❗️ Over 30 official Red Hat npm packages were compromised. How they got in:
- A Red Hat employee's GitHub account was compromised.
- Attackers pushed "orphan commits" (detached from branch history) straight in, bypassing code review with no pull request.
- Payload "Miasma" (Mini Shai-Hulud variant) steals GitHub/cloud/Vault/SSH/npm secrets. Rotate everything since June 1.
- The commits added a workflow (ci.yaml) + script (_index.js) that abused npm trusted publishing, requesting a real OIDC token to publish backdoored versions.
My German is pretty good, but the Switzerland people have a dialect which is a bit tough for me.
Anyway, my campsite is waiting for me. 👍🇫🇷🛶🎣🍻
#frischgemäht
Microsoft introduces Microsoft Scout, also known as Autopilot.
Scout is always on and has file system and application access "based on your corporate policy".
Best news for Threat Actors in a long time
https://t.co/M3pyfcbTBm
I've been taking pictures of my skin disease which started in December, and then made an animation of those.
It has become a horror movie.
I'm doing much better now, but what a trip this has been. 🔥
Google is about to conduct one of the LARGEST open-air biological experiments in U.S. HISTORY.
64 MILLION bacteria-infected mosquitoes are set to be released into Florida and California — potentially causing irreversible ecosystem disruptions.
This must be STOPPED.