Microsoft has uncovered a supply chain attack involving malicious npm packages registered under organizational scopes that mirror real internal corporate namespaces, employing dependency confusion technique to deploy a reconnaissance payload. https://t.co/z2GjRIAyYS
A threat actor operating under three maintainer aliases, mr.4nd3r50n, ce-rwb, and t-in-one, published malicious packages that impersonate internal corporate packages, with several spoofing internal enterprise infrastructure URLs in their package.json to appear legitimate.
Once installed, the packages download and execute an obfuscated payload from an attacker-controlled command-and-control (C2) server to collect system information, hostnames, environment variables, and developer context. Read the blog for in-depth analysis and mitigation, detection, and hunting details.
@AlyssaM_InfoSec@gmgchow ... which reminds me, I need to poke the CA FTB. They require password changes every 90 days because of "IRS requirements"
Someone somewhere didn't get the memo from NIST
The threat at the Islamic center has been neutralized.
Media staging has been established as the Northwest Corner of Lindbergh Park.
(4141 Ashford Street, SD, Ca, 92111)
#SDPDPIO
My office and I are aware of and monitoring this horrific situation and will share updates as we learn more. Right now, I’m praying for any victims and I thank our brave first responders on the scene.
SDPD is on scene at the Islamic Center of San Diego in the 7000 block of Eckstrom Ave for a reported active shooter.
Please avoid the area. Updates to follow. #SDPDPIO
This is a complete own goal. It would triple the amount of AI computing power that China adds next year - before taking into account illegal smuggling. And it would divert scarce AI compute resources away from U.S. firms. This will help China close the gap with the U.S. in AI.
Q: What was https://t.co/tcoBMYOmYn's longest lasting negative impact on .NET?
A: The introduction of CLS (Common Language Specification), which has no value nowadays but we use `int` almost everywhere that `uint` would have been a better choice because uint wasn't CLS compliant.
@aarnott Yup - in .net there is a norm of "Y should try not to break things across major versions because it will break X when users update Y" and binding redirects do the same.
Still a little weird for people to be asking for a new X so they can use the new Y.
@aarnott I'm not saying they are 100% right to ... but it's because NuGet/.NET is not modular: 1) consumers of X see Y and 2) changing *my* use of Y from v1 to v2 also changes what version X uses - neither is the case in many other ecosystems.
My students asked me if it was true that the entire Internet was really coded by hand. All those kernels, protocols, router firmware, browsers, databases, etc. Somebody coded these and debugged them by hand?!?!? They used BBEdit?!?!??! The idea that this was even possible seems amazing to them. I can imagine some future Moon Landing like conspiracy theory that says it never happened.
0.1% of accounts on Polymarket make 67% of the profits.
Among the top 0.1% of accounts in frequency of trades, 75% are profitable.
But for the other 99.9%, the majority of accounts lose money.
The national debt was such a big issue in 1992 that a third party candidate took 19% of the vote only talking about that single issue.
Today, no one cares and thinks it even exists.
Back and forth illusion
The rows of blue and yellow rectangles move smoothly to the right at a constant speed; however, they seem to move back and forth from side to side.
往復錯視
青と黄の長方形の列は、一定速度で滑らかに右に動いてるが、左右に往復運動をしているように見える。
Kenya's Sabastian Sawe wins the London Marathon in world record time, becoming the first athlete to run a marathon in under two hours. https://t.co/2ogIRtGK4j
When simulation becomes the norm, it weakens the human capacity for discernment. As a result, our social bonds close in upon themselves, forming self-referential circuits that no longer expose us to reality. We thus come to live within bubbles, impermeable to one another. Feeling threatened by anyone who is different, we grow unaccustomed to encounter and dialogue. In this way, polarization, conflict, fear and violence spread. What is at stake is not merely the risk of error, but a transformation in our very relationship with truth.
Waymo is so good at saving lives that if it were a new drug in trial, it would hit the bar for being unblinded and made immediately available to the control group for ethical reasons.
@MorePerfectUS would prefer to keep killing pedestrians.