‼️🚨 A new npm supply-chain attack compromised 57 packages across over 286 malicious versions in under 2 hours. The attackers used self-replicating malware, a new version of the Miasma worm, which also used evasion techniques to stay under the radar.
The payload targets CI/CD and developer credentials, including GitHub Actions secrets, cloud credentials, Vault tokens, SSH keys, npm and GitHub tokens, and password-manager stores. This variant also injects AI coding assistant config files at `.claude`, `.cursor`, `.gemini`, and `.vscode` paths, a separate persistence and repo-poisoning angle.
Spoke at Oxford yesterday on accelerating sovereign industrialization in Africa
Was honored to be in the presence of the Vice President of Ghana, Professor Naana Jane, President of Sierra Leone, Julius Maada Bio, CG of Nigeria Customs, Dr Bashir Adeniyi, and other dignitaries
As I prepare for my security certification, I am also considering writing a risk management cert. My learning so far suggests that managing risk is key, and this varies depending on the context.
🚨 SECURITY ALERT: Vercel Infrastructure Compromise via 3rd-Party AI Tool
Vercel has confirmed a security breach linked to a compromised third-party AI tool called Context AI.
Hackers gained unauthorized access to Vercel’s internal systems through Context AI, exposing API keys, passwords, and environment variables.
If you use Vercel, take action immediately:
Read below 👇🏽
We’ve agreed to a partnership with @SpaceX that will substantially increase our compute capacity.
This, along with our other recent compute deals, means that we’ve been able to increase our usage limits for Claude Code and the Claude API.
1/2‼️🇳🇬 The Oyo State Ministry of Trade, Industry, Investment and Cooperatives (oyostatecommerce) has allegedly been breached, with 275,000 commerce identity card images leaked on a popular cybercrime forum for free.
⠀
‣ Threat Actor: AckLine
‣ Category: Data Leak
‣ Victim: Oyo State Ministry of Trade, Industry, Investment and Cooperatives
‣ Industry: Government / Commerce
⠀
The actor states the data was scraped roughly a year ago and that duplicates were not removed. The leak consists of ID card images issued to traders, farmers, artisans, and other commerce-registered individuals across Oyo State.
⠀
What's in it:
⠀
▪️ 275,000 ID card images
▪️ Size: 21.5 GB compressed, around 70 GB extracted
▪️ Type: image files (commerce ID cards)
⠀
Fields visible on each card:
⠀
▪️ Surname and other name
▪️ Date of birth
▪️ Gender
▪️ Business address
▪️ Occupation (farmer, artisan, videographer, phone engineer, etc.)
▪️ ID number
▪️ Card validity date
▪️ Photograph of cardholder