Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Tanawts

@Enigma@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Things are not always what they seem

Redfin | Rent Head of Information Security

Former Ubisoft Director of Security Operations
Microsoft Alumni | Former Director of MSRC's Cloud Incident Response | He/Him/Hrm | Philosopher & Ninja

SANS:
GCIH #16353 - Cerified Incident Handler
GWAPT #3274- Web Application Pen Tester
GXPN #164 - Exploit Researcher and Advanced Penetration Tester

370 Followers
123 Following
20 Posts
Joined November 06, 2022
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago

Previous internet worms, you could patch to protect yourself; these new worms aren't stopped by patching, there's a fundamental change needed to your development lifecycle thats needed, and you should be working on it right_now.

A great write up by StepSecurity to give a recap of the last few days this week.

https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough

stepsecurity.io

5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough - StepSecurity

7
0
3
1
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago

Very prudent slides from Blue Hat 2026 a few weeks ago.

"A compromised dev workstation is NOT a user endpoint compromise -- it is potentially a compromise of every service the workstations tokens can reach.

3
0
1
0
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago

You may have heard that Github had an incident recently involving the TeamPCP Supply Chain Worm, in this case a poisoned Visual Studio Code Extension. I cannot stress this enough, this is not a 'GitHub only' risk, these worms propagate by stealing personal access tokens, ssh keys, api keys, and other forms of credentials to infect other downstream users/consumers.

Did you or your company also install/update the same Visual Studio Code Extension that GitHub did?

These worms are spreading fast, May 11th, we saw announcements from StepSecurity that 174 packages were compromised. On May 19th, another round added an additional 323 packages as compromised.

If you have not already:
* You should be taking actions to block auto-updates of packages with Cooldown timers to prevent a package refresh that pulls in a poisoned package. https://cooldowns.dev/

* You should be implementing governance controls over Visual Studio Code to inventory and allow/deny list extensions: https://code.visualstudio.com/docs/enterprise/policies

* Lastly, should be checking your incident response processes to be able to quickly respond quickly to revocation of Personal Access Tokens (PATs) and other dev credentials. https://github.blog/changelog/2025-04-29-credential-revocation-api-to-revoke-exposed-pats-is-now-generally-available/

cooldowns.dev

Dependency Cooldowns - Dependency Cooldowns

A guide to configuring dependency cooldowns across package managers to protect against supply chain attacks.

2
0
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 26mo ago
Replying to
@jerry I am frequently reminded how fortunate I am that I hitched my horse to this specific corner of the fediverse
41
0
3
0
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago
Replying to
@GossiTheDog@cyberplace.social , can we get a signal boost? Cooldown enforcement on Extensions, Packages, and Plugins are Table stakes and should not be optional or missing features from MS.
1
0
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago

RE: @techradar@flipboard.com

Yaaa, you will want Incident Reports to be certified organic...

Templates and style-guides are highly recommended though

flipboard.com
1
5
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago

Well, this post aged well...

1
0
1
0
Open post
Tanawts @Enigma@infosec.exchange
· 17mo ago
Replying to
@evacide@hachyderm.io in more ways than one... I worry just how much technology and infosec will be used to proliferate fascism
6
0
2
0
Open post
Tanawts @Enigma@infosec.exchange
· 13mo ago
Replying to
@GossiTheDog@cyberplace.social "The bar is low."
3
0
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 16mo ago
Replying to
@Viss@mastodon.social my gut instinct tells me that it will look like an initial wave of Contractor work as businesses start to realize a hangover is coming, followed by a quarter or two of re-calculated forecasts, and then an uptick of FTE hiring due to the hangover really setting in with better data on scope+effort for projects on the next semester of work.
4
2
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 13mo ago
Replying to
@BleepingComputer@infosec.exchange It would be nice if Github could be talked to about their preference for strong wording so as not to cause a panic... Patched Versions: None Affected versions: All? Remediation steps, blanket rotate all creds in all things with dependencies on debug? come on folks... https://github.com/advisories/GHSA-8mgj-vmr8-frr6
GHSA-8mgj-vmr8-frr6 - GitHub Advisory Database
GitHub

GHSA-8mgj-vmr8-frr6 - GitHub Advisory Database

Duplicate Advisory: Malware in debug

2
2
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 16mo ago
Replying to
@Viss@mastodon.social @rytmis@hachyderm.io @th3blu3kn19ht@infosec.exchange "Can't Install Simple Security Program"
2
2
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 16mo ago
Replying to
@Viss@mastodon.social I wonder what the rehire boom will look like...
2
15
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 16mo ago
Replying to
@Viss@mastodon.social @th3blu3kn19ht@infosec.exchange I am anticipating that it won't really be 'AI' contract work, but contract work for things that companies thought would be solved by AI that weren't.
1
2
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 13mo ago
Replying to
@BleepingComputer@infosec.exchange Ok, fixed, github updated their advisory to reflect the affected debug version: 4.4.2
0
0
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago

If you are a GitHub Enterprise Server customer, you will need to take action. GitHub announced that one of the keys compromised by the threat actor breach was a signing key.

https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/

Investigation update: GitHub Enterprise Server signing key rotation
The GitHub Blog

Investigation update: GitHub Enterprise Server signing key rotation

GitHub Enterprise Server customers need to take immediate action.

0
0
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago

If you're keeping score, it's been a very big week

https://cybersecuritynews.com/megalodon-malware-github-repos/

cybersecuritynews.com
0
0
0
0
Open post
Tanawts @Enigma@infosec.exchange
· 4mo ago
Replying to
@briankrebs@infosec.exchange I can get you bootstrapped. What's the best means to get you my contact info.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:47:05 UTC