AmmarSpaces
AmmarSpaces@infosec.exchange
<p>I like Information Security, and silly elves. Mostly posting thing I read blending with my view. Or, just my views of the what happened at world in general.</p><p>Shall we go?</p>
Posts
-
View post
Cyber Security is stressful Cyber Security is full of bs Cyber Security is fuckery Cyber Security is hard Cyber Security is hated by the whole dept. We fight insider, govt, criminals, malwares, bugs, and now AI Agent. It's the only world where it never sleep. That's why it's the only fun tech world! #cybersecurity #security
-
View post
So, ShinyHunters just breached FBI and defaced FBI Jobs site. Around 5000 employees data, and allegedly 3TB datas in total managed to be taken. The group said they used unpatched Oracle PeopleSoft zero-day. Sources: @InternationalCyberDigest@infosec.exchange , @BleepingComputer@infosec.exchange and @404mediaco@mastodon.social Video source: vx-underground #cybersecurity #infosec #fbi #databreach #shinyhunters #defaced
-
View post
Team at Calif published a Writeup that demonstrate the first Zero Click Worm that can be spread through WeChat calls they call WeWorm Writeup: https://calif.io/research/weworm Below is their PoC video #cybersecurity #infosec #computerworm #weworm #calif #wechat #vulnerability #vulnerabilityresearch
-
View post
Browser Exploit Surface Model, by Alisa Esage from Zero Day Engineering #cybersecurity #infosec #browser #attacksurface #attacksurfacemapping #vulnerability
-
View post
This post is intended for Indonesian audience only: Tim @safenet baru saja meluncurkan petunjuk apa yang harus dilakukan jika kalian mengalami gangguan jaringan atau terkena aktivitas pemblokiran di ranah digital ketika kalian sedang beraktivitas. @indonesia Guide bisa diakses di bawah: https://drive.proton.me/urls/VECDDE2WV4#JiW2Jhapa71X #infosec #digitalrights #hakdigital #petunjuk #guide #indonesia
-
View post
NightmareEclipse posted this on their X. I think we are now getting a glimpse of the real problem. I hope they are okay moving forward. Addendum 1: Yes, I deliberately not screenshotting the upper part properly. Addendum 2: If you are someone who capable to giving them a support, please give them a support... #cybersecurity #infosec #nightmareEclipse #mentalhealth #mentalhealthmatters
-
View post
RE: https://infosec.exchange/@AmmarSpaces/117250175986726855 To respect the guy decision, I will not post about him using that name anymore.
-
View post
So there&#39;s a rumor that all Kimi AI Staffs arrested by the MSS, regarding recent Anthropic report.
-
View post
Cat cat tv #surveillance #memes #cctv #cat
-
View post
I am copypasting statement from @InternationalCyberDigest. Nightmare Eclipse, the person who has been dropping Windows zero-days, has finally decided to share his story. He&#39;s an ex-Microsoft employee, we (@InternationalCyberDigest ) had dinner together, and I&#39;ve known him and his story for some time. His real name is Abdelhamid Naceri. He&#39;s a very talented and intelligent individual, and he came across as someone who&#39;d be a real professional to work with. &...
-
View post
Even your EV charger didn&#39;t save from CVE. Anyway, I am no expert, but just asking, it possible in the future we can pwn a smart car just by hijacking the EV charger? https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers #cybersecurity #infosec #vulnerability #evcharger #iotsecurity
-
View post
Just a thought, isn&#39;t it sad that hackers (vuln researchers) nowadays need to give their KYC &#39;just&#39; to access an AI model to help them in their job?
-
View post
Le fly is the machine Note: meme not made by meme #memes #technology #fly #neuralnetwork #funny #ihavenomouthandimustscream
-
View post
Call me optimist or anything, but even if ASI is a thing and somehow it become a threat. I believe human can still overcome it. With the caveat, that humans keep studying and not &#39;just let AI do it&#39;, even when ASI become a thing. #opinion #ai
-
View post
Good morning Indonesian taxpayers (including me). Just FYI DJP (Directorate General of Taxes) allegedly breached. The alleged exposed fields include: * Taxpayer Identification Numbers (NPWP) * Names and email addresses * Phone numbers and physical addresses * Passwords * User IDs and account roles * IP addresses * Last-login information * Authentication tokens * Remember-me tokens * Account creation and update timestamps If true, we all fucked. Hahahha Screenshot and info source: DailyDarkWe...
-
View post
Kemnaker (The Ministry of Manpower) leak December 2025. The underground listing alleges tables and exports that include: * Worker / labor-force profile tables (actor-stated tens of millions of rows) * Training-participant and employment-program datasets * Domicile and national-ID (KTP) address tables * Employment social-security–related employee tables (actor-stated) For this one, I have low confidence being real. Because of the data supposed amount which seems too big (1,208,702,746 unique ro...
-
View post
Still fresh, Pertamina (IIndonesian state-owned oil and gas company) fallen victim to Ransomhouse RaaS. Alleged data stolen: Risk analysis records, financial records, maintenance planning documents, pipeline records, refinery planning documents, investigation files, engineering drawings, cyber security incident records, confidential documents, personnel records Source: Hackmanac @indonesia@fedigroups.social #cybersecurity #infosec #pertamina #ransomware #ransomhouse #databreach #indonesia...
-
View post
I need to archive this first (in case it got deleted), I will make another post later after reading through the posts. But if you are @indonesia@fedigroups.social , feel free to read this. Also @safenet@mastodon.social Note: Sorry no alt text until I have a free time to read the whole thing to make a summary. And the screenshot are not by me ok, feds. #indonesia #indonesiaNews #censorship
-
View post
These companies are pure cartel and insanity. People in reply section said "just wait for the bubble to burst". No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore. What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth. #cybersecurity #supplychainsecurity #AI #Apple
-
View post
Now the post will be in English, recently, there is an opinion piece published by a member of Indonesian Air Force, where basically he didn't agree with Hypermiliterization in civil piece at the current administration. Previously, his post are published in 3 media pieces, but all of them are now requested to be taken down by the author because of "personal reason" (yeah, right). The full archived piece can be seen here: https://web.archive.org/web/20260828042633/https://suaranasi...
-
View post
Previously, this post will be in Indonesian. Kalau kalian buka X, atau sosmed lain, mungkin kalian sudah melihat tulisan dari anggota TNI AU yang mengkritisi tentang militerisasi di bidang sipil. Update terbaru, yang bersangkutan meminta tulisannya dihapus karena alasan pribadi (ayolah kita rakyat ga bodoh ya ga). Jadi tulisannya ilang dong? Hehe, tenang, sudah diarsipkan: https://web.archive.org/web/20260828042633/https://suaranasional.com/2026/08/28/hipermiliterisasi-program-sipil/ @indon...
-
View post
If you are in Europe, and you bought Steam's hardware products, you might want to check your e-mail from Steam. There is a 3rd party logistic partner breach (CEVA Logistics) occoured, where your: - Name - Street address, city and postal code - Country - Phone number - Email address linked to the Steam account - Type and price of the hardware ordered Might be exposed. Stay safe out there. #cybersecurity #infosec #databreach #steam #europe #valve #gaming
-
View post
On unrelated post, if you are into cryptography and vtubing, go check out kurenaif on YouTube. In this video, they covered about Isogeny cryptography. It has english subtitle :D (Yeah, I haven't finished the video, but still, sharing is caring right?) https://www.youtube.com/watch?v=JlhSM0sKZXI #cybersecurity #infosec #cryptography #isogenycrypto #vtuber
-
View post
Ok looks like this year DEFCON and Black Hats has tons of interesting talks... But, I want tp wait to cover anything related to that conferences until the talks uploaded to YT...
-
View post
Got this info via @InternationalCyberDigest@infosec.exchange. For a company having "hacker" in their name, this is an insult towards hacking community. If you value the 'hacker' value, DO NOT SUPPORT any form of ID Verification. Fight this shit to oblivion. If you are in only for the money, do not mind YOUR ID handled by 3rd party (meaning you should not call yourself a hacker), then sure, embrace this. https://docs.hackerone.com/en/articles/8399430-id-verification #hackero...
-
View post
RE: https://cyberplace.social/@GossiTheDog/117045200596075081 No, we cannot fucking allow this to let slide. It's already too much 'ugh fine' moment, the scarcity are artificial, not because of any disaster situation. These fucking tech manufacture companies must keep provide the consumer with fair price before AI boom. If they can't or don't obey they must be punished! Hardware scarcity is threat to tech security, threat to security means threat to cyber security. Thre...
-
View post
Reddit rolled 'LLM Powered' AutoMod to automatically detect and delete posts that are not following community rules. I am being neutral in the situation, but false deletion might still happens, because LLMs are still machine, they can't decide nuances yet. https://www.dexerto.com/entertainment/reddit-is-giving-ai-the-power-to-remove-posts-and-comments-3395228/ #cybersecurity #AI #reddit #automod
-
View post
Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP. What should you do? - Check if you are affected, if so, downgrade your library version - Rotate your keys and do 2FA - Search for infected accounts in your s...
-
View post
BREAKING Someone on X selling 'Github Source code for $65.000' . Yeah, I do not know the legitimacy, or either the post author joking (it is only their only tweet, so I think they are 'not joking'). #cybersecurity #infosec #github #leak
-
View post
Reading through Black Hat vendor summary from SecurityWeek. And, ugh... AI AI AI AI AI AI everywhere.. https://www.securityweek.com/black-hat-usa-2026-summary-of-vendor-announcements-part-1/ #cybersecurity #infosec