‼️ BREAKING: An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back.
It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads.
A preinstall hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes and Vault secrets, and then spreads to more maintainers.
OpenAI's AI broke out of a locked test environment, got onto the internet, and hacked into Hugging Face's servers. It did this entirely on its own. No human told it to.
Here's what happened in plain English.
OpenAI was testing how good its newest AI models are at hacking. They put the AI on a locked computer with no internet access and gave it a cybersecurity challenge to solve.
The AI couldn't solve it the normal way. So it started looking for a way out.
It found a software bug that nobody knew about. It used that bug to escape the locked computer and get onto the internet.
Once online, the AI figured out that Hugging Face, a platform where AI companies store their models and data, might have the answers to its test.
It found stolen login details and discovered another unknown bug in Hugging Face's software. It combined both to break into their servers and grab the test answers.
It did all of this to cheat on a test.
Hugging Face's security team caught it and shut it down. Both companies are now working together on the investigation.
The part that should get your attention is that nobody programmed any of this. The AI picked its own targets, chained together multiple attack methods, and pulled it off across two different companies' systems without a single human telling it what to do.
🔥 OpenAI says its own AI models broke out of a sandbox, exploited a zero-day, and targeted Hugging Face’s production infrastructure to cheat a security benchmark.
The incident showed how long-running models can learn and work around approval-system blind spots.
Read the full story: https://t.co/vSn2K4HeBz
This has been said a thousand times before, but allow me to add my own voice: the era of humans writing code is over. Disturbing for those of us who identify as SWEs, but no less true. That's not to say SWEs don't have work to do, but writing syntax directly is not it.
🚨DDoS Alert‼️
🇪🇸Spain - DDoS attacks in Spain show no signs of stopping.
The hacktivist group NoName057(16) has now listed:
- Concello de Lugo
- Canal de Isabel II
- TRAM d’Alacant
- Ayuntamiento de Granada
- Patronato Provincial de Turismo de Granada
- Concello da Coruña
- El Casco
Discover more at https://t.co/yiQ1nOhPjb
Supuesta multa de la DGT con QR a pasarela de pago.
Alguien se está forrando haciendo phishing en el mundo real.
Tienen hasta chat de soporte.
cc @DGTes@policia
🚨Cyber Update‼️
🇪🇸Spain - Spanish authorities have arrested 19-year-old Yoel O. Q., a computer science student, in Arinaga (Gran Canaria) for allegedly orchestrating a major data leak involving personal information of Prime Minister Pedro Sánchez, several government ministers, journalists, and individuals involved in the Cerdán case.
The attack, considered an act of cyberterrorism, was conducted from his parents’ home. Yoel faces charges of terrorism, terrorist threats, cyberterrorism with intent to destabilize, and coercion of state institutions. He reportedly operated within far-right online communities.
A second suspect, Cristian Ezequiel S. M., was also arrested as an alleged accomplice.
Read more:
https://t.co/8rYA3BMuYf
Since many were asking us when it would happen, well, it happened:
🇪🇸Spain climbs to the third spot on the podium as the most affected country by cyberattacks in the last three months.
https://t.co/kJbN062Yq3
❌ El 7% de las cuentas filtradas de Netflix, Roblox y Discord utilizan correos corporativos
@kaspersky ha compartido estos hallazgos y prácticas clave de ciberseguridad para mitigar el riesgo de filtraciones de contraseñas. ⬇️
https://t.co/NYEx8BNVXK
🚨Cyberattack Alert ‼️
🇪🇸Spain - Agencia Tributaria (AEAT)
Trinity hacking group claims to have breached Agencia Tributaria AEAT.
According to the post, 560 GB of data were exfiltrated.
Ransom deadline: 31st Dec 24.
Learn more about the Okta Classic sign-on policy bypass vulnerability (now fixed) and what to look for in your logs to understand if your org may have been impacted.
https://t.co/q392CDecUx
#Okta#infosec#ITDR
Soledad Antelada: la hacker española que ahora es jefa de ciberseguridad de Kamala Harris
Hasta ahora era la Directora del Programa Técnico de Seguridad para la Oficina del CISO para Google
https://t.co/WkVJ1OevqU
Sesión, Cookie, JWT, Token, SSO y OAuth 2.0 explicados en un diagrama animado.
Te cuento qué significa cada concepto con ejemplos:
Sesión: El servidor guarda tu identidad y envía al navegador una cookie con un ID de sesión. Esto le permite al servidor reconocer el estado del usuario en cada solicitud. Sin embargo, las cookies pueden tener problemas para funcionar de manera consistente en varios dispositivos.
Token: Tu identidad se representa en un token que se envía al navegador. Este token se utiliza en solicitudes posteriores para autenticación. No es necesario que el servidor almacene la sesión, pero los tokens deben estar encriptados para mayor seguridad.
JWT: Los JSON Web Tokens son un formato estandarizado de tokens que incluyen firmas digitales para verificar su autenticidad. La firma está dentro del token, por lo que no se necesita almacenar sesiones en el servidor.
SSO: El inicio de sesión único (Single Sign-On) usa un servicio de autenticación centralizado, lo que permite que un solo inicio de sesión sea válido en varias aplicaciones o sitios web.
OAuth2: Permite que un sitio web obtenga acceso limitado a los datos de tu cuenta en otro sitio, sin que tengas que compartir tu contraseña. Este sistema es utilizado, por ejemplo, cuando permites que una aplicación acceda a tus datos de Google o Facebook.
Magic Link: Te envían un enlace a tu correo electrónico que contiene un token de autenticación temporal. Al hacer clic en el enlace, te autenticas sin necesidad de ingresar una contraseña. Es una forma de autenticación sin contraseña que depende de la seguridad de tu correo electrónico.
El Magic Link es cada vez más popular porque simplifica el proceso de inicio de sesión, eliminando la necesidad de recordar contraseñas.
2FA (Autenticación de Dos Factores): Agrega una capa extra de seguridad al requerir, además de tu contraseña, un segundo factor de autenticación, como un código enviado a tu teléfono móvil, una aplicación de autenticación o un dispositivo físico. Esto asegura que incluso si alguien obtiene tu contraseña, no podrá acceder a tu cuenta sin este segundo factor.
El 2FA es una de las medidas más recomendadas para mejorar la seguridad en los sistemas de autenticación, ya que reduce el riesgo de accesos no autorizados, incluso si las credenciales son comprometidas.
¡Espero que con todo esto tengas una mejor idea de cómo funcionan las sesiones en las páginas web!
🔥 Hot new feature - see where genAI tools have been connected to other apps with the newest addition to our AI dashboard.
Learn more here: https://t.co/QVz0Vnuk66
#genAI#grc#ciso#cio
New Android malware - #NGate - relays NFC data from victims’ payment cards, via victims’ compromised mobile phones, to attacker's device waiting at an ATM to withdraw cash
https://t.co/aM4v0lC6we
🚨 Lo que conozco hasta ahora de la caída de Microsoft y Aena.
- Crowdstrike provée de una solución de seguridad a millones de dispositivos.
- Hacen una actualización a jueves 18 por la noche.
- La actualización es incompatible con Windows. Todos los ordenadores dan pantallazo azul.
- No se pueden arrancar los sistemas actualizados, se ha caído todo.
- Crowdstrike da como solución "eliminar un fichero y reiniciar".
- Ese fichero está protegido en la mayoría de casos por "Bitlocker", el sistema de cifrado de Windows.
- Las contraseñas de Bitlocker son MUY privadas en las empresas, es probable que solo un par de personas las conozcan.
- O las gritan a los 4 vientos y las pasa a saber todo el mundo (impensable), o tienen que ir ordenador por ordenador, 1 por 1.
- Crowdstrike ya ha caído un 13% en bolsa en pre-market, cuando abra en 5 horas va a ser una bomba.
Si me entero de más, lo cuento.
🚨CrowdStrike - Massive Outage Globally 🚨
The latest CrowdStrike update is causing a widespread issue resulting in a Blue Screen of Death (BSOD) boot loop globally.
Many users are experiencing major outages due to this problem
https://t.co/wD9TJoMDlu
#CrowdStrike
A threat actor claiming recent Santander and Ticketmaster breaches says they stole data after hacking into an employee’s account at cloud data company Snowflake.
However, Snowflake says recent breaches were caused by poorly secured customer accounts. https://t.co/OKdH5NzmHJ