Pasi-Pekka Karppinen

736 posts

Pasi-Pekka Karppinen banner
Pasi-Pekka Karppinen

Pasi-Pekka Karppinen

@ppkarppi

Curious explorer. One of the odd ones who enjoy the road less traveled. Someone somewhere in summertime.

Earth Katılım Şubat 2010
2.4K Takip Edilen505 Takipçiler
Pasi-Pekka Karppinen retweetledi
Wholesome Side of 𝕏
Wholesome Side of 𝕏@itsme_urstruly·
I can't properly describe to anyone under the age of 30 just how cool the Internet was before Amazon, Google, Meta, and Apple turned it all into a walled garden of garbage and commerce.
English
40
140
1.1K
11.2K
Pasi-Pekka Karppinen retweetledi
⭕ AI & Design (Marco)
⭕ AI & Design (Marco)@AIandDesign·
I'm not gonna lie, the @Meta layoffs are some of the most dystopian I've ever seen. They got told to work from home, they were sent the emails at 4AM in the morning. Those who weren't impacted have software on their computer that tracks their every move, preparing AI to take their job as well. They're literally training the AI that will eliminate their position as well. Meanwhile, Meta is raking in RECORD PROFITS. I am a massive, unapologetic AI enthusiast. Yet, this is NOT the future I had in mind. I wish for Meta to crash and burn. This is not the way. Literally nobody benefits from this.
English
1.9K
3.5K
27.6K
2.9M
Pasi-Pekka Karppinen retweetledi
Dark Web Informer
Dark Web Informer@DarkWebInformer·
🚨 GitHub source code allegedly offered for sale: Internal orgs and private repositories claimed A threat actor using the alias TeamPCP claims to be selling GitHub source code and internal organization data. The actor claims the dataset includes around 4,000 private repositories and says samples can be provided to interested buyers to verify authenticity. ━━━━━━━━━━━━━━━━━━━━ Target: GitHub Country: United States Sector: Technology / Software Development / Source Code Incident Type: Alleged Source Code Sale Claimed Exposure: Around 4,000 private repositories Actor: TeamPCP Price: Offers over $50,000 ━━━━━━━━━━━━━━━━━━━━ According to the post, the actor claims the material includes source code and internal organization data tied to GitHub’s main platform. The post also references a public file list and includes screenshots showing numerous repository archive names. Why it matters: If authentic, exposed source code and internal repository data could increase the risk of code review by hostile actors, vulnerability discovery, supply chain targeting, impersonation, phishing, and follow-on attacks against developer infrastructure. Status: This remains an unverified underground forum claim. The actor states this is not a ransom attempt and claims the data may be leaked publicly if no buyer is found. Stop guessing what's redacted. Subscribers see everything → darkwebinformer.com/pricing
Dark Web Informer tweet mediaDark Web Informer tweet media
English
18
127
597
99K
Pasi-Pekka Karppinen retweetledi
GitHub
GitHub@github·
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
English
1.7K
5.4K
25.5K
13.7M
Pasi-Pekka Karppinen retweetledi
POLITICOEurope
POLITICOEurope@POLITICOEurope·
EXCLUSIVE: Several Chinese tech companies have recently stopped updating previously open AI models, which could indicate they're moving development behind closed doors, Germany’s cyber chief has warned. 🔗 politico.eu/article/china-…
POLITICOEurope tweet media
English
5
38
69
19.5K
Pasi-Pekka Karppinen retweetledi
Glenn Tunes
Glenn Tunes@glenn_tunes·
Elon Musk fucked up twitter 🤷
English
58
85
945
8.9K
Pasi-Pekka Karppinen retweetledi
Andrew Curran
Andrew Curran@AndrewCurran_·
Mythos has cracked MacOS. It took five days.
Andrew Curran tweet media
English
91
366
3.9K
591.7K
Pasi-Pekka Karppinen retweetledi
News from Google
News from Google@NewsFromGoogle·
The Google Threat Intelligence Group has detected the first known instance of a threat actor using an AI-developed zero-day exploit in the wild. While the attackers planned a wide-scale strike, our proactive counter-discovery may have prevented that from happening. This finding is part of our new report on AI-powered threats.
English
310
1.7K
13.9K
5.1M
Pasi-Pekka Karppinen retweetledi
Pasi-Pekka Karppinen retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
❗️ UPDATE on today's npm supply-chain attack: • Per Socket Security: 121 more compromised package artifacts found across 84 additional package names. 64 of them are UiPath artifacts. • Combined with the earlier TanStack hits, the current known total is 205 affected npm package artifacts. • Reach now spans enterprise automation, AI/MCP, auth, workflow, and dev tooling. The worm is still propagating.
International Cyber Digest@IntCyberDigest

‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.

English
9
84
507
83.3K
Pasi-Pekka Karppinen retweetledi
The Hacker News
The Hacker News@TheHackersNews·
⚠️ RubyGems has suspended new signups after a major malicious attack involving hundreds of packages, some reportedly carrying exploits. The incident raises fresh concerns over open-source supply chain security. Details here: thehackernews.com/2026/05/rubyge…
English
5
64
158
22.5K
Pasi-Pekka Karppinen retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
International Cyber Digest@IntCyberDigest

‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.

English
129
745
4K
2.7M
Pasi-Pekka Karppinen retweetledi
Aikido Security
Aikido Security@AikidoSecurity·
🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.
Aikido Security@AikidoSecurity

🚨 Update: Mini Shai-Hulud supply chain attack is back and hit the TanStack npm ecosystem today. At least 84 packages were compromised in two waves starting at 19:20 UTC. @tanstack/react-router, @tanstack/history, @tanstack/router-core, and dozens more across tens of millions of weekly downloads. This is likely from the same TeamPCP campaign behind the SAP npm compromise two weeks ago. If you ran npm install on any @ tanstack package today, treat your environment as compromised. Rotate GitHub tokens, npm tokens, cloud credentials, and CI secrets immediately. Tanner Linsley confirmed affected versions have been unpublished.

English
21
125
768
838.6K
Pasi-Pekka Karppinen retweetledi
soothsayer
soothsayer@iamasoothsayer·
2023: Corona ended 2026: Hantavirus
Català
30.1K
93K
412.8K
0
Pasi-Pekka Karppinen retweetledi
░ perfectloop ░
░ perfectloop ░@PERFECTL00P·
𝙵𝚊𝚒𝚛𝚕𝚒𝚐𝚑𝚝 𝚛𝚞𝚗𝚗𝚎𝚛 🎹🖥️⌨️
GIF
English
22
178
1.5K
68.2K
Pasi-Pekka Karppinen retweetledi
Hackster.io
Hackster.io@Hacksterio·
The Apple Lisa is back! The open source LisaFPGA Project recreates the legendary 1983 machine with modern essentials like HDMI and USB. hackster.io/news/the-1983-…
English
4
86
297
13.5K
Pasi-Pekka Karppinen retweetledi
Ericland_Jazz
Ericland_Jazz@ericmasaki·
Jazz & Cafe Bar Crescent 理想のジャズ喫茶 完璧すぎる #ジャズ喫茶 #jazzkissa
Ericland_Jazz tweet mediaEricland_Jazz tweet mediaEricland_Jazz tweet media
日本語
1
11
220
7.5K
Pasi-Pekka Karppinen retweetledi
TaraBull
TaraBull@TaraBull·
Rick Springfield is 76 years old 🤯
English
719
587
6.5K
336.1K