Mini Shai Hulud strikes again... again! We've identified three malicious versions of Microsoft's durabletask on PyPI, 1.4.1, 1.4.2, and 1.4.3, that contain a dropper injected directly into the package's Python source files. This does smell of more TeamPCP shenanigans, but we can’t be sure for now.
If you have these versions of durabletask installed, read our blog for remediation steps and more details about how the worm and infostealer work
-> https://t.co/stOYm7wYO9
@kirodotdev is rewriting how software gets built. We're making sure it's secure.
Aikido is the first security partner globally that @awscloud going to market with for Kiro. 🚀
AI agents now generate most of your code. Catching security issues in review doesn't scale. So we put Aikido where the agents are. Every change gets scanned automatically.
🚨 Cyberattack Sept 19 forced manual check-in/boarding @BrusselsAirport. Traced to an external provider, so other airports on same system possibly hit. BRU has historically run @CollinsAero #vMUSE — confirmation pending. #CyberAttack#AviationSecurity
🚨 Cyberattack Sept 19 forced manual check-in/boarding @BrusselsAirport. Traced to an external provider, so other airports on same system possibly hit. BRU has historically run @CollinsAero #vMUSE — confirmation pending. #CyberAttack#AviationSecurity
🚨 Live OS Supply Chain Attack!
15 NPM packages that appear to belong to @gluestack with a total of 1 million weekly downloads, have been compromised.
A Remote Access Trojan has been injected into each package, allowing the actor run shell commands, upload files, and take screenshots on affected systems
hard launching Container AutoFix today 🔥
huge for devs wasting days on manual container upgrades
fix vulnerable images automatically — with Aikido AI.
break the fix>rebuild>break cycle in seconds - try it out 👀
icymi yesterday, we identified a major malware #supplychainattack in #XRP
a backdoor was added to the official NPM package of XRP to steal private keys and send them to an attacker's C2 server 🗝️
If you believe you are impacted, assume any seed or private key processed by the code is compromised. Good news: @XRPLF quickly pushed a new secure version with no malware.
as of today you can integrate aikido in your @windsurf_ai / @codeiumdev IDE to secure code as its written (and generated)
get security done 🤝 get back to building
Shout out to silver sponsor @AikidoSecurity! Providing advanced code scanning & cloud vulnerability assessments—prioritizes real threats, reduces false-positives & makes Common Vulnerabilities & Exposures understandable.
@SecurityBSides@BSidesSATX@AustinISSA@dc512@LASCONATX
Dang! Best keep your package(s) secure.
A single vulnerable open source package can compromise entire systems, exposing sensitive data and leading to significant breaches. #staysafe#aikidosecurity creds @MiaNeethling
🛡️New Partnership Announcement with @laravelphp
to launch @AikidoSecurity's no-nonsense security directly into Laravel forge, helping 600k+ developers get #appsec done in minutes, not hours 👾
When it comes to creating killer apps, building them is one part. Securing them is another. Until now.
Proud to launch partnership w/ @laravelphp!
Laravel helps devs create their best work. Now they can secure it with Aikido, directly in Forge.
Helping 600k+ devs get security done 🤝 get back to building.
@relai_app Hey! Buying bitcoin with Relai takes 1 minute and if you use my code REL138638 your fees will be reduced by 0.5%! 😎
Download the app here
https://t.co/ogVZUv7eKk