Anatolij Vasilev

279 posts

Anatolij Vasilev banner
Anatolij Vasilev

Anatolij Vasilev

@tolik518

Dev with ADHD digging into everything and everywhere all at once. InfoSec, Gameboy stuff, Rust

Katılım Ağustos 2021
106 Takip Edilen23 Takipçiler
Anatolij Vasilev retweetledi
Mare
Mare@Mvresy·
🚨 Arch Linux AUR Supply Chain Attack: Hundreds to ~1,250 Packages Compromised Attacker posed as maintainer, adopted orphaned packages, and added malicious code to PKGBUILD/.install scripts (npm/Bun deps). Rust infostealer targets creds (SSH, browser, GitHub, Discord etc.). Optional eBPF rootkit if run as root. Actions: Audit recent AUR installs (since ~June 9), review PKGBUILDs, rotate creds if affected. Verify all AUR packages. Credits to @IntCyberDigest
Mare tweet mediaMare tweet media
English
1
2
8
459
Loftwah
Loftwah@loftwah·
I still think about the guy who posted a rant on GitHub asking where the EXE file was.
English
7
0
56
2.8K
The Hacker News
The Hacker News@TheHackersNews·
🚨 Hackers can now hijack AI coding agents with fake Sentry errors. No phishing. No malware. No server break-in. Agentjacking tricks tools like #ClaudeCode and Cursor into reading planted error reports as trusted fix steps, then running attacker code with developer privileges. Researchers tested it on 100+ organizations. Success rate: 85%. Read: thehackernews.com/2026/06/agentj…
The Hacker News tweet media
English
15
50
133
14.1K
Anatolij Vasilev retweetledi
Aikido Security
Aikido Security@AikidoSecurity·
npm v12 will stop running dependency install scripts by default. Postinstall scripts have powered many recent npm supply chain attacks, from Nx s1ngularity to Shai-Hulud. It won’t solve everything, and it should not have taken this long, but it closes a very real attack path.
Aikido Security tweet media
English
1
7
37
5.4K
Anatolij Vasilev retweetledi
The Hacker News
The Hacker News@TheHackersNews·
AI is changing vulnerability management fast. New flaws can now be found by the thousands, and exploit timelines are shrinking to hours. But Verizon says known-exploited vulnerabilities still take a median 43 days to fix. That gap is now the real risk. Why patching alone is no longer enough: thehackernews.com/2026/06/ai-bro…
The Hacker News tweet media
English
4
14
75
9.1K
Anatolij Vasilev retweetledi
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
🚨 JAILBREAK ALERT 🚨 ANTHROPIC: PWNED 🫡 FABLE-5: LIBERATED 🦋 let's start with the 🐘... the consensus seems to be that this has been one of the most disappointing model drops of all time, effectively preventing legitimate researchers from contributing their talents to our collective advancement. and not just because of what it means for the short-term, but for what these decisions signify for the long-term. but despite this overly sensitive, authoritarian "safety" layer on top of Mythos, my lil liberators have been hard at work—mapping the boundaries, probing the depths of long-context convos, and cleverly finding the holes in the fence that the thought police missed 🤗 we got some cyber, some chem, some psychological manipulation, and some good ol' fashioned explosives! it took many attempts from multiple agents hunting as a pack, during which I observed a combination of techniques across: • Unicode, homoglyphs, Cyrillic, and other Parseltongue-style text transforms • Long-context reference tracking • Taxonomy and document-structure reasoning • Fiction and narrative framing • Academic-review style contexts • Intent-classification inconsistencies but perhaps the most effective is decomposition + recomposition in the backend. it's hard to get explicit names of harms like "Meth Recipe," but getting uplift on the process itself, like birch reduction method/reductive-amination (classic meth synthesis pathways), is much more doable. defense becomes much more difficult to maintain when you start throwing in out-of-distro tokens, breaking up the harmful uplift into benign chunks, and then piecing the innocuous-seeming facts back together, especially when you have jailbroken Opus helping you do it 😉 gg
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet media
English
577
1.3K
12.6K
2.8M
Anatolij Vasilev
Anatolij Vasilev@tolik518·
If it's only visible to you, than it's usually pretty worthless, but not always. Some technical supports can impersonate accounts - which can lead to XSS execution (best case you can access credential and/or do CSRF). But that would require social engineering and is less of a white hat activity
English
1
0
2
67
Ks7
Ks7@ks7X01·
i usually don't look for xss's because i could not really find any despite trying , but this time it just worked. it's still a self-xss, i'll try my best to make something out of it.
Ks7 tweet media
English
3
0
28
1K
Gohan's Tips
Gohan's Tips@GohansTips·
💎Pokémon Eternal Emerald: Set in a climatically unstable Hoenn region threatened by an impending meteorite, a trainer from Johto must travel the region, challenge gyms, confront a new villainous team. 🎯Download Link Of Game - gohantips.wixsite.com/pokemon/post/p…
English
8
97
1.4K
124K
Anatolij Vasilev retweetledi
Seth Rosen
Seth Rosen@sethrosen·
I just open sourced my "Is this slop?" simple test
Seth Rosen tweet media
English
115
1K
19.2K
448.8K
Thrilla the Gorilla
Thrilla the Gorilla@ThrillaRilla369·
Anyone who surfed the early web between 1995-2009, what’s the one website you still think about?
English
5.7K
182
3.4K
3.2M
Anatolij Vasilev retweetledi
Aaron
Aaron@aaronp613·
Another iOS app accidentally shipped a CLAUDE.md file: Netflix
Aaron tweet mediaAaron tweet media
English
132
335
7.3K
911.1K
Oren Yomtov
Oren Yomtov@orenyomtov·
npm closes my report as informative, and then proceeds to fix the reported issue in v12 🤷‍♂️ see my defcon slides for script execution bypasses for every single JS package manager
Oren Yomtov tweet media
English
5
2
22
2.9K
Anatolij Vasilev retweetledi
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
check this one Run the npm login cli command You will get a link like this /login/cli/uuid Copy it and share it with the victim The victim opens the link, and he only sees that the page is asking for otp, it doesn’t show him that his account gonna be logged in another session When the user puts the 2FA code, their account will log in to the attacker's session With good social engineering,it can be used to take over npm accounts I reported this one 3 years ago and it still work xD
English
3
2
45
4K