I factored the number RSA1024-1 using my home-built QPU stack; alarming sign that RSA1024 will soon be broken.
I'm choosing Full Disclosure, in the interest of transparency and Science advancement: https://t.co/UyImHud2n2
Non-ZK proof that the correct RSA1024 was used: https://t.co/eLdU0xpTMU
@yuvadm your move
Cloudflare Mesh is here. Ready to connect your devices, servers, and agents to a single private network 🔐
And with Workers VPC, your Workers, Agents, and Durable Objects running on Cloudflare can now reach your private MCPs, APIs, and databases directly
Oh, and it's 50 nodes + 50 users free on every account
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.