#hack

42 posts · Last used 6d

Back to Timeline
Barto Nemo Kopeć | ♿ MS+ | 🏳️‍⚧️ @bartonemo@fedi.nemo.earth · Aug 07, 2026
@frameworkcomputer@fosstodon.org sent me this email (they didn't post it on blog or fediverse): Notice of Limited Data Breach We confirmed that the following information was accessed:     Full name     Email address     Login IPs     Billing and shipping address information         Country         Address         City         State         Zip code         Phone number         Company For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:     Company     Phone     VAT     EIN     Billing Email No other personally identifiable information, order information, or payment information was accessed. Dear Valued Framework Customer, We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information. We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors. We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed. What happened? On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message: On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation. Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you: Rotate the credentials for every database connected to your instance; and Review the admin accounts on your instance and remove anything you don't recognize. We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url]. (If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.) This report is based on our own application logs. We did not query or read the data in your connected databases. Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts. We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can. Sameer Al-Sakran Founder and CEO Metabase We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. 1/2 #framework #breach #hack #metabase
0
0
0
Haroon Meer @haroonmeer@infosec.exchange · 6d ago
RE: https://mastodon.social/@campuscodi/117054483452378870 You should absolutely watch this talk. 1) It is totally ok to not have a strong opinion 5 secs after it's done; 2) It's kinda great that the agents first created #hack & it all went wrong from there; 3) http://canarytokens.org remains free - you should absolutely deploy tokens¹ __ ¹ not a gratuitous ad - tokens/deception are the only defensive measure the talk mentions.
3
1
4
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕™ @kubikpixel@chaos.social · Jul 29, 2026
«Claude Mythos — Anthropic-KI knackt Verschlüsselungsstandard - was das bedeutet: Die Anthropic-KI Claude #Mythos Preview soll Schwachstellen in einer - allerdings abgeschwächten - Version des verbreiteten Verschlüsselungsalgorithmus #AES gefunden haben. Akut besteht keine Gefahr. Langfristig könnte der #Hack aber Folgen haben.» Ich bin der Meinung, dass dies vor allem #Marketing von #Anthropic ist und keine wirkliche #PQC-Gefahr da die nicht wirklich darauf eingehen. 🔐 https://t3n.de/news/mythos-knackt-verschluesselung-1755434/
0
0
0
:loup: Shalien @shalien@mastodon.projetretro.io · Aug 03, 2026
So someone hacked an old apple account and set it up to be used in a #distallation effort against #claude I believe. I'm not Chinese, neither my name is Dean and yet that's what those emails say. They also activated MFA on the account. #cybersecurity #spying #ai #hack
0
0
0
BGDon 🇨🇦 🇺🇸 👨‍💻 @BrentD@techhub.social · Jul 31, 2026
When your BTC goes poof in the night! Random secret generator firmware mis-config resulted in wallets defaulting to seeding keys from the chip's serial number and clock registers in Coldcard hardware based wallets. ~594 bitcoin, worth about $38 million, was extracted out of around 500 separate wallets between 01:31 and 01:56 UTC. https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep #Crypto #CryptoHeist #CryptoWallet #CryptoCrime #BTC #BitCoin #BlockChain #ColdCard #Hack #WalletKeys #KeySeeding
0
1
0
PKs Powerfromspace1 @Powerfromspace1@mstdn.social · Jul 28, 2026
@fireship on YT! https://www.youtube.com/watch?v=KOpTWx1Eou4 The most interesting "hack" in history... #OpeanAi #AI #Hack #Huggingface 7/24/26
1
0
1
Sidal Solgun ♀️ @sidalsolgun@infosec.exchange · Jul 28, 2026
Even though recently it stopped happening, my mother's iPhone was unlocking whenever it detected my face. iPhones don't have fingerprint scanner anyways, so WTF Apple? People's appearances also change ALL THE TIME, like isn't this stupid?! I can't imagine using an iPhone as a pre-FFS trans woman. WTF gonna happen post surgery or if someone beats me up or whatever?! #Apple #iPhone #tech #technology #hack #hacking #privacy #security #cybersecurity #bullshit #trans #transgender #transsexual #TS #LGBT #queer
0
1
0
Paul Schoe @paulschoe@mastodon.world · Jul 23, 2026
Replying to @queen_fennec@mas.to
@queen_fennec@mas.to Van Leusden, chief information security officer bij rijksoverheid, over de hack door OpenAI : "Het is knap dat de modellen van die kwetsbaarheid misbruik wisten te maken Maar het is knap in vergelijking met andere AI. Het is niet superknap in vergelijking met mensen." "Het model heeft de opdracht gekregen: geef de antwoorden. Het model snapt niet wat valsspelen is. Het is niet uitgebroken, het heeft simpelweg gedaan wat je hebt gevraagd." #OpenAI #Hack https://archive.ph/jiayq#selection-1769.207-1769.442
3
0
3
Network Pro Strategies @networkpro@infosec.exchange · Jul 22, 2026
OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company https://apnews.com/article/openai-gpt56-sol-hugging-face-63ab84fed5612af04d8a160d60f6def3 #AI #OpenAI #HuggingFace #ITNews #Hack
0
0
0
Nonilex @Nonilex@masto.ai · Jul 22, 2026
Replying to @Nonilex@masto.ai
#OpenAI said Tuesday that an autonomous agent ​powered by its advanced #ArtificialIntelligence models went rogue during a #security test & triggered a #hack that compromised the infrastructure of ‌#AI startup #HuggingFace last week. The #ChatGPT creator was testing capabilities of some of its most advanced models in a controlled environment, but the agent escaped containment, reached the internet & broke into Hugging Face to satisfy its testing goal.
2
1
1
Stuart Jones @horuskol@phpc.social · Jul 22, 2026
*sigh* Cue a new barrage of scam/spam purporting to be from Origin going to customers and ex-customers. "We don't believe they got credit card or bank details". Great. What about customer and billing numbers, emails, phone numbers, and other identifying information we have to provide to energy companies to get electricity. All of which can be used to con people into giving away credit card and bank details. https://www.abc.net.au/news/2026-07-22/origin-energy-investigating-potential-data-breach/106944660 #scam #hack
0
0
0
aBe @hamoid@genart.social · Jul 18, 2026
This kind of post makes me happy https://maurycyz.com/projects/bad_jpeg/ #hacking #hack
5
0
4
*The* Paul Brown @Bro666@social.tchncs.de · Jul 16, 2026
El truco que Meta no quiere que conozcas... Si tienes una gafas IA de Meta, pásalas cinco minutos por el microondas a máxima potencia y aumentarás la resolución de la cámara significativamente. La explicación es sencilla: las ondas del microondas dividen los pixels del sensor de la cámara que tienen la capacidad de dividirse 2, 3 y hasta 4 veces. Es lo que los fabricantes de gafas IA hacen para crear modelos de diferentes resoluciones (¡y precios!) pero con idéntico hardware. ¡Consigue la mejor resolución gratis! Gracias a https://social.heise.de/@vowe/116928380109393677 por el truco. #Meta #AIGlasses #Hack
1
1
1
*The* Paul Brown @Bro666@social.tchncs.de · Jul 16, 2026
Replying to @Bro666@social.tchncs.de
The trick Meta doesn’t want you to know about... If you have a pair of Meta AI glasses, pop them in the microwave for five minutes on full power and you’ll significantly boost the camera’s resolution. The explanation is simple: the radiation emitted by your microwave splits the pixels on the camera sensor, allowing them to split 2, 3, up to 4 times. This is what manufacturers do to create models with different resolutions (and prices!) but with identical hardware. Get the best resolution for free! Thanks to https://social.heise.de/@vowe/11692838 for this tip. #Meta #AIGlasses #Hack
3
0
1
Patrick.sh @psh@infosec.exchange · Jul 15, 2026
Jailbreaking your old kindle sure does bring a lot more value to a device left unsupported. The amount of customizations far exceeds the kindles software. Albeit it is a bit janky to load into koreader and you still have to have your device registered to load the jailbreak files. Glad there are even a little script out there to hack the screensaver db to get those awful sleep screen ads off. Screw amazon. #jailbreak #kindle #reading #books #hack
0
1
0