注册并分享邀请链接,可获得视频播放与邀请奖励。

23pds (山哥)
@im23pds
Dad/@SlowMist_Team Partner&CISO/#Web3# Security Researcher/RedTeam/Pentester/Ai安全猎人 #bitcoin#
6K 正在关注    15.2K 粉丝
🤣 AI 还说不懂 人心险恶
大裁员后的翻车来了。这几天,Meta 旗下的 Instagram,被曝 AI 助手出现史诗级漏洞,导致多个 Ins 博主账号被盗。 平台给 AI 助手,默认开了一个超级权限,可以在无任何验证的情况下,直接帮人修改 Ins 的绑定邮箱。 流程则是 1. 用 VPN 假装自己在目标账号的国家 2. 跑到 Meta AI 聊天里,说我是这个账号的主人,想换个新邮箱 3. AI 傻乎乎地相信了,发验证码给黑客的新邮箱 4. 黑客把验证码告诉 AI,AI 就直接把账号邮箱,换成黑客的了,然后黑客就能重置密码、抢走账号 目前,Meta 已紧急修补了这个巨大漏洞。
显示更多
🎉 正式宣布!imBack 已成为 @SlowMist_Team 慢雾区生态合作伙伴! 慢雾( imBack( 感谢慢雾安全团队的认可与支持! #SlowMist# #区块链安全# #CryptoRecovery# #imBack#
显示更多
TrapDoor 加密货币窃取活动正在npm、PyPI和 目前已发现34个恶意软件包和384个版本及构件,攻击者持续在各生态系统中推送新版本。 TrapDoor主要针对加密货币、DeFi、AI和安全领域的开发者。
显示更多
🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io. Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems. TrapDoor targets #crypto#, #DeFi#, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys. Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.
显示更多
这三天集中使用腾讯的 Marvis、CodeBuddy、WorkBuddy,三个结合起来用,设计架构、开发项目、审查代码真的不错,模型使用GLM-5.1、DeepSeek-V4-Pro,外出时配合元宝远程下发指令,很方便。 想配合微信操作,可惜… 微信目前只能绑一个Agent。
显示更多
Polymarket 正在被黑客攻击,合约被利用,超5000个账户被攻击和超60万美元的资产被转走 今天下午,Zach @zachxbt 最先发出社区警报:一个Polymarket 部署者地址似乎已在Polygon网络上遭到入侵 随后Bubblemaps也发出警报,Polymarket 合约被利用,黑客正以平均30秒一起盗窃案发生的速度,转走用户资产 Polymarket 回应称,是内部运营的钱包私钥泄露所致,并非合约被攻击
显示更多
ALERT: 🚨 Polymarket contract exploited Attackers are removing 5,000 $POL every 30 seconds – $600k stolen so far Pause all Polymarket activity for now
0
25
28
4
转发到社区
报告:Nx Console v18.95.0 供应链被黑报告
GitHub 被黑涉及的VS 插件 Nx Console 👇
We’re continuing to work with Microsoft and GitHub to investigate the impact of the malicious Nx Console version 18.95.0. I'll share any updates on X (@jeffbcross and @NxDevTools) as well as in our security advisory: Initially, Microsoft indicated to us that there were 28 installs of the malicious version 18.95.0. Based on our own analytics for the compromised version, we currently believe the number of users who received the malicious package may be significantly higher; potentially over 6k installs. We’ll keep working to determine the actual impact and exposure, and I don’t want to speculate beyond the facts we have right now. But I also don’t want to minimize the situation. This is my top priority right now. Our team has been, and continues to be focused on understanding exactly what happened, helping affected users, hardening our systems and release processes, and being as transparent as possible throughout the investigation.
显示更多
最新事后分析证实 @LayerZero_Labs 的集中化基础设施被朝鲜黑客入侵,导致 rsETH 桥被盗 $2.92 亿。 一名工程师被社工攻击,其笔记本被完全控制 6 周,而不被发现,暴露惊人的单点故障和监控缺失。 这延续了 LZ Labs 一贯的糟糕操作安全,包括用生产 multisig 交易垃圾币、密钥多年未轮换,且对风险轻描淡写。 这一切本可避免。希望行业能向安全优先的基础设施迁移,别再重蹈覆辙。
显示更多
We’re sharing our completed post-mortem on the April 18th incident, prepared with @Mandiant and @CrowdStrike. We are publishing both an executive summary and the full report at the link below. Over the past four weeks, we’ve worked with hundreds of partners to help them understand their current security posture, and harden it where appropriate. We’ll continue this work, alongside taking additional proactive steps for the benefit of not only our partners, but also the ecosystem as a whole. We want to extend our thanks to our partners for their support and patience this past month. There’s a reason that over $12 billion has moved across the network in the past four weeks, and why the world’s most valuable asset issuers have stood by our side: they believe in us, in what the LayerZero protocol has to offer, and in the value of modular, isolated, application-controlled security. The work continues. And we look forward to continue showing up for the applications that trust us with their business, as well as the broader ecosystem.
显示更多
最新 nginx 版本 1.31.0 全新的远程代码执行漏洞
Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0. nginx-rift has been patched, but our security agent Vega has found a new 0 day. We will release the full technical writeup with ASLR bypass 30 days after the patch on
显示更多
0
7
157
24
转发到社区
🧐 我们@SlowMist_Team 刚刚分析网络犯罪论坛的爆料,黑客可能用Anthropic 的Mythos 安全AI,用它精准突破 GitHub 的防线,偷走约4000个核心内部仓库: 里面有Copilot的源码、CodeQL的算法、Actions运行时和整个计费系统等等太多信息了。 后续分析这些代码,可能会再次攻击,对整个开源社区产生深远安全影响。 cc @evilcos
显示更多
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
显示更多
0
20
191
26
转发到社区
GitHub 官方发布更多细节: 一起员工设备被攻破,该事件涉及一个被污染的 VS Code 扩展。 这种方式我们 @SlowMist_Team 很早就公布过手法。真是醉了😵‍💫
显示更多
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
显示更多
NPM 互联网上最成功的俄罗斯套娃命令…大坑 NPM让前端进入万物皆包的时代,每天都在npm install… 装个业务20M,能装几千个依赖 2.3G,而且你永远不知道自己装的是什么,这些依赖有没有人维护、有没有被投毒🤣
显示更多
UPDATE: So far we've identified 639 compromised npm package versions across 323 unique packages in tonight’s Mini Shai-Hulud wave. That includes 558 versions across 279 unique @​antv packages. Most were detected within ~6 minutes of publication.
显示更多
该事件源于通过Mini Shai-Hulud活动的TanStack npm供应链攻击。
🔎 开发者注意排查了 👇
每周被下载 110 万次的开源基础包,被系统标记为已知恶意软件。 它的供应链安全评分直接归零。 这是一个名叫“迷你沙虫”(Mini Shai-Hulud)的代码蠕虫。 它近期在开源代码库里完成了大面积感染。 受害者名单里全是高频组件。 阿里巴巴的数据可视化套件 antv,数百个包被植入恶意代码。 前端常用的 echarts-for-react、timeago.js 等工具也无一幸免。 单是 echarts-for-react 这一项,每周的装机量就高达 110 万次。 起因是一个普通开发者账号失守。 用户名 atool 的账号被盗取了权限。 黑客接管后,往这些底层组件里塞进了混淆的恶意代码。 带毒的 3.2.7 版本发布仅仅 19 分钟,漏洞扫描就全红了。 现代软件工业的底层其实非常脆弱。 无数估值百亿的科技公司,底层都依赖着这些靠个人维护的开源轮子。 只要一个邮箱的密码被攻破,几百万个下游项目的安全大门就会被同时撬开。
显示更多
昨天开始,各种模仿攻击者出现,要乱套了😅
MistEye 🚨 NPM 蠕虫 Shai-Hulud 开源,供应链风险升高。 Shai-Hulud 是近期备受关注的 'Git 恶意蠕虫',现已被开源。 这意味着 TeamPCP 或其他方发布了完整可执行版本,潜在威胁显著增加。 各项目方和平台需提高警惕,立即加强防护,防范 NPM 供应链攻击。
显示更多
🙂‍↔️ 现在每天两眼一睁就是新的CVE、新的攻击 😢
Today's two supply chain incidents are likely connected: 1. `actions-cool/issues-helper` was compromised 2. AntV was compromised shortly after I noticed AntV was using `actions-cool/issues-helper@main` in GitHub Actions. Rspack was not affected because we pin Actions to commit ids via renovate's `pinGitHubActionDigests`. Strongly recommend enabling it.
显示更多
Granafa 调查没有发现任何证据表明客户的生产系统或运营受到损害。 经过初步评估,除了源代码外,下载的内容还包括一些Grafana Labs团队用来协作和存储内部运营信息以及有关业务的其他详细信息的GitHub存储库。
显示更多
⚠️ On May 16, 2026, we confirmed a targeted attack by a cybercrime group that gained unauthorized access to our GitHub repositories and downloaded our codebase. Here is the latest update about our investigations.
显示更多
wtf?? GitHub 疑似被黑? 坐等看看
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
显示更多
🙂‍↕️ Verus-以太坊跨链桥( AI 持续加速攻击 😑
🚨 Community alert: Blockaid's exploit detection system has identified an on-going exploit on the @veruscoin Verus-Ethereum Bridge ( ~$11.58M drained so far. More details in🧵
显示更多