Forwarded from The Hacker News
π¨ WARNING: The self-spreading βMini Shai-Huludβ worm compromised npm & PyPI packages tied to TanStack, Mistral AI, Guardrails AI, OpenSearch & more.
The attack used GitHub OIDC token hijacking and cache poisoning to spread credential-stealing malware across 42 TanStack packages and 84 versions.
Check your dependencies immediately β https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html
The attack used GitHub OIDC token hijacking and cache poisoning to spread credential-stealing malware across 42 TanStack packages and 84 versions.
Check your dependencies immediately β https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html
β‘2π€―1
Forwarded from yoseph.won (Yoseph Wondimu π)
Not even close to where I want to be
but far from where it all started
and that's enough to keep me going π€
but far from where it all started
and that's enough to keep me going π€
β‘13
so YouTubers and other influencers tell us to check our passwords if they are crackable or leaked by copying and pasting them to websites like Have I Been Pwned
I mean do you guys believe those sites those :) ? I have been questioning this myself for a long time thats why
@AfroSec
I mean do you guys believe those sites those :) ? I have been questioning this myself for a long time thats why
@AfroSec
π€5π€1πΏ1
π₯13π1
thanks to someone now am addicted to the violin hiphop
https://www.youtube.com/watch?v=13SG0auXCco
@AfroSec
https://www.youtube.com/watch?v=13SG0auXCco
@AfroSec
YouTube
γViolin x Hip Hop Playlistγ β Sharp Rhythm, Deep Flow
π» Tokyo Violinhop is where violin leads hip-hop into deep focus and creative flow.
Tokyo Violinhop blends expressive, emotional violin with the pulse of modern hip hop.
Each track brings warm violin melodies into a clean world of boom-bap drums, deep bassβ¦
Tokyo Violinhop blends expressive, emotional violin with the pulse of modern hip hop.
Each track brings warm violin melodies into a clean world of boom-bap drums, deep bassβ¦
β€βπ₯5π₯1
AfroSec
wining is the only option fam, πͺπͺ @AfroSec
No one cares about your life story until the day you win
so again, winning is the only option
not trynna be a motivator here but just telling what should be told π€·ββοΈ
@AfroSec
π―17π2
has anybody faced a honeypot so far?
Not me, tho, but it is good to know how to detect honeypot setups.
> They have outdated services and ports, like they are a complete decoy, such as an old version of WordPress or Apache and Nginx.
> They have a perfect bait, like a default password or something like that
> And they have a passive response; they are not real operating systems, so they won't have a full handshake. They will refuse at some point, u will see some inconsistency
To figure out (identify the decoy):
> Lookup the IP and domain on threat intel platforms like Shodan, which may reveal the ASN that IP belongs to and stuff like that
> Or use an automated scanner with less threat ig
this is what i found from the internet eski arif honeypot resource kagegnew i will share it
@AfroSec
Not me, tho, but it is good to know how to detect honeypot setups.
> They have outdated services and ports, like they are a complete decoy, such as an old version of WordPress or Apache and Nginx.
> They have a perfect bait, like a default password or something like that
> And they have a passive response; they are not real operating systems, so they won't have a full handshake. They will refuse at some point, u will see some inconsistency
To figure out (identify the decoy):
> Lookup the IP and domain on threat intel platforms like Shodan, which may reveal the ASN that IP belongs to and stuff like that
> Or use an automated scanner with less threat ig
this is what i found from the internet eski arif honeypot resource kagegnew i will share it
@AfroSec
π2π€2β1
What a Sunday
I was minding my own business and suddenly stumbled upon some weird TG channel and found a link to a library-like SaaS application. I clicked it, it took me to the site, and I saw the book, but it asked for a login. Then I logged in with a temp email, tried to download the file, but ended up needing to pay.
Huh, seriously? Nibba nah, nah
I intercepted the request. I saw the backend is Supabase and the frontend is on Vercel. Then I opened Burp and everything was there, like the download URL and hidden subdomain. I went to that subdomain, but only the devs can log in. But lucky me, I can request any book and download via interception. :)
Not a bad guy after all; I reported it to them ππππ
@AfroSec
I was minding my own business and suddenly stumbled upon some weird TG channel and found a link to a library-like SaaS application. I clicked it, it took me to the site, and I saw the book, but it asked for a login. Then I logged in with a temp email, tried to download the file, but ended up needing to pay.
Huh, seriously? Nibba nah, nah
I intercepted the request. I saw the backend is Supabase and the frontend is on Vercel. Then I opened Burp and everything was there, like the download URL and hidden subdomain. I went to that subdomain, but only the devs can log in. But lucky me, I can request any book and download via interception. :)
Not a bad guy after all; I reported it to them ππππ
@AfroSec
π₯8π2π«‘2β€1π1
Last spam of the day:
so kdm, which 11:30 PM Akababi local time Indeed, I went out with my bro to play PS, then the owner was initiating a kernel exploit to play FIFA 2026. I saw the logs on the screen and asked my bro; he said this is the jailbroken one, so Leza new Mnamn and i was like ufff ππ
i bet the dude dont know what actually happening behind the scene belew
@AfroSec
so kdm, which 11:30 PM Akababi local time Indeed, I went out with my bro to play PS, then the owner was initiating a kernel exploit to play FIFA 2026. I saw the logs on the screen and asked my bro; he said this is the jailbroken one, so Leza new Mnamn and i was like ufff ππ
i bet the dude dont know what actually happening behind the scene belew
@AfroSec
π€£7β€1π1