The "Steps to Validate" in the readme are just "look at the logs", if this is legit then I'd expect a demonstration of some concrete impact
The "Steps to Validate" in the readme are just "look at the logs", if this is legit then I'd expect a demonstration of some concrete impact
I'm calling slop
excellent emoji use btw
Check out the LinkedIn profile with the same name. And yes, I intentionally didn’t say “his” profile.
www.reddit.com/r/cybersecur... www.reddit.com/r/cybersecur... reddit came to the same conclusion, someone's roleplaying
and uh judging by the replies in the thread, it's someone who is convinced their phone is spying on them, and is asking chatgpt to imagine possible vulnerabilities, and then posting them to github, reddit, etc
yikes
The last time this happened (which was yesterday, btw) this was also my conclusion
endless september arriving a bit early i guess
The guys repos are pure AI slop.
Slopcurity researchers and slopcurity engineers.
look at their other GitHub repositories - one has “C2 post-compromise indicators” confirmed by MobileAssets being queried, and Find My/friends doing key rotation in logs
100% slop. The entire evidence is "I think these are debug only logs" and some of that is flimsy too. It's just written like slop too.