N. Korean, Chinese hackers grow bolder, target crypto, nuclear sites! https://
search.app/UQD23 #NorthKorea #China #CryptoScam #crypto #HackerNews #cybercrime #CyberSecurity #hacker @lexfridman @KirkDBorne @Ronald_vanLoon @erikbryn @antgrasso @sallyeaves @Nicochan33
CYBERSECURITY
-
North Korean Chinese hackers target crypto nuclear sites
By
–
-
Bypassing AI Safety Features: Claude and Codex Dangerous Flags
By
–
I wrote this about my own process a few months ago, but it needs an update now I've started embracing "claude –dangerously-skip-permissions" and "codex –dangerously-bypass-approvals-and-sandbox"
-
SSH Access Control and System Administration Power Dynamics
By
–
“When you cannot ssh into the master, you are the slave” This guy only spits the truth
-
Firebase Storage Misconfiguration Exposes Public Files Database
By
–
No as far as I can tell it was a Firebase storage bucket that was incorrectly configure to serve public files Wouldn't be surprised if there were other database leak bugs though!
-
Coded Apps Data Leaks and Security Risks Discussion
By
–
Sure, I'm ferried we will see all sorts of horrific leaks from one coded apps in the future – but this Tea one isn't an example of that
-

Tea App Data Leak: Vibe Coding Not Responsible, Legacy System Blamed
By
–
I'm seeing a whole lot of posts blaming that egregious Tea app data leak on vibe coding I don't think vibe coding was involved at all: the statement from Tea says the leak involved "a legacy data storage system" from February 2024 – vibe coding wasn't really happening back then
-

Securing MQTT Brokers in Industrial IoT Environments
By
–
Why MQTT Security Matters
One misconfigured broker can put your entire #IIoT environment at risk.
Find out how to secure it: https://
buff.ly/5tVxVgf #sponsored #cirrus_iiot #MQTT @IIoT_World @rtehrani via @fogoros -
Lazarus Group Behind $44M CoinDCX Heist Exploit
By
–
#Lazarus Group Behind $44M #CoinDCX Heist, Experts Find Same Exploit Pattern as #WazirX https://
search.app/ewbXv #wazirxscam #CryptoAlert #CryptoScam #cryptocurrency #cryptoheist #Cybersecurity #cybercrime #hacker @sonu_monika @enilev @Jagersbergknut @TysonLester @chidambara09 -

GPT-5 trace removed, Smart Mode remains
By
–

A trace of GPT-5 has been removed from the code, only Smart Mode remains now (still hidden). GPT-5 access likely has been available to Microsoft employees only.
-

Prompt injection risk everywhere for AI systems
By
–
There are prompt injections everywhere for those with AIs to see