
Mangel Sánchez
7.8K posts

Mangel Sánchez
@slaimer
Ingeniero de Software 💻 - Senior Backend Developer en @secture_com 🏴☠️ - Podcaster en @LeyendoSciFi 🎤- Escribo en https://t.co/bwxDOqs0KV…


‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.



🚨 BREAKING: New Linux zero-day "Dirty Frag" lets ANY local user become root on most major distros. The PoC is already public, half of it isn't patched yet. Discovered by researcher Hyunwoo Kim, the exploit chains two kernel bugs and sits in the same family as Dirty Pipe and Copy Fail. ▪️ CVE-2026-43284 (xfrm-ESP Page-Cache Write): patched in mainline Linux. ▪️ CVE-2026-43500 (RxRPC Page-Cache Write): NO PATCH yet. The exploit is reliable by design. Attackers don't have to win a timing race, the system won't crash and alert anyone if it fails, and it succeeds nearly every run. The embargo got broken before distros could ship fixes, so the working code is now sitting on GitHub. Confirmed working on: Ubuntu 24.04.4, RHEL 10.1, openSUSE Tumbleweed, CentOS Stream 10, AlmaLinux 10, Fedora 44.















El rey Juan Carlos asistió a la tradicional corrida del Domingo de Resurrección en Sevilla, acompañado por la infanta Elena.

Programa especial de urgencia sobre el lanzamiento de la misión Artemisa 2, la primera tripulada con destino a la Luna desde hace mas de 50 años. Radio Skylab no podía perder esta ocasión y cuenta con la plantilla al completo. Todo listo, ¡Despegamos! radioskylab.es/2026/04/04/2x0…

🔴Trump admite que envió armas a los manifestantes iraníes durante las protestas de principios de año con la esperanza de fomentar un levantamiento contra el estamento clerical del país: "Un montón de armas que enviamos a través de los kurdos" europapress.es/internacional/…









