Fredrik L. Andersen

10.3K posts

Fredrik L. Andersen banner
Fredrik L. Andersen

Fredrik L. Andersen

@ifredriks

When wireless is perfectly applied the whole earth will be converted into a huge brain - All tweets are my own - Sr Major Account Manager - Palo Alto Networks

Norway Katılım Mayıs 2011
2.6K Takip Edilen1.2K Takipçiler
Fredrik L. Andersen retweetledi
Unit 42
Unit 42@Unit42_Intel·
Offensive and defensive framework ROADtools is being misused by nation-state actors for cloud attacks. Understand how to identify the activity that signals its malicious usage, including proactive hunting for anomalous activity: bit.ly/4fyQYHB
Unit 42 tweet media
English
0
19
56
7.1K
Fredrik L. Andersen retweetledi
Evan Luthra
Evan Luthra@EvanLuthra·
🚨A HACKER GROUP JUST STOLE 4,000 OF GITHUB'S OWN PRIVATE REPOSITORIES.. PUT THEM UP FOR SALE FOR $50,000.. AND THE WAY THEY GOT IN IS THE SCARIEST PART.. They didn't hack GitHub's servers.. They poisoned a VS Code extension.. One GitHub employee installed it.. And the attackers walked through the front door using the employee's own credentials.. The group calls themselves TeamPCP.. They name their malware after the sandworms from Dune.. And they've been running the most sophisticated supply chain attack campaign in cybersecurity history.. Here's how the whole thing unfolded.. In March.. They poisoned Trivy.. One of the most trusted security scanners in the world.. Used by over 10,000 development workflows globally.. They injected credential-stealing malware into Trivy's official GitHub Action.. The malware ran silently BEFORE the security scan.. So every log showed "scan completed successfully" while the malware was stealing AWS keys, SSH credentials, database passwords, and Kubernetes tokens in the background.. It took Aqua Security 5 days to fully remove them.. Using the stolen credentials.. They breached Cisco Systems.. Cloned over 300 private repositories.. Including source code for unreleased AI products.. And repositories belonging to Cisco's customers.. Major banks.. Government agencies.. BPO firms.. In April.. They hit Checkmarx.. Another security vendor.. Poisoned 5 official Docker images in 83 minutes.. The scanner worked perfectly.. It just silently sent all your secrets to the attackers.. That automatically cascaded into Bitwarden.. The password manager.. Their CI/CD system pulled the poisoned Docker image.. And the attackers injected malware into Bitwarden's official CLI package published on npm.. One compromised security scanner poisoned a password manager.. Automatically.. No human involved.. In May.. They hit TanStack.. Libraries downloaded millions of times per week.. 84 malicious package versions across 42 packages.. And here's the terrifying part.. The malware scraped the raw memory of GitHub's build servers.. Extracted authentication tokens.. Used those tokens to bypass two-factor authentication.. And then published the infected packages with completely valid cryptographic signatures.. Every security verification tool on earth said the packages were legitimate.. Because they were signed by the real pipeline.. Using real keys.. The attackers just happened to be inside the pipeline when it signed.. They defeated the entire trust model of modern software supply chains.. The same week they hit the Nx Console VS Code extension.. 2.2 million installations.. The malware specifically targeted Claude Code configurations.. Hunting for AI assistant credentials.. That's a first.. Supply chain malware designed to steal your AI's access keys.. Then on May 19.. They revealed the GitHub breach.. 4,000 internal repositories.. Listed for sale at $50,000.. With a warning.. "If nobody buys it.. We leak everything for free".. Their malware is self-propagating.. Once it infects one package.. It automatically finds every other package that developer maintains.. Steals the publish tokens.. And infects all of them.. Then those packages infect the next developer.. And the next.. It jumps between npm and PyPI automatically.. The group doesn't even do the extortion themselves.. They sell stolen credentials to ransomware gangs.. One gang used TeamPCP's data to threaten Cisco with leaking FBI and NASA personnel records.. And the scariest part of all.. They didn't break any encryption.. They didn't find any zero-days.. They exploited the fact that the entire software industry blindly trusts its own build tools.. Every security scanner.. Every Docker image.. Every VS Code extension.. Every GitHub Action.. Is a potential weapon if someone poisons it upstream.. And right now.. Nobody can tell the difference between a legitimate build and a compromised one.. Because the compromised ones have valid signatures too.
Evan Luthra tweet mediaEvan Luthra tweet media
GitHub@github

We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.

English
168
1K
3.3K
611.8K
Fredrik L. Andersen retweetledi
NATO
NATO@NATO·
Repost to join us in celebrating our Ally 🇳🇴 Norway on its Constitution Day! @NorwayNATO 🤝 #WeAreNATO
English
74
370
1.9K
47.9K
Daniel Smidstrup
Daniel Smidstrup@DanielSmidstrup·
USA has ChatGPT USA has Grok USA has Claude USA has Gemini China has DeepSeek China has Qwen China has Kimi China has MiniMax Europe has?
Indonesia
6.4K
513
6.3K
1.4M
Fredrik L. Andersen retweetledi
NCIA
NCIA@nato_ncia·
🇳🇴 Gratulerer med dagen, Norge! 🇳🇴 Happy National Day to our Ally, Norway! As a founding #NATO Member since 1949, Norway continues to strengthen our collective defence - from protecting the skies over the Nordic region and providing capabilities for Arctic operations, to delivering advanced air defences to Ukraine 🇺🇦 #StrongerTogether #WeAreNATO #Norway @NorwayNATO @NorwayMFA
NCIA tweet media
English
4
15
101
952
Fredrik L. Andersen retweetledi
Palo Alto Networks
Palo Alto Networks@PaloAltoNtwks·
Enterprise AI may be scaling faster than your security model 🔐 See how the Equinix Distributed AI Hub + Palo Alto Networks Prisma AIRS help enterprises secure distributed AI with centralized policy, real-time guardrails and visibility across models and providers. Learn more ➡️ bit.ly/4uRgnAQ
Palo Alto Networks tweet media
English
0
2
10
1K
Fredrik L. Andersen retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 This is wild. OpenAI just confirmed it got hit in the TanStack npm supply chain attack, and the attackers were close to being able to ship malicious code inside official OpenAI software, signed and trusted, if their incident response had not caught it in time. The campaign is the work of TeamPCP, the same crew running the Mini Shai-Hulud wave. Two employee devices in OpenAI's corporate environment were compromised through the malicious TanStack packages. The attackers used that foothold to reach a limited subset of internal source code repositories. OpenAI says only "limited credential material" was successfully exfiltrated, with no customer data, production systems, intellectual property or deployed software impacted. Here is the part that should grab your attention. OpenAI is rotating its code-signing certificates and forcing every macOS user to update their OpenAI apps. You do not rotate signing certs for "limited credential material." You rotate signing certs when the attacker was close enough to signing malicious binaries as OpenAI. The "we contained it in time" framing is doing serious heavy lifting here. For wider context, the same TeamPCP wave also hit Mistral AI, UiPath, Guardrails AI, OpenSearch and SAP npm packages. The TanStack compromise is tracked as CVE-2026-45321 at CVSS 9.6, and Mistral AI source code is already being advertised for sale by the group.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
80
332
2.2K
297.5K
Fredrik L. Andersen retweetledi
CISA Cyber
CISA Cyber@CISACyber·
NEW RELEASE: Guidance on minimum elements for an AI software bill of materials. The guide, developed with G7 cyber experts, offers practical advice to enhance transparency and #Cybersecurity throughout the AI supply chain. More here 👉 go.dhs.gov/5J7
CISA Cyber tweet media
English
7
46
116
12.3K
Fredrik L. Andersen retweetledi
Palo Alto Networks
Palo Alto Networks@PaloAltoNtwks·
"We're going to have millions of agents floating around in the IT infrastructure. All these agents need to be identified. All these agents need to be understood. All their data needs to be brought together.” - @nikesharora That's exactly why we introduced Idira™ today at CyberArk IMPACT 2026, our next-gen identity security platform built to secure every human, machine, and agentic identity.
Palo Alto Networks tweet mediaPalo Alto Networks tweet mediaPalo Alto Networks tweet mediaPalo Alto Networks tweet media
English
1
3
10
1.1K
Fredrik L. Andersen retweetledi
Will Townsend
Will Townsend@WillTownTech·
Looking forward to spending time this week with @PaloAltoNtwks at @CyberArk Impact in Austin! Stay tuned for my live insights from the event and a LoneStar Advisory & Research note capturing my three big takeways ⬇️
English
1
2
6
1.1K
Dashrath Mundkar
Dashrath Mundkar@dashmundkar·
Your new Azure VM can't reach the internet. That's not a bug → it's the new default. After March 31, 2026, every new VNet ships private by default. No NAT Gateway = no apt update, no Windows Update. Nothing. 👇 Why Microsoft killed default outbound: ❌ IP owned by Microsoft — could change anytime ❌ No ICMP, no fragmented packets ❌ Inconsistent across NICs & VMSS ❌ Zero Trust violation by design Your 4 fixes (in order): ✅ NAT Gateway ← do this Standard LB + outbound rules Instance-level public IP Firewall/NVA + UDR Why NAT Gateway wins: → 64,000 SNAT ports per IP (vs ~64) → Scales to 1M+ ports → You own the egress IP → Attach once per subnet. Done. The migration (don't skip step 4): Find affected NICs → Advisor → Operational Excellence Attach NAT Gateway to the subnet Set defaultOutboundAccess = false Stop + deallocate the VMs ← everyone forgets Start. Verify egress IP. Gotchas: ⚠️ Old Terraform AzureRM → still permissive ⚠️ LB backend pool by IP → leaks default outbound ⚠️ Windows Activation/Update → silently fails The lesson: Implicit defaults feel free. They're never free. You pay at 3 AM when an IP rotates or SNAT ports dry up. Explicit > implicit. Always.
Dashrath Mundkar tweet media
English
5
21
115
16K
Fredrik L. Andersen retweetledi
Unit 42
Unit 42@Unit42_Intel·
Copy Fail (CVE-2026-31431) is a critical privilege escalation in the Linux kernel's crypto subsystem. Attackers can stealthily write to page cache, bypassing integrity checks. This impacts Kubernetes, multi-tenant hosts and CI/CD. Details: bit.ly/4cTVWgs
Unit 42 tweet media
English
4
28
88
8.8K
Fredrik L. Andersen retweetledi
Cyber Security News
Cyber Security News@The_Cyber_News·
⚠️ Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch Source: cybersecuritynews.com/microsoft-edge… Microsoft Edge decrypts every stored password into process memory the moment the browser launches and keeps them there as cleartext, regardless of whether the user ever visits those sites. A researcher who systematically tested every major Chromium-based browser for credential memory handling behavior. Edge was the only browser that exhibited this behavior, loading the entire password vault into plaintext process memory at startup and retaining it for the duration of the session. In a published proof-of-concept video accompanying the disclosure, a compromised administrator account was used to successfully extract stored credentials. #cybersecuritynews
Cyber Security News tweet media
English
24
249
923
68.5K