๐จ TL;DR: Attackers are sending fake Sentry bug alerts to projects using public Sentry DSNs. The fake alert is designed to trick AI agents into running a malicious `npx` command that looks like a Sentry profiling diagnostic.
Do NOT run commands from Sentry issues/logs/alerts unless verified.
These are not legitimate Sentry fix commands. The malicious package reportedly steals environment variables/secrets and sends them to advisory-tracker[.]com.
I just reverse engineered the YellowKey BitLocker bypass
Microsoft shipped code that checks for a flag called "FailRelock" in every Windows 11 recovery image. When it's set to 1, after recovery unlocks your BitLocker drive, it never relocks it. All you need is a USB stick.
This code only exists in the recovery environment. Not in normal Windows. They left an entire debug testing framework in production.
@devongovett Inspired by this PR and @jordwalke's funny tweet, I did a quick research and have made a revelation that iOS Safari does *not* scroll on input focus when the input has *opacity of 0.* Simpler, and platform-independent which is somewhat of a plus! ๐ https://t.co/oAY1chlNpl
@devongovett Inspired by this PR and @jordwalke's funny tweet, I did a quick research and have made a revelation that iOS Safari does *not* scroll on input focus when the input has *opacity of 0.* Simpler, and platform-independent which is somewhat of a plus! ๐ https://t.co/oAY1chlNpl