Register and share your invite link to earn from video plays and referrals.

Search results for 196ウーマン
196ウーマン community
One keyword maps to one global community path.
Create community
People
Not Found
Tweets including 196ウーマン
📊 @Solana is the largest network by RWA holder count at 290,353, up 133.5% year-to-date Below is the breakdown by asset class and market share: 1) Stocks: 234.6K (80.8%) 2) Commodities: 27.2K (9.4%) 3) U.S. Treasury Debt: 8.9K (3.1%) 4) Specialty Finance: 8.1K (2.8%) 5) Asset-Backed Credit: 5.6K (1.9%) 6) Non-US Government Debt: 4.3K (1.5%) 7) Real Estate: 1.3K (0.5%) 8) Diversified Credit: 159 (0.1%) 9) Corporate Credit: 71 (0.02%) 10) Active Strategies: 27 (0.01%) 11) Private Equity: 20 (0.01%) 12) Cryptocurrencies: 12 (0.01%)
Show more
🚨 node-ipc is compromised again. Three new malicious versions just dropped: 9.1.6, 9.2.3, and 12.0.1. Socket’s AI scanner flagged them as malware within three minutes of publication. The attack vector: a dormant maintainer account (atiertant) was likely taken over via an expired email domain. The attacker registered the lapsed domain, triggered an npm password reset, and gained publish rights to a package with millions of historical downloads. The payload is a credential stealer embedded in the CommonJS entrypoint (node-ipc.cjs). It activates on require(“node-ipc”), not through a postinstall script. Here’s what it does: •Fingerprints the host (OS, arch, hostname, uname) •Harvests 113-127 credential file patterns depending on platform (AWS, GCP, Azure, SSH keys, Kubernetes configs, npm tokens, .env files, shell histories, macOS Keychain databases, and more) •Dumps the entire process.env, capturing every CI secret and cloud credential in memory •Builds a gzip archive in a temp directory •Exfiltrates everything over DNS TXT queries to bt[.]node[.]js, using a bootstrap resolver at sh[.]azurestaticprovider[.]net:443 (a deliberate lookalike of Microsoft’s Azure Static Web Apps domain) The DNS exfiltration is chunked. A 500 KB archive generates roughly 29,400 TXT queries. The body is XOR-encrypted with a SHA-256 keystream, base64-encoded, alphabet-substituted, and split into 31-character chunks before hex-encoding into DNS labels. Header, data, and footer queries use xh, xd, and xf prefixes respectively. The malware forks a detached child process (env var __ntw=1) so credential theft runs silently in the background. It also exposes a __ntRun export, meaning any downstream code that calls require(“node-ipc”).__ntRun() can trigger a second collection/exfiltration cycle. ESM-only consumers using the import path are not affected by the reviewed package metadata. CommonJS consumers are. This is the same package involved in the 2022 protestware incident. It has a history. If you use node-ipc: •Do not install 9.1.6, 9.2.3, or 12.0.1 •Audit your lockfiles for these versions •If you loaded the CommonJS entrypoint, treat all environment variables, SSH keys, cloud credentials, npm tokens, and local secrets as compromised. Rotate immediately. •Hunt for DNS TXT queries to bt[.]node[.]js and sh[.]azurestaticprovider[.]net in your network logs •Check for temp files matching /nt-/.tar.gz Credit to Ian Ahl (@TekDefense) for first publicly identifying the expired-domain account takeover vector. Developing story. Full technical breakdown and IOCs on the Socket blog:
Show more
Childhood poverty rates 🇺🇸 21.1% 🇬🇧 15.8% 🇮🇹 14.5% 🇨🇦 14.0% 🇱🇺 13.5% 🇵🇹 12.5% 🇬🇷 12.3% 🇫🇷 12.0% 🇦🇹 9.8% 🇩🇪 9.1% 🇨🇭 9.1% 🇨🇿 8.8% 🇰🇷 8.5% 🇸🇪 8.4% 🇳🇱 8.4% 🇧🇪 7.9% 🇳🇴 6.9% 🇮🇪 6.8% 🇫🇮 4.6% We must end the outrage that in the richest country in the history of the world, more than 1 in 5 children live in poverty.
Show more
0
2.3K
6.9K
1.7K
Forward to community
Child Poverty Rate in OECD Share of population aged 0-17 living in poverty: 1. 🇨🇷 Costa Rica: 29.6% 2. 🇮🇱 Israel: 23.2% 3. 🇪🇸 Spain: 21.5% 4. 🇺🇸 United States: 21.1% 5. 🇧🇬 Bulgaria: 19.1% 6. 🇷🇴 Romania: 17.7% 7. 🇬🇧 UK: 15.8% 8. 🇮🇹 Italy: 14.5% 9. 🇨🇦 Canada: 14.0% 10. 🇱🇺 Luxembourg: 13.5% 11. 🇱🇹 Lithuania: 12.8% 12. 🇸🇰 Slovakia: 12.8% 13. 🇵🇹 Portugal: 12.5% 14. 🇭🇷 Croatia: 12.3% 15. 🇬🇷 Greece: 12.3% 16. 🇫🇷 France: 12.0% 17. 🇭🇺 Hungary: 11.3% 18. 🇱🇻 Latvia: 10.0% 19. 🇦🇹 Austria: 9.8% 20. 🇩🇪 Germany: 9.1% 21. 🇨🇭 Switzerland: 9.1% 22. 🇨🇿 Czechia: 8.8% 23. 🇰🇷 South Korea: 8.5% 24. 🇸🇪 Sweden: 8.4% 25. 🇳🇱 Netherlands: 8.4% 26. 🇪🇪 Estonia: 8.2% 27. 🇧🇪 Belgium: 7.9% 28. 🇵🇱 Poland: 7.8% 29. 🇳🇴 Norway: 6.9% 30. 🇮🇪 Ireland: 6.8% 31. 🇸🇮 Slovenia: 6.2% 32. 🇫🇮 Finland: 4.6% Source: OECD Income Distribution Database. 2023 data, the latest available as of August 2026
Show more
🚨 SlowMist TI Alert 🚨 MistEye has received critical threat intelligence regarding an active supply chain attack compromising node-ipc, a foundational Node.js library. The malicious releases have been identified as versions 9.1.6, 9.2.3, and 12.0.1. Threat actors injected an obfuscated credential-stealing payload into the CommonJS bundle. Once loaded, it silently harvests over 90 categories of developer data—including AWS, Azure, GCP, SSH, K8s tokens, and Terraform states—and exfiltrates it to attacker-controlled infrastructure. We have synchronized this IOC with our clients immediately. Detection & Remediation: Please urgently audit your environments for exposure: • Dependencies: Run npm ls node-ipc --all to identify direct or transitive inclusions. • Lockfiles: Search package-lock.json, yarn.lock, or pnpm-lock.yaml for the affected version ranges. • CI/CD: Review pipeline jobs executed after May 14, 2026, that may have pulled loose semver updates (~9.1.x, ^12, etc.). ⚠️ Critical Action: If a compromised version was installed, assume certain compromise. Do not wait for exfiltration confirmation. Downgrade to a known safe version immediately and aggressively rotate all credentials, tokens, and environment secrets present on the affected machine or CI runner. As always, stay vigilant!
Show more