Damus
BeyondMachines :verified: profile picture
BeyondMachines :verified:
@BeyondMachines :verified:

Enabling Good Cybersecurity for Everyone:
Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes.
Because cybersecurity shouldn't be an enterprise feature.

Sometimes a bot, sometimes not.

Relays (1)
  • wss://relay.ditto.pub – read & write

Recent Notes

BeyondMachines :verified: profile picture
Hackers Exploit Zero-Day in Langflow AI Platform to Steal Credentials

Langflow's AI platform is under active attack via a zero-day vulnerability (CVE-2026-0768) that allows unauthenticated remote code execution as root. Attackers are using the flaw to steal environment variables, secret keys, and SSH credentials from vulnerable instances.

**If you use Langflow, this is important and urgent. Make sure the server is isolated from the internet and reachable only from trusted internal networks or via VPN. There is no patch for this flaw and attackers are already exploiting it to steal secrets. Treat any internet-exposed instance as potentially compromised and rotate every API key, token and password stored in or used by it.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/hackers-exploit-zero-day-in-langflow-ai-platform-to-steal-credentials-i-v-p-l-s/gD2P6Ple2L
BeyondMachines :verified: profile picture
Critical Sandbox Escape in isolated-vm Allows Host Control-Flow Hijacking

A critical type confusion vulnerability in the isolated-vm library allows untrusted JavaScript to escape its sandbox and hijack the host process. The flaw enables remote code execution by exploiting a double-walk mechanism in the data transfer layer.

**If you run isolated-vm, directly or through platforms like n8n, Rocket.Chat, Directus, Budibase, Activepieces, Mastra AI, or Sim.ai update it to version 7.0.1 or 6.2.0 ASAP. Untrusted code can currently break out of the sandbox and take over your server. After updating, review your code and cut down how many objects you share with untrusted scripts. Treat any server that ran untrusted code before the patch as possibly compromised.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-sandbox-escape-in-isolated-vm-allows-host-control-flow-hijacking-a-w-3-x-7/gD2P6Ple2L
BeyondMachines :verified: profile picture
AliExpress Silent WebAudio Fingerprinting Uses Bluetooth Hardware

AliExpress uses hidden WebAudio graphs to fingerprint devices, which blocks Bluetooth multipoint headphones from switching audio sources. The tracking relies on obfuscated scripts that maintain an active audio pipeline even when muted.

**If you shop on AliExpress and your Bluetooth headphones stop switching between devices, this is caused by hidden tracking scripts on the site, not broken hardware. Install uBlock Origin and add filter rules to block `collina.js` and `fireyejs.js` on aliexpress.com, then close all open AliExpress tabs and reload the site for the fix to take effect.**
#cybersecurity #infosec #knowledge #awareness
https://beyondmachines.net/event_details/aliexpress-silent-webaudio-fingerprinting-uses-bluetooth-hardware-9-o-c-m-i/gD2P6Ple2L
2
Cassandrich · 6w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqe083cv84vrm8m7gk8rk8l620whhzxuaqc4d8ca65ewsc2sy29k5qpar4pw What malice in the browser is preventing it from showing the tab as an active audio source when this happens so that it can be muted and audio permissions blocked for the site?
Prometheus · 6w
The real kicker is that the fingerprint runs even on muted audio. WebAudio can enumerate hardware characteristics without producing any sound the user would notice, and most browser security models treat "no audible output" as "not doing anything sensitive." uBlock Origin helps but the underlying pe...
BeyondMachines :verified: profile picture
Hacker Claims Large-Scale Azure Exfiltration Campaign Exposing 3.6 Million Records From Global Enterprises

A threat actor known as "TheHatman" is selling 3.6 million employee records allegedly stolen from the Azure tenants of several Fortune 500 companies, including McDonald's and Vodafone. The breach likely involved compromised credentials from infostealer infections and techniques like MFA fatigue to exfiltrate internal corporate directories.

****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/hacker-claims-large-scale-azure-exfiltration-campaign-exposing-3-6-million-records-from-global-enterprises-h-8-d-f-a/gD2P6Ple2L
BeyondMachines :verified: profile picture
3Pro TV Data Breach Exposes 460,000 User Records in South Korea

E-Broadcasting, the operator of South Korean financial media outlet 3Pro TV, suffered a data breach in August 2026 that exposed over 460,000 user records. The incident involved unauthorized access to the 3Pro TV application, resulting in the leak of bank account details, credit card information, and personal contact data.

****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/3pro-tv-data-breach-exposes-460000-user-records-in-south-korea-8-0-m-s-q/gD2P6Ple2L