Here are a few of my favorite websites for OSINT/Web Recon:
1 - CentralOps https://t.co/J6EIvjvx4r
2 - ViewDNS https://t.co/qbhck39tQQ
3 - URLScan https://t.co/tvTG0kSEKb
4 - IP2Proxy https://t.co/y2x9H00xjA
5 - HostingThis https://t.co/9LTQ28f4gM
</CODE4>
#OSINT
@wearehackerone +1 to this, and the landscape is changing constantly, so anyone who was an expert a few months ago, might not be any more, so much to constantly learn
Just pushed a new update to Coyote as NPM-focused supply chain attacks seem to be on the rise. Here's the details on what was added:
- npm-specific supply chain detection added to Coyoteβs core scanner.
- New checks catch suspicious install-time lifecycle scripts like risky preinstall/postinstall behavior.
- The scanner now flags remote dependency sources in package.json, insecure .npmrc settings, and Node lockfiles that use plain HTTP or lack integrity hashes.
- Wired the new findings into scoring, attack path analysis, and test coverage so they affect real risk evaluation.
Done β
New update to Coyote that adds a scan for the axios/npm supply-chain attack, details below π½
- add dedicated dependency findings for:
- compromised releases `[email protected]` and `[email protected]`
- IOC package `plain-crypto-js`
- include incident metadata, install-time execution context, and
remediation guidance in dependency findings
- ensure supply-chain IOC findings still fail CI under
`--deps-reachable-only` since this campaign executed at install time
- map new rule names into supply-chain attack-path analysis
- add tests for malicious axios releases, IOC package detection,
gate behavior, and attack-path categorization
- update README dependency scan docs with Axios incident coverage
Google Threat Intelligence Group is tracking an active supply chain attack π
North Korea-nexus actor UNC1069 compromised the "axios" NPM package (v1.14.1 & 0.30.4), deploying the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux.
Learn more: https://t.co/pII35aPpRA
Just pushed a new update to Coyote Security to Github, and working on a second one now as the axios/npm supply-chain-attack is a big deal, and a perfect place to use Coyote.
First, here's the update I just pushed that I'm pretty excited about, adding a core feature ppl have been asking for.
feat(remediation): add actionable remediation guidance to findings and reports
Add remediation text across the finding pipeline so scan output is not just
descriptive, but also tells users what to do next.
- extend PatternMatch with a remediation field
- add remediation text to all secret and smell patterns
- add sensitive-file remediation lookup helper
- populate remediation in scanner findings for sensitive files, secrets,
smells, entropy hits, gitignore issues, and large files
- add upgrade/monitor remediation for dependency vulnerability findings
- include remediation in JSON, Markdown, HTML, and SARIF outputs
- add remediation-focused tests covering patterns, reports, SARIF, and
sensitive file behavior
Validation:
- python3 -m unittest tests.test_remediation
Now live on Github.
π‘οΈ PentAGI β Automated AI-Powered Pentesting Tool that Integrates 20+ Security Tools
Source: https://t.co/50TAGdMf5t
PentAGI introduces an AI-driven approach to penetration testing, automating complex workflows with tools like Nmap and Metasploit while generating detailed reports
The tool stands out for its fully autonomous AI agents that dynamically plan and execute pentests, integrating over 20 professional security tools, including Nmap for network discovery, Metasploit for exploitation, and sqlmap for database attacks.
Users define a target, and PentAGIβs multi-agent system, comprising researcher, developer, and executor roles, orchestrates the process, leveraging long-term memory to recall past successes and adapt strategies.
#cybersecuritynews
Just pushed a new update to Coyote, now live on GH.
Here's what's new:
Coyote can now generate CycloneDX v1.5 Software Bill of Materials from your dependency lockfiles. One command gives you a compliance-ready inventory across Python, npm, Go, and Rust projects.
- Supports requirements.txt, poetry.lock, package-lock.json, pnpm-lock.yaml, go.mod, and
Cargo.lock
- Generates spec-compliant PURLs for every component with proper ecosystem normalization
- Dev dependencies excluded by default β opt in with --include-dev
- For a full supply chain security workflowPairs with existingcoyote depsandcoyote gate
I built an open-source library of 700+ cybersecurity skills for AI coding agents -- covers DFIR, threat hunting, cloud security, and more https://t.co/vM5SgmXCrO