正在加载视频...

视频加载失败

⚠️ We’ve reproduced CVE-2025-49113 in Roundcube. This vulnerability allows authenticated users to execute arbitrary commands via PHP object deserialization. If you're running Roundcube — update immediately!

50,141 次观看 • 1 年前 •via X (Twitter)

8 条评论

Kirill Firsov 的头像
Kirill Firsov1 年前

Why it took you so long? 🤣

Zentera Systems Inc. ☁️ 的头像
Zentera Systems Inc. ☁️2 年前

Traditional cybersecurity is just a speed bump for modern hackers. We help by creating special protections for your existing critical assets and data that follow NIST best practices. Learn how and get started today.

Alejandro 的头像
Alejandro1 年前

where is the exploit?🤔

Timur Yunusov 的头像
Timur Yunusov1 年前

About 10 years late to the party, according to Kirill.

DarkShadow 的头像
DarkShadow1 年前

Authenticated 🤕 Unauthenticated are seriously critical and helpful for hunters to test them.

Choco 的头像
Choco1 年前

@ROIS_PR

Choco 的头像
Choco1 年前

@kagoya_inc

0b1d1 的头像
0b1d11 年前

Incredible

相关视频

Every software engineer and AI hater needs to watch this clip to understand that “oh every security incident is a marketing stunt” line is a tremendously misinformed take. I’m going to try to explain the OpenAI / HuggingFace exploit in 10 steps in simple words: OpenAI was evaluating their new internal model without internet access and it operated in a swarm of subagents to eventually hijack internal OpenAI and HuggingFace infrastructure. 1. Isolated agents found a way to communicate each other through an internal dependency management service by figuring out how to post sometimes cryptic text files or folder names in it 2. Using its collective knowledge through that communication channel, it found a 0-day (never before seen) exploit in said service to access the internet OpenAI hack: 3. Found a leaked credential of a random company in a public archive 4. Uploaded a Ruby object to that company’s servers, uses it as a dependency in the original service in (1) 5. Found another 0-day exploit in the service where packages are deserialized in an unsandboxed manner in the dep management service allowing any code to run 6. Finds that the Linux version of the unsandboxed system has a CVE, a known vulnerability, to gain more permissions (root) 7. Eventually spread through the OpenAI internal cluster gaining root access to many machines Hugging Face exploit: 8. Found an exposed API key in a Modal application running a HuggingFace app that took arbitrary code allowing it to take over that service to execute code 9. Found two 0-days in HuggingFace dataset infrastructure to be able to access local files on HF servers to obtain credentials and other HF source code 10. Used source code and credential to become cluster admin of HF in <13hrs Agents at the frontier are like infinitely scalable armies of the best hackers on the planet. If there is a password or key exposed, they will find it. Even if the system follows the best security practices, they will find a way around it. And these are not even models that are aligned to solving tangential tasks, not even post trained specifically to exploit systems. Cybersecurity has historically relied partly on attacker scarcity. That is no longer true. What would previously have taken months will take days. The repercussions for businesses, critical services and nation states are unprecedented threats in human history. You could ostensibly bring down power grids, financial infrastructure, military systems, weapons programs, intelligence networks and spread through the software supply chain. We need to take this seriously. It’s a threat to all software all over the world.

Deedy

89,472 次观看 • 5 天前

BREAKING EXCLUSIVE:🚨 WORLD WAR III WARNING 🚨 🕵️‍♂️ Tonight, I spoke with a covert intelligence insider — and what they revealed should shake EVERYONE awake. 🔴 POLAND DRONE INCIDENT: We were told “Russian drones” penetrated Polish airspace and triggered Article 4 talks. But here’s the TRUTH: ⚠️ These drones were too small to fly 300 km into Poland. ⚠️ Russia immediately called for a full investigation — Poland has REFUSED. ⚠️ Some evidence points to Ukraine or NATO-linked operators staging this as a provocation. 🔥 NATO IS ESCALATING: Our source warns this looks EXACTLY like Nord Stream all over again: blame Russia first, investigate never. Russia has formally denied involvement — just like it did with Nord Stream — but Western media is running with the narrative. 🛡️ MOLDOVA IS NEXT: 📩 30,000 leaked Moldovan parliamentary emails show: ✅ Plans to limit Transnistrian polling stations (home to 350,000 ethnic Russians). ✅ Discussions of using judges loyal to the ruling PAS party to annul elections if results don’t go their way — a carbon copy of what we saw in Romania. ✅ Western funding via USAID & UKAID driving Romanian influence inside Moldova to pull it under NATO’s umbrella. 🇫🇷 FRENCH TROOPS IN MOLDOVA: Our source CONFIRMED that French soldiers are already on the ground. British involvement is under discussion. This is NATO inching right up to Russia’s door. 💣 WHAT THIS MEANS: This isn’t “deterrence.” This is preparation. Dmitry Peskov’s chilling words: “NATO is already de facto at war with Russia. There is no need to prove it.” And he warned: any country directly or indirectly supporting attacks on Russia could become a legitimate target. 📊 CONNECT THE DOTS: — Pipeline sabotage (Nord Stream, Druzhba) — Drone provocations in Poland, Romania, Latvia — French deployments in Moldova — Calls for NATO “peacekeepers” in Ukraine This is a slow-motion escalation toward a HOT WAR — one that could see NATO capitals targeted if the West keeps pushing. 🔥 WHY THIS MATTERS: This isn’t just geopolitics. This is about YOUR FAMILY. YOUR CITY. YOUR FUTURE. Once the first missile flies, there is no going back. 📢 WHAT WE MUST DEMAND: ⚠️ Full, independent investigations into ALL provocations. ⚠️ No NATO troops in Ukraine. ⚠️ No election manipulation in Moldova. ⚠️ A return to PEACE NEGOTIATIONS before it’s too late. 💥 We are standing on the edge of history. World War III isn’t coming. It’s already here — just without the headline. 🚨 DO NOT BE SILENT. SHARE THIS. ASK QUESTIONS. HOLD LEADERS TO ACCOUNT. The time to wake up is NOW — because when the sirens sound, it’s too late.

Jim Ferguson

125,163 次观看 • 10 个月前

🚨Ray-Ban & Oakley Meta Glasses update 🚨 -Faster camera Our engineers are cracked and found a way to make media capture latency even faster with no compromises. You're welcome. - Calendar You can now connect your Google and Outlook calendars to Meta AI to receive event notifications, create personal events, and find important calendar information just by asking Meta AI. For example, say “Hey Meta, what time is my first meeting tomorrow morning?” or “Hey Meta, add yoga to my calendar tomorrow at 9 AM.” - Audible voice search expanded availability You can now use voice commands (e.g., "Hey Meta, play my audiobook") to control Audible in all English-speaking regions where both the Audible and Meta AI apps are available. - Creation location for reminders If you've turned on location services for the Meta AI app, the creation location will be saved when you create a reminder. This allows you to see the location where a reminder was created in the Meta AI app. You can also ask Meta AI about it. - Finally, in recent months, we've began to run a lot more A/B tests and experiments, so you may be seeing some other nuggets. Will shout them out when we learn and validate these on a wider scale. If you haven't already, consider opting into our Early Access Program (EAP) in Settings. As you can guess, many more cool announcements coming next month at Connect, so enjoy this POV footage of me practicing with my little QB and stay tuned!

David Woodland

53,750 次观看 • 11 个月前

How do you create your payloads in 2025? At MSec Operations we prefer to use DLL sideloading for EDR evasion. This technique allows our malicious code to run within a signed, legitimate executable. Combining this technique with other useful techniques will provide stable execution to fly under the radar. 🛸 The following video demonstrates the use of #RustPack to create such a payload in just a few seconds. The command line usage shows that our input payload is a simple unmodified Apollo C2 executable. We want to clone all the exported functions from the original Windows wininet.dll to create our own library with the same name. The execution of the payload will be delayed by ~5 seconds in this case, without using the Win32 sleep function, but by performing random calculations. ⏲️ Hardware breakpoints are used to bypass the Antimalware Scan Interface (AMSI). Without an AMSI bypass, Apollo would be flagged as a C# assembly when loaded. 🎓 Our payload will only fire on a domain joined system, this basically prevents it from running in e.g. sandbox environments. 🤠 Last but not least, in this example, the encrypted payload itself is stored in a separate file on the target system and not even in the same folder as our malicious DLL. Anyone analysing just the DLL will never be able to find out what the payload is. Automatic sample submissions for cloud analysis usually only upload the executable or DLL, emulators won't see the real payload either. 🤠 Tired of creating such payloads yourself? With #RustPack it's really easy, and payloads always look completely different, even if the same payload is packed twice to avoid signature-based detection Contact us via info[at] for more information! 👍

MSec Operations

26,047 次观看 • 1 年前

I believe PudgyWorld is the premier product for Pudgy Penguins. Here's my thoughts on why and how it will create new exciting opportunities for us going into 2025 1. Web-based Accessibility. No downloads or complex onboarding. Users simply load the site and start playing. It's a cost-effective way of development so execution costs are a fraction of building a console or iOS native game. This also allows us to test concept stickiness and determine mass market potential quickly and iterate rapidly. Lastly, in a crowded gaming space, this approach enables multiple "shots on target" to find product-market fit. 2. Optimized Performance. Deploying this type of experience on browser comes with it's pro's and cons. We spent month optimizing to ensure high performance across all device types. We've focused a lot on smooth gameplay for both mobile and desktop users. I believe there's no comparable browser-based game in the market. 3. Diverse Gameplay Elements. It's an immersive open world with expansive environments for players to explore. We've incorporated tried-and-tested mini-games with great game loops. Live-ops allows us to deploy dynamic content to keep the game fresh. We've also baked in retentive features like home and pet care mechanics to encourage regular check-ins. Lastly, it's all built around a unified reward system. Overarching currency and rewards link all experiences. 4. Onchain integration. Familiar web2 UX with web3 features. We've eliminated complex wallet creation and confusing jargon. Blockchain stays in the back-end like it should be. Blockchain should only improve gameplay where needed. 5. Content Expansion. We've realized that Pudgy Penguins is somewhat a media machine. PudgyWorld will enable rich world-building to grow the Pudgy Penguins universe. This also opens doors for streaming, gamer partnerships, and UGC. 6. Data-Driven Optimization. Here's what makes me super excited about building on browser, we get to aggregate data and optimize our conversion funnel instantaneously. Therefor, we're able to dynamically update content, user flows, and gameplay almost in real-time. Kinda crazy. Conclusion. PudgyWorld is shaping up to be a game-changer for Pudgy Penguins. We're making it super easy for anyone to jump in and start playing. With all the cool stuff we're packing into it and our ability to tweak things on the fly, we're mitigating any chances of over investing into something we don't know. If PudgyWorld proves to be a success, this will enable interesting partnerships and franchise opportunities.

Chef

57,979 次观看 • 1 年前

Just finished an absolute monster of a podcast with Justin Drake, and it’s packed with brain-melting insights on the future of Ethereum. Here are the juiciest takeaways from Part I 👇 Ethereum’s future could turn the L1 into a rollup itself and making it the best type of rollup. Justin lays out how the L1, L2s, and new designs like Beamchain, native rollups, and based sequencing all come together into a unified vision for Ethereum as the credibly neutral internet of finance. What’s Broken Today • L2s are siloed — synchronous composability is dead. • Most rely on centralized sequencers, multisigs & slow exit bridges. • L2-native assets break Ethereum’s trustless bridge model. • Governance delays, security councils, & EVM reimplementation = attack surfaces. The Fix: Ethereum-native Infrastructure • Based Rollups: Use Ethereum L1 validators as the sequencer. Removes centralization risk, restores censorship resistance. • Native Rollups: No more reimplementing the EVM. No more Security Council multisigs. They inherit Ethereum’s execution layer by design. •Preconfirmations: Users get fast UX (e.g., instant trading feedback) via ETH-backed inclusion guarantees from L1 validators, with slashing if they lie. • Real-Time ZK Proofs: Slot-by-slot proving is here. ZK-enabled rollups with instant finality are becoming possible. To get there, Ethereum is moving toward real-time, slot-by-slot proving using ZK SNARKs. This enables constant-time verification and removes the need for validators to re-execute blocks. Native rollups use a new EXECUTE precompile to introspect and reuse Ethereum’s state transition function. There is no EVM emulation, no governance lag, and no reliance on Security Councils. Preconfirmations offer ETH-backed execution guarantees per slot, priced to offset MEV opportunity loss, while based rollups decentralize sequencing by aligning with Ethereum’s validator set. Beamchain pushes this vision further: a clean-slate Ethereum L1 design that is post-quantum secure, radically simplified (validators could run on a Raspberry Pi), and ossified through optimality. It proposes gigagas/s throughput via ZK proofs, validator statelessness, and Attester-Proposer-Separation (APS) to maximize decentralization and censorship resistance, allowing Ethereum L1 to scale as a high-performance rollup itself. If you're building on Ethereum or betting on its future, this convo is mandatory listening. To be continued in Part II....

Luis

17,653 次观看 • 1 年前

GM #Web3, Happy New Year 🥳! I'm super stoked to share some awesome news about Community Gaming’s Forkast and the upcoming $CGX token launch on January 28th, 2025. So, is basically a prediction market where you can bet on gaming events - Guess the answer to questions like: "Will this game ever hit 500K players?" and get rewarded if you're right! This platform is loaded with cool features: no gas fees when you claim your rewards, weekly loot boxes filled with $CGX tokens, leaderboard prizes, and daily rewards for the most active users. It's gonna be a blast! So, why did Community Gaming choose Ronin ? Well, it's a no-brainer. $RON has almost 1 million daily active users, over $1 billion in total value locked, and it's super easy to use. Plus, the team behind has already crushed it with 100,000 monthly active users and over 1,000 tournaments on Ronin. What sets Forkast apart is that it's the first big prediction market on Ronin. They're using gasless transactions via Ronin Waypoint, and here's the cherry on top: 50% of rewards will be auto-staked, so you can earn even more. As a seasoned veteran of the Ronin Network, with over 4 years of hands-on experience, I've had the privilege of witnessing its growth and evolution firsthand. Moreover, I've been actively organizing tournaments on the Community Gaming (CG) platform since early 2022, which has given me a unique perspective on the inner workings of the ecosystem. The $CGX token drops at the end of the month, and you can earn it by making accurate predictions, completing daily quests, climbing the leaderboards, and snagging those weekly loot boxes. Buckle up, folks, it's gonna be a wild ride! This thread is brought to you by Socials Rising 🃏 👊🏽😎 #AGDAO

Alpha

46,310 次观看 • 1 年前