84 Followers
184 Following
140 Posts

undocumented feature enthusiast, sysadmin turned security analyst, amateur radio nerd, executive board member of a non-profit org, neuro-spicy, unapologetically anti-fascist

#blueteam #redteam #purpleteam #rainbowteam #infosec #hamradio

Pronounshe/him
Blueskyhttps://bsky.app/profile/aeris.cc
Websitehttps://aeris.cc

Elastic's security team has released Supply Chain Monitor, an internal tool that monitors top npm and PyPI packages for supply chain compromises, a tool that also caught the recent Axios incident

https://www.elastic.co/security-labs/how-we-caught-the-axios-supply-chain-attack

https://github.com/elastic/supply-chain-monitor

How we caught the Axios supply chain attack — Elastic Security Labs

Joe Desimone shares the story of how he caught the Axios supply chain attack with a proof of concept tool built in an afternoon.

CISA KEV dropped for F5 BIG-IP RCE on a Friday afternoon? Yeesh.

RE: https://infosec.exchange/@k3ym0/116297258355796740

now do alt text on images in mastodon posts

This is your reminder that Chuck Norris was a hateful, racist ghoul.
$3 at the local dollar store. Can't imagine this will take long to pick. 
Looking at you, Mozilla.

RE: https://infosec.exchange/@patrickcmiller/116245864189047078

Is this the new "don't push to prod on Friday"?