sibuser

491 posts

sibuser

sibuser

@SibuserNsk

Head of Security at Gateway FM

Sweden Katılım Mart 2014
102 Takip Edilen57 Takipçiler
Adam Gordon
Adam Gordon@Adam_ITProTV·
Welcome to the #cissp 'Q of the D' !!!! Question 1747 / Day 1747 - DOMAIN - Security Assessment & Testing: (correct answer to be provided tomorrow) Show how smart you are & post your answers #cisspsuccess #isc2 #themoreyouknow
Adam Gordon tweet media
English
9
1
2
247
Adam Gordon
Adam Gordon@Adam_ITProTV·
Welcome to the #cissp 'Q of the D' !!!! Question 1746 / Day 1746 - DOMAIN - Security Assessment & Testing: (correct answer to be provided tomorrow) Show how smart you are & post your answers #cisspsuccess #isc2 #themoreyouknow
Adam Gordon tweet media
English
7
0
3
223
Adam Gordon
Adam Gordon@Adam_ITProTV·
Welcome to the #cissp 'Q of the D' !!!! Question 1744 / Day 1744 - DOMAIN - Security and Risk Management: (correct answer to be provided tomorrow) Show how smart you are & post your answers #cisspsuccess #isc2 #themoreyouknow
Adam Gordon tweet media
English
7
0
4
223
Tony Dang
Tony Dang@dangtony98·
Agents should NOT be reading your .env files. Yes, that’s Claude, Cursor, Codex you name it. Infisical CLI throws .env into the dust bin and lets you store/inject environment variables into your dev process. Leaving your secrets out there in plaintext is just bad security hygiene and you deserve better.
Infisical@infisical

Rest in peace, .env. You served us well but you gotta go. Infisical fetches secrets at runtime so they never touch disk. CLI works with any language + SDKs and infra integrations. Docs below.

English
10
12
135
24.9K
Adam Gordon
Adam Gordon@Adam_ITProTV·
Welcome to the #cissp 'Q of the D' !!!! Question 1742 / Day 1742 - DOMAIN - Security and Risk Management: (correct answer to be provided tomorrow) Show how smart you are & post your answers #cisspsuccess #isc2 #themoreyouknow
Adam Gordon tweet media
English
7
0
4
229
Adam Gordon
Adam Gordon@Adam_ITProTV·
Welcome to the #cissp 'Q of the D' !!!! Question 1741 / Day 1741 - DOMAIN - Security and Risk Management: (correct answer to be provided tomorrow) Show how smart you are & post your answers #cisspsuccess #isc2 #themoreyouknow
Adam Gordon tweet media
English
7
1
3
253
sibuser retweetledi
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
545
4.1K
16.3K
12.2M
sibuser
sibuser@SibuserNsk·
@linuxcity It should be delivered to your door in printing😂
English
0
0
1
14
Zhe
Zhe@linuxcity·
Maybe the font size and the number of confirms should scale with the size of the transaction? For $50M the font should fill up the whole phone screen.
Stani@StaniKulechov

Earlier today, a user attempted to buy AAVE using $50M USDT through the Aave interface. Given the unusually large size of the single order, the Aave interface, like most trading interfaces, warned the user about extraordinary slippage and required confirmation via a checkbox. The user confirmed the warning on their mobile device and proceeded with the swap, accepting the high slippage, which ultimately resulted in receiving only 324 AAVE in return. The transaction could not be moved forward without the user explicitly accepting the risk through the confirmation checkbox. The CoW Swap routers functioned as intended, and the integration followed standard industry practices. However, while the user was able to proceed with the swap, the final outcome was clearly far from optimal. Events like this do occur in DeFi, but the scale of this transaction was significantly larger than what is typically seen in the space. We sympathize with the user and will try to make a contact with the user and we will return $600K in fees collected from the transaction. The key takeaway is that while DeFi should remain open and permissionless, allowing users to perform transactions freely, there are additional guardrails the industry can build to better protect users. Our team will be investigating ways to improve these safeguards going forward.

English
1
0
1
147
sibuser
sibuser@SibuserNsk·
Everyday as a security officer i need to check multiple systems but thanks to ai i can build a tailor solution to automate my work in a way I need. Using ai to build non ai projects.
English
0
0
0
12
Zhe
Zhe@linuxcity·
@levelsio @sama You can get them for around 800 eur in Sweden 🙈
English
1
0
2
56
@levelsio
@levelsio@levelsio·
That 64GB ram stick I bought 2 months ago for $350 is now goes for $2500 because of @sama buying up 40% of the RAM supply in the world Should I sell them? I have 2 sets of these actually so it'd be $5000? Or about $4300 profit 😂 I won't but damn that's crazy!
@levelsio tweet media@levelsio tweet media
@levelsio@levelsio

Anyone know why GPU PC won't boot, just goes max fan and no video: I just upgraded 2x 32GB Corsair Vengeance sticks and added to 2 more, so 4x They're DDR5 6400MHz 64GB 2x32GB CL32 RAM Motherboard is ASUS ROG STRIX X870E-E GAMING WIFI ChatGPT says it's cause it can't handle 4x RAM sticks at 6400MHz? So you gotta push the MHz down in BIOS? But also sounds like it's hallucinating

English
149
87
2K
688.1K
sibuser
sibuser@SibuserNsk·
@vas3k @sult Да, книга супер. Одно из эпичных осознаний было что если люди забудут как писать или говорить, то этот навык придется изобретать
Русский
0
0
3
120
Вастрики
Вастрики@vas3k·
@sult О, книжка топ, одна из любимых!
Русский
1
0
17
3.2K
Sultee
Sultee@sult·
Не могу устоять между маленькими дурацкими контейнерами (книжка для масштаба)
Sultee tweet media
Українська
6
0
39
5.5K
Zhe
Zhe@linuxcity·
I have nothing to hide but I f**king hate KYC.
English
1
0
1
45
sibuser
sibuser@SibuserNsk·
@TrustVanta It’s been almost two weeks of back-and-forth with support, and there’s still no solution to fix an issue blocking a feature we’re paying for.
English
0
0
0
13
sibuser
sibuser@SibuserNsk·
GitHub personal access tokens are bad and evil. But you still need them to use GitHub Packages, since fine-grained tokens don’t support it 😪 So… npmjs it is.
English
0
0
0
30
sibuser
sibuser@SibuserNsk·
Bought flipper zero a year ago and still find it very useful tool.
English
0
0
0
35
sibuser
sibuser@SibuserNsk·
But here’s the twist: no matter how fast we go, we eventually adapt. The new speed becomes normal — the new gear 1.
English
0
0
1
9
sibuser
sibuser@SibuserNsk·
AI agents showed up and boom — gear 4. And if you run multiple agents in parallel? The acceleration is unreal.
English
1
0
0
11
sibuser
sibuser@SibuserNsk·
When you shift gears in a car, you feel the speed — until it becomes the new normal. Same with technology and our abilities.
English
1
0
1
15