SOVA by @SecureNexus caught a coordinated npm typosquatting campaign in under 3 hours — two completely different attack vectors (postinstall dropper + hidden C2 beacon) from the same publisher using maintainer correlation + multi-layer static + AI analysis.
We cover recon, developer compromise, dependency abuse, CI/CD compromise, malicious package injection, registry and artifact compromise, and container plus IaC poisoning, ending with a capstone kill chain and mitigation with TPRM.
Yes, Shai-Hulud 2.0 and variants are included.
Zero day is optional. Supply chain compromise is not.
At BHASIA 2026 I am teaching “Attacking the Software Supply Chain” with @beingsecure (Apr 21 to 22).
Dev workstation → deps → CI/CD → artifacts → containers/IaC → multi-stage kill chain.
Early pricing ends Feb 6.
🗓️ Happening tomorrow at 05:30 pm, Vegas Time - "Legal Entity-Driven Reconnaissance with OWASP Amass: Enhancing Bottom-Up Discovery Using RDAP" by Jeff Foley @jeff_foley at Recon Village.
cc: @DEFCON#OWASP#DEFCON33#DCVillages#ReconVIllage
📣 Calling all chaos tamers & OSINT lovers!
Recon Village @defcon needs YOU. Call for Volunteers is OPEN.
Volunteer with us and be part of the madness.
Apply now → https://t.co/cV4USbVqXU
#ReconVillage#DEFCON33
⚠️ This is a message from the universe.
To be part of something cool.
To give back.
To get free hacker karma.
Volunteer at Recon Village @defcon → https://t.co/cV4USbVqXU
#recon2025#recon#osint#dcvillages
You've stalked systems. Now, stalk badge queues and speaker schedules with us.
Volunteer for Recon Village @defcon.
😎 https://t.co/cV4USbVqXU
#recon2025#recon#osint#dcvillages
The success of Recon Village @defcon depends on the people behind the scenes.
Volunteers are the backbone of everything we do.
If you're committed, organized, and want to contribute to #OSINT and #Recon research, Sign up: https://t.co/cV4USbVqXU"
🚨 Hackers, OSINTers, recon nerds, it’s almost time! 🚨
As we prep for @ReconVillage @ @defcon 2025, relive past chaos: talks, demos & CTFs 🎥https://t.co/ARq1vBaG5S
This August, we’re back - louder, sharper & full of surprises.
#ReconVillage#DEFCON2025#OSINT#HackerLife
📢 CFP is LIVE!
Recon Village is back at @defcon 33 and calling all #OSINT nerds and #Recon maniacs. Got a technique, toolkit, or wild OSINT case? We want it.
📅 CFP closes: June 15
🎯 Submit now: https://t.co/o9DdWFHp9g
#OSINT#DEFCON#ReconVillage#CFP#dcvillages
Bootstrapping = building with passion.. don't miss out on the opportunity to see how we're transforming security landscapes with cutting-edge technology... #CyberSecurity#GISEC2024
We are extremely happy to announce a full fledge multi-station hardware hackinng village at this years conference. Thank you very much @SeedonD@Zero0x00 kiran Gupta Ujwal patel and team for organizing this. This village is sponsored by @SecureNexus@beingsecure
We are having a great time hosting talks, running CTF and our brand-new context Recon Aacharya.
We would like to give a shout-out to our sponsors for supporting us. Thanks a lot - @SecureNexus, @RedHuntLabs, @payatulabs and @Hak5.
@gupta14881@mybmc@MLJ_GoI@PMOIndia@GurukrupaGroup Some sick people who pretend to be stray dog lovers have created a big problem in our society... It has become difficult for us to walk in the early morning or late evening .. they attack kids and elderly people. Please take action before it is too late...