| Photography | @betapixels |
| Website | https://norsec.xyz |
| Bluesky | @theomegabit |
| Threads | @theomegabit |
| Photography | @betapixels |
| Website | https://norsec.xyz |
| Bluesky | @theomegabit |
| Threads | @theomegabit |
Happened to stumble upon a malicious repo on Github serving some info-stealer malware. Report submitted to @github
See: https://gist.github.com/theomegabit/624b4a9d18aa35fc792610576f379271
🚨 500+ malicious PRs. One campaign.
Wiz Research traced 6 waves of prt-scan starting 3 weeks earlier.
AI-powered, automated attacks exploiting pull_request_target.
Low success rate—but real npm + cloud creds hit.
Full story: https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign
So RSR is back (now BSI - background security improvements). The old name was better.
Raw specs aren't everything.
RE: https://infosec.exchange/@wiz/116058451362120328
Well this is kinda cool
Reason number 374 why Microsoft can’t be taken seriously.
I think I’m in the market for another mechanical keyboard.
~75% size. Butter keys. Backlit if possible. I currently have the Nuphy Air75 v1.
What should I look at now?