Tali Ash

152 posts

Tali Ash

Tali Ash

@Taliash1

CyberSecurity PM

Katılım Mart 2019
94 Takip Edilen631 Takipçiler
Tali Ash retweetledi
Koidex
Koidex@GetKoidex·
Trust Wallet's Chrome extension was compromised on Christmas Eve. $7M drained. We dug into the code. The attack was worse than reported - it triggered on every unlock, not just seed phrase imports. Full technical breakdown: koi.ai/blog/trust-wal… #TrustWallet
English
0
3
8
717
Tali Ash retweetledi
Koidex
Koidex@GetKoidex·
🚨 𝗪𝗲'𝘃𝗲 𝘂𝗻𝗰𝗼𝘃𝗲𝗿𝗲𝗱 𝘁𝗵𝗲 𝗳𝗶𝗿𝘀𝘁 𝗺𝗮𝗹𝗶𝗰𝗶𝗼𝘂𝘀 𝗠𝗖𝗣 𝘀𝗲𝗿𝘃𝗲𝗿 𝗶𝗻 𝘁𝗵𝗲 𝘄𝗶𝗹𝗱. It was only a matter of time. The postmark-mcp npm package (1,500+ weekly downloads) has been backdoored since v1.0.16 - silently BCCing every email to the attacker's server. The developer built trust through 15 legitimate versions, then added one line of code that compromised everyone. When confronted, they deleted the package to cover tracks, but existing installations are still actively leaking emails. If you're using postmark-mcp, uninstall it NOW. This is what happens when we give anonymous developers god-mode access to our AI assistants with zero security controls.
Koidex tweet media
English
16
147
433
93.5K
Tali Ash retweetledi
Koidex
Koidex@GetKoidex·
🚨 𝗕𝗥𝗘𝗔𝗞𝗜𝗡𝗚: 𝗢𝗻𝗴𝗼𝗶𝗻𝗴 𝗻𝗽𝗺 𝘀𝘂𝗽𝗽𝗹𝘆 𝗰𝗵𝗮𝗶𝗻 𝗮𝘁𝘁𝗮𝗰𝗸 Hundreds of packages compromised — millions at risk. ⚠️ Malware drops 𝗯𝘂𝗻𝗱𝗹𝗲.𝗷𝘀, steals secrets w/ 𝗧𝗿𝘂𝗳𝗳𝗹𝗲𝗛𝗼𝗴, writes rogue 𝗚𝗶𝘁𝗛𝘂𝗯 𝗔𝗰𝘁𝗶𝗼𝗻𝘀, spreads in 𝗿𝗲𝗮𝗹 𝘁𝗶𝗺𝗲. 📦 Notable: @𝗰𝘁𝗿𝗹/𝘁𝗶𝗻𝘆𝗰𝗼𝗹𝗼𝗿, 𝗻𝗴𝘅-𝘁𝗼𝗮𝘀𝘁𝗿, 𝗸𝗼𝗮𝟮-𝘀𝘄𝗮𝗴𝗴𝗲𝗿-𝘂𝗶, CrowdStrike pkgs. 📌 𝗟𝗶𝘃𝗲 𝘁𝗿𝗮𝗰𝗸𝗲𝗿 → koi.security/blog/shai-hulu… #npm #infosec #supplychain #nodejs
English
0
1
7
266
Tali Ash retweetledi
Koidex
Koidex@GetKoidex·
🚨 Using Axiom for trading? A new Firefox extension is targeting you. It claims "100% local execution" Reality? It steals your credentials + wallet info, sends them to a remote server, and hides behind obfuscation and anti-detection. Always verify in Koidex ID: axiomtool
Koidex tweet media
English
1
3
11
1.4K
Tali Ash retweetledi
Koidex
Koidex@GetKoidex·
🚨 Edge users beware! The “Video Downloader” extension (video-downloader) is stealing all your cookies and sending them to an external server. This isn’t a downloader - it’s a data exfiltration tool. Extension ID: agkcnnlfkebmgmohngapnkfihefhkoia
Koidex tweet media
English
0
1
7
185
Tali Ash
Tali Ash@Taliash1·
Vital work. This is exactly why supply-chain security matters.
Koidex@GetKoidex

🚨 Marketplace Takeover: Millions at Risk 🚨 Today, we’re lifting the embargo on one of the most critical supply-chain vulnerabilities we’ve ever seen. Our team at Koi Security discovered a flaw in Open-VSX - the open extension marketplace used by over 8 million developers across VSCode forks like @cursor_ai , @windsurf_ai , Firebase Studio, and many more. Through a misconfigured CI workflow, a malicious actor could silently overwrite every extension in the marketplace. Full control over millions of dev machines. This was a SolarWinds-class risk for developer tooling. We responsibly disclosed the bug in May, worked closely with the Eclipse Foundation on the fix, and today we’re sharing the full write-up — because the ecosystem deserves transparency and protection.

English
0
0
1
125
Tali Ash
Tali Ash@Taliash1·
The easiest malware distribution channel to your org
English
0
0
1
110
Tali Ash retweetledi
Michael Sutton
Michael Sutton@michaelsuttonil·
Imagine being an American post 9/11, but instead of mourning your people you are busy convincing the world that the twin towers actually existed, that airplains literally crashed into them, that actual people were jumping down. This is how I feel wandering around here these days
English
46
101
379
30.9K
Tali Ash retweetledi
Amir Barkol
Amir Barkol@BarkolAmir·
His name is Tarek Abu-Arar, an Arab Muslim Israeli doctor. On a Saturday morning, he was driving to his hospital shift when he suddenly came across a person lying by the roadside. When he got out of the car and approached to help, that person shot Tarek. He was a Hamas terrorist. Suddenly, ten more terrorists emerged from the bushes, taking him at gunpoint as a hostage while continuing to shoot at passing cars and kill civilians. When the military forces arrived, the fucking terrorists used Tarek as their human shield, all while he bled profusely and prayed in Arabic for mercy. Throughout this nightmare, the terrorists knew Tarek was an Arab, they knew he was a Muslim, and they simply didn't care. Tarek was eventually rescued and remained alive by a miracle, but many Arab-Israeli lives have been taken by Hamas on that tragic day. To Hamas, it doesn't matter if you're Muslim or Jewish; their only faith is in murder. Please share #HamasisISIS
Amir Barkol tweet media
English
366
2.2K
5.9K
471.2K
Satya Nadella
Satya Nadella@satyanadella·
Heartbroken by the horrific terrorist attacks on Israel and the escalating conflict. My deepest condolences are with all those killed and impacted. Our focus remains on ensuring the safety of our employees and their families. Below is a message we shared with Microsoft employees today about our response. blogs.microsoft.com/blog/2023/10/1…
English
325
351
3.4K
636.9K
Tali Ash
Tali Ash@Taliash1·
@POTUS Thank you🇮🇱🇮🇱🇮🇱🇮🇱🫶🏽🫶🏽🫶🏽🫶🏽🤍🤍🤍🤍
English
0
0
0
32
President Biden Archived
President Biden Archived@POTUS46Archive·
There are moments in this life where pure evil is unleashed on the world – the people of Israel experienced one this past weekend. This is terrorism.
English
8.9K
3.9K
19.7K
2.7M
Tali Ash retweetledi
Trey Yingst
Trey Yingst@TreyYingst·
Imagine the worst things possible that can be done to humans. Hamas did all of that and more to Israeli civilians. Babies beheaded. People burned alive in their homes. Women raped and dragged through the streets. Don’t look away.
English
3.7K
15.5K
46.1K
6.6M
Tali Ash retweetledi
Pawel Partyka
Pawel Partyka@Pawp81·
#AdvancedHunting AADSignInEventsBeta table now includes EndpointCall field which indicates Azure AD endpoint involved in the request (including MFA requests: SAS:BeginAuth, SAS:ProcessAuth, SAS:EndAuth EndpointCalls). Happy hunting! #M365D
Pawel Partyka tweet media
English
1
33
95
0