BlueT - Matthew Lien

5.8K posts

BlueT - Matthew Lien

BlueT - Matthew Lien

@BlueT

Head of Resilient Architecture, NICS & PDIS. Travel and read 用靈魂和肉體,紀錄世界。 Geek, (Co)founder, CTO, Advisor, Entrepreneur, whatever. #Linux #Security #OpenSource

Taiwan Tham gia Temmuz 2007
2.8K Đang theo dõi1.6K Người theo dõi
BlueT - Matthew Lien
@sciwork I can't attend but would love to support. Do you accept small donations to support this project? (maybe by adding one more ticket type without requiring to select food types, etc)
English
0
0
0
13
sciwork
sciwork@sciwork·
📣 scisprint Hsinchu in April is now open! Want to build projects or improve your skills but find it hard to start alone? Come code, focus, and meet people with similar interests 🙌 More info in the comments 👇
sciwork tweet media
English
2
1
2
1.2K
BlueT - Matthew Lien đã retweet
Aakash Gupta
Aakash Gupta@aakashgupta·
North Korean intelligence agents built an entire fake company to compromise one JavaScript developer. And it worked. UNC1069 didn't hack Axios. They befriended its maintainer. They cloned a real company founder's identity, built a branded Slack workspace with fake employee profiles and LinkedIn post channels, then scheduled a Microsoft Teams call with what appeared to be a full team. During the call, a fake error message said his system needed an update. He installed it. That update was the RAT. From one developer's laptop, they had everything: npm credentials, publishing access, the keys to a package installed in 80% of cloud environments. Axios gets 100 million downloads per week. The attackers published two poisoned versions at 12:21 AM UTC on a Sunday night, tagging both the latest and legacy branches within 39 minutes. The malicious dependency had been pre-staged 18 hours earlier with a clean decoy version to build registry history. Three separate RAT payloads were pre-built for macOS, Windows, and Linux. The malware self-deleted after execution to erase forensic evidence. The poisoned versions were live for about three hours before npm pulled them. Huntress observed 135 endpoints across all operating systems calling the attacker's command-and-control server during that window. Wiz found the malicious versions in roughly 3% of environments scanned. Every affected machine needs full credential rotation: npm tokens, AWS keys, SSH keys, CI/CD secrets, everything in .env files. The part that keeps getting worse: this isn't isolated. The same threat cluster compromised Trivy (a security scanner), KICS, LiteLLM, and multiple GitHub Actions in the two weeks before Axios. Google estimates hundreds of thousands of stolen secrets are now circulating from these combined attacks. The maintainer had 2FA enabled. He said himself: "I have 2FA/MFA on practically everything." The exact method of token compromise is still undetermined. One person. One fake Teams call. 100 million weekly downloads weaponized in under three hours. The npm ecosystem runs on mass trust in individual maintainers who volunteer their time, and North Korean intelligence now has a repeatable playbook for turning that trust into a delivery mechanism.
flavio@flaviocopes

How Axios was compromised 🤯

English
65
715
3K
433K
BlueT - Matthew Lien
BlueT - Matthew Lien@BlueT·
這幾天建議大家先別安裝、更新 js 模組 😂 Axios 中招,這波影響應該誇張大... 作者帳號被盜,模組被更新成塞了惡意程式碼的版本...
Feross@feross

@SocketSecurity UPDATE in case you missed it earlier: This is bigger than initially reported. Both axios@1.14.1 AND axios@0.30.4 were compromised – the attacker poisoned the 1.x and 0.x branches within 39 minutes of each other, maximizing blast radius across projects using caret ranges.

中文
0
2
7
396
pofeng
pofeng@pofeng·
請問一下各位專家,這裡的"假名化",要怎樣改善比較好? eg: 只儲存身分證號,但沒有姓名,生日,依此條例,是否算假名化? 全民健康保險資料管理條例 第 3 條 四、假名化:指健保資料經處理或加工後,非透過其他資訊對照,不能識別其身分,且該其他資訊應分開存放,並採取技術上或組織上保護措施之程序
pofeng tweet media
中文
2
0
1
288
BlueT - Matthew Lien đã retweet
pofeng
pofeng@pofeng·
跟著 au 前大臣的腳步,一人一 emoji,連署請 Hugging Face 提供 TAIDE-12b 的推論 API
pofeng tweet media
中文
0
1
5
549
BlueT - Matthew Lien đã retweet
KK.aWSB
KK.aWSB@KKaWSB·
这位外国小哥教你如何判断来电者是否是AI诈骗‼️ 只需问问他有没有纸杯蛋糕的食谱就行了!哈哈……
中文
59
364
3.2K
380.5K
BlueT - Matthew Lien đã retweet
Kritika
Kritika@kritikakodes·
POV: You say 'I'm full-stack' thinking it's just React + Node.
Kritika tweet media
English
82
468
4.8K
156K
BlueT - Matthew Lien đã retweet
Lydia Hallie ✨
Lydia Hallie ✨@lydiahallie·
Excited to announce Claude for Open Source ❤️ We're giving 6 months of free Claude Max 20x to open source maintainers and core contributors. If you maintain a popular project or contribute across open source, please apply! claude.com/contact-sales/…
English
588
1.4K
12.5K
1.8M
pofeng
pofeng@pofeng·
@BlueT 保重,美國 CDC 建議 6 個月以上,所有人都要接種流感疫苗。
中文
1
0
1
38
pofeng
pofeng@pofeng·
真誇張,今天 *全部* 都是B型流感。
中文
1
0
0
141
pofeng
pofeng@pofeng·
Talk is cheap. Show me the code. Code is cheap now. Show me the ... interface ?
English
1
0
0
124
Alex Cheema
Alex Cheema@alexocheema·
Running GLM-4.7-Flash on 4 x M4 Pro Mac Minis using @exolabs. Uses tensor parallelism with RDMA over Thunderbolt & MLX backend (h/t @awnihannun). Runs at 100 tok/sec. We're working on optimizing this at @exolabs. Aiming to hit ~200 tok/sec on this setup soon.
Alex Cheema@alexocheema

Running LLM evals with @exolabs on 8 x M4 Pro Mac Minis. M5 Pro Mac Mini memory bandwidth should be ~30% faster (~350GB/s) + 4x FLOPS w/ Neural Accelerators (tensor cores). 8 x M5 Pro Mac Mini cluster would have a total of 2.8TB/s memory bandwidth with RDMA over Thunderbolt 5.

English
41
63
580
62K