Apacalpa's Avatar

Apacalpa

@apacalpa

Turning bad ideas into worse inventions. I overcomplicate the simplest problems for your entertainment. https://youtube.com/@apacalpa

23
Followers
55
Following
29
Posts
24.11.2024
Joined
Posts Following

Latest posts by Apacalpa @apacalpa

10/10

The lesson? Even billion-dollar companies can overlook BASIC security hygiene:

Protect your dev environments

Secure critical infrastructure

Vet your third-party providers

Otherwise, congratsβ€”you've just funded North Korea.

09.03.2025 16:41 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

9/10

Experts point to North Korea’s Lazarus Group as the likely culprits. Yep, Bybit’s crypto stash might now fund a little a small country...

09.03.2025 16:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

8/10

Bybit has been scrambling, promising tighter security. Safe{Wallet} is investigating how a single compromised developer environment brought down their entire security.

09.03.2025 16:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

7/10

Forensic analysts discovered the truth hidden in the Chrome cacheβ€”because even hackers forget browser cache exists... sometimes.

09.03.2025 16:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

6/10

And just TWO MINUTES after pulling off the heist, the attackers wiped all evidence, updating Safe{Wallet}’s AWS bucket with clean code. Talk about efficiency.

09.03.2025 16:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

5/10

When Bybit security signed off on the transaction, it appeared perfectly legitimate, until the altered script silently redirected all the ETH straight into the hacker’s wallet.

09.03.2025 16:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

4/10

This code didn’t just blindly steal funds, it specifically activated ONLY when Bybit moved funds from their cold wallet. Sneaky, targeted, and patient.

09.03.2025 16:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

3/10

Hackers compromised a Safe{Wallet} developer's computer via social engineering, stole AWS tokens, and quietly injected malicious JavaScript into Safe{Wallet}'s AWS bucket.

09.03.2025 16:41 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

2/10

Bybit relied on Safe{Wallet}, a secure, third-party multisig wallet.

Sounds safe, right?

Well, someone thought it'd be a good idea to store critical signing JavaScript in an AWS bucket.

09.03.2025 16:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

1/10

Bybit, a major crypto exchange, lost $1.5 BILLION in Ethereum. But this wasn't some high-tech, futuristic cyberattack.... it's worse.

09.03.2025 16:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

BYBIT ROBBED OF $1.5 BILLIONβ€”AND THE REASON IS DUMBER THAN YOU THINK

a 🧡

#BybitHack #CryptoFail #CyberSecurity

09.03.2025 16:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
The Virus That Committed a War Crime (StuxNet Explained)
The Virus That Committed a War Crime (StuxNet Explained) YouTube video by Apacalpa

A USB stick helped unleash the first cyberweapon that sabotaged nuclear centrifuges and rewrote the rules of cyberwarfare.

πŸŽ₯ Watch here: www.youtube.com/watch?v=SzEd...

Next up: Miraiβ€”the botnet that turned baby monitors into cyberweapons. Maker vids still coming!

#CyberSecurity #MalwareStories

02.03.2025 14:35 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
DPRK hackers dupe targets into typing PowerShell commands as admin North Korean state actor 'Kimsuky' (aka 'Emerald Sleet' or 'Velvet Chollima') has been observed using a new tactic inspired from the now widespread ClickFix campaigns.

This isn’t hacking, this is psychological warfare against common sense. And the worst part? It’s working.

www.bleepingcomputer.com/news/securit...

12.02.2025 19:27 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
2.8 million IP addresses being used in brute force attack on VPNs Security devices all over the world have been targeted

VPNs are getting hit by 2.8 million brute-force attacks. Soon, VPN providers will start offering 'double VPN' services, which is just two layers of failure for twice the price.

www.tomsguide.com/computing/vp...

11.02.2025 18:52 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Newspaper operations disrupted A "cybersecurity event" has disrupted many of the systems and networks this week at Lee Enterprises, the parent company of the Post-Dispatch and dozens of other newspapers, the company's CEO

Cybercriminals took out a newspaperβ€”next, they’ll hack into billboards and start running ads for their ransomware services. 'Get locked out of your files in 30 minutes or less, guaranteed.'

www.stltoday.com/newspaper-op...

10.02.2025 08:50 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
New Google Chrome Drive-By Hack Attackβ€”Users Must Act Now As hackers target Google Chrome app downloads, here’s what you need to know.

Oh great, Chrome is getting hacked just by visiting a website. Guess it’s time to browse the internet exclusively through Notepad again.
www.forbes.com/sites/daveyw...

09.02.2025 18:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
RTX 4090 liquid cooled with 12,000 BTU air conditioner, RTX 5090 up next β€” GPU runs at 20C Initial tests on a 13900K plus RTX 4090 PC system are positive. RTX 5090 is waiting for a water block.

RTX 4090 with a full air conditionerβ€”because nothing says 'gaming' like a GPU that needs its own climate control system. RTX 5090? Probably gonna require a mini nuclear reactor.
www.tomshardware.com/pc-component...

09.02.2025 18:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
I Built a RetroBright Box SO Good, It ATE My Gameboy Shell!
I Built a RetroBright Box SO Good, It ATE My Gameboy Shell! YouTube video by Apacalpa

soo... don't forget things inside a retrobrightbox, pls!
youtu.be/qibXysiGQRk

04.01.2025 10:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
I Streamed To A Game Boy
I Streamed To A Game Boy YouTube video by ChromaLock

Found a new way to watch my favorite videos...with horrendous framerate and an even worse ppi!

Thanks @chromalock.bsky.social

youtu.be/yPI6gURLLUs

21.12.2024 10:07 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

I don't think stock.

You could theoretically vary the magnetron’s output power to encode binary data. This would involve dynamically adjusting the power supply to create different output levels.

high voltage that is necessary for multiple components would be needed to switch on/off rapidly...

10.12.2024 16:16 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

if you replace the magnetron with a wifi transmitter, yes!

10.12.2024 11:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Got some new electrical wires, and they have this weirdly sweet, synthetic apple scent. I can’t stop sniffing them…

Now I have a headache. Totally worth it.

09.12.2024 15:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
2. **Truncated SHA-256 Hash Collisions**: The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious image can be served in place of a legitimate one, allowing the attacker to "poison" the artifact cache and deliver compromised images to unsuspecting users.

2. **Truncated SHA-256 Hash Collisions**: The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious image can be served in place of a legitimate one, allowing the attacker to "poison" the artifact cache and deliver compromised images to unsuspecting users.

Stop. Truncating. Hashes.

www.phoronix.com/news/OpenWrt...

08.12.2024 16:40 πŸ‘ 23 πŸ” 6 πŸ’¬ 3 πŸ“Œ 1

TIL: That you can still rip CDs with Windows Media Player (Legacy).

And it appears that the fingerprinting for media location services is not only still working, but the catalog appears to be up-to-date.

05.12.2024 21:47 πŸ‘ 134 πŸ” 20 πŸ’¬ 9 πŸ“Œ 0

I got a whole jar of 1 and 2 cent coins that we don't use here anymore, we can work out a deal

06.12.2024 17:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If we make one for you... would you edit the next video faster?

pretty please?

06.12.2024 17:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

FatFern incoming!

30.11.2024 06:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is a 'keyhole slot.' Riveting stuff, huh?

30.11.2024 06:07 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The next video: Yellow fades, the light burns, and the plastic remembers. It’s not ready. Neither am I.

30.11.2024 05:54 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
I Built the WORLD'S FIRST Actual Universal Charger!
I Built the WORLD'S FIRST Actual Universal Charger! YouTube video by Apacalpa

Who knew lightbulb USB chargers were already a thing?
Not me. But I still made one, and it’s gloriously inefficient and totally not universal.

youtu.be/LM-pTcHPPNs

30.11.2024 05:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0