Our third winner is @realArcherL! 🎊
Another nice writeup, the technique of creating a delay by spamming the server with requests for JS/CSS was particularly.. interesting 😆
Read it here 👇
https://t.co/2tozdwqdYI
For people who don't know npm package ms is by far one of the biggest supply chain threat. If it falls 7k of the top 10k packages will be effected.
Here's a visualization of that compromise:
https://t.co/698ynV8NmP
We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin:
https://t.co/0S939n3qHC
@VenomShady@shiri_shh For people who don't know npm package ms is by far one of the biggest supply chain threat. If it falls 7k of the top 10k packages will be effected.
Here's a visualization of that compromise:
https://t.co/698ynV8NmP
Tried to map the structural ceiling — if one of the top 1000 npm packages were compromised, how many others could it theoretically reach?
example: es-errors https://t.co/QkXVrZ1gSh
🧨 Axios only needed to be resolved somewhere in your dependency graph to affect you.
Semver + transitive deps + runtime installs = hidden blast radius.
If you only checked your project’s lockfile, you may still not know.
https://t.co/JGWOOFWEY6 #nodejs
If you installed either affected version: assume breach.
✅ Rotate ALL secrets
✅ Isolate and rebuild affected machines, don't try to clean them
✅ Check logs for outbound connections to 142.11.206.73:8000
✅ Review CI pipeline build logs for the March 31 UTC window
BREAKING: axios
Maintainer or developer, do yourself a favor and star this repo, send it to your entire dev team, and follow curated and battle-tested advice to avoid future security incidents and npm package compromise: https://t.co/Thb657k4ms
I CANNOT STRESS ENOUGH
I want to share a quick thought for people in cyber security. This will be my longest tweet ever.
I’ve spoken to many lately who are having an existential crisis from the constant posts about “the end of cybersecurity jobs.”
Yes, things are changing quickly. This is a significant moment for the tech industry. Change can be uncomfortable. But we’ve seen cycles like this before.
• When GitHub and open source took off, people said software engineers would disappear because code was free.
• When AWS and cloud computing emerged, people said infrastructure jobs would vanish.
• When fuzzing and SAST tools improved, people said vulnerability research would disappear.
• Virtualization would eliminate infrastructure jobs.
• Mobile computing was going to end desktop dev.
• Exploit mitigations would end exploitability. It didn't.
Each time automation improved, the amount of software grew faster than the automation. It does feel "different" this time as it's explosive.
Some roles will shrink:
• repetitive pentesting
• basic vulnerability scanning
• tier-1 SOC monitoring
But other areas are expanding rapidly:
• AI system security
• supply chain security
• identity architecture
• autonomous agent security
• critical infrastructure protection
Historically, every time we eliminate one class of bugs, new classes emerge. Right now people are vibe-coding entire systems, giving AI access to their machines, crossing trust boundaries, and deploying autonomous agents with excessive permissions. The legal and regulatory world is nowhere close to ready.
There will absolutely be new failure modes. Humans are amazing and always adapt, finding new ways to do things.
The worst thing you can do right now is fall into a doom loop.
...and I’ll be honest, I too have felt the "psychological paralysis" a few times thinking, “Is this time different?” It's especially impactful when it comes from someone I respect in the community. There are certainly unknowns, in an industry where we've become accustomed to predictability.
But... the majority of those reactions are usually driven by social media, not reality. Platforms like X reward engagement, and sensational doom posts spread faster than measured thinking.
If you see something like:
“Holy #$%^! Opus 66.6 just found every bug in Chrome and replaced 50 startups!”
…mute it and move on.
Instead:
Stay curious.
Learn the new technology.
Adapt your skillsets.
Build things.
We’ll get through this transition the same way we always have. If I'm wrong then Sam Altman better be right about UBI! :) I'm sure that if this tweet gets any engagement that I'll get some heat for it, but a good friend of mine reminds me often to focus on what you have control over. I'll revisit this tweet at DEF CON 40!
@rez0__@DanielMiessler What can we as bug bounty hunters and researchers do? What’s the next step for us? Given that people are no longer in denial phase
It's no secret that we love TypeScript and that's why we're super excited about the latest Node.js release, 23.6.0!
This release enables executing TS without any additional configuration 🎉
How will this release change your workflow?
https://t.co/a0cTE77qyo
Dr. Manmohan Singh (1932 - 2024) 💔
He made India the fastest growing economy, gave us Right to Education Act, Right to Information Act, secured the nuclear deal and ensured free and independent media.
He was also the last Indian prime minister to give a press conference in 2014