注册并分享邀请链接,可获得视频播放与邀请奖励。

与「Mali」相关的搜索结果

Mali 贴吧
一个关键词就是一个贴吧,路径全站唯一。
创建贴吧
用户
未找到
包含 Mali 的内容
Impact: Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
显示更多
🚨SlowMist TI Alert🚨 We first reached out to the team privately to responsibly disclose the issue before making any public statement. 💸 @ether_fi Loss: ~15.45 ETH 🔍 Root Cause: `AtomicQueue.solve()` lacks access control on the caller-supplied `solver` — there is no `solver == msg.sender` check, nor any signature, registration, or consent verification. The attacker first created a maliciously crafted `AtomicRequest` using the `updateAtomicRequest()` function, then forced a victim address to act as the `solver`. AtomicQueue subsequently called `finishSolve` on the victim and executed `want.transferFrom(solver, users[i], assetsToUser)`, abusing the victim's pre-existing ERC-20 allowance to drain funds. 📌 Attacker: `0xa5cc6e490bce9185fa47b421f2eac677a83b64ea` 📌 Vulnerable Contract (AtomicQueue): `0xd45884b592e316eb816199615a95c182f75dea07` Powered by Tx:
显示更多
🚨 Threat Intelligence | The StealC Info-Stealing Chain Behind the Qwen Impersonation Repository SlowMist Security Team identified a #GitHub# repository impersonating local quantized weights for Qwen 3.8 27B. A real Q4_K_M 27B package should exceed 16 GB. The asset delivered was only 487 KB — no GGUF weights, just three files: Application.cmd, a renamed LuaJIT interpreter, and an obfuscated Lua script disguised as cert.txt. The official #Qwen# project was not compromised. The repo kept the look of a normal offline model project, while the malicious ZIP sat in assets/. After deobfuscation, the script collects host data, takes a screenshot, and POSTs them to C2. When the hardcoded server fails, it reads a fallback C2 from a Polygon contract via eth_call, so operators can rotate infrastructure with a single on-chain transaction. Preserved C2 responses then delivered an inner payload we attribute to #StealC#, targeting: 🔹 Browser logins, cookies, and history — including a Chrome App-Bound Encryption bypass 🔹 Email, WinSCP, and Steam credentials 🔹 Wallet-related files and extension data, dispatched by server-side tasks MistEye reconstructed the multi-stage chain and compared 29 similar ZIPs across 23 repositories using the same Lua delivery stack. Between two collection dates, repositories, filenames, the outer PE, and the AES key had already rotated. A 27B model that downloads in 487 KB is not a model. Inspect asset size and unpack downloaded packages before running them. Read the full analysis 👇
显示更多
When Gabriel Martinelli sent Ngolo Kante back to Mali. My boy will be missed.
0
179
682
272
转发到社区
Welcome Havenex. Series A is underway and closing soon, already applied for all required licenses (even more than required). DM me if interested to invest, note that allocation is already quite packed. After extensive discussions with regulators, central bank governors, Financial Market Authority leadership, banks, family offices, exchanges, wallet providers and custodians, my mission became very clear: Build the most transparent, safest, institutional-grade, fully regulated exchange possible, with continuous, verifiable proofs of solvency. Not just web3. Havenex is not trying to become another Coinbase, Binance, Bybit or Kraken. The focus is different: infra that allows financial institutions to offer digital and traditional financial assets to their customers, while meeting the standards they expect around regulation, custody, security and transparency. My principles are simple: 100% multi-chain. Verifiable custody. Continuous solvency proofs. Multi-sig by default. Quantum-safe keys. Hardware 2FA wallets. Confidential and RWA assets wherever regulation allows. Unique self-custody and key-loss protection mechanisms. Some of the best engineers and experts in cryptography, exchanges and privacy-preserving technology are joining the effort. Havenex will use Sui tech wherever it makes sense, but it will also integrate the best primitives, assets and bridges from other ecosystems. I'm personally helping Havenex as an advisor, although it was my idea. Mysten Labs and Sui remain my focus, nothing changes there. Chief & Hacker team Officer, as always, innovating at daily basis :) As all of you know since my Satoshi days, my goal has always been bigger: help crypto meet regulation without sacrificing ownership, transparency or security, while protecting users against malicious and shady activity and giving the best ecosystems room to thrive. We cannot keep accepting another FTX or Mt. Gox as the cost of doing business, nor the silly, insane bugs driven by LLMs lately. Havenex intends to set a different standard. The most transparent effort in regulatory-friendly crypto. You have my signature.
显示更多
0
38
225
43
转发到社区
LATEST: 🚨 Security firm Socket discovered 40 malicious Firefox extensions impersonating crypto wallets and Web3 apps in order to steal wallet secrets or credentials.
0
25
58
9
转发到社区
The malicious claim that American Jews are inviting violence against themselves is dangerous and antisemitic. There is zero justification for threats against the safety of our Jewish brothers and sisters at a moment of rising hate. We will fight the cancer of antisemitism with the fierce urgency of now.
显示更多
0
4.1K
6.8K
992
转发到社区
CORRECTION: We previously stated that Omeed Malik is funding Tucker Carlson. That statement was false. In October 2023, 1789 Capital - not Mr. Malik personally -led a seed-stage investment in Last Country, Inc., the company that operates the Tucker Carlson Network. Tucker Carlson and Neil Patel bought out all outside investors, including 1789 Capital, in 2025. Neither Mr. Malik nor 1789 Capital has funded Tucker Carlson or his company at any time since. We did not intend to suggest, and we do not contend, that Mr. Malik bears responsibility for Mr. Carlson’s statements or that he exercises any influence of that kind over any public official. We regret the error.
显示更多
My investigation on the GTA 6 Leaker is done and I have emailed all the evidence to TAKE2 and Rockstar Games legal team As much as I wanted and loved to actually reveal who we are dealing with here, full identity and all, I believe that would be doxxing. Since the way I got to this guy was through a mix of OSINT and some people familiar with the matter via TG, I don’t want anyone to get into trouble, so for now I’ll leave out personal details and how I obtained the information One of the stronger findings links to what appears to be this guy’s personal bank account, the bank is located in Europe. It’s obviously not out of the question that the bank account in question might be stolen, but given the circumstances and some other correlations I saw, I believe we have him Going forward, I’ll refer to him as Leeker With the data I have provided to T2, I believe it will make their job easier when cooperating with law enforcement and help pin down the people involved (it’s not just one). Given the nature of the data I found, revealing it publicly could give the guys time to cover their tracks or alter evidence But I don’t want to leave people hanging so I’ll share some stuff below and answer as much as I can in the comments without it being damaging Stuff I have learned that can be shared: -> The leeker is actually a threat actor who has previous malicious activity under a different alias It also seems that there is genuine hatred toward this guy from the people around him. Much of my current information comes from his peers snitching after my first post -> This leak was apparently due to a breach or an insider. Nature of how is still unknown to me, But I’ve received two different stories about this so I'll share them anyway: 1. One story I got is that leeker bought a backdoor access or some sort from someone 2. Another person told me this is somewhat related to some incident inside Rockstar a while ago Keep in mind it’s pretty common for these crypto bros to boast and lie about their “gains” to each other, so I honestly don’t know which to believe here -> Not related at all to the ‘Mafia 808’ group -> I haven’t heard anything about Rockstar India being hacked unlike some other people are claiming -> This build we are seeing here is apparently from a year ago (as confirmed in ResetEra forums), but the theft I believe happened in April 2026 and the leeker has been preparing since then -> From what I can tell, and as I explained in one of the earlier posts, I don’t think they possess a live build. Most likely pre-recorded footage, but this is just my assumption The voting thing they did initially was to make people want to get the coin so the market cap can grow I highly recommend staying away from the coin. This is a literal pump and dump, don't buy into their "Fighting for gamers" bullshit. I won’t be surprised if they at some point start threatening to leak the story unless people donate to them in the poll. Even if that happens, don’t do it That’s all I can responsibly share right now. Questions that don’t risk the investigation or the people involved are welcome in the replies
显示更多
0
1.5K
8K
442
转发到社区
We resolved the vulnerability upon discovery and released an update on August 11. Please ensure your Rabby extension is up to date. The mobile app is unaffected. The conditions required to trigger this vulnerability are extremely limited: 1/ The wallet must be connected to a malicious website. 2/ The user must have manually set their auto-lock timer to specifically 10 minutes (all other timer settings are completely unaffected). No exploits have been detected in the wild.
显示更多