AmmarSpaces
I like Information Security, and silly elves. Mostly posting thing I read blending with my view. Or, just my views of the what happened at world in general.
Shall we go?
I guess, I am in another non productivity phase again.
There are two hypothesis for the culprit:
1. Every time I opened my Laptop in my apartment, my brain just don't like doing any serious things, it prefer to open social media. So far, I can only manage to do things that are not technical. I think I need to do something with my apartment.
2. The job at my office, I think because of the uncertainty on what to do now (the company is just starting up), I do not feel any necessity on jobs that has no clear time deadline. So, my brain is just tired to do assignment because of it and looking for any shortcut. Which I am afraid may be bad in long run. For this, I think I will try fresh brain restart for next week and having self deadline in mind.
Don't worry, I just need to express what inside my mind to clear things up.
If you are in Europe, and you bought Steam's hardware products, you might want to check your e-mail from Steam.
There is a 3rd party logistic partner breach (CEVA Logistics) occoured, where your:
- Name
- Street address, city and postal code
- Country
- Phone number
- Email address linked to the Steam account
- Type and price of the hardware ordered
Might be exposed.
Stay safe out there.
#cybersecurity #infosec #databreach #steam #europe #valve #gaming
Recently there is a YT hack involving hundreds of artists account being 'compromised' to deliver random videos. Apperently the 'hack' were sourced from exploited 3rd party app that just too easy to fool.
Really sad to hear. But, I am afraid the situation will be like the abandonment of DEFCON China.
Because it is clear that Middle East situation will be uncertain for years to come.
I hope I am wrong though.
Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.
What should you do?
- Check if you are affected, if so, downgrade your library version
- Rotate your keys and do 2FA
- Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.
More details: https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/
#cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware
RE: @AmmarSpaces@infosec.exchange
If you stumbled upon my post from 2 months ago...
The link to the presentation is invalid in that post, I have edited it. Sorry >w<
So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
Hmm, I guess I should also start writing... But, idk. Let's see a week from now
