Is London still safe? George Simion, Romanian presidential candidate, joins The Liz Truss Show to sound an alarm on Western Europe’s future and the impact of mass migration.
BREAKING: Axios reports that Trump told Netanyahu in their latest phonecall, 'You’re f***ing crazy. You’d be in prison if it weren’t for me. I’m saving your ass. Everybody hates you now. Everybody hates Israel because of this.'
Toncoin (TON) -> Gram (GRAM)
Community vote is live.
Since Telegram took a leading role in TON's development, the chain got 10× faster, fees 6× lower.
And now Telegram proposes one more change: renaming Toncoin to Gram - the name from the original TON White Paper that never left the codebase.
Vote here -> https://t.co/TH8DTmXJ61
BREAKING: TON's native currency is rebranding to Gram
TON remains the name of the blockchain
this is step 4/7 to Make $TON Great Again
Durov's cooking something 👀
Microsoft has identified a npm supply chain compromise impacting 90+ redhat-cloud-services/* packages, including patch-client 4.0.4, insights-client 4.0.4, rbac-client 9.0.3, host-inventory-client 5.0.3, frontend-components 7.7.2, and others. The payload is a self-propagating worm that infects other npm packages and self-publishes.
Each compromised package adds a malicious preinstall hook, embedding an index.js script in the package.json that silently executes “node index.js” during installation, downloads Bun, and runs a payload that steals secrets from npm, GitHub, Amazon Web Services (AWS), and Secure Shell (SSH). The added code bloats index.js from ~8KB to ~4.3MB, acting as a heavily obfuscated ROT-9 eval loader.
If any of the compromised packages are installed, users and organizations should assume compromise, rotate credentials, revert to a previously trusted version, and block compromised packages. Identified compromised npm packages have been taken down, and we continue to work with the npm team. Microsoft continues to investigate this attack and will publish updates as more information is available.
TeamPCP’s supply chain campaign leverages CI/CD pipelines to steal credentials at scale. Our research details how stolen npm tokens were reused within 24 hours in the Bitwarden CLI hijack. Read the latest report from TrendAI™ Research: https://t.co/jrSBUugCiY
$TON is undervalued and here's why:
BTW, $8 will be fair... for now
No other blockchain in the world has direct, seamless access (via its built-in Wallet) to the HUGE Web2 native audience.
@telegram has one billion monthly active users (MAU). Currently, analysts estimate the number of activated wallets with transaction history in the TON network at ~25-40M
This means that the conversion rate of Telegram users to Web3 users on TON is currently only around 2-4%.
Even if this figure grows to 10%, the network will have almost 100M active addresses.
I believe Telegram will become something like WeChat - only for the entire world. Hundreds of millions of people will use it for daily payments, thereby fueling TON.
The market has not yet priced in this potential conversion. So, the price of $TON might be at least four times higher - $8 (plus future market recovery)
Seqrite reports a China-linked campaign targeting the Czech Republic and Taiwan, using two delivery paths to deploy Rust loader and AZUREVEIL C2 via Azure Blob Storage with 36 commands for in-memory, multi-stage espionage. https://t.co/7aCewM4Mp0
🚨 Security researchers are now handing over vulnerabilities to Nightmare Eclipse after he was banned on both GitLab and GitHub.
It should be a fun month, because man has it been boring the last couple of weeks.
Not that ‘responsible’ disclosure shit again 🙄
No vendor uses that term unless they want to call someone irresponsible.
Even if someone drops 0day, patch & move on. Going after a researcher is a great way to turn 1 bad relationship into many terrible relationships.
Famous Chollima, the North Korean threat group known for fake job interview lures, appears to have used a PHP/Packagist package path in a targeted developer lure.
We found the loader in a compromised Laravel package, on a branch that could be installed through Composer. It was appended after a normal Tailwind config and used TRON, Aptos, and BNB Smart Chain RPC infrastructure to retrieve and run remote JavaScript.
Developers should be careful with “interview task” or “take-home project” requests that ask them to clone a repo, check out a specific branch, or install an exact dev dependency.
Yesterday the FBI released an advisory on the Silent Ransom Group (SRG), aka Luna Moth, Chatty Spider, and UNC3753, who use social engineering techniques like phone calls and phishing emails to access victim computers. SRG actors have been steadily targeting law firms since 2023, and they focus on accessing victim systems, exfiltrating data, and extorting their victims by threatening to release or sell the stolen data.
Since SRG actors use legitimate remote access tools, there are few artifacts of their attacks. Review the advisory to learn how SRG actors operate to exfiltrate data and potential signs of SRG activity: https://t.co/JxQXleJNC8.
Microsoft has uncovered a supply chain attack involving malicious npm packages registered under organizational scopes that mirror real internal corporate namespaces, employing dependency confusion technique to deploy a reconnaissance payload. https://t.co/z2GjRIAyYS
A threat actor operating under three maintainer aliases, mr.4nd3r50n, ce-rwb, and t-in-one, published malicious packages that impersonate internal corporate packages, with several spoofing internal enterprise infrastructure URLs in their package.json to appear legitimate.
Once installed, the packages download and execute an obfuscated payload from an attacker-controlled command-and-control (C2) server to collect system information, hostnames, environment variables, and developer context. Read the blog for in-depth analysis and mitigation, detection, and hunting details.
Viele deutsche Unternehmen halten trotz Sanktionen in Russland laut einer neuen Umfrage ihre Stellung. Beim Wirtschaftsforum in St. Petersburg gibt es nun erstmals auch einen Business-Dialog. https://t.co/j6RRKCJ8yZ