@MsftSecIntel SecOpsAl Supply Chain Alert in https://t.co/2YPOfjG7MS discovered this compromised package at 3:08 AM İstanbul time, everyone should have this free open source security tool.
@prd_008 I used it to review a product I built with gpt 5.5, it found some interesting stuff and I fixed them with gpt 5.5( would be too expensive to fix with fable), though not cybersecurity related
Super excited about the release of the Colab CLI! 🔥
Enabling your agents to easily interact with Colab is about to unlock lots of fun experiments
https://t.co/xyQ6GFINtg
⚠️ Multiple @ redhat-cloud-services npm packages were found carrying malicious payloads that fire via a preinstall hook on every npm install. All packages were published via GitHub Actions OIDC, indicating the CI/CD pipeline was compromised.
The payload targets GitHub Actions secrets, AWS, GCP, Azure, Kubernetes, HashiCorp Vault, npm and CircleCI tokens. It reads /proc/mem to bypass log masking, self-propagates via harvested npm tokens bypassing 2FA, and persists on developer devices via Claude Code and VS Code injection.
We’re excited to officially launch Flow Fellowship Program! 🎉
A 12-week cohort-based contribution + mentorship program for builders, researchers, creatives, and operators who want to work on meaningful open-source systems.
Read more and apply here: https://t.co/wkweSAsLVl