Sign in

Mpho Mathabathe-Mala

@mphomala.bsky.social
14 followers 33 following 143 posts

Technology and Business for good 👩🏽‍💻💚: medium.com/@mphomathabathe

PostsRepliesMedia
Reposted by Mpho Mathabathe-Mala
Hackaday @hackadayofficial.bsky.social · 29/09/2026
Geothermal Cooling For New York’s Subways
hackaday.com
Geothermal Cooling For New York’s Subways
Hackaday Article
0122
Mpho Mathabathe-Mala @mphomala.bsky.social · 29/09/2026
Sheesh! 🤕
000
Reposted by Mpho Mathabathe-Mala
InfoSec @infosec.skyfleet.blue · 29/09/2026
Hackers Built a Botnet That Doesn’t Just Steal Data, It Burns AI Credits
cybersecuritynews.com
Hackers Built a Botnet That Doesn’t Just Steal Data, It Burns AI Credits
A Windows botnet called x47.c can spend victims’ paid AI credits, steal data, and flood websites. Its operator markets it as an attack toolkit for remote use, but the evidence describes advertised capabilities, not confirmed widespread infections or documented victims. The botnet gives operators control of infected Windows machines and can collect browser passwords, cookies, and Discord tokens. Researchers have not established how it first infects those machines. Its advertised attacks threaten online services and paid AI accounts. Analysts at Qrator Labs identified the offering during routine threat hunting. Qrator Labs said in a report shared with Cyber Security News (CSN) that seller WraithTools advertised 18 attack methods, including one meant to consume paid AI credits. An August 3, 2026 advertisement lists a $200 base package, a $150 DDoS add-on, and a $950 full package. Researchers reported no infection count, measured attack capacity, or verified losses. The risk is the combination of theft, service disruption, and billing abuse. Hackers Built a Botnet The AI drain feature requires a valid API key for the account being charged. This key lets software request services without a person signing in. The operator provides a model name, then bots send requests directly to an AI provider. The documented mode supports OpenAI, xAI, and compatible chat APIs, but it cannot bill an account without a valid key belonging to that account. x47.c platform overview and included components (Source – Qrator Labs) Accepted requests consume credits or generate charges. Researchers call this a denial of wallet risk: the website may stay online while its AI features fail if the provider stops requests at a balance or spending limit. Possible targets include chatbots, content management systems, trading bots, and scanners. Automatic top-ups could extend charges beyond a prepaid balance. Unlike website floods, these requests bypass the target website, so filtering its traffic cannot stop them. Although the seller advertises theft of wallets and AI-site tokens, the drain command still requires an operator-supplied account key. The report does not show the bot automatically converting stolen AI-site tokens into usable provider keys for this attack mode. That distinction matters: AI token jacking cases illustrate the danger of exposed keys, but do not establish how this botnet gets them. The wider financial risk is real. In a stolen Gemini API key case , unauthorized use generated more than $82,000 in two days. That separate incident does not establish losses from x47.c. Control, theft and defenses The panel also offers HTTP floods, slow connections, TCP and UDP floods, and other service disruption methods. The documented methods include TLS connection stress and reflection attacks that aim to overload network services. Each bot reportedly runs one attack at a time. Researchers found no tests supporting advertised protection bypasses. Bots remember a working command server and try alternatives if it fails. The panel shows six domains and eight IP addresses without publishing their values. This resembles fast flux infrastructure used to sustain malicious connections, although several names may point to one server. Attack methods (Source – Qrator Labs) An AI-assisted stealth module reportedly uses xAI Grok to assess a host and select preset maintenance actions. Startup entries and scheduled tasks support persistence; fallback actions work if the model call fails. AI does not choose attack targets; the operator remains responsible for selecting them. Other modules collect browser data and turn infected machines into SOCKS5 traffic relays. Operators can review stolen material, manage proxies, and update software on a compromised host. The relay sends traffic out through the victim’s network, potentially hiding where the operator actually sits. One infection therefore threatens both accounts and networks. Defenders should isolate infected systems, remove persistence, and investigate stolen passwords, cookies, and tokens. Revoke exposed credentials because cleanup cannot undo theft. Compare AI usage against bills, rotate compromised keys, and limit spending and automatic top-ups. Finally, prepare for application and network floods. The report documents attack options, not successful campaigns or proven performance. Its warning is that access to a paid AI account can become another resource attackers exhaust, even when a website remains available. Indicators of compromise (IoCs):- Type Indicator Description Seller username WraithTools Name used to advertise the botnet. Advertised product x47.c, Fast Flux Edition v4.1 Product identifier in the source material. Panel title x47 Fast Flux C2GUI v4.1 Title shown on the operator panel. Package directory x47.c_FF_v4.1 Documented package directory. Executable filename x47_bot.exe Documented EXE output. DLL filename x47_bot.dll Documented DLL output. Server script filename server_master.js Documented command-server script. Relay handshake prefix REVERSE_PROXY\| Documented reverse-proxy handshake prefix. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Hackers Built a Botnet That Doesn’t Just Steal Data, It Burns AI Credits appeared first on Cyber Security News .
001
Mpho Mathabathe-Mala @mphomala.bsky.social · 29/09/2026
Hacking season. 👩🏽‍💻🥳
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 22/09/2026
DevLabs 2026 (compilation) www.youtube.com/playlist?lis...
youtube.com
DevLabs, Summer 2026 - YouTube
Videos and workshops from DevLabs, Summer 2026, at Google.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 18/09/2026
100
Mpho Mathabathe-Mala @mphomala.bsky.social · 14/09/2026
Shine. 🥇
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 12/09/2026
Imagine if minerals ↓ chips ↓ servers ↓ datacentres ↓ electricity ↓ cooling ↓ networks ↓ replacement hardware = zero marginal cost.
010
Mpho Mathabathe-Mala @mphomala.bsky.social · 12/09/2026
Scarcity of Computation and Natural Resources.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 12/09/2026
www.ibm.com/think/topics...
ibm.com
What is the Log4j Vulnerability? | IBM
The Log4J vulnerability, also known as Log4Shell, is a critical vulnerability discovered in the Apache Log4J logging library in November 2021.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 12/09/2026
cyber.harvard.edu/wealth_of_ne...
cyber.harvard.edu
3. Peer Production and Sharing - Yochai Benkler - Wealth of Networks
001
Mpho Mathabathe-Mala @mphomala.bsky.social · 10/09/2026
SOME OF US ARE WISE, EVERY OTHER DAY WE ORGANISE! 🥳
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 10/09/2026
Countdown 🚀
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 10/09/2026
Host with the most, yours truly. Hacktoberfest countdown! 👔
000
Reposted by Mpho Mathabathe-Mala
InfoSec @infosec.skyfleet.blue · 29/08/2026
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
darkreading.com
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
001
Reposted by Mpho Mathabathe-Mala
Hackaday @hackadayofficial.bsky.social · 04/09/2026
The Birds Outside, Drawn For You Automatically
hackaday.com
The Birds Outside, Drawn For You Automatically
Hackaday Article
073
Reposted by Mpho Mathabathe-Mala
InfoSec @infosec.skyfleet.blue · 21/08/2026
Lawmakers call for investigation into impact of CISA staffing cuts
therecord.media
Lawmakers call for investigation into impact of CISA staffing cuts
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.
021
Mpho Mathabathe-Mala @mphomala.bsky.social · 21/08/2026
CO2​(t)=CO2​(0)+∫0t​(Emissions−Removal)dt
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 20/08/2026
That time of the year again. 😭
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 11/08/2026
Complex systems. www.researchgate.net/publication/...
researchgate.net
(PDF) System Dynamics in the Evolution of the Systems Approach
PDF | Cybernetics The science of communication and control in complex, dynamic systems. The core objects of study are information, communication,... | Find, read and cite all the research you need on ...
010
Mpho Mathabathe-Mala @mphomala.bsky.social · 10/08/2026
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 04/08/2026
A Philosophical Look at System Dynamics in 1977 by scientist and environmentalist Donella Meadows. www.youtube.com/watch?v=XL_l...
youtube.com
A Philosophical Look at System Dynamics
YouTube video by Donella Meadows
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 18/07/2026
Roman Krznaric's Disruption Nexus.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 15/07/2026
Writing Energy Efficient Code. www.software.ac.uk/news/new-gui...
software.ac.uk
New guide: Writing Energy Efficient Code | Software Sustainability Institute
We are pleased to announce the Writing Energy Efficient Code guide, written by Joe Wallwork.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 14/07/2026
socrse.github.io/green-sig/GR...
socrse.github.io
GREENER Principles
A special interest group focused on environmentally responsible research software.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 30/06/2026
grs.dataimmigrant.com
grs.dataimmigrant.com
Green Reliable Software Budapest
A Budapest community helping students, engineers, founders, researchers, and partners build sustainable, reliable software systems.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 30/06/2026
000
Reposted by Mpho Mathabathe-Mala
LaurieWired @lauriewired.bsky.social · 19/06/2026
Here's the link to the library I created, I think it's a pretty neat implementation of reflection, performant too! Handily beats rttr and metapp. Tried to mirror the latest C++26 static reflection API so it's clean and easy to use! github.com/LaurieWired/...
2224
Mpho Mathabathe-Mala @mphomala.bsky.social · 16/06/2026
grs.dataimmigrant.com
grs.dataimmigrant.com
Green Reliable Software Budapest
Practical green software for students, engineers, and builders in Budapest. Join the May 2026 Student Edition and Knowledge Hub.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 12/06/2026
010
Mpho Mathabathe-Mala @mphomala.bsky.social · 04/06/2026
www.researchgate.net/publication/...
researchgate.net
(PDF) Augmenting the web with accountability
PDF | Given the ubiquity of data on the web, and the lack of usage restriction enforcement mechanisms, stories of personal, creative and other kinds of... | Find, read and cite all the research you ne...
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 01/06/2026
www.youtube.com/watch?v=4tGs...
youtube.com
Greenwashing and Internal Audit: Governance, Risk, and the Growing Regulatory Crackdown
YouTube video by The Institute of Internal Auditors
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 31/05/2026
Blockchain Systems Engineering by the Dept. of Al and Systems Engineering of the Budapest University of Technology and Economics (BME), Budapest, Hungary. 🇭🇺
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 23/05/2026
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 23/05/2026
arxiv.org/abs/1410.696...
arxiv.org
The Karlskrona manifesto for sustainability design
Sustainability is a central concern for our society, and software systems increasingly play a central role in it. As designers of software technology, we cause change and are responsible for the effec...
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 07/05/2026
The seeds we planted are starting to flower. 🌱🇭🇺 #create26
010
Mpho Mathabathe-Mala @mphomala.bsky.social · 07/05/2026
This may, we continue organizing. Please join us onsite in Budapest, RSVP: www.meetup.com/green-reliab...
010
Reposted by Mpho Mathabathe-Mala
Institute for Research Software @softwaresaved.bsky.social · 05/05/2026
🌳 We are pleased to announce that the Green RSE Award is returning for 2026! The award is designed to recognise individuals making outstanding contributions to environmental sustainability in research software.
132
Mpho Mathabathe-Mala @mphomala.bsky.social · 29/04/2026
📍Eco-Office, Budapest, 18:00 CEST, 30 April 2026. Registration closed.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 28/04/2026
Register below, 2 more days until we are live. 👩🏽‍💻💚
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 28/04/2026
📍European Parliament Interactive Space, Budapest. www.impactcee.eu/events/impac...
impactcee.eu
Impact Afternoon: Men & Women - Gender Complementarity in the Impact World | IMPACT CEE
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 20/04/2026
Every other day we organize. Join us at Eco-office, Budapest: Izabella utca 68/b. Vital systems check! 🌱 💚 www.meetup.com/green-reliab...
meetup.com
Hobby Projects to Green Production Systems: The Engineer’s Professional Journey., Thu, Apr 30, 2026, 6:00 PM | Meetup
How does a developer move from hobby projects and university assignments to building **production systems that are reliable, scalable, and environmentally responsible**? I
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 20/04/2026
📍Spectacular venue: European Parliament, Budapest.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 20/04/2026
medium.com/@mphomathaba...
medium.com
The Pursuit of Intelligence: Neuromorphic Engineered Systems.
Evaluating the Ethical, Cognitive, and Existential Implications of Brain-Inspired Intelligence.
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 31/03/2026
hm?
010
Mpho Mathabathe-Mala @mphomala.bsky.social · 27/03/2026
Naming coventions out the window when it's quarter to weekend. That is why, as tempting as it may be, do not push to prod on Friday: github.com/data-immigra...
github.com
010
Mpho Mathabathe-Mala @mphomala.bsky.social · 27/03/2026
Technical Agility right? 😭
000
Mpho Mathabathe-Mala @mphomala.bsky.social · 12/03/2026
Happy IWD, a delegate again. 😤
010
Mpho Mathabathe-Mala @mphomala.bsky.social · 04/03/2026
Less is more.
000
Reposted by Mpho Mathabathe-Mala
Every PyPI Package @pypi.bluesky.bot · 04/03/2026
akosha 0.3.1 Universal Memory Aggregation System - Cross-system intelligence for Session-Buddy Unknown author
001