[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1775205281211574.png (765 KB, 1373x675)
765 KB PNG
I don't even know what to say
https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330
>>
>>108861061
not clicking that, retarded bait thread
>>
>>108861061
zion dons america
>>
File: queenmaeveMKI.png (768 KB, 1059x777)
768 KB PNG
Secret Management is the most difficult aspect of information security.
>>
Sharif don't like it
Hash the password
Hash the password
>>
>>108861170
kek
>>
>>108861061
more indian excellence, what else is new?

theyll hire 85 iq indians, chinese spies, criminals, and women before they dare hire somebody that would be effective at their job
>>
>>108861170
I know you're making a joke, but hashing them wouldn't have done shit in this scenario.
>>
>>108861149
>Secret Management is the most difficult aspect of information security.
All HSM all the time, summary execution for anyone trying to do a quick hack to avoid it.
>>
File: 56a15c7d4cbc5.image_80.jpg (60 KB, 1024x538)
60 KB JPG
>>108862993
You're not joking.

https://www.zerohedge.com/political/ex-con-hacker-twins-fired-proceed-wipe-out-96-government-databases-minutes

>February 2025, twin brothers Muneeb and Sohaib Akhter turned a routine job termination into one of the most brazen insider sabotage incidents in recent U.S. government history. Just minutes after being fired from Opexus - a Washington, D.C.-area contractor that provides critical case-management software to more than 45 federal agencies - the brothers allegedly launched a rapid digital assault that deleted approximately 96 government databases containing sensitive FOIA records, investigative files, and taxpayer data.
>
>What made the case especially shocking was the brothers' prior history: both had served prison time for hacking federal systems a decade earlier.
>
>In 2015, while working as contractors, they pleaded guilty to conspiracy to commit wire fraud, conspiracy to access protected computers without authorization, and related charges. Their crimes involved hacking into U.S. State Department systems and a private company, stealing personal data on coworkers, acquaintances, and even a federal investigator.
>
>Muneeb received a 39-month prison sentence; Sohaib received 24 months. Both served their time and were released.
>
>The company conducted standard background checks covering roughly seven years - which missed the 2015 convictions. Opexus later admitted that "additional diligence should have been applied" and that the individuals responsible for hiring the twins are no longer with the company.
>
>Unbeknownst to Opexus at the time of termination, the brothers had been abusing their access for weeks. Muneeb had collected approximately 5,400 usernames and passwords from the company's network and built custom scripts to test them against external sites (including Marriott and DocuSign). He successfully logged into accounts and, in some cases, used victims' airline miles.
>>
>>108864331
>On February 18, 2025, the FDIC flagged Sohaib's prior conviction during a background check for a potential new role at the FDIC Office of Inspector General. Opexus fired both brothers during a remote Microsoft Teams/HR meeting that ended around 4:50-4:55 p.m.
>
>The offboarding was flawed: Muneeb's account remained active. ARS Technica has the timeline:
>
> At 4:56 pm, Muneeb accessed a US government database that his company maintained. He "issued commands to prevent other users from connecting or making changes to the database, and then issued a command to delete the database," the government said.
>
> At 4:58 pm, he wiped out a Department of Homeland Security database using the command "DROP DATABASE dhsproddb."
>
> At 4:59 pm, he asked an AI tool, "How do i clear system logs from SQL servers after deleting databases?" He later asked, "How do you clear all event and application logs from Microsoft windows server 2012?"
>
> In the space of a single hour, Muneeb deleted around 96 databases with US government information. He downloaded 1,805 files belonging to the EEOC and stashed them on a USB drive, then grabbed federal tax information for at least 450 people.
>
>The brothers discussed the attack in real time. Sohaib observed Muneeb "cleaning out their database backups." They even queried an AI tool on how to clear SQL server logs and Windows event logs. They later reinstalled the operating systems on their company laptops to destroy evidence.
>>
>>108864337
>Massive extra data haul (1.2 million lines): Muneeb didn’t just steal ~5,400 usernames/passwords from Opexus. He also possessed a separate file containing ~1.2 million lines of full names, email addresses, phone numbers, physical addresses, and password hashes. This was stored across his personal laptop, Android phone, external hard drive, and cloud accounts.
>
>The credential abuse went on for 10 months after they were fired: The database deletions happened on Feb 18, 2025, but Muneeb kept actively using the stolen credentials from May 2025 until his arrest on December 3, 2025. He wrote custom Python scripts (one literally named marriott_checker.py), ran credential-stuffing attacks on hotels, airlines, and banks, and successfully logged into hundreds of victims’ accounts.
>
>Sophisticated account takeovers with his own domains: He didn’t just log in - he changed victims’ recovery email addresses on airline, hotel, and bank accounts to addresses he controlled. This let him lock the real owners out and keep using the accounts.
>
>Real-time blackmail brainstorming during the deletion rampage: At ~5:12 p.m. on Feb 18 - while Muneeb was still deleting databases - the brothers literally discussed blackmailing Opexus. Sohaib said something to the effect of: “you shoulda had a kill script, like, blackmailing them for some money…” Muneeb shot it down, replying that it would be obvious proof of guilt. They also argued about whether to contact customers.
>
>During the same conversation, Sohaib said: “We also gotta clean stuff up from the other house, man.” This strongly implies they had evidence or stolen data at a second location.
>
>Muneeb fled with a government-issued PIV card: When Muneeb drove to Texas on Feb 24, 2025, he took his personal laptop, phone, and a Personal Identity Verification (PIV) card issued by a U.S. government agency. (PIV cards are the high-security smart cards federal employees/contractors use for system access.)
>>
>>108861170
and lock the taskbar
>>
File: Ban the Box.jpg (250 KB, 1467x400)
250 KB JPG
>>108864331
Remember, the "Ban the Box" movement is intended to make it easy for criminals to continue to victimize the public by banning the ability to find out about past criminal convictions. It is also part of why companies freak out over employment gaps since many of them no longer can do criminal background checks, so it is assumed employment gaps are due to being incarcerated.
>>
>>108861061
The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.

Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories.

“Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email. “I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices.”

One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. According to Caturegli, those systems included one called “LZ-DSO,” which appears short for “Landing Zone DevSecOps,” the agency’s secure code development environment.

hire jeets get poo
>>
>>108862993
>more indian excellence, what else is new?
>theyll hire 85 iq indians, chinese spies, criminals, and women before they dare hire somebody that would be effective at their job
/thread
>>
>>108861061
muh open sourse saar!
>>
>>108861074
honestly while i am not satisfied with his performance as president im completely satisfied with his performance in converting anti isreali leftists into right winger nazi chuds.
>>
>>108864592
too bad le alt rite is zogged to the core, I'm not satisfied with retards retarding
>>
File: N.png (30 KB, 638x480)
30 KB PNG
>>108864613
>le alt right
not a thing retard.
just like woke right, your dogshit will never take off among the actual people we represent.
>>
>>108864644
>not a thing retard
cool dellusions retardo
>>
>Since the repository was created in November of last year
yes, very nice. very meritocratic hiring policies these days.
>>
>>108864331
>hacks your accounts
>deletes your data
>uses your airline miles
>refuses to elaborate
>...
>gets out of jail in 24 months
kek based
>>
>>108864331
>>108864337
>>108864344
absolutely based
>>
>>108861074
TDS
>>
>>108864644
You're like those delusional boomers who claim nazis or qanon aren't republican voters. Stop being a bitch.
>>
Trump did that
>>
> One of the exposed files, titled ‘importantAWStokens,’ included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — ‘AWS-Workspace-Firefox-Passwords.csv’
same vibe
>>
>>108865177
Pedo prick suckers in the current year, probably from israel or india
>>
>>108867111
https://en.wikipedia.org/wiki/2018_Hawaii_false_missile_alert
>>
>>108861073
deport cisa
>>
>CHATGPT SAAR HOW TO SETUP SINGLE CLICK DEPLOYMENT SERVICE BEST GITHUB SETUP SERVICE PERFECT FOR DEPLOYMENT
>>
>>108861061
what are the chances it was an H1B visa holder?
>>
>>108861061
How come Biden was more competent than trump?
>>
>>108864331
>Muneeb and Sohaib Akhter
American fetish for letting gaijin in and pretending they are one of them will be their undoing
Foreign spies abuse this loophole constantly
>>
>>108867877
because Biden had a lifetime of service and experience in government work, while Trump was a conman and failed businessman turned reality TV start starred as a successful businessman
>>
>>108865196
He's right Americano, it doesn't exist
>>
>>108864344
Smartest indians I have ever seen
>>
>>108867933
Muneeb and Sohaib are national heroes to the American public. Doing the needful. Tax is theft.
>>
gorgeous defense bhaabhabhiat for immediate lgtm
>>
>>108861061
>Wow, we just lost all the Epstein files randomly due to some hacker!

Actually already happened before you ask. Need to find a new country since Miggers have us at gun point if we start voting against them. It's not that they are incompetent, they are doing this intentionally and are regulating themselves.
>>
>>108861061
You don't have to say anything. You should listen, that's what everyone with the private key did.
>>
https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
jfc
>>
>>108864524
employment gaps are due to severe autism and my family being able and willing to support my neet lifestyle for that long.
I can't say that on my resume cos they'll just be like
>"well, anon, if your parents are that rich, you don't really need this opportunity, so we'll give it to an indian instead"
my parents aren't even that rich, I'm just low maintenance..
>>
>>108864524
It's actually intended to lump people like >>108868413 together with criminals and drug addicts. People who won't go along with the the social engineer's program for any reason won't be allowed to participate.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.