CyberGhost

1.5K posts

CyberGhost

CyberGhost

@CyberGh0ost007

Software Developer. Building https://t.co/qAxlYtQBIW and https://t.co/Ea74uyh6Ic

Maputp Katılım Ekim 2021
231 Takip Edilen41 Takipçiler
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
International Cyber Digest@IntCyberDigest

‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.

English
130
748
4K
2.6M
Modat
Modat@modat_magnify·
CVE-2026-44578  ⚠️ Next.js – WebSocket Upgrade SSRF (CVSS 8.6)  A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler.  By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data.  Affected: Next.js 13.4.13+, 14.x, 15.x <15.5.16, 16.0.0–16.2.4  Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.   Modat Magnify Query:  technology="Next.js"  The platform:  magnify.modat.io  #threatintel #vulnerability #CVE202644578 #Nextjs #SSRF #WebSocket #CloudSecurity #infosec #Critical #ModatMagnify
Modat tweet media
English
72
411
2.4K
1.4M
CyberGhost
CyberGhost@CyberGh0ost007·
What a hell
Socket@SocketSecurity

🚨 Socket detected malicious activity in newly published versions of node-ipc, an npm package with 822K weekly downloads. Affected versions: node-ipc@9.1.6 node-ipc@9.2.3 node-ipc@12.0.1 Socket’s AI scanner flagged the malware within ~3 minutes of publication. Early analysis shows obfuscated stealer/backdoor behavior, including host fingerprinting, local file enumeration, payload wrapping, and attempted exfiltration.

English
0
0
0
6
antonymwangi
antonymwangi@tonykagoh·
@Joe__Bassey Guy doesn't even understand english, 'this shop must not be closed' how will he reason with a foregin businessman in S.A
English
2
0
1
66
Typical African
Typical African@Joe__Bassey·
This is the current situation in South Africa 🇿🇦: since yesterday, some indigenous black South Africans have been demanding that every shop belonging to immigrants close on Friday.
English
107
125
324
19K
CyberGhost
CyberGhost@CyberGh0ost007·
@Gabybigs @Joe__Bassey Bro, he's demanding proof of investment in 5 million. It doesn't make any sense. Now don't you wanna know if they are illegal no more? 😅
English
1
0
0
14
MABITSELA KWENA
MABITSELA KWENA@Gabybigs·
@Joe__Bassey Is our country and yes they must go to their countries. We are sick and tired of them mxm.
English
2
0
5
603
Lucilio
Lucilio@margielaaaman1·
@SulikaJr a lógica é que a tendência de todos novos lançamentos é estar o mais próximo possivel da realidade
Português
1
0
0
84
Mário Ferreira
Mário Ferreira@MarioFaife·
Professor: Quem não quiser assistir minha aula pode sair. Eu: *levanto para sair* Professor:
Mário Ferreira tweet media
Português
2
0
27
522
CINE7
CINE7@JerThaPlug·
Sul africano são abençoados ya 😔 SiR, Boyz II Men, Maxwell, Jorja Smith, Dave, Jill Scott, J Cole, Drake 😔 2026 Abençoado
CY
22
38
243
5.3K
Eduardo “PYTHON” Jr
Eduardo “PYTHON” Jr@JnorEduardOfice·
@iGraHms @JerThaPlug @slutttyyykiksss No meu ponto de vista eles têm essas oportunidades por conta do inglês, uma vez Ismael disse: “Se Moçambique adoptasse o inglês como idioma principal, teríamos mais ganhos económicos e culturais”.
Português
1
1
0
131
ClaudeDevs
ClaudeDevs@ClaudeDevs·
Claude Code weekly limits are increasing 50%, now through July 13. Live now for all Pro, Max, Team, and seat-based Enterprise users.
ClaudeDevs tweet media
English
1.3K
2K
21.9K
2.5M
Richie
Richie@MeeSowCorny·
@gloccnem bruh 😭😭😭 this is like going to work a 9-5 and never getting a paycheck
English
1
0
4
456
José Arlindo
José Arlindo@Muianga·
Façam machambas perto de casa. Não se preocupem com o preço do combustível, ouviram? ⛽😂
Português
19
17
103
5.3K
Barbosa
Barbosa@Allan_brb·
@douglasnbraga O time é horroroso Pragmático,medroso,e sem criatividade A única jogada deles é Bola aérea Eu torço mto pra eles perderem qualquer título
Português
10
0
37
7.1K
Douglas
Douglas@douglasnbraga·
Se o Arsenal conquistar algum titulo esse ano, quem perde é o futebol Time nojento, asqueroso, moroso, ridiculo
Português
135
108
804
119K
Premier League
Premier League@premierleague·
Another step closer to the Premier League title for @Arsenal 🔴
Premier League tweet media
English
1.3K
3.8K
23.1K
489.5K