Ax Sharma

3.6K posts

Ax Sharma banner
Ax Sharma

Ax Sharma

@Ax_Sharma

Security Researcher | Tech Journalist | 📰 Bylines + seen on: BBC, BleepingComputer, Channel 5, TechCrunch | ✉️ [email protected]

🇨🇦🇬🇧 Katılım Nisan 2016
1.4K Takip Edilen5.3K Takipçiler
Ax Sharma
Ax Sharma@Ax_Sharma·
5 supply chain attacks in 72 hours. GitHub's own internal repos (~3,800). Microsoft's official Azure-associated package. And attackers... already stealing your Claude and Cursor config files via this attack vector.
English
1
0
5
309
Ax Sharma retweetledi
SafeDep
SafeDep@safedepio·
🚨 The "𝙼𝚎𝚐𝚊𝚕𝚘𝚍𝚘𝚗" Campaign is live... 𝟻,𝟽𝟷𝟾 malicious commits to 𝟻,𝟻𝟼𝟷 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected 𝙶𝚒𝚝𝙷𝚞𝚋 𝙰𝚌𝚝𝚒𝚘𝚗𝚜 workflows containing 𝚋𝚊𝚜𝚎𝟼𝟺-𝚎𝚗𝚌𝚘𝚍𝚎𝚍 bash payloads that exfiltrate: - CI secrets, - cloud credentials - SSH keys - OIDC tokens - source code secrets Check your repo / Technical details: safedep.io/megalodon-mass…
SafeDep tweet media
English
24
166
608
218.5K
Ax Sharma retweetledi
Windows Latest
Windows Latest@WindowsLatest·
After 10 years of running WindowsLatest, I think this is finally the end of an era. Google comfirmed that Search is becoming an AI box, which means you'll not be encouraged to click "blue links." Yes, the blue linke are still on the page, but they're becoming irrelevant. For a decade, I watched Google rank Reddit threads, forums, spam, and sites that merely linked to my reporting above the original articles I broke. I complained to Googlers repeatedly. I showed them my original work being outranked by spammers copying it. Nobody at Google cared... I never sold products with affiliate links. Ive never recommended anything for a commission. I have never ran a sponsored post. Being the "nice guy" earned me nothing Google had already decimated independent publishers long before this announcement. AI Mode is just the funeral
philip lewis@Phil_Lewis_

Google Search as you know it is over "Instead of returning a simple list of links, Google Search will drop users into AI-powered interactive experiences at times." techcrunch.com/2026/05/19/goo…

English
30
137
1.5K
107.7K
Ax Sharma
Ax Sharma@Ax_Sharma·
A trojanized Bitwarden npm version appeared for 90 minutes last month. 9 days later it got a CVE—after the package was already pulled. That's an incident response notification, not what CVEs were originally built for. Agentic AI makes this gap much worse csoonline.com/article/417342…
English
0
0
3
214
Ax Sharma retweetledi
Microsoft Threat Intelligence
Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages. Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, antv/g2). As these packages are widely used as dependencies, the compromise propagated into downstream libraries like echarts-for-react, impacting a much broader set of applications and continuous integration (CI) environments. All compromised packages contain a byte-identical, obfuscated credential-stealing payload delivered via a preinstall hook (Bun). The malware targets high-value secrets including: - GitHub personal access tokens (PATs) and OpenID Connect (OIDC) tokens - npm / Amazon Web Service (AWS) credentials and Security Token Service (STS) sessions - Secure Shell (SSH) keys, kubeconfigs, and .env / .npmrc files - Software-as-a-service (SaaS) tokens (Slack, Stripe, Vault) Exfiltration occurs over HTTPS with Transport Layer Security (TLS) validation disabled. The payload also abuses stolen OIDC tokens to forge Supply-chain Levels for Software Artifacts (SLSA) provenance and propagate malicious releases, exhibiting worm-like behavior across repositories. Malicious files distributed through npm packages are detected by Microsoft Defender as Trojan:AIGen/NPMStealer , "Suspicious Node.js process behavior", or “Credential access attempt”, preventing credential theft and malicious post-install execution. Mitigation: - Audit dependencies for affected antv and related packages; pin or downgrade to known-good versions (pre-2025-05-18). - Revoke and rotate exposed credentials (GitHub, npm, cloud tokens, SSH keys). - Validate integrity of CI pipelines and recent build artifacts. - Network IOC: Stolen credentials are exfiltrated over HTTPS to t.m-kosche[.]com:443. Block at egress and review network logs for outbound connections.
Microsoft Threat Intelligence tweet media
English
35
235
1.3K
173.6K
Ax Sharma retweetledi
Zack Korman
Zack Korman@ZackKorman·
Cloudflare is right about this. You're not going to be able to patch fast enough, but you can build your systems so that the vast majority of vulnerabilities don't matter. If you've not done that, you're going to have a bad time.
Zack Korman tweet media
English
31
44
274
43.7K
Ax Sharma
Ax Sharma@Ax_Sharma·
Francisco Rosales (@0xmagic0) of @Manifold_ai_sec found and reported the vulnerability. Fixed in v3.6.0. The filtering logic already existed. It just wasn't being called in both places. Update now.
English
1
3
4
703
Ax Sharma
Ax Sharma@Ax_Sharma·
The tool names are in the README. Set to read-only mode. 'kubectl_delete' is not on the list. But if you call it anyway, the pod is gone...
English
1
1
1
853
Ax Sharma
Ax Sharma@Ax_Sharma·
The read-only mode in mcp-server-kubernetes (20,000+ weekly npm downloads) ...doesn't actually restrict anything. Neither do the other two access control modes. CVE-2026-46519, CVSS 8.8 🧵
Ax Sharma tweet media
English
3
9
43
62.9K
Ax Sharma retweetledi
Hackmanac
Hackmanac@H4ckmanac·
🚨Cyber Alert ‼️ WormGPT A threat actor known as Sythe claimed to have leaked the database of WormGPT, a cybercrime-focused AI platform, exposing data linked to more than 19,000 users. The leaked data allegedly includes email addresses, user IDs, and subscription and billing metadata. Sector: ICT Threat class: Cybercrime Observed: Feb 10, 2026 Status: Pending verification — About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
Hackmanac tweet media
English
19
107
683
63.4K
Ax Sharma retweetledi
tuckner
tuckner@tuckner·
lmao for real?
tuckner tweet media
English
5
3
47
11.3K
Ax Sharma
Ax Sharma@Ax_Sharma·
Responsible disclosure is built on an assumption that "doing the right thing" = timely action & fair treatment, if not a bounty award. Lately, that assumption is collapsing. For CISOs, this is gradually evolving into a risk management nightmare. csoonline.com/article/412476…
English
0
0
0
192
Ax Sharma
Ax Sharma@Ax_Sharma·
A NationStates game player found a critical vulnerability and then crossed a line... He copied production data and app code to his personal system. bleepingcomputer.com/news/security/… Finding a flaw is enough. Demonstrate it safely, report it responsibly and stop there.
English
0
0
0
199
Ax Sharma
Ax Sharma@Ax_Sharma·
Such data can expose who runs what, at what scale, and when contracts renew. This serves as prime intel for competitors/customer poaching but also for threat actors aiming to launch targeted phishing, BEC and extortion attacks. bleepingcomputer.com/news/security/…
English
0
0
0
247
Ax Sharma
Ax Sharma@Ax_Sharma·
BREAKING: Threat actors are seeking data on ~1,800 MSPs after a Pax8 spreadsheet with customer and Microsoft licensing info was accidentally emailed to ~40 partners yesterday.
Ax Sharma tweet media
English
1
0
0
397