forestxfire

1.2K posts

forestxfire banner
forestxfire

forestxfire

@forestxfire_

jw- check out my music below

가입일 Aralık 2019
808 팔로잉658 팔로워
고정된 트윗
forestxfire
forestxfire@forestxfire_·
Sample i made today
English
1
2
15
609
forestxfire 리트윗함
♰ 𝙽𝚊𝚎𝚝𝚘
♰ 𝙽𝚊𝚎𝚝𝚘@fw_naetoblaq·
Ngl the music your parents introduce you to stays with you forever
English
372
14.4K
71K
2.8M
forestxfire 리트윗함
Tyler Hill
Tyler Hill@TylerhillCo·
Yall celebrated Kevin Samuels passing away, Tory lanez getting stabbed and will smith getting cheated on. But Meg needs to be protected.
English
501
5.4K
36.7K
890.7K
forestxfire 리트윗함
𐌁𐌉Ᏽ 𐌕𐌉𐌌𐌉
Companies replacing junior roles with AI and then wondering why they can't find senior talent in five years is going to be the most predictable crisis in hiring history.
English
227
9.9K
99.6K
1M
forestxfire 리트윗함
goma
goma@soigomaa·
STRONG opinion: students wouldn't use Ai if school was about LEARNING and not GRADES.
English
451
5.9K
61.7K
621K
forestxfire 리트윗함
HFR Podcast
HFR Podcast@hfrpodcast·
Kendrick Lamar was spotted leaving the studio last night in LA 🔥 (via @TMZ)
HFR Podcast tweet media
English
629
1.7K
32.3K
3M
forestxfire 리트윗함
Miss Ally
Miss Ally@MissAlly_01·
The Chinese man who invented the camera lens has passed away. Rest in peace, Zoo Min.
English
365
5.2K
89.6K
2.7M
forestxfire 리트윗함
My Mixtapez
My Mixtapez@mymixtapez·
Dave Chappelle responds to backlash for doing a show in Saudi Arabia: “They fund Netflix, Hollywood movies—don’t be a hypocrite now that a Black man got paid.” 👀
My Mixtapez tweet media
English
332
3.1K
28.6K
883.8K
forestxfire 리트윗함
Basic Human Stuff
Basic Human Stuff@basichumanstf·
Maturing is letting the spider stay in the ceiling corner of your room
English
602
6.3K
44.7K
1.1M
forestxfire 리트윗함
glock ☦︎
glock ☦︎@gloccnem·
supervisor: i’m sorry we can’t sign the papers to approve your vacation. me :
glock ☦︎ tweet media
English
90
2.9K
18.3K
379.7K
forestxfire 리트윗함
AWS Developers
AWS Developers@awsdevelopers·
‼️The AWS console has been retired. All services must now be used through the CLI only.
English
288
474
6K
744.9K
forestxfire 리트윗함
Jen 🎈
Jen 🎈@lunchbag·
Your SOC2 compliance is fake, your deploy platform leaks private user data, and your HTTP library has malware in it. Happy Monday.
English
51
186
2.7K
95.4K
forestxfire 리트윗함
shaurya
shaurya@shauseth·
first date idea: we establish a tcp connection
English
67
807
6.4K
119.5K
forestxfire 리트윗함
Anish Moonka
Anish Moonka@anishmoonka·
A tiny piece of code called axios runs inside almost every app on your phone and every website you visit. Developers download it 100 million times a week. A few hours ago, someone poisoned it with malware that hands an attacker full control of your computer. If you’ve never heard of axios, that’s normal. It does one boring but important job: it lets apps talk to the internet. When a website pulls up your feed or an online checkout processes your card, axios is probably doing the work underneath. Over 173,000 other code packages plug into it. It’s everywhere. The attacker stole a lead developer’s login for npm (think of it as an app store, but for code that programmers use to build software). Once inside, they swapped the developer’s email to an anonymous ProtonMail account and uploaded the poisoned version by hand. That jumped past every security check the project normally runs before new code goes live. And this was not some rushed job. The attacker staged the malware at least 18 hours before pulling the trigger. They built separate versions for Windows, Mac, and Linux. They poisoned both the current version and an older one within 39 minutes of each other, casting the widest net possible. Once the malware ran on a machine, it deleted itself to cover its tracks. The trick was smart. They never touched a single line of code inside axios itself. Instead, they tucked in a fake add-on called plain-crypto-js, built to pass as a well-known, trusted library. It copied the real library’s description and author info, so nothing looked off at a glance. When a developer installed axios, this fake package quietly ran the malware on its own. When a smaller package called ua-parser-js got hijacked back in 2021 with about 8 million weekly downloads, the security world treated it like a four-alarm fire. Axios has 100 million. Over 12x the exposure, with 173,000+ packages depending on it. Socket, the security firm that flagged this, caught it in about 6 minutes. That’s fast. But 6 minutes is still plenty of time for automated systems at companies everywhere to pull and install the bad version before anyone can react. If you or your team runs axios: lock your version to 1.14.0 (or 0.30.3 for the older branch). Change every password, API key, and access token on any machine that installed the compromised update. And check your network logs for connections to sfrclak dot com or the IP address 142.11.206.73.
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
50
610
3.6K
659.5K
forestxfire 리트윗함
soup🍓
soup🍓@thrluv·
benadryl smart af, you can’t have allergies if you’re unconscious
English
140
4.6K
40.8K
596.7K