baas

1.6K posts

baas banner
baas

baas

@baas

HTB CAPE | OSEP | OSCP | CARTE | CRTO | CRTP

Katılım Mayıs 2008
433 Takip Edilen744 Takipçiler
baas retweetledi
Aikido Security
Aikido Security@AikidoSecurity·
Update 5:05 PT: The attack has now expanded well beyond @TanStack and @Mistral. 373 malicious package-version entries across 169 npm package names, including @uipath, @squawk, @tallyui, @beproduct, and more. The malware propagates by stealing your CI credentials and using them to publish new compromised versions. Full IOCs, affected package list, and detection steps: aikido.dev/blog/mini-shai…
Aikido Security@AikidoSecurity

🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.

English
76
492
2.6K
2.4M
baas retweetledi
Microsoft Threat Intelligence
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
Microsoft Threat Intelligence tweet media
English
117
698
4.9K
4.1M
baas retweetledi
Tom Jøran Sønstebyseter Rønning
Tom Jøran Sønstebyseter Rønning@L1v1ng0ffTh3L4N·
Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them.
English
251
1.4K
8.9K
1.5M
baas retweetledi
Dark Web Informer
Dark Web Informer@DarkWebInformer·
‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017. Website: copy.fail Write-up: xint.io/blog/copy-fail… GitHub: github.com/theori-io/copy… It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su. Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise. Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.
English
60
827
3.3K
399.2K
baas retweetledi
RTL Nieuws
RTL Nieuws@RTLnieuws·
Bijna alle inwoners van Epe getroffen door datalek, 500.000 bestanden gestolen rtl.nl/nieuws/binnenl…
Nederlands
0
25
25
16.6K
baas retweetledi
impulsive
impulsive@weezerOSINT·
Lovable has a mass data breach affecting every project created before november 2025. I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account. nvidia, microsoft, uber, and spotify employees all have accounts. the bug was reported 48 days ago. its not fixed. They marked it as duplicate and left it open.
impulsive tweet mediaimpulsive tweet mediaimpulsive tweet media
English
269
722
5.7K
1.4M
baas retweetledi
K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵
hackers as the first group to embrace KYC for access to new models is cutting me deep. we used to be rebels
English
21
40
376
25.5K
baas retweetledi
baas retweetledi
Adam Back
Adam Back@adam3us·
i'm not satoshi, but I was early in laser focus on the positive societal implications of cryptography, online privacy and electronic cash, hence my ~1992 onwards active interest in applied research on ecash, privacy tech on cypherpunks list which led to hashcash and other ideas.
English
2K
3.5K
28.6K
3M
baas retweetledi
Claude
Claude@claudeai·
You can now enable Claude to use your computer to complete tasks. It opens your apps, navigates your browser, fills in spreadsheets—anything you'd do sitting at your desk. Research preview in Claude Cowork and Claude Code, macOS only.
English
4.9K
14.5K
139.3K
77.9M