Claude doesn't do that. It READS code the way a human security researcher would. Traces data flows. Understands how components interact. Catches logic flaws that rule-based tools can't see. And it just outperformed every cybersecurity tool on the market. Combined. Wall Street figured this out fast. If an AI can find what your $500k/year security team missed... Why do you need the team? If an AI catches bugs that CrowdStrike, Okta, and Cloudflare couldn't... Why are you paying those subscriptions? Barclays came out saying the selloff was "illogical" and Claude "doesn't compete" with these companies. But here's what Barclays missed: It's not about what Claude competes with TODAY. It's about what it replaces TOMORROW. The SaaS apocalypse hit legal software 3 weeks ago. Thomson Reuters dropped 18% in one day. $285 billion wiped from software stocks. Now it's cybersecurity's turn. The pattern is obvious: Every industry that sells "expertise as a service" is about to get repriced. Legal research? Done. Code vulnerability scanning? Done. Compliance checking? Coming soon. Financial analysis? On deck. Companies that spent 20 years building "moats" around specialized knowledge are watching AI swim right over them. CrowdStrike is worth $95 billion. They have 30,000 customers. Claude just found 500 bugs their tools missed. Do the math. The smart money already sees what's happening. The iShares Expanded Tech-Software Sector ETF is down 23% YTD. Heading for its largest quarterly decline since the 2008 financial crisis. Not because software is dying... But because software companies that charge per-seat subscriptions for AI-replicable work are dying. Anthropic just proved that a general-purpose AI can outperform DECADES of specialized cybersecurity infrastructure. In a single product release. While still in "limited research preview." It's not even fully launched yet. What happens when it scales? We're about to find out.

Ricardo

110,899 просмотров • 5 месяцев назад

Man, I absolutely love Bill Burr! Been a huge fan for over 20 years, and it’s been a blessing to watch him evolve. Seeing him work out new material is like getting a master class in comedy. But I have to say, his take on people "doing their own research" about the management of the LA fires is exactly like his take on COVID and masks (which, let's be honest, he got completely wrong). This kind of stance risks alienating his blue-collar, hardworking fanbase. "Trust the experts?" When the LAFD Chief said LA wasn’t prepared due to policy decisions and budget cuts, I’m inclined to take her word for it—it sounds like serious mismanagement. Bill talks about people doing their own research, but when it comes to the LA fires, folks have been diving into the data and uncovering the truth. That information isn’t some hidden secret behind a firewall—it’s out there, accessible to anyone willing to look, and people are putting in the work to piece it together. "Trust the experts" is exactly why mainstream news has lost so much credibility. Bill’s right that there’s a lot of info out there, but that doesn’t mean it’s all perfectly filtered or accurately presented by every so-called "expert." I love Bill, but he really needs to stop insulting people who are trying to figure things out for themselves. The way the LA fires were handled was a disaster—so much so that you have to seriously wonder if it was mismanaged on purpose.

Sam Tripoli

528,222 просмотров • 1 год назад

"I'm not sure that we need the dog whistle at this point. And maybe there are ways to re-create it." ~Nolan "There might be a day when Skywatcher doesn't need to exist." ~Nolan "If I had been running the whole show, nobody would even know what Skywatcher is right now." ~Nolan ~My comments in ( )~ Garry P. Nolan: "We've got a lot of data from multiple alleged sightings, both radar and other kinds of data. First it was about getting the raw-data files all put in one place because some of the data was collected by James (Fowler) before there was, officially, kind of a Skywatcher. "And so, getting that data, getting the instrument names that he used for those, then getting the technical manuals of what the settings might be and how much of that information is collected in the metadata when you're collecting the thing... All of this is just the organization that you need to do before you do anything else. "And then, getting from the companies how it is that they parse their raw data. Because some of these data files are put into...I wouldn't call them encrypted, but they're stacked into a certain kind of file structure - and I've seen the file structure - which is, you can think of it as a giant spreadsheet with headings and numbers for each of the columns and time on the row axis. "And so, you know, we've started looking at some of the data and put it into, let's say, 3D tracking. And it's clear that there are some things about the data that we needed to go back to the vendor who makes the instrument and say, 'Why is this and this and this happening, you know, every few dozen milliseconds?'" (I wonder if some of what they saw in their data, and labelled as anomalous, has maybe turned out to be a sensor artifact?) Nolan: "And so, you know, just getting an answer from these companies, often, when you don't even own the instrument, they're like, 'Well, why should we give you the information about how our data is constructed? How do we know that you're not a competitor?' Right? I mean, and so these are the kinds of things that we then contact somebody who has a behind-the-scenes access to this so that we can, again, it's all of these little steps. "And I'm sure there's somebody who's gonna tweet, 'Well, why don't you just put all the raw data out on the internet?' For exactly the same reason you don't put the raw data from ancient DNA sequencing. Because people will make mistakes about it. And so, if I'm going to be involved, I'm not gonna make any mistakes like that. So I'm sorry if people want stuff early. "I think you know, perhaps, if... Well, if I had been running the whole show, nobody would even know what Skywatcher is right now. We'd just be collecting the data in a fully-stealthed mode. And...but, you know, it's...there's reasons, good reasons, why they wanted some publicity. And, you know, but I don't always get my way." Vinnie - 𝐕𝐢𝐧𝐧𝐢𝐞 𝐀𝐝𝐚𝐦𝐬 𝕏: "Would you say that the data is exciting?" Nolan: "Oh, there's some interesting stuff in there. I mean, frankly, perhaps some of the better data that we have is just a couple of pictures from the ground of the helicopter with something about, you know, 200 feet in front of it. It's a clear blue sky and there's an object right in front of the helicopter. And the people in the helicopter said at the time that they couldn't see anything, even though we could see it from the ground. "But meanwhile, all of their instruments are going haywire. So, there was an effect. So why couldn't they see it? Maybe it was just out of view? Who knows? So it wasn't a lens flare, and it certainly wasn't a seagull. Mick (both laugh)." Vinnie: "Not in the desert anyway." Nolan: "I can't help myself." Vinnie: "I'm all for it. I'm sure Mick would, too. Hopefully. You know, James Fowler, we know he's left and moved on working with a new company. You know, all the best to him. Am I right in saying some of the technology being utilized by Skywatcher was proprietary to him, specifically? Maybe the dog whistle even? Is that still going to be able to be used by Skywatcher? How's that going to look going forward?" Nolan: "Umm, I'm not sure that we need the dog whistle at this point. And maybe there are ways to recreate it. I'm not party to the discussions around that. And so, we'll see where that goes." (That sounds like Fowler is NOT going to allow Skywatcher to use the dog whistle. That's a big disappointment. I mean, if this is really NHI and the dog whistle works 100% of the time, as claimed, then the whole world deserves to know about it.) Nolan: "I mean, James is not like, gone and forgotten. I mean, I could Signal chat him right now. And so he's there to help us. But, you know, my take on things is, you know, James has a life to live and a family to feed, and maybe his focus isn't entirely on UAP. He certainly has an interest in it. And maybe he has, you know, a company to build, and an opportunity that, actually, we all see now in terms of detecting drones. And, you know, if he wants to run a company like that then running around with a bunch of UAPologists might not be to that benefit. "And there might be a day when Skywatcher doesn't need to exist. The whole idea of Skywatcher is to show that something like this can be done, and it can be done in a serious way." (jakebarber claimed that they could BRING DOWN a craft. If that's true, it would change the world. What happened with that? Barber also said, "Who is operating [UAP]? How are they being operated? Where are they coming from? We should be able to answer those questions, probably entirely, in the next 12 months." Time is running out. Does he still stand behind that? Full Barber post with video clip: ) ~ Nolan: "I mean, I would...I, frankly, hope that if UAPDA - Disclosure Act is passed, because then the information that can be allowed to be out can be let out, and the stuff that needs to be kept secret stays secret. Again, I'm not, I would never advocate for a data dump." (I would 100% advocate for a data dump, minus details on anything that can be used as a weapon. Nobody, including the USG or private contractors owns this information. If it's gonna be a slow drip, for decades, then I fully support an Edward Snowden-type of leaker.) Nolan: "And so, you know, call it controlled disclosure, what have you. It needs to be done the proper way. And, you know, if any of the claims are true, there are reasons why you want to be methodical about it." (Who gets to decide what "the proper way" looks like? It seems like we're having more gatekeeping on top of the original gatekeeping. Not good.)

Joe Murgia

32,437 просмотров • 11 месяцев назад

Google just confirmed the first case of hackers using AI to build a zero-day exploit from scratch. An actual zero-day vulnerability that no human had EVER found before, discovered by an AI model, turned into a working weapon, and aimed at a mass exploitation campaign targeting thousands of systems simultaneously. Google's Threat Intelligence Group caught it yesterday and killed the operation before it scaled. But the details of how it worked are genuinely scary: The AI found a flaw in a popular two-factor authentication system that traditional security tools had missed entirely. The vulnerability was a logic error buried deep in the authentication flow where a developer had hard-coded a trust exception years ago. No human security researcher or automated scanner had caught it. The flaw was invisible to EVERY tool the cybersecurity industry has built over the past two decades. But the AI spotted it immediately. Then it wrote a full Python exploit script to weaponize it. Google's analysts could tell the code was AI-generated because it had textbook formatting, educational comments explaining every function, and even a hallucinated severity score that doesn't exist in any real database. The AI literally graded its own attack with a fake rating. So the code had MISTAKES in it. The criminals' implementation was clumsy enough that it probably interfered with the actual deployment. This was the sloppy first attempt by people who are still learning how to use these tools. And it still found a vulnerability that the entire cybersecurity industry missed. Google's chief threat analyst John Hultquist said: "There's a misconception that the AI vulnerability race is imminent. The reality is that it's already begun. For every zero-day we can trace back to AI, there are probably many more out there." But here's where it gets truly insane... This wasn't even a sophisticated operation. North Korea's APT45 hacking unit is sending thousands of repetitive prompts to AI models, recursively analyzing known vulnerabilities and building an entire exploit arsenal that would be physically impossible for human hackers to assemble at the same speed. They're essentially industrializing cyberattacks. A Chinese state-linked group jailbroke Google's own Gemini by simply asking it to "pretend to be a network security expert" and then used that persona to research how to hack TP-Link routers and corporate file transfer systems. Another Chinese group deployed autonomous AI agents that probed a Japanese tech firm with minimal human oversight, deciding on their own which tools to use and pivoting between targets based on internal reasoning. And then there's PROMPTSPY, an Android backdoor that calls Google's Gemini API to read your phone screen in real time, navigate your interface autonomously, capture your biometric data, replay your lock screen PIN, and block you from uninstalling it by placing an invisible overlay over the uninstall button. It literally OPERATES your phone using commercial AI tools anyone can access. Everyone spent the last 3 years arguing about whether AI would take people's jobs. Meanwhile AI is making every password, every firewall, and every two-factor authentication system on Earth fundamentally less secure. The entire $190 billion cybersecurity industry was built on one assumption: that finding vulnerabilities is hard and requires deep expertise. But AI just removed that assumption from the equation. And the scariest part is that Google said the criminals made errors this time. The implementation was rough and the campaign probably didn't fully work. These were amateurs, now imagine what professionals are able to do. There's a reason Sam Altman predicted an inevitable massive cyberattack THIS year. What do you think?

Ricardo

50,564 просмотров • 2 месяцев назад