I am new to programming and writing code. I love it and this is a place where we can share thoughts or give advice. I will also retweet tech related news.
🐍 Python developers beware! A malicious package named "crytic-compilers" was discovered on PyPI, designed to deliver the Lumma info stealer.
Learn more: https://t.co/yvPXkmwgGX
#cybersecurity#technews#malware
I run this thing called Portmaster which blocks all outgoing network requests until I allow them. The reason?
Microsoft Edge _WEBVIEW_ as in, the component that's in everything in Windows, is now trying to phone home to ChatGPT:
A malicious Python package, pytoileur, has been found in PyPI, aiming at #cryptocurrency theft. Downloaded 316 times and re-uploaded after removal, this highlights significant risks in open-source ecosystems.
Learn more: https://t.co/EqbHyIJ8hJ
#cybersecurity
The DoJ just busted a massive scam involving North Korean IT workers infiltrating major US companies.
They had some help in the US and were posing as remote freelancers to siphon off money and sensitive info.
Holy crap, here's what we know:
Foxit PDF Reader users, beware! A design flaw is being weaponized to deliver malware including Agent Tesla, AsyncRAT, DCRat, NanoCore RAT, NjRAT, Pony, Remcos RAT, and XWorm.
Learn more: https://t.co/LdsYX0gpsN
#infosec#hacking#cybersecurity
Today has been a whirling wind of chaos.
tl;dr we don't know anything. We need solid proof.
First, earlier this morning the current owner of Doxbin, Operator, was allegedly beaten and kidnapped. Footage released by the would-be kidnappers shows, presumably Operator, tied to a pole and being punched and kicked. However, many viewers immediately expressed doubt on the footage and some said it's a 'detrace' operation — essentially an exit strategy for Operator.
We do not know the truth. We can only speculate. It is strange.
Secondly, BreachForum was seized today. Following the takedown there were lots of rumors floating around about Breach being a honey-pot, that key members have been arrested, etc. While this may certainly be true, there is no confirmation from law enforcement agencies on arrests or indictments. ShinyHunter, the other administrator of the website, has stated the other administrator, Baphomet, has been arrested. While we don't doubt this (ShinyHunter of all people would probably know), we would like an official Department of Justice announcement or court document confirming these statements.
What we can say though is that although Breach is gone, we are certain another forum will appear (eventually) to fill the power vacuum. It's only a matter of time.
Anyway, looking forward to Breach and/or Raid rebrand number 4!
HardeningMeter - Open-Source Python Tool Carefully Designed To Comprehensively Assess The Security Hardening Of Binaries And Systems https://t.co/gpqJp3lpoI
Yesterday The New York Times unveiled that General Motor's had accidentally enrolled millions of people into its "OnStar Smart Driver+" program. If consumers chose to not enroll through the phone app – it would do it anyways.
Unenrolling requires consumers to contact OnStar customer support line. However, some people do not trust them and have turned to stripping the electronic devices from their car.
The OnStar Smart Driver+ data was being sold to LexisNexis, and insurance companies, to modify insurance rates. The data sold was invasive and logged:
- Number of trips
- Miles driven
- Minutes driven
- Hard-brake vents
- Rapid accelerates
- Speeding events
The reporter from the New York Times requested a copy of their data and received it. See attached image.