🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
Apple has landed the rights to turn ‘MISTBORN’ into a film franchise & ‘THE STORMLIGHT ARCHIVE’ into a TV series.
Brandon Sanderson will write, produce and consult on all projects.
(Source: https://t.co/Ka6RvxmT3S)
🚨🚨🚨We just broke everyone’s favorite CTF PoW🚨🚨🚨
Our teammate managed to achieve a 20x SPEEDUP on kctf pow through AVX512 on Zen 5. Full details here: https://t.co/aCIU220IBf
The Sloth VDF is dead😵
This is why kernelCTF no longer has PoW!
My @dayzerosec co-host zi and I are giving our 1st training @ https://t.co/Na25TGbLQE with a focus on attacking security hypervisors! Trainings are something we've wanted to do for a while.
Take a look and share to those who would be interested :)
https://t.co/zM6QJjPcrk
💡 ARM TrustZone-based TEEs secure devices like smartphones; drones, but they have critical vulnerabilities
Join @0ddc0de at #hw_ioUSA2025 to analyze system designs, spot security flaws & explore isolation and confidentiality techniques
👉 https://t.co/s5G5Sjpg7u
#TrustZoneTEE
Security through transparency: all chips have vulnerabilities, and most vendors' strategy is not to talk about them. In contrast, we aim to find and fix them.
Read the results of our RP2350 Hacking Challenge: https://t.co/g3ZOPw8Rqp
There are no gods here, only monsters ⚔️
We're thrilled to reveal the first look at #TheWitcherIV — our upcoming single-player open-world RPG. It marks the beginning of a new saga with Ciri as a protagonist, embarking on her own journey to become a professional monster slayer.
Watch in 4K: https://t.co/dRUwF6X8yV
I'm thrilled to announce that Project Polaris has entered the full-scale production phase! With new challenges just around the corner, it’s the talented and hard-working people who make me believe we can together make the upcoming Witcher Saga a remarkable experience. No stopping now! Stay tuned for what’s on the other side of the coin!⚔️
LakeCTF is back with a new edition! Join us on December 7th for a chance to qualify for the finals, or win tickets and accommodation for the @1ns0mn1h4ck 2025 conference in Lausanne (Switzerland)
more info here 👉 https://t.co/4rvOEqF4Mn
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate.
Full disclosure:
https://t.co/e2EwvUMgqw
The award-winning Qualys Threat Research Unit (TRU) has discovered a critical vulnerability in OpenSSH, designated CVE-2024-6387 and aptly named "regreSSHion." This Remote Code Execution bug grants full root access, posing a significant exploitation risk. https://t.co/uDHHSuzd5f