4 828
订阅者
+724 小时
+1417 天
+4 10230 天
帖子存档
4 831
Regarding the recent password reset outage that happened a while ago...
About a month ago, I discovered a Critical Zero-Day vulnerability in Meta's GraphQL. The exploit allowed for zero-interaction Account Takeovers (ATO) under specific conditions, enabling mass account hijacking without any victim interaction. I managed to pull a few OG handles with it, and this exploit was the exact reason Meta was forced to temporarily shut down their reset endpoints for hours to rapidly patch the vulnerable routing paths.
The bug has been officially reported, triaged, and fixed.
@sscoot
4 831
Fake Account Ban
اي احد عنده حساب لقم باند (فيك اكاونت)
1-ما يقدم طعن ابدا
2-يسجل خروج من الحساب والحسابات كلها الي مسجل فيها عشان تتجنب الباند
3-تتركه يوم يومين وينفك من نفسه
现已上线!2025 年 Telegram 研究 — 年度关键洞察 
