Ahsen

555 posts

Ahsen banner
Ahsen

Ahsen

@ahsentekd

security software engineer

Katılım Ağustos 2015
420 Takip Edilen522 Takipçiler
Ahsen retweetledi
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
538
4.1K
16.3K
12.1M
Ahsen retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨‼️"Team PCP" — the group behind the Trivy compromise — have likely hit more software vendors and repos, stealing even more credentials in the process. LiteLLM is just one of many. More disclosures are expected in the coming days. Stay alert!
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
9
51
270
25.8K
Ahsen retweetledi
vx-underground
vx-underground@vxunderground·
> be kippu > some startup app or something > idfk > goes live > people sign up > realize it's vibe coded > nerds get silly > nerds do http get on api endpoint > dumps entire database *image censored, although it's all over xitter
vx-underground tweet media
English
46
103
2.1K
97.9K
Ahsen retweetledi
OSINT Industries
OSINT Industries@OSINTindustries·
Krebs (@briankrebs) on Security used OSINT Industries to help track down operators of the Badbox 2.0 botnet: 10 million compromised Android devices. Phone numbers, emails, corporate entities connected across China. This is what proper OSINT looks like 💪🏼 Full investigation ⬇️🎯 krebsonsecurity.com/2026/01/who-op…
OSINT Industries tweet media
English
1
27
160
11.1K
Ahsen retweetledi
Mandiant (part of Google Cloud)
CORNFLAKE.V3 malware spotted in an access-as-a-service operation using the ClickFix technique. 🥣 UNC5518 uses fake CAPTCHA pages for access, which UNC5774 then leverages to deploy the CORNFLAKE.V3. Learn more: bit.ly/4mZ64a3
Mandiant (part of Google Cloud) tweet media
English
1
41
118
10.7K
Ahsen retweetledi
Tersine Mühendisler Odası
Tersine Mühendisler Odası@__TTMO__·
🔥 Tersine mühendisler, 6. toplantıya koşun! Yusuf İşlek, Ahsen Tekdemir, Celil Ünüver ve Utku Çorbacı ile, 16 Ağustos, İzmir'de. RT == MOV PC, 0x41414141414141
Tersine Mühendisler Odası tweet media
Türkçe
6
9
59
11.8K
Ahsen retweetledi
The Hacker News
The Hacker News@TheHackersNews·
🚨 RubyGems & PyPI under attack: 🔸 60 fake RubyGems stole social media logins (275K+ downloads) 🔸 PyPI fakes hijacked crypto staking wallets Both hide credential-stealing code in legit-looking packages. Details → thehackernews.com/2025/08/rubyge…
English
1
27
59
22.3K
Ahsen retweetledi
Samuel Colvin
Samuel Colvin@samuelcolvin·
New release of pytest-examples github.com/pydantic/pytes… now supports calling a function or coroutine within the example code. I'd love to rename the package so people can actually find and use it, but I can't think of a good name that's easier to search for.
English
1
2
21
2.5K
Ahsen retweetledi
numan turle
numan turle@numanturle·
In collaboration with @rizasabuncu , we promptly identified and reported a vulnerability in iOS and macOS to Apple’s security team. This vulnerability had the potential to allow unauthorized access to user activities or browsing history, even when the device was in lockdown or incognito mode. We worked closely with Apple’s security team to provide detailed information on the vulnerability and contributed to its fix. ---- support.apple.com/en-us/121250 support.apple.com/en-us/121238
numan turle tweet media
English
3
2
65
4.1K
Ahsen retweetledi
Pablo Galindo Salgado
Pablo Galindo Salgado@pyblogsal·
🐍💥Python 3.13.0 has been released! 🎉 This is the first version with 🧵experimental GIL-free mode, an experimental JIT compiler🔧, a slick new REPL 🖌️ and many new cool features! And it's faster, smarter, and more colorful than ever! 🚀 Get it here: python.org/downloads/rele…
English
18
368
1.3K
163.4K
Ahsen retweetledi
Naveen Srinivasan
Naveen Srinivasan@Naveen_Srini_·
Can your current tools cache 10,000 SBOMs transitive dependents in 30 seconds? Minefield can.
English
29
118
1.5K
2.9M