Useful 🛡️ The #Microsoft AntiSSRF library is a security-developed, exhaustively-tested secure code library that provides robust URL validation to mitigate the risk of Server-Side Request Forgery (SSRF) vulnerabilities. It is an easy-to-use drop-in library with minimal adoption effort for developers, available for both .NET and Node.js applications.
https://t.co/9j1LRSK9Uc
#InfoSec #AppSec
🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading.
Newly confirmed compromised artifacts:
@opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads)
mistralai: 2.4.6 on PyPI
guardrails-ai: 0.10.1 on PyPI
additional @squawk/* packages on npm
guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.pyz, writes it to /tmp/transformers.pyz, and runs it with python3 without integrity verification.
The git-tanstack.com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds
Regardless I just came to say hello :^)”
The page also linked to a YouTube video and you can probably guess which one.
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you.
The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads.
The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate.
Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
A good read for every CISO and general counsel 🛡️ The Invisible Insider: How AI Agents Enable Undetectable Trade Secret Theft – and What Companies Must Do Now
https://t.co/KOsYuvGvm0 #CISO
If you are in the UK we are looking for a principal security researcher to join the team. If you have a threat hunting or incident response background, especially if you deeply understand Entra and other Azure technologies, this may be the role for you
https://t.co/TBAxJZ9F6t
@1Password, since I couldn't find where to report a bug, I would like to report a bug
Issue:
1Password extension breaks documentation with syntax highlight, which possibly came from an update around 2-3 weeks ago
Step to reproduce:
1. Have 1Password extension installed and enabled
2. Go to https://t.co/9n3bLmwjCO
This happens with both Chromium and Safari and both Desktop in both (Windows, MacOS and possibly Linux) and mobile devices (iOS, Android)
Impact:
Possibly happens to any website that is written with Vitepress, including but not limited to
- https://t.co/xcsH5ud2EP
- https://t.co/7F4gBOIxsz
- https://t.co/La5ZF3ZGr4
- https://t.co/18ZOIDq2Sj
Additional detail:
1Password build: 8.11.22.27
One of the biggest limitation of Gemini interface right now is the inability to integrate MCP servers. I can do it in Gemini CLI, but for 80% of the people in my company they really want a chat client. So my highest priority ask would be integrating MCP servers allowing me to add any MCP server into the Gemini client
@joshwoodward A native app will be amazing. My ask is an easier way to provide Google workspace files such as Google Docs as input. The current interface with using mentions is very unstable and hard to use. A browse dialogue box will be much easier.
@johnennis@joshwoodward I do that with Gemini every day. You can even give it a presentation template and ask it to use the styles and colors. Try asking Gemini how to achieve this. The trick is canvas.
Google delivers what Apple promises.
The importance of latency-free live streaming in outstanding quality can hardly be overstated.
It breaks down barriers, brings people together, creates social connections, and also facilitates easier economic cooperation and collaboration, exchange, and so much more.
If the video truly reflects this quality, Google has achieved what humanity has dreamed of for ages: global communication in real time.
Kudos to Google, you deliver every single day.
P.S.: Apple promised exactly this kind of live translation, but only Google is delivering it.
Thanksgiving is a great time to remember others that are less fortunate. Please join me in giving. If we can raise $1 million by midnight on December 2, The Reid Hoffman Foundation and the Khosla Family will triple the amount.
https://t.co/mTYPFkZkob https://t.co/aBWV9av7xM
@salesforce hardening for integrations and humans should be top priority for every CISO 🛡️ @Google says hackers stole data from 200 companies following Gainsight breach #Infosec https://t.co/Hm4KqTiKwj
🌟 Announcing a significant upgrade to the Gemini CLI user experience, making your terminal interactions more robust, intuitive, and visually stable.
It’s the same powerful Gemini CLI, just dramatically smoother!
See all the new upgrades here → https://t.co/zHYMZvwyBf
I'm hiring for 10 roles right now at AWS focused on developers.
- technical marketing (sr and mid level)
- associate developer advocates (LATAM and NAMER)
- program manager
- technical program manager
- community manager
- event manager