Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. No new npm packages compromised?

No new npm packages compromised?

Scheduled Pinned Locked Moved Uncategorized
26 Posts 14 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • viss@mastodon.socialV viss@mastodon.social

    @ciaranmak @starchturrets @cR0w oh god yes. docker 0day. shoot that shit right into my veins

    starchturrets@mastodon.socialS This user is from outside of this forum
    starchturrets@mastodon.socialS This user is from outside of this forum
    starchturrets@mastodon.social
    wrote last edited by
    #10

    @Viss @ciaranmak @cR0w well runc isn't really a very strong boundary compared to gvisor or kata containers, so I'm not too worried there

    1 Reply Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

      rikusilvola@infosec.exchangeR This user is from outside of this forum
      rikusilvola@infosec.exchangeR This user is from outside of this forum
      rikusilvola@infosec.exchange
      wrote last edited by
      #11

      @cR0w here you go https://www.openwall.com/lists/oss-security/2026/05/15/2

      1 Reply Last reply
      1
      0
      • cr0w@infosec.exchangeC cr0w@infosec.exchange

        No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

        nuclearoatmeal@beige.partyN This user is from outside of this forum
        nuclearoatmeal@beige.partyN This user is from outside of this forum
        nuclearoatmeal@beige.party
        wrote last edited by
        #12

        @cR0w

        Day ain't over yet.

        badsamurai@infosec.exchangeB shellsharks@shellsharks.socialS 2 Replies Last reply
        0
        • cr0w@infosec.exchangeC cr0w@infosec.exchange

          No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

          huronbikes@cyberplace.socialH This user is from outside of this forum
          huronbikes@cyberplace.socialH This user is from outside of this forum
          huronbikes@cyberplace.social
          wrote last edited by
          #13

          @cR0w maybe all the fire is hiding some fire we don't know about

          cr0w@infosec.exchangeC 1 Reply Last reply
          1
          0
          • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

            @cR0w maybe all the fire is hiding some fire we don't know about

            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchange
            wrote last edited by
            #14

            @huronbikes You mean fire can grow?!

            huronbikes@cyberplace.socialH 1 Reply Last reply
            1
            0
            • nuclearoatmeal@beige.partyN nuclearoatmeal@beige.party

              @cR0w

              Day ain't over yet.

              badsamurai@infosec.exchangeB This user is from outside of this forum
              badsamurai@infosec.exchangeB This user is from outside of this forum
              badsamurai@infosec.exchange
              wrote last edited by
              #15

              @NuclearOatmeal @cR0w

              Link Preview Image
              da_667@infosec.exchangeD 1 Reply Last reply
              0
              • cr0w@infosec.exchangeC cr0w@infosec.exchange

                No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

                nyanbinary@infosec.exchangeN This user is from outside of this forum
                nyanbinary@infosec.exchangeN This user is from outside of this forum
                nyanbinary@infosec.exchange
                wrote last edited by
                #16

                @cR0w darf asked nicely

                cr0w@infosec.exchangeC 1 Reply Last reply
                0
                • cr0w@infosec.exchangeC cr0w@infosec.exchange

                  No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

                  J This user is from outside of this forum
                  J This user is from outside of this forum
                  jackryder@infosec.exchange
                  wrote last edited by
                  #17

                  @cR0w Gearing up for Monday morning...

                  Link Preview Image
                  1 Reply Last reply
                  0
                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                    @huronbikes You mean fire can grow?!

                    huronbikes@cyberplace.socialH This user is from outside of this forum
                    huronbikes@cyberplace.socialH This user is from outside of this forum
                    huronbikes@cyberplace.social
                    wrote last edited by
                    #18

                    @cR0w I heard a rumor that it can but it's hard to confirm what with being on fire and all.

                    1 Reply Last reply
                    0
                    • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

                      @cR0w darf asked nicely

                      cr0w@infosec.exchangeC This user is from outside of this forum
                      cr0w@infosec.exchangeC This user is from outside of this forum
                      cr0w@infosec.exchange
                      wrote last edited by
                      #19

                      @nyanbinary That doesn't sound like @darfplatypus ...

                      darfplatypus@infosec.exchangeD 1 Reply Last reply
                      0
                      • cr0w@infosec.exchangeC cr0w@infosec.exchange

                        @nyanbinary That doesn't sound like @darfplatypus ...

                        darfplatypus@infosec.exchangeD This user is from outside of this forum
                        darfplatypus@infosec.exchangeD This user is from outside of this forum
                        darfplatypus@infosec.exchange
                        wrote last edited by
                        #20

                        @cR0w @nyanbinary 🀐🀐🀐 pending analysis. Sorry y'all.

                        1 Reply Last reply
                        0
                        • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                          @NuclearOatmeal @cR0w

                          Link Preview Image
                          da_667@infosec.exchangeD This user is from outside of this forum
                          da_667@infosec.exchangeD This user is from outside of this forum
                          da_667@infosec.exchange
                          wrote last edited by
                          #21

                          @badsamurai @NuclearOatmeal @cR0w zero days. zero days, erryday

                          Link Preview Image
                          1 Reply Last reply
                          0
                          • cr0w@infosec.exchangeC cr0w@infosec.exchange

                            No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.social
                            wrote last edited by
                            #22

                            @cR0w docker 0days coming, stuff embargoed atm. more npm tooooo https://xchglabs.com/blog/

                            cr0w@infosec.exchangeC 1 Reply Last reply
                            1
                            0
                            • viss@mastodon.socialV viss@mastodon.social

                              @cR0w docker 0days coming, stuff embargoed atm. more npm tooooo https://xchglabs.com/blog/

                              cr0w@infosec.exchangeC This user is from outside of this forum
                              cr0w@infosec.exchangeC This user is from outside of this forum
                              cr0w@infosec.exchange
                              wrote last edited by
                              #23

                              @Viss I saw that but no timeline and no descriptions. Could be total bummers like a lot of the "coming soon" stuff from ZDI and Talos. Fingers crossed though.

                              1 Reply Last reply
                              0
                              • nuclearoatmeal@beige.partyN nuclearoatmeal@beige.party

                                @cR0w

                                Day ain't over yet.

                                shellsharks@shellsharks.socialS This user is from outside of this forum
                                shellsharks@shellsharks.socialS This user is from outside of this forum
                                shellsharks@shellsharks.social
                                wrote last edited by
                                #24

                                @NuclearOatmeal @cR0w OpenClaw says "my turn" - https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw

                                cr0w@infosec.exchangeC 1 Reply Last reply
                                0
                                • shellsharks@shellsharks.socialS shellsharks@shellsharks.social

                                  @NuclearOatmeal @cR0w OpenClaw says "my turn" - https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw

                                  cr0w@infosec.exchangeC This user is from outside of this forum
                                  cr0w@infosec.exchangeC This user is from outside of this forum
                                  cr0w@infosec.exchange
                                  wrote last edited by
                                  #25

                                  @shellsharks @NuclearOatmeal In fairness, isn't OpenClaw basically like a Damn Vulnerable Agent for testing and learning at this point?

                                  shellsharks@shellsharks.socialS 1 Reply Last reply
                                  0
                                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                    @shellsharks @NuclearOatmeal In fairness, isn't OpenClaw basically like a Damn Vulnerable Agent for testing and learning at this point?

                                    shellsharks@shellsharks.socialS This user is from outside of this forum
                                    shellsharks@shellsharks.socialS This user is from outside of this forum
                                    shellsharks@shellsharks.social
                                    wrote last edited by
                                    #26

                                    @cR0w @NuclearOatmeal Yeah if DVWA was installed on thousands of endpoints and *checks notes* also exposed to the Internet 😭

                                    Protean Labs | Engineering Blog

                                    favicon

                                    (protean-labs.io)

                                    1 Reply Last reply
                                    0
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • World
                                    • Users
                                    • Groups