1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
Are you an aspiring hacker?
Web Security Academy is the perfect place for you to kickstart your journey! And the best part is, it’s TOTALLY FREE!
Download your main tool here 👇
https://t.co/DEh3hHPH16
Start learning here 👇
https://t.co/mp7JjcMrKA
If you’re tracking the AV detection rate for the web shells dropped in recent SharePoint attacks (CVE-2025-53770), here’s the current picture:
Samples:
27c45b8ed7b8a7e5fff473b50c24028bd028a9fe8e25e5cea2bf5e676e531014
92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514
8d3d3f3a17d233bc8562765e61f7314ca7a08130ac0fb153ffd091612920b0f2
b336f936be13b3d01a8544ea3906193608022b40c28dd8f1f281e361c9b64e93
Detections: still very low or zero.
But my colleague Arnim’s community YARA rule caught these immediately when first dropped:
https://t.co/4u4yGbaHhZ
A solid reminder why layered detection approaches matter.
#SharePoint #YARA #ThreatDetection #CVE202553770
Btw, this detection is already live in THOR Lite and THOR Cloud Lite. I’ll also add detection for the compiled ASPX soon.
https://t.co/AaMCX5PZMD
Top 10 System design concepts to learn in 2025
1. Caching
2. DB Sharding
3. load-balancing
4. replication
5. fault-tolerance
6. high-availability
7. API Gateway
8. scalability
9. Performance
10. Indexing
learn more on DesignGuru - https://t.co/jBqv3o2zzL
@RussianPanda9xx Thanks for that great writeup on StealC v2! In addition to the HTTP based C2 there seems to be another C2 that also uses base64, but directly over TCP (no HTTP). Any ideas what this could be and how to parse this data?
🛠️ Guide to Essential Penetration Testing Commands💻
Penetration testing (pentesting) is essential for identifying cybersecurity vulnerabilities. Here’s an overview of key commands for information gathering, exploitation, and access maintenance.
Introduction to Windows Kernel Exploitation for Beginners
Part 1: https://t.co/iytco8khA0
Part 2: https://t.co/Kr5z56e0pV
Part 3: https://t.co/sdI2uEndk6
Part 4: https://t.co/6DmUNO3iQU
Part 5: https://t.co/CW1ulPqGqq
#windows#infosec#kernal#exploit#100xSecurity
Innalillahi , Semoga Allah Ta’ala merahmati Ustadz Yazid bin Abdul Qadir Jawas dengan rahmatNya yang luas.
Beliau termasuk di antara da’i di Indonesia yang telah menghabiskan masa hidupnya untuk mendakwahkan tauhid.
Semoga Allah mengampuni dosa-dosa beliau, menerima amal shalih beliau, dan semoga apa yang beliau sampaikan berupa ilmu bisa menjadi jariyah yang terus mengalir pahalanya.
Semoga kita dimudahkan untuk bisa mengamalkan nasihat-nasihat beliau.