golmatt's profile picture. Auditor de Sistemas, Pentester, Linuxero, Piloto Comercial, Apasionado de la Tecnología, Seguridad, Crypto ,Fotografía y la Aeronáutica ... Viajero incansable..

Matias N. Golini

@golmatt

Auditor de Sistemas, Pentester, Linuxero, Piloto Comercial, Apasionado de la Tecnología, Seguridad, Crypto ,Fotografía y la Aeronáutica ... Viajero incansable..

Matias N. Golini reposted

oh my.. this GeoSpy AI can track your exact location using social media photos


Matias N. Golini reposted

🚨 ALERT: New sophisticated phishing attack targeting crypto influencers on X bypasses 2FA by exploiting X's app authorization system. Attackers use fake Google Calendar links that redirect to malicious apps requesting account access. Do not click unexpected links in DMs and do…

Cointelegraph's tweet image. 🚨 ALERT: New sophisticated phishing attack targeting crypto influencers on X bypasses 2FA by exploiting X's app authorization system. 

Attackers use fake Google Calendar links that redirect to malicious apps requesting account access. Do not click unexpected links in DMs and do…

Matias N. Golini reposted

🚨 Un juego gratuito de Steam estuvo activo durante DOS MESES con un malware que robaba tus contraseñas al abrirlo 🔴 Robó +30.000 dólares a un streamer con cáncer 🔴 Tenía +200 reviews de bots 🔴 Lo recomendó un medio español en Agosto 🔴 Fue eliminado de Steam hoy Domingo tras…

steamcito_ar's tweet image. 🚨 Un juego gratuito de Steam estuvo activo durante DOS MESES con un malware que robaba tus contraseñas al abrirlo

🔴 Robó +30.000 dólares a un streamer con cáncer
🔴 Tenía +200 reviews de bots
🔴 Lo recomendó un medio español en Agosto
🔴 Fue eliminado de Steam hoy Domingo tras…
steamcito_ar's tweet image. 🚨 Un juego gratuito de Steam estuvo activo durante DOS MESES con un malware que robaba tus contraseñas al abrirlo

🔴 Robó +30.000 dólares a un streamer con cáncer
🔴 Tenía +200 reviews de bots
🔴 Lo recomendó un medio español en Agosto
🔴 Fue eliminado de Steam hoy Domingo tras…

Chat, I'm not video game developer, but this file looks strange. Why does this video game contain a .bat file that looks for your browser credentials and crypto wallets?

vxunderground's tweet image. Chat, I'm not video game developer, but this file looks strange. Why does this video game contain a .bat file that looks for your browser credentials and crypto wallets?


Matias N. Golini reposted

IMPORTANT: Trezor firmware and hardware wallets are not affected by the Nx/NPM supply-chain attack. The attack involved malicious JavaScript packages from the public npm registry. This technology is not being used in Trezor firmware at all. As always, remember: ✅ Hardware…


Matias N. Golini reposted

Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒 It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,…

P3b7_'s tweet image. Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒

It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,…

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works…



Matias N. Golini reposted

🚨 ATENCIÓN 🚨 Se descubrió hoy que hay una importante librería de Javascript infectada (con casi mil millones de descargas y presente en casi todas las wallets y sitios web), que modifica on the fly direcciones crypto: o sea que vos pones enviar a A y la reemplaza por B sin que…

PabloSabbatella's tweet image. 🚨 ATENCIÓN 🚨
Se descubrió hoy que hay una importante librería de Javascript infectada (con casi mil millones de descargas y presente en casi todas las wallets y sitios web), que modifica on the fly direcciones crypto: o sea que vos pones enviar a A y la reemplaza por B sin que…

Matias N. Golini reposted

⚠️ Multiple Hikvision Vulnerabilities Let Attackers Execute Malicious Commands Read more: cybersecuritynews.com/multiple-hikvi… Hikvision has disclosed three significant security vulnerabilities affecting multiple versions of its HikCentral product suite that could enable attackers to…

The_Cyber_News's tweet image. ⚠️ Multiple Hikvision Vulnerabilities Let Attackers Execute Malicious Commands 

Read more: cybersecuritynews.com/multiple-hikvi…

Hikvision has disclosed three significant security vulnerabilities affecting multiple versions of its HikCentral product suite that could enable attackers to…

Matias N. Golini reposted

Google will soon require verified developer registration for all Android apps — including those installed outside the Google Play Store — aiming to reduce malware and scams. To simplify the process, an Android Developer Console will be made available. alternativeto.net/news/2025/8/an…

AlternativeTo's tweet image. Google will soon require verified developer registration for all Android apps — including those installed outside the Google Play Store — aiming to reduce malware and scams. To simplify the process, an Android Developer Console will be made available.
alternativeto.net/news/2025/8/an…

Matias N. Golini reposted

Este hombre encontró miles de secretos de usuarios de ChatGPT. Solo tuvo que buscar en Google… elconfidencial.com/tecnologia/202…


Matias N. Golini reposted

🚨 ALERT 🔐 Apple has released a patch for iOS and iPadOS for a Zero day being exploited for highly targeted attacks on what we have been warning for a long time: just by receiving an image in your iPhone or Mac, your device can be FULLY compromised. Update your devices ASAP

PabloSabbatella's tweet image. 🚨 ALERT 🔐
Apple has released a patch for iOS and iPadOS for a Zero day being exploited for highly targeted attacks on what we have been warning for a long time: just by receiving an image in your iPhone or Mac, your device can be FULLY compromised.
Update your devices ASAP
PabloSabbatella's tweet image. 🚨 ALERT 🔐
Apple has released a patch for iOS and iPadOS for a Zero day being exploited for highly targeted attacks on what we have been warning for a long time: just by receiving an image in your iPhone or Mac, your device can be FULLY compromised.
Update your devices ASAP

Matias N. Golini reposted

⚠️ A single click on a fake site can hijack your password manager. Researchers found 11 popular extensions (1Password, LastPass, iCloud & more) vulnerable—putting logins, 2FA codes, and credit cards at risk. 6 vendors still haven’t patched. Protect your PASSWORDS ↓…

TheHackersNews's tweet image. ⚠️ A single click on a fake site can hijack your password manager.

Researchers found 11 popular extensions (1Password, LastPass, iCloud & more) vulnerable—putting logins, 2FA codes, and credit cards at risk.

6 vendors still haven’t patched.

Protect your PASSWORDS ↓…

Matias N. Golini reposted

📝 WhatsApp beta for iOS 25.17.10.70: what's new? WhatsApp is working on a feature to choose a username for phone number privacy, and it will be available in a future update! wabetainfo.com/whatsapp-beta-…

WABetaInfo's tweet image. 📝 WhatsApp beta for iOS 25.17.10.70: what's new?

WhatsApp is working on a feature to choose a username for phone number privacy, and it will be available in a future update!

wabetainfo.com/whatsapp-beta-…

Matias N. Golini reposted

🚨 ALERT: Microsoft has discovered a new trojan, StilachiRAT, targeting cryptocurrency wallets in the Google Chrome browser. The malware attacks 20 different extensions, including MetaMask, Coinbase Wallet, Trust Wallet, OKX Wallet, Bitget Wallet, Phantom, and more.

Cointelegraph's tweet image. 🚨 ALERT: Microsoft has discovered a new trojan, StilachiRAT, targeting cryptocurrency wallets in the Google Chrome browser. 

The malware attacks 20 different extensions, including MetaMask, Coinbase Wallet, Trust Wallet, OKX Wallet, Bitget Wallet, Phantom, and more.

Matias N. Golini reposted

HOLY SHITT, Sesame Labs just dropped CSM (Conversational Speech Model) - Apache 2.0 licensed! 💥 > Trained on 1 MILLION hours of data 🤯 > Contextually aware, emotionally intelligent speech > Voice cloning & watermarking > Ultra fast, real-time synthesis > Based on llama…


Matias N. Golini reposted

⚠️ Warning: Lazarus Group Expanding Targeting in Crypto Industry We've updated our Lazarus blog with new intelligence: threat actors are not only targeting major crypto companies but also their prospective hires. These organizations have been mentioned in logs linked to recent…


Matias N. Golini reposted

Filtración de datos de DeepSeek: 12 000 claves de API y contraseñas activas codificadas expuestas cybersecuritynews.com/deepseek-data-…

elhackernet's tweet image. Filtración de datos de DeepSeek: 12 000 claves de API y contraseñas activas codificadas  expuestas
cybersecuritynews.com/deepseek-data-…
elhackernet's tweet image. Filtración de datos de DeepSeek: 12 000 claves de API y contraseñas activas codificadas  expuestas
cybersecuritynews.com/deepseek-data-…

Matias N. Golini reposted

So TL;DR the safe app frontend was compromised as far back as 19th February. Compromise happened through leaked infra keys via a safe developer's machine. They specifically went after bybit but could have hit any one of you Now after losing $1.5bn can we switch to local apps?

LefterisJP's tweet image. So TL;DR  the safe app frontend was compromised as far back as 19th February.

Compromise happened through leaked infra keys via a safe developer's machine.

They specifically went after bybit but could have hit any one of you

Now after losing $1.5bn can we switch to local apps?

Matias N. Golini reposted

If you are using Safe for any significantly large amount of funds, this is your wake up call to self-host the UI on your own (secured) IT infrastructure, and/or run completely separate secured interface (such as ape-safe)

Damn. Bybit just released their audit report—the compromise was not Bybit, but SAFE's servers. They hot swapped the Gnosis SAFE UI with JS code that ONLY targeted Bybit's cold wallet. Independently confirmed by WaybackMachine snapshots. Lazarus Group is on another level.



Matias N. Golini reposted

Safe always put security first. Including securing its web frontend. It was compromised anyway. We need to add more layers of security like: * making it easy to verify transactions independent of what is shown on the front end * having additional processes to co-sign that also do…


Loading...

Something went wrong.


Something went wrong.