Hatlen @hatlen
I do cybersecurity and make computer go beep boop when it doesn't want to. Joined September 2019-
Tweets492
-
Followers26
-
Following219
-
Likes2K
🚨A HACKER GROUP JUST STOLE 4,000 OF GITHUB'S OWN PRIVATE REPOSITORIES.. PUT THEM UP FOR SALE FOR $50,000.. AND THE WAY THEY GOT IN IS THE SCARIEST PART.. They didn't hack GitHub's servers.. They poisoned a VS Code extension.. One GitHub employee installed it.. And the attackers walked through the front door using the employee's own credentials.. The group calls themselves TeamPCP.. They name their malware after the sandworms from Dune.. And they've been running the most sophisticated supply chain attack campaign in cybersecurity history.. Here's how the whole thing unfolded.. In March.. They poisoned Trivy.. One of the most trusted security scanners in the world.. Used by over 10,000 development workflows globally.. They injected credential-stealing malware into Trivy's official GitHub Action.. The malware ran silently BEFORE the security scan.. So every log showed "scan completed successfully" while the malware was stealing AWS keys, SSH credentials, database passwords, and Kubernetes tokens in the background.. It took Aqua Security 5 days to fully remove them.. Using the stolen credentials.. They breached Cisco Systems.. Cloned over 300 private repositories.. Including source code for unreleased AI products.. And repositories belonging to Cisco's customers.. Major banks.. Government agencies.. BPO firms.. In April.. They hit Checkmarx.. Another security vendor.. Poisoned 5 official Docker images in 83 minutes.. The scanner worked perfectly.. It just silently sent all your secrets to the attackers.. That automatically cascaded into Bitwarden.. The password manager.. Their CI/CD system pulled the poisoned Docker image.. And the attackers injected malware into Bitwarden's official CLI package published on npm.. One compromised security scanner poisoned a password manager.. Automatically.. No human involved.. In May.. They hit TanStack.. Libraries downloaded millions of times per week.. 84 malicious package versions across 42 packages.. And here's the terrifying part.. The malware scraped the raw memory of GitHub's build servers.. Extracted authentication tokens.. Used those tokens to bypass two-factor authentication.. And then published the infected packages with completely valid cryptographic signatures.. Every security verification tool on earth said the packages were legitimate.. Because they were signed by the real pipeline.. Using real keys.. The attackers just happened to be inside the pipeline when it signed.. They defeated the entire trust model of modern software supply chains.. The same week they hit the Nx Console VS Code extension.. 2.2 million installations.. The malware specifically targeted Claude Code configurations.. Hunting for AI assistant credentials.. That's a first.. Supply chain malware designed to steal your AI's access keys.. Then on May 19.. They revealed the GitHub breach.. 4,000 internal repositories.. Listed for sale at $50,000.. With a warning.. "If nobody buys it.. We leak everything for free".. Their malware is self-propagating.. Once it infects one package.. It automatically finds every other package that developer maintains.. Steals the publish tokens.. And infects all of them.. Then those packages infect the next developer.. And the next.. It jumps between npm and PyPI automatically.. The group doesn't even do the extortion themselves.. They sell stolen credentials to ransomware gangs.. One gang used TeamPCP's data to threaten Cisco with leaking FBI and NASA personnel records.. And the scariest part of all.. They didn't break any encryption.. They didn't find any zero-days.. They exploited the fact that the entire software industry blindly trusts its own build tools.. Every security scanner.. Every Docker image.. Every VS Code extension.. Every GitHub Action.. Is a potential weapon if someone poisons it upstream.. And right now.. Nobody can tell the difference between a legitimate build and a compromised one.. Because the compromised ones have valid signatures too.
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely
@rootxharsh @HacktronAI What do you mean "isn't limited to PAN-OS"?
@DarkWebInformer Looks like just a scrape of their public "find employees" function. It's on the website. Not really sure why they post private post address there, but besides that it's really nothing. Not an AD dump at all I think.
@alexocheema @eastdakota @Cloudflare Cloudflare seems to disagree. Not even their whole backbone is measured in Pbps. Not sure what in HPC you are comparing it to? I doubt it's network speeds.
@alexocheema @eastdakota @Cloudflare Takes a lot of scaling going from 400Gbps to Pbps, but sure. You would need 2500 400 Gbps NICs to reach a single petabit.
@MoonguardX @0xFar3000 @eastdakota @Cloudflare That is 5800 Gbps. Generating a data stream locally isn't the problem, delivering it through the internet at 580 times what you can generate is the problem. Even out of a country you might start capping well before that for cross-country backbone links.. oversubscription is key
@alexocheema @eastdakota @Cloudflare You have more than 400Gbps interfaces in those beasts?
@_yushe My biggest fear in life is someone seeing my code.
@pjlast_ You lost me at "bank allows you to specify javascript", that is wild. What could go wrong? I really want to know how they implemented this, lol.
@NotTravisNewman @strager Now you can do the latter js-less version with complex javascript, polyfills and libraries! Without leaving any JS out of the backend written frontend! So we can achieve the same results as before, but with a lot more complex code. What is there to not understand?
Is Microsoft Recall MANDATORY now? What do you think? Over reacting? Or is this really a privacy concern? #windows #microsoft #ai #linux #macos #blackmirror #privacy @_JohnHammond @christitustech
@evilsocket Not ignoring it, but you still gotta print, right? Still a great, awesome find nevertheless.
@miketheitguy I realize I'm late to the game. Did you decide? My two cents are on Netgate if you're going physical! :)
@el_nawser Any attacker will just pass the hash and do winrm or whatever.
FortiGate under active exploitation. Patch ASAP and check your logs for compromise.
ERICK TRUMP @ETrump248
465 Followers 4K Following Fan page of Executive vice President of The @Trump organization. Large advocate of @StJude Children’s Hospital #MAGA
Bjørn @bhenninen
68 Followers 343 Following Helping companies that have been hacked Can also roll dice and venture down in dungeons with dragons. Tweets are my own and does not reflect views of employer
Simen @bottekott
57 Followers 553 Following
TomU | I'm still here... @c_APT_ure
8K Followers 6K Following #InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
Thomas R @trensvold
135 Followers 337 Following
Marc-André Moreau @awakecoding
6K Followers 2K Following Remote desktop protocol expert, OSS contributor and Microsoft MVP. I love designing products with Rust, C# and PowerShell. Proud to be CTO at Devolutions. 🇨🇦
Jef Kazimer @JefTek
5K Followers 3K Following Principal Product Manager @Microsoft #MicrosoftEmployee #Microsoft #Entra #Identity #EntraID - Tweets are my own
The ICT Guy @theictguy_co_uk
2K Followers 4K Following Daddy to 2, Geek, 3rd Line IT Engineer, Security & Compliance focused, #Intune #Azure #Cloud specialist. Sleeps better when devices are compliant. Views my own.
Rob de Jong @rjong999
3K Followers 776 Following Digital Marketing Professional, specializing in PPC and interested in applying AI and deep learning to bidding optimization algorithms.
𝙠𝙤𝙙𝙚24 @kode24no
2K Followers 737 Following Nettavisa for norske utviklere er nå ferdige med X, men følg oss gjerne på Bluesky! 👋
regnil @regnil
34 Followers 414 Following
rayh4c @rayh4c
2K Followers 4K Following
Sam Erde @SamErde
3K Followers 2K Following PowerShell MVP that is passionate about helping others succeed with Active Directory, Entra ID, Defender XDR, and Microsoft 365. Always learning! ✝️👨👩👧👦☕
Karim El-Melhaoui @karimscloud
823 Followers 724 Following Principal Security Architect & Partner at https://t.co/yIU71SfS40, CloudSec Researcher. Find me at bsky
Vilje @Vilje34326832
38 Followers 189 Following
Ally @Ally37149753
29 Followers 339 Following
Mrtn @Mrtn9
1K Followers 1K Following
Hans-Petter Fjeld @atluxity
861 Followers 2K Following Senior security analyst at Defendable. Co-founder Oslo hackerspace Hackeriet. Former head of Norwegian Unix User Group. https://t.co/HuK8ccOXJL
Marit Iren 👩🏼�... @maritio_o
499 Followers 714 Following @bootplug_ctf / @soprasteria_no / Pwnrpuff Girls / Oslo CTF / Engaged in security, and encouraging students to learn ethical hacking and secure development
Tom Gankz @0xTomG
143 Followers 240 Following CTI Analyst at NORMA Cyber Resilience Centre. Proud member of 5H3LL. He\Him. Tweets are my own. @CuratedIntel Profile credit https://t.co/pBdZ3DffQB
Dark Web Informer @DarkWebInformer
221K Followers 72 Following One guy. Global cybercrime. Tracked so you don't have to. Ransomware, data breaches, dark web activity, darknet markets, IOCs & emerging threats. Stay informed!
watchTowr @watchtowrcyber
12K Followers 12 Following watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.
Unblvr @Unblvr1
467 Followers 42 Following CTF player | https://t.co/qfpNfBaxFK | https://t.co/fpmI3UGuh8
Bjørn @bhenninen
68 Followers 343 Following Helping companies that have been hacked Can also roll dice and venture down in dungeons with dragons. Tweets are my own and does not reflect views of employer
Simen @bottekott
57 Followers 553 Following
TomU | I'm still here... @c_APT_ure
8K Followers 6K Following #InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
Thomas R @trensvold
135 Followers 337 Following
C:\hristina @divinetechygirl
23K Followers 7K Following Information Security Leader & Published Author • Leading InfoSec & Cyber @ 🏈 • Love a fitted but I don’t 🧢
Marc-André Moreau @awakecoding
6K Followers 2K Following Remote desktop protocol expert, OSS contributor and Microsoft MVP. I love designing products with Rust, C# and PowerShell. Proud to be CTO at Devolutions. 🇨🇦
Ransomware News @RansomwareNews
31K Followers 0 Following This Twitter Bot gets updates from ransomware groups For removal requests DM @vxunderground Feed maintained by @joshhighet
Johann Rehberger @wunderwuzzi23
10K Followers 616 Following Hacking neural networks so that we don’t get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg
MCKSys Argentina @MCKSysAr
1K Followers 146 Following Exploit Writer, Reverser, Old School Cracker, Atheist, etc. Breaking stuff since '98. Tweets are my own.
Gameel Ali 🤘 @MalGamy12
7K Followers 965 Following Threat Researcher @nextronsystems All opinions are my own
Justin Gardner @Rhynorater
37K Followers 2K Following Christian | Full-time Bug Bounty Hunter | Host of @ctbbpodcast | Advisor @CaidoIO | 4x LHE MVH | 🗣️ English, 日本語 | ♥️ @mariahchan_ ♥️
Dr. Anton Chuvakin @anton_chuvakin
42K Followers 9K Following Information security - #SIEM, #DFIR, #EDR formerly at Gartner! Now @GoogleCloud Office of the #CISO; host of @CloudSecPodcast https://t.co/VpKtfz8nXG
Aurélien Chalot @Defte_
4K Followers 487 Following Hacker, sysadmin and security researcher @OrangeCyberdef 💻 Calisthenic enthousiast 💪 and wannabe philosopher https://t.co/SqDDhIGGGh 📖 🔥 Hide&Sec 🔥
The ICT Guy @theictguy_co_uk
2K Followers 4K Following Daddy to 2, Geek, 3rd Line IT Engineer, Security & Compliance focused, #Intune #Azure #Cloud specialist. Sleeps better when devices are compliant. Views my own.
Soren Iverson @soren_iverson
290K Followers 128 Following Idea guy. Building @iverson and @stompersapp
John @jabjorkhaug
454 Followers 630 Following Professional pwner. I break things for a living. All tweets are my own, and must not relate to my work.
Rowan Cheung @rowancheung
593K Followers 565 Following Founder of the world’s most read daily AI newsletter @therundownai. Sharing the latest developments in the world of artificial intelligence.
Jeremy Moskowitz @jeremymoskowitz
4K Followers 1K Following 20-Time Microsoft MVP awardee (Former) in GPOs and MDM. CTO Endpoints @Netwrix. Tech blogs at https://t.co/l8yIknrtFE.
Ned is 🌮🏃🦖�... @Ned1313
4K Followers 1K Following Curious Human, Technical Educator, Microsoft Azure MVP, Pluralsight author, HashiCorp Ambassador, serial podcaster, imbiber of delicious beer, 🌮🌮🌮. He/him.
Doug @dougsbaker
645 Followers 331 Following Microsoft Security & Compliance enthusiast 💻 Helping people navigate M365💡 Youtuber 🎥 Tweeting tips and tricks 💬 Making the digital world a safer place
Rob de Jong @rjong999
3K Followers 776 Following Digital Marketing Professional, specializing in PPC and interested in applying AI and deep learning to bidding optimization algorithms.
Kit @smallfoxx
79 Followers 450 Following Tech geek, Windows guru, PoSh scripter, and Azure advocate
Tim Bolton @jsclmedave
843 Followers 584 Following Fishing, Music, Golf, anything with my wife and son Loki. PowerShell, Azure Identity. Views posted here are my own.
NO LONGER HERE, FIND ... @JustinWGrote
3K Followers 305 Following I NO LONGER USE X. Now on BlueSky: https://t.co/5GDjDFw2aD
dfo @dfowler_
78 Followers 363 Following Email Architect but my Interests include Dogs, Email Security, M365, Powershell, pellet grills and DAD JOKES
Thom McKiernan (now o... @thommck
837 Followers 1K Following Enough is enough, find me on Bluesky, LI & Insta. https://t.co/TVmAjjDIaD Tech & Sustainability Specialist @Microsoft
spencer @techspence
17K Followers 3K Following 🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack | @SecurIT360 & @CyberThreatPOV
Josh Duffney @joshduffney
7K Followers 304 Following mid programmer | cloud-native @microsoft | uses vim | containers & wasm nerd | lego dad | minimalist wannabe
Buck Woody @BuckWoodyMSFT
11K Followers 264 Following
Andres Bohren 🇨�... @andresbohren
2K Followers 1K Following Cloud Architect, Messaging and Communication Expert, M365, ADDS, Entra ID, Entra Sync, Azure, Security, PowerShell Enthusiast, CCSP, Microsoft MVP 🇨🇭
mRr3b00t @UK_Daniel_Card
123K Followers 8K Following Department of Cyber WAR. Member of the Counter Spider Collective. Wielder of AI to defend in Cyber Space. Ralph Vibe Specialist. VibeOps Operator!
Tech Girl @TechGrlTweeter
1K Followers 1K Following
Merill Fernando @merill
20K Followers 4K Following Ex-Microsoft PM | Tweets my own Built → https://t.co/QbUp63ffXf • https://t.co/8W7yvQi3jb • https://t.co/NFLDqDIY8h • https://t.co/tSWrIw8Ajh 📰 Newsletter→ https://t.co/tPzAEl0Zuq & https://t.co/894nfObWuU 🎙️ Podcast→ https://t.co/TBlNKTzn8t
Steve Syfuhs @SteveSyfuhs
16K Followers 2K Following Windows and Authentication at Microsoft. Developer. Mostly dog pictures. Might actually be two dogs in a trench coat. 🇺🇸 / 🇨🇦 @syfuhs.net on blue sky
Jef Kazimer @JefTek
5K Followers 3K Following Principal Product Manager @Microsoft #MicrosoftEmployee #Microsoft #Entra #Identity #EntraID - Tweets are my own
Greg Linares (Laughin... @Laughing_Mantis
37K Followers 2K Following 20+ yrs in Infosec. Malware Influencer. I turn Malware into Art and Music. Art @MalwareArt. 4x Pwnie Nominee. 𝕍𝕏. GameDev. Autistic.
John Breth (JB) | Cyb... @JBizzle703
32K Followers 770 Following Founder (@jbc_sec) | IT/Cyber Architect | Author ▶️ https://t.co/tQe0lylvuo Maine born🦞 | CyberSec Pitbull USAF UMUC JHU
Fabian Bader @fabian_bader
10K Followers 890 Following #Security #Azure #AAD #MDE #M365 #AD #PKI #XDR #EntraID Microsoft MVP Tweets and opinions are my own @[email protected]
Michael Argast @michaelargast
1K Followers 1K Following https://t.co/yoGWoJCyQN co-founder - Cybersecurity programs for small to medium business. Parent, environmentalist, infovore. He/him.
Pomme @pxmme1337
7K Followers 430 Following Genuine oddity | Pomme@Hackerone | Pomme@Intigriti | ByeFelicia@BugCrowd | Senior Sec Engineer @ somewhere | Ex-HackerOne














