Mini Shai-Hulud is back and it hits harder each time.
317 packages. 633 versions. One compromised maintainer account.
size-sensor, echarts-for-react, timeago.js and the entire @antv scope. 15M+ monthly downloads collectively.
analysis -> https://t.co/n86DOr9blv
more details would be updated soon, analysis going on. stay tuned...
Black Hat Asia 2026, wrapped. ✅
It's always something special being in a room full of people who genuinely care about making the security space better. Great conversations, sharp minds, and a few sessions that genuinely made us think differently.
Big thanks to everyone who stopped by and connected with our team. See you at the next one.
#BlackHatAsia2026 #CTEM #AIExposure #RedHuntLabs #Cybersecurity
The response Shubham Mittal (@upgoingstar) got after his talk "No CVE for That" at @nullcon Goa 2026 was incredible and we didn't want it to stop there.
We've put the full deck on SlideShare so the wider security community can make benefit from this research talk. Access the full deck here: https://t.co/m9UlWy1JBA
From exposed Ollama instances to leaked OpenAI keys to unauthenticated vector databases, the AI stack is the new attack surface, and most organizations have zero visibility into it.
If you're building with AI, securing it, or advising teams that are, this one's for you and worth sharing.
#AISecurity #CTEM #LLMSecurity #AIExposure #RedHuntLabs
Merry Christmas to the only community that understands that Santa is clearly one of us.
Think about it:
1. He procrastinates for 364 days.
2. He pulls a global all-nighter fueled by sugar and deadline panic.
3. He completes the entire year's work in a manic 8-hour hyperfocus fugue state.
He is the Patron Saint of Executive Dysfunction. We claim him. 🎄
In the sixth batch of community open source reviews, I checked out 8 awesome projects! ⚔️
- actsense by @0xCardinal
- Indie UI by @alibey_10
- React Bits by @davidhdev
- npm bet by @haydenbleasel
- ElementSnap by @moumensoliman
- react-icons-sprite by @jurerotar
- Christmas Photo by @bargues_sofia
- ReadmeBit by @najibdev
Huge respect to everyone building cool stuff in the open! 💚
Next stream coming soon, submit yours https://t.co/z5LQzNl7QE
You can also see all reviewed projects there.
FOR THE HORDE! 🪓
I’ve been working on actsense (https://t.co/56Uqb0fR29) — an open-source GitHub Actions auditor — and I’m really happy with how it’s coming together.
It’s now public, so feel free to try it out, break it, share feedback, or even contribute.
Here’s a sneak peek 👇
Cheers!
We had a fantastic time hosting the Command Line Heroes Bengaluru Edition this past Saturday!
Big thanks to everyone who joined us, your questions and energy made the event special.
😮💨…and sometimes users accidentally push sensitive information into Git platforms which can be exploited by malicious actors
Join @0xCardinal at #NullconGoa2025 to uncover security risks of dangling commits
👉 https://t.co/GeVN7uJKUe
#GitHub#GitLab#Bitbucket
really nice and elaborate research on leaving AWS canary at different places and the metrics are really something!
worth a read!
https://t.co/45iPUPVEzh
Reputation Farming in OSS Ecosystem! 🌱
Malicious actors boost their GitHub reputation by commenting or approving closed Pull Requests, discussions, or Issues they're not genuinely involved in 😱
✍️Curated more details on my blog - https://t.co/B3tqD4mK4G