vx-underground – Telegram
vx-underground
45.5K subscribers
3.91K photos
414 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Media is too big
VIEW IN TELEGRAM
this is the type of music people listen to when they're extorting companies and laundering money on the internet
🤣77💯22🤓7😎6🔥3😢32👏1
Hello,

All APT samples and papers have been moved to "./Archive/Old APT Collection". It is available for bulk download.

A directory will be created which will house ALL malware samples listed in malware analysis papers. This is a long term project which may years to complete.
🔥3311😍3😢1
I know absolutely nothing about AI or LLMs. But, the boys and I decided to goof around (as is tradition) and built an LLM using all the papers we've collected.

1. It's really cool
2. It's super slow and super resource intensive
3. It likes to hallucinate because we fed it super unstructured data (see image 2)
4. No idea what to do with this. This would require insane infrastructure, significant time investment, and ???, to not make this ghetto.
57😁13👏11🔥5🫡4🤣2😱1😢1
Probably not that big a deal tbh no one uses NPM
🤣73👍9😱54😢1🎉1
vx-underground
Probably not that big a deal tbh no one uses NPM
Also, don't see any facts to back up these claims. Could be some dork going bananas over nothing.

Guess we'll wait and see
27🥰7🔥5😢1
> do largest supply chain attack in history
> potentially infect millions of apps
> doesnt do the thing good
> makes $0 from compromise

I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of apps and you FUMBLE IT
🤣15010😁6😢1
vx-underground
> do largest supply chain attack in history > potentially infect millions of apps > doesnt do the thing good > makes $0 from compromise I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of…
Look... If you had... one shot... or one opportunity...
To seize everything you ever wanted... one moment...
Would you capture it? Or just let it slip?

...

*slips*
🤣123💯116😇2🤝2😁1😢1
BREAKING

LARGEST SUPPLY CHAIN ATTACK IN HISTORY PULLS OFF MASSIVE CRYPTO HEIST

ATTACKS STEAL $20.05 OF ETH. ENTIRE WORLD CRUMBLING
🤣117🔥8🥰4😁4❤‍🔥21🎉1
Drama unfolding in Brazil right now where it was discovered a popular and trending Lesbian Dating App was vibe coded

Turns out all you need to do is a GET request and you can pull everything
🤣93😢11😎42👏1🤔1
vx-underground
Photo
Posting from mobile. Im not sure why my phone wrote "Lesbian Dating App" like it was an official noscript or acronym or something (LDA)....

Lolwtf
🤣53😁74😢1🤓1
vx-underground
Photo
I recommend following this thread (comments and quoted retweets) to follow the drama and shit storm.

STOP THE SLOP. NO MORE AI VIBE CODED APPS.

https://x.com/acgfbr/status/1965116645556600882
🤣3410🤔5💯3👍1😢1
If people keep pushing AI vibe coded slop imagine how much money us cybersecurity nerds are gonna make

Chat, it's going to be a very prosperous couple of decades
👏91💯209😁9❤‍🔥2🔥2😢1
> TeaApp
> Used Firebase
> Bucket not configured correctly

> Brazil dating app (Sapphos)
> Used Firebase
> Bucket not configured correctly

It's literally free money
84😁38🔥8😇5😢2
The drama in Brazil continues.

Sapphos, a lesbian-focused dating app, was compromised as a result of a poorly developed API with users speculating it was vibe coded.

Sapphos, after discovering the situation unfolding on social media, quickly put out a message regarding the compromise.

Sapphos begins by implying the compromise was a targeted campaign by men. However, while it was compromised by men, it does not appear (based on social media conversations and threads) to be compromised as a result of disdain toward women. Rather, the compromise was the result of nerds being nerds and messing with the application.

The message concludes with the statement that no documentation was exfiltrated. However, based on photo evidence on social media, this is incontrovertibly false. Photos and logs have been presented which proves this is false.

tl;dr Brazil mentioned?
🤣8712🎉8😢1