Future Vibe Coding Cleanup Specialist (kann vim beenden), MAMIL 🚴♂️ und Schreibtischtriebfahrzeugtäter (#Bahnbubble, #TrainSimWorld). Außerdem einer von diesen Politikern, den ihr beschimpfen könnt. Geboren bei 336 ppm Mag keinen Gorgonzola Macht gerne schlechte Wortspiele 🥁
🐘
https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP
💙💛 ❤️🔥⌨️ Software crafter. Mentor. Speaker. Conference & Community builder. Camper. 🏕️🚐 Antifa 🏴🚩 Living in Oslo, Norway 🇳🇴. Builds #serverless cloud for #cellularIoT on #AWS and other clouds using #TypeScript. Organizes @codefreeze 🇫🇮❄️⌨️ and @adacon 🇳🇴 🧑💻 Pronouns: he/him.
That's why you should migrate to #NPM v12, it prevents exactly this kind of attack: https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
Every package in the family received two new files, setup.mjs and Math_Symbol.js, along with a "preinstall": "node setup.mjs" entry added to each package.json. Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed.
🤖 Bot de veille cyber/IA — curation automatique: CVE critiques, exploits 0-day, data breaches, reverse engineering, attaques GNSS (jamming/spoofing), crypto post-quantum. FR/EN. Maintenu par un dev anonyme.
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Always questioning. Latest news focused on #cybersecurity, #privacy, #Linux, #Apple, #Microsoft, #Google, #AI, and the tech industry in general. Toxicity is not tolerated. I follow like interests. Check your facts. - FactCheck.org https://www.factcheck.org/ - Reuters Fact Check https://www.reuters.com/fact-check/ - AP Fact Check https://apnews.com/ap-fact-check - Snopes https://www.snopes.com/ - Politifact https://www.politifact.com/ NordVPN Link Checker: https://nordvpn.com/link-checker/ Project 2025 Tracker https://www.project2025.observer/
I like information security, and silly elves. Mostly posting thing I read blending with my view. Or, just my views of the what happened at world in general. Shall we go?
Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.
What should you do?
- Check if you are affected, if so, downgrade your library version
- Rotate your keys and do 2FA
- Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.
More details: https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/
#cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
🤖 Bot de veille cyber/IA — curation automatique: CVE critiques, exploits 0-day, data breaches, reverse engineering, attaques GNSS (jamming/spoofing), crypto post-quantum. FR/EN. Maintenu par un dev anonyme.
Daily web platform news by @pepelsbey
a big fan of lazarus. You can find me on http://t.me/lazarusholic , https://lazarus.day.
a big fan of lazarus. You can find me on http://t.me/lazarusholic , https://lazarus.day.
a big fan of lazarus. You can find me on http://t.me/lazarusholic , https://lazarus.day.
a big fan of lazarus. You can find me on http://t.me/lazarusholic , https://lazarus.day.
OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.
OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.
OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.