bood

3.4K posts

bood banner
bood

bood

@_Bood

▶️ https://t.co/ayv0OsqLYX

Nuevo León, México Katılım Ağustos 2011
490 Takip Edilen203 Takipçiler
bood retweetledi
basil
basil@BasiilLeaf·
new hobby just dropped
basil tweet media
English
66
2.3K
21.6K
366.2K
bood
bood@_Bood·
Weekly armory #1 R1 Marlynn ⚔️ R2 Gravy ⚔️ R3 Dash IO ⚔️ R4 Mario ❌ Armory #2 R1 Vynnset ⚔️ R2 Dash IO ⚔️ R3 Oscilio ❌ #fabtcg
bood tweet media
CY
0
0
0
103
bood retweetledi
Luis Lira 👾
Luis Lira 👾@Luis_LiraC·
El ecosistema de JavaScript en estos momentos se siente así
Luis Lira 👾 tweet media
Español
0
1
12
253
bood retweetledi
Ojos color sol
Ojos color sol@ojoscol0rsol·
Ojos color sol tweet media
ZXX
5
4.8K
16.3K
209.2K
bood
bood@_Bood·
Semana de testeo ☠️ #fabtcg
bood tweet media
Español
0
0
0
72
bood retweetledi
Karthik
Karthik@karthikponna19·
"it worked on production just like it did on localhost"
English
126
1.2K
14.6K
512.8K
bood retweetledi
Andrew Brown
Andrew Brown@andrewbrown·
If we are redesigning GitHub lets do it in the style of Final Fantasy / Dragon Quest.
Andrew Brown tweet media
English
101
402
3.8K
129K
bood retweetledi
Gajus
Gajus@kuizinas·
There is a surge of supply chain attacks (and it is only going to get worse) If you are using pnpm, take these steps to protect yourself: * set minimumReleaseAge to 7 days * set blockExoticSubdeps to true * configure onlyBuiltDependencies npm / yarn have similar settings
Socket@SocketSecurity

🚨 We’ve confirmed the intercom-client@7.0.4 was compromised in the ongoing Mini Shai-Hulud worm attack. The npm package includes a malicious preinstall hook that downloads and executes an unverified Bun binary, then runs an 11.7 MB obfuscated payload designed to steal Kubernetes, Vault, cloud, GitHub, and CI/CD secrets. The attack closely overlaps with the SAP CAP, Cloud MTA, and lightning@2.6.2 compromises.

English
13
65
716
141.3K
bood retweetledi
Flesh and Blood
Flesh and Blood@fabtcg·
Learn from the best with a monthly Masterclass lesson from renowned pro player Yuki Lee Bender! ⚡️ This month, Yuki breaks down a critically important element of Flesh and Blood – defending 🛡️ Learn when and why to defend, and more: buff.ly/RKi99QW
Flesh and Blood tweet media
English
0
31
112
6.3K
bood retweetledi
trash
trash@trashh_dev·
mood
trash tweet media
English
18
78
1.1K
22K
bood retweetledi
Christoffer Bjelke
Christoffer Bjelke@chribjel·
Ai generated prs be like
Christoffer Bjelke tweet media
English
22
212
4.2K
112.2K
bood retweetledi
Sarah Gooding
Sarah Gooding@sarahgooding·
TL;DR: - Maintainer controls the unscoped tanstack npm package - README presents it as “TanStack Player” - Package is not affiliated with TanStack - Maintainer demands $10k from TanStack creator - TanStack files legal docs related to a pending trademark infringement claim - No response from npm on the brand-squatting - Package later ships malware that steals .env files This is another form of abuse OSS maintainers are forced to deal with: brand impersonation, extortion attempts, and platform inaction until users are finally exposed to malware.
Socket@SocketSecurity

🚨 A brand-squatting npm package impersonating TanStack shipped malicious versions that exfiltrate environment variables from developers’ machines during install. We spoke to @tannerlinsley, creator of @tan_stack, who confirmed that the maintainer of the unscoped tanstack package is not associated with TanStack or the official @tanstack/* projects in any way. The package is unrelated to the project's official CLI, and represents an ongoing brandjacking issue. He also said TanStack has filed legal documents related to a pending trademark infringement claim against the maintainer, that the maintainer previously demanded $10,000 from him, and that TanStack has repeatedly tried, unsuccessfully, to get @npmjs to address the situation.

English
2
28
293
28.9K
bood retweetledi
Socket
Socket@SocketSecurity·
🚨 BREAKING: Socket and @Docker uncovered what appears to be a broader Checkmarx supply chain compromise affecting official KICS Docker images and recent Checkmarx VS Code extension releases. We found malicious images in the official checkmarx/kics Docker Hub repo, including overwritten tags and a new tag outside the normal release flow. Our analysis also found signs that recent Checkmarx extension releases introduced code capable of downloading and executing what appears to be a malicious remote addon. We’re in touch with the Checkmarx team and still investigating the incident.
English
23
144
583
186.6K
bood retweetledi
Het Mehta
Het Mehta@hetmehtaa·
OWASP just dropped APTS A governance standard for autonomous pentesting platforms. Not a methodology. A control layer. Focus: scope enforcement, safe autonomy, manipulation resistance, accountability. As AI-driven testing scales, this is the guardrail the industry needed. github.com/OWASP/APTS
Het Mehta tweet media
English
4
103
425
31.2K
bood retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
Oh my, if you're having a bad day you should look at this person's day. 💀
International Cyber Digest tweet media
English
105
88
2.9K
258.2K