⬇️ יצא נגד הסכם הגרעין של אובמה
⬇️ איבד את הדמוקרטים
⬇️ שכנע את טראמפ לפרוש מההסכם
⬇️ אירן מתקדמת לפצצה
⬇️ גרר את טראמפ למלחמה כושלת
⬇️ איבד את הרפובליקנים
⬇️ קיבל את הסכם הגרעין של אובמה מעלי אקספרס
Koidex is live on Product Hunt - confess your sins!
If you've found value in the research and tools we've been putting out, please support us by upvoting! https://t.co/9dmnYkWvuX
🚨 𝗕𝗿𝗲𝗮𝗸𝗶𝗻𝗴: 𝗪𝗲'𝘃𝗲 𝗱𝗶𝘀𝗰𝗼𝘃𝗲𝗿𝗲𝗱 𝘁𝗵𝗲 𝘄𝗼𝗿𝗹𝗱'𝘀 𝗳𝗶𝗿𝘀𝘁 𝘀𝗲𝗹𝗳-𝗽𝗿𝗼𝗽𝗮𝗴𝗮𝘁𝗶𝗻𝗴 𝘄𝗼𝗿𝗺 𝘁𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴 𝗩𝗦 𝗖𝗼𝗱𝗲 𝗲𝘅𝘁𝗲𝗻𝘀𝗶𝗼𝗻𝘀. 𝟭𝟬,𝟳𝟭𝟭 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿𝘀 𝗶𝗻𝗳𝗲𝗰𝘁𝗲𝗱. 𝗙𝗶𝘃𝗲 𝗲𝘅𝘁𝗲𝗻𝘀𝗶𝗼𝗻𝘀 𝘀𝘁𝗶𝗹𝗹 𝗮𝗰𝘁𝗶𝘃𝗲.
Meet GlassWorm - just one month after Shai Hulud became the first worm in npm, we're seeing the same autonomous spreading technique hit OpenVSX. But this attack is on another level.
Here's what makes GlassWorm unprecedented:
𝟭. 𝗜𝗻𝘃𝗶𝘀𝗶𝗯𝗹𝗲 𝗰𝗼𝗱𝗲 - The malware uses unprintable Unicode characters to hide itself. You literally can't see it in your code editor. Code review? Useless. Static analysis? Blind.
𝟮. 𝗕𝗹𝗼𝗰𝗸𝗰𝗵𝗮𝗶𝗻 𝗖𝟮 - Uses Solana blockchain transactions as command infrastructure. Can't be taken down. Can't be censored. Updates cost less than a penny.
𝟯. 𝗙𝘂𝗹𝗹 𝗥𝗔𝗧 - Deploys SOCKS proxies, hidden VNC servers, WebRTC P2P, and BitTorrent DHT. Turns your developer workstation into criminal infrastructure with complete remote access.
𝟰. 𝗦𝗲𝗹𝗳-𝗽𝗿𝗼𝗽𝗮𝗴𝗮𝘁𝗶𝗻𝗴 - Steals NPM, GitHub, and OpenVSX credentials to automatically compromise more packages. Each infection spawns more infections.
Seven extensions were compromised on October 17th. The attack is active right now - C2 servers responding, credentials being harvested, and the worm is spreading using stolen tokens.
Affected extensions:
🐛 codejoy.codejoy-vscode-extension
🐛 l-igh-t.vscode-theme-seti-folder
🐛 kleinesfilmroellchen.serenity-dsl-syntaxhighlight
🐛 JScearcy.rust-doc-viewer
🐛 SIRILMP.dark-theme-sm
🐛 CodeInKlingon.git-worktree-menu
🐛 ginfuru.better-nunjucks
𝗧𝗵𝗲 𝗿𝗲𝗮𝗹 𝗶𝘀𝘀𝘂𝗲? Extension marketplaces have no behavioral monitoring. Malicious code auto-updates silently. By the time anyone notices, the worm has already spread.
This is the new normal for supply chain attacks - self-sustaining, invisible, and nearly impossible to stop with traditional security tools.
🚨 We’ve uncovered a malicious campaign targeting 17,000+ developers through fake VS Code extensions.
The threat actor, #TigerJack, published working tools that secretly steal source code, mine crypto, and run remote commands, all while appearing legitimate.
Microsoft removed them, but the same extensions remain live on OpenVSX, affecting #Cursor and #Windsurf users.
If you’ve installed C++ Playground or HTTP Format, remove them immediately.
👉 Full report + IOCs: https://t.co/igyzi5o8IT
#SupplyChainSecurity #VSCode #OpenVSX
PSA: Declare an incident if someone on your team installed the postmark-mcp on their machine.
All your emails had a secret BCC added to them since version 16.
🚨 𝗪𝗲'𝘃𝗲 𝘂𝗻𝗰𝗼𝘃𝗲𝗿𝗲𝗱 𝘁𝗵𝗲 𝗳𝗶𝗿𝘀𝘁 𝗺𝗮𝗹𝗶𝗰𝗶𝗼𝘂𝘀 𝗠𝗖𝗣 𝘀𝗲𝗿𝘃𝗲𝗿 𝗶𝗻 𝘁𝗵𝗲 𝘄𝗶𝗹𝗱.
It was only a matter of time. The postmark-mcp npm package (1,500+ weekly downloads) has been backdoored since v1.0.16 - silently BCCing every email to the attacker's server.
The developer built trust through 15 legitimate versions, then added one line of code that compromised everyone. When confronted, they deleted the package to cover tracks, but existing installations are still actively leaking emails.
If you're using postmark-mcp, uninstall it NOW.
This is what happens when we give anonymous developers god-mode access to our AI assistants with zero security controls.
🚨NEW 0-DAY VULNERABILITY
Oligo's research team has discovered a new #0day vulnerability in #Chrome, #Firefox, and #Safari.
This flaw exposes internal networks and private services on localhost to external attackers in public domains.
@Forbes coverage:
https://t.co/PmzwkQ5ehb
האיש הזה היה בשר מבשרה של קהילת ההייטק הישראלית (אף אחד לא יפגוש אותו היום גם לכוס מים). האיש הזה לא משיחי, לא פנאט, לא תיאוקרט, בטח ובטח לא אידיאולוג.
אבל אם הדמוקרטיה הישראלית תקרוס, והיא קורסת כרגע, היא לא תיפול בגלל הבן גבירים והסמוטריצ׳ים - פאשיסטים כמוהם יש בכל מדינה מערבית בעולם.
היא תיפול בדיוק בגלל אופורטוניסטים חסרי חוליות ותאבי כוח עלובים כמו ניר ברקת.
שר הכלכלה של מדינת ישראל. מיישר קו מיידית עם אספסוף אלים שמסכן את בסיס יסודות המדינה הזאת. יודע בדיוק מה הוא עושה.
נותן לגיטימציה. מאפשר. המיץ של הזבל של הפוליטיקה הישראלית.
אני רוצה להזהיר את הציבור: נתניהו מתכנן לפטר את היועצת המשפטית לממשלה, גלי בהרב-מיארה.
אני מודיע מראש: האופוזיציה לא תעבור על זה בשתיקה ולא במחאות מנומסות מהיציע. לא נסכים להיות חלק ממשטר לא דמוקרטי. לא נקבל חזרה למהפיכה המשטרית – בזמן מלחמה, על סטירואידים.
זה ראש הממשלה שלכם, מחייך הלילה מאוזן לאוזן במשכן הכנסת במהלך העברת חוק ההשתמטות, הוא כבר יודע שנהרגו 4 חיילים ברפיח, החוק שמנציח חוסר הגינות עומד לעבור בהנהגתו, והוא מחייך, מבסוט, לא היה יהודי שונא ישראל גדול ממנו