g3n3r4l15
-
Chat Control Must Be Stopped Now (privacyguides.org)
Act now to stop chat control mass surveillance. privacyguides.org
-
AI Coding Blog Post by Geohot (geohot.github.io)
A blog post on AI coding, exploring the intersection of artificial intelligence and software development.
-
beaglesecurity.substack.com (beaglesecurity.substack.com)
AI-Powered Ransomware Emerges as Threat – The first AI-powered ransomware is here, marking a new era in automated cyber threats.
-
Widespread npm supply chain attack impacts debug, chalk, and beyond, with over 2 billion weekly downloads compromised.
-
18 Popular Code Packages Hacked (krebsonsecurity.com)
Eighteen popular code packages were hacked and rigged to steal crypto in a major supply chain attack.
-
GhostAction GitHub Steals 3,325 Secrets (bleepingcomputer.com)
Hackers steal 3,325 secrets in the GhostAction GitHub supply chain attack, compromising numerous repositories.
-
NPM Packages Compromised via Maintainer Hack (orca.security)
NPM packages were compromised after maintainer 'qix' was hacked, leading to a widespread supply chain incident.
-
Salt Typhoon Hack Affects Everyone in US (proton.me)
The Salt Typhoon hack affects everyone in the US, according to a new security advisory.
-
Anatomy of a Billion-Download NPM Attack (jdstaerk.substack.com)
Analysis of the malicious code found in the largest NPM supply-chain attack in history.
-
Security Alert for chalk, debug, color (semgrep.dev)
chalk, debug and color on npm compromised in new supply chain attack, prompting a major security alert.
-
Major NPM Attack Impacts Mobile Apps (nowsecure.com)
Major NPM supply-chain attack has a potential impact on mobile applications, exposing a vast attack surface.
-
Software Packages Hit in Supply-Chain Attack (arstechnica.com)
Software packages with more than 2 billion weekly downloads hit in a massive supply-chain attack.
-
APT37 Targets Windows with Rust Backdoor (zscaler.com)
APT37 targets Windows with a Rust backdoor and Python loader in a new campaign.
-
mXSS Cheatsheet for Web Security (sonarsource.github.io)
A comprehensive mXSS cheatsheet for understanding and preventing mutation-based XSS vulnerabilities.
-
OWASP Checklist Tracker for Testing (adanalvarez.github.io)
An OWASP checklist tracker to help manage and track web security testing guide progress.
X2
-
Japan PSIA Database Allegedly Leaked (@H4ckmanac)
A threat actor claims to have leaked the full 2.3 TB database of Japan’s Public Security Intelligence Agency (PSIA). Watch Here
-
GFW Report on Great Firewall Leak (@gfw_report)
The Great Firewall of China (GFW) experienced a massive internal document leak, exposing over 500GB of source code and logs. Watch Here
y0utube4
-
Gen AI, Cybersecurity & AI Agents (youtube.com)
Experts answer questions on Gen AI, cybersecurity, and AI agents in a dedicated session. Watch Here
-
One Prompt Hacked Lenovo’s Chatbot (youtube.com)
A single prompt was used to hack Lenovo’s chatbot, demonstrating a critical vulnerability. Watch Here
-
Largest npm Supply Chain Attack History (youtube.com)
Analysis of what is potentially the largest supply chain attack in npm history. Watch Here
-
Biggest Supply Chain Hack Ever (youtube.com)
This is literally the biggest supply chain hack ever, with unprecedented scale and impact. Watch Here
g1thub10
-
MCP Server for Metasploit Integration (github.com)
An MCP Server for Metasploit, enabling new integration and automation capabilities for the framework. Explore on GitHub
-
Cobalt Strike Aggressor Script Arsenal (github.com)
An Aggressor script to automatically download and load an arsenal of open source and private Cobalt Strike tooling. Explore on GitHub
-
CVE-2025-57817 GitHub Advisory Details (github.com)
The GitHub Advisory Database entry for CVE-2025-57817, providing details on the vulnerability. Explore on GitHub
-
FancyTracker Firefox Port for PostMessage (github.com)
A modern postMessage tracker ported to Firefox, inspired by Frans Rosens original work. Explore on GitHub
-
FlareSolverr Bypasses Cloudflare Protection (github.com)
A proxy server to bypass Cloudflare protection, useful for web scraping and automation. Explore on GitHub
-
CoRPhone Android Kernel Pwn Challenge (github.com)
CoRCTF 2025 - CoRPhone: An Android Kernel Pwn challenge from the capture the flag event. Explore on GitHub
-
Inboxfuscation for Mailbox Rule Obfuscation (github.com)
An advanced framework for mailbox rule obfuscation and detection in Exchange environments. Explore on GitHub
-
BadPIE for Security Testing (github.com)
A tool named badpie for various security testing purposes. Explore on GitHub
-
Sni5Gect 5GNR Sniffing Framework (github.com)
A 5G sniffer and downlink injector framework with Wireshark support for network analysis. Explore on GitHub
-
Crimson7 NPM Scanner for Supply Chain (github.com)
An advanced supply chain security analysis tool for detecting malicious NPM packages from the September 2025 compromise. Explore on GitHub