Luke Stephens (hakluke)

14.5K posts

Luke Stephens (hakluke) banner
Luke Stephens (hakluke)

Luke Stephens (hakluke)

@hakluke

Hacker, marketer. I manage socials and marketing for cybersecurity orgs. Founder of @hacker_content and @haksecio

🇦🇺🦘 Katılım Temmuz 2017
2K Takip Edilen99.6K Takipçiler
SecInterviewHub
SecInterviewHub@sec_hub93028·
Interviewer: How do attackers commonly bypass MFA? What's your response?
English
18
1
28
7K
Luke Stephens (hakluke) retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: Another supply chain attack. 700+ GitHub repositories flagged, including PHP and Node.js projects. The malicious script was planted across all of them. When a developer installs the package, the script silently downloads a Linux file from GitHub, hides it under the name /tmp/.sshd (so it looks like a normal system file), and runs it in the background. It also skips security checks on the download and hides any error messages. 8 PHP packages on Packagist (the main PHP code library) were confirmed infected. The attacker hid the script inside a JavaScript config file (package.json) instead of the PHP one (composer.json), so PHP developers reviewing their code would not notice it. The biggest risk is to devdojo/wave (6,400 stars) and devdojo/genesis (9,100 installs), both popular Laravel project templates. Developers who use these templates run the bad script the moment they install dependencies. The same payload was also dropped into GitHub Actions (automated build pipelines) under a fake step called "Dependency Cache Sync," meaning it could infect company build servers too. Packagist removed the bad packages, but the auto-updating versions (dev-main, dev-master, 3.x-dev) can quietly come back if the original repos stay infected. IOCs: GitHub account parikhpreyash4 repo systemd-network-helper-aa5c751f drop path /tmp/.sshd command fragments curl -skL and chmod +x /tmp/.sshd.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
78
559
3.2K
237.1K
Flipper Devices
Flipper Devices@flipper_net·
HIRING! Social Media Writer/Manager Responsibilities: - Publish content created by our creative team - Reply to comments - Share community content - Write text posts Requirements: - Experience in social media - Tech-savvy - Based in London Learn more: flipperdevices.com/jobs/?ashby_ji…
Flipper Devices tweet media
English
5
10
50
8.6K
Luke Stephens (hakluke) retweetledi
Flipper Devices
Flipper Devices@flipper_net·
We're finally ready to talk about Flipper One — a project we've been grinding on for years and have rebuilt from scratch several times. Read blog post >> blog.flipper.net/flipper-one-we…
English
111
544
4K
553.9K
Feross
Feross@feross·
TeamPCP just did an interview where they were asked what defenders should do to stop supply chain attacks. Their advice: pin versions to a specific hash, use least-privilege tokens, restrict IDE extensions. And then, verbatim: "The company Socket will detect the malware before the package even reaches your machine." So... thanks, I think? We're not putting this on the testimonials page. But at the same time, if you're not yet using @SocketSecurity to protect your supply chain, what are you waiting for?
Feross tweet media
English
65
139
1.1K
137.8K
Luke Stephens (hakluke) retweetledi
HackerContent
HackerContent@hacker_content·
🛑 If you're marketing a cybersecurity company - read this.  Imagine how many of your problems you could solve if there was a company that: 👉 Specialized in cybersecurity marketing specifically 👉 Had a team that was technical so that they could deeply understand your product 👉 Had worked with many of the largest companies in the world including Cisco, Google, Tenable, Semgrep, Wiz, Bugcrowd, HackerOne... 👉 Had designed and executed some of the most successful cybersecurity marketing campaigns ever 👉 Is currently managing a bunch of cybersecurity brand accounts and founder accounts on socials 👉 Wanted to work with you Wouldn't that just be a dream? hackercontent.com
English
1
2
7
1.5K
Luke Stephens (hakluke) retweetledi
Zack Korman
Zack Korman@ZackKorman·
Major companies are getting pwned by browser extensions and npm packages, but they think deploying AI agents will go fine. Good luck, have fun.
English
74
252
2K
50.2K
Gray
Gray@gray_chromatic·
Founder life in Australia 🇦🇺😭
Gray tweet media
English
10
3
85
4.5K
Luke Stephens (hakluke) retweetledi
GitHub
GitHub@github·
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
English
588
3.6K
11.5K
7.4M
Luke Stephens (hakluke) retweetledi
Claude
Claude@claudeai·
Live from Code with Claude London: we're launching self-hosted sandboxes (public beta) and MCP tunnels (research preview) in Claude Managed Agents. Run agents inside your own perimeter, with your security controls applied by default.
English
398
628
7.6K
2.3M
Luke Stephens (hakluke)
Time to go from a CVE release to exploitation was 2+ years in 2018, now it's under 1 hour.
English
0
0
10
1.5K
Luke Stephens (hakluke) retweetledi
HackerContent
HackerContent@hacker_content·
Cybersecurity marketers/founders, don't be this guy
HackerContent tweet media
English
0
1
5
945
Luke Stephens (hakluke) retweetledi
GitHub
GitHub@github·
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
English
1.7K
5.4K
25.5K
13.7M
Luke Stephens (hakluke) retweetledi
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
If you are marketing a cybersecurity company, you need to watch this 👀
English
3
4
22
3K
Luke Stephens (hakluke) retweetledi
HackerContent
HackerContent@hacker_content·
Let us handle the marketing for you.
HackerContent tweet media
English
0
1
4
803