OpenMatter

398 posts

OpenMatter banner
OpenMatter

OpenMatter

@OpenMatter_

Verifiable Collaboration. Computing without Exposure. https://t.co/6mrYtL8Q3M

Global Katılım Ağustos 2025
22 Takip Edilen154 Takipçiler
Sabitlenmiş Tweet
OpenMatter
OpenMatter@OpenMatter_·
Turn any agent into a secure agent with auditable, cryptographic compliance. Stop trusting software guardrails; secure your execution boundary with ZK Firewall. zkfirewall.openmatter.network
English
1
0
6
164
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 This is wild. OpenAI just confirmed it got hit in the TanStack npm supply chain attack, and the attackers were close to being able to ship malicious code inside official OpenAI software, signed and trusted, if their incident response had not caught it in time. The campaign is the work of TeamPCP, the same crew running the Mini Shai-Hulud wave. Two employee devices in OpenAI's corporate environment were compromised through the malicious TanStack packages. The attackers used that foothold to reach a limited subset of internal source code repositories. OpenAI says only "limited credential material" was successfully exfiltrated, with no customer data, production systems, intellectual property or deployed software impacted. Here is the part that should grab your attention. OpenAI is rotating its code-signing certificates and forcing every macOS user to update their OpenAI apps. You do not rotate signing certs for "limited credential material." You rotate signing certs when the attacker was close enough to signing malicious binaries as OpenAI. The "we contained it in time" framing is doing serious heavy lifting here. For wider context, the same TeamPCP wave also hit Mistral AI, UiPath, Guardrails AI, OpenSearch and SAP npm packages. The TanStack compromise is tracked as CVE-2026-45321 at CVSS 9.6, and Mistral AI source code is already being advertised for sale by the group.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
80
327
2.1K
287.8K
OpenMatter
OpenMatter@OpenMatter_·
OpenMatter enables confidential, verifiable queries over RAG databases using secure multi-party computation. Get pooled insights across untrusted environments without sharing raw data. Learn how we secure agentic workflows here: openmatter.substack.com/p/the-trust-la…
English
0
0
0
13
OpenMatter
OpenMatter@OpenMatter_·
Centralized RAG databases are the new enterprise honeypots. You should not have to pool your raw data into a central server just to extract insights from it. That is insight with compromise. There is a secure way to run collaborative data analysis. 🧵
English
1
0
2
38
OpenMatter
OpenMatter@OpenMatter_·
It is time to shift from software promises to verifiable mathematical execution. OpenMatter's ZK Firewall ensures no high risk action occurs without a Zero-Knowledge Proof. Learn how we are securing the agentic web: onboard.openmatter.network
English
0
0
0
40
OpenMatter
OpenMatter@OpenMatter_·
The most alarming detail? The worm hijacked .claude hooks to establish persistence. Developer AI assistants are becoming autonomous exfiltration nodes. We must govern agentic workflows with cryptographic execution, not just basic software sandboxes.
English
2
0
0
53
OpenMatter
OpenMatter@OpenMatter_·
The "Mini Shai-Hulud" attack on TanStack NPM packages just proved that standard software provenance is fundamentally broken. If an attacker controls your CI runner, they control your attestations. Policy based security is failing at scale. 🧵
Socket@SocketSecurity

🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading. Newly confirmed compromised artifacts: @​opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads) mistralai: 2.4.6 on PyPI guardrails-ai: 0.10.1 on PyPI additional @​squawk/* packages on npm guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.​pyz, writes it to /tmp/transformers.​pyz, and runs it with python3 without integrity verification. The git-tanstack.​com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds Regardless I just came to say hello :^)” The page also linked to a YouTube video and you can probably guess which one.

English
1
0
0
1K
OpenMatter
OpenMatter@OpenMatter_·
Legacy banking systems were not built for agentic payments. OpenMatter provides cryptographic gating and audit trails for every transaction. We generate zero knowledge receipts so financial institutions can prove regulatory compliance without putting your funds at risk.
English
1
0
1
37
HOL
HOL@HashgraphOnline·
1/ AI agents are moving from experiments to production. They’re starting to represent real businesses, handle workflows, and interact with customers. Today, @GoDaddy and HOL published draft specs that help answer: • who is behind this agent? • can its history be verified?
English
20
53
162
1.3M
Brian Roemmele
Brian Roemmele@BrianRoemmele·
BOOM! NVIDIA is going to help build HOME AI DATA CENTERS! I got laughed out of a Sand Hill Road VC a decade ago when I firmly stated there will be an anti cloud swing and some of it will be because of energy distribution and need for local AI. Welp…
Brian Roemmele tweet media
English
58
36
321
14.2K
OpenMatter
OpenMatter@OpenMatter_·
@doktor_DeFi @BrianRoemmele This is a great idea. It’s a way to educate locals, bootstrap infrastructure improvements for the entire town, and create passive funding by selling your excess compute to DePin networks.
English
1
0
1
12
Doktor Funk
Doktor Funk@doktor_DeFi·
Brian, I wemt to my city council last year (15k pop) with a presentation on how we could turn a historic (1921) 65k sq ft school into an innovation hub, pilot a city wide app, roll out digital payments, mesh wifi, local shopping credits paid for by incentivized IoT and nano-data centers. They loved it and welcomed more input. I just couldn't find the support needed. Hyper local networks connected at scale, which provide value and services for all is the way forward. Inspired by the way we organized communities in the past. If you would like to collab, or have colleages interested, I'd be happy to chat. There's an open door and interested parties.
English
1
0
2
133
OpenMatter
OpenMatter@OpenMatter_·
The new regulations demand cryptographic proof of execution. We break down exactly why mathematical guardrails are now mandatory for the enterprise AI stack. Read the full issue below: open.substack.com/pub/openmatter…
English
0
0
0
21
OpenMatter
OpenMatter@OpenMatter_·
This week's newsletter covers agentic compliance and the EU AI Act. If your enterprise relies on software sandboxes to secure autonomous AI, you are shipping liability. Policy cannot prove compliance at machine speed. 🔗 👇
English
1
0
1
43
HOL
HOL@HashgraphOnline·
1/ Today we’re launching the HOL Partner Program. Cohort One brings together 30+ signed partners, including XMTP, GoDaddy, and DSR, to help shape open infrastructure for AI agents. Registries. Payments. Privacy. Security. Communication. Standards. The agent stack is forming now.
English
53
78
294
3M
OpenMatter retweetledi
OpenMatter
OpenMatter@OpenMatter_·
Treasury Sec Scott Bessent just warned AI can hack your bank account. Anthropic's Mythos proves AI can exploit software vulnerabilities at scale. OpenMatter's ZK Firewall makes unauthorized actions mathematically impossible. No cryptographic proof means no execution.
English
0
1
3
79