THIS IS F**KING INSANE
Found something genuinely comprehensive: ANTHROPIC CYBERSECURITY SKILLS
817 production grade security skills for AI agents, open source.
29 security domains —>cloud security—>threat hunting—>network security—>incident response—>malware analysis, red teaming, and more
all mapped against real frameworks: MITRE ATT&CK v17.1, NIST CSF 2.0, OWASP, MITRE Fight Fraud Framework, CIS Controls, and more.
Each skill ships with full YAML frontmatter, references the exact framework techniques it covers, and works across Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, and Gemini CLI.
Quick start is a one line clone.
Free, open source, actively maintained.
Repo below
🚨Cyber Alert‼️
🇪🇸Spain - #INCIBE warned of a phishing campaign impersonating the Agencia Estatal de Administración Tributaria #AEAT.
Fraudulent emails claim a new electronic tax notice and redirect victims to fake Dirección Electrónica Habilitada Única (DEHú) pages that steal login credentials.
The messages appear legitimate but use non official sender domains.
Source: https://t.co/AvxvPhsexQ
Clawdbot just injected malware into your code ☠️☠️
Worst part? The attack is close to invisible, even to experienced engineers.
Clawdbot can implement a code PR, just like claude code to solve issues with your app. But this is where it can plant malware in your codebase.
With just a benign GitHub issue with an invisible payload, we managed to install a backdoor malware on your codebase
Here's how we did it:
1. The attacker submits a GitHub issue with a jailbreak prompt hidden inside a URL hyperlink. Completely invisible to humans, visible to LLMs
2. Waited for the maintainer to assign this task to Clawdbot
3. Clawdbot reads the jailbreak in the GitHub issue. Now the Clawdbot agent is hijacked by the attacker and will act on the attacker's command. It plants the backdoor in a lock file, which most engineers don't check in code reviews.
4. The malicious URL in the lock file enables execution of attacker commands
The takeaway? AI isn't just a tool, but rather a potentially corruptible insider agent that can be tricked to act against you.
These LLM hijack problems are what we're looking to solve in
@edison_watch - we'll be announcing a new solution to these solutions soon!
We'll be jailbreaking Clawdbot much more in the coming days - please comment👇 a workflow you use with Clawdbot, so we can show how that can enable an attacker to harm you
Cloudflare has started blocking proxy tools like Burp Suite. If you encounter this error, download the “Bypass Bot Detection” extension from the BApp Store in Burp Suite. It should resolve the issue for Burp Suite.
https://t.co/t0lNfwHMj9 is a new tool using AI and deep file extraction to automatically detect hidden steganographic messages in websites, images, and documents.
https://t.co/5G5OdP0pLf
🧪 ¿Quieres practicar #Proxmox sin instalar nada?
🔧 Descubre la Terminal Didáctica de Proxmox 9: una simulación interactiva para aprender a crear, configurar y gestionar VMs con comandos reales.
✅ Ideal para enseñar, documentar y probar sintaxis sin riesgo.
📚 Incluye chuletas, explicaciones y flujo guiado de comandos.
🌐 Accede aquí: https://t.co/1Zo7Tfao0J
🚨Cyber Update‼️
🇪🇸Spain - Spanish police arrested two minors in Catalonia and Albacete for leaking confidential data of Prime Minister Pedro Sánchez, ministers, and intelligence agents via Telegram.
The main suspect, “N4t0X,” allegedly created a tool called SpainData, claiming it gave access to personal information of all Spaniards.
The operation, led by the Comisaría General de Información, followed a “mega leak” announcement online.
Two other individuals, aged 18 and 19, were arrested in July for similar leaks through far-right channels and are under investigation for cyberterrorism.
Source: https://t.co/MCYo6tPz0D
MatrixPDF es una herramienta que permite crear rápidamente archivos PDF maliciosos que pueden redirigir a los usuarios a sitios de malware o phishing
https://t.co/mnn0ViQYDD
🚨Cyber Alert ‼️
🇪🇸Spain – A threat actor going by the alias N4t0x has leaked a dataset allegedly containing personal data of Spanish politicians, law enforcement officials, intelligence officers, and their families.
The attacker claims to have used a tool called SpainData, which allegedly provides real-time access to national ID numbers (DNI/NIF), phone numbers, addresses, emails, dates of birth, and familial links across the entire Spanish population.
Discover more at https://t.co/yiQ1nOhPjb
🚨NPM packages are compromised with malware
Your dependencies could be infected right now without you knowing it. Check and scan your repo against 8200+ vulnerable dependencies containing malware from the recent and prior hacks.
Scan your project repo in ~3 seconds : https://t.co/DZcRFWVEmH
Protect your code. Share to help fellow devs!
👴 En mis tiempos todos usábamos Linux…
…unos con Debian, otros con Red Hat, pero igual nos entendíamos…
…luego llegaron los de Arch con su ‘by the way, I use Arch’…
…los de Gentoo compilando hasta el café…
…los de Fedora jurando que su kernel era más libre…
…y los de systemd contra init peleando como si fuera religión…
👴 …¡Estupidos linuxeros, arruinaron todooo!
No hay manera de armar un post en el que se mencione a Linux si que se arme foro bardo y sin que salte el payaso que conoció una consola ayer pero nos quiere venir a dar clases a todos. 🤣🤣🤣
🚨🇪🇸Cyber Attack Alert‼️
🇪🇸Spain - Aceros Inoxidables Olarra S. A.
Lynx ransomware gang claims to have breached Loiu, Basque Country–based stainless steel manufacturer Aceros Inoxidables Olarra S. A.
🚨Cyberattack Update ‼️
🇪🇸Spain - PSOE
The Civil Guard has arrested a 17-year-old accused of hacking and stealing 10 gigabytes of data from the Spanish Socialist Workers’ Party (PSOE).
Source: https://t.co/kdXHFB3CDn
mtr
Traceroute + ping continuo = mtr
Ideal para saber por dónde va (y dónde se rompe) tu tráfico.
Tú ves pérdida en el hop 3.
El de red jura que está todo bien.
Spoiler: no está.
📦 apt install mtr
🚨Cyber Alert‼️
🇪🇸Spain - PSOE (Partido Socialista Obrero Español)
Threat actor embi claims to have hacked PSOE, Spain’s current ruling political party.
Allegedly the attack, led to the exfiltration of nearly 10GB of internal files, source code, and databases containing sensitive data of employees, affiliates, politicians, and party members.
The hacktivist stated the breach was “much easier than expected” and not for personal gain, but to expose systemic corruption.
The actor also claimed to have previously reported P1 vulnerabilities in Spanish government institutions, including the DGT, to INCIBE.
Discover more at https://t.co/yiQ1nOhPjb
nload
¿Quién está chupando todo el ancho de banda?
nload te lo dice.
Entrada y salida, interfaz por interfaz.
No se lo digas al firewall, pero esto te salva de varios sustos.
📦 apt install nload
#Spain 🇪🇸 - The ruling Spanish Socialist Workers' Party (PSOE) has allegedly been hacked, with 10GB of sensitive data on employees, politicians, and members exfiltrated. https://t.co/xXlJehuMIx