Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. No new npm packages compromised?

No new npm packages compromised?

Scheduled Pinned Locked Moved Uncategorized
26 Posts 14 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cr0w@infosec.exchangeC cr0w@infosec.exchange

    No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

    J This user is from outside of this forum
    J This user is from outside of this forum
    jackryder@infosec.exchange
    wrote last edited by
    #17

    @cR0w Gearing up for Monday morning...

    Link Preview Image
    1 Reply Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      @huronbikes You mean fire can grow?!

      huronbikes@cyberplace.socialH This user is from outside of this forum
      huronbikes@cyberplace.socialH This user is from outside of this forum
      huronbikes@cyberplace.social
      wrote last edited by
      #18

      @cR0w I heard a rumor that it can but it's hard to confirm what with being on fire and all.

      1 Reply Last reply
      0
      • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

        @cR0w darf asked nicely

        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchange
        wrote last edited by
        #19

        @nyanbinary That doesn't sound like @darfplatypus ...

        darfplatypus@infosec.exchangeD 1 Reply Last reply
        0
        • cr0w@infosec.exchangeC cr0w@infosec.exchange

          @nyanbinary That doesn't sound like @darfplatypus ...

          darfplatypus@infosec.exchangeD This user is from outside of this forum
          darfplatypus@infosec.exchangeD This user is from outside of this forum
          darfplatypus@infosec.exchange
          wrote last edited by
          #20

          @cR0w @nyanbinary 🤐🤐🤐 pending analysis. Sorry y'all.

          1 Reply Last reply
          0
          • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

            @NuclearOatmeal @cR0w

            Link Preview Image
            da_667@infosec.exchangeD This user is from outside of this forum
            da_667@infosec.exchangeD This user is from outside of this forum
            da_667@infosec.exchange
            wrote last edited by
            #21

            @badsamurai @NuclearOatmeal @cR0w zero days. zero days, erryday

            Link Preview Image
            1 Reply Last reply
            0
            • cr0w@infosec.exchangeC cr0w@infosec.exchange

              No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.social
              wrote last edited by
              #22

              @cR0w docker 0days coming, stuff embargoed atm. more npm tooooo https://xchglabs.com/blog/

              cr0w@infosec.exchangeC 1 Reply Last reply
              1
              0
              • viss@mastodon.socialV viss@mastodon.social

                @cR0w docker 0days coming, stuff embargoed atm. more npm tooooo https://xchglabs.com/blog/

                cr0w@infosec.exchangeC This user is from outside of this forum
                cr0w@infosec.exchangeC This user is from outside of this forum
                cr0w@infosec.exchange
                wrote last edited by
                #23

                @Viss I saw that but no timeline and no descriptions. Could be total bummers like a lot of the "coming soon" stuff from ZDI and Talos. Fingers crossed though.

                1 Reply Last reply
                0
                • nuclearoatmeal@beige.partyN nuclearoatmeal@beige.party

                  @cR0w

                  Day ain't over yet.

                  shellsharks@shellsharks.socialS This user is from outside of this forum
                  shellsharks@shellsharks.socialS This user is from outside of this forum
                  shellsharks@shellsharks.social
                  wrote last edited by
                  #24

                  @NuclearOatmeal @cR0w OpenClaw says "my turn" - https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw

                  cr0w@infosec.exchangeC 1 Reply Last reply
                  0
                  • shellsharks@shellsharks.socialS shellsharks@shellsharks.social

                    @NuclearOatmeal @cR0w OpenClaw says "my turn" - https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw

                    cr0w@infosec.exchangeC This user is from outside of this forum
                    cr0w@infosec.exchangeC This user is from outside of this forum
                    cr0w@infosec.exchange
                    wrote last edited by
                    #25

                    @shellsharks @NuclearOatmeal In fairness, isn't OpenClaw basically like a Damn Vulnerable Agent for testing and learning at this point?

                    shellsharks@shellsharks.socialS 1 Reply Last reply
                    0
                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                      @shellsharks @NuclearOatmeal In fairness, isn't OpenClaw basically like a Damn Vulnerable Agent for testing and learning at this point?

                      shellsharks@shellsharks.socialS This user is from outside of this forum
                      shellsharks@shellsharks.socialS This user is from outside of this forum
                      shellsharks@shellsharks.social
                      wrote last edited by
                      #26

                      @cR0w @NuclearOatmeal Yeah if DVWA was installed on thousands of endpoints and *checks notes* also exposed to the Internet 😭

                      Protean Labs | Engineering Blog

                      favicon

                      (protean-labs.io)

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups